Re: [c-nsp] mac flapping on 6509 between core and fwsm

2012-04-19 Thread Randy
--- On Thu, 4/19/12, ryanL wrote: > From: ryanL > Subject: Re: [c-nsp] mac flapping on 6509 between core and fwsm > To: "Randy" > Cc: "Mario Ruiz" , cisco-nsp@puck.nether.net > Date: Thursday, April 19, 2012, 6:58 PM > On Thu, Apr 19, 2012 at 5:54 PM, > Randy > wrote: > > --- On Thu, 4/19/12,

Re: [c-nsp] mac flapping on 6509 between core and fwsm

2012-04-19 Thread ryanL
On Thu, Apr 19, 2012 at 5:54 PM, Randy wrote: > --- On Thu, 4/19/12, Mario Ruiz wrote: > > Who is reporting the mac-flaps - the 6509 with fwsm OR fwsm itself? > > it appears that you are seeing it on the 6509 that has the fwsm? > > if that is the case, the an arp-reply from host at 0024.f716.514

Re: [c-nsp] mac flapping on 6509 between core and fwsm

2012-04-19 Thread Randy
--- On Thu, 4/19/12, Mario Ruiz wrote: > From: Mario Ruiz > Subject: Re: [c-nsp] mac flapping on 6509 between core and fwsm > To: "ryanL" > Cc: cisco-nsp@puck.nether.net > Date: Thursday, April 19, 2012, 5:14 PM > I,ve  seen events  when > server switch ports are  not properly teamed. >   And p

Re: [c-nsp] mac flapping on 6509 between core and fwsm

2012-04-19 Thread Mario Ruiz
I,ve seen events when server switch ports are not properly teamed. And physically connected to separate access layer on a switches. Bridged interfaces ...find where the mac address is located On Thu, Apr 19, 2012 at 6:10 PM, ryanL wrote: > does anyone know what would cause this? po30 up

[c-nsp] When will SFP+ 10GBase-T optics be available?

2012-04-19 Thread Eric Rosenberry
I have hosts and storage arrays arriving that are coming with 10GBase-T ports onboard (and no SFP+ ports). This makes it very hard to hook to my SFP+ *only* switches. ;-) My research indicates that the lack of 10GBase-T SFP+ modules is likely due to the power consumption of 10 gig over copper be

[c-nsp] mac flapping on 6509 between core and fwsm

2012-04-19 Thread ryanL
does anyone know what would cause this? po30 uplinks to a core router, and po579 is the internal etherchannel assignment for the fwsm. the fwsm is bridging. the 6509 is spanning-tree root for the vlan. vl1250 is the outside interface. the mac in question is core router, configured as po30.1250. the

[c-nsp] converting mp-ibgp full mesh to dual redundant route reflectors

2012-04-19 Thread Aaron
Is this normal/expected when converting from full mesh mp-ibgp to dual redundant rr's ? this is output from one of my pe's learning routes from my dual hub pe's (.1 and .2) (.4 and .8.2 are just two other pe's) sh bgp vpnv4 u al sum ... 10.101.0.1 4650002540270011707

Re: [c-nsp] New Cisco ME3400 IOS?

2012-04-19 Thread Pavel Skovajsa
The new 12.2(58)EX is out there, can somebody please share experience with it? Also would be great if someone can shed some light on what is actually considered an 'Enhanced QoS buffer management' since from the release notes http://www.cisco.com/en/US/docs/switches/metro/me3400e/software/release/1

Re: [c-nsp] Understanding Out/Input bytes in Interface Counters on 2811

2012-04-19 Thread Peter Subnovic
Hi, thanks again to all who replied, i appreciate it. To answer your question: The reported Volume from the ISP is 300GB but the interface counter for output bytes are "only" showing 3 Billion bytes (3GB) and input bytes are at around 750 MB in a timeframe of 6 weeks (just checked when the count

Re: [c-nsp] L3VPN works, but not default route

2012-04-19 Thread Bruce Pinsky
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Aaron wrote: > I didn't have to use import, and they still came into vrf. ? any idea why? > With unique RD, each route advertised by each PE is considered a separate prefix with a different nexthop. So, bestpath is run for each of those unique RD/P

