<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cisco &#8211; How To configure an IPSec VPN</title>
	<atom:link href="http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/</link>
	<description>Tips and Video Tutorials - Cisco .:. Linux .:. VOIP</description>
	<lastBuildDate>Tue, 29 Nov 2011 04:01:10 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Dionysios</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-39098</link>
		<dc:creator>Dionysios</dc:creator>
		<pubDate>Mon, 24 Oct 2011 19:32:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-39098</guid>
		<description>How would you modify this for DDNS routers?</description>
		<content:encoded><![CDATA[<p>How would you modify this for DDNS routers?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denny</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-38504</link>
		<dc:creator>Denny</dc:creator>
		<pubDate>Thu, 02 Jun 2011 15:34:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-38504</guid>
		<description>ok... i got it working.  my nat entries needed the &quot; route-map POLICY-NAT extendable&quot; part... talk about a pain, i have over 120 NAT entries.

however... NOW my DNS servers (the ones that face the internet for our websites) won&#039;t work.  WTH?!</description>
		<content:encoded><![CDATA[<p>ok&#8230; i got it working.  my nat entries needed the &#8221; route-map POLICY-NAT extendable&#8221; part&#8230; talk about a pain, i have over 120 NAT entries.</p>
<p>however&#8230; NOW my DNS servers (the ones that face the internet for our websites) won&#8217;t work.  WTH?!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denny</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-38502</link>
		<dc:creator>Denny</dc:creator>
		<pubDate>Thu, 02 Jun 2011 13:39:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-38502</guid>
		<description>whoa... just made some progress.  figured out it was only from machines which had a static public NAT&#039;d IP that the error is happening.</description>
		<content:encoded><![CDATA[<p>whoa&#8230; just made some progress.  figured out it was only from machines which had a static public NAT&#8217;d IP that the error is happening.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denny</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-38501</link>
		<dc:creator>Denny</dc:creator>
		<pubDate>Thu, 02 Jun 2011 13:28:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-38501</guid>
		<description>http://img834.imageshack.us/img834/9711/vpnhn.jpg

here is a diagram of how our VPN is layed out.</description>
		<content:encoded><![CDATA[<p><a href="http://img834.imageshack.us/img834/9711/vpnhn.jpg" rel="nofollow">http://img834.imageshack.us/img834/9711/vpnhn.jpg</a></p>
<p>here is a diagram of how our VPN is layed out.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denny</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-38500</link>
		<dc:creator>Denny</dc:creator>
		<pubDate>Thu, 02 Jun 2011 13:11:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-38500</guid>
		<description>and from the 2650.

Version:

Cisco Internetwork Operating System Software
IOS (tm) C2600 Software (C2600-IK9O3S3-M), Version 12.3(19), RELEASE SOFTWARE (f
c2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2006 by cisco Systems, Inc.
Compiled Fri 12-May-06 04:14 by evmiller
Image text-base: 0x80008098, data-base: 0x81A0C1A4

ROM: System Bootstrap, Version 12.1(3r)T2, RELEASE SOFTWARE (fc1)
ROM: C2600 Software (C2600-IK9O3S3-M), Version 12.3(19), RELEASE SOFTWARE (fc2)

sky2650 uptime is 18 hours, 15 minutes
System returned to ROM by power-on
System image file is &quot;flash:c2600-ik9o3s3-mz.123-19.bin&quot;


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco 2650 (MPC860P) processor (revision 0x200) with 111616K/19456K bytes of mem
ory.
Processor board ID JAB05380878 (4003562465)
M860 processor: part number 5, mask 2
Bridging software.
X.25 software, Version 3.0.0.
1 FastEthernet/IEEE 802.3 interface(s)
2 Serial network interface(s)
32K bytes of non-volatile configuration memory.
32768K bytes of processor board System flash (Read/Write)

Configuration register is 0x2102

Diag:

