Re: [c-nsp] OSPF fast convergence on Sup32/SXI

2009-08-30 Thread Gert Doering
Hi, On Mon, Aug 31, 2009 at 09:33:46AM +1000, Ben Steele wrote: > If you can work a solution that incorporates BFD you will be better off in > the long run(as your router certainly won't get less busy as time goes on) > if the ultimate goal is fast convergence with 5 exclamation marks :) I'd *lov

Re: [c-nsp] Wierd memory issue with SXI/SXI1 on 6500 w/ SUP720-3BXL [SOLVED]

2009-08-30 Thread Chris Phillips
A "show memory allocating-process totals" is very telling. llocator PC Summary for: Processor Displayed first 2048 Allocator PCs only PC Total Count Name 0x4035A6C8 2951861724420 BGP battr chun 0x40809510 45688268 695 CEF: fib BGP is definitely the culprit. It has

Re: [c-nsp] OSPF fast convergence on Sup32/SXI

2009-08-30 Thread Ben Steele
You can try OSPF fast hello's but the general consensus is to not use them purely because there is no pseudo preemption for it(unlike bfd) so if you have a busy router, or even a router with bursty busyness aka snmp polling you can draw false positives into your fast hello's. Having said that some

[c-nsp] Help with Cisco ASA w/CSC-SSM and WCCP Configuration..

2009-08-30 Thread Howard Leadmon
I figured I would post here and see if anyone has set this up before, and come across a decent solution for the issue I am currently trying to work through. First off I have a Cisco ASA-5510 with the CSC-SSM-10 module installed in it. The ASA is running the most current 8.2.1 code, and the

Re: [c-nsp] Monitor 3560

2009-08-30 Thread Gert Doering
Hi, On Thu, Aug 27, 2009 at 01:08:32PM -0400, Randy McAnally wrote: > It does however, count traffic routed between VLANs. No. Well - *if* it does, you have a BIG problem, because that would mean "CPU switched traffic". gert -- USENET is *not* the non-clickable part of WWW!

Re: [c-nsp] Monitor 3560

2009-08-30 Thread Gert Doering
Hi, On Thu, Aug 27, 2009 at 03:30:03PM +0300, almog ohayon wrote: > Hello Everyone,i wondered if anyone knows how to monitor 3560 interface vlan > traffic ? "take the 3560 and beat your cisco sales rep with it". This still won't give you per-vlan counters, but vent off some of the frustration t

Re: [c-nsp] Wierd memory issue with SXI/SXI1 on 6500 w/ SUP720-3BXL

2009-08-30 Thread Gert Doering
Hi, it's a bit hard to comment on this, as it is lacking the most important bit - *which process* is losing the memory? ("show proc mem sort", run every few days, compare the output). On Sun, Aug 30, 2009 at 10:11:10AM -0700, Chris Phillips wrote: > I did not have this issue with SXH* on this s

Re: [c-nsp] Wierd memory issue with SXI/SXI1 on 6500 w/ SUP720-3BXL

2009-08-30 Thread Azher Mughal
SXI2 will give you another malloc bug :) CSCtb27643cat6000 Medium buffers leak on SP leading to crash Here is a workaround suggested by Cisco: One workaround is to disable the diag test 'TestEARLInternalTables' on all the DFC/PFC modules. However, this workaround will only stop further me

Re: [c-nsp] Migrate 6500 to 7600

2009-08-30 Thread Rob Shakir
On Sun, Aug 30, 2009 at 05:25:25PM +0100, Mateusz Blaszczyk wrote: > On Sat, Aug 29, 2009 at 07:50:22PM +0100, Mateusz Blaszczyk wrote: > > > With SXF this has never been a > > > problem, only with SRB/SXH and newer. > > > > Yes, I forgot about the SXF can be run on both platforms. Then one thing

Re: [c-nsp] Wierd memory issue with SXI/SXI1 on 6500 w/ SUP720-3BXL

2009-08-30 Thread e ninja
Grab multiple captures of sh proc mem to identify the process "holding" and not releasing (i.e. leaking) memory. When memory is heavily depleted, grab a *show memory allocating-process totals* and feel free to unicast. Any MALLOC failures? -Eninja On Sun, Aug 30, 2009 at 10:11 AM, Chris Phillip

[c-nsp] Wierd memory issue with SXI/SXI1 on 6500 w/ SUP720-3BXL

2009-08-30 Thread Chris Phillips
Every six weeks or so I am running out of memory on a 6509 w/ dual SUP720-3BXL with mostly 6700-series line cards. I have 21 other nodes with this exact same configuration, some even running SXI or SXI1 that do not have this issue, which first led me to believe that the issue might be hardware

Re: [c-nsp] Migrate 6500 to 7600

2009-08-30 Thread Gert Doering
Hi, On Sun, Aug 30, 2009 at 05:25:25PM +0100, Mateusz Blaszczyk wrote: > done some reading and it seems 7606S was supported first by SR train: 7606S definitely does NOT boot under SXH. Been there, done that, returned the chassis. (We told them "we want to run modular". They said "oh, why both

Re: [c-nsp] IPV6 in general was Re: Large networks

2009-08-30 Thread Grzegorz Janoszka
Mohacsi Janos wrote: I disagree. Not worst than DHCP. By the way how do you distribute parameters for local links? DHCP fake offers are better filterable I think. With v6 we now use mostly static IP addressing. Still working for DHCP over v6. -- Grzegorz Janoszka

Re: [c-nsp] Migrate 6500 to 7600

2009-08-30 Thread Mateusz Blaszczyk
On Sat, Aug 29, 2009 at 07:50:22PM +0100, Mateusz Blaszczyk wrote: > > With SXF this has never been a > > problem, only with SRB/SXH and newer. > > Yes, I forgot about the SXF can be run on both platforms. Then one thing > less to worry about. > not so happy anymore. done some reading and it seem

Re: [c-nsp] IPV6 in general was Re: Large networks

2009-08-30 Thread Grzegorz Janoszka
Gert Doering wrote: What exactly is "incredibly insecure" in *sending* RAs? I could understand if a host does not want to *receive* RAs, if the network environment is not trusted and there is no SeND available yet. Maybe nothing not that wrong with sending, but I recently compared DHCP and ND

Re: [c-nsp] OSPF fast convergence on Sup32/SXI

2009-08-30 Thread Clue Store
Ive had a few customers on a small scale routers perfectly, I believe the dead time in Cisco default is 4 times the hello. I have all of them set of 3 sec Hello packets and a 30 second heal time and zero route instabitliey. But I have zero experience with the sup32/6509 kit. This has been done on

Re: [c-nsp] Migrate 6500 to 7600

2009-08-30 Thread Clue Store
Hi Pete, Im about to undego this same process with 7203bXL, and i'd like to know what roles ur 7606's play?? (BGP, PE, IPv6, 6pe, etc) What has been your most stable non-bgp bugged image that you use??? On Sat, Aug 29, 2009 at 1:50 PM, Mateusz Blaszczyk wrote: > > With SXF this has never been

Re: [c-nsp] Data VLAN/Voice VLAN

2009-08-30 Thread Clue Store
What platform/IOS are you running?? I think the older 3500xl PoE switch had to be in trunk mode to accomplish the dot1(p)(q) header info so trust the EF marking of the packet would work due to CDP improvements and working without actually having a it in "trunk mode". Think newer platforms and IOS,