Re: [c-nsp] Maximum-routes Routes on 7600 with SUP2/PFC2

2007-06-05 Thread Mohacsi Janos
On Mon, 4 Jun 2007, Zahid Hassan wrote: Dear All, I am carrying full feed Internet (219K) plus VPNv4 routes (1K) on an OSR-7609 with SUP-2/PFC2. I seems to be getting intermittent packets drops and loss of connectivity from CPEs terminating on this OSR. I wondering if has anything

[c-nsp] NSE-150 issues

2007-06-05 Thread Brad Gould
Hi, Anyone else running 7304 NSE-150's? Having issues? Please contact me off list and we can swap notes. Thanks Brad -- Brad Gould, Network Engineer Internode PO Box 284, Rundle Mall 5000 Level 3, 132 Grenfell Street, Adelaide 5000 P: 08 8228 2999 F: 08 8235 6999 [EMAIL PROTECTED];

Re: [c-nsp] Low activity systems lose net connectivity

2007-06-05 Thread Phil Mayers
Tauren Mills wrote: Phil, Thanks for the suggestion. However, changing the arp timeout to 300 doesn't seem to have helped. Hmm. Re-reading your email, it doesn't sound like that was the problem anyway. Can you supply more detail on the physical topo? Does the router hang off the switch

Re: [c-nsp] no hits on egress flow-sampler map 7600/WS-SUP720-3BXL

2007-06-05 Thread Phil Mayers
On Tue, 2007-06-05 at 11:35 +0200, Koen wrote: Hello list, I have the following issue with a 7600/WS-SUP720-3BXL (12.2(33)SRA3). I only see hits on the ingress flow-sampler map and no hits on the egress map? I have configured netflow like this: My understanding was that egress netflow

[c-nsp] Sup720 PFC3 logging counters

2007-06-05 Thread Mark Tohill
Hi, Is there anyway of getting reliable ACL counters from a Sup720 with PFC3 (non-B/BXL) ? Is it true that 'show access-lists ACLNAME' only shows software (MSFC) handled traffic while 'show tcam interface vlanXXX acl in ip' shows the hardware counters. Thanks, Mark Mark Tohill UTV

Re: [c-nsp] Sup720 PFC3 logging counters

2007-06-05 Thread Ian MacKinnon
I think what you want is optimised acl logging http://www.cisco.com/en/US/products/hw/switches/ps708/products_configuration_guide_chapter09186a00801609f6.html#wp1035523 Mark Tohill wrote: Hi, Is there anyway of getting reliable ACL counters from a Sup720 with PFC3 (non-B/BXL) ? Is it

[c-nsp] Hot Swaping 7206 Power Supplies

2007-06-05 Thread Richey
I've always been told that the card slots in the non VXR 7206s were not hot swappable. I've got a non VXR 7206 with 1 AC and 1 DC power supply. The DC needs to come out and an AC stuck back in it's place because it's new home does not have DC power available. Can you hot swap the power supply

Re: [c-nsp] Hot Swaping 7206 Power Supplies

2007-06-05 Thread Adrian Chadd
On Tue, Jun 05, 2007, Richey wrote: I've always been told that the card slots in the non VXR 7206s were not hot swappable. I've got a non VXR 7206 with 1 AC and 1 DC power supply. The DC needs to come out and an AC stuck back in it's place because it's new home does not have DC power

Re: [c-nsp] OSPF Redistribution

2007-06-05 Thread Adrian Chadd
On Tue, Jun 05, 2007, Shakeel Ahmad wrote: Guys, In a scenario, we want to advertise the connected network (Loopback interface) into Two OSPF process. It works fine but while advertising we need to keep our loopback Classful as connected redistribution doesn't allow classless. .. redist

[c-nsp] OSPF Redistribution

2007-06-05 Thread Shakeel Ahmad
Guys, In a scenario, we want to advertise the connected network (Loopback interface) into Two OSPF process. It works fine but while advertising we need to keep our loopback Classful as connected redistribution doesn't allow classless. Is there any idea, how can i redistribute a /32 instead of

Re: [c-nsp] NSE-150 issues

2007-06-05 Thread Rodney Dunn
I've worked a couple of issues with the NSE-150 if you want to elaborate on what problem(s) you are seeing. I don't consider myself an expert on it yet though. Rodney On Tue, Jun 05, 2007 at 06:08:00PM +0930, Brad Gould wrote: Hi, Anyone else running 7304 NSE-150's? Having issues?