Slot 0:
        C2650 1FE Mainboard Port adapter, 3 ports
        Port adapter is analyzed
        Port adapter insertion time unknown
        EEPROM contents at hardware discovery:
        Hardware Revision        : 2.0
        PCB Serial Number        : JAB05380878 (4003562465)
        Part Number              : 73-5024-04
        RMA History              : 00
        RMA Number               : 0-0-0-0
        Board Revision           : B0
        Deviation Number         : 0-0
        Product (FRU) Number     : C2600M-1FE
        EEPROM format version 4
        EEPROM contents (hex):
          0x00: 04 FF 40 01 C1 41 02 00 C1 18 4A 41 42 30 35 33
          0x10: 38 30 38 37 38 20 28 34 30 30 33 35 36 32 34 36
          0x20: 35 29 82 49 13 A0 04 04 00 81 00 00 00 00 42 42
          0x30: 30 80 00 00 00 00 FF FF FF FF FF FF FF FF FF FF
          0x40: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
          0x50: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
          0x60: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
          0x70: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF

        WIC Slot 0:
        FT1 BT8360
        Hardware revision 1.3           Board revision B0
        Serial number     25333331      Part number    800-03279-04
        FRU Part Number   WIC-1DSU-T1=

        Test history      0x0           RMA number     00-00-00
        Connector type    Wan Module
        EEPROM format version 2
        EEPROM contents (hex):
          0x20: 02 11 01 03 01 82 8E 53 50 0C CF 04 00 00 00 00
          0x30: 58 00 00 00 01 07 01 01 FF FF FF FF FF FF FF FF

        WIC Slot 1:
        FT1 BT8360
        Hardware revision 1.3           Board revision C0
        Serial number     14664217      Part number    800-03279-03
        FRU Part Number   WIC-1DSU-T1=

