Re: [c-nsp] Syslog timezone

2018-03-22 Thread Dan Letkeman
The syslog messages don't have the correct timezone. The timezone in the event is correct. service timestamps log datetime msec localtime show-timezone I think this did fix it. It just took a while. On Thu, Mar 22, 2018 at 1:09 PM, Alan Buxey wrote: > just to check -

[c-nsp] Syslog timezone

2018-03-22 Thread Dan Letkeman
Hello, I'm trying to change the syslog message timezone to the correct one for my location. This: service timestamps log datetime msec localtime show-timezone Only changes the console log timezone to the correct timezone. The syslog messages continue to use the UTC timezone. Is there any way

[c-nsp] 4500R+E input voltage

2015-02-26 Thread Dan Letkeman
Hello, Just wondering if anyone has switched from 110v to 220v on a 4500 chassis without shutting it off? Power Fan Inline Supply Model No Type Status Sensor Status -- - --- ---

[c-nsp] asa, internal web filter

2013-12-12 Thread Dan Letkeman
Hello, We currently have our gateway / web filter routing setup in this manor: lan --- 2921 ---asa(firewall) ---internet | -- web filter So the traffic destined to the internet that is not supposed to be filtered goes right through the router to the asa. The

Re: [c-nsp] redistribute bgp subnet

2013-08-15 Thread Dan Letkeman
Ok, found out that the subnet I was trying to use is not transfered over to our ISP so nothing I was trying was workingIt's all good now. On Thu, Aug 15, 2013 at 4:28 PM, Darren O'Connor darre...@outlook.comwrote: You can run BGP with your customer. Set aside some of your address space

[c-nsp] redistribute bgp subnet

2013-08-14 Thread Dan Letkeman
Hello, Excuse my ignorance, as this is my first time working with BGP outside of a lab. I am working on an ASR that is in use as a BGP peer to an ISP and also an EIGRP neighbor to an internal network. I have setup this router for NAT/PAT and all is working well for the internal private subnets.

Re: [c-nsp] vrf-lite routing

2013-07-17 Thread Dan Letkeman
it. Then you wont have to add vlans for every new internet customer. But shaping may be harder to do as you dont have the customers interface in your core. //Mattias On Wed, Jul 17, 2013 at 4:12 AM, Dan Letkeman danletke...@gmail.comwrote: Hello, Just wondering if anyone can direct me down

Re: [c-nsp] vrf-lite routing

2013-07-17 Thread Dan Letkeman
I think it makes more sense to do this based on the equipment they have. http://packetlife.net/blog/2009/apr/30/intro-vrf-lite/ Get the performance of routing on the 3k switches but the segregation of VRF-lite if they want it. Dan. On Wed, Jul 17, 2013 at 7:45 PM, Dan Letkeman danletke

[c-nsp] vrf-lite routing

2013-07-16 Thread Dan Letkeman
Hello, Just wondering if anyone can direct me down the correct path. I have been asked by a friend to help replace an ISR2851 with a new ASR1001. The 2851 currently does some route-maps for different networks and a few customers as well as some shaping. They want to use the ASR to peer with

Re: [c-nsp] 2960 - 4948 - no more drops :)

2013-02-16 Thread Dan Letkeman
Same here. We went from 3560G's to 4948's and it was night and day. Zero output drops now and a noticeable performance improvement, as we were using these switches for ISCSI traffic. No qos tuning or disabling helped our situation on the 3560G's. What type of traffic were you sending through

Re: [c-nsp] redundant radius server config

2012-12-10 Thread Dan Letkeman
Specifies for how many minutes a RADIUS server that is not responding to authentication requests is passed over by requests for RADIUS authentication. Alberto -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto: cisco-nsp-boun...@puck.nether.net] On Behalf Of Dan Letkeman

[c-nsp] redundant radius server config

2012-12-09 Thread Dan Letkeman
Hello, Having some trouble with my redundant radius server config. I have configured the switch to use two different radius servers in a group. When I shutdown one of the radius servers the switch still requests a connection to the down server, then times out and tries the secondary server, but

[c-nsp] Config management

2012-10-26 Thread Dan Letkeman
Hello, Curious as to what everyone is using for config management for switches. I have a few hundred 2960's and 3560's to manage on a regular basis, and I would like to have something that can make mass config changes. Not really looking for anything to monitor them as I have that part covered.

