Re: [c-nsp] Management Vlan VS Vlan1

2009-08-19 Thread Seth Mattinen
shadow floating wrote: Hi All, I just have a question, as we know that Cisco preserve VLAN 1 for management issues and network management needed protocols like CDP, VTP and the like, and all access from other VLANs to this VLAN should be restricted except from the management VLAN, as for our

[c-nsp] CIsco 3560 SVI SNMP

2009-08-19 Thread almog ohayon
Hello Everyone,Does anyone know if there is an option to get statistics from Cisco 3560 Interface Vlan ? I need throughput statistics from my interfaces vlans and i only get physical interface statistics . if anyone can help... Thanks -- Almog ___

[c-nsp] per interface ARP policing (6500)

2009-08-19 Thread Daniel Verlouw
Hi, my google-fu is not much of help on this one: 6509VE(config)#mls qos protocol arp police 32k This overrides the per interface ARP policing Does anyone know where to find the default settings for this per interface ARP policer ? And are these sufficient to protect against ARP attacks? sh

Re: [c-nsp] CIsco 3560 SVI SNMP

2009-08-19 Thread Gert Doering
Hi, On Wed, Aug 19, 2009 at 11:13:52AM +0300, almog ohayon wrote: Hello Everyone,Does anyone know if there is an option to get statistics from Cisco 3560 Interface Vlan ? Yes - and the answer is no. 3560 / 3750s are not able to do proper counting on VLAN interfaces. Packets seen by the CPU

Re: [c-nsp] Arp Inspection Rate Limit

2009-08-19 Thread Alexander Clouter
Hi, nm...@guesswho.com wrote: Thanks for the response. Funny you mention the print server because that happens to be one device port I need to tweak since it occasionally exceeds the 15 pps. We have been fine at 10 for over a year now[1], however it took us a while to figure out that for

[c-nsp] RSPAN + VACL Redirect

2009-08-19 Thread Charuntorn Baimoung
Hi Everyone, I'would like to know this config is work properly on 6500 same box. Configure the Source VLANs or Ports monitor session 1 source int giga9/1 , giga8/1 , giga8/2 , giga8/3 , giga8/4 rx monitor session 1 destination remote vlan 300 Configure the Destination Monitoring

Re: [c-nsp] RSPAN + VACL Redirect

2009-08-19 Thread Phil Mayers
Charuntorn Baimoung wrote: Hi Everyone, I'would like to know this config is work properly on 6500 same box. I seriously doubt it. What are you trying to do? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

[c-nsp] Problem with DHCP over wireless on 1811W

2009-08-19 Thread Ingimar Jónsson
Hi all. This is my first post to this list so please bear with me. I'm trying to configure a 1811W to act as a DHCP relay for its wireless AP. The scenario is like this; The 1811W is located in a remote office and forwards RADIUS and DHCP to local servers. DHCP is working on FastEthernet ports

[c-nsp] RP/SP BOOT synchronisation issue on 6500/7600

2009-08-19 Thread Tassos Chatzithomaoglou
Has anyone met such an issue? Whenever i use more than 2 files in the boot sequence, i get the SP BOOT variable desynchronized (RP BOOT is fine). I have seen it in SXH3a, SXI1, SRD2a. Is there a lower limit on the number of chars in SP BOOT than in RP BOOT? On some versions i also get

Re: [c-nsp] Management Vlan VS Vlan1

2009-08-19 Thread harbor235
I would not use VLAN for disabled ports either, create a PARK vlan and reassign all unused diabled ports to the PARK vlan. That wy vlan 1 has no chance to be mistakenly activated. mike On Wed, Aug 19, 2009 at 3:02 AM, Seth Mattinen se...@rollernet.us wrote: shadow floating wrote: Hi All, I

Re: [c-nsp] ISIS Problem

2009-08-19 Thread Mark Tinka
On Tuesday 18 August 2009 09:24:47 pm Ibrahim Abo Zaid wrote: To make it clearer , i don't have a problem with default route on R1 i have a problem with the default route on R2 and R3 As Yuri had suggested, have you tried simplifying your IS-IS configuration by having only a single instance

Re: [c-nsp] Arp Inspection Rate Limit

2009-08-19 Thread Frank Bulk - iName.com
We deal with this issue on the BWA side of the house. We typically set up the client radios to rate-limit broadcasts (yes, there's more to broadcast than ARP, but ARP is most of it) to 7 pps and main radio to as low as 12 pps. Frank -Original Message- From:

