Re: [c-nsp] How can one escalate within Cisco TAC?

2023-02-08 Thread Joe Maimon via cisco-nsp
Effective human capability redundancy does not persist as a stable status inside of any discreet organization. Mark Tinka via cisco-nsp wrote: On 2/8/23 16:45, Aaron wrote: i think the problem is they let the good ones go. That is a trend currently affecting our industry - mostly because

Re: [c-nsp] storm-control errdisable with no traffic or vlan

2022-08-04 Thread Joe Maimon via cisco-nsp
Thanks for responding. I was looking for a controller like command to see maybe there were some malformed frames or something, but couldnt find one on this platform. Saku Ytti wrote: On Thu, 4 Aug 2022 at 02:06, Joe Maimon via cisco-nsp wrote: I have a vendor trying to turn up a 10gb

Re: [c-nsp] storm-control errdisable with no traffic or vlan

2022-08-04 Thread Joe Maimon via cisco-nsp
Gert Doering wrote: Hi, Make the port a routed port (= ingress packets go nowhere), set up a SPAN session, find out what sort of packets are coming in (broacast, multicast, unknown-unicast) and how many of them. Adjust limits, as ytti said. Interesting approach, even if not sure it will

[c-nsp] storm-control errdisable with no traffic or vlan

2022-08-03 Thread Joe Maimon via cisco-nsp
I have a vendor trying to turn up a 10gb link from their juniper mx to a cisco 4900M, using typical X2 LR. The link was being upgraded from a functioning 1gb. Same traffic. Even with switchport mode trunk and switchport allowed vlan none, with input counters in single digits, storm control

Re: [c-nsp] Cisco Router IRB

2018-03-05 Thread Joe Maimon
James Bensley wrote: I thought that IRB did use CEF on the ISR-G2s? Cheers, James. On software routers, even CEF enabled features do not compare well with the most optimal and optimized routing operation flows, which is essentially IP in Ethernet interface, un-encapsulated, unencumbered

Re: [c-nsp] sup720 hairpin packet loss

2017-11-15 Thread Joe Maimon
Adam Straws on wrote: You have IP redirects disabled? Much better. thank you. Joe ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] sup720 hairpin packet loss

2017-11-15 Thread Joe Maimon
Adam Straws on wrote: You have IP redirects disabled? On the face of it, that sounds irrelevant. But I suppose you mean that having that enabled can cause unwanted forwarding path/punting, so turning that off is what I am trying now. Thanks much! Joe

[c-nsp] sup720 hairpin packet loss

2017-11-15 Thread Joe Maimon
I seem to be running across this frequently, where a sup720 hairpins a route out the same vlan interface to another sup720 there is a fair bit of packet loss. Am I missing some magic mls command to make that go away? Help, advice, tips all appreciated. Best, Joe

Re: [c-nsp] 3550 crashes upon errdisable recovery from port-security violation

2014-08-01 Thread Joe Maimon
Bottom line. c3550-ipservicesk9-mz.122-55.SE9.bin is bad news. c3550-ipservicesk9-mz.122-55.SE6.bin is not. Joe Joe Maimon wrote: FYI Upon recovery from errdisable after port-security violation the switch crashes and upon reboot displays the below. Verified on multiple switches in the 3550

[c-nsp] 3550 crashes upon errdisable recovery from port-security violation

2014-07-31 Thread Joe Maimon
FYI Upon recovery from errdisable after port-security violation the switch crashes and upon reboot displays the below. Verified on multiple switches in the 3550 line and that it does not occur with 12.2(44), other versions being looked into. *Mar 1 00:02:01: %PLATFORM_CAT3550-1-CRASHED:

[c-nsp] local policy routing RTP streams from PA-VX cards on 7200

2014-06-18 Thread Joe Maimon
Anyone know if this is supported? I seem to be running across many instances where only the RTP streams do not obey local policy routing and instead follow the routing table. Since they usually work anyways (unexpected source addresses notwithstanding) I have not figured out exactly how

[c-nsp] malloclite memory leak

2013-08-24 Thread Joe Maimon
I dont think these are normal numbers, happening on bunch of similar configuration routers. r1#sh proc mem so Processor Pool Total: 362681452 Used: 124296132 Free: 238385320 I/O Pool Total: 33554432 Used:3254704 Free: 30299728 Transient Pool Total: 16777216 Used: 364668

Re: [c-nsp] Resetting (or not) a 6500/sup720 from the console/rommon

2013-08-12 Thread Joe Maimon
Lamar Owen wrote: On 07/30/2013 08:23 AM, Joe Maimon wrote: All, Having a similar situation here. Hoping to get more feedback then Phil ever did. Is there a way through console only to worm back into the SP/rommon/reset? I can boot an old msfc image on the RP (hybrid mode with both SP

Re: [c-nsp] Resetting (or not) a 6500/sup720 from the console/rommon

2013-08-12 Thread Joe Maimon
Phil Mayers wrote: On 12/08/13 15:14, Andriy Bilous wrote: I suspect you would need to sync config-registers on both. In some circumstances when SP fails to boot, chassis would program 'halt on boot' on RP to prevent infinite reset cycling (most electrical failures happen on reset). Erm...

