Re: [c-nsp] vPC members use identical virtual addresses without HSRP

2024-04-24 Thread Nathan Lannine via cisco-nsp
nodes/roles. You can implement this same configuration for Nexus following the configuration documentation for VXLAN anycast gateway. Thank you, Nathan On Sun, Apr 21, 2024 at 8:55 PM Chen Jiang via cisco-nsp < cisco-nsp@puck.nether.net> wrote: > Hi! Michael > > Thanks for your

Re: [c-nsp] Support for CFP2

2024-01-19 Thread Nathan Lannine via cisco-nsp
In particular, the page I linked (and I may just not be understanding correctly) seems to be saying that QSFP-100G-ER4L-S may be compatible with what you are looking for. Regards, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.

Re: [c-nsp] Extended Route Target Community Bug - Solved!

2023-09-27 Thread Nathan Ward via cisco-nsp
On 27/09/2023 at 4:15:31 PM, Mark Tinka wrote: > > > On 9/24/23 03:43, Nathan Ward wrote: > > My only assumption was that early versions of VRF implementation in IOS > did not expect that operators would require more fine-grained use of > import/export policies, and

Re: [c-nsp] Extended Route Target Community Bug - Solved!

2023-09-23 Thread Nathan Ward via cisco-nsp
of expected RTs? It would certainly make it a lot faster to generate the list of RTs to advertise with rtfilter - though given that’s only at config commit time perhaps it’s not a big deal. It means that policy in Cisco can be shorter, which is nice I suppose.

Re: [c-nsp] "next-table" Equivalent for IOS XR - Default Route into Global Routing Table

2023-08-29 Thread Nathan Ward via cisco-nsp
te a static default and leak that, it follows wherever that default goes, and doesn’t follow the logic you would expect for label mode per-vrf - so if it’s a default to null, the packets get dropped. Default to a vrf with a next-hop - packets go out to that next-hop. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Blocking SNMPv3 engine-id discovery [was: Re: How to disable ILMI/SNMP CSCvs33325]

2023-03-02 Thread Nathan Lannine via cisco-nsp
On Wed, Sep 21, 2022 at 6:52 AM Simon Leinen via cisco-nsp < cisco-nsp@puck.nether.net> wrote: > Gert Doering writes: > > On Wed, Sep 21, 2022 at 08:14:30AM +0300, Hank Nussbacher wrote: > >> Indeed the SNMP leaks appear to be exactly CSCtw74132 which we did > >> not know about nor did Cisco TAC

Re: [c-nsp] DWDM-SFP-10G-C not working in 3650

2020-08-07 Thread Nathan Lannine
earch instead on your 3650 PID, you may find otherwise, but from what I can tell, there is one other DWDM and a CWDM module that *are* supported, just not the DWDM-SFP10G-C-S. Thank you, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net ht

Re: [c-nsp] remote VPN chaining (nested)

2020-03-25 Thread Nathan Lannine
> > Has anyone established a remote access vpn inside another remote access > vpn? I have never done it myself. I have found using a VM to work well for this. > > Does it work? any challenges, do you need the same VPN client? > I have had more cases with my users breaking one VPN client

Re: [c-nsp] 6509 w/SUP720-3BXL and high CPU load

2020-03-19 Thread Nathan Lannine
t was some kind of link local IPv6 stuff. Either way, it would be nice to know what you find the problem to be. Thank you, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://

Re: [c-nsp] ASR920: egress ACL on BDIs

2020-01-28 Thread Nathan Lannine
> > Somewhat related, IOS (all flavours) do in-place ACL unless you do > object ACLs. In-place ACL update behaviour essentially doubles your > FWIW we are actually using object ACLs. What's the behavior then? Copy-swap? Is there a real name for that which I'm not remembering?