Re: [c-nsp] Understanding Out/Input bytes in Interface Counters on 2811

2012-04-19 Thread Keegan Holley
2012/4/19 Peter Subnovic > Thanks Chuck, Bruce and James for your replys, > > I did clear the counters 6 weeks ago (near the beginning of march) while i > was troubleshooting another issue . > > The router was not rebooted for 15 weeks. > > Thanks for the hint that the counters are (most probably

Re: [c-nsp] Understanding Out/Input bytes in Interface Counters on 2811

2012-04-19 Thread Bruce Pinsky
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Peter Subnovic wrote: > Thanks Chuck, Bruce and James for your replys, > > I did clear the counters 6 weeks ago (near the beginning of march) while i > was troubleshooting another issue . > > The router was not rebooted for 15 weeks. > > Thanks for

Re: [c-nsp] Understanding Out/Input bytes in Interface Counters on 2811

2012-04-19 Thread Keegan Holley
32bit counters would wrap at 4.29GB so it would never get to 300GB. As far as I know most newer devices have 64 bit counters, but I could be mistaken. The last update I could find on cisco.com was from 2007. It would be pretty stupid to have gigabit interfaces on a device with counters that wrap

Re: [c-nsp] Understanding Out/Input bytes in Interface Counters on 2811

2012-04-19 Thread Peter Subnovic
Thanks Chuck, Bruce and James for your replys, I did clear the counters 6 weeks ago (near the beginning of march) while i was troubleshooting another issue . The router was not rebooted for 15 weeks. Thanks for the hint that the counters are (most probably) 32-bit counters, although the 3 Billio

Re: [c-nsp] Understanding Out/Input bytes in Interface Counters on 2811

2012-04-19 Thread Bruce Pinsky
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Chuck Church wrote: > Could be a bunch of reasons. Were the counters cleared at the time when the > provider's time of measure started? Did the router reboot or were the > counters cleared since? These counters are either a 32 or 64 bit counter. > T

Re: [c-nsp] L3VPN works, but not default route

2012-04-19 Thread Aaron
I didn't have to use import, and they still came into vrf. ? any idea why? "maximum-paths ibgp 2" - didn't work "maximum-paths ibgp unequal-cost 2" - worked me3600(config)#router bgp 65000 me3600(config-router)#address-family ipv4 vrf one me3600(config-router-af)#maximum-paths ibgp unequal-cost

Re: [c-nsp] Understanding Out/Input bytes in Interface Counters on 2811

2012-04-19 Thread Chuck Church
Could be a bunch of reasons. Were the counters cleared at the time when the provider's time of measure started? Did the router reboot or were the counters cleared since? These counters are either a 32 or 64 bit counter. They do occasionally wrap and start over at 0, pretty frequent on 32 bit cou

[c-nsp] Understanding Out/Input bytes in Interface Counters on 2811

2012-04-19 Thread Peter Subnovic
Dear List, i am having an Cisco 2811 with IOS (C2800NM-ADVENTERPRISEK9-M), Version 12.4(24)T Our Provider told us that we had a traffic volume of 300GB last month, but the interface counters do not reflect these values: I am curios, if the reported volume should be reflected in the out/input byt

Re: [c-nsp] L3VPN works, but not default route

2012-04-19 Thread Aaron
Thanks so much, y'all are great. I do already have the unique RD's on all pe's. I do not have the max paths...i tested that yesterday and it didn't seem to work, I think it's because I only used the "maximum-paths 2" without those other iebgp things looks good now. "maximum-paths ibgp 2" - d

[c-nsp] IP-FORWARD-MIB from RFC 2096 on ASA etc.