[c-nsp] Rogue NAT gateways

2012-07-15 Thread Dan Letkeman
Wondering if anyone has any tricks for disabling the use of any NAT gateways? I know the best way is to remove it physically, but in the case of guest access and mobile devices its sometimes difficult to do so. Now that many devices can act as a hotspot, some of these devices are becoming

Re: [c-nsp] Replace 3750 with 3600x

2012-07-07 Thread Dan Letkeman
Thanks Reuben, excellent post. Dan. On Sat, Jul 7, 2012 at 2:21 AM, Reuben Farrelly reuben-cisco-...@reub.net wrote: On 7/07/2012 11:45 AM, Dan Letkeman wrote: Hello, Looking at replacing a 3750G-12S-12 with an ME-3600X-24FS-M. I have never used or seen a 3600x, and I was wondering

[c-nsp] Replace 3750 with 3600x

2012-07-06 Thread Dan Letkeman
Hello, Looking at replacing a 3750G-12S-12 with an ME-3600X-24FS-M. I have never used or seen a 3600x, and I was wondering for the basic switch services does it have the same command line options. Just doing dot1q trunking, maybe some qos marking, rstp, eigrp, etherchannel, and some simple ipv4

Re: [c-nsp] Small DC switch design

2012-05-16 Thread Dan Letkeman
Tinka mark.ti...@seacom.mu wrote: On Wednesday, May 16, 2012 05:14:54 AM Dan Letkeman wrote: Most high bandwidth traffic is to and from the servers and sans, and would stay within the 4500-E, second to that would be the traffic from all of the users from all the buildings to and from the servers

Re: [c-nsp] Small DC switch design

2012-05-15 Thread Dan Letkeman
Jason, Thank you for the response. I have a few more questions and maybe some clarification if you could. On Tue, May 15, 2012 at 10:58 AM, Jason Gurtz jasongu...@npumail.com wrote: Your size sounds fairly close to our situation... Do you have a spare fiber pair going to each location?

[c-nsp] Small DC switch design

2012-05-14 Thread Dan Letkeman
Hello, I'm working on options for a small DC switch design. This DC has 5 virtual hosts with 10-20 guest vm's each. Each server has two quad port gig nics with 6 of the 8 gig ports connected (3 for iSCSI and 3 for data or management. It also has two 3 node sans each with 2 gig ports per node,

[c-nsp] ASA NAT/PAT rpf-check

2012-02-12 Thread Dan Letkeman
Hello, Having some trouble with an rpf-check on an ASA when doing pat to an internal web server. I have static nat working: network object laptop host 192.168.75.208 network object internet-75 host 100.1.1.75 nat (inside,outside) after-auto source dynamic laptop internet-75 No problems here,

Re: [c-nsp] shaping outbound

2011-12-29 Thread Dan Letkeman
my sub interfaces for my guest networks on the router. It seems as if you are not allowed to add shaping even with a child/parent policy map. Dan. On Sun, Dec 25, 2011 at 2:46 PM, Anton Kapela tkap...@gmail.com wrote: Dan, On Sat, Dec 24, 2011 at 2:49 PM, Dan Letkeman danletke...@gmail.com

[c-nsp] shaping outbound

2011-12-24 Thread Dan Letkeman
Hello, I'm confused as to when and where it is possible to shape traffic. I have a 50Mbps internet connection from our ISP and I would like to shape some of the download traffic using our 2821. Here is what I have setup: lan users - g0/0 - 2821 - g0/1 --internet Currently I have no

Re: [c-nsp] shaping outbound

2011-12-24 Thread Dan Letkeman
-Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Dan Letkeman Sent: Saturday, December 24, 2011 22:49 To: cisco-nsp Subject: [c-nsp] shaping outbound Hello, I'm confused as to when and where it is possible to shape

[c-nsp] shaping w/sub interfaces - drops

2011-12-21 Thread Dan Letkeman
Hello, I'm wondering if its possible to eliminate drops using shaping? I have a sub interface set-up for guest access and I want to limit all access to 3mbps and http access to 2mbps. If I apply a policy to the sub interface I continuously see drops on the http class when it runs in and around

[c-nsp] remote location voice qos with switches

2011-08-16 Thread Dan Letkeman
Hello, I have a remote location, where I have a 3560 which connects to our main location via a wireless bridge and goes into a 3560G. The wireless bridge has approximately 70mbps throughput. This remote location has about 12 7962 phones, and for the most part everything works fine, except when

Re: [c-nsp] tftp woes

2011-07-25 Thread Dan Letkeman
multicast as well, but sometimes the guys who do the imaging want to unicast instead for what ever reason. Dan. On Mon, Jul 25, 2011 at 2:25 AM, Peter Hicks peter.hi...@poggs.co.uk wrote: On Sun, 2011-07-24 at 21:43 -0500, Dan Letkeman wrote: After about 12-15 machines start the image transfer

