[c-nsp] 3750 tcam log

2007-04-10 Thread Brian Turnbow
Hello Everyone, I have a 3750 stack running 12.2(35)SE2 that had the cpu shoot up this weekend and imediately thought that we had exhausted our tcam space but looking it seems that this is not the issue. We have prefered routing and 9 routed interfaces actually configured. There was no jump in the

Re: [c-nsp] 3750 tcam log

2007-04-11 Thread Brian Turnbow
(only the 6500) does anyone know of a way to track this besides a script? Thanks Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Turnbow Sent: martedì 10 aprile 2007 19.15 To: cisco-nsp@puck.nether.net Subject: [c-nsp] 3750 tcam log Hello

Re: [c-nsp] Cisco 1811 DNS Server overload

2007-04-16 Thread Brian Turnbow
Do you have dns spoofing on ? If so turn it off. That is what causes dns proxy You can disable dns lookups completly with no ip domain lookup Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Skeeve Stevens Sent: lunedì 16 aprile 2007 15.07 To:

[c-nsp] 3750 high cpu from icmp

2007-05-07 Thread Brian Turnbow
Hello Everyone, I have been working on a 3750 that has a high cpu usage and wanted to ask for some help. My first thought was tcam space , but that was ok and I don't see any bad adjacencies or routes. The switch has high interupt cpu levels and checking into it I have found that it seems to be

Re: [c-nsp] 3750 high cpu from icmp

2007-05-14 Thread Brian Turnbow
Turnbow Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] 3750 high cpu from icmp On Mon, May 14, 2007, Brian Turnbow wrote: Wanted to post an update on this in case anyone else ever has problems. The only way I found to resolve this issue was to move traffic onto different interfaces , removing

Re: [c-nsp] VoIP without QoS

2007-05-23 Thread Brian Turnbow
Hi George We run Voip services to enterprises and only do Qos on the (small) termination lines up/down with llq. Otherwise the core has no Qos and plenty of bandwidth. Works great as long as there is bandwidth and the routers can handle the forwarding. Brian -Original Message- From:

Re: [c-nsp] ADSL QOS

2007-06-19 Thread Brian Turnbow
Hi Ian, You need to use the pre classify on the virtual template qos pre-classify Search llq for vpn on cco Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Ian MacKinnon Sent: martedì 19 giugno 2007 15.41 To: cisco-nsp@puck.nether.net

Re: [c-nsp] AS5400XM Question

2007-06-29 Thread Brian Turnbow
Yes it can do it You need a data dial peer to use to specify which are data calls. http://www.cisco.com/en/US/products/sw/iosswrel/ps1839/products_feature_guide09186a0080110d2b.html Regards Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Paul

Re: [c-nsp] Unicast storms

2007-07-03 Thread Brian Turnbow
-Original Message- From: Vincent De Keyzer [mailto:[EMAIL PROTECTED] Sent: martedì 3 luglio 2007 14.43 To: Brian Turnbow; cisco-nsp@puck.nether.net Subject: RE: [c-nsp] Unicast storms Brian, I don't think this is the way unicast storm-control is supposed to work. Of course the traffic

Re: [c-nsp] Cheap Cisco Voice Solution

2007-07-13 Thread Brian Turnbow
Staying in the cisco family there is also the linksys line which is far less expensive. I've used the phones and ata's but not the pbx. Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Paul Stewart Sent: venerdì 13 luglio 2007 15.05 To:

Re: [c-nsp] Catalyst6506 w/ sup1amsfc2 6148-ge-tx large packets aredropped

2007-10-09 Thread Brian Turnbow
, looking into ip tcp mss adjust or the like Or you can change your interface , for example use the sup1A interface. Regards Brian -Original Message- From: Comm-AG [mailto:[EMAIL PROTECTED] Sent: martedì 9 ottobre 2007 12.55 To: Brian Turnbow; cisco-nsp@puck.nether.net Subject: RE: [c

Re: [c-nsp] Flowmask Config?

