Re: IDS Sensors [7:74442]

2003-08-29 Thread dre
""Lupi, Guy"" wrote in message ... > I am not a security specialist, so please bear with me if this is what every > IDS device does. I am looking for advice/opinions on a device that can > accomplish the following, I was looking at the Cisco 4250 XL IDS sensor. > > Inspect over 400 Mbps of traffi

CCNA two step--exam reviews [7:74465]

2003-08-29 Thread Andy Barkl
Are you preparing to take the new CCNA exams 640-821 (INTRO) and 640-811(ICND)? I offer my exam reviews to help you along the way. http://www.tcpmag.com/Exams/article.asp?EditorialsID=79 http://www.tcpmag.com/Exams/article.asp?EditorialsID=80 Good luck! Message Posted at: http://www.groupstud

Catalyst 6500 Architecture [7:74460]

2003-08-29 Thread neil K
Folks, The Catalyst 6500 uses a Shared bus Architecture and to increase the Backplane capacity you have to have Switch fabric module (SFM) with fabric Enabled modules to make it work. Is there a vendor which has a better architecture or a better solution. Thanks, neil K. Message Posted at: h

TCP/UDP port for CHAP [7:74480]

2003-08-29 Thread Thomas N
I got SOHO sites with PPPoE connection to the Internet. They use CHAP for authentication. I would like to setup an ACL to filter out traffic on the outside interface. I am wondering what TCP/UDP port CHAP protocol use? Thanks! Thomas Message Posted at: http://www.groupstudy.com/form/read.ph

802.3x switch traffic disruption [7:74455]

2003-08-29 Thread [EMAIL PROTECTED]
I need some expert option on the following matter: I have a Netgear Fast Ethernet Switch FS608 (which does 802.3x Flow control) connected to a DLink 5 port switch (no flow control) Twice this week, the FS608 locked itself causing ALL traffic in the company to be disrupted. The problem was solved

Erasing IOS from FLash [7:74459]

2003-08-29 Thread Curious
Hi I have 3 IOS images on my Cisco 2600 Router. 1 5742076 c2600-d-mz.121-5.t9.bin [deleted] 2 10574412 c2600-ds-mz.122-7.bin 3 7411544 c2600-i-mz.123-1a.bin I want to delete 2 of them. I issued the command delete flash:c2600-d-mz.121-5.t9.bin , after that i can see word deleted ap

Console port now working on 4000 [7:74489]

2003-08-29 Thread Rohit-Sundriyal\(CCNA\)
Hi All My Cisco 4000 consol port is not work any idea what whent wrong or how to make it work. Thanks in advance Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=74489&t=74489 -- **Please support GroupStudy by purchasing from th

PKI [7:74482]

2003-08-29 Thread Thomas N
I am not sure if this question is off the topic or not but hopping people can give me some suggestion. I am working on DMVPN and it seems PKI can not be missed out of the design for security purpose. I am wondering what are good PKI vendors out there? Is there any hardware appliance PKI vendor?

RE: threats etc. [7:74474]

2003-08-29 Thread Howard C. Berkowitz
At 2:23 PM -0400 8/26/03, Reimer, Fred wrote: > >I'm almost positive that the exact same material is in all four other >courses, and I hope that this is within the bounds of fair use, but page 2-4 >says: > > >There are four primary threats to network security: > >* Unstructured threats > >* Str

Re: Cisco ICS 7750 experiences [7:74481]

2003-08-29 Thread [EMAIL PROTECTED]
I just deployed one for a single site manufacturing new construction. 150 IP phones 7940s / 7960s, IPCC, Unity Unified, etc. It took me about two days to get all of the builds completed because of the patches you have to add, but I got it configured pretty quick and, once it was up and I was maki

RE: Re: Thank you! [7:74488]

2003-08-29 Thread [EMAIL PROTECTED]
Dear [EMAIL PROTECTED] The email that you sent to [EMAIL PROTECTED] did not reach the intended receipient due to existance of virus. Kindly have your computer check for virus. Best Regards, Mail Administrator Datacraft Asia Ltd Message Posted at: http://www.groupstudy.com/form/read.php?f=7&

Choosing Cisco Router ..Help Requested [7:74486]

2003-08-29 Thread Brijesh Patel
Hi, I want one BRI port and 14 Sync/Async Ports in the Router. I have choosed the 2691 router as follows: Cisco 2691 Router Particulars Qty NM 8A/s Card1 WIC 2A/s Card3 But how to take BRI Port??? Is there any option in 2600 router??? Or

Erasing IOS from Flash [7:74457]

2003-08-29 Thread Curious
Hi I want to know how can i delete this IOS from my FLash System flash directory: File Length Name/status 1 5742076 c2600-d-mz.121-5.t9.bin [deleted] 3 7411544 c2600-i-mz.123-1a.bin I issued the delete flash command c2600-d-mz.121-5.t9.bin , now i can see deleted in front of this i

new ccnp test books [7:74463]

