Re: [c-nsp] ISIS Problem

2009-08-18 Thread Ibrahim Abo Zaid
Hi All R1 isn't setting ATT bit in its LSP it is like that R1 forwards L1 default route to all its L1 neighbors in DEF the originatation area (but it is not shown in R1-LSP) , I connected R4 to R1 with L2 ADJ between them and there is no DEF route !! any explainsion ? R1#sh isis database IS-IS

Re: [c-nsp] EoMPLS between subinterface and physical interface

2009-08-18 Thread Tassos Chatzithomaoglou
Arie, I'm actually trying something strange in the lab, but i wanted to ask opinions before trying all the alternatives. More specifically i want to transfer double tagged traffic from multiple subifs of a local MUX-UNI interface to multiple remote physical interfaces, where the outer tag

Re: [c-nsp] ISIS Problem

2009-08-18 Thread Ibrahim Abo Zaid
Hi all To make it clearer , i don't have a problem with default route on R1 i have a problem with the default route on R2 and R3 best regards --Ibrahim On Tue, Aug 18, 2009 at 10:24 AM, Ibrahim Abo Zaid ibrahim.aboz...@gmail.com wrote: Hi All R1 isn't setting ATT bit in its LSP it is

Re: [c-nsp] EoMPLS between subinterface and physical interface

2009-08-18 Thread Marko Milivojevic
Have you tried to use native VLAN on 7600-1 for the subinterface? Mind you, I'm not 100% sure if you can actually xconnect native VLAN, but you may give it a go... -- Marko CCIE #18427 (SP) My network blog: http://cisco.markom.info/ On Tue, Aug 18, 2009 at 09:19, Tassos

Re: [c-nsp] EoMPLS between subinterface and physical interface

2009-08-18 Thread Marko Milivojevic
On Tue, Aug 18, 2009 at 13:32, Marko Milivojevicmar...@markom.info wrote: Have you tried to use native VLAN on 7600-1 for the subinterface? Mind you, I'm not 100% sure if you can actually xconnect native VLAN, but you may give it a go... Sorry, I meant to say on 7600-2. -- Marko CCIE #18427

Re: [c-nsp] Monitoring Nexus 7000 platform

2009-08-18 Thread Ross Vandegrift
On Mon, Aug 17, 2009 at 01:15:13PM -0400, Lee wrote: Maybe that'll help push my learn perl todo item up a bit higher on my list :) But that's assuming netconf/xml makes expect scripts a bit less dependent on the exact formatting of the output. If upgrading the OS requires updating the xml

Re: [c-nsp] Feedback on Bug Toolkit (BTK), IOS Software Download Planner, etc...

2009-08-18 Thread Rodney Dunn
This is the only other contact I have right now: Oscar Bauer ba...@cisco.com Software Downloads (in general ast here are internal code names) Software Delivery System (SDS) FTP.cisco.com Cisco View Planner Resource Management Essentials (RME) Planner IOS Upgrade Planner (retired in April)

Re: [c-nsp] EoMPLS between subinterface and physical interface

2009-08-18 Thread Arie Vayner (avayner)
Well, you could use a loopback cable solution (not the prettiest solution around). So on 7600-2 you use a trunk port with multiple sub-ifs (like on 7600-1) but loop it back to a regular l2 trunk port. Then you just connect the CPE's to regular access ports on the VLANs. What I am not sure is

Re: [c-nsp] EoMPLS between subinterface and physical interface

2009-08-18 Thread Marko Milivojevic
What I am not sure is whether the 7600 would even allow you to put an access port on the same VLAN used on the sub-if. No quick way for me to test it right now. I can answer that... It won't allow it. This solution with LAN line cards would require VLAN mapping, which isn't pretty, at all. --

[c-nsp] Cisco Security Advisory: Cisco Security Advisory: Cisco IOS XR Software Border Gateway Protocol Vulnerability

2009-08-18 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Security Advisory: Cisco IOS XR Software Border Gateway Protocol Vulnerability Advisory ID: cisco-sa-20090818-bgp http://www.cisco.com/warp/public/707/cisco-sa-20090818-bgp.shtml Revision 1.0 For Public Release 2009

Re: [c-nsp] EoMPLS between subinterface and physical interface

2009-08-18 Thread Gert Doering
Hi, On Tue, Aug 18, 2009 at 05:19:51PM +0200, Arie Vayner (avayner) wrote: What I am not sure is whether the 7600 would even allow you to put an access port on the same VLAN used on the sub-if. No quick way for me to test it right now. Not with SX* software - VLAN space is global, and a VLAN

Re: [c-nsp] EoMPLS between subinterface and physical interface

2009-08-18 Thread Arie Vayner (avayner)
This is true. The only way to get rid of the global VLAN scope is by using SIP/ES modules (which require SR software) Arie -Original Message- From: Gert Doering [mailto:g...@greenie.muc.de] Sent: Tuesday, August 18, 2009 19:38 To: Arie Vayner (avayner) Cc: Tassos Chatzithomaoglou;

Re: [c-nsp] OSM support for 1000BaseT

2009-08-18 Thread Ian Cox
Yes it is meant to be supported. It was supported in previous releases. Ian Cameron Dry wrote: Does anyone know if the OSM-2+4GE-WAN+ supports copper GBICs in the WAN ports - currently installed in a 7600 running 12.2SRC4. Thanks Cameron

[c-nsp] Order of Operations for processing a packet (ingress and egress)

2009-08-18 Thread Justin Shore
Does anyone have any good links to an order of operations for what happens in what order on the assorted types of Cisco interfaces in both the ingress and egress directions? I found one that touchs on the QoS order of operations:

Re: [c-nsp] Order of Operations for processing a packet (ingress and egress)

2009-08-18 Thread Ian Cox
I don't believe there is a comprehensive one published on CCO besides the following document for the 7600. http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/prod_white_paper0900aecd80673385.html If we just consider LAN modules, then all encapsulation operations are done by the

Re: [c-nsp] Arp Inspection Rate Limit

2009-08-18 Thread Murphy, William
On access layer ports in our environment 15pps works well. Very rarely we have some weird print server or some device that bursts above that, but we never have had to go above 30pps on an access port. Since we limit on the edge ports we don't put a limit on the trunks... Bill M -Original

[c-nsp] Sup720 hang while writing SP crashinfo?