Re: [c-nsp] Hot Swaping 7206 Power Supplies

2007-06-05 Thread Jon Lewis
On Tue, 5 Jun 2007, Richey wrote: I've always been told that the card slots in the non VXR 7206s were not hot swappable. I've got a non VXR 7206 with 1 AC and 1 DC power supply. The DC needs to come out and an AC stuck back in it's place because it's new home does not have DC power

Re: [c-nsp] Trouble with reverse telnet on NPE-G2/12.2(31)SB5

2007-06-05 Thread Falk Stern
Hi all, On 05.06.2007, at 12:51, Falk Stern wrote: Hi all, I have trouble configuring reverse telnet on a 7200/NPE-G2 running 12.2(31)SB5. #sh run | i aaa: aaa new-model aaa authentication login default local aaa authorization exec default local aaa authorization reverse-access default

Re: [c-nsp] wireless lan controller and remote ap

2007-06-05 Thread Frank Bulk
Besides on-site rogues, there's also the issue of 'accidental' associations to neighboring APs. Frank -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Seth Mattinen Sent: Monday, June 04, 2007 7:44 PM To: cisco-nsp@puck.nether.net Subject: Re: [c-nsp]

Re: [c-nsp] Maximum-routes Routes on 7600 with SUP2/PFC2

2007-06-05 Thread Phil Bedard
I know on our SUP2s running SXF8 that command doesn't produce any output, not sure if it worked in previous versions... Phil On Jun 5, 2007, at 3:35 AM, Mohacsi Janos wrote: On Mon, 4 Jun 2007, Zahid Hassan wrote: Dear All, I am carrying full feed Internet (219K) plus VPNv4 routes

Re: [c-nsp] OSPF Redistribution

2007-06-05 Thread Shakeel Ahmad
i know its a wiered question: redist connected , i could have used it as a network statement in both OSPF process of which i am not sure (not able to achieve too) : say i have a loopback 0 with ip: 1.1.1.1/32 so putting network statements in OSPF process 1 2 (in different areas) will not let me

Re: [c-nsp] Maximum-routes Routes on 7600 with SUP2/PFC2

2007-06-05 Thread Julio Arruda
Mohacsi Janos wrote: On Mon, 4 Jun 2007, Zahid Hassan wrote: ... I am carrying full feed Internet (219K) plus VPNv4 routes (1K) on an OSR-7609 with SUP-2/PFC2. I seems to be getting intermittent packets drops and loss of connectivity from CPEs terminating on this OSR. I wondering if has

Re: [c-nsp] Hot Swaping 7206 Power Supplies

2007-06-05 Thread Dave Weis
Jon Lewis wrote: On Tue, 5 Jun 2007, Richey wrote: I've always been told that the card slots in the non VXR 7206s were not hot swappable. I've got a non VXR 7206 with 1 AC and 1 DC power supply. The DC needs to come out and an AC stuck back in it's place because it's new home does not have

Re: [c-nsp] wireless lan controller and remote ap

2007-06-05 Thread Voll, Scott
If I had to be perfectly honest..I hate making changes to 24 AP 50 would really be a pain. If this is a School district. why do they have to have local access. Is each school Firewalled? Someone did recommend multiple controllers for redundancy which is a good Idea. But if the

Re: [c-nsp] wireless lan controller and remote ap

2007-06-05 Thread Dan
The schools are not firewalled between each other. They all have a local file server. Maybe I'm getting confused... Here's an example. Notebook A connects to an access point in the school, is able to roam from AP to AP within the building, the user logs into the local server does there work

Re: [c-nsp] wireless lan controller and remote ap

2007-06-05 Thread Voll, Scott
I was told the same thing.. but Just tell TAC you only have 8 per site =) -Original Message- From: Pickett, McLean (OCTO) [mailto:[EMAIL PROTECTED] Sent: Tuesday, June 05, 2007 8:48 AM To: Voll, Scott; Dan; [EMAIL PROTECTED]; cisco-nsp@puck.nether.net Subject: RE: [c-nsp]

Re: [c-nsp] wireless lan controller and remote ap

2007-06-05 Thread Voll, Scott
Your right I don't want to traverse the WAN twice either but how much traffic is really going across twice. Is it enough to worry about? Scott -Original Message- From: Dan [mailto:[EMAIL PROTECTED] Sent: Tuesday, June 05, 2007 8:44 AM To: Voll, Scott Cc: [EMAIL PROTECTED];

