Re: [c-nsp] IOS: catch 22 when enabling new bgp neighbors

2014-06-22 Thread Vinny Abello
Ditto. I didn't know you could do this either. That's why I love mailing lists. They're a massive pool of collective experience. :) Brocade has an interesting way of handling this as well. I had always wondered why (until now) Cisco didn't have an equivalent. On Brocade you can do:

Re: [c-nsp] ICMP echo reply packages received over IPsec tunnel don't reach IOS ping utility

2013-05-21 Thread Vinny Abello
(type 3 code 10) messages to Cisco router. regards, Martin 2013/5/21, Vinny Abello vi...@abellohome.net: On , c...@marenda.net wrote: Hi, I have an IPsec tunnel between Cisco 1841 and ZyXEL routers over public Internet. I do not have access to ZyXEL router. According

Re: [c-nsp] ICMP echo reply packages received over IPsec tunnel don't reach IOS ping utility

2013-05-20 Thread Vinny Abello
On , c...@marenda.net wrote: Hi, I have an IPsec tunnel between Cisco 1841 and ZyXEL routers over public Internet. I do not have access to ZyXEL router. According to show crypto session IPsec tunnel is up and active. This IPsec tunnel connects 192.168.157.0/24 and 192.168.136.0/24 networks

Re: [c-nsp] ASR-9001 IOS-XR, no image

2012-06-29 Thread Vinny Abello
On 6/25/2012 11:34 AM, Jared Mauch wrote: On Jun 25, 2012, at 11:23 AM, Vinny Abello wrote: I recently just received a few ASR-9001 routers and was surprised to find they did not come with the required IOS-XR 4.2.1 image at all and are effectively paperweights. I had observed

[c-nsp] ASR-9001 IOS-XR, no image

2012-06-25 Thread Vinny Abello
Hello, I recently just received a few ASR-9001 routers and was surprised to find they did not come with the required IOS-XR 4.2.1 image at all and are effectively paperweights. As far as I've determined, it seems like there might have been an error in the ordering process which omitted this.

Re: [c-nsp] ASA VPN - DMZ

2012-06-08 Thread Vinny Abello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Alternately, you can also change the default behavior of the ASA by issuing: no sysopt connection permit-vpn This will cause all traffic from VPN tunnels to be subject to the access-lists on the ingress interface. Note that Cisco recommends using

Re: [c-nsp] 6500/SUP2/MSFC2 Port based EoMPLS capability

2012-06-08 Thread Vinny Abello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 6/8/2012 8:58 AM, Gert Doering wrote: Hi, On Fri, Jun 08, 2012 at 08:40:16AM -0400, Jason Lixfeld wrote: I'm going through feature navigator looking for compatibility and it says that port based EoMPLS is available in the 12.2SXF train, but

Re: [c-nsp] Cisco 2811 performance issue - dual(new) isp

2011-12-22 Thread Vinny Abello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 What kind of performance do you see if you temporarily remove the ip access-group and ip inspect commands from the interface? (Sorry if you already did this. I might have missed some posts). What's configured on the interface connected to the

Re: [c-nsp] Cisco 2811 performance issue - dual(new) isp

2011-12-21 Thread Vinny Abello
To add to Chuck's questions: Can you post your FastEthernet0/1 configuration? What exactly is this interface plugged into? What IOS version are you running? I think you said this works fine with a computer connected directly to the provider, but just out of curiosity what other device is

Re: [c-nsp] Cisco 2811 performance issue - dual(new) isp

2011-12-19 Thread Vinny Abello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mike, I don't believe Verizon FiOS uses compression. Neither would the Windows machine plugged directly into the hand off, so it would not compress or decompress data in communicating with Verizon's hardware. Compression of an entire link is CPU

