getXML('<?xml version="1.0" encoding="UTF-8"?><ActiveMessages>Challenges of Running Small and Medium Businesses152<Community id=".ee6b2b0" title="Networking Professionals">  <Forum id=".1ddbf5a5" title="Small and Medium Business"><Topic id=".1ddbf5a6" private="" title="Challenges of Running Small and Medium Businesses"><Conversation id=".2cd4f3b7" messages="0" subscribed="yes" title="Windows 2008 Gratuitous ARP "><Message attachment="no" canreply="yes" editable="yes" id=".2cd4f3b7" level=""><Author authinfo=" EMC">schrader_john</Author><Timestamp>Nov 18, 2009, 7:31am PST</Timestamp><Msgbody>Apparently Microsoft has change the way a machine broadcasts the change of a virtual IP address from one machine to another.&lt;br /&gt;&lt;br /&gt;Assume you have two IP addresses bound to a NIC on NodeA.  IP Address 192.168.1.20 and Virtual IP VIP) address 192.168.1.21.  Then remove the VIP from NodeA and add it to NodeB.&lt;br /&gt;&lt;br /&gt;In Windows 2003, the arp cache of a routher would accept the broadcast change of the MAC address for VIP from the MAC address of NodeA to the MAC address of NodeB.  &lt;br /&gt;&lt;br /&gt;Windows 2008 does not update the arp cache in the router from the MAC address of NodeA to the MAC address of NodeB.&lt;br /&gt;&lt;br /&gt;However, if the VIP is moved from NodeA to NodeB by MS Cluster Server (MSCS) the arp cache is updated on the routers.&lt;br /&gt;&lt;br /&gt;Obviously, MS has changed the behavior of arp broadcasts between Windows 2003 and 2008, however they have also compensated if the customer is using MSCS.&lt;br /&gt;&lt;br /&gt;Can anyone suggest what has changed in Windows that causes this behavior?  Also, is there any workaround that will cause Windows to revert to the Windows 2003 model?&lt;br /&gt;&lt;br /&gt;I have done some research on this and some people throrize that Windows 2008 mow uses Multicast packets instead of Unicast packets but I can&apos;t confirm the right way to compensate for this change in Windows bahavior.&lt;br /&gt;&lt;br /&gt;Thanks...JS</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd4ecf1" messages="1" subscribed="no" title="Multi-Subnet VPN"><Message attachment="no" canreply="yes" id=".2cd4ecf1" level="">      <Author authinfo="Tech Support Rep, Reynwood Communications">jmalloy22</Author><Timestamp>Nov 12, 2009, 3:36pm PST</Timestamp><Msgbody>I have an ASA 5505 and 5510 connected via IPSec L2L VPN. The 5505 has a single 192.168.15.x subnet on Eth0/1, while the 5505 has 10.101.10.x and 172.30.10.x subnets on Eth0/1 and Eth0/2 respectively. With the current VPN I can access 10.101.10.x from 192.168.15.x and vice versa. What I can not figure out is how to access  172.30.10.x from 192.168.15.x over the existing VPN. Any thoughts...?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4ecf1/0" level="1." new="yes">      <Author authinfo="Senior Network Engineer, WPS EXTERNAL TECHNOLOGY SOLUTIONS">collin_clark</Author><Timestamp>Nov 16, 2009, 1:40pm PST</Timestamp><Msgbody>You&apos;ll need to add the other subnet into NAT0 and the crypto ACLs. Here&apos;s a link to a configuration guide.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807f9a89.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807f9a89.shtml&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Hope it helps.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4a831" messages="1" subscribed="no" title="VPN 3000 using AD auth. - How do I disable accounts from VPN"><Message attachment="no" canreply="yes" id=".2cd4a831" level=""><Author>dwaldowcs</Author><Timestamp>Oct 5, 2009, 2:29pm PST</Timestamp><Msgbody>I have a Cisco VPN 3000 concentrator that uses AD authentication to my domain controller.  Everyone in AD can connect.  How do I continue to authenticate through AD but only allow specific accounts to use the vpn?  Or deny specific accounts from using the VPN?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4a831/0" level="1." new="yes">      <Author authinfo="CCIE-V, Systems Administrator, Ball Homes" ccie="yes">bbuffin</Author><Timestamp>Nov 10, 2009, 12:06pm PST</Timestamp><Msgbody>You&apos;ll need to configure IAS on your Windows server to make this happen. There is no way to do this with authentication from the concentrator directly to AD. Take a look at the following link.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a0080094700.shtml&apos;)"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a0080094700.shtml&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Hope this helps.&lt;br /&gt;&lt;br /&gt;Brandon</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd490d6" messages="1" subscribed="no" title="SMB network requirement"><Message attachment="no" canreply="yes" id=".2cd490d6" level="">            <Author authinfo=" shridhar">shridhar_sdl</Author><Timestamp>Sep 21, 2009, 3:31am PST</Timestamp><Msgbody>I have two 1841 cisco router , but for one router serial interface is totally damaged , pls let me know how i can use two different ISP,s same time , is there any way ...</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd490d6/0" level="1." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Sep 22, 2009, 4:43pm PST</Timestamp><Msgbody>If you plan to use an ADSL card, then the answer is no.&lt;br /&gt;&lt;br /&gt;If the providers present the lines as Ethernet, then yes.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd48d5e" messages="3" subscribed="no" title="Access-list"><Message attachment="no" canreply="yes" id=".2cd48d5e" level=""><Author authinfo=" COLLEGE DE ROSEMONT">g-lacoursiere</Author><Timestamp>Sep 17, 2009, 5:05pm PST</Timestamp><Msgbody>Hi, I have been configuring access-list on a 2811 router to deny all traffic except TFTP.  Right now, only the router who&apos;s IP adresse are in the ACL, can copy their running-config to the TFTP server.  However, the router that is directly connected to the TFTP server, and on which interface the ACL is placed out, is enable to copy it&apos;s own running-config, even thow the ACL is not allowing his IP address (only those from the other routers in the network).  Look like the routers is not passing it&apos;s own traffic in the ACL ??  Is thi possible ??.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd48d5e/0" level="1." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Sep 17, 2009, 5:47pm PST</Timestamp><Msgbody>Can you post a network diagram and the config please?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd48d5e/1" level="1.1" new="yes"><Author authinfo=" COLLEGE DE ROSEMONT">g-lacoursiere</Author><Timestamp>Sep 17, 2009, 6:46pm PST</Timestamp><Msgbody>Here is the topology and the runing-config of router named R2.&lt;br /&gt;&lt;br /&gt;Its the R2 router that is able to copy to the TFTP server even though the access-list does not permit him to copy.&lt;br /&gt;&lt;br /&gt;I hope this is not too confusing !!&lt;br /&gt;&lt;br /&gt;Thanks for your answer.