Re: [c-nsp] ASR920: egress ACL on BDIs

2020-01-28 Thread Nathan Lannine
> > Do you happen to have a bug reference for this? We’ve been seeing this > behaviour intermittently on some csr 1ks and haven’t had the time/energy to > debate it with TAC yet. Sorry, just saw this. https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuw19907 . That's for the Catalyst 4500x,

Re: [c-nsp] 10/25 interface behavior

2020-01-28 Thread Nathan Lannine
> > > Is this the norm for the Cisco 10/25 switches as well? I don't have any to > test with at the moment. > > Cisco 3850's have some 1/10 uplink module ports that are identified as Gigabit or TenGigabit based on the configuration. However, both types of interfaces always exist logically, they

Re: [c-nsp] ASR920: egress ACL on BDIs

2020-01-19 Thread Nathan Lannine
> > > This bug not only affects ACLs but other commands as well. Unsure if it is > fixed in newest XE versions. Could this also affect you? > > Aside from this behavior, XE in the enterprise access layer is full of bugs related to ACLs. We've recently begun a practice of maintaining two distinct

Re: [c-nsp] ASR920: egress ACL on BDIs

2020-01-19 Thread Nathan Ward
s". Yay. This is what happens on J ACX boxes.. stunningly bad behaviour :-( -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Granularity for BFD in CoPP policy

2019-10-31 Thread Nathan Lannine
If "echo" is used, I think you might need something like the following, replicating the ACEs exactly on each side. // permit udp eq 3784 permit udp eq 3785 permit udp eq 3784 permit udp eq 3785 permit udp eq 3784 permit udp eq 3785 permit udp eq 3784 permit udp eq 3785 // On

Re: [c-nsp] cisco VPC problem on nx 3064

2019-10-10 Thread Nathan Lannine
On Thu, Oct 10, 2019 at 2:36 AM BASSAGET Cédric < cedric.bassaget...@gmail.com> wrote: > Hello aain, > It seems my problem is related to STP. > After rebooting a switch, VPC peer-link is disabled by spanning tree : > > > interface port-channel13 > > switchport mode trunk > > switchport trunk

Re: [c-nsp] understanding the IP SLA "icmp-jitter" calculations

2019-04-04 Thread Nathan Lannine
On Thu, Apr 4, 2019 at 2:07 PM Martin T wrote: > Hi Nathan, > > > I could be wrong, but doesn't the output you provided above represent 1 > ms of jitter? > > Yes, but the output of "sh ip sla statistics" in my first e-mail shows > that RTT(round-trip time)

Re: [c-nsp] understanding the IP SLA "icmp-jitter" calculations

2019-04-04 Thread Nathan Lannine
t doesn't the output you provided above represent 1 ms of jitter? Thank you, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Cisco Nexus 3064

2019-04-02 Thread Nathan Lannine
you can no longer attach a new service contract to it (through Cisco). Though, there are third parties out there that might attach a non-Cisco service contract to it for you. Thank you, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://pu

Re: [c-nsp] IS-IS as PE-CE protocol

2019-03-21 Thread Nathan Lannine
? I mean (blatant free training request here) how does this get handled by the VPN customer? Just navel gazing here, but I am wondering if there would be any benefit to me running BGP as my own PE-CE protocol. Thank you, Nathan ___ cisco-nsp maili

Re: [c-nsp] DHCP per user features

2019-03-06 Thread Nathan Ward
Hi, This is a very common deployment. You have some questions you need to understand about your product/solution - some examples: - are you using IP pools on the BNG, or in the RADIUS server? - how will you identify users? Option 82 - if so Remote ID or Circuit ID? MAC? - what parameters do

Re: [c-nsp] Cisco 9200L static route limit

2019-01-22 Thread Nathan Lannine
> > Do we have an idea if there is static route limit in Cisco 9200L as we had > in cisco 3750. Is it working in L2 mode and needs licensing to run L3 > features. > > Also, is SVI supported in Network Essential License. >From this,

Re: [c-nsp] RFC5837

2019-01-13 Thread Nathan Ward
> On 13/01/2019, at 10:26 PM, Saku Ytti wrote: > > I'm happy to write supporting traceroute for linux+osx should someone > have supporting device to test against :) How about you write the Linux implementation of the client and responder :-) --

Re: [c-nsp] DHCPv6 on IOS-XR with multiple pools?

