Re: [c-nsp] Prove it's not the network!

2008-05-15 Thread Justin Shore
Nathan wrote: Proceed by elimination. If there is someone else in the office (I suppose the T1 is not just for one person) whose Outlook is *not* slow, and especially if someone else can be extended to everybody else then the problem is not the network. Outlook can have severe

Re: [c-nsp] vlan tagging question

2008-05-15 Thread Gert Doering
Hi, On Wed, May 14, 2008 at 07:43:53AM -0500, Chad Whitten wrote: I have a non-cisco access device connecting to a cisco 3750 via gigE. The 3750 interface is set for 802.1q trunking with two vlans - 100 and 201. Vlan 201 is the native vlan on the cisco interface. Should the access device be

Re: [c-nsp] Prove it's not the network!

2008-05-15 Thread Whisper
Justin, I have alwasy been under the impression that Network Engineers primary role was going around constantly proving that the Network is not the problem. :) Your rant, I suspect, is more or less repeated on daily basis by Network Engineers all around the world. On Thu, May 15, 2008 at 3:41

[c-nsp] analyze BGP traffic with SNMP

2008-05-15 Thread Alexandre Snoeck
Hi all, Is it possible to analyze where traffic is going with SNMP on a BGP router? If so how? I checked most mib files with BGP info in it but couldn't find anything. I have to check where the most traffic is going on the backbone bgp router. I have checked for Sflow and Netflow to do this

Re: [c-nsp] analyze BGP traffic with SNMP

2008-05-15 Thread Roland Dobbins
On May 15, 2008, at 3:41 PM, Alexandre Snoeck wrote: not a system that has to run most of the time to have decent information. This type of system is far more desirable from an operational standpoint, as it provides insight into behavior over time. Snapshots of this type of

[c-nsp] Multiple AS numbers

2008-05-15 Thread Gary Roberton
Hello All I run an AS number but also want to run a second AS to advertise specific networks to an external BGP peer which I will do with a tunnel. However, can I run a second AS or do I specifically need to set up a stand alone router running its own instance of BGP just to send updates.

Re: [c-nsp] Multiple AS numbers

2008-05-15 Thread Paul Cosgrove
Hi Gary, I'm not completely clear on what your requirements are, but you may want to have a look at the 'local-as' bgp neighbor option. Will let your router behave like another ASN on that single peering. http://www.cisco.com/en/US/docs/ios/iproute/command/reference/irp_bgp3.html#wp1014448

Re: [c-nsp] Multiple AS numbers

2008-05-15 Thread Ionut PIRVA
Should you take a look at the local-as feature: http://www.cisco.com/warp/public/459/39.html On Thu, May 15, 2008 at 12:52 PM, Gary Roberton [EMAIL PROTECTED] wrote: Hello All I run an AS number but also want to run a second AS to advertise specific networks to an external BGP peer which I

Re: [c-nsp] analyze BGP traffic with SNMP

2008-05-15 Thread Alexandre Snoeck
Thanks for the advice If you're determined to use SNMP and snapshots, you may wish to take a look at the NetFlow MIB, which lets you get a snapshot of the NetFlow table. Any idea if there is an equivalent in SFlow? I have been looking around the Sflow Mib but didn't find any usefull

Re: [c-nsp] Prove it's not the network!

2008-05-15 Thread Jeff Fitzwater
I sure hope Justin lets us know what the problem really was, after all this.. Jeff Fitzwater OIT Network Systems Princeton University On May 15, 2008, at 3:56 AM, Whisper wrote: Justin, I have alwasy been under the impression that Network Engineers primary role was going around

[c-nsp] 3550-48 - 3560-48TS-E migration?