Re: [c-nsp] IOS XR BGP

2011-11-25 Thread Vinny Abello
- From: Vinny Abello [mailto:vi...@abellohome.net] Sent: 24 November 2011 19:17 To: Oliver Boehmer (oboehmer) Cc: Nick Ryce; Eric Morin; cisco-nsp@puck.nether.net Subject: Re: [c-nsp] IOS XR BGP On 11/24/2011 11:04 AM, Oliver Boehmer (oboehmer) wrote: I require the specific to be from IGP

Re: [c-nsp] IOS XR BGP

2011-11-24 Thread Vinny Abello
On 11/24/2011 11:04 AM, Oliver Boehmer (oboehmer) wrote: I require the specific to be from IGP. I have a funny feeling all I need to do is redistribute OSPF into BGP then use the aggregate-address as-set summary-only yes, and it looks you can limit the OSPF redistribution to a few (a

Re: [c-nsp] 1841 dumps to rommon only on power failure

2011-07-22 Thread Vinny Abello
Of Vinny Abello Sent: lundi 18 juillet 2011 5:58 To: cisco-nsp@puck.nether.net Subject: [c-nsp] 1841 dumps to rommon only on power failure Got an interesting problem I thought someone else might have experienced. I have an 1841 in my home that I've used for a while. Recently

Re: [c-nsp] 1841 dumps to rommon only on power failure

2011-07-22 Thread Vinny Abello
...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Vinny Abello Sent: lundi 18 juillet 2011 5:58 To: cisco-nsp@puck.nether.net mailto:cisco-nsp@puck.nether.net Subject: [c-nsp] 1841 dumps to rommon only on power failure Got

Re: [c-nsp] 1841 dumps to rommon only on power failure

2011-07-22 Thread Vinny Abello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 7/19/2011 11:31 AM, Marty Adkins wrote: On 7/17/2011 11:58:11 PM Vinny Abello vi...@abellohome.net wrote: Got an interesting problem I thought someone else might have experienced. I have an 1841 in my home that I've used for a while

[c-nsp] 1841 dumps to rommon only on power failure

2011-07-17 Thread Vinny Abello
Got an interesting problem I thought someone else might have experienced. I have an 1841 in my home that I've used for a while. Recently (probably within the past year) I noticed that when it looses power, the next time it powers on it doesn't boot properly and just gets dumped to rommon. This

Re: [c-nsp] cisco optics for longhaul fiber

2011-07-02 Thread Vinny Abello
I've done something extremely similar with the Transition Networks TN-GLC-ZX-SM-15 which is rated for ~150km and had excellent success. This was going over about a 115km span, but due to expected loss at each junction and the optical properties of the fiber given to me, the ZX-SM-15 was much

Re: [c-nsp] uRPF lacking on ME3600X?

2011-06-16 Thread Vinny Abello
I consider that the same platform. ;) -Vinny On Jun 16, 2011, at 2:25 AM, LM asturlui...@gmail.com wrote: Is the same in 7600 El 15/06/11 18:46, vinny_abe...@dell.com escribió: Oh yuck, really?? Is this a limitation of the platform? -Vinny -Original Message- From:

Re: [c-nsp] need help about network

2008-12-04 Thread Vinny Abello
Check for something like TCP Offload on the machine where you are seeing this problem. This can often interfere with things and result in incorrect TCP checksums in packet captures. Outside of that, do you have an MTU smaller than 1500 bytes anywhere you know of in the network? It could be

Re: [c-nsp] Cisco VPN Client Causes Mac OS X Crash

2008-12-03 Thread Vinny Abello
Works great for me on OS X 10.5.5... also on a MBP. No stability problems at all. Now if I could get the VPN client to add the domain suffix to my search order each time I connect, it would be perfect. Has anyone seen that work on OS X? -Vinny -Original Message- From: [EMAIL

Re: [c-nsp] Cisco VPN Client Causes Mac OS X Crash

2008-12-03 Thread Vinny Abello
From: Mark Tinka [EMAIL PROTECTED] Sent: Wednesday, December 03, 2008 9:36 PM To: Vinny Abello Cc: Ryan Wilkins; cisco-nsp@puck.nether.net Subject: Re: [c-nsp] Cisco VPN Client Causes Mac OS X Crash On Thursday 04 December 2008 07:06:13 Vinny Abello wrote: Works great for me on OS X 10.5.5... also

