[c-nsp] EOMPLS between 10G subinterface and GE subinterface between two 7600

2010-02-17 Thread Ioan Branet
Hello group, I try to creaty an EOMPLS VLAN mode circuit betweet one 10G subinterface and GE interface between two 7600 as PE. Here is my config: PE1: sh running-config interface TenGigabitEthernet7/3.999 Building configuration... Current configuration : 141 bytes ! interface

Re: [c-nsp] EOMPLS between 10G subinterface and GE subinterface between two 7600

2010-02-17 Thread Ioan Branet
Hello, We run EOMPLS on port and vlan mode on GE interfaces but we did not run EOMPLS Vlan mode between 10G and 1G subinterfaces until now. Any feedback is appreciated. Thank you, John On Wed, Feb 17, 2010 at 10:43 AM, Mikael Abrahamsson swm...@swm.pp.sewrote: On Wed, 17 Feb 2010, Ioan Branet

[c-nsp] netiquette

2010-02-17 Thread Mikael Abrahamsson
Since this has now happened to me TWICE in 24 hours, I feel I need to post this because it seems enough people doesn't know about it: http://lowendmac.com/lists/netiquette.shtml Never post private (off-list) correspondence to the list without the permission of the sender. -- Mikael

Re: [c-nsp] EOMPLS between 10G subinterface and GE subinterface between two 7600

2010-02-17 Thread Tassos Chatzithomaoglou
I'm running EoMPLS between 10GE subif and 1GE subif without any problem. 7600-ash mpls l2 vc 3601 Local intf Local circuit Dest addressVC ID Status - -- --- -- -- Gi4/20.3601Eth VLAN 3601

Re: [c-nsp] Controlling allowed VLANs, alternatives?

2010-02-17 Thread Phil Mayers
On 02/16/2010 10:21 PM, Randy McAnally wrote: Nothing wrong...it's exactly what I needed. Long hours of coding makes me overlook these kinds of things and I really appreciate the added eyes of the community :) FWIW we define an alias: alias interface tagvlan switchport trunk allowed vlan add

Re: [c-nsp] netiquette

2010-02-17 Thread Marco Regini
Thanks. So if I post a question to cisco-nsp@puck.nether.net and t...@gmail.com answer to me directly, I can't replay to the mailing list but only to tom? Even if the message is only about technical stuff? Marco -Original Message- From: cisco-nsp-boun...@puck.nether.net

Re: [c-nsp] EOMPLS between 10G subinterface and GE subinterface between two 7600

2010-02-17 Thread Ioan Branet
Hello, Maybe there is a bug with SRB IOS. I still have VC up on both ends but I cant ping between CE1 and CE2. On CE1 (Juniper side) I learn arp address of remote CE2 device and receive arp request and send arp reply: show arp no-resolve | match xe-3/1/0 00:16:9c:6d:42:80 150.1.1.1

Re: [c-nsp] Controlling allowed VLANs, alternatives?

2010-02-17 Thread Saku Ytti
On (2010-02-17 09:33 +), Phil Mayers wrote: alias interface tagvlan switchport trunk allowed vlan add alias interface detagvlan switchport trunk allowed vlan remove ...because forgetting that add and remove can do really really really bad things... Agreed. Alternatives are using EEM or

Re: [c-nsp] netiquette

2010-02-17 Thread Mikael Abrahamsson
On Wed, 17 Feb 2010, Marco Regini wrote: Thanks. So if I post a question to cisco-nsp@puck.nether.net and t...@gmail.com answer to me directly, I can't replay to the mailing list but only to tom? Even if the message is only about technical stuff? That is correct. Unless you KNOW for sure

[c-nsp] Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Agent

2010-02-17 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Multiple Vulnerabilities in Cisco Security Agent Advisory ID: cisco-sa-20100217-csa Revision 1.0 For Public Release 2010 February 17 1600 UTC (GMT

Re: [c-nsp] EOMPLS between 10G subinterface and GE subinterface between two 7600

2010-02-17 Thread Ioan Branet
Hello, I tried with Cisco 7600 as CE instead of Juniper and it works, I have to find out what is wrong there. Thank you for your help, Regards, John -- Forwarded message -- From: Ioan Branet ioan.bra...@gmail.com Date: Wed, Feb 17, 2010 at 11:44 AM Subject: Re: [c-nsp] EOMPLS

[c-nsp] Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances

2010-02-17 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances Advisory ID: cisco-sa-20100217-asa Revision 1.0 For Public Release 2010 February 17 1600 UTC (GMT

[c-nsp] Cisco Security Advisory: Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability

2010-02-17 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability Advisory ID: cisco-sa-20100217-fwsm http://www.cisco.com/warp/public/707/cisco-sa-20100217-fwsm.shtml Revision 1.0

Re: [c-nsp] EOMPLS between 10G subinterface and GE subinterface between two 7600

2010-02-17 Thread Manu Chao
Hello, It is just a config problem on your J CE1: You needn't flexible-vlan-tagging (nor flexible-ethernet-services encapsulation) R/ Manu On Wed, Feb 17, 2010 at 5:01 PM, Ioan Branet ioan.bra...@gmail.com wrote: Hello, I tried with Cisco 7600 as CE instead of Juniper and it works, I have to

Re: [c-nsp] Renumbering serial interfaces

2010-02-17 Thread Paul Stewart
Test this ahead of time with a lab box if you can ;) What I've done in this scenarios is to build the snippets of config I need to apply and put them into a plain text file. Then do a copy tftp://blahblah/filename running-config which merges the changes. Before I do the copy I do a reload in 15

Re: [c-nsp] Renumbering serial interfaces

2010-02-17 Thread Ryan Lambert
You can renumber serial links with one person. Standard disclaimer of paying attention to detail, being careful, etc. If you can tolerate a few minutes downtime worst-case (which, I'm making the assumption this is being done in a window that can), you can also use the 'reload in x' command, where

Re: [c-nsp] ASA - Monitor an IPSEC Tunnel via SNMP

2010-02-17 Thread Ryan West
B, -Original Message- Sent: Wednesday, February 17, 2010 1:22 PM To: cisco-nsp@puck.nether.net Subject: [c-nsp] ASA - Monitor an IPSEC Tunnel via SNMP What's the best way to monitor an IPSec tunnel via SNMP on an ASA (v8)? I just want to know if it is up or down. I did an

Re: [c-nsp] Renumbering serial interfaces

2010-02-17 Thread Gert Doering
Hi, On Wed, Feb 17, 2010 at 11:19:31AM -0700, james edwards wrote: I have a bunch of T-1 (ATM) interfaces that I need to renumber. I have always done this with 2 people, one on each end. Is it possible for one person to do this, from one end ? If I am on the near side, I log into the far

Re: [c-nsp] netiquette

2010-02-17 Thread nick hatch
On Wed, Feb 17, 2010 at 2:54 AM, Mikael Abrahamsson swm...@swm.pp.sewrote: On Wed, 17 Feb 2010, Marco Regini wrote: Thanks. So if I post a question to cisco-nsp@puck.nether.net and t...@gmail.com answer to me directly, I can't replay to the mailing list but only to tom? Even if the

Re: [c-nsp] EOMPLS between 10G subinterface and GE subinterface between two 7600

2010-02-17 Thread Ioan Branet
Hello, I used also vlan-tagging but with same result: show configuration interfaces xe-3/1/0 description ** Link To PE1 **; vlan-tagging; link-mode full-duplex; gigether-options { no-auto-negotiation; } unit 999 { bandwidth 10g; vlan-id 999; family inet { accounting {