[c-nsp] Fwd: VLAN 1 through routed ports

2009-01-09 Thread Engelhard Labiro
On Fri, Jan 9, 2009 at 2:22 AM, Justin Shore jus...@justinshore.com wrote: And by all means DO NOT USE VLAN 1. That's what bit me in the ass last night. An unconfigured 7600 LAN port with switchport, mode access and no access vlan defined was a piece in the puzzle of the cluster that was my

Re: [c-nsp] Procurve DHCP relay question

2009-01-09 Thread Jeremy L. Gaddis
On Thu, 8 Jan 2009, Eric Cables wrote: I'm in the middle of a transition from HP - Cisco, with an HP 2848 as the core, so sorry if this e-mail is off topic. I am having a hard time getting DHCP relay to work, and was hoping someone with HP experience could chime in with some assistance.

Re: [c-nsp] 6500 and VSS

2009-01-09 Thread Nick Griffin
So, I'm building this 6509/VSS in the configuration tool on cisco's web site, and I'm getting an error that concerns me. Whenever I select advance ip services, sxi, I think it's telling me I must also have a secondary supervisor, basically for anything other than ip base? Is this other's

[c-nsp] TLU/PLU memory on engine 2 line card (12000)

2009-01-09 Thread Drew Weaver
I know that the packet RAM and route RAM are different but what is the difference between TLU/PLU memory and packet memory? I was just upgrading an E2 card and noticed that on the diagram it specifically indicates that slot 7 (PLU) and slot 8 (TLU) are not user serviceable but all 6 of the

Re: [c-nsp] Fwd: VLAN 1 through routed ports

2009-01-09 Thread Higham, Josh
From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Engelhard Labiro On Fri, Jan 9, 2009 at 2:22 AM, Justin Shore jus...@justinshore.com wrote: And by all means DO NOT USE VLAN 1. That's what bit me in the ass last night. An

[c-nsp] PIX question

2009-01-09 Thread chloe K
Hi all I enable the http and snmp community in dmz 192 network http server enable http 192.168.0.0 255.255.255.0 dmz snmp-server community aaa but I can't access both (httpd and snmpwalk) in any hosts of 192.168.0.0 network What am I doing wrong? Thank you

Re: [c-nsp] PIX question

2009-01-09 Thread Brad Hedlund
On 1/9/09 1:05 PM, chloe K chloekcy2...@yahoo.ca wrote: Hi all I enable the http and snmp community in dmz 192 network http server enable http 192.168.0.0 255.255.255.0 dmz snmp-server community aaa but I can't access both (httpd and snmpwalk) in any hosts of

Re: [c-nsp] PIX question

2009-01-09 Thread Ge Moua
Could be a routing issue on the pix; do you get any syslog msgs about no route . . . ; traffic could be coming in on the dmz interface but leaving out the default route to say like the outside interface. If this is indeed the case then create a route statement: route your_ip_addr

Re: [c-nsp] PIX question

2009-01-09 Thread chloe K
Thank you for your doc info You mean I have to put access-list before http and snmp can work access-list ANY extended permit ip any any access-group ANY in interface dmz ls it OK? One question, Why the telnet and ssh are working now? Thank you again Brad Hedlund

Re: [c-nsp] PIX question

2009-01-09 Thread chloe K
Thank you for your doc info You mean I have to put access-list before http and snmp can work access-list ANY extended permit ip any any access-group ANY in interface dmz ls it OK? One question, Why the telnet and ssh are working? Thank you again

Re: [c-nsp] TLU/PLU memory on engine 2 line card (12000)

2009-01-09 Thread Marc Binderberger
Hi Drew, PLU (pointer lookup) and TLU (table lookup) is memory used by the layer3 ASIC. It contains your FIB/MFIB/LFIB data (read: your CEF and labels). The packet memory keeps - the packet :-) By user serviceable do they mean that you just can't upgrade them? by non-user-upgradable,

Re: [c-nsp] PIX question

2009-01-09 Thread Brad Hedlund
On 1/9/09 2:41 PM, chloe K chloekcy2...@yahoo.ca wrote: One question, Why the telnet and ssh are working? You mean I have to put access-list before http and snmp can work OK. I may have misunderstood your original question. It now sounds like you are trying to enable management of the

Re: [c-nsp] cisco-nsp Digest, Vol 74, Issue 20

2009-01-09 Thread Chris Burwell
Hi Eric, There are a few basic things that should be checked first. I don't mean to insult anyone, but I sometimes overlook some simple steps when I dive into a problem. First, ensure you have the latest software (as HP calls it) running on the switch. This is freely available from the Procurve

[c-nsp] Logical Router Segmentation

2009-01-09 Thread Chris Burwell
I am looking for a bit of guidance on logically segmenting an existing router. Currently I have a core network router that has fiber connections to all of our buildings. Each building is in it's own VLAN. We run OSPF on the router and all VLANS are in the same area 0.0.0.1. In the future things

Re: [c-nsp] cisco-nsp Digest, Vol 74, Issue 20

2009-01-09 Thread Eric Cables
I haven't updated the sw yet, maybe that will yield some results. I have confirmed that I can ping the DHCP server from the switch, and vice versa. I'll check out the software image, and see how behind it is. Thanks for the tips.. -- Eric Cables On Fri, Jan 9, 2009 at 3:30 PM, Chris Burwell

Re: [c-nsp] Logical Router Segmentation

2009-01-09 Thread Brad Hedlund
On 1/9/09 5:52 PM, Chris Burwell cburw...@gmail.com wrote: I am looking for a bit of guidance on logically segmenting an existing router. I appreciate any help! Chris, I think it would help if you drew this up in a Visio, saved it as a PDF, and uploaded it to a URL for folks to look at as

Re: [c-nsp] PIX question

2009-01-09 Thread chloe K
Yes. you are right it works now. https works fine But I can't logon in http as user pix and pw Do I need to do anything? snmp works fine. But I can't get CPU info in cacti? It only shows the interface. Do you have any idea? Thank you again Brad Hedlund

Re: [c-nsp] Logical Router Segmentation

2009-01-09 Thread Chris Burwell
Brad, Thank you for the suggestion! http://www.hiddenone.net/Topology.pdf That PDF has two pages. Page one represents our current topology and page two represents what I would like to do. The red lines on page two represent what would be outside of our network (the two connections). - Chris

Re: [c-nsp] Logical Router Segmentation

2009-01-09 Thread Brad Hedlund
On 1/9/09 8:54 PM, Chris Burwell cburw...@gmail.com wrote: http://www.hiddenone.net/Topology.pdf Chris, Thanks for the diagram. I can now visualize what you are trying to do. For this to work as diagramed you will need to create two separate routing instances on the District Router, one for

Re: [c-nsp] Logical Router Segmentation

2009-01-09 Thread Douglas C. Stephens
Chris, Does your switch or router have VRF-lite in its feature set? I had a similar problem wrapping my brain around layer-3 segmentation. What you describe seems similar in concept to problems I faced in the past couple of years. I found some docs at Cisco that were close to what I wanted