Re: [c-nsp] Resetting (or not) a 6500/sup720 from the console/rommon

2013-07-30 Thread Joe Maimon
All, Having a similar situation here. Hoping to get more feedback then Phil ever did. Is there a way through console only to worm back into the SP/rommon/reset? I can boot an old msfc image on the RP (hybrid mode with both SP and RP running IOS), but havent figured out anything further yet.

Re: [c-nsp] 7204VXR reboots

2013-01-23 Thread Joe Maimon
Joe Pruett wrote: 3. not really 12 vs 15, but i have never really been able to figure out what the 'service provider' or 'sp services' feature set really means. mpls seems to be only in the sp side, but lots of other features are removed from sp compared to my ipsec variant. i guess by

[c-nsp] Cisco TAC successfully disappoints again

2012-12-19 Thread Joe Maimon
What exactly does Support mean? I just cannot believe the following fits the definition. Hello Joe, My name is J*** C and I’m the manager of the Routing Protocols team within Cisco TAC. I’m contacting you on behalf of J*** M* who is the owner of this SR. After reviewing the case

Re: [c-nsp] Cisco TAC successfully disappoints again

2012-12-19 Thread Joe Maimon
. You should also talk to the DM aka Duty Manager and they can work to resolve the issue. - Jared On Dec 19, 2012, at 10:49 AM, Joe Maimon wrote: What exactly does Support mean? I just cannot believe the following fits the definition. Hello Joe, My name is J*** C and I’m the manager

Re: [c-nsp] Cisco TAC successfully disappoints again

2012-12-19 Thread Joe Maimon
, Joe Maimon wrote: What exactly does Support mean? I just cannot believe the following fits the definition. Hello Joe, My name is J*** C and I’m the manager of the Routing Protocols team within Cisco TAC. I’m contacting you on behalf of J*** M* who is the owner of this SR. After

Re: [c-nsp] Upgrade IOS and incompatible config

2012-12-09 Thread Joe Maimon
Once you get off the upgrade train it can be difficult to get back on. Joe Mike wrote: On 12/04/2012 12:51 AM, Gert Doering wrote: Hi, On Mon, Dec 03, 2012 at 06:08:20PM -0800, Mike wrote: If it helps, my current running version is c7200p-advipservicesk9-mz.122-33.SRD8 while the version

[c-nsp] Traffic shaping does not work (and is not supported) on Port-Channel interfaces on Software based routers

2012-10-10 Thread Joe Maimon
All, FYI, yet another occurrence of Cisco TAC coming to the conclusion that yes it does not work, and no, they dont have to fix it, because they have decided that it is not supported. Is it an unreasonable expectation to expect product features to interoperate unless clearly stated that

Re: [c-nsp] Traffic shaping does not work (and is not supported) on Port-Channel interfaces on Software based routers

2012-10-10 Thread Joe Maimon
Gert Doering wrote: Hi, On Wed, Oct 10, 2012 at 10:05:50AM -0400, Joe Maimon wrote: Is it an unreasonable expectation to expect TAC support contracts to deliver results and resolutions instead of yet another thing we wont support? But they *do* deliver results. Documentation gets updated

[c-nsp] QoS match vlan

2012-07-11 Thread Joe Maimon
Hey All, I am looking for some experience or information regarding this feature, which allows you to apply qos service policies across diverse vlan subinterfaces, by using a class matching the vlan tags on the parent interface. The feature seems to work on software platforms (7200

Re: [c-nsp] Overlapping Subnet Issue - Gateway IP Resides in Vendor Assigned Public IP Range

2012-07-11 Thread Joe Maimon
Spencer Barnes wrote: Hello, I can change the g0/0 interface to 10.0.128.66 255.255.255.252 and assign the other interface g0/1 10.0.128.96 255.255.255.224 but then I lose a bunch of external IPs. Only with proxy-arp. Your provider has put that subnet on the wire. Seems like they want

Re: [c-nsp] automatic bgp route refresh

2012-07-11 Thread Joe Maimon
Joe Maimon wrote: Hey All, I would greatly appreciate it if somebody would point me to the release notes for the change I see in 15.1 where BGP neighbor route-map configurations happen in real time, without needing any clearing, soft or otherwise. Much obliged. Best, Joe So I opened

