Re: [c-nsp] need help.....

2009-06-11 Thread jcovini
C2950(config)#vlan 0 Command rejected: Bad VLAN list - character #2 (EOL) delimits a VLAN number (0) out of the range 1..4094. But go and check the following doc, you will see that VLAN 0 can be used by a Cisco switch to forward DOT1P-tagged voices frames :

Re: [c-nsp] X2 to GigE

2009-04-21 Thread jcovini
Selon Skeeve Stevens ske...@eintellego.net: Hey All, I am looking at using a HP 10GbE switch with X2 slots but only X2 - no GigE. Why not using a Procurve 5406 with some J8707A modules (x4 port 10G slots) and J8436A transceivers (10-GbE X2-SC SR Optics), which runs fine with 50u

Re: [c-nsp] X2 to GigE

2009-04-20 Thread jcovini
Selon Skeeve Stevens ske...@eintellego.net: Hey All, I am looking at using a HP 10GbE switch with X2 slots but only X2 - no GigE. Why not using a Procurve 5406 with some J8707A modules (x4 port 10G slots) and J8436A transceivers (10-GbE X2-SC SR Optics), which runs fine with 50u MMF ?

Re: [c-nsp] 3560 vrf unwanted leaking when using tracked static route

2009-03-03 Thread jcovini
Fixed in 12.2.46 :) The problem you noticed is documented under the following bug ID: CSCsl31925 Externally found moderate defect: Duplicate (D) Static routes using VRF object tracking not working . . It eventually was found to be due to bug: CSCsf25288

Re: [c-nsp] Can I post the network question here?

2009-03-03 Thread jcovini
Why not running a dynamic routing protocol between Main, A, B, and C. ? Static routes = manual maintenance. Selon Deric Kwok deric.kwok2...@gmail.com: Hi all I have network question and hope you can help main router- 3 static routes ip route 192.168.0.0/24 10.0.0.1 (routerA) ip

Re: [c-nsp] 3560 vrf unwanted leaking when using tracked static route

2009-02-06 Thread jcovini
Just tried : it still installs the route with global flag ip route vrf Internet 192.168.0.0 255.255.255.0 Vlan999 9.9.9.9 global track 2 Selon Wouter Prins w...@null0.nl: Can you try to specify the outgoing interface in your static vrf route and test again? 2009/2/6 jcov...@free.fr Hey,

[c-nsp] 3560 vrf unwanted leaking when using tracked static route

2009-02-06 Thread jcovini
Hey, Got a strange behavior on a C3560 12.2(35)SE5. I am locally attached interface to 9.9.9.0/24 network where my next hop 9.9.9.9 is. This interface is member of vrf Internet I have a vrf static route, working perfect : ip route vrf Internet 192.168.0.0 255.255.255.0 9.9.9.9 As soon as I

[c-nsp] %VRF: does not exist

2009-01-27 Thread jcovini
Hi, Im trying to setup IP SLA IpIcmpEcho monitor inside a VRF, onto a C3560 running 12.2(35)SE5. However, Im facing an error msg stating my vrf doesn't exist : Switch#show ip vrf Internet Name Default RD Interfaces Internet 1:1

Re: [c-nsp] %VRF: does not exist

2009-01-27 Thread jcovini
You made my day, thanks Selon Gert Doering g...@greenie.muc.de: Hi, On Tue, Jan 27, 2009 at 10:23:01AM +0100, jcov...@free.fr wrote: Switch(config-rtr-echo)#vrf Internet %VRF: Internet does not exist Switch(config-rtr-echo)# From the error message this looks like you typed

[c-nsp] Quad FWSM

2008-10-29 Thread jcovini
Hi gents, Little question about FWSM redundancy. I didn't attend the trainings :) Scenario : - Four 6500/Sup7203bxl - Each one has a FWSM card. Is it possible to have FWSM in an Active/Stby/Stby/Stby setup ? Or does failover only works by pair ? Jerome