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Attachment Keywords : &lt;/b&gt; &lt;br /&gt;1) Topologie.jpg&lt;br /&gt;2) R2.txt&lt;br /&gt;</Msgbody><Attachment><Document><FileName>Topologie.jpg</FileName><DocID>121213</DocID><ContentType>image/pjpeg</ContentType><InternalType>image</InternalType><Size>43445</Size><ExpirationDate>09/17/2014</ExpirationDate><IsExpired>no</IsExpired></Document><Document><FileName>R2.txt</FileName><DocID>121214</DocID><ContentType>text/plain</ContentType><InternalType>text</InternalType><Size>3756</Size><ExpirationDate>09/17/2014</ExpirationDate><IsExpired>no</IsExpired></Document></Attachment></Message><Reply><Message attachment="no" canreply="yes" id=".2cd48d5e/2" level="1.1.1" new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Sep 20, 2009, 8:29pm PST</Timestamp><Msgbody>Just a test, but remove &lt;b&gt;permit ip any any&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Have you tried using &lt;b&gt;ip access-group TFTP in&lt;/b&gt;?</Msgbody><Attachment/></Message></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd47abf" messages="1" subscribed="no" title="can callmanager BARS support callmanager 5.1"><Message attachment="no" canreply="yes" id=".2cd47abf" level="">      <Author authinfo="Advisory Network Systems Planner, ENA SOLUTIONS PTY LTD">robert.sebie@ena.com.au</Author><Timestamp>Sep 7, 2009, 8:57pm PST</Timestamp><Msgbody>Can callmanager Backup And Restore System support callmanager version 5.1? How to backup callmanager 5.1?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd47abf/0" level="1." new="yes">            <Author authinfo=" COMPU SEARCH">smalkeric</Author><Timestamp>Sep 11, 2009, 12:16pm PST</Timestamp><Msgbody>For Cisco CallManager 3.3 or later, you need to use the supported Cisco BARS utility. If you use an earlier version of Cisco CallManager, use the Cisco IP Telephony Applications Backup Utility (3.5). On Cisco CallManager 5.0 and later, the BARS utility is replaced by the Disaster Recovery System. &lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/drs/5_0_4/drsag504.html&apos;)"&gt;http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/drs/5_0_4/drsag504.html&lt;/A&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd47ac4" messages="1" subscribed="no" title="can callmanager BARS support callmanager 5.1"><Message attachment="no" canreply="yes" id=".2cd47ac4" level="">      <Author authinfo="Advisory Network Systems Planner, ENA SOLUTIONS PTY LTD">robert.sebie@ena.com.au</Author><Timestamp>Sep 7, 2009, 9:00pm PST</Timestamp><Msgbody>Hi everybody,&lt;br /&gt;&lt;br /&gt;I am just wondering whether callmanager BARS support callmanager 5.1. When I try to install BARS in the voice mail server, there is an error message that You must use cisco approved hardware to install BARS. But the voice mail server is an Cisco server. So what is cisco approved server?&lt;br /&gt;&lt;br /&gt;Thanks&lt;br /&gt;</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd47ac4/0" level="1." new="yes">      <Author authinfo="TELECOM ANALYST, Mount Royal University">rob.huffman</Author><Timestamp>Sep 11, 2009, 5:02am PST</Timestamp><Msgbody>Hi Robert,&lt;br /&gt;&lt;br /&gt;In CCM 5.x and above this is now called "Disaster Recovery System" pretty cool! So you don&apos;t need to install the BARS Utility. Here is a look at the related info; &lt;br /&gt;&lt;br /&gt;The Disaster Recovery System (DRS), which can be invoked from Cisco Unified CallManager 6.0 Administration, provides full data backup and restore capabilities for all servers in a Cisco Unified CallManager cluster. The Disaster Recovery System allows you to perform regularly scheduled automatic or user-invoked data backups. DRS supports only one backup schedule. &lt;br /&gt;&lt;br /&gt;The Cisco Disaster Recovery System performs a cluster-level backup, which means that it collects backups for all servers in a Cisco Unified CallManager cluster to a central location and archives the backup data to physical storage device. &lt;br /&gt;&lt;br /&gt;When performing a system data restoration, you can choose which nodes in the cluster you want to restore. &lt;br /&gt;&lt;br /&gt;The Disaster Recovery System includes the following capabilities: &lt;br /&gt;&lt;br /&gt;A user interface for performing backup and restore tasks. &lt;br /&gt;&lt;br /&gt;A distributed system architecture for performing backup and restore functions. &lt;br /&gt;&lt;br /&gt;Scheduled backups. &lt;br /&gt;&lt;br /&gt;Archive backups to a physical tape drive or remote sftp server. &lt;br /&gt;&lt;br /&gt;The Disaster Recovery System contains two key functions, Master Agent (MA) and Local Agent (LA). The Master Agent coordinates backup and restore activity with all the Local Agents. &lt;br /&gt;&lt;br /&gt;The system automatically activates both the Master Agent and the Local Agent on all nodes in the cluster. &lt;br /&gt;&lt;br /&gt;From this excellent doc; &lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/drs/6_1_2/DRS_CUCM/drsag612.html&apos;)"&gt;http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/drs/6_1_2/DRS_CUCM/drsag612.html&lt;/A&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;For these new CCM Versions BARS is no longer used :) &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hope this helps! &lt;br /&gt;Rob &lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd47854" messages="2" subscribed="no" title="Map mulitple static IP through single 877 router for subnets"><Message attachment="no" canreply="yes" id=".2cd47854" level=""><Author>tkeuleman</Author><Timestamp>Sep 4, 2009, 12:49pm PST</Timestamp><Msgbody>Hello All.&lt;br /&gt;I have searched around a bit and I believe the 877 router will do what I want but I would like to have this confirmed.&lt;br /&gt;Here&apos;s the situation.&lt;br /&gt;Assume there is a static IP address 201.97.237.216 (not the real IP) for a ADSL service.&lt;br /&gt;The ISP has mapped a block of other static IP&apos;s that are directed to 201.97.237.216 address.  Assume the block goes from 201.97.229.128 to 201.97.229.135.&lt;br /&gt;I want to hook up a 877 router and configure the wan port to be 201.97.237.216 and then have port one on the lan side connected to a router with the ip address 201.97.229.130.  This router will be one subnet or vnet.  Port two on the 877 router would be connected to another router with the ip address of 201.97.229.131.  This would be a second subnet.  &lt;br /&gt;&lt;br /&gt;Can the 877 router support this?  If I read the specs correctly it looks like it supports vlan&apos;s.  &lt;br /&gt;Would a web user be able to connect to 201.97.229.130 and be connected to the subnet 1 through port 1 of the 877 router?&lt;br /&gt;&lt;br /&gt;Is the web interface intuitive enough to allow this to be configured easily?&lt;br /&gt;&lt;br /&gt;If someone knows of a sample config file for this type of connection I would appreciate seeing it.