Re: [c-nsp] Testing New BGP Provider

2012-05-06 Thread Joe Maimon
Have them setup an additional multihop ebgp setup that you can funnel to a disjoint route server so that you can examine what exactly is in their full table. Thats a good way to find the rfc1918 prefixes and customer routes and more specific peer routes that really dont belong there. Or

Re: [c-nsp] Failing to load IOS

2012-04-04 Thread Joe Maimon
You can run latest 151 on npe-400 Why dont you try that instead of going from one outdated ios to another? Joseph Mays wrote: Also, just as a sanity check -- I cannot find a listing for separate ram for the IOS. Does the NPE-400 set aside memory for the IOS load from the main memory? And if

Re: [c-nsp] Megapath frame relay question

2012-02-26 Thread Joe Maimon
originating from the router itself. BTW, the reason I need this to work is the router has a couple FXS ports in it. None of the dial-peer stuff works under the current configuration. -Original Message- From: Joe Maimon [mailto:jmai...@ttec.com] Sent: Friday, February 24, 2012 1:08 PM To: Bill

Re: [c-nsp] Megapath frame relay question

2012-02-24 Thread Joe Maimon
Use some nat if you want to source traffic from the router and have it attempt to use the unrouted address and still work. Of course, you could start hard configuring which address various router initiated traffic sourced from, but this is a much more complete approach. ip access-list

Re: [c-nsp] Megapath frame relay question

2012-02-23 Thread Joe Maimon
Odds are you have non routed address on the wan interface. Bill wrote: Dear Cisco gurus, I have the following simple config for a frame-relay T1 on Megapath's network: interface FastEthernet0/0 ip address x.x.x.x x.x.x.x (publicly addressable /29) duplex auto speed auto !

[c-nsp] automatic bgp route refresh

2012-02-21 Thread Joe Maimon
Hey All, I would greatly appreciate it if somebody would point me to the release notes for the change I see in 15.1 where BGP neighbor route-map configurations happen in real time, without needing any clearing, soft or otherwise. Much obliged. Best, Joe

Re: [c-nsp] WS-C2970G-24TS as access switches

2011-12-28 Thread Joe Maimon
Nikolay Shopik wrote: I've noticed WS-C2970G-24TS actually 1,5U, while other model just 1U. So I wonder if there any overheating issues? The physical design appears to be the same as 3550-12G and some of the 3750. The extra height is taken up by the PS and 2 fans which are on their own

Re: [c-nsp] multihoming solution over two different ISP's

2011-08-08 Thread Joe Maimon
Get a 2950 or even a 3524XL, use vlans and subinterfaces. Use BGP if available. Otherwise, if you are already using NAT, then this should work fine. http://www.cisco.com/en/US/docs/ios/12_3/12_3x/12_3xe/feature/guide/dbackupx.html https://supportforums.cisco.com/docs/DOC-8313 If you need

[c-nsp] Generic Traffic Shaping

2011-06-24 Thread Joe Maimon
Hey All, GTS. I believe it is inferior to any other policy-map that can get its bandwidth direct from the interface or layer2 configuration. GTS is for a fallback, for logical interfaces, for interfaces that do not have any other way of controlling and signaling available bandwdith.

Re: [c-nsp] Dynamic dns on a cisco ios router

2011-06-14 Thread Joe Maimon
I have found that using ip sla http method to be much more reliable and configurable for my purposes. Joe Ziv Leyes wrote: As promised, I report back, sorry for the delay... I can confirm that this method worked fine for me! The only captcha that I had (I've forgotten about it and took me a

Re: [c-nsp] More than 128M CF on C1800 router?

2010-11-25 Thread Joe Maimon
Nick Hilliard wrote: So, C1800 series routers nominally support a maximum of 128M external flash (CF). Will 256M flash cards work at all, or will they do something silly like refusing to boot? 128M CF cards have become less easy to get these days, and I'm not inclined to pay a discounted $700

[c-nsp] L2TP radius periodic acccounting

2010-09-14 Thread Joe Maimon
Any ideas on how to get a LAC to obey aaa accounting update periodic 5 Its just sending floods. I have had to turn off accounting. Getting L2TP lac to use specific aaa methods seems to be problematic as well. Thanks, Joe ___ cisco-nsp mailing

Re: [c-nsp] PA-FE-TX, PA-FE-TX/ISL, PA-2FE-TX, PA-2FE-TX/ISL

2010-08-31 Thread Joe Maimon
I would stay far far away from the 2 port FE port adapters, no matter what they say on them. I would stick with VIP2-50 (or higher) with 128DRAM and only port adapters that work well in there. Only VIP2-50 (or better) and RSP in the chassis. Nothing else. Use a cheap catalyst switch like