[c-nsp] EIGRP HSRP Successors

2011-07-24 Thread Dan Letkeman
Hello, I'm working on a test configuration for hsrp between two switches where i'm running eigrp, and I'm wondering if its best practice to leave the added successors in the route list? For example, after I made vlan 501 into an hsrp enabled vlan between the two switches it added itself as an

[c-nsp] tftp woes

2011-07-24 Thread Dan Letkeman
Hello, We have imaging servers in all of our locations, and we normally image around 30 to 60 machines at once. The image is usually stored on a server with local SAS raid storage, which is connected to a 3560G at1Gbps, and then to 2960's (10/100 w/Gig Uplinks to the 3560G). After about 12-15

Re: [c-nsp] off-topic NMS Suggestion

2011-05-24 Thread Dan Letkeman
Intermapper has worked well for me for the past few years, easy to setup, not expensive, and has the ability to make a nice graphical map of all your devices any which way you please. Dan. On Tue, May 17, 2011 at 9:38 PM, omar parihuana omar.parihu...@gmail.com wrote: Hi List, Please could

[c-nsp] Core: 2x4948 or 1x4503

2011-05-04 Thread Dan Letkeman
Hello, We are looking at replacing our core switches (2x3560G). I'm looking at a few options, but the ones that interest me the most is the 4948E-E, and the 4503-E w/two 48 Port line cards and a SUP 6L-E. As far as bandwidth required, we have three esx hosts and two san's. About 40 vm's. We do

Re: [c-nsp] 3560 vs 4948 shared buffer memory

2011-03-08 Thread Dan Letkeman
Yes, I knew there was something I was missing.Thats too bad. Dan. On Tue, Mar 8, 2011 at 10:12 AM, Brandon Ewing nicot...@warningg.com wrote: On Mon, Mar 07, 2011 at 11:15:01PM -0500, Chris Evans wrote: We don't use 3750 or smaller switches anymore due to this.  4948 is deemed data center

[c-nsp] 3560 vs 4948 shared buffer memory

2011-03-07 Thread Dan Letkeman
Hello, I've noticed a fair amount of output drops from traffic bursts on our 3560G's. This is happening with or without QOS on. So I have been looking a replacing these switches for this reason and others. From what I understand there is a problem with the shared memory buffer space, when

Re: [c-nsp] asa routed public network through asa

2011-02-05 Thread Dan Letkeman
Yes, I only have the /26 with a pre-existing netmask. On Fri, Feb 4, 2011 at 9:54 PM, Jeff Kell jeff-k...@utc.edu wrote: On 2/4/2011 9:16 PM, Dan Letkeman wrote: The asa is running 8.3(2), and I have a /26 from our isp to work with.  One of those IP's currently exists on the routed outside

[c-nsp] asa routed public network through asa

2011-02-04 Thread Dan Letkeman
Hello, I have an odd network design request that I'm trying to figure out. Currently I have an asa 5520 thats configured to NAT a few dozen private networks to one public IP for desktop access. Simple enough. What I want do do is create a private network inside the current network, but give

Re: [c-nsp] Constant output drops on etherchannel

2011-01-16 Thread Dan Letkeman
to start. I know that I need to learn some more about qos, because we do have a voice network that is growing very fast. Do you know of some good documentation or books that I can start with? Dan. On Sun, Jan 16, 2011 at 9:14 AM, Nick Hilliard n...@foobar.org wrote: On 16/01/2011 02:30, Dan Letkeman

Re: [c-nsp] Constant output drops on etherchannel

2011-01-15 Thread Dan Letkeman
dedicated interface.  This may or may not working depending on what's happening on those vlans, but the idea is to reduce the load on each of the circuits. In the end you may be asking too much out of that switch. Klementina On Fri, 14 Jan 2011, Dan Letkeman wrote: So is there any way

[c-nsp] Constant output drops on etherchannel

2011-01-14 Thread Dan Letkeman
Hello, I'm seeing many of our etherchannel's on different switches having output drops: Port-channel2 is up, line protocol is up (connected) Hardware is EtherChannel, address is 001b.d59d.7199 (bia 001b.d59d.7199) MTU 1500 bytes, BW 20 Kbit, DLY 100 usec, reliability 255/255, txload

Re: [c-nsp] Constant output drops on etherchannel

2011-01-14 Thread Dan Letkeman
, Dan. On Fri, Jan 14, 2011 at 10:12 AM, Phil Mayers p.may...@imperial.ac.uk wrote: On 14/01/11 16:08, Dan Letkeman wrote: Hello, I'm seeing many of our etherchannel's on different switches having output drops: Platform? IOS version? Config of the interface(s) (routed, SVI, etc.)   Input

