Re: [c-nsp] need help about switch cisco 4 9 4 8

2009-02-20 Thread Matthew Huff
config register 2142 means boot without config in the rommon set config-register to 0x2102 and type restart I'm not up on the 4948 management interface. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim

Re: [c-nsp] need help about switch cisco 4 9 4 8

2009-02-20 Thread Matthew Huff
it may be that your flash is corrupt, is missing a ios image, etc... My rommon memory is a bit fuzy atm, but you should be able to do a dir flash: or dir /all and see what images are there. Then do a boot imagename Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY

Re: [c-nsp] PIX causing problems with TLS esmtp session

2009-02-27 Thread Matthew Huff
setup an access list with the hosts in it and port 25. use the capture command to setup a capture on both interfaces. See which side is sending the reset (the real host, or the firewall) Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com

Re: [c-nsp] cisco router

2009-03-24 Thread Matthew Huff
of flash. If you can't get one on ebay with that, buy a cheap one and get memory from a third-party retailer such as memory Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com  | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139

Re: [c-nsp] aironet disable ssid when no lan connection

2009-04-03 Thread Matthew Huff
Will station-role root access-point fallback track fa 0 under the radio interface work for you? On 4/3/09 9:10 PM, Dan Letkeman danletke...@gmail.com wrote: Hello, Is there a command on an 1131ag aironet ap that allows you to disable the ssid broadcast if there is no lan connection to the

[c-nsp] sup 720 3c 10GE blades for 7600

2009-04-28 Thread Matthew Huff
Our cisco rep and var are pushing back on our plans to upgrade our 7600 from sup32 to the RSP 720 with 10GE saying they are in limited production. Of course, they are pushing us toward the ASR product line. Anyone know of any issues with the RSP 720 w 10GE interfaces? Matthew Huff

Re: [c-nsp] sup 720 3c 10GE blades for 7600

2009-04-28 Thread Matthew Huff
That's good news. That's what we heard as well. Since we are doing box-to-box redudancy (eigrp load balancing) and not using SSO, RPR/RPR+ then there shouldn't be an issue. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460

[c-nsp] BGP Med and outbound metric

2009-04-30 Thread Matthew Huff
number of prefixes 1 Both outputs show a metric of 0. Any ideas? Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com  | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 ___ cisco-nsp

Re: [c-nsp] BGP Med and outbound metric

2009-04-30 Thread Matthew Huff
Ah. I didn't realize the show was before the route-map was applied. I was trying to make sure everything was setup correctly on our side before contacting the other ASN. They may very well have something that zero's the metric. Matthew Huff   | One Manhattanville Rd OTA Management

Re: [c-nsp] Nexus 5000?

2009-05-06 Thread Matthew Huff
It's an SFP port rather than a copper 10/100/1000. Every Cisco SFP port fiber or copper is 1g only. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com  | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message

Re: [c-nsp] Nexus 5000?

2009-05-10 Thread Matthew Huff
Thanks. It appears that some of the fixed configuration switches that have SFP ports can be 10/100/1000. I've never run into that, as all the SFP ports I've seen on the 6500/7600 are fixed at 1G. I thought it was a SFP thing, but apparently not. Matthew Huff   | One Manhattanville Rd

Re: [c-nsp] No ACL egress logging on 3550s (12.2(44)SE3)

2009-05-31 Thread Matthew Huff
careful with this is the interface has high packet utilization. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com  | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun

Re: [c-nsp] ASR7401 and PA-FE-TX (ISL)

2009-06-08 Thread Matthew Huff
on the 3560 int fa1/2 speed 100 duplex full switchport switchport mode access spanning-tree portfast If you are paranoid with portfast, add spanning-tree bpduguard enable Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com  | Phone: 914

Re: [c-nsp] [c-nap] Location of 67xx rommon (c2lc-rm) images?