Re: [c-nsp] PA-FE-TX, PA-FE-TX/ISL, PA-2FE-TX, PA-2FE-TX/ISL

2010-08-31 Thread Joe Maimon
Real world I would not expect any more than roughly the same throughput through a 7500 RSP4 with VIP2-50 as you will an NPE-400. Sridhar Ayengar wrote: Joe Maimon wrote: If you are shopping the used market, you may be better off with the 7200 series. The 7500 isnt worth the juice it sucks

Re: [c-nsp] Linear Flash

2010-08-30 Thread Joe Maimon
A recent bootflash image will boot system images from ATAPI/IDE (normal) flash, and will work with cf+pc card adapter up to at least 1gb size (personal experience) rt01#sh bootflash: -#- ED type --crc--- -seek-- nlen -length- -date/time- name 1 .. image

Re: [c-nsp] Linear Flash

2010-08-30 Thread Joe Maimon
, SN: 21850522 Sridhar Ayengar wrote: Joe Maimon wrote: A recent bootflash image will boot system images from ATAPI/IDE (normal) flash, and will work with cf+pc card adapter up to at least 1gb size (personal experience) This applies to the RSP4 too? Not just the RSP4+? Peace... Sridhar

Re: [c-nsp] PA-FE-TX Duplex

2010-08-18 Thread Joe Maimon
Gert Doering wrote: Hi, On Tue, Aug 17, 2010 at 11:28:48PM -0400, Sridhar Ayengar wrote: Is there any way to get a PA-FE-TX to autonegotiate duplex? No. The PA-FE-TX and the 7200-IO-FE just don't do duplex negotiation. This is about the only bit of hardware that still needs forcing of

Re: [c-nsp] Cisco ASR BGP within the box question

2010-08-02 Thread Joe Maimon
I sure hope you have better luck than I did. http://www.mail-archive.com/cisco-nsp@puck.nether.net/msg20125.html steven.glog...@swisscom.com wrote: hi all just a short question (related to a quite new feature from cisco). with the new cisco ASR software (15.0(1)S - released some days ago)

Re: [c-nsp] pop site battery backup recommendations

2010-07-22 Thread Joe Maimon
Mike wrote: Howdy, This isn't exactly cisco-centric, but it's certainly related operationally. I operate a county wide isp network and I have about 15 different pops. I equip each with APC700/1400's and with XR battery packs, with the goal being around 8 hours of runtime in the event of a

Re: [c-nsp] Redistributing External EIGRP routes through MPLS vpn

2010-05-18 Thread Joe Maimon
thing like eigrp stub connected :) - Luan Nguyen Chesapeake NetCraftsmen, LLC. - -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Joe Maimon Sent

Re: [c-nsp] Redistributing External EIGRP routes through MPLS vpn

2010-05-18 Thread Joe Maimon
, Joe Maimon jmai...@ttec.com mailto:jmai...@ttec.com wrote: Perhaps something like this shows what I ran into better - I'll have to try and see if I can build it in a lab. The CE would not see the connected routes of the other CE's, unless a network statement is used instead

[c-nsp] Redistributing External EIGRP routes through MPLS vpn

2010-05-17 Thread Joe Maimon
Hey All, Seems like I have run into a difficulty where CE#1 external EIGRP routes (redistribute connected/redistribute static) are learned by PE#1, redistributed to PE#2, but not redistributed to CE#2 CE - PE, EIGRP PE - PE, MPLS/BGP The workaround is to use network statements, making the

Re: [c-nsp] Redistributing External EIGRP routes through MPLS vpn

2010-05-17 Thread Joe Maimon
of the CCO document ? http://www.cisco.com/en/US/docs/ios/12_2t/12_2t15/feature/guide/fteipece.html#wp1027175 Shimol Shah On 5/17/10 2:57 PM, Joe Maimon wrote: Hey All, Seems like I have run into a difficulty where CE#1 external EIGRP routes (redistribute connected/redistribute static

Re: [c-nsp] CPE with tracking redundancy and long lived (UDP) nat sessions

2010-01-25 Thread Joe Maimon
Ivan Pepelnjak wrote: The problem is that the session stays active. I want the session to be lost. I believe the rules should be adhered to a bit more strictly. The session DOES NOT stay active. The phone is stupid. It should have realized there's no reply and restart the session. With

