Re: [c-nsp] anaysis networrk

2008-11-06 Thread Francois ROPERT
More features and above all more SECURITY. Wireshark dissectors are tested against fuzzing by Mister G. Combs and should be by dissectors authors by running tools/fuzz-test.sh before putting public dissectors on bugs.wireshark.org. My advice here is to always use the last version for limiting

Re: [c-nsp] 12.2SRC or 12.4T for 7200VXR NPE400

2008-11-06 Thread Antal GERGELY
fyi about 4B ASN :) Gert Doering wrote: Hi, On Thu, Oct 30, 2008 at 11:59:13AM -0600, Forrest W Christian wrote: The must-have features in my mind are: BGP4 w/Long ASN Complain to your Cisco sales representative. And do it loudly. To my knowledge, there is *still* no IOS version

[c-nsp] Cisco 881 3G Router Experiences

2008-11-06 Thread Anton . Schweitzer
Hi, is anybody here using a Cisco 881 3G Router with IPSEC and can share his experiences/config with me ? Cheers Anton Anton Schweitzer Senior Specialist BS Projekt Service Customer Design o2 (Germany) GmbH Co.OHG Georg Brauchle-Ring 23-25, D-80992 München Tel +49(0)89-2442-5794

Re: [c-nsp] show ip cef resources

2008-11-06 Thread David Freedman
What kind of box is this? GSR? what kind of cards? Dave. Drew Weaver wrote: This is kind of a trivial question but does anyone know at or around what numbers the 'show ip cef resources' is no longer G (Green?) It has been creeping up over the last year or so and I'm just

Re: [c-nsp] ip cef optimize neighbor resolution

2008-11-06 Thread Lincoln Dale
hi Ross, Ross Vandegrift wrote: Hi everyone, Has anyone running SXH on a SUP720-3B(-XL) series 6500 tried ip cef optimize neighbor resolution? Cisco's docs seem to offer the usual tautologous explanation, and as a bonus, include a circular reference: LOL, classic. Both indicate that it

Re: [c-nsp] problems filtering multicast]

2008-11-06 Thread William
Thanks James this worked perfectly! Cheers. W 2008/11/5 James Slepicka [EMAIL PROTECTED]: use the ip multicast boundary command: http://www.cisco.com/en/US/docs/ios/12_2/ipmulti/command/reference/1rfmult1.html#wp1058494 e.g. ip access-l standard mcast_boundary_vl999 permit 224.9.9.9 int

Re: [c-nsp] 10G MMF on 12k ?

2008-11-06 Thread vince anton
There is no need to use attenuators for 10GBASE-LR even if you run it over a 1 meter cable. Also, I would be very surprised if cisco didn't support SR in that module, where did you get that information? The datasheet doesnt say anything about supporting SR in that SPA. looks like 10km with

[c-nsp] 10G MMF on 12k ?

2008-11-06 Thread vince anton
Hi Im looking at enabling 10G on the 12k platform and it looks like the SPA-1x10GE-L-V2 is the one to go for inside a SIP601. But it seems like the SPA only supports single mode SFPs. Im finding hard to believe that i need to use single mode fibre to connect the SPA to a switch in the same rack,

Re: [c-nsp] 10G MMF on 12k ?

2008-11-06 Thread Mikael Abrahamsson
On Thu, 6 Nov 2008, vince anton wrote: Im looking at enabling 10G on the 12k platform and it looks like the SPA-1x10GE-L-V2 is the one to go for inside a SIP601. But it seems like the SPA only supports single mode SFPs. The SPA-1x10GE-L-V2 supports XFP, not SFP. Im finding hard to believe

[c-nsp] BGP Question

2008-11-06 Thread Stephens, Jamie A
Is there a command to allow received routes from the same AS #? E-MAIL CONFIDENTIALITY NOTICE: The contents of this e-mail message and any attachments are intended solely for the addressee(s) and may contain confidential and/or legally privileged information. If you are not the

[c-nsp] PIX 6.x Site2Site with dynamic IP?

2008-11-06 Thread William
Hi Chaps, I use to have a VPN tunnel running between two sites using Cisco Pix 6.x, the B end now has a dynamic IP address every time the router reloads which means the tunnel has gone down and to get it back up we have to reconfigure a ISAKMP key and change our config here on the A end. Is

Re: [c-nsp] 10G MMF on 12k ?

