RSM,MLS, MLS-RP,etc [7:5220]

2001-05-21 Thread Arumugam Sundarum

Hi Cisco Comrades,
Anybody can lead me to the resouces for the above that I can get for better
understanding ?

rgds.




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5220&t=5220
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Voice over IP Documents and sample configs [7:5221]

2001-05-21 Thread Hamid

Hi

Can anybody tell me where I can find some sample configs for VoIP and a good
and complete document for it.

Thanks

Hamid




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5221&t=5221
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: RSM,MLS, MLS-RP,etc [7:5220]

2001-05-21 Thread Stephen Skinner

Hi,

www.mplsrc.com

http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/120newft/120t/120t5/vpn.htm

http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/switch_c/xcprt4/xcdtagc.htm


hope this helps

steve

>From: "Arumugam Sundarum" 
>Reply-To: "Arumugam Sundarum" 
>To: [EMAIL PROTECTED]
>Subject: RSM,MLS, MLS-RP,etc [7:5220]
>Date: Mon, 21 May 2001 03:55:01 -0400
>
>Hi Cisco Comrades,
>Anybody can lead me to the resouces for the above that I can get for better
>understanding ?
>
>rgds.
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

_
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5222&t=5220
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



share ethernet [7:5223]

2001-05-21 Thread md. nazri

hi all,
i got 2 routers sharing the same ethernet...both ether should active at the
same time(so i think hsrp not meaningful) with each ether have different ip
address with same subnet. Server on LAN should point to one particular
ip(can it be two..?)...how do i achieve that...??  pls help

tq

rgds
nazri




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5223&t=5223
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



single or mutlimode? [7:5224]

2001-05-21 Thread Andy Low

Hi,

May I know what is the command to check where the ATM interface card is
multi-mode or single-mode?

Thanks,

Andy




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5224&t=5224
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



ccie written [7:5225]

2001-05-21 Thread Stefano Andrello

Today I passed my CCIE written, score 95%.
Thanks to the group and to boson test.
Let's go for the lab

Stefano Andrello
CCIE written, CCNA




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5225&t=5225
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: ccie written [7:5225]

2001-05-21 Thread Moh'd, Quayoom

Hi Stefano
Congratulations on your CCIE written. Can you tell us which books you have
used and  which Boson Test you practiced
Thanks
Mohd.

> -Original Message-
> From: Stefano Andrello [SMTP:[EMAIL PROTECTED]]
> Sent: Mon, May 21, 2001 12:10 PM
> To:   [EMAIL PROTECTED]
> Subject:  ccie written [7:5225]
> 
> Today I passed my CCIE written, score 95%.
> Thanks to the group and to boson test.
> Let's go for the lab
> 
> Stefano Andrello
> CCIE written, CCNA
> FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5226&t=5225
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



QOS/Policy routing [7:5227]

2001-05-21 Thread Frank Kim

Hi folks,
I like to setup a policy so that any traffic destined to 1.1.1.0/24 will
take precedence over the rest.  My outbound link is a single T1.  Please
throw me a short sample config.  Thanks for helping.

-Frank




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5227&t=5227
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



passed CIT [7:5228]

2001-05-21 Thread George Kadeishvili

A traditional Thank All message
Just passed CIT, and completed CCNP.
Priscillas flash cards are great. But the exam itself sucks. Routing was
by far the best one in CCNP track.
Now have to start thinking about CCIE writen.
Regards
George




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5228&t=5228
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: passed CIT [7:5228]

2001-05-21 Thread Vivek Singh

I agree 100% with George...!!!

Vivek

CNE, MCSE, Compaq ASE, CLP Admin, CLP Dev., CCNA, CCDA, CCNP, SCSA

-Original Message-
From: George Kadeishvili [mailto:[EMAIL PROTECTED]]
Sent: Monday, May 21, 2001 3:04 PM
To: [EMAIL PROTECTED]
Subject: passed CIT [7:5228]


A traditional Thank All message
Just passed CIT, and completed CCNP.
Priscillas flash cards are great. But the exam itself sucks. Routing was
by far the best one in CCNP track.
Now have to start thinking about CCIE writen.
Regards
George
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5229&t=5228
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



OT 2B+D Basic Rate ISDN Emulator [7:5231]

2001-05-21 Thread Rashid Lohiya

Hi Guys,

I am thinking of buying this unit for my lab.

2B+D Basic Rate ISDN Simulation with the 2B+D Emulator.

Pls. share experiences? (Good or Bad).

Thanks,

Rashid




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5231&t=5231
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: QOS/Policy routing [7:5227]

2001-05-21 Thread Curtis Call

How about this?:

access-list 100 permit ip any 1.1.1.0 0.0.0.255
priority-list 1 protocol ip high list 100

Then on the interface do a priority-group 1

At 03:32 AM 5/21/01, you wrote:
>Hi folks,
>I like to setup a policy so that any traffic destined to 1.1.1.0/24 will
>take precedence over the rest.  My outbound link is a single T1.  Please
>throw me a short sample config.  Thanks for helping.
>
>-Frank
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5232&t=5227
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: ccie written [7:5225]

2001-05-21 Thread Ronny Jonathan

> Today I passed my CCIE written, score 95%.
> Thanks to the group and to boson test.
> Let's go for the lab
> 
> Stefano Andrello
> CCIE written, CCNA

Wow ! what a score ...
Can you share with us what tips and book you use to prepare for
CCIE written ?

Regards,
Ronny




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5233&t=5225
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



AS-PATH Regular Expression [7:5234]

2001-05-21 Thread Tay Chee Yong

Hi all,

I am suppose to accept the following routes from my peer AS123, which has 
peering with another AS (AS456). I was told to accept the following routes 
from them, but I don't really understand the regular expression. Can anyone 
please help to explain to me the following? And what does the "+" and the 
parenthese means in this AS-PATH.

(_123)+(_456)+

I am confused with the parenthese and the "+" sign. Please advise. Thank you.

Regards,
Cheeyong




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5234&t=5234
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



sybex virtual lab e-trainer [7:5235]

2001-05-21 Thread James, Eric L.

Has anyone used Sybex Virtual Lab E-Trainer for ccna studying? 



Eric James
Network Admin 2
Franklin County Data Center




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5235&t=5235
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: certificate [7:5200]

2001-05-21 Thread Robertson, Douglas

I am not so sure that this " flame " was appropriate, it was a simple
question, if you do not think this subject is for the Cisco groupstudy list
why not just move on to the next mail and forget it. Anyway I didn't see you
flaming the Juniper questions, what do they have to do with the Cisco
Groupstudy list. In fact you are part of the Juniper discussions.

Doug

-Original Message-
From: Drew Simonis [mailto:[EMAIL PROTECTED]]
Sent: Sunday, May 20, 2001 11:38 PM
To: [EMAIL PROTECTED]
Subject: Re: certificate [7:5200]


Jim Bond wrote:
> 
> Hello,
> 
> My client wants to use certificate server to
> authenticate PCs on the network. Is there a way to do
> it? I thought certificate has to be used with browser.
> How do you give PC a certificate?


1. What the hell does this have to do with Cisco, with Cisco 
certifications or with study for Cisco certifications?  Why
on God's green earth would you think that this is the sort of
place for your question?  I'm really curious.

2. Of course you can authenticate users (who log into a PC 
on a network) using certificates.  How do you give a PC a
certificate?  You copy the file on to it.  Viola.  

Check the web, use a search engine, and learn the answers.
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5236&t=5200
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: sybex virtual lab e-trainer [7:5235]

2001-05-21 Thread RCL


--- "James, Eric L." 
wrote:
> Has anyone used Sybex Virtual Lab E-Trainer for ccna
> studying? 
> 
> 
> 
> Eric James
> Network Admin 2
> Franklin County Data Center
> FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to
[EMAIL PROTECTED]


=
= = = = = = = = = = = = = = = = = =
Please send replys to:

[EMAIL PROTECTED]
= = = = = = = = = = = = = = = = = =

__
Do You Yahoo!?
Yahoo! Auctions - buy the things you want at great prices
http://auctions.yahoo.com/




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5237&t=5235
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: passed CIT [7:5228]

2001-05-21 Thread RCL

How do you find "Priscillas flash cards"  


--- George Kadeishvili  wrote:
> A traditional Thank All message
> Just passed CIT, and completed CCNP.
> Priscillas flash cards are great. But the exam
> itself sucks. Routing was
> by far the best one in CCNP track.
> Now have to start thinking about CCIE writen.
> Regards
> George
> FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to
[EMAIL PROTECTED]


=
= = = = = = = = = = = = = = = = = =
Please send replys to:

[EMAIL PROTECTED]
= = = = = = = = = = = = = = = = = =

__
Do You Yahoo!?
Yahoo! Auctions - buy the things you want at great prices
http://auctions.yahoo.com/




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5238&t=5228
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: AS-PATH Regular Expression [7:5234]

2001-05-21 Thread ElephantChild

On Mon, 21 May 2001, Tay Chee Yong wrote:

> Hi all,
> 
> I am suppose to accept the following routes from my peer AS123, which has 
> peering with another AS (AS456). I was told to accept the following routes 
> from them, but I don't really understand the regular expression. Can
anyone
> please help to explain to me the following? And what does the "+" and the 
> parenthese means in this AS-PATH.
> 
> (_123)+(_456)+
> 
> I am confused with the parenthese and the "+" sign. Please advise. Thank
you.

*browsebrowsebrowse*
http://www.cisco.com/univercd/cc/td/doc/product/software/ios113ed/113ed_cr/
np1_r/1rbgp.htm#xtocid2382618
[...]
   as-regular-expression
 
   Autonomous system in the access list using a regular expression. See
   the "Regular Expressions" appendix in the Dial Solutions Command
   Reference for information about forming regular expressions.

-- 
"Someone approached me and asked me to teach a javascript course. I was
about to decline, saying that my complete ignorance of the subject made
me unsuitable, then I thought again, that maybe it doesn't, as driving
people away from it is a desirable outcome." --Me




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5239&t=5234
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Examine: Doyle's protocol analyser [7:5241]

2001-05-21 Thread Deloso, Elmer G (WPNSTA Yorktown)

Hi, all.
Does anybody know the name of the company that wrote the "Examine" protocol
analyser featured in Jeff Doyle's Routing TCP/IP Vol.1?
Thanks.

Elmer




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5241&t=5241
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: sybex virtual lab e-trainer [7:5235]

2001-05-21 Thread Waters, Kris - TS/Corporate

I used it. Personally, I didn't think it was worth the $100 price tag. Boson
has one that's only $30 I think.

Kris.

-Original Message-
From: RCL [mailto:[EMAIL PROTECTED]]
Sent: Monday, May 21, 2001 8:43 AM
To: [EMAIL PROTECTED]
Subject: Re: sybex virtual lab e-trainer [7:5235]



--- "James, Eric L." 
wrote:
> Has anyone used Sybex Virtual Lab E-Trainer for ccna
> studying? 
> 
> 
> 
> Eric James
> Network Admin 2
> Franklin County Data Center
> FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to
[EMAIL PROTECTED]


=
= = = = = = = = = = = = = = = = = =
Please send replys to:

[EMAIL PROTECTED]
= = = = = = = = = = = = = = = = = =

__
Do You Yahoo!?
Yahoo! Auctions - buy the things you want at great prices
http://auctions.yahoo.com/
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5240&t=5235
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



OSPF - Do Not Age LSA [7:5242]

2001-05-21 Thread Paulo Roque

Hi All,

In the following situation, where sholud I see the "DoNotAge LSA"

a- only in router R2
b- only in router R1
c- in R2 and R3
d- in all router.

Please, explain your answer

Router R2 is configured with "ip ospf demand-circuit"

   area 0
x---
|
x--
|   R1   |  ABR area 6
x--
|
|
[PTSN]
|
|
x- -x--
|   R2   ||   R3|
x- -x--
||
x---x
 area 25







--
Eng. Paulo Roque
Network Engineer
[EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5242&t=5242
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: 1605 56k csu dsu to 1602 CSU DSU [7:5091]

2001-05-21 Thread Donald B Johnson jr

You can also use a single jack as a loop to bring the interface up. You just
need two copper wires and a jack. Make sure wire 1 goes from pin1 to pin 8
in the jack and wire two goes from pin 2 to pin 7 in the jack. Plug the jack
in and you should get an up up status.
This is good for lab if you want to add another network and then advertise
it say over the ethernet interface for any routing protocol. Just remove the
plug and the interface goes down, hence the network goes down,  get for
debug and troubleshooting.
Don



- Original Message -
From: "Brian Dennis" 
To: 
Sent: Friday, May 18, 2001 11:43 PM
Subject: RE: 1605 56k csu dsu to 1602 CSU DSU [7:5091]


> www.cisco.com/warp/public/471/75.html
>
>
> Brian Dennis, CCIE #2210 (R&S)(ISP/Dial) CCSI #98640
> 5G Networks, Inc.
> [EMAIL PROTECTED]
> (925) 260-2724
>
> > -Original Message-
> > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of
> > Randy Espiritu
> > Sent: Friday, May 18, 2001 10:52 PM
> > To: [EMAIL PROTECTED]
> > Subject: 1605 56k csu dsu to 1602 CSU DSU [7:5091]
> >
> >
> > Hi All
> >
> > Anyone know how to configure 2 1600 series router connecting both
> > WIC-1DSU-56K from each router using cross over cable
> >
> > thanks all in advance
> > FAQ, list archives, and subscription info:
> > http://www.groupstudy.com/list/cisco.html
> > Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5243&t=5091
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: CCIE Written [7:5188]

2001-05-21 Thread Charles Manafa

...also add Boson prep tests in your shopping list (they are "must have")

CM

> -Original Message-
> From: EA Louie [mailto:[EMAIL PROTECTED]]
> Sent: 21 May 2001 05:17
> To: [EMAIL PROTECTED]
> Subject: Re: CCIE Written [7:5188]
> 
> 
> Gary - in a word, Tons.
> 
> Start with the Blueprint
> http://www.cisco.com/warp/public/625/ccie/certifications/rsblu
> eprint.html
> and assess yourself with the subjects (I have a 
> self-assessment spreadsheet
> that you're welcome to have on request)
> 
> Then, look at their Recommended Reading list
> http://www.cisco.com/warp/public/625/ccie/certifications/routi
ng.html#34

Towards the bottom of the list, there are LOTS of links to Cisco-generated
documents that you can have for free (well, for the cost of bits on a disk,
or sheets of 8-1/2 x 11 paper)

Finally, when you feel you have the subject matter pretty well handled,
there's a great book that my one of my study partners has loaned me
CCIE Prep Kit CCIE 350-001 Routing and Switching, published by Que ISBN
0-7897-2359-x

which will ice the cake for you.  If you have lots of experience, your
reading will probably be more on the theoretical side.  If you have little
or no experience, you'll need some of the background information that's
provided in the Cisco docs.

hth...   -e-

- Original Message -
From: "Gary Hughes" 
To: 
Sent: Sunday, May 20, 2001 11:28 AM
Subject: CCIE Written [7:5188]


> Any good books or study material recommended for the CCIE Written
test?
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5244&t=5188
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



my head hurts! (Terminal server) [7:5245]

2001-05-21 Thread George Dodds

Can someone explain how the following excerpt from a
menu on a 2511 being used as a terminal server works!
  