2018-11-13 Thread Nathan Ward
900 set a DHCP option? I believe you can match to a class based on DHCP options on the ASR9k, but I’ve not personally done this. It may only be when doing DHCP proxying on the ASR9k, not sure if this applies to using the ASR9k as a DHCP relay/proxy target. -- Nathan Ward _

Re: [c-nsp] 3750 stacks

2018-09-13 Thread Nathan Lannine
need. The provided link should be helpful. - Nathan On Thu, Sep 13, 2018 at 7:48 AM Harry Hambi - Atos wrote: > Hi List, > If I introduce a new member switch to a stack, switch it on, can I then > copy an IOS image from an existing members flash to the new stack member? > Any

Re: [c-nsp] ASR 901 MPLS issues

2018-01-25 Thread Nathan Lannine
erface on a 6500. Could it be the "switchport" config is causing a problem? Would it not work if you configured "no switchport" on the parent interface? - Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Quad Sup6t 6807, ARP issue.

2018-01-12 Thread Nathan Lannine
> > We are seeing ARP packets being dropped within the VSS for some ARP > packets. (We still have single connected sites to the VSS, hence the need > for Quad Sup6T's) > Some ARP requests are arriving on one chassis within the VSS, and are not > being broadcast on the other chassis, resulting in

Re: [c-nsp] Setting relay agent IP on 4500

2017-07-29 Thread Nathan Lannine
>> The issue is the 4500 stamps the relay agent IP in the DISCOVER as >> being the incoming interface IP where the DISCOVER was received, Yeah, that's expected and required behavior. I sort of assumed, as Mr. Mayer indicated, that the "global" option would still set the giaddr to the receiving

Re: [c-nsp] Setting relay agent IP on 4500

2017-07-28 Thread Nathan Lannine
quot;global" argument not accomplish this? I.e. "ip helper-address global " That's how I read this: http://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipapp/command/iap-cr-book/iap-i1.html#wp1413119578 Of course the above is more clear in it's description of

Re: [c-nsp] OT Solarwinds Alternatives

2017-07-28 Thread Nathan Lannine
ory and tracking. It works great for us, is super easy to get running, and has really responsive support. ATM, I actually can't imagine using anything else for the same functions. Now I'm in a similar boat of having to decide on change management/config backup. - Nat

Re: [c-nsp] "snmpEngineTime" seems to wrap with "sysUpTime" in old IOS release

2017-04-06 Thread Nathan Lannine
> How to explain this behavior? Is it likely some kind of SNMP agent I may not have this totally right, but I believe sysUpTime is a 32-bit value, which will only go out about 400 and some odd days before it wraps to 0. ___ cisco-nsp mailing list

Re: [c-nsp] administrative inquiry

2017-03-31 Thread Nathan Lannine
> Do people still want to receive PSIRT notices here? The PSIRT notifications through this list always beat my Cisco subscribed notifications by two to three days. So for me getting the notifications via this list's subscription to Cisco's notifications is unnecessarily redundant. I will likely

Re: [c-nsp] c7301 and hot-swapping of PAs?

2016-11-11 Thread Nathan Ward
> On 11/11/2016, at 10:23 PM, James Bensley wrote: > > On a side note, does my memory serve me correctly, did they also have > the two power cords that feed into one Y shaped connector? I seem to > remember nervously connecting a spare power feed to the spare > connector on

Re: [c-nsp] VASI NAT with MPLS

2016-11-01 Thread Nathan Ward
d is better for some reason and the physicals should have “ip nat outside" - though I’m not sure why. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] ip device tracking on IOS-XE

2016-08-08 Thread Nathan Lannine
error. Good luck, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] ASR9k - IPoE termination

