Re: [c-nsp] blackholed traffic on ether-channel

2016-04-07 Thread Holemans Wim
Just bought several C6880-X to replace some 6500 with Sup32. They will have a lot of LACP channels... Tried to search for the bug numbers mentioned below, the first one came back as not cisco inside only, the second one comes with an information page with the title :

[c-nsp] nexus 5548 versus C4900M

2012-11-21 Thread Holemans Wim
We have a service cluster build around a C4900M : it concentrates a mix of 10G (intercampus) connections and 1G connections (some backup lines and central services such as DNS, VPN servers,...) This works fine but to be able to connect all these, I had to add the 20 port 10/100/1000 UTP card

[c-nsp] nexus material and coloured CWDM 10G SFP+

2011-09-09 Thread Holemans Wim
Recently we started using CWDM coloured 10G SFP+ interfaces (smartoptics) on our campus network (in 4900M with OneX convertors). This works just fine although Cisco probably will tell us that is not supported... I'm wondering if someone already did the same thing on nexus 5xxx switches,

[c-nsp] changing buffer size on 4900M - discards

2011-07-27 Thread Holemans Wim
We are seeing discards on a newly installed 4900M, probably coming from the fact that most input to the C4900M is coming from routers connected to it on 10G lines and is going out on a 2G etherchannel, although the total load on the 2G channel is just about 250-300 Mb/s. The 2G connection goes

[c-nsp] 3750E cluster replacement

2011-07-26 Thread Holemans Wim
We have a network based on a VSS with 20G channels to 3750E-24 clusters top-of-rack. We are seeing a lot of discards on the cluster which connects to our NetApp SANs. I suspect this is because of the small buffers in the 3750E switches and the growth of our traffic to the SAN, especially ISCI

Re: [c-nsp] 3750E cluster replacement

2011-07-26 Thread Holemans Wim
Netwerkdienst Universiteit Antwerpen Network Services University of Antwerp From: chandler.bass...@gmail.com [mailto:chandler.bass...@gmail.com] On Behalf Of Chandler Bassett Sent: dinsdag 26 juli 2011 13:14 To: Holemans Wim Cc: cisco-nsp Subject: Re: [c-nsp] 3750E cluster replacement Why's

Re: [c-nsp] 3750E cluster replacement

2011-07-26 Thread Holemans Wim
...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Martin Barry Sent: dinsdag 26 juli 2011 14:12 To: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] 3750E cluster replacement $quoted_author = Holemans Wim ; We use clusters to protect us from hardware failures ; all servers and SAN

Re: [c-nsp] OT: Console cables on new platforms

2011-06-28 Thread Holemans Wim
Nothing comes free with Cisco (unless this changed since we got our latest copy of the GPL in feb) : CAB-CONSOLE-USB=Console Cable 6 ft with USB Type A and mini-B 30,00$ CAB-CONSOLE-RJ45Console Cable 6ft with RJ45 and DB9F 30,00$ CAB-CONSOLE-USB Console Cable 6 ft with

[c-nsp] cpu spike every minute

2011-01-11 Thread Holemans Wim
We are seeing a cpu spike (and corresponding icmp respons latency) every minute on one of our 65XX. It is a 6506-E with Sup32-8G running IOS version ipbasek9-vz.122-18.SXF6. I checked al our mgmt processes (snmp requests, arp table copies,...) but found nothing that could lead to this

[c-nsp] 10G for 6506-E with Sup32-8Gb or replace with 4900M

2010-12-23 Thread Holemans Wim
We have 3 campus with on each campus a 6506-E/Sup720-10G as 'master router' and a 6506/E-Sup32-8gbit as backup router, in a HSRP config. In each router we also have GBIC boards to connect the different buildings. These Sup32 routers also act as L2 concentrator for part of each campus. Now we

Re: [c-nsp] Strange problem with Cat6500 freeze

2010-12-14 Thread Holemans Wim
Not exactly the same but we had an 'automatic' reboot on a Sup720 and Sup32 during a broadcast storm after upgrading tot SXI4a. Before the upgrade the machine kept running (unresponsive but running) until the cause of the broadcast storm was removed. Something seems to have changed in SXI4a

[c-nsp] 6506-E module provisioning

2010-06-17 Thread Holemans Wim
I've been searching the cisco website for this but didn't find an answer. We have a new 6506-E to replace an old one, and I'll have to move some modules between them as we don't have spare ones. Is there a way to 'provision' these modules in the config of the new router so I can just copy the

Re: [c-nsp] 3750-E + CVR-X2-SFP10G + SFP-10G-SR = disappearing media

2010-05-11 Thread Holemans Wim
We have a similar setup but with X2 interfaces, so no X2 to SFP+ convertors and that works just fine. Have you checked the transceiver parameters ? Maybe they are not within limit causing a shutdown of the interface ? (temperature, input power, output power). The first batch of (non-cisco) X2

[c-nsp] best ios version for VSS

2010-01-27 Thread Holemans Wim
We have a VSS running, L2 only for the moment. We plan to enable L3 (static routing only for the moment) next week (along with a FWSM board in each chassis). We are running version s72033-advipservicesk9_wan-mz.122-33.SXI1.bin for the moment (I know this version has too much features for what we

Re: [c-nsp] FWSM logging problem

2009-12-17 Thread Holemans Wim
-max 4096) I'll have to live with this until I can upgrade. Wim -Original Message- From: Andrew Yourtchenko [mailto:ayour...@cisco.com] Sent: woensdag 16 december 2009 19:35 To: Holemans Wim Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] FWSM logging problem On Wed, 16 Dec 2009

[c-nsp] FWSM logging problem

2009-12-16 Thread Holemans Wim
It seems our FWSM doesn't log all denied ACLs. I blocked an IP address on our FWSM and wanted to see whomever on campus is trying to access this address (Botnet CC). I added the following line in the ACL (even raised priority), you can see that the rules triggers when I tried to telnet the

Re: [c-nsp] 3750G vs. Nexus for a SAN

2009-11-12 Thread Holemans Wim
What version of IOS does it run ? Base version or lite version ? Wim Holemans Network Services University of Antwerp -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Jim McBurnett Sent: vrijdag 13 november 2009 5:17 To:

[c-nsp] STP and RSTP interaction

2009-09-24 Thread Holemans Wim
Until now we used standard STP in our network with changed diameter parameters (diameters of 10,11,..) We plan to migrate to RSTP and as far as I tell from reading about it, this should be no problem if we start changing from the outside into the core. I now have to add a new part to our network

[c-nsp] 2801 as console server

2009-09-16 Thread Holemans Wim
I've been looking through the Cisco doc but didn't found what I was looking for, therefor this question : I transformed a 2801 router which we used as a dialin server to a console server. The config seems to work, I can do a telnet xxx 2018 to get access to serial port 0/1/1, also ssh -l

Re: [c-nsp] ASA 5505 stops servicing inbound connections

2009-08-11 Thread Holemans Wim
Look in the log files for the following error : 160Aug 01 2009 15:29:49: %ASA-0-716528: Unexpected fiber scheduler error; possible out-of-memory condition This kills our asa's (running version 8) on a regular basis (once a month), reload is the only way to resolve this. We have a case open for

Re: [c-nsp] VSS out-of-band mgmt

2009-07-14 Thread Holemans Wim
on this list. Wim Holemans -Original Message- From: Alasdair McWilliam [mailto:alasda...@gmail.com] Sent: dinsdag 14 juli 2009 19:33 To: Buhrmaster, Gary Cc: Holemans Wim; Cisco NSP Subject: Re: [c-nsp] VSS out-of-band mgmt We have VSS deployed and it's management interface is on a mgmt

Re: [c-nsp] VSS out-of-band mgmt

2009-07-14 Thread Holemans Wim
: Holemans Wim; Cisco NSP Subject: Re: [c-nsp] VSS out-of-band mgmt We have VSS deployed and it's management interface is on a mgmt-vrf. So far everything that needs a source interface seems to work, although I've not actually configured syslog yet, TACACS is now vrf aware. You have to define

[c-nsp] VSS out-of-band mgmt

2009-07-13 Thread Holemans Wim
I have a VSS router that I want to do some out-of-band mgmt with. Is this possible with VRF-lite ? I would like to build a channel with the UTP ports on the sup720, give the VSS an address on this trunk but keep this interface out of the standard routing table. Can this be done with VRF-lite ? Or

[c-nsp] network simulator

2009-05-18 Thread Holemans Wim
I'm looking for a (free) network simulator that allows me to simulate a small network (20 switches) with different vlans on it. I want to test different scenario's : what happens if this switch goes down or that link goes down, how do the packets flow in each scenario for the different vlans...

Re: [c-nsp] network simulator

2009-05-18 Thread Holemans Wim
Just found out through google, will give it a try tomorrow. Thanks, Wim Holemans From: Michal Prazenka [mailto:michal.praze...@gtsce.com] Sent: maandag 18 mei 2009 19:35 To: Holemans Wim Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] network

[c-nsp] VSS upgrade problems

2009-02-04 Thread Holemans Wim
I'm testing a VSS solution for our campus network, most things seem to work as expected. I ran however into problems when testing the eFSU upgrade procedure. The system came with ip base 12.33SXH4 on, I created the cluster with this version without problem (although the notes state that you

Re: [c-nsp] upgrading stack of 3750E's

2009-01-27 Thread Holemans Wim
(I'm the one who posted the original question). Just tested it again with a second stack of 3750E's ; this gave the same result : Upgrading from 12.2.2(35) to 12.2.(46) and reload of second switch gave a Version Mismatch with left the second switch hanging. Only a reload of the master restored

[c-nsp] upgrading stack of 3750E's

2009-01-26 Thread Holemans Wim
We are testing the following setup : 65XX-VSS - etherchannel - 3750E stack (2 switches) - teaming enabled servers This should give maximal uptime, overriding defects on the router or 3750E switches. We intend to use these switches in L2 mode only, managing them via the mgmt fa0 interface.

[c-nsp] Virtual Routers

2008-11-17 Thread Holemans Wim
Is there a way to divide a 6500 into multiple 'Virtual Routers' with different routing tables ? I've read about VRF-Lite but it is always mentioned in a VPN environment with remote and central devices. I need to get some traffic into a FWSM on a 6500, out of the 6500 to an IPS and back into the

Re: [c-nsp] Catalyst 3750 stacks with many members

2008-11-17 Thread Holemans Wim
Got some personal mails all in support of the stacking, saw only negative mails on the list, interesting... Price difference between 2x 3750 and a 6504 is not so small and a 6504 with one supervisor is still a single point of failure where a cluster of 2 switches would give me redundancy.

Re: [c-nsp] Catalyst 3750 stacks with many members

2008-11-16 Thread Holemans Wim
Could you/someone elaborate on 'failure of one part is a failure of the stack' ? I thought Cisco just pushed this construction to get more redundancy/uptime in the network ? We were planning to replace some single switches with a lot of dual-line channels with a cluster of 2 of these 36xx or

[c-nsp] rtr responder on 6500

2008-10-20 Thread Holemans Wim
We are setting up a testbed for IP SLA monitoring and I wanted to include our core 6500 switches into the test. For 2 of them this went without problem, on two others this doesn't work : I get the following error (after putting on debug) : RTR unable to set SO_STRICT_ADDR_BIND option I

[c-nsp] FWSM convertion

2008-10-01 Thread Holemans Wim
Anyone has a good reference on the steps to take to convert a standalone FWSM to the primary of a FAILOVER FWSM pair. Current FWSM is running 3.2.8 and has 2 transparent contexts. Are there any steps that will influence the current running FWSM (take it down or so) ? Thanks, Wim

[c-nsp] FWSM failover transparent mode

2008-09-05 Thread Holemans Wim
Just upgraded our FWSM to version 3.1.11 after 3 random crashes in a month. Now we are thinking about buying a second FWSM to do failover in order to limit downtime and facilitate upgrades : most of our servers are connected to the 6513 carrying this FWSM. We use the 2 standard virtual contexts

Re: [c-nsp] FWSM failover transparent mode

2008-09-05 Thread Holemans Wim
] Sent: vrijdag 5 september 2008 18:59 To: Holemans Wim Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] FWSM failover transparent mode Not to hijack this thread, but what modules are you using for server connectivity in your 6513? We deployed some 6513s as SF switches long ago (bad decision

Re: [c-nsp] 6509 ACE/FWSM Modules??????????

2008-07-31 Thread Holemans Wim
Can someone clarify the PAGP problem ? I had a discussion with someone of Cisco for a new design in one of our datarooms and we had chosen a VSS solution with dual 3750E stacks and 20Gig uplinks in each rack to the VSS chassis for max redundantie. According to our Cisco contact, this was a working

[c-nsp] Cisco vulnerabilities

2008-05-12 Thread Holemans Wim
I got this via Qualys but haven't seen it on this list (hope I didn't miss it). So to be sure : The following vulnerabilities were added to the Vulnerability KnowledgeBase of the QualysGuard Web service between May 05, 2008 and May 11, 2008. QIDSev. Title ... 43134 P 3 Cisco IOS

[c-nsp] Port down 6500 warning via syslog

2008-04-29 Thread Holemans Wim
I know I have seen this before, but I can't find the article. On most cisco IOS switches, you get syslog messages if a port goes down or up. On a 6500 this is not the case. But I remember seeing an article in which a way was shown how to enable this feature on 65XX IOS. Anyone has a pointer to

Re: [c-nsp] Port down 6500 warning via syslog

2008-04-29 Thread Holemans Wim
Thanks for all who answered to my question. The command is : logging event link-status default Wim Holemans -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Holemans Wim Sent: dinsdag 29 april 2008 10:38 To: cisco-nsp@puck.nether.net Subject: [c-nsp

[c-nsp] etherchannel problems

2007-11-19 Thread Holemans Wim
We just got bitten by a serious etherchannel problem : we have an 2 gig etherchannel link between 2 campus. Someone on the other end misconfigured an interface (typed 6/1 instead of 1/6) and had overwritten the allowed vlans on one of the interfaces. As a result of this, the interface was thrown

[c-nsp] Max performance 6148(A--GE-TX boards

2007-10-25 Thread Holemans Wim
We have a bunch of 65XX with 6148-GE-TX or 6148A-GE-TX boards to connect a large number of servers and different etherchannels between them. When i checked the release notes for 12.2SX, i found the following lines : ... WS-X6148A-GE-TX *Number of ports: 48 Number of port groups: 6 Port ranges per

[c-nsp] Temp sensors on 6500 48 10/100/1000 module

2007-07-18 Thread Holemans Wim
Can anyone tell me where the temp sensors on a WS-X6148-GE-TX board are physically located ? This is part of the env info : module 2 outlet temperature: 27C module 2 inlet temperature: 24C module 2 device-1 temperature: 25C module 2 device-2 temperature: 27C module 3 outlet