Re: Pix load balance? [7:42974]

2002-05-06 Thread Engelhard M. Labiro
Hi, Do you have any URL on Cisco site which point on how to configure a CCS11 to provide a load balance to PIXes ? I tried looking at cisco.com but couldn`t find it. This URL is the closest that I found on Firewall load balance with CCS, but it doesn`t specifically says it is a PIX.

Re: assign (static) IP address to VPN client [7:43329]

2002-05-06 Thread Engelhard M. Labiro
Hans, To assign an address to a remote client once it connected, you have four options. These options are as follow : 1. Use Client Address (supplied by the client software) 2. Use Address from Authentication Server (supplied by an auth server) 3. Use DHCP (supplied by a DHCP server). 4. Use

About Catalyst Switch 8540 rumour [7:42651]

2002-04-26 Thread Engelhard M. Labiro
Dear members, I would like to ask about the rumour I heard regarding Catalyst Switch 8540. According to the rumour Cat 8540 is a big failure product of Cisco switch line-up. I have a catalog of Catalyst switches, this 8540 is not shown on the catalog. Does anyone have information or an

Re: DLSW direct encapsulation confusion--for Experts only [7:41176]

2002-04-11 Thread Engelhard M. Labiro
interface s0/0 pass-thru Engelhard M. Labiro ([EMAIL PROTECTED]) Security Group, Technical Solution Center, Netmarks Inc. 2-13-34 Konan, Minato-Ku, Tokyo 108-0075 Tel: +81-3-5461-2575, Fax: +81-3-5461-2093 - Original Message - From: IT Guy To: Sent: Thursday, April 11, 2002

Re: Frame-Relay Problem [7:41250]

2002-04-11 Thread Engelhard M. Labiro
Ping, Have you configure the following comands on FR switch ? 1. Global config mode : frame-relay switching 2. Interface config mode: frame-relay intf-type dce - Original Message - From: PING To: Sent: Friday, April 12, 2002 10:49 AM Subject: Frame-Relay Problem [7:41250] If I

Re: VPN 500 Concentrator and non-Cisco VPN clients [7:40788]

2002-04-08 Thread Engelhard M. Labiro
Cisco website to be able to connect to the VPN 5000 concentrator... Engelhard M. Labiro ([EMAIL PROTECTED]) Security Group, Technical Solution Center, Netmarks Inc. 2-13-34 Konan, Minato-Ku, Tokyo 108-0075 Tel: +81-3-5461-2575, Fax: +81-3-5461-2093 Message Posted at: http

Re: netbios over internet [7:40784]

2002-04-08 Thread Engelhard M. Labiro
How about NetBIOS over TCP/IP (NBT) and encapsulate it with IPSec. Another idea is using a GRE tunnel to pass the NetBIOS to the next hop. I don't think you can, besides bridging on every internet hop. On Sun, 2002-04-07 at 23:14, cage wrote: how can I make the netbios over Internet

Re: MAU 8228 [7:39891]

2002-04-01 Thread Engelhard M. Labiro
Hi Pierre, Yes, I am using IBM 8228 as the Token-Ring Hub, connecting two Cisco 2612, with a straigth UTP cable. No problem so far, the Token-ring interface can run on 16MB speed. HTH Engelhard M. Labiro Security Group, Technical Solution Center, Netmarks Inc. 2-13-34 Konan, Minato-Ku, Tokyo

Re: Ipexpert's Lab 7 questions. [7:39292]

2002-03-23 Thread Engelhard M. Labiro
Rajesh 1. Item 2 : I couldn't get the following things properly : R2 should have the summarized entry in its routing table if either R5 or R6 fails. R5 and R6 are ABR for area 1, and requirements is network on area 1 should be summarized before its enter the area 0. Think of the command

Re: CISCO 2600 router [7:39130]

2002-03-22 Thread Engelhard M. Labiro
The router is looking for a config file on a TFTP server by broadcasting messages. You can disable this behaviour by no service config command. HTH Hi, Need Help in understanding why the following problem is occuring. When I connect the CISCO 2600 router through the console port. I get the

