Cisco

Interesting information / help what i found during my work. And working with Cisco Equipment. Any questions are suitable and getting response of what you want to know.

Yesterday I walked into a problem that the Cisco ISR 897VA was rebooted due to a power failure in the building. There was a preload update of the IOS software. The Software which was preloaded were: c800-universalk9-mz.SPA.156-2.T1.bin. After the reboot, the router came up. but there was not a proper connection. After checking that the…

Read More Cisco 897VA and Orange France compatibility issue

In my previous post in april I figured out how to upgrade the software step by step. In the mean time I found out it’s possible to do this in once. You need to setup first some tools before you can start. Have a TFTP and a FTP Server TFTP server needs to contain the…

Read More Cisco ASA – SourceFire 5506-X | direct upgrade to latest build

Lately I’m busy to configure Cisco IOS routers in combination with Remote offices where we place Meraki Appliances (like the MX64, MX65 or the Z1) When we do this we create also a VPN connection (site to site). In this setup the Main office has a Cisco IOS router. Configuration of the Main Office. (Cisco…

Read More Cisco | Cisco IOS router to Meraki Appliance | site-to-site VPN with Zone based Firewalling

To see if you SSL version for AnyConnect is on a safe level. You want to check this first via the following website https://www.ssllabs.com/ssltest/analyze.html You need to enter your domain name which you use to connect with the clients to logon to. For this you need to use at lease ASA software version 9.3(2) or…

Read More Cisco | ASA disable SSL 3.0 settings and change it to TLS V1.2

Since a couple of years actually I noticed that when I use recent IOS versions on a Cisco ISR device. That there are some struggles with NAT rules in combination with a VPN client. In somecases you have to put the access-list for the NAT rule with a Permit like below. ip access-list extended ACL_OUTSIDE_NO_NAT…

Read More Cisco | IOS version difference in case of use NO_NAT