Re: [c-nsp] Hot Swaping 7206 Power Supplies

2007-06-05 Thread Richey
It's been running about a year on AC power. It's always had 1 DC and 1 AC in the router, it's never had both connected at the same time. When it was moved we were going to setup our own DC power plant but it never got done. The UPS that feeds the router is on borrowed time so I need to get it

Re: [c-nsp] wireless lan controller and remote ap

2007-06-05 Thread Pickett, McLean (OCTO)
The 8 AP H-REAP limitation has been lifted. You can have as many H-REAP AP's on a controller as you like. The limitation was marketing driven, and as far as I know, it was never enforced. There are some limitations with H-REAP relating to RRM and location services. Check out the deployment

Re: [c-nsp] 10Gig Ethernet commands

2007-06-05 Thread Jared Mauch
'show int cap' perhaps? - jared On Tue, Jun 05, 2007 at 08:01:04PM +0300, Hank Nussbacher wrote: I lost it and it was posted here a few days ago - what is the command to see the type of interface used on a 10GigE connection? Thanks, Hank

Re: [c-nsp] wireless lan controller and remote ap

2007-06-05 Thread Frank Bulk
It's the north-south/east-west discussion. With H-REAP you can manage them centrally but switch the traffic locally. As McLean noted, with the low number of APs at each location, RRM and LBS won't really be possible. If go without a distributed solution then you'll want to analyze your current

Re: [c-nsp] wireless lan controller and remote ap

2007-06-05 Thread Voll, Scott
Same problem I ran into... if each site is Firewalled then tunneling traffic back to the local network becomes a problem for local access. The only problem with out Firewalled Sites is that you traverse the WAN twice. This has nothing to do with security as much as it does traffic flow. Scott

[c-nsp] Migration from vlan 1 for core.

2007-06-05 Thread Jeff Crowe
Hi all, I am planning on migrating a legacy network that utilizes VLAN 1 on Cisco devices for it's core network to another VLAN ID (100 in this case). Is there any gotcha's that I should be aware of? All the switches and routers have IP addresses that reside in vlan 1, so this may cause me some

Re: [c-nsp] 10Gig Ethernet commands

2007-06-05 Thread Church, Charles
Show int status? It lists the transceiver on the GE cards. Not sure about 10GE though... Chuck -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Hank Nussbacher Sent: Tuesday, June 05, 2007 3:40 PM To: Jared Mauch Cc: cisco-nsp@puck.nether.net Subject:

[c-nsp] AS5350 Question

2007-06-05 Thread Paul Stewart
Hi folks... We're looking at deploying some 5350 boxes for dial-up Internet purposes. I'm pretty sure they can support what we need but my question is specific to T1 inbound... We know they support PRI (23B+1D) but can you run 24 channels at 56K instead of 23 channels at 64K? In our telco area

Re: [c-nsp] AS5350 Question

2007-06-05 Thread Jon Lewis
On Tue, 5 Jun 2007, Paul Stewart wrote: We know they support PRI (23B+1D) but can you run 24 channels at 56K instead of 23 channels at 64K? In our telco area we know this as DEA versus PRI and the older Livingston Portmasters etc support this just fine - presuming you can do this with Cisco

Re: [c-nsp] 10Gig Ethernet commands

2007-06-05 Thread Justin M. Streiner
On Tue, 5 Jun 2007, Hank Nussbacher wrote: On Tue, 5 Jun 2007, Jared Mauch wrote: 'show int cap' perhaps? Nope. That one I know. It's output was 1 line per interface and showed near the end of the line the type of GBIC identified. -Hank show interface status jms

Re: [c-nsp] 10Gig Ethernet commands

2007-06-05 Thread Jay Ford
On Tue, 5 Jun 2007, Hank Nussbacher wrote: Nope. That one I know. It's output was 1 line per interface and showed near the end of the line the type of GBIC identified. -Hank You're probably thinking of show interface status [module slot].

