Re: [c-nsp] 3750 high cpu from icmp

2007-05-14 Thread Adrian Chadd
On Mon, May 14, 2007, Brian Turnbow wrote: Wanted to post an update on this in case anyone else ever has problems. The only way I found to resolve this issue was to move traffic onto different interfaces , removing the router on a stick routing. Did you stick the port into a SPAN group and

[c-nsp] Load balancing techniques

2007-05-14 Thread Sami Joseph
Hello, I'm confused with the different load balancing techniques in IOS, which is used for what and what are the disadvantages of each, any of them done in hardware, your private email would be appreciated. per-flow, per packet, per destination? Are they documented nicely any where? What is a

Re: [c-nsp] 3750 high cpu from icmp

2007-05-14 Thread Brian Turnbow
Yes and there were none. The icmp queue debugs also list source / destination macs and Ips where you can see that it would be the 3750 that needs to generate a redirect. Brian -Original Message- From: Adrian Chadd [mailto:[EMAIL PROTECTED] Sent: lunedì 14 maggio 2007 11.07 To: Brian

Re: [c-nsp] Problem getting right result with PBR

2007-05-14 Thread Rodney Dunn
You need to use an extended ACL. ie: access-list 144 permit ip 1.1.1.0 0.0.0.255 2.2.2.0 0.0.0.255 That says any traffic with a matching source of 1.1.1.0/24 going to a destination in the 2.2.2.0/24 range then send it to the PBR next hop configured. If you have overlapping route-map entries

Re: [c-nsp] Netflow stats lost

2007-05-14 Thread Nikolay Pavlov
On Wednesday, 2 May 2007 at 5:18:55 +0300, Nikolay Pavlov wrote: On Tuesday, 1 May 2007 at 15:25:47 +0100, Paolo Lucente wrote: Hi Nikolay, it reports you that the cache in which NetFlow data are stored is full. Depending on the architecture and the available options you can: *

[c-nsp] Access-list Question

2007-05-14 Thread Paul Stewart
Ok... I know I had a rough weekend but I don't get this.. Creating a new access-list for an interface on a 2621 router: access-list 100 permit ip host xxx.xxx.xxx.64 yyy.yyy.yyy.64 255.255.255.192 I want to permit access from one particular host to the yyy.yyy.yyy.64/26 subnet... When I do a

Re: [c-nsp] Access-list Question

2007-05-14 Thread Voll, Scott
Don't use subnet mask.. need to use Wildcard. IE access-list 100 permit ip host xxx.xxx.xxx.64 yyy.yyy.yyy.yyy 0.0.0.63 Scott -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Paul Stewart Sent: Monday, May 14, 2007 8:37 AM To:

Re: [c-nsp] Access-list Question

2007-05-14 Thread Peter Nyamukusa
-Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED] On Behalf Of Paul Stewart Sent: Monday, May 14, 2007 5:37 PM To: cisco-nsp@puck.nether.net Subject: [c-nsp] Access-list Question Ok... I know I had a rough weekend but I don't get this.. Creating

Re: [c-nsp] Access-list Question

2007-05-14 Thread Paul Stewart
Ah crap..;) Thanks everyone for the replies Note to self - don't work on access-lists after a long weekend...hehee... Paul -Original Message- From: Voll, Scott [mailto:[EMAIL PROTECTED] Sent: Monday, May 14, 2007 11:50 AM To: Paul Stewart; cisco-nsp@puck.nether.net Subject: RE:

Re: [c-nsp] Is this config even possible?

2007-05-14 Thread Tuc at T-B-O-H.NET
On 5/12/07, Tuc at T-B-O-H.NET [EMAIL PROTECTED] wrote: I want a floating default route. The order would be : Over the E1/0 tunnel If unavailable, then over E1/0 If unavailable, then over E0/0 tunnel If unavailable, then over E0/0 If unavailable.Cry... Given the huge mix

Re: [c-nsp] Port-Channel Problem

2007-05-14 Thread Dan Armstrong
As a followup to this problem I posted about earlier - I've observed some very strange behaviour that might explain why this GEC went stupid on me for no apparent reason: I setup a brand new GEC link, with 1 physical interface in the group. This was brand new, to a new empty switch, so of course

Re: [c-nsp] Port-Channel Problem

2007-05-14 Thread Dan Armstrong
As a followup to this problem I posted about earlier - I've observed some very strange behaviour that might explain why this GEC went stupid on me for no apparent reason: I setup a brand new GEC link, with 1 physical interface in the group. This was brand new, to a new empty switch, so of

[c-nsp] BGP and full traffic overload

2007-05-14 Thread Donato Dunguihual
Hi, I have a bgp peering over full traffic overload link, the bgp session up and down frequently. I think that is for traffic overload .I'm looking for a way to reserve a minimal bandwidth for bgp messages,. QOS or SPD are two options. Does anybody knows how to configure this for

[c-nsp] SNMP on 6513

2007-05-14 Thread Jonathan Charles
Installed a 6513 for a customer, they want to use SNMP to dynamically poll a few interfaces for traffic, how do I set this up (CatOS at layer-2) to poll just a few interfaces? There is no SNMP configuration on the box. I want to poll ports 1/1 -1/4 Jonathan

Re: [c-nsp] problem eith EIGRP and BGP

2007-05-14 Thread sanju shastri
HI Oli, Thx for replying , that really a good option . i was not awrae of the same. i would like to share my solution with you.. What i have done i have created a route map in which i have permitted the subnets for which i need to change the AD while using a prefix list. then i redistributed

Re: [c-nsp] problem eith EIGRP and BGP

2007-05-14 Thread sanju shastri
Hi Phil, Thx for replying. The backdoor route feature i have learned is useful when u want to make MPLS L3 VPN as primary and the alternate link as secondary.but i have a scenario opposite to it. in my case L3 VPN would be secondary. i think i can selectivity change the AD for specific

[c-nsp] GBIC in 3524XL

2007-05-14 Thread Joe Maimon
May 14 22:50:08: %GBIC_SECURITY-4-VN_DATA_CRC_ERROR: GBIC interface Gi0/1 has bad crc And the port is shutdown. Ideas? Cisco Internetwork Operating System Software IOS (tm) C3500XL Software (C3500XL-C3H2S-M), Version 12.0(5)WC17, RELEASE SOFTWARE (fc1) Copyright (c) 1986-2007 by cisco Systems,

Re: [c-nsp] CBWFQ ...

2007-05-14 Thread Mark Rogaski
An entity claiming to be Azher Amin ([EMAIL PROTECTED]) wrote: : : I tried cbwfq, but since it is applied only to output of serial, thus it : helped a bit and speed is improved. However is there anyway to reduce : the traffic on this serial interface from coming in from the provider side ? :

Re: [c-nsp] BGP and full traffic overload

2007-05-14 Thread Liviu Pislaru
hello, what type of L3 switches / routers do you use (paste here IOS too) ? what are the intervals that the BGP session goes up and down ? are you 100% sure the problem is generated because of the overloaded link ? paste here please the output of the command: sh ip bgp nei IP for both

Re: [c-nsp] Netflow stats lost

2007-05-14 Thread Nikolay Pavlov
On Monday, 14 May 2007 at 23:13:49 -0400, Andrew Mabe wrote: Please send me the hardware this is being collected on and the Sup engine you are using in this device. Hi Andrew. Here is my hardware: cscat4507-Core2-TOR#sh module Chassis Type : WS-C4507R Power consumed by backplane : 40 Watts