<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Cisco forum - dslreports.com community</title>
<link>http://www.dslreports.com/forum/equip,cis</link>
<description>Cisco forum current topics</description>
<language>en</language>
<copyright>Copyright 2007, dslreports.com</copyright>
<pubDate>Tue, 07 Oct 2008 01:02:40 EDT</pubDate>
<lastBuildDate>Tue, 07 Oct 2008 01:02:40 EDT</lastBuildDate>

<image>
<title>dslreports.com</title>
<url>http://i.dslr.net/bbrdisc1.gif</url>
<link>http://www.dslreports.com</link>
<width>19</width>
<height>18</height>
<description>bbr disc</description>
</image>

<item>
<title>[HELP] cisco851  adsl config</title>
<link>http://www.dslreports.com/forum/remark,21224615</link>
<description><![CDATA[Hi,

I am trying to make my cisco 851 cpe talk to bras router to get ip address via dhcp. 

 cpe-(atm0)---dslam--eth--BRAS

I see that cpe sends out DHCP DISCOVER to BRAS, my BRAS responds with DHCP OFFER, but i do not see cpe receiving it.
I did talk with ciena dslam  support, looks like dslam is okay. Is there any way i can see on cisco --stats  or any other config help will be deeply appreciated.

cpe3#sh running-config 
Building configuration...

Current configuration : 3746 bytes
!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname cpe3
!
boot-start-marker
boot-end-marker
!
logging buffered 51200 warnings
!
no aaa new-model
!
resource policy
!
ip dhcp limited-broadcast-address
!
!
ip cef    
no ip domain lookup
ip domain name yourdomain.com
vpdn enable
!
!
!
crypto pki trustpoint TP-self-signed-1383177109
 enrollment selfsigned
 subject-name cn=IOS-Self-Signed-Certificate-1383177109
 revocation-check none
 rsakeypair TP-self-signed-1383177109
!
!
crypto pki certificate chain TP-self-signed-1383177109
 certificate self-signed 01
  3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030 
  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274 
  69666963 6174652D 31333833 31373731 3039301E 170D3032 30333031 30303035 
  34305A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649 
  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 33383331 
  37373130 3930819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281 
  8100C302 4153E462 8FD7D2FF 069C0773 FDA59E64 F33E439A B8C0024B 634EFC5D 
  F22CC9F9 EAF270E6 0C1555E3 9CE733D4 AA47AF2D C2B00D8C 337E3067 3D3B6135 
  9B7D8AD3 43EE7B75 41B617BB 1F24475B C340BDB7 99361E24 7A3ABD69 C76D2C44 
  2C677DD4 B38DFDC9 7FE7F1F5 EFB8AC43 EA2030DF 5E219EFF 1EDFE6DD 5A6D0612 
  35710203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603 
  551D1104 1B301982 17796F75 726E616D 652E796F 7572646F 6D61696E 2E636F6D 
  301F0603 551D2304 18301680 1456BD1B 3198B391 2963CAE5 8A9DC224 0C40A53D 
  28301D06 03551D0E 04160414 56BD1B31 98B39129 63CAE58A 9DC2240C 40A53D28 
  300D0609 2A864886 F70D0101 04050003 81810013 F24A0BFE E4224385 998B6111 
  2DE1A7E5 0E616506 2EA41AD0 B9CC459D 5C501E26 4FC4A146 CBC2E739 D051AA43 
  03955521 747741AE 3B68A135 4F2341C4 7C97BEC3 A71A0644 EBAC3783 7C715A64 
  97ED17EE D298BB35 EB649AF3 BBFA125A AAD3AEF0 9A1D493E A3AA696C A119D847 
  FC999D04 24302EAD CA5C076F 05A9364C 03C497
  quit
username cisco privilege 15 secret 5 $1$W6se$tTqBxoQw80kzKM8YWsDsD1
!
! 
!
bridge irb
!
!
interface ATM0
 no ip address
 no atm ilmi-keepalive
 dsl operating-mode auto 
 hold-queue 208 in
!
interface ATM0.1 point-to-point
 no snmp trap link-status
 pvc 8/37 
  encapsulation aal5snap
 !
 bridge-group 1
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface BVI1
 ip address dhcp
!
!
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 102 interface Dialer1 overload
!
no cdp run
!
control-plane
!
bridge 1 protocol ieee
bridge 1 route ip]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21224615</guid>
<pubDate>2008-10-06 17:33:10</pubDate>
</item>