[c-nsp] CPE with tracking redundancy and long lived (UDP) nat sessions

2010-01-24 Thread Joe Maimon
Hey All, So as is commonly talked about, I have seen a number of end user sites with simple redundancy service using IOS routers. Multiple lines, coulds be the same provider, could be different providers, no dynamic routing, different source addresses, uRPF/SAV at the provider(s) is to be

Re: [c-nsp] CPE with tracking redundancy and long lived (UDP) nat sessions

2010-01-24 Thread Joe Maimon
- From: Joe Maimon [mailto:jmai...@ttec.com] Sent: Sunday, January 24, 2010 5:06 PM To: cisco-nsp Subject: [c-nsp] CPE with tracking redundancy and long lived (UDP) nat sessions Hey All, So as is commonly talked about, I have seen a number of end user sites with simple redundancy service using

Re: [c-nsp] CPE with tracking redundancy and long lived (UDP) nat sessions

2010-01-24 Thread Joe Maimon
Ivan Pepelnjak wrote: Obviously the router does NOT check the ip nat rules if it gets a match in the NAT translation table. This behavior makes sense; if you'd change the NAT parameters of a live session, you'd lose the session anyway. The problem is that the session stays active. I want

Re: [c-nsp] NPE-G1 cant read Compact Flash

2010-01-08 Thread Joe Maimon
the key is whether the flash is referred to as slotX or diskX. if the nomenclature is slotX it uses a proprietary disk format which cannot be read by an external reader. to format CF card for use with older system format slot0: Joe Maimon wrote: ML wrote: Are the alternate CF cards formatted

Re: [c-nsp] spanning-tree bpdufilter leaks

2010-01-08 Thread Joe Maimon
Marko Milivojevic wrote: On Fri, Jan 8, 2010 at 04:00, Joe Maimonjmai...@ttec.com wrote: Apparently, bpdufilter leaks sometimes on some switches, and I have the packet traces to prove it. The switches are probably not supported, so replacements are likely in order. Did you have it enabled

Re: [c-nsp] spanning-tree bpdufilter leaks

2010-01-08 Thread Joe Maimon
Bill Blackford wrote: Do you have any details? Models? Code vers? -b 3524XL, 12.0(5)WC17 ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at

Re: [c-nsp] spanning-tree bpdufilter leaks

2010-01-08 Thread Joe Maimon
Marko Milivojevic wrote: On Fri, Jan 8, 2010 at 04:00, Joe Maimonjmai...@ttec.com wrote: Apparently, bpdufilter leaks sometimes on some switches, and I have the packet traces to prove it. The switches are probably not supported, so replacements are likely in order. To clarify, it only

[c-nsp] spanning-tree bpdufilter leaks

2010-01-07 Thread Joe Maimon
Apparently, bpdufilter leaks sometimes on some switches, and I have the packet traces to prove it. The switches are probably not supported, so replacements are likely in order. Anyone have an opinion of which cisco switches/IOS are guaranteed not to leak through bpdufilter?

[c-nsp] NPE-G1 cant read Compact Flash

2009-12-24 Thread Joe Maimon
So this happily running router executes a write mem, which archives a copy to the CF card. Then it hangs and doesnt come back. Hard reset of the router doesnt read the CF card and boots the boot helper instead or just hangs. ROMMON cant read the CF card, a 256MB. Cant read a new 1G card.

Re: [c-nsp] NPE-G1 cant read Compact Flash

2009-12-24 Thread Joe Maimon
ML wrote: Are the alternate CF cards formatted correctly for your platform? Probably. However, IOS doesnt seem to think there is any card there or worse, it hangs upon insert. The original CF card may have gone bad but if you're sure the other CF cards are OK then they may be formatted

Re: [c-nsp] NPE-G1 cant read Compact Flash

2009-12-24 Thread Joe Maimon
Łukasz Bromirski wrote: On 2009-12-24 17:51, Joe Maimon wrote: The original CF card may have gone bad but if you're sure the other CF cards are OK then they may be formatted wrong. The card is fine, tested in external reader. They are all fine. The CF slot of NPE-G1 is very picky about CF

Re: [c-nsp] Enhanced download procedure

2009-09-17 Thread Joe Maimon
Jay Hennigan wrote: What the #$^$...@# is going on with Cisco's download site? It completely hangs Firefox with some shopping cart java thing. And this is downright scary: http://www.west.net/~jay/images/cisco-wants-root.png Enhanced downloads, brought to you by the same people who brought

Re: [c-nsp] C7206VXR boot issue

2009-08-17 Thread Joe Maimon
Probably would help to know what IO controller and NPE you have, what image is the bootloader, where and what image you are trying to boot. Not always can a 7200 boot directly of ide flash. Do you have any configuration, such as boot statements? Mikisa Richard wrote: Hi all, I have an issue