2009-08-18 Thread Kevin Graham
We had a Sup720B (non-redundant, running modular SXI) crash, due to what looks like was due to a CPU_MONITOR watchdog event. What was nasty though was that rather than reload, it hung (dead and unresponsive console) and required a power cycle. The RP crashinfo made it out fine, however SP

Re: [c-nsp] Sup720 hang while writing SP crashinfo?

2009-08-18 Thread Eninja
There are multiple causes of crashes and several causes of system 'hang' (high CPU, memory depletion, etc) and both should be investigated independently. Do you have any syslogs from a few minutes before the crash? If yes send over along with RP crashinfo, whatever was captured from SP and

[c-nsp] Traffic shaping on a Sup32

2009-08-18 Thread Graham Wooden
Hi there, I need to implement some traffic shaping on some SVI VLAN interfaces (a customer either with 1 server or 10 servers) on a 6509/Sup32. Running IOS is advipservicesk9_wan-mz.122-33.SXI1. I have currently setup some policy-maps that do some policing, which are feed by class-maps with

Re: [c-nsp] Bridge devices - ARP takeover

2009-08-18 Thread Graham Wooden
Update: I could not keep the link up on the Sup32. Even hardcoding the MAC addresses, traffic would flat stop at random times. However, it's been up for 4 days now on a Sup2. Specific interface/vlan config is exactly the same. Only differences are the Sups, IOS, and linecard. So, does anyone

Re: [c-nsp] Arp Inspection Rate Limit

2009-08-18 Thread NMaio
William, Thanks for the response. Funny you mention the print server because that happens to be one device port I need to tweak since it occasionally exceeds the 15 pps. Thanks again, Nick -Original Message- From: Murphy, William [mailto:william.mur...@uth.tmc.edu] Sent: Tuesday,

Re: [c-nsp] Monitoring Nexus 7000 platform

2009-08-18 Thread Lincoln Dale
On 18/08/2009, at 11:48 PM, Ross Vandegrift wrote: Those namespaces are specified as versions of the netconf namespace, not as Cisco-specific namespaces. Those will change only for subsequent versions of the top-most, Netconf-defined tags. Unfortunately, JUNOS does encode generating versions

Re: [c-nsp] Bridge devices - ARP takeover

2009-08-18 Thread Rodney Dunn
You need to get more data when it's failing for anyone to help. sh ip arp sh adj detail sh mls cef ip as starters. Graham Wooden wrote: Update: I could not keep the link up on the Sup32. Even hardcoding the MAC addresses, traffic would flat stop at random times. However, it's been up for 4

Re: [c-nsp] Traffic shaping on a Sup32

2009-08-18 Thread Graham Wooden
Ah-ha! I found the solution to my first inquire - traffic shapping on SVIs. Apparently the key was mls qos vlan-based on the actual LAN interface. Now its adhering both input and output. I'll see if I can tweak to fit a dot1q subint. On 8/18/09 8:52 PM, Graham Wooden gra...@g-rock.net wrote:

Re: [c-nsp] Bridge devices - ARP takeover

2009-08-18 Thread Graham Wooden
Hi Rodney, When the last outage occurred, I did a quick assessment of the output of those two commands and reviewed it with output while it was working - and nothing stuck out wrong or incorrect. I however, didn't do the sh mls cef. In a haste effort to get this particular customer up, I moved

Re: [c-nsp] Traffic shaping on a Sup32

2009-08-18 Thread Graham Wooden
Oh, the fun. I am not making much headway with this. After reading the Qos on the PFC, I am even more lost. I can't seem to do any traffic shaping within the map. I can't do the police cir, bandwidth percentage, etc. Does anyone have any good working examples? class-map match-any VOIP match

Re: [c-nsp] Traffic shaping on a Sup32

2009-08-18 Thread Mikael Abrahamsson
On Tue, 18 Aug 2009, Graham Wooden wrote: Oh, the fun. I am not making much headway with this. After reading the Qos on the PFC, I am even more lost. I can't seem to do any traffic shaping within the map. I can't do the police cir, bandwidth percentage, etc. Does anyone have any good working

Re: [c-nsp] Traffic shaping on a Sup32

2009-08-18 Thread Graham Wooden
Thanks Mikael - that did the trick. By hardcoding the bit rate on the police I am now able to sort out my specified traffic into my different rate patterns. -graham On 8/18/09 10:08 PM, Mikael Abrahamsson swm...@swm.pp.se wrote: On Tue, 18 Aug 2009, Graham Wooden wrote: Oh, the fun. I

Re: [c-nsp] Sup720 hang while writing SP crashinfo?

2009-08-18 Thread Kevin Graham
There are multiple causes of crashes and several causes of system 'hang' (high CPU, memory depletion, etc) and both should be investigated independently. Yes, crash itself didn't seem particularly interesting, but am pursuing that w/ TAC. It looked like it was a good and orderly reset,

[c-nsp] Management Vlan VS Vlan1

2009-08-18 Thread shadow floating
Hi All, I just have a question, as we know that Cisco preserve VLAN 1 for management issues and network management needed protocols like CDP, VTP and the like, and all access from other VLANs to this VLAN should be restricted except from the management VLAN, as for our network, we are