2016-06-22 Thread Nathan Ward
memcache. I have not tested any of these yet, and am mulling them over. If you are using proxy DHCP functionality, perhaps you can auth both BNGs, and control which you respond to in your DHCP server - if your DHCP server can support such things. Perhaps the FreeRADIUS DHCP support can help

[c-nsp] ASR9k eBGP multihop with peer in leaked route

2016-06-10 Thread Nathan Ward
aused by the route being a local route or not. Are there some funny rules that are preventing eBGP multihop from coming up when the peer address is learned over a leaked route? Or.. a leaked route from the local PE? -- Nathan Ward ___ cisco-nsp mailing list

Re: [c-nsp] ASR1006 Routers

2016-06-03 Thread Nathan Ward
t;http://www.cisco.com/c/en/us/support/docs/routers/asr-1000-series-aggregation-services-routers/110531-asr-packet-drop.html> -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp arc

Re: [c-nsp] LNS Alternatives

2016-05-23 Thread Nathan Ward
an fine for Internet access. Check out http://mpd.sourceforge.net/doc5/mpd30.html <http://mpd.sourceforge.net/doc5/mpd30.html> for details on how to do most of the things you’d want with it, triggered by RADIUS. Not mentioned there, but CoA is supported for many attribut

Re: [c-nsp] BGP flowspec S/RTBH for large DDoS

2016-05-16 Thread Nathan Ward
ou only use flowspec routes from external networks if they are the best path for that prefix. There’s an I-D that updates this to relax it a little so it can be used if you have multiple eBGP peers between two ASNs (which is obviously quite common). -- Nathan Ward __

Re: [c-nsp] ASR9001 Vs ASR1006

2016-05-14 Thread Nathan Ward
ell enough. http://www.apc.com/shop/us/en/products/Rack-Side-Air-Distribution-2U-115V-60HZ/P-ACF201BLK Actually we’ve got the 220v version but you the the idea. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.ne

Re: [c-nsp] ASR920 stops routing unexpectedly

2016-05-11 Thread Nathan Ward
the network. > 3. High traffic rate > 4. Combination of traffic streams with varying packet sizes Hi Eric, Sounds likely, yeah. Well spotted. Looks like software took a while to get fixed, I saw+reported it in like, August last year. I won’t be trusting them with MPLS/L2VPN anywhere I car

Re: [c-nsp] ASR920 stops routing unexpectedly

2016-05-11 Thread Nathan Ward
er on this list as well actually. Here we go, poke around here, and let me know if you want any more info: http://marc.info/?l=cisco-nsp=144524503928911=2 -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] ISR4431 integrated "POE" ports

2016-05-10 Thread Nathan Ward
, perhaps that was used. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Cisco ASR 9k and Windows RADIUS server

2016-05-09 Thread Nathan Ward
nd filter it until this (totally bone-headed) bug is fixed. Here is the start of the thread on this, on the FreeRADIUS list. http://lists.freeradius.org/pipermail/freeradius-users/2016-March/082547.html -- Nathan Ward ___ cisco-nsp mailing list cisco-ns

Re: [c-nsp] IOS XR BGP default route - prepending AS

2016-04-20 Thread Nathan Ward
, so, may as well just include it rather than potentially obscuring things ;) -- Nathan Ward > On 20/04/2016, at 16:50, Brian Knight <brian.t.kni...@gmail.com> wrote: > > At $DAYJOB we use MPLS VPNs from other carriers to provide Internet access > to customers conne

Re: [c-nsp] MTU size, fragmentation and drops

2016-04-14 Thread Nathan Ward
arger than 1500B - remember the reply would contain the original payload from the request, and would not be fragmented. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] blackholed traffic on ether-channel

2016-04-06 Thread Nathan Lannine
s. There was a somewhat complex workaround, but we upgraded to resolve it. I think the bug was a regression in 15.1(2)SY5 from a prior fix to resolve the same issue with 1G links. We went to 15.2(1)SY1a, which fixed it for us. Nathan ___ cisc

