Re: [c-nsp] Larger scale router rollout tools?

2007-07-04 Thread Garry
Thanks for the input ... due to the fact that things like the scp, or even netconf, would require setting up a working network config first, I stuck with hacking up a little expect script, which now does: - initial console login - configuring vlan1 - retrieving the router config via tftp to star

[c-nsp] Interface Problem - ATM dropped packets

2007-07-04 Thread Paul Stewart
How do I resolve this? acs4-con-mb#sh interfaces ATM1/0 ATM1/0 is up, line protocol is up Hardware is ENHANCED ATM PA Description: Bell ATM Cloud MTU 4470 bytes, sub MTU 4470, BW 149760 Kbit, DLY 80 usec, reliability 255/255, txload 122/255, rxload 74/255 Encapsulation ATM, loopback n

Re: [c-nsp] ARP table fwsm through snmp

2007-07-04 Thread David LaPorte
I asked about a year and a half ago to have this implemented, but I don't believe it's made it in yet. Dave Bernard wrote: > Hi, > > Is it possible to get the arp table from the fwsm (using mainly Cisco > Firewall Services Module Version 3.2(1)) through snmp. > The device is manageable through

[c-nsp] ARP table fwsm through snmp

2007-07-04 Thread Bernard
Hi, Is it possible to get the arp table from the fwsm (using mainly Cisco Firewall Services Module Version 3.2(1)) through snmp. The device is manageable through snmp (interface status, load, system info etc) however when I try to get the arp table through snmp with snmpwalk I don't get any

[c-nsp] CN=Aaron Jeskey/O=zwickerpc is out of the office.

2007-07-04 Thread ajeskey
I will be out of the office starting Fri 06/29/2007 and will not return until Mon 07/09/2007. I will be out of the office beginning June 29 thru July 9th. Should you need immediate assistance during this time please contact Joe Smith at 978.686.2255 (3517) or call HelpDesk at 978.686.2255 (4357)

Re: [c-nsp] Configure two AS on one BGP router

2007-07-04 Thread Jason Plank
You could technically trick the router by using the local-as command but that is probably not what you are going for. If you are multi-homed you should probably be applying for your own AS. Could you be mores specfic with what your goals are? On 7/3/07 2:07 PM, "Paul Stewart" <[EMAIL PROTECTED]>

[c-nsp] Lawful Intercept Questions

2007-07-04 Thread Skeeve Stevens
Hi all, In previous posts I asked about a way to 'mirror' or intercept a PPPoE session. It seems the consensus was this wasn't really possibly without utilising the lawful intercept features available in IOS. Further questions on this topic: 1) The LI feature-set - latest 12.4T has:

Re: [c-nsp] Unicast storms

2007-07-04 Thread Stephen Wilcox
On Wed, Jul 04, 2007 at 06:32:16PM +0300, Saku Ytti wrote: > On (2007-07-04 15:44 +0100), Stephen Wilcox wrote: > > > I take it you mean unicast frames with mac addresses that are currently > > unknown to the switch on that port? In which case you cant limit it that > > way.. but you have two op

Re: [c-nsp] Netflow: 7600, egress

2007-07-04 Thread Dmitry Kiselev
Hello! On Wed, Jul 04, 2007 at 06:37:26PM +0400, alexey wrote: > Hm... > Not for MSFC, because comand guide recommends to configure cef... > By the way, may be you try evidently configure cef on interface! :) It is default configuration :) Any way here is output: 7600-RSP720#conf t Enter con

Re: [c-nsp] MPLS design in a non-MPLS cored network - was Re: MPLS and VLAN on same FE or GE interface ?