2008-11-06 Thread Mikael Abrahamsson
On Thu, 6 Nov 2008, vince anton wrote: The datasheet doesnt say anything about supporting SR in that SPA. looks like 10km with LR optics is the lowest you can go to cross a rack !!! - check it out at

Re: [c-nsp] BGP Question

2008-11-06 Thread Luan Nguyen
Neighbor allowas-in Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Stephens, Jamie A Sent: Thursday, November 06, 2008 9:18 AM To: cisco-nsp Subject: [c-nsp] BGP Question Is there a

Re: [c-nsp] ipsec over gre with nhrp

2008-11-06 Thread Eric Cables
Make certain that if you have multiple tunnels on your gateway device that use the same tunnel source/ipsec profile, that you specify the shared keyword at the end of the tunnel protection statement. -- Eric Cables On Wed, Nov 5, 2008 at 7:11 PM, Rakesh Hegde [EMAIL PROTECTED] wrote: Hello,

Re: [c-nsp] ISIS Route Flapping Issue

2008-11-06 Thread David Jacobs
Hello Peter, thank you for your reply, I changed my NET address back to the original and reloaded and I tried to dig up more data on this FYI This is what my config looks like on this box. router isis net 49.0001.0001.5011.1565.00 is-type level-2-only metric-style wide spf-interval 30

Re: [c-nsp] Cisco 881 3G Router Experiences

2008-11-06 Thread Luan Nguyen
Basically just another DHCP interface IP-wise. Here's a sample configuration for DMVPN/IPSEC I used for 1841 3G-EVDO. I used it as a primary connection as well as backup connection. interface Dialer1 ip address negotiated ip virtual-reassembly encapsulation ppp dialer pool 1 dialer

Re: [c-nsp] PIX 6.x Site2Site with dynamic IP?

2008-11-06 Thread Luan Nguyen
Just change your A end to use dynamic map. http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_configuration _example09186a0080094680.shtml Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

Re: [c-nsp] ip cef optimize neighbor resolution

2008-11-06 Thread Ross Vandegrift
On Thu, Nov 06, 2008 at 08:49:27PM +1100, Lincoln Dale wrote: the feature is essentially an enhancement for how CEF Gleans and the like are handled. if you're familiar with how those kinds of things work, they would typically need to punt to software to resolve a (not yet available)

[c-nsp] service policy + SYN flood vs. periodic high cpu load

2008-11-06 Thread Nemeth Laszlo
Hi all, I'm testing the control plane policy in my lab. Now i found a very interesting event. I have a 6500/sup720 whit different IOS (SXF6, SXF10a, SXH3a). I send a very big SYN flood to this router. I'm doing this test in clear config. (erase startup, reload :) ) I made a policy:

[c-nsp] GSR no ldp all of a sudden

2008-11-06 Thread Mark Tech
Hi I have a couple of GSR's and 7600'2 running ldp in an an MPLS test environment. All of a sudden 1 GSR has lost all its LDP neighours. I have cleared the mpls ldp neighours, and finally ended up rebooting the router with no success Here is an brief output of some ldp commands: -here

Re: [c-nsp] 6509 sup 720 + export map

2008-11-06 Thread Rakesh Hegde
Thanks for the input. -Rakesh On Wed, Nov 5, 2008 at 4:27 AM, Oliver Boehmer (oboehmer) [EMAIL PROTECTED] wrote: Tim Franklin mailto:[EMAIL PROTECTED] wrote on Wednesday, November 05, 2008 10:03: On Wed, November 5, 2008 6:24 am, Oliver Boehmer (oboehmer) wrote: if I recall

[c-nsp] sup1a - sup32 image questions

2008-11-06 Thread Jason LeBlanc
Hi all, I'm about to begin upgrading our old sup1a/msfc1 switches from both native and hybrid ios to sup32 native. My main requirements are simple, bgp and ios slb. The new download layout and new hardware are causing me some problems. Am I going to need both sp and rp images or a single

Re: [c-nsp] sup1a - sup32 image questions

2008-11-06 Thread Gert Doering
Hi, On Thu, Nov 06, 2008 at 10:58:39AM -0500, Jason LeBlanc wrote: Am I going to need both sp and rp images or a single image? For native, it's a single image. We run s3223-advipservicesk9_wan-mz.122-18.SXF7.bin and yours should be similarily named (starting with s3223-...). gert --

Re: [c-nsp] GSR no ldp all of a sudden

2008-11-06 Thread David Freedman
control plane overloaded by traffic? are you doing control plane policing? Mark Tech wrote: Hi I have a couple of GSR's and 7600'2 running ldp in an an MPLS test environment. All of a sudden 1 GSR has lost all its LDP neighours. I have cleared the mpls ldp neighours, and finally ended up

Re: [c-nsp] GSR no ldp all of a sudden

2008-11-06 Thread Brian Turnbow
I would start with what was done here ? Nov  6 14:44:45 GMT: %SYS-5-CONFIG_I: Configured from console by vty0 (5.14.64.1) Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mark Tech Sent: giovedì 6 novembre 2008 17.39 To:

