Erasing IOS from FLash [7:74459]

2003-08-29 Thread Curious
Hi I have 3 IOS images on my Cisco 2600 Router. 1 5742076 c2600-d-mz.121-5.t9.bin [deleted] 2 10574412 c2600-ds-mz.122-7.bin 3 7411544 c2600-i-mz.123-1a.bin I want to delete 2 of them. I issued the command delete flash:c2600-d-mz.121-5.t9.bin , after that i can see word deleted

Console port now working on 4000 [7:74489]

2003-08-29 Thread Rohit-Sundriyal\(CCNA\)
Hi All My Cisco 4000 consol port is not work any idea what whent wrong or how to make it work. Thanks in advance Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74489t=74489 -- **Please support GroupStudy by purchasing from the

PKI [7:74482]

2003-08-29 Thread Thomas N
I am not sure if this question is off the topic or not but hopping people can give me some suggestion. I am working on DMVPN and it seems PKI can not be missed out of the design for security purpose. I am wondering what are good PKI vendors out there? Is there any hardware appliance PKI vendor?

RE: threats etc. [7:74474]

2003-08-29 Thread Howard C. Berkowitz
At 2:23 PM -0400 8/26/03, Reimer, Fred wrote: I'm almost positive that the exact same material is in all four other courses, and I hope that this is within the bounds of fair use, but page 2-4 says: There are four primary threats to network security: * Unstructured threats * Structured

Re: Cisco ICS 7750 experiences [7:74481]

2003-08-29 Thread [EMAIL PROTECTED]
I just deployed one for a single site manufacturing new construction. 150 IP phones 7940s / 7960s, IPCC, Unity Unified, etc. It took me about two days to get all of the builds completed because of the patches you have to add, but I got it configured pretty quick and, once it was up and I was

RE: Re: Thank you! [7:74488]

2003-08-29 Thread [EMAIL PROTECTED]
Dear [EMAIL PROTECTED] The email that you sent to [EMAIL PROTECTED] did not reach the intended receipient due to existance of virus. Kindly have your computer check for virus. Best Regards, Mail Administrator Datacraft Asia Ltd Message Posted at:

Choosing Cisco Router ..Help Requested [7:74486]

2003-08-29 Thread Brijesh Patel
Hi, I want one BRI port and 14 Sync/Async Ports in the Router. I have choosed the 2691 router as follows: Cisco 2691 Router Particulars Qty NM 8A/s Card1 WIC 2A/s Card3 But how to take BRI Port??? Is there any option in 2600 router???

Erasing IOS from Flash [7:74457]

2003-08-29 Thread Curious
Hi I want to know how can i delete this IOS from my FLash System flash directory: File Length Name/status 1 5742076 c2600-d-mz.121-5.t9.bin [deleted] 3 7411544 c2600-i-mz.123-1a.bin I issued the delete flash command c2600-d-mz.121-5.t9.bin , now i can see deleted in front of this

new ccnp test books [7:74463]

2003-08-29 Thread brian d
how are the books from sybex for the new ccnp test ? switching book is by Terry Jack routing book is by Carl Timm __ Do you Yahoo!? Yahoo! SiteBuilder - Free, easy-to-use web site design software http://sitebuilder.yahoo.com Message Posted at:

RE: threats etc. [7:74450]

2003-08-29 Thread Howard C. Berkowitz
At 2:23 PM -0400 8/26/03, Reimer, Fred wrote: I'm almost positive that the exact same material is in all four other courses, and I hope that this is within the bounds of fair use, but page 2-4 says: There are four primary threats to network security: * Unstructured threats * Structured

RE: Re: Your application [7:74449]

2003-08-29 Thread [EMAIL PROTECTED]
Dear [EMAIL PROTECTED] The email that you sent to [EMAIL PROTECTED] did not reach the intended receipient due to existance of virus. Kindly have your computer check for virus. Best Regards, Mail Administrator Datacraft Asia Ltd Message Posted at:

Reverse Telnet [7:74469]

2003-08-29 Thread Edwin R. Gonzalez
I can only reverse telnet to two of seven routers in my lab. I've compared the configs with the two that I can telnet two but I do not see anything wrong. I have a 2511 for my term serv and I don't see anything wrong with it. Here is the config for the Term_Serv; sh config Using 1101 out of

Re: Redistribution of connected routes??? [7:74447]

