Re: [c-nsp] ME3600 switch interface showing Packet drops on Trunk Port.

2012-09-21 Thread Muthukumar Rajagopalan
Thanks Ivan for sharing the Thread, I just glanced the thread quickly, in our setup, there is no QOS applied as of now. The interface is a 1 Gig interface only and here is the show controller output. show controllers ethernet-controller gigabitEthernet 0/1 Transmit GigabitEthernet0/1

Re: [c-nsp] ME3600 switch interface showing Packet drops on Trunk Port.

2012-09-21 Thread Ivan
Hi Muthu, As per that thread the default buffer size for the Gi interfaces is very small and can be increased with a QoS policy as Warris described. I was seeing Total output drops increasing in the output of show int gi0/x AT a quick glance I can't see this information in the output you

[c-nsp] DCEF720 card together with CEF256/classic line cards in Cat6.5k with Sup720?

2012-09-21 Thread Lars Fenneberg
Hi all, I think I might be a little confused on this so I'm asking here: Is a DCEF720 card like the WS-X6708-10G-3CXL supported together with a Supervisor 720 and a bunch of classic and CEF256 line cards? If it's supported: Would there still be any remaining benefit in using a DFC-equipped

Re: [c-nsp] DCEF720 card together with CEF256/classic line cards in Cat6.5k with Sup720?

2012-09-21 Thread Brian Turnbow
HI -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- boun...@puck.nether.net] On Behalf Of Lars Fenneberg Sent: venerdì 21 settembre 2012 14:42 To: cisco-nsp@puck.nether.net Subject: [c-nsp] DCEF720 card together with CEF256/classic line cards in

[c-nsp] ISIS authentication

2012-09-21 Thread Adam Vitkovsky
Hi Would it make sense to enable authentication on IIH packets -when running ISIS over leased Ethernet circuits please? I was confronted with an advice about authentication on IIH packets as a base security when running ISIS over leased circuits (e.g. when you order an Ethernet circuit and you

Re: [c-nsp] ISIS authentication

2012-09-21 Thread Saku Ytti
On (2012-09-21 16:36 +0200), Adam Vitkovsky wrote: I'd like to hear the other's opinion on IGP authentication in the core in general I would do MD5 for hello and lsp in ISIS. It's not hard to config, as it does not require downtime. Maybe some old link is repurposed as core link and you leave

[c-nsp] METRO Ethernet CFM question -Ethernet SLA

2012-09-21 Thread Adam Vitkovsky
Hi While I'm searching the web I'd love to hear your ideas on this Are there any standards/recommendations on how to set the Ethernet SLA probes for proper measurements please? Thanks adam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] ISIS authentication

2012-09-21 Thread Adam Vitkovsky
OMG I shouldn't know this now I'll have nightmares for the rest of my life Ok Lesson learned adam -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Saku Ytti Sent: Friday, September 21, 2012 4:47 PM To:

Re: [c-nsp] 2900 - 2960 config question

2012-09-21 Thread Joseph Mays
Well, I did the switch from the 2900 to the 2960, everything works fine except for one thing... Port 22 on the original switch is set to be a vlan trunk that links to another switch (sw2, also a 2900XL) in another building with a different set of vlans on it. interface FastEthernet0/22

Re: [c-nsp] 2900 - 2960 config question

2012-09-21 Thread Jon Lewis
On Fri, 21 Sep 2012, Joseph Mays wrote: interface FastEthernet0/22 description Trunk to sw2.dist.win.net duplex full speed 100 switchport access vlan 22 switchport trunk allowed vlan 1,201-224,1002-1005 switchport mode trunk no cdp enable The client on the remote switch, vlan 202, does not

Re: [c-nsp] 2900 - 2960 config question

2012-09-21 Thread TNW Lists
On Fri, Sep 21, 2012 at 10:48 AM, Joseph Mays m...@win.net wrote: Well, I did the switch from the 2900 to the 2960, everything works fine except for one thing... Port 22 on the original switch is set to be a vlan trunk that links to another switch (sw2, also a 2900XL) in another building

Re: [c-nsp] 2900 - 2960 config question

2012-09-21 Thread Seth Mattinen
On 9/21/12 8:56 AM, Jon Lewis wrote: On Fri, 21 Sep 2012, Joseph Mays wrote: interface FastEthernet0/22 description Trunk to sw2.dist.win.net duplex full speed 100 switchport access vlan 22 switchport trunk allowed vlan 1,201-224,1002-1005 switchport mode trunk no cdp enable The

