Re: [c-nsp] Router Suggestion for console access?

2007-09-05 Thread Tim Franklin
On Tue, September 4, 2007 7:56 pm, Kevin Graham wrote: The downside is alot bigger than that, given that End of Renewal for them is less than a year away. Of all devices, a console server is certainly one I'd want to make sure got updates to PSIRT issues Really? I'd have thought it's an

[c-nsp] About tcp window size

2007-09-05 Thread Hiromasa Sekiguchi
Hello, About below condition. [client]--[cisco3745]-[Web server] When TCP connection starts between client and web server, they can't finish TCP connection. The TCP windows scaling is configured with web server. So, should we change the tcp window size on cisco3745? e.g.

[c-nsp] About tcp window size

2007-09-05 Thread Hiromasa Sekiguchi
Hello, About below condition. [client]--[cisco3745]-[Web server] When TCP connection starts between client and web server, they can't finish TCP connection. The TCP windows scaling is configured with web server. So, should we change the tcp window size on cisco3745? e.g.

Re: [c-nsp] About tcp window size

2007-09-05 Thread Lincoln Dale (ltd)
configuring ip tcp window-size on the router has nothing to do with the IP packets being forwarded _through_ the router. a client that cannot complete a TCP session is a classic symptom of an incorrect MTU somewhere and PMTUD failing to perform its task. is your topology really that simple as 3

[c-nsp] SFP- Fiber that Does 1.25 Gbps

2007-09-05 Thread Raymond Macharia
Hello all, I am looking for an SFP that has a reasonable price that does 1.25 Gbps and works with a Cisco 3560G 24TS switch. I have done a search on Cisco's site and found one known as the CWDM SFP problem is the price tag quoted by cisco will buy me 4 more 3560 switches. Is there any none Cisco

Re: [c-nsp] Strange ARP problem between 3560 and Linksys

2007-09-05 Thread Raymond Macharia
Sounds like STP to me, how have you configured the STP. please privide a simple schematic of physical connections. will help in narrowing down to the source of your problem Raymond Macharia On 9/4/07, Garry Glendown [EMAIL PROTECTED] wrote: Hi, I've had some strange problem at a customer

Re: [c-nsp] Router Suggestion for console access?

2007-09-05 Thread Kevin Graham
There shouldn't be any customer traffic going anywhere near it; in fact, something upstream should be dropping packets not from your management network before they get close. I invoked PSIRT as a generic bug you really want to fix example. That console server is one the most critical devices

[c-nsp] Cisco Security Advisory: Cisco Video Surveillance IP Gateway and Services Platform Authentication Vulnerabilities

2007-09-05 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Video Surveillance IP Gateway and Services Platform Authentication Vulnerabilities Advisory ID: cisco-sa-20070905-video http://www.cisco.com/warp/public/707/cisco-sa-20070905-video.shtml Revision 1.0 For Public

[c-nsp] Cisco Security Advisory: Denial of Service Vulnerabilities in Content Switching Module

2007-09-05 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Denial of Service Vulnerabilities in Content Switching Module Document ID: 97826 Advisory ID: cisco-sa-20070905-csm http://www.cisco.com/warp/public/707/cisco-sa-20070905-csm.shtml Revision 1.0 For Public Release 2007

[c-nsp] bgp connection refused

2007-09-05 Thread O S
Hi all, This should be simple but I failed to find out why. I have two cisco routers connected via an eth--l2 mpls--eth. But the bgp connections between two routers are refused. Any help will be appreciated. Thanks, OS router-a (c3825-advipservicesk9-mz.124-9.T3.bin): router bgp 65470

Re: [c-nsp] SFP- Fiber that Does 1.25 Gbps

2007-09-05 Thread sthaug
I am looking for an SFP that has a reasonable price that does 1.25 Gbps and works with a Cisco 3560G 24TS switch. I have done a search on Cisco's site and found one known as the CWDM SFP problem is the price tag quoted by cisco will buy me 4 more 3560 switches. Is there any none Cisco one that