2008-05-15 Thread Jon Lewis
Having just gone past the end of software maintenance date for the 3550, and with the need to start at least looking at supporting IPv6 on our customer aggregation switches in the not so distant future, I suppose it's time to seriously consider the 3560-48TS as a replacement / upgrade path for

Re: [c-nsp] CVR-X2-SFP

2008-05-15 Thread Justin Shore
Simon Lockhart wrote: On Wed May 14, 2008 at 01:56:20PM +0200, [EMAIL PROTECTED] wrote: Who can tell me whether the Twingig CVR-X2-SFP are supported in 6500 module WS-X6708-10G-3C ? No - they depend on an additional connector at the back of the slot which is only in the 3750E etc boxes.

Re: [c-nsp] 3550-48 - 3560-48TS-E migration?

2008-05-15 Thread Ian MacKinnon
Jon Lewis wrote: Having just gone past the end of software maintenance date for the 3550, and with the need to start at least looking at supporting IPv6 on our customer aggregation switches in the not so distant future, I suppose it's time to seriously consider the 3560-48TS as a replacement /

Re: [c-nsp] 3550-48 - 3560-48TS-E migration?

2008-05-15 Thread Arie Vayner (avayner)
Jon, You might want to take a look at Catalyst 4948, which might present a better feature parity/richness and might be a better match for your requirements. The normal 4948 would do IPv6 in software, so it really depends on how wide you expect your deployment to be, but you can take a look at the

Re: [c-nsp] 3550-48 - 3560-48TS-E migration?

2008-05-15 Thread Masood Ahmad Shah
The thing I'm missing is, it does not support Policy-Based Routing (PBR) when forwarding IPv6 traffic:( The software supports IPv4 PBR only when the dual-ipv4-and-ipv6 routing template is configured. Here is the link for more on dual-ipv4-ipv6:

Re: [c-nsp] Switch processing delay

2008-05-15 Thread Everton da Silva Marques
On Tue, May 13, 2008 at 07:09:31PM -0400, Uddin, Tahir wrote: Does anyone know the switching delay for a 1500 byte packet (or any size packet) through a 6509E with a Sup720 10G supervisor. Packet coming in one 10gig port and out another 10Gig. The following paper:

[c-nsp] Weird Issue with 3750-PoE Switches...

2008-05-15 Thread Jeff Cartier
We recently swapped out some non-PoE Cisco switches with Cisco 3750 48port PoE switches and have noticed the following issue. When users reboot their PC they have troubles establishing their folder connections in Windows...the following error is seen in the event log. Windows cannot obtain

Re: [c-nsp] Weird Issue with 3750-PoE Switches...

2008-05-15 Thread Jeff Fitzwater
If you have Spanning tree enabled on the CISCO (which is default ) then you need to add spanning-tree portfast to all access ports. This will speed up initial boot of machine instead of going through the LISTENING LEARNING FORWARDING states. Well this sounds like your problem. Jeff

Re: [c-nsp] Weird Issue with 3750-PoE Switches...

2008-05-15 Thread Jeff Cartier
Ports are already configured for port-fast. Like I said, it seems that after disabling PoE on the port everything works fine. -Original Message- From: Jeff Fitzwater [mailto:[EMAIL PROTECTED] Sent: Thursday, May 15, 2008 2:29 PM To: Jeff Cartier Cc: cisco-nsp@puck.nether.net Subject:

Re: [c-nsp] Weird Issue with 3750-PoE Switches...

2008-05-15 Thread Jeff Cartier
No Phones are connected to the switchports which are having the issues. It is a straight connection to the PC. From: Fredrik Jacobsson [mailto:[EMAIL PROTECTED] Sent: Thursday, May 15, 2008 2:37 PM To: Jeff Cartier Cc: Jeff Fitzwater;

[c-nsp] Cisco PfR

2008-05-15 Thread Shaun R.
I'm looking to deploy PfR in my network. Right now the network is simple for the most part. two 7206VXR-NPE-G2's each with a upstream connected, they are also linked to eachother. Then both borders connect to my core/access layer which is a stack of 3750G's. OSPF is run between core and

[c-nsp] Cat 3560

2008-05-15 Thread Jason Berenson
Greetings, This is probably an obvious question but I seem to be overlooking something. I have a Catalyst 3560 running c3560-advipservicesk9-mz.122-25.SED1.bin. I just changed out the SFP on gi0/2 to be a fiber SFP instead of copper. Here's what I see when it's not plugged in, is this