        Test history      0x0           RMA number     00-00-00
        Connector type    Wan Module
        EEPROM format version 2
        EEPROM contents (hex):
          0x20: 02 11 01 03 00 DF C2 19 50 0C CF 03 00 00 00 00
          0x30: 60 00 00 00 99 07 02 01 FF FF FF FF FF FF FF FF</description>
		<content:encoded><![CDATA[<p>and from the 2650.</p>
<p>Version:</p>
<p>Cisco Internetwork Operating System Software<br />
IOS &#8482; C2600 Software (C2600-IK9O3S3-M), Version 12.3(19), RELEASE SOFTWARE (f<br />
c2)<br />
Technical Support: <a href="http://www.cisco.com/techsupport" rel="nofollow">http://www.cisco.com/techsupport</a><br />
Copyright (c) 1986-2006 by cisco Systems, Inc.<br />
Compiled Fri 12-May-06 04:14 by evmiller<br />
Image text-base: 0&#215;80008098, data-base: 0x81A0C1A4</p>
<p>ROM: System Bootstrap, Version 12.1(3r)T2, RELEASE SOFTWARE (fc1)<br />
ROM: C2600 Software (C2600-IK9O3S3-M), Version 12.3(19), RELEASE SOFTWARE (fc2)</p>
<p>sky2650 uptime is 18 hours, 15 minutes<br />
System returned to ROM by power-on<br />
System image file is &#8220;flash:c2600-ik9o3s3-mz.123-19.bin&#8221;</p>
<p>This product contains cryptographic features and is subject to United<br />
States and local country laws governing import, export, transfer and<br />
use. Delivery of Cisco cryptographic products does not imply<br />
third-party authority to import, export, distribute or use encryption.<br />
Importers, exporters, distributors and users are responsible for<br />
compliance with U.S. and local country laws. By using this product you<br />
agree to comply with applicable laws and regulations. If you are unable<br />
to comply with U.S. and local laws, return this product immediately.</p>
<p>A summary of U.S. laws governing Cisco cryptographic products may be found at:<br />
<a href="http://www.cisco.com/wwl/export/crypto/tool/stqrg.html" rel="nofollow">http://www.cisco.com/wwl/export/crypto/tool/stqrg.html</a></p>
<p>If you require further assistance please contact us by sending email to<br />
<a href="mailto:export@cisco.com">export@cisco.com</a>.</p>
<p>cisco 2650 (MPC860P) processor (revision 0&#215;200) with 111616K/19456K bytes of mem<br />
ory.<br />
Processor board ID JAB05380878 (4003562465)<br />
M860 processor: part number 5, mask 2<br />
Bridging software.<br />
X.25 software, Version 3.0.0.<br />
1 FastEthernet/IEEE 802.3 interface(s)<br />
2 Serial network interface(s)<br />
32K bytes of non-volatile configuration memory.<br />
32768K bytes of processor board System flash (Read/Write)</p>
<p>Configuration register is 0&#215;2102</p>
<p>Diag:</p>
<p>Slot 0:<br />
        C2650 1FE Mainboard Port adapter, 3 ports<br />
        Port adapter is analyzed<br />
        Port adapter insertion time unknown<br />
        EEPROM contents at hardware discovery:<br />
        Hardware Revision        : 2.0<br />
        PCB Serial Number        : JAB05380878 (4003562465)<br />
        Part Number              : 73-5024-04<br />
        RMA History              : 00<br />
        RMA Number               : 0-0-0-0<br />
        Board Revision           : B0<br />
        Deviation Number         : 0-0<br />
        Product (FRU) Number     : C2600M-1FE<br />
        EEPROM format version 4<br />
        EEPROM contents (hex):<br />
          0&#215;00: 04 FF 40 01 C1 41 02 00 C1 18 4A 41 42 30 35 33<br />
          0&#215;10: 38 30 38 37 38 20 28 34 30 30 33 35 36 32 34 36<br />
          0&#215;20: 35 29 82 49 13 A0 04 04 00 81 00 00 00 00 42 42<br />
          0&#215;30: 30 80 00 00 00 00 FF FF FF FF FF FF FF FF FF FF<br />
          0&#215;40: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF<br />
          0&#215;50: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF<br />
          0&#215;60: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF<br />
          0&#215;70: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF</p>
<p>        WIC Slot 0:<br />
        FT1 BT8360<br />
        Hardware revision 1.3           Board revision B0<br />
        Serial number     25333331      Part number    800-03279-04<br />
        FRU Part Number   WIC-1DSU-T1=</p>
<p>        Test history      0&#215;0           RMA number     00-00-00<br />
        Connector type    Wan Module<br />
        EEPROM format version 2<br />
        EEPROM contents (hex):<br />
          0&#215;20: 02 11 01 03 01 82 8E 53 50 0C CF 04 00 00 00 00<br />
          0&#215;30: 58 00 00 00 01 07 01 01 FF FF FF FF FF FF FF FF</p>
<p>        WIC Slot 1:<br />
        FT1 BT8360<br />
        Hardware revision 1.3           Board revision C0<br />
        Serial number     14664217      Part number    800-03279-03<br />
        FRU Part Number   WIC-1DSU-T1=</p>
<p>        Test history      0&#215;0           RMA number     00-00-00<br />
        Connector type    Wan Module<br />
        EEPROM format version 2<br />
        EEPROM contents (hex):<br />
          0&#215;20: 02 11 01 03 00 DF C2 19 50 0C CF 03 00 00 00 00<br />
          0&#215;30: 60 00 00 00 99 07 02 01 FF FF FF FF FF FF FF FF</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denny</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-38499</link>
		<dc:creator>Denny</dc:creator>
		<pubDate>Thu, 02 Jun 2011 13:10:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-38499</guid>
		<description>Sure... the VPN module was on the old 2650, and worked fine.  it&#039;s the new 2901 that&#039;s killing me.  here are the outputs from the 2901.