2003-08-29 Thread Petr Jambor
Hi, I noticed the same behavior with EIGRP and ISIS. The explanation I made is that the router is right. Indeed, the directly connected route is not learned by ISIS (because it is directly connected :-)). This is always a question, if to redistribute directly connected subnets or to include

Re: Choosing Cisco Router ..Help Requested [7:74486]

2003-08-29 Thread M.C. van den Bovenkamp
Brijesh Patel wrote: I want one BRI port and 14 Sync/Async Ports in the Router. I have choosed the 2691 router as follows: Cisco 2691 Router Particulars Qty NM 8A/s Card1 WIC 2A/s Card3 But how to take BRI Port??? Is there

Flash [7:74491]

2003-08-29 Thread PPC-DAT Ep-Ng-Ist
We want to set up lab with 2500s but the flash size is 8M and 4M read-only and we want to load 12.2 IOS.Does anyone have an idea on how we should go about it ? Rgds, Akpome Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74491t=74491

Re: PKI [7:74482]

2003-08-29 Thread annlee
This page (mind the wrap) http://www.ealaddin.com/partners/findpartner2.asp?SolutionCategory=11PartnershipCategory=PartnerName=CompanyProduct=PartnerSearch.x=39PartnerSearch.y=7 lists a number of PKI Infrastructure partners to an etoken company. It might be place to start. Annlee Thomas N

RE: Flash [7:74491]

2003-08-29 Thread [EMAIL PROTECTED]
I tried some nasty things from rommon trough the console a few times, So booting to rommon and whiping the whole thing from there would help you further, then tftp upgrade/reload the image you want. Martijn -Oorspronkelijk bericht- Van: PPC-DAT Ep-Ng-Ist [mailto:[EMAIL PROTECTED]

RE: Erasing IOS from Flash [7:74457]

2003-08-29 Thread Kaminski, Shawn G
Use the squeeze command. Cisco states The squeeze command, which is used to erase all files marked for deletion on a Flash file system, is now available on Cisco 2600 and Cisco 3600 series routers. So, you did the first step by deleting the IOS, but now you have to squeeze it in order to remove

RE: Catalyst 6500 Architecture [7:74460]

2003-08-29 Thread [EMAIL PROTECTED]
The SFM is a piece of junk...and not as useful as you might seem... The new Supervisor 720 has the SFM built-in...which greatly enhances its use.. -Original Message- From: neil K [mailto:[EMAIL PROTECTED] Sent: Friday, August 29, 2003 5:31 AM To: [EMAIL PROTECTED] Subject: Catalyst

Re: Erasing IOS from FLash [7:74459]

2003-08-29 Thread NetChild
Hi, did you try erase flash after the delete command ? Regards, Curious wrote in message news:[EMAIL PROTECTED] Hi I have 3 IOS images on my Cisco 2600 Router. 1 5742076 c2600-d-mz.121-5.t9.bin [deleted] 2 10574412 c2600-ds-mz.122-7.bin 3 7411544 c2600-i-mz.123-1a.bin I

RE: Reverse Telnet [7:74469]

2003-08-29 Thread Daniel Cotts
Try no exec under your line 1 16 Also do a sh line to verify they are clear. -Original Message- From: Edwin R. Gonzalez [mailto:[EMAIL PROTECTED] Sent: Friday, August 29, 2003 4:31 AM To: [EMAIL PROTECTED] Subject: Reverse Telnet [7:74469] I can only reverse telnet to two of

What am I missing? [7:74504]

2003-08-29 Thread Hyman, Craig
ALL- I have a CBOS router and trying to set it up as a filter router. When I inputthis rule base nothing works? Does anybody have any suggestions? Thanks set filter 0 on allow incoming eth0 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 protocol tcp set filter 1 on allow incoming eth0 0.0.0.0 0.0.0.0

RE: TCP/UDP port for CHAP [7:74480]

2003-08-29 Thread [EMAIL PROTECTED]
In your example, VPDN is built over Ethernet, and there must be some kind of dialer where you want your access-list on. That imposes e1 ATM0 can be without access-list, the untrusted traffic, is coming in encapsulated in PPP over E. So within the PPP session there will be IP (dialer, say dhcp

IS-IS [7:74508]

2003-08-29 Thread PPC-DAT Ep-Ng-Ist
Is IS-IS tested on the ccie lab exam? Rgds, Akpome. Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74508t=74508 -- **Please support GroupStudy by purchasing from the GroupStudy Store: http://shop.groupstudy.com FAQ, list