Re: [c-nsp] ASR920 "console" port....ugh

2016-02-01 Thread Nathan Ward
ones that are not a full 19” wide have poor brackets. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] ASR920 "console" port....ugh

2016-01-16 Thread Nathan Ward
with two USB A holes underneath is a pretty common part as well. I guess it was partially a price thing - probably similar to why serial ended up on RJ45 in the first place? I haven’t been around long enough to know :-) -- Nathan Ward ___ cisco-nsp ma

Re: [c-nsp] ASR920 "console" port....ugh

2016-01-16 Thread Nathan Ward
> On 16/01/2016, at 23:51, Erik Sundberg <esundb...@nitelusa.com> wrote: > > My rack mount brackets don't look like that... Interesting! Post a pic? -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.net

Re: [c-nsp] ASR920 "console" port....ugh

2016-01-16 Thread Nathan Ward
> On 16/01/2016, at 22:03, CiscoNSP List <cisconsp_l...@hotmail.com> wrote: > > Thanks Nathan - I really question Cisco's thought processwhat was "wrong" > with the traditional style RJ45 console port? Took up too much realestate?? > > We have rack kits fo

Re: [c-nsp] ASR920 "console" port....ugh

2016-01-16 Thread Nathan Ward
so the brackets take up the extra space. Because they’ve got an extra couple cm to cover, they need the extra thickness so the bracket works in wall mount mode. No replaceable PSUs on these either. You either get naff brackets or PSUs that stick out the front,

Re: [c-nsp] ASR920 "console" port....ugh

2016-01-15 Thread Nathan Ward
tors only have 4 pins. Also, have you got ASR920 rack mount ears? Ever notice that they’re taller than 1RU because of the folded bits? It’s a pretty bad product from a physical design POV. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.n

Re: [c-nsp] ASR920 "console" port....ugh

2016-01-15 Thread Nathan Ward
> On 16/01/2016, at 20:54, Gert Doering <g...@greenie.muc.de> wrote: > > Hi, > > On Sat, Jan 16, 2016 at 08:50:49PM +1300, Nathan Ward wrote: >> Hi, there is both a USB signalled console port, and an RS232 console. >> The RS232 console uses a USB style co

Re: [c-nsp] lack of snmp parity with cli

2016-01-07 Thread Nathan Ward
either, but, trust me - it’s certainly better than using the CLI! -- Nathan Ward > On 8/01/2016, at 00:13, Mike <mike-cisconspl...@tiedyenetworks.com> wrote: > > Hello group, > > I have a tool I developed in house which polls a cisco router terminating > PPPoE sessions in

Re: [c-nsp] Cache DNS servers

2015-12-01 Thread Nathan Ward
what needs to be looked at. We chart queries per CPU%, recursion times, all sorts of good stuff. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Cisco Nexus as MetroE switch?

2015-10-19 Thread Nathan Ward
> On 19/10/2015, at 19:29, CiscoNSP List <cisconsp_l...@hotmail.com> wrote: > > Hi Nathan - Can you please elaborate on the 920/MPLS issues under load(What > load did you see the issue? CPU, PPS, Throughput?), and what IOS you were > running? > > We've purch

Re: [c-nsp] Cisco Nexus as MetroE switch?

2015-10-18 Thread Nathan Ward
> On 19/10/2015, at 14:46, James Jun <ja...@towardex.com> wrote: > > On Sun, Oct 18, 2015 at 07:42:27PM +1300, Nathan Ward wrote: >> Sorry, I should look better. > > I would say Juniper ACX is more comparable to ASR 901 Series meant for cell > sites with simple

Re: [c-nsp] Cisco Nexus as MetroE switch?

2015-10-18 Thread Nathan Ward
> On 17/10/2015, at 17:54, Mark Tinka <mark.ti...@seacom.mu> wrote: > > > > On 17/Oct/15 06:26, Nathan Ward wrote: > >> I’m surprised no one has yet mentioned Juniper ACX - or at least I couldn’t >> see it in a quick scan of the thread. > > It w

Re: [c-nsp] Cisco Nexus as MetroE switch?