Re: NAT PIX [7:38633]

2002-03-18 Thread Engelhard M. Labiro
Assuming that the 100 IP addresses you mention below are addresses on the inside network, the answer is yes, you can allow all of them and use only one public IP to get to the internet. Just enable PAT (Port Address Translation) using global (inside) command. HTH Hi I have a PIX firewall,

Re: possible quirk in cisco IOS [7:37628]

2002-03-07 Thread Engelhard M. Labiro
I never experienced such stall mode problem when changing IOS between three IOSes on a router`s flash. See below: lone_rhino#sh flash System flash directory: File Length Name/status 1 10630360 c3640-is-mz_121-5_T10.bin 2 4405204 c3640-js-mz.112-18.P.bin 3 13955200

Re: PIX questions [7:37129]

2002-03-03 Thread Engelhard M. Labiro
That wouldn`t work ! Telnet from outside network is prohibited even if you define it with telnet blah outside command. The work around is to protect the telnet traffic with IPSec or configure SSH if you don`t want hassle with IPSec configuration. HTH u dont need to add a conduit for telnet

Re: PIX PAT Problem!! Urgent [7:37052]

2002-03-02 Thread Engelhard M. Labiro
Assume that you want to access every host on 10.1.1.0 from network 205.11.1.0 with the source address tranlasted to 10.1.1.100 , then I don`t think it is possible with a PIX. A router would be able to do such requirement. That is Very very Urgent!!!Please Help!!! Does anyone know that Can

Re: 2612 Translational Bridging [7:36468]

2002-02-25 Thread Engelhard M. Labiro
Could someone tell me how to conigure 2612 for Translational bridging? I need to bridge ethernet and Token ring traffic in 2612. I don't have any other routers. This is simple config that I use on 2612: The virtual ring is 10, the pseudo-ring for ethernet is 110. ! source-bridge

Re: PIX v6.2 [7:35987]

2002-02-22 Thread Engelhard M. Labiro
I heard that from another mailing-list, 6.2 will be release around April 2002. It seems that Cisco PIX team would not leak the 6.2 beta for public consume, CMIIW. Hummm, I too scanned the Cisco site for 6.2 and only found 6.1.2. I'd heard from the rumor-mill that 6.2 was out, but perhaps

Re: exec-timeout 0 0 ?? [7:36018]

2002-02-20 Thread Engelhard M. Labiro
What does this cmd. #exec-timeout 0 0 exactly do? I am confused. Does it set the console timeout to 0 min 0 sec or to infinitynever time out...which is what I want on my routers :-) Which one? The later is right. 0 0 means there will be no timeout for the configured mode. HTH

Re: IPexpert BGP question. [7:34932]

2002-02-08 Thread Engelhard M. Labiro
Configure a confederation inside the AS 200 ! Point no 4 says : Configure R7 and R8 in AS65078.- This was done. Configure R7 and R8 such that if any new routers were added to the 150.50.4.0 subnet they could peer to R7 or R8 in AS200 Configure R7 and R8 as peers - This is done too I

Re: ATTEMPT state.....Why? [7:32788]

2002-01-22 Thread Engelhard M. Labiro
Hello,In an OSPF netw. in a FR hub-and-spoke topology(RTA and RTC being the spokes and RTB being the hub), using physical intfs. and using map statements in the spokes, and neighbor statements, why do the spokes show a state of Attempt/Drother for the other spoke but in the hub show the

Re: Ipexpert lab 4 question. [7:32555]

2002-01-19 Thread Engelhard M. Labiro
Rajesh, I was going thru the Lab 4 of IPEXPERT notes - IGRP/EIGRP. I couldn't follow the reason why on Router 4's serial interface ip split-horizon is given. This is to prevent R4`s IGRP to not re-inject the routes its learned from R2. Remember that R2 and R4 are in the same IGRP routing

Re: How to make Serial 0 up/up without connecting [7:32410]