I know that traffic is being passed through e0 using
the specified port, but i need to know how the hell it
manages to get to the specified switches.   

menu CONNECT text 1 Cisco 2912 LAN Switch #3
menu CONNECT command 1 telnet 10.1.1.12 2001
menu CONNECT text 2 Cisco 2912 LAN Switch #4
menu CONNECT command 2 telnet 10.1.1.12 2002


interface Ethernet0
 ip address 10.1.1.12 255.255.255.0
 no ip redirects
 no ip directed-broadcast
 no ip proxy-arp
 no cdp enable

Thanks in advance from one of the ignorant masses!!



=
George Dodds

CCNA, MCP

__
Do You Yahoo!?
Yahoo! Auctions - buy the things you want at great prices
http://auctions.yahoo.com/




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5245&t=5245
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Cable Multiservice Operators [7:5246]

2001-05-21 Thread Alec Smiths

Hi group,

I need to speak with a networker who has cable
operator experience. My company (ISP) will become a
partner with a CATV operator and will begin to give
data services over CATV network. But I have some
questions to discuss with group members who are
experienced about  this type of network. please reply
if you have something to say about Cable Multiservice
Operations.

Cheers,

Alec

__
Do You Yahoo!?
Yahoo! Auctions - buy the things you want at great prices
http://auctions.yahoo.com/




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5246&t=5246
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



PIX question... [7:5248]

2001-05-21 Thread Rizzo Damian

Hey all, is it possible to translate public IP addresses (outside) to
private IP addresses (inside) on a PIX firewall. Basically the exact
opposite of what's usually performed on a firewall. We are going to have
users dial in to our internet router and receive a Public IP address. They
have to get through our firewall to gain access to our LAN. Is there a way
to translate the Public IP address they will obtain into a private IP
address used by our LAN so they can access it?  I thank you for your help...
 
 
  -Rizzo




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5248&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: QOS/Policy routing [7:5227]

2001-05-21 Thread Vincent Chong

Hi;

Policy Routing sample

interface serial 0
ip address x.w.y.z /netmask
ip policy route-map frank
!
access-list 101 permit ip any 1.1.1.0 0.0.0.25
!
route-map frank permt 10
match ip address 101
set ip precedence critical
!

Prority Queue is another option.

HTH
Vincent Chong


""Frank Kim""   Hi folks,
> I like to setup a policy so that any traffic destined to 1.1.1.0/24 will
> take precedence over the rest.  My outbound link is a single T1.  Please
> throw me a short sample config.  Thanks for helping.
>
> -Frank
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5250&t=5227
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



IEEE 802 Standards for free [7:5249]

2001-05-21 Thread Oleg Mazurov

-- quote

No Charge to View IEEE 802 Standards

The IEEE Standards Association (IEEE-SA) has announced a pilot program
that
grants public access to view and download individual electronic (PDF)
IEEE
Local and Metropolitan Area Network (802) standards at no charge. New
IEEE
802 standards will be added to the "Get IEEE 802" program, in PDF
format,
six months after publication. For more information, please visit
http://standards.ieee.org/announcements/getieee802.html

-- quote




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5249&t=5249
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: AS-PATH Regular Expression [7:5234]

2001-05-21 Thread ElephantChild

On Mon, 21 May 2001, ElephantChild wrote:

> On Mon, 21 May 2001, Tay Chee Yong wrote:
> 
> > Hi all,
> > 
> > I am suppose to accept the following routes from my peer AS123, which
has
> > peering with another AS (AS456). I was told to accept the following
routes
> > from them, but I don't really understand the regular expression. Can
anyone
> > please help to explain to me the following? And what does the "+" and
the
> > parenthese means in this AS-PATH.
> > 
> > (_123)+(_456)+
> > 
> > I am confused with the parenthese and the "+" sign. Please advise. Thank
you.
> 
> *browsebrowsebrowse*
> http://www.cisco.com/univercd/cc/td/doc/product/software/ios113ed/113ed_cr/
> np1_r/1rbgp.htm#xtocid2382618

(rest snipped)

Sorry, folks, incomplete answer. I meant to add the URL for the actual
syntax description, then decided as I read it that it was a bit obscure 
as an introduction to regular expressions. Anyway, here's my FMTYWTK
answer:

_ matches any character that separates individual ASNs in an AS path,
including the start or end of the AS path. So _123 ensures that the 123
in the regular expression won't match say, AS 4123. It could, however,
match AS 1234 if used by itself, but the rest of the expression will
take care of that.

+ matches at least one occurence, and perhaps more than one, of the
preceding character or sub-expression between (). So if your peer
indulges in AS path prepending, (_123)+ will take care of that by
matching 123 123 or 123 123 123 12345 as well as a single 123 or 1234.
The rest of the regular expression, and specifically the _ that starts
(_456)+, takes care of that, since it doesn't match the 4 in 1234 or
12345, but only the separator after the 3 of the final 123.

Now that I dissected your regular expression, I will say that IMHO, it's
more complex than what you need, and may still not do what you want in
some cases. Depending on what you want, you may use one of the
following:

- To match any AS path that contains ASNs 123 and 456 in that order, and
  may contain any other ASN either before or after, but not between, use
  _123_456_ (Note that this would still match 123 789 456 123 456, but
  that path has a loop in it, and if your peer will feed you that kind
  of paths, you have more serious trouble than just an unwanted 789.)

- To match any AS path that starts with one or more occurences of ASN
  123, followed with one (at least) occurence of 456, possibly followed
  by other ASNs, use ^(123_)+456_

- To match any AS path that starts with one or more occurences of ASN
  123, possibly followed by one or more occurences of ASN 456, but
  contains no other ASN, use ^(123_)+(456_)*$

-- 
"Someone approached me and asked me to teach a javascript course. I was
about to decline, saying that my complete ignorance of the subject made
me unsuitable, then I thought again, that maybe it doesn't, as driving
people away from it is a desirable outcome." --Me




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5251&t=5234
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Stop the Flaming [7:5252]

2001-05-21 Thread ccnawan

I know I am going to get flamed by the negative people on this list. When I
joined on this list it was for the study of certification. Whenever anyone
asks a question related to certification, they get flamed. There is nothing
wrong with asking a question, there are no stupid questions.What is wrong
with helping someone starting out? Nothing (People should check the archives
first.) When a company hires someone it is more for how they get along than
there certs.
If you don't like what someone says either delete the message or mind you
own business.

Dan Evensen CCNAWS CNS




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5252&t=5252
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: PIX question... [7:5248]

2001-05-21 Thread Richard Tufaro

Scary, use VPN

>>> "Rizzo Damian"  05/21 10:15 AM >>>
Hey all, is it possible to translate public IP addresses (outside) to
private IP addresses (inside) on a PIX firewall. Basically the exact
opposite of what's usually performed on a firewall. We are going to have
users dial in to our internet router and receive a Public IP address. They
have to get through our firewall to gain access to our LAN. Is there a way
to translate the Public IP address they will obtain into a private IP
address used by our LAN so they can access it?  I thank you for your help...
 
 
  -Rizzo
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5254&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: b**** tests [7:5194]

2001-05-21 Thread [EMAIL PROTECTED]

On Sun, 20 May 2001, John Andrews wrote:

> First of all:
>
> I worded the subject space that way because I was unsure if the word B
> is
> banned here or not, so that was to be on the safe side so this would go
> through to the group.
>
> My question:
>
> Are the above tests for switching close to the exam type questions that
> appear
> on the prometric. I have both switching exams and have been using them for
> practice examinations.

If the name you're thinking of is the same as that of the class of
elementary pbrticles that follow the Bose-Einstein statistics, as
opposed to say, a female representative of species Canis domesticus or
(according to some) Homo sapiens, you can use it here. Boson. Boson.
Boson boson bosonbosonboson. See? :-) And it's been abundantly discussed
on this here fine list, so hitting the archives is probably your best
bet.

--
"Someone approached me and asked me to teach a javascript course. I was
about to decline, saying that my complete ignorance of the subject made
me unsuitable, then I thought again, that maybe it doesn't, as driving
people away from it is a desirable outcome." --Me
FAQ, list archives, and subscription info: 
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5253&t=5194
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: Passed BCMSN [7:4546]

2001-05-21 Thread McClendon Susan Contr AEDC/ACS

John, Kevin and Group,
I know most on this list agree..
What difference does it make if we start from books & go to
experience, or start with experience and go to books?  The main point is we
know where we want to go, and either way we'll get there. 
Does anyone on list know the story of blue crabs in a bucket? No
matter how many crabs try to escape, they always get pulled back down by a
crab below them.  No crab ever gets away, and no lid is ever used. So if
somebody finds fault with your path, your way, remember those blue crabs.
They're really yummy.

live well, smile lots, 
- susan
lab scheduled for Jan. 10/11, 2002 RTC




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5255&t=4546
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: b**** tests [7:5194]

2001-05-21 Thread [EMAIL PROTECTED]

On Sun, 20 May 2001, John Andrews wrote:

> First of all:
>
> I worded the subject space that way because I was unsure if the word B
> is
> banned here or not, so that was to be on the safe side so this would go
> through to the group.
>
> My question:
>
> Are the above tests for switching close to the exam type questions that
> appear
> on the prometric. I have both switching exams and have been using them for
> practice examinations.

If the name you're thinking of is the same as that of the class of
elementary pbrticles that follow the Bose-Einstein statistics, as
opposed to say, a female representative of species Canis domesticus or
(according to some) Homo sapiens, you can use it here. Boson. Boson.
Boson boson bosonbosonboson. See? :-) And it's been abundantly discussed
on this here fine list, so hitting the archives is probably your best
bet.

--
"Someone approached me and asked me to teach a javascript course. I was
about to decline, saying that my complete ignorance of the subject made
me unsuitable, then I thought again, that maybe it doesn't, as driving
people away from it is a desirable outcome." --Me
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info: 
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5256&t=5194
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: share ethernet [7:5223]

2001-05-21 Thread Tony Medeiros

Use a routing protocol or static routes.  The default router for the server
will send an ICMP redirect to the server for any networks reachable by the
other router.

Or, set the servers defualt gateway to it's self and let proxy arp do the
router selection.

Tony M.
#6172

- Original Message -
From: md. nazri 
To: 
Sent: Monday, May 21, 2001 1:53 AM
Subject: share ethernet [7:5223]


> hi all,
> i got 2 routers sharing the same ethernet...both ether should active at
the
> same time(so i think hsrp not meaningful) with each ether have different
ip
> address with same subnet. Server on LAN should point to one particular
> ip(can it be two..?)...how do i achieve that...??  pls help
>
> tq
>
> rgds
> nazri
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5257&t=5223
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Stop the Flaming [7:5252]

2001-05-21 Thread Howard C. Berkowitz

>I know I am going to get flamed by the negative people on this list. When I
>joined on this list it was for the study of certification. Whenever anyone
>asks a question related to certification, they get flamed.

Dan, I take your post in a positive sense.  Nevertheless, there are 
certain things I do regard as inappropriate, although I generally 
don't join in the flame war, or occasionally try to deflect it with a 
bit of humor.  When it comes to flaming, I've rarely if ever done it 
here. When I was writing one of my books and made a comment about 
lawyers, the editor quibbled that it might be insulting to lawyers. 
My response was that if it wasn't clear that it was insulting, I'd 
make every effort to make the insult unambiguous.

Let me talk about _my personal_ reaction to certain kinds of questions.

1.  "How many questions" and the like -- not really harmful, but I'm puzzled
 what anyone can do with the information. Especially if the test format
 is such that you can't go back (and that _is_ valuable information),
 what can you do other than keep answering questions until you run out
 of time?

2.  Questions directly posted from some review source, with NO discussion of
 what the poster thinks might be the right answer, or why, perhaps, all
 the possible answers are incorrect.  I'm glad to help people work out
 the nuances of specific answers, but I expect to see that they've tried
 first. Otherwise, I get a sense that they are just trying to memorize
 without understanding.

 There also may be copyright issues in directly posting questions.

 As something of a personal note, which I suspect would be echoed by
 most firms that write review materials, if there's a problem with one
 of our questions, it's often more productive to send a query to customer
 service than just posting the question to the list.  Believe me, at
 CertZone, such queries are taken seriously, and usually go to the actual
 author of the question.  I know that there have been times when I
received
 such a query on one of my questions, looked at it, and realized I made
 a typo or logic error.  We promptly let people know about the
correction.
 The question author is in the best position to know what he or she
meant.

 That isn't to say that the review sites should be in the business of
 explaining more detail about a question that is verified correct.  On
 a commercial basis, that would be tutoring. I know I will suggest, on
 occasion, that the person asking direct the discussion to the list.

3.  Closely related to the commercially questionable explanation are the
 posts beginning "my client wants to..."  My immediate reaction is that
 I am usually paid to answer commercial questions.  Of course, my
greatest
 annoyance is when I get this in private mail from someone I don't know.

 That isn't to say that a real-world problem can't be discussed on the
 list as a way of gaining insight. You'll probably notice that I respond
 to quite a few BGP routing policy situations. I do this for several
 reasons.  One, it fits in with my general IETF/NANOG/etc. teaching
 role and role in avoiding Internet problems, and second, these often
 wind up in case studies in my books.

4.  Another problem area is apparent buggy behavior in a Cisco product,
 to which my immediate reaction is "what does the TAC say?"  If the
 TAC has been consulted but didn't give a good answer, the problem
 should be escalated in Cisco -- indeed, how to do so is part of the
 CIT exam.  I can understand asking for bug support for a personal lab,
 but frankly, I would say that anyone without a massive internal support
 infrastructure is crazy not to have at least basic SmartNet.

>There is nothing
>wrong with asking a question, there are no stupid questions.What is wrong
>with helping someone starting out? Nothing (People should check the archives
>first.)


And yes, checking the archives and CCO should be a given. 

>When a company hires someone it is more for how they get along than
>there certs.
>If you don't like what someone says either delete the message or mind you
>own business.
>
>Dan Evensen CCNAWS CNS




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5258&t=5252
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Weird trace results [7:5259]

2001-05-21 Thread Watson, Rick, CTR, OUSDC

All,

When performing a trace on an IP address (for "testing purposes we'll use
10.1.2.3) this is the result I get:

router#trace 10.1.2.3

Type escape sequence to abort.
Tracing the route to 10.1.2.3

  1 192.1.2.2 4 msec
192.1.2.10 4 msec
192.1.2.2 4 msec
  2 10.1.2.3 0 msec 4 msec 4 msec
  3  *  *  * 
  4  *  *  * 
  5  *  *  * 
  6  *  *  * 

This to me shows that I am still trying to find a path to the IP
address...but if the IP Address is returned at the 2nd hop, why is the trace
still continuing? I thought that it would stop when the trace has the
"path". Also note that when a "ping" is performed it returns the infamous
"."

This has really got me perplexed, and any help would be greatly appreciated.
Maybe I am just not understanding something about the trace command/ICMP.

Rick Watson
Network Engineer
Advanced Systems Development, Inc.
OUSD(Comptroller)
703.697.5710 office
800.309.7782 pager ([EMAIL PROTECTED])
[EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5259&t=5259
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: PIX question... [7:5248]

2001-05-21 Thread Craig Columbus

Sounds like a VPN is your best bet.
Should you decide to implement the VPN, you may want to consider whether 
you still need to maintain the modem pool on the Internet router.  Reducing 
this cost could help justify the cost of implementing a VPN solution.  A 
properly authenticated VPN user should be able to use any dial-up Internet 
connection to reach your LAN.

Craig

At 10:15 AM 5/21/2001 -0400, you wrote:
>Hey all, is it possible to translate public IP addresses (outside) to
>private IP addresses (inside) on a PIX firewall. Basically the exact
>opposite of what's usually performed on a firewall. We are going to have
>users dial in to our internet router and receive a Public IP address. They
>have to get through our firewall to gain access to our LAN. Is there a way
>to translate the Public IP address they will obtain into a private IP
>address used by our LAN so they can access it?  I thank you for your help...
>
>
>   -Rizzo
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5260&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Weird trace results [7:5259]

2001-05-21 Thread Vincent Chong

I suggest that you check your routing table, that's what come out my mind.

HTH
Vincent Chong

""Watson, Rick, CTR, OUSDC""   All,
>
> When performing a trace on an IP address (for "testing purposes we'll use
> 10.1.2.3) this is the result I get:
>
> router#trace 10.1.2.3
>
> Type escape sequence to abort.
> Tracing the route to 10.1.2.3
>
>   1 192.1.2.2 4 msec
> 192.1.2.10 4 msec
> 192.1.2.2 4 msec
>   2 10.1.2.3 0 msec 4 msec 4 msec
>   3  *  *  *
>   4  *  *  *
>   5  *  *  *
>   6  *  *  *
>
> This to me shows that I am still trying to find a path to the IP
> address...but if the IP Address is returned at the 2nd hop, why is the
trace
> still continuing? I thought that it would stop when the trace has the
> "path". Also note that when a "ping" is performed it returns the infamous
> "."
>
> This has really got me perplexed, and any help would be greatly
appreciated.
> Maybe I am just not understanding something about the trace command/ICMP.
>
> Rick Watson
> Network Engineer
> Advanced Systems Development, Inc.
> OUSD(Comptroller)
> 703.697.5710 office
> 800.309.7782 pager ([EMAIL PROTECTED])
> [EMAIL PROTECTED]
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5261&t=5259
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: Passed BCMSN [7:4546]

2001-05-21 Thread Howard C. Berkowitz

>John, Kevin and Group,
>   I know most on this list agree..
>   What difference does it make if we start from books & go to
>experience, or start with experience and go to books?  The main point is we
>know where we want to go, and either way we'll get there.

Valid observation. It's a constant circle. Part of my job involves 
designing routers and protocol implementation, so I can't have had 
experience on something that doesn't yet exist.  A deep knowledge of 
real theory -- in the computer science sense, not just message 
formats and the like -- is what I have to fall back on.

But experience is a factor.  When I started working with the 
Stratacom/Cisco switches, I wasn't dependent only on the courseware 
-- I knew what the things were supposed to do, so I started looking 
for features and commands I knew had to be there.

>   Does anyone on list know the story of blue crabs in a bucket? No
>matter how many crabs try to escape, they always get pulled back down by a
>crab below them.  No crab ever gets away, and no lid is ever used. So if
>somebody finds fault with your path, your way, remember those blue crabs.
>They're really yummy.


I have to share one vaguely on-topic story from my days teaching with 
Geotrain.  Training partners have lots of work to do shipping around 
the portable labs, and they often have a couple of freight 
specialists on staff. It's especially bad if the equipment has 
traveled internationally.  We had our freight person go to 
Baltimore-Washington Airport, in the Delta air freight area, to help 
get our equipment out of Customs during a Customs crackdown.

Apparently, there was one shipment ahead of ours in the inspector's 
queue:  a shipment of live crabs. They were in what essentially was a 
cage -- a series of pans with chicken wire around them.  Not 
satisfied with poking through the wire, the inspector insisted on 
having a cage opened.

For whatever reason, loosening a particular wire caused an entire 
stack of cages to fall apart.  The standard crab protocol of pulling 
back escapers doesn't apply when all of the crabs are on the floor.

Crabs to the left of them. Crabs to the right of them. Crabs running 
away. Crabs running at the inspectors, the air freight staff, our 
freight specialist, etc.  Customs inspector losing it completely and 
screaming "STOP THEM! THEY MIGHT BE CARRYING DRUGS!"

The warehouse smelled of crabs for several weeks, and it did take a 
while to air out that particular portable lab...its aroma led to some 
strange student reviews.

>
>live well, smile lots,
>- susan
>lab scheduled for Jan. 10/11, 2002 RTC




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5262&t=4546
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: b**** tests [7:5194]

2001-05-21 Thread Howard C. Berkowitz

>On Sun, 20 May 2001, John Andrews wrote:
>
>>  First of all:
>>
>>  I worded the subject space that way because I was unsure if the word
B
>>  is
>>  banned here or not, so that was to be on the safe side so this would go
>>  through to the group.
>>
>>  My question:
>>
>>  Are the above tests for switching close to the exam type questions that
>>  appear
>>  on the prometric. I have both switching exams and have been using them
for
>>  practice examinations.
>
>If the name you're thinking of is the same as that of the class of
>elementary pbrticles that follow the Bose-Einstein statistics, as
>opposed to say, a female representative of species Canis domesticus or
>(according to some) Homo sapiens, you can use it here. Boson. Boson.
>Boson boson bosonbosonboson. See? :-) And it's been abundantly discussed
>on this here fine list, so hitting the archives is probably your best
>bet.
>

Somehow, you remind me that the answer to the CID beta delay may be 
that the test designer is Schrodinger's Cat.  Test takers were in a 
state of either having passed or not passed, but the state could not 
be known without opening the box.

(Reminding my cat that this is only theoretical and that he should not worry.)




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5263&t=5194
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



New CCNP [7:5264]

2001-05-21 Thread John Pusledzki

Just a big thank you all... passed CIT today with an 890. Be careful who you 
believe, I thought this exam was the hardest out of the four ?!!! Guess it 
just comes down to how lucky you are with the question database. I had 
very little ISDN and lots and lots of VTP/ISL questions

On to Checkpoint and CCIE Written now..
_
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5264&t=5264
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: PIX question... [7:5248]

2001-05-21 Thread Rizzo Damian

We are aware of the VPN solution and that is our long term goal. However,
for the moment, all I need to know is if it is possible to NAT from an
outside (not trusted) interface to an inside (trusted) interface.

 Thank you!

  -Rizzo




-Original Message-
From: Craig Columbus [mailto:[EMAIL PROTECTED]] 
Sent: Monday, May 21, 2001 11:44 AM
To: Rizzo Damian
Cc: [EMAIL PROTECTED]
Subject: Re: PIX question... [7:5248]

Sounds like a VPN is your best bet.
Should you decide to implement the VPN, you may want to consider whether 
you still need to maintain the modem pool on the Internet router.  Reducing 
this cost could help justify the cost of implementing a VPN solution.  A 
properly authenticated VPN user should be able to use any dial-up Internet 
connection to reach your LAN.

Craig

At 10:15 AM 5/21/2001 -0400, you wrote:
>Hey all, is it possible to translate public IP addresses (outside) to
>private IP addresses (inside) on a PIX firewall. Basically the exact
>opposite of what's usually performed on a firewall. We are going to have
>users dial in to our internet router and receive a Public IP address. They
>have to get through our firewall to gain access to our LAN. Is there a way
>to translate the Public IP address they will obtain into a private IP
>address used by our LAN so they can access it?  I thank you for your
help...
>
>
>   -Rizzo
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5265&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: single or mutlimode? [7:5224]

2001-05-21 Thread Daniel Cotts

The closest is "show atm int atm x/0" - where x is the slot number.
If you're referring to the CX-AIP card there is no command that shows. You
have to physically inspect the card. A single mode card has ST connectors
and a laser warning label. A multimode has SC connectors.
The part numbers get interesting. A single mode is a CX-AIP-SS and a
multimode is a CX-AIP-SM. The first "S" stands for SONET. So far, so good.
However the singlemode card has UNI-155SM printed on its front. I don't have
a multimode handy to view. Hopefully it says UNI-155MM.

> -Original Message-
> From: Andy Low [mailto:[EMAIL PROTECTED]]
> Sent: Monday, May 21, 2001 3:57 AM
> To: [EMAIL PROTECTED]
> Subject: single or mutlimode? [7:5224]
> 
> 
> Hi,
> 
> May I know what is the command to check where the ATM 
> interface card is
> multi-mode or single-mode?
> 
> Thanks,
> 
> Andy
> FAQ, list archives, and subscription info: 
> http://www.groupstudy.com/list/cisco.html
> Report misconduct 
> and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5266&t=5224
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Weird trace results [7:5259]

2001-05-21 Thread Darren Crawford

I've seen this before in networks using HSRP and no route caching.  Is it
causing a problem or just interesting?

Darren

At 11:59 AM 05/21/2001 -0400, Vincent Chong wrote:
>I suggest that you check your routing table, that's what come out my mind.
>
>HTH
>Vincent Chong
>
>""Watson, Rick, CTR, OUSDC""   All,
>>
>> When performing a trace on an IP address (for "testing purposes we'll use
>> 10.1.2.3) this is the result I get:
>>
>> router#trace 10.1.2.3
>>
>> Type escape sequence to abort.
>> Tracing the route to 10.1.2.3
>>
>>   1 192.1.2.2 4 msec
>> 192.1.2.10 4 msec
>> 192.1.2.2 4 msec
>>   2 10.1.2.3 0 msec 4 msec 4 msec
>>   3  *  *  *
>>   4  *  *  *
>>   5  *  *  *
>>   6  *  *  *
>>
>> This to me shows that I am still trying to find a path to the IP
>> address...but if the IP Address is returned at the 2nd hop, why is the
>trace
>> still continuing? I thought that it would stop when the trace has the
>> "path". Also note that when a "ping" is performed it returns the infamous
>> "."
>>
>> This has really got me perplexed, and any help would be greatly
>appreciated.
>> Maybe I am just not understanding something about the trace command/ICMP.
>>
>> Rick Watson
>> Network Engineer
>> Advanced Systems Development, Inc.
>> OUSD(Comptroller)
>> 703.697.5710 office
>> 800.309.7782 pager ([EMAIL PROTECTED])
>> [EMAIL PROTECTED]
>> FAQ, list archives, and subscription info:
>http://www.groupstudy.com/list/cisco.html
>> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



***
Darren S. Crawford
Lucent Technologies Worldwide Services 
2377 Gold Meadow WayPhone: (916) 859-5200 x310 
Suite 230   Fax: (916) 859-5201 
Sacramento, CA 95670Pager: (800) 467-1467 
Email: [EMAIL PROTECTED] Epager: [EMAIL PROTECTED] 
http://www.lucent.com   Network Systems
Consultant - CCNA, CCIE Written

"Providing the Power Operable Networks."


***
"Ham and Eggs - A day's work for a chicken; A lifetime commitment
for a
pig."




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5267&t=5259
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: PIX question... [7:5248]

2001-05-21 Thread Patrick Bass

Yeah.  It's called static NAT.  And then you create an access-list to open
services to that host.

""Rizzo Damian""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> We are aware of the VPN solution and that is our long term goal. However,
> for the moment, all I need to know is if it is possible to NAT from an
> outside (not trusted) interface to an inside (trusted) interface.
>
>  Thank you!
>
>   -Rizzo
>
>
>
>
> -Original Message-
> From: Craig Columbus [mailto:[EMAIL PROTECTED]]
> Sent: Monday, May 21, 2001 11:44 AM
> To: Rizzo Damian
> Cc: [EMAIL PROTECTED]
> Subject: Re: PIX question... [7:5248]
>
> Sounds like a VPN is your best bet.
> Should you decide to implement the VPN, you may want to consider whether
> you still need to maintain the modem pool on the Internet router.
Reducing
> this cost could help justify the cost of implementing a VPN solution.  A
> properly authenticated VPN user should be able to use any dial-up Internet
> connection to reach your LAN.
>
> Craig
>
> At 10:15 AM 5/21/2001 -0400, you wrote:
> >Hey all, is it possible to translate public IP addresses (outside) to
> >private IP addresses (inside) on a PIX firewall. Basically the exact
> >opposite of what's usually performed on a firewall. We are going to have
> >users dial in to our internet router and receive a Public IP address.
They
> >have to get through our firewall to gain access to our LAN. Is there a
way
> >to translate the Public IP address they will obtain into a private IP
> >address used by our LAN so they can access it?  I thank you for your
> help...
> >
> >
> >   -Rizzo
> >FAQ, list archives, and subscription info:
> >http://www.groupstudy.com/list/cisco.html
> >Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5268&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: IEEE 802 Standards for free [7:5249]

2001-05-21 Thread Donald B Johnson jr

Awesome
Already on my hard-disk.
Thank You,

Don Johnson


- Original Message -
From: "Oleg Mazurov" 
To: 
Sent: Monday, May 21, 2001 7:27 AM
Subject: IEEE 802 Standards for free [7:5249]


> -- quote
>
> No Charge to View IEEE 802 Standards
>
> The IEEE Standards Association (IEEE-SA) has announced a pilot program
> that
> grants public access to view and download individual electronic (PDF)
> IEEE
> Local and Metropolitan Area Network (802) standards at no charge. New
> IEEE
> 802 standards will be added to the "Get IEEE 802" program, in PDF
> format,
> six months after publication. For more information, please visit
> http://standards.ieee.org/announcements/getieee802.html
>
> -- quote
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5269&t=5249
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



unsubscribe cisco [7:5270]

2001-05-21 Thread Robert Sullivan

unsubscribe cisco




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5270&t=5270
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



"network logon problems" [7:5271]

2001-05-21 Thread Robert Perez

HELP!!
I have an issue where it appears that multiple users cannot login.  I
receive the error "you will be logged on using a cached account" and once
logged on, all network devices are available.  I have ensured that on the
catalyst 3548XL, all ports have Port fast enabled and I have also enabled
STP to try and overcome the problem with no success.  I have also moved the
users to switches that have no issues and I still have the same problem.  I
also did a ipconfig /release renew and replaced the nic card and did a cold
boot and warm boot on the machines with no success.  All other user are fine
and it is only affecting like 3 people.  I even set them to auto, auto and
the switch to auto,auto and this did not work either.  I then tried 100 full
and half and that did not work either.  I also do not have port security
enabled.  It appears to be a network issue with the catalystr switches, but
I am unsure as to the root of the problem.Don't know if this would do
anything, but I did a NBTSTAT -RR from the command line as well.  Any help
would be greatly appreciated.Thank you.




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5271&t=5271
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Help its very very urgent ..isl trunking [7:5272]

2001-05-21 Thread Arun

Hi
I am facing problem in setting the isl trunk between 29900xL series switch
and 7100 series router .The configuration is like i am using fast ethernet
port 0/16 of switch for trunk .
i configure it using commands as below for the switch  i do..

conf t
int vlan 1
ip adress 192.168.3.215 255.255.255.0
ip default-gateway 192.168.3.210

conf ter
int fast eth0/16
switchport mode trunk
switchport trunk encapsulation isl(right )
swicthport trunk allowed vlan all
conf ter
int fast0/15
switchport access vlan 2
spannig portfast
exit
also i did like
vlan database
vtp server
vlan 2

now for the router
conf t
int fast0/0
no shutdown
exit
int fast0/0.1
encap isl 1
ip add 192.168 .3.210 255.255.255.0
exit
int fast0/0.2
encap isl 2
ip add 192.168 .4.210 255.255.255.0
exit


now the problem is i am not able to ping from router to interface
192.168.3.210 ..am i doing something wrong ..also after this if i do
show cdp neigh the router see the switch but if i do it on switch it doesn't
see the router ..please help .
where i am doing wrong ..Please help
Thanx in advance


Regards
Arun Sharma




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5272&t=5272
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: ISL using 11.2????? [7:5273]

2001-05-21 Thread Arun

Yes i think u need to upgrade to 11.8

""Jeff""  wrote in message
9aricg$6i0$[EMAIL PROTECTED]">news:9aricg$6i0$[EMAIL PROTECTED]...
> I am using a 4500 with a Fast Ethernet interface and would like to be able
> to route between VLANs that are setup on my 2900. I don't have the option
to
> use encapsulation ISL using Ver 11.2 on the 4500. Do I have to upgrade to
> 11.3 or something higher to be able to use ISL?
>
> Thanks!




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5273&t=5273
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: PIX question... [7:5248]

2001-05-21 Thread Craig Columbus

I'm not clear on what you're asking.  Are you asking if the PIX can take a 
public IP and make it appear as a private IP on the internal network?  The 
answer is yes, although you certainly want to be careful with this and I 
can't say that this is a recommended config.  You'll need a config similar 
to the one below:

nat (outside)  1 0 0
static (inside,outside)  
 netmask 255.255.255.255
access-list  permit ip any host 

For more info, reference 
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v52/config/examples.htm#xtocid274896

Thanks,
Craig

At 12:14 PM 5/21/2001 -0400, you wrote:
>We are aware of the VPN solution and that is our long term goal. However,
>for the moment, all I need to know is if it is possible to NAT from an
>outside (not trusted) interface to an inside (trusted) interface.
>
>  Thank you!
>
>   -Rizzo
>
>
>
>
>-Original Message-
>From: Craig Columbus [mailto:[EMAIL PROTECTED]]
>Sent: Monday, May 21, 2001 11:44 AM
>To: Rizzo Damian
>Cc: [EMAIL PROTECTED]
>Subject: Re: PIX question... [7:5248]
>
>Sounds like a VPN is your best bet.
>Should you decide to implement the VPN, you may want to consider whether
>you still need to maintain the modem pool on the Internet router.  Reducing
>this cost could help justify the cost of implementing a VPN solution.  A
>properly authenticated VPN user should be able to use any dial-up Internet
>connection to reach your LAN.
>
>Craig
>
>At 10:15 AM 5/21/2001 -0400, you wrote:
> >Hey all, is it possible to translate public IP addresses (outside) to
> >private IP addresses (inside) on a PIX firewall. Basically the exact
> >opposite of what's usually performed on a firewall. We are going to have
> >users dial in to our internet router and receive a Public IP address. They
> >have to get through our firewall to gain access to our LAN. Is there a way
> >to translate the Public IP address they will obtain into a private IP
> >address used by our LAN so they can access it?  I thank you for your
>help...
> >
> >
> >   -Rizzo
> >FAQ, list archives, and subscription info:
> >http://www.groupstudy.com/list/cisco.html
> >Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5274&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: BGP question [7:4973]

2001-05-21 Thread Tom Pruneau

Greetings All

I think the context of some of the conversation is missing.

BGP can handle any class of address, and in fact the BGP being run on the
net at present (BGP4) is classless. The whole reason for CIDR was that it
was intended to shrink the size of the BGP routing tables. SO them saying
BGP will only work with class C is totally bogus!

BUT

Any ISP running BGP will implement a BGP policy, a hopefully uniform way in
which they do BGP routing and handle BGP peering with their customers.
There may be rules they have set up regarding how they do BGP, and you may
be asking for something outside of the capabilities of their Policy. That
doesn't mean BGP can't do it, it means they do not do that.

As for your having a class A address. Who do you work for? There are only
127 class A addresses, mopst belonging to ISPs or the Government, or
Reserved. I can think of one compnay who has a Class A, HP, they have the
15.0.0.0 network.

However if you have a RFC1918 Class A that you're using that's a whole
different story.

What is your address range, and which ISP told you they couldn't handle
class A addresses?

Inquiring minds want to know

Tom





>
>Rizzo Damian wrote:
>> 
>> Hey folks, I have a quick question regarding BGP. We are looking for an
>> alternative ISP for our Internet. One company we spoke with that offers a
>> 100MB connection, said that in order to use their services we need to
>> implement BGP on our Internet router. We currently utilize a class A
>address
>> on our Internet router, and they said BGP will only work with Class C
>> addresses. I don't know enough about BGP yet to argue this fact, so I turn
>> to you to ask if you agree or disagree with this comment?  Thanks a lot!
>> 
>> 
>>   -Rizzo
>> FAQ, list archives, and subscription info:
>http://www.groupstudy.com/list/cisco.html
>> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>
>
Tom Pruneau 
Trainer Network Operations

GENUITY
3 Van de Graff Drive Burlington Ma. 01803
24 Hr. Network Operations Center 800-436-8489
If you need to get a hold of me my hours are 8AM-4PM ET Mon-Fri

---
This email is composed of 82% post consumer recycled data bits
---

"Once in a while you get shown the light 
in the strangest of places if you look at it right"




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5275&t=4973
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Weird trace results [7:5259]

2001-05-21 Thread Brian

Like the other reply sez, a routing table check may be in order, you have
multiple routes out of equal preference?

Brian "Sonic" Whalen
Success = Preparation + Opportunity


On Mon, 21 May 2001, Watson, Rick, CTR, OUSDC wrote:

> All,
>
> When performing a trace on an IP address (for "testing purposes we'll use
> 10.1.2.3) this is the result I get:
>
> router#trace 10.1.2.3
>
> Type escape sequence to abort.
> Tracing the route to 10.1.2.3
>
>   1 192.1.2.2 4 msec
> 192.1.2.10 4 msec
> 192.1.2.2 4 msec
>   2 10.1.2.3 0 msec 4 msec 4 msec
>   3  *  *  *
>   4  *  *  *
>   5  *  *  *
>   6  *  *  *
>
> This to me shows that I am still trying to find a path to the IP
> address...but if the IP Address is returned at the 2nd hop, why is the
trace
> still continuing? I thought that it would stop when the trace has the
> "path". Also note that when a "ping" is performed it returns the infamous
> "."
>
> This has really got me perplexed, and any help would be greatly
appreciated.
> Maybe I am just not understanding something about the trace command/ICMP.
>
> Rick Watson
> Network Engineer
> Advanced Systems Development, Inc.
> OUSD(Comptroller)
> 703.697.5710 office
> 800.309.7782 pager ([EMAIL PROTECTED])
> [EMAIL PROTECTED]
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5276&t=5259
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: "network logon problems" [7:5271]

2001-05-21 Thread Craig Columbus

Has this ever worked?  Did the problem just recently occur?
If the user logs in with the cached credentials, verifies that he is able 
to access the correct network resources, logs off, logs back in, and still 
can't connect to the domain, then you can rule out spanning-tree 
calculations as the problem.
Is the domain in which the user accounts reside available and properly 
configured on each of the problem workstations?
I can only think of a few things that would cause this problem:
1)  The correct domain is not available, or does not (or is unable to) 
respond within the time-out for some reason.
2)  The correct domain is not configured properly in Windows.
3)  The switch port is blocking for some reason.

Craig

At 01:01 PM 5/21/2001 -0400, you wrote:
>HELP!!
>I have an issue where it appears that multiple users cannot login.  I
>receive the error "you will be logged on using a cached account" and once
>logged on, all network devices are available.  I have ensured that on the
>catalyst 3548XL, all ports have Port fast enabled and I have also enabled
>STP to try and overcome the problem with no success.  I have also moved the
>users to switches that have no issues and I still have the same problem.  I
>also did a ipconfig /release renew and replaced the nic card and did a cold
>boot and warm boot on the machines with no success.  All other user are fine
>and it is only affecting like 3 people.  I even set them to auto, auto and
>the switch to auto,auto and this did not work either.  I then tried 100 full
>and half and that did not work either.  I also do not have port security
>enabled.  It appears to be a network issue with the catalystr switches, but
>I am unsure as to the root of the problem.Don't know if this would do
>anything, but I did a NBTSTAT -RR from the command line as well.  Any help
>would be greatly appreciated.Thank you.
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5277&t=5271
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: "network logon problems" [7:5271]

2001-05-21 Thread Richard Tufaro

Can you ping domain controllers by name on said boxes?

Richard Tufaro, CCNA, MCSE, GSEC
Network Engineer
Anda Inc.
[EMAIL PROTECTED]

>>> "Robert Perez"  05/21 1:01 PM >>>
HELP!!
I have an issue where it appears that multiple users cannot login.  I
receive the error "you will be logged on using a cached account" and once
logged on, all network devices are available.  I have ensured that on the
catalyst 3548XL, all ports have Port fast enabled and I have also enabled
STP to try and overcome the problem with no success.  I have also moved the
users to switches that have no issues and I still have the same problem.  I
also did a ipconfig /release renew and replaced the nic card and did a cold
boot and warm boot on the machines with no success.  All other user are fine
and it is only affecting like 3 people.  I even set them to auto, auto and
the switch to auto,auto and this did not work either.  I then tried 100 full
and half and that did not work either.  I also do not have port security
enabled.  It appears to be a network issue with the catalystr switches, but
I am unsure as to the root of the problem.Don't know if this would do
anything, but I did a NBTSTAT -RR from the command line as well.  Any help
would be greatly appreciated.Thank you.
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5278&t=5271
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: PIX question... [7:5248]

2001-05-21 Thread Rizzo Damian

Actually it seems as if you understand exactly what I'm asking. Your idea is
very similar to mine. However it didn't work unfortunately. Let me ask this
another way, if you don't mind...You have an internet router which is
directly connected to the external (un-trusted) interface of your PIX
firewall. Basically I want to be able to access my internal LAN with private
IP addresses from the Internet router with Public IP addresses. So I should
be able to telnet onto my internet router and ping my privately held LAN.
Forget about Security, I just want to know if it can be done. The static
mapping doesn't seem to work. Probably because it require a one-to-one
mapping no?   Thanks for any help in advance!



  -Rizzo





-Original Message-
From: Craig Columbus [mailto:[EMAIL PROTECTED]] 
Sent: Monday, May 21, 2001 1:12 PM
To: [EMAIL PROTECTED]
Subject: RE: PIX question... [7:5248]

I'm not clear on what you're asking.  Are you asking if the PIX can take a 
public IP and make it appear as a private IP on the internal network?  The 
answer is yes, although you certainly want to be careful with this and I 
can't say that this is a recommended config.  You'll need a config similar 
to the one below:

nat (outside)  1 0 0
static (inside,outside)  
 netmask 255.255.255.255
access-list  permit ip any host 

For more info, reference 
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v52/config/exa
mples.htm#xtocid274896

Thanks,
Craig

At 12:14 PM 5/21/2001 -0400, you wrote:
>We are aware of the VPN solution and that is our long term goal. However,
>for the moment, all I need to know is if it is possible to NAT from an
>outside (not trusted) interface to an inside (trusted) interface.
>
>  Thank you!
>
>   -Rizzo
>
>
>
>
>-Original Message-
>From: Craig Columbus [mailto:[EMAIL PROTECTED]]
>Sent: Monday, May 21, 2001 11:44 AM
>To: Rizzo Damian
>Cc: [EMAIL PROTECTED]
>Subject: Re: PIX question... [7:5248]
>
>Sounds like a VPN is your best bet.
>Should you decide to implement the VPN, you may want to consider whether
>you still need to maintain the modem pool on the Internet router.  Reducing
>this cost could help justify the cost of implementing a VPN solution.  A
>properly authenticated VPN user should be able to use any dial-up Internet
>connection to reach your LAN.
>
>Craig
>
>At 10:15 AM 5/21/2001 -0400, you wrote:
> >Hey all, is it possible to translate public IP addresses (outside) to
> >private IP addresses (inside) on a PIX firewall. Basically the exact
> >opposite of what's usually performed on a firewall. We are going to have
> >users dial in to our internet router and receive a Public IP address.
They
> >have to get through our firewall to gain access to our LAN. Is there a
way
> >to translate the Public IP address they will obtain into a private IP
> >address used by our LAN so they can access it?  I thank you for your
>help...
> >
> >
> >   -Rizzo
> >FAQ, list archives, and subscription info:
> >http://www.groupstudy.com/list/cisco.html
> >Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5279&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



R 2523 [7:5280]

2001-05-21 Thread RamG

Gang - Is USD.590 for above router without flash is worth buying?  

Thanks for your feedback.

RamG




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5280&t=5280
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: "network logon problems" [7:5271]

2001-05-21 Thread Wojtek Zlobicki

Set up a ping once you can authenticate and let it run for a few hours (ping
the DC or another client resource).  If you see that you have packet loss
that occurs on all the machines at the same time, you may begin to suspect
STP buggering up.  Do you have any loops that could be causing STP to prune
certain connections ?


""Robert Perez""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> HELP!!
> I have an issue where it appears that multiple users cannot login.  I
> receive the error "you will be logged on using a cached account" and once
> logged on, all network devices are available.  I have ensured that on the
> catalyst 3548XL, all ports have Port fast enabled and I have also enabled
> STP to try and overcome the problem with no success.  I have also moved
the
> users to switches that have no issues and I still have the same problem.
I
> also did a ipconfig /release renew and replaced the nic card and did a
cold
> boot and warm boot on the machines with no success.  All other user are
fine
> and it is only affecting like 3 people.  I even set them to auto, auto and
> the switch to auto,auto and this did not work either.  I then tried 100
full
> and half and that did not work either.  I also do not have port security
> enabled.  It appears to be a network issue with the catalystr switches,
but
> I am unsure as to the root of the problem.Don't know if this would do
> anything, but I did a NBTSTAT -RR from the command line as well.  Any help
> would be greatly appreciated.Thank you.
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5281&t=5271
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Voice over IP Documents and sample configs [7:5221]

2001-05-21 Thread Wojtek Zlobicki

This is a good link :
""Hamid""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> Hi
>
> Can anybody tell me where I can find some sample configs for VoIP and a
good
> and complete document for it.
>
> Thanks
>
> Hamid
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5282&t=5221
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: ISL using 11.2????? [7:5273]

2001-05-21 Thread Vincent Chong

Minimum Requiremnet,  11.3(1) T

""Arun""   Yes i think u need to upgrade to 11.8
>
> ""Jeff""  wrote in message
> 9aricg$6i0$[EMAIL PROTECTED]">news:9aricg$6i0$[EMAIL PROTECTED]...
> > I am using a 4500 with a Fast Ethernet interface and would like to be
able
> > to route between VLANs that are setup on my 2900. I don't have the
option
> to
> > use encapsulation ISL using Ver 11.2 on the 4500. Do I have to upgrade
to
> > 11.3 or something higher to be able to use ISL?
> >
> > Thanks!
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5284&t=5273
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Voice over IP Documents and sample configs [7:5221]

2001-05-21 Thread Wojtek Zlobicki

Link included  this time :)


http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/12cgcr/voice
_c/index.htm


Cisco has some very good resources on their site. I recommend searching CCO.


""Hamid""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> Hi
>
> Can anybody tell me where I can find some sample configs for VoIP and a
good
> and complete document for it.
>
> Thanks
>
> Hamid
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5283&t=5221
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: video conference [7:5217]

2001-05-21 Thread Wojtek Zlobicki

Kevin,

At what speeds to the three locations access the Internet.


""kevin A.""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> We have three location. All location have internet
> access. We would like to have video conference setup
> for all location. What are some good product out
> there. Need to be easy to use and very good tech
> support. How does this solution compare to Isdn
> solution. Where can we buy these products. Thank you.
>
> __
> Do You Yahoo!?
> Yahoo! Auctions - buy the things you want at great prices
> http://auctions.yahoo.com/
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5285&t=5217
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Help its very very urgent ..isl trunking [7:5272]

2001-05-21 Thread Vincent Chong

What do you find in show vtp  comand set ?

Check your trunking mode in the catalyst.

HTH
Vincent Chong

""Arun""   Hi
> I am facing problem in setting the isl trunk between 29900xL series switch
> and 7100 series router .The configuration is like i am using fast ethernet
> port 0/16 of switch for trunk .
> i configure it using commands as below for the switch  i do..
>
> conf t
> int vlan 1
> ip adress 192.168.3.215 255.255.255.0
> ip default-gateway 192.168.3.210
>
> conf ter
> int fast eth0/16
> switchport mode trunk
> switchport trunk encapsulation isl(right )
> swicthport trunk allowed vlan all
> conf ter
> int fast0/15
> switchport access vlan 2
> spannig portfast
> exit
> also i did like
> vlan database
> vtp server
> vlan 2
>
> now for the router
> conf t
> int fast0/0
> no shutdown
> exit
> int fast0/0.1
> encap isl 1
> ip add 192.168 .3.210 255.255.255.0
> exit
> int fast0/0.2
> encap isl 2
> ip add 192.168 .4.210 255.255.255.0
> exit
>
>
> now the problem is i am not able to ping from router to interface
> 192.168.3.210 ..am i doing something wrong ..also after this if i do
> show cdp neigh the router see the switch but if i do it on switch it
doesn't
> see the router ..please help .
> where i am doing wrong ..Please help
> Thanx in advance
>
>
> Regards
> Arun Sharma
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5286&t=5272
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: OT Looking for tech presentation tips [7:5111]

2001-05-21 Thread Priscilla Oppenheimer

Ask your manager to send you to a class on doing presentations. You 
shouldn't be expected to do this without training any more than the junior 
engineers can do their jobs without training. In a training class, you will 
get a chance to practice in a safe environment. You will also learn how to 
handle questions.

A helpful tip is to keep in mind that you are the expert. The students 
signed up for the class because they want to learn from you. If they get 
disruptive, the best approach is to stand right beside the disruptive 
person so all eyes in the classroom are drawn to him.

To avoid the jitters, stick to decaf! ;-) Good luck!

Priscilla

At 06:37 AM 5/19/01, Rashid Lohiya wrote:
>Hey Guys,
>
>I am a CCNP with 15 yrs of network experience, I am well travelled in the
>course of my work.
>
>I think I generally know what I am doing, but have great difficulty
>explaining myself to more junior staff.
>
>I can design/configure/troubleshoot networks and create accurate
>diagrams/documents/reports etc.
>
>As I am the Senior in my department, my boss is expecting me to help train
>the 6 x new trainees/graduates that are in the Network department. I once
>had to give a presentation and I was shaking and stuttering and I must have
>seemed insecure and unconfident. I was lost for words and really stressed. I
>was sweating and confused, I knew the answers to their questions, but I just
>could not explain to them.
>
>Any tips on how to overcome this?
>
>Rashid Lohiya
>[EMAIL PROTECTED]
>020 8509 2990
>07785 362626
>www.pioneer-computers.com
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Priscilla Oppenheimer
http://www.priscilla.com




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5288&t=5111
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: ccie written [7:5225]

2001-05-21 Thread Daniel Lafraia

I could see in your signature that you have CCNA and CCIE written. Don't you
have to have CCNP before applying to CCIE tests?

cya
Daniel Lafraia


""Stefano Andrello""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> Today I passed my CCIE written, score 95%.
> Thanks to the group and to boson test.
> Let's go for the lab
>
> Stefano Andrello
> CCIE written, CCNA
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5289&t=5225
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: PIX question... [7:5248]

2001-05-21 Thread Craig Columbus

I just realized that the config I sent through to the list didn't come 
through as I typed it.  Probably because the filter is set to take out 
certain characters.  Rizzo, hopefully you got the correct config in the 
message I sent you directly.

Using the static command should work, provided that it's coupled with the 
appropriate NAT command (to tell the router where to NAT and in what 
direction) and the correct access-list command (needed to tell the router 
to pass traffic from the particular public IP identified in the static
config).

In your particular case, you'll need to setup a static command and 
access-list for each IP address in your modem pool.

Refer again to the URL I sent in the previous message.  It has specific 
configuration commands to do exactly what you're trying to do.

Thanks,
Craig

At 01:32 PM 5/21/2001 -0400, you wrote:
>Actually it seems as if you understand exactly what I'm asking. Your idea is
>very similar to mine. However it didn't work unfortunately. Let me ask this
>another way, if you don't mind...You have an internet router which is
>directly connected to the external (un-trusted) interface of your PIX
>firewall. Basically I want to be able to access my internal LAN with private
>IP addresses from the Internet router with Public IP addresses. So I should
>be able to telnet onto my internet router and ping my privately held LAN.
>Forget about Security, I just want to know if it can be done. The static
>mapping doesn't seem to work. Probably because it require a one-to-one
>mapping no?   Thanks for any help in advance!
>
>
>
>   -Rizzo
>
>
>
>
>
>-Original Message-
>From: Craig Columbus [mailto:[EMAIL PROTECTED]]
>Sent: Monday, May 21, 2001 1:12 PM
>To: [EMAIL PROTECTED]
>Subject: RE: PIX question... [7:5248]
>
>I'm not clear on what you're asking.  Are you asking if the PIX can take a
>public IP and make it appear as a private IP on the internal network?  The
>answer is yes, although you certainly want to be careful with this and I
>can't say that this is a recommended config.  You'll need a config similar
>to the one below:
>
>nat (outside)  1 0 0
>static (inside,outside)
>  netmask 255.255.255.255
>access-list  permit ip any host
>
>For more info, reference
>http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v52/config/exa
>mples.htm#xtocid274896
>
>Thanks,
>Craig
>
>At 12:14 PM 5/21/2001 -0400, you wrote:
> >We are aware of the VPN solution and that is our long term goal. However,
> >for the moment, all I need to know is if it is possible to NAT from an
> >outside (not trusted) interface to an inside (trusted) interface.
> >
> >  Thank you!
> >
> >   -Rizzo
> >
> >
> >
> >
> >-Original Message-
> >From: Craig Columbus [mailto:[EMAIL PROTECTED]]
> >Sent: Monday, May 21, 2001 11:44 AM
> >To: Rizzo Damian
> >Cc: [EMAIL PROTECTED]
> >Subject: Re: PIX question... [7:5248]
> >
> >Sounds like a VPN is your best bet.
> >Should you decide to implement the VPN, you may want to consider whether
> >you still need to maintain the modem pool on the Internet router. 
Reducing
> >this cost could help justify the cost of implementing a VPN solution.  A
> >properly authenticated VPN user should be able to use any dial-up Internet
> >connection to reach your LAN.
> >
> >Craig
> >
> >At 10:15 AM 5/21/2001 -0400, you wrote:
> > >Hey all, is it possible to translate public IP addresses (outside) to
> > >private IP addresses (inside) on a PIX firewall. Basically the exact
> > >opposite of what's usually performed on a firewall. We are going to have
> > >users dial in to our internet router and receive a Public IP address.
>They
> > >have to get through our firewall to gain access to our LAN. Is there a
>way
> > >to translate the Public IP address they will obtain into a private IP
> > >address used by our LAN so they can access it?  I thank you for your
> >help...
> > >
> > >
> > >   -Rizzo
> > >FAQ, list archives, and subscription info:
> > >http://www.groupstudy.com/list/cisco.html
> > >Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
> >FAQ, list archives, and subscription info:
> >http://www.groupstudy.com/list/cisco.html
> >Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>FAQ, list archives, and subscription info:
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5290&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Help its very very urgent ..isl trunking [7:5272]

2001-05-21 Thread Arun

Hi
I have checked the trunking mode on the port it shows it as encaps isl
and i found this with show int fast0/16 switchport command
Regards
""Vincent Chong""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> What do you find in show vtp  comand set ?
>
> Check your trunking mode in the catalyst.
>
> HTH
> Vincent Chong
>
> ""Arun""   Hi
> > I am facing problem in setting the isl trunk between 29900xL series
switch
> > and 7100 series router .The configuration is like i am using fast
ethernet
> > port 0/16 of switch for trunk .
> > i configure it using commands as below for the switch  i do..
> >
> > conf t
> > int vlan 1
> > ip adress 192.168.3.215 255.255.255.0
> > ip default-gateway 192.168.3.210
> >
> > conf ter
> > int fast eth0/16
> > switchport mode trunk
> > switchport trunk encapsulation isl(right )
> > swicthport trunk allowed vlan all
> > conf ter
> > int fast0/15
> > switchport access vlan 2
> > spannig portfast
> > exit
> > also i did like
> > vlan database
> > vtp server
> > vlan 2
> >
> > now for the router
> > conf t
> > int fast0/0
> > no shutdown
> > exit
> > int fast0/0.1
> > encap isl 1
> > ip add 192.168 .3.210 255.255.255.0
> > exit
> > int fast0/0.2
> > encap isl 2
> > ip add 192.168 .4.210 255.255.255.0
> > exit
> >
> >
> > now the problem is i am not able to ping from router to interface
> > 192.168.3.210 ..am i doing something wrong ..also after this if i do
> > show cdp neigh the router see the switch but if i do it on switch it
> doesn't
> > see the router ..please help .
> > where i am doing wrong ..Please help
> > Thanx in advance
> >
> >
> > Regards
> > Arun Sharma
> > FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> > Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5291&t=5272
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: "network logon problems" [7:5271]

2001-05-21 Thread Craig Columbus

Yes, but really what I was referring to was that the port will not pass 
traffic when it's trying to figure out the spanning-tree.  Since you're set 
to portfast, the port should immediately go to forwarding.
Since this is affecting only a few users on the network, I really can't see 
that STP is the issue.
My instincts say that this is probably not a network issue; that it's more 
likely a Windows issue.  However, there are some tests you can do to 
determine the point of failure:
1)  Hookup a sniffer to the switch in question, mirror the problem port(s), 
fire up the workstations, and watch the traffic.  Do you see the 
workstation trying to authenticate?  Do you see responses from the DC?
2)  If the DC is trying to respond, but the workstation isn't receiving the 
messages, look for errors on the switch ports.
3)  If all traffic looks normal and you're not seeing any errors, start 
looking at your Windows configuration and/or logins.  Make sure the users 
aren't selecting a domain that is no longer available on your network or 
something like that.

Thanks,
Craig

At 01:43 PM 5/21/2001 -0400, you wrote:
>Yes and it just started last week, so according to what you have said,
>spanning tree is ruled out.  Now when you say the port is blocking, are you
>referring to the port that station is connected to?
>
>-Original Message-
>From: Craig Columbus [mailto:[EMAIL PROTECTED]]
>Sent: Monday, May 21, 2001 1:18 PM
>To: Robert Perez
>Cc: [EMAIL PROTECTED]
>Subject: Re: "network logon problems" [7:5271]
>
>
>Has this ever worked?  Did the problem just recently occur?
>If the user logs in with the cached credentials, verifies that he is able
>to access the correct network resources, logs off, logs back in, and still
>can't connect to the domain, then you can rule out spanning-tree
>calculations as the problem.
>Is the domain in which the user accounts reside available and properly
>configured on each of the problem workstations?
>I can only think of a few things that would cause this problem:
>1)  The correct domain is not available, or does not (or is unable to)
>respond within the time-out for some reason.
>2)  The correct domain is not configured properly in Windows.
>3)  The switch port is blocking for some reason.
>
>Craig
>
>At 01:01 PM 5/21/2001 -0400, you wrote:
> >HELP!!
> >I have an issue where it appears that multiple users cannot login.  I
> >receive the error "you will be logged on using a cached account" and once
> >logged on, all network devices are available.  I have ensured that on the
> >catalyst 3548XL, all ports have Port fast enabled and I have also enabled
> >STP to try and overcome the problem with no success.  I have also moved
the
> >users to switches that have no issues and I still have the same problem. 
I
> >also did a ipconfig /release renew and replaced the nic card and did a
cold
> >boot and warm boot on the machines with no success.  All other user are
>fine
> >and it is only affecting like 3 people.  I even set them to auto, auto and
> >the switch to auto,auto and this did not work either.  I then tried 100
>full
> >and half and that did not work either.  I also do not have port security
> >enabled.  It appears to be a network issue with the catalystr switches,
but
> >I am unsure as to the root of the problem.Don't know if this would do
> >anything, but I did a NBTSTAT -RR from the command line as well.  Any help
> >would be greatly appreciated.Thank you.
> >FAQ, list archives, and subscription info:
> >http://www.groupstudy.com/list/cisco.html
> >Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5293&t=5271
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Weird trace results [7:5259]

2001-05-21 Thread Hire, Ejay

I'd say there was an access-list or firewall blocking ICMP-echo replies, but
not TTL expired messages.  

This is a guess.  This is only a guess.  In the event of a real answer, the
statements just typed would have been followed by supporting documentation.

Ejay Hire


-Original Message-
From: Watson, Rick, CTR, OUSDC [mailto:[EMAIL PROTECTED]]
Sent: Monday, May 21, 2001 11:53 AM
To: [EMAIL PROTECTED]
Subject: Re: Weird trace results [7:5259]


All,

When performing a trace on an IP address (for "testing purposes we'll use
10.1.2.3) this is the result I get:

router#trace 10.1.2.3

Type escape sequence to abort.
Tracing the route to 10.1.2.3

  1 192.1.2.2 4 msec
192.1.2.10 4 msec
192.1.2.2 4 msec
  2 10.1.2.3 0 msec 4 msec 4 msec
  3  *  *  * 
  4  *  *  * 
  5  *  *  * 
  6  *  *  * 

This to me shows that I am still trying to find a path to the IP
address...but if the IP Address is returned at the 2nd hop, why is the trace
still continuing? I thought that it would stop when the trace has the
"path". Also note that when a "ping" is performed it returns the infamous
"."

This has really got me perplexed, and any help would be greatly appreciated.
Maybe I am just not understanding something about the trace command/ICMP.

Rick Watson
Network Engineer
Advanced Systems Development, Inc.
OUSD(Comptroller)
703.697.5710 office
800.309.7782 pager ([EMAIL PROTECTED])
[EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5292&t=5259
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



CIT Exam Cram Book [7:5294]

2001-05-21 Thread

Does anyone out there have a copy of the CIT Exam Cram book ?  Does anyone
know where to obtain a copy.  I can't seem to find a copy in print
anywhere...[borders/barnes/etc.]

thanks in advance

Mike




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5294&t=5294
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



ISDN [7:5295]

2001-05-21 Thread Michelle Sanderson

Please help, I can't ping the remote side of this ISDN connection.

Here is the config AND the log with debug ppp negotiation showing a
PROTREJ(toward the end of output).  Does that mean PPP is not working or
setup right?

When I ping the remote, the call is made to the customer but I don't get a
reply.  Also, if I show ip route after I ping(while the line is still up) I
see a route like this 192.168.2.58/32 what does the /32 mean-I know it's
subnet bits but how is it 32?  Before the dialer makes the call if I show ip
route I see it as 192.168.2.56/29(I'm 192.168.2.57 and customer is
192.168.2.58) The rest of the output show what happens when I ping the other
side with debug ppp negotiation on.  Thanks for any help.

isdn switch-type basic-ni1
!
interface BRI0/0
 ip address 192.168.2.57 255.255.255.248
 encapsulation ppp
 isdn spid1 9258255950
 isdn spid2 9258255957
 dialer idle-timeout 57
 dialer map ip 192.168.2.58 name customer 1904296
 dialer-group 1
 ppp chap hostname service
 ppp chap password xxx

ping 192.168.2.58
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.2.58, timeout is 2 seconds:
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: PIX question... [7:5248]

2001-05-21 Thread Andras Bellak

Correct-

It can be done, but it does require a static mapping. One question to verify
what you are asking:

You want to ping from the internet to you lan like so:

Ping from x.x.x.x to y.y.y.y, where x.x.x.x is an internet routable address,
and y.y.y.y is a static translation of your private addresses, and not the
private address themselves?

andras

-Original Message-
From: Rizzo Damian [mailto:[EMAIL PROTECTED]]
Sent: Monday, May 21, 2001 10:50 AM
To: [EMAIL PROTECTED]
Subject: RE: PIX question... [7:5248]


Actually it seems as if you understand exactly what I'm asking. Your idea is
very similar to mine. However it didn't work unfortunately. Let me ask this
another way, if you don't mind...You have an internet router which is
directly connected to the external (un-trusted) interface of your PIX
firewall. Basically I want to be able to access my internal LAN with private
IP addresses from the Internet router with Public IP addresses. So I should
be able to telnet onto my internet router and ping my privately held LAN.
Forget about Security, I just want to know if it can be done. The static
mapping doesn't seem to work. Probably because it require a one-to-one
mapping no?   Thanks for any help in advance!



  -Rizzo





-Original Message-
From: Craig Columbus [mailto:[EMAIL PROTECTED]] 
Sent: Monday, May 21, 2001 1:12 PM
To: [EMAIL PROTECTED]
Subject: RE: PIX question... [7:5248]

I'm not clear on what you're asking.  Are you asking if the PIX can take a 
public IP and make it appear as a private IP on the internal network?  The 
answer is yes, although you certainly want to be careful with this and I 
can't say that this is a recommended config.  You'll need a config similar 
to the one below:

nat (outside)  1 0 0
static (inside,outside)  
 netmask 255.255.255.255
access-list  permit ip any host 

For more info, reference 
http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v52/config/exa
mples.htm#xtocid274896

Thanks,
Craig

At 12:14 PM 5/21/2001 -0400, you wrote:
>We are aware of the VPN solution and that is our long term goal. However,
>for the moment, all I need to know is if it is possible to NAT from an
>outside (not trusted) interface to an inside (trusted) interface.
>
>  Thank you!
>
>   -Rizzo
>
>
>
>
>-Original Message-
>From: Craig Columbus [mailto:[EMAIL PROTECTED]]
>Sent: Monday, May 21, 2001 11:44 AM
>To: Rizzo Damian
>Cc: [EMAIL PROTECTED]
>Subject: Re: PIX question... [7:5248]
>
>Sounds like a VPN is your best bet.
>Should you decide to implement the VPN, you may want to consider whether
>you still need to maintain the modem pool on the Internet router.  Reducing
>this cost could help justify the cost of implementing a VPN solution.  A
>properly authenticated VPN user should be able to use any dial-up Internet
>connection to reach your LAN.
>
>Craig
>
>At 10:15 AM 5/21/2001 -0400, you wrote:
> >Hey all, is it possible to translate public IP addresses (outside) to
> >private IP addresses (inside) on a PIX firewall. Basically the exact
> >opposite of what's usually performed on a firewall. We are going to have
> >users dial in to our internet router and receive a Public IP address.
They
> >have to get through our firewall to gain access to our LAN. Is there a
way
> >to translate the Public IP address they will obtain into a private IP
> >address used by our LAN so they can access it?  I thank you for your
>help...
> >
> >
> >   -Rizzo
> >FAQ, list archives, and subscription info:
> >http://www.groupstudy.com/list/cisco.html
> >Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5296&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Help its very very urgent ..isl trunking [7:5272]

2001-05-21 Thread Vincent Chong

First, trunk mode is desirable, non-neigotate, auto, none, something like
that.

Second, isl is an encapsulation method, it is not a trunk mode.

I am pretty sure you have layer 2 problem, cdp command is layer 2
troubleshooting tool.

HTH
Vincent Chong

""Arun""   Hi
> I have checked the trunking mode on the port it shows it as encaps isl
> and i found this with show int fast0/16 switchport command
> Regards
> ""Vincent Chong""  wrote in message
> [EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> > What do you find in show vtp  comand set ?
> >
> > Check your trunking mode in the catalyst.
> >
> > HTH
> > Vincent Chong
> >
> > ""Arun""   Hi
> > > I am facing problem in setting the isl trunk between 29900xL series
> switch
> > > and 7100 series router .The configuration is like i am using fast
> ethernet
> > > port 0/16 of switch for trunk .
> > > i configure it using commands as below for the switch  i do..
> > >
> > > conf t
> > > int vlan 1
> > > ip adress 192.168.3.215 255.255.255.0
> > > ip default-gateway 192.168.3.210
> > >
> > > conf ter
> > > int fast eth0/16
> > > switchport mode trunk
> > > switchport trunk encapsulation isl(right )
> > > swicthport trunk allowed vlan all
> > > conf ter
> > > int fast0/15
> > > switchport access vlan 2
> > > spannig portfast
> > > exit
> > > also i did like
> > > vlan database
> > > vtp server
> > > vlan 2
> > >
> > > now for the router
> > > conf t
> > > int fast0/0
> > > no shutdown
> > > exit
> > > int fast0/0.1
> > > encap isl 1
> > > ip add 192.168 .3.210 255.255.255.0
> > > exit
> > > int fast0/0.2
> > > encap isl 2
> > > ip add 192.168 .4.210 255.255.255.0
> > > exit
> > >
> > >
> > > now the problem is i am not able to ping from router to interface
> > > 192.168.3.210 ..am i doing something wrong ..also after this if i
do
> > > show cdp neigh the router see the switch but if i do it on switch it
> > doesn't
> > > see the router ..please help .
> > > where i am doing wrong ..Please help
> > > Thanx in advance
> > >
> > >
> > > Regards
> > > Arun Sharma
> > > FAQ, list archives, and subscription info:
> > http://www.groupstudy.com/list/cisco.html
> > > Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
> > FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> > Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5298&t=5272
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: sybex virtual lab e-trainer [7:5235]

2001-05-21 Thread George Murphy CCNP

Eric, I used it and it was pretty good for reinforcing knowlegde in the
basic areas. It
has about 8 module labs and you can complete them pretty quickly. I would
rate it as
more of a beginning stage resource for folks who have not had much
experience. If you
have experience in the basic areas already like configuring static and
default routes,
vlans etc, you may want to check into something else like RouterSIM Good
Luck...

"James, Eric L." wrote:

> Has anyone used Sybex Virtual Lab E-Trainer for ccna studying?
>
> Eric James
> Network Admin 2
> Franklin County Data Center
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5297&t=5235
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: ccie written [7:5225]

2001-05-21 Thread William E. Gragido

No, you do not need the Professional level certs before taking the CCIE
written.  You don't even need the CCNA.

-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of
Daniel Lafraia
Sent: Monday, May 21, 2001 1:16 PM
To: [EMAIL PROTECTED]
Subject: Re: ccie written [7:5225]


I could see in your signature that you have CCNA and CCIE written. Don't you
have to have CCNP before applying to CCIE tests?

cya
Daniel Lafraia


""Stefano Andrello""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> Today I passed my CCIE written, score 95%.
> Thanks to the group and to boson test.
> Let's go for the lab
>
> Stefano Andrello
> CCIE written, CCNA
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5299&t=5225
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: video conference [7:5217]

2001-05-21 Thread Andras Bellak

One big thing to consider is the potential for drops and jitter going over
the Internet. We use Polycom FX units (Polyspan FX in Europe) to do this
over our WAN (frame and MPLS). We have good quality most of the time, but do
get some drops on occasion. Most of the time our VP's love it, but one or
two start to complain if we drop even two or three packets during a call.
The sound and video quality are great with the units above. Some questions:

1. Are all your sites connected by the same backbone ISP?
2. Do you use a VPN to connect the sites?
3. As the last question asked, what are the internet connection speeds?
4. How many hops between sites (or better, what is the response time?).

andras

-Original Message-
From: Wojtek Zlobicki [mailto:[EMAIL PROTECTED]]
Sent: Monday, May 21, 2001 11:04 AM
To: [EMAIL PROTECTED]
Subject: Re: video conference [7:5217]


Kevin,

At what speeds to the three locations access the Internet.


""kevin A.""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> We have three location. All location have internet
> access. We would like to have video conference setup
> for all location. What are some good product out
> there. Need to be easy to use and very good tech
> support. How does this solution compare to Isdn
> solution. Where can we buy these products. Thank you.
>
> __
> Do You Yahoo!?
> Yahoo! Auctions - buy the things you want at great prices
> http://auctions.yahoo.com/
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5300&t=5217
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: "network logon problems" [7:5271]

2001-05-21 Thread McClendon Susan Contr AEDC/ACS

Robert,
Since you can see network devices then it's probably access to the
domain controller SAMs database that is hosing your PCs. Especially if
ipconfig/release renew found the DHCP server & received new IP info then
TCP/IP is working fine, so timing issues are a low probability. It's
winders. Check DHCP config, compare with config of working PCs for:
Duplicate computer names (both current on net at same time)
Incorrect domain name received from DHCP. 
NT box with name from old replaced PC. (old PC no longer on network
- delete from Server Manager & wait 20 minutes then try to re-add computer
as member of domain with admin account)

Also check  http://support.microsoft.com for this error message.

- susan

>>> "Robert Perez"  05/21 1:01 PM >>>
HELP!!
I have an issue where it appears that multiple users cannot login.  I
receive the error "you will be logged on using a cached account" and once
logged on, all network devices are available.  I have ensured that on the
catalyst 3548XL, all ports have Port fast enabled and I have also enabled
STP to try and overcome the problem with no success.  I have also moved the
users to switches that have no issues and I still have the same problem.  I
also did a ipconfig /release renew and replaced the nic card and did a cold
boot and warm boot on the machines with no success.  All other user are fine
and it is only affecting like 3 people.  I even set them to auto, auto and
the switch to auto,auto and this did not work either.  I then tried 100 full
and half and that did not work either.  I also do not have port security
enabled.  It appears to be a network issue with the catalystr switches, but
I am unsure as to the root of the problem.Don't know if this would do
anything, but I did a NBTSTAT -RR from the command line as well.  Any help
would be greatly appreciated.Thank you.
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5302&t=5271
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: ccie written [7:5225]

2001-05-21 Thread Andras Bellak

No, anyone can take the CCIE written, no prior tests or certs required.

andras

-Original Message-
From: Daniel Lafraia [mailto:[EMAIL PROTECTED]]
Sent: Monday, May 21, 2001 11:16 AM
To: [EMAIL PROTECTED]
Subject: Re: ccie written [7:5225]


I could see in your signature that you have CCNA and CCIE written. Don't you
have to have CCNP before applying to CCIE tests?

cya
Daniel Lafraia


""Stefano Andrello""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> Today I passed my CCIE written, score 95%.
> Thanks to the group and to boson test.
> Let's go for the lab
>
> Stefano Andrello
> CCIE written, CCNA
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5301&t=5225
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: passed CIT [7:5228]

2001-05-21 Thread Priscilla Oppenheimer

You find them here:

http://www.priscilla.com

Of course! ;-)

Priscilla

At 08:45 AM 5/21/01, RCL wrote:
>How do you find "Priscillas flash cards"  
>
>
>--- George Kadeishvili  wrote:
> > A traditional Thank All message
> > Just passed CIT, and completed CCNP.
> > Priscillas flash cards are great. But the exam
> > itself sucks. Routing was
> > by far the best one in CCNP track.
> > Now have to start thinking about CCIE writen.
> > Regards
> > George
> > FAQ, list archives, and subscription info:
> > http://www.groupstudy.com/list/cisco.html
> > Report misconduct and Nondisclosure violations to
>[EMAIL PROTECTED]
>
>
>=
>= = = = = = = = = = = = = = = = = =
>Please send replys to:
>
>[EMAIL PROTECTED]
>= = = = = = = = = = = = = = = = = =
>
>__
>Do You Yahoo!?
>Yahoo! Auctions - buy the things you want at great prices
>http://auctions.yahoo.com/
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Priscilla Oppenheimer
http://www.priscilla.com




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5303&t=5228
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: PIX question... [7:5248]

2001-05-21 Thread Daniel Cotts

How about conduit statements allowing the outside addresses access to the
inside addresses. (Or access lists for the newer OS versions.) You could run
it wide open or be specific to addresses and ports.

> -Original Message-
> From: Rizzo Damian [mailto:[EMAIL PROTECTED]]
> Sent: Monday, May 21, 2001 12:50 PM
> To: [EMAIL PROTECTED]
> Subject: RE: PIX question... [7:5248]
> 
> 
> Actually it seems as if you understand exactly what I'm 
> asking. Your idea is
> very similar to mine. However it didn't work unfortunately. 
> Let me ask this
> another way, if you don't mind...You have an internet router which is
> directly connected to the external (un-trusted) interface of your PIX
> firewall. Basically I want to be able to access my internal 
> LAN with private
> IP addresses from the Internet router with Public IP 
> addresses. So I should
> be able to telnet onto my internet router and ping my 
> privately held LAN.
> Forget about Security, I just want to know if it can be done. 
> The static
> mapping doesn't seem to work. Probably because it require a one-to-one
> mapping no?   Thanks for any help in advance!
> 
> 
> 
>   -Rizzo
> 
> 
> 
> 
> 
> -Original Message-
> From: Craig Columbus [mailto:[EMAIL PROTECTED]] 
> Sent: Monday, May 21, 2001 1:12 PM
> To: [EMAIL PROTECTED]
> Subject: RE: PIX question... [7:5248]
> 
> I'm not clear on what you're asking.  Are you asking if the 
> PIX can take a 
> public IP and make it appear as a private IP on the internal 
> network?  The 
> answer is yes, although you certainly want to be careful with 
> this and I 
> can't say that this is a recommended config.  You'll need a 
> config similar 
> to the one below:
> 
> nat (outside)  1 0 0
> static (inside,outside)  
>  netmask 255.255.255.255
> access-list  permit ip any host 
> 
> For more info, reference 
> http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_
> v52/config/exa
> mples.htm#xtocid274896
> 
> Thanks,
> Craig
> 
> At 12:14 PM 5/21/2001 -0400, you wrote:
> >We are aware of the VPN solution and that is our long term 
> goal. However,
> >for the moment, all I need to know is if it is possible to 
> NAT from an
> >outside (not trusted) interface to an inside (trusted) interface.
> >
> >  Thank you!
> >
> >   -Rizzo
> >
> >
> >
> >
> >-Original Message-
> >From: Craig Columbus [mailto:[EMAIL PROTECTED]]
> >Sent: Monday, May 21, 2001 11:44 AM
> >To: Rizzo Damian
> >Cc: [EMAIL PROTECTED]
> >Subject: Re: PIX question... [7:5248]
> >
> >Sounds like a VPN is your best bet.
> >Should you decide to implement the VPN, you may want to 
> consider whether
> >you still need to maintain the modem pool on the Internet 
> router.  Reducing
> >this cost could help justify the cost of implementing a VPN 
> solution.  A
> >properly authenticated VPN user should be able to use any 
> dial-up Internet
> >connection to reach your LAN.
> >
> >Craig
> >
> >At 10:15 AM 5/21/2001 -0400, you wrote:
> > >Hey all, is it possible to translate public IP addresses 
> (outside) to
> > >private IP addresses (inside) on a PIX firewall. Basically 
> the exact
> > >opposite of what's usually performed on a firewall. We are 
> going to have
> > >users dial in to our internet router and receive a Public 
> IP address.
> They
> > >have to get through our firewall to gain access to our 
> LAN. Is there a
> way
> > >to translate the Public IP address they will obtain into a 
> private IP
> > >address used by our LAN so they can access it?  I thank 
> you for your
> >help...
> > >
> > >
> > >   -Rizzo
> > >FAQ, list archives, and subscription info:
> > >http://www.groupstudy.com/list/cisco.html
> > >Report misconduct and Nondisclosure violations to 
> [EMAIL PROTECTED]
> >FAQ, list archives, and subscription info: 
> >http://www.groupstudy.com/list/cisco.html
> >Report misconduct and Nondisclosure violations to 
> [EMAIL PROTECTED]
> FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
> FAQ, list archives, and subscription info: 
> http://www.groupstudy.com/list/cisco.html
> Report misconduct 
> and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5304&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: ccie written [7:5225]

2001-05-21 Thread Hire, Ejay

No.  Their are no pre-requisites to the CCIE Certification.

Ejay Hire

-Original Message-
From: Daniel Lafraia [mailto:[EMAIL PROTECTED]]
Sent: Monday, May 21, 2001 2:16 PM
To: [EMAIL PROTECTED]
Subject: Re: ccie written [7:5225]


I could see in your signature that you have CCNA and CCIE written. Don't you
have to have CCNP before applying to CCIE tests?

cya
Daniel Lafraia


""Stefano Andrello""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> Today I passed my CCIE written, score 95%.
> Thanks to the group and to boson test.
> Let's go for the lab
>
> Stefano Andrello
> CCIE written, CCNA
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5305&t=5225
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: ccie written [7:5225]

2001-05-21 Thread Daniel Cotts

There is no prerequisite to taking the CCIE. While doing CCNP first might be
good preparation, it is not required.

> -Original Message-
> From: Daniel Lafraia [mailto:[EMAIL PROTECTED]]
> Sent: Monday, May 21, 2001 1:16 PM
> To: [EMAIL PROTECTED]
> Subject: Re: ccie written [7:5225]
> 
> 
> I could see in your signature that you have CCNA and CCIE 
> written. Don't you
> have to have CCNP before applying to CCIE tests?
> 
> cya
> Daniel Lafraia
> 
> 
> ""Stefano Andrello""  wrote in message
> [EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> > Today I passed my CCIE written, score 95%.
> > Thanks to the group and to boson test.
> > Let's go for the lab
> >
> > Stefano Andrello
> > CCIE written, CCNA
> > FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> > Report misconduct and Nondisclosure violations to 
> [EMAIL PROTECTED]
> FAQ, list archives, and subscription info: 
> http://www.groupstudy.com/list/cisco.html
> Report misconduct 
> and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5307&t=5225
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: ccie written [7:5225]

2001-05-21 Thread Patrick Bass

sigh.

""Daniel Lafraia""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> I could see in your signature that you have CCNA and CCIE written. Don't
you
> have to have CCNP before applying to CCIE tests?
>
> cya
> Daniel Lafraia
>
>
> ""Stefano Andrello""  wrote in message
> [EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> > Today I passed my CCIE written, score 95%.
> > Thanks to the group and to boson test.
> > Let's go for the lab
> >
> > Stefano Andrello
> > CCIE written, CCNA
> > FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> > Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5306&t=5225
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: R 2523 [7:5280]

2001-05-21 Thread Daniel Cotts

Depends on how much you will have to pay for replacement Flash. Also where
will you obtain an IOS image? 2523's are going on eBay for $800-900 with 16
MB Flash and 8-16 MB DRAM.
A recent auction on eBay sold compatible 8 MB Flash for the 2500s at $60
each.

> -Original Message-
> From: RamG [mailto:[EMAIL PROTECTED]]
> Sent: Monday, May 21, 2001 12:54 PM
> To: [EMAIL PROTECTED]
> Subject: R 2523 [7:5280]
> 
> 
> Gang - Is USD.590 for above router without flash is worth buying?  
> 
> Thanks for your feedback.
> 
> RamG
> FAQ, list archives, and subscription info: 
> http://www.groupstudy.com/list/cisco.html
> Report misconduct 
> and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5308&t=5280
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Newbie question [7:5309]

2001-05-21 Thread Roger

My ISP just placed a new router outside of our PIX 515, and now, every 4
hours, the PIX loses connectivity and needs to be rebooted.  Is this an ARP
problem (is it looking for the mac of the old server)?  Any info would be
appreciated.  Thanks.




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5309&t=5309
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Windows 2000 Server Architechture/ Data Organization [7:5310]

2001-05-21 Thread Kevin O'Gilvie

Hi Everyone,

I am in the process of reorginizing this my network, Prior to me everything 
was just put everywhere and I need to come up with a full proof plan. My 
questions are:

-For a 60 user enviorment how many servers do I need to run Active Directory 
on, Should AD be on a dedicated box?

-How should I organize data, (users / corp data/ Fin Data) What restrictions 
should I put on these shares?

-DNS, Wins, DHCP, Exchange, SQL, IIS5, Inoculate, Backup Exec, Print 
Services,  What should be on dedicated boxes what shouldnt?

TIA,

Kevin


_
Get your FREE download of MSN Explorer at http://explorer.msn.com




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5310&t=5310
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



vlans 1-1000 are automatically transported [7:5311]

2001-05-21 Thread Reel, JohnX

Comrades,

I have one quick question that I have not been able understand so far... can
someone please help with an answer or a direction pointer. I appreciate your
help.

(1) CAT5509 as a reference
(2) Cisco "Building Cisco Multilayer Switched Networks," book by Karen Webb,
page 106.


The Cisco book states ~"vlans 1-1000 are automatically transported... even
if a range was specified... one must use the "clear" command to remove the
unnecessary vlans".

When two test vlans are added to the 5509 and then the "show vlan" command
is used, I do not see where "unnecessary' vlans have been added.  Note that
example:

1   default   active 3   3/1-12
 5/1-2
 7/1-3
2   jr_vlan2  active 146 5/9-16
3   jr_vlan3  active 146 5/17-25
...

John L. Reel
Intel-Gigabit Lab




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5311&t=5311
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: ISDN [7:5295]

2001-05-21 Thread McClendon Susan Contr AEDC/ACS

Michelle,
Check this ISDN debug ppp site.
http://www.cisco.com/warp/public/112/chapter17.htm#ISDNOUT , ISDN Outbound
Calling section.
Your log was not attached to the message so we don't know what happened.
Also, try adding 
ppp authentication chap
to your config under your BRI0/0 interface and see if it makes any
difference.  Both sides need the same encap usernames/passwords,
compression, authentication method. 

good luck!
- susan


-Original Message-
From: Michelle Sanderson [mailto:[EMAIL PROTECTED]]
Sent: Monday, May 21, 2001 1:36 PM
To: [EMAIL PROTECTED]
Subject: ISDN [7:5295]


Please help, I can't ping the remote side of this ISDN connection.

Here is the config AND the log with debug ppp negotiation showing a
PROTREJ(toward the end of output).  Does that mean PPP is not working or
setup right?

When I ping the remote, the call is made to the customer but I don't get a
reply.  Also, if I show ip route after I ping(while the line is still up) I
see a route like this 192.168.2.58/32 what does the /32 mean-I know it's
subnet bits but how is it 32?  Before the dialer makes the call if I show ip
route I see it as 192.168.2.56/29(I'm 192.168.2.57 and customer is
192.168.2.58) The rest of the output show what happens when I ping the other
side with debug ppp negotiation on.  Thanks for any help.

isdn switch-type basic-ni1
!
interface BRI0/0
 ip address 192.168.2.57 255.255.255.248
 encapsulation ppp
 isdn spid1 9258255950
 isdn spid2 9258255957
 dialer idle-timeout 57
 dialer map ip 192.168.2.58 name customer 1904296
 dialer-group 1
 ppp chap hostname service
 ppp chap password xxx

ping 192.168.2.58
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.2.58, timeout is 2 seconds:
FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5312&t=5295
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: CIT Exam Cram Book [7:5294]

2001-05-21 Thread Adam Hickey

e=Book&prodID=51773969


http://shop.barnesandnoble.com/booksearch/isbnInquiry.asp?userid=0JY02VDQIQ&m
scssid=T2QP66PW0SM18LRP0JSELXN3QLCS2T6D&isbn=1576106810


http://www1.fatbrain.com/asp/bookinfo/bookinfo.asp?theisbn=1576106810&vm=


http://www.elgrande.com/elgrande/book_product.asp?sku=856814&session=C8HAJTN2
9ESR2PCG00A4005R0K115PJ0&searchstr=exam+cram+ccnp&smethod=contain&criteria=ti
tle


(watch the word wrap)


Adam Hickey
[EMAIL PROTECTED]
_
Before you criticize someone, make sure to walk a mile in their shoes.
That way, when you do criticize them, you're a mile away and you have their
shoes.



- Original Message -
From: ; "Michael (CAP, AFS, Contractor)"

To: 
Sent: Monday, May 21, 2001 11:32 AM
Subject: CIT Exam Cram Book [7:5294]


> Does anyone out there have a copy of the CIT Exam Cram book ?  Does anyone
> know where to obtain a copy.  I can't seem to find a copy in print
> anywhere...[borders/barnes/etc.]
>
> thanks in advance
>
> Mike
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5313&t=5294
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: vlans 1-1000 are automatically transported [7:5311]

2001-05-21 Thread Darren Crawford

Try using "sh trunk" to see what you're looking for.