Re: [c-nsp] Management Vlan VS Vlan1

2009-08-19 Thread Mark Tinka
On Wednesday 19 August 2009 03:02:55 pm Seth Mattinen wrote: I don't use VLAN 1 at all anywhere. Except for the disabled ports. Same here. Mark. signature.asc Description: This is a digitally signed message part. ___ cisco-nsp mailing list

Re: [c-nsp] Management Vlan VS Vlan1

2009-08-19 Thread Murphy, William
In all recent IOS versions and switching hardware you can disable VLAN 1 on trunk ports (switchport trunk allowed vlan remove 1) and the protocols you mentioned will still continue to function. This is how Cisco recommends you do it. -Original Message- From:

[c-nsp] Cisco Security Advisory: Firewall Services Module Crafted ICMP Message Vulnerability

2009-08-19 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Firewall Services Module Crafted ICMP Message Vulnerability Advisory ID: cisco-sa-20090819-fwsm http://www.cisco.com/warp/public/707/cisco-sa-20090819-fwsm.shtml Revision 1.0 For Public Release 2009 August 19 1600 UTC (GMT

[c-nsp] TCP throughput /WAN delay simulation with back to back routers

2009-08-19 Thread Thilak T
Hello Folks , I am trying to test TCP throughput with different variables. I want to simulate a delay of aprox 45msec between two test PCs connected two bat to back routers . How do we introduce an artificial delay where in the actual delay is on 2-3 msec.Using cisco routers.? Thilak

Re: [c-nsp] TCP throughput /WAN delay simulation with back to back routers

2009-08-19 Thread Brandon Applegate
On Wed, 19 Aug 2009, Thilak T wrote: Hello Folks , I am trying to test TCP throughput with different variables. I want to simulate a delay of aprox 45msec between two test PCs connected two bat to back routers . How do we introduce an artificial delay where in the actual delay is on 2-3

Re: [c-nsp] TCP throughput /WAN delay simulation with back to back routers

2009-08-19 Thread sthaug
I am trying to test TCP throughput with different variables. I want to simulate a delay of aprox 45msec between two test PCs connected two bat to back routers . How do we introduce an artificial delay where in the actual delay is on 2-3 msec.Using cisco routers.? FreeBSD and Dummynet, on a

[c-nsp] Fwd: strange archive feature on c3560

2009-08-19 Thread Sergey Khalavchuk
hello, group i've recently discovered strange behavior on clean catalyst 3560 with 122-40.SE IOS: whenever i try to save config, i get: SWITCH#wr Building configuration... nv_done: unable to open flash:/archive/backup.config.new[OK] SWITCH# who knows what is it, and how to enable/disable this?

Re: [c-nsp] TCP throughput /WAN delay simulation with back to back routers

2009-08-19 Thread Ivan Pepelnjak
http://wanem.sourceforge.net/ You can download an ISO image that boots off the CD. It can be used on a PC with two interfaces (emulating a router) or with a bit of static-route trickery on the end hosts. Worked perfectly for me when I had to do similar tests. Ivan

[c-nsp] T.38 Fax Relay from 2620XM

2009-08-19 Thread Gregory Boehnlein
Hello, I have a couple of 2620XM units that I am using as PRI to SIP gateways. I have been trying to get T.38 fax relay working w/ an endpoint. What I have discovered is that the Cisco is not sending T.38 invite information in the SDP message. Call Path - ISDN PRI (ni2) - 2620XM -

Re: [c-nsp] Management Vlan VS Vlan1

2009-08-19 Thread Alan Buxey
Hi, I would not use VLAN for disabled ports either, create a PARK vlan and reassign all unused diabled ports to the PARK vlan. That wy vlan 1 has no chance to be mistakenly activated. aye - we have a similar 'blackhole' VLAN which is present but doesnt do anything. (i was toying with the

Re: [c-nsp] TCP throughput /WAN delay simulation with back to back routers

2009-08-19 Thread Kaegler, Mike
If you have a linux machine laying around (a default ubuntu install will do...), drop it on the same subnet as either one of the two PCs. (only one ethernet card needed) Do: iptables -A OUTPUT -p icmp --icmp-type redirect -j DROP tc qdisc add dev eth0 root netem delay 45msec echo -n 1