2002-01-18 Thread Engelhard M. Labiro
Use loopback command at the serial interface mode. For ethernet I/F, use no keepalive command. Could someone help me this : Configure Serial interface up/up without a cable connecting to it... Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=32415t=32410

Re: CCIE #8642 [7:32411]

2002-01-18 Thread Engelhard M. Labiro
Hi William, Congratulations! Passed at first time, that is impressive. Any secrets ? How long did you prepare for the lab after you got the written? Any lab`s materials can you recommend other than what we already knew ? Regards, First I would like to thank everyone here who has answered my

Re: How to make Serial 0 up/up without connecting [7:32410]

2002-01-18 Thread Engelhard M. Labiro
My finding is different with you. What IOS version do you use ? This behavior may be version or router type dependent . r8#sh controllers s0/0 Interface Serial0/0 Hardware is PowerQUICC MPC860 No serial cable attached There is no way you can spoof a serial line to up/up state via

Re: How to make Serial 0 up/up without connecting [7:32410]

2002-01-18 Thread Engelhard M. Labiro
Re-post, groupstudy filters part of the e-mail. -start re-post My finding is different with you. What IOS version do you use ? This behavior may be version or router type dependent . r8#sh controllers s0/0 Interface Serial0/0 Hardware is PowerQUICC

Re: Help !! 3620 + NM-1E2W + WIC-2T = trouble [7:31976]

2002-01-15 Thread Engelhard M. Labiro
I have a 3620 with 64 MB RAM 16 MB Flash. I installed module NM-1E2W and it works fine, but when I install the WIC-2T in either WAN slots it doesn't recognize it. The WIC-2T works on my 1720 and 2610. I've tried 2 different IOS already (IOS 12.2 Enterprise Plus IPSec 56 and 12.1 IP Plus

Re: How to interpret information on Show version [7:31943]

2002-01-14 Thread Engelhard M. Labiro
Can anyone enlighten me what does 8192K/4096K bytes mean when we perform show version ? Your total DRAM memory is 8192+4096 = 12288 K. The number before the slash (8192) is the amount of DRAM allocated for Local Memory, and the number after the slash (4096) is the amount of DRAM allocated

Re: Emergency: PIX 515 password recovery [7:31514]

2002-01-10 Thread Engelhard M. Labiro
How about setup a temporary AAA server with an userpassword and login with that username? You can use sniffer for the IP address of AAA server going out the PIX interface. for my case, once I use default password cisco to enter it... the aaa configuration take effect, and it prompt out

Re: IGRP Subnet mask issues [7:31349]

2002-01-09 Thread Engelhard M. Labiro
Without changing the interface subnetmask to /24, break 10.0.0.0/24 to several /30 networks (10.0.0.0/30 to 10.0.0.252/30) , make a static route for each /30 network to the interface connecting 10.0.0.0/24, and redistribute those static routes to IGRP domain. This kind of solution is defined at

Re: IGRP Subnet mask issues [7:31349]

2002-01-09 Thread Engelhard M. Labiro
Hi Aamer, This is another solution without static routes. The idea is still the same, break 10.0.0.0/24 to smaller /30 networks to fit with the interface of IGRP domain (10.3.255.8/30), using summary-address at OSPF. r2#sh run router ospf 1 summary-address 10.0.0.0 255.255.255.252

Re: Call Manager 3.1 [7:31335]

2002-01-08 Thread Engelhard M. Labiro
Hi Jim, Just received Cisco AVVID IP Telephony Networks book, and according to that book, Cisco has certified Compaq DL320 and Compaq DL380 to run CallManager. Refer to this URL regarding the approved hardware for Compaq ProLiant

Re: IDS Test [7:30806]

2002-01-03 Thread Engelhard M. Labiro
Does anyone have any info on the IDS test. Specifically, Do you have to memories the couple hundered pages of Signatures in the IDS book ? Yes, there are specific questions about signatures. I didn`t spend too much time with signatures and only try to understand the points and memories the

Re: How to Block MSN ... [7:30891]

