RE: Cat4006 - Prompt [7:63984]

2003-02-27 Thread Martin J.
create new prompt with no string: set promt "nothing" Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63991&t=63984 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondi

Re: VPN client conflict [7:63951]

2003-02-27 Thread Martin J.
no fix available. Cisco allows no other client installed. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63992&t=63951 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and No

RE: VPN Client behind PIX [7:64358]

2003-03-05 Thread Martin J.
try do encapsulate IPSec in UDP, otherwise IPSec will be dropped. IKE is already UDP500, bit EPS and AH are Protocol 50 and 51. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=64479&t=64358 -- FAQ, list archives, and subscription in

RE: VPN Client behind PIX [7:64358]

2003-03-06 Thread Martin J.
i am not sure about that. i have a checkpoint FW (let's say it is stateful). behind the FW sits the VPN 3000. i connect with VPN SW Client. works fine with IPSec over UDP. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=64579&t=64358 --

RE: Compression on 2610 routers [7:64702]

2003-03-07 Thread Martin J.
For SW you don't need an AIM. HW requires an AIM example of HW compression: frame-relay payload-compression FRF9 stac caim 0 for SW replace stac caim 0 with software. Be sure, that 12.1 work well wiht your central Router. We had som troubles with a 7206 on central site. we are now on 12.2.12 h

RE: CCSP track [7:64735]

2003-03-10 Thread Martin J.
i think order of taking tests isn't importent (maybe safe test should be last). i started last week with csvpn, next will do mcns so i get the "vpn specialist ". problem of ids is, who does isd and when doing, who does it with cisco ;-) tell if you hear other opinions. Message Posted at: http:

RE: Compression on 2610 routers [7:64702]

2003-03-10 Thread Martin J.
We have typical office-envirement: some word, excel, some host, web. HW-compression brings up to 9:1 (average, i thing 4-5:1). Take attention with SW, even a 72xx can't handle many of SW compressed links. Lupi is right. Before implementing you have to test. Ask your Cisco Provider for AIM Boards t

Switch Monitoring via Trunk on Cat [7:65045]

2003-03-11 Thread Martin J.
Hi All Is there a way to set up a span (monitoring) port via a link or a trunk? The meaning is, that the port I like to monitor is on a catalyst in an other building. Thanks for your help Martin Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=65045&t=65045

RE: VPN: difference between hash / group/encryp ? [7:65131]

2003-03-12 Thread Martin J.
Hash is needed for Data Integrity. Two possibilities: HMAC-MD5 or HMAC-SHA-1 A sent the message and the shared secret key trough the Hash-Algorithm. Hash is appended at the message. B recomputes the Hash with the message and the shared secret key. Hashs are compared. If matching, integrity of messa

RE: Off-topic: VPN possible? [7:65239]

2003-03-13 Thread Martin J.
in an NAT environement you need to encapsulete the VPN traffic into UDP or TCP (because ESP has no port#, has protocolnumber 50).Otherwise VPN traffic after IKE will be dropped. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=65276&t=65239

RE: VPN Concentrator Setup Question [7:65299]

2003-03-13 Thread Martin J.
I am not sure to understand your problem. Fact is that VPN 3002 is the HW Client. VPN3005/15/30/60/80 are Concentrators. - SW Clients can connect to Concentrator. - HW Clients can connect to Conce3ntrator. - Conentrator can connect to Concentrator. - SW Client can not connect to HW Client. - SW cli

RE: ISP OSPF Design [7:65316]

2003-03-13 Thread Martin J.
normally ISP networks are with BGP. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=65317&t=65316 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations

RE: Setting up dial-in [7:66058]

2003-03-24 Thread Martin J.
Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=66059&t=66058 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

RE: VPN remote access via analog modem?? [7:65991]

2003-03-24 Thread Martin J.
to 1): PIX 515 can terminate 1000 tunnels (SW) or 2000 (HW)at max 10Mps VPN Performance. to 2): analog is no problem (same as ISDN). ISP gives you the "physical" address. If connecting to your VPN site you will be given a tunnel address from your central site. Both physical and tunnel IP's are ac

RE: VPN remote access via analog modem?? [7:65991]

2003-03-25 Thread Martin J.
to 1): PIX 515 can terminate 1000 tunnels (SW) or 2000 (HW)at max 10Mps VPN Performance. to 2): analog is no problem (same as ISDN). ISP gives you the "physical" address. If connecting to your VPN site you will be given a tunnel address from your central site. Both physical and tunnel IP's are ac

RE: Software Compression [7:66312]

2003-03-27 Thread Martin J.
Compression Ratio <1.0 is negative, thats correct. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=66314&t=66312 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclo

Re: reload 3500XL switch [7:66222]

2003-03-27 Thread Martin J.
Hi The command is: switch#reload ? LINEReason for reload at Reload at a specific time/date cancel Cancel pending reload in Reload after a time interval Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=66315&t=66222 --

RE: 2 different CCNP certifications [7:66547]

2003-03-31 Thread Martin J.
Hi With the 2nd option you can save some money. But the foundation exam will take much more time than one single exam. I think it is more difficult to take the foundation exam. With single exams you can take step by step an then "forget" the non-relating themes ;-) For example it can be confusin

RE: VPN 3000 & Token Server [7:66577]

2003-04-01 Thread Martin J.
Hi We implemented with ActivCard's AvtivPack Server. http://www.activcard.com We have Novell NDS for User Database. Activcard is best integrated in NDS. We also had a pilot with SecureID, but Integration in NDS (via LDAP) did not fit. Regards Martin Message Posted at: http://www.groupstudy.co

RE: ISDN Question [7:66610]

2003-04-02 Thread Martin J.
maybe with debug isdn q921 or debug isdn events regards martin Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=66671&t=66610 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduc

RE: VPN 3000 & Token Server [7:66810]

2003-04-04 Thread Martin J.
Hi Ed Sure I answered 04-01: Hi We implemented with ActivCard's AvtivPack Server. http://www.activcard.com We have Novell NDS for User Database. Activcard is best integrated in NDS. We also had a pilot with SecureID, but Integration in NDS (via LDAP) did not fit. Regards Martin Message

RE: icmp [7:66827]

2003-04-04 Thread Martin J.
Once i heard, that a ping from a Cisco Box is not the same like a ping from a Windows PC. One is icmp the other is udp. Can anyone confirm? and, where is udp , where is icmp. One solution to make it all clear is to take a sniffer - or i could search my CIT Course stuff this weekend ;-) Martin