Friday, August 12, 2011

I Rule for F5 LTM

I- Rule is a power full  code which modify the http header and redirect the http request to any way you want.
One of the common use is to transfer a http request to https based connection for security or www.x.com to https://x.com. I am attaching the sample code for http transfers.

rule 1

rule redirect_HTTPS

when HTTP_REQUEST {
  if { [TCP::local_port] == 80 }{
    HTTP::redirect https://[getfield [HTTP::host] ":" 1][string tolower [HTTP::uri]]
  }
}

rule 2

when HTTP_REQUEST {
            if { [HTTP::host] contains "www.x.com"} {
            HTTP::redirect https://x.com[HTTP::uri] }
}



Monday, August 8, 2011

Friday, August 5, 2011

Bria SIP phone (Phone Power) configuration for IPAD2

Steps for configuring the BRIA -Counterpath sip phone IPAD2 version  1.0 are given below. This steps are for phone power customers only
Go to User account settings
select
user name: your phone number
password: provided by the voip provider
domain:208.64.8.6:5060
proxy:208.64.8.6
once you entered the credentials, reboot the voip phone adapter and later restart the IPAD2. After an hour try to register the phone. It will show the message as REGISTERED. Once the sip phone is registered, you are ready to go.

Tuesday, May 31, 2011

Install SSL Certificate in F5 Load Balancer


The installation procedure to upload a SSL certificate from Verisign into F5 load balancer is given below

STEP I: Export Certificate and Private Key from the first IIS 6.0 server


Create an MMC Snap-in for Managing Certificates:



1. Start > run > MMC

2. Go into the Console Tab > File > Add/Remove Snap-in

3. Click on Add > Click Certificates > Add

4. Choose Computer Account

5. Choose Local Computer

6. Close the Add Standalone Snap-in window.

7. Click OK at the Add/Remove Snap-in window.



Export the Certificate with Private Key attached:



8. Expand Certificates in the Console Tree

9. Look for a folder called Personal > Certificates

10. Select the Certificate that you wish to back up.

11. Right-click on the file and choose > ALL TASKS > Export

12. The Certificate Export Wizard will start up. Click Next

13. Choose Yes, export the private key

14. Select Include all certificates in the certification path and click Next

15. Set a password to protect the export of the Private key file with the Certificate. Click Next

16. Choose to save the file to a set location.



Type the file name in the 'File Name' box, and click Save

Click Next

The file is given a *.pfx file-name extension
Login into F5 and change the directory to var/tmp
start the ftp prompt
Bin
get .pfx file
exit ftp
convert the .pfx file into .pem file by
openssl pkcs12 -in sap.ltg.info.pfx -out sap.ltg.info.pem –nodes
export the .pem file into your workstation.
open the pem file using wordpad
copy the key to notepad and save all ALL files .key
copy cert to not a notepad and save ALL file .crt
Load the key into F5 and then CRT file. Once the certificate is loaded, the certificate details will be displayed under SSL certificates tab.

Wednesday, August 18, 2010

Voice VLAN Configuration

•Before you enable voice VLAN, we recommend that you enable QoS on the switch by entering the mls qos global configuration command and configure the port trust state to trust by entering the mls qos trust cos interface configuration command.

• The Port Fast feature is automatically enabled when voice VLAN is configured. When you disable voice VLAN, the Port Fast feature is not automatically disabled.

• When you enable port security on an interface that is also configured with a voice VLAN, you must set the maximum allowed secure addresses on the port to at least two.

• If any type of port security is enabled on the access VLAN, dynamic port security is automatically enabled on the voice VLAN.

• You cannot configure static secure or sticky secure MAC addresses on a voice VLAN.
Configuring a Port to Connect to a Cisco 7960 IP Phone

VOICE VLAN CONFIGURATION:

Because a Cisco 7960 IP Phone also supports a connection to a PC or other device, a port connecting the switch to a Cisco 7960 IP Phone can carry mixed traffic.

You can configure the port to carry voice traffic in one of these ways:

• Configuring Ports to Carry Voice Traffic in 802.1Q Frames

• Configuring Ports to Carry Voice Traffic in 802.1P Priority-Tagged Frames
You can configure the IP phone to carry data traffic in one of these ways:

• Overriding the CoS Priority of Incoming Data Frames

• Configuring the IP Phone to Trust the CoS Priority of Incoming Data Frames
switchport voice vlan dot1p :

Instruct the switch port to use IEEE 802.1p priority tagging for voice traffic and to use the default native VLAN (VLAN 0) to carry all traffic. By default, the Cisco IP phone forwards the voice traffic with an IEEE 802.1p priority of 5.
switchport voice vlan vlan-id

Instruct the Cisco IP Phone to forward all voice traffic through the specified VLAN. By default, the Cisco IP Phone forwards the voice traffic with an 802.1Q priority of 5. Valid VLAN IDs are from 1 to 4094.
switchport priority extend cos value :

Set the IP phone access port to override the priority received from the PC or the attached device.
The CoS value is a number from 0 to 7. Seven is the highest priority. The default is 0.

switchport priority extend trust
Set the IP phone access port to trust the priority received from the PC or the attached device.

Wednesday, March 17, 2010

Installation of Cisco Expansion module 7916

Installation of Cisco Expansion module 7916

When you add an expansion module new Cisco IP phone, the module acts weird. Sometimes there is no label displayed.
First reset the phone by unplugging the Ethernet cable and plug back in. Press # during the power up time. Press 123456789*0# when the button lights are moving one to another. Wait until the phone downgraded to factory default. Then the phone will be upgraded to latest firmware from the call manager. Once the phone is upgraded to latest firmware, the firmware will be displayed under active ID in call manager under device properties. Then plug the module, add the module name under device, module section and save the config. Then apply the config. The expansion module will start to work.

Wednesday, February 17, 2010

Missed calls log missing

It happens to some Cisco IP phones that missed calls log become empty. It is a weird situation and it may confuse the end users. You may see this behavior in ccm 7.x version. The problem won't go away even if you reset the firmware to default version and then upgrade to the latest version. The best solution is to remove the phone device and directory number from the data base. make a search that directory number does not exist in call manager. Then create the phone and assign the directory number to the phone.

Turn off pop notifications in chrome browser from major news outlets

 On Chrome browser, go to settings select privacy and security select site settings select Java Script Select Don't allow sites to use J...

Turn off pop notifications in chrome browser from major news outlets