Re: [c-nsp] Multicast

2013-04-15 Thread David Barak
I've seen that before when the RPF interface is one where PIM is not enabled. Have you double checked to make sure that PIM is up, working, and has neighbors on all of the interfaces (don't forget loopbacks)? David Barak Sent from a mobile device, please forgive autocorrection. On Apr 15

Re: [c-nsp] MPLS VPN over mGRE

2013-01-30 Thread David Barak
Last I checked ISIS didn#39;t work over mgre interfaces and you#39;d need to use OSPF. This might be code-dependent. David Barak ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http

Re: [c-nsp] *** GMX Spamverdacht *** RE: IPSEC over NAT - what am I missing?

2013-01-26 Thread David Barak
for a small number of people to be preserved. David Barak Sent from a mobile device, please forgive autocorrection. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail

Re: [c-nsp] IOS auto mapping?

2013-01-22 Thread David Barak
, but the reports and maps are pretty readable. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http

Re: [c-nsp] Rationale for ISIS default origination behavior

2013-01-21 Thread David Barak
don't need to have many areas. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net

Re: [c-nsp] CA Server vs Key Server (GetVPN)

2012-12-11 Thread David Barak
the functionality of this. Certificates are orthogonal to the KS functionality of GDOI (GetVPN), but you need the KS to be on-line, while generally you'll want an off-line CA, so you're probably better keeping those separate.  I've had great success with GDOI.  David Barak Need Geek Rock

Re: [c-nsp] MPLS TE conver from IOS to IOS-XR

2012-02-27 Thread David Barak
BFD is great stuff. Is there any chance of getting BFD on the 45k platform? David Barak (apologies for the mobile-device-style top post) ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive

[c-nsp] 45k BFD

2012-01-31 Thread David Barak
Hi all,   I know that the 4500 Sup 6E doesn't support BFD right now.  Does anyone know whether this is a roadmapped feature, or is that never going to be supported? David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com

Re: [c-nsp] How to effect a totally stubby area in IS-IS

2011-06-24 Thread David Barak
to figure out some good boundaries. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http

Re: [c-nsp] How to effect a totally stubby area in IS-IS

2011-06-23 Thread David Barak
hierarchy, then the backbone itself are the L1/L2 routers (but each one is in a different area). If you have a three-layer hierarchy, then L1/L2 belongs in the middle. Hope that helps, David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com

Re: [c-nsp] How to effect a totally stubby area in IS-IS

2011-06-23 Thread David Barak
defaults. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] How to effect a totally stubby area in IS-IS

2011-06-23 Thread David Barak
, but that can be expensive depending on the platform. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive

Re: [c-nsp] Small network Route Reflectors?

2011-03-15 Thread David Barak
-family is not supported on many images. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http

Re: [c-nsp] which one is ugly

2010-12-11 Thread David Barak
I use both and you can even use the former as an unnumbered interface source. Both work fine. David (sorry about the top post; mobile device) ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] Need help with setting up ip multicastrouting

2010-10-13 Thread David Barak
There is a document on cisco#39;s site regarding how IGMP snooping breaks multicast in typical LAN environments. I don#39;t have the link handy, but it should be googleable. Effectively, the issue is that the switches do not have a way to properly identify the mrouter port, and end up cutting

Re: [c-nsp] Need help with setting up ip multicast routing...correction

2010-10-08 Thread David Barak
that matches the RP-address. There's a lot more to optimization and troubleshooting, but that should provide initial connectivity. Some good tutorials on the subject can be found at http://nanog.org/resources/tutorials/ David Barak Need Geek Rock? Try The Franchise: http

Re: [c-nsp] BGP to OSPF redistribution

2010-01-13 Thread David Barak
passwords doens't hurt either :) Why not just use site-to-site BGP across the VPLS provider instead of OSPF?  A simple prepend will make sure that the AS_PATHs work out right, and then all of the ickiness which is redistribution can be avoided.   David Barak Need Geek Rock? Try The Franchise

Re: [c-nsp] Finding the serial numbers of cisco devices

2010-01-07 Thread David Barak
it in (using snmp-server chassis-id or the like).  Other than that, the automated tools are definitely the way to go. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com ___ cisco-nsp mailing list cisco-nsp

Re: [c-nsp] Controllers for a VWIC2-1MFT-T1/E1

2009-12-15 Thread David Barak
you're missing the command card type t1 0 0 Until you do that, the router doesn't know whether it's a T1 or an E1.  David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com - Original Message From: james edwards lists.james.edwa...@gmail.com To: cisco-nsp

Re: [c-nsp] c7200, only one IP configured, seeing 2 as connected

2009-11-16 Thread David Barak
will modify the PPP behavior. -David Barak Roger Wiklund wrote: Hi I have a strange problem. I have a Serial interface with one /30 IP configure as a link network between PE and CE. interface Serial1/0 description MPLS Circuit bandwidth 34368 ip address 206.115.103.122 255.255.255.252 ip