&lt;br /&gt;&lt;br /&gt;Thanks for considering this post.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd47854/0" level="1." new="yes"><Author authinfo=" Starplex">vkapoor5</Author><Timestamp>Sep 10, 2009, 6:42pm PST</Timestamp><Msgbody>PAT offers Maps multiple IP addresses to one or a few IP addresses.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6640/product_data_sheet0900aecd8064c999.html&apos;)"&gt;http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6640/product_data_sheet0900aecd8064c999.html&lt;/A&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd47854/1" level="2." new="yes">      <Author authinfo="Senior Network Engineer, WPS EXTERNAL TECHNOLOGY SOLUTIONS">collin_clark</Author><Timestamp>Sep 11, 2009, 4:50am PST</Timestamp><Msgbody>&lt;i&gt;Support for 2 VLANs with Base Image. One VLAN dedicated to DMZ.&lt;/i&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/prod/collateral/routers/ps380/ps6200/product_data_sheet0900aecd8028a976.html&apos;)"&gt;http://www.cisco.com/en/US/prod/collateral/routers/ps380/ps6200/product_data_sheet0900aecd8028a976.html&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;I&apos;ve never used the web interface, but this is a pretty straight forward setup so it should be pretty intuitive. &lt;br /&gt;&lt;br /&gt;Assign the WAN interface the IP of 201.97.237.216. Assign the LAN or DMZ interface with 201.97.229.x. Then you can assign other hosts in the 201.97.229.x range. They must be in the same VLAN as your inside/DMZ interface.&lt;br /&gt;&lt;br /&gt;Hope it helps.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd46a4b" messages="1" subscribed="no" title="How to place switches in spanning tree debug mode"><Message attachment="no" canreply="yes" id=".2cd46a4b" level=""><Author>dai_nish@yahoo.co.nz</Author><Timestamp>Aug 27, 2009, 9:56pm PST</Timestamp><Msgbody>Hello everyone&lt;br /&gt;&lt;br /&gt;I have been unable to place a few switches in spanning-tree debug mode using the debug spanning-tree events. The command gets returned as invalid input in priviliged EXEC mode. In other modes it is retured as an unrecognized command. I looked into the configuration of the spanning tree in the show spanning-tree output and it seems all fine. Please advise me how to enable this debugging functionality.&lt;br /&gt;&lt;br /&gt;Thank you for reading,&lt;br /&gt;&lt;br /&gt;Dee</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd46a4b/0" level="1." new="yes"><Author authinfo=" Bytes &amp; Sites">tstanik</Author><Timestamp>Sep 2, 2009, 7:39am PST</Timestamp><Msgbody>Use the debug spanning-tree privileged EXEC command to debug spanning-tree activities. Use the no form of this command to disable debugging output. &lt;br /&gt;debug spanning-tree {all | backbonefast | bpdu | bpdu-opt | config | csuf | etherchannel | events | exceptions | general | mstp | pvst+ | root | snmp | switch | uplinkfast} &lt;br /&gt;&lt;br /&gt;no debug spanning-tree {all | backbonefast | bpdu | bpdu-opt | config | csuf | etherchannel | events | exceptions | general | mstp | pvst+ | root | snmp | switch | uplinkfast} &lt;br /&gt;&lt;br /&gt;To view the syntax description click this link.&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/switches/lan/catalyst2940/software/release/12.1_13_ay/command/reference/debug.html#wp1029961&apos;)"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst2940/software/release/12.1_13_ay/command/reference/debug.html#wp1029961&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd46815" messages="1" subscribed="no" title="ASA 5510 to route Vlans"><Message attachment="no" canreply="yes" id=".2cd46815" level=""><Author authinfo=" ">chris.noon</Author><Timestamp>Aug 26, 2009, 6:47pm PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;I have a Cisco ASA 5510 and need to use it to route between VLANs as i don&apos;t have a router for the time being.  I have been reading online and it is possible as it is a layer 3 device, although I can&apos;t seem to get it working.&lt;br /&gt;&lt;br /&gt;I have an inside, outside and a DMZ.  The DMZ is in the IP range 172.99.0.0/24 and in vlan 80 and the inside is in the IP range 10.192.3.0/24 and in vlan 10.  These are the 2 vlan/ip ranges I need to communicate.&lt;br /&gt;&lt;br /&gt;On the switch I am using the config commands:&lt;br /&gt;&lt;br /&gt;Interface 0/48&lt;br /&gt;switchport trunk allowed vlan all&lt;br /&gt;switchport mode trunk&lt;br /&gt;&lt;br /&gt;Then ports 1 to 36 are placed on vlan 10 and ports 37 to 47 are on vlan 80; all set for access mode.&lt;br /&gt;&lt;br /&gt;On the ASA i am using the config:&lt;br /&gt;&lt;br /&gt;Interface Ethernet 0/3&lt;br /&gt;No ip address&lt;br /&gt;No shutdown&lt;br /&gt;Nameif VLAN_Routing&lt;br /&gt;Security-level 100&lt;br /&gt;&lt;br /&gt;Interface Etherenet 0/3.1&lt;br /&gt;Ip address 172.99.0.1 255.255.255.0&lt;br /&gt;Nameif DMZ_VLAN&lt;br /&gt;Security-level 100&lt;br /&gt;Vlan 80&lt;br /&gt;no shutdown&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Interface Etherenet 0/3.2&lt;br /&gt;Ip address 10.192.3.2 255.255.255.0&lt;br /&gt;Nameif Inside_VLAN&lt;br /&gt;Security-level 100&lt;br /&gt;Vlan 1&lt;br /&gt;no shutdown&lt;br /&gt;&lt;br /&gt;####&lt;br /&gt;I thought the problem may be because I don&apos;t have any encapsulation on the trunking ports.  The ASA command "vlan 10" apparently encapsulates in dot1q automatically, but i can&apos;t seem to find where to do this on the switch: the switch is a catalyst 2960.&lt;br /&gt;&lt;br /&gt;Hopefully someone can help me get these 2 lans communicating.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd46815/0" level="1." new="yes">      <Author authinfo="Senior Network Engineer, WPS EXTERNAL TECHNOLOGY SOLUTIONS">collin_clark</Author><Timestamp>Aug 31, 2009, 8:45am PST</Timestamp><Msgbody>On the 2960 I&apos;m pretty sure that only dot1q is supported. On the switch you can verify if the trunk is working with &lt;b&gt;show interface trunk&lt;/b&gt; and it should show fa0/48 as a trunk. I do see an error on the ASA config. The main interface can not have a nameif.&lt;br /&gt;&lt;br /&gt;interface Eth0/3&lt;br /&gt; no nameif&lt;br /&gt;&lt;br /&gt;You will also need &lt;b&gt;same-security-traffic permit inter-interface &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Hope that helps.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd46b3b" messages="1" subscribed="no" title="Disable stackwise - 3750"><Message attachment="no" canreply="yes" id=".2cd46b3b" level="">      <Author authinfo="Engineer, CIBER">matthubach</Author><Timestamp>Aug 28, 2009, 7:42am PST</Timestamp><Msgbody>Can someone please help me disable the stackwise config in a 3750 switch. I have removed the switch from a stackwise configuration and need it as a standalone.&lt;br /&gt;&lt;br /&gt;When I run the command...&lt;br /&gt;no switch [#] provision&lt;br /&gt;...I get the error...&lt;br /&gt;%IDBs can not be removed when switch is active.