2015-10-18 Thread Nathan Ward
ill, I'd test before buying. Just dump your current Juniper > configurations on to the thing and see what happens. Normally, sure, but they’re impossible to get ahold of. Current configs are on ME3600X for me, so I expect I’ll get errors :-) -- Nathan Ward __

Re: [c-nsp] Cisco Nexus as MetroE switch?

2015-10-16 Thread Nathan Ward
can report back on how well they work. -- Nathan Ward > On 15/10/2015, at 10:52, Gavin McBride <gavmcb.li...@gmail.com> wrote: > > Hello all, > > I've been evaluating a few platforms for a smallish MetroE-style > deployment, focused on E-Line services between a number

Re: [c-nsp] VASI support on ASR920

2015-09-23 Thread Nathan Ward
forwarding when it came under under heavy load, but you know, we’re getting there..) -- Nathan Ward > On 24/09/2015, at 14:35, Pshem Kowalczyk <pshe...@gmail.com> wrote: > > Hi, > > I don't expect that platform to ever support those sort of features (but > that's my person

Re: [c-nsp] Multihoming

2015-09-01 Thread Nathan Ward
he second to last port. Same goes for other switches you might connect, same reasoning. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Peering + Transit Circuits

2015-08-18 Thread Nathan Ward
in other countries, but it depends on the network. -- Nathan Ward On 19/08/2015, at 00:29, Tim Durack tdur...@gmail.com wrote: Question: What is the preferred practice for separating peering and transit circuits? 1. Terminate peering and transit on separate routers. 2. Terminate peering

Re: [c-nsp] VRF route leaking

2015-05-06 Thread Nathan Ward
as your BNG. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] VRF route leaking

2015-05-06 Thread Nathan Ward
there so the customer runs private addressing within their cloud. Putting lots of subscriber traffic over a VASI just to get the packets in to the right VRF is pretty uncommon. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https

Re: [c-nsp] redistribute subscriber route leaking on ASR9k

2015-05-05 Thread Nathan Ward
else is impacted by it hit me up of list and we’ll try get it fixed. --  Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Internet in VRF

2015-05-04 Thread Nathan Ward
even seen it myself! -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Internet in VRF

2015-05-03 Thread Nathan Ward
default in, and advertise that, and not have your traffic label switched to null - per-VRF does a route lookup when the VPN label is popped. -- Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo

[c-nsp] redistribute subscriber route leaking on ASR9k

2015-05-03 Thread Nathan Ward
on a different router, but that doesn’t work where we have POPs which consist of only a BNG and a CDN hanging off it. --  Nathan Ward ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive

Re: [c-nsp] Assistance configuring a router to trigger remote blackhole

2009-09-18 Thread Naveen Nathan
that gave input advice. -- Naveen Nathan To understand the human mind, understand self-deception. - Anon ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail

Re: [c-nsp] Assistance configuring a router to trigger remote blackhole

2009-09-18 Thread Naveen Nathan
Glad to hear that you got it working! Thanks. Out of curiosity, would you mind sharing the specific pref list entry you ended up using? Was it simply 'everything/32'? Tinkering with the prefix-list at first, got the results I expected. I was redistributing the static routes to BGP,

[c-nsp] Assistance configuring a router to trigger remote blackhole

2009-09-17 Thread Naveen Nathan
assuming not. I've attached a portion of the cisco-config (substituting sensitive info, but it should be easy enough to follow). Would someone mind suggesting if I'm missing anything of particular importance. It would be much appreciated. Thanks. -- Naveen Nathan To understand the human mind

Re: [c-nsp] Assistance configuring a router to trigger remote blackhole

2009-09-17 Thread Naveen Nathan
Does a 'sh ip route' for the /32 indicate that its being redistributed? If you do a 'sh ip bgp nei nei adver' does it show it being advertised? Below I pasted excerpts from the router. The route appears to be redistributed by the correct route-map. The STATIC-TO-BGP map proceeds to set the