RE: TCP/UDP port for CHAP [7:74480]

2003-08-29 Thread Reimer, Fred
CHAP authentication does not use a TCP/UDP port. CHAP is handled in the PPP protocol between the client and the router. The router may use some other type of authentication (RADIUS, TACACS+, etc) to authenticate the user to some outside security server, but the CHAP communications is carried

RE: Reverse Telnet [7:74469]

2003-08-29 Thread Joe Gagznos
I had a similar issue with my 2511. In chapter 2 of Caslow's book, Caslow recommends using the modem host command under the line configuration. The command worked for me - I can now reverse telnet to all the devices. Hope that helps! Message Posted at:

RE: Erasing IOS from FLash [7:74459]

2003-08-29 Thread Chibwe, Oliver J, NEO
Go ahead issue command squeez should delete all files in flashremember whenever you delete a file you must issue squeez too or else the router gives you another chance see if you really want to do that.Just a safety catch I guess... Thank you Ollie ATT Common Backbone 866-397-7309 Opt 1

RE: Reverse Telnet [7:74469]

2003-08-29 Thread Chibwe, Oliver J, NEO
Is it possible to send what kind of error you get whenever you try to telnet term serve other five hosts...? Thank you Ollie ATT Common Backbone 866-397-7309 Opt 1 -Original Message- From: Edwin R. Gonzalez [mailto:[EMAIL PROTECTED] Sent: Friday, August 29, 2003 4:31 AM To: [EMAIL

Re: Sprint Layoff [7:74354]

2003-08-29 Thread bmwjason
Hey Travis, Todd's situation appears to have been mitigated by the (albeit short) contract w/ TWC. Luck him. Todd, I was laid off by LU in December. Very few openings for router/networking geeks like us around KC. I _finally_ have an offer, but it will require moving to the east coast. But as my

RE: Flash [7:74491]

2003-08-29 Thread Chibwe, Oliver J, NEO
First you need to upgrade all of the 2500s 16/16 for 12.2 by that flash/DRAM...check for flash/Dram on E.bay good deals.. Thank you Ollie ATT Common Backbone 866-397-7309 Opt 1 -Original Message- From: PPC-DAT Ep-Ng-Ist [mailto:[EMAIL PROTECTED] Sent: Friday, August 29, 2003 5:29 AM

RE: IS-IS [7:74508]

2003-08-29 Thread Salvatore De Luca
Yes... ISIS routing L1,L2,L1-L2 is a requsite on the CCIE Bluprint.. -Sal PPC-DAT Ep-Ng-Ist wrote: Is IS-IS tested on the ccie lab exam? Rgds, Akpome. Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74514t=74508 --

Re: Proority Queuing [7:74254]

2003-08-29 Thread Peter Retief
It seems the earliest IOS release supporting Priority Queueing on the Cisco 828 is 12.2(8)T. I found this using the Cisco feature navigator www.cisco.com/go/fn (requires a Cisco login) What IOS version are you using? Skarphedinsson Arni V. wrote in message news:[EMAIL PROTECTED] Hi I am

RE: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread Priscilla Oppenheimer
It sounds like the Netgear Layer 2 802.3 flow control is buggy. It sounds like you can't turn it off, though, because it's not a managed switch. Should have bought Cisco!? :-) You can turn it off on the workstations, though, and I would somewhat hesitantly recomment that. You might risk other

RE: Flash [7:74491]

2003-08-29 Thread Kaminski, Shawn G
You have to upgrade the 2500's to 16MB Memory and 16MB Flash to put 12.2 IOS on them. However, to do this you need to make sure the Boot ROM version in each router is at least 10.2(8a). Do a show version on the router to see what version the Boot ROM is. You can buy memory and flash on many of the

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread annlee
Netgear does have its problems... http://www.dslreports.com/shownews/31774?mode=flat That said, all the inexpensive devices have problems of one sort or another. I think it's a case of getting what you paid for / caveat emptor. For small networks clients, I always try to get them to buy one

RE: Catalyst 6500 Architecture [7:74460]

2003-08-29 Thread R. Benjamin Kessler
I think the SFM's were an interim step; the current direction seems to be the Sup720 blades. What kind of speeds feeds are you requiring? ~~ R. Benjamin Kessler Network Engineer CCIE #8762, CISSP, CCSE Kessler Consulting Email: [EMAIL PROTECTED] http://www.kesslerconsulting.com Phone:

PPTP win98 to PIX not working [7:74521]

