Skip to main content

Posts

Error Message %DUAL-6-NBRINFO: EIGRP-IPv4 34256

If you see the error  %DUAL-6-NBRINFO: EIGRP-IPv4 xxxx  is blocked: not on common subnet then it simply means that there are EIGRP devices sending multicast hellos on an interface which have a different IP Range configured to the receiving router.  160617: .Feb 22 15:11:05.194 GMT: %DUAL-6-NBRINFO: EIGRP-IPv4 34256: Neighbor 17 2.31.253.1 (Vlan43) is blocked: not on common subnet                                                     (172.31.252.1/31) 160618: .Feb 22 15:11:12.770 GMT: %DUAL-6-NBRINFO: EIGRP-IPv4 34256: Neighbor 19 2.168.205.0 (Vlan44) is blocked: not on common subnet (192.168.204.1/31)                                                                       ...

ASA5585-X Does not support EIGRP between contexts

Since upgrading to the ASA5585-X firewall running in multi-context mode we have had a number of questions around functionality.  We raised a case with Cisco TAC to find out why EIGRP peering is not supported between contexts.  This was their response:- Thank you for your patience on this case; the behavior you are seeing on the ASA is expected since inter-context exchange of multicast is not supported “Context Guidelines EIGRP instances cannot form adjacencies with each other across shared interfaces because inter-context exchange of multicast traffic is not supported.” https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/general/asa-96-general-config/route-eigrp.html#ID-2179-0000001b As a workaround, you can configure static neighbors but it is supported only on point-to-point links. https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuo76566/?reffering_site=dumpcr So due to inter-context exchange of multicast traffic not being supp...

ASA5585-X Multi Context mode does not allow clientless webvpn access.

Since migrating to an ASA5585-X running in multi context mode, we have been unable to use the clientless webvpn mode to push down the anyconnect software.  We opened a TAC case and got this response from Cisco. Thanks for the information provided. Unfortunately clientless webvpn access is not supported in multiple context mode, that is the reason why you get the “Internal server error” when trying to access the ASA using a browser. While using the ASA in multiple context mode you need to find an alternative way to distribute the Anyconnect software and profile to the remote users since you won’t be able to provide it directly from the ASA. The following enhancement request was opened to address this issue in future releases: ENH: Add Features in Remote Access VPN in Multi-Context Mode CSCuw19758 Description Symptom: This is an Enhancement Request Add support for below features in Remote Access VPN in Multi-Context Mode: 1. Username-from-certificate and pre...

Introducing Network Solutions Consultancy

Add caption Network Solutions Consultancy  provides specialist Cisco network design and implementation services within the UK.   We have experience in producing advanced converged network designs for LAN, WAN and Datacentre connectivity as well as PCI compliant secure hosting environments for e-commerce platforms. The approach we offer is very different to our competitors; we understand that with network design, one size does not fit all.   Too many of our competitors just offer “cookie cutter” designs which are just intended to maximise their hardware sales.  Our highly experienced network architects spend the time to work closely with your business, learning about it, uncovering your requirements and pain points.  The design they produce will be tailored to meet not only your present needs, but also your future requirements. Whether you are a small to medium business needing the addtion of a single firewall, or a large multi-site company requiring ...

Installing PVDM into Cisco 2811

In order to install a PVDM into the Cisco 2800 series simply follow the steps below. Firstly power down the router and remove the case by undoing the case screws. At the back of the router near the power supply you will notice the memory (DIMM Slots) and behind them the PVDM slots (which are white). If you look closely on the mother board you will notice that one is labeled PVDM0 and the other PVDM1. If you are only installing one PVDM then you will need to install it in the PVDM0 slot. The PVDM has a little notch cut out of it which means it will only fit into the slot one way.  Locate the PVDM into the slot at a slight angle and then tip pull it upright until the clips click into place and hold it in position. Put the case back onto the router and switch it on.  Once booted do a show inventory and you should now see the PVDM listed.

Determining the number of active SSL connections on CSS/ACE

Whilst designing a new web farm network I needed to know how many SSL sessions our CSS was currently terminating in order to purchase the right SSL license for the Cisco ACE we were upgrading to. To determine the number of active SSL connections a CSS is using at that point in time use the command. show ssl flows The equivalent command on a Cisco ACE is... Show resource usage

Changing the hostname on CSS11500

First time I configured one of these it took me a while to figure out how to change the hostname. Its easy once you know the answer but it is not found in configuration mode. From enable mode you simply type the command prompt and then a name e.g.  CSS11500# prompt my-css-01 Simple huh!