Re: [c-nsp] Constant output drops on etherchannel

2011-01-14 Thread Dan Letkeman
So is there any way to increase the buffers without causing more damage? Or is this a hardware limitation? On Fri, Jan 14, 2011 at 3:54 PM, Gert Doering g...@greenie.muc.de wrote: Hi, On Fri, Jan 14, 2011 at 12:28:03PM -0600, Dan Letkeman wrote: 3560 or 3560G. Lame switches with too-small

Re: [c-nsp] 2821 NAT Limitations

2010-10-14 Thread Dan Letkeman
-- On 10/13/10 4:11 PM, Dan Letkeman wrote: Hi, Wondering if anyone has some experience with the NAT limitations on a 2821 router? I have about 1500 users, which about half of them are on the internet at one time, but we have a proxy web filter appliance that all of the clients connect

Re: [c-nsp] 2821 NAT Limitations

2010-10-14 Thread Dan Letkeman
...@zyedge.com wrote: Dan, -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Dan Letkeman Sent: Thursday, October 14, 2010 9:26 AM To: rod...@cisco.com Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] 2821 NAT Limitations

[c-nsp] 2821 NAT Limitations

2010-10-13 Thread Dan Letkeman
Hi, Wondering if anyone has some experience with the NAT limitations on a 2821 router? I have about 1500 users, which about half of them are on the internet at one time, but we have a proxy web filter appliance that all of the clients connect to that does a website lookup, and check before it

Re: [c-nsp] ios l2tp ipsec vpn help

2010-05-30 Thread Dan Letkeman
Aktas Sent: Sunday, May 30, 2010 9:50 AM To: 'Dan Letkeman Cc: 'cisco-nsp' Subject: Re: [c-nsp] ios l2tp ipsec vpn help Hi Dan, Have a look this simple example on CCO for configuring L2TP over IPSec. I guess your router should be configured as LAC for your clients and then initiate

[c-nsp] ios l2tp ipsec vpn help

2010-05-29 Thread Dan Letkeman
I'm struggling with getting a connection to our vpn service provider from our 2821 router. I would like to terminate the vpn on the router so I can route certain traffic through the vpn. Example info I got from our vpn provider is: address: vpn.provider.com username: user password: pass l2tp

[c-nsp] router as l2tp vpn client

2010-05-28 Thread Dan Letkeman
Hello, I'm wondering if anyone has a configuration example of how to make an l2tp vpn client connection from an ISR? There seems to be many options regarding vpdn, client-initiated, etc. I'm confused as to where to start. I have the connection information for the vpn server, that I have

Re: [c-nsp] Routing SSDP for Windows Desktops

2010-05-11 Thread Dan Letkeman
defaultish configured, it is localnet, which includes only the local subnet. Regards, dtb On 05/10/2010 09:06 PM, Dan Letkeman wrote: Thanks, that worked.  But I wonder if windows allows this?  I can now see the device, but it seems I have no access if i'm on a different subnet. Dan. On Sun

Re: [c-nsp] Routing SSDP for Windows Desktops

2010-05-10 Thread Dan Letkeman
Thanks, that worked. But I wonder if windows allows this? I can now see the device, but it seems I have no access if i'm on a different subnet. Dan. On Sun, May 9, 2010 at 11:43 PM, Anton Kapela tkap...@gmail.com wrote: On May 9, 2010, at 10:17 PM, Dan Letkeman wrote: Am I missing

[c-nsp] Routing SSDP for Windows Desktops

2010-05-09 Thread Dan Letkeman
Hello, I'm struggling with getting media device discovery on Windows 7 working across my network. I have enabled multicast routing PIM dense mode on the respective interfaces where the workstations are located, igmp snooping is enabled, the group 239.255.255.250 exists on all switches, and I

[c-nsp] Dynamic DNS updates to Local DNS Server

2009-06-16 Thread Dan Letkeman
Hello, I cannot seem to find any information or configuration examples of using a Cisco IOS DHCP server to update A records on a local dns server. I would like to have the router that is running dhcp update the records for a few windows workstation to a bind dns server. Any help would be

[c-nsp] 827 noise margin

2009-05-15 Thread Dan Letkeman
Hello, I have an 827 router that seems to have noise issue's after a while and i'm wondering if it is the device or the line? The noise margin drops down after a week or two of use. If I restart the router the noise margin is back up to about 7 dB. This is what is looks like after a week or two:

Re: [c-nsp] 3560 memory problem?