Version:

Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version 15.0(1)M5, REL
EASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2011 by Cisco Systems, Inc.
Compiled Wed 23-Feb-11 15:41 by prod_rel_team

ROM: System Bootstrap, Version 15.0(1r)M9, RELEASE SOFTWARE (fc1)

router uptime is 19 hours, 19 minutes
System returned to ROM by power-on
System image file is &quot;flash0:c2900-universalk9-mz.SPA.150-1.M5.bin&quot;
Last reload type: Normal Reload


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

Cisco CISCO2901/K9 (revision 1.0) with 483328K/40960K bytes of memory.
Processor board ID FTX151703TR
2 Gigabit Ethernet interfaces
2 Serial interfaces
2 Channelized T1/PRI ports
1 Virtual Private Network (VPN) Module
DRAM configuration is 64 bits wide with parity enabled.
255K bytes of non-volatile configuration memory.
254464K bytes of ATA System CompactFlash 0 (Read/Write)


License Info:

License UDI:

-------------------------------------------------
Device#   PID                   SN
-------------------------------------------------
*0        CISCO2901/K9          FTX151703TR



Technology Package License Information for Module:&#039;c2900&#039;

----------------------------------------------------------------
Technology    Technology-package          Technology-package
              Current       Type          Next reboot
-----------------------------------------------------------------
ipbase        ipbasek9      Permanent     ipbasek9
security      securityk9    Evaluation    securityk9
uc            None          None          None
data          None          None          None

Configuration register is 0x2102

Diag:
Slot 0:
        C2901 Mother board 2GE, integrated VPN and 4W Port adapter, 4 ports
        Port adapter is analyzed
        Port adapter insertion time 19:19:46 ago
        EEPROM contents at hardware discovery:
        PCB Serial Number        : FOC15115W40
        Hardware Revision        : 1.0
        Part Number              : 73-11834-06
        Top Assy. Part Number    : 800-30795-02
        Board Revision           : E0
        Deviation Number         : 113332
        Fab Version              : 03
        Product (FRU) Number     : CISCO2901/K9
        Version Identifier       : V02
        CLEI Code                : CMMBN00ARA
        Processor type           : C1
        Chassis Serial Number    : FTX151703TR
        Chassis MAC Address      : 6400.f1a5.aa48
        MAC Address block size   : 72
        Manufacturing Test Data  : 00 00 00 00 00 00 00 00
        EEPROM format version 4
        EEPROM contents (hex):
          0x00: 04 FF C1 8B 46 4F 43 31 35 31 31 35 57 34 30 40
          0x10: 06 17 41 01 00 82 49 2E 3A 06 C0 46 03 20 00 78
          0x20: 4B 02 42 45 30 88 00 01 BA B4 02 03 CB 8C 43 49
          0x30: 53 43 4F 32 39 30 31 2F 4B 39 89 56 30 32 20 D9
          0x40: 04 40 C1 CB C2 C6 8A 43 4D 4D 42 4E 30 30 41 52
          0x50: 41 09 C1 C2 8B 46 54 58 31 35 31 37 30 33 54 52
          0x60: C3 06 64 00 F1 A5 AA 48 43 00 48 C4 08 00 00 00
          0x70: 00 00 00 00 00 F3 00 65 40 01 25 41 00 87 42 00
          0x80: 00 F8 00 28 03 E8 1C 89 07 D0 20 21 0B B8 20 93
          0x90: 0F A0 21 2F 13 88 21 83 17 70 21 A8 1B 58 21 B0
          0xA0: 1F 40 21 AB 23 28 21 79 27 10 21 78 41 01 1D 42
          0xB0: 00 00 F8 00 28 03 E8 1C 20 07 D0 1F 40 0B B8 20
          0xC0: 6C 0F A0 21 34 13 88 21 34 17 70 21 98 1B 58 21
          0xD0: 98 1F 40 21 98 23 28 21 34 27 10 21 34 FF FF FF
          0xE0: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
          0xF0: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF

        WIC Slot 0:
        VWIC2-2MFT-T1/E1 - 2-Port RJ-48 Multiflex Trunk - T1/E1
        Hardware Revision        : 0.0
        Top Assy. Part Number    : 800-22629-05
        Board Revision           : C0
        Deviation Number         : 0
        Fab Version              : 04
        PCB Serial Number        : FOC15142CF2
        RMA Test History         : 00
        RMA Number               : 0-0-0-0
        RMA History              : 00
        Product (FRU) Number     : VWIC2-2MFT-T1/E1
        Version Identifier       : V01
        EEPROM format version 4
        EEPROM contents (hex):
          0x00: 04 FF 40 03 FC 41 00 00 C0 46 03 20 00 58 65 05
          0x10: 42 43 30 88 00 00 00 00 02 04 C1 8B 46 4F 43 31
          0x20: 35 31 34 32 43 46 32 03 00 81 00 00 00 00 04 00
          0x30: CB 90 56 57 49 43 32 2D 32 4D 46 54 2D 54 31 2F
          0x40: 45 31 89 56 30 31 20 D9 02 40 C1 FF FF FF FF FF
          0x50: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
          0x60: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF
          0x70: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF</description>
		<content:encoded><![CDATA[<p>Sure&#8230; the VPN module was on the old 2650, and worked fine.  it&#8217;s the new 2901 that&#8217;s killing me.  here are the outputs from the 2901.</p>
<p>Version:</p>
<p>Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version 15.0(1)M5, REL<br />
EASE SOFTWARE (fc2)<br />
Technical Support: <a href="http://www.cisco.com/techsupport" rel="nofollow">http://www.cisco.com/techsupport</a><br />
Copyright (c) 1986-2011 by Cisco Systems, Inc.<br />
Compiled Wed 23-Feb-11 15:41 by prod_rel_team</p>
<p>ROM: System Bootstrap, Version 15.0(1r)M9, RELEASE SOFTWARE (fc1)</p>
<p>router uptime is 19 hours, 19 minutes<br />
System returned to ROM by power-on<br />
System image file is &#8220;flash0:c2900-universalk9-mz.SPA.150-1.M5.bin&#8221;<br />
Last reload type: Normal Reload</p>
<p>This product contains cryptographic features and is subject to United<br />
States and local country laws governing import, export, transfer and<br />
use. Delivery of Cisco cryptographic products does not imply<br />
third-party authority to import, export, distribute or use encryption.<br />
Importers, exporters, distributors and users are responsible for<br />
compliance with U.S. and local country laws. By using this product you<br />
agree to comply with applicable laws and regulations. If you are unable<br />
to comply with U.S. and local laws, return this product immediately.</p>
<p>A summary of U.S. laws governing Cisco cryptographic products may be found at:<br />
<a href="http://www.cisco.com/wwl/export/crypto/tool/stqrg.html" rel="nofollow">http://www.cisco.com/wwl/export/crypto/tool/stqrg.html</a></p>
<p>If you require further assistance please contact us by sending email to<br />
<a href="mailto:export@cisco.com">export@cisco.com</a>.</p>
<p>Cisco CISCO2901/K9 (revision 1.0) with 483328K/40960K bytes of memory.<br />
Processor board ID FTX151703TR<br />
2 Gigabit Ethernet interfaces<br />
2 Serial interfaces<br />
2 Channelized T1/PRI ports<br />
1 Virtual Private Network (VPN) Module<br />
DRAM configuration is 64 bits wide with parity enabled.<br />
255K bytes of non-volatile configuration memory.<br />
254464K bytes of ATA System CompactFlash 0 (Read/Write)</p>
<p>License Info:</p>
<p>License UDI:</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Device#   PID                   SN<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
*0        CISCO2901/K9          FTX151703TR</p>
<p>Technology Package License Information for Module:&#8217;c2900&#8242;</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Technology    Technology-package          Technology-package<br />
              Current       Type          Next reboot<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
ipbase        ipbasek9      Permanent     ipbasek9<br />