Re: [c-nsp] AS5350 Question

2007-06-05 Thread Paul Stewart
Thanks ;) Just purely for dial-up in a remote area I finally found reference on Cisco's site after sending out this message and it shows 48,56,64K options on each channel...;) All the best, Paul -Original Message- From: Jon Lewis [mailto:[EMAIL PROTECTED] Sent: Tuesday, June

Re: [c-nsp] AS5350 Question

2007-06-05 Thread Tim Jackson
DEA? as in 24 CAS EM Trunks? It should support it, I know that there are issues handling delivery of the calling-party ANI over this in EM Wink configs on some other IOS platforms... Probably some TCL work arounds to handle *ANI*DNIS* instead of just DNIS, but for dial-up you really wouldn't need

Re: [c-nsp] 10Gig Ethernet commands

2007-06-05 Thread Justin M. Streiner
On Tue, 5 Jun 2007, Church, Charles wrote: Show int status? It lists the transceiver on the GE cards. Not sure about 10GE though... Yes, it works in 10G interfaces too. ... Te9/1 gw1.ocl Ten1/1 connectedroutedfull10G 10Gbase-LX4 Te9/2 gw2.omc Ten7/1 connected

Re: [c-nsp] Best Routing Protocol for Scenario

2007-06-05 Thread Rodney Dunn
How are you identifying voice traffic? I'll probably have to think of a hack to make what you are asking for to work. ea On Thu, May 31, 2007 at 01:11:38PM -0400, Paul Stewart wrote: Hi folks... A while back (month or so) I posed a few questions about Policy Based Routing - thinking

Re: [c-nsp] AS5350 Question

2007-06-05 Thread Tim Jackson
You'd configure it like this: controller t1 X/X/X mode cas framing esf linecode b8zs ds0-group 0 timeslots 1-24 type em-wink-start ! That'd create voice-port X/X/X:0 for you... 12.4(11)T supports this: em-delay-dial E M Delay Dial em-fgd E M Type II FGD

Re: [c-nsp] Cisco 3550 appears dead, flashing lights on post

2007-06-05 Thread Dan
Weak power supply? Do you have one that you can switch it out with? Dan. Jonathan Charles wrote: I have a Cisco 3550-24... on post all lights flash amber very quickly and stay that way... nothing on the console... Any ideas on fault? Jonathan

Re: [c-nsp] WS-C3560G-48TS-S per port ACLs?

2007-06-05 Thread Tom Zingale \(tomz\)
Yes the SMI software feature set supports ACL's on a per port basis -Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED] On Behalf Of TCIS List Acct Sent: Tuesday, June 05, 2007 11:46 AM To: cisco-nsp@puck.nether.net Subject: [c-nsp] WS-C3560G-48TS-S per

Re: [c-nsp] 10Gig Ethernet commands

2007-06-05 Thread Michael Balasko
Like so? 6513-720-01 (enable) sho mod 12 Mod Slot Ports Module-Type Model Sub Status --- - - --- --- 12 12 4 1BaseGX Ethernet WS-X6704-10GE yes ok Michael Balasko CCSP,MCSE,MCNE,SCP

Re: [c-nsp] Cisco 3550 appears dead, flashing lights on post

2007-06-05 Thread Jonathan Charles
No. This worked fine for 4 years and died this morning... I woke up and it was all blinky... Jonathan On 6/5/07, Dan [EMAIL PROTECTED] wrote: Weak power supply? Do you have one that you can switch it out with? Dan. Jonathan Charles wrote: I have a Cisco 3550-24... on post all lights

Re: [c-nsp] AS5350 Question

2007-06-05 Thread Scott Granados
Just a parallel question relating to this thread. Won't this type of T1 service yield bad performance? Is this a case where switch lines are muxed on to a channel bank type thing and then demuxed again in theory adding all sorts of nice artifacts? As opposed to a multipath type thing that

Re: [c-nsp] 6500 with IOS Firewall - Any experiences?

2007-06-05 Thread Gustavo Novais
Thanks Brian, By any chance do you know if in case he'd choose the IOS firewall, there would be anything like SDM to manage it? I didn't find anything like it. Anyway, you've convinced me. I'll suggest him to continue using its current pix525 cluster, although I still think he'd be better

[c-nsp] fwsm ipv6

2007-06-05 Thread matthew zeier
Anyone have experience with a working fwsm v6 setup? I have a couple v4 hosts behind the fwsm that I want to v6 enable. Can I just enable v6 on the inside outside interfaces and it'll just work (with the right access-list)? ___ cisco-nsp mailing

Re: [c-nsp] 6500 with IOS Firewall - Any experiences?