&lt;br /&gt;&lt;br /&gt;I see some documentation that mentioned renumbering the switch. However, once I renumber it I get the same error.&lt;br /&gt;----------------------------------------&lt;br /&gt;version 12.2&lt;br /&gt;no service pad&lt;br /&gt;service timestamps debug uptime&lt;br /&gt;service timestamps log uptime&lt;br /&gt;no service password-encryption&lt;br /&gt;!&lt;br /&gt;hostname Switch&lt;br /&gt;!&lt;br /&gt;no aaa new-model&lt;br /&gt;switch 1 provision ws-c3750-48p&lt;br /&gt;----------------------------------------&lt;br /&gt;I am starting to wonder if it is even possible to remove the default switch 1 config when you have stackwise ports??? Any ideas? Thanks!!!</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd46b3b/0" level="1." new="yes">            <Author authinfo=" NONSTOP NETWORKS LLC" ccie="yes">nsn-amagruder</Author><Timestamp>Aug 28, 2009, 10:41am PST</Timestamp><Msgbody>I don&apos;t have one in front of me to confirm, but I believe this is default config.  Do a show switch and if only one switch exist, you can&apos;t remove it.&lt;br /&gt;&lt;br /&gt;If you do a switch 2 provision (model), then do a show run, you will be able to provision the ports that don&apos;t exist until the switch is phyically connected.&lt;br /&gt;&lt;br /&gt;hope this helps,&lt;br /&gt;&lt;br /&gt;Aaron Magruder&lt;br /&gt;NonStop Networks, LLC&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.nonstopnetworks.net&apos;)"&gt;http://www.nonstopnetworks.net&lt;/A&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cc1b0b2" messages="2" subscribed="no" title="Adding second IP address and configure NAT"><Message attachment="no" canreply="yes" id=".2cc1b0b2" level=""><Author authinfo=" None">neilmackland</Author><Timestamp>Aug 28, 2008, 2:49am PST</Timestamp><Msgbody>Hi&lt;br /&gt;&lt;br /&gt;Finally got my 857 up and working and have NAT working to port forward ports 80, 25 and 443 to my internal servers.&lt;br /&gt;&lt;br /&gt;I have a block of IP &apos;S and want to configure the router to use a second IP address so that I can configure citrix web access so that when my users go to &lt;A HREF="javascript:newWin(&apos;http://www.domain.com&apos;)"&gt;www.domain.com&lt;/A&gt; in goes to my web server and when they input citrix.domain.com it goes to my citrix web access server.&lt;br /&gt;&lt;br /&gt;I think I have added the secondary IP address to the dialer but am unsure how to configure NAT with the secondary public IP address</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cc1b0b2/0" level="1." new="yes">      <Author authinfo="Senior Network Engineer, WPS EXTERNAL TECHNOLOGY SOLUTIONS">collin_clark</Author><Timestamp>Aug 28, 2008, 5:23am PST</Timestamp><Msgbody>No need to add a secondary address to the dialer. Simply create a new NAT statement with a new IP address. &lt;br /&gt;&lt;br /&gt;Hope that helps.</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cc1b0b2/1" level="2." new="yes"><Author authinfo=" EMPIRED LTD">timkaye@empired</Author><Timestamp>Aug 27, 2009, 8:24pm PST</Timestamp><Msgbody>Hello.&lt;br /&gt;&lt;br /&gt;Can I ask what software version you&apos;re running.&lt;br /&gt;&lt;br /&gt;I cannot get 443 to forward.  Everything else is fine.&lt;br /&gt;&lt;br /&gt;Appreciate any information.&lt;br /&gt;&lt;br /&gt;Tim</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd462c0" messages="5" subscribed="no" title="CISCO ASA 5520 "><Message attachment="no" canreply="yes" id=".2cd462c0" level="">            <Author authinfo=" Guyana Defence Force">mark.stclaire</Author><Timestamp>Aug 24, 2009, 8:19am PST</Timestamp><Msgbody>I need urgent or assistance with the above device. If you&apos;re welling to assist drop me a line troy336@yahoo.com</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd462c0/0" level="1." new="yes">      <Author authinfo="Engineer, Instructor, MasterLink Corp. / ieMentor Corp." ccie="yes">roman.rodichev@iementor.com</Author><Timestamp>Aug 24, 2009, 11:11am PST</Timestamp><Msgbody>Mark, can you post your question here?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd462c0/1" level="1.1" new="yes">            <Author authinfo=" Guyana Defence Force">mark.stclaire</Author><Timestamp>Aug 24, 2009, 11:19am PST</Timestamp><Msgbody>hey roman thanks for reply.... I send you an e-mail. However I&apos;m have a cisco ASA 5520 Firewall. I need to configure it for routed mode. I&apos;ll be using 3 interface. DMZ, OUTSIDE and INSIDE. I want to accomplish communication from my clients to the DMZ in and out. Also my DMZ in and out the OUTSIDE. And later on VPN to my DMZ.  I can show you my config and diagram.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd462c0/3" level="1.1.1" new="yes">      <Author authinfo="Engineer, Instructor, MasterLink Corp. / ieMentor Corp." ccie="yes">roman.rodichev@iementor.com</Author><Timestamp>Aug 26, 2009, 4:45am PST</Timestamp><Msgbody>Feel free to attach your diagram and config file here. Do you already have some existing configuration and need help with specific features or are you looking for the entire ASA config?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd462c0/4" level="1.1.1.1" new="yes">            <Author authinfo=" Guyana Defence Force">mark.stclaire</Author><Timestamp>Aug 26, 2009, 6:25am PST</Timestamp><Msgbody>Hey Roman attached is wat I have so far and what I want to accomplish. Long story short I&apos;m lost with my NAT and ACLs&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Attachment Keywords : &lt;/b&gt; &lt;br /&gt;1) ASA Version 7.doc&lt;br /&gt;2) my network.jpg&lt;br /&gt;</Msgbody><Attachment><Document><FileName>ASA Version 7.doc</FileName><DocID>120287</DocID><ContentType>application/octet-stream</ContentType><InternalType>exe</InternalType><Size>39936</Size><ExpirationDate>08/26/2014</ExpirationDate><IsExpired>no</IsExpired></Document><Document><FileName>my network.jpg</FileName><DocID>120288</DocID><ContentType>image/pjpeg</ContentType><InternalType>image</InternalType><Size>48120</Size><ExpirationDate>08/26/2014</ExpirationDate><IsExpired>no</IsExpired></Document></Attachment></Message></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd462c0/2" level="1.2" new="yes">            <Author authinfo=" Guyana Defence Force">mark.stclaire</Author><Timestamp>Aug 24, 2009, 11:48am PST</Timestamp><Msgbody>hey roman thanks for reply.... I send you an e-mail. However I&apos;m have a cisco ASA 5520 Firewall. I need to configure it for routed mode. I&apos;ll be using 3 interface. DMZ, OUTSIDE and INSIDE. I want to accomplish communication from my clients to the DMZ in and out. Also my DMZ in and out the OUTSIDE. And later on VPN to my DMZ.  I can show you my config and diagram.