2002-01-03 Thread Engelhard M. Labiro
It uses TCP port 1863. See the detail at MSN page itself http://messenger.msn.com/support/firewall.asp HTH Can anyone tell me how can I block msn messanger on my network..What port in the access list should I block to stop workers from using msn messanger ??Does it uses a fix port ?I

Re: Subinterface P-2-P [7:30070]

2001-12-24 Thread Engelhard M. Labiro
I am trying to set-up a point-to-point subinterface but I do not see the point-to-point or multipoint options under the physical interface as follows: r5-s(config)#interface serial 0.1 ? I am having problems creating the point-to-point subinterface on both the 2500 and 2600 router

Re: Cisco RIP Off [7:29612]

2001-12-20 Thread Engelhard M. Labiro
Would you share us the sources for QoS exam ? Appreciate for any pointers. - Original Message - From: Steven A Ridder To: Sent: Thursday, December 20, 2001 1:18 AM Subject: Re: Cisco RIP Off [7:29612] I took it. It took us 4 guys with books, internet and 8 hours to get two people

Re: How to connect cisco device console thruogh Linux machine [7:28660]

2001-12-10 Thread Engelhard M. Labiro
How to connect console through serial port of linux machine? Try minicom , refer to this link: http://rtfm.phpwebhosting.com/tips/2000/06/13/34.shtml HTH Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=28660t=28660 -- FAQ,

Re: what command to use... [7:28636]

2001-12-09 Thread Engelhard M. Labiro
the command to stay in Priviliged Exce Mode, the router keep kicking me out and I have to type enable password again to login if I let router idle for a while.. Add exec-timeout 0 0 to VTY for telnet or CON for console. HTH Message Posted at:

Re: Deny trace route using ACL on Cisco router [7:28047]

2001-12-04 Thread Engelhard M. Labiro
Ciscos ( Unixes) use ICMP time-exceeded reply to the host that doing traceroute, so not return icmp time-exceeded or drop all the icmp packet would be better, eg: access-list 101 deny icmp any any and assign it to the interface to the Internet. Can someone share with me the experience in

Re: isdn problem [7:27975]

2001-12-03 Thread Engelhard M. Labiro
Assume that router1 initiates call to router2, the password that router1 send to router2 must be the SAME with the password configured at router2. router1#sh run username router2 password 0 router2 router2#sh run Building configuration... Current configuration: ! version 12.0

Re: Policy routing BGP Neighbor relationships [7:27976]

2001-12-03 Thread Engelhard M. Labiro
Is it me or does BGP not allow you to form a peering session unless you have a route to the host in the routing table, no matter what. Yes, eBGP won`t form a session if the peer address is not in its route table. It closes connected sessions even if I have policy route data forwarding

Re: CCIE R/S written [7:27968]

2001-12-03 Thread Engelhard M. Labiro
does any body knows the tentative date of the new version of CCIE R/S written qualificationt test would be applied The rumour is January 2002. how much material difference it would be compared to the old one ? Have no idea. I'm preparing for CCIE R/S written test, and it seems to be a bad

Re: IOS PROBLEM!! [7:26978]

2001-11-21 Thread Engelhard M. Labiro
If you have an CCO account, using the IOS Feature Navigator could easily search base on Feature or IOS version which router platform support which feature. Searching with IGRP keyword, the result is 1000 series is the lowest Cisco router that support IGRP.

Re: Is Pix failover can be Load balancer ? [7:26673]

2001-11-19 Thread Engelhard M. Labiro
AFAIK PIX Failover only provides redundancy, no traffic load balance. If you need Firewall load-balance, go to the Nokia IP series firewall, or Checkpoint+Stonebeat combo (www.stonebeat.com) HTH I wish to know wheather 2 cisco pix firewalls can be configured for redundancy as well as Load

Re: CCNA 1.0 and CCNP 2.0 [7:26606]

2001-11-18 Thread Engelhard M. Labiro
I have a question here, I got my CCNA 1.0 before and I completed the CCNP 2.0 today. Do I need to re-exam CCNA 2.0?? FYI, you can monitor your cert. progress and the expiration date for each certification you earned through http://www.galton.com/~cisco. HTH Message Posted at:

