Friday, 29 July 2011

Fortigate MR3 VPN to Cisco

So I'm doing a lot more Fortigate work in a new job.  Got to grips with most of the Forti foibles but this is a new one..

We've got a site with a Fortigate at the head office and Ciscos at the remote sites.  They're in construction so the Ciscos get kicked, dropped, spiked etc but just keep going.

I was adding a new site after recently updating the Fortigate to MR 3 PL1 and it would not work. The VPN just would not come up. Identical Cisco config (bar IP addresses) and the HO Forti VPN config looked identical too.  Until you get to the CLI...

Seems now there is a mode-cfg setting that defaults to enabled and the Cisco's don't like being told what to do.  Turn that off in the CLI and the VPN came up. By the way the VPNs on the Cisco end are VTIs using routes as these seem to play better and you don't have to specify and match proxies.

Monday, 7 March 2011

Reformed Orcon user

This is a New Zealand specific thing so not relevant to most.

I finally had had a guts full of our previous ISP Orcon and changed to Telecom several weeks ago.

Talk about night and day!  We can use youtube etc.  Even two of us at the same time!  This was unheard of on Orcon.  It took tens of minutes to load a 30 second clip. Downloads were regularly 2KB per second.  Whoever set up their shaping needs castrating.

Speed test shows not quite as dramatic results.  Download is up about 30 to 50 per cent depending on the day, and this is on ADSL 1 as I'm still using an old Cisco 1751 router. Ping is usually about half what it was.

To be fair Orcon quite quite good at 5AM.  We could watch youtube and download at hundreds of KB per second.So I'm guessing they just not good at the shaping and over subscribed.  A shame given they used to be one of the best 5 years ago.  Seems change of leadership a while back has led to more flash ('cuse the pun) and less substance.

Monday, 6 December 2010

Useful Cisco Links

Useful Cisco links...

Easy place to keep them so I don't forget and maybe helpful for others...


http://www.cisco.com/en/US/docs/ios/12_3t/12_3t14/feature/guide/gtpsscer.html#wp1027265

Generate self sign cert for http secure-server trustpoint.

Monday, 15 November 2010

Linux keyboard madness

This happens to me every so often so it I put it here I'll know where it is...

Something changes on the box and I can't type ', ", ` etc. I type ' twice and get
´ and other accents on characters.

Just seems to be /etc/X11/xorg.conf having

Option "XkbVariant" "intl"

Under the keyboard input device. Remove that and it works as normal...



Saturday, 2 October 2010

Epiphany opening pages twice on crash recovery

I have this happen all the time and it really annoys me but found an easy fix this morning.

Typically I log in and every time I log in I get a dialog Ephiphany crashed do you want to recover or cancel. You click recover and every window that was open is now duplicated.

Just by chance this morning I closed the dialog. Not cancelled but 'X'ed it and I got one copy of all my windows from last time.

Give it a whirl.

Saturday, 11 September 2010

Bring back the nice English lady on the UC500..

I use a UC500 for our phone system and recently upgraded to the 8.04 software pack with Cisco Unity Express (CUE) 8.0.2 voicemail. It looks a lot nicer and has some cool new features but I couldn't get my favourite prompts back. The nice English lady has a wonderful voice :-)

So I sat down this morning and kept at it until I got her back. Not that hard really... Here we go:

Ingredients:

Take one UC520-8.0.4.zip file
one language file. I used cue-vm-en_GB-langpack.uc500.8.0.2.prt1 but any language to your liking.
one ftp server
and a UC520.

Separate the UC520-8.0.4.zip file: Unzip it and there should be file named SCUE-UC500-8.0.2.zip. Unzip that one and look for a file named cue-vm-langpack.uc500.8.0.2.pkg. Take this file and the language file and put them on an ftp server (anonymous or not.) I'm Mac based so that's just there but everyone has a FTP server they can use on their OS.

I'm assuming defaults here so you may need to vary things.

Telnet to 10.1.10.1 port 2002 which makes a session to the CUE module. Login to that with your normal login or cisco/cisco if that doesn't work.

telnet 10.1.10.1 2002

Now we're into the good stuff...

software install add url ftp://ftpserver/cue-vm-langpack.uc500.8.0.2.pkg (optionally add username nick password password if your server requires it.)

