pix + router, design issue [7:63244]

2003-02-18 Thread Skarphedinsson Arni V.
I have a case with a customer that I am installing a PIX and a border router for, He want´s to have controle over the border router, but the Service Provider, is providing their router as the CPE. one interface on the Service Providers router has an ip address from the customers public ip address r

CCNP Done, finaly [7:63355]

2003-02-19 Thread Skarphedinsson Arni V.
Just finished BSCI today, and also my CCNP. boy the BSCI was realy hard, I think it was harder then all the other combined. But thats probably beacuse I dont have that much experince with Routing Protocols, used the Sybex book, and hands on with my router lab to prepair. I got a lot on BGP and EI

City Wide MAN Design [7:63706]

2003-02-25 Thread Skarphedinsson Arni V.
Hi all I am looking for some insightes into a MAN desigin spanning a city using Fiber Gigabit Ethernet Links. What I am realy looking for are comments about the pros and cons of a Ring design vs. the standard Core-Dist.-Acces. design with redundant paths from the dist to the core. any thoughts

Core Layer L2 or L3 [7:63708]

2003-02-25 Thread Skarphedinsson Arni V.
In a Core-Distribution-Access Layer design, would you keep the Core L2 or with high end L2/L3 switches such as the Cat6500 do you think it would be better to do L3 in the core ? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63708&t=63708

RE: ADSL Between Head Office and Remote Branch [7:63711]

2003-02-25 Thread Skarphedinsson Arni V.
I would think that you would have to use the 828 G.SHDSL Router, not an 837 ADSL, as an ADSL connection requires an DSLAM to connect to, but the G.SHDSL is for point to point Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63712&t=63711 ---

VLAN Trunking + Access lista [7:63739]

2003-02-25 Thread Skarphedinsson Arni V.
Hi When using vlan trunking from a router, for example in a router on a stick enviroment, I would create subinterfaces on the ethernet interface on the router, does that in some way limit the use of access-lista to controle traffic, like traffic between the vlans and out of the router through ano

New CCDP [7:63848]

2003-02-26 Thread Skarphedinsson Arni V.
Please note that under the new structure, Remote Access exam (640-605) will no longer be a required exam for CCDP. Registration for the current 640-025 exam will end on May 27, 2003, and the existing Cisco Internetwork Design (CID) course will end-of-life on April 28, 2003. For those candidates who

PIX Stateful Failover [7:63959]

2003-02-27 Thread Skarphedinsson Arni V.
Hi I am reading the Cisco PIX Firewalls book by Richard A. Deal. and it states that to use the Stateful Failover feature I require a special license from cisco for the PIX. I can´t find any information about this license on the cisco website, can anyone give me some more information about this ?

CCDP question [7:63963]

2003-02-27 Thread Skarphedinsson Arni V.
I have a CCNA and CCNP yesterday I took the CID 640-025, will this do for the old requierments for CCDP, or will I also have to take the CCDA ? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=63963&t=63963 -- FAQ, list archives, a

RE: PIX Stateful Failover [7:63959]

2003-02-27 Thread Skarphedinsson Arni V.
Yes I know about the UR, and failover license, but the book gives the impresion "at least to me" that you require a seprate license from that. but having looked for it on cisco, I dont think that is the case, so I think I would just need one UR and one Failover license and with that can do both no

RE: New Voice CCIE [7:64620]

2003-03-06 Thread Skarphedinsson Arni V.
I would say it sound very intresting, sepcialy for those that have call manager / voice experince. I wonder how much routing it has, for example, I doubt you have to configure BGP on this one, or what do you think ? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=64624&t=64620 --

NAT + VPN Tunnel [7:64731]

2003-03-07 Thread Skarphedinsson Arni V.
In the following secnaryo should there be any problems for the hosts on the inside of router1 to connect to the hosts on the otherside of the VPN tunnel inside networkrouter1router2internet inside of router1 are RFC1918 addresses are used router1 is doing NAT in between the router is

ATM for Practice Lab [7:65087]

2003-03-11 Thread Skarphedinsson Arni V.
Hi All Can someone give me some clues as to what is the best way to go for ATM in an home CCIE practice LAB, I know about the LS100 and that can be found for a fair price, but what about the routers and modules ? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=65087&t=65087

Good book for CCIE Written Prep [7:65104]

2003-03-11 Thread Skarphedinsson Arni V.
Can anyone recomend a good book for CCIE Written preperation ? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=65104&t=65104 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct a

RE: CID exam - 640-025 [7:65139]

2003-03-12 Thread Skarphedinsson Arni V.
I passed it three weeks ago, no to hard I uesd the Top Down Network Design book, it´s a great book, but I actuly just got through half of it before the exam. it´s not that hard, and I took the CCDA, the old version after the CID and i would say the cid is a little harder, and not as boring i.e. d

9E0-541 Exam trobules [7:65162]

2003-03-12 Thread Skarphedinsson Arni V.
Damm routing and switching Spec. exam 9E0-541, I have taken It two times in two weeks, and failed both times the first time I got 819 need 825, today I got 777, I am s pissed, at myself for the mostpart but this exam is rather hard, atleast the version I got to day, the one I got last we

RE: 9E0-541 Exam trobules [7:65162]

2003-03-12 Thread Skarphedinsson Arni V.
I totaly agree with you about the point of pepole just learning what is enough to pass the tests, and take them again and again just to pass them, As I come from a microsoft background and am a former Microsoft MCT traineer I know this all to well, as it is a even bigger problem on that side. I wo

Cisco IOS Telephony Service [7:65363]

2003-03-14 Thread Skarphedinsson Arni V.
has any one had experince with this http://www.cisco.com/univercd/cc/td/doc/product/voice/c_ipphon/keyswtch/ft_its21.htm Sound like a good idea for small company´s Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=65363&t=65363 --

help with Debug output [7:65419]

2003-03-14 Thread Skarphedinsson Arni V.
g=218.1.140.1, len 1514, forward I am a little confused as to what the above line is telling me, can anyone please explain ? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=65419&t=65419 -- FAQ, list archives, and subscription inf

Catalyst 2948G L3 [7:65733]

2003-03-19 Thread Skarphedinsson Arni V.
Can I do SPAN monitoring on this switch, for example to do monitoring with a sniffer ? Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=65733&t=65733 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.