2007-12-10 Thread Brian Turnbow
Do a show mls netflow flowmask Nat requires interface full flow Take a look here http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/native/configuration/guide/netflow.html Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of

Re: [c-nsp] 7604/sup32

2008-01-08 Thread Brian Turnbow
Hi, 7600 is a hardware forwarding platform(basically a catalyst 6500), whereas the 7200 is processor based. The 7600 can forward much much more traffic. With full routes however the sup-32 isn't going to cut it you need the 720 with PFC3BXL. The sup32 doesn't have enough tcam space for full

[c-nsp] npe-g2

2008-01-16 Thread Brian Turnbow
Hello We are in the processes of deploying our first npe-g2 in production and I wanted to see what the consensus is for a stable ios version. The router will be used for pppoa termination and will be running mpls vpn, bgp cbwfq/llq qos. thanks in advance Brian

Re: [c-nsp] L2TP/IPSEC VPN for MS Windows PCs

2008-01-16 Thread Brian Turnbow
Hi Felix, Why not use the cisco client ? It's free (as long as you are entitled to the crypto ios at least) and the configuration and maintenace is going to be much easier than with windows in the long run. There is a technote on configuring l2tp ipsec between windows and ios

Re: [c-nsp] ISDN : Dial on demand

2008-01-17 Thread Brian Turnbow
I decided to use the command clear int bri 0 between each site for hanging up the current call. use Isdn disconnect or Isdn test disconnect Depending on your version Brian ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] 2960 not switching packets (hub-like behavior)

2008-01-17 Thread Brian Turnbow
Most times this is related to the arp aging time on the sending device vs mac aging time on the switch. The switch will learn the location of the mac when it transmits, but after not recieving data sourced from the mac for more than the aging time the mac gets removed from the mac addres

Re: [c-nsp] cisco 3560 layer3 performance

2008-01-22 Thread Brian Turnbow
Check out this thread http://puck.nether.net/pipermail/cisco-nsp/2007-May/040374.html I had a similar issue with a 3750, the cause was redirected traffic Even though ip redirects were disabled on the vlan interface they were being punted to the cpu and then dropped. Try a 3750E-Jenner#sh

Re: [c-nsp] 6500 vs. 7600 revisited again

2008-04-10 Thread Brian Turnbow
Indeed, folks have tested Sup32 with a 3BXL update, and it works, but it's unsupported, and most likely there is a check in recent IOS versions Ato make sure it doesn't work anymore. We told you this is not supported!. I remember seeing this roadshow

Re: [c-nsp] Cisco ISP Essentials?

2008-04-17 Thread Brian Turnbow
Check out this site ftp://ftp-eng.cisco.com/cons/ There is an isp essetialns posted from 2002 and there is alot of material and presentations that are useful. Regards Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Howard Jones Sent: giovedì

Re: [c-nsp] Standby mode switchport status

2008-04-23 Thread Brian Turnbow
Standby is for backup interfaces. Do you have switchport backup interfaace xxx in your config? Regards Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Tom Storey Sent: Wednesday, April 23, 2008 9:28 AM To: cisco-nsp@puck.nether.net Subject: [c-nsp]

Re: [c-nsp] Blocking VTP

2008-04-23 Thread Brian Turnbow
There was set vtp port x/x disable in catos at least for 6500s . I don't think it ever worked it's way into ios though. Number 2 will do the job for you. Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Phil Mayers Sent: Wednesday, April 23,

[c-nsp] R: Re: Blocking VTP

2008-04-23 Thread Brian Turnbow
] Cc: Brian Turnbow [EMAIL PROTECTED]; cisco-nsp@puck.nether.net cisco-nsp@puck.nether.net Oggetto: Re: [c-nsp] Blocking VTP http://www.cisco.com/en/US/docs/ios/lanswitch/command/reference/lsw_u1.html#wp1013452 I guess enabling vtp on your internal ports and disabling it on your external ones

Re: [c-nsp] C3560 as CPE, possible TCAM contention

2008-04-29 Thread Brian Turnbow
Note that the tcam utilization is based on the assumtion of up to 8 routed interfaces If you have more you will not be able to reach the max values. We have some with similar values on routing templates that work fine, this particular unit has 13 routed interfaces. Unicast mac addresses:

Re: [c-nsp] BGP Route selection

2008-05-23 Thread Brian Turnbow
Setting the metric is not going to affect your BGP route selection. On router A you can set the weight Or on router 2 you can prepend an AS.(you could have used local preference if the as was the same) Check out http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a0080094431.shtml

Re: [c-nsp] Both my borders crashed?

2008-05-28 Thread Brian Turnbow
SegV exceptions are related to software issues, there is a doc on the cisco site on how to troubleshoot them. The short answer is you are going to need to change your ios release. Regards Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Shaun R.