Upgrade Supervisor Memory in the ME6524

The ME6524 ships with 256MB of Switch Processor Memory and 512MB of Route processor memory.  These can both be upgraded to 1Gig.  The part numbers for the ME6524 upgrades are... MEM-XCEF720-256M - Default memory on the Cisco ME 6524 switch processor MEM-XCEF720-512M - 512-MB memory upgrade option for the switch processor MEM-XCEF720-1GB - 1-GB memory upgrade option for the switch processor MEM-MSFC2-512MB - Default memory on the Cisco ME 6524 router processor MEM-MSFC3-1GB - 1-GB memory upgrade option for the router processor MEM-C6K-CPTFL512M - Default external 512-MB compact flash memory I will now detail how to perform and upgrade to the Switch Processor memory.  This is needed in order to support the higher IOS feature sets.  The route processor upgrade allows for larger routing tables. First of all you will need to remove all rack mount kits and undo all the screws until the top can slide backwards. Now the motherboard is exposed you will notic...

Quick Test for Cisco IPS functionality

If you ever need to test a Cisco IPS is inspecting and blocking traffic after you have installed it here is a quick test you can perform. Ideally you will have a web server behind the IPS you can test against else otherwise just setup on up quickly (google HFS for an awesome little tool). Initially you should try reaching the URL of the webserver normally.  If you have set everything up correctly then you should have no issues. Now in order to test the IPS blocking an attack simply append the following to the end of the URL "/../../windows/system32/cmd.exe". The URL should now look like http://www.testurl.com/windows/system32/cmd.exe You should now find that your request fails.  A quick look in the IPS event log will show that this fired the WWW WindowsNT cmd.exe rule.  It believes someone is attempting a buffer overflow error to obtain the command prompt and blocks it. This is a nice simple test to ensure that the IPS is inspecting and blocking traffic.

3750 Stackwise using mixed versions

I was unsure if it was possible to create a 3750 stack using a mixture of standard and enhanced licenses.  I was pretty sure they would join the stack but was unsure what features would work afterwards.  Would the entire stack gain routing functionality or would it be limited to just the EMI images?  Would the entire stack be forced to run as an SMI image?  These were the questions I needed answers to.  After much digging I came across a Cisco TAC article which answered all my questions. * The IOS software version on all stack members, including the stack master, should be the same. This helps ensure full compatibility in the stack protocol version among the stack members. For example, all stack members should have either the EMI or SMI * If your switch stack must have switches running SMI and EMI software,the switch running the EMI software should be the stack master. EMI features become unavailable to all stack members if the stack master is runni...

Secure Copy Protocol SCP

I have just discovered the joys of SCP.  When doing IOS upgrades across the internet this is the only way to go.  Who wants to mess around getting FTP working?  TFTP is next to useless across any unstable medium and even HTTP can be hassle to setup (unles you are using the awesome HFS portable app!). SCP simply allows you to transfer files to any device you can SSH to. It requires SSH and AAA to be setup on the device.  The first step as always is to generate an RSA key. Router(config)#hostname R1 R1(config)#crypto key generate rsa general-keys modulus 512 The name for the keys will be: R1.mydomain % The key modulus size is 512 bits % Generating 512 bit RSA keys, keys will be non-exportable...[OK] You must then turn on aaa and setup authentication and authorization (very important) to look for local usernames and passwords. R1(config)#aaa new-model R1(config)#aaa authentication login default local R1(config)#aaa authorization exec default...

Stateful NAT

Stateful NAT allows you to configure routers to synchronise their NAT tables.  It is useful in situations where you have redundant gateways and need the traffic to flow uninterrupted in the event of a failover. The first thing to setup is the stateful NAT mapping id.  This determines how the routers communicate their NAT information.  You can configure the synchronisation to use either UDP or TCP.  The redundancy name should be used in the HSRP configuration later. ip nat Stateful id 1 redundancy HSRP_IN mapping-id 1 as-queuing disable protocol udp We now need to create the NAT and HSRP settings on the interfaces.  Obviously we are setting the NAT inside and outside.  The HSRP is tracking the opposite interface so that the priority is reduced if it fails triggering a failover.  interface FastEthernet0/0 ip address 10.44.0.2 255.255.255.0 ip nat inside ip virtual-reassembly duplex auto speed auto standby ip 10.44.0.1 standby prio...

Shutting Cisco 3750 Stackwise ports

Today I came across a customers 3750 switch stack which had a flapping stackwise link. The stackwise link was transitioning up/down around 3 times a second and causing massive issues with connectivity and EIGRP routing for the site. Previously I believed that I would need to physically remove the Stackwise cable in order to restore service by shutting the flapping link. It seems it is possible to shut the Stackwise port from the CLI although it is done from enable mode rather than Configure terminal. The command is.. Switch#switch 1 stack port 1 ? disable Disable stack port enable Enable stack port The first number 1 would indicate the switch number in the stack and the second number 1 after the port is the Stackwise port number you want to shut. Make a note of which switch and port you shut as it will not show up in the config or the show outputs which could prove tricky when you want to reenable it.. You can determine the status of the ports using the command below but not how ...

