Q.1It means IOS 7.1 is not stable one. and i have to load ios 7.2 , am i right?
Q.2 i don't want any traffic start frpm 7.33 to any public ip.
i have putted command:
ip ACL inside deny ip host 172.16.7.33 any
after this command still i am getting the log, due to so many log firewall behave drametically. once we use this command firewalll should block the oubound connection but it is not doing.please find my nat statemenet
global (outside) 1 interface
nat (inside) 0 access-list inside_nat0_outbound
nat (inside) 1 172.16.0.3 255.255.255.255
nat (inside) 1 172.16.0.19 255.255.255.255
nat (inside) 1 172.16.7.32 255.255.255.255
as you suggest global(outside) 1 in (it is all ready there)
nat (inside) 1 172.16.0.0 255.255.0.0 (what this coomand will do , i thing it will nat all 172.16 subnet right, that we don't want we want only stop the loggs. and in mu comapany we have seprate network for internet access. only certan host we have permitted for talking to public up.
I got yours point, i check my DNS server in DNS server property , they had define root server. i need to remove root server from my internal DNS server. becouse i Intranet is not directly connected with internet. we have seprate network for internet.
Thanks for yours reponce.
I have one more qustion.
Q.1 regarding IOS, as i mentioned i have 7.1 , what you suggest can i change the IOS?
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :