Cisco IPSec VPN (site-to-site)

Site A R1(config)#crypto isakmp policy 1 R1(config-isakmp)#authentication pre-share R1(config)#crypto isakmp key Password address SITE.B.IP.ADDRESS R1(config)#access-list 100 permit ip 10.0.0.0 0.255.255.255 192.168.32.0 0.0.0.255 R1(config)#crypto ipsec transform-set MYSET esp-sha-hmac esp-aes Combine above global config to my crypto map 1 R1(config)#crypto map MYMAP 1 ipsec-isakmp R1(config-crypto-map)#set transform-set MYSET R1(config-crypto-map)#set peer SITE.B.IP.ADDRESS R1(config-crypto-map)#match address 100 Turn on R1(config)#interface...

CCNP 300-101 Route

VPN Check isakmp policy R1# show crypto isakmp policy Enable isakmp R1(config)#crypto isakmp enable Create a policy with pre-shared key R1(config)# crypto isakmp policy 100 R1(config-isakmp)# authentication pre-share R1(config-isakmp)# encryption 3des R1(config-isakmp)# hash md5 R1(config-isakmp)# lifetime 86400 R1(config)# crypto isakmp key 6 CCNP address 10.1.1.252 R1(config)# crypto ipsec transform-set CCNP_LAB ah-md5-hmac R1(cfg-crypto-trans)# mode tunnel...

CCNP 300-115 Switch study Part 1/2

How to determine the root bridge? SW# show spanning-tree vlan 192 Indicated as “This bridge is the root“. All the port Roles are Desg (designated port)   Make this switch a root bridge SW250(config)# spanning-tree vlan 192 priority 0   CAM (Content Addressable Memory) A term used synonymously with MAC Address Table that refers...

Common Cisco file management commands

Present Working Directory SW1# pwd Show directory SW1# dir ? Change Directory SW1# cd Copy SW1# copy running-config backup.running.txt Delete and remove SW1# delete flash:/sing-file.txt SW1# rm folders-directories Delete a directory in flash: (without prompt) SW1# delete /force /recursive flash: Show flash SW1# show flash Erase (wipe configuration & start with default config) SW1#...

How to upgrade Cisco switch IOS

Check existing version SW1# show version Check existing boot location SW1# show boot Backup existing version SW1# copy flash:c3750-ipbasek9-mz.122-25.SEE3.bin tftp: Download new IOS and verify MD5 SW1# copy tftp flash SW1# dir flash: SW1# verify /md5 flash:c3750-ipbasek9-mz.122-25.SEE3.bin Get-FileHash on Windows dir Get-FileHash <filepath> -Algorithm MD5 Get-FileHash .\c3750-ipbasek9-mz.122-55.SE12.bin -Algorithm MD5 Ask switch to boot from...

Common Cisco commands

Enable name lookup SW1(config)# ip domain-lookup SW1(config)# ip name-server YOUR.DNS.SERVER.IP SW1(config)# ip domain name yourDomainName.com Disable name lookup SW1(config)# no ip domain-lookup Give DNS domain name SW1(config)# ip domain-name example.com Increase SSH session timeout (e.g. 720 mins = 30 hours and 0 sec) SW252(config)# line vty 0 4 SW252(config-line)# exec-timeout 720 0 Change History...

Cisco troubleshooting commands

Display live syslog messages SW1# terminal monitor SW1# terminal no monitor Show log SW1# show logging SW1# show logging history Show IP address of each interface SW1# show ip int br SW1# show ip interface brief Show route SW1# show ip route Show IP address of vlan 172 SW1# show ip int br...

Backup Cisco running-config via SSH

Copy running config R#copy running-config scp:\\192.168.1.2Address or name of remote host ? 192.168.1.2Destination username ? kimDestination filename ? R.txtWriting MOLR.txtPassword: Sink: C0644 3655 MOLR.txt!3655 bytes copied in 8.548 secs (428 bytes/sec) Config file will be stored at user’s home directory    Other methods of copying running-config MOLR#copy running-config ?archive: Copy to archive: file systemflash:...

Apply Cisco license

Apply license Router# copy tftp flash: Address or name of remote host ? 192.168.1.200 Source filename ? uck9_license.lic Destination filename ? Accessing tftp://192.168.1.200/uck9_license.lic… Loading uck9_license.lic from 192.168.1.200 (via GigabitEthernet0/1.192): ! 1161 bytes copied in 0.059 secs (19678 bytes/sec)   Router# license install flash:uck9_license.lic Installing licenses from “flash:uck9_license.lic” Installing…Feature:uck9…Successful:Supported...

Configure clock time on Cisco device

Manually set clock time Step 1. Router(config)# clock timezone GMT 8 Step 2. Configure Daylight Saving time Router(config)# clock summer-time GMT recurring Step 3. #in Privileged mode not Global Configuration Mode Router# clock set 17:47:00 JUN 14 2016 Verify time Router# show clock #Set Cisco time with NTP (Network Time Protocol) Router(config)# ntp server...

Scroll to top