Philip D'Ath

Member Since: Oct 25, 2001

User Badges:
  • Purple, 4500 points or more
  • Cisco Designated VIP,

    2017 WAN, LAN, VPN

English
Philip D'Ath commented on VPN Cisco ASDM in VPN 3 hours ago

No.

Philip D'Ath commented on VPN Cisco ASDM in VPN 4 hours ago

I mostly use StrongSwan, but this makes it much easier now you have said that.  Use these...

Philip D'Ath commented on VPN Cisco ASDM in VPN 4 hours ago

And has the remote end changed their configuration to use IKEv2 as well? Chances are that will fix...

Philip D'Ath commented on VPN between CISCO ISR4321 and CISCO1941 in VPN 5 hours ago

There is not enough of the log to determine the issue. We also need the log from both ends while...

Philip D'Ath commented on Mac Address forwarding from c2960x to d-link in LAN, Switching and Routing 5 hours ago

Yucky and messy and bound to cause ongoing grief.  Get rid of the DLink if you want to use 802.1x.

Philip D'Ath commented on IWAN Saclalblity. in Solutions and Architectures 5 hours ago

I don't know the answer.  I would expect it to be many thousands of sites per router. I was...

Philip D'Ath commented on ISE 2.2 Vmware Memory into Swapped whole vm HANG in AAA, Identity and NAC 5 hours ago

The screenshot shows a large memory balloon.  VMWare uses a memory balloon when it does not have...

Philip D'Ath commented on VPN Cisco ASDM in VPN 5 hours ago

IKEv2 is much better at handling tricky things like this.  Can you change to IKEv2?

Philip D'Ath commented on Going from 3750 to ASR 920 in WAN, Routing and Switching 5 hours ago

You are using a flat vlan structure across all your buildings. I'm not sure the ASR920 was the best...

Philip D'Ath commented on ISE 2.2 Vmware Memory into Swapped whole vm HANG in AAA, Identity and NAC 5 hours ago

You need to add more memory to your physical host.

Philip D'Ath commented on dmvpn with spokes from one nat pool in VPN 5 hours ago

So there are a bunch of spokes sitting behind a firewall doing NAT, correct? This is a problematic...

Philip D'Ath commented on DRP in WAN, Routing and Switching 5 hours ago

You could buy a QinQ circuit from your provider to link the primary and DR site (easiest option)....

Philip D'Ath commented on IPSEC over GRE ios 15.2 in VPN 5 hours ago

VTI

Philip D'Ath commented on BGP Not advertising prefixes in WAN, Routing and Switching 5 hours ago

Try adding a "redistributed connected subnets" under the address family.

Philip D'Ath commented on FMC on a Mac? in Intrusion Prevention Systems/IDS 5 hours ago

Does Fusion run standard ESXi server images?

Philip D'Ath commented on Is valid ARP required for a route to be active? in WAN, Routing and Switching 5 hours ago

I don't believe that the route will be withdrawn due to an arp adjacency failure.

Philip D'Ath commented on Cisco 3850 stacking in Network Management 5 hours ago

If you configure the NIC adaptors for switch assisted teaming then you need to configure a Port-...

Philip D'Ath commented on BGP Advertisement in WAN, Routing and Switching 5 hours ago

/24's will be preferred over a /19.

Philip D'Ath commented on VPN Cisco ASDM in VPN 5 hours ago

Are you able to use IKEv2 to the remote peer?

Philip D'Ath commented on VPN Cisco ASDM in VPN 5 hours ago

To be clear, you are using ASAv in Amazon AWS?

Philip D'Ath commented on DHCP on 2801 in LAN, Switching and Routing 8 hours ago

You have not got the router configured to be a DNS server, so change: dns-server 192.168.2.1 8.8.8....

Philip D'Ath commented on SIP & QOS in IP Telephony 8 hours ago

If the MPLS circuit only has VoIP traffic and nothing else on it then you don't need to worry.  ...

Philip D'Ath commented on Spanning Tree in LAN, Switching and Routing 8 hours ago

Automatic.

Philip D'Ath commented on Unable to ping website address in Firewalling 8 hours ago

Try adding: policy-map global_policy class inspection_default   inspect icmp error

Philip D'Ath commented on cisco7606s There was an illegal address issue when upgrading the version in WAN, Routing and Switching 10 hours ago

This is your ROMMON version. ROM: System Bootstrap, Version 12.2(33r)SRE, RELEASE SOFTWARE (fc1)...

Philip D'Ath commented on Slow transfer rate across vlans in LAN, Switching and Routing 17 hours ago

You don't need to create any routes on the core switch as they will be directly connected...

Philip D'Ath commented on cisco7606s There was an illegal address issue when upgrading the version in WAN, Routing and Switching 1 day ago

I'm not sure once you are in ROMMON.  Before hand "show ver" will tell you.

Philip D'Ath commented on cisco7606s There was an illegal address issue when upgrading the version in WAN, Routing and Switching 1 day ago

Have you used this same image on other 7606's? Do they have the same ROMMON version? Another...

