Re: [c-nsp] Cisco IOS content filtering

2009-06-08 Thread Ivan Pepelnjak
Haven't tried the server-based configuration yet (it only works on ISRs), here's what you can do locally: http://wiki.nil.com/Local_Content_Filtering_in_Cisco_IOS Best regards Ivan http://www.ioshints.info/about http://blog.ioshints.info/ > -Original Message- > From: Jay Nakamura [mai

[c-nsp] ME3400 Transmit queues and architecture

2009-06-08 Thread ML
This is a multi part question please bear with me. Background synopsis: A large (on the order of millions) of output queue drops were causing noticeable breakup of multicast video streams. I learned that the default egress queue size is 160 starting in 12.2.46SE. I upgraded some lab switches,

Re: [c-nsp] Netflow analyzer suggestions

2009-06-08 Thread Frank Bulk - iName.com
It's not cheap, but Xangati may be a good match. Frank -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Andy Dills Sent: Tuesday, June 02, 2009 2:21 PM To: cisco-nsp@puck.nether.net Subject: [c-nsp] Netflow analyzer suggest

Re: [c-nsp] hung vty on SXH3a?

2009-06-08 Thread Frank Bulk - iName.com
Have you tried the SNMP approach? Frank -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Gert Doering Sent: Wednesday, June 03, 2009 2:16 AM To: cisco-nsp@puck.nether.net Subject: [c-nsp] hung vty on SXH3a? Hi, so far, we

[c-nsp] data corruption erros on the 7606 sup-720

2009-06-08 Thread Andy Saykao
Anybody come across data corruption erros on the 7606 sup-720 before? What's causing them? Are they bad or can we live with them Eg: router-1#sh data-corruption Data inconsistency records for: s72033_rp Software (s72033_rp-IPSERVICESK9_WAN-M), Version 12.2(18)SXF16, RELEASE SOFTWARE (fc2

Re: [c-nsp] ASR7401 and PA-FE-TX (ISL)

2009-06-08 Thread Matthew Huff
Duplex problems typically show runt, crc and collisions. The show interface line with: Full-duplex, Unknown Speed, 100BaseTX/FX might be the problem. How about : interface FastEthernet1/0 ip address *.*.*.* *.*.*.* load-interval 30 speed 100 duplex full end and check the config on the

Re: [c-nsp] "sh run" crashes router

2009-06-08 Thread Paul Stewart
What are some of the versions you are running? We have some 1710/1711 routers and many 2621 in the field and have never experienced that particular issue.. Agree with eninja though - always IOS bug 95% of the time anyways...;) Paul -Original Message- From: cisco-nsp-boun...@puck.nether

[c-nsp] ASR7401 and PA-FE-TX (ISL)

2009-06-08 Thread Elmar K. Bins
Re folks, my private 7401 felt a bit empty, and I bought an ISL for it (this should be the mgt interface, not much bandwidth). I wonder if it is broken, or if I am doing something wrong, or if this just cannot work because I'm too st00p1d and bought the wrong thing... The "show interface" output

Re: [c-nsp] "sh run" crashes router

2009-06-08 Thread e ninja
Segmentation Violations (SegV) exceptions are _always_ caused by a bug in Cisco IOS and could be triggered by either of the following: - Accessing an invalid memory address e.g. attempting to access the lowest 16KB of memory on powerPC platforms - Writing to a read-only memory region

[c-nsp] "sh run" crashes router

2009-06-08 Thread Richey
I am setting up Tacacs+ on all of our far end routers so I can run rancid. I have found several 1720s and a 2621 that crash when I log in to them and issue the "sh run" command. They reboot quickly and then I don't have a problem with the "sh run" command after the reload. If I look at the outp

[c-nsp] Cisco IOS content filtering

2009-06-08 Thread Jay Nakamura
I am trying out for the first time the IOS content filtering feature. Detail documentation seems little lacking. One thing I can't find references to is what exactly does each security categories and productivity categories includes. For example, UNBLEMISHED, what web sites does that include? An

Re: [c-nsp] 7500 performance

2009-06-08 Thread Pete Templin
Walter Keen wrote: Speaking of CPU performance, does anyone have any feedback on the Cisco 7500 series, I'm considering using it instead of multiple 7204's to aggregate/terminate atm (9 oc3, 1 ds3) and T1 (channelized ds3) traffic, I'm looking at the RSP8, with vip4-80's and the appropriate PA'

[c-nsp] MPLS

2009-06-08 Thread madunix
agree with you security concern and latency, the overhead to make the routing work in an MPLS network will slow the traffic down, this will creates latency concerns for the customer. >madunix wrote: >> I have 3x sites with DS8100 SAN Storage at each side, I will be >> replicating data from one si

Re: [c-nsp] 7600 router and Etherchannel across multiple line card

2009-06-08 Thread Pete Templin
Ibrahim Abo Zaid wrote: I am trying to establish L2 Etherchannel between 2 7609 routers , SUP720-MSFC3 , PFC is 3BXL and Line cards WS-X6148-GE and IOS is * 12.2(33)SRD* are there any concerns to establish this etherchannel between ports in different line cards ? I vaguely recall a major limi

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread A . L . M . Buxey
Hi, > What are the there legal ramifications to this? While I like to think that > "it's my network, I'll do what I want to measure its performance", I *think* > that sniffing voice traffic without consent is considered wiretapping. > IANAL, but it would behoove you to get a consent form from

Re: [c-nsp] BGP Advertising - Question re more specific block

2009-06-08 Thread Paul Stewart
Thank you We've messed already with a number of the options as you mentioned - this is really a last resort from our viewpoint. ;) The upstream (AS3320) does not have good reach when going against our other upstreams/peering and we are locked in a contract so trying to hit our minimum commit

Re: [c-nsp] 4510 reporting dozens of config changes throughout the day...