2003-08-29 Thread Michael Barnhart
Hello all. I have a problem with pptp to pix. Client has win98 machines on their network, all behind a DSL router. They connect via MS PPTP to my PIX box. The connection is fine, without errors. Problem is, they cannot do anything on my network. If they disconnect from their network, dial up

Re: PPTP win98 to PIX not working [7:74521]

2003-08-29 Thread Brian
is there an mtu difference, causing dont fragment failures? Brian The path to a desireable destination is often more difficult than the path to stay where you are. On Fri, 29 Aug 2003, Michael Barnhart wrote: Hello all. I have a problem with pptp to pix. Client has win98 machines

Re: PPTP win98 to PIX not working [7:74521]

2003-08-29 Thread Michael Barnhart
I will take a look and see. Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74525t=74521 -- **Please support GroupStudy by purchasing from the GroupStudy Store: http://shop.groupstudy.com FAQ, list archives, and subscription info:

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread [EMAIL PROTECTED]
No, I don't think I have a design issue: the network has 7 clients and 1 server so the architecture is very simple. My client was complaining of slow speed when opening files. My approach was to optimize at every layer possible. Choosing 802.3x feature was just one thing among others I did to

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread Annlee
A Google search on 802.3x yields a lot of discussion of flow control issues people seem to have -- linux as well as windows clients. One item I found at the IEEE's web page was this: http://grouper.ieee.org/groups/802/3/efm/public/email/msg02446.html /quote In working with Ethernet for over 20

Pix VPN SMTP [7:74527]

2003-08-29 Thread John Cianfarani
I have a Pix 501 setup for VPN for a few users, now the outgoing SMTP server for all their email (from Bell Sympatico) only allows relaying when on the Bell domain. So everything works fine when people are in the office but if they go home and use say Rogers to connect to the internet, then VPN

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread Annlee
I think I'd look at a sniffer as a quick check of what's happening--especially if you can catch it just before the freeze. One problem with device compatibility is matching up the exact models in use -- which 3COM NICs, and which switch. I don't know a source of compatiblity info off the top

Re: 802.3x switch traffic disruption [7:74455]

2003-08-29 Thread [EMAIL PROTECTED]
Thank you Annlee, this is enlightening. My users mainly use word/excel documents along with a small access database. I know that sounds awful but what performance gain I will loose by using a cheap switch that does not do flow control? If I where able to convince my client and we used a Cisco

RE: VPNs and CEF [7:74429]

2003-08-28 Thread Joseph Brunner
Vpn's dont like out of order packets. Forget load balancing at layer3. USE MLPPP and do layer 2 load balancing. CEF may or may not be needed. You have to experiment with CPU util. I do the same thing. Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74430t=74429

RE: Metric of OSPF Summary Routes [7:74361]

2003-08-28 Thread alaerte Vidali
Hi, A guy from Cisco confirmed that it is a version approach. 11.2 uses the lowest metric (RFC RFC1583). 12.0 and later uses the highest metric (RFC2328). Thanks Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74431t=74361 --

Your details [7:74297]

2003-08-28 Thread [EMAIL PROTECTED]
Please see the attached file for details. [GroupStudy removed an attachment of type application/octet-stream which had a name of wicked_scr.scr] Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74297t=74297 -- **Please support

RE: Flash amp; MEM upgrade for 2500 series questi [7:74298]

2003-08-28 Thread Kaminski, Shawn G
You can do a show version to see what version of Boot ROM you have. You need at least Boot ROM version 10.2(8a) to upgrade to 16 MB Flash. You can find them on the auction sites. Here's one I found. There are plenty more out there (watch for wrap):

Re: Flash amp; MEM upgrade for 2500 series questi [7:74298]

2003-08-28 Thread Reza
ROM version has to be 10 or higher. You can get them on ebay for about $10 a set. Hope this helps Reza dave petit wrote in message news:[EMAIL PROTECTED] I have several 2500 series routers I am using for a practice lab. I want to upgrade them to 16flash/16mem to support the later IOS

RE: CCNP Lab design and Topology [7:74389]

2003-08-28 Thread Aspiring Cisco Gurl
Do these lab companions have specific labs for study or does it only work off of the Network Academy books? Basically, what I am asking is if they can be used separately with my own home lab versus do I need to get the whole package of Network Academy companion book, lab book, and journal? (What

PRI to PRI - HELP !!! [7:74433]

