Re: [c-nsp] access lists on vlan interfaces

2007-04-11 Thread liviu . pislaru
hi, think of a router as a circle with you inside (center of that circle) :). inbound traffic is the traffic that come towards YOU through interface/SVI you want to configure ACL (SVI 100) an leaves the router through another interface. outbound traffic is the destined traffic for vlan 100

Re: [c-nsp] access lists on vlan interfaces

2007-04-11 Thread cisco
What about VACL? What is it for? What does VACL look like? Thanks hi, think of a router as a circle with you inside (center of that circle) :). inbound traffic is the traffic that come towards YOU through interface/SVI you want to configure ACL (SVI 100) an leaves the router through

Re: [c-nsp] 3750 tcam log

2007-04-11 Thread Brian Turnbow
Hello all, I am posting this as a follow up. It seems it was related to tcam resource exhaustion. I reduced the number of routes going into the 3750 and now see 3750E-Jenner#sh platform tcam log-results

Re: [c-nsp] access lists on vlan interfaces

2007-04-11 Thread liviu . pislaru
hello, VACL are a little bit different. Standard and extended IOS ACLs are configured on the INPUT and OUTPUT of router interfaces and, as such, are applied to routed packets. The use of IOS ACLs requires both a PFCx and a MSFCx on the Catalyst 6500 Series for example. VLAN ACLs (VACLs)

[c-nsp] Port rate-limiting on a 4503

2007-04-11 Thread Vincent
Hello guys, I need to limit a GigE port to 500 Mbps on a Cat4503 (with WS-X4424-GB-RJ45) which I am slightly unfamiliar with. It runs Cisco IOS Software, Catalyst 4000 L3 Switch Software (cat4000-I9S-M), Version 12.2(25)EWA4, RELEASE SOFTWARE (fc1). Can I rate-limit with a policy-map?

[c-nsp] SPA-10X1GE-V2 port channel

2007-04-11 Thread hjan
Hello, on my test GSR running IOS 12.0(32)SY2 there's a SIP 601 with a 10x1GE-V2. If I try to configure a port channel I obtain the following message: 12K-QOS-2(config)#int g0/1/8 12K-QOS-2(config-if)#channel-group 1 Error: not supported on GigabitEthernet0/1/8. On cisco's site i can't find any

Re: [c-nsp] [Fwd: Re: SPA-10X1GE (12000) Port-channel Feature]

2007-04-11 Thread hjan
gben ha scritto: Hello Gianluca, Oli give this info. Thanks George! I'll wait for 33S train :) Gianluca ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at

Re: [c-nsp] SPA-10X1GE-V2 port channel

2007-04-11 Thread Andy Furnell
On 11/04/07, hjan [EMAIL PROTECTED] wrote: Hello, on my test GSR running IOS 12.0(32)SY2 there's a SIP 601 with a 10x1GE-V2. If I try to configure a port channel I obtain the following message: 12K-QOS-2(config)#int g0/1/8 12K-QOS-2(config-if)#channel-group 1 Error: not supported on

Re: [c-nsp] 827 router as 'DMZ'

2007-04-11 Thread Dan
Jesse, I only have one external IP. So it looks like I'm stuck with having nat on the 827. What I really wanted to do is to have all four of my dsl lines terminated on the 2801 router with the hwic 4esw. I have explored that option and it will not work because of a limitation of the hwic.

Re: [c-nsp] Switch/router recommendations?

2007-04-11 Thread nachocheeze
On 4/10/07, Ed Ravin [EMAIL PROTECTED] wrote: Netgear support seems to be completely, completely hopeless. Preach it, brother, preach it. Even for basic ordinary hardware RMA's, it's an uphill battle. ___ cisco-nsp mailing list

[c-nsp] What version FOS

2007-04-11 Thread Voll, Scott
What version of FWSM matches up with the Pix / ASA 7.2 code train? Thanks Scott ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] Sub Interfaces on 3660

2007-04-11 Thread Richey
I am trying to setup Ethernet sub internfaces on a 3660. I can create the interface and ping it from the router but when I connect my laptop up to the port and try and ping the same IP I get nothing. I am sure I am missing more.The Google lottery turns up some stuff about bridge groups but

Re: [c-nsp] Sub Interfaces on 3660

2007-04-11 Thread Voll, Scott
Is your laptop tagging ISL? Unless a trunk is setup between the router and switch and your configured for ISL over that trunk and tag your port the Laptop is plugged into you won't be able to ping it. Scott -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf

Re: [c-nsp] Sub Interfaces on 3660

2007-04-11 Thread Richey
I have tried this with FA0/1 numbered and unnumbered. I get the same result for any sub interface, though I can ping 10.1.1.1 if that IP bound to FA0/1 -Richey -Original Message- From: Burton Windle [mailto:[EMAIL PROTECTED] Sent: Wednesday, April 11, 2007 3:52 PM To: Richey Subject:

Re: [c-nsp] Sub Interfaces on 3660

2007-04-11 Thread Richey
I am sure it won't do ISL, we use Tranzeo and Canopy. I have tried messing with dot1Q as well, but I get the same results. Does anyone have a suggestion as to how to accomplish what I am trying to do? Just some things laying around the building are some 3500XL and 4000 switches. This is one

[c-nsp] adsl config for 827 router

2007-04-11 Thread Dan
Hello, I'm having some trouble with connecting an 827 router to my isp. I have tried calling them but they don't seem to want to help. When i'm connected via the console the virtual-access1 interface just goes up and down and never connects. Building configuration... Current configuration :

[c-nsp] TDM solution on ONS15454

2007-04-11 Thread David Kim
Dear All, We have cisco two ONS15454-E(SDH) and we'd like to use them for add/drop TDM( T1,E1,DS3) between 4F and 28F. In this box , we just have control b'd and 10G cross-connect and 2 STM64 and 4port STM-4 and 12port Ethernet. Coould you give me any suggestion how can we provision TDM with these

Re: [c-nsp] TDM solution on ONS15454

2007-04-11 Thread Michael K. Smith - Adhost
Hello David: -Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED] On Behalf Of David Kim Sent: Wednesday, April 11, 2007 1:30 PM To: cisco-nsp@puck.nether.net Subject: [c-nsp] TDM solution on ONS15454 Dear All, We have cisco two ONS15454-E(SDH) and

Re: [c-nsp] adsl config for 827 router

2007-04-11 Thread Dan
Thanks, The debug commands helped me out. It was an authentication problem. I had to change this: ppp chap hostname nothere ppp chap password 7 nothere to this: ppp authentication chap callin Dan. Ian McDonald wrote: Dan wrote: Hello, I'm having some trouble with connecting an 827

Re: [c-nsp] Sub Interfaces on 3660

2007-04-11 Thread Oliver Boehmer \(oboehmer\)
Please use SVI (interface Vlan) and configure this port as trunk.. AFAIR, sub-interfaces are not supported on the 3560. See http://www.cisco.com/warp/public/473/howto_L3_intervlanrouting.html for an example.. oli Richey wrote on Wednesday, April 11, 2007 10:53 PM: I am sure it won't

Re: [c-nsp] What version FOS

2007-04-11 Thread Asbjorn Hojmark - Lists
What version of FWSM matches up with the Pix / ASA 7.2 code train? None of them completely matches it. 3.x comes close. -A ___ cisco-nsp mailing list [EMAIL PROTECTED] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at