2007-07-04 Thread Tim Franklin
On Wed, July 4, 2007 3:29 pm, Reuben Farrelly wrote: > I am in the process of reworking/migrating some of our existing > infrastructure - and working with tagged MPLS and VLAN traffic in this > sort of config is certainly something I expect I will doing real soon. > > In our situation we have 4 72

Re: [c-nsp] Netflow: 7600, egress

2007-07-04 Thread Dmitry Kiselev
Hello! On Wed, Jul 04, 2007 at 10:18:14AM -0400, Phil Bedard wrote: > It is only supported on the RSP720/MSFC4/SRB afaik. You can get > netflow stats for L2-switched traffic, I think "ip flow l2-switched > vlan xxx." > Have you tried not having both ingress and egress on the same > inter

Re: [c-nsp] Unicast storms

2007-07-04 Thread Saku Ytti
On (2007-07-04 15:44 +0100), Stephen Wilcox wrote: > I take it you mean unicast frames with mac addresses that are currently > unknown to the switch on that port? In which case you cant limit it that > way.. but you have two options: In risk of repeating myself, you can rate-limit them on PFC3C

[c-nsp] Rate Limit/Police/Etc a dot1q trunk

2007-07-04 Thread Skeeve Stevens
Hey guys, I have a situation where I have some dot1q trunks coming in one trunk and going out another. I would like to somehow limit the speed that these dot1q VLAN's are able to do on an individual VLAN basis. The equipment I want to do this on is a 3560G (Enhanced). I would al

Re: [c-nsp] Unicast storms

2007-07-04 Thread Stephen Wilcox
On Wed, Jul 04, 2007 at 04:37:11PM +0200, Vincent De Keyzer wrote: > > Hi Vincent, > > I'm saying it works just fine but the implementation is sucky. I use it > > extensively but you just need to set your thresholds pretty high to make > > sure they arent tripped. I also usually have it just filte

[c-nsp] Per Sorensen is out of the office.

2007-07-04 Thread Per Sorensen
I will be out of the office starting 29-06-2007 and will not return until 09-07-2007. I will respond to your message when I return. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at htt

Re: [c-nsp] L3 Interface for 2821

2007-07-04 Thread Bernd Ueberbacher
Found this module 5 min ago :-) The HWIC-1GE-SFC was expensive and suddenly I stumbled over http://www.cisco.com/en/US/products/ps5853/products_data_sheet0900aecd80581fe6.html which would be a great alternative. It's supported since Cisco IOS 12.4(11)XJ so i guess it's pretty new. In my 2821 on

Re: [c-nsp] Netflow: 7600, egress

2007-07-04 Thread alexey
Hm... Not for MSFC, because comand guide recommends to configure cef... By the way, may be you try evidently configure cef on interface! :) 2007/7/4, Dmitry Kiselev < [EMAIL PROTECTED]>: > > Hello! > > On Wed, Jul 04, 2007 at 05:35:31PM +0400, alexey wrote: > > > Hello! > > Dmitry, where have you

Re: [c-nsp] Unicast storms

2007-07-04 Thread Vincent De Keyzer
> Hi Vincent, > I'm saying it works just fine but the implementation is sucky. I use it > extensively but you just need to set your thresholds pretty high to make > sure they arent tripped. I also usually have it just filter rather than > shut the port that way it will auto-recover. > > As to wha

Re: [c-nsp] ifHCOutOctets Counter64

2007-07-04 Thread Alexandru Tudori
Hello, There is a bug in cisco IOS 12.2(33) SRA1-3 (CSCsh69601). Workaround: Upgrade to SRA4. On 6/21/07, talex < [EMAIL PROTECTED]> wrote: > > Hello, > > After upgradeing the IOS version to 12.2(33)SRA3 on C7613 Sup720, i've > noticed > some errors in the result returned by the snmp OID > ifHCO

Re: [c-nsp] Netflow: 7600, egress

2007-07-04 Thread alexey
Hm... Not for MSFC only, because comand guide recommends to configure cef... By the way, may be you try evidently configure cef on interface :) 2007/7/4, Dmitry Kiselev < [EMAIL PROTECTED]>: > > Hello! > > On Wed, Jul 04, 2007 at 05:35:31PM +0400, alexey wrote: > > > Hello! > > Dmitry, where have

[c-nsp] MPLS design in a non-MPLS cored network - was Re: MPLS and VLAN on same FE or GE interface ?

