Re: [c-nsp] Configure two AS on one BGP router

2007-07-19 Thread OCOSA ListAcct
If you have the dual AS BGP feature in your IOS verison you can easily setup the two AS options. otis Kamlesh Sharma wrote: > Hi All, > > Configuring two AS in cisco router is not possible. but yes it is very > easily possible in Juniper Router's. I know i shouldn't be talking about it > b

Re: [c-nsp] Configure two AS on one BGP router

2007-07-19 Thread Kamlesh Sharma
Yes you are right that would be 15 different routing instances but that router does allow you to have routing in between these logical router so ultimately we can have a router running two virtual router and having coonectivity between them thanks On 7/20/07, Bruce Pinsky <[EMAIL PROTECTED]> wrot

Re: [c-nsp] Configure two AS on one BGP router

2007-07-19 Thread Bruce Pinsky
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Kamlesh Sharma wrote: > Hi All, > > Configuring two AS in cisco router is not possible. but yes it is very > easily possible in Juniper Router's. I know i shouldn't be talking about it > but yes by creating vertual router in Juniper box you can have u

Re: [c-nsp] Configure two AS on one BGP router

2007-07-19 Thread Justin M. Streiner
On Fri, 20 Jul 2007, Kamlesh Sharma wrote: > Configuring two AS in cisco router is not possible. but yes it is very > easily possible in Juniper Router's. I know i shouldn't be talking about it > but yes by creating vertual router in Juniper box you can have upto 15 AS > no. on that. You can use

[c-nsp] Configure two AS on one BGP router

2007-07-19 Thread Kamlesh Sharma
Hi All, Configuring two AS in cisco router is not possible. but yes it is very easily possible in Juniper Router's. I know i shouldn't be talking about it but yes by creating vertual router in Juniper box you can have upto 15 AS no. on that. -- Thanks Kamlesh Sharma _

Re: [c-nsp] cisco 2811 won't do ppp :(

2007-07-19 Thread Masood Ahmad Shah
Paste here... debug vpdn debug ppp Regards, Masood Ahmad Shah -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of fernando fernandes Sent: Friday, July 20, 2007 1:56 AM To: cisco-nsp@puck.nether.net Subject: [c-nsp] cisco 2811 won't do ppp :( lo there...

[c-nsp] cisco 2811 won't do ppp :(

2007-07-19 Thread fernando fernandes
lo there... hoppe u guys can help me .. i have an cisco 2811 with and wic-adsl, it sync okay in the dsl line ive setuped the dialer so it can to the ppp mas it just simply won't start :( any ideas? ff ___ cisco-nsp mailing list cisco-nsp@puck.nether.ne

Re: [c-nsp] VRF forwarding limits on SVI?

2007-07-19 Thread Ian Cox
At 02:20 PM 7/19/2007 -0400, Chris Griffin wrote: >Are we going to see eompls support on SVIs at some point on the >Sup720 (PFC MPLS)? There is a special case of EoMPLS being supported on an SVI for Sup720 which is referred to as mux-uni. http://www/en/US/products/hw/routers/ps368/products_conf

Re: [c-nsp] ASA Remote site VPN

2007-07-19 Thread Amol Sapkal
Kris, In the below configuration, how are you allowing the incoming traffic? (from outside to inside/internal) Can you share your logs, when you try to initiate an access to the inside? (output of 'show logging') Regards, Amol PS: Hope the user/pass on the configs are not the actual ones! O

[c-nsp] ASA Remote site VPN

2007-07-19 Thread krishna
Hi All, Iam confguring remote site VPN on ASA 5510. Iam using Cisco VPN client. I can able to connect the vpn successfully, after connecting i cant able to access the lan on ASA side. the config is as like as follows, sh run : Saved : ASA Version 7.0(5) ! hostname ASA domain-name .xx ena

Re: [c-nsp] VRF forwarding limits on SVI?

2007-07-19 Thread Chris Griffin
Are we going to see eompls support on SVIs at some point on the Sup720 (PFC MPLS)? I have heard yes, but future code, and then no unless you have SIP/SPAs. Thanks! Chris Ian Cox wrote: > At 11:02 AM 7/19/2007 -0400, Jeff Kell wrote: >> 6500 Sup-II/MSFC2/PFC2 can't do SVI VRF forwarding? >> >>>

Re: [c-nsp] static Nat on Non Standard TCP port on PIX 506

2007-07-19 Thread Howard Leadmon
Your static translations don't look right, I would remove them and try something like this: static (inside,outside) tcp interface 7778 192.168.1.5 7778 netmask 255.255.255.255 0 0 Also your inbound ACL should read: access-list INBOUND permit tcp any host 192.168.1.5 eq 7778 The real big quest

Re: [c-nsp] static Nat on Non Standard TCP port on PIX 506

2007-07-19 Thread Michael K. Smith - Adhost
Hello Peter: > -Original Message- > From: [EMAIL PROTECTED] [mailto:cisco-nsp- > [EMAIL PROTECTED] On Behalf Of Peter Nyamukusa > Sent: Thursday, July 19, 2007 5:21 AM > To: cisco-nsp@puck.nether.net > Subject: [c-nsp] static Nat on Non Standard TCP port on PIX 506 > > > Hi guys, > > I

Re: [c-nsp] VRF forwarding limits on SVI?

