Karsten Iwen

Member Since: Dec 21, 2006

English
Karsten Iwen's Activity on Cisco Support Community
Currently displaying 50 results

Karsten Iwen has commented on Site-to-Site VPN without IPSEC on ASA?

1 day 19 hours ago
Is it just about showing that one transmission is clear text and the other is...

Karsten Iwen has commented on Question regarding ASA Upgrade Path 8.0(5) to 9.1.7(9)

2 days 3 hours ago
The automatic migration is not producing optimal code when the NAT config is...

Karsten Iwen has commented on Is it possible to use dual hub dual cloud DMVPN in Phase 1?

2 days 20 hours ago
The Hubs don't need four interfaces in that case, One per ISP is enough. You...

Karsten Iwen has commented on Is it possible to use dual hub dual cloud DMVPN in Phase 1?

3 days 44 min ago
Well, you could run it with four tunnels to have maximum redundancy. But that...

Karsten Iwen has commented on Is it possible to use dual hub dual cloud DMVPN in Phase 1?

3 days 4 hours ago
In this scenario you use two tunnel-interfaces on your spoke. Each tunnel is...

Karsten Iwen has commented on ACL with time-range not working

3 days 9 hours ago
You specified the ports 80 and 443 as source-ports, but you have to specify...

Karsten Iwen has commented on Issues with site-to-site VPN between ASA and Router

4 days 7 hours ago
On the router you have ip in the crypto ACL while the ASA has top and ICMP....

Karsten Iwen has commented on AnyConnect automatic logon

4 days 8 hours ago
Not sure about Windows, but perhaps you could build a workflow with OpenConnect...

Karsten Iwen has commented on 2811 IOS availability

4 days 8 hours ago
For most of the Cisco devices you need a valid service contract to download...

Karsten Iwen has commented on CPT 6.1.1 ASA5505 NAT from a subnet different from the connected interface

5 days 8 hours ago
For sure! If you can, then summarize all your internal networks to have...

Karsten Iwen has commented on Tacacs on Alternate Port

5 days 9 hours ago
You are using the legacy config. Try the new config-style: core1(config)#...

Karsten Iwen has commented on Upgrade ASA5510 to latest available software

5 days 9 hours ago
The information how to upgrade is always outlined in the release notes. You...

Karsten Iwen has commented on CPT 6.1.1 ASA5505 NAT from a subnet different from the connected interface

5 days 10 hours ago
The NAT should work. If the outside laptop sees the internal IP I would think...

Karsten Iwen has commented on Question regarding ASA Upgrade Path 8.0(5) to 9.1.7(9)

6 days 20 min ago
The first statement is/was kind of true (although the example is mostly wrong)...

Karsten Iwen has commented on ISE 2.0 cisco press book

6 days 20 hours ago
You got a chance to review the third book ? No, and with ISE 2.1 available...

Karsten Iwen has commented on Radius Server key

1 week 4 hours ago
At least it's a config that is shown in Cisco best practices and I assume that...

Karsten Iwen has commented on Cisco 5525 Licencing

1 week 23 hours ago
"Normally" your licenses should merge without any problems. But there are...

Karsten Iwen has commented on Site to Site VPN DNS resolving Issue

1 week 1 day ago
The clients in the remote site need to use a DNS-server that can resolve the...

Karsten Iwen has commented on Traffic shaping and rate limit in ASA Firewall

1 week 1 day ago
The server is allowed to burst traffic over the rate of 2MBit/s. Thats normal....

Karsten Iwen has commented on Traffic shaping and rate limit in ASA Firewall

1 week 1 day ago
How do you test it? You have to transfer a big file to see it working.

Karsten Iwen has commented on Recommended Router

1 week 1 day ago
If you don't add many CPU-consuming services, it could work with these...

Karsten Iwen has commented on Traffic shaping and rate limit in ASA Firewall

1 week 1 day ago
But when the policy is applied on the outside interface, your ACL Srvr...

Karsten Iwen has commented on Recommended Router

1 week 1 day ago
Look at the ISR 4000 range of routers. They should fit your needs: http://www....

Karsten Iwen has commented on Radius Server key

1 week 1 day ago
Not all passwords can be protected efficiently. While there are functions in...

Karsten Iwen has commented on Traffic shaping and rate limit in ASA Firewall

1 week 2 days ago
Are you sure that you applied the policy in the right direction? The way you...

Karsten Iwen has commented on Site-to-site DNS config

1 week 2 days ago
What do you mean with group-policy-configuration? The one on the ASA? That...

Karsten Iwen has commented on CCNP Security Lab

1 week 3 days ago
For CCNP Security it depends on which Exam you are studying for: SENSS:You...