[c-nsp] vrf-lite and pppoA interfaces

2008-11-06 Thread Wayne Lee
Hello List I have a dedicated LNS for what we call our pwan customers, all connections are ADSL PPPoA and they all use private IP ranges as there is currently no internet access. We have about 150 connections spread over 8 customers, these are currently grouped by customer and then separated from

Re: [c-nsp] sup1a - sup32 image questions

2008-11-06 Thread Jason LeBlanc
Great, thanks for simplifying this for me. ;) Gert Doering wrote: Hi, On Thu, Nov 06, 2008 at 10:58:39AM -0500, Jason LeBlanc wrote: Am I going to need both sp and rp images or a single image? For native, it's a single image. We run s3223-advipservicesk9_wan-mz.122-18.SXF7.bin

[c-nsp] Slave Supervisor for Sup 720 10G Crashing on 6500's

2008-11-06 Thread Richard Chew
Hi All, We have recently deployed 17, 6500's on campus, and about two months in we have already had 5 supervisors fail for no apparent reason. When we call TAC they just RMA us a new Sup, but I suspect (cannot prove) that something else is causing this problem. At first I thought it was

Re: [c-nsp] Slave Supervisor for Sup 720 10G Crashing on 6500's

2008-11-06 Thread Pavel Skovajsa
I will at least give it a try and upgrade to SXH3a or wait couple weeks for SXH4. SXH2 is really buggy. pavel On Thu, Nov 6, 2008 at 6:11 PM, Richard Chew [EMAIL PROTECTED] wrote: Hi All, We have recently deployed 17, 6500's on campus, and about two months in we have already had 5

[c-nsp] Catalyst LAN Input Errors Query...

2008-11-06 Thread Howard Leadmon
Hello to all, I thought this would be easy to find, and maybe I haven't looked in the right place, but figured I'd ask. I have a Cat6509 switch, and on a couple of the interfaces I have feeding from some servers, I keep seeing input errors, as shown below: FastEthernet9/48 is up, line

Re: [c-nsp] ISIS Route Flapping Issue

2008-11-06 Thread Peter Rathlev
On Thu, 2008-11-06 at 09:48 -0500, David Jacobs wrote: When I do a sh spf-log this is the message I keep seeing On Cisco 00:24:50 72109 8 router1.00-00 TLVCONTENT 00:24:20 72109 8 router1.00-00 TLVCONTENT 00:23:50 76109 8

[c-nsp] Cisco IOS for broadband aggregation

2008-11-06 Thread Ruben Alvarez
Hi All, I'm upgrading IOS on my c7206VXR with an npe-300 and: UBR7200-I/O-2FE/E PA-A3-T3= PA-IMA-T1= PA-4E= I'm currently using 122-28.SB2 and noticed a 122-31.SB. Is anyone using the 12.2(31)SB instead of the 12.2(28)SB? I've been looking online and haven't seen much about it. I assume it's

Re: [c-nsp] Cisco IOS for broadband aggregation

2008-11-06 Thread Roddy Strachan
Ruben, Funny you mention it. I've just finished an upgrade of a mixture of 7301 and 7206vxr to 12.2(31)SB13. Had a 7301 running in production for 1 week, no issues, the LNS seems a lot more stable if you ask me. Don't know how the 7206 will go as they have been in production less than an hour

Re: [c-nsp] Cisco IOS for broadband aggregation

2008-11-06 Thread Rinse Kloek
Ruben, We are using the 12.2.(31)SB on one of our routers. We saw some problems with policy routing with VRF's with the SB6 release, but we expect this be fixed in the SB12+. For a full list of software/hardware features/caveats, see

Re: [c-nsp] Cisco IOS for broadband aggregation

2008-11-06 Thread Rinse Kloek
What kind of features do you use with the 7206VXR box ? We are also looking to upgrade to 12.2.31SB13 because we have some problems with 12.2(31)SB6. regards Rinse Roddy Strachan schreef: Ruben, Funny you mention it. I've just finished an upgrade of a mixture of 7301 and 7206vxr to

Re: [c-nsp] Catalyst LAN Input Errors Query...

