Re: [c-nsp] Fake Cisco Equipment News Articles - very interesting

2008-05-12 Thread Jay Hennigan
Ted Mittelstaedt wrote: > After the initial reaction of laughing, I have this to say about it. > > It is clearly rediculous that Chinese crackers are going to steal > national security secrets by using counterfeit WIC-1DSU-T1 cards. > I think the majority of counterfeit gear they picked up was pr

Re: [c-nsp] PIX questions

2008-05-12 Thread Ziv Leyes
You must understand that the NAT is being performed on a "from-->to" basis, that is why the command is "static (inside,outside)" so if the NAT is between inside and outside you can't hit it when coming from the dmz, for this to be achieved you should use a "static (inside,dmz)" command, but the

Re: [c-nsp] Fake Cisco Equipment News Articles - very interesting

2008-05-12 Thread Ted Mittelstaedt
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] Behalf Of Skeeve Stevens > Sent: Monday, May 12, 2008 9:30 AM > To: [EMAIL PROTECTED] > Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED]; cisco-nsp@puck.nether.net; > [EMAIL PROTECTED] > Subject: [c-nsp] Fake Cisco Equipme

Re: [c-nsp] CEF Load balancing over Etherchannel (3750)

2008-05-12 Thread Stig Johansen
>Does anyone know how to make CEF load balancing work over etherchannels >and actually load balance on the etherchannel? >I have two GEC interfaces with 2 ports in each, and then I have two >routes multipath, one to each GEC interface >The problem is that the CEF algorithm is the same as the ethe

Re: [c-nsp] Huge number of input queue drops on 6500

2008-05-12 Thread Pshem Kowalczyk
Hi, We moved those interfaces to a 6724 modules and all the problems went away. Thank you for your help. kind regards Pshem ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.n

[c-nsp] Old Aironet Gear Issus

2008-05-12 Thread 刘Tom
Hi ivor, I have a old CISCO AIR-AP1230B. But it's firmware is very older.I want to updating the firmware.Can you give me a new firmware for CISCO AIR-AP1230B,Please.Thank you very much. Tom _ 新年换新颜,快来妆扮自己的MSN给心仪的TA一个惊喜! http:

Re: [c-nsp] PIX questions

2008-05-12 Thread Michael K. Smith - Adhost
Hello Gregori: > -Original Message- > From: [EMAIL PROTECTED] [mailto:cisco-nsp- > [EMAIL PROTECTED] On Behalf Of Gregori Parker > Sent: Monday, May 12, 2008 10:35 AM > To: cisco-nsp@puck.nether.net > Subject: Re: [c-nsp] PIX questions > > I was hoping to see an answer to this, as I ran i

Re: [c-nsp] CEF Load balancing over Etherchannel (3750)

2008-05-12 Thread Paul
It doesn't really have anything to do with etherchannel, that works just fine by itself. It has to do with the CEF load balancing algorithm being exactly the same as the etherchannel one. This even propagates through to multiple switches, for instance I have tested it like: 3750 with 2 ether

Re: [c-nsp] PIX questions

2008-05-12 Thread Gregori Parker
The alias command still seems usable in 7.2, but I tried this in my scenario and it didn't affect anything (also tried the 'dns doctoring' and 'hairpinning' solutions) -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Raul Lopez Nevot Sent: Monday, May 12,

Re: [c-nsp] Any to terminate a DSL loop on a 72xx or 75xx?

2008-05-12 Thread Chris Adams
Once upon a time, Chris Riling <[EMAIL PROTECTED]> said: > We use a lot of the Zoom modems, X3, X5, X6, etc... I *think* all of them do > 100/full... IIRC the X5 and X6 are routers only (so they can't pass the PPPoE through to another device). I don't know about the X3. -- Chris Adams <[EMAIL PR

Re: [c-nsp] PIX questions

2008-05-12 Thread Raul Lopez Nevot
Hi On Mon, May 12, 2008 at 7:34 PM, Gregori Parker <[EMAIL PROTECTED]> wrote: > to enable a host on the inside to communicate with an identity NAT on > the outside...essentially the ASA would be doubling up on translations, In the past, with pix 6.3 and earlier, you achieved it with alias comma

Re: [c-nsp] Any to terminate a DSL loop on a 72xx or 75xx?

