Re: [c-nsp] How to monitor BGP sessions

2007-04-17 Thread liviu . pislaru
hello robert, you can try to obtain automatically (with the same monitoring script) neighbors ip adresses (ipv4 or ipv6); EXAMPLE (perl): - you have router X with the ip adress $iprouter: $comm=""; # put here your own password $oid="1.3.6.1.2.1.15.3.1.7"; ($session,$error) = Net::SNMP

Re: [c-nsp] %LC-6-PSA_UCODE_NO_SUPPORT: Current bundle does NOT support(Link bundling)

2007-04-17 Thread Oliver Boehmer \(oboehmer\)
Peter Kranz <> wrote on Wednesday, April 18, 2007 2:27 AM: > Any quick hits on how to solve this: > > SLOT 3:Apr 17 11:51:02: %LC-6-PSA_UCODE_NO_SUPPORT: Current bundle > does NOT support (Link bundling) > > On a GSR 12008 running a Engine 2 3 port GigE card > > Relevant config/details: > > IO

Re: [c-nsp] PPS

2007-04-17 Thread Saku Ytti
On (2007-04-18 07:16 +0800), Lincoln Dale (ltd) wrote: > actually, it really does "depend" on the platform. many platforms have > 'distributed' forwarding - e.g. take a 6500 or 7600. > you *can* have centralized forwarding (no DFCs installed) or you can > have 'partially centralized' (DFCs on some

Re: [c-nsp] BGP hold time problem

2007-04-17 Thread Bruce Pinsky
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Matthew Simpson wrote: > I'm having a problem with a BGP session with level3. It has dropped > twice in the last week now with a hold time expired message. The port > stays up and the BGP session comes back 5 minutes later. > > Log: > > %BGP-3-NO

[c-nsp] Regarding QinQ and 802.1ad-2005

2007-04-17 Thread Arnab Bakshi
Hi All, I have been experimenting with QinQ a few days and I came across some issues and questions I would like to put forward. My question is whether QinQ or 802.1Q which is said to be supported by cisco 3550, 7206 series switch/router is the same as the QinQ tunnelling that is defined in

[c-nsp] BGP hold time problem

2007-04-17 Thread Matthew Simpson
I'm having a problem with a BGP session with level3. It has dropped twice in the last week now with a hold time expired message. The port stays up and the BGP session comes back 5 minutes later. Log: %BGP-3-NOTIFICATION: received from neighbor 4.78.220.xx 4/0 (hold time expired) 0 bytes %BGP

Re: [c-nsp] 7200 / NPE-G2

2007-04-17 Thread Frank Bulk
That raises a good question...if an NPE-400 with 2000 PPPoA and 35 PPPoE operates at 44% today, what would a G2 bring that down to? Frank -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Clayton Zekelman Sent: Tuesday, April 17, 2007 7:08 PM To: ; cisco-ns

[c-nsp] %LC-6-PSA_UCODE_NO_SUPPORT: Current bundle does NOT support (Link bundling)

2007-04-17 Thread Peter Kranz
Any quick hits on how to solve this: SLOT 3:Apr 17 11:51:02: %LC-6-PSA_UCODE_NO_SUPPORT: Current bundle does NOT support (Link bundling) On a GSR 12008 running a Engine 2 3 port GigE card Relevant config/details: IOS (tm) GS Software (GSR-K4P-M), Version 12.0(28)S2, RELEASE SOFTWARE (fc1) gsr-

[c-nsp] SNMP & IPv6 (WAS: Re: How to monitor BGP sessions)

2007-04-17 Thread Trent Lloyd
Howdy, Antonio Querubin wrote: > On Tue, 17 Apr 2007, Robert Boyle wrote: > >> The MIB is: >> >> 1.3.6.1.2.1.15.3.1.2.a.b.c.d >> >> where a.b.c.d is the IP address of your BGP neighbor. > > Anyone know how the 'a.b.c.d' is mapped for an IPv6 BGP neighbor? I've > got a bunch of such neighbors b

Re: [c-nsp] 7200 / NPE-G2

2007-04-17 Thread Clayton Zekelman
I'm running one with Version 12.4(4)XD4. So far 15 weeks of uptime, no issues with 924 L2TP, and 762 PPPoE sessions - 24% CPU Utilization. Come to think of it, I would have thought I'd be seeing a bit better performance. - Original Message --- Subject: [c-nsp] 7200 / NPE-G2

Re: [c-nsp] PPS

2007-04-17 Thread Lincoln Dale \(ltd\)
> > I was looking to find the total PPS the switch is doing, the switch > > performacne sheet on cisco i think said it could handle 35,000,000 or > > 40,000,000. Is it talking about each interface being able to handle > this > > amount? I assumed it was the total amount of everything combine? >

Re: [c-nsp] How to monitor BGP sessions

2007-04-17 Thread Antonio Querubin
On Tue, 17 Apr 2007, Robert Boyle wrote: > The MIB is: > > 1.3.6.1.2.1.15.3.1.2.a.b.c.d > > where a.b.c.d is the IP address of your BGP neighbor. Anyone know how the 'a.b.c.d' is mapped for an IPv6 BGP neighbor? I've got a bunch of such neighbors but doing an snmpwalk through that OID subtree

Re: [c-nsp] PIX VPN

2007-04-17 Thread Ahmad Cheikh-Moussa
Hi! On Apr 13, 07, Ahmad Cheikh-Moussa wrote: > Hi! > > I have a general question to PIX and VPN > A customer has a PIX 506 with 6.3(5) and wants to establish > a vpn tunnel. Normally no big thing, but he wants to terminate > the vpn tunnel on the inside interface. Do not ask why. > Actually he h

Re: [c-nsp] 7200 / NPE-G2

2007-04-17 Thread
Arie, Aggregation of frame and leased lines, some dot1q, and EIGRP for a routing protocol. For hardware I'd fill them with PA-2T3+ and PA-MC-2T3+ adapters. On 4/17/07, Arie Vayner (avayner) <[EMAIL PROTECTED]> wrote: > Can you give a bit more info what you are planning to use the 7200 > router

Re: [c-nsp] Citrix / load balance / cef

2007-04-17 Thread Rodney Dunn
On Tue, Apr 17, 2007 at 09:35:18AM -0700, Voll, Scott wrote: > I'm trouble shooting a Citrix issue dropping. > > > > The setup involves two T1's to the site. I'm per packet load balancing > over them. (note they just went from one t1 to two) You will have packets out of order. Did you try MLP

[c-nsp] ASA 5500 Appliance - HTTPs stateful failover replication

2007-04-17 Thread Juan Angel Menendez
Hello list, Reading the ASA Software version 7.2 documentation, I found that, among other things, HTTP stateful replication is provided. Does this include HTTPs (443) replication for WebVPN ? Ie: (SSL Browser) -> ASA -> HTTPs -> SSL WebServer If not

[c-nsp] STG and ifHCOctets

2007-04-17 Thread Vincent
Hi, this is more a STG question than a Cisco question, but I have no other place to ask : did anybody get STG to work with 64-bit interface counters? Packet capture shows that STG is doing a SNMPv1 request, while it should be v2c. STG site (http://leonidvm.chat.ru/) vaguely claims support for v

[c-nsp] Citrix / load balance / cef

2007-04-17 Thread Voll, Scott
I'm trouble shooting a Citrix issue dropping. The setup involves two T1's to the site. I'm per packet load balancing over them. (note they just went from one t1 to two) They say they get kicked off every 10 minutes. Is there any kind of thing within IOS with either per packet load bala

Re: [c-nsp] How to monitor BGP sessions

2007-04-17 Thread Ed Ravin
On Tue, Apr 17, 2007 at 05:20:08PM +0200, chiel wrote: > I was wondering how you guys monitor your BGP sessions. Do you > use snmp traps or do you poll the router with a snmp get As already posted by others, you can use either method. Here's a script that uses SNMP to get the router status, and c

[c-nsp] How to monitor BGP sessions

2007-04-17 Thread chiel
Hello, I was wondering how you guys monitor your BGP sessions. Do you use snmp traps or do you poll the router with a snmp get (if thats posible)? I ask this because I want don't want to get notified if one bgp goes down. But I would like to know if a important bgp session goes down/flapping.

Re: [c-nsp] How to monitor BGP sessions

2007-04-17 Thread Robert Boyle
At 11:20 AM 4/17/2007, you wrote: >Hello, > >I was wondering how you guys monitor your BGP sessions. Do you use >snmp traps or do you poll the router with a snmp get (if thats posible)? >I ask this because I want don't want to get notified if one bgp goes >down. But I would like to know if a impo

Re: [c-nsp] How to monitor BGP sessions

2007-04-17 Thread Justin M. Streiner
On Tue, 17 Apr 2007, chiel wrote: > I was wondering how you guys monitor your BGP sessions. Do you use snmp > traps or do you poll the router with a snmp get (if thats posible)? > I ask this because I want don't want to get notified if one bgp goes > down. But I would like to know if a important

Re: [c-nsp] How to monitor BGP sessions

2007-04-17 Thread Roland Dobbins
On Apr 17, 2007, at 9:02 AM, Justin M. Streiner wrote: > An external system (NMS, etc) would need to determine what > "important", > "flap", etc mean, based on rules provided by you. Arbor Peakflow SP watches BGP and can provide some correlation between BGP events and traffic events observed

Re: [c-nsp] Cisco load balancers with SSL offload

2007-04-17 Thread Marcin Mazurek
> > We've also tested the ACE, and have several in production. It's going > to be a definite upgrade from the CSS when some of the little kinks are > worked out. We are currently using their 6500 module, and have the > actual appliance that is going to be released in testing. There are > so

Re: [c-nsp] 7200 / NPE-G2

2007-04-17 Thread Arie Vayner \(avayner\)
Can you give a bit more info what you are planning to use the 7200 router for? Arie -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Sent: Tuesday, April 17, 2007 17:27 PM To: cisco-nsp@puck.nether.net Subject: [c-nsp] 7200 / NPE-G2 Does anyone have exper

Re: [c-nsp] >256MByte Processor Memory for Linecards running a fullBGP-table?