2009-05-11 Thread Dan Letkeman
Thanks! 2009/5/11 Lukasz Bromirski luk...@bromirski.net: On 2009-05-11 05:31, Dan Letkeman wrote: Hello, I just noticed this on one of our switches: cisco WS-C3560-24TS (PowerPC405) processor (revision E0) with 0K/8184K  12.2(44)SE Known bug: CSCsq70343. cisco WS-C3560-24TS (PowerPC405

[c-nsp] 3560 memory problem?

2009-05-10 Thread Dan Letkeman
Hello, I just noticed this on one of our switches: cisco WS-C3560-24TS (PowerPC405) processor (revision E0) with 0K/8184K bytes of memory. Processor board ID CAT1115RH2K Last reset from power-on 13 Virtual Ethernet interfaces 24 FastEthernet interfaces 2 Gigabit Ethernet interfaces The

[c-nsp] cef load sharing timeouts

2009-04-30 Thread Dan Letkeman
Hello, I have five 827 adsl routers in front of a 2821 for internet access. The 2821 is doing cef load sharing: ip cef load-sharing algorithm include-ports source destination Browsing the internet works great, but it seems like large downloads timeout often, but not all of the time. When i

[c-nsp] 2821 hardware compatibility

2009-04-19 Thread Dan Letkeman
Hello, I'm looking at putting in some WIC-1ADSL cards into a 2821 router. I would need to put in 6 of them, but the 2821 only has 4 onboard slots and I was wondering if the NM-2E2W is compatible with a 2821 router so I can add the last two? Thanks Dan.

[c-nsp] passive ftp static nat

2009-04-10 Thread Dan Letkeman
Hello, I'm having trouble logging into our ftp server from an external source. It works when you set the client to active mode, but passive mode always hangs. 2821, IOS Firewall Relevant config: ip inspect name SDM_LOW ftp interface GigabitEthernet0/0 ip address 10.10.10.1 255.255.255.252

Re: [c-nsp] aironet disable ssid when no lan connection

2009-04-04 Thread Dan Letkeman
I think the shutdown command would work. Thanks! On Fri, Apr 3, 2009 at 11:30 PM, Matthew Huff mh...@ox.com wrote: Will station-role root access-point fallback track fa 0  under the radio interface work for you? On 4/3/09 9:10 PM, Dan Letkeman danletke...@gmail.com wrote: Hello

[c-nsp] aironet disable ssid when no lan connection

2009-04-03 Thread Dan Letkeman
Hello, Is there a command on an 1131ag aironet ap that allows you to disable the ssid broadcast if there is no lan connection to the ap? Thanks, Dan. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

[c-nsp] multiple wic-1adsl

2009-03-27 Thread Dan Letkeman
Hello, I'm wondering if there is a low cost router that could handle six wic-1adsl cards? I'm looking at replacing six cisco 827 routers (connected to dsl) that are sitting in-front of another router which is doing cef load sharing between the six 827's users---cef load sharing router

[c-nsp] vpn configuration

2009-03-25 Thread Dan Letkeman
Hello, I have the need to create a vpn between two routers. R2 is behind R1 which is doing nat, and R3 has an interface with a public ip. R3 has to initiate the vpn connection because it has a dynamic public ip. I also need to be able to run ospf across the vpn and monitor the vpn traffic.

[c-nsp] ip dns server load information

2009-02-17 Thread Dan Letkeman
Hello, I'm interested in using a cisco router as a DNS server and I was wondering if anyone has real world experience or documentation that could inform me as to how many users/clients could one router handle if it were the primary dns server. Also, i'm wondering if there is a way to have a

Re: [c-nsp] HWIC-4ESW

2008-11-19 Thread Dan Letkeman
It was a while ago, but If I remember correctly, it did not work on the hwic, only on the integrated ports. You could pickup a cheap 827 or 837 router on ebay to do the pppoe. Dan. On Wed, Nov 19, 2008 at 11:36 AM, Peter Chuba [EMAIL PROTECTED] wrote: Hi, I've got a 2801 whose built-in ports

[c-nsp] route problem

2008-11-17 Thread Dan Letkeman
Hello, I have setup a guest vlan for internet access. When the users connect to the guest network they get only internet access and no access to any of the servers on the rest of the network. The problem I'm having now is that the users on the guest network cannot access our internal web

Re: [c-nsp] route problem

2008-11-17 Thread Dan Letkeman
? Go to next hop...etc.. Rodney On Mon, Nov 17, 2008 at 05:05:42PM -0600, Dan Letkeman wrote: Hello, I have setup a guest vlan for internet access. When the users connect to the guest network they get only internet access and no access to any of the servers on the rest of the network

[c-nsp] routing email domain

2008-11-16 Thread Dan Letkeman
Hello, Is there any way to route different email traffic by each domain name? eg: make email from @domain1.com go out route 1.1.1.1 and email from @domain2.com go out route 2.2.2.2 All of this email traffic is coming from the same email server. Dan.