Re: ospf config [7:26034]

2001-11-12 Thread Engelhard M. Labiro
The network 192.168.30.0/24 and 192.168.31.0/24 are in different networks, the routers won`t see each other. Change the netmask to 16 bits. CDP will finds the other neighbour since it operates at Layer 2. HTH Router A: int e0/0 ip address 192.168.30.0 255.255.255.0 ip ospf network

Re: ebgp-multihop command [7:24482]

2001-10-29 Thread Engelhard M. Labiro
Hi, Normaly use ebgp-multihop if you put the IP address of loopback interface of your peer at the neighbor command eg: if your peer loopback is 1.1.1.1, the command will be neighbor 1.1.1.1 remote-as 1 neighbor 1.1.1.1 update-source loopback neighbor 1.1.1.1 ebgp-multihop. As the document says

Re: OSPF across PIX [7:24608]

2001-10-29 Thread Engelhard M. Labiro
Pat, Since OSPF uses IP protocol 89, permit this protocol between the two OSPF routers with access-list applied at outside and inside PIX interfaces, something like this: access-list 101 permit 89 host 1.1.1.1 host 2.2.2.2 access-list 102 permit 89 host 2.2.2.2 host 1.1.1.1 access-group 101

Re: OSPF across PIX [7:24608]

2001-10-29 Thread Engelhard M. Labiro
Sorry, replying my own message. The access-list below assumes that you are able to use nat 0 command (no NAT translation will occur for the internal IP addressess to be seen from outside network). If you are doing NAT then a global and nat combination need to represent the internal IP addresses

Re: OSPF Authentication with Virtual Links [7:24457]

2001-10-28 Thread Engelhard M. Labiro
Hi, At the virtual link line for both routers, add a message-digest authentication, eg: Router A area 1 virtual link 192.168.5.5 message-digest-key 1 md5 pass The area 0 auth message-digest is needed at RouterA also since it is ABR for area 3. HTH Ran into following during a lab scenario, but

Re: how to connect to token interface on router with IBM 8228 [7:18220]

2001-09-02 Thread Engelhard M. Labiro
Use a CAT 5 straight cable, plug one end to the router`s RJ45 and the other end to the IBM MAU`s connector. This connector which I don`t know whats its name, you plug it to the IBM 8228 and its has a RJ45 at the other end. Someone point me out to use IBM 8228 as Token Ring switch a while before,

Re: How do I get into the COLT? [7:17531]

2001-08-28 Thread Engelhard M. Labiro
AFAIK the link is no longer available even if you have CCO account. I am studying for my third Cisco exam. I've heard about taking the Colt testing for a practice dry run. How do I get into the COLT? I have a CCO account, but I can't seem to find the COLT within the CISCO website.

Re: how to clear a router counter at frequency basis [7:16787]

2001-08-22 Thread Engelhard M. Labiro
Try expect script. HTH - Original Message - From: Sim, CT (Chee Tong) To: Sent: Wednesday, August 22, 2001 7:09 PM Subject: how to clear a router counter at frequency basis [7:16787] Hi.. I need to clear counter on a router at frequency basis eg:1 day and save it to file in a

Re: For FR Grus.... [7:16635]

2001-08-21 Thread Engelhard M. Labiro
Hi Cisco Lover, Looks like the DLCIs advertised by the FR-Switch, try use no frame-relay inversearp to disable the spokes router keeps hearing the DLCIs from FR-Switch. HTH Oopss Sorry guys...I donto know where it lost in b/w..Any way..I have write it here again. Thanks for the kind

Re: books on PIX? [7:16720]

2001-08-21 Thread Engelhard M. Labiro
There are two books that cover for PIX Firewall for several chapters: 1. MCNS by Michael Wenstrom 2. Cisco Secure Internet Solutions by Andrew G. Mason. I have these two but I think the informations provided in these books, anyone can find it on CCO instead. HTH Anyone know of any good