<item>
<title>[HELP] Cisco 800 series-Configuration page</title>
<link>http://www.dslreports.com/forum/remark,21188972</link>
<description><![CDATA[I'm don't know exactly what model I have but its a older 800 series SOHO router.  I'm have troubles accessing the configuration page through IE.  Tried Firefox but that has never worked right.  I tried doing a search but the best I could come up with was that newer browsers have problems with the configuration page.  I thought there was something special I had to do years ago with IE, but I don't remember.  Could someone lend a hand.
--
Hey, I don't believe that any system is totally secure|This is Unix, I know this stuff!|Some people get rich and others eat shit and die.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21188972</guid>
<pubDate>2008-09-29 20:35:50</pubDate>
</item>

<item>
<title>[HELP] Memory Upgrade on 871w: error... :-(</title>
<link>http://www.dslreports.com/forum/remark,21168534</link>
<description><![CDATA[Today I purchased a DRAM module for my 871w. I found a new Kingston KVR133X64C3L/128, as mentioned in the FAQ. After putting it in, the router bootet into rommon, with the following text on the console:
System Bootstrap, Version 12.3(8r)YI2, RELEASE SOFTWARE&#012;Technical Support: http://www.cisco.com/techsupport&#012;Copyright (c) 2005 by cisco Systems, Inc.&#012; &#012;C870 series (Board ID: 3-148) platform with 262144 Kbytes of main memory&#012; &#012;*** Data Access Exception ***&#012;PC = 0xfff2a180, Vector = 0x300, SP = 0x800048cc&#012; &#012;System Bootstrap, Version 12.3(8r)YI2, RELEASE SOFTWARE&#012;Technical Support: http://www.cisco.com/techsupport&#012;Copyright (c) 2005 by cisco Systems, Inc.&#012; &#012;C870 series (Board ID: 3-148) platform with 262144 Kbytes of main memory&#012; &#012;*** Data Access Exception ***&#012;PC = 0xfff2a180, Vector = 0x300, SP = 0x800048cc&#012; &#012;System Bootstrap, Version 12.3(8r)YI2, RELEASE SOFTWARE&#012;Technical Support: http://www.cisco.com/techsupport&#012;Copyright (c) 2005 by cisco Systems, Inc.&#012; &#012;C870 series (Board ID: 3-148) platform with 262144 Kbytes of main memory&#012; &#012;rommon 1 &gt;&#012;
At this moment, I am not capable of testing the ram in another device, but I guess it's ok, since it was new, and I read about the same problems in a thread from april'08.

Any ideas to get it working?

--
Using a Cisco 871w @home on a 16mbit cable-isp in Vienna, Austria. On broadband since 1997...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21168534</guid>
<pubDate>2008-09-25 17:16:53</pubDate>
</item>

<item>
<title>[HELP] VPN not accessing internal network on ASA 5505</title>
<link>http://www.dslreports.com/forum/remark,21203449</link>
<description><![CDATA[I setup our ASA 5505 as per Cisco's instructions here (http://is.gd/3qHt). I can connect with the AnyConnect client via SSL and have configured split tunneling, yet no matter what I do I can't seem to access any internal hosts. I've tried various NAT exemption rules but to no avail, and cannot get any contact between the VPN subnet (192.168.25.X) and the inside network (192.168.50.X).

Configuration is attached and any help is GREATLY appreciated. At this point I'm still an ASDM lackey, so ASDM-centric guidance is appreciated.

