[c-nsp] Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Software

2015-04-08 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Multiple Vulnerabilities in Cisco ASA Software Advisory ID: cisco-sa-20150408-asa Revision 1.0 For Public Release 2015 April 8 16:00 UTC (GMT) +- Summary === Cisco Adaptive

[c-nsp] Cisco Security Advisory: Cisco ASA FirePOWER Services and Cisco ASA CX Services Crafted Packets Denial of Service Vulnerability

2015-04-08 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco ASA FirePOWER Services and Cisco ASA CX Services Crafted Packets Denial of Service Vulnerability Advisory ID: cisco-sa-20150408-cxfp Revision 1.0 For Public Release 2015 April 8 16:00 UTC (GMT

[c-nsp] Trigger for IP FRR

2015-04-08 Thread Dhamija Amit via cisco-nsp
 Hi I have a question for trigger on IP FRR, apart from Link/Protocol Adj down can IP FRR be triggered by Link down LSA/LSP updates. I am using below topology:- RTR-C /\ / \ / \ RTR-A -SWRTR-B A and

Re: [c-nsp] VPLS : Loop avoidance

2015-04-08 Thread Aaron
I think split horizon loop avoidance is a default behavior for pw's under a vfi context. So with that in mind , you should have no forwarding of frames between the (2) neighbor pw statements under the 6880's l2 vfi. I believe that is treated like an etree service whereas the root of the tree is

[c-nsp] VPLS : Loop avoidance

2015-04-08 Thread Nicolas KARP
Hello, We are going to interconnect two of our datacenters. In one datacenter we have a 6880-X configured with VSS and on the other hand, we have a pair of ASR 1001-X. We would like to configure the VPLS and I have some questions about the redundancy and loop avoidance. You can find a diagram

Re: [c-nsp] VPLS : Loop avoidance

2015-04-08 Thread Nicolas KARP
Hi Aaron, Both interfaces configuration on the two asr have been provided on my first email. It's just an interface with some service instances configured with some vfi. In fact in my case, the leafs are connected together via a layer2 network (switches) and the the two leafs are connected to

Re: [c-nsp] VPLS : Loop avoidance

2015-04-08 Thread Adam Vitkovsky
Hello Nicolas, Right the split horizon is there so packets coming from a PW will not be forwarded to another PW in the same VFI so that takes care of loops in MPLS. However you need to take care of the loops created via LAN/DC side so you need to have a dedicated forwarder for the BUM traffic

[c-nsp] Nightmare for load balancing of L2VPN traffic on CRS (traffic from ME3600)

2015-04-08 Thread Darren Liew
Hi Guys, We are a fixed line operator with majority of L2VPN xconnect traffic on our network. Our equipments are CRS-8- Core P router ME3600 - Access PE router Most L2VPN xconnect traffic starts and ends at ME3600. We are beginning to see our CRS-8 not being able to load balance among the