Re: DS3 Question [7:16533]

2001-08-20 Thread Engelhard M. Labiro
This URL may help you : http://www.cisco.com/pcgi-bin/front.x/newConfig/config_root.pl HTH - Original Message - From: Scarlett Tony To: Sent: Monday, August 20, 2001 9:31 PM Subject: DS3 Question [7:16533] Hi, I have been reading the threads in this group for several months now and

Re: traceroute [7:16494]

2001-08-19 Thread Engelhard M. Labiro
Press Shift-Ctrl and 6 , two times. hi , how can we quit in between when router is tracerouteing any destination from traceroute or cancel the traceroute thanx kaushlender Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=16498t=16494

Re: traceroute [7:16494]

2001-08-19 Thread Engelhard M. Labiro
While you are doing reverse telnet, then the command below will send you back to the terminal_server instead of stopping the traceroute command. ctrl+shift+6 then press x Best Regards Have A Good Day!! *** Farhan Ahmed* MCSE+I, MCP

Re: Access list to allow IPSEC traffic through? [7:16367]

2001-08-17 Thread Engelhard M. Labiro
Permit the following for IPSEC traffic: IKE : UDP port 500 ESP: protocol 50 HTH - Original Message - From: Andy To: Sent: Friday, August 17, 2001 10:38 PM Subject: Access list to allow IPSEC traffic through? [7:16367] Hi Does anyone know the correct requirements to allow IPSEC

Re: 2513 to MAU RJ-45 connection? [7:16426]

2001-08-17 Thread Engelhard M. Labiro
Hi, I have 4 2612 (one RJ45 Token Ring I/F), how do I connect these routers` Token Ring I/Fs back-to-back? I tried using a UTP 5 straigh/cross cable but the link is down/down state. Searching the CCO but only come up connecting MAU to RJ-45 as you mention below. Any idea ? Thanks, -

C2948G-L3 support for IP policy [7:12458]

2001-07-16 Thread Engelhard M. Labiro
Hi group, I have two routers R1 and R2 in front of C2948-L3 switch and a Lotus Notes server and several servers behind the C2948 switch. I want to control the traffic coming to and going out from the Lotus Notes server goes through R2 only and the others traffic should goes to router R1. Does it

Re: MCNS 2.0 [7:12091]

2001-07-12 Thread Engelhard M. Labiro
Hi, I prepared using Michael Wenstrom book and Donald C. Lee`s book (Enhanced IP Services for Cisco Networks, Chapter 6-8 ISBN 1-57870-106-6). I think Donald`s book is easy to understand than Michael`s which looks like a manual that anyone can download from CCO. Understanding the concept to pass

Re: Voice Specialization Exam 640-647 [7:11037]

2001-07-05 Thread Engelhard M. Labiro
Hi, CVOICE 640-647 retired for individual NP specialization, but it is still available as a specialization requirement for Field Engineer at Cisco Partner, see http://www.cisco.com/warp/public/765/partner_programs/specialization/voice_a ccess/requirements.shtml EML CCNP+Voice, CCDP -

Re: CVOICE 640-647 [7:6402]

2001-05-30 Thread Engelhard M. Labiro
Hi Passing score is 700. BTW, the exam is already retired as May 15. HTH Engelhard M. Labiro Netmarks Inc. 3rd Group, Network Solution Department, Technology Eng. Division 1-3-12 Moto Akasaka, Minato-Ku, Tokyo, Japan 107 - Original Message - From: To: Sent: Wednesday, May 30, 2001 8

Re: CVOICE 640-647 [7:6402]

2001-05-30 Thread Engelhard M. Labiro
Laszlo, CVOICE 640-647 is retired also as CCNP Specialization exam, as May 14, 2001. However it still available for Cisco Partner qualification. HTH Engelhard M. Labiro Netmarks Inc. 3rd Group, Network Solution Department, Technology Eng. Division 1-3-12 Moto Akasaka, Minato-Ku, Tokyo, Japan