Re: [c-nsp] security

2008-12-03 Thread Vinny Abello
I've also seen directed broadcast needed for remote management of some thin client platforms across subnets. -Vinny -Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED] On Behalf Of Chris Gauthier Sent: Wednesday, December 03, 2008 9:55 AM To:

Re: [c-nsp] Cisco 877 DSL Sync issue

2008-10-11 Thread Vinny Abello
The 877 is for ADSL. Last I knew, I thought Covad's DSLAMs only did SDSL. What Netopia model does it work with? I can confirm if the 877 is incompatible if you let me know what does work with it. -Vinny -Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED]

Re: [c-nsp] NAT/ACL options in a PIX

2008-08-27 Thread Vinny Abello
-Original Message- From: John Ramz [mailto:[EMAIL PROTECTED] Sent: Wednesday, August 27, 2008 8:20 AM To: Vinny Abello; cisco-nsp@puck.nether.net Subject: RE: [c-nsp] NAT/ACL options in a PIX Vinny, #thanks for the reply. So, host 5.6.7.8 wants to access that internal #host

Re: [c-nsp] NAT/ACL options in a PIX

2008-08-26 Thread Vinny Abello
Correct, you are doing NAT as a straight 1 to 1 translation for traffic. Using PAT, you can specify either TCP or UDP traffic and the outside and inside port numbers. This is still accomplished with the static statement. You'll still need the access-list entry as well unless you have another

Re: [c-nsp] ADSL weirdness

2008-08-24 Thread Vinny Abello
-Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED] On Behalf Of Mateusz Blaszczyk Sent: Sunday, August 24, 2008 4:26 PM To: Daniel D Jones Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] ADSL weirdness Daniel, interface Dialer1 mtu 1492

Re: [c-nsp] Monitoring concurrent connections on a ASA

2008-08-15 Thread Vinny Abello
There probably is an OID (check the ASA MIB from Cisco), but the ASA includes ASDM which will show you concurrent connections (as well as memory, cpu, and bandwidth load) in realtime. You can also just do show conn count while logged in. -Vinny -Original Message- From: [EMAIL

Re: [c-nsp] IPv6 Migration with ISIS (was Route Reflector Design)

2008-07-04 Thread Vinny Abello
-Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED] On Behalf Of Mikael Abrahamsson Sent: Friday, July 04, 2008 1:42 AM To: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] IPv6 Migration with ISIS (was Route Reflector Design) On Thu, 3 Jul 2008, Vinny

Re: [c-nsp] Telnet FROM a PIX Appliance?

2008-07-04 Thread Vinny Abello
-Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED] On Behalf Of Peder @ NetworkOblivion Sent: Friday, July 04, 2008 8:28 AM To: cisco-nsp@puck.nether.net Cisco-NSP Mailing List Subject: Re: [c-nsp] Telnet FROM a PIX Appliance? What!? The original PIX

Re: [c-nsp] Telnet FROM a PIX Appliance?

2008-07-04 Thread Vinny Abello
-Original Message- From: Sam Stickland [mailto:[EMAIL PROTECTED] Sent: Friday, July 04, 2008 10:58 AM To: Vinny Abello Cc: Peder @ NetworkOblivion; cisco-nsp@puck.nether.net Cisco-NSP Mailing List Subject: Re: [c-nsp] Telnet FROM a PIX Appliance? Vinny Abello wrote: Also, minus

Re: [c-nsp] Telnet FROM a PIX Appliance?