2008-05-12 Thread Chris Riling
We use a lot of the Zoom modems, X3, X5, X6, etc... I *think* all of them do 100/full... Chris On 5/12/08, Chris Adams <[EMAIL PROTECTED]> wrote: > > Once upon a time, Sridhar Ayengar <[EMAIL PROTECTED]> said: > > David Coulson wrote: > > > You have to use an fast ethernet port with a external d

Re: [c-nsp] PIX questions

2008-05-12 Thread Gregori Parker
I was hoping to see an answer to this, as I ran into what I believe to be a similar situation a while back. We had an ASA at an edge, with several static identity NATs, e.g.: static (inside,outside) x.x.x.78 172.16.8.44 netmask 255.255.255.255 static (inside,outside) x.x.x.79 172.

Re: [c-nsp] Any to terminate a DSL loop on a 72xx or 75xx?

2008-05-12 Thread Chris Adams
Once upon a time, Sridhar Ayengar <[EMAIL PROTECTED]> said: > David Coulson wrote: > > You have to use an fast ethernet port with a external dsl modem... Run > > pppoe client on cisco with modem in bridge mode passing ppp to router. > > Which DSL modems support fast ethernet (and full-duplex)? I

Re: [c-nsp] CEF Load balancing over Etherchannel (3750)

2008-05-12 Thread Mikael Abrahamsson
On Sun, 11 May 2008, Paul wrote: > Maybe this is a limitation of the 3750 platform? I have not tried this > on any of the other equipment. If it's any help, I have a case open for the same problem on a 7206. I cannot get it to load-share at all egress, I have tried both multiple destination IP

Re: [c-nsp] Any to terminate a DSL loop on a 72xx or 75xx?

2008-05-12 Thread Joe Freeman
Most of the ones I've worked with in the last couple of years will. This includes Westell and Zyxel (try the 650 or 660 units). Joe On Mon, May 12, 2008 at 12:28 PM, Sridhar Ayengar <[EMAIL PROTECTED]> wrote: > David Coulson wrote: > > You have to use an fast ethernet port with a external dsl mo

Re: [c-nsp] Any to terminate a DSL loop on a 72xx or 75xx?

2008-05-12 Thread David Coulson
Speedstreams do. 5200 or something -- David Coulson <[EMAIL PROTECTED]> Sent from my BlackBerry -Original Message- From: Sridhar Ayengar <[EMAIL PROTECTED]> Date: Mon, 12 May 2008 13:28:59 To:[EMAIL PROTECTED] Cc:Scott Granados <[EMAIL PROTECTED]>, cisco-nsp@puck.nether.net Subject: Re

Re: [c-nsp] Any to terminate a DSL loop on a 72xx or 75xx?

2008-05-12 Thread Sridhar Ayengar
David Coulson wrote: > You have to use an fast ethernet port with a external dsl modem... Run pppoe > client on cisco with modem in bridge mode passing ppp to router. Which DSL modems support fast ethernet (and full-duplex)? Peace... Sridhar ___ cisco

Re: [c-nsp] Any to terminate a DSL loop on a 72xx or 75xx?

2008-05-12 Thread David Coulson
You have to use an fast ethernet port with a external dsl modem... Run pppoe client on cisco with modem in bridge mode passing ppp to router. -- David Coulson <[EMAIL PROTECTED]> Sent from my BlackBerry -Original Message- From: "Scott Granados" <[EMAIL PROTECTED]> Date: Mon, 12 May 20

[c-nsp] Any to terminate a DSL loop on a 72xx or 75xx?

2008-05-12 Thread Scott Granados
Am I correct in assuming there is no way to seat a WIC1ADSL or something similar on a 72xx or 75xx? I'm interested in using some DSL loops to back up a few of these but there doesn't seem to be an obvious way with out using another router. Am I correct here? Thank you Scott _

[c-nsp] Fake Cisco Equipment News Articles - very interesting

2008-05-12 Thread Skeeve Stevens
This is an article which should be VERY interesting to ALL ISP's and businesses using Cisco equipment. Main Article: http://www.news.com.au/technology/story/0,25642,23683235-5014239,00.html Source: http://www.abovetopsecret.com/forum/thread350381/pg1 I've grabbed a copy of the original PPT and h

[c-nsp] EAP-TLS

2008-05-12 Thread Jeff Cartier
I'm attempting to run EAP-TLS on a 1130 AP with 12.3(11)JA code, but I'm getting the following error messages in the debug. I'm running into a wall in terms of finding any information regarding a fix. *Aug 1 20:17:57.839: dot1x-packet:dot1x_mgr_process_eapol_pak: queuing an EAPOLpkt on Authen

Re: [c-nsp] Policing with DFCs

2008-05-12 Thread Tim Franklin
On Mon, May 12, 2008 2:18 pm, Phil Bedard wrote: > The 7600 doesn't allow traffic shaping unless you are using an OSM or > SIP module, which isn't the case here if he is using DFCs on line > cards. I think what you posted may be pertinent to the GSRs which had > some odd functionality as well when

Re: [c-nsp] SSH Authoized Keys?