Re: [c-nsp] BGP Route selection

2008-05-30 Thread Brian Turnbow
: Gert Doering [mailto:[EMAIL PROTECTED] Sent: giovedì 29 maggio 2008 22.20 To: Brian Turnbow Cc: Gary Roberton; Pete Templin; cisco-nsp@puck.nether.net Subject: Re: [c-nsp] BGP Route selection Hi, On Fri, May 23, 2008 at 05:08:58PM +0200, Brian Turnbow wrote: Setting the metric is not going

Re: [c-nsp] Applying bandwidth to an ATM VC path

2008-06-09 Thread Brian Turnbow
Check out PVP http://www.cisco.com/en/US/tech/tk39/tk48/technologies_q_and_a_item09186a008011a901.shtml#qa13 Regards Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of james edwards Sent: lunedì 9 giugno 2008 5.38 To: cisco-nsp@puck.nether.net

Re: [c-nsp] ATM to Frame internetworking

2008-06-11 Thread Brian Turnbow
And lastly to map the atm to frame and translate it. connect ADSL2FRAMEDPVC Serial6/0:0 33 ATM5/0 2/357 service-interworking If I remember correctly, it's been awhile, using service-interworking you need to use service translation. Ie connect ADSL2FRAMEDPVC Serial6/0:0 33 ATM5/0 2/357

Re: [c-nsp] 7200s (VXRs and not) and MPLS capabilities

2008-06-12 Thread Brian Turnbow
The 7200s non vxr will do mpls just fine. I ran some in the past with npe 225s for mpls L3 VPNs with no problem. Having said that I would spend the extra money and get a vxr chassis, especially if you are going to be doing VoIP. You can still go with an older NPE to save money but you will have

[c-nsp] R: Re: 7200s (VXRs and not) and MPLS capabilities

2008-06-14 Thread Brian Turnbow
It gives you support for newer npes. Non vxrs max out at npe225. - Messaggio originale - Da: David Coulson [EMAIL PROTECTED] Inviato: sabato 14 giugno 2008 3.15 A: Eric Kagan [EMAIL PROTECTED] Cc: 'Justin Shore' [EMAIL PROTECTED]; Brian Turnbow [EMAIL PROTECTED]; Cisco-nsp cisco-nsp

Re: [c-nsp] 7200s (VXRs and not) and MPLS capabilities

2008-06-16 Thread Brian Turnbow
I even need a VXR to run a NPE-300? Yes. Don't tell that to this router System image file is slot0:c7200-p-mz.120-32.S7.bin cisco 7206 (NPE300) processor with 262144K/32768K bytes of memory. Processor board ID 18283396 R7000 CPU at 262Mhz, Implementation 39, Rev 2.1, 256KB L2 Cache 6

[c-nsp] Surge protection on leased lines

2008-08-25 Thread Brian Turnbow
Hello, We have several customers that our having problems every time a storm goes through. Our national telco company seems to offer no lightning protection on their lines, and every storm causes a line outage and burns up the attached wic. We've made sure the chassis are grounded , but would

Re: [c-nsp] 3560 ACL performance?

2008-08-25 Thread Brian Turnbow
We use them and have never experienced problems as long as you keep in the tcam space. With too many routes/acls ecc they punt to cpu. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Christian MacNevin Sent: venerdì 15 agosto 2008 6.00 To:

Re: [c-nsp] 6500 snmp and vty acls ?

2008-08-25 Thread Brian Turnbow
COPP is done in hardware ACL on VTY/SNMP is software as far as I remember -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jeff Fitzwater Sent: mercoledì 13 agosto 2008 22.17 To: cisco-nsp@puck.nether.net Subject: [c-nsp] 6500 snmp and vty acls ? Does

Re: [c-nsp] UBR+ and service-policy on ATM PVCs

2008-08-25 Thread Brian Turnbow
In order to use qos on atm pvc you need to use abr/vbr/cbr UBR and + are for best effort services offering no bandwidth guarantee so you cannot utilize the service policy That said we mainly use 12.2(31)SB11 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

Re: [c-nsp] Surge protection on leased lines

2008-08-25 Thread Brian Turnbow
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jay Hennigan Sent: lunedì 25 agosto 2008 17.34 To: Cisco Mailing list Subject: Re: [c-nsp] Surge protection on leased lines Brian Turnbow wrote: Hello, We have several customers that our having problems

Re: [c-nsp] RTP related question

2008-09-02 Thread Brian Turnbow
You can use saa on cisco routers to simmulate traffic and gather stats (jitter packet loss ecc). That won't tell if the ports oare open but you can check line quality ecc. http://www.cisco.com/en/US/tech/tk869/tk769/technologies_white_paper09186a00801b1a1e.shtml Brian -Original

Re: [c-nsp] OK, what is a cheap and dirty hack to test a port

2008-10-15 Thread Brian Turnbow
If I simply assign something like IP 127.0.0.5/30 to the port and throw a ton of traffic to 127.0.0.6, will the packets actually go out the port? Or will the router see that the port is looped and just discard the traffic? From the router running extended pings to the 127.0.0.5 address