2009-06-11 Thread Matthew Huff
It's hidden. We ran into the same thing. Look under the LAN Switches section, for switches, 6509, then the 6500 Virtual Switching Supervisor 720, IOS Rommmon. It's only there, and it's the same for DFC with regular sup 720. We found this out from a TAC case. Matthew Huff   | One

Re: [c-nsp] ASA 5510 Configuration Replication Failure

2009-06-11 Thread Matthew Huff
Try connecting to the serial port on both boxes and setting the name on both, and then retrying the sync. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original

Re: [c-nsp] cisco-nsp Digest, Vol 79, Issue 37

2009-06-11 Thread Matthew Huff
. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- boun...@puck.nether.net] On Behalf Of Jeff

Re: [c-nsp] 7201 NPE-G2 vs. 7204 with NPE-G2 engine

2009-06-15 Thread Matthew Huff
I believe the deal with the 7201 is that you are paying for the compactness. Also the 7204 is probably the most mass produced 72xx, so it's probably an economy of scale, especially if you are looking at refurb. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY

Re: [c-nsp] Network Perefromance

2009-06-16 Thread Matthew Huff
x.x.x.x codec g729a ip sla schedule 1 life forever start-time now Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun

Re: [c-nsp] QoS for skype with nbar on 837 with 12.3(11)YZ2

2009-06-19 Thread Matthew Huff
to proxy the ssl traffic at the source). I'd be happy to be proved wrong, but I believe, at least for now, that Skype has won the war. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139

Re: [c-nsp] QoS for skype with nbar on 837 with 12.3(11)YZ2

2009-06-21 Thread Matthew Huff
I'm afraid you are out of look. In order to get skype 3.0 into IOS, Cisco had to leave behind PDLM and hard code it. Even then it's pretty useless. Only solution is to get to 12.4(22)T+ Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com

[c-nsp] Non export of netflow of dscp bits from PCF3A

2009-06-30 Thread Matthew Huff
. The difference is the distribution switch is a PFC3A where the core switches are PFC3Bs. Anyone seen this issue before? I've verified that the netflow configurations are identical, and that the packets do have the attributes set as they pass throught he distribution. Matthew Huff | One

Re: [c-nsp] Non export of netflow of dscp bits from PCF3A

2009-07-01 Thread Matthew Huff
That's what I suspected, but I couldn't find a release note/tech note that detailed that. And cisco support hasn't been helpful either, even though I mentioned that I suspected it was a limitation of the PFC3A. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY

Re: [c-nsp] disable break on boot for IOS??

2009-07-13 Thread Matthew Huff
If you are running a newer IOS and newer ROMMON you can disable password-recover (i.e. break during boot) using no service password-recovery. Make sure to read http://www.cisco.com/en/US/docs/ios/12_3/12_3y/12_3ya8/gtnsvpwd.html completely, you can brick a router otherwise. Matthew

Re: [c-nsp] multiple vlans on a port

2009-07-13 Thread Matthew Huff
access vlan 120 switchport trunk native vlan 120 switchport trunk allowed vlan 100,120,231,321 switchport mode trunk switchport nonegotiate end Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com  | Phone: 914-460-4039 aim

Re: [c-nsp] Software versioning on SUP720s

2009-07-17 Thread Matthew Huff
Yes, it's a problem. do a show run | include boot system to see what the boot string says. also do a 'show boot' and 'show redundancy'. I bet you are missing the image on the redundant sup. Do a dir disk0: and a dir slavedisk0: or disk1 depending on the boot string Matthew Huff

Re: [c-nsp] Balancing T1's with CEF

2009-07-30 Thread Matthew Huff
Unless you do per-packet load-sharing (which you don't want to do since it's cpu switched), the path is session based. If most of the traffic is going from one source to one destination, it won't be load-shared. What do the routing tables look like in both directions? Matthew Huff

Re: [c-nsp] VSS 1440 issues

2009-08-05 Thread Matthew Huff
. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- boun...@puck.nether.net] On Behalf Of C and C

Re: [c-nsp] Cisco 6509-E WiSM - OIR

2009-08-12 Thread Matthew Huff
Not folklore. I've had a 6509 with Sup 720-3B crash twice during OIR. Cisco claims the first time I inserted too fast, the second time too slow. I've also had a 6509 linecard scorch the backplane due to a short. Not a fun day. Matthew Huff   | One Manhattanville Rd OTA Management LLC

Re: [c-nsp] Open Source Substitute for Cisco's Secure ACS?

2009-08-13 Thread Matthew Huff
future upgrade paths to the next-generation ACS 5.x platform. Please see the Cisco Secure ACS 5.0 User Guide at http://www.cisco.com/en/US/products/ps9911/tsd_products_support_series_home. html for a more detailed comparison of ACS 4.0 and ACS 5.0. Matthew Huff   | One Manhattanville Rd OTA

Re: [c-nsp] Smartnet pricing?