Large number of VLANS [7:65815]

2003-03-20 Thread Skarphedinsson Arni V.
Hi One question If I have the need to use many VLANS, let´s say around 400, can could I use a 3550 switch that supports 1005 vlans as the core, and then 2950 switches in the wiring closets, but they dont support more than 250 vlans, i.e. can I use the 3550 with all the vlans, and the just trunk f

RE: Large number of VLANS [7:65815]

2003-03-20 Thread Skarphedinsson Arni V.
I was testing this in my lab, and could not get VTP to work with this setup, as soon as I went over 254 vlans the Cat2950 gave me this message 00:17:11: %SW_VLAN-6-VTP_MODE_CHANGE: VLAN manager changing device mode from CLIENT to TRANSPARENT. 00:17:11: VTP LOG RUNTIME: VTP mode changed to Transpar

Re: Large number of VLANS [7:65815]

2003-03-20 Thread Skarphedinsson Arni V.
I have goten it to work in a lab enviroment, i.e. with out using VTP, just using VTP transperant mode and manualy configuring the vlans on all the switchs. Even though I use the "switchport trunk allowed vlan" command to limmit vlans on the trunk links, VTP still send the whole list through, and t

RE: PIX Question - IPX Support? [7:66338]

2003-03-27 Thread Skarphedinsson Arni V.
No the PIX does not support IPX only IP, you will need a router for that Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=66341&t=66338 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report m

Multicast [7:66831]

2003-04-04 Thread Skarphedinsson Arni V.
I need a little information about, multicast, if I am using multicast within a single IP network can I use the cisco 2950 switches, i.e. do I need any multicast protocolls such as IGMP and the like. Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=66831&t=66831 ---

Hosting Question [7:70255]

2003-06-06 Thread Skarphedinsson Arni V.
Hi all I have a question about hosting enviroments, For example, let say I am running a hosting buissness and I have 15 customers that I host servers for, some of the servers like DNS and such are shared for all, and some a just for one customer, all the customers have a high speed link to my net

RE: Online Audios/Videos of Networking Courses [7:70214]

2003-06-06 Thread Skarphedinsson Arni V.
I thnik its great that you have taken the time to make these courses avalible online, I am sure it will help a lot of pepole, my self included, one sugestion, It would be better to download them if you had them on an FTP Site. Keep up the good work. best regards, Arni Message Posted at: http:/

PIX & Router [7:70001]

2003-06-03 Thread Skarphedinsson Arni V.
I have a router connected to a vlan trunk one for internet access, and one for a remote branch,but then I have a pix that all my users connect throuhg, and does the NAT, but then of course the users in the remote branch that connect directly to the border router, cant access the internet as that ro

Tunnel interface Problem [7:70590]

2003-06-12 Thread Skarphedinsson Arni V.
Hi all I am trying to bring up a tunnel interface, I get up and up, but the folowing statement is shown when i do a show int tunnel Tunnel protocol/transport uninitialized and I can not get any traffic to flow through the tunnel, any thoughts ? Message Posted at: http://www.groupstudy.com/form

Re: Tunnel interface Problem [7:70590]

2003-06-13 Thread Skarphedinsson Arni V.
I will post the config, as soon as I am able, but I have a route on both sides, and can ping, Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=70621&t=70590 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list

mac address filtering [7:72684]

2003-07-21 Thread Skarphedinsson Arni V.
Hi I have some catalyst 2950 and 3550 switches, that I need to control the mac addresses of the machines that are alowed to connect to the switches, i.e. something similar to port security, but i dont want to configure it per port, but rather for a whole switch or vlan, what would be the best way

PIX xlate question [7:74012]

2003-08-15 Thread Skarphedinsson Arni V.
why would I see the folowing when I do sh xlate on the pix, i.e. one global address is beeing translated to the next in line global address ? and sugestions would be welcome Global 213.213.128.143 Local 213.213.128.142 Global 213.213.128.142 Local 213.213.128.141 Global 213.213.128.137 Local 21

RE: PIX xlate question [7:74012]

2003-08-18 Thread Skarphedinsson Arni V.
Here are the Global and NAT statements global (outside) 1 213.213.128.100-213.213.128.200 global (outside) 2 213.213.128.50 global (dmz) 1 192.168.17.150 nat (inside) 0 access-list 100 nat (inside) 2 157.157.144.49 255.255.255.255 0 0 nat (inside) 2 10.100.0.0 255.255.0.0 0 0 nat (inside) 1 0.0.0.

Proority Queuing [7:74254]

2003-08-20 Thread Skarphedinsson Arni V.
Hi I am trying to configure prioryti queuing on a cisco 828 router, I can create the priority-list just fine, but can´t apply it to any interface, in interface config mode, the priority group command is missing, any ideas on why that is ? and how I can work around this problem to give certan traffi

VACL, ACL or ???? [7:74559]

2003-08-30 Thread Skarphedinsson Arni V.
I have a question regarding L3 switches and security If I have for example an catalyst 3550 swithc with 30 vlans, and don´t want traffif flowing from vlan to vlan, I just want to allow traffic from the vlans to go to a special server vlan, and then the internet, but there are also some groups of v