[c-nsp] PBR with NAT/PAT - strange (non-deterministic) behaviour

2008-03-06 Thread Dale Shaw
Hi all, I'm trying to configure two 2611XMs to do PBR and NAT. The relevant config snippet is included below, but essentially one of the routers is doing what I want, and the other isn't. I suspect I'm hitting an IOS bug, or my config isn't quite right (hmmm, thanks captain obvious.) I have a PBR

Re: [c-nsp] Bogon Filter - Least Resource/CPU intensive method?

2008-03-06 Thread Seth Mattinen
Whisper wrote: > Thanks for all the replies, they have been very enlightning. > > Are there any other methods people use to filter/block bogons? > > Its always good to hear about the relative real world pros & cons of > implementing specific policy decisions. > Not precisely a bogon list, but t

Re: [c-nsp] ASA help configuration

2008-03-06 Thread Jorge Evangelista
Hi, Cisco friends, the issue was solved, the problem was a unmanaged dlink switch, I changed it with a switch 3COM, now Cisco ASA works fine. Regards. On 3/6/08, Fields, Jesse <[EMAIL PROTECTED]> wrote: > > I have ran into a similar problem recently on a 5505 and kicked myself > for overlookin

Re: [c-nsp] About bgp fast-external-fallover

2008-03-06 Thread Peter Salanki
Running BFD on iBGP is probably not a good idea though, as iBGP is multihop (unless you have an "interesting" network design). Relying on the IGP and letting the IGP trigger BGP withdrawals is the way to go for iBGP On Mar 6, 2008, at 7:57 PM, Ben Steele wrote: > > On 07/03/2008, at 2:18 PM

Re: [c-nsp] About bgp fast-external-fallover

2008-03-06 Thread Ben Steele
On 07/03/2008, at 2:18 PM, Hiromasa Sekiguchi wrote: > Hi, > > The cisco products have "bgp fast-external-fallover" function. > It is available on only eBGP, isn't it? Yes, only for eBGP > > > We'd like to do same behabior like it on iBGP. > So, is there any solutions? Have a look at bfd for BG

[c-nsp] About bgp fast-external-fallover

2008-03-06 Thread Hiromasa Sekiguchi
Hi, The cisco products have "bgp fast-external-fallover" function. It is available on only eBGP, isn't it? We'd like to do same behabior like it on iBGP. So, is there any solutions? Regards, ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https:/

Re: [c-nsp] ASA help configuration

2008-03-06 Thread Fields, Jesse
I have ran into a similar problem recently on a 5505 and kicked myself for overlooking it. Try hard setting your port speed/duplex on the ASA and switch. GL -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jorge Evangelista Sent: Thursday, March 06, 2008

Re: [c-nsp] QOS Configuration Help

2008-03-06 Thread Nick Griffin
I've experienced and tried this only on the supV's. I would assume, however never tested to see the same results on the 4948 since they are pretty much identical from a os/platform standpoint. A good hint is if the 4948 will actually even LET you place "qos" commands on the port channel itself. If

Re: [c-nsp] Opinions on Cisco VoIP products...

2008-03-06 Thread Jonathan Charles
Well, the Cucumber is ok, it combines CCM 6.X and CUC 6.X in a single box, the downside is you can't integrate with AD and you can only have 5 remote sites. Also, since it is a single server, there is no redundancy, so you may need a big, fat router for SRST depending on how many users you have.

Re: [c-nsp] QOS Configuration Help

2008-03-06 Thread Gert Doering
Hi, On Wed, Mar 05, 2008 at 08:32:05PM -0600, Justin Shore wrote: > I thought it was weird too but I pretty much copied that out of the new > Router Security Strategies book, pages 210-211, just to be sure. The > first sentence under the "No-negotiate mode" heading is: > > "Puts the LAN port i

Re: [c-nsp] Opinions on Cisco VoIP products...

2008-03-06 Thread Jared Mauch
On Thu, Mar 06, 2008 at 02:19:41PM -0500, Drew Weaver wrote: > Hi there, we are going to be updating our phone system from a very > old t1 unit to a new VoIP product and we are looking for advice from folks > who have deployed Unified Communication Manager 6.1 in a single server MCS > de

[c-nsp] Opinions on Cisco VoIP products...

2008-03-06 Thread Drew Weaver
Hi there, we are going to be updating our phone system from a very old t1 unit to a new VoIP product and we are looking for advice from folks who have deployed Unified Communication Manager 6.1 in a single server MCS deployment (I believe they call deploying it this way "Cisco Unified Co

Re: [c-nsp] Bogon Filter - Least Resource/CPU intensive method?

2008-03-06 Thread Justin M. Streiner
On Thu, 6 Mar 2008, Phil Mayers wrote: > It depends on the platform, but on 6500s at least I know you get an > output interface of 0. > > Sadly you get an output interface of 0 for a whole lot of other stuff, > including glean failures (i.e. couldn't arp for the next hop), RPF > failures and also

Re: [c-nsp] Bogon Filter - Least Resource/CPU intensive method?

2008-03-06 Thread Phil Mayers
Justin Shore wrote: > Jeff Kell wrote: >> Justin Shore wrote: >>> Personally I'm still using ACLs on my border routers. At this point >>> in time I want the ACE hit counters for those rogue packets >> Hrmmm... will these show up in netflow in some identifiable fashion? > > That's a good question

Re: [c-nsp] Bogon Filter - Least Resource/CPU intensive method?

2008-03-06 Thread Justin M. Streiner
On Thu, 6 Mar 2008, Justin Shore wrote: > Jeff Kell wrote: >> Justin Shore wrote: >>> Personally I'm still using ACLs on my border routers. At this point >>> in time I want the ACE hit counters for those rogue packets >> >> Hrmmm... will these show up in netflow in some identifiable fashion? > >

Re: [c-nsp] Bogon Filter - Least Resource/CPU intensive method?

2008-03-06 Thread Justin Shore
Jeff Kell wrote: > Justin Shore wrote: >> Personally I'm still using ACLs on my border routers. At this point >> in time I want the ACE hit counters for those rogue packets > > Hrmmm... will these show up in netflow in some identifiable fashion? That's a good question. I'm not sure if NF will

Re: [c-nsp] ASA help configuration

2008-03-06 Thread Andrew Froehlich
If you are using the base ASA license, there is a limitation of traffic flow on 3 routed VLANS. You have to issue the following command to get the 3rd vlan to work: ASA(config-if)# no forward interface (vlan-number) This limits you to being able to receive traffic on the VLAN but not sending it.

Re: [c-nsp] Large File Transfers

2008-03-06 Thread Peter Rathlev
On Thu, 2008-03-06 at 09:43 -0600, Dale W. Carder wrote: > On Mar 5, 2008, at 5:36 PM, Ben Steele wrote: > > I'm going to recommend rsync mainly for it's resume of transfer > > ability over scp(given your files sound large), you can tunnel it via > > ssh using a flag like "--rsh=ssh" or similar for

Re: [c-nsp] Large File Transfers

2008-03-06 Thread Dale W. Carder
On Mar 5, 2008, at 5:36 PM, Ben Steele wrote: > I'm going to recommend rsync mainly for it's resume of transfer > ability over scp(given your files sound large), you can tunnel it via > ssh using a flag like "--rsh=ssh" or similar for security I would second the use of rsync for it's ability to b

Re: [c-nsp] Bogon Filter - Least Resource/CPU intensive method?

2008-03-06 Thread Jeff Kell
Justin Shore wrote: > Personally I'm still using ACLs on my border routers. At this point in > time I want the ACE hit counters for those rogue packets Hrmmm... will these show up in netflow in some identifiable fashion? Jeff ___ cisco-nsp mailing lis

Re: [c-nsp] ASA help configuration

2008-03-06 Thread Alasdair Gow
Do you see anything interesting in the debug logging? What kind of packets is it dropping? > icmp unreachable rate-limit 1 burst-size 1 is it dropping icmp packets? have you checked the duplex settings? everything talking the same? can you do a mirror port on the switch to see via tcpdump wha