2003-08-28 Thread Robert Bentley
Hi I'm slowly getting my teeth into the world of cisco - but I am struggling to set up the following. I have two Cisco 2611XM routers, each with a serial card and a PRI card. I have set up the serial interfaces with a 30 bit IP address range, and the 2Mb serial link works well. I would now like

GroupStudy Server [7:74437]

2003-08-28 Thread Paul Borghese
The server circuit breakers fired do to the continuous internet worm outbreaks. Please resend if you sent a message that did not appear on the list. Also, any recommendations for a LOW COST 1u server we may use to replace the current GroupStudy server? Thanks! Paul Message Posted at:

ATM and Rate-limiting [7:74438]

2003-08-28 Thread [EMAIL PROTECTED]
Is it popssible to use rate-limit command on an ATM interface? Thanks, Mario Puras SoluNet Technical Support Mailto: [EMAIL PROTECTED] Direct: (321) 309-1410 888.449.5766 (USA) / 888.SOLUNET (Canada) Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74438t=74438

RE: PRI to PRI - HELP !!! [7:74433]

2003-08-28 Thread star star7
hello r u using a PRI E1 or T1 If PRI E1 configure the serial n:15 ip address line code hdb3 framing CRC-4 no shut configure this as the backup link for ur serial Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74439t=74433

RE: CCNP Lab design and Topology [7:74389]

2003-08-28 Thread Priscilla Oppenheimer
Aspiring Cisco Gurl wrote: Do these lab companions have specific labs for study or does it only work off of the Network Academy books? Basically, what I am asking is if they can be used separately with my own home lab versus do I need to get the whole package of Network Academy companion

IDS Sensors [7:74442]

2003-08-28 Thread Lupi, Guy
I am not a security specialist, so please bear with me if this is what every IDS device does. I am looking for advice/opinions on a device that can accomplish the following, I was looking at the Cisco 4250 XL IDS sensor. Inspect over 400 Mbps of traffic from at least 4,000 IP subnets.

What am I missing? [7:74441]

2003-08-28 Thread Hyman, Craig
ALL- I have a CBOS router and trying to set it up as a filter router. When I inputthis rule base nothing works? Thanks set filter 0 on allow incoming eth0 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 protocol tcp set filter 1 on allow incoming eth0 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 protocol udp set

RE: GroupStudy Server [7:74437]

2003-08-28 Thread Ryan Finnesey
Paul We would be happy to host the list for you if you would like. Ryan -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Paul Borghese Sent: Thursday, August 28, 2003 11:58 AM To: [EMAIL PROTECTED] Subject: GroupStudy Server [7:74437] The server

Redistribution of connected routes??? [7:74447]

2003-08-28 Thread Jason Viera
I have searched high and low for an explanation as to why I occasionally have problems when redistributing, if I don't use a redistribute connected statement and try to use the IGP to advertise a connected network. Hopefully I don't confuse anyone or myself, but here is the issue I ran into

Re: PRI to PRI - HELP !!! [7:74433]

2003-08-28 Thread Dave Madland
Robert Bentley wrote: Hi I'm slowly getting my teeth into the world of cisco - but I am struggling to set up the following. I have two Cisco 2611XM routers, each with a serial card and a PRI card. I have set up the serial interfaces with a 30 bit IP address range, and the 2Mb serial link works

Frame slips on T1 controller (7206 NPE 200) [7:74446]

2003-08-28 Thread puro prasad
Hi, I have VXC-2TE1+ port adapter in 7206 (NPE200) router. The Line is experiencing a lot of frameslips which seems to be a clocking problem. Experienced the same problem in another 7206VXR (NPE G1) router. Issued the 'frame-clock-select' global command to resolve the problem on VXR router but

BGP Route-maps [7:74424]

2003-08-27 Thread Matthew Webster
Hi all, I have a few problems with configuring route maps in conjunction with BGP. I have configured a community that advertises all networks except two but these two networks are still advertised to the peer after doing the clear ip bgp * command on both peers. I have read in the Cisco book

RE: Load Balancing; help explain [7:74376]

2003-08-27 Thread Priscilla Oppenheimer
lazy mentor wrote: I've seen where people load balanced two T1's on a per packet basis and achieved 1.5 megs on both circuits. Which would give them a total of 3Megs, but the provider said that they are load balancing 1.5 megs over two T1's. I asked different person same provider, that if

Back-to-Back ISDN WIC-1B-U [7:74420]