Re: [c-nsp] 7206VXR and CBWFQ

2008-10-20 Thread Brian Turnbow
40 1/10 http://www.cisco.com/en/US/tech/tk39/tk824/technologies_configuration_example09186a0080094cf6.shtml Brian From: Victor Cappuccio [mailto:[EMAIL PROTECTED] Sent: venerdì 17 ottobre 2008 18.52 To: Brian Turnbow Cc: Networkers; cisco-nsp

Re: [c-nsp] 7206VXR and CBWFQ

2008-11-02 Thread Brian Turnbow
Cisco IOS Software, 7200 Software (C7200P-JS-M), Version 12.2(31)SB13, RELEASE SOFTWARE (fc1) Brian From: Networkers [mailto:[EMAIL PROTECTED] Sent: domenica 2 novembre 2008 18.20 To: Brian Turnbow; Victor Cappuccio Cc: cisco-nsp@puck.nether.net Subject: Re

[c-nsp] CISCO-AAL5-MIB

2008-11-04 Thread Brian Turnbow
Hello all, I have some vxrs running 12.2.31SB13 and have run into a strange situation. We use snmp for statistics gathering ecc . Specifically we use the aal5 mib for atm info gathering 1.3.6.1.4.1.9.9.66.1.1.1.1.1 Everything seemed to be going fine but now I see that some vcs do not show up in

Re: [c-nsp] GSR no ldp all of a sudden

2008-11-06 Thread Brian Turnbow
I would start with what was done here ? Nov  6 14:44:45 GMT: %SYS-5-CONFIG_I: Configured from console by vty0 (5.14.64.1) Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Mark Tech Sent: giovedì 6 novembre 2008 17.39 To:

Re: [c-nsp] vrf-lite and pppoA interfaces

2008-11-07 Thread Brian Turnbow
Hi Wayne, Take a look into assigning via radius the vrf for the ppoa sessions. If you google on the list you will find several discussions on the issue. You can then use vrf aware firewall features (like vrf aware nat ecc) for internet access.

Re: [c-nsp] Cisco IOS for broadband aggregation

2008-11-07 Thread Brian Turnbow
We're stil on 12.2.31SB13 with g2s mainly due to an issue we found with tcp header compression with SRC We have some small vbr connections for voip with header compression enabled and found that a telnet session over the link would cause the router to crash in SRC. Brian -Original

Re: [c-nsp] Config Length Limit? 7600

2008-11-07 Thread Brian Turnbow
You can always save /boot to/from a copy saved to disk Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of David Prall Sent: venerdì 7 novembre 2008 15.01 To: 'Paul Stewart'; cisco-nsp@puck.nether.net Subject: Re: [c-nsp] Config Length Limit? 7600

Re: [c-nsp] interface packets/sec MIB

2008-11-13 Thread Brian Turnbow
RFC 1213 .1.3.6.1.2.1.2.2.1 Inside you may find unicast packets and non unicast packets Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Samit Sent: giovedì 13 novembre 2008 9.36 To: cisco-nsp@puck.nether.net Subject: [c-nsp] interface

[c-nsp] R: ISDN to VoIP dial-peer Question

2008-11-19 Thread Brian Turnbow
use translation rules. add a prefix inbound on each side and use that for routing. i.e add 111 from pots and 222 from ip outgoing on pots the destination pattern 222T will strip the 222 and sendit out clean on the ip side 111T , you will need to traslate outgoing to remove the 111 as voip perrs

[c-nsp] R: Tunnel keepalive in NAT environment problem

2008-11-19 Thread Brian Turnbow
why not set up saa to ping through the tunnel on each router? It will keep the tunnel up without having to set up keepalive. Brian Da: [EMAIL PROTECTED] per conto di Brett Frankenberger Inviato: mar 18/11/2008 19.48 A: Oliver Boehmer (oboehmer) Cc:

Re: [c-nsp] wireless access-controll feature in ios software

2008-11-26 Thread Brian Turnbow
you mean the authentication proxy in ios? http://www.cisco.com/en/US/docs/ios/12_0t/12_0t5/feature/guide/iosfw2_1.html Brian -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Arne Larsen / Region Nordjylland Sent: martedì 25 novembre 2008 21.53 To:

Re: [c-nsp] Stream Association Failed: Requested codec=0x5=g711ulaw, Negotiated codec=0xFFFFFFFF=No Code

