Re: [c-nsp] Debug icmp for vrf

2015-09-02 Thread Pierre Emeriaud
Hi, > The "tail" is provided by a third party, and they are investigating from > there side, but Id like to exhaust all possibilities on our side also - Is > there any "vrf" icmp debugging options I could run on our PE..debug ip icmp ? > doesnt give any "vrf" options. > > > > Any suggestions/a

[c-nsp] Debug icmp for vrf

2015-09-02 Thread CiscoNSP List
Hi Everyone, Had a bit of a google, but couldnt find anything useful, so hoping someone on the list can assist :) We have a weird problem with a customer tail - Customer has tried connecting 2 different Cisco 1900's (In case 1st was faulty), very basic config, no dot1q, no natting, no acl

Re: [c-nsp] BGP multipath load balancing.. broken sessions upon hash change

2015-09-02 Thread Peter Kranz
I am attempting to load balance ~100 Gbps of inbound traffic across several processing nodes. Each node advertising the same /32 back to the core router and CEF nicely divides the traffic so that 1/16th of it arrives at each node. The problem arises when a node is brought out of rotation, existi

Re: [c-nsp] BGP multipath load balancing.. broken sessions upon hash change

2015-09-02 Thread Chase Christian
Correct, in order to have a "sticky" session, the device would have to keep the TCP session state in a table somewhere (like a NAT table), which ECMP and CEF do not do. On Wed, Sep 2, 2015 at 2:55 PM, Łukasz Bromirski wrote: > Peter, > > > On 02 Sep 2015, at 22:49, Peter Kranz wrote: > > > > I’

Re: [c-nsp] BGP multipath load balancing.. broken sessions upon hash change

2015-09-02 Thread Łukasz Bromirski
Peter, > On 02 Sep 2015, at 22:49, Peter Kranz wrote: > > I’m using bgp maximum-paths and several peers announcing the same /32 to > create a poor man’s load balancer. This works well with up to 16 peers after > which the CEF number of buckets is exceeded. > > However, if the number of connecte

Re: [c-nsp] Cisco IOS SLB performance under Supervisor 2T

2015-09-02 Thread Łukasz Bromirski
> On 02 Sep 2015, at 22:52, Peter Kranz wrote: > > This document indicates a maximum of 8G of throughput for IOS SLB under a > Supervisor 720-3BXL > > http://www.cisco.com/c/en/us/products/collateral/interfaces-modules/persiste > nt-storage-device-module/product_data_sheet0900aecd806b5dc9.html

[c-nsp] Cisco IOS SLB performance under Supervisor 2T

2015-09-02 Thread Peter Kranz
This document indicates a maximum of 8G of throughput for IOS SLB under a Supervisor 720-3BXL http://www.cisco.com/c/en/us/products/collateral/interfaces-modules/persiste nt-storage-device-module/product_data_sheet0900aecd806b5dc9.html Is anyone aware of what the performance limitation of this fe

[c-nsp] BGP multipath load balancing.. broken sessions upon hash change

2015-09-02 Thread Peter Kranz
I’m using bgp maximum-paths and several peers announcing the same /32 to create a poor man’s load balancer. This works well with up to 16 peers after which the CEF number of buckets is exceeded. However, if the number of connected peers change, all sessions break, which I would like to avoid. For

Re: [c-nsp] SNMP ifLastChange > 30 days

2015-09-02 Thread Howard Jones
On 02/09/2015 18:11, Drew Weaver wrote: Hey all, I've been dealing with an issue in SNMP (6500) where I need to know whether an interface has changed its operational status within the last 30 days. I came across the oid ifLastChange which tracks against the 32 bit counter sysUptime.0, the pro

Re: [c-nsp] SNMP ifLastChange > 30 days

2015-09-02 Thread Peter Rathlev
On Wed, 2015-09-02 at 17:11 +, Drew Weaver wrote: > I came across the oid ifLastChange which tracks against the 32 bit > counter sysUptime.0, the problem obviously is that when sysUptime.0 > resets ifLastChange becomes pretty much useless. > > It seems as though there would be some way to 'mat

[c-nsp] SNMP ifLastChange > 30 days

2015-09-02 Thread Drew Weaver
Hey all, I've been dealing with an issue in SNMP (6500) where I need to know whether an interface has changed its operational status within the last 30 days. I came across the oid ifLastChange which tracks against the 32 bit counter sysUptime.0, the problem obviously is that when sysUptime.0 re

Re: [c-nsp] FW: N7K F2e Module

2015-09-02 Thread Tim Stevenson
When F2E is mixed with M, then F2E ports operate as L2 only, but in this case he is unable to configure the *M* ports with anything other than "switchport host". That's just wrong. Probably the first step is to get on decent code, and see if the issue remains. Ie, 6.2.12 or 6.2.14. Tim At 0

Re: [c-nsp] FW: N7K F2e Module

2015-09-02 Thread Sandor Rozsa
I dag this issue and found out that if you mix M1 with f2e than on the f2e you'll have only l2 features. You can try by creating an f2e only vdc and see if the features are available. sandor On Wed, Sep 2, 2015 at 12:39 PM, Mohammad Khalil wrote: > Please check below > > sh vdc > Switchwide mod

[c-nsp] Cisco Security Advisory: Cisco Integrated Management Controller Supervisor and Cisco UCS Director Remote File Overwrite Vulnerability

2015-09-02 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Integrated Management Controller Supervisor and Cisco UCS Director Remote File Overwrite Vulnerability Advisory ID: cisco-sa-20150902-cimcs Revision 1.0 For Public Release 2015 September 2 16:00 UTC (GMT

[c-nsp] MACSec support on Catalyst 4500-X

2015-09-02 Thread Cisco NSP
I read that MACSec inter-switch is supported between a pair of Catalyst 4500-X. Not Cisco TrusSec MACSec. What are the differences (standard versus proprietary)? Is it right? Any limitations or pre-requisites? Thanks for your advice, Manu ___ cisco-ns

[c-nsp] FW: N7K F2e Module

2015-09-02 Thread Mohammad Khalil
Please check below sh vdc Switchwide mode is m1 f1 m1xl f2 m2xl f2e vdc_id vdc_name state mac typelc -- - -- - -- 1 JCBank_Core1

[c-nsp] N7K F2e Module

2015-09-02 Thread Mohammad Khalil
Hi all I have Cisco N7K with 6.2.2a Image I brought F2e module to be installed on my system and I have already M1xl (30 ports fiber module ) already in place After installing the F2e module , most of the ports on the M1 module (which were configured as trunk ports) shows the I cannot configure