[c-nsp] Route redistribution and selection

2009-08-13 Thread Joe Maimon
We are having a problem where routes originated by the customer because of their backup paths are preventing the mpls bgp routes from being installed and used on the PE. Customer has an eigrp routed network. We are hosting a bgp mpls network for the customer. At the Customer's HQ PE router,

[c-nsp] SHDSL Wic in a 1751-1 CPE

2009-08-13 Thread Joe Maimon
I am testing a turnkey CPE solution combining T1, SDSL, ADSL and PRI handoff to customer PBX, with the 1751 transcoding SIP to PRI channels. A CPE I am testing with a WIC-1SHDSL-V2 doesnt seem to be training properly. The controller continues to report DSL firmware download in progress,

Re: [c-nsp] IOS Recommendation | 7600/RSP720-3CXL

2009-08-13 Thread Joe Maimon
Raymond, Steven wrote: Have found the least bugs in SRD1, but non-cisco bgp neighbors sometimes require the use of hidden command neighbor x.x.x.x dont-capability-negotiate or the session won't restore. I recall being on the other end of that one. Good tip.

Re: [c-nsp] Route redistribution and selection

2009-08-13 Thread Joe Maimon
- From: Luan Nguyen [mailto:l...@netcraftsmen.net] Sent: Thursday, August 13, 2009 3:44 PM To: 'Joe Maimon'; 'cisco-nsp' Subject: Re: [c-nsp] Route redistribution and selection You might want to check this link out: http://wiki.nil.com/Multihomed_MPLS_VPN_sites_running_EIGRP Regards

Re: [c-nsp] 7500 for DSL aggregation - RSP memory error?

2009-08-04 Thread Joe Maimon
I view the rpr feature as completely useless in the real world. Cold spare are way more effective. The last time I had a rp failure, it was fixed by yanking one and leaving the other. In other words, odds are it causes more issues than it resolves. Just added complexity for a box where its

[c-nsp] ip per-packet load-sharing on single interface

2009-07-15 Thread Joe Maimon
ip per-packet load-sharing on single ethernet interface with multiple iBGP routes installed to different nodes on that ethernet interface. Software router, 12.3 Does not seem to be balancing. Is this supposed to work? ___ cisco-nsp mailing list

Re: [c-nsp] ip per-packet load-sharing on single interface

2009-07-15 Thread Joe Maimon
Of Joe Maimon Sent: Wednesday, July 15, 2009 22:29 To: cisco-nsp Subject: [c-nsp] ip per-packet load-sharing on single interface ip per-packet load-sharing on single ethernet interface with multiple iBGP routes installed to different nodes on that ethernet interface. Software router, 12.3 Does

Re: [c-nsp] DNS rewrite global capabilities

2009-06-29 Thread Joe Maimon
Sam Stickland wrote: Roland Dobbins wrote: But even more than that, putting your public-facing DNS (or any other kind of server) behind a firewall is a very serious architectural mistake; firewalls in front of public-facing servers provide no security value whatsoever, and degrade the

Re: [c-nsp] Global Route Leaking on same PE

2009-06-17 Thread Joe Maimon
Tim Durack wrote: Amen to that. I've played around with the various loopback strategies, including using a gre tunnel that originates/terminates on the same PE. It worked, but didn't seem like a scalable solution. A dot1q trunk between two ports (if your not using a switch platform as

Re: [c-nsp] c7200 format bootflash: etc

2009-05-24 Thread Joe Maimon
Hey, I am having the same issue with a I/O controller, I have been trying different combinations of IOS, but I cant seem to get this resolved. Do you have c7200-boot-mz.120-21.ST.bin ? Thanks, Joe FreeLSD wrote: btw, seems 122-14.S15 and 122-18.S10 have broken format for bootflash: and

[c-nsp] vrf aware cluster-id

2009-04-01 Thread Joe Maimon
Running 124T to take advantage of per vrf bgp router id so that the router can have loopback bgp connections. However, route-reflector-client is not taking effect, the neighbor reports denied CLUSTER_LIST loop. Apparently cluster-id needs to be vrf aware as well for this to work. Is this in

Re: [c-nsp] How to assign same virtual interface to a PPPoE customer

2009-03-09 Thread Joe Maimon
Assuming you use a radius server that can place its accounting data in a sql server, this should work fairly well for you http://www.jmaimon.com/freeradius/mrtg-radsql/mrtg-radsql.tar.gz M Usman Ashraf wrote: Hi Oliver, Just wanted to plot MRTG for customers whose CPE has no SNMP support