Karsten Iwen has commented on Cisco ISE features and license requirements

1 week 4 days ago
Hi Marvin, there should be a license for up to 5000 guest users on ISE express...

Karsten Iwen has commented on Cisco ISE features and license requirements

1 week 4 days ago
Based on these requirements, the ISE Express could be a possible license for...

Karsten Iwen has commented on Cisco ASA Web VPN (Anyconnect)

1 week 4 days ago
Each combination of IP/Port can only be used with one service. If you can't get...

Karsten Iwen has commented on ASA 5505 - Request for Anyconnect Client, IPS/IDS Modul

1 week 5 days ago
Searching the forum and web I found out that Anyconnect and IPS/IDS licenses...

Karsten Iwen has commented on Setting up NAT with firewall behind router

1 week 5 days ago
The (IOS) router has much more features for site-to-site VPN than the ASA...

Karsten Iwen has commented on Setting up NAT with firewall behind router

1 week 5 days ago
For NAT, a rule of thumb is that it's implemented on the device that has the...

Karsten Iwen has commented on LAP LED Cycle between Green and Red

1 week 5 days ago
As far as I know it's still only an option for the customer to buy the...

Karsten Iwen has commented on Poor throughput with Atnt 1GB GigaPower with ASA 5510 in the home

1 week 5 days ago
The ASA 5510 is rated for a maximum throughput of 300 MBit/s. Far away of what...

Karsten Iwen has commented on ASA 5545 ACL Question

1 week 5 days ago
I also just tried to find it without any success. It's documented in the...

Karsten Iwen has commented on ASA 5545 ACL Question

1 week 5 days ago
Same here, The ASA-ACLs don't filter ASA-originated traffic.

Karsten Iwen has commented on Which Cisco AP model for SMB?

1 week 5 days ago
If the APs can reach the internet, then you should look at the Meraki line of...

Karsten Iwen has commented on How to setup Windows server to capture my Syslog from my 2901 router

1 week 6 days ago
You could give tftp64 a try. It's free software that also includes a syllog-...

Karsten Iwen has commented on reduce download speed when connect to cable modem

1 week 6 days ago
The 2811 can push about 60 MBit/s, which will get reduced by NAT, FW or...

Karsten Iwen has commented on Cisco ASA HA - WAN Mesh

2 weeks 12 min ago
right, the "no monitor-interface" is meant for unimportant interfaces that are...

Karsten Iwen has commented on CISCO881-K9

2 weeks 20 min ago
To my knowledge, only the maximum IPsec tunnels are documented (which are 20)....

Karsten Iwen has commented on CISCO881-K9

2 weeks 30 min ago
From the ordering guide: 2.1 Servers and Platforms  AnyConnect...

Karsten Iwen has commented on LAP LED Cycle between Green and Red

2 weeks 46 min ago
The UX APs don't have a default regulatory domain and have to be "primed"...

Karsten Iwen has commented on CISCO881-K9

2 weeks 52 min ago
There are different options. You are most likely looking for an AnyConnect Plus...

Karsten Iwen has commented on ASA5506 X Natting

2 weeks 1 hour ago
I am leaning on NAT Overload or Port Forwarding I believe... Just for the...

Karsten Iwen has commented on CISCO881-K9

2 weeks 1 hour ago
The licenses on the 881 are already shown. But client to site VPNs (or RA-VPNs...

Karsten Iwen has commented on Upgrade path from 9.1(5) to 9.4(2)

2 weeks 3 hours ago
If you are at least on 9.1(2), you can upgrade to any 9.1(3) or higher release...

Karsten Iwen has commented on Cisco ASA HA - WAN Mesh

2 weeks 4 hours ago
Do a sh run monitor-interface I assume that you are just missing a monitor-...

Karsten Iwen has commented on 1921/K9 vs 1921-SEC/K9

2 weeks 4 hours ago
Don't give to much on these descriptions. They can't list all features that are...

Bio

I started my work in the IT at about 1995/1996 as a freelance Trainer and consultant with a focus on networking, Novell NetWare and Microsoft Backoffice. In 2001 I started teaching Cisco classes at Global Knowledge in Germany. Since 2003 I'm again Freelancer with a strong focus on security technologies and infrastructure.
And yes, you can hire me for your security-projects and security-workshops. ;-)








  • Cisco Designated VIP

    2016 Firewalling, VPN





  • Cisco Designated VIP

    2015 Security





  • Cisco Designated VIP

    2014 Security





  • Cisco Designated VIP

    2013 Security





  • Community Spotlight Award

    Mobile App Contributor August 2012









Karsten Iwen's Stats

Points6661
Discussion started 18
Answers marked as Correct 884
Endorsed 27
Content Rated 96