2007-07-04 Thread Reuben Farrelly
Tim Franklin wrote: > On Wed, July 4, 2007 10:24 am, Code Monkey wrote: > >> Back in 2003 I failed miserably at configuring two 7206 VXR so that >> their FE interfaces could be connected to a VLAN switch, running MPLS >> in one VLAN and non-MPLS in other VLANs. > > I've done this in a previous li

Re: [c-nsp] ISP Connection

2007-07-04 Thread Jason Lixfeld
Get your ISP to provision a /30 between them and your 2800. Then have them statically route the /25 to your end of the /30, then on your router you can do whatever you want with the /25. Assign it to an interface, subnet it further, whatever. On 4-Jul-07, at 10:20 AM, Gary Roberton wrote:

[c-nsp] ISP Connection

2007-07-04 Thread Gary Roberton
Hi I have a 'raw' internet feed from my ISP who has also allocated a /25 address space. My ISP is using the first address for thier kit and I have the next address on my 2801 f0/0 interface. I want to place a firewall on f0/1 so would normally use ip unnumbered but you cannot have this on an eth

Re: [c-nsp] Netflow: 7600, egress

2007-07-04 Thread Phil Bedard
It is only supported on the RSP720/MSFC4/SRB afaik. You can get netflow stats for L2-switched traffic, I think "ip flow l2-switched vlan xxx." Have you tried not having both ingress and egress on the same interface at the same time? I know that it won't create flows for traffic originat

Re: [c-nsp] MPLS and VLAN on same FE or GE interface ?

2007-07-04 Thread Code Monkey
On 7/4/07, Matthew Kirkland <[EMAIL PROTECTED]> wrote: > Code Monkey wrote: > > Hi, > > > > Back in 2003 I failed miserably at configuring two 7206 VXR so that > > their FE interfaces could be connected to a VLAN switch, running MPLS > > in one VLAN and non-MPLS in other VLANs. > > We run this quit

Re: [c-nsp] Netflow: 7600, egress

2007-07-04 Thread Dmitry Kiselev
Hello! On Wed, Jul 04, 2007 at 05:35:31PM +0400, alexey wrote: > Hello! > Dmitry, where have you find anything about egress NetFlow on 7600? :) > I am reading config guide attentively > http://www.cisco.com/en/US/products/hw/routers/ps368/products_configuration_guide_chapter09186a0080699369.html#

Re: [c-nsp] L3 Interface for 2821

2007-07-04 Thread Bernd Ueberbacher
16 VLANs... Hmm, looking a bit further into the future, it might be a good idea to buy a NM-16ESW instead? Also supported by my 2821, I could use this module, would have enough ports, could use the Catalyst somewhere else and follow Paul's suggestion to do a interface FastEthernet4 switchport mode

[c-nsp] Packet drops

2007-07-04 Thread Blake Willis
Hi Mack, "Total output drops" from sh int and "sh queueing int" are interesting (and they seem to correspond), but I'm not certain if this only shows packets dropped by the RP (though IIRC it's a hardware counter). The "sh int switching" hidden command usually provides plenty of info,

Re: [c-nsp] Netflow: 7600, egress

2007-07-04 Thread alexey
Hello! Dmitry, where have you find anything about egress NetFlow on 7600? :) I am reading config guide attentively http://www.cisco.com/en/US/products/hw/routers/ps368/products_configuration_guide_chapter09186a0080699369.html#wp1078217 but no nothing about egress netflow! 2007/7/4, Dmitry Kiselev

Re: [c-nsp] Unicast storms

2007-07-04 Thread Stephen Wilcox
Hi Vincent, I'm saying it works just fine but the implementation is sucky. I use it extensively but you just need to set your thresholds pretty high to make sure they arent tripped. I also usually have it just filter rather than shut the port that way it will auto-recover. As to what 'pretty h