2007-07-19 Thread Alexandre Snarskii
On Thu, Jul 19, 2007 at 11:02:46AM -0400, Jeff Kell wrote: > 6500 Sup-II/MSFC2/PFC2 can't do SVI VRF forwarding? > > > UTC-6509(config)#interface Vlan801 > > UTC-6509(config-if)# description No Man's LAN ring 1 > > UTC-6509(config-if)# ip vrf forwarding no-mans-lan > > %This interface does not sup

Re: [c-nsp] VRF forwarding limits on SVI?

2007-07-19 Thread Ian Cox
At 11:02 AM 7/19/2007 -0400, Jeff Kell wrote: >6500 Sup-II/MSFC2/PFC2 can't do SVI VRF forwarding? > > > UTC-6509(config)#interface Vlan801 > > UTC-6509(config-if)# description No Man's LAN ring 1 > > UTC-6509(config-if)# ip vrf forwarding no-mans-lan > > %This interface does not support ip vrf for

Re: [c-nsp] ? Config management software ?

2007-07-19 Thread Jason LeBlanc
For a more robust system you might look into OpsWare, expensive but covers a lot of things and plugs into Tivoli and Remedy. This is obviously a large enterprise app and one might expect the costs and time to be commensurate. We use rancid currently but we're looking at OpsWare's Network Auto

[c-nsp] VRF forwarding limits on SVI?

2007-07-19 Thread Jeff Kell
6500 Sup-II/MSFC2/PFC2 can't do SVI VRF forwarding? > UTC-6509(config)#interface Vlan801 > UTC-6509(config-if)# description No Man's LAN ring 1 > UTC-6509(config-if)# ip vrf forwarding no-mans-lan > %This interface does not support ip vrf forwarding Say it ain't so...? IOS c6sup22-jk2s-mz.121-2

Re: [c-nsp] ? Config management software ?

2007-07-19 Thread Joel M Snyder
For Windows: Kiwi Cat Tools For Unix: Rancid jms ChrisSerafin wrote: > Does anyone have a recommendation for vendor neutral configuration > management software? I'm looking to alert on changes made to servers, > firewalls, routers/switches, etc. Something that would poll the device > for chan

Re: [c-nsp] ? Config management software ?

2007-07-19 Thread Jeffrey C. Ollie
On Thu, 2007-07-19 at 09:41 -0500, ChrisSerafin wrote: > Does anyone have a recommendation for vendor neutral configuration > management software? I'm looking to alert on changes made to servers, > firewalls, routers/switches, etc. Something that would poll the device > for changes and alert wh

[c-nsp] ? Config management software ?

2007-07-19 Thread ChrisSerafin
Does anyone have a recommendation for vendor neutral configuration management software? I'm looking to alert on changes made to servers, firewalls, routers/switches, etc. Something that would poll the device for changes and alert when noticed. Thanks, Chris Serafin Security Engineer [EMAIL PR

[c-nsp] PIX/ASA 7.0(6) on DSD EPL (Australia)

2007-07-19 Thread Dale Shaw
This is mainly of interest to Australians working in Fed Gov't.. PIX/ASA version 7.0(6) has been listed on the DSD EPL as complete (EAL4+). http://www.dsd.gov.au/infosec/evaluation_services/epl/network_security/cisco_secure_pix_firewall_v7.html cheers, Dale __

[c-nsp] static Nat on Non Standard TCP port on PIX 506

2007-07-19 Thread Peter Nyamukusa
Hi guys, I am trying to allow external access to an oracle web server sitting on a private IP behind a PIX 506 The public ip is 2.2.2.2 and the private IP of the server is 192.168.1.5 and the application is running on port 7778 I am access the server from a source ip 10.1.1.2 but its not working

Re: [c-nsp] Newbie help with cisco 877w

2007-07-19 Thread Brett Looney
> I am trying to configure a cisco router, the 877w model. I have used the > build in SDM to configure, and now i have added some NAT rules with the > wizard, but i cant get them to work. Is there any way to solve my problem ? You might consider posting the config or at least a vague idea of what

[c-nsp] Newbie help with cisco 877w

2007-07-19 Thread Rui Oliveira
Hi :) I am trying to configure a cisco router, the 877w model. I have used the build in SDM to configure, and now i have added some NAT rules with the wizard, but i cant get them to work. Is there any way to solve my problem ? -- Sem Mais Rui Oliveira 351 - Portugal _

Re: [c-nsp] Temp sensors on 6500 48 10/100/1000 module

2007-07-19 Thread Gert Doering
Hi, On Wed, Jul 18, 2007 at 02:11:18PM +0200, Holemans Wim wrote: > I also have a question about the fans : there is a command to show the > fan status but what is the output if one of the fans fails ? > Does it signal single fan failure or only full-fan failure ? At least with the FAN1, all you