2009-06-08 Thread Scott McGrath
Port autonegotiation may be a cause you may prefer not logging port status changes which DO alter the running config Sent with Good (www.good.com) -Original Message- From: Steven Fischer [mailto:sfischer1...@gmail.com] Sent: Sunday, June 07, 2009 10:06 PM Central Standard Time To:

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Ge Moua
smokeping supports latency metrics out of the box; add plugins for jitter easy to install (debian based *nix) apt-get install smokeping Regards, Ge Moua | Email: moua0...@umn.edu Network Design Engineer University of Minnesota | Networking & Telecommunications Services Kasper Adel wrote:

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Eric Van Tol
> -Original Message- > From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- > boun...@puck.nether.net] On Behalf Of Bryan Campbell > Sent: Monday, June 08, 2009 8:46 AM > To: Kasper Adel > Cc: cisco-nsp@puck.nether.net > Subject: Re: [c-nsp] Opensource tool to measure Jitter for VoIP

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Bryan Campbell
You cannot measure VOIP (sip) jitter using ICMP tools. You will only isolate false positives when the ICMP is not doing well. Route or mirror the customers traffic trough a monitoring station. Run tcpdump or Wireshark to get a pcap file that contains traffic of interest. Wash the pcap file thr

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Pekka Savola
On Mon, 8 Jun 2009, mas...@nexlinx.net.pk wrote: MTR is a nice tool to check delay, loss and jitter stuff. If you wana keep track of historic logs, you can use nagios (or a tool like nagios). Note that MTR is measuring almost everything it does from the ICMPs generated by the routers. As such

Re: [c-nsp] 7500 performance (was: Re: IO 7200 GE Improve Performance and help with the CPU Load?)

2009-06-08 Thread Rodney Dunn
As long as you want just basic IP with very little features and you make sure it's all dCEF switched you will probably be ok. Watch the VIP cpu loads though if you pack the oc3's and etherchannels. It's all software, although distributed, switching. Rodney On Fri, Jun 05, 2009 at 02:35:01PM -07

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Ray Burkholder
> > Thanks guys, the customer is looking for a third party vendor for this > test > because we already used IP SLA and it looks good but the Media Gateways > vendor has its own measurement tool inside and they mentioned that > their > values are bad (8 msec jittter). Obtain nProbe from NTOP. It

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Kasper Adel
Thanks guys, the customer is looking for a third party vendor for this test because we already used IP SLA and it looks good but the Media Gateways vendor has its own measurement tool inside and they mentioned that their values are bad (8 msec jittter). Cheers, Kas On Mon, Jun 8, 2009 at 2:31 PM,

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread masood
MTR is a nice tool to check delay, loss and jitter stuff. If you wana keep track of historic logs, you can use nagios (or a tool like nagios). You can write your own scripts (using tcl, bash, perl or whatever u like) to monitor delay, jitter and loss and can feed the output to nagios for historic

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Peter Rathlev
(Hist Ctrl+Enter a little fast before, sorry. :-)) On Mon, 2009-06-08 at 13:13 +0300, Kasper Adel wrote: > I'm looking for a way to measure Jitter for a VoIP network and i cant > get my hands on IXIA or any fancy tool like that so i'm asking if > anyone used any open source tool specifically for t

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Peter Rathlev
On Mon, 2009-06-08 at 13:13 +0300, Kasper Adel wrote: > I'm looking for a way to measure Jitter for a VoIP network and i cant > get my hands on IXIA or any fancy tool like that so i'm asking if > anyone used any open source tool specifically for the matter. > > IPerf is an option but i've never us

Re: [c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Ian MacKinnon
Is using IP SLA functionality on your routers an option? Then graph the data with Cacti or mrtg. Or smoke ping, http://oss.oetiker.ch/smokeping/ > -Original Message- > From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- > boun...@puck.nether.net] On Behalf Of Kasper Adel > Sent: 08

[c-nsp] Opensource tool to measure Jitter for VoIP

2009-06-08 Thread Kasper Adel
Hello, I'm looking for a way to measure Jitter for a VoIP network and i cant get my hands on IXIA or any fancy tool like that so i'm asking if anyone used any open source tool specifically for the matter. IPerf is an option but i've never used it, so can you guys point me if i can be used and wha

Re: [c-nsp] 4510 reporting dozens of config changes throughout the day...

2009-06-08 Thread Steven Fischer
doing a compare, I found a single config element, "ip ssh logging events" that was present on the device generating the messages, but not on the 4510 that isn't. Removed it, and will see what that does. On Mon, Jun 8, 2009 at 5:36 AM, Tom Lanyon wrote: > On 08/06/2009, at 6:53 PM, David Freedma

Re: [c-nsp] 4510 reporting dozens of config changes throughout the day...

2009-06-08 Thread Tom Lanyon
On 08/06/2009, at 6:53 PM, David Freedman wrote: Silly question, but are you running RANCID and do these changes appear to be to port/vlan membership? It is quite a common occurrence to have flapping ports be shown as members and then suddenly not members of a vlan when rancid executes the "

Re: [c-nsp] ACL creation and editing tool suggestions?

2009-06-08 Thread David Freedman
A newcomer to the 12.4(T) train is "ACL Object Groups" http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_object_group_acl.html I can see this making everybody's lives useful when it hits real production trains. For the time being, I'm emulating this functionality with my own h

Re: [c-nsp] 4510 reporting dozens of config changes throughout the day...

2009-06-08 Thread David Freedman
Silly question, but are you running RANCID and do these changes appear to be to port/vlan membership? It is quite a common occurrence to have flapping ports be shown as members and then suddenly not members of a vlan when rancid executes the "show vlan" command. Dave. Steven Fischer wrote: > I