2003-08-27 Thread Joseph R. Taylor
Team, Is it possible to configure back-to-back ISDN WIC-1B-U connections for a home lab setup? JoeT MCSE, CCNP Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74420t=74420 -- **Please support

RE: BGP Route-maps [7:74424]

2003-08-27 Thread Salvatore De Luca
Matthew, In your current configuration you have a route-map com1 with a sequence of 10 in which BGP will look at first as you recieve updates from neighbor R1. Now, within that route map you have specified match ip address 3, so in acl 3 you are PERMITTING 10.3.2.0/24 and then set acl 3 to

PPTP and IPSEC support [7:74428]

2003-08-27 Thread James Gosnold
Dear all, I'm looking for a DSL router for a remote office (827 or 837?) that will support IPSEC and PPTP VPN's. At Head office I have a Microsoft ISA Server which is easier to setup with PPTP connections, however I would like to have a go at setting up an IPSEC infrastructure so ideally a

VPNs and CEF [7:74429]

2003-08-27 Thread Jason Owens
I have a remote site that is looking into getting 4 T1's to the internet and tunneling all traffic to my site (3015 concentrator with redundant DS3's). Clearly I can't use CEF per-destination as there is only one source-dest. pair and I want to utilize all T1's. Are there any issues with CEF

Metric of OSPF Summary Routes [7:74361]

2003-08-26 Thread alaerte Vidali
Is there a way to define the metric of a OSPF summary route? This is strange, but two routers with the same IOS (and similar commands) are using different approaches: one router is using the highest metric of more specific routes, while the other router is using the lower metric. This one is

Re: Urgent . ATM [7:74345]

2003-08-26 Thread Derek Gaff
Shap You can do ATM Discovery on the ATM interface and this will let you know what the VPI/VCI that you should use. Lookup on Cisco Websie. derek - Original Message - From: Reimer, Fred To: Sent: Monday, August 25, 2003 8:57 PM Subject: RE: Urgent . ATM [7:74345] That would kind of

PIX VPN Client Configuration - At my wit's end! [7:74363]

2003-08-26 Thread James Willard
Hi all, Thanks in advance for reading this message. I am completely boggled on an issue here that I have literally been trying to troubleshoot for some 12 hours now. I'm trying to configure a PIX 515E for Cisco VPN Client connectivity. Here are the relevant parts of my config: :PIX Version

Ping Reply (Packet Filtered) [7:74365]

2003-08-26 Thread Eric W
All I am still fairly new with ACL's. However I m interested in blocking ICMP to my network behind router A (Interface e0/1 = my network). But when a icmp request is issued from the outside the router replys with packet filtered from (interface e0/0 = outside network) ACL is applied on in coming

help with vpn scenario [7:74366]

2003-08-26 Thread Chandler Mike
Please help with the following scenario: A laptop user works for Company A and possesses a Company A laptop that belongs to their domain. The user has needs to frequently access confidential records that belong to Company A, while on another company's network. The user also works onsite (with

PIX VPN Setup [7:74367]

2003-08-26 Thread John Cianfarani
I'm setting up a small VPN just for home use so me and a few friends can log in remotely via a PIX 501 w/ 3DES over my cable connection. Now I've got it working, but found a few strange things I had questions about. I have each user setup with the VPNGROUP config lines. (I will post config

RE: Ping Reply (Packet Filtered) [7:74365]

2003-08-26 Thread Priscilla Oppenheimer
Eric W wrote: All I am still fairly new with ACL's. However I m interested in blocking ICMP to my network behind router A (Interface e0/1 = my network). But when a icmp request is issued from the outside the router replys with packet filtered from (interface e0/0 = outside network) ACL

PIX VPN Setup [7:74369]

2003-08-26 Thread John Cianfarani
I'm setting up a small VPN just for home use so me and a few friends can log in remotely via a PIX 501 w/ 3DES over my cable connection. Now I've got it working, but found a few strange things I had questions about. I have each user setup with the VPNGROUP config lines. (I will post config

access list question [7:74370]

2003-08-26 Thread dave petit
I have an access list (101) on my router that is tied to a cable modem network. The access list contains the following icmp deny statment. It seems to workok. The question is; what the heck does (3/13) mean in the log line?? Thanks!! from access-list 101: access-list 101 deny icmp any any

RE: Ping Reply (Packet Filtered) [7:74365]