</Msgbody><Attachment/></Message></Reply></Reply></Replies></Conversation><Conversation id=".2cd46165" messages="7" subscribed="no" title="Lock ipphone 7940"><Message attachment="no" canreply="yes" id=".2cd46165" level=""><Author>marciagirardi</Author><Timestamp>Aug 22, 2009, 5:05pm PST</Timestamp><Msgbody>Gents,&lt;br /&gt;&lt;br /&gt;Is it possible to lock an ipphone 7940? How could I do it ?&lt;br /&gt;&lt;br /&gt;Please, answer to cesar_c_santos@hotmail.com&lt;br /&gt;&lt;br /&gt;Kind regards&lt;br /&gt;&lt;br /&gt;CÃ©sar Santos&lt;br /&gt;&lt;br /&gt;</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd46165/0" level="1." new="yes">      <Author authinfo="CCIE-V, Systems Administrator, Ball Homes" ccie="yes">bbuffin</Author><Timestamp>Aug 24, 2009, 7:54am PST</Timestamp><Msgbody>While not specifically designed for this purpose, one option is to use Extension Mobility. Take a look at the following post.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;forum=Unified%20Communications%20and%20Video&amp;topic=Video%20over%20IP&amp;topicID=.ee6c82f&amp;fromOutline=&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cbefc93&apos;)"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;forum=Unified%20Communications%20and%20Video&amp;topic=Video%20over%20IP&amp;topicID=.ee6c82f&amp;fromOutline=&amp;CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.2cbefc93&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;Hope this helps.&lt;br /&gt;&lt;br /&gt;Brandon</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd46165/1" level="1.1" new="yes"><Author>marciagirardi</Author><Timestamp>Aug 24, 2009, 8:14am PST</Timestamp><Msgbody>Hi Brandon, Thanks.&lt;br /&gt;&lt;br /&gt;For example, I would like to lock the IP telephone device when I will out of my workstation.&lt;br /&gt;&lt;br /&gt;regards,</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd46165/2" level="1.1.1" new="yes">      <Author authinfo="CCIE-V, Systems Administrator, Ball Homes" ccie="yes">bbuffin</Author><Timestamp>Aug 24, 2009, 9:07am PST</Timestamp><Msgbody>I&apos;m not aware of any way to do this. Sorry.&lt;br /&gt;&lt;br /&gt;Brandon</Msgbody><Attachment/></Message></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd46165/3" level="2." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Aug 24, 2009, 3:04pm PST</Timestamp><Msgbody>How about logout (Services &gt; Logout)?</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd46165/4" level="3." new="yes">      <Author authinfo="TELECOM ANALYST, Mount Royal University">rob.huffman</Author><Timestamp>Aug 25, 2009, 10:06am PST</Timestamp><Msgbody>Hi Ceasar,&lt;br /&gt;&lt;br /&gt;Just to add a note to the great info from Brandon and Leo (+5 points each guys!)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;There is also this 3rd party product; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.andtek.com/communications-products-lockout.html&apos;)"&gt;http://www.andtek.com/communications-products-lockout.html&lt;/A&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Hope this helps! &lt;br /&gt;Rob &lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd46165/6" level="3.1" new="yes"><Author>marciagirardi</Author><Timestamp>Aug 26, 2009, 5:40am PST</Timestamp><Msgbody>Hi Rob, thanks for the help!&lt;br /&gt;&lt;br /&gt;regards,&lt;br /&gt;&lt;br /&gt;Cesar</Msgbody><Attachment/></Message></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd46165/5" level="4." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Aug 25, 2009, 2:25pm PST</Timestamp><Msgbody>Thanks for the rating Rob.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd45d5c" messages="1" subscribed="no" title="how to create a new directory in callmanager"><Message attachment="no" canreply="yes" id=".2cd45d5c" level=""><Author>simonmeli</Author><Timestamp>Aug 19, 2009, 9:38pm PST</Timestamp><Msgbody>in ip phone, there is a softkey call corp directory from which you can search all staff in your company. But now, my company has a lot of store which will have their own id, address and phone number. So how can I create another directory for all store which just like corp directory? Can I reprogram the softkey?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd45d5c/0" level="1." new="yes">            <Author authinfo=" COMPU SEARCH">smalkeric</Author><Timestamp>Aug 25, 2009, 1:32pm PST</Timestamp><Msgbody>Re-program the softkey is achieved through a &apos;Template&apos; this template is then applied to the phones you wish to change.&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/admin/4_0_1/ccmcfg/b06skey.html#wp1007555&apos;)"&gt;http://www.cisco.com/en/US/docs/voice_ip_comm/cucm/admin/4_0_1/ccmcfg/b06skey.html#wp1007555&lt;/A&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd453cc" messages="1" subscribed="no" title="GetVPN with DC"><Message attachment="no" canreply="yes" id=".2cd453cc" level=""><Author authinfo=" ITALTEL PERU">henrry.huaman</Author><Timestamp>Aug 16, 2009, 7:37am PST</Timestamp><Msgbody>Hi Guys.&lt;br /&gt;Please, we are working in deployment of GetVPN with DC, could be help me with design or recomendations other deployment?&lt;br /&gt;&lt;br /&gt;thanks in advance</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd453cc/0" level="1." new="yes"><Author authinfo=" WLF Consulting">ebreniz</Author><Timestamp>Aug 21, 2009, 10:25am PST</Timestamp><Msgbody>Please follow up on this guide in PDF format in the following link:&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6525/ps9370/ps7180/GETVPN_DIG_version_1_0_External.pdf&apos;)"&gt;http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6525/ps9370/ps7180/GETVPN_DIG_version_1_0_External.pdf&lt;/A&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4559f" messages="1" subscribed="no" title="VPN3000 upgrade question"><Message attachment="no" canreply="yes" id=".2cd4559f" level=""><Author>bliems</Author><Timestamp>Aug 17, 2009, 8:48am PST</Timestamp><Msgbody>I am going to upgrade the IOS on the VPN3005 Concentrator. It has 32MB of Flash.  I need to know how to check the amount of memory currently being used by the current image. We are running:&lt;br /&gt;&lt;br /&gt;vpn3005-4.1.2.Rel-k9.bin&lt;br /&gt;&lt;br /&gt;I wanted to know also, what would be a good replacement image for this.