2007-04-17 Thread Matt Addison
The linecards do not carry full BGP tables, just the CEF table. Check the output of "execute-on slot show memory free", you probably have a good amount of free memory on the LCs (I have ~ 80MB free on my LCs). ~Matt From: [EMAIL PROTECTED] on behalf of Sven J

Re: [c-nsp] PAgP or LACP timers

2007-04-17 Thread Pickett, McLean (OCTO)
Dell has a pass through card that allows you to connect the server NIC's directly to your 3750, which is perfect and solves all of these problems. A quick check to the IBM site did not a comparable Ethernet card. The Cisco switch modules are inadequate because you cannot channel server NIC's insi

[c-nsp] 7200 / NPE-G2

2007-04-17 Thread
Does anyone have experience/feedback that they're willing to share on the moderately new G2 engine ? I suspect that software is more of a wild card than the hardware itself. Does anyone have an opinion on whether one is better off with 12.4.11T or 12.2SB ?

Re: [c-nsp] PPS

2007-04-17 Thread Shaun
I was looking to find the total PPS the switch is doing, the switch performacne sheet on cisco i think said it could handle 35,000,000 or 40,000,000. Is it talking about each interface being able to handle this amount? I assumed it was the total amount of everything combine? ~Shaun > Don't

Re: [c-nsp] Bonding

2007-04-17 Thread Tom Sands
You should be able to use any switch that supports etherchannel via LACP (which is just about any Cisco switch). The commands will depend on what switch you are going to go with. -- Tom Sands

Re: [c-nsp] Best Practice for ISP (Rebooting the switch)

2007-04-17 Thread Rader, Troy D.
A comical aside to this topic is people comparing uptimes. Much of our equipment (6500/7600) is currently in the 2+ years range now. In the past, I have seen, a 2500 router up over 4+ years. Recently, a friend at Cisco sent a note about a switch or router that had been up for 8+ years. Clearly,

Re: [c-nsp] PPS

2007-04-17 Thread Saku Ytti
On (2007-04-16 23:56 -0700), Shaun wrote: > I was looking to find the total PPS the switch is doing, the switch > performacne sheet on cisco i think said it could handle 35,000,000 or > 40,000,000. Is it talking about each interface being able to handle this > amount? I assumed it was the tot

[c-nsp] Bonding

2007-04-17 Thread Eusebio López
Hi, I want to make bonding between linux and switch. I need that switch is Cisco? That commands I must use? Could use switch allied telesyn? Cheers ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo

Re: [c-nsp] PAgP or LACP timers

2007-04-17 Thread Arie Vayner \(avayner\)
Ran, I am not 100% sure this would help, but you may want to try and use UDLD on the ports. The timer can be reduced down to 1 second. I would recommend you run it in aggressive mode. Take a look here: http://www.cisco.com/univercd/cc/td/doc/product/lan/cat3750/12235se/scg/ swudld.htm Arie ---

[c-nsp] Converting Junos firewalls to Cisco ACL

2007-04-17 Thread Ian MacKinnon
Hi all, Has anybody seen a tool for converting Junos firewall rules into Cisco ACL's? I know Juniper have one to go the other way. I have several hundred to do, and manually will be a pain and liable to error. Junos rules look like :- filter test-out { term permit_tcp_established {

[c-nsp] >256MByte Processor Memory for Linecards running a full BGP-table?

2007-04-17 Thread Sven Juergensen
Dear list, we have several FRU: Linecard/Module: 3GE-GBIC-SC= Processor Memory: MEM-GRP/LC-256= Packet Memory: MEM-PKT-512-UPG= L3 Engine: 2 - Backbone OC48 (2.5 Gbps) MBUS Agent Software version 2.48 (RAM) (ROM version is 3.47) ROM Monitor version 17.1 Fabric Downloade

Re: [c-nsp] 6500 / 7600 output drops

2007-04-17 Thread Richard Harvey
If you're getting output drops then the interface may well be getting genuinely congested, albeit on a very temporary basis. I have seen an IPTV platform achieve a target streaming rate by 'bursting' at full line rate - eg. 100mbps achieved by sending full 1Gbps of traffic then 9 x 0Gbps of traff

Re: [c-nsp] Cisco 1811 DNS Server overload

2007-04-17 Thread John Kougoulos
Hello, I had a similar situation on a 1812 running 12.4(11)T with dns spoofing enabled and while I was searching at the release notes I saw that a lot of new functionalities where added in the DNS process on 12.4(11)T. eg. dns views. I disabled spoofing, downgraded to 12.6T6 and everything loo