Result of the command: "show running-config"&#012; &#012;: Saved&#012;:&#012;ASA Version 8.0(4) &#012;!&#012;hostname border&#012;domain-name &#012;!&#012;interface Vlan1&#012; nameif inside&#012; security-level 100&#012; ip address 192.168.50.1 255.255.255.0 &#012; ospf cost 10&#012;!&#012;interface Vlan2&#012; nameif outside&#012; security-level 0&#012; ip address 208.104.193.45 255.255.255.248 &#012; ospf cost 10&#012;!&#012;interface Vlan3&#012; no forward interface Vlan1&#012; nameif dmz&#012; security-level 50&#012; ip address 192.168.66.1 255.255.255.0 &#012; ospf cost 10&#012;!&#012;interface Ethernet0/0&#012; switchport access vlan 2&#012;!&#012;interface Ethernet0/1&#012;!&#012;interface Ethernet0/2&#012; switchport access vlan 3&#012;!&#012;interface Ethernet0/3&#012;!&#012;interface Ethernet0/4&#012;!&#012;interface Ethernet0/5&#012;!&#012;interface Ethernet0/6&#012;!&#012;interface Ethernet0/7&#012;!&#012;boot system disk0:/asa804-k8.bin&#012;same-security-traffic permit inter-interface&#012;same-security-traffic permit intra-interface&#012;access-list inside_nat0_outbound extended permit ip any 192.168.50.128 255.255.255.128 &#012;access-list inside_nat0_outbound remark VPN&#012;access-list inside_nat0_outbound extended permit ip 192.168.50.0 255.255.255.0 192.168.25.0 255.255.255.0 &#012;access-list VPNInternalNetworks standard permit 192.168.50.0 255.255.255.0 &#012;access-list VPNInternalNetworks standard permit 192.168.66.0 255.255.255.0 &#012;pager lines 24&#012;logging enable&#012;logging asdm informational&#012;mtu inside 1500&#012;mtu outside 1500&#012;mtu dmz 1500&#012;ip local pool VPN 192.168.50.150-192.168.50.200 mask 255.255.255.0&#012;ip local pool SSLClientPool 192.168.25.1-192.168.25.50 mask 255.255.255.0&#012;ip verify reverse-path interface outside&#012;icmp unreachable rate-limit 1 burst-size 1&#012;asdm image disk0:/asdm-613.bin&#012;no asdm history enable&#012;arp timeout 14400&#012;nat-control&#012;global (outside) 1 interface&#012;nat (inside) 0 access-list inside_nat0_outbound&#012;nat (inside) 1 192.168.50.0 255.255.255.0&#012;nat (dmz) 1 192.168.66.0 255.255.255.0&#012;static (inside,outside) tcp interface 3074 192.168.50.30 3074 netmask 255.255.255.255 &#012;static (dmz,outside) tcp 208.104.193.44 smtp 192.168.66.5 smtp netmask 255.255.255.255 &#012;static (inside,outside) tcp interface 25258 192.168.50.58 25258 netmask 255.255.255.255 &#012;static (inside,outside) tcp 208.104.193.44 13509 192.168.50.71 13509 netmask 255.255.255.255 &#012;static (dmz,outside) 208.104.193.43 192.168.66.10 netmask 255.255.255.255 &#012;static (dmz,outside) 208.104.193.42 192.168.66.4 netmask 255.255.255.255 &#012;static (inside,dmz) 192.168.50.0 192.168.50.0 netmask 255.255.255.0 &#012;access-group outside_access_in in interface outside&#012;!&#012;router rip&#012; version 1&#012;!&#012;route outside 0.0.0.0 0.0.0.0 208.104.193.41 1&#012;timeout xlate 3:00:00&#012;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&#012;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&#012;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&#012;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&#012;dynamic-access-policy-record DfltAccessPolicy&#012;# radius/cert info deleted&#012;vpn-addr-assign local reuse-delay 60&#012;telnet timeout 5&#012;ssh timeout 5&#012;console timeout 0&#012;dhcpd auto_config outside&#012;!