Author Archives: cyruslab

Anyconnect VPN using local account

Network diagram Configure inside and outside interface ciscoasa(config)# int gi0/1 ciscoasa(config-if)# nameif outside INFO: Security level for “outside” set to 0 by default. ciscoasa(config-if)# ip address dhcp setroute ciscoasa(config-if)# no shut ciscoasa(config-if)# int gi0/0 ciscoasa(config-if)# nameif inside INFO: Security level … Continue reading

Posted in General stuffs, VPN | Tagged , , , , , | Leave a comment

[CISCO ACI] Inter tenant contract

The ACI configuration for inter tenant contract is complicated. A contract provides two functions: Provide filter. Provide route leak. A tenant is considered a VRF itself. In this example there are two tenants T05 and T06. T05 exports the contract … Continue reading

Posted in General stuffs, Software Defined Network | Tagged , | Leave a comment

[CISCO ACI] Same VRF contract

I have an EPG Web and an EPG DB, I have provided a contract in EPG web and consumed contract in EPG DB. The results are: DB server can ping to Web server, and Web server can ping to DB … Continue reading

Posted in Software Defined Network | Tagged , , | Leave a comment

bigip snat automap

You created a forwarder virtual server for your servers behind the bigip appliance to access the internet, your server could not get a respond back. You troubleshoot the problem and found that: Default route is configured in the bigip. You … Continue reading

Posted in F5, General stuffs | Tagged | Leave a comment

Is bigip packet filter stateful or stateless?

Packet filter I have allowed vmnet5 to http and dns to any destination, and drop all for the rest. Nmap from client Actually nmap could not determine whether port 80 is opened or closed because there is no response. Packet … Continue reading

Posted in General stuffs | Leave a comment

Upgrade bigip image in active/standby HA

Import the latest iso to both the active and standby bigip Install latest iso on standby bigip On command line: [root@bigip2:Standby:In Sync] config # tmsh root@(bigip2)(cfg-sync In Sync)(Standby)(/Common)(tmos)# /sys software image root@(bigip2)(cfg-sync In Sync)(Standby)(/Common)(tmos.sys.software.image)# install BIGIP-12.1.0.0.0.1434.iso volume HD1.1 HD1.1 currently … Continue reading

Posted in F5, General stuffs, High Availability | Tagged , | Leave a comment