Re: [c-nsp] Cat 3560

2008-05-15 Thread Tassos Chatzithomaoglou
You're probably using a fake SFP. What does show errdisable recovery show? You can try a combination of the following, but i'm not sure if they'll help you. service unsupported-transceiver no errdisable detect cause gbic-invalid Check the ios version too, below:

Re: [c-nsp] Cat 3560

2008-05-15 Thread Jason Berenson
There doesn't seem to be a service unsupported-transciever command: router(config)#service uns? % Unrecognized command I tried a shut/no shut, on one of the routers it seemed to work but not on the other. It still doesn't show the media type though. Here's some output from the logs. I have

Re: [c-nsp] Weird Issue with 3750-PoE Switches...

2008-05-15 Thread Jeff Fitzwater
Take a look at this doc, some version of CISCO had POE PINOUT incorrect. http://pinouts.ru/Net/poe_pinout.shtml Jeff Fitzwater OIT Network Systems Princeton University On May 15, 2008, at 2:34 PM, Jeff Cartier wrote: No Phones are connected to the switchports which are having the issues.

Re: [c-nsp] Cat 3560

2008-05-15 Thread Jason Berenson
Now I get media type unknown on one router and media type not supported on the other. Justin Shore wrote: It's a hidden command. Copy and paste it in anyway. Justin Jason Berenson wrote: There doesn't seem to be a service unsupported-transciever command: router(config)#service uns? %

Re: [c-nsp] Cat 3560

2008-05-15 Thread Justin Shore
I'd check the IOS version against the model of SFP to make sure that it's supported (though I imagine it will be). I'd agree with the other guys in saying that it's likely counterfeit. Do you get it from a reputable vendor? Justin Jason Berenson wrote: Now I get media type unknown on one

[c-nsp] iBGP not propogating route to 0/8

2008-05-15 Thread Justin Shore
I just noticed that my RTBH setup is not propagating one of my BOGON routes. Specifically it's not propagating 0.0.0.0/255.0.0.0 (0/8). The static is set up just like all my other RTBH routes complete with the appropriate tag: ip route 0.0.0.0 255.0.0.0 Null0 tag 66 name BOGON ip route

Re: [c-nsp] Cat 3560

2008-05-15 Thread mack
-- Message: 6 Date: Thu, 15 May 2008 16:21:36 -0500 From: Justin Shore [EMAIL PROTECTED] Subject: Re: [c-nsp] Cat 3560 To: Jason Berenson [EMAIL PROTECTED] Cc: cisco-nsp@puck.nether.net cisco-nsp@puck.nether.net Message-ID: [EMAIL PROTECTED] Content-Type: text/plain;

Re: [c-nsp] Cat 3560

2008-05-15 Thread Jason Berenson
I just pulled the SFP and it turns out it's an HP. The vendor is shipping me two new ones. Can anyone give me a snippit of config with SVI being used? mack wrote: -- Message: 6 Date: Thu, 15 May 2008 16:21:36 -0500 From: Justin Shore [EMAIL PROTECTED]

[c-nsp] Set a L3 routed interface on a 6500 + SUP2 to 'promiscuous' mode?

2008-05-15 Thread Rafael Rodriguez
Hello all, Here is the issue I am facing: We have a server that need to send lots of data to IP addresses not on its local subnet. Server will be directly connected to router interface via ethernet. The server SHOULD set ALL packets with a dst MAC Address of the router (its default gateway) so

Re: [c-nsp] Set a L3 routed interface on a 6500 + SUP2 to 'promiscuous'mode?

2008-05-15 Thread David Coulson
What mac is it sending too? where does it get the arp entry from? -- David Coulson [EMAIL PROTECTED] Sent from my BlackBerry -Original Message- From: Rafael Rodriguez [EMAIL PROTECTED] Date: Thu, 15 May 2008 19:34:25 To:cisco-nsp@puck.nether.net Subject: [c-nsp] Set a L3 routed

Re: [c-nsp] Set a L3 routed interface on a 6500 + SUP2 to 'promiscuous'mode?