Resilient VPN's - Part 1

I have been working on building a resilient VPN architecture for our monitoring network. One of the stipulations was that it was not to use GRE tunnels and must be capable of terminating at any number of peer VPN devices on the customers network. Routing must work automatically and no manual intervention is required. The problem you get with using plain IPSEC tunnels is that first you need some way of knowing if the tunnel is up. Then you have to adjust the routing on the customer side so that traffic destined to your network exits their network via the router with the currently active IPSEC tunnel. This is not an easy task and has taken a while to come up with some workable designs to deploy. I have settled on IPSEC HA in our datacentre and using Reverse route injection on the customer network to push our subnets into their dynamic routing protocol. I will go through the RRI solution in the next post for now lets have a look at the IPSEC HA configuration. IPSEC HA is available on the ...

WOL over the Internet

If like me you have ever wanted to wake up your computers at home from a remote location to grab some files or start some tasks off then you need Wake on LAN. This technology has been around for a while and basically allows a computer to wake up when it recieves a special UDP packet which contains 16 copies of its MAC address. Do a search on Wikipedia if you want to learn more about how the technology works. You will also have to ensure that your PC is capable of using WOL and that your OS is setup to allow it. We need some way of broadcasting the WOL packet onto the LAN from the internet. Firstly add the ip directed-broadcast command to the LAN interface to which your PC is connected. This allows the router to "explode" a unicast packet into a broadcast on your LAN. We now need to create a static nat which will convert your packet from the internet into a broadcast address on the LAN. In this case we are using port 7 but you could use any port of your choice for this. ...

Moving the SSH port on a CISCO router

If you admin your routers over the internet you probably know you should be using SSH. Telnet being sent in clear text is easily sniffed and your passwords captured. However Cisco routers use the standard TCP port 22 for their SSH service. As soon as you open this up to the world and turn on SSH access logging you will start to see hundreds of IP's connecting to your device and running dictionary attacks against you using standard username and password combinations. The majority of these IP's seem to originate from China or Russia and they find your open port extremely quickly. This is very anoying it fills up your log files with these attacks and uses up your system resources dealing with them. I believe they are simply running scans for any open TCP port 22. For this reason I decided I could cut down the amount of attacks by moving the SSH port to a different number. One thing you should know before we start is that there is no way to actually change the SSH port number o...

XBOX Live with Cisco NAT

When you connecting your XBOX 360 to XBOX Live through a CISCO router you are likely to get told that your NAT type is strict. This is because the CISCO routers do not support UPnP like most home routers. In order to resolve this issue you will need to configure your router to allow certain ports through and create some static NAT entries. Whilst a lot of games will work quite happily with NAT type strict you will notice finding other players for multiplayer matches is very slow. Gears of War 2 however will simply never find any other players if you have NAT type strict. There are 3 important ports needed for XBOX Live and they are TCP 3074 (used to connect to XBOX live and transfer data i.e. marketplace downloads, new content etc...) UDP 3074 which is used for delay sensitive traffic (multiplayer game sessions use this port) and UDP 88 (which is used for Kerberos. This is how you authenticate to the Microsoft XBOX Live servers) The first thing you need to do is to create a static NAT...

Top Talkers

Ever had slow WAN links and wanted to see exactly who was using up the bandwidth. What you need is the Top Talkers feature. You will first need to turn on NetFlow against the interface in question like so... interface serial 0/0 ip flow egress ip flow ingress Then we enable the top talkers feature ip flow-top-talkers top 20 sort-by bytes cache-timeout 3600000 The top command defines how many flows you want in the list in this case we will display the top 20 flows. The sort-by command determines how the flows are ordered. The choices are either bytes or packets. Generally bytes is more useful as it shows the weightier flows as top. You can also sort by packets this can help show a server which is perhaps sending a lot of smaller packets. The last command is cache-timeout this specifies the length of time the list of top talkers remains before being recalculated. The shorter the period the more system resources it uses. Once you have this configured you can view the top talker list by ...

Setup Netflow Collectors

Netflow is a great feature which provides detailed information on connection flows passing through your router or switch. You can use the data raw from the IOS CLI or export it to a Netflow collector for graphing and analysis. There are many free software packages out there for this and a google search will point you in the right direction. To get Netflow up and running you first need to configure the interfaces you want to get the flow data from. interface serial0/0 ip flow egress ip flow ingress The Egress command obviously turns on NetFlow for transmitted data whilst Ingress is data into the interface. (On older IOS version ip flow ingress was turned on with the command ip route-cache flow ) Now we can configure the NetFlow collector we wish to export the data to. ip flow-export source Loopback0 ip flow-export version 5 ip flow-export destination x.x.x.x 9996 The first command specifies the interface the NetFlow data will be sourced from. In this case we are using a loopback int...