2007-06-05 Thread Kevin Graham
On 6/5/07, Gustavo Novais [EMAIL PROTECTED] wrote: I'll suggest him to continue using its current pix525 cluster, If they want to give the IOS Firewall a shot though for what a dual-720 is going to cost, putting in a pair of 2821 or 2851 SEC-K9 bundle's with SDM shouldn't be too painful. Do

Re: [c-nsp] 6500 with IOS Firewall - Any experiences?

2007-06-05 Thread Gustavo Novais
I've only raised this thread exactly because it is painful to me, that someone even considers only using sup720 for L2 Switching. If they have money to spend, they should spend it wisely, but... unfortunately, given what has been said here, IOS FW on sup720 is not a good choice, either because

Re: [c-nsp] WS-C3560G-48TS-S per port ACLs?

2007-06-05 Thread TCIS List Acct
Tom Zingale (tomz) wrote: Yes the SMI software feature set supports ACL's on a per port basis So I can apply an ACL on a Layer2 port, that allows/denies TCP/IP traffic? I know I can do this on some Foundry switches, but have never tried on a 35xx when the port is not a L3 port.. --Mike

Re: [c-nsp] WS-C3560G-48TS-S per port ACLs?

2007-06-05 Thread Tom Zingale \(tomz\)
Yes on a vlan or port you can allow/deny tcp/ip traffic. See the docs http://www.cisco.com/en/US/partner/products/hw/switches/ps5528/products_ configuration_guide_chapter09186a008081da63.html -Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED] On Behalf

Re: [c-nsp] 10Gig Ethernet commands

2007-06-05 Thread Hank Nussbacher
On Tue, 5 Jun 2007, Jay Ford wrote: Ba-bing! Thanks, -Hank On Tue, 5 Jun 2007, Hank Nussbacher wrote: Nope. That one I know. It's output was 1 line per interface and showed near the end of the line the type of GBIC identified. -Hank You're probably thinking of show interface status

[c-nsp] 6to4 relay setup?

2007-06-05 Thread matthew zeier
Having problems figuring out what I need to configure on a Cisco router to make it a 6to4 relay. Any pointers? I plan on anycasting 192.88.99.0/24 from this router. thanks. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] 6to4 relay setup?

2007-06-05 Thread David Prall
6to4 Auto Tunnels http://www.cisco.com/en/US/products/sw/iosswrel/ps5187/products_configuratio n_guide_chapter09186a00801d6604.html#wp1048589 -- http://dcp.dcptech.com -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of matthew zeier Sent: Tuesday,

Re: [c-nsp] 6to4 relay setup?

2007-06-05 Thread matthew zeier
thanks - dunno why I couldn't find that on my own. If I anycast 192.88.99.0/24, am I right that the tunnel source must be 192.88.99.1? Or is it some other globally routable interface? David Prall wrote: 6to4 Auto Tunnels

Re: [c-nsp] Multilink PPP (MLPPP) Asymmetrical Throughput Problem NxT1

2007-06-05 Thread Sean Shepard
Thank you for the reply on this. We did exactly what you mention here (trying to isolate channels) and found the performance metrics didn't change very much except that there seemed to be little impairment with just a single T-1. We do not believe that variance in latency exists to the point

Re: [c-nsp] WS-C3560G-48TS-S per port ACLs?

2007-06-05 Thread TCIS List Acct
Tom Zingale (tomz) wrote: Yes on a vlan or port you can allow/deny tcp/ip traffic. See the docs http://www.cisco.com/en/US/partner/products/hw/switches/ps5528/products_ configuration_guide_chapter09186a008081da63.html Thanks, that link answers most of my questions. Performance wise, it

Re: [c-nsp] 6to4 relay setup?

2007-06-05 Thread matthew zeier
David Prall wrote: In a 6to4 auto tunnel, you use 2002:192 88:99 1::1/16 as your address. Where the IPv4 address is converted to Hex. I'm not sure you should anycast the address, since this address is typically used as your BGP next hop. Might load balance it with sticky, only need an IPv4

Re: [c-nsp] 6to4 relay setup?

2007-06-05 Thread virendra rode //
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 matthew zeier wrote: thanks - dunno why I couldn't find that on my own. If I anycast 192.88.99.0/24, am I right that the tunnel source must be 192.88.99.1? Or is it some other globally routable interface? - - If my memory