2003-08-26 Thread Eric W
Priscilla please forgive me for my lack of vocabulary in this issue. But yes I am try to make the router silent. Inter e0/0 (Outside) 192.168.1.20/24 Inter ee0/1 (Inside) 192.168.10.0/24 Ping from outside to (192.168.10.0/24) produces from e0/0(reply from 192.168.1.20 packet filtered). This

RE: help with vpn scenario [7:74366]

2003-08-26 Thread Reimer, Fred
It depends on Company B's firewall, and how it is setup to allow IPsec traffic (or not). Theoretically, there is no difference between connecting to Company A via an ISP connection and connecting to Company A through Company B, except that Company B's firewall may not allow or be capable of

RE: SAFE and the Holy Hand Grenade of Antioch [7:74304]

2003-08-26 Thread Reimer, Fred
I agree with you that it is a pretty serious issue if it is not searchable on Cisco's site, or in their SAFE white papers. However, it IS in every single }current{ documentation/training materials for their security certifications. Well, at least for all of their CCSP security certifications. I

RE: Ping Reply (Packet Filtered) [7:74365]

2003-08-26 Thread Zsombor Papp
'no ip unreachables' Thanks, Zsombor Eric W wrote: All I am still fairly new with ACL's. However I m interested in blocking ICMP to my network behind router A (Interface e0/1 = my network). But when a icmp request is issued from the outside the router replys with packet filtered from

Load Balancing; help explain [7:74376]

2003-08-26 Thread Aspiring Cisco Gurl
I was asked a question about load balancing on routers and servers. Ive looked it up on the websites but can someone give me their 2 cents about it? Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74376t=74376 -- **Please support

RE: access list question [7:74370]

2003-08-26 Thread Zsombor Papp
I think it's the ICMP type/code. Thanks, Zsombor dave petit wrote: I have an access list (101) on my router that is tied to a cable modem network. The access list contains the following icmp deny statment. It seems to workok. The question is; what the heck does (3/13) mean in the log

RE: Ping Reply (Packet Filtered) [7:74365]

2003-08-26 Thread Priscilla Oppenheimer
Priscilla Oppenheimer wrote: Eric W wrote: Priscilla please forgive me for my lack of vocabulary in this issue. But yes I am try to make the router silent. Inter e0/0 (Outside) 192.168.1.20/24 Inter ee0/1 (Inside) 192.168.10.0/24 Ping from outside to (192.168.10.0/24)

Cisco CIM cds... are they really worth it? [7:74375]

2003-08-26 Thread Aspiring Cisco Gurl
I am thinking about buying some Cisco CIM cds... something like IP routing, Link-state, CCIE multiprotocol challenge, and ISDN access. Do you think it is worth it or should I just stick to plain old lab work? Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74375t=74375

RE: Ping Reply (Packet Filtered) [7:74365]

2003-08-26 Thread Priscilla Oppenheimer
Eric W wrote: Priscilla please forgive me for my lack of vocabulary in this issue. But yes I am try to make the router silent. Inter e0/0 (Outside) 192.168.1.20/24 Inter ee0/1 (Inside) 192.168.10.0/24 Ping from outside to (192.168.10.0/24) produces from e0/0(reply from 192.168.1.20

RE: SAFE and the Holy Hand Grenade of Antioch [7:74304]

2003-08-26 Thread Charlie Wehner
This is an excellent example of why I hated taking the SAFE exam. I found myself for several questions thinking... Well, I depends on what you mean by this term. I agree with Fred though. I believe the answers they are looking for are Unstructured, Structured, External and Internal. Message

Re: help with vpn scenario [7:74366]

2003-08-26 Thread Francisco Gomez
Hi Chandler, To secure the laptop of company a while connected via VPN form company B my suggestion is to run the Client Firewall feature the concentrator has, (this is why I love this device so much). While you are connected via VPN, the concentrator will inject a set of rules, (a firewall

Re: PIX VPN Setup [7:74369]

2003-08-26 Thread Francisco Gomez
John, One question at the time: 1) I noticed that I never set an isakmp pre-share key - Remember that for a VPN client connection, ISAKMP or Phase I is established using aggressive mode in this case and due the remote connection would come from any place on the Internet; a pre-share

RE: ACL VS Null Route [7:74267]

2003-08-26 Thread Doan Nguyen
P B has a good explanation. However black hole routing is usually done on the fly when you have a DoS attack and can't really change ACL on X routers in your network. Routing an unwanted network into Null is the quick and temporary way. However in the long run it is in good practice to use ACL