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4559f/0" level="1." new="yes"><Author>rrjoas45</Author><Timestamp>Aug 21, 2009, 10:15am PST</Timestamp><Msgbody>You can view it from monitoring | system status option. This screen shows the status of several software and hardware variables at the time the screen displays. From this screen you can also display the status and statistics for SEP modules, system power supplies, memory, and network interfaces. &lt;br /&gt;&lt;br /&gt;One of the screen elements:&lt;br /&gt;RAM Size — The total amount of SDRAM memory installed in the VPN Concentrator. Memory Status is a link to a table that displays information about memory use on the VPN Concentrator; it includes information about block size, with data about used and free blocks, bytes, and percentages. &lt;br /&gt;Refer the below URL for more info:&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/security/vpn3000/vpn3000_47/administration/guide/sysstat.html&apos;)"&gt;http://www.cisco.com/en/US/docs/security/vpn3000/vpn3000_47/administration/guide/sysstat.html&lt;/A&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd44b0b" messages="1" subscribed="no" title="uc500 number transfer"><Message attachment="no" canreply="yes" id=".2cd44b0b" level="">            <Author authinfo=" QWEST COMMUNICATIONS">kepollett1</Author><Timestamp>Aug 11, 2009, 8:35am PST</Timestamp><Msgbody>Numbers appearing on phones as monitor, when call is transfered cannot light busy lamp when pickup on 7962 phones and phones with 7915 sidecars. Normal operation fine</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd44b0b/0" level="1." new="yes">            <Author authinfo=" QWEST COMMUNICATIONS">kepollett1</Author><Timestamp>Aug 13, 2009, 6:45am PST</Timestamp><Msgbody>Found my own answer to this. Some of the 7962 phones with the 7915 sidecar and other 7942 phones had an older phone load. Made sure all received new phone load and worked properly with the 7915 sidecars after</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd44236" messages="1" subscribed="no" title="Passowrd Notification via WIFI to AD domain "><Message attachment="no" canreply="yes" id=".2cd44236" level="">            <Author authinfo=" DOA">nocoperators</Author><Timestamp>Aug 6, 2009, 7:54am PST</Timestamp><Msgbody>How can I get Wifi users to get password notification from Active Directory using VPN connection?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd44236/0" level="1." new="yes"><Author authinfo=" WLF Consulting">ebreniz</Author><Timestamp>Aug 12, 2009, 3:30pm PST</Timestamp><Msgbody>We can prompt users for change of password ahead of time but it requires to use LDAP not Radius&lt;br /&gt;&lt;br /&gt;tunnel-group radiustest1 general-attributes&lt;br /&gt;password-management  password-expire-in-days 14&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/vpngrp.html#wp1166214&apos;)"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/vpngrp.html#wp1166214&lt;/A&gt;&lt;br /&gt;&lt;br /&gt;So if LDAP is enabled on your AD Server, you can have ASA talk to the AD server directly.&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4422d" messages="1" subscribed="no" title="ES20+  QinQ"><Message attachment="no" canreply="yes" id=".2cd4422d" level="">      <Author authinfo="Technical, SIRTI">g3r4rd1n4</Author><Timestamp>Aug 6, 2009, 7:45am PST</Timestamp><Msgbody>I can configure two protocol on phisical interface cisco 7600 with card es20+:  &lt;br /&gt;802.1q and 802.1ad&lt;br /&gt;thanks</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4422d/0" level="1." new="yes">      <Author authinfo="IT ADMINISTRATOR, AFD CONSULTING">k.poplitz</Author><Timestamp>Aug 12, 2009, 1:03pm PST</Timestamp><Msgbody>Custom Ethertype feature customizes the Ethernet settings in an ES20 line card. This feature enables the user to configure ethertype with outer tag for .1Q and QinQ packets. Custom Ethertype is supported for both EVCs (802.1Q and QinQ) and QinQ routed subinterfaces. By default Cisco 7600 series router supports Ethertype 0x8100 for .1Q and Q-in-Q outer tag. You can use the Custom Ethertype feature to configure the following Ethertypes for each port for ES20 line cards: &lt;br /&gt;• 0x8100 - 802.1q &lt;br /&gt;• 0x9100 - Q-in-Q &lt;br /&gt;• 0x9200 - Q-in-Q &lt;br /&gt;• 0x88a8 - 802.1ad &lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/docs/routers/7600/install_config/ES20_config_guide/SRD/baldcfg.html&apos;)"&gt;http://www.cisco.com/en/US/docs/routers/7600/install_config/ES20_config_guide/SRD/baldcfg.html&lt;/A&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd41a63" messages="2" subscribed="no" title="vmware dms"><Message attachment="no" canreply="yes" id=".2cd41a63" level=""><Author>juanignaciofernandes</Author><Timestamp>Jul 13, 2009, 1:58pm PST</Timestamp><Msgbody>Im having problems to access to the DMM.&lt;br /&gt;I´ve already installed the VMWare from the ciscoet but I can´t access to the DMM principal page. I believe is a problem with the VMWare.&lt;br /&gt;Did anyone have the same problem?&lt;br /&gt;</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd41a63/0" level="1." new="yes"><Author authinfo=" MCSX">htarra</Author><Timestamp>Jul 20, 2009, 7:32pm PST</Timestamp><Msgbody>Here is the troubleshooting for the DMM. I hope it helps you.&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/products/ps6028/products_configuration_guide_chapter09186a0080899a23.html#wp35720&apos;)"&gt;http://www.cisco.com/en/US/products/ps6028/products_configuration_guide_chapter09186a0080899a23.html#wp35720&lt;/A&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd41a63/1" level="2." new="yes">            <Author authinfo=" PLANNET SERVICE SA">rguzman.plannet</Author><Timestamp>Aug 11, 2009, 2:44pm PST</Timestamp><Msgbody>Hi,&lt;br /&gt;&lt;br /&gt;I´m trying to instal DMS on VMWare as well, I´m using VMWare-server-2.0.1-156745. I am instaling DMS from Cisco Digital Media Manager V4.1 CD but the virtual machine displays an error "The system detected is unknown. You cannot continue furthe¨r"&lt;br /&gt;&lt;br /&gt;Please let me know if this is the same trouble you´re experiencing.&lt;br /&gt;&lt;br /&gt;Regards</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4499c" messages="1" subscribed="no" title="Multiple gateway on single router"><Message attachment="no" canreply="yes" id=".2cd4499c" level=""><Author>csco11096668</Author><Timestamp>Aug 10, 2009, 3:33pm PST</Timestamp><Msgbody>How can i configure a router with two gateways</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4499c/0" level="1." new="yes">      <Author authinfo="Senior Network Engineer, WPS EXTERNAL TECHNOLOGY SOLUTIONS">collin_clark</Author><Timestamp>Aug 11, 2009, 7:15am PST</Timestamp><Msgbody>Do you mean the router will provide the two gateways? Use a secondary IP or trunk and use sub-interfaces for each subnet.&lt;br /&gt;&lt;br /&gt;Do you mean you have two destination gateways?&lt;br /&gt;&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 1.1.1.1&lt;br /&gt;ip route 0.0.0.0 0.0.0.0 2.2.2.2&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4318b" messages="1" subscribed="no" title="C2650xm memory upgrade"><Message attachment="no" canreply="yes" id=".2cd4318b" level="">      <Author authinfo="Network Support Engineer, ">ihatelogin</Author><Timestamp>Jul 27, 2009, 6:15pm PST</Timestamp><Msgbody>Just upgraded the dram to 192mb install 32(48)mb flash and installed the bootrom 12.2(8r) to support the memory. when i type show c2600 i can see the 2 memory modules in the slots 1x 128mb and 1x64m but when i type show ver or show hard it only lists 128mb of memory.  Has this upgrade worked? how can i confirm that all the memory is available to be used?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4318b/0" level="1." new="yes"><Author authinfo=" Starplex">gmarogi</Author><Timestamp>Aug 5, 2009, 3:00pm PST</Timestamp><Msgbody>Show Version-Always shows memory in chassis based on running image (for example, with 128-MB DIMM shows 128, 160-MB shows 160)&lt;br /&gt;&lt;br /&gt;• Show C2600-Always shows specific physical memory in each slot (for example, DIMM slot 0-128 MB, DIMM slot 1-32 MB)&lt;br /&gt;&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;https://www.cisco.com/en/US/prod/collateral/routers/ps259/prod_qas0900aecd800f71dd.html&apos;)"&gt;https://www.cisco.com/en/US/prod/collateral/routers/ps259/prod_qas0900aecd800f71dd.html&lt;/A&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd43431" messages="1" subscribed="no" title="DC input operating range for PWR-C49M-1000DC"><Message attachment="no" canreply="yes" id=".2cd43431" level="">            <Author authinfo=" VINCO-T">andreypetrov</Author><Timestamp>Jul 29, 2009, 12:29am PST</Timestamp><Msgbody>Does anybody exactly know what&apos;s the DC input operating range for PWR-C49M-1000DC?&lt;br /&gt;Is a 69 VDC acceptable?&lt;br /&gt;Thanks in advance. </Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd43431/0" level="1." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Jul 29, 2009, 7:00pm PST</Timestamp><Msgbody>No.  DC input operating range: -48 to -60 VDC. &lt;br /&gt;&lt;br /&gt;Cisco Catalyst 4900M Switch DC Power Supply&lt;br /&gt;&lt;A HREF="javascript:newWin(&apos;http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9402/product_bulletin_c25-508039.html&apos;)"&gt;http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9402/product_bulletin_c25-508039.html&lt;/A&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd4294d" messages="1" subscribed="no" title="SDM  for Site to Site VPN feature avilable but not enabled ?"><Message attachment="no" canreply="yes" id=".2cd4294d" level=""><Author authinfo=" PROLIENT GROUP CORPORATION">MKCHAURASIA</Author><Timestamp>Jul 22, 2009, 7:46am PST</Timestamp><Msgbody>I have 3640, 1700 and 2600 series router &lt;br /&gt;I want to implement site to site VPN using SDM the problem is when I log in to SDM I see all the green dots saying IP enable with a check mark, VPN green dot and says feature avilable but not enabled firewall featured avilable but not enabled, &lt;br /&gt;I tried using crypto isakamp enable still I dont see in SDM as green dot and and a check mark on it. &lt;br /&gt;&lt;br /&gt;so over all how do I use SDM to set up Site to Site VPN or suggest me some Image name for 3640, 1700, 2600 router that uses SDM.&lt;br /&gt;&lt;br /&gt;I know the steps of configuring it I just need help in to see VPN green dot and check mark on it &lt;br /&gt;Thanks </Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd4294d/0" level="1." new="yes">            <Author authinfo=" AFD CONSULTING">beth-martin</Author><Timestamp>Jul 28, 2009, 5:43am PST</Timestamp><Msgbody>You can enable the Firewall, config-&gt; firewall and ACL -&gt; create firewall on SDM.</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd42a22" messages="5" subscribed="no" title="over clocking"><Message attachment="no" canreply="yes" id=".2cd42a22" level=""><Author authinfo=" ">jason108247</Author><Timestamp>Jul 22, 2009, 4:52pm PST</Timestamp><Msgbody>What are the pros and cons of over clocking your router?</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd42a22/0" level="1." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Jul 24, 2009, 1:24am PST</Timestamp><Msgbody>CONS:  You immediately burn your warranty and support. </Msgbody><Attachment/></Message></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd42a22/1" level="2." new="yes">      <Author authinfo="Senior Network Engineer, WPS EXTERNAL TECHNOLOGY SOLUTIONS">collin_clark</Author><Timestamp>Jul 24, 2009, 7:53am PST</Timestamp><Msgbody>I guess I&apos;m hacking ignorant. How do overclock a CPU on a router?</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd42a22/3" level="2.1" new="yes"><Author authinfo=" ">jason108247</Author><Timestamp>Jul 27, 2009, 8:55am PST</Timestamp><Msgbody>Collin,&lt;br /&gt;&lt;br /&gt;when you hook two routers through serial ports you are given the chance to set the clock rate. For instance 64000. The clock rate can be altered by the engineer. I know the standard is usually about 64000 but I know that it can go much higher than that. </Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd42a22/4" level="2.1.1" new="yes">      <Author authinfo="Senior Network Engineer, WPS EXTERNAL TECHNOLOGY SOLUTIONS">collin_clark</Author><Timestamp>Jul 27, 2009, 10:30am PST</Timestamp><Msgbody>That&apos;s the clockrate of the serial link. You can go above 64000 and not hurt anything, you&apos;ll just be emulating a faster circuit. I thought you were talking about overclocking the CPU.</Msgbody><Attachment/></Message></Reply></Reply></Reply><Reply><Message attachment="no" canreply="yes" id=".2cd42a22/2" level="3." new="yes">            <Author authinfo=" EDS (AUSTRALIA) PTY LIMITED">leolaohoo</Author><Timestamp>Jul 24, 2009, 6:36pm PST</Timestamp><Msgbody>Hi Collin, &lt;br /&gt;&lt;br /&gt;Give it some weed.  He he he ...</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd426dc" messages="0" subscribed="no" title="ccna voice ver 6.1 study guide"><Message attachment="no" canreply="yes" id=".2cd426dc" level="">      <Author authinfo="ENGINEER, BT">arnie.allen</Author><Timestamp>Jul 21, 2009, 6:46am PST</Timestamp><Msgbody>Can you recomend a book for me as I would like to take an exam for the 642-436 cvoice 6.0&lt;br /&gt;mukesh.ved@bt.com</Msgbody> <Attachment/></Message></Conversation><Conversation id=".2cd423c4" messages="3" subscribed="no" title="Cisco IOS Router to PIX VPN Issues"><Message attachment="no" canreply="yes" id=".2cd423c4" level="">            <Author authinfo=" IPC CONSULTANT PROGRAM MEMBERS">tommyjreige</Author><Timestamp>Jul 19, 2009, 4:38pm PST</Timestamp><Msgbody>Hi Everyone,&lt;br /&gt;I have a small issue here which someone may be able to shed some light on.&lt;br /&gt;&lt;br /&gt;I have a Cisco IOS router which is terminating a site-to-site VPN connection on the dialer interface.  The PIX on the other end is behind a NAT router.  The tunnel is being established and one subnet is able to see another when the tunnel is up.  The thing we are having an issue is both networks on each side of the VPN contain multiple subnets and i cannot connect to all the subnets over the same tunnel.&lt;br /&gt;&lt;br /&gt;Any ideas.</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd423c4/0" level="1." new="yes">      <Author authinfo="Senior Network Engineer, WPS EXTERNAL TECHNOLOGY SOLUTIONS">collin_clark</Author><Timestamp>Jul 20, 2009, 12:19pm PST</Timestamp><Msgbody>Do you have all the networks in the NAT exemption and in the interesting traffic ACL? Also check to make sure your routing is in place for all the subnets.