&#012; &#012;threat-detection basic-threat&#012;threat-detection scanning-threat shun&#012;threat-detection statistics host&#012;threat-detection statistics port&#012;threat-detection statistics protocol&#012;threat-detection statistics access-list&#012;no threat-detection statistics tcp-intercept&#012;ntp server XXXXX source outside&#012;ssl trust-point ASDM_TrustPoint0 outside&#012;webvpn&#012; enable outside&#012; svc image disk0:/anyconnect-win-2.2.0140-k9.pkg 1&#012; svc image disk0:/anyconnect-linux-2.2.0140-k9.pkg 2&#012; svc image disk0:/anyconnect-macosx-i386-2.2.0140-k9.pkg 3&#012; svc enable&#012; tunnel-group-list enable&#012;group-policy SSLClientPolicy internal&#012;group-policy SSLClientPolicy attributes&#012; wins-server value 192.168.50.5&#012; dns-server value 192.168.50.5&#012; vpn-tunnel-protocol svc webvpn&#012; split-tunnel-policy tunnelspecified&#012; split-tunnel-network-list value VPNInternalNetworks&#012; default-domain value prevoyancegroup.local&#012; vlan none&#012; address-pools value SSLClientPool&#012; webvpn&#012;  svc keep-installer installed&#012;  svc rekey time 30&#012;  svc rekey method ssl&#012;  svc ask none default svc&#012;group-policy DefaultRAGroup internal&#012;group-policy DefaultRAGroup attributes&#012; wins-server value 192.168.50.5&#012; dns-server value 192.168.50.5&#012; vpn-tunnel-protocol l2tp-ipsec &#012; default-domain value prevoyancegroup.local&#012;group-policy DfltGrpPolicy attributes&#012; vpn-tunnel-protocol l2tp-ipsec &#012;tunnel-group DefaultRAGroup general-attributes&#012; address-pool VPN&#012; default-group-policy DefaultRAGroup&#012;tunnel-group DefaultRAGroup ipsec-attributes&#012; pre-shared-key *&#012;tunnel-group DefaultRAGroup ppp-attributes&#012; authentication ms-chap-v2&#012;tunnel-group SSLClientProfile type remote-access&#012;tunnel-group SSLClientProfile general-attributes&#012; authentication-server-group PrevoyanceGroup&#012; default-group-policy SSLClientPolicy&#012;tunnel-group SSLClientProfile webvpn-attributes&#012; group-alias "SSL VPN Client" enable&#012;!&#012;class-map inspection_default&#012; match default-inspection-traffic&#012;!&#012;!&#012;policy-map type inspect dns preset_dns_map&#012; parameters&#012;  message-length maximum 512&#012;policy-map global_policy&#012; class inspection_default&#012;  inspect dns preset_dns_map &#012;  inspect ftp &#012;  inspect h323 h225 &#012;  inspect h323 ras &#012;  inspect rsh &#012;  inspect rtsp &#012;  inspect esmtp &#012;  inspect sqlnet &#012;  inspect skinny  &#012;  inspect sunrpc &#012;  inspect xdmcp &#012;  inspect sip  &#012;  inspect netbios &#012;  inspect tftp &#012;!&#012;service-policy global_policy global&#012;smtp-server 192.168.66.4&#012;prompt hostname context &#012;Cryptochecksum:&#012;: end&#012;]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21203449</guid>
<pubDate>2008-10-02 11:15:49</pubDate>
</item>

