Re: [c-nsp] IOS-XR OSPF path selection

2013-03-05 Thread C P
According to the below link, it's not quite as simple as the Cisco OSPF Design Guide writes: http://blog.ine.com/2011/04/04/understanding-ospf-external-route-path-selection/ ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] MPLS down to the CPE

2013-03-05 Thread Adam Vitkovsky
We are looking for pros/cons of doing so. Just to mention several aspects: -with adding CEs into your MPLS cloud you're going to increase the number of routes IGP has to carry. -you mentioned the CE is in customer premises dependent on their environment variables that can eventually contribute

Re: [c-nsp] MPLS down to the CPE

2013-03-05 Thread Saku Ytti
On (2013-03-05 09:58 +0100), Adam Vitkovsky wrote: -with adding CEs into your MPLS cloud you're going to increase the number of routes IGP has to carry. Unless you run OptB Security is the main concern I don't know about this one. How plausible is that customer will replace your device

Re: [c-nsp] MPLS down to the CPE

2013-03-05 Thread Benny Amorsen
Adam Vitkovsky adam.vitkov...@swan.sk writes: How plausible is that customer will replace your device with theirs without you noticing it + they crack all the passwords so they can run ISIS, LDP and BGP sessions with you. They don't need to do that. Just put a switch between the CE and the

Re: [c-nsp] MPLS down to the CPE

2013-03-05 Thread Saku Ytti
On (2013-03-05 11:06 +0100), Benny Amorsen wrote: Maybe one day we will get either strict MPLS label checks or L2 encryption and authentication. At that point the only attacks are to the CE itself. I am not holding my breath. You need lung capacity of just weeks. Next IOS-XR release will

Re: [c-nsp] MPLS down to the CPE

2013-03-05 Thread Phil Bedard
There are a number of solutions like using BGP labeled unicast, downstream on demand labels, or service level solutions like multi segment pseudowires. We have thousands of MPLS CPEs deployed at this point. Those endpoints are all L2 pseudowires, which are end to end or terminate into virtual L3

[c-nsp] Influence VTI tunnel QoS based on remote site bw change?

2013-03-05 Thread Fernando Santos
Good morning, I would like to ask you all for some suggestions. In my scenario there are several hundreds of remote sites and 2 central sites. We're using IPSec VTI tunnels between the remote and central sites. Each remote site has a primary and a backup circuit with different BW. We were

[c-nsp] Lightweight Access Point behind NAT

2013-03-05 Thread Terence Scott
Dear all, I am trying to deploy an Aironet 1242AG lightweight access point at a remote site which connects to the main office via an ADSL link. The ADSL modem also functions as a NAT gateway for this remote site. The problem I am facing is that although the LAP registers successfully with the

Re: [c-nsp] MPLS down to the CPE

2013-03-05 Thread Adam Vitkovsky
There are a number of solutions like using BGP labeled unicast, downstream on demand labels, or service level solutions like multi segment pseudowires Yes these all fall under the unified mpls umbrella EVPN should help out with things as well Yes the PBB-EVPN should be available this year adam

[c-nsp] Upgrading 12K IOS XR from 3.6 to 4.2

2013-03-05 Thread ibogzipper iboge
Hi, I'm in the process of upgrading 12K IOS XR from 3.6 to 4.2. But according to cisco upgrade path its seems to be from 3.6 - 3.9 , 3.9 - 4.2 ( http://www.cisco.com/web/Cisco_IOS_XR_Software/index.html#XR12000) . therefore i'm wondering that whether i can do turboboot . but there is no reference

Re: [c-nsp] MPLS down to the CPE

2013-03-05 Thread Adam Vitkovsky
I was concerned about the control plane security. And I admit I haven't thought about the data-plane security i.e. sniffing or forging of the PE to PE data type of attacks. So you are 100% sure that no one can access your wires under no circumstances in all of your backbone? I mean this is why

Re: [c-nsp] MPLS down to the CPE

2013-03-05 Thread Saku Ytti
On (2013-03-05 14:07 +0100), Adam Vitkovsky wrote: So you are 100% sure that no one can access your wires under no circumstances in all of your backbone? Not at all. But adding MPLS to customer would increase our exposure. -- ++ytti ___

