Re: [c-nsp] Differences between 3750-E and 3560-E switches

2010-01-21 Thread Marian Ďurkovič
On Wed, 20 Jan 2010 10:17:39 -0600, Jeff Bacon wrote I've read through the data sheets, and I also can't see any signficant differences. I was wondering if there was some hardware differences (like CAM table size, ethernet input/output buffer sizes), etc... Is the packet buffering on

Re: [c-nsp] MPLS VPN with lot of PPP interfaces and central firewall

2010-01-21 Thread Gerald Krause
Am 21.01.2010 08:10, Oliver Boehmer (oboehmer) schrieb: I'am looking for a good solution to separate multiple branches from each other by using a central firewall setup. The overall view looks like that: [...] The () components will be under control of the customer, all other systems are

Re: [c-nsp] MPLS VPN with lot of PPP interfaces and central firewall

2010-01-21 Thread Gerald Krause
Am 21.01.2010 07:43, John Kougoulos schrieb: On Thu, 21 Jan 2010, Gerald Krause wrote: For now I see 3 options for us: a) implement dedicated VRFs for each branch and map VRFn-VLANn on the RTRs b) build a brigded L2 LAN from the CPE Dialer-Interfaces up to the Firewall-Ethernet

[c-nsp] Radius solution for VPN Concentrator and 802.1x

2010-01-21 Thread luismi
Hi all, I am looking for a Radius solution to configure on it the user accounts of the users of the VPN Concentrator 3030 we have here -that is the primary goal-. In the future I would like to use the same radius for 802.1x in the wireless network and maybe some captive portals or similar. The

Re: [c-nsp] Radius solution for VPN Concentrator and 802.1x

2010-01-21 Thread Frederic LOUI
Hi Luismi, Freeradius is a good alternative and can be used to cover all the needs you mentioned. Coupled with openldap, you can benefit from having all the LDAP Directory GUI for user creation. In addition, you can use MySQL backend for accounting purposes. As far as I could find,

Re: [c-nsp] Radius solution for VPN Concentrator and 802.1x

2010-01-21 Thread Steve Bertrand
Frederic LOUI wrote: Hi Luismi, Freeradius is a good alternative and can be used to cover all the needs you mentioned. Coupled with openldap, you can benefit from having all the LDAP Directory GUI for user creation. In addition, you can use MySQL backend for accounting purposes. As far

Re: [c-nsp] Radius solution for VPN Concentrator and 802.1x

2010-01-21 Thread Frederic LOUI
Hi Steve, It supports HA for itself and its database back-ends, and has a web gui (dialupadmin) for those so inclined, that does everything that the OP required out of it. Finally, the whole solution can run on LINUX. Most Unix-like OSs have pre-built packages that can be installed

Re: [c-nsp] cisco 6509 rommon mode [SEC=UNCLASSIFIED]

2010-01-21 Thread Wilkinson, Alex
0n Wed, Jan 20, 2010 at 11:32:54AM -0500, Kevin Loch wrote: Warning: Rommon NVRAM area is corrupted. Initialize the area to default values c6k_sup2 processor with 262144 Kbytes of main memory I've been bitten by this exact same bug. You have hit a hardware bug. Please see the

[c-nsp] A good SSL VPN Solution ?

2010-01-21 Thread Mehdi Badreddine
Hi all, Can you advise me a good vpn ssl solution for accessing Office LAN from my desktop computer without having to install a client software ? We should be able to access machines with ssh, http, imap and https. Are cisco asa appliances a good solution for this purpose ? In this case, what

Re: [c-nsp] cisco 6509 rommon mode [SEC=UNCLASSIFIED]

2010-01-21 Thread Ulici Alexandru
Had the same problem, and the same solution (RMA). alex 0n Wed, Jan 20, 2010 at 11:32:54AM -0500, Kevin Loch wrote: Warning: Rommon NVRAM area is corrupted. Initialize the area to default values c6k_sup2 processor with 262144 Kbytes of main memory I've been bitten by this

Re: [c-nsp] Radius solution for VPN Concentrator and 802.1x

2010-01-21 Thread luismi
Yes, FreeRadius could be a solution, but I don't want to expend 2 or more weeks learning how to get the best from the software and how to integrate it in the network without problems. In the other hand, Radiator looks to be great too. The paid support behind gives me some relax. I dont need to

Re: [c-nsp] A good SSL VPN Solution ?