2003-08-29 Thread brian d
how are the books from sybex for the new ccnp test ? switching book is by Terry Jack routing book is by Carl Timm __ Do you Yahoo!? Yahoo! SiteBuilder - Free, easy-to-use web site design software http://sitebuilder.yahoo.com Message Posted at: http://www.grou

RE: threats etc. [7:74450]

2003-08-29 Thread Howard C. Berkowitz
At 2:23 PM -0400 8/26/03, Reimer, Fred wrote: > >I'm almost positive that the exact same material is in all four other >courses, and I hope that this is within the bounds of fair use, but page 2-4 >says: > > >There are four primary threats to network security: > >* Unstructured threats > >* Str

RE: Re: Your application [7:74449]

2003-08-29 Thread [EMAIL PROTECTED]
Dear [EMAIL PROTECTED] The email that you sent to [EMAIL PROTECTED] did not reach the intended receipient due to existance of virus. Kindly have your computer check for virus. Best Regards, Mail Administrator Datacraft Asia Ltd Message Posted at: http://www.groupstudy.com/form/read.php?f=7&

Reverse Telnet [7:74469]

2003-08-29 Thread Edwin R. Gonzalez
I can only reverse telnet to two of seven routers in my lab. I've compared the configs with the two that I can telnet two but I do not see anything wrong. I have a 2511 for my term serv and I don't see anything wrong with it. Here is the config for the Term_Serv; sh config Using 1101 out of 32762

Re: Redistribution of connected routes??? [7:74447]

2003-08-29 Thread Petr Jambor
Hi, I noticed the same behavior with EIGRP and ISIS. The explanation I made is that the router is right. Indeed, the directly connected route is not learned by ISIS (because it is directly connected :-)). This is always a question, if to redistribute directly connected subnets or to include

Re: Choosing Cisco Router ..Help Requested [7:74486]

2003-08-29 Thread M.C. van den Bovenkamp
Brijesh Patel wrote: > I want one BRI port and 14 Sync/Async Ports in the Router. I have choosed > the 2691 router as follows: > > Cisco 2691 Router > > Particulars Qty > > NM 8A/s Card1 > WIC 2A/s Card3 > > But how to take BRI Port??? I

Flash [7:74491]

2003-08-29 Thread PPC-DAT Ep-Ng-Ist
We want to set up lab with 2500s but the flash size is 8M and 4M read-only and we want to load 12.2 IOS.Does anyone have an idea on how we should go about it ? Rgds, Akpome Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=74491&t=74491 ---

Re: PKI [7:74482]

2003-08-29 Thread annlee
This page (mind the wrap) http://www.ealaddin.com/partners/findpartner2.asp?SolutionCategory=11&PartnershipCategory=&PartnerName=&CompanyProduct=&PartnerSearch.x=39&PartnerSearch.y=7 lists a number of PKI Infrastructure partners to an etoken company. It might be place to start. Annlee Thomas N w

RE: Flash [7:74491]

2003-08-29 Thread [EMAIL PROTECTED]
I tried some nasty things from rommon trough the console a few times, So booting to rommon and whiping the whole thing from there would help you further, then tftp upgrade/reload the image you want. Martijn -Oorspronkelijk bericht- Van: PPC-DAT Ep-Ng-Ist [mailto:[EMAIL PROTECTED] Verz

RE: Erasing IOS from Flash [7:74457]

2003-08-29 Thread Kaminski, Shawn G
Use the "squeeze" command. Cisco states " The squeeze command, which is used to erase all files marked for deletion on a Flash file system, is now available on Cisco 2600 and Cisco 3600 series routers." So, you did the first step by deleting the IOS, but now you have to squeeze it in order to remo

RE: Catalyst 6500 Architecture [7:74460]

2003-08-29 Thread [EMAIL PROTECTED]
The SFM is a piece of junk...and not as useful as you might seem... The new Supervisor 720 has the SFM built-in...which greatly enhances its use.. -Original Message- From: neil K [mailto:[EMAIL PROTECTED] Sent: Friday, August 29, 2003 5:31 AM To: [EMAIL PROTECTED] Subject: Catalyst 650

Re: Erasing IOS from FLash [7:74459]

2003-08-29 Thread NetChild
Hi, did you try "erase flash" after the delete command ? Regards, ""Curious"" wrote in message news:[EMAIL PROTECTED] > Hi > I have 3 IOS images on my Cisco 2600 Router. > > > 1 5742076 c2600-d-mz.121-5.t9.bin [deleted] > 2 10574412 c2600-ds-mz.122-7.bin > 3 7411544 c2600-i-mz.12