security      securityk9    Evaluation    securityk9<br />
uc            None          None          None<br />
data          None          None          None</p>
<p>Configuration register is 0&#215;2102</p>
<p>Diag:<br />
Slot 0:<br />
        C2901 Mother board 2GE, integrated VPN and 4W Port adapter, 4 ports<br />
        Port adapter is analyzed<br />
        Port adapter insertion time 19:19:46 ago<br />
        EEPROM contents at hardware discovery:<br />
        PCB Serial Number        : FOC15115W40<br />
        Hardware Revision        : 1.0<br />
        Part Number              : 73-11834-06<br />
        Top Assy. Part Number    : 800-30795-02<br />
        Board Revision           : E0<br />
        Deviation Number         : 113332<br />
        Fab Version              : 03<br />
        Product (FRU) Number     : CISCO2901/K9<br />
        Version Identifier       : V02<br />
        CLEI Code                : CMMBN00ARA<br />
        Processor type           : C1<br />
        Chassis Serial Number    : FTX151703TR<br />
        Chassis MAC Address      : 6400.f1a5.aa48<br />
        MAC Address block size   : 72<br />
        Manufacturing Test Data  : 00 00 00 00 00 00 00 00<br />
        EEPROM format version 4<br />
        EEPROM contents (hex):<br />
          0&#215;00: 04 FF C1 8B 46 4F 43 31 35 31 31 35 57 34 30 40<br />
          0&#215;10: 06 17 41 01 00 82 49 2E 3A 06 C0 46 03 20 00 78<br />
          0&#215;20: 4B 02 42 45 30 88 00 01 BA B4 02 03 CB 8C 43 49<br />
          0&#215;30: 53 43 4F 32 39 30 31 2F 4B 39 89 56 30 32 20 D9<br />
          0&#215;40: 04 40 C1 CB C2 C6 8A 43 4D 4D 42 4E 30 30 41 52<br />
          0&#215;50: 41 09 C1 C2 8B 46 54 58 31 35 31 37 30 33 54 52<br />
          0&#215;60: C3 06 64 00 F1 A5 AA 48 43 00 48 C4 08 00 00 00<br />
          0&#215;70: 00 00 00 00 00 F3 00 65 40 01 25 41 00 87 42 00<br />
          0&#215;80: 00 F8 00 28 03 E8 1C 89 07 D0 20 21 0B B8 20 93<br />
          0&#215;90: 0F A0 21 2F 13 88 21 83 17 70 21 A8 1B 58 21 B0<br />
          0xA0: 1F 40 21 AB 23 28 21 79 27 10 21 78 41 01 1D 42<br />
          0xB0: 00 00 F8 00 28 03 E8 1C 20 07 D0 1F 40 0B B8 20<br />
          0xC0: 6C 0F A0 21 34 13 88 21 34 17 70 21 98 1B 58 21<br />
          0xD0: 98 1F 40 21 98 23 28 21 34 27 10 21 34 FF FF FF<br />
          0xE0: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF<br />
          0xF0: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF</p>
<p>        WIC Slot 0:<br />
        VWIC2-2MFT-T1/E1 &#8211; 2-Port RJ-48 Multiflex Trunk &#8211; T1/E1<br />
        Hardware Revision        : 0.0<br />
        Top Assy. Part Number    : 800-22629-05<br />
        Board Revision           : C0<br />
        Deviation Number         : 0<br />
        Fab Version              : 04<br />
        PCB Serial Number        : FOC15142CF2<br />
        RMA Test History         : 00<br />
        RMA Number               : 0-0-0-0<br />
        RMA History              : 00<br />
        Product (FRU) Number     : VWIC2-2MFT-T1/E1<br />
        Version Identifier       : V01<br />
        EEPROM format version 4<br />
        EEPROM contents (hex):<br />
          0&#215;00: 04 FF 40 03 FC 41 00 00 C0 46 03 20 00 58 65 05<br />
          0&#215;10: 42 43 30 88 00 00 00 00 02 04 C1 8B 46 4F 43 31<br />
          0&#215;20: 35 31 34 32 43 46 32 03 00 81 00 00 00 00 04 00<br />
          0&#215;30: CB 90 56 57 49 43 32 2D 32 4D 46 54 2D 54 31 2F<br />
          0&#215;40: 45 31 89 56 30 31 20 D9 02 40 C1 FF FF FF FF FF<br />
          0&#215;50: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF<br />
          0&#215;60: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF<br />
          0&#215;70: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-38496</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Wed, 01 Jun 2011 21:59:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-38496</guid>
		<description>Denny,