Re: [c-nsp] TCP throughput /WAN delay simulation with back to back routers

2009-08-19 Thread Ryan Wilkins
You can also look at http://www.linuxfoundation.org/en/Net:Netem. I use Netem to simulate satellite delay. My configured delays are about 265 ms each way with 2 ms of variation. Works really well and support is compiled directly recent Ubuntu Linux versions and probably many others as

[c-nsp] ISIS Adj-filter problem

2009-08-19 Thread Ibrahim Abo Zaid
Hi All I was testing ISIS Adj-filter option , R1,R2 and R3 are connected over ethernet switch (using dynamips) with the below configuration the configuration works for adj point and both R2 and R3 have ADJ with R1 only , the problem is R2 is droping R1 and R3 LSPs and debug shows it is dropped

Re: [c-nsp] Management Vlan VS Vlan1

2009-08-19 Thread Brett Frankenberger
On Wed, Aug 19, 2009 at 10:56:23AM -0500, Murphy, William wrote: In all recent IOS versions and switching hardware you can disable VLAN 1 on trunk ports (switchport trunk allowed vlan remove 1) and the protocols you mentioned will still continue to function. This is how Cisco recommends you

Re: [c-nsp] CIsco 3560 SVI SNMP

2009-08-19 Thread Ryan West
Gert, Is this behavior different on the higher end models? -ryan -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Gert Doering Sent: Wednesday, August 19, 2009 4:33 AM To: almog ohayon Cc: cisco-nsp@puck.nether.net

Re: [c-nsp] TCP throughput /WAN delay simulation with back to back routers

2009-08-19 Thread Thilak T
Thanks Ivan,Kaegler, Wouter sthaug . I could find a similar software which runs on windows and was able to introduce desired delay. (I used shunra Ve - http://static.shunra.com/free-trials.php). regards Thilak On Wed, Aug 19, 2009 at 1:54 PM, Kaegler, Mikekaegl...@tessco.com wrote: If you

Re: [c-nsp] CIsco 3560 SVI SNMP

2009-08-19 Thread Ryan West
Peter, Thanks for your input, I was able to verify that a 4500 with a SupIV is also able to show the proper SVI stats. -ryan -Original Message- From: Peter Rathlev [mailto:pe...@rathlev.dk] Sent: Wednesday, August 19, 2009 8:05 PM To: Ryan West Cc: cisco-nsp@puck.nether.net Subject:

Re: [c-nsp] Sup720 hang while writing SP crashinfo?

2009-08-19 Thread e ninja
Kevin, Looks like the RP reset the system because the SP failed to respond to RP-SP cpu availability heartbeat keepalives (aka CPU MONITOR). The TAC engineer should not bother decoding the RP tracebacks as this would most likely be generic functions. The root cause lies in the SP and

[c-nsp] ISIS partition avoidance

2009-08-19 Thread Ibrahim Abo Zaid
Hi All Does any one knows why ISIS partition avoidance is needed ? according to DocCD To cause an Intermediate System-to-Intermediate System (IS-IS) Level 1-2 border router to stop advertising the Level 1 area prefix into the Level 2 backbone when full connectivity is lost between the border

[c-nsp] 6500 QoS

2009-08-19 Thread ML
I'm about to turn on mls qos for the first time on a 6509E. I would like some background information from the QoS experts on this list. Last time I turned on mls qos it was a 3560 which has certain undesirable defaults when mls qos is turned on. I want avoid the same result with the 6509

Re: [c-nsp] TCP throughput /WAN delay simulation with back to back routers

2009-08-19 Thread Ian Henderson
On Wed, 19 Aug 2009, Thilak T wrote: I am trying to test TCP throughput with different variables. I want to simulate a delay of aprox 45msec between two test PCs connected two bat to back routers . How do we introduce an artificial delay where in the actual delay is on 2-3 msec.Using cisco

Re: [c-nsp] Management Vlan VS Vlan1

2009-08-19 Thread shadow floating
Thanks alot guys for all your informative response, but still if I migrate the management VLAN from VLAN 1 to another VLAN , won't I have to protect 2 VLANs instead of just taking care of VLAN 1?..is there any good reason prevent one from using VLAN1 for management and restrict access from other