It will come back with

WARNING:: This command will install the necessary software to
WARNING:: complete an add-on install. It is recommended that a backup be done
WARNING:: before installing software.

Would you like to continue?[confirm]

Say y to this. It will download the package and verify it. This can take a while.

It should show you this menu...

Running Script Processor for ui_install

Language add-ons found on the system (1):

Installed SKU Name (version)
------------------------------------------------------------------
* ENU CUE Voicemail US English (8.0.2)

Maximum 2 language add-ons allowed for this platform.
You may install 1 more language(s) from the following list:
Please select language(s) to install from the following list:

Language Installation Menu:

# Selected SKU Language Name (version)
----------------------------------------------------------------------
1 ITA CUE Voicemail Italian (8.0.2)
2 ESP CUE Voicemail European Spanish (8.0.2)
3 FRA CUE Voicemail European French (8.0.2)
4 ESO CUE Voicemail Latin American Spanish (8.0.2)
5 ESM CUE Voicemail Mexican Spanish (8.0.2)
6 ARA CUE Voicemail Arabic (8.0.2)
7 NLD CUE Voicemail Dutch (8.0.2)
8 SVE CUE Voicemail Swedish (8.0.2)
9 NOR CUE Voicemail Norwegian (8.0.2)
10 FRC CUE Voicemail Canadian French (8.0.2)
11 PTG CUE Voicemail Portuguese (8.0.2)
12 TUR CUE Voicemail Turkish (8.0.2)
13 HUN CUE Voicemail Hungarian (8.0.2)
14 ENG CUE Voicemail UK English (8.0.2)
15 DAN CUE Voicemail Danish (8.0.2)
16 PTB CUE Voicemail Brazilian Portuguese (8.0.2)
17 DEU CUE Voicemail German (8.0.2)
18 KOR CUE Voicemail Korean (8.0.2)
19 CHS CUE Voicemail Mandarin Chinese (8.0.2)
20 JPN CUE Voicemail Japanese (8.0.2)
21 RUS CUE Voicemail Russian (8.0.2)
----------------------------------------------------------------------

Available commands are:
# - enter the number for the language to select one
r # - remove the language for given #
i # - more information about the language for given #
x - Done with language selection

Enter Command:

type 14 (or whichever you want) and an asterisk should appear next to it.

14 * ENG CUE Voicemail UK English (8.0.2)

Then enter x to continue.

It will download the prompts file, install it and reload. This takes a while and a few times looks like it has failed but just wait. It's quite interesting to watch the module restart. It's basically a 2.4 kernel linux box.

Once it comes up with the host name or ip followed by hash you should be back up and running. One last command to switch the preferred language to UK. You can do this in the web interface but this is faster:

SYSTEM ONLINE
10.1.10.1# conf t
Enter configuration commands, one per line. End with CNTL/Z.
10.1.10.1(config)# system language preferred "en_GB"


Dial your voicemail or autoattendant and your should have that nice lady back.




Monday, 2 August 2010

Site to site VPN Cisco and Fortinet

This may save someone some time...

I was setting up a Cisco <-> Fortinet VPN using interface mode on the Fortinet, IPSEC protected GRE tunnel in Cisco's world.

I could not get it to fully come up. Phase 1 was fine but no luck with phase 2. The Cisco debug showed proposal did not match but they did! I promise :-)

Turns out my mistake was using AES and SHA. Well in fact after more trial, anything but 3DES and MD5 will fail. Even DES and MD5! So, there seems to be something screwy in the phase two exchange. I think this may be on the Cisco side as it does complain about proposals not matching even though the profile clearly does.

OK so I was using v3 mr7 of the Fortinet software and 12.3 of the Cisco IOS so it wasn't the newest but that is just crazy talk

Later: got it. The tunnel command protection profile doesn't seem to choose the transformation set like you'd expect. So it was falling back to the transform set in the last ipsec policy which was the VPN client users and this was 3DES/MD5.

Librewolf shows “some of LibreWolf’s security features may offer less protection on your current operating system”

I'm test driving Ubuntu after using Gentoo for years and found Librewolf gave me this warning banner. “some of LibreWolf’s security feat...