Re: [c-nsp] Ethernet to ATM local connect

2009-02-04 Thread Mohammad Khalil
http://www.cisco.com/en/US/docs/ios/12_0s/feature/guide/qinq.html#wp1043332 Date: Tue, 3 Feb 2009 22:21:06 + From: rekordmeis...@gmail.com To: cisco-nsp@puck.nether.net Subject: [c-nsp] Ethernet to ATM local connect Hi there Is there a cisco platform / sw out there that can the

[c-nsp] VSS upgrade problems

2009-02-04 Thread Holemans Wim
I'm testing a VSS solution for our campus network, most things seem to work as expected. I ran however into problems when testing the eFSU upgrade procedure. The system came with ip base 12.33SXH4 on, I created the cluster with this version without problem (although the notes state that you

Re: [c-nsp] Ethernet to ATM local connect

2009-02-04 Thread Arie Vayner (avayner)
Hi, Take a look here: http://www.cisco.com/en/US/products/hw/routers/ps368/module_installation _and_configuration_guides_chapter09186a0080440138.html#wp1135748 Then, using ES20 for Ethernet with EVC, you have the option to bridge-domain a QinQ VLAN to the same global SVI. I have never tested

[c-nsp] VPN with Static mapping - ASA5520

2009-02-04 Thread Mikisa Richard
Hi all, Scenario is the need to create a VPN tunnel to remote site but remote site requires that the machine (local host) they connect to have a public IP. So I have setup a static mapping 10.101.25.25 - 41.202.X.X. The tunnel comes up but the connection to the 10.101.25.25 fails. Conf

[c-nsp] OSPF and metrics

2009-02-04 Thread Ian MacKinnon
Hi All, I think my brain is misfiring today. I am trying to provide some backup services between to gateway routers, on one router I just have a simple route statetment, and on the second router I have the same route with a metric on the end :- router 1 ip route 10.0.0.0 255.255.255.0

Re: [c-nsp] OSPF and metrics

2009-02-04 Thread Ian MacKinnon
and what is the default distance of OSPF? yes its 110, so you need to make the floating route have a distance higher than that! So, all working now. On 04/02/2009 11:37, Ian MacKinnon wrote: Hi All, I think my brain is misfiring today. I am trying to provide some backup services between

[c-nsp] Ethernet VPN circuits

2009-02-04 Thread Rens
Hi, We have a provider that has a new product and I would like to know if I could use it with our current infrastructure to interconnect sites. This is how it works on the provider site: 1 Central Site where everything arrives Multiple Remote Sites that you can connect to the Central

[c-nsp] access list help

2009-02-04 Thread Deric Kwok
Hi All I am new in cisco and trying to config the access list in my switch My switch ip is 192.168.0.118 I am trying to block the http traffic in the host 192.168.0.115 When I do it in, I can not accces the switch ! But I can access http://192.168.0.115 Can you help what is wrong? Can you

Re: [c-nsp] ASA 5520 Remote Access VPN

2009-02-04 Thread Eimantas Zdanevičius
Sigurbjörn Birkir Lárusson wrote: Hmm, assuming you are using the Cisco VPN client you shouldn't be getting a default if the split-tunnel configuration is working http://www.cisco.com/en/US/products/ps6120/products_configuration_example091 86a0080702999.shtml#s2 Has pretty good ASDM

Re: [c-nsp] access list help

2009-02-04 Thread Steve Bertrand
Deric Kwok wrote: Hi All I am new in cisco and trying to config the access list in my switch My switch ip is 192.168.0.118 I am trying to block the http traffic in the host 192.168.0.115 When I do it in, I can not accces the switch ! But I can access http://192.168.0.115 Can you

Re: [c-nsp] ASA 5520 Remote Access VPN

2009-02-04 Thread Sigurbjörn Birkir Lárusson
It shouldn't be sending you a default route at all, just the tunnel routes BR, Sibbi On 4.2.2009 14:05, Eimantas Zdanevičius eiman...@occ.lt wrote: Sigurbjörn Birkir Lárusson wrote: Hmm, assuming you are using the Cisco VPN client you shouldn't be getting a default if the split-tunnel

Re: [c-nsp] Fast UDLD timers in SXI?