2008-07-04 Thread Vinny Abello
-Original Message- From: Sam Stickland [mailto:[EMAIL PROTECTED] Sent: Friday, July 04, 2008 10:58 AM To: Vinny Abello Cc: Peder @ NetworkOblivion; cisco-nsp@puck.nether.net Cisco-NSP Mailing List Subject: Re: [c-nsp] Telnet FROM a PIX Appliance? Vinny Abello wrote: Also, minus

Re: [c-nsp] ip icmp rate-limit unreachables DF broken in IOS 12.2(28)SB6

2007-11-27 Thread Vinny Abello
I hate replying to my own post, but I just discovered that the default value of 500 milliseconds on unreachables DF also breaks PMTU discovery. The only way it works is if it's completely turned off with no ip icmp rate-limit unreachables DF. Vinny Abello wrote: Hello Cisco fans, I've been

Re: [c-nsp] Dialup problems on a AS5300

2007-11-26 Thread Vinny Abello
... but whatever. You may also want to pose the same question in cisco-nas list. I don't know how active it is, but someone there may have better answers than I. Good luck! -- Vinny Abello Network Engineer [EMAIL PROTECTED] (973)940-6100 (NOC) PGP Key Fingerprint: 3BC5 9A48 FC78 03D3 82E0 E935 5325 FBCB

Re: [c-nsp] Access list question

2007-10-30 Thread Vinny Abello
On Oct 30, 2007, at 10:17 PM, Jefri Abdullah wrote: Dear List, I've two routers running ibgp as routing protocol, some how, one of these router should advertise network 0.0.0.0 (via default-information network statement) to another ebgp peer. But the ibgp peer should deny to receive this

Re: [c-nsp] BFD support on ISR

2007-10-01 Thread Vinny Abello
of this. The Foundry only supports version 1 and until recent code, Cisco only supports version 0. -- Vinny Abello Network Engineer [EMAIL PROTECTED] (973)940-6100 (NOC) PGP Key Fingerprint: 3BC5 9A48 FC78 03D3 82E0 E935 5325 FBCB 0100 977A Tellurian Networks - The Ultimate Internet Connection http

Re: [c-nsp] BFD support on ISR

2007-10-01 Thread Vinny Abello
Yep, we plan on looking at this release. :) Robert Crowe wrote: 6500 support version 1 in SXH. Rob -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Vinny Abello Sent: Monday, October 01, 2007 12:35 PM To: Robert Boyle Cc: cisco-nsp

Re: [c-nsp] PIX 515E PPTP VPN Routing?

2007-09-24 Thread Vinny Abello
/ ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ -- Vinny Abello Network Engineer Server Management [EMAIL PROTECTED] (973)300-9211 x

Re: [c-nsp] Recommended 7206 12.2(x)SB for MPLS?

2007-09-19 Thread Vinny Abello
Mark Tinka wrote: On Wednesday 19 September 2007 02:06, Vinny Abello wrote: I know we're up to SB9 last I checked, but I haven't tested that yet. On SB6, when I started configuring mpls ip and mpls traffic-eng tunnels on interfaces with other routers and the LDP adjacency comes up, I

[c-nsp] Recommended 7206 12.2(x)SB for MPLS?

2007-09-18 Thread Vinny Abello
. Thanks! -- Vinny Abello Network Engineer Server Management [EMAIL PROTECTED] (973)300-9211 x 125 (973)940-6125 (Direct) PGP Key Fingerprint: 3BC5 9A48 FC78 03D3 82E0 E935 5325 FBCB 0100 977A Tellurian Networks - The Ultimate Internet Connection http://www.tellurian.com (888)TELLURIAN Courage

Re: [c-nsp] IS-IS Emergency

2007-06-22 Thread Vinny Abello
to ISIS migration... maybe minus the ip fast-convergence. Our (Cisco) platforms are generally Cat6500 12.2(18)SXF and 7206 12.2(28)SB builds. -- Vinny Abello Network Engineer [EMAIL PROTECTED] (973)940-6100 PGP Key Fingerprint: 3BC5 9A48 FC78 03D3 82E0 E935 5325 FBCB 0100 977A Tellurian