2009-01-14 Thread Brian Turnbow
A dial peer pots cannot have a codec You need to place it the voip dial peer. The defualt codec is g729 , you can change it by setting a default codec clas using voice class codec Regards Brian -Original Message- From: cisco-nsp-boun...@puck.nether.net

Re: [c-nsp] MPLS Question - Applying QoS using MQC

2009-01-23 Thread Brian Turnbow
Why not use a service policy on the input interface to color your traffic? This can be sent by radius as well depending on your ios. With this method you could even classify different incoming traffic(ie high priority, normal ecc) inside the VPN. Then match based on dscp. Much more flexible

Re: [c-nsp] Hardware limitations on SUP32 with LDP and full routing table

2009-01-23 Thread Brian Turnbow
As has been said before...it's unfortunate cisco decided not to do a Sup32-3bxl. It renders the Sup32 unsuitable for use in networks where a Sup2 doesn't cut it, but Sup720-3bxl is overkill. Especially after they said they would (at lest at this roadshow)

Re: [c-nsp] 7200VXR for Session Border Controller

2009-02-09 Thread Brian Turnbow
You need to look for unified border element , it used to be multiservice ip to ip gateway. There should be some basic examble on the site as well. Here is the configuration guide http://www.ciscosystems.com/en/US/docs/ios/voice/cube/configuration/guide/12_4t/vb_12_4t_book.html Brian

Re: [c-nsp] snmp-server ifindex persist - store data on flash/disk?

2009-03-10 Thread Brian Turnbow
I'm guessing you want the fixed ifindex for snmp polling purposes. If that is the case try the aal5 cisco mib where you can poll based on vc data. Note that it seems to not work well if you have persistent indexes in use , at least on 12.2SB. Brian -Original Message- From:

Re: [c-nsp] 7206 NON VXR

2009-03-17 Thread Brian Turnbow
225 is the last supported version 300 will work depending on ios version. It is not supported by cisco and 12.1 and above don't let you boot with a 300 in it 12.0 will. System returned to ROM by reload at 11:33:21 CEST Fri Aug 22 2008 System restarted at 11:34:44 CEST Fri Aug 22 2008 System

Re: [c-nsp] 3750 High Cpu IP Input

2009-04-24 Thread Brian Turnbow
You can use show controller cpu to help see whats going to the cpu Make sure you have no ip redirects and no proxy arp on all the interfaces. How many routed interfaces do you have ? The output below for max is for 8 routed interfaces if you have more you should change to the desktop switching

Re: [c-nsp] 3750 High Cpu IP Input

2009-04-24 Thread Brian Turnbow
: Chris Lane [mailto:clane1...@gmail.com] Sent: venerdì 24 aprile 2009 11.17 To: Brian Turnbow Cc: Peter Rathlev; cisco-nsp@puck.nether.net Subject: Re: [c-nsp] 3750 High Cpu IP Input sh controllers cpu-interface ASICRxbiterr RxunderFwdctfix Txbuflos Rxbufloc Rxbufdrain

Re: [c-nsp] Reload without confirmation

2009-06-24 Thread Brian Turnbow
In the past I used snmp dto do this, you need to enable snmp-server system-shutdown Before it is possible, and it is not possible on all platforms, but is it takes this command it should work I don't have the mib handy , but can dig for it if you can't find it Brian -Original

Re: [c-nsp] round-trip differences towards google

2009-07-08 Thread Brian Turnbow
As google is not a single server but a cloud of clusters of servers you are getting routed by a load balancer of some sort. In a nutshell this is what happens, the IP address 209.85.227.103 is a virtual address that gets sent to various real servers. As the source address changes the load

Re: [c-nsp] Manually set WS-X6148-GE-TX MTU size (1500, 1518)

2009-07-30 Thread Brian Turnbow
1518 = 1500 payload(ie IP) + 18Byte ethernet header and trailer You need the 6148A to go higher Brian -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of falz Sent: mercoledì 29 luglio 2009 20.04 To:

Re: [c-nsp] IP unnumbered vlan subinterfaces question

2009-08-03 Thread Brian Turnbow
Not sure what's attached to the IP, or what you want to achieve , but a different approach would be to add no keepalive to the ethernet so it is always up. Brian -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of

Re: [c-nsp] 7500 for DSL aggregation - RSP memory error?

2009-08-04 Thread Brian Turnbow
It's been awhile since I've had one but The MD error is a memory parity error. 2w5d: %RSP-3-ERROR: Cybus1 parity error (bytes 0:7) 04 -Traceback= 0x40588CDC 0x405891CC 0x405892F0 0x4058A978 0x404CFA54 Means that it was received on cybus1 ( slots5-7) This comes from the VIP, so I don't think

Re: [c-nsp] 3750 Suggestions?