2009-02-04 Thread Mauritz Lewies
I've not had much chance to play with it but will Ethernet CFM not work for this? On Wed, 2009-02-04 at 08:49 +1000, David Hughes wrote: Yup, that's exactly the situation. STP will work around some of the problem caused by this but if you are presenting an etherchannel over multiple

[c-nsp] PPPoA sessions

2009-02-04 Thread Mohammad Khalil
Hey all , i have a router with PPPoE and PPPoA sessions i used to the OID 1.3.6.1.4.1.9.9.194.1.1.1 to draw the PPPoE sessions i searched for OID to draw the PPPoA but didnt find an OID for it can anyone help ?? _ Invite your mail

Re: [c-nsp] access list help

2009-02-04 Thread Deric Kwok
Hi Steve Thank you. I don't understand why I can access http://192.168.0.115 if this access-list is valid ? My access list doesn't block www traffic to http://192.168.0.115 but block telnet / www to switch 192.168.0.118 I also don't understand about access-list 120 permit any any If I have

Re: [c-nsp] ASA 5520 Remote Access VPN

2009-02-04 Thread Eimantas Zdanevičius
Sigurbjörn Birkir Lárusson wrote: It shouldn't be sending you a default route at all, just the tunnel routes BR, Sibbi Problem solved. Default route was overrided by linux NetworkManager (vpnc) software on vpnclient machine. I need to set 'Use this connection only for resources on this

Re: [c-nsp] reacheability issue in MEL link

2009-02-04 Thread Ahmed Mohamed
CEMetroethernet(carrier)-switchethernet(cable)-PE for a link as simple as above, if : + the CE , the Agg. switch and the PE interfaces are in the same vlan + the CE and the PE IP interfaces are in the same subnet the i must (at least)

Re: [c-nsp] access list help

2009-02-04 Thread Steve Bertrand
Deric Kwok wrote: Hi Steve Thank you. I don't understand why I can access http://192.168.0.115 http://192.168.0.115/ if this access-list is valid ? My access list doesn't block www traffic to http://192.168.0.115 http://192.168.0.115/ but block telnet / www to switch 192.168.0.118

Re: [c-nsp] PPPoA sessions

2009-02-04 Thread Frank Bulk - iName.com
I've asked this before on cisco-bba: there doesn't appear to be an OID for that. I'm afraid you might need to screen-scrape. Frank -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Mohammad Khalil Sent: Wednesday, February

Re: [c-nsp] PPPoA sessions

2009-02-04 Thread Wayne Lee
On Wed, Feb 4, 2009 at 3:39 PM, Frank Bulk - iName.com frnk...@iname.com wrote: I've asked this before on cisco-bba: there doesn't appear to be an OID for that. I'm afraid you might need to screen-scrape. Frank -Original Message- From: cisco-nsp-boun...@puck.nether.net

Re: [c-nsp] access list help

2009-02-04 Thread Tim Franklin
On Wed, February 4, 2009 3:04 pm, Deric Kwok wrote: I don't understand why I can access http://192.168.0.115 if this access-list is valid ? My access list doesn't block www traffic to http://192.168.0.115 but block telnet / www to switch 192.168.0.118 Is your switch being a *switch* in

Re: [c-nsp] ASA 5520 Remote Access VPN

2009-02-04 Thread Sigurbjörn Birkir Lárusson
Hmm, assuming you are using the Cisco VPN client you shouldn't be getting a default if the split-tunnel configuration is working http://www.cisco.com/en/US/products/ps6120/products_configuration_example091 86a0080702999.shtml#s2 Has pretty good ASDM instructions on how to do this, I don't use

Re: [c-nsp] Ethernet VPN circuits

2009-02-04 Thread Dean Smith
Cant speak for your product...but in the UK we've used similar from the 4 or 5 biggest suppliers at the all work the same... At the central site access is delivered over a single high B/W Trunk. We (Customer) and supplier agree a vlan tag per site. At the remote site the port is provided with no

Re: [c-nsp] VSS upgrade problems

2009-02-04 Thread Gert Doering
Hi, On Wed, Feb 04, 2009 at 10:51:09AM +0100, Holemans Wim wrote: ip base 12.33 SXI without problem. The I decided to test the eFSU upgrade procedure (available from 12.33SXI) which should give no downtime at all (if all your connections are trunks to both chassis). I tried to upgrade from ip