2010-01-21 Thread Chris Wopat
Hi all, Can you advise me a good vpn ssl solution for accessing Office LAN from my desktop computer without having to install a client software ? We should be able to access machines with ssh, http, imap and https. Are cisco asa appliances a good solution for this purpose ? In this case,

Re: [c-nsp] A good SSL VPN Solution ?

2010-01-21 Thread Jason LeBlanc
On Jan 21, 2010, at 9:08 AM, Chris Wopat wrote: Hi all, Can you advise me a good vpn ssl solution for accessing Office LAN from my desktop computer without having to install a client software ? We should be able to access machines with ssh, http, imap and https. Are cisco asa appliances

Re: [c-nsp] A good SSL VPN Solution ?

2010-01-21 Thread Jason Shearer
Keep in mind that Cisco's AnyConnect solution requires a client to be installed. It has a pretty small footprint but a client nonetheless. As Chris stated it is cheap. Like an additional $750 list for a 5520 which will support 750 concurrent sessions. Jason -Original Message- From:

Re: [c-nsp] A good SSL VPN Solution ?

2010-01-21 Thread Bill Blackford
I believe there is additional costs for the SSL licensing on the asa5520 and it fairly high. -b -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Jason Shearer Sent: Thursday, January 21, 2010 8:48 AM To: Chris Wopat;

Re: [c-nsp] A good SSL VPN Solution ?

2010-01-21 Thread Jason Shearer
For traditional clientless SSL that is right. It is a per user cost. With 8.2.1 there is a new license you can purchase called AnyConnect Essentials. It is a flat license with no per user count. If you have it installed you can ONLY run AnyConnect and not clientless SSL. Jason

Re: [c-nsp] cisco 6509 rommon mode [SEC=UNCLASSIFIED]

2010-01-21 Thread Cyrill Malevanov
SUP2 costs $400. So even he doesn't have smartnet, this would be not very expensive. On Jan 21, 2010, at 5:28 PM, Ulici Alexandru wrote: Had the same problem, and the same solution (RMA). alex 0n Wed, Jan 20, 2010 at 11:32:54AM -0500, Kevin Loch wrote: Warning: Rommon NVRAM area is

[c-nsp] Mysterious ASIC

2010-01-21 Thread David Freedman
Look at this: #sh ver | in cisco WS- cisco WS-C2960G-48TC-L (PowerPC405) processor (revision E0) with 0K/4088K bytes of memory. #sh platform port-asic version Port-Asic Version Info: ASIC-0: Version:1 DeviceType:0x2CA ASIC-1: Version:1 DeviceType:0x2CA ASIC-2:

Re: [c-nsp] BGP Hold time expired/ospf dropping 6500 Sup720-3BXL

2010-01-21 Thread Andy B.
Hi, I just fell over this thread while doing a little reseach to solve a similar situation. Hardware: - 6509 with SUP720-3BXL on both ends - SXF15a - Uptime: 46 weeks Problem: - OSPF (for the loopback between cores) and BGP (mostly customers whom we send the full table) going up and down all

Re: [c-nsp] BGP Hold time expired/ospf dropping 6500 Sup720-3BXL

2010-01-21 Thread Jason LeBlanc
Can you send your snipped OSPF config? On Jan 21, 2010, at 5:28 PM, Andy B. wrote: Hi, I just fell over this thread while doing a little reseach to solve a similar situation. Hardware: - 6509 with SUP720-3BXL on both ends - SXF15a - Uptime: 46 weeks Problem: - OSPF (for the

Re: [c-nsp] BGP Hold time expired/ospf dropping 6500 Sup720-3BXL

2010-01-21 Thread Andy B.
Hi, here we go: Core router that is causing headaches: interface Loopback0 ip address x.x.x.130 255.255.255.255 interface TenGigabitEthernet9/1 ip address y.y.y.1 255.255.255.252 no ip redirects no ip proxy-arp no cdp enable router ospf 1 router-id x.x.x.130 log-adjacency-changes

[c-nsp] mysql update

2010-01-21 Thread madunix
I have the following update procedure that update mySQL DB over the internet between source Linux Centos (local machine on my net behind a DMZ with real IP A.B.C.D) and target Linux fedora (web server www.myweb.com) every day on a specific time 18:00 through a crontab on my source linux server