[c-nsp] Rate limit or policy-map

2008-11-27 Thread Mikisa Richard
Hi all I have a scenario where I have to dedicate 256K to a particular host out of my 1M link. What would be the best way to go about it? Should I do a simple interface rate limit or should I do a policy and police off that ? Regards Richard.

Re: [c-nsp] Rate limit or policy-map

2008-11-27 Thread Arie Vayner (avayner)
Richard, Using a policer (rate-limit) does not dedicate or allocate any minimal bandwidth... It creates an upper limit for the specific class. You should be using the bandwidth statement inside the correct class-map for the relevant traffic. A very basic config for something that sounds like

Re: [c-nsp] cisco6500-vlans missing

2008-11-27 Thread Tassos Chatzithomaoglou
ambedkar wrote on 27/11/2008 07:09: hi, 1. In cisco 6500 switch, the vlans are missing whenever it is restarted manually. please give me solution why it is happening. Is it a vtp client? What does sh vtp status show? 2. one of the gig port showing errdisable. Do you have errdisable

[c-nsp] dns rewrite on FWSM

2008-11-27 Thread Arne Larsen / Region Nordjylland
Hi Folks. Isn't it possible to do rewrite dns on a Firewall service modul, or do I need to make an upgrade off the software ?? I'm current running 3.1(6). /Arne ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] ASA AIP-SSM-10

2008-11-27 Thread Hitesh Vinzoda
Does that tftp server need to be of the same subnet for which i had one for IPS or nothing to be done. Regards On 11/26/08, Joerg Mayer [EMAIL PROTECTED] wrote: On Wed, Nov 26, 2008 at 01:30:32AM -0800, Hitesh Vinzoda wrote: We were upgrading the patches on AIP-SSM-10 and IPS seems not to

Re: [c-nsp] Opinions about ICMP Destination Unreachable

2008-11-27 Thread sthaug
I am just wondering how many people have ICMP Destination Unreachables disabled on their core routers. Could an CPE router, which may encapsulate data, be able to depend on ICMP Unreachables to be sent to it? I know there are many cases where router implementations default it to off

Re: [c-nsp] dns rewrite on FWSM

2008-11-27 Thread Arie Vayner (avayner)
Arne, Can you please explain what you want to achieve? What do you mean by DNS Rewrite? Thanks Arie -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Arne Larsen / Region Nordjylland Sent: Thursday, November 27, 2008 11:34 AM To:

[c-nsp] load balance between to EBGP peers

2008-11-27 Thread moshe mizrachi
Hi all , i have MPLS/VPN network based on 7600's . all the Internet is going via VRF-INTERNET , my ASBR gets full route from 2 peers via OC12 POS interfaces on VRF INTERNET , also he gets 0.0.0.0 route from both peers but of course only 1 gets to FIB . my target is to get load balance between

Re: [c-nsp] load balance between to EBGP peers

2008-11-27 Thread Arie Vayner (avayner)
Moshe, Take a look at these command: http://www.cisco.com/en/US/docs/ios/iproute/command/reference/irp_bgp3.h tml#wp1012317 Arie -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of moshe mizrachi Sent: Thursday, November 27, 2008 15:27 PM To:

Re: [c-nsp] load balance between to EBGP peers

2008-11-27 Thread Lynch, Tomas
You don't need the default route from your providers, just the full table. Inside your VRF, originate the default route locally from you ASBR and redistribute it to the rest of your routers (I'm assuming you are not sending the full table to the rest of the routers due to several limitations you

Re: [c-nsp] Opinions about ICMP Destination Unreachable

2008-11-27 Thread Jen Linkova
On Thu, Nov 27, 2008 at 8:10 AM, Dino Farinacci [EMAIL PROTECTED] wrote: I am just wondering how many people have ICMP Destination Unreachables disabled on their core routers. Could an CPE router, which may encapsulate data, be able to depend on ICMP Unreachables to be sent to it? I know

Re: [c-nsp] broadcast address question

2008-11-27 Thread lee . e . rian
Either one works, but the all 1s broadcast address is more correct. See RFC-1122 Requirements for Internet Hosts -- Communication Layers 3.3.6 Broadcasts Hosts SHOULD use the Limited Broadcast address to broadcast to a connected network. Lee [EMAIL PROTECTED] wrote: - To:

Re: [c-nsp] dns rewrite on FWSM

2008-11-27 Thread Arne Larsen / Region Nordjylland
Hi Arie. As Jen Likova wrote it should be possible to change the answer from an public dns server. My problem is that we got to access RFC1918 address from our internal network to dmz web-servers, and public users need to use public address off cause. So by rewriteing the dns answer we wont

Re: [c-nsp] dns rewrite on FWSM

2008-11-27 Thread Jeff Kell
Arne Larsen / Region Nordjylland wrote: As Jen Likova wrote it should be possible to change the answer from an public dns server. My problem is that we got to access RFC1918 address from our internal network to dmz web-servers, and public users need to use public address off cause. So by

Re: [c-nsp] wireless access-controll feature in ios software

2008-11-27 Thread Velasquez Venegas Jaime Omar
I believe auth proxy can authenticate on specific and a limited number of protocols (telnet,http,ssh).Authentication forced by captive portal applies to any type traffic going through which is mostly the case for a typical wireless users network .Can anyone confirm? Thanks -Mensaje

Re: [c-nsp] load balance between to EBGP peers

2008-11-27 Thread Peter Rathlev
On Thu, 2008-11-27 at 15:26 +0200, moshe mizrachi wrote: i have MPLS/VPN network based on 7600's . all the Internet is going via VRF-INTERNET , my ASBR gets full route from 2 peers via OC12 POS interfaces on VRF INTERNET , also he gets 0.0.0.0 route from both peers but of course only 1 gets

Re: [c-nsp] Downloadable ACLs without using ACS

2008-11-27 Thread Jim McBurnett
I've got customer's using Microsoft IAS... But they have spent lots of time securing AD so that non-employee users have no AD folder/LAN permissions.. This makes me say- any standards based RADIUS should work.. jim -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

Re: [c-nsp] cisco6500-vlans missing

2008-11-27 Thread ambedkar
  hi, this is the log... 106_6509_CAT_1 106_6509_CAT_1 sh port * = Configured MAC Address. # = 802.1X Authenticated Port Name. Port Name Status Vlan Duplex Speed Type - -- -- -- --- -- -- 1/1