[c-nsp] Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers

2009-02-04 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers Advisory ID: cisco-sa-20090204-wlc http://www.cisco.com/warp/public/707/cisco-sa-20090204-wlc.shtml Revision 1.0 For Public Release 2009 February 04 1600 UTC (GMT

Re: [c-nsp] VSS upgrade problems

2009-02-04 Thread oles
tried to upgrade from ip base 12.33SXI to ip services 12.33SXI. This 01:02:21: %RF-SW2_SP-5-RF_RELOAD: Peer reload. Reason: RF Client RFS RF(520) notification timeout Hi, I guest you have the problem I had with my (VSS/SXI) AND (a big setup file, lot of ports, lot of port channels ...). I

Re: [c-nsp] Cisco 3750E

2009-02-04 Thread Sigurbjörn Birkir Lárusson
The claimed forwarding rate is 101.2Mpps. Assuming full-duplex and maximum speed used on all ports at the same time (48*2+2*20=136Gbit=17Gbyte/sec of traffic) means that the average packet size would have to be less than 168 bytes for you not to get wirespeed forwarding. Given that I think you

[c-nsp] WAE/WAAS in VRF environment

2009-02-04 Thread Ramcharan, Vijay A
Is it possible to configure application acceleration using WAAS in a vrf environment? In other words, my WAN interface on the router is in a VRF, the LAN interface is in another VRF and the WAE is on another VRF. -- I have gotten as far as the WAE registering the

Re: [c-nsp] WAE/WAAS in VRF environment

2009-02-04 Thread Mike Louis
How are you routing between your WAN and LAN interfaces today? Are you leaking routes between the VRFs on the same router? From: cisco-nsp-boun...@puck.nether.net [cisco-nsp-boun...@puck.nether.net] On Behalf Of Ramcharan, Vijay A

Re: [c-nsp] WAE/WAAS in VRF environment

2009-02-04 Thread Ramcharan, Vijay A
My LAN and WAE interfaces are in the same VRF. They are aware of the routes within my WAN vrf. The reverse is also true. My WAN vrf is aware of the routes reachable via the LAN and WAE interfaces. I can ping from the WAE in one site over to the WAE in the other site across the WAN without any

Re: [c-nsp] Cisco 3750E

2009-02-04 Thread A . L . M . Buxey
Hi, Hey everyone, Can anyone tell me what the oversubscription ratios are on the 10/100/1000 GigE ports on the 48-port 3750E switch? ? oversubscription ? all the 3750E have a 68Mbps wire rate backplane so for pure L2 work they can shove more across the backplane than there are ports.

[c-nsp] AToM Lab Problem

2009-02-04 Thread Ibrahim Abo Zaid
Hi All I was labbing AToM scenario and uses IOS 12.2(33)SRC for ATM AAL5 and ATM Cell-relay feature but i can't get dynamips run for this image , it always results *** Error: 209-unable to start VM instance error messages any body lab this feature using different image or know how to fix this

Re: [c-nsp] AToM Lab Problem

2009-02-04 Thread Wayne Lee
On Wed, Feb 4, 2009 at 8:51 PM, Ibrahim Abo Zaid ibrahim.aboz...@gmail.com wrote: Hi All I was labbing AToM scenario and uses IOS 12.2(33)SRC for ATM AAL5 and ATM Cell-relay feature but i can't get dynamips run for this image , it always results *** Error: 209-unable to start VM instance

Re: [c-nsp] PPPoA sessions

2009-02-04 Thread Frank Bulk
Definitely doesn't work with 12.2(31)SB14. I get all zeroes on my box. OID Object TypeValue 1.3.6.1.4.1.9.10.24.1.1.1.0 cvpdnTunnelTotalGAUGE 0 1.3.6.1.4.1.9.10.24.1.1.2.0 cvpdnSessionTotal GAUGE 0 1.3.6.1.4.1.9.10.24.1.1.3.0