[c-nsp] ips usbflash

2008-11-08 Thread Dan Letkeman
Hello, I have configured IPS on a 2821 running the firewall ios. I have the configuration and signature files on a usbflash card. It all works fine until the router reloads, then the usbflash does not mount. Is there a command load it? If I do a show usb device 1 it show the device, and all

Re: [c-nsp] ips usbflash

2008-11-08 Thread Dan Letkeman
configured right? also how did you copy the sigs to the usb drive, from a pc? or ftp through the router? On Sat, Nov 8, 2008 at 8:04 PM, Dan Letkeman [EMAIL PROTECTED] wrote: As far as I know yes. ip ips config location usbflash1:/ retries 5 timeout 10 Dan. On Sat, Nov 8, 2008 at 6:56 PM

[c-nsp] 1131ag vs 521

2008-10-12 Thread Dan Letkeman
Hello, I'm wondering what the main differences between an 1131ag access point and a 521 express access point is? I know the 1131ag has a 5ghz card in it and supports telnet. Are there any other differences between the two? I'm interested in buying about 15-20 access points for one building.

[c-nsp] load-sharing round robin time?

2008-09-11 Thread Dan Letkeman
Hello, I'm doing load-sharing on a 2621 router with ios 12.3(26). ip route 0.0.0.0 0.0.0.0 192.168.11.251 ip route 0.0.0.0 0.0.0.0 192.168.11.252 ip route 0.0.0.0 0.0.0.0 192.168.11.253 This was working just fine, but now we implemented a squid cache just behind the router and it strips the

Re: [c-nsp] load-sharing round robin time?

2008-09-11 Thread Dan Letkeman
, then the squid box will actually route directly to one of the gateways, rather than through the 2621... Not sure how your environment is build - Maybe a routing table and some other interface configs would help? Dan Letkeman wrote: Hello, I'm doing load-sharing on a 2621 router with ios 12.3(26

[c-nsp] Recommended 2800 ISR

2008-09-04 Thread Dan Letkeman
I was wondering if anyone has recommendations for a 2800 series router for a 20-30mbit internet connection. I would like to run a firewall IOS and, nat and basic ACL's. Would a 2811 be an appropriate choice? Thanks, Dan. ___ cisco-nsp mailing list

Re: [c-nsp] Recommended 2800 ISR

2008-09-04 Thread Dan Letkeman
I have read that document before, do those numbers (2811 - 61.44mpbs CEF Fast switching) mean that it can process that bandwidth with nothing else running on the router? On Thu, Sep 4, 2008 at 7:43 PM, GIULIANO (UOL) [EMAIL PROTECTED] wrote: Dan, Yes. It is a good choice. Take a look:

Re: [c-nsp] 827 nat translations

2008-08-31 Thread Dan Letkeman
Is there a way that you can off load the NAT to a router instead of the 827 handling it? On Sat, Aug 30, 2008 at 9:29 PM, Adrian Chadd [EMAIL PROTECTED] wrote: On Sat, Aug 30, 2008, Dan Letkeman wrote: I'm currently running a 2621 just behind the 827(s) which is doing CEF load distribution. I

Re: [c-nsp] 827 nat translations

2008-08-30 Thread Dan Letkeman
connecting via 827's or whatever else works best. Any suggestions would be appreciated. Thanks, Dan. On Sat, Aug 30, 2008 at 12:10 AM, Adrian Chadd [EMAIL PROTECTED] wrote: On Fri, Aug 29, 2008, Dan Letkeman wrote: How many nat translations could an 827 router handle? This is for a school

[c-nsp] 827 nat translations

2008-08-29 Thread Dan Letkeman
How many nat translations could an 827 router handle? This is for a school environment where there are about 300 workstations (assuming that not everyone would be browsing at once) and a 7mbit internet connection. Could this router handle this kind of load? Is there anything I could do to take

Re: [c-nsp] route availability

2008-08-25 Thread Dan Letkeman
: http://www.cisco.com/en/US/docs/ios/ipapp/configuration/guide/ipapp_eot. html Arie -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dan Letkeman Sent: Sunday, August 24, 2008 07:27 AM To: cisco-nsp@puck.nether.net Subject: [c-nsp] route