Re: [c-nsp] setting source address for icmp messages

2009-02-09 Thread Joe Maimon
Oliver Boehmer (oboehmer) wrote: Mike wrote on Monday, February 09, 2009 00:28: No. I am trying to ensure that if the router ever emits icmp messages like 'destination host unreachable', 'icmp frag needed' and the like, that I'm using a public routed ip and not some random flavor of the

Re: [c-nsp] 3550 switch password question

2008-12-06 Thread Joe Maimon
Jen Linkova wrote: On Sat, Dec 6, 2008 at 4:47 AM, chloe K [EMAIL PROTECTED] wrote: 1/ When I boot up the switch, the switch can be accessed by console without password in user mode ls it normal? Absolutely. It's a default configuration which allows you to access the switch and

Re: [c-nsp] Bridging ATM on 7206? (Getting really frustrated here)

2008-10-24 Thread Joe Maimon
Nathan wrote: On Wed, Oct 22, 2008 at 3:04 PM, Nathan [EMAIL PROTECTED] wrote: I can't believe this isn't simple! I just want to change the PVC on the [expletive] ATM cells and push them back the same way they came, how can that be so difficult? Are you looking for the local switching

Re: [c-nsp] Crypto map + traffic via ip route vrf ... global

2008-07-14 Thread Joe Maimon
Peter Rathlev wrote: Hi, The traffic that doesn't get encrypted comes from a VRF Lite subinterface on the back of the 7200. This VRF has a static 0/0 route with a global next hop, and the global table has a static route pointing the other way. Sure would make things simpler if inter-vrf

Re: [c-nsp] Peoples experiences with the 3825

2008-06-26 Thread Joe Maimon
David Barak wrote: I don#39;t have the link in front of me, but I remember a document describing the 3825 as working well for a partial DS3, and the 3845 as working for a full DS3. I believe thats with all features such as nat, acl, fw, ipsec, ids turned on. Also, the ESW modules have

[c-nsp] ASA vpn client to secondary ip address

2008-06-25 Thread Joe Maimon
Hey all, I am trying to get a new range of IP addresses on a asa/pix to work for vpn clients. Doesnt seem to work. Can anyone share any tips? Thanks, Joe ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] ASA vpn client to secondary ip address

2008-06-25 Thread Joe Maimon
. Except one is actually the ASA's outside interface address and the other isnt. Thanks, Joe Christian Koch wrote: can you elaborate? do you mean create a pool of ip's for ravpn users to grab from? On Wed, Jun 25, 2008 at 7:03 PM, Joe Maimon [EMAIL PROTECTED] mailto:[EMAIL PROTECTED

Re: [c-nsp] Routing between VRF and non-VRF

2008-06-20 Thread Joe Maimon
Garry wrote: Maybe I'm missing something here, but what's the right way of routing between VRF and non-VRF interfaces? In my opinion, by being able to define a physical or logical interface between them. Which you can currently, at cost of handling the packet twice. Which is silly, but

Re: [c-nsp] BGP network stops being advertized

2008-06-05 Thread Joe Maimon
Deepak Jain wrote: Justin Shore wrote: Jeff Fitzwater wrote: loopback or another interface (usually a static route of last resort to the loopback address/interface). loopback or null? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] Giving customers access to your gear.

2008-06-03 Thread Joe Maimon
Christian wrote: I've had to deal with the same scenario on multiple occasions It comes down to if we give customer access to the router, then the managed service disappears - as it defeats the purpose of managed services - if they wish to obtain control then let them buy the router from you

[c-nsp] line protocol stays down

2008-06-01 Thread Joe Maimon
Hey All, On a 3845 with 4 VWIC-2MFT-T1 wics. 3 on the engine blade, one in a network module. One day IOS boots up with cookie errors, VWIC on NM is unrecognized. Reload, it comes back. However, T1 on that VWIC comes up green, but line protocol stays down. T1 works fine in other VWIC,

Re: [c-nsp] Frame to ATM

2008-05-27 Thread Joe Maimon
Jason Berenson wrote: Greetings, We just got a new Covad DS3 and ordered an end T1 as frame relay. The backhaul is ATM. Here's my network: Covad will perform FRF ATM conversion for you. You just take the pvc and do your ip routing on it. Now if you want a multilink configuration,

Re: [c-nsp] DMVPN Rollout -- MTU questions

2008-05-23 Thread Joe Maimon
John Kougoulos wrote: On Thu, 22 May 2008, Eric Cables wrote: The above, however, doesn't seem to work in some cases. Users as these sites complain of intermittent connectivity problems, which seem to be solved rather quickly by reducing the IP MTU, and configuring TCP adjust-mss. I

Re: [c-nsp] Discussion list for RADIUS?