2012-04-19 Thread Aled Morris
>From what I've been able to determine Cisco has no plans to expose the routing table via SNMP from the ASA platform. Does anyone in the community have a bug or feature request open with TAC for this? Maybe a bit of "customer demand" would help persuade them. Aled ___

Re: [c-nsp] unicast storm

2012-04-19 Thread Ray Van Dolson
On Wed, Apr 18, 2012 at 09:00:41PM -0700, ujjwal maghaiya wrote: > Could anyone tell to me the possible cases of UNICAST STORM. > Improperly configured vSphere hosts with vMotions going on... Solaris boxes with multiple interfaces on the same subnet/switch... i

Re: [c-nsp] Protecting MLX/XMR MP against attacks with IP Receive ACLs / extended ACL behaviour

2012-04-19 Thread Rolf Hanßen
Sorry, wrong list, should go to foundry-nsp ;) > Hello, > > this week we had an attack directly against one of our XMR (UDP packets to > a transfer network IP). > I was looking for an CoPP-equivalant and found the "IP Receive ACLs" > feature. > > In sample case of "I block all UDP and allow everth

[c-nsp] Protecting MLX/XMR MP against attacks with IP Receive ACLs / extended ACL behaviour

2012-04-19 Thread Rolf Hanßen
Hello, this week we had an attack directly against one of our XMR (UDP packets to a transfer network IP). I was looking for an CoPP-equivalant and found the "IP Receive ACLs" feature. In sample case of "I block all UDP and allow everthing else" I would use that config here according to the manual

Re: [c-nsp] L3VPN works, but not default route

2012-04-19 Thread Tim Durack
You will need a unique RD per PE, to allow multiple VPN routes to be "discriminated." You also need to enable maximum-paths for the bgp vrf context: PE1: vrf definition rd route-target both end PE2: vrf definition rd route-target both end router bgp address-family ipv4 vrf maxim

Re: [c-nsp] L3VPN works, but not default route

2012-04-19 Thread Oliver Boehmer (oboehmer)
> As a continuation of this thread/task, I now have the default route from my > dual core ce-pe hubs, thanks to you all :) ...and now shown below is some > output from one of my other pe's further out into the edge of my > network...it seems that it is rcv'ing the dual default routes from the du

Re: [c-nsp] L3VPN works, but not default route

2012-04-19 Thread Aaron
As a continuation of this thread/task, I now have the default route from my dual core ce-pe hubs, thanks to you all :) ...and now shown below is some output from one of my other pe's further out into the edge of my network...it seems that it is rcv'ing the dual default routes from the dual ce/pe co

[c-nsp] IPsec from Linux to Cisco dynamic-map?

2012-04-19 Thread Peter Olsson
Hello! I'm trying to configure an IPsec star network with a couple of Linux boxes connecting to a central IOS router using dynamic-map. The Linux boxes all get their public IP addresses from DHCP, so the IOS router must use only dynamic peering for this IPsec network. The IOS router I'm testing w

Re: [c-nsp] router does not see IGMP joins

2012-04-19 Thread Victor Sudakov
Hitesh Vinzoda wrote: > > > > It seems that the problem disappeared after the host sending IGMP > > joins was moved from a hub (10BASE-T HD) to a switch (100BASE-T FD). > > > > I am still confused about the possible cause of the problem. > > > > Is PIM enabled on that interface ? I posted the out

Re: [c-nsp] unicast storm

2012-04-19 Thread Saku Ytti
On (2012-04-19 08:26 +0100), Phil Mayers wrote: > 1. Cause the host to emit traffic > 2. Lower the ARP time to < FDB timeout ACK. 4h is brutally long as IOS default in IOS, some other options: FreeBSD: > sysctl net.link.ether.inet.max_age net.link.ether.inet.max_age: 1200 Linux: % sysctl net.i

[c-nsp] IP Source Guard and Smartlog on 3750s

2012-04-19 Thread Martin Clifton
Hi, I'm looking at implementing IPSG on our 3750s. This is a test which stops a host using a port unless its mac-address/host-address match the ip dhcp snooping table. This works fine. IOS is 15.0(1)SE2. The specific hardware is Catalyst 3750G-24PS. My problem is that I want to be alert

Re: [c-nsp] unicast storm

2012-04-19 Thread Phil Mayers
On 04/19/2012 05:00 AM, ujjwal maghaiya wrote: Could anyone tell to me the possible cases of UNICAST STORM. One common cause is a host that receives a lot of traffic, but doesn't send it - e.g. a syslog server. If the ARP timeout is > FDB timeout, when t