Re: [c-nsp] BGP Multihomed Selective/Conditional Advertisement

2008-10-27 Thread Nathan
On Mon, Oct 27, 2008 at 6:41 PM, [EMAIL PROTECTED] wrote: Nathan, thanks for this idea. Your idea could work. I just need to find out if they will accept my 2x /25 routes if I split the /24. Frances Albemuth refined my proposal with better knowledge of Cogent's communities

Re: [c-nsp] BGP Multihomed Selective/Conditional Advertisement

2008-10-27 Thread Nathan
have a choice between Cogent and ATT don't send to Cogent. -- HTH, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] BGP Multihomed Selective/Conditional Advertisement

2008-10-27 Thread Nathan
and then to you. If Cogent does not have a direct connection to ATT (OK so that is unlikely), then traffic will leave Cogent on a path towards ATT . . . and the intermediary might just send it back to Cogent . . . -- HTH, Nathan ___ cisco-nsp mailing list

Re: [c-nsp] BGP Multihomed Selective/Conditional Advertisement

2008-10-26 Thread Nathan
default on Cogent routes. -- advertise whole network to ATT, without prepends. -- receive default route from ATT, with default local-preference. If I've correctly understood what you want then that should do it. -- HTH, Nathan ___ cisco-nsp mailing list

Re: [c-nsp] Bridging ATM on 7206? (Getting really frustrated here)

2008-10-24 Thread Nathan
and not expensive as long as you don't deviate from the norm). I just can't believe a 7200 can't do this. I can't get a definitive response either way from the Cisco docs. Anyone? Please? -- Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https

Re: [c-nsp] Bridging ATM on 7206? (Getting really frustrated here)

2008-10-24 Thread Nathan
On Fri, Oct 24, 2008 at 10:10 AM, Joe Maimon [EMAIL PROTECTED] wrote: Nathan wrote: I can't believe this isn't simple! I just want to change the PVC on the [expletive] ATM cells and push them back the same way they came, how can that be so difficult? Are you looking for the local switching

Re: [c-nsp] Bridging ATM on 7206? (anything goes)

2008-10-24 Thread Nathan
(one for each VLAN), or just one tunnel with 802.1q tags, or even just one tunnel for one VLAN and another VLAN as default VLAN? -- Thanks, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp

Re: [c-nsp] EoMPLS terminating on PE?

2008-10-24 Thread Nathan
% capacity for a Cisco 12000 :-) Not that I've got the list price for a 12000 with ATM SMI and GBE cards in front of me, but something tells me it isn't going to happen. -- Thanks, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https

Re: [c-nsp] Bridging ATM on 7206? (anything goes)

2008-10-24 Thread Nathan
- ethernet2ATMconverter - ATM - 7200 - ATM - ethernet2ATMconverter - ethernet - my871 - LANs site B, where the LANs are currently two untagged RJ45s on each side but could be a single RJ45 with a dot1q trunk). In your opinion, no way of doing it with L2TP on my 871s? -- Thanks for your help, Nathan

Re: [c-nsp] Bridging ATM on 7206? (Getting really frustrated here)

2008-10-23 Thread Nathan
On Wed, Oct 22, 2008 at 3:04 PM, Nathan [EMAIL PROTECTED] wrote: On Wed, Oct 22, 2008 at 1:57 PM, Eric Kagan wrote: Just a thought - did you try 'atm route-bridged ip' on the atm sub-interfaces ? I just had to add this to a recent config in order for layer 3 to work. I took it OUT

Re: [c-nsp] Bridging ATM on 7206?

2008-10-22 Thread Nathan
On Tue, May 20, 2008 at 6:08 PM, Matthew Crocker [EMAIL PROTECTED] wrote: Nathan, It sounds like what you want to do should be possible. I'm not sure if the 7206 can do it or not. I'm pretty sure a Redback SE-400 can do it. ... I have no idea if this is even close to a working config

Re: [c-nsp] Bridging ATM on 7206?