<item>
<title>CCIE: To be or not to be......</title>
<link>http://www.dslreports.com/forum/remark,21213886</link>
<description><![CDATA[ I'm just about done with the CCNP certification track, however I'm torn on my next move  :hmm:

I'd like to dive into CCVP as an opportunity of enhancing my overall skillsets, as IP tlephony is a huge market that keeps growing by the day.

However there are obvious perks that come with CCIE(Routing/switching)cert. One of the obvious being immediate (...better) job prospects. The only handicap here is the significant amount of resources you have set aside to suit up for it.

Question is, Would it be wiser to take the CCVP track, get it over with, then concentrate on CCIE ?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21213886</guid>
<pubDate>2008-10-04 03:06:40</pubDate>
</item>

<item>
<title>Cisco Aironet 1240AG Access Configuration Help</title>
<link>http://www.dslreports.com/forum/remark,21205908</link>
<description><![CDATA[I have one of these that I need to configure and would like some help.  Basically, I'm not familiar with the wireless configuration aspect of it so I'm looking for some examples of WPA/WPA2 setups.  I tried using the web GUI to get it going (which I can but it's unencrypted) and then add the security but the web GUI sucks, of course and it's giving me fits.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21205908</guid>
<pubDate>2008-10-02 18:00:36</pubDate>
</item>

<item>
<title>CISCO 1750 IOS</title>
<link>http://www.dslreports.com/forum/remark,21211629</link>
<description><![CDATA[I am looking for the lastest IOS for my CISCO 1750. Can anyone please help? Thank you for your time!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21211629</guid>
<pubDate>2008-10-03 16:47:18</pubDate>
</item>

<item>
<title>[Config] Deny Reverse Path Check?</title>
<link>http://www.dslreports.com/forum/remark,21191423</link>
<description><![CDATA[
Outside = T1

ASA 5520,  I keep getting Deny TCP reverse path check from (IP) on interface OUTSIDE

Everything was working on the T1,  I just added the cablemodem for the general services for client PC's,  keeping the servers on the T1,  incoming routes to the servers aren't working, probably something to do with the default route and reverse path.   I want the cablemodem serving the clients and the t1 serving incoming/outgoing server services.

Do I need to setup static routes for each server?