[c-nsp] CVR-X2-SFP

2008-05-14 Thread jcovini
Who can tell me whether the Twingig CVR-X2-SFP are supported in 6500 module WS-X6708-10G-3C ? cheerios Jerome Covini ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at

Re: [c-nsp] Transparent ASA 5510 on a dot1q Trunk

2008-04-08 Thread jcovini
Hi Chris, This is feasible if you use multiple contexts in transparent mode as described here : http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/examples.html#wp1010043 Basically you define all necessary vlan subifs into the global context, then you use them as

[c-nsp] 3750G and 3750E in a stack

2008-02-25 Thread jcovini
Hi all, Is it possible to mix C3750E and C3750 in stackwise thing ? I need to run a stack made of x2 C3750, but also x2 C3750E for ensuring 10Gig uplinks, is there any reason why the stackwise connection wouldn't be compatible between these two models ?

Re: [c-nsp] Ethernet over Coax

2007-12-04 Thread jcovini
I believe that is pretty obsolete... Last time I seen ethernet over coax it was maybe 10 years ago, and it was already obsolete... Jerome Selon Dracul [EMAIL PROTECTED]: Hi Guys, I'm reviewing cabling solutions. Has anyone tried the ethernet over coax? Has it improved over the years (they

[c-nsp] ASA/AIP-SSM-10 to replace a IDS-42xx

2007-10-19 Thread jcovini
Hi, Is it possible to use an ASA with a AIP-SSM-10 like a simple IDS sensor ? Idea is to span a vlan on a switchport, then connect and use the physical GE interface featured on the AIP-SSM-10 module to sniff traffic and report alerts. No IPS functionnality is needed. Is such a way of using

Re: [c-nsp] ASA/AIP-SSM-10 to replace a IDS-42xx

2007-10-19 Thread jcovini
Hi, Is it possible to use an ASA with a AIP-SSM-10 like a simple IDS sensor ? I am sorry, I did post on the wrong thread. I am going to start a new thread. -jc ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] ASA/AIP-SSM-10 to replace a IDS-42xx

2007-10-19 Thread jcovini
I quickly seek some docs about transparent mode, and the fact it implies to use two interfaces only - inside and outside. ... if I want to only do IDS, not IPS, i.e. if I only want to do threat report, not necessary filter or block a given malicious connexion, do you think it's possible to plug

Re: [c-nsp] ASA/AIP-SSM-10 to replace a IDS-42xx

2007-10-19 Thread jcovini
So transparent mode is equivalent to a L2 bridge, i.e. bump in the wire ? In this case I have to use 2 interfaces of the ASA and use it as a physical tap ? Selon Fred Reimer [EMAIL PROTECTED]: You can put the ASA in transparent mode so that you don't have to route through it, but the traffic

Re: [c-nsp] iphone, Cisco AP/WLC web-auth

2007-08-03 Thread jcovini
This is a classic when it comes to Wifi PDAs. Power save then reauth :/ On some WinCE.NET devices (only one I tested...) there is a powerscheme allowing only the LCD to be shutdown (CPU, Wifi and Speaker remains on, ex, for softphone ringing), and that's the only way to go I know. Maybe it's

Re: [c-nsp] Why it won't route vlan 1 ?

2007-05-16 Thread jcovini
Selon Gert Doering [EMAIL PROTECTED]: Hi, On Tue, May 15, 2007 at 07:51:29PM +0200, Jerome Covini wrote: Jared Mauch wrote: if you have vlan1 on more than one interface (eg: gig1/1 and gig1/2) they are actually the same vlan. This device is a switch, not an independent router.

Re: [c-nsp] Why it won't route vlan 1 ?

2007-05-16 Thread jcovini
Selon Lamar Owen [EMAIL PROTECTED]: Just out of curiosity, why are you migrating from the 8540's in the first place? What feature are you missing that the 12.1(26)E IOS can't do? These C8540 are reaching EOS next year, and our hardware support contract is ending this year.