Cisco – LDAP AAA Error ‘AAA Server has been removed”
Jan11

Cisco – LDAP AAA Error ‘AAA Server has been removed”

KB ID 0001271  Problem Seen while attempting to test AAA authentication via LDAP to a Windows domain Controller. Authentication test to host {IP-Address} failed. Following error occurred –  ERROR: Authentication Server not responding: AAA Server has been removed Solution This is a terribly ambiguous error! What it means is that the ASA cannot bind to active directory, either because; The ASA bind account password is wrong. The...

Read More
Cisco Licence Differences LAN-Lite / LAN Base / IP Base / IP Services
Jan11

Cisco Licence Differences LAN-Lite / LAN Base / IP Base / IP Services

KB ID 0001270  Problem Actually finding the answer to this question is far more challenging than it needs to be! As usual Cisco can change this on a whim so before you purchase any equipment it’s still a good policy to check on the feature navigator. Solution This is about the best reference I’ve found. Although anyone who can tell me what the correct Layer 2 differences between Enterprise Access and Complete Access are,...

Read More
Deploy Cisco FirePOWER Management Center (Appliance)
Nov30

Deploy Cisco FirePOWER Management Center (Appliance)

KB ID 0001263 Problem You have been able to manage your firewalls Internal SFR module for  while using the ASDM Setup FirePOWER Services (for ASDM) For most people that’s fine, but if you have a lot of FirePOWER devices to manage that does not scale well. In those cases you should use theFMC  (FirePOWER Management Center). Here ‘Im going to use the Vmware virtual appliance, (at time of writing there is no Hyper-V version)....

Read More
Cisco ASA – Remote IPSEC VPN With the NCP Entry Client
Nov23

Cisco ASA – Remote IPSEC VPN With the NCP Entry Client

KB ID 0001260  Problem I’ve covered Cisco IPSEC Remote VPNs a long time ago, and I’ve also blogged about the Cisco IPSEC VPN Client Software. Yes you can get the Cisco VPN Client Working on Windows 10, but can you imagine rolling that out to a few hundred users? The bottom line is Remote Cisco IPSEC VPN is a dead technology, Cisco, (and Me!) want you to use AnyConnect. For a couple of users you can use the work arounds...

Read More
Cisco SFR Session – Cannot Exit To Command Line
Nov22

Cisco SFR Session – Cannot Exit To Command Line

KB ID 0001259 Problem This tripped me up once before, and I didn’t document it! Normally if you have a console session open with your FirePOWER Module, (that you opened with a ‘session sfr’ command), then you can just quit, and exit back to the firewall by typing ‘exit’, like so; ciscoasa# session sfr Opening command session with module sfr. Connected to module sfr. Escape character sequence is...

Read More
Cisco IOS – How To Find VLAN IPs (SVI’s)
Nov16

Cisco IOS – How To Find VLAN IPs (SVI’s)

KB ID 0001258  Problem If you have a complicated network, you can spend more time finding out how it’s configured, than actually doing any work on it! Today I had a client that needed some changes made on their LAN, I knew their name, and their network address, and common sense told me which of the core switches they were connected to. Solution A quick search on the client name told me what VRF they were in, and what VLAN they...

Read More
Cisco AnyConnect – With Google Authenticator 2 Factor Authentication
Nov10

Cisco AnyConnect – With Google Authenticator 2 Factor Authentication

KB ID 0001256  Problem This was asked as a question on Experts Exchange this week, and it got my interest. A quick search turned up a bunch of posts that said, yes this is possible, and you deploy it with FreeRADIUS and it works great. The problem was, a lot of the information is a little out of date, and some of it is ‘wrong enough’ to make the non-technical types give up. But I persevered, and got it to work. Disclaimer:...

Read More
Meraki To Cisco ASA 5500 Site to Site VPN
Nov08

Meraki To Cisco ASA 5500 Site to Site VPN

KB ID 0001255  Problem This was surprisingly easier than I was expecting! Special thanks to  Steve for letting me loose on his test network for the Meraki end of the tunnel. Here I’m using an MX 64 Security appliance, and a Cisco ASA 5510. Note: The Meraki device will need a static IP. Solution Configuring Meraki MX Device for VPN to a Cisco ASA From your Meraki dashboard > Security Appliance > Site To Site VPN. If you...

Read More
MAC TFTP Software (OS X )
Oct15

MAC TFTP Software (OS X )

Mac TFTP KB ID 0001247 Problem Every time I go to a networking event theres a sea of MacBooks in the audience, If techs like MacBooks so much why is there such a lack of decent Mac TFTP software? Solution The thing is, I’m looking at the problem with my ‘Windows User’ head on. When I have a task to perform I’m geared towards looking for a program do do that for me. OS X is Linux (There I said it!) Linux in a...

Read More

Cisco IOS ‘Crypto’ Unrecognized Command?

KB ID 0001246 Problem I was working on a Cisco 3750-G last week, and I was in the process of setting up SSH access. When I went to generate the crypto key and enable SSH, It fired an error at me. In fact it wouldn’t execute any crypto commands; Core-SW(config)#crypto ? % Unrecognized command   Now I have seen this before, (but not for a while). You need to be running a K9 version of the code. A quick ‘show version’...

Read More