Re: [c-nsp] MTBF for Cisco products

2007-12-07 Thread Ted Mittelstaedt
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] Behalf Of Peter Rathlev > Sent: Monday, December 03, 2007 3:05 PM > To: cisco-nsp@puck.nether.net > Subject: Re: [c-nsp] MTBF for Cisco products > > > [EMAIL PROTECTED] skrev man, 03 dec 2007: > > Ted Mittelstaedt

Re: [c-nsp] MTBF for Cisco products

2007-12-07 Thread Ted Mittelstaedt
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] Behalf Of Will Hargrave > Sent: Monday, December 03, 2007 10:55 AM > Cc: Cisco-nsp > Subject: Re: [c-nsp] MTBF for Cisco products > > > Ted Mittelstaedt wrote: > > > (nor, in fact, for the additional money that the

Re: [c-nsp] Policing Question

2007-12-07 Thread Frank Bulk
It appears that WRED is not supposed on the WS-X6748-GE-TX...the "random-detect" command is not listed. The closest is "wrr-queue random-detect", but the queue id's match up to "1 for the standard low-priority queue, 2 is for the standard high-priority queue, and 3 is for strict priority", and I'm

[c-nsp] Check for scheduled reload through SNMP?

2007-12-07 Thread Jeffrey Ollie
Is there a way to check a device to see if a reload has been scheduled (i.e. reload at 23:00)? I thought that that would be an interesting item to add to my monitoring system. I've grepped though the mibs that I grabbed off of Cisco's FTP site and couldn't find anything obvious. Jeff ___

Re: [c-nsp] confederation same as peer

2007-12-07 Thread jared mauch
This would work for a peer that is in your ibgp mesh. Otherwise it will likely not do what you intend. Jared Mauch On Dec 7, 2007, at 6:18 PM, "Rubens Kuhl Jr." <[EMAIL PROTECTED]> wrote: > Is it protocol-wise allowed to configure a BGP confederation like > this ? > > router(config)#router b

[c-nsp] confederation same as peer

2007-12-07 Thread Rubens Kuhl Jr.
Is it protocol-wise allowed to configure a BGP confederation like this ? router(config)#router bgp 65010 router(config-router)#bgp confederation identifier 42 router(config-router)#bgp confederation peers 42 router(config-router)#neighbor 1.1.1.1 remote-as 42 Reading the RFC on BGP Confeds didn't

Re: [c-nsp] Router/Switch performance

2007-12-07 Thread Juan Angel Menendez
Here you go: http://www.cisco.com/web/partners/tools/quickreference/index.html Regards, Juan At 16:56 07/12/2007, Roy wrote: >Up until recently Cisco had two very handy PDF files: One had the >various routers and their expected PPS while the other covered switches. > >They

[c-nsp] Opinion on ASA Anti-X edition

2007-12-07 Thread Jason Lixfeld
Anyone have any opinion on this? Pros? Cons? Experiences vs. other vendors like Fortinet or Juniper, for example? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nethe

Re: [c-nsp] Router/Switch performance

2007-12-07 Thread Alex Balashov
On Fri, 7 Dec 2007, Roy wrote: > They have both disappeared from the Cisco site. Does anyone still have > copies? They disappeared, along with the PPS. -- Alex Balashov Evariste Systems Web: http://www.evaristesys.com/ Tel: +1-678-954-0670 Direct : +1-678-954-0671 __

Re: [c-nsp] Router/Switch performance

2007-12-07 Thread Gary Stanley
At 02:56 PM 12/7/2007, Roy wrote: >Up until recently Cisco had two very handy PDF files: One had the >various routers and their expected PPS while the other covered switches. > >They have both disappeared from the Cisco site. Does anyone still have >copies? http://www.cisco.com/web/partners/tool

[c-nsp] Router/Switch performance

2007-12-07 Thread Roy
Up until recently Cisco had two very handy PDF files: One had the various routers and their expected PPS while the other covered switches. They have both disappeared from the Cisco site. Does anyone still have copies? Roy ___ cisco-nsp mailing list c

Re: [c-nsp] Native VLAN mismatches between 2924/2950

2007-12-07 Thread Pierre Lamy
Sorry I meant to say the 4mb 2924XL doesn't support dot1q Pierre Lamy wrote: > Turns out was because (as far as I can tell) the 2950 only supports > dot1q and the 2924XL only supports ISL. Go figure > > Pierre > > Pierre Lamy wrote: > >> I'm getting a lot of Native VLAN mismatches between my 2