Philip D'Ath commented on cisco7606s There was an illegal address issue when upgrading the version in WAN, Routing and Switching 1 day ago

Perhaps the image is corrupt.  You could try downloading it again. Perhaps ROMMON itself needs an...

Philip D'Ath commented on 3650 switch firmware upgrade in LAN, Switching and Routing 1 day ago

If you just do this it should upgrade both of them in the stack: software install file flash:...

Philip D'Ath commented on Cisco 4451 High Memory Utilization in WAN, Routing and Switching 1 day ago

From my experience, you can spend hours and hours of time investigating an issue that was resolved...

Philip D'Ath commented on Cisco 4451 High Memory Utilization in WAN, Routing and Switching 1 day ago

You are about 5 patch releases behind.  There could be 1,000 bugs fixed between the code you are on...

Philip D'Ath commented on Cisco 4451 High Memory Utilization in WAN, Routing and Switching 1 day ago

Hmm, you have code at the start of a train.  Always a recipe for an issue.  I wouldn't do anything...

Philip D'Ath commented on Cisco 4451 High Memory Utilization in WAN, Routing and Switching 1 day ago

I lie, you have OSPF, not BGP.  This makes me most suspicious of the IOS-XE version you are using.

Philip D'Ath commented on Cisco 4451 High Memory Utilization in WAN, Routing and Switching 1 day ago

There is not enough information to determine anything. Lets start with the obvious.  What IOS-XE...

Philip D'Ath commented on Slow transfer rate across vlans in LAN, Switching and Routing 1 day ago

The most obvious answer is the firewall can not do routing at Gigabit speeds ...

Philip D'Ath commented on Anycast Routing for Disaster Recovery in LAN, Switching and Routing 1 day ago

I would use the bandwidth command only at the DR site, and only on the replicated VLAN(s).  Correct...

Philip D'Ath commented on Anycast Routing for Disaster Recovery in LAN, Switching and Routing 1 day ago

I normally use HSRP.  I have one customer where their DR plan involves manually moving the gateway...

Philip D'Ath commented on How can a VLAN be extended between 2 data centers for only a few weeks. in VPN 1 day ago

Just thinking; you have specified "spanning-tree bpduguard enable" but are plugging two switch...

Philip D'Ath commented on How can a VLAN be extended between 2 data centers for only a few weeks. in VPN 1 day ago

Is GigabitEthernet0/0/4 a "routed" interface, or an interface on a switch module? You can use...

Philip D'Ath commented on Site to Site with remote Strongswan not passing traffic in VPN 2 days ago

You don't need vpn-filter at all.  You can delete that. The issue is the NAT.  You are NATing your...

Philip D'Ath commented on Network Position in Other Network Infrastructure Subjects 2 days ago

A NOC Engineer is usually a network engineer who works in a NOC.  Where you work has little...

Philip D'Ath commented on Contract term in How To Training 2 days ago

You can buy 1, 3, 5, 7 and 10 year licences.  If you have already bought a 12 month licence you...

Philip D'Ath commented on Please find IOS version for IP SEC service in WAN, Routing and Switching 2 days ago

IPSec will work fine with the base memory. With the 2800 you have a specific image for each...

Philip D'Ath commented on DHCP snooping in LAN, Switching and Routing 2 days ago

You want to be using up to date software.  I had some issues with the earlier software many years...

Philip D'Ath commented on Does Cisco GLC-T 1000BASE-T SFP Copper RJ-45 Transceiver support Catalyst 6500 9-slot Chassis System in Network Management 2 days ago

This is the compatibility matrix. http://www.cisco.com/c/en/us/td/docs/interfaces_modules/...

Philip D'Ath commented on Anycast Routing for Disaster Recovery in LAN, Switching and Routing 2 days ago

They need an "AX" licence.  They will work fine.  I'm going to guess you'll get 50Mb/s to 100Mb/s...

Philip D'Ath commented on Anycast Routing for Disaster Recovery in LAN, Switching and Routing 2 days ago

As with any solution you do need a router with enough grunt to drive it ... Also I strongly like...

Philip D'Ath commented on Anycast Routing for Disaster Recovery in LAN, Switching and Routing 2 days ago

Ah yes, that is one of my prior answers as well. Yes, because the VLAN would be hot at both sites...

Philip D'Ath commented on Anycast Routing for Disaster Recovery in LAN, Switching and Routing 2 days ago

To do this you would use a protocol called L2TPv3.  You need a router on each end with a spare...

Bio

0804414F0015451A174B1C0D2E0B2D2E3E7B2C1613580D1B

User Badges:
  • Badge.
    Purple
    4500 points or more
  • Badge.
    Community Spotlight Award

    Member's Choice, May 2016

  • Badge.
    Community Spotlight Award

    Small Business, March 2016

  • Badge.
    Community Spotlight Award

    Best Publication, February 2016

  • Badge.
    Community Spotlight Award

    Questions Answered, January 2016

  • Badge.
    Community Spotlight Award

    Questions Answered, December 2015

  • Badge.
    Cisco Designated VIP

    2017 WAN, LAN, VPN

Philip D'Ath's Stats

Discussion started
Answers marked as Correct
Endorsed
Content Rated
Website: