Re: Ping ethernet interface with datagram over 1500 [7:63085]

2003-02-14 Thread M.C. van den Bovenkamp
Sean Kim wrote: > There isn't any problem with connection of performance. But I am very > curious about why this is happening. > Does anybody have any idea why this would happen? Or can anybody give me a > clue as to how to approach this problem? Think MTU difference. Regards,

Ping ethernet interface with datagram over 1500 [7:63085]

2003-02-14 Thread Sean Kim
Hello, My company has this 3rd party connection through ATM. The ATM TA has an ethernet outlet which is and connected to our core router. Our parner company is connected with anATM module on their router. Recently, I was told by our partner company that they were running ping test and they could

Re: Layer3 Routers VS Switches [7:63072]

2003-02-14 Thread Larry Letterman
L3 is usually considered to be wire speed and uses faster asics... Routers such as 7200/7500 use older slower hardware to route... Larry Letterman Network Engineer Cisco Systems - Original Message - From: "Nanda" To: Sent: Friday, February 14, 2003 4:46 PM Subject: Layer3 Routers VS

RE: access-group difference [7:62769]

2003-02-14 Thread Ismail Al-Shelh
Well am again confused, because the thing which was in my mind that access-group acl_in in interface inside means that the access-list binds to the inside interface for the outbound traffic not the inbound traffic! I agree that the command access-group acl_out in interface outside mean that the a

RE: access-group difference [7:62769]

2003-02-14 Thread Ismail Al-Shelh
Thanks Priscilla, the " fist example permits TCP coming into the outside interface. The second example permits traffic coming into the inside interface." Made the concept clear. Thanks again. Ismail Al-Shelh Abdulla Fouad Company Network Engineer CD-Dammam -Original Message- From: Pri

Re: Dropped Packet on 6506 switch [7:63053]

2003-02-14 Thread The Long and Winding Road
""Priscilla Oppenheimer"" wrote in message news:[EMAIL PROTECTED]... > If nothing's plugged in, it has to drop the packets!?! :-) Are you sure this > isn't normal? Being a switch, it shouldn't be sending any unicasts out the > port, because it couldn't have learned a MAC address that is out that p

Setting Privilege Levels for Users [7:63073]

2003-02-14 Thread Jason Steig
I'am working on a Boson's CCIE lab with a friend and we are working on setting up privilege levels for users who need to telnet to the router. User1 needs to have access to just the user level commands nothing more. User2 needs access to all the commands that user 1 has access to as well as about

Re: Connecting two small offices [7:63042]

2003-02-14 Thread Brad Ellis
A couple of PIX 501s would be a really good solution for you. If you are running call mangler at one or both locations, you could also tie some of the voice solution together as well. How many PCs do you have at each location? If you only have one PC at one of the locations, you could probably j

Pix 501 or 520? [7:63078]

2003-02-14 Thread K Ali
Hi all, Just want to clear that which Pix Firewall is being used in the following modules. 1. Cisco Security specialist. 2. Cisco VPN specialist. 3. Cisco IDS specialist. Is it 501 or 520? Because at the moment I have got the optionto buy 501 or 520. So which one I should go for? Message Pos

Re: Cataylst 5505 or 3500 [7:62927]

2003-02-14 Thread K Ali
Thanks alot guys for your help. Regards, K. Ali ""Jens Neelsen"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > Hi, > > my answer to this question is: You need both 5000 and 3550. > > The 5000 switch is used for CCNP now. and usd in many > installations. > > The 3550 switch is

Re: VPN & Cisco Secure PIX Firewall [7:63013]

2003-02-14 Thread Zeke Gibson
Sure, Main Cisco PIX IPsec config examples: http://www.cisco.com/en/US/tech/tk583/tk372/tech_configuration_examples_list .html Simple PIX-to-PIX tunnel: http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration _example09186a0080094761.shtml Best of luck, -Zeke Sonic Networ

Layer3 Routers VS Switches [7:63072]

2003-02-14 Thread Nanda
Hi Guys... We have Layer3 Switches and routers...In what scenario one would ideally use Layer3 switches over routers.. Do They have any significant advantage over using routers Why do they have layer3 switches when we have routers are good enough to do the job... I am confused...I wud apprecia

RE: FTP site needed for MPLS for 2500 files [7:63070]

2003-02-14 Thread Dennis Laganiere
As long as it's available to everybody, that's good enough for me. Thanks... --- Dennis -Original Message- From: Aidan Marks [mailto:[EMAIL PROTECTED]] Sent: Friday, February 14, 2003 12:34 PM To: Dennis Laganiere Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED] Subject: Re: FTP site needed fo

H.323 and gatekeer [7:63069]

2003-02-14 Thread J B
Can someone please help me to understand the following terms. H323 and Gatekeeper. I have a polycom video conferencing equipment and I'm trying to set up a IP to IP video connection between two cities. The conection works, but the quality is very bad a lot of jitter and delay. I was told by the

Re: explain these ACLs [7:62843]

2003-02-14 Thread The Long and Winding Road
""Barbu Alexandru"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > Ok! Pay attention that the access-list that is > actually applied to the interface for inbound traffic > is access-list 194, which denies all ip traffic. > > Now lets see what the other access-lists do. > >

RE: Cisco works 2000 cd one 5th Edition [7:63023]

2003-02-14 Thread Mung Go
I tried to upgrade Ciscoworks 2000 cd one from 4th edition to 5th edition, I experienced a lot of problem. Also, I prefer to have fresh install rather than upgrade. You can backup your database and restore it back after your Ciscoworks2000 is newly installed. Message Posted at: http://www.groupst

Re: Dropped Packet on 6506 switch [7:63053]

2003-02-14 Thread Sam Sneed
I'm not sure what you mean by hybrid mode. I have the sh ver, sh mod, sh ver for MSFC and below. I have nothing plugged into at leat 3 ports which still report dropped packets. 800,000 daily. Whats strange is that the 800,000 is almost the same on all 3 ports. I have disabled them since then but w

Re: explain these ACLs [7:62843]

2003-02-14 Thread Barbu Alexandru
Ok! Pay attention that the access-list that is actually applied to the interface for inbound traffic is access-list 194, which denies all ip traffic. Now lets see what the other access-lists do. access-list 195 deny udp any gt 1024 any eq 1434 access-list 195 permit ip any any This

RE: Deleted PVC still works [7:63055]

2003-02-14 Thread Mung Go
Try clear frame-relay map, or clear frame-relay pvc, etc Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63064&t=63055 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Non

Re: Dropped Packet on 6506 switch [7:63053]

2003-02-14 Thread MADMAN
Not real clear on your description. You see dropped packets on interfaces with nothing plugged in!? Since you refer to the 6500 as a switch I assume your running hybrid mode. You also mention there is an MSFC. I ASSume again that your seeing drops on the L2 interface but with nothing plugge

Re: Deleted PVC still works [7:63055]

2003-02-14 Thread The Long and Winding Road
""McHugh Randy"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > Happy Valentines everyone > I have a deleted PVC that still works to connect through a frame switch to > another router. Anyone else seen this? > Here is the config > r1#sh frame pvc 401 > > PVC Statistics for interfa

RE: Connecting two small offices [7:63042]

2003-02-14 Thread Aaron Ajello
Sonicwall makes a good, inexpensive product for this kindof thing. http://www.sonicwall.com/products/vpnapp.html Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63061&t=63042 -- FAQ, list archives, and subscription info: http://www.

Re: Update of Anti-Mime Software [7:63043]

2003-02-14 Thread The Long and Winding Road
""Ken Diliberto"" wrote in message [EMAIL PROTECTED]">news:[EMAIL PROTECTED]... > The first line was just a link. I guess the system didn't like it. > This was it: > > http://www.csupomona.edu/~ken/website/TII/tiigeneral/index.htm > > >>> "Ken Diliberto" 02/14/03 10:22AM >>> > Just a quick link

Re: Deleted PVC still works [7:63055]

2003-02-14 Thread John Neiberger
Do a show cdp neighbor and verify that the both endpoints are where you think they are. Obviously, the ACTIVE side in the output below is where you think it is, but I'd bet money that the opposite endpoint is not r1 as shown below, or at least not on s0. On R1, did you move your cable from Seri

RE: Connecting two small offices [7:63042]

2003-02-14 Thread [EMAIL PROTECTED]
501's are great for that... Or OpenBSD !!! Wonderful and Free!!! -Original Message- From: Symon Thurlow [mailto:[EMAIL PROTECTED]] Sent: Friday, February 14, 2003 10:45 AM To: [EMAIL PROTECTED] Subject: RE: Connecting two small offices [7:63042] PIX 501 would be a good Cisco solutio

OT: Cisco Sale [7:63057]

2003-02-14 Thread NetEng
No work for 7 months plus tuition due means my lab must go. I would prefer to sell complete, but will separate. Here is what I have: CS-500 (16 ports although one is bad. It was that way when I got it) 2501 16/16 flash/ram w/ 12.0(21a) IOS 2504 16/16 flash/ram w/ 12.0(21a) firewall/IDS IOS 2521 16

Re: FTP site needed for MPLS for 2500 files [7:63056]

2003-02-14 Thread Aidan Marks
The 2500 mpls images are available here: ftp://ftp-eng.cisco.com/rraszuk/specials/ They have been there for a while. What more do you need? Aidan At 07:09 AM 15/02/2003, Dennis Laganiere wrote: >A few months ago I put together a free document for loading an experimental >version of IOS that al

Deleted PVC still works [7:63055]

2003-02-14 Thread McHugh Randy
Happy Valentines everyone I have a deleted PVC that still works to connect through a frame switch to another router. Anyone else seen this? Here is the config r1#sh frame pvc 401 PVC Statistics for interface Serial0 (Frame Relay DTE) DLCI = 401, DLCI USAGE = LOCAL, PVC STATUS = DELETED, INTERFACE

FTP site needed for MPLS for 2500 files [7:63054]

2003-02-14 Thread Dennis Laganiere
A few months ago I put together a free document for loading an experimental version of IOS that allows you to run MPLS on cheap 2500 series routers. I didn't create the software, I just gave instructions for installing it and then pointed out where the files were, for anybody who wanted to play wit

Dropped Packet on 6506 switch [7:63053]

2003-02-14 Thread Sam Sneed
Hello, I'm seeing strange things on a 6500 switch. I see dropped pakets and int errors on interfaces with no servers plugged in. These are of signifcant amounts and I believe tis causing problems.We're talking about 800,000 in 24 hours. Does anyone have any idea on what this happens on INT that ar

Re: Update of Anti-Mime Software [7:63043]

2003-02-14 Thread Ken Diliberto
The first line was just a link. I guess the system didn't like it. This was it: http://www.csupomona.edu/~ken/website/TII/tiigeneral/index.htm >>> "Ken Diliberto" 02/14/03 10:22AM >>> Just a quick link test. These are pictures of our construction project to upgrade the network. >>> "Paul Bor

Re: IOS 12.2 Prob?? [7:63016]

2003-02-14 Thread adil
Had the same problem, just upgrading to c1700-y-mz.122-8.T5.bin helped resolve the issue. Thanks ADIL - Original Message - From: To: Sent: Friday, February 14, 2003 4:19 AM Subject: IOS 12.2 Prob?? [7:63016] > Hi.. > > i am trying to configure a 1721 with wic 2 A/S for Async Dialin.

Re: Update of Anti-Mime Software [7:63043]

2003-02-14 Thread John Neiberger
[The above is a completely OT link intended for testing purposes only. It is included again below for further testing.] http://www.denverpost.com/broncos/broncos.htm Ken, it appears that your link was munged. I've sent three links this morning to a test queue and all arrived correctly. Paul

RE: Snort versus Cisco IDS [7:62939]

2003-02-14 Thread Will Gragido
Exactly! Great points Paul, SNORT truly is top drawer. There are so many good reasons to use it (price, continual updates etc.). I would advise anyone interested in IDS though to consider using two variants (signature based, anomaly based, application behavior based et al). This will provide a

RE: Snort versus Cisco IDS [7:62939]

2003-02-14 Thread Will Gragido
I love NESSUS, again, not that commercial products aren't or can't be as good, but it seems to me that open source tools (for reasons we've mentioned often here), win out in the end. Will Gragido CISSP CCNP CIPTSS CCDA MCP 9450 W. Bryn Mawr Ave. Suite 325 Rosemont, Il 60018 www.ins.com [EMAIL PR

Re: Update of Anti-Mime Software [7:63043]

2003-02-14 Thread Ken Diliberto
Just a quick link test. These are pictures of our construction project to upgrade the network. >>> "Paul Borghese" 02/14/03 08:43AM >>> Ok, I updated our anti-mime software. Let's see if that fixes the problem of having a URL on the first line. I personally have not been able to duplicate the

Re: Connecting two small offices [7:63042]

2003-02-14 Thread Michael Linehan
In the case of the PIX 501 would you set up a box at each site and make them peers? Or would you set up one office with the 501 and make the other a slave? Or (as I am assuming) is it possible to do it either way? Thanks, Michael Linehan Systems Consultant Alignex, Inc. 952-224-5344 - Origina

RE: Connecting two small offices [7:63042]

2003-02-14 Thread Symon Thurlow
PIX 501 would be a good Cisco solution, or you could go for a linux based FW on a PC, such as Ipcop. Symon -Original Message- From: Michael Linehan [mailto:[EMAIL PROTECTED]] Sent: 14 February 2003 16:13 To: [EMAIL PROTECTED] Subject: Connecting two small offices [7:63042] Great networ

Update of Anti-Mime Software [7:63043]

2003-02-14 Thread Paul Borghese
Ok, I updated our anti-mime software. Let's see if that fixes the problem of having a URL on the first line. I personally have not been able to duplicate the problem. Please send me any bug reports! Paul -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of

Connecting two small offices [7:63042]

2003-02-14 Thread Michael Linehan
Great networking guru's: I have not done much in the way of networking small offices together. I would imagine that a private WAN link will be too expensive for the company. What are the logical options as far as setting up VPN between two small offices that have DSL level bandwidth? Thanks, Mich

RE: Snort versus Cisco IDS [7:62939]

2003-02-14 Thread Kent Hundley
BTW, for the record I am personally a big fan of snort. Snort is what I use on my own home network. But then I'm a tech geek with limited funds, so it fits my needs perfectly. ;-) Regards, Kent On Fri, 2003-02-14 at 10:32, Kent Hundley wrote: > The term "team" was meant to by inclusive of engine

Re: Snort versus Cisco IDS [7:62939]

2003-02-14 Thread steve
hi, it`s even worse than you thought... the unix director no longer exsists ... the policy manager has now gone,and is now included as part of the new ciscoworks VPN/Secuirty 2.1 SUITE of software...and you can`t get it seperatly.. . the ids hook into OV simple report`s message

RE: Snort versus Cisco IDS [7:62939]

2003-02-14 Thread Kent Hundley
The term "team" was meant to by inclusive of engineers as well as sales. I can assure you I have talked to many competent Cisco engineers, some of them who specialize in security, who do in fact recommend the Cisco IDS to their large clients. And yes, salespeople will obviously always push thei

Quick Newbie question [7:63031]

2003-02-14 Thread [EMAIL PROTECTED]
Does the IOS/CatOS/PIX config files support commented-out descriptions? Thanx mkj Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63031&t=63031 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.ht

Re: Catalyst 6500 vs 7200 VXR [7:62892]

2003-02-14 Thread [EMAIL PROTECTED]
We are pretty happy with 6509 switches. Before that, 7507 routers were responsable for packet forwarding ( more or less 96 Mbps of inter-vlan traffic). My only concern is about using 6509 on a MPLS backbone. From what I have search, it is necessary a specific card. "Peter van Oene" @groupstu

Re: Easy question [7:63002]

2003-02-14 Thread Kevin O'Gilvie
You need to enter config reg 0x2102 depends on the router.. What kind of router? - Original Message - From: "Johnson, Richard (NY Int)" To: Sent: Thursday, February 13, 2003 11:21 PM Subject: Easy question [7:63002] > Hi all, > > > Every time I boot my router, it asks if I want to confi

Re: CCIE and Packet (the cut'n'paste from hell!) [7:62998]

2003-02-14 Thread bergenpeak
Scanning the exam topics, specifically the second to last bullet item: Optical Networking Designs Describe the scalability issues of using OSPF and IS-IS as interior gateway protocols in a service provider network and list solutions for each What do IGPs have to do with optical network de

RE: CCIE and Packet (the cut'n'paste from hell!) [7:62998]

2003-02-14 Thread Paul Borghese
In this case the issue is the URL spans more the 72 characters which is the size most e-mail clients use as a width of a message. When you cut/paste you do not capture the entire URL. But this is not GroupStudy's faults, it is the fault of the client software. But there is a case where GroupStud

Re: Qos [7:63014]

2003-02-14 Thread [EMAIL PROTECTED]
You could configure LLQ for audio; but for video, I have seem some articles saying that video could starve other traffic. One approach would be limit your video, for example 200 Kbps, using CAR, and after that apply LLQ. Regards,

RE: Ethernet/Server Issues [7:62940]

2003-02-14 Thread taz taz
Hi catalyst 3548 they have been taking off the market , and that been replast with 2948 The have this problem ( dropping packet ) in the interface if you type show interface 0/ X You will notes the dropped packet Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63025&t=62940 -

RE: Ethernet/Server Issues [7:62940]

2003-02-14 Thread taz taz
Hi catalyst 3548 they have been taking off the market , and that been replast with 2948 The have this problem ( dropping packet ) in the interface if you type show interface 0/ X You will notes the dropped packet Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63024&t=62940 -

Cisco works 2000 cd one 5th Edition [7:63023]

2003-02-14 Thread Tim Champion
I am trying to upgrade to CW2000 5th edition but am having some problems. When attempting to suspend all jobs using: cwjava -cw install_directory com.cisco.nm.cmf.jrm.DisableJobs I recieve the following message: "unable to launch JVM" Has anyone else run into this problem? Many thanks in advan

Re: MPLS and CEF [7:62993]

2003-02-14 Thread John Murphy
MPLS uses the CEF table adjacencies in establishing a Label Switched Path. Additionally, each VPN Routing and Forwarding (VRF) uses a derived CEF table, in addition to its own forwarding table. There's a pretty good list 'mpls-ops' hosted at mplsrc.com if you want to get more involved in MPLS. J

RE: flapping of trunk ports (trunk non-trunk) [7:62951]

2003-02-14 Thread Walker, James - Is
I have seen this problem before. Basically you have a layer 1 problem thus, your fiber. Some possible problems to look at: 1. Is your fiber longer than IEEE standard? With GBIC-SX, 550m for multi-mode With GBIC-LH, 300m for multi-mode With GBIC-LH with modal cable, 550m for multi-mode With GBIC

Re: MPLS and CEF [7:62993]

2003-02-14 Thread Anne Beatriz
Hello, I think MPLS require CEF because some mechanisms like: Packets are switched in the interrupt code using the CEF cache (FIB table). It supports per-packet load balancing (previously only supported by process switching), per-source/destination load balancing (only supported by CEF switching),

RE: Snort versus Cisco IDS [7:62939]

2003-02-14 Thread DeVoe, Charles (PKI)
2) Has never talked to any of the Cisco teams that manage large global accounts Of course these are sales people. Sales people make their livelihood off of the sales. So obviously, they will push the product. Rule 1. Never trust a salesperson. Rule 2. Never Believe a salesperson. Rule 3. N

RE: flapping of trunk ports (trunk non- [7:62951]

2003-02-14 Thread Luca Ciasca
ahmed, thank you for your feedback. My msfc is the 12.1(6)E1 version, anyway you'll find below the "show version" on the L3 routing engine of my 6509. I'he searched in the Cisco bug tool at: http://www.cisco.com/cgi-bin/Support/Bugtool/launch_bugtool.pl but I've not found any reference to any tr

Re: flapping of trunk ports (trunk non-trunk) [7:62951]

2003-02-14 Thread Luca Ciasca
Larry, thank you for your feedback. I have found that the "nonegotiate" is considered just a temporary workaround in this cisco document: www.cisco.com/networkers/nw00/pres/2807_6-28.pdf Anyway I'll check the g-bics. Thanks again Luca Message Posted at: http://www.groupstudy.com/form/read.ph

IOS 12.2 Prob?? [7:63016]

2003-02-14 Thread [EMAIL PROTECTED]
Hi.. i am trying to configure a 1721 with wic 2 A/S for Async Dialin. i am running the IOS 12.2 (c1700-y-mz.122-4.YA2.bin) the strange thing i see is that there is no command to configure a Modem, i wanted to enter modem autoconfigure discovery or modem autoconfigure type. it just does not allow m

Re: Easy question [7:63002]

2003-02-14 Thread Larry Letterman
if the config register is set incorrectly and pointing at something like 0x2142, it will always boot up and bypass the nvram config file. You need to change it back to 0x2102. Larry Letterman Network Engineer Cisco Systems - Original Message - From: "Will Gragido" To: Sent: Thursday,

Qos [7:63014]

2003-02-14 Thread Projet AIM
Hi all, I have a project on a cisco 3620 router and I want to know how can i configure the quality of service on this router to priviledge the video traffic over the other sincerly PIPPOO _ MSN Search, le moteur de recherche qui p