Re: [c-nsp] Netconf (over SSHv2) in SXI

2009-02-04 Thread Jeffrey Ollie
On Mon, Feb 2, 2009 at 6:11 AM, Lincoln Dale l...@cisco.com wrote: that is purely a guess - but checking the XML schema definition (XSD) that should also be posted on cisco.com will let you verify. Any clues on where to find the XSDs? I can't seem to find them except inline in the

Re: [c-nsp] PPPoA sessions

2009-02-04 Thread Tomasz Lemiech
On Wed, 4 Feb 2009, Frank Bulk wrote: Definitely doesn't work with 12.2(31)SB14. I get all zeroes on my box. OID Object TypeValue 1.3.6.1.4.1.9.10.24.1.1.1.0 cvpdnTunnelTotalGAUGE 0 1.3.6.1.4.1.9.10.24.1.1.2.0 cvpdnSessionTotal GAUGE 0

Re: [c-nsp] AToM Lab Problem

2009-02-04 Thread Antonio Soares
There's another problem: ATM AAL5 over MPLS and ATM Cell Relay over MPLS are not supported with the PA-A1, the only ATM interface supported by Dynamips. http://www.cisco.com/en/US/docs/ios/12_0s/feature/guide/atom25s.html#wp1068980 Regards, Antonio Soares, CCIE #18473 (RS) amsoa...@netcabo.pt

Re: [c-nsp] Netconf (over SSHv2) in SXI

2009-02-04 Thread Lincoln Dale
Jeffrey Ollie wrote: On Mon, Feb 2, 2009 at 6:11 AM, Lincoln Dale l...@cisco.com wrote: that is purely a guess - but checking the XML schema definition (XSD) that should also be posted on cisco.com will let you verify. Any clues on where to find the XSDs? I can't seem to find them

[c-nsp] How to add new rule in the same access-list

2009-02-04 Thread Deric Kwok
Hi I have old rule in the switch but don't know how to add new rule in the same access-list When I add new deny rule, it will be put at the end of the access-list If I remove the access-list 140, I have to re-type all lines again. Please help. Thank you switch#sh access-list 140 Extended

Re: [c-nsp] How to add new rule in the same access-list

2009-02-04 Thread Brett Looney
I have old rule in the switch but don't know how to add new rule in the same access-list When I add new deny rule, it will be put at the end of the access-list If I remove the access-list 140, I have to re-type all lines again. Start using named access lists: # show access-list Extended IP

Re: [c-nsp] Fast UDLD timers in SXI?

2009-02-04 Thread David Hughes
Hi Good point. I see CFM has been introduced in SXI. But after wading through the doco, particularly in the area of Continuity Check Messages I see - CFM CCMs have the following characteristics: •Transmitted at a configurable periodic interval by MEPs. The interval can be

Re: [c-nsp] How to add new rule in the same access-list

2009-02-04 Thread Tony Varriale
conf t ip access-list ext 140 But, based on your output, I'd guess your IOS doesn't support sequenceable ACLs. What code are you running? tv - Original Message - From: Deric Kwok deric.kwok2...@gmail.com To: cisco-nsp@puck.nether.net Sent: Wednesday, February 04, 2009 8:26 PM

[c-nsp] 3750-12G interfaces dropping out

2009-02-04 Thread Vigar, Damien
Hi all, We're having an odd issue with a 3750 that's running as the core switch at one of our sites. It's been fine for years; suddenly, this week, it's decided that some of it's interfaces should reset randomly, disrupting access to staff phones and PCs in the buildings at the other end.

Re: [c-nsp] Fast UDLD timers in SXI?

2009-02-04 Thread Gert Doering
Hi, On Thu, Feb 05, 2009 at 02:54:53PM +1000, David Hughes wrote: (config)#udld message time ? 7-90 Time in seconds between sending of messages in steady state SXI, Sup32: Cisco-M(config)#udld message time ? 7-90 Time in seconds between sending of messages in steady state

Re: [c-nsp] How to add new rule in the same access-list

2009-02-04 Thread Seth Mattinen
Deric Kwok wrote: Hi I have old rule in the switch but don't know how to add new rule in the same access-list When I add new deny rule, it will be put at the end of the access-list If I remove the access-list 140, I have to re-type all lines again. That's correct. You need to remove