Re: [c-nsp] interfaces flapping QinQ and/or spanning tree

2009-09-01 Thread David Barak
the servers in-situ or to maintain a list of allocated virtual MAC addresses and watch for duplicates. Good luck, David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com - Original Message From: Bruno Filipe brun0_fil...@yahoo.com To: cisco-nsp

Re: [c-nsp] TACACS/RADUIS/AD

2009-08-09 Thread David Barak
of the non-Cisco implementations of TACACS+. -David Barak Ziv Leyes wrote: Hi all, I'm in need to implement an AAA method other than local for our Cisco devices (routers/switches) I was thinking of using the already existing Active Directory, because all people has an account

Re: [c-nsp] Humor: Cisco announces end of BGP

2009-07-28 Thread David Barak
ODR perhaps? Or maybe OER (that#39;s one letter higher anyway...) ;) -David Hank Nussbacher wrote: I just got this product alert from Cisco: From: cisconotificationserv...@cisco.com To: h...@efes.iucc.ac.il Subject: Cisco Notification Alert -Alerts_Daily-07/28/2009 07:38 GMT Cisco

Re: [c-nsp] BGP Multihomed Selective/Conditional Advertisement

2008-10-28 Thread David Barak
deterministic. Prepending toward cogent is a good idea to increase the likelihood of deterministic behavior. -David Barak Nathan wrote: On Mon, Oct 27, 2008 at 11:56 PM, [EMAIL PROTECTED] wrote: So what would be the behavior if I set the community for Cogent to set the Local Preference

Re: [c-nsp] problem with serial number on cisco 7200 routers /maintenance contract

2008-10-03 Thread David Barak
I can confirm that this appears to be true of NPE-G2s as well. David Barak Daniel Roesen wrote: On Thu, Oct 02, 2008 at 07:15:19PM -0700, Irfan Siddiqui wrote: I don't think this is possible on 720X you have to read it of of chassis Indeed. We resorted to configure the chassis sticker ID

Re: [c-nsp] a multicast problem

2008-08-12 Thread David Barak
Have you taken a look at this Cisco notice: http://www.cisco.com/application/pdf/paws/68131/cat_multicast_prob.pdf and mitigated the IGMP snooping problem? David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com --- On Tue, 8/12/08, 田云生 [EMAIL PROTECTED] wrote

Re: [c-nsp] Peoples experiences with the 3825

2008-06-26 Thread David Barak
I don#39;t have the link in front of me, but I remember a document describing the 3825 as working well for a partial DS3, and the 3845 as working for a full DS3. Also, the ESW modules have some definite quirks, so check to make sure that all of your features work before deploying them. -David

Re: [c-nsp] Setting weight on import into vrf

2008-06-04 Thread David Barak
is next in the algorithm, and it should do what you want. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp

Re: [c-nsp] Catalyst 3750 failure - marsupial interference

2008-04-02 Thread David Barak
of the interfaces can have their Marsupial Transmission Unit value changed and some cannot. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com You rock. That's why

Re: [c-nsp] Router security defaults (WAS RE: Proxy ARP -- To disable, or not to disable..)

2008-03-24 Thread David Barak
. I haven#39;t looked lately, so hopefully that behavior has changed. -David Barak Justin Shore wrote: hostname host ip domain-name domain.tld crypto key generate rsa modulus 2048 ! ip ssh time-out 60 ip ssh version 2 ip ssh authentication-retries 3 ! service nagle no service pad

Re: [c-nsp] Loopback Advertise in OSPF

2008-02-27 Thread David Barak
Hi, I believe the initial poster was talking about normal loopbacks- ther kind you#39;d use for network management, ibgp peering, or perhaps anycast. In that case, you needn#39;t be worried about spf churn, because they#39;re yours, and not going down, and you would want the routes generated

Re: [c-nsp] Loopback Advertise in OSPF

2008-02-27 Thread David Barak
Hi, I believe the initial poster was talking about normal loopbacks- ther kind you#39;d use for network management, ibgp peering, or perhaps anycast. In that case, you needn#39;t be worried about spf churn, because they#39;re yours, and not going down, and you would want the routes generated

Re: [c-nsp] DMVPN single cloud with resiliency

2008-01-16 Thread David Barak
of your remote sites to prefer a single path, go with dual-hub. David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com --- On Wed, 1/16/08, Luan Nguyen [EMAIL PROTECTED] wrote: From: Luan Nguyen [EMAIL PROTECTED] Subject: [c-nsp] DMVPN single cloud with resiliency

Re: [c-nsp] DMVPN with OSPF

2007-06-19 Thread David Barak
domain, and you'll get into number of routers in a single area limits. Make sure that the crypto you're using is hardware-based. I've personally used it up to about 60 sites. -David Barak David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com

Re: [c-nsp] Crypto and CEF

2007-06-12 Thread David Barak
cases where it's a good idea, but I agree: in general it'd be better to use connected rather than static routing for a LAN. -David Barak David Barak Need Geek Rock? Try The Franchise: http://www.listentothefranchise.com