2008-10-22 Thread Nathan
(Replying to list but removing Eric's e-mail address completely) On Wed, Oct 22, 2008 at 1:57 PM, Eric Kagan wrote: Just a thought - did you try 'atm route-bridged ip' on the atm sub-interfaces ? I just had to add this to a recent config in order for layer 3 to work. Oh yes, that's standard

Re: [c-nsp] EoMPLS terminating on PE?

2008-10-22 Thread Nathan
On Mon, Oct 20, 2008 at 12:54 PM, Oliver Boehmer (oboehmer) [EMAIL PROTECTED] wrote: Nathan wrote on Monday, October 20, 2008 10:29 AM: In effect, I want to extend the VC coming in on one PE so that it (L3) terminates on another PE. you need the routed pseudowire feature

Re: [c-nsp] question about service provider network design

2008-10-21 Thread Nathan
) connected by one WAN link, with all routers having an interface connected to both switches at its location? -- Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net

Re: [c-nsp] question about service provider network design

2008-10-21 Thread Nathan
On Tue, Oct 21, 2008, Adam Armstrong [EMAIL PROTECTED] wrote: Nathan wrote: - Is running OSPF on a switch at all useful when the switch is connecting routers that are running MPLS, MP-BGP, and OSPF? Can it provide faster detection of link loss? The routers can see each other directly at L2

Re: [c-nsp] question about service provider network design

2008-10-21 Thread Nathan
as possible in IGP (so just links and loopbacks), but i guess you already knew that! :) It's not stressed enough in docs about setting up iBGP and MP-BGP, unfortunately, but yes I did learn that later on :-/ Thanks, -- Nathan ___ cisco-nsp mailing list cisco

Re: [c-nsp] question about service provider network design

2008-10-21 Thread Nathan
of your routers, PE routers included, therefore you need your loopbacks in your IGP, therefore you need IGP on your PE routers. I suppose you could somehow make the network function without it, but you'd lose redundancy at the very least. -- Nathan

[c-nsp] EoMPLS terminating on PE?

2008-10-20 Thread Nathan
, -- Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] EoMPLS terminating on PE?

2008-10-20 Thread Nathan
problem? All the examples I've seen do xconnects between VLANs or between PVCs, not between a VLAN on one hand and a PVC on the other hand. Thanks, Nathan (Anxiously waiting to see if anyone has insights on my service provider network design question from a few days ago, no one's taken me up so far

Re: [c-nsp] Converting OSPF backbone to iBGP

2008-10-16 Thread Nathan
bgp 65000 subnets route-map JustATeensyFiftyRoutesOrSo results in redistribute bgp 65000 subnets and that *hurts* -- HTH Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive

[c-nsp] question about service provider network design

2008-10-15 Thread Nathan
missing or misunderstanding some crucial documentation or insight? Thanks for any comments, -- Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco

Re: [c-nsp] 3750, QinQ Jumbo Frames?

2008-10-15 Thread Nathan
and is configured with system mtu jumbo but only works on gigabit interfaces. I believe your switches have an FE maximum MTU of 1998, so if you are just making room for some QinQ headers on a 1500-byte packet then you have nothing to worry about :-) -- HTH, Nathan

[c-nsp] software for cable asset management?

2008-06-20 Thread Nathan Lee
recommendations for software that can manage physical layer assets reasonably well? Any comments on iTracs or Ulticam? TIA, Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net

Re: [c-nsp] IGP iBGP Configuration Problem in Transit AS

2008-06-16 Thread Nathan
between routers). In this context a mesh means that every router must be configured as an iBGP neighbor to all the others (plus restrictions in option b) above). -- HTH Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net

Re: [c-nsp] 7200s (VXRs and not) and MPLS capabilities

2008-06-12 Thread Nathan
, but doesn't mention that it chose the wrong outgoing interface. At the time I searched CCO for the bug, didn't find it, tested on 12.3, could not reproduce, and therefore upgraded to 12.3. -- HTH Nathan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

  1   2   >