Re: [c-nsp] Cisco Infra DDOS Protection

2012-09-21 Thread ar
Thanks. What could be a good replacement for 7600s to overcome this limitation? ASR9K?Nexus7K? By the way, I have tried netflow on 7600 and tcam shoots up. I am still researching as to why 7600 sucks on this. thanks From: Dobbins, Roland rdobb...@arbor.net

Re: [c-nsp] 2900 - 2960 config question

2012-09-21 Thread Gert Doering
Hi, On Fri, Sep 21, 2012 at 10:48:29AM -0400, Joseph Mays wrote: I don't know what might be causing this, unless something about the vlan database is not created by cutting and pasting the config from the 2900XL to the 2960. Most likely exactly this: the vlan 202 is not existing, since the

Re: [c-nsp] 2900 - 2960 config question

2012-09-21 Thread Nick Hilliard
On 21 Sep 2012, at 18:06, Gert Doering g...@greenie.muc.de wrote: (Stupid move. Even more stupid, still the same with vtp v3 The cynic in me wonders what you expect if you use vtp? :-) Nick, ex-vtp user, blood-stained t shirt and all ___ cisco-nsp

Re: [c-nsp] 2900 - 2960 config question

2012-09-21 Thread Gert Doering
Hi, On Fri, Sep 21, 2012 at 07:04:09PM +0100, Nick Hilliard wrote: On 21 Sep 2012, at 18:06, Gert Doering g...@greenie.muc.de wrote: (Stupid move. Even more stupid, still the same with vtp v3 The cynic in me wonders what you expect if you use vtp? :-) Nick, ex-vtp user, blood-stained t

[c-nsp] warning... ASR901 running 15.1(2)SNH

2012-09-21 Thread Aaron
Don't do this! Conf t Ethernet cfm global If you do, 75 seconds later IP reachability, OSPF, MPLS, L2VPN (vpws) PW's, will all come crashing down. I lost a cell tower on my Ethernet cell backhaul network, and sent a CO Tech speeding down the road in his truck to reboot that

Re: [c-nsp] Are Nexus and per-interface or FEX MTU settings possible?

2012-09-21 Thread Conkel, Joshua
Actually, I just installed a 10G LR fiber optic module in each of them in order to connect to the 5Ks. I was sure to add the spanning-tree port type edge trunk command on the Nexus so I didn't risk ISSU support. The way I see it, we should be able to keep this working by making sure no hosts

Re: [c-nsp] Are Nexus and per-interface or FEX MTU settings possible?

2012-09-21 Thread Conkel, Joshua
Haha. For our datacenter migration, we are traveling over about two miles of singlemode fiber with the 10G links. (5 patches total!) I know it's not best practice, but we are doing this to avoid having to readdress servers during the live transition. Once the transition is complete, the Nexus

Re: [c-nsp] Are Nexus and per-interface or FEX MTU settings possible?

2012-09-21 Thread Andrew Jones
Also, why LR optics? Unless you need to distance, SR optics are 1/4 the price. Or if you are patching into the same rack, twinax cables even cheaper. Ive generally placed 5k in a central location near core / aggregation switches, then distributed the 2k over the data hall with multimode fibre.

Re: [c-nsp] Are Nexus and per-interface or FEX MTU settings possible?

2012-09-21 Thread Andrew Jones
Im assuming your 3560 has gigabit ports to connet the 5ks? Then you can do jumbo frames on those interfaces, as per the following from cisco.com http://www.cisco.com/en/US/products/hw/switches/ps700/products_configuration_example09186a008010edab.shtml#c3 You will need to reboot the switch

Re: [c-nsp] Are Nexus and per-interface or FEX MTU settings possible?

2012-09-21 Thread Andrew Jones
PMTUD should take care of the rest... Andrew Jones -Original Message- From: Conkel, Joshua [mailto:conk...@wems-llc.com] Sent: Saturday, 22 September 2012 10:47 AM To: Andrew Jones Cc: cisco-nsp@puck.nether.net Subject: RE: Are Nexus and per-interface or FEX MTU settings possible?