[c-nsp] route availability

2008-08-23 Thread Dan Letkeman
Hello, I currently have a four default routes on a 2621 router that is doing load balancing to four adsl modems/routers (which are doing NAT). ip cef ip route 0.0.0.0 0.0.0.0 192.168.11.251 ip route 0.0.0.0 0.0.0.0 192.168.11.252 ip route 0.0.0.0 0.0.0.0 192.168.11.253 ip route 0.0.0.0 0.0.0.0

Re: [c-nsp] ip cef load sharing

2008-08-18 Thread Dan Letkeman
-packet is if you get another IP routed down all 3 adsl lines and put it on a loopback and NAT everything against that. Ben - Original Message - From: Dan Letkeman [EMAIL PROTECTED] To: Rodney Dunn [EMAIL PROTECTED]; cisco-nsp@puck.nether.net Sent: Saturday, August 16, 2008 3:29 AM

[c-nsp] content filter placement in data center

2008-08-17 Thread Dan Letkeman
Hello, I have a few questions regarding content filter placement and routing in the data center. I would like to place our content/spyware/web filter in our data center, but I would like to place it in such a way that if it fails or has problems that it does not take everything down. Currently

Re: [c-nsp] content filter placement in data center

2008-08-17 Thread Dan Letkeman
|| - Thanks, Dan. On Sun, Aug 17, 2008 at 6:17 PM, Adrian Chadd [EMAIL PROTECTED] wrote: On Sun, Aug 17, 2008, Dan Letkeman wrote: Is there a way to connect it to the router and use policy routing, and the verify availability option so that if the content filter is down the system still works

[c-nsp] ip cef load sharing

2008-08-15 Thread Dan Letkeman
Hello, I have a 2621 router running 12.3(26) and I would like to setup load sharing to multiple adsl lines. When I do a traceroute on the router it randomly picks a dsl line and seems to work fine. But when I do traceroute tests from a workstation it always seems to take the same adsl line. Is

Re: [c-nsp] ip cef load sharing

2008-08-15 Thread Dan Letkeman
15, 2008 at 12:12 PM, Rodney Dunn [EMAIL PROTECTED] wrote: Try ip load-sharing per-packet on both egress interfaces. On Fri, Aug 15, 2008 at 12:00:46PM -0500, Dan Letkeman wrote: Hello, I have a 2621 router running 12.3(26) and I would like to setup load sharing to multiple adsl lines. When

Re: [c-nsp] ip cef load sharing

2008-08-15 Thread Dan Letkeman
, Aug 15, 2008 at 12:49 PM, Rodney Dunn [EMAIL PROTECTED] wrote: On Fri, Aug 15, 2008 at 12:35:01PM -0500, Dan Letkeman wrote: ip load-sharing per-packet I tried adding this to F0/1 and the trace route works now(it randomly picks either line), but there seems to be issues with maybe the MTU

[c-nsp] best way to load share adsl

2008-08-14 Thread Dan Letkeman
Hello, I would like to setup load sharing on a 2621 for three adsl lines. Currently each of the adsl connections has a modem/router combo which is doing nat. All I need for the cisco router to do is load sharing or load balancing. What would be the best way to do this and could anyone recommend

[c-nsp] shaping http traffic on a 2821

2008-08-05 Thread Dan Letkeman
Hello, I'm wondering if anyone has some good documentation or examples of shaping http traffic on a router. I have been ask to look into this for an educational institute where they don't want to add more bandwidth, but make better use of what they have. The connection is currently a 20mbit

[c-nsp] route-map local destination device

2008-07-24 Thread Dan Letkeman
Hello, I have a router that is doing some route-map's for various destinations. On the fa0/0 port I have ip policy route-map inet and the route-map's are done like this route-map inet permit 10 match ip address 111 set ip next-hop 187.174.55.2 ! route-map inet permit 40 match ip address 222

Re: [c-nsp] combining multiple dsl lines

2008-07-23 Thread Dan Letkeman
balancing or ppp multlink could. Another option worth throwing in is the use of ip sla on your routes so as to remove them from the equation should one link go down, can also be done with the route-map using verify-availability on the next-hop option. Ben On 23/07/2008, at 1:39 PM, Dan Letkeman

Re: [c-nsp] combining multiple dsl lines

2008-07-23 Thread Dan Letkeman
a back up path, no point forcing traffic down a dsl line that has died. http://www.cisco.com/en/US/docs/ios/12_3t/12_3t4/feature/guide/gtpbrtrk.html - Original Message - From: Dan Letkeman [EMAIL PROTECTED] To: Ben Steele [EMAIL PROTECTED]; cisco-nsp@puck.nether.net Sent: Thursday