&lt;br /&gt;&lt;br /&gt;Hope that helps.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd423c4/1" level="1.1" new="yes">            <Author authinfo=" IPC CONSULTANT PROGRAM MEMBERS">tommyjreige</Author><Timestamp>Jul 20, 2009, 3:27pm PST</Timestamp><Msgbody>Yes all this is setup.&lt;br /&gt;I have just found out that Cisco IOS can only make connections from 1 network per crypt map unless multiple connections are made from server to host.  This is quite disturbing because i have not seen this in any documentation.&lt;br /&gt;Does anyone know of IOS to PIX IPsec with multiple subnets on each side of the network.</Msgbody><Attachment/></Message><Reply><Message attachment="no" canreply="yes" id=".2cd423c4/2" level="1.1.1" new="yes">      <Author authinfo="Senior Network Engineer, WPS EXTERNAL TECHNOLOGY SOLUTIONS">collin_clark</Author><Timestamp>Jul 21, 2009, 5:22am PST</Timestamp><Msgbody>I&apos;m not sure where you you got your information, but it is incorrect. I have configured multiple subnets for VPN with a single connection. </Msgbody><Attachment/></Message></Reply></Reply></Reply></Replies></Conversation><Conversation id=".2cd41981" messages="1" subscribed="no" title="Problems with VPN ASA 5510"><Message attachment="no" canreply="yes" id=".2cd41981" level="">            <Author authinfo=" Equipos y Sistemas">vidaluzarista</Author><Timestamp>Jul 13, 2009, 7:12am PST</Timestamp><Msgbody>Hi All&lt;br /&gt;&lt;br /&gt;I have a ASA 5510, I have configure 2 VPN, router 850-ASA is OK, but I can&apos;t establish the other VPN ASA-Astaro, the error is:&lt;br /&gt;Jul 09 15:35:57 [IKEv1]: Group = 200.50.2.114, IP = 200.50.2.114, QM FSM error (P2 struct &amp;0x3bcd8c0, mess id 0x4f4f1e75)!&lt;br /&gt;Jul 09 15:35:57 [IKEv1]: Group = 200.50.2.114, IP = 200.50.2.114, construct_ipsec_delete(): No SPI to identify Phase 2 SA!&lt;br /&gt;Jul 09 15:35:57 [IKEv1]: Group = 200.50.2.114, IP = 200.50.2.114, Removing peer from correlator table failed, no match!&lt;br /&gt;Jul 09 15:36:03 [IKEv1]: Group = 200.50.2.114, IP = 200.50.2.114, construct_ipsec_delete(): No SPI to identify Phase 2 SA!&lt;br /&gt;Jul 09 15:36:03 [IKEv1]: Group = 200.50.2.114, IP = 200.50.2.114, Removing peer from correlator table failed, no match!&lt;br /&gt;&lt;br /&gt;My configuration for VPN is:&lt;br /&gt;&lt;br /&gt;ACL:&lt;br /&gt;access-list Internet_cryptomap_40 extended permit ip 192.168.0.0 255.255.255.0 192.168.3.0 255.255.255.0&lt;br /&gt;access-list Internet_cryptomap_60 extended permit ip 192.168.0.0 255.255.255.0 192.168.1.0 255.255.255.0&lt;br /&gt;&lt;br /&gt;VPN:&lt;br /&gt;&lt;br /&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac&lt;br /&gt;crypto ipsec security-association lifetime seconds 86400&lt;br /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;br /&gt;crypto map Internet_map 20 match address Internet_cryptomap_20_1&lt;br /&gt;crypto map Internet_map 20 set peer 186.1.10.74&lt;br /&gt;crypto map Internet_map 20 set transform-set ESP-3DES-MD5&lt;br /&gt;crypto map Internet_map 20 set security-association lifetime seconds 86400&lt;br /&gt;crypto map Internet_map 20 set security-association lifetime kilobytes 4608000&lt;br /&gt;crypto map Internet_map 20 set nat-t-disable&lt;br /&gt;crypto map Internet_map 40 match address Internet_cryptomap_40&lt;br /&gt;crypto map Internet_map 40 set peer 165.98.233.180&lt;br /&gt;crypto map Internet_map 40 set transform-set ESP-3DES-MD5&lt;br /&gt;crypto map Internet_map 40 set security-association lifetime seconds 86400&lt;br /&gt;crypto map Internet_map 40 set security-association lifetime kilobytes 4608000&lt;br /&gt;crypto map Internet_map 60 match address Internet_cryptomap_60&lt;br /&gt;crypto map Internet_map 60 set peer 200.50.2.114&lt;br /&gt;crypto map Internet_map 60 set transform-set ESP-3DES-MD5&lt;br /&gt;crypto map Internet_map 60 set security-association lifetime seconds 28800&lt;br /&gt;crypto map Internet_map 60 set security-association lifetime kilobytes 4608000&lt;br /&gt;crypto map Internet_map interface Internet&lt;br /&gt;isakmp identity address&lt;br /&gt;isakmp enable Internet&lt;br /&gt;isakmp enable management&lt;br /&gt;isakmp policy 10 authentication pre-share&lt;br /&gt;isakmp policy 10 encryption aes&lt;br /&gt;isakmp policy 10 hash md5&lt;br /&gt;isakmp policy 10 group 2&lt;br /&gt;isakmp policy 10 lifetime 86400&lt;br /&gt;tunnel-group DefaultRAGroup ipsec-attributes&lt;br /&gt;isakmp keepalive threshold 10 retry 2&lt;br /&gt;tunnel-group 186.1.10.74 type ipsec-l2l&lt;br /&gt;tunnel-group 186.1.10.74 ipsec-attributes&lt;br /&gt;pre-shared-key *&lt;br /&gt;tunnel-group 165.98.233.180 type ipsec-l2l&lt;br /&gt;tunnel-group 165.98.233.180 ipsec-attributes&lt;br /&gt;pre-shared-key *&lt;br /&gt;tunnel-group 200.50.2.114 type ipsec-l2l&lt;br /&gt;tunnel-group 200.50.2.114 ipsec-attributes&lt;br /&gt;pre-shared-key *&lt;br /&gt;&lt;br /&gt;Thanks in Advanced&lt;br /&gt;&lt;br /&gt;Regards </Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd41981/0" level="1." new="yes"><Author authinfo=" Bitcom Consulting">vmoopeung</Author><Timestamp>Jul 17, 2009, 1:47pm PST</Timestamp><Msgbody>Removing peer from correlator table failed, no match!&lt;br /&gt;&lt;br /&gt;This typically means one of a few things including, incorrect peer address configured in the L2L setup page, mis-matched local and remote newtork definitions, Agressive Mode vs. Main Mode misconfig, and IKE Proposal parameters not matching up on both ends. &lt;br /&gt;</Msgbody><Attachment/></Message></Reply></Replies></Conversation><Conversation id=".2cd41a21" messages="1" subscribed="no" title="Cisco Unified Communications CUPC issues"><Message attachment="no" canreply="yes" id=".2cd41a21" level=""><Author>DKoettingWWT</Author><Timestamp>Jul 13, 2009, 11:54am PST</Timestamp><Msgbody>We recently implemented Call Manager 6 with CUPC.  We are seeing issues with users working off of our network and are unable to get presence status when logging in.  We have seen a few issues that could cause this.  These include the following:&lt;br /&gt;&lt;br /&gt;Windows Firewall is not allowing exceptions&lt;br /&gt;VPN Adapter Statful Firewall is on&lt;br /&gt;&lt;br /&gt;We are using CUPC 7.0.2 and VPN Client 5.0.02.  &lt;br /&gt;&lt;br /&gt;This issue is not across the board.  I would say appx 100 users report this issue.  We are using Windows XP Pro on our image.  Any suggestions?&lt;br /&gt;&lt;br /&gt;</Msgbody> <Attachment/></Message><Replies><MessagesSelected>30</MessagesSelected><Reply><Message attachment="no" canreply="yes" id=".2cd41a21/0" level="1." new="yes"><Author authinfo=" CSB TECHNOLOGY PARTNERS">benbollinger@home.com</Author><Timestamp>Jul 17, 2009, 9:28am PST</Timestamp><Msgbody>I fixed this on our asa by disabling "inspect sip".  Hope that helps.</Msgbody><Attachment/></Message></Reply></Replies></Conversation></Topic></Forum></Community></ActiveMessages>')