Re: [c-nsp] bgp connection refused

2007-09-05 Thread David Prall
I would suspect because you are using the outgoing interface as the source address, instead of a loopback. You need to add update-source loopback X. As well you have ebgp-multihop defined for an ibgp peering within a peer-group definition. A peer-group definition can be either ibgp or ebgp, but

Re: [c-nsp] bgp connection refused

2007-09-05 Thread Tolstykh, Andrew
Incorrect local address, update your configuration with the appropriate source interface: Neighbor X.X.X.X update-source source interface Sep 5 17:15:50.359 GMT: BGP: 10.170.150.9 open active, local address 10.170.132.17 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

Re: [c-nsp] SFP- Fiber that Does 1.25 Gbps

2007-09-05 Thread Barton F. Bruce
Other than as a happy customer, I have no connection to: http://www.fluxlightinc.com/ , but suggest you call them WRT your cisco problems. They seem to be quite familiar with the issues. I am looking for an SFP that has a reasonable price that does 1.25 Gbps and works with a Cisco 3560G 24TS

Re: [c-nsp] Strange ARP problem between 3560 and Linksys

2007-09-05 Thread Garry Glendown
Raymond Macharia wrote: Sounds like STP to me, how have you configured the STP. please privide a simple schematic of physical connections. will help in narrowing down to the source of your problem A===B | | L A/B Cisco 3560 L Linksys On Cisco

[c-nsp] Will a WS-G5483 work in a WS-X5403?

2007-09-05 Thread Jeff Crowe
Hi all, Can someone tell me if a WS-G5483 GBIC TX adapater work with the WS-X5403 Gig Card in a 5500? Thanks Jeff. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at

[c-nsp] Learning Resources...

2007-09-05 Thread Justin Scott
Good afternoon, sorry if this is off-topic. I've been a network/systems administrator for small networks for several years, so small that they generally only have one router out to the public Internet and that's about as advanced as I've dealt with. I'm trying to learn more about higher-level

Re: [c-nsp] bgp connection refused

2007-09-05 Thread Fedorov, Konstantin
Hi router bgp 65470 neighbor GRP1 remote-as 65470 neighbor GRP1 ebgp-multihop 4 neighbor 10.170.150.9 peer-group GRP1 This is IBGP, not EBGP. First remove ebgp-multihop , and try. --- Sincerely Yours, Konstantin Fedorov -Original Message- From: [EMAIL PROTECTED]

Re: [c-nsp] ACS and ASA VPN user authentication

2007-09-05 Thread Nicholas Weaver
Yeah, I basically use the IAS rule to define which group they belong to in Active Directory and then pass back the RADIUS value to choose the corresponding group I created in ASA. I had 3 different groups and it worked great. I just make sure that the higher level groups are higher in the rule

Re: [c-nsp] GSR-12008 -----%SYS-2-CHUNKBOUNDS

2007-09-05 Thread Aaron
Check the amt of memory on the card. Is it what you expected? Are you taking full routes? Aaron On 9/4/07, John van Oppen [EMAIL PROTECTED] wrote: I am assuming you mean the interface on the line card is shutdown. If so, that is the normal behavior as dCEF is still enabled on a card with

Re: [c-nsp] About tcp window size

2007-09-05 Thread Hiromasa Sekiguchi
Hi, Thank you for your advices. I'll check them. Regards, Hiromasa Lincoln Dale (ltd) wrote [2007/09/05 19:24(JST)]: configuring ip tcp window-size on the router has nothing to do with the IP packets being forwarded _through_ the router. a client that cannot complete a TCP session is a

[c-nsp] 646-058 exam resources

2007-09-05 Thread Brett Looney
Greets, Does anyone have a place where I can get resources for the 646-058 (Cisco Lifecycle Services Advanced Routing and Switching) exam? The Cisco page: http://www.cisco.com/web/learning/le3/current_exams/646-058.html gives an outline but I need the in-depth stuff. Thanks! B.