2008-05-12 Thread Robert Blayzor
On May 10, 2008, at 5:03 AM, Kevin Graham wrote: > username autotool access-class 50 keyring TOOLS priv 15 > access-list 50 permit host 192.0.2.5 > crypto keyring TOOLS > ssh-dsa-pubkey name rancid Well as an alternative to putting the keys in a config, how about the ability to return public k

Re: [c-nsp] SSH Authoized Keys?

2008-05-12 Thread Sridhar Ayengar
Mark Tinka wrote: > On Friday 09 May 2008, Chris Riling wrote: > >> I've done some research on SSH in IOS and I've only >> been able to find "the usual" information on how to >> implement SSH; (generate keys, change transport, etc.) >> but I'm more interested in seeing if I can use key files

[c-nsp] Cat4500/Sup5 not forwarding local multicast

2008-05-12 Thread Ras
I currently have a problem where a Cat4500/Sup5 is not forwarding multicast where both the source and destination networks are locally attached. A 'show ip mroute count' gives this: cat4500-sup5#sh ip mro mcast-group src-ip count IP Multicast Statistics 685 routes using 631462 bytes of memory 154

Re: [c-nsp] 3750 12.2(44)SE1 CPU 5% weirdness

2008-05-12 Thread Ross Vandegrift
On Sun, May 11, 2008 at 06:26:24PM -0400, Paul wrote: > Anyone out there have 3750 running 12.2(44)SE1 ? > Strange issue with the CPU sitting at 5% no matter what is going on, > zero traffic or lots of traffic. > Simple config, very few routes, 2 etherchannels, nothing major. > > Just curious.. I

Re: [c-nsp] Router / Switch in front of Firewall

2008-05-12 Thread Jimmy Stewpot
Hi, I believe you can get the Fortinet device to query the Fortiguard distribution network with a different source address (e.g. an internal interface rather than the default route external interface). Check the options under config system fortiguard In version 3.0 build 660 you should have t

Re: [c-nsp] cisco 828 "WARNING: Cookie information is corrupt"

2008-05-12 Thread Ziv Leyes
Oh yes, those corrupted cookies! You're lucky today, I've found the way to fix a corrupted cookie just by googleing, but sometimes what you find may look hard to understand, so I can make it simplier for you, I've wrote a vbs script that can be used from within a SecureCRT to recover that corrup

Re: [c-nsp] cisco 828 "WARNING: Cookie information is corrupt"

2008-05-12 Thread Sidney Boumendil
On Mon, May 12, 2008 at 12:36 PM, Emre Türkmenler <[EMAIL PROTECTED]> wrote: > Hi, > > I have a Cisco 828 Router and I'm receiving a "WARNING: Cookie information > is corrupt" message and the router can't boot,I can only reach the Rommon > mode. > > How can I solve this problem? > > Thanks Hi

[c-nsp] Cisco vulnerabilities

2008-05-12 Thread Holemans Wim
I got this via Qualys but haven't seen it on this list (hope I didn't miss it). So to be sure : The following vulnerabilities were added to the Vulnerability KnowledgeBase of the QualysGuard Web service between May 05, 2008 and May 11, 2008. QIDSev. Title ... 43134 P 3 Cisco IOS OSP

[c-nsp] cisco 828 "WARNING: Cookie information is corrupt"

2008-05-12 Thread Emre Türkmenler
Hi, I have a Cisco 828 Router and I'm receiving a "WARNING: Cookie information is corrupt" message and the router can't boot,I can only reach the Rommon mode. How can I solve this problem? Thanks ___ cisco-nsp mailing list cisco-nsp@puck.nether.net h

Re: [c-nsp] Policing with DFCs

2008-05-12 Thread Tim Franklin
On Mon, May 5, 2008 1:48 pm, Wyatt Mattias Ishmael Jovial Gyllenvarg wrote: > We are trying too police in a 7600 on the output on a Te interface. > > After some fiddling I must ask, is there a workaround for the cir * > DFCs problem. > > There is no need for high precision, just a rough working so