2008-05-15 Thread David Prall
VACL Capture on OSM/SPA/LAN interfaces or even SPAN on LAN interfaces should work fine. What info does the server receive when it arps for a remote address. I'll assume that both ends have a /30 configured, and you aren't attempting to use Proxy-arp. -- http://dcp.dcptech.com -Original

[c-nsp] Cisco ACE Web Application Firewall

2008-05-15 Thread carl
Has anyone had a chance to get a hold of one of these devices, if so what are your thoughts? We currently use Foundry ServerIrons in a DSR setup for our load balancing method and was wondering if the ACE would work in that scenario. ___ cisco-nsp

Re: [c-nsp] Cat 3560

2008-05-15 Thread Daniel Hooper
carnilya-sw#sh run interface Vlan 2 Building configuration... Current configuration : 109 bytes ! interface Vlan2 description MANAGEMENT SVI ip address 10.10.10.105 255.255.255.0 no ip route-cache end -Original Message- From: [EMAIL PROTECTED] [mailto:cisco-nsp- [EMAIL PROTECTED]

Re: [c-nsp] Weird Issue with 3750-PoE Switches...

2008-05-15 Thread Brett Looney
I had a similar issue many moons ago with Macs plugged into 3750 switches - they had intermittent issues reaching some network resources. The NIC driver was having a cow about the trunk negotiate packets coming from the switch. Try doing a switchport nonegotiate on the port and see if that fixes

[c-nsp] CME 7970 question

2008-05-15 Thread Jeremy Stinson
Hello, We are having an issue with our 7970 phones and the redial button and I have not been able to find anything on Google. When the user hits the redial button it take up to 20 seconds for the last number dial to appear. Does anyone have any insight into this? Thanks, Jeremy

Re: [c-nsp] Set a L3 routed interface on a 6500 + SUP2 to 'promiscuous'mode?

2008-05-15 Thread Rafael Rodriguez
Thanks for the replies. Post below is a bit long but easy to read, please let me know if you guys have any advice. What mac is it sending too? where does it get the arp entry from? Unfortunately this server does not attempt to 'arp' for the remote address, proxy-arp would be the solution in

Re: [c-nsp] Set a L3 routed interface on a 6500 + SUP2 to 'promiscuous'mode?

2008-05-15 Thread David Prall
The only time I've seen products like this, they had to be on a layer 2 subnet. Typically a hub was placed between the Internet Router or Firewall Internal Interface, and the switch. Everything just magically happened there. The software appears to think they are on the same L2 subnet. It is

Re: [c-nsp] Cat 3560

2008-05-15 Thread Stig Johansen
Jason wrote: I just pulled the SFP and it turns out it's an HP. The vendor is shipping me two new ones. Can anyone give me a snippit of config with SVI being used? Try this: ! ip routing ! vlan 100 name whatever ! interface GigabitEthernet0/2 description TLS 1G primary switchport

Re: [c-nsp] Set a L3 routed interface on a 6500 + SUP2 to'promiscuous'mode?

2008-05-15 Thread Stig Johansen
Sorry, but this sounds like a won't work. Your server is depending on sending spoofed packets. If this was on a local VLAN, you could simply put if2 in the same VLAN as the sniffer-if and let it work from there. I see you mentioned the traffic is fed by RSPAN, so I guess the traffic isn't local,

Re: [c-nsp] Fake Cisco Equipment News Articles - very interesting

2008-05-15 Thread Ted Mittelstaedt
-Original Message- From: Peter Rathlev [mailto:[EMAIL PROTECTED] Sent: Wednesday, May 14, 2008 1:35 AM To: Ted Mittelstaedt Cc: cisco-nsp Subject: RE: [c-nsp] Fake Cisco Equipment News Articles - very interesting On Tue, 2008-05-13 at 22:43 -0700, Ted Mittelstaedt wrote: