Re: [c-nsp] EoMPLS ?s

2011-10-13 Thread Jason LeBlanc
have a larger MTU on the core (usually the way it is implemented today), or reduce MTU at both sides. As this is a L2 link, you can't use things like MSS adjust etc... Arie -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Jason

[c-nsp] EoMPLS ?s

2011-10-12 Thread Jason LeBlanc
We're considering using EoMPLS port mode to bridge two datacenters together temporarily for a move using sup720-3BXL on both ends with 6724 blades, probably 2 or 4 gig links, possibly 10g if I can get them to buy the HW. The question I have primarily is with regard to MTU. I have heard there

Re: [c-nsp] 4500 Inconsistent Line Cards

2010-10-31 Thread Jason Leblanc
Thank you Łukasz! 2010/10/30 Łukasz Bromirski luk...@bromirski.net On 2010-10-31 01:31, Jason Leblanc wrote: Are there any issues with mixed blades WC-4548 WC-4648 running on the same 4500E-R chassis? It looks like there is an oversubscription difference of 8:1 vs. 2:1 but I assume thats

[c-nsp] 4500 Inconsistent Line Cards

2010-10-30 Thread Jason Leblanc
Are there any issues with mixed blades WC-4548 WC-4648 running on the same 4500E-R chassis? It looks like there is an oversubscription difference of 8:1 vs. 2:1 but I assume thats local only to the blades. I have a client that has this setup currently and is looking to purchase another chassis

[c-nsp] Nexus 7k CoPP

2010-05-21 Thread Jason Leblanc
Hello, We are deploying a ton of Nexus 7ks right now. Our traditional standard had a named ACL for SNMP, we also use transport input ssh and have an ACL allowing access for that, Our tools are only allowed from certain segments etc... On the 7k's the only option is to use CoPP. Does anyone

Re: [c-nsp] Best practice - Core vs Access Router

2010-02-10 Thread Jason LeBlanc
These are great! Thanks Leif On Feb 10, 2010, at 1:03 PM, Leif Sawyer wrote: Here's some of my common aliases. top is the one that you'll probably use !# Global Aliases (should work on all platforms ! alias exec ifsum sho int sum | incl ^\*|Interface|: |-- alias exec sib show ip

Re: [c-nsp] Self rebooting pix?

2010-01-27 Thread Jason LeBlanc
The point of termination between the pix and the power supply end point (shaped like a 7) is a known issue. If it moves at all or gets bumped at all it will reboot the devices. To rule this out you can try to zip tie it to the device in an effort to keep it still. If there is no possible

Re: [c-nsp] MPLS VPN Running BGP w/ failover IPSec VPN Over Internet

2010-01-27 Thread Jason LeBlanc
the MPLS VPN cloud? -Original Message- From: Jason LeBlanc [mailto:jasonlebl...@gmail.com] Sent: Wednesday, January 27, 2010 1:48 AM To: Luan Nguyen Cc: 'Cisco-nsp' Subject: Re: [c-nsp] MPLS VPN Running BGP w/ failover IPSec VPN Over Internet Current topology is pretty simple. ATT

Re: [c-nsp] best ios version for VSS

2010-01-27 Thread Jason LeBlanc
I did the exact same thing first go round ;) Crazy thing is I just went through this 2 days ago and thanks to Matthew got it fixed! On Jan 27, 2010, at 4:03 PM, Alasdair McWilliam wrote: I take back what I just said about the specified workaround not working... I clearly had blinkers on

Re: [c-nsp] A good SSL VPN Solution ?

2010-01-21 Thread Jason LeBlanc
On Jan 21, 2010, at 9:08 AM, Chris Wopat wrote: Hi all, Can you advise me a good vpn ssl solution for accessing Office LAN from my desktop computer without having to install a client software ? We should be able to access machines with ssh, http, imap and https. Are cisco asa appliances

Re: [c-nsp] BGP Hold time expired/ospf dropping 6500 Sup720-3BXL

2010-01-21 Thread Jason LeBlanc
Can you send your snipped OSPF config? On Jan 21, 2010, at 5:28 PM, Andy B. wrote: Hi, I just fell over this thread while doing a little reseach to solve a similar situation. Hardware: - 6509 with SUP720-3BXL on both ends - SXF15a - Uptime: 46 weeks Problem: - OSPF (for the

[c-nsp] OSPF Campus Design : Excessive SPF Runs

2010-01-14 Thread Jason LeBlanc
Hello, We currently have Layer 3 Routed Access configured at all of our Metro Campus locations. There are a few obvious deviations from the best practice design guides. The current setup is: Core --Datacenter Distribution -- | (fiber connect) | -- Building Distribution --

Re: [c-nsp] Syslog Platform for a Telco Environment

2010-01-11 Thread Jason LeBlanc
Splunk for sure! On Jan 11, 2010, at 8:27 AM, Felix Nkansah wrote: Hi All, A telco (fixed line/mobile carrier) is looking to deploy a centralized syslog solution for their environment for storing, viewing and analyzing logs. The plan is to have about 1,000+ server and network nodes

Re: [c-nsp] Syslog Platform for a Telco Environment

2010-01-11 Thread Jason LeBlanc
As it should be :) Its earned it! On Jan 11, 2010, at 9:47 AM, Simon Lockhart wrote: A telco (fixed line/mobile carrier) is looking to deploy a centralized syslog solution for their environment for storing, viewing and analyzing logs. A linux-based platform / commercial offering is

Re: [c-nsp] Bug ID CSCsv50653

2010-01-07 Thread Jason LeBlanc
Is 12.2(46)SE6 the recommended most stable version then since it was the last supported version? On Jan 6, 2010, at 3:47 PM, Hector Herrera wrote: On Wed, Jan 6, 2010 at 2:03 PM, Jeff Kell jeff-k...@utc.edu wrote: On 1/6/2010 4:55 PM, Jason Shearer wrote: After reload, 3550 does not load

Re: [c-nsp] IOS Code Recommendations

2010-01-07 Thread Jason LeBlanc
. Thank you very much for you time I can definitely build off of this. Regards, //LeBlanc On Jan 7, 2010, at 12:08 PM, Peter Rathlev wrote: Hi Jason, On Sat, 2010-01-02 at 23:11 -0700, Jason LeBlanc wrote: Cisco only does safe harbor on a few select devices. Being as how this group

Re: [c-nsp] Bug ID CSCsv50653

2010-01-06 Thread Jason LeBlanc
Jeff or all, What is the most stable current release available? Would it be the same 12.2(46)SE6? (non-DC) Thanks, //LeBlanc On Jan 6, 2010, at 3:03 PM, Jeff Kell wrote: On 1/6/2010 4:55 PM, Jason Shearer wrote: After reload, 3550 does not load share 1st Found-In 12.2(35)SE Known

[c-nsp] IOS Code Recommendations

2010-01-02 Thread Jason LeBlanc
All, Cisco only does safe harbor on a few select devices. Being as how this group is made up of a lot of service providers and enterprise networks, does anyone know the latest stable version of code for any or all of the following: 2651XM WS-C3550-24-PWR WS-C3560-24PS-S Catalyst 3560-48TS

Re: [c-nsp] MTU Mismatch

2009-12-28 Thread Jason LeBlanc
From a routing perspective this makes sense. Will there be any adverse effects if the Jumbo frames is bumped up anywhere in the chain? Meaning L2 vs. the L3 Routing. I believe thats where the MTU path discovery comes into play correct? Sorry to add to this but while we were on the subject I

Re: [c-nsp] MTU Mismatch

2009-12-28 Thread Jason LeBlanc
a larger size than the edge. LR Mack McBride Network Architect Viawest, Inc. -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Jason LeBlanc Sent: Monday, December 28, 2009 10:09 AM To: Marko Milivojevic Cc: cisco

[c-nsp] Cisco 7206VXR/NPE-G1 -- Cisco WS-C6506 (R7000)

2009-12-07 Thread Jason LeBlanc
We have a 7206 that is getting lots of input errors and overrun errors on the LAN side without CRC errors. On the WAN side we are getting all 3 but on a much smaller scale. Every couple of weeks the CPU goes through the roof but the box has never rebooted. Can anyone give me a detailed

Re: [c-nsp] PIX/ASA Change Control

2009-06-28 Thread Jason LeBlanc
We've moved to this as well, much nicer and easier to get running than cvsweb. Hughes, Scott GRE/MG wrote: Websvn is very slick. RSS feeds, colorized diffs. On Jun 26, 2009, at 8:04 AM, Ryan West rw...@zyedge.com wrote: If you're ever run a ./configure script on a *nix system, you'll be

Re: [c-nsp] Rancid and commercial config management tools

2009-02-09 Thread Jason LeBlanc
+1 I really like Opsware. Ramcharan, Vijay A wrote: We use Opsware NAS. I haven't configured it or anything but it is quite commercial and can do nice things like configuration checks against a standard policy, notifications of config changes, config automation and things like that. Vijay

Re: [c-nsp] Any good filters for syslog output

2008-12-18 Thread Jason LeBlanc
The other nice thing about SEC is that it can handle a busy log server without nuking the cpu. You can get pretty crazy with it too in terms of complexity. Christian Zeng wrote: Hi, * Eric Cables ecab...@gmail.com wrote: I've been using swatch for a couple of years now, and have been

[c-nsp] sup1a - sup32 image questions

2008-11-06 Thread Jason LeBlanc
Hi all, I'm about to begin upgrading our old sup1a/msfc1 switches from both native and hybrid ios to sup32 native. My main requirements are simple, bgp and ios slb. The new download layout and new hardware are causing me some problems. Am I going to need both sp and rp images or a single

Re: [c-nsp] sup1a - sup32 image questions

2008-11-06 Thread Jason LeBlanc
Great, thanks for simplifying this for me. ;) Gert Doering wrote: Hi, On Thu, Nov 06, 2008 at 10:58:39AM -0500, Jason LeBlanc wrote: Am I going to need both sp and rp images or a single image? For native, it's a single image. We run s3223-advipservicesk9_wan-mz.122-18.SXF7.bin

Re: [c-nsp] Recommended 2800 ISR

2008-09-05 Thread Jason LeBlanc
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I have two 2811s with a full view on each and partial for ibgp, no issues. Justin M. Streiner wrote: On Thu, 4 Sep 2008, Dan Letkeman wrote: I was wondering if anyone has recommendations for a 2800 series router for a 20-30mbit internet

Re: [c-nsp] Few questions regarding fixed vs modular and when which is better.

2008-08-28 Thread Jason LeBlanc
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On new builds I prefer to run cabling to each rack and use 65xx (not the 13 slot) for distribution layer. Hard to install cable into a crowded cage/datacenter, so sometimes a switch per rack makes sense. Drew Weaver wrote: What is the

Re: [c-nsp] best fault management solutions?

2008-08-22 Thread Jason LeBlanc
You could do something as simple as mrtg templates and a few simple scripts to auto-gen the mrtg configs with thresholds that email you. You also get graphs of the trends to boot. We have several tools running but I tend to use mrtg more than the others. I have some code if you're interested,

Re: [c-nsp] smoke and condensation damage to routers

2008-08-21 Thread Jason LeBlanc
If you can believe this. ;) Hurricane Wilma took the roof off our corp hq a couple years back, water ran down between floors, through conduits, etc and got more or less everywhere. We had a 6500 in a wiring closet that got dumped full of water. Believe it or not that switch has been running in

Re: [c-nsp] DMVPN Rollout -- MTU questions

2008-05-23 Thread Jason LeBlanc
IME, something in the chain blocking icmp packet-too-big messages will cause problems. I've tried to explain to some people we network with that blocking all icmp is not a good idea, tcp/ip needs certain types allowed to work properly. In this case for PMTUD (path MTU discovery) to work.

Re: [c-nsp] GRE and NHRP; avoiding routing through the hub

2008-04-15 Thread Jason LeBlanc
Why not nail up a separate GRE tunnel between the two spokes and let the spoke routers handle the routing, completely separate of your MP GRE? Bob Tinkelman wrote: This is a cry for some design advice. I have an existing configuration using multipoint GRE tunnels and NHRP to implement backup

Re: [c-nsp] DMVPN's, or another way?

