[c-nsp] Incorrect bandwidth

2010-03-09 Thread nasir.shaikh
Hi, I have an 2621XM running c2600-ik9s-mz.123-22a.bin and I noticed something strange. Reports were showing utilisation of more than 100%. This can be true in some cases but for E1 interfaces I always thought that the router calculates the correct bw depending on the number of channels used. e.g

Re: [c-nsp] 3550 as CE

2010-01-12 Thread nasir.shaikh
Arie, Thanks. No I don't have a subrate link although I do intend to use (an aggregate) policer on the !G link. I am currently happily running 12.1(22)EA8 do you think I should upgrade to 12.2(44)SE? I only need to be able to do QoS marking based on IP acls. tia Nasir Shaikh -Original

[c-nsp] 3550 as CE

2010-01-11 Thread nasir.shaikh
Hi, Due to the global shortage of 73xx routers I am contemplating to use some old 3550-12Ts as CE routers on a stie where a connection is required urgently. I will be using a fibre link from the local ADM as my WAN link (int g0/11 or g0/12 on the 3550) I have enough experience with the 3550

[c-nsp] 6506-E moving from sup2 to sup32

2009-09-17 Thread nasir.shaikh
Hi, I am upgrading from sup2a to sup32 on a 6506-E remotely. I know that 2 different sups are not supported but would the chassis running with sup2a recognize a sup32 when inserted? Makes the upgrade much easier. Appreciate any experiences in this regard Nasir Shaikh | Senior Consultant | BT

[c-nsp] 6500 - sup2a to sup32 upgrade

2009-09-17 Thread nasir.shaikh
Hi, I am upgrading from sup2a to sup32 on a 6506-E remotely. I know that 2 different sups are not supported but would the chassis running with sup2a recognize a sup32 when inserted? Makes the upgrade much easier. Appreciate any experiences in this regard Nasir

[c-nsp] Rolling over preshared keys

2009-03-24 Thread nasir.shaikh
Hi, I am familiar with auto rollover of CA certificates but is there also a way to do an automatic rollover for pre-shared keys? I am looking to do this in a still to be deployed DMVPN environment and security people would like a policy to change the keys periodically. Kind regards Nasir

Re: [c-nsp] Export routes from VRF to the global routing table

2009-03-18 Thread nasir.shaikh
Hi, I am also looking for a way to a complete mutual redistribution between 2 vrfs. For political reasons I am not allowed to put all the interfaces on the redistributing router in the same vrf. Is there some way to do it? If I mutually import/export the route-targets between both vrfs, would

Re: [c-nsp] Interesting NAToverload issue

2009-03-17 Thread nasir.shaikh
Hi Andrew, Our client is using this option (in fact this service is being managed bu MSOL themselves). Only port 443 is allowed on the firewalls and in fact my NAT selection is based on traffic with destination ip of MS Exchange server and port 443. But it seems that the Outlook client will open

[c-nsp] Interesting NAToverload issue

2009-02-25 Thread nasir.shaikh
Hi, I have a client who has moved their Microsoft Exchange servers to a service provider location (as part of a de-perimeterization strategy). These servers are reachable via the Internet. Thus, the client IP are NATted before they cross the corporate boundary. There are about 45000 users.

Re: [c-nsp] Interesting NAToverload issue

2009-02-25 Thread nasir.shaikh
Hi John, That is indeed a good idea. But there are 2 routers doing this NAT and the load towards them is being load-balanced by the choke router before them. I will then have to configure NAT in such a way that each IP from the NAT pool can only be used for about 32000 sessions (as I cannot

[c-nsp] EoMPLS restrictions

2009-02-25 Thread nasir.shaikh
Hi, Can someone shed some light on the following limitation of EoMPLS? Layer 2 connection restrictions: - You cannot have a direct Layer 2 connection between provider-edge routers with EoMPLS Why is this? I have a MAN running MPLS where my PE are directly connected. I need to do extend my

[c-nsp] How secure are VLANs and VRFs?

2009-02-03 Thread nasir.shaikh
Hi, I am looking for some studies/papers to convince my customer (and myself) that VLANs can be as secure as physical segments and VRFs also provide a secure segregation of traffic. A few years back I came across a post referring to a document on the FBI or the NSA site stating that VLANs were

[c-nsp] Strange IPSec problem

2008-12-23 Thread nasir.shaikh
Hi, I have an Ipsec tunnel established between a 871 on the remote end and a 2811 on the central side. There are several other remote sites all connecting to the same central router. All IPSec tunnels are active. From this particular router I can ping servers/hosts on the central site without any

Re: [c-nsp] PA-POS-1OC3 vs. PA-A3-OC3SMI

2008-09-19 Thread nasir.shaikh
Sorry for cutting in into this thread but from the responses looks like my question would fit here too. We are about to provide a customer with a price for upgrading one of the STM-1 ISP links to an STM-4 link with a 200 Mb port. The router we have in place is a 7206 VXR NPE G1. What card would

[c-nsp] OT: network inventory

2008-08-19 Thread nasir.shaikh
Hi, Anybody familiar with (freeware/shareware) tools for a network inventory? Install-base is 100% cisco. Are there other utilities around that would scan the collected configurations and read relevant info (descriptions, ip add, link bandwidth etc)? Nasir Shaikh

[c-nsp] Placing a AON device on an existing /30 subnet

2007-05-31 Thread nasir.shaikh
Hi, We are currently looking at Cisco 8340s and IPANEMA IP engines to deploy an application optimization service for one of our customers. These devices would have to be inserted in an existing point-to-point connection which is using a /30 subnet. For management of the device I would have