config2asdm image disk0:/asdm512-k8.bin&#012;no asdm history enable&#012;:&#012;ASA Version 7.1(2) &#012;!&#012;hostname Cisco5520&#012;domain-name anon.org&#012;enable password ****************** encrypted&#012;names&#012;!&#012;interface GigabitEthernet0/0&#012; nameif OUTSIDE&#012; security-level 0&#012; ip address 74.223.14.150 255.255.255.248 &#012;!&#012;interface GigabitEthernet0/1&#012; nameif INSIDE&#012; security-level 100&#012; ip address 172.16.0.1 255.255.0.0 &#012;!&#012;interface GigabitEthernet0/2&#012; nameif DMZ&#012; security-level 50&#012; ip address 192.168.0.1 255.255.255.0 &#012;!&#012;interface GigabitEthernet0/3&#012; nameif CABLEMODEM&#012; security-level 0&#012; ip address 173.8.37.33 255.255.255.248 &#012;!&#012;interface Management0/0&#012; nameif management&#012; security-level 100&#012; ip address 192.168.1.1 255.255.255.0 &#012; management-only&#012;!&#012;passwd ********** encrypted&#012;ftp mode passive&#012;clock timezone EST -5&#012;clock summer-time EDT recurring&#012;dns server-group DefaultDNS&#012; domain-name elc-fg.org&#012;same-security-traffic permit intra-interface&#012;object-group service Streaming tcp-udp&#012; port-object range 8000 8001&#012; port-object range 6970 7000&#012; port-object eq 7007&#012; port-object eq 1755&#012;access-list outside_in extended permit gre any any &#012;access-list outside_in extended permit ip any any &#012;access-list outside_in extended permit tcp host 164.51.143.228 host 74.223.14.148 eq 3389 &#012;access-list outside_in extended permit tcp host 208.11.223.20 host 74.223.14.148 eq 3389 &#012;access-list outside_in extended permit tcp any host 74.223.14.147 eq smtp &#012;access-list outside_in extended permit tcp any host 74.223.14.147 eq www &#012;access-list outside_in extended permit tcp any host 74.223.14.147 eq https &#012;access-list outside_in extended permit tcp any host 74.223.14.146 eq www &#012;access-list outside_in extended permit tcp any host 74.223.14.146 eq pptp &#012;access-list INSIDE_nat0_outbound extended permit ip 172.16.0.0 255.255.0.0 192.168.99.0 255.255.255.0 &#012;access-list INSIDE_nat0_outbound extended permit ip any 172.16.200.0 255.255.254.0 inactive &#012;access-list INSIDE_nat0_outbound extended permit ip 172.168.0.0 255.255.0.0 192.168.99.0 255.255.255.0 &#012;access-list INSIDE_nat0_outbound extended permit ip any 172.166.200.0 255.255.254.0 &#012;access-list INSIDE_nat0_outbound_V1 extended permit ip interface INSIDE 192.168.99.0 255.255.255.0 &#012;access-list INSIDE_nat0_outbound_V1 extended permit ip 172.16.0.0 255.255.0.0 192.168.99.0 255.255.255.0 &#012;access-list csc extended permit tcp any any eq www &#012;access-list csc extended permit tcp any any eq https &#012;access-list csc extended permit tcp any any eq smtp &#012;access-list csc extended permit tcp any any eq pop3 &#012;access-list DMZ_pnat_outbound extended permit ip any any &#012;access-list DMZ_access_in extended permit ip any any &#012;access-list INSIDE_access_in extended permit ip any any &#012;access-list OUTSIDE_cryptomap_20_1 extended permit ip interface INSIDE 192.168.99.0 255.255.255.0 &#012;access-list OUTSIDE_cryptomap_20 extended permit ip 172.16.0.0 255.255.0.0 192.168.99.0 255.255.255.0 &#012;access-list CABLEMODEM_access_in extended permit ip any any &#012;pager lines 10&#012;logging enable&#012;logging monitor debugging&#012;logging asdm errors&#012;mtu OUTSIDE 1500&#012;mtu INSIDE 1500&#012;mtu DMZ 1500&#012;mtu CABLEMODEM 1500&#012;mtu management 1500&#012;ip verify reverse-path interface OUTSIDE&#012;ip verify reverse-path interface INSIDE&#012;no failover&#012;monitor-interface OUTSIDE&#012;monitor-interface INSIDE&#012;monitor-interface DMZ&#012;monitor-interface CABLEMODEM&#012;monitor-interface management&#012;asdm image disk0:/asdm512-k8.bin&#012;no asdm history enable&#012;arp timeout 14400&#012;nat-control&#012;global (OUTSIDE) 1 interface&#012;global (INSIDE) 3 interface&#012;global (CABLEMODEM) 4 interface&#012;nat (INSIDE) 0 access-list INSIDE_nat0_outbound_V1&#012;nat (INSIDE) 4 0.0.0.0 0.0.0.0&#012;nat (DMZ) 4 0.0.0.0 0.0.0.0&#012;static (INSIDE,OUTSIDE) tcp 74.223.14.146 pptp 172.16.0.3 pptp netmask 255.255.255.255 &#012;static (INSIDE,OUTSIDE) tcp 74.223.14.146 www 172.16.0.5 www netmask 255.255.255.255 &#012;static (INSIDE,OUTSIDE) tcp 74.223.14.148 3389 172.16.0.6 3389 netmask 255.255.255.255 &#012;static (INSIDE,OUTSIDE) 74.223.14.147 172.16.0.8 netmask 255.255.255.255 &#012;access-group outside_in in interface OUTSIDE&#012;access-group INSIDE_access_in in interface INSIDE&#012;access-group DMZ_access_in in interface DMZ&#012;access-group CABLEMODEM_access_in in interface CABLEMODEM&#012;rip INSIDE