2008-04-08 Thread Jason LeBlanc
Frankly we're very happy with our dual hub dmvpn thus far. We're running this on a pair of 2811s with no issues, but our bandwidth per site is small (200-500kb/s). You might look at a pool of cheap hub routers that have ipsec hw acceleration built in (2811, 2821, 37xx) and do some simple

[c-nsp] Cisco 851 3DES Performance

2007-09-12 Thread Jason LeBlanc
I can't seem to find anything real world as to how much 3des throughput these can do, if anyone has experience please post. Also interested in 1841 throughput in case the 851 can't do 10mb/s. Looking at one of these for a dmvpn spoke router. Thanks. Jason

Re: [c-nsp] Cisco 851 3DES Performance

2007-09-12 Thread Jason LeBlanc
Actually that shows the 850 as 5.12mb/s with 64 byte packets, not ipsec. I know it offloads, but I don't know how much it really can do. They show the 1841 as 38.4mb/s so that might be the safe way to go since I already have one. Jason Gurtz wrote: I can't seem to find anything real world

Re: [c-nsp] [Retrieved] Fiber issue, banging my head.

2007-09-10 Thread Jason LeBlanc
I also remember some bugs back in my GSR days, did you do a bug scrub? There were several 'cosmetic bugs' where counters would increment in the show commands but there would not actually be any problems. I already deleted your original email, so I can't reference that. Are there actual

Re: [c-nsp] Router Suggestion for console access?

2007-09-04 Thread Jason LeBlanc
I've always used 2511s with no issues. We have Cyclades for unix box consoles, but I prefer my IOS. 2511s are cheap on eBay too, I see no reason to pay more per port for anything else. Paul Stewart wrote: Hi folks... Looking for feedback on what still works well for console access via a

Re: [c-nsp] Router Suggestion for console access?

2007-09-04 Thread Jason LeBlanc
My console routers are not subject to anything psirt offers, in an oob net with very little access. All of my network mgmt gear is this way. They are old, with 11.8 code would be fine for what I use them for. It just depends on the need I guess, while the panel and 2801 are a nice solution,

[c-nsp] bgp slow prefix learning

2007-08-21 Thread Jason LeBlanc
I'm wondering if I have something that is by design or if something else is slowing my routers down. I have two 2811s with 768 megs running 12.4(4)T3, each connected to different upstreams via fast ethernet. I'm using prefix lists to limit them to /22, but I should have enough ram for a full

Re: [c-nsp] bgp slow prefix learning

2007-08-21 Thread Jason LeBlanc
at 12:42:14PM -0400, Jason LeBlanc wrote: I'm wondering if I have something that is by design or if something else is slowing my routers down. I have two 2811s with 768 megs running 12.4(4)T3, each connected to different upstreams via fast ethernet. I'm using prefix lists to limit them

Re: [c-nsp] Providing 3rd party access to logs (syslog)

2007-08-16 Thread Jason LeBlanc
You might look at Sawmill as well, has user level access controls to various log files. Its not a straight view of the logs, it is an analyzer and allows the ability to search and organize things. Dale Shaw wrote: Hi Roland, On 8/16/07, Roland Dobbins [EMAIL PROTECTED] wrote: Could you

Re: [c-nsp] Replacing a 2611 with PIX 515E + PIX 7.2

2007-08-16 Thread Jason LeBlanc
That would help cpu, can find them on ebay cheap. The 28xx would be the way to go, however. We replaced our 3620s with 2811s and they run circles around the old 3620s, built in ipsec acceleration not to mention boatloads more ram and cpu (and not on the verge of EoL). Joe Maimon wrote:

Re: [c-nsp] Default route pointed to an interface

2007-08-16 Thread Jason LeBlanc
default-information originate metric 1000 (adjust metric according to which router you wish to actually be the default route) Justin Shore wrote: Seth Mattinen wrote: Justin Shore wrote: I have a pair of border routers, 1 with 2 upstream connection and the other with a single

Re: [c-nsp] OT: project management

2007-07-21 Thread Jason LeBlanc
We use an app called Version One, it is web based. I do not have much hands on with it however so I really can't give you much feedback. Voll, Scott wrote: It's off topic but I'm hoping someone can give a little input. We are looking for a Project Management suite. It needs to be able

Re: [c-nsp] advice for L2 switches

2007-06-23 Thread Jason LeBlanc
I second a pair of used 6500 chassis with used sup1a/msfc(1) and cheap used 6348 blades. Were you near someone who keeps spares you could probably borrow or rent a lot of it, much easier to setup with just 2 chassis than 40 or so smaller switches. I'm betting you could get it all on the gray