2009-09-28 Thread Matthew Huff
. Otherwise, maybe your customer will learn about being pennywise and pound foolish :) Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com  | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp

Re: [c-nsp] Fiber

2009-11-12 Thread Matthew Huff
being done to future proof the wiring. Most of the times the fiber never ends up being used. Cat6a is backwards compatible with 5e, so if you are doing a new wiring plant, that's enough future proof for the next reasonable term. Matthew Huff   | One Manhattanville Rd OTA Management LLC

Re: [c-nsp] 6500 - What determines whether certain traffic is punted or not?

2009-11-24 Thread Matthew Huff
...so: mac-address-table aging-time 14400 Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com  | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp

Re: [c-nsp] IOS Version for 7206VXR

2009-12-04 Thread Matthew Huff
I've been pretty happy with 12.4(24)T2. We are doing bgp, access-list, etc...but not ospf.. 12.4(24)T fixed a lot of bugs in bgp and T2 seems stable. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim

[c-nsp] EIGRP route knob tuning

2009-12-11 Thread Matthew Huff
to the max (same as a 10GB interface) fixed the problem. What happens when 100GB uplinks appear? Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com  | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139

Re: [c-nsp] EIGRP route knob tuning

2009-12-11 Thread Matthew Huff
on aggregated 10gb trunks. I assume Cisco will have to come up with some new EIGRP version that's backward compatible which will encapsulate the old metrics within a new larger field. Anyone here anything about this yet from Cisco? Matthew Huff   | One Manhattanville Rd OTA Management LLC

[c-nsp] Failed crypto key generate after upgrading to SXI3

2009-12-28 Thread Matthew Huff
creation failed, status -1 Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] Failed crypto key generate after upgrading to SXI3

2009-12-28 Thread Matthew Huff
not indicate an error (it comes from an additional check on SSO sync buffer size). Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: Andrew

[c-nsp] Differences between 3750-E and 3560-E switches

2010-01-19 Thread Matthew Huff
have any war stories? Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https

Re: [c-nsp] Differences between 3750-E and 3560-E switches

2010-01-19 Thread Matthew Huff
I also can't tell the difference. We've been using pairs of 3560E's as replacement for stacked pairs of 3750G's (non-E) and are very happy about that. They have almost the exact same specs according to the data sheets[0] apart from the stacking thing. And in my eyes it's wrong to pay for

Re: [c-nsp] best ios version for VSS

2010-01-27 Thread Matthew Huff
(config)#crypto key generate rsa general-keys label switch-core1.ox.co modulus 512 switch-core1(config)#crypto key zeroize rsa switch-core1.ox.co and the phantom key will be gone. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914

Re: [c-nsp] best ios version for VSS

2010-01-27 Thread Matthew Huff
The base bug is CSCtc41114. The workaround that I provided is derived from the bugid and a cisco engineer. -Original Message- From: Adam Korab [mailto:adam.ko...@gmail.com] Sent: Wednesday, January 27, 2010 5:43 PM To: Matthew Huff Cc: Alasdair McWilliam; Holemans Wim; cisco-nsp

[c-nsp] 10GE WAN options for 7606 for market data / micro-bursting

2010-01-29 Thread Matthew Huff
or VRF, or QinQ or any other tunneling, but we need the most flexible, best 10GB WAN interface that can help us deal with bursting/QOS. Any experiences, suggestions, warnings...? Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914

Re: [c-nsp] 10GE WAN options for 7606 for market data / micro-bursting

2010-01-30 Thread Matthew Huff
that quarter. -Original Message- From: Rob Shakir [mailto:r...@eng.gxn.net] Sent: Saturday, January 30, 2010 5:05 PM To: Matthew Huff Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] 10GE WAN options for 7606 for market data / micro-bursting On 30 Jan 2010, at 17:59, Pavel Skovajsa wrote

[c-nsp] IOS Server Load Balancing on C3560-E switches ??

2010-02-10 Thread Matthew Huff
Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net

Re: [c-nsp] IOS Server Load Balancing on C3560-E switches ??

2010-02-10 Thread Matthew Huff
http/https load balancing? Something as simple and cheap as possible. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: David Prall

[c-nsp] strange ipv6 problems on 3550 SVI

2010-03-18 Thread Matthew Huff
: IPv6-EIGRP(0) 14607: Neighbor FE80::20A:F4FF:FE0E:7980 (FastEthernet0/0) is down: retry limit exceeded 009795: Mar 18 11:05:56.597 PDT: %DUAL-5-NBRCHANGE: IPv6-EIGRP(0) 14607: Neighbor FE80::20A:F4FF:FE0E:7980 (FastEthernet0/0) is up: new adjacency Matthew Huff   | One Manhattanville Rd

Re: [c-nsp] strange ipv6 problems on 3550 SVI

2010-03-19 Thread Matthew Huff
Bingo! Yes, I agree, it's worse. I knew the 3550 only did ipv6 in software, but this was going to be a low packet count test. Something things seem to work, but not really. Oh well, that division budgets won't be available to upgrade that switch until after Sept 2011, so it will have to wait.

Re: [c-nsp] NPE-G1 / G2 performance

2010-03-19 Thread Matthew Huff
What type of interfaces do you need? IF just Ethernet, why not look at a 3560-E with IP services or a 4900M -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Jeff Bacon Sent: Friday, March 19, 2010 3:42 PM To:

[c-nsp] Queue type and buffer size on 10GE interfaces on rsp-720-10ge

2010-05-04 Thread Matthew Huff
I'm having difficulty finding any details on the size of the port buffers and/or queue type on the RSP720-3C-10GE sup card for a 7606-s. Anyone know the queue type (receive 8q4t, transmit 1p7q4, etc...) or port buffer size (16mb, 200mb, etc..). Matthew Huff   | One Manhattanville

Re: [c-nsp] Queue type and buffer size on 10GE interfaces on rsp-720-10ge

2010-05-04 Thread Matthew Huff
Thanks. That answers the QOS question, the ports have 8q8t/1p7q8t. Still haven't found the port buffer size on them though. Is it 16mb per port like the 6704 or the 200mb like the 6708? Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com

Re: [c-nsp] 12.2-33.SXI3 SSH broken after changing IP

2010-06-02 Thread Matthew Huff
that will overwrite the phantom, then delete it: switch-core1(config)#crypto key generate rsa general-keys label switch-core1.ox.co modulus 512 switch-core1(config)#crypto key zeroize rsa switch-core1.ox.co and the phantom key will be gone. Matthew Huff   | One Manhattanville Rd OTA Management

Re: [c-nsp] NTP synchronization problems C2801

2010-06-29 Thread Matthew Huff
You need 3, preferably 4 NTP sources so that clients will work correctly. If you have 2, how does it know which one is a better source of time? 3 gives you a quorum, but if 1 fails, then you are back to 2. Four is the magic number. Since you have 2 setup as strata 1, setup two boxes that use

Re: [c-nsp] NTP synchronization problems C2801

2010-06-29 Thread Matthew Huff
erratic sometimes. -Original Message- From: Mack McBride [mailto:mack.mcbr...@viawest.com] Sent: Tuesday, June 29, 2010 7:32 PM To: Peter Rathlev; Matthew Huff Cc: 'cisco-nsp@puck.nether.net' Subject: RE: [c-nsp] NTP synchronization problems C2801 I would try using the same IOS version

Re: [c-nsp] Brief CPU spikes on 6500 Sup 720

2010-07-14 Thread Matthew Huff
Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf

Re: [c-nsp] Brief CPU spikes on 6500 Sup 720

2010-07-14 Thread Matthew Huff
interface is chosen by the higher IP. With dynamic routing and HSRP, it's even easier to create asymetrical routing. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139

Re: [c-nsp] 6509 input queue drops

2010-07-21 Thread Matthew Huff
interface gi3/2 To get an idea of what packets it's dropping. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun

Re: [c-nsp] 6509 input queue drops

2010-07-21 Thread Matthew Huff
The 6148 has 1.4MB buffers per 8 ports. Is there another port free that maybe the group of 8 ports are less busy? Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139

Re: [c-nsp] 6509 input queue drops

2010-07-21 Thread Matthew Huff
That works with software routers/switches, but hold-queue has no positive effect on hardware switches such as the 6500. The hold-queue will only effect software switched packets. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone

Re: [c-nsp] 6509 input queue drops

2010-07-21 Thread Matthew Huff
Actually, I take some of that back. There are some circumstances where increasing the hold queue will help, but not for buffer overruns in hardware where microbursting is causing the overflow. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http

Re: [c-nsp] Multicast issues on 7600s with WS-6748-sfp blades

2010-07-29 Thread Matthew Huff
good at the CEF/mfib level, and all counters show the packet count increasing, but the packets never get forwarded out of the linecard. Cisco engineering was able to verify this was happening, but had no solution other than resetting the linecard. Once it was reset, everything worked. Matthew

Re: [c-nsp] GSR not switching multicast

2010-07-30 Thread Matthew Huff
How about allowing igmp message in/out the interface? permit igmp any any Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun

Re: [c-nsp] DNS Naming conventions for Switches

2010-09-02 Thread Matthew Huff
. Then if I need to address individual interfaces I setup a forward A record for those, but leave the PTR going back to the loopback name. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914

Re: [c-nsp] Need help with setting up ip multicast routing...correction

2010-10-11 Thread Matthew Huff
If the switch doesn't provide layer 3 services (routing) itself, but is really a l2 switch, then you don't need multicast routing / pim, etc...However, you should have igmp snooping on. -Original Message- From: cisco-nsp-boun...@puck.nether.net

[c-nsp] Redistributing ipv6 static default route into eigrp failure

2010-10-19 Thread Matthew Huff
successors, FD is 512 via Connected, TenGigabitEthernet1/2 Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 ___ cisco-nsp mailing

Re: [c-nsp] Redistributing ipv6 static default route into eigrp failure

2010-10-20 Thread Matthew Huff
Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Matthew Huff

Re: [c-nsp] Redistributing ipv6 static default route into eigrpfailure

2010-10-21 Thread Matthew Huff
be fine, but accepting the command and then not working isn't okay. Matthew Huff   | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun

[c-nsp] Adjusting MTU on 802.1q links

2010-12-03 Thread Matthew Huff
I don't know why it never occurred to me, but on 802.1q trunk links, non-native vlans are encapsulated within 802.1q headers, therefore max packets would have to be fragmented. On trunks that support it, should standard practice to bump up the mtu on both sides to account for the 802.1q header.

Re: [c-nsp] Adjusting MTU on 802.1q links

2010-12-03 Thread Matthew Huff
I have. A cisco 3750, but an older release. Must be a bug. But wanted to know if it was a general problem overall. Doesn't look like it. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC | Phone: 914-460-4039 aim

Re: [c-nsp] ASA 5505 doesn't like itself

2011-02-25 Thread Matthew Huff
Cisco PIX/ASA are not routers. For example, you cannot ping from the inside network to the outside interface, or any other simular type of test. -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Tom Sutherland Sent:

Re: [c-nsp] Sup720, multicast bothers the CPU

2011-03-25 Thread Matthew Huff
and will hose your network. Nothing other than control protocols should use 224.0.0.0-224.0.0.255. The 224.0.1.40 is for Cisco RP discovery and is normal The 239.255.255.250 is SSDP and is a Microsoft Thing and is normal The 239.255.255.253 is SLP and is normal Matthew Huff | 1

Re: [c-nsp] IP GRE tunnel up/down

2011-07-13 Thread Matthew Huff
If it cannot make the original connection it will show up/down Can you route from the source to the tunnel destination and are there any firewalls that would block the GRE protocol? Can the destination route back to the source loopback1? -Original Message- From:

Re: [c-nsp] 7600 HFIB bug?

2011-07-28 Thread Matthew Huff
., what does the interface config look like? Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun

Re: [c-nsp] 7600 HFIB bug?

2011-07-28 Thread Matthew Huff
routes and push some traffic through it. Then add feature by feature back testing heavily each step. If you run into a bug, you might want to look at the latest SRE train. From: Persio Pucci [mailto:per...@gmail.com] Sent: Thursday, July 28, 2011 3:53 PM To: Matthew Huff Cc: cisco-nsp

Re: [c-nsp] ios based FW

2011-08-02 Thread Matthew Huff
Check out the new Zone Based Firewall configuration for IOS Fw feature set. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message

[c-nsp] Incomplete netflow on 7606/RSP720/MSFC4 L3 hardware switched interface with NAT ACLs

2011-08-08 Thread Matthew Huff
exclude is disabled From the config - mls aging long 64 mls aging normal 32 mls flow ip interface-destination-source mls nde sender version 5 ip flow-export source Loopback0 ip flow-export version 9 ip flow-export destination xx.xx.xx.xx 2055 Matthew Huff | 1

Re: [c-nsp] A bit of 6513-E confusion

2011-08-17 Thread Matthew Huff
cards in slots 9 through 13. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun...@puck.nether.net

[c-nsp] WARNING: Netflow Data Export Hardware assisted NAT not supported on 76xx/65xx on the same interface

2011-08-26 Thread Matthew Huff
us the most accurate realtime look at the market data. Evidently I was wrong. I'm sending this so that no one else will make the same mistake we did as well as being in the nsp archives. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA

Re: [c-nsp] WARNING: Netflow Data Export Hardware assisted NAT not supported on 76xx/65xx on the same interface

2011-08-27 Thread Matthew Huff
@puck.nether.net Subject: Re: [c-nsp] WARNING: Netflow Data Export Hardware assisted NAT not supported on 76xx/65xx on the same interface On 08/26/2011 05:25 PM, Matthew Huff wrote: I'm looking at using SPAN to replicate the data and send it to a linux box to then create netflow data exports

Re: [c-nsp] WARNING: Netflow Data Export Hardware assisted NAT not supported on 76xx/65xx on the same interface

2011-08-27 Thread Matthew Huff
) that won't coexist should be pointed out very obviously in their literature. -Original Message- From: Dale W. Carder [mailto:dwcar...@wisc.edu] Sent: Saturday, August 27, 2011 5:13 PM To: Matthew Huff Cc: 'cisco-nsp@puck.nether.net' Subject: Re: [c-nsp] WARNING: Netflow Data Export

Re: [c-nsp] WARNING: Netflow Data Export Hardware assisted NAT not supported on 76xx/65xx on the same interface

2011-08-28 Thread Matthew Huff
To: Matthew Huff; 'Dale W. Carder' Cc: 'cisco-nsp@puck.nether.net' Subject: RE: [c-nsp] WARNING: Netflow Data Export Hardware assisted NAT not supported on 76xx/65xx on the same interface Matthew said: If it was made apparent, could you point to any public documentation that states that? I've scoured

Re: [c-nsp] WARNING: Netflow Data Export Hardware assisted NAT not supported on 76xx/65xx on the same interface

2011-08-28 Thread Matthew Huff
Netflow *collection* of flows traversing the NAT-ed interface. Sorry, I can see why that would be confusing. -Original Message- From: Gert Doering [mailto:g...@greenie.muc.de] Sent: Sunday, August 28, 2011 5:14 AM To: Matthew Huff Cc: 'Dale W. Carder'; 'cisco-nsp@puck.nether.net

Re: [c-nsp] WARNING: Netflow Data Export Hardware assisted NAT not supported on 76xx/65xx on the same interface

2011-08-28 Thread Matthew Huff
Bottom line: you *should* be able to trust vendor marketing, but you *can't*, and I strongly advise you don't, for Cisco or any other vendor - they simply don't convey accurate information reliably enough :o( I agree. Caveat Emptor. I would understand the limitation if I was using some

Re: [c-nsp] ASA vs ISR ZBFW

2011-09-09 Thread Matthew Huff
in ios. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp- boun

Re: [c-nsp] ASA vs ISR ZBFW

2011-09-09 Thread Matthew Huff
clients use the new EPSV verb without failing back correctly to PASV even over ipv4 connections (RFC2428). I've run into this a few times especially with older cisco load balancers. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC

Re: [c-nsp] Troubleshoot UDP out-of-sequence

2011-09-12 Thread Matthew Huff
I have also run into some hosts with optimized udp offloading and/or streams offloading that will send a small percentage of packets outbound out of order, especially on hosts that have IRQ balancing algos. So if the host is out of order -Original Message- From:

Re: [c-nsp] ASA vs. ASR for large Wireless NAT deployment ?

2011-11-13 Thread Matthew Huff
One thing to be aware of is that currently the ASA doesn't support setting the managed or other flag for the RA for ipv6 for DHCPv6 support. This is supposed to be fixed in the next release for the ASA real soon now (tm). -Original Message- From: cisco-nsp-boun...@puck.nether.net

[c-nsp] Weird Multicast microburst amplification issue

2011-12-09 Thread Matthew Huff
to mitigate this? Matthew Huff | 1 Manhattanville Rd Director of Operations | Purchase, NY 10577 OTA Management LLC | Phone: 914-460-4039 aim: matthewbhuff| Fax: 914-460-4139 ___ cisco-nsp mailing list cisco-nsp

Re: [c-nsp] Weird Multicast microburst amplification issue

2011-12-09 Thread Matthew Huff
burst. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: Chuck Church [mailto:chuckchu...@gmail.com] Sent: Friday