passive version 2&#012;rip DMZ passive version 2&#012;route INSIDE 0.0.0.0 0.0.0.0 74.223.14.145 2&#012;route CABLEMODEM 0.0.0.0 0.0.0.0 173.8.37.38 1&#012;timeout xlate 3:00:00&#012;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&#012;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00&#012;timeout mgcp-pat 0:05:00 sip 0:30:00 sip_media 0:02:00&#012;timeout uauth 0:05:00 absolute&#012;aaa-server DCs protocol nt&#012;aaa-server DCs host 172.168.0.3&#012; nt-auth-domain-controller AD1&#012;aaa-server DCs host 172.16.0.3&#012; nt-auth-domain-controller AD1&#012;username admin password ************** encrypted privilege 15&#012;aaa authentication ssh console LOCAL &#012;http server enable&#012;http 172.168.0.0 255.255.0.0 INSIDE&#012;http 172.16.0.0 255.255.0.0 INSIDE&#012;http 192.168.1.0 255.255.255.0 management&#012;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &#012;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac &#012;crypto map OUTSIDE_map 20 match address OUTSIDE_cryptomap_20&#012;crypto map OUTSIDE_map 20 set peer 75.145.61.41 &#012;crypto map OUTSIDE_map 20 set transform-set ESP-DES-MD5&#012;crypto map OUTSIDE_map interface OUTSIDE&#012;isakmp identity address &#012;isakmp enable OUTSIDE&#012;isakmp policy 10 authentication pre-share&#012;isakmp policy 10 encryption des&#012;isakmp policy 10 hash md5&#012;isakmp policy 10 group 1&#012;isakmp policy 10 lifetime 86400&#012;isakmp nat-traversal  20&#012;tunnel-group DefaultL2LGroup ipsec-attributes&#012; pre-shared-key *&#012; isakmp keepalive threshold infinite&#012;tunnel-group DefaultRAGroup ipsec-attributes&#012; pre-shared-key *&#012; isakmp keepalive threshold infinite&#012;tunnel-group 75.145.61.41 type ipsec-l2l&#012;tunnel-group 75.145.61.41 ipsec-attributes&#012; pre-shared-key *&#012; isakmp keepalive disable&#012;no tunnel-group-map enable ou&#012;no tunnel-group-map enable ike-id&#012;no tunnel-group-map enable peer-ip&#012;telnet 172.168.0.0 255.255.0.0 INSIDE&#012;telnet 172.16.0.0 255.255.0.0 INSIDE&#012;telnet 0.0.0.0 0.0.0.0 management&#012;telnet timeout 5&#012;ssh 172.168.0.0 255.255.0.0 INSIDE&#012;ssh 172.16.0.0 255.255.0.0 INSIDE&#012;ssh 0.0.0.0 0.0.0.0 management&#012;ssh timeout 60&#012;console timeout 0&#012;dhcpd address 192.168.0.2-192.168.0.254 DMZ&#012;dhcpd address 192.168.1.2-192.168.1.254 management&#012;dhcpd dns 208.67.222.222 208.67.220.220&#012;dhcpd lease 3600&#012;dhcpd ping_timeout 50&#012;dhcpd enable DMZ&#012;dhcpd enable management&#012;!&#012;class-map inspection_default&#012; match default-inspection-traffic&#012;class-map class-csc&#012; match access-list csc&#012;!&#012;!&#012;policy-map global_policy&#012; description Global Policy&#012; class inspection_default&#012;  inspect dns maximum-length 512 &#012;  inspect h323 h225 &#012;  inspect h323 ras &#012;  inspect rsh &#012;  inspect sqlnet &#012;  inspect skinny &#012;  inspect sunrpc &#012;  inspect xdmcp &#012;  inspect sip &#012;  inspect netbios &#012;  inspect tftp &#012;  inspect pptp &#012;  inspect ftp &#012; class class-csc&#012;  csc fail-open&#012;!&#012;service-policy global_policy global&#012;Cryptochecksum:*****************&#012;: end&#012; &#012;
--
TekMunki"There are 10 types of people in this world, those who understand binary and those who don't."www.tekmunki.com]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21191423</guid>
<pubDate>2008-09-30 10:21:35</pubDate>
</item>

<item>
<title>[Info] PIX 501 Maximum Site to Site</title>
<link>http://www.dslreports.com/forum/remark,21211091</link>
<description><![CDATA[I'm looking to purchase a used Cisco PIX 501 (or some other flavor of the same) to replace an existing VPN router that is configured for approximately 20 site-to-site tunnels.  

I expect that I will only use 2 to 3 Cisco VPN clients.  This implies that a 10 client license will be fine for me.

But how about site-to-site tunnels?  Are there any limits on these?  I didn't immediately see this in the Cisco PIX Firewall and Configure Guide .PDF that I downloaded.  And a bit of googling, too.

So how many site-to-site tunnels will this puppy handle?  Is this limit (officially) documented anywhere?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21211091</guid>
<pubDate>2008-10-03 15:08:43</pubDate>
</item>

<item>
<title>[Config] Scripts for changing Cisco passwords</title>
<link>http://www.dslreports.com/forum/remark,21207999</link>
<description><![CDATA[Hi!

Has anyone created scripts to automate changing the passwords on their Cisco switches/routers?

Regards,

James]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,21207999</guid>
<pubDate>2008-10-02 23:25:52</pubDate>
</item>

</channel>
</rss>
