Re: [c-nsp] 7600 interfaces not showing as down

2009-01-14 Thread Mark Tech
Got it, seems to work well, thanks all - Original Message From: Peter Rathlev pe...@rathlev.dk To: Mark Tech techcon...@yahoo.com Cc: cisco-nsp@puck.nether.net Sent: Tuesday, January 13, 2009 5:46:59 PM Subject: Re: [c-nsp] 7600 interfaces not showing as down On Tue, 2009-01-13 at

[c-nsp] Where do you buy used Cisco equipment?

2009-01-14 Thread Hank Nussbacher
1) I do not want to hear from resellers - I would like to hear from users - where do you buy your used Cisco equipment? 2) How do you handle IOS downloads for used equipment? What do you need to buy from Cisco for this? 3) What about servicing? Does Cisco offer service contracts on someone

[c-nsp] CCIE tracks

2009-01-14 Thread Gabbar
Hi, Anyone working in a service provider or telco and done the CCIE (service provider)? I'm thinking of doing this, but am not sure of value/differences with say the CCIE (routing/switching) track. Any comments, opinions will be appreciated. Regards, Gabb. Stay connected to the

Re: [c-nsp] CCIE tracks

2009-01-14 Thread Mohammad Khalil
hey man , please contact de...@fasttelco.net he has 2 CCIE , service provider and RS Best Regards, Mohammad Khalil Date: Wed, 14 Jan 2009 02:17:46 -0800 From: gabbarsingh9...@yahoo.com To: cisco-nsp@puck.nether.net Subject: [c-nsp] CCIE tracks Hi, Anyone working in a service provider

[c-nsp] L2TP problem in Cisco 1841

2009-01-14 Thread kharananda
Dear All, Is there any issue with L2TP in Cisco1841 ? I am using c1841-adventerprisek9-mz.124-16.bin IOS. I am facing drops after few successive ping packets. Can it be MTU issues?? I tried with global config ip tcp path-mtu-discovery to address if it is MTU issue but in vain. Regards,

[c-nsp] Stream Association Failed: Requested codec=0x5=g711ulaw, Negotiated codec=0xFFFFFFFF=No Code

2009-01-14 Thread Aljula Hasa
Hi, I am trying to run TCL IVR v2.0 script. The voice/audio is not heard. TCL IVR application seems to run ok but don't hear voice for the reason Stream Association Failed: Requested codec=0x5=g711ulaw, Negotiated codec=0x=No Code. How to set codec g711ulaw in gateway? The dial-peer is

Re: [c-nsp] Stream Association Failed: Requested codec=0x5=g711ulaw, Negotiated codec=0xFFFFFFFF=No Code

2009-01-14 Thread Brian Turnbow
A dial peer pots cannot have a codec You need to place it the voip dial peer. The defualt codec is g729 , you can change it by setting a default codec clas using voice class codec Regards Brian -Original Message- From: cisco-nsp-boun...@puck.nether.net

Re: [c-nsp] CCIE tracks

2009-01-14 Thread Dave Kruger
Hey Gabb I've worked for two internet providers (one was a telco) - and attempted the SP lab exam in November. And I must say, majority of the topics in the blueprint are used in the real world. I haven't attempted RS yet - but from what I understand SP concentrates more on bgp, and in

[c-nsp] SNMP OID cpumem on 6500

2009-01-14 Thread Charuntorn Baimoung
Hi How can I know SNMP OID cpumen and maybe pps on 6500 each module. Somebody help me. Thanks, Charuntorn -- Network Operation Center (NC) Internet Thailand Public Company Limited Tel : +662-257-7111 Fax : +662-257-7275

[c-nsp] X25 / PAD / Aux Port Problem

2009-01-14 Thread Anton . Schweitzer
Hi, we need to connect a cash box to a cisco router. It seems there is an solution using the aux port auf the router for this. I got a config for a router but something seems missing or not correct. We want to use service pad to-xot and pad from-xot The thing is that im a total X25 idiot, so

Re: [c-nsp] 6513 SVI issues with SXH4 and SXI SUPs WS-SUP720-3BXL

2009-01-14 Thread Alexandre Snarskii
On Tue, Jan 13, 2009 at 01:49:30PM -0500, Manuel Mar?n wrote: Hi Phil Attached are the SVI and interface configs #TRUNK TO CISCO 3750 interface GigabitEthernet6/24 description Barrancas switchport switchport trunk encapsulation dot1q switchport trunk native vlan 1000 mls