2009-08-06 Thread Brian Turnbow
It'll give for more mac space , but you'll have the same problem with routes. Vlan is basically a layer 2 only template so all your ip routes with not be hardware forwarded. For this you'd need an external router.You could try and take a 3750 out of the stack and use it as the router , the

Re: [c-nsp] Leaking specific routes from a VRF

2009-09-07 Thread Brian Turnbow
-Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of luismi Sent: lunedì 7 settembre 2009 10.17 To: Tomas Caslavsky Cc: ivan.d...@raxon.es; cisco-nsp@puck.nether.net; Daniska Tomas Subject: Re: [c-nsp] Leaking specific routes

Re: [c-nsp] 2801 as console server

2009-09-16 Thread Brian Turnbow
-Is there a way to access the async line from within the router itself ? So just a telnet/ssh to the router and then something like 'connect line XXX' ? The connect command on the router seems an equivalent of telnet for outgoing tcp sessions and I don't see another command that could

Re: [c-nsp] QoS best practices

2009-10-15 Thread Brian Turnbow
The 3560 buffering discussion has reminded me: It's not hard to find documentation on configuring QoS, but I haven't yet found any best practices reagarding how to specifically classify, i.e. what traffic goes in what queue with what DSCP/CoS marking. RFC 4594 is a good start For VoIP it

Re: [c-nsp] Flow Control and 10GE interfaces

2009-11-23 Thread Brian Turnbow
-Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Phil Mayers Sent: lunedì 23 novembre 2009 17.05 To: Gert Doering Cc: Matthew Melbourne; cisco-nsp@puck.nether.net; Ross Vandegrift Subject: Re: [c-nsp] Flow Control and

Re: [c-nsp] Basic QoS on ATM subinterfaces

2009-11-24 Thread Brian Turnbow
You can't do it with ubr/ubr+ interfaces ,you need to set a different class of service. Here is an example technote http://www.cisco.com/en/US/tech/tk39/tk824/technologies_configuration_example09186a0080094cf6.shtml Brian -Original Message- From: cisco-nsp-boun...@puck.nether.net

Re: [c-nsp] what is it with 3550s?

2010-02-03 Thread Brian Turnbow
-Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Jeff Bacon Sent: mercoledì 3 febbraio 2010 18.03 To: cisco-nsp@puck.nether.net Subject: [c-nsp] what is it with 3550s? They seem to be an incredibly popular device,

Re: [c-nsp] find window's machine from Cisco Router

2010-02-05 Thread Brian Turnbow
Though not as reliable as a port scanner, you could do something like this even from remote access-list 101 permit udp any any range 137 138 log access-list 101 permit any any interface fa1 ip access-group 101 in Then Show log to see netbios packet users Brian -Original

Re: [c-nsp] find window's machine from Cisco Router

2010-02-05 Thread Brian Turnbow
sorry forgot the ip access-list 101 permit ip any any Brian Turnbow Network Manager TWT S.p.A. From: vijay gore [mailto:vijaygor...@gmail.com] Sent: venerdì 5 febbraio 2010 10.42 To: Brian Turnbow Cc: Andrew Gabriel; cisco-nsp@puck.nether.net Subject

Re: [c-nsp] find window's machine from Cisco Router

2010-02-05 Thread Brian Turnbow
udp any any range 137 138 then debug ip packet 102 when done don't forget undebug all Brian From: vijay gore [mailto:vijaygor...@gmail.com] Sent: venerdì 5 febbraio 2010 10.57 To: Brian Turnbow Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] find

Re: [c-nsp] Renumbering serial interfaces

2010-02-18 Thread Brian Turnbow
Besides the reload in xx that several have mentioned you can also put secondary Ips on the link Nad then cancel the primary. I.e. interface ATM0/0.32 point-to-point Ip add 2.2.2.2 255.255.255.252 secondary Telnet/ssh to this address using source address 2.2.2.1 Then no ip add 1.1.1.1

Re: [c-nsp] Renumbering serial interfaces

2010-02-18 Thread Brian Turnbow
- From: Steve Bertrand [mailto:st...@ibctech.ca] Sent: giovedì 18 febbraio 2010 14.22 To: Brian Turnbow Cc: james edwards; cisco-nsp@puck.nether.net Subject: Re: [c-nsp] Renumbering serial interfaces On 2010.02.18 03:22, Brian Turnbow wrote: Besides the reload in xx that several have mentioned you