RE: Reverse Telnet [7:74469]

2003-08-29 Thread Daniel Cotts
Try "no exec" under your line 1 16 Also do a "sh line" to verify they are clear. > -Original Message- > From: Edwin R. Gonzalez [mailto:[EMAIL PROTECTED] > Sent: Friday, August 29, 2003 4:31 AM > To: [EMAIL PROTECTED] > Subject: Reverse Telnet [7:74469] > > > I can only reverse telnet to

What am I missing? [7:74504]

2003-08-29 Thread Hyman, Craig
ALL- I have a CBOS router and trying to set it up as a filter router. When I inputthis rule base nothing works? Does anybody have any suggestions? Thanks set filter 0 on allow incoming eth0 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 protocol tcp set filter 1 on allow incoming eth0 0.0.0.0 0.0.0.0 0.0.

RE: TCP/UDP port for CHAP [7:74480]

2003-08-29 Thread [EMAIL PROTECTED]
In your example, VPDN is built over Ethernet, and there must be some kind of dialer where you want your access-list on. That imposes e1 ATM0 can be without access-list, the untrusted traffic, is coming in encapsulated in PPP over E. So within the PPP session there will be IP (dialer, say dhcp ne

IS-IS [7:74508]

2003-08-29 Thread PPC-DAT Ep-Ng-Ist
Is IS-IS tested on the ccie lab exam? Rgds, Akpome. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=74508&t=74508 -- **Please support GroupStudy by purchasing from the GroupStudy Store: http://shop.groupstudy.com FAQ, list archive

RE: TCP/UDP port for CHAP [7:74480]

2003-08-29 Thread Reimer, Fred
CHAP authentication does not use a TCP/UDP port. CHAP is handled in the PPP protocol between the client and the router. The router may use some other type of authentication (RADIUS, TACACS+, etc) to authenticate the user to some outside security server, but the CHAP communications is carried over

RE: Reverse Telnet [7:74469]

2003-08-29 Thread Joe Gagznos
I had a similar issue with my 2511. In chapter 2 of Caslow's book, Caslow recommends using the "modem host" command under the line configuration. The command worked for me - I can now reverse telnet to all the devices. Hope that helps! Message Posted at: http://www.groupstudy.com/form/read.php

RE: Erasing IOS from FLash [7:74459]

2003-08-29 Thread Chibwe, Oliver J, NEO
Go ahead issue command "squeez" should delete all files in flashremember whenever you delete a file you must issue squeez too or else the router gives you another chance see if you really want to do that.Just a safety catch I guess... Thank you Ollie AT&T Common Backbone 866-397-7309 Opt 1

RE: Reverse Telnet [7:74469]

2003-08-29 Thread Chibwe, Oliver J, NEO
Is it possible to send what kind of error you get whenever you try to telnet term serve other five hosts...? Thank you Ollie AT&T Common Backbone 866-397-7309 Opt 1 -Original Message- From: Edwin R. Gonzalez [mailto:[EMAIL PROTECTED] Sent: Friday, August 29, 2003 4:31 AM To: [EMAIL PROT

Re: Sprint Layoff [7:74354]

2003-08-29 Thread bmwjason
Hey Travis, Todd's situation appears to have been mitigated by the (albeit short) contract w/ TWC. Luck him. Todd, I was laid off by LU in December. Very few openings for router/networking geeks like us around KC. I _finally_ have an offer, but it will require moving to the east coast. But as my w

RE: Flash [7:74491]

2003-08-29 Thread Chibwe, Oliver J, NEO
First you need to upgrade all of the 2500s 16/16 for 12.2 by that flash/DRAM...check for flash/Dram on E.bay good deals.. Thank you Ollie AT&T Common Backbone 866-397-7309 Opt 1 -Original Message- From: PPC-DAT Ep-Ng-Ist [mailto:[EMAIL PROTECTED] Sent: Friday, August 29, 2003 5:29 AM To

RE: IS-IS [7:74508]

2003-08-29 Thread Salvatore De Luca
Yes... ISIS routing L1,L2,L1-L2 is a requsite on the CCIE Bluprint.. -Sal PPC-DAT Ep-Ng-Ist wrote: > > Is IS-IS tested on the ccie lab exam? > Rgds, > Akpome. > > Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=74514&t=74508 ---

Re: Proority Queuing [7:74254]

2003-08-29 Thread Peter Retief
It seems the earliest IOS release supporting Priority Queueing on the Cisco 828 is 12.2(8)T. I found this using the Cisco feature navigator www.cisco.com/go/fn (requires a Cisco login) What IOS version are you using? ""Skarphedinsson Arni V."" wrote in message news:[EMAIL PROTECTED] > Hi I am t