Darren

At 03:11 PM 05/21/2001 -0400, Reel, JohnX wrote:
>Comrades,
>
>I have one quick question that I have not been able understand so far... can
>someone please help with an answer or a direction pointer. I appreciate your
>help.
>
>(1) CAT5509 as a reference
>(2) Cisco "Building Cisco Multilayer Switched Networks," book by Karen Webb,
>page 106.
>
>
>The Cisco book states ~"vlans 1-1000 are automatically transported... even
>if a range was specified... one must use the "clear" command to remove the
>unnecessary vlans".
>
>When two test vlans are added to the 5509 and then the "show vlan" command
>is used, I do not see where "unnecessary' vlans have been added.  Note that
>example:
>
>1   default   active 3   3/1-12
>   5/1-2
>   7/1-3
>2   jr_vlan2  active 146 5/9-16
>3   jr_vlan3  active 146 5/17-25
>...
>
>John L. Reel
>Intel-Gigabit Lab
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



***
Darren S. Crawford
Lucent Technologies Worldwide Services 
2377 Gold Meadow WayPhone: (916) 859-5200 x310 
Suite 230   Fax: (916) 859-5201 
Sacramento, CA 95670Pager: (800) 467-1467 
Email: [EMAIL PROTECTED] Epager: [EMAIL PROTECTED] 
http://www.lucent.com   Network Systems
Consultant - CCNA, CCIE Written

"Providing the Power Operable Networks."


***
"Ham and Eggs - A day's work for a chicken; A lifetime commitment
for a
pig."




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5316&t=5311
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



startup config issue [7:5314]

2001-05-21 Thread Justin Lofton

If I reload router it doesn't bring up the startup config.  What should I
check or change to fix this.

Thanks everyone.

Justin Lofton
Account Executive/CCNA
Tredent Data Systems
[EMAIL PROTECTED]
(818) 222-3770
http://www.tredent.com/




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5314&t=5314
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Newbie question [7:5309]

2001-05-21 Thread Darren Crawford

Yes it's an ARP issue.  I bet your PIX has the following line:

arp timeout 14400  (equal 4 hours in seconds)

The other parameters for timeout settings are something like the following:

timeout xlate 1:00:00 conn 1:00:00 udp 0:02:00
timeout rpc 0:10:00 h323 0:05:00
timeout uauth 0:05:00 absolute

Darren


At 03:08 PM 05/21/2001 -0400, Roger wrote:
>My ISP just placed a new router outside of our PIX 515, and now, every 4
>hours, the PIX loses connectivity and needs to be rebooted.  Is this an ARP
>problem (is it looking for the mac of the old server)?  Any info would be
>appreciated.  Thanks.
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



***
Darren S. Crawford
Lucent Technologies Worldwide Services 
2377 Gold Meadow WayPhone: (916) 859-5200 x310 
Suite 230   Fax: (916) 859-5201 
Sacramento, CA 95670Pager: (800) 467-1467 
Email: [EMAIL PROTECTED] Epager: [EMAIL PROTECTED] 
http://www.lucent.com   Network Systems
Consultant - CCNA, CCIE Written

"Providing the Power Operable Networks."


***
"Ham and Eggs - A day's work for a chicken; A lifetime commitment
for a
pig."




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5315&t=5309
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: startup config issue [7:5314]

2001-05-21 Thread Laszlo Csosza

Hi!

press break while booting up, and check the config register...


--

cU,

Laszlo Csosza


""Justin Lofton""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> If I reload router it doesn't bring up the startup config.  What should I
> check or change to fix this.
>
> Thanks everyone.
>
> Justin Lofton
> Account Executive/CCNA
> Tredent Data Systems
> [EMAIL PROTECTED]
> (818) 222-3770
> http://www.tredent.com/
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5317&t=5314
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: "network logon problems" [7:5271]

2001-05-21 Thread Donald B Johnson jr

I don't believe that it is a catalyst problem, I think it is a MS problem.
Try logging in with a different account on same station, then try logging in
with same account on different station. Users are just logging in using a
cached account. Try this also, create a new account then log in at the
station using this account and see if you can authenticate to the domain.
Obviously that account won't be cached at the station. It has been sooolong
since I worked an NT domain but I beleive there is a check box having to do
with a slow network connection that will use the cached account somewhere.
Thank You,

Don Johnson
Engineering
Adelphia Communications Corp.
P# 814-260-3259 office
P# 814-274-9391 lab
F# 814-260-3227
[EMAIL PROTECTED]

---
This email is composed of 82% post consumer recycled data bits
---

- Original Message -
From: "Robert Perez" 
To: 
Sent: Monday, May 21, 2001 10:01 AM
Subject: "network logon problems" [7:5271]


> HELP!!
> I have an issue where it appears that multiple users cannot login.  I
> receive the error "you will be logged on using a cached account" and once
> logged on, all network devices are available.  I have ensured that on the
> catalyst 3548XL, all ports have Port fast enabled and I have also enabled
> STP to try and overcome the problem with no success.  I have also moved
the
> users to switches that have no issues and I still have the same problem.
I
> also did a ipconfig /release renew and replaced the nic card and did a
cold
> boot and warm boot on the machines with no success.  All other user are
fine
> and it is only affecting like 3 people.  I even set them to auto, auto and
> the switch to auto,auto and this did not work either.  I then tried 100
full
> and half and that did not work either.  I also do not have port security
> enabled.  It appears to be a network issue with the catalystr switches,
but
> I am unsure as to the root of the problem.Don't know if this would do
> anything, but I did a NBTSTAT -RR from the command line as well.  Any help
> would be greatly appreciated.Thank you.
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5318&t=5271
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



ATM in Lab [7:5319]

2001-05-21 Thread No Data

Ive never worked with ATM before and would like to
start playing with it in my home lab.  Do I need to
buy an LS1010 (or LS100) or can I do all the
configuration stuff that is necessary with an MC3810? 
I havent really been able to differentiate between the
two products all that much yet (of course I dont have
any ATM xp either).

Ben

__
Do You Yahoo!?
Yahoo! Auctions - buy the things you want at great prices
http://auctions.yahoo.com/




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5319&t=5319
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: my head hurts! (Terminal server) [7:5245]

2001-05-21 Thread Alan Melick

George,

Sorry if this hits twice.  

When someone on that router types in CONNECT a menu will be displayed.  The
'text' is what's displayed in the menu so they would see...

1 Cisco 2912 LAN Switch #3 
2 Cisco 2912 LAN Switch #4 

If they type in a 1 it will execute the command associated with 1 (ie.
telnet 10.1.1.12 2001)  This doesn't telnet 'out' e0, it telnet's to
10.1.1.12 port 2001.  Port 2001 just happens to be the first async port on a
2511.  Look in the doc's for more information on this.  Basically if someone
chooses 1 then they will be connected to whatever's physically connected to
that first async cable (probably the console on Lan Switch 3).

Good luck!

--Alan

George Dodds wrote:
> 
> Can someone explain how the following excerpt from a
> menu on a 2511 being used as a terminal server works!
>   
> I know that traffic is being passed through e0 using
> the specified port, but i need to know how the hell it
> manages to get to the specified switches.   
> 
> menu CONNECT text 1 Cisco 2912 LAN Switch #3
> menu CONNECT command 1 telnet 10.1.1.12 2001
> menu CONNECT text 2 Cisco 2912 LAN Switch #4
> menu CONNECT command 2 telnet 10.1.1.12 2002
> 
> 
> interface Ethernet0
>  ip address 10.1.1.12 255.255.255.0
>  no ip redirects
>  no ip directed-broadcast
>  no ip proxy-arp
>  no cdp enable
> 
> Thanks in advance from one of the ignorant masses!!
> 
> 
> 
> =
> George Dodds
> 
> CCNA, MCP
> 
> __
> Do You Yahoo!?
> Yahoo! Auctions - buy the things you want at great prices
> http://auctions.yahoo.com/
> 
> 




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5321&t=5245
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



RE: PIX question... [7:5248]

2001-05-21 Thread Darren Crawford

OK kids.  Allowing packets from a lower security level interface to a higher
security level interface requires a conduit or access list.  So yes, it can
be
done.  I wouldn't forget about security though.  ;^)

D.

At 01:50 PM 05/21/2001 -0400, Rizzo Damian wrote:
>Actually it seems as if you understand exactly what I'm asking. Your idea is
>very similar to mine. However it didn't work unfortunately. Let me ask this
>another way, if you don't mind...You have an internet router which is
>directly connected to the external (un-trusted) interface of your PIX
>firewall. Basically I want to be able to access my internal LAN with private
>IP addresses from the Internet router with Public IP addresses. So I should
>be able to telnet onto my internet router and ping my privately held LAN.
>Forget about Security, I just want to know if it can be done. The static
>mapping doesn't seem to work. Probably because it require a one-to-one
>mapping no?   Thanks for any help in advance!
>
>
>
>  -Rizzo
>
>
>
>
>
>-Original Message-
>From: Craig Columbus [mailto:[EMAIL PROTECTED]] 
>Sent: Monday, May 21, 2001 1:12 PM
>To: [EMAIL PROTECTED]
>Subject: RE: PIX question... [7:5248]
>
>I'm not clear on what you're asking.  Are you asking if the PIX can take a 
>public IP and make it appear as a private IP on the internal network?  The 
>answer is yes, although you certainly want to be careful with this and I 
>can't say that this is a recommended config.  You'll need a config similar 
>to the one below:
>
>nat (outside)  1 0 0
>static (inside,outside)  
> netmask 255.255.255.255
>access-list  permit ip any host 
>
>For more info, reference 
>http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v52/config/exa
>mples.htm#xtocid274896
>
>Thanks,
>Craig
>
>At 12:14 PM 5/21/2001 -0400, you wrote:
>>We are aware of the VPN solution and that is our long term goal. However,
>>for the moment, all I need to know is if it is possible to NAT from an
>>outside (not trusted) interface to an inside (trusted) interface.
>>
>>  Thank you!
>>
>>   -Rizzo
>>
>>
>>
>>
>>-Original Message-
>>From: Craig Columbus [mailto:[EMAIL PROTECTED]]
>>Sent: Monday, May 21, 2001 11:44 AM
>>To: Rizzo Damian
>>Cc: [EMAIL PROTECTED]
>>Subject: Re: PIX question... [7:5248]
>>
>>Sounds like a VPN is your best bet.
>>Should you decide to implement the VPN, you may want to consider whether
>>you still need to maintain the modem pool on the Internet router.  Reducing
>>this cost could help justify the cost of implementing a VPN solution.  A
>>properly authenticated VPN user should be able to use any dial-up Internet
>>connection to reach your LAN.
>>
>>Craig
>>
>>At 10:15 AM 5/21/2001 -0400, you wrote:
>> >Hey all, is it possible to translate public IP addresses (outside) to
>> >private IP addresses (inside) on a PIX firewall. Basically the exact
>> >opposite of what's usually performed on a firewall. We are going to have
>> >users dial in to our internet router and receive a Public IP address.
>They
>> >have to get through our firewall to gain access to our LAN. Is there a
>way
>> >to translate the Public IP address they will obtain into a private IP
>> >address used by our LAN so they can access it?  I thank you for your
>>help...
>> >
>> >
>> >   -Rizzo
>> >FAQ, list archives, and subscription info:
>> >http://www.groupstudy.com/list/cisco.html
>> >Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>>FAQ, list archives, and subscription info: 
>>http://www.groupstudy.com/list/cisco.html
>>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>FAQ, list archives, and subscription info:
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>FAQ, list archives, and subscription info: 
>http://www.groupstudy.com/list/cisco.html
>Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



***
Darren S. Crawford
Lucent Technologies Worldwide Services 
2377 Gold Meadow WayPhone: (916) 859-5200 x310 
Suite 230   Fax: (916) 859-5201 
Sacramento, CA 95670Pager: (800) 467-1467 
Email: [EMAIL PROTECTED] Epager: [EMAIL PROTECTED] 
http://www.lucent.com   Network Systems
Consultant - CCNA, CCIE Written

"Providing the Power Operable Networks."


***
"Ham and Eggs - A day's work for a chicken; A lifetime commitment
for a
pig."




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5322&t=5248
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



Re: Passed BCMSN [7:4546]

2001-05-21 Thread Kevin Schwantz

Please don't get me wrong, I am not advocating memory work without any hands
on experience. I just wanted to correct the person who mentioned that one
requires practical experience to pass the BCMSN exam. If I had a choice, I
would have loved to build a multilayer swithching lab to practice on, but
the truth of the matter is that I did not have the resources. If I had put
that obstacle in my path , I would have never gotten my CCNP.I pursued my
CCNP for the purpose of gaining sound fundamentals in networking issues and
to see the broader picture. I strongly believe that if want to pursue a
certification to prove your salt in "hands on" work, go take the CCIE.
 I really wonder why employers don't set up a lab tests to select  job
canidates.

Kevin Schwantz


""John Andrews""  wrote in message
[EMAIL PROTECTED]">news:[EMAIL PROTECTED]...
> I guess I will be first.  I am also memorizing and studying in hopes of
> passing my switching exam with no experience.  I currently work for a very
> small company with ten 95 computers and 15 or so unix machines on a unix
> server.  My main job is to unsnag people who lock their computers up and
to
> print reports.  But, I am studying for my tests.  Hopefully one day, when
I
> finish I can gain some real networking experience.  In the meantime, I am
> learning the unix language and have learned great self restraint of the
> defined art of self control when wanting to strangle users.  You just keep
> plugging away, but, noone I don't think would ever say that practical
> networking experience is not a valuable asset to have..it's just that some
> of
> us don't have a choice.  But you don't quit trying.
>
> And that's my two cents:
> John Andrews
>
> >= Original Message From "Sudarshan Narasimhachari"
>  =
> >Kevin et all Brain dump people out there,
> >
> >I have no comments on your ability to memorise a whole book. What we
> >are talking here about is real achievements. I hope people in this
> >group will agree with me in the difference between real experience and
> >knowledge and just brain dumps.
> >
> >I know there are going to be fumes on this now. Let them come:-)
> >
> >- Sudarshan
> >
> >-Original Message-
> >From: Kevin Schwantz [mailto:[EMAIL PROTECTED]]
> >Sent: Thursday, May 17, 2001 11:06 AM
> >To: [EMAIL PROTECTED]
> >Subject: Re: Passed BCMSN [7:4546]
> >
> >
> >I passed BCMS with only a book. Never configured a switch before. You
> >just
> >have to memorise it all.
> >
> >
> >Kevin
> >
> >
> >__
> >Do You Yahoo!?
> >Yahoo! Auctions - buy the things you want at great prices
> >http://auctions.yahoo.com/
> >FAQ, list archives, and subscription info:
> http://www.groupstudy.com/list/cisco.html
> >Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]
>
> Have a great day!
> John A
> FAQ, list archives, and subscription info:
http://www.groupstudy.com/list/cisco.html
> Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=5247&t=4546
--
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]



  1   2   >