Re: [c-nsp] router as bridge for netflow exports

2008-08-04 Thread Stig Johansen
Setup a sniffer and use netflow export on it. See f.ex. http://www.ntop.com/nProbe.html Best regards, Stig Meireles Johansen -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Dan Letkeman Sent: 3. august 2008 18:19 To: cisco-nsp@puck.nether.net Subject:

[c-nsp] NPE-G2 Adjustable MTU

2008-08-04 Thread Soon Kian
Hi Guys, Has anyone successfully increase the interface MTU on the tunnel with MPLS VPN Inter-AS command mpls bgp forwarding configured at the same time ? So far I have tried several IOS feature, they can only support either but not both commands @ the same time. We are trying to establish

Re: [c-nsp] Filtering telnet without ACL

2008-08-04 Thread David Freedman
I think if I loosen the definition of telnet I can win here. no transport input telnet on the VTYs. Then connect your console/aux into your terminal server / DCN and access it via telnet. Dave. Joost greene wrote: Hello, Someone challenged me with a question on how i can filter telnet

Re: [c-nsp] 6509 ACE/FWSM Modules??????????

2008-08-04 Thread Hashiru Aminu -X (haminu - SSAI at Cisco)
I would say for Design reference this is really good and informativeyou might wana take a look at it http://www.cisco.com/application/pdf/en/us/guest/netsol/ns376/c649/ccmig ration_09186a008078de90.pdf your first puzzle will be the logical placement of the module and the devices and the

Re: [c-nsp] LDP Graceful restart

2008-08-04 Thread Hashiru Aminu -X (haminu - SSAI at Cisco)
Your answer is Yes, logically you can have graceful restart on a router that does not have multiple RSP, but you will need to have the neighboring router to at least have the NSF/SSO feature Take a look at this link. http://www.cisco.com/en/US/docs/ios/mpls/configuration/guide/mp_ldp_grac

Re: [c-nsp] MPLS PE Routers for a Mobile Carrier?

2008-08-04 Thread Stephen Fulton
WAN being SIP (be careful with ES20). Would you mind elaborating on that? I'm leaning toward the ES20 at the moment for our needs.. -- Stephen Saku Ytti wrote: On (2008-08-02 17:52 -0300), Rubens Kuhl Jr. wrote: AFAIK, ASR 1000 or 4500/Sup6-E don't support MPLS in current software

[c-nsp] buffer leak in 12.4(19)?

2008-08-04 Thread Adam Greene
Hi, I have a 2811 router running Advanced IP Services 12.4(19) which has been acting funny. First issue I had was after inserting (2) WIC-1ADSL cards the processor jumped to 99%. After shutting down the interfaces and rebooting, the router went back to normal. Now the router is becoming

Re: [c-nsp] Adding vlan 1 to vlan-group

2008-08-04 Thread Stig Johansen
Sure is.. it's called a cable, and runs from a port in your vlan 1 to a port in another vlan which you configure on your ACE-module. :) Best regards, Stig Meireles Johansen -Opprinnelig melding- Fra: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] På vegne av Teller, Robert Sendt: 4. august

Re: [c-nsp] buffer leak in 12.4(19)?

2008-08-04 Thread Adam Greene
Cisco 2811 (revision 53.51) with 245760K/16384K bytes of memory. - Original Message - From: Alex Moya [EMAIL PROTECTED] To: Adam Greene [EMAIL PROTECTED] Cc: cisco-nsp@puck.nether.net Sent: Monday, August 04, 2008 2:28 PM Subject: Re: [c-nsp] buffer leak in 12.4(19)? How much men

Re: [c-nsp] buffer leak in 12.4(19)?

2008-08-04 Thread Alex Moya
Should work fine.You could have a bad card Sent from my iPhone On Aug 4, 2008, at 3:41 PM, Adam Greene [EMAIL PROTECTED] wrote: Cisco 2811 (revision 53.51) with 245760K/16384K bytes of memory. - Original Message - From: Alex Moya [EMAIL PROTECTED] To: Adam Greene [EMAIL

[c-nsp] CPE for IPSEC

2008-08-04 Thread Michael Malitsky
Greetings, The auditors are trying to force me to encrypt our WAN traffic. The WAN in question is Cogent's ethernet service - built as a mesh of point-to-point VLANs. There are 3 sites, at every site I have a single port over which I receive 2 VLANs in a dot1q trunk. Aggregate bandwidth on the

[c-nsp] DSCP / NAT

2008-08-04 Thread Paul Stewart
Hi folks. This is probably a dumb question ;) Is there any way for a packet that hits NAT to have it's DSCP bits honored? For example: Interface FastE0 - public IP - ip nat outside Interface FastE1 - private IP - ip nat inside Device attached to FastE1 sends DSCP 46 - looking

Re: [c-nsp] DSCP / NAT

2008-08-04 Thread Church, Charles
I thought that was the default action for most NATing devices? I'm pretty sure the 12.4 Cisco devices I've used all do that. Chuck -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Paul Stewart Sent: Monday, August 04, 2008 8:45 PM To:

Re: [c-nsp] DSCP / NAT

2008-08-04 Thread Darryl Dunkin
Correct, it should just go straight through, NAT translates the address/port only. It should not touch the rest of the packet unless otherwise configured. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Church, Charles Sent: Monday, August 04, 2008 18:06