Re: PIX VPN Client Configuration - At my wit's end! [7:74363]

2003-08-26 Thread Francisco Gomez
Hi James, It would be nice to have the output of the show crypto ipsec sa on the PIX while pinging back and forth. It would be nice to get the output of the debug icmp trace and the sh access-list as well but in any case my suggestion is this: 1) If you are doing split-tunneling I will

RE: Ping Reply (Packet Filtered) [7:74365]

2003-08-26 Thread Eric Washington
Thanks all.. Solved all my problems. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Tuesday, August 26, 2003 11:52 AM To: [EMAIL PROTECTED] Subject: RE: Ping Reply (Packet Filtered) [7:74365] 'no ip unreachables' Thanks, Zsombor Eric W wrote: All I

RE: SAFE and the Holy Hand Grenade of Antioch [7:74304]

2003-08-26 Thread Reimer, Fred
Indubitably - Checked on www.m-w.com :-) Fred Reimer - CCNA Eclipsys Corporation, 200 Ashford Center North, Atlanta, GA 30338 Phone: 404-847-5177 Cell: 770-490-3071 Pager: 888-260-2050 NOTICE; This email contains confidential or proprietary information which may be legally privileged. It is

CCNP and CCSP Lab design and Topology [7:74388]

2003-08-26 Thread Magdy Ibrahim
Hi All, I am wondering If I can find any help here regarding this case but I am trying as I knew that most of the list members are involved in Networking and communications Ok, Now I am trying to build CCNP LAB here for studying purposes in Cairo University, Egypt.. This lab will use for CCNP

CCNP Lab design and Topology [7:74389]

2003-08-26 Thread Magdy Ibrahim
Hi All, I am wondering If I can find any help here regarding this case but I am trying as I knew that most of the list members are involved in Networking and communications Ok, Now I am trying to build CCNP LAB here for studying purposes in Cairo University, Egypt.. This lab will use for CCNP

Re: PIX VPN Client Configuration - At my wit's end! [7:74363]

2003-08-26 Thread Derek Gaff
James Your missing the command vpdn enable outside from your config. regards derek - Original Message - From: James Willard To: Sent: Tuesday, August 26, 2003 12:17 AM Subject: PIX VPN Client Configuration - At my wit's end! [7:74363] Hi all, Thanks in advance for reading this

RE: BCRAN 2.0 questions [7:13450]

2003-08-26 Thread [EMAIL PROTECTED]
Hi Thienan Nguyen, Did you take the 642-821 exam...or did you take the 640-605 exam?I am currently preparing for the BCRAN and contemplating taking the new exam which is about to be released soon. Thanks for the help Pooven -Original Message- From: thienan nguyen [mailto:[EMAIL

1000BaseT GBIC [7:74392]

2003-08-26 Thread Nima Javidi
Is 1000BaseT GBIC Autosense? Is it Support 10/100/1000? Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=74392t=74392 -- **Please support GroupStudy by purchasing from the GroupStudy Store: http://shop.groupstudy.com FAQ, list

RE: LLC1 and LLC2 (What is the difference?) [7:74341]

2003-08-26 Thread [EMAIL PROTECTED]
Brilliant - thx -Original Message- From: Priscilla Oppenheimer [mailto:[EMAIL PROTECTED] Sent: 25 August 2003 18:59 To: [EMAIL PROTECTED] Subject: RE: LLC1 and LLC2 (What is the difference?) [7:74341] [EMAIL PROTECTED] wrote: Can anyone enlighten me on this? From Troubleshooting

RE: 1000BaseT GBIC [7:74392]

2003-08-26 Thread [EMAIL PROTECTED]
Nope. Martijn -Oorspronkelijk bericht- Van: Nima Javidi [mailto:[EMAIL PROTECTED] Verzonden: dinsdag 26 augustus 2003 10:54 Aan: [EMAIL PROTECTED] Onderwerp: 1000BaseT GBIC [7:74392] Is 1000BaseT GBIC Autosense? Is it Support 10/100/1000? **Please support GroupStudy by purchasing

RE: Load Balancing; help explain [7:74376]

2003-08-26 Thread [EMAIL PROTECTED]
What kind of process do you want to balance, ie what layer? Fail-over or load-balance defined on source/destination/traffic or true server cpu load? Sometimes you want do watch a quorum process (or critical application) and monitor that from a serverfarm instead of doing a layer

<    2   3   4   5   6   7   8   9   10   11   >