RE: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread Priscilla Oppenheimer
It sounds like the Netgear Layer 2 802.3 flow control is buggy. It sounds like you can't turn it off, though, because it's not a managed switch. Should have bought Cisco!? :-) You can turn it off on the workstations, though, and I would somewhat hesitantly recomment that. You might risk other prob

RE: Flash [7:74491]

2003-08-29 Thread Kaminski, Shawn G
You have to upgrade the 2500's to 16MB Memory and 16MB Flash to put 12.2 IOS on them. However, to do this you need to make sure the Boot ROM version in each router is at least 10.2(8a). Do a "show version" on the router to see what version the Boot ROM is. You can buy memory and flash on many of th

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread annlee
Netgear does have its problems... http://www.dslreports.com/shownews/31774?mode=flat That said, all the inexpensive devices have problems of one sort or another. I think it's a case of getting what you paid for / caveat emptor. For small networks clients, I always try to get them to buy one ste

RE: Catalyst 6500 Architecture [7:74460]

2003-08-29 Thread R. Benjamin Kessler
I think the SFM's were an interim step; the current direction seems to be the Sup720 blades. What kind of speeds & feeds are you requiring? ~~ R. Benjamin Kessler Network Engineer CCIE #8762, CISSP, CCSE Kessler Consulting Email: [EMAIL PROTECTED] http://www.kesslerconsulting.com Phone:

PPTP win98 to PIX not working [7:74521]

2003-08-29 Thread Michael Barnhart
Hello all. I have a problem with pptp to pix. Client has win98 machines on their network, all behind a DSL router. They connect via MS PPTP to my PIX box. The connection is fine, without errors. Problem is, they cannot do anything on my network. If they disconnect from their network, dial up

Re: PPTP win98 to PIX not working [7:74521]

2003-08-29 Thread Brian
is there an mtu difference, causing dont fragment failures? Brian The path to a desireable destination is often more difficult than the path to stay where you are. On Fri, 29 Aug 2003, Michael Barnhart wrote: > Hello all. > > I have a problem with pptp to pix. Client has win98 machine

Re: PPTP win98 to PIX not working [7:74521]

2003-08-29 Thread Michael Barnhart
I will take a look and see. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=74525&t=74521 -- **Please support GroupStudy by purchasing from the GroupStudy Store: http://shop.groupstudy.com FAQ, list archives, and subscription info:

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread [EMAIL PROTECTED]
No, I don't think I have a design issue: the network has 7 clients and 1 server so the architecture is very simple. My client was complaining of slow speed when opening files. My approach was to optimize at every layer possible. Choosing 802.3x feature was just one thing among others I did to speed

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread Annlee
A Google search on "802.3x" yields a lot of discussion of flow control issues people seem to have -- linux as well as windows clients. One item I found at the IEEE's web page was this: http://grouper.ieee.org/groups/802/3/efm/public/email/msg02446.html /quote In working with Ethernet for over 2

Pix VPN & SMTP [7:74527]

2003-08-29 Thread John Cianfarani
I have a Pix 501 setup for VPN for a few users, now the outgoing SMTP server for all their email (from Bell Sympatico) only allows relaying when on the Bell domain. So everything works fine when people are in the office but if they go home and use say Rogers to connect to the internet, then VPN in

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread Annlee
I think I'd look at a sniffer as a quick check of what's happening--especially if you can catch it just before the freeze. One problem with device compatibility is matching up the exact models in use -- which 3COM NICs, and which switch. I don't know a source of compatiblity info off the top of

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread [EMAIL PROTECTED]
Thank you Annlee, this is enlightening. My users mainly use word/excel documents along with a small access database. I know that sounds awful but what performance gain I will loose by using a "cheap" switch that does not do flow control? If I where able to convince my client and we used a Cisco

Serial line problem [7:74530]

2003-08-29 Thread Jeroen Timmer
Hi all, Small problem We got an update today from 128kb to 512kb leased line. We got 2 3640 routers, 1 on each end off the leased line . IOS on first 3640 12.0(13) on second 3640 router 12.0(4). Both routers have a NM-4T module. On first router: All is up, DCD=up DSR=up DTR=up RTS

Re: Console port now working on 4000 [7:74489]

2003-08-29 Thread William Lijewski
Does it display anything when you powercycle the router? Does it display the bootup information and then freeze? If it displays the bootup information and then freezes you may have accidentally put 'no exec' under the console port. You would need to break into the router, just like you would if

Re: Serial line problem [7:74530]

2003-08-29 Thread M.C. van den Bovenkamp
Jeroen Timmer wrote: > Don't those 2 clockrates have to be the same, 511680 looks good to me for a > 512kb line? And does this problem point > to the Telco who has a problem with their clockrate ?? Yeah, that's what it looks like. Your first router isn't getting a clock from the line. Assuming i