Re: [c-nsp] Weird Multicast microburst amplification issue

2011-12-09 Thread Matthew Huff
To: Matthew Huff; 'cisco-nsp' Subject: RE: [c-nsp] Weird Multicast microburst amplification issue Can you move the source server over to switch B to see if the problem still exists on switch B then, or moves to switch A? Anything showing up in the logs? Chuck -Original Message

Re: [c-nsp] Weird Multicast microburst amplification issue

2011-12-09 Thread Matthew Huff
Yes, only the correct stream. I've opened a case with Cisco. I'm suspecting that the multicast replication engine is doing something that causes it to amplify the bursty nature of the traffic causing the microburst overruns. Matthew Huff | 1 Manhattanville Rd Director

Re: [c-nsp] Weird Multicast microburst amplification issue

2011-12-12 Thread Matthew Huff
120Mbps and/or 12,000 pps output on the port. Other than moving to 10GB, I don't see any solutions. Given the 6748 buffer size, I'm surprised it's overrunning it at this volume. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC

Re: [c-nsp] Weird Multicast microburst amplification issue

2011-12-13 Thread Matthew Huff
like the data rates are killing the port buffers. I was hoping that the 6500/sup720 with 6748 would handle 120Mbps, 12k pps multicast, but it doesn't look like it. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC | Phone

[c-nsp] NTP no longer slewing clock under 12.2(33)SXJ2 ???

2012-01-08 Thread Matthew Huff
), drift is 0.00180 s/s system poll interval is 512, last update was 1219 sec ago. switch-core1#show clock detail 12:29:18.402 EST Sun Jan 8 2012 Time source is NTP Summer time starts 02:00:00 EST Sun Mar 11 2012 Summer time ends 02:00:00 EDT Sun Nov 4 2012 Matthew Huff | 1

Re: [c-nsp] NTP no longer slewing clock under 12.2(33)SXJ2 ???

2012-01-08 Thread Matthew Huff
. So, setting up an acl and defining ntp acess-group peer xxx solves the issue. -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Matthew Huff Sent: Sunday, January 08, 2012 12:30 PM To: 'cisco-nsp@puck.nether.net

Re: [c-nsp] Outbound drops on 6748

2012-01-28 Thread Matthew Huff
What is the type of data? Is it bursty? Is the data coming from an bigger pipe upstream? You are likely hitting microbursts. The traffic levels you state are measured over an interval (30 seconds minimum probably). During peak activity you can easy overrun the buffers on the 6748 if your

Re: [c-nsp] Outbound drops on 6748

2012-01-28 Thread Matthew Huff
, January 28, 2012 12:39 PM To: cisco-nsp@puck.nether.net Cc: Matthew Huff Subject: Re: [c-nsp] Outbound drops on 6748 On Sat, Jan 28, 2012 at 4:45 PM, Matthew Huff mh...@ox.com wrote: You are likely hitting microbursts. The traffic levels you state are measured over an interval (30

Re: [c-nsp] Outbound drops on 6748

2012-01-28 Thread Matthew Huff
at Arista. -Original Message- From: Robert Hass [mailto:robh...@gmail.com] Sent: Saturday, January 28, 2012 12:52 PM To: Matthew Huff Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] Outbound drops on 6748 On Sat, Jan 28, 2012 at 6:42 PM, Matthew Huff mh...@ox.com wrote: Cisco

Re: [c-nsp] Outbound drops on 6748

2012-01-28 Thread Matthew Huff
Smith [mailto:d...@eatworms.org.uk] Sent: Saturday, January 28, 2012 2:27 PM To: Matthew Huff; cisco-nsp@puck.nether.net Subject: RE: [c-nsp] Outbound drops on 6748 Its user web browsing (no multicast) and the flow is :- Clients - ACE (load Balance)- 6748 - Appliance - 6748 - 6708

Re: [c-nsp] Filtering traffic to destinations based off of DNSaddresses on an ASA?

2012-02-09 Thread Matthew Huff
Go into your recursive DNS server. Add a blank authoritative forward zone for google.com. Boom, it's dead to you. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914

Re: [c-nsp] Recommended IPv6 Resources

2012-03-13 Thread Matthew Huff
have to find out yourself. Matthew Huff | 1 Manhattanville Rd Director of Operations   | Purchase, NY 10577 OTA Management LLC | Phone: 914-460-4039 aim: matthewbhuff  | Fax:   914-460-4139 -Original Message- From: cisco-nsp-boun...@puck.nether.net

  1   2   >