Re: [c-nsp] Native VLAN mismatches between 2924/2950

2007-12-07 Thread Pierre Lamy
Turns out was because (as far as I can tell) the 2950 only supports dot1q and the 2924XL only supports ISL. Go figure Pierre Pierre Lamy wrote: > I'm getting a lot of Native VLAN mismatches between my 2950 and 2924s. > This is due to the case difference on the 2 platforms, between VLAN1 and >

Re: [c-nsp] How to easily and securely pull configuration from a PIX/ASA

2007-12-07 Thread John Kougoulos
> The only option I can think of here if for you to grant access to a > userid that is allowed to run 'copy running-config > tftp://aaa.bbb.ccc.ddd/upload/pix.cfg' where aaa.bbb.ccc.ddd is the IP > of the authorized TFTP server on a secured portion of your LAN. That I think that you could also u

Re: [c-nsp] How to easily and securely pull configuration from a PIX/ASA

2007-12-07 Thread Tassos Chatzithomaoglou
Justin Shore wrote on 7/12/2007 5:26 μμ: > Marc Haber wrote: >> On Thu, Dec 06, 2007 at 09:03:39PM +, Thorsten Dahm wrote: >>> Marc Haber wrote: Which access privileges would RANCID need, and how far can the RANCID account be restricted? >>> The same as any user who is able to to a "

Re: [c-nsp] multilink bundle

2007-12-07 Thread David Freedman
IMA? /me hides Joseph Jackson wrote: > Would it be considered retarded to put 23 T1's into a multilink bundle? > > > Joseph > ___ > cisco-nsp mailing list cisco-nsp@puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at htt

Re: [c-nsp] How to easily and securely pull configuration from a PIX/ASA

2007-12-07 Thread Justin Shore
Marc Haber wrote: > On Thu, Dec 06, 2007 at 09:03:39PM +, Thorsten Dahm wrote: >> Marc Haber wrote: >>> Which access privileges would RANCID need, and how far can the RANCID >>> account be restricted? >> The same as any user who is able to to a "sh run". > > Which access privileges are needed

Re: [c-nsp] How to easily and securely pull configuration from a PIX/ASA

2007-12-07 Thread Thorsten Dahm
Marc Haber wrote: > On Thu, Dec 06, 2007 at 09:03:39PM +, Thorsten Dahm wrote: >> Marc Haber wrote: >>> Which access privileges would RANCID need, and how far can the RANCID >>> account be restricted? >> The same as any user who is able to to a "sh run". > > Which access privileges are needed

Re: [c-nsp] How to easily and securely pull configuration from aPIX/ASA

2007-12-07 Thread Andy Davidson
On 5 Dec 2007, at 17:33, Marc Haber wrote: > On Wed, Dec 05, 2007 at 12:06:54PM -0500, Eric Van Tol wrote: >> I could be wrong, but I believe that the PIX/ASA configuration can >> be seen via the internal web server. It's encrypted via SSL, so a >> wget should work, if it's compiled with SSL

Re: [c-nsp] How to easily and securely pull configuration from a PIX/ASA

2007-12-07 Thread Gert Doering
Hi, On Fri, Dec 07, 2007 at 10:50:38AM +0100, Marc Haber wrote: > Is it possible to authenticate through a ssh key, and is it possible > to restrict a key to be only accepted from one single IP address? As far as I understand, currently Cisco does not understand this concept. (And their SSH impl

Re: [c-nsp] Policing Question

2007-12-07 Thread Paolo Lucente
Hi Bill, Considering an interval of 0.25ms your calculation is fine for the 8Mbps Be. Though such calculation leaves no margin and you really want to have some to be sure the switch can sustain the rate. The switch might even inform you that your burst value is not legal as the minimum configurab

Re: [c-nsp] How to easily and securely pull configuration from a PIX/ASA

2007-12-07 Thread Marc Haber
On Thu, Dec 06, 2007 at 09:03:39PM +, Thorsten Dahm wrote: > Marc Haber wrote: > > Which access privileges would RANCID need, and how far can the RANCID > > account be restricted? > > The same as any user who is able to to a "sh run". Which access privileges are needed to do a "sh run"? > >