Re: [c-nsp] Upgrading 12K IOS XR from 3.6 to 4.2

2013-03-05 Thread Grzegorz Janoszka
On 05-03-13 14:01, ibogzipper iboge wrote: Hi, I'm in the process of upgrading 12K IOS XR from 3.6 to 4.2. But according to cisco upgrade path its seems to be from 3.6 - 3.9 , 3.9 - 4.2 ( http://www.cisco.com/web/Cisco_IOS_XR_Software/index.html#XR12000) . therefore i'm wondering that

[c-nsp] summary, but leak a couple

2013-03-05 Thread Aaron
In ios xr how would I summarize all more specific's within this range, BUT leak a more specifics ? router bgp 64512 vrf one rd 1.1.1.1:1 address-family ipv4 unicast aggregate-address 10.0.0.0/8 summary-only but I want to leak, 10.10.10.0/24 how would I do that ? Aaron

Re: [c-nsp] Upgrading 12K IOS XR from 3.6 to 4.2

2013-03-05 Thread ibogzipper iboge
Thanks Grzegorz, down time window is the problem to go for 2 steps . rommon upgrades are in the FPD package but if i want to do the turboboot there is no way that i can install the new pie c12k-fpd.pie-4.2.4 on 3.6.2 and upgrade the rommon . is there any package that i can copy and upgrade the

Re: [c-nsp] Upgrading 12K IOS XR from 3.6 to 4.2

2013-03-05 Thread Aaron
Have you looked to see if you download the rommon separately? On Tue, Mar 5, 2013 at 10:48 AM, ibogzipper iboge ibogzip...@gmail.comwrote: Thanks Grzegorz, down time window is the problem to go for 2 steps . rommon upgrades are in the FPD package but if i want to do the turboboot there is

Re: [c-nsp] cisco nexus 6001/6004

2013-03-05 Thread James Slepicka (c-nsp)
25Mb per 3 QSFP ports. http://d2zmdbbm9feqrf.cloudfront.net/2013/eur/pdf/BRKARC-3453.pdf 6004 starts at $90k list. 6001 pricing is not finalized yet, but should be around half of that. -Original Message- From: cisco-nsp-boun...@puck.nether.net

Re: [c-nsp] Influence VTI tunnel QoS based on remote site bw change?

2013-03-05 Thread Dale Shaw
[resending using cisco-nsp subscribed address] On Mar 6, 2013 5:13 AM, Dale Shaw dale.s...@gmail.com wrote: Hi Fernando, On Mar 5, 2013 9:52 PM, Fernando Santos fernandomiguelsan...@gmail.com wrote: […] We were trying to figure out if there is a way to keep only 1 tunnel between each

Re: [c-nsp] Influence VTI tunnel QoS based on remote site bw change?

2013-03-05 Thread Fernando Santos
Thanks for the suggestion Dale, I'll have a look into that. In the meantime, if anybody has any more ideas please let me know. Regards, Fernando On 05/03/2013, at 18:13, Dale Shaw dale.s...@gmail.com wrote: Hi Fernando, On Mar 5, 2013 9:52 PM, Fernando Santos

[c-nsp] mac flap

2013-03-05 Thread harbor235
I hope someone has seen something like this: %SW_MATM-4-MACFLAP_NOTIF: Host .. in vlan 111 is flapping between port Fa0/15 and port Fa0/8 Fa0/15 and F0/8 are server ports,the servers connected to the ports are sending Ethernet frames destined to the all zero's mac address. What is

Re: [c-nsp] IOS XR and router rib rump always-replicate

2013-03-05 Thread Mattias Gyllenvarg
About that, Oliver, is multicast-BGP production ready in IOS ans IOS XR. Specifically ASR9k, 7606 Sup720, ME3600X and 3560/3750? Whould be nice too remove PIM from the core, just as Gert says limited use = limited support. On 1 March 2013 19:23, Gert Doering g...@greenie.muc.de wrote: Hi,

Re: [c-nsp] IOS XR and router rib rump always-replicate

2013-03-05 Thread Mikael Abrahamsson
On Wed, 6 Mar 2013, Mattias Gyllenvarg wrote: About that, Oliver, is multicast-BGP production ready in IOS ans IOS XR. Specifically ASR9k, 7606 Sup720, ME3600X and 3560/3750? People have been running multicast on XR (ASR9K) and 7600 since forever. I'd be more worried about ME3600X and