Re: [c-nsp] ASR v VXR

2010-02-26 Thread Brian Turnbow
Hello, I've got a pair of 7200VXRs w/ NPE400s doing bba for 3 ATM DS3s as well as T-1 aggregation and a server farm. I was looking at my options for upgrading and consolidating these boxes and I think it would either be an 7200VXR-G1 (G2?) or an ASR1002. These two options seem to carry

Re: [c-nsp] SecureACS Appliance AD Authentication

2010-03-01 Thread Brian Turnbow
-Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Ryan Lambert Sent: lunedì 1 marzo 2010 17.48 To: Saxon Jones Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] SecureACS Appliance AD Authentication yeah, sorry, I

Re: [c-nsp] L2 Link Failover

2010-03-31 Thread Brian Turnbow
But this handshake is done at the time of beginging when PORTCHANNEL COMES up. ONce etherchannel is up , link are brought out of the etherchannel when physical interface goes down. Actually there are periodic packets in lcap, depending on what you are using they can be configured. IIRC 30

Re: [c-nsp] Cisco 3660 url filter

2010-03-31 Thread Brian Turnbow
Hi,   I am looking to do the url filtering on my cisco 3660 router.   Hi Bunny, You can use nbar Try googling nbar youtube you will find many examples Brian ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] Cisco 3660 url filter

2010-04-01 Thread Brian Turnbow
, Brian Turnbow b.turn...@twt.it wrote: From: Brian Turnbow b.turn...@twt.it Subject: RE: [c-nsp] Cisco 3660 url filter To: Bunny Singh jump2fl...@yahoo.com, cisco-nsp@puck.nether.net Date: Wednesday, March 31, 2010, 5:07 PM Hi

Re: [c-nsp] Remote Parking Gates VPN to Campus Network with 3G

2010-04-13 Thread Brian Turnbow
-Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of schilling Sent: martedì 13 aprile 2010 16.58 To: Luan Nguyen Cc: cisco-nsp Subject: Re: [c-nsp] Remote Parking Gates VPN to Campus Network with 3G We talked about 880s,

Re: [c-nsp] Huawei instead of Cisco

2010-05-13 Thread Brian Turnbow
What about the CPE side? We have been offered Huawei devices to be used as G.SHDSL.bis termination devices (on the CPE side), and they look quite interesting - a Cisco 1841 with a SHDSL-WIC would also work, of course, but the WIC is just too expensive for a CPE... We have a couple installed ,

Re: [c-nsp] RFC 4797 Support?

2010-07-08 Thread Brian Turnbow
Hi, I have a question: Other than something like 2547oDMVPN, is there any implementation of an RFC4797 style PE-PE interconnect using an IP only (no mpls) core? Where the outer-most transit label is replaced with an IP header, or GRE header? You can do mpls on a gre tunnel, just configure

Re: [c-nsp] Multiple E1s on 2821

2010-07-12 Thread Brian Turnbow
Peter Hicks wrote: All, We have three E1 voice circuits on a 2821 - two from the same provider on on E1 0/0/0 and E1 0/0/1, and a third from a different provider on a E1 0/1/0 - a separate VIC. After fixing a broken fan on the router, the third E1 is experiencing slip seconds. The

Re: [c-nsp] ASR1000 Series PPPoA

2010-07-21 Thread Brian Turnbow
Anyone heard anything on PPPoA on the ASR 1000 series yet? As far as i know it isn't supported (yet?) but i might be wrong :) PPPoA would make it a superb replacement for our 720X series We've been told it won't happen at least any time soon and to go with 10k as an upgrade path... Not

Re: [c-nsp] ASR1000 Series PPPoA

2010-07-22 Thread Brian Turnbow
Anyone heard anything on PPPoA on the ASR 1000 series yet? As far as i know it isn't supported (yet?) but i might be wrong :) PPPoA would make it a superb replacement for our 720X series We've been told it won't happen at least any time soon and to go with 10k as an upgrade path... Not

Re: [c-nsp] pop site battery backup recommendations

2010-07-23 Thread Brian Turnbow
Yes, you would be much better served by an online UPS, which would be anything in the Smart-UPS RT series if you want to stick with APC. Below that it's just line interactive. An online UPS also has a bypass in them, so in theory any faults should cause the unit to switch to bypass and send an

Re: [c-nsp] Weird Traceroute Issue to Specific Destination

2010-09-21 Thread Brian Turnbow
Hi all Please see comments in line -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Paul Stewart Sent: martedì 21 settembre 2010 17.48 To: 'Heath Jones' Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] Weird