[c-nsp] Securing a shared IP SAN

2009-01-14 Thread Robert Blayzor
I have a project where I need to implement a shared IP SAN (ISCSI) network of about a dozen users with various clients. Since everything is in one colo, I'd like to keep this simple by keeping it layer2 as much as possible and not get into the mess of having the client have to use routes

Re: [c-nsp] Securing a shared IP SAN

2009-01-14 Thread Ross Vandegrift
On Wed, Jan 14, 2009 at 08:58:58AM -0500, Robert Blayzor wrote: Of course I'm open to any other suggestions on securing this at L2, keeping in mind two things. The ISCSI target cannot talk VLANing and cannot be multihomed. (I guess it makes best use via MPIO in the ISCSI protocol) It

Re: [c-nsp] Securing a shared IP SAN

2009-01-14 Thread Robert Blayzor
On Jan 14, 2009, at 10:14 AM, Ross Vandegrift wrote: I'd strongly suggest you reconsider the bias against L3 serperation. It's vastly simpler and, so long as you are doing hardware forwarding on the 6500, it has no performance impact. I've got a few VLANs of iSCSI installations that work like

[c-nsp] BGP default-originate route

2009-01-14 Thread Scott Ingram
I'm trying to assess the best options on implementing site redundancy to the network default-originate for all my MPLS sites Internet traffic.I'm trying to validate if I could have 2 CE's within the MPLS network using the default-originate and supply the best path. IMPORTANT NOTICE:

[c-nsp] Cisco ACS

2009-01-14 Thread Mohammad Khalil
Hey all , im trying to use Cisco ACS v3.3 as a radius with modification of av-pair attributes ?? can this be done ? anyone has a document that assist in this ?? thanks in advance _ Invite your mail contacts to join your friends

Re: [c-nsp] 6513 SVI issues with SXH4 and SXI SUPs WS-SUP720-3BXL

2009-01-14 Thread Manuel Marín
Does the SRA IOS version works for the cisco 6513? Checking the cisco download section for the cisco 6513 it seems that only SXH, SXF and SXI are available for 6513 with WS-SUP720-3BXL -Original Message- From: Alexandre Snarskii [mailto:s...@snar.spb.ru] Sent: Wednesday, January 14,

[c-nsp] Cisco Security Advisory: IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities

2009-01-14 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities Advisory ID: cisco-sa-20090114-ironport Revision 1.0 For Public Release 2009 January 14 1600 UTC (GMT

Re: [c-nsp] BGP default-originate route

2009-01-14 Thread Scott Ingram
Brad, Thanks for the reply and the thought process. I think to keep it simple all I want is to do one site primary and the other standby only. From: Brad Hedlund [mailto:brhed...@cisco.com] Sent: Wed 1/14/2009 12:14 PM To: Scott Ingram;

Re: [c-nsp] BGP default-originate route

2009-01-14 Thread Brad Hedlund
On 1/14/09 11:19 AM, Scott Ingram sing...@clayton.com wrote: I think to keep it simple all I want is to do one site primary and the other standby only. Scott, I'm sure the SP guys will jump in at this point but that should be a fairly straight forward setup, where the standby site's PE is

[c-nsp] AS53 Cards

2009-01-14 Thread Andrew Jimmy
I'm intrested in buying the following cards AS535-DFC-8CE1 AS5XM-VUFC-108NP But supplier is quoting for instead: AS54-DFC-8CE1 and AS54-DFC/VUFC-108NP Is there any difference between the above mentioned cards.

[c-nsp] 3560 QoS/shaping

2009-01-14 Thread Jon Lewis
I'm configuring my first 3560s, and am a little shocked to see that per-port output policing (via service-policy output policyname) as we've done for years on 3550s isn't permitted on the 3560. Trying it results in police command is not supported for this interface Configuration failed!

[c-nsp] vrf source selection

2009-01-14 Thread Rado Vasilev
Hi All, I'd appreciate your feedback on Cisco's vrf selection feature ( http://www.cisco.com/en/US/docs/ios/12_0s/feature/guide/vrfselec.html ). I'm planning to use it on 7609/Sup720-3B/PFC3 for diverting traffic over LDP LSP (MPLS L3 VPN) to wholesale ISP partners. I'm interested if

[c-nsp] OSPF domain-id secondary ?