Re: [c-nsp] L3 Interface for 2821

2007-07-04 Thread Dan IOSUB
the HWIC-4ESW have support for max.16 VLAN's; and you can do a trunk link with all of them ... On 7/4/07, Tom Storey <[EMAIL PROTECTED]> wrote: > > The documentation for the HWIC-4ESW > ( > http://www.cisco.com/en/US/products/ps5853/products_data_sheet0900aecd8016b > f0b.html) mentions dot1q trunk

[c-nsp] several ME-C3750-24TE crushed at the same time with 12.2(35)SE2

2007-07-04 Thread Emanuel Popa
hi, several minutes ago we've just experienced the most awkward network event: 6 catalyst switches ME-C3750-24TE configured as MPLS PE have crushed at the same time. we upgraded IOS version last week to 12.2(35)SE2. although it seems like a clear IOS issue and we are standing by for update from C

Re: [c-nsp] L3 Interface for 2821

2007-07-04 Thread Tom Storey
The documentation for the HWIC-4ESW (http://www.cisco.com/en/US/products/ps5853/products_data_sheet0900aecd8016b f0b.html) mentions dot1q trunking as a supported feature, but doesnt seem to hint at how many VLANs can be trunked, therefore, I'd be assuming that it can do as many as is supported by y

[c-nsp] PPPOE on 7246VXR

2007-07-04 Thread Paul Stewart
Hi there... Just looking for feedback on running PPPOE on a Ubr7246VXR CMTS router? According to what I'm reading it supports PPPOE just like any other router pretty much anyone using it and/or have any "gotchas" to share? Thanks in advance, Paul ___

[c-nsp] PPPOE on 7246VXR

2007-07-04 Thread Paul Stewart
Hi there... Just looking for feedback on running PPPOE on a Ubr7246VXR CMTS router? According to what I'm reading it supports PPPOE just like any other router pretty much anyone using it and/or have any "gotchas" to share? Thanks in advance, Paul

Re: [c-nsp] L3 Interface for 2821

2007-07-04 Thread Paul Stewart
You only need to create the SVI's if you need layer3 in place... if you just want to trunk VLAN's between the two there's no need to use them I would image you can do a LOT of VLAN's on them (don't know for sure but guessing at 250) never done many as never had reason. But the nice thing

Re: [c-nsp] L3 Interface for 2821

2007-07-04 Thread Bernd Ueberbacher
Thanks for the fast reply! What would I do if I need about 10 VLANs on my 4 port interface? The router doesn't shout at me if I configure one of the ports of the 4ESW as a trunk. Should I do that and then create interface Vlan1, Vlan2, ...? Is this a "good" solution, considering performance etc

[c-nsp] dhcp snooping clarification

2007-07-04 Thread William Jackson
Hi I have a dhcp snooping setup on a 3550 switch. I have downstream some other access devices that insert option82 information to the DHCP requests. On my switch I have: ip dhcp smart-relay ip dhcp relay information option ip dhcp relay information policy keep ! ip dhcp snoop

Re: [c-nsp] L3 Interface for 2821

2007-07-04 Thread Dan IOSUB
Hi, 4ESW module knows 802.1q trunking. BR//Dan On 7/4/07, Paul Stewart <[EMAIL PROTECTED]> wrote: > > interface FastEthernet4 > switchport mode access > switchport access vlan 10 > > interface Vlan10 > ip address 10.1.1.1 255.255.255.0 > > Create the VLAN in your VLAN database and that should do

Re: [c-nsp] L3 Interface for 2821

2007-07-04 Thread Paul Stewart
interface FastEthernet4 switchport mode access switchport access vlan 10 interface Vlan10 ip address 10.1.1.1 255.255.255.0 Create the VLAN in your VLAN database and that should do the trick just fine You need to use a SVI to make it layer3 I don't believe you can do trunking on the 4ESW bu

Re: [c-nsp] L3 Interface for 2821

2007-07-04 Thread Paul Stewart
interface FastEthernet4 switchport mode access switchport access vlan 10 interface Vlan10 ip address 10.1.1.1 255.255.255.0 Create the VLAN in your VLAN database and that should do the trick just fine You need to use a SVI to make it layer3 I don't believe you can do trunking on the 4ESW bu