It sounds like you do not have a vpn module in the 2650. Can you post the output of &#039;show version&#039; and &#039;show diag&#039;?

Josh</description>
		<content:encoded><![CDATA[<p>Denny,</p>
<p>It sounds like you do not have a vpn module in the 2650. Can you post the output of &#8216;show version&#8217; and &#8216;show diag&#8217;?</p>
<p>Josh</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denny</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-38495</link>
		<dc:creator>Denny</dc:creator>
		<pubDate>Wed, 01 Jun 2011 21:39:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-38495</guid>
		<description>I&#039;m at my wits end... and hopefully you can help.

We had a working VPN on a 2650 that allowed our 2 branches to connect to us.  It was slow over the single T1, but it worked ok.  We upgraded to a second T1 (bonded with multilink PPP encap) and a new router (Cisco 2901) and all hell has broken loose.

The internet works fine, nice and fast.  However the VPN is a nightmare.  Even copying (for the most part, obviously the IPs are different) what you have here I get nowhere.  When i run a ping from the router, sourced to the ethernet port, everything is fine.  Response times are around 80-85ms.  However if I ping them from my desktop the times are all over the place; some going through at 80ms like from the router, and some timing out entirely even with the timeout set to 20,000.  I&#039;ve had my ISP&#039;s techs working on it, and been working at it myself, for the past 3 days to no avail and am about to pull my hair out... any suggestions (other than a nice wig company)?</description>
		<content:encoded><![CDATA[<p>I&#8217;m at my wits end&#8230; and hopefully you can help.</p>
<p>We had a working VPN on a 2650 that allowed our 2 branches to connect to us.  It was slow over the single T1, but it worked ok.  We upgraded to a second T1 (bonded with multilink PPP encap) and a new router (Cisco 2901) and all hell has broken loose.</p>
<p>The internet works fine, nice and fast.  However the VPN is a nightmare.  Even copying (for the most part, obviously the IPs are different) what you have here I get nowhere.  When i run a ping from the router, sourced to the ethernet port, everything is fine.  Response times are around 80-85ms.  However if I ping them from my desktop the times are all over the place; some going through at 80ms like from the router, and some timing out entirely even with the timeout set to 20,000.  I&#8217;ve had my ISP&#8217;s techs working on it, and been working at it myself, for the past 3 days to no avail and am about to pull my hair out&#8230; any suggestions (other than a nice wig company)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ines</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-38416</link>
		<dc:creator>ines</dc:creator>
		<pubDate>Sun, 08 May 2011 13:20:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-38416</guid>
		<description>how to start capture with wireshark</description>
		<content:encoded><![CDATA[<p>how to start capture with wireshark</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gbenga</title>
		<link>http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/comment-page-2/#comment-37831</link>
		<dc:creator>gbenga</dc:creator>
		<pubDate>Mon, 14 Feb 2011 14:06:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.blindhog.net/cisco-how-to-configure-an-ipsec-vpn/#comment-37831</guid>
		<description>thanks a lot for work i so much appreciate it.how connect my active directory to a lan- to lan ipsec cisco tunnel</description>
		<content:encoded><![CDATA[<p>thanks a lot for work i so much appreciate it.how connect my active directory to a lan- to lan ipsec cisco tunnel</p>
]]></content:encoded>
	</item>
</channel>
</rss>