2009-01-14 Thread kevin gannon
I noticed this option today but can not find a real life use for it ? Anyone using it and might shed some light ? regards Kevin ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at

[c-nsp] Sourcing TACACS and Syslog on PIX (6.x) to go over VPN

2009-01-14 Thread ChrisSerafin
If I have a Tacacs and syslogs servers available via VPN and would like a remote PIX running 6.x code, how would I source the traffic? I see you can source the interface, but will this send it through the VPN or just send it out the inside interface? *tacacs-server (inside) host

Re: [c-nsp] Management Interface 2960

2009-01-14 Thread Adam g
hmm. Then is there any purpose for having a loopback interface on a 2960? I am able to configure one, along with the default gateway. On Tue, Jan 13, 2009 at 4:33 PM, James Baker james.ba...@chelmer.co.nzwrote: Hi Adam Loopback is only available on Layer 3 devices. Refer:

[c-nsp] What to do with old Cisco kit

2009-01-14 Thread Pavel Skovajsa
Hello all, Can you please recommend a process by which one should properly dispose old Cisco kit, preferably by selling to refurbishing vendors etc. South Africa or EMEA preffered. Regards, Pavel Skovajsa ___ cisco-nsp mailing list

Re: [c-nsp] GRE on Cat-4948 switch

2009-01-14 Thread Geyer, Nick
I tried this once as a 'last shot' solution for a problem I was encountering, across gig network with sustained traffic rate over the tunnel of around 80Mbps. CPU instantly skyrocketed and the switch cried no more. The switch had very minimal other traffic (around 20Mbps) and very basic config, no

Re: [c-nsp] Max number of users on Aironet 1252AG

2009-01-14 Thread David Hughes
On 12/01/2009, at 1:15 PM, Tony wrote: A previous poster suggested 25-30 users per AP. A quick search reveals quite a few credible sites with similar figures. I'm sure you can do the math, that's quite a few AP's. Yup, 30 per 1200 class AP is a fair number. Thats the sort of density we

Re: [c-nsp] Sourcing TACACS and Syslog on PIX (6.x) to go over VPN

2009-01-14 Thread Alex Moya
Make sure to source it from a ip addres that can send traffic over the VPN Sent from my iPhone On Jan 14, 2009, at 3:09 PM, ChrisSerafin ch...@chrisserafin.com wrote: If I have a Tacacs and syslogs servers available via VPN and would like a remote PIX running 6.x code, how would I

Re: [c-nsp] 6513 SVI issues with SXH4 and SXI SUPs WS-SUP720-3BXL

2009-01-14 Thread Antonio Soares
Yes they work. You need to look under the 7600 IOS options. Regards, Antonio Soares, CCIE #18473 (RS) amsoa...@netcabo.pt -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Manuel Marín Sent: quarta-feira, 14 de Janeiro

Re: [c-nsp] 3560 QoS/shaping

2009-01-14 Thread Brad Henshaw
Jon Lewis wrote: I'm configuring my first 3560s... you can't police the output of a port you can't even define an output service-policy for a port. This is correct as far as I'm aware. It appears the 3560-way to do this is to use srr-queue bandwidth shape on the interface, but the syntax

Re: [c-nsp] 3560 QoS/shaping

2009-01-14 Thread Jon Lewis
On Thu, 15 Jan 2009, Brad Henshaw wrote: you can't police the output of a port you can't even define an output service-policy for a port. This is correct as far as I'm aware. This is awfully disappointing considering the 3560 is supposed to be the successor to the 3550. You can try the

Re: [c-nsp] 3560 QoS/shaping

2009-01-14 Thread Brad Henshaw
Jon Lewis wrote: That also won't work in this special case, as the rate-limiting/shaping is only to be done on a class of traffic, and only if that traffic has to egress through a particular port. Under normal conditions, the traffic won't need to be shaped. In that case I think you're

Re: [c-nsp] 3560 QoS/shaping

2009-01-14 Thread Yan Filyurin
Not that I am mentioning anything that hasn't been discovered, but here are two great articles about it: http://blog.internetworkexpert.com/2008/02/23/catalyst-qos-3550-explained/#more-81 http://blog.internetworkexpert.com/tag/3550/ Neither one of them answers your question, but I think with

Re: [c-nsp] 3560 QoS/shaping

2009-01-14 Thread Yan Filyurin
What's the difference between normal and special condition. As in are you able to do something with it, where it could go either to a shaped queue or a shared queue based on its DSCP for example? From: Brad Henshaw brad.hens...@qcn.com.au To: Jon Lewis