[c-nsp] Netflow: 7600, egress

2007-07-04 Thread Dmitry Kiselev
Hello! On my 7600 test box with RSP720 I failed to do egress netflow. Here is config snapshot: mls flow ip interface-full interface GigabitEthernet1/25 ip address XXX.YYY.17.2 255.255.255.252 ip flow ingress ip flow egress ! interface GigabitEthernet1/26 ip address XXX.YYY.16.2 255.255.255.2

[c-nsp] L3 Interface for 2821

2007-07-04 Thread Bernd Ueberbacher
Hi there! Once again I have a small problem and I'm sure you guys can help me out ;-) I have two 2821 routers. They have 2 Gi interfaces onboard. In one of them I have a HWIC-4ESW. I'd like to connect a Catalyst 2950 to a third interface of the router. I need to configure the switchports (on the

Re: [c-nsp] snmp trap v3

2007-07-04 Thread Daniel Hooper
A reboot isn't exactly a solution .. what ios are you running? Might be worth lodging a bug on it. -Daniel -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Sergey Velikanov [Intelsoft] Sent: Wednesday, 4 July 2007 4:02 PM To: cisco-nsp@puck.nether.net Subj

Re: [c-nsp] MPLS and VLAN on same FE or GE interface ?

2007-07-04 Thread Tim Franklin
On Wed, July 4, 2007 10:24 am, Code Monkey wrote: > Back in 2003 I failed miserably at configuring two 7206 VXR so that > their FE interfaces could be connected to a VLAN switch, running MPLS > in one VLAN and non-MPLS in other VLANs. I've done this in a previous life, using the on-board ports on

Re: [c-nsp] MPLS and VLAN on same FE or GE interface ?

2007-07-04 Thread Matthew Kirkland
Code Monkey wrote: > Hi, > > Back in 2003 I failed miserably at configuring two 7206 VXR so that > their FE interfaces could be connected to a VLAN switch, running MPLS > in one VLAN and non-MPLS in other VLANs. > > Basically I'd like to have > > int fa0/0.2 > description MPLS VLAN for my rout

Re: [c-nsp] cisco VPN client to an IOS router: sending ALL traffic thru the VPN

2007-07-04 Thread Philippe Strauss
oops forgot IOS version: c870-adventerprisek9-mz.124-11.T2 ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] MPLS and VLAN on same FE or GE interface ?

2007-07-04 Thread Code Monkey
Hi, Back in 2003 I failed miserably at configuring two 7206 VXR so that their FE interfaces could be connected to a VLAN switch, running MPLS in one VLAN and non-MPLS in other VLANs. Basically I'd like to have int fa0/0.2 description MPLS VLAN for my routers encapsulation dot1Q 2 ip addres

[c-nsp] cisco VPN client to an IOS router: sending ALL traffic thru the VPN

2007-07-04 Thread Philippe Strauss
Hello, I'm trying to setup a small router (c876) for a customer, with a VPN setup such that VPN client get the default route thru the VPN, hence all traffic goes thru the VPN (no split-tunneling). Along with NAT on the "central" c876, it's not easy as it seems. Basically, client VPN enter thru th

Re: [c-nsp] Larger scale router rollout tools?

2007-07-04 Thread Phil Mayers
On Tue, 2007-07-03 at 17:55 -0700, Kevin Graham wrote: > Or more generally still, just NETCONF. Hopefully it Isn't the CCE a netconf proxy in effect? > will eventually kill the stupid templates we all have > floating around in some form or another: > > http://www.cisco.com/univercd/cc/td/doc/pro

Re: [c-nsp] snmp trap v3

2007-07-04 Thread Sergey Velikanov [Intelsoft]
Sergey Velikanov [Intelsoft] wrote: > Hello > > Could anybody provide valid snmpv3 trap config? > > I've tryed > > snmp-server user trap_user trap_group v3 > snmp-server group trap_group v3 noauth notify *tv.0001..0F > snmp-server enable traps snmp authentication linkdown lin