2008-05-23 Thread Joe Maimon
Tuc at T-B-O-H.NET wrote: Hi, Hi, Does anyone know of a good discussion list for the RADIUS protocol? You could try the freeradius list. You could also try the freeradius server. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] Router / Switch in front of Firewall

2008-05-11 Thread Joe Maimon
Gert Doering wrote: Hi, On Sun, May 11, 2008 at 03:51:38PM +0200, Tor-Ivar Kristoffersen wrote: Solution is to set a Cisco switch / router in front with 2 IF's. A 3550 will do as well. Get a reasonable supplyer. Forcing RFC1918 addresses on customer transit links is no way to run an

Re: [c-nsp] mac address question

2008-05-07 Thread Joe Maimon
Take an old ethernet card, copy its mac address and throw the ethernet card out. Use that mac address. Realistically, the TELCO is actually asking for what to put in a layer 2 access list. You want to be able to connect multiple routers, for example with an ATM switch, so tell them a mac

Re: [c-nsp] mac address question

2008-05-07 Thread Joe Maimon
to make one up and pass that along to them? Thanks, Paul P.A -Original Message- P.A From: Joe Maimon [mailto:[EMAIL PROTECTED] P.A Sent: Wednesday, May 07, 2008 10:50 AM P.A To: Paul A P.A Cc: cisco-nsp@puck.nether.net P.A Subject: Re: [c-nsp] mac address question P.A

Re: [c-nsp] RBE and PPPOE on the same router

2008-05-06 Thread Joe Maimon
. Thanks, Paulo Amaral MegaNet Communications P: 508 646 0030 - P.A -Original Message- P.A From: Joe Maimon [mailto:[EMAIL PROTECTED] P.A Sent: Tuesday, May 06, 2008 3:50 PM

Re: [c-nsp] Route reflectors, BGP router redundancy et. Al.

2008-04-22 Thread Joe Maimon
Dracul wrote: Hi All, I'm building a design that involves having a 2nd BGP router to act as a backup if something goes wrong with the main router (heaven forbid). I have two peers to different ISP's. There are some questions I have in mind: a. Should my configuration involve route

Re: [c-nsp] 2950 Spanning-tree question

2008-04-06 Thread Joe Maimon
Is there anything to the right of FIBER? Charles Regan wrote: I want to implement a spanning-tree configuration on my network to have redundant path in case of hardware failure. Currently my setup is like this: FIBER TRAFFIC-SHAPER-BRIDGE CACHE-SERVER-BRIDGE 2811 ROUTER

Re: [c-nsp] ppp limit ccp

2008-03-31 Thread Joe Maimon
Oliver Boehmer (oboehmer) wrote: Joe Maimon wrote on Monday, March 31, 2008 3:26 PM: Anybody know exactly what this command does? Cant find it documented. router(config)#ppp limit ccp ? 1-8000 Number of CCP sessions allowed as the name suggests, one can limit the number of PPP

Re: [c-nsp] MLPPP product from the provider point of view

2008-03-27 Thread Joe Maimon
Gert Doering wrote: Hi, On Wed, Mar 12, 2008 at 09:07:51AM -0400, Joe Maimon wrote: - In theory, one virtual template can be used for all mlppp customers, as they will establish seperate bundles with their endpoint discriminators, correct? Yes. How do you protect against

Re: [c-nsp] MPLS or ?

2008-03-17 Thread Joe Maimon
Troy Beisigl wrote: Hi all, We are looking to do the setup shown below. Customer 1 has 3 locations (A, B and C) and would like to be able to pass private traffic between all (WAN) and would also like to get internet access as well. Two of those locations will be DS1 circuits and the

[c-nsp] MLPPP product from the provider point of view

2008-03-12 Thread Joe Maimon
Hey all, Thought I would ping the list and try to benefit from the collective experience. - We show that testing can leave 15-30% bandwidth on the table per link, should this be acceptable or should more troubleshooting be done? - Is it really neccessary to utilize Mutltilink interfaces on

[c-nsp] 7200 vxr as analog dialup access server with PRI

2008-03-04 Thread Joe Maimon
Is there any way to get the vxr to support analog dialup access using pri t1's? the group-range command doesnt seem to work on int group-async0 Thanks, Joe ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] 7200 vxr as analog dialup access server with PRI

2008-03-04 Thread Joe Maimon
Adrian Chadd wrote: On Tue, Mar 04, 2008, Joe Maimon wrote: Is there any way to get the vxr to support analog dialup access using pri t1's? IIRC, If there's no DSPs there's no analog dialup. What about the MIX port adapters? ___ cisco-nsp

  1   2   >