Re: [c-nsp] SegV exception On 7206 LNS

2010-09-22 Thread Brian Turnbow
My Cisco 7206VXR with NPE-G2 runs as an LNS terminating PPPOE sessions. It also terminates a DS3 used for data T1s. About once a week or so, a SegV exception happens, and the router resets itself. I have no idear why. There seems to be no pattern to it, and I can't figure out for

Re: [c-nsp] much to much filtered packets punted to CPU on 7604

2010-10-08 Thread Brian Turnbow
see both counters from sh access-list and sh tcam interface.. increasing at nearly the same rate (see below). I use 2 extended ACLs applied to an interface for filtering inbound/outbound traffic. There is plenty of TCAM space, I don't use log statement, no ip unreachables is configured

Re: [c-nsp] Suggested Time - 1pm CET + US/Eastern - Wednesday - Re: CCO Login to ftp.cisco.com hosed [was Re: FYI: SXI5 posted]

2010-11-11 Thread Brian Turnbow
But there *could* be someone out there downloading new IOS who doesn't have a support contract! That's *literally* stealing food from the mouths of Cisco coders! In the same way as the music, movie and software industries decide that they're not selling as much as they think they should,

Re: [c-nsp] SIP to ISDN Call Progress

2010-11-15 Thread Brian Turnbow
Hello, I configured my dial-peer in this way: dial-peer voice 1400 pots voice cut-through alert preference 4 destination-pattern 199151119 progress_ind setup enable 1 no digit-strip port 0/0/1:15 ! Better to use progress_ind setup enable 3 Telling the network that the

Re: [c-nsp] ATM Subinterface QoS

2010-12-20 Thread Brian Turnbow
Trying to add service-policy output MAP-1536-OUT to the subinterface gives me the error GTS : Not supported on this interface If I add it to the PVC I get the error GTS : Not supported over ATM VCs Hi Dave Short answer Can't apply it to a ubr interface(default) use ABR/VBR/CBR For a

Re: [c-nsp] BGP next-ASN check built-in ?

2011-04-11 Thread Brian Turnbow
Hi See in-line -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- boun...@puck.nether.net] On Behalf Of tim Sent: lunedì 11 aprile 2011 11:17 To: cisco-nsp@puck.nether.net Subject: [c-nsp] BGP next-ASN check built-in ? Hi list, I thought I had read

Re: [c-nsp] MQC and PA-A6

2012-04-16 Thread Brian Turnbow
Hi -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- boun...@puck.nether.net] On Behalf Of Marco Marzetti Sent: lunedì 16 aprile 2012 16:13 To: cisco-nsp@puck.nether.net Subject: [c-nsp] MQC and PA-A6 Hello, Simple and plain question: does MQC work

Re: [c-nsp] LNS Error %VPDN-3-NORESOURCE:

2012-06-15 Thread Brian Turnbow
Hi, Hi. Thanks for the reply. What I noticed today was, I tried to authenticate one vrf-enabled l2tp session and one global (no- vrf). The one with VRF can't authenticate. Giving me the error of LNS no resources for user... But the one with no-vrf was able to authenticate

[c-nsp] ASR1000 and QOS

2012-08-22 Thread Brian Turnbow
Hello Everyone, I am trying to realize a qos configuration on an asr 1006 for pppoe services being sold by our national incumbent. On a single GE interface I will receive two classes of services, cos 0 and cos 1, each with a set bandwidth. i.e. cos 0 100mbps cos 1 20mbps. Each dslam gets

Re: [c-nsp] Port Errors

2012-08-28 Thread Brian Turnbow
-Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- boun...@puck.nether.net] On Behalf Of Harry Hambi Sent: martedì 28 agosto 2012 11:17 To: cisco-nsp@puck.nether.net Subject: [c-nsp] Port Errors Hi All, I have a module (16 SFM-capable 16 port

Re: [c-nsp] Port Errors

2012-08-28 Thread Brian Turnbow
Hi All, I have a module (16 SFM-capable 16 port 10/100/1000mb RJ45) in a 6500 chasis running IOS Version 12.1(23), giving the following errors Aug 26 06:41:48.965: %PM_SCP-SP-6-LCP_FW_ERR_INFORM: Module 9 is experiencing t e following error: Pinnacle #0, Frames with Bad Packet CRC

Re: [c-nsp] Sup720 SVI ACL deny punted? (no logging)

2012-08-29 Thread Brian Turnbow
A couple of ideas 1 to generate an ip unreachable ? try disabling them on the SVI 2 I remember something about acl and netflow (punts to create flows) but it was sup-2. I'm not sure if it still applies to sup-720 Brian -Original Message- From: cisco-nsp-boun...@puck.nether.net

  1   2   >