Re: [c-nsp] output rate-limiting not working in 7609

2008-03-06 Thread Edwin Lok
Hi Tim, How about the egress policing on a 7600-SIP-400 and SPA-2X1GE-V2 combo? Is egress policing done at the egress or still on the FE ingress interfaces? Thanks Rgds Edwin On Thu, Mar 6, 2008 at 1:24 AM, Tim Stevenson <[EMAIL PROTECTED]> wrote: > The problem exists as long as there are mult

[c-nsp] ASA help configuration

2008-03-06 Thread Jorge Evangelista
Hi guys, I have configured a Cisco ASA 5505 with two LAN's one for inside (servers) and other for business (users), I can do a ping from business to inside and viceversa hosts, I can authenticate me in the domani MS only when I connect a PC in ports of ASA with access vlan 3, however when I con

Re: [c-nsp] Bogon Filter - Least Resource/CPU intensive method?

2008-03-06 Thread Justin Shore
Personally I'm still using ACLs on my border routers. At this point in time I want the ACE hit counters for those rogue packets. ACLs of course consume more resources but it gives me what I want. I do ingress and egress and I update my ACLs within a few days of IANA announcing the allocation

Re: [c-nsp] Possible flash problem

2008-03-06 Thread Bruno Filipe
Thanks very much INDEED. It's working NOW RGDS /Bruno Filipe - Original Message From: Oliver Boehmer (oboehmer) <[EMAIL PROTECTED]> To: Bruno Filipe <[EMAIL PROTECTED]>; cisco-nsp@puck.nether.net Cc: [EMAIL PROTECTED] Sent: Thursday, March 6, 2008 1:56:45 PM Subject: RE: [c-nsp] Possib

Re: [c-nsp] Possible flash problem

2008-03-06 Thread Oliver Boehmer (oboehmer)
Bruno Filipe <> wrote on Thursday, March 06, 2008 12:35 PM: > Hi there... > > I'm facing a problem with a 3825 after upgrading from 256 RAM to two > 512 DIMM modules... > > that's the OUTPUT from the console. > > > *Mar 6 11:22:58.627: %SYS-4-NV_BLOCK_INITFAIL: Unable to initialize > the geo

Re: [c-nsp] Deploying RADIUS for user logins ?

2008-03-06 Thread kevin gannon
Thanks a lot for all the input RANCID seems to be the way to go. Thanks for the template config I will look again at TACACS+. Thanks & Regards Kevin On Mon, Mar 3, 2008 at 5:30 PM, Peter Rathlev <[EMAIL PROTECTED]> wrote: > On Mon, 2008-03-03 at 10:18 -0600, Justin Shore wrote: > > Assuming you'

Re: [c-nsp] Bogon Filter - Least Resource/CPU intensive method?

2008-03-06 Thread Whisper
Thanks for all the replies, they have been very enlightning. Are there any other methods people use to filter/block bogons? Its always good to hear about the relative real world pros & cons of implementing specific policy decisions. On Thu, Mar 6, 2008 at 5:51 PM, Matt Carter <[EMAIL PROTECTED]>

[c-nsp] Possible flash problem

2008-03-06 Thread Bruno Filipe
Hi there... I'm facing a problem with a 3825 after upgrading from 256 RAM to two 512 DIMM modules... that's the OUTPUT from the console. *Mar 6 11:22:58.627: %SYS-4-NV_BLOCK_INITFAIL: Unable to initialize the geometry of nvram *Mar 6 11:22:58.859: NV: Invalid Pointer value(6307D87C) in priv

Re: [c-nsp] Route-reflector client on 6500 & 7600

2008-03-06 Thread Phil Mayers
Wyatt Mattias Ishmael Jovial Gyllenvarg wrote: > Hi All > > Why is it that when you restart a 7600 or 6500 the "route-reflector > client" statment is erased from the config? > > Highly frustrating feature too troubleshoot over the phone > > Anyone else have this? No. It works fine in our co

[c-nsp] Route-reflector client on 6500 & 7600

2008-03-06 Thread Wyatt Mattias Ishmael Jovial Gyllenvarg
Hi All Why is it that when you restart a 7600 or 6500 the "route-reflector client" statment is erased from the config? Highly frustrating feature too troubleshoot over the phone Anyone else have this? What can I do to make this "more" permanent?!? Best Regards Mattias Gyllenvarg Omnitron _