[c-nsp] combining multiple dsl lines

2008-07-22 Thread Dan Letkeman
I have a customer that is wanting to combine 4 adsl connection through one router. In the past I have setup systems where I have taken groups of ip's from the internal network and have route-map'd them to different adsl connections. Is there a way to combine the dsl connections or is using

[c-nsp] 7961G won't boot

2008-07-21 Thread Dan Letkeman
Hello, I have a 7961G that won't boot up. It powers on via poe, shows the cisco splash screen with the checkmark in the bottom left corner, then shows the upgrading screen for a few seconds, then says error on the upgrading screen, then goes back to the cisco splash screen and there is a circle

[c-nsp] preventing unwanted devices on the network

2008-05-31 Thread Dan Letkeman
Hello, I'm looking for the best way to prevent unwanted wireless routers or other unwanted bridging devices on a network. For example a wireless router with the wan port plugged in to the network or a router in bridging mode with dhcp off. From other posts I have read about using dhcp snooping.

Re: [c-nsp] preventing unwanted devices on the network

2008-05-31 Thread Dan Letkeman
Thanks for this info. I will look into this some more, but I think there should be some stuff here that should help me. On Sat, May 31, 2008 at 4:43 PM, [EMAIL PROTECTED] wrote: Hi, Also I would like to prevent unwanted static ip addresses on this network as well. My current setup is a

[c-nsp] blocking skype traffic

2008-05-30 Thread Dan Letkeman
Hello, Is there anyway to block skype traffic with the cisco firewall IOS? Thanks, Dan. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] 1131ag input and crc errors

2008-05-18 Thread Dan Letkeman
Hello, I have an 1131ag that has a lot of input and crc errors on both the wlan interface and the ethernet interface. It seems to be an on going thing, it has the latest ios, and is connected to an edge switch which is connected to the core switch. All other traffic seems to be fine on that

Re: [c-nsp] 2801 - can it handle this?

2008-05-04 Thread Dan Letkeman
set in 12.4. most sincerely, Richard -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dan Letkeman Sent: Sunday, May 04, 2008 12:36 AM To: cisco-nsp@puck.nether.net Subject: [c-nsp] 2801 - can it handle this? Hello, I have a 2801

[c-nsp] 2801 - can it handle this?

2008-05-03 Thread Dan Letkeman
Hello, I have a 2801 router with the firewall IOS. I have a 10mbit connection to the internet. There will be anywhere from 100-300 users using this router for browsing the internet at one time. I will be running ips and some security acl's. No voip, maybe one or two video connections. Will

[c-nsp] nat for video call

2008-04-28 Thread Dan Letkeman
Hello, I was wondering if anyone has used a cisco router in place of a device like this? http://www.polycom.com/usa/en/products/video/security_firewall_traversal/vbp_4350t_series.html I have the need to do nat/firewall traversal and I was hoping that my 2800 series router could do that.

Re: [c-nsp] 2801 bandwidth limiting

2008-04-25 Thread Dan Letkeman
the same set of QoS features as the regular L3 interfaces, so you can't shape on these ports. Can you move your uplink to one of the built-in FE ports instead? oli Dan Letkeman wrote on Friday, April 25, 2008 2:37 AM: Luan, I have tried this, but it doesn't seem to take

Re: [c-nsp] 2801 bandwidth limiting

2008-04-25 Thread Dan Letkeman
-normal and burst-max and I can't check it easily since I'm using a phone. That may work for you though. CAR is simple and works but it's not as elegant or feature-rich as its more complicated class-based kin. Justin Dan Letkeman wrote: That's kind of what I thought. I will be able

[c-nsp] 2801 bandwidth limiting

2008-04-24 Thread Dan Letkeman
Hello, We have changed our internet connection over from 4 dsl lines to one connection. We have a 25mbit connection provided by a neighboring company and we have an agreement with them that we will only use 10mbit bursting to 12 or 13mbit. What would I need to do on our 2801 to limit our

Re: [c-nsp] 2801 bandwidth limiting

2008-04-24 Thread Dan Letkeman
Joe, I tried using the shape command under the policy-map but it doesn't seem to take effect. When I use the police command it does take effect. Any ideas? On Thu, Apr 24, 2008 at 4:35 PM, Joe Maimon [EMAIL PROTECTED] wrote: shaping Dan Letkeman wrote: Hello, We have changed

  1   2   >