2008-11-06 Thread Peter Rathlev
On Thu, 2008-11-06 at 14:24 -0500, Howard Leadmon wrote: FastEthernet9/48 is up, line protocol is up (connected) Hardware is C6k 100Mb 802.3, address is 0004.de66.8f73 (bia 0004.de66.8f73) MTU 1500 bytes, BW 10 Kbit, DLY 100 usec,

Re: [c-nsp] Cisco IOS for broadband aggregation

2008-11-06 Thread Ruben Alvarez
That's a great Cisco doc, thanks. I haven't been able to find anything on Google, but we are having issues with static IP configuration with the new Actiontec M1000 modem firmware (v2.) I can assign static IP addresses to the modem via radius, but cannot with the IP unnumbered mode feature in

Re: [c-nsp] watchdog timeout - nmi reset

2008-11-06 Thread Curtis Doty
10:55am Mark Tinka said: Hi all. We've had a bit of bad luck lately with a couple of NPE-G1's suddenly reloading due watchdog timeouts. WAG: The pseudo-preemption gets tangled by something like BFD? http://puck.nether.net/pipermail/cisco-nsp/2008-October/055734.html ../C

Re: [c-nsp] Cisco IOS for broadband aggregation

2008-11-06 Thread Roddy Strachan
No real special features. MQOS to allow QOS policies on the fly as well as POD radius disconnects. Other than that its a plan vanilla PPP/LNS termination device. On 7/11/08 8:14 AM, Rinse Kloek [EMAIL PROTECTED] wrote: What kind of features do you use with the 7206VXR box ? We are also

Re: [c-nsp] Catalyst LAN Input Errors Query...

2008-11-06 Thread Peter Rathlev
On Thu, 2008-11-06 at 22:20 +0100, Peter Rathlev wrote: 1067610 packets input, 920823086 bytes, 0 no buffer Received 0 broadcasts (0 multicasts) 0 runts, 0 giants, 0 throttles 980 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored cut I have googled around a bit,

[c-nsp] Limiting upstream paths to downstream customer - BGP

2008-11-06 Thread Paul Stewart
Hi there. I'm looking for a Cisco doc or a quick guide to *best practice* for the following scenario: Provider A gets 5 upstream BGP feeds via two core routers. Provider B wants to purchase transit from Provider A but does not want to send/receive any traffic via one of Provider A's

[c-nsp] Link level compression

2008-11-06 Thread Anton Yurchenko
Hi All, I am researching if there is a possibility to save some money on links by using link compression. I am not talking WAN acceleration, but something that will basically zip packets on one end and unzip on another. Link bandwidths are 10Gig and up. Any recommendations/experiences are

Re: [c-nsp] Catalyst LAN Input Errors Query...

2008-11-06 Thread Howard Leadmon
On Thu, 2008-11-06 at 14:24 -0500, Howard Leadmon wrote: FastEthernet9/48 is up, line protocol is up (connected) Hardware is C6k 100Mb 802.3, address is 0004.de66.8f73 (bia 0004.de66.8f73) MTU 1500 bytes, BW 10 Kbit, DLY 100

Re: [c-nsp] Catalyst LAN Input Errors Query...

2008-11-06 Thread Howard Leadmon
On Thu, 2008-11-06 at 22:20 +0100, Peter Rathlev wrote: 1067610 packets input, 920823086 bytes, 0 no buffer Received 0 broadcasts (0 multicasts) 0 runts, 0 giants, 0 throttles 980 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored cut I have googled around a

Re: [c-nsp] Catalyst LAN Input Errors Query...

2008-11-06 Thread Aaron Riemer
Hi, That module is limited to 32Gbps which is split up into 4 ASIC's that handle 12 ports each. Quoting Cisco's website - http://www.cisco.com/en/US/products/hw/switches/ps700/products_configura tion_example09186a0080118a5c.shtml You can also take a look at the counters that indicate if the

[c-nsp] Need help in V6MCAST Group count

2008-11-06 Thread Ramnath Velnarayanan
Hi All, I am facing an issue with Ipv6-multicast. Here I am seeing variance in route entries with different command outputs 1) sh ipv mld groups summary MLD Route Summary No. of (*,G) routes = 16 No. of (S,G)

[c-nsp] 65K: 10G SPAN destination interface outputs is significantly less traffic than sum of all source interfaces -- (not oversubscribed)...

2008-11-06 Thread Jeremy Reid
Hi, I'm wondering if anyone else on the list here has seen this issue we've been struggling to pin down: We are using interface SPAN (both rx tx) on the 65k platform (S720/3BXL, currently running SXH3a) to aggregate data from (3) different 10G interfaces into a 10G output port for use with a

Re: [c-nsp] Cisco IOS for broadband aggregation

2008-11-06 Thread Ivan Gasparik
Hi, be careful with your NPE-300, which has already reached End-of-everything and is not supported with 12.2SB train. As far as I know the last supported S-based train for NPE-300 is 12.2S. You might notice the warning message at bootup of the router or if issuing of show version command. Ivan