Re: [c-nsp] (no subject)

2012-08-14 Thread Engelhard M. Labiro
What line cards are inserted ? Do you have enough power ? On Tue, Aug 14, 2012 at 5:35 PM, Harry Hambi wrote: > Hi All, > I have the following global command, diagnostic level complete. Is this > command doing some sort of Diag on the line cards?. Also the output of > the sh mod command is as fo

Re: [c-nsp] modify cisco router config with scripting?

2011-06-15 Thread Engelhard Mahandar Labiro
I use Teraterm Macro script to automate some repetitive tasks in the router/switch. Have a look at http://ttssh2.sourceforge.jp/manual/en/macro/ On Wed, Jun 15, 2011 at 6:26 PM, d tbsky wrote: > hi: >   I want to write a script to modify the acl entry for cisco 3725 and > cisco 3750G. > I find no

Re: [c-nsp] Wireless 802.1x authentication failures

2011-06-14 Thread Engelhard Mahandar Labiro
I think this has something to do with Server's type certificate which doesn't bound properly to MS IAS EAP settings. You may want to re-check if any missing checkbox related to Server's certificate. On Tue, Jun 14, 2011 at 3:53 PM, Edward Iong wrote: > Hi there, > > I have checked the cert is not

Re: [c-nsp] Wireless 802.1x authentication failures

2011-06-13 Thread Engelhard
You may want to eliminate several issues contributing to this problem. One thing to check is the expiration date of the certificate issued for MS ISA. HTH Sent from my iPhone On 2011/06/14, at 15:13, Edward Iong wrote: > > Dear All, > > We are using windows certificates for authenticate do

Re: [c-nsp] cisco web site down ?

2011-04-09 Thread Engelhard
I can see the Cisco mobile web from Japan. No issue at the accessibility. Sent from my iPhone On 2011/04/10, at 8:43, Jeff Orr wrote: > Cisco.com mobile and full working here in Ohio... > > Sent from my AT&T iPhone > > On Apr 9, 2011, at 7:39 PM, John Brown wrote: > >> I tried from my Cell

[c-nsp] Load balance IPSec with Cisco ACE

2010-04-21 Thread Engelhard
Does anyone know if Cisco ACE can loadbalance IPSec protocol? Docs on Cisco said that AcE only able to loadbalance TCP/UDP/SIp/SSL/ Firewall but doesn't mention specifically about IPSec Appreciate for any info ___ cisco-nsp mailing list cisco-nsp@puc

Re: [c-nsp] DMVPN scalability question on the 28XX ISR's

2010-04-21 Thread Engelhard Mahandar Labiro
sco IP Solution Center. > > > -Luan > > -Original Message- > From: cisco-nsp-boun...@puck.nether.net > [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Engelhard > Sent: Monday, April 19, 2010 8:06 PM > To: rod...@cisco.com > Cc: cisco-nsp@puck.net

Re: [c-nsp] DMVPN scalability question on the 28XX ISR's

2010-04-19 Thread Engelhard
Any suggestion for 2000+ spokes with 4 headends? Headends will be ASR100x. We think to put Loadbalancer (ACE) in front of ASR to spread DMVPN traffic. Is it design wise? Sent from my iPhone On 2010/04/19, at 23:28, Rodney Dunn wrote: My suggestion is to run code that support dynamic BGP n

Re: [c-nsp] OT: Learning about SONET/SDH

2009-08-11 Thread Engelhard Mahandar Labiro
As always a book from Cisco Press. It covers some case studies to design and implement SONET/SDH Optical Network Design and Implementation by Vivek Alwayn Publisher: Cisco Press Pub Date: March 17, 2004 Print ISBN-10: 1-58705-105-2 Print ISBN-13: 978-1-58705-105-0 Pages: 840 HTH Engel On Wed, Au

Re: [c-nsp] vpn configure

2009-08-11 Thread Engelhard Mahandar Labiro
> How can I configure remote subnet and local subnet for vpn in cli? > > ls pix only accessed by https in inside for configuration? > > No other way for http configuration outside? I won't enable HTTP on an outside I/F let alone a Firewall that suppose to be secured. Better to enable an IPSec tunn

Re: [c-nsp] Interface descriptions - what do you put in?

2009-05-21 Thread Engelhard Labiro
Pete, for WAN connection we put the Provider name and circuit number, for LAN connection we put the hostname of the other end and its interface number. HTH, Engel On Fri, May 22, 2009 at 12:07 AM, Pete Templin wrote: > List, > > What do you put into your interface descriptions?  Do you document

Re: [c-nsp] SNMP OIDs for packet counters in 7600/6500 "show ibc | i bytes"

2009-04-23 Thread Engelhard Labiro
Have you tried "snmpwalk" to your router to retrieve all available values there? Piping those may get you to similar counter. On Apr 24, 2009, at 6:05 AM, Everton da Silva Marques > wrote: Hi, Please point out the SNMP OIDs (if any) for reading the packet counters displayed as output of "sh

Re: [c-nsp] SNMP OID of 3825 router

2009-04-23 Thread Engelhard Labiro
Try "SNMP object navigator" at cisco.com's Tools&Resources. On Apr 23, 2009, at 3:17 PM, Tseveendorj wrote: Hello, How do I know logged user on 3825 by SNMP ? Really appreciate for any help. Sincerely, Tseveen. ___ cisco-nsp mailing list cisco-n

Re: [c-nsp] cisco command to show 10GE module type?

2009-04-17 Thread Engelhard Labiro
Use command "show int status" Sent from my iPhone On 2009/04/18, at 11:04, Neil d wrote: Hi all, Is there any command to show what kind of Xenpak 10G module in the 6704-10GE card? from cisco website, there're a bunch of them: Cisco XENPAK-10GB-CX4: . • Cisco XENPAK-10GB-LX4: • Cisco XENP

Re: [c-nsp] VTY Lines

2009-04-15 Thread Engelhard Labiro
Is this bug or just config under vty that disabled session timeout? Do you have entry "exec timeout 0 0" at line vty? On 2009/04/16, at 12:53, Yevgeniy Voloshin wrote: Hi, I have the same problem on ME-C3750-24TE with Cisco IOS Software -> C3750ME Software (C3750ME-I5-M), Version 12.2(44

Re: [c-nsp] WS-X6748-SFP temperature sensor

2009-04-14 Thread Engelhard Labiro
Couldn`t find doco on cisco that state it has a temp.sensor..but "sh env" of the module indicates that the chassis is able to show the temp. of the card. sh module Mod Ports Card Type Mode --- - -- -- 18 CEF

Re: [c-nsp] reacheability issue in MEL link

2009-02-03 Thread Engelhard Labiro
> i told the carrier i want to have the packets transferred with dot1q > encapsulation, and they replied that they are providing a transparent > environment, reagardless the two ends are access or trunk Does your carrier support 802.1QinQ or something alike that is able to transport your dot1q tag

Re: [c-nsp] ASA 5520 Remote Access VPN

2009-02-03 Thread Engelhard Labiro
> hostname(config)# ip local pool testpool 192.168.0.10-192.168.0.15 I guess this is a routing problem, since you assign 192.168.0.x to vpn client which is located on different segment with PIX's own interface. The pix must response to arp request for 192.168.0.10 to 15 on behalf of the vpn clien

Re: [c-nsp] cisco-nsp Digest, Vol 74, Issue 67

2009-01-21 Thread Engelhard Labiro
This happen when you have a mismatch configuration between your "Port-channel interface" setting and Gigabit interfaces which are members of that Port-channel. Compare again the settings in Port-channel and its members. All must be the same otherwise you will get several port-channels w/ alphabet

Re: [c-nsp] Public table on 7206 VXR with NPE-G1 - 512MB or 1GB?

2009-01-21 Thread Engelhard Labiro
Hi Mick, FYI a 7206VXR-NPE-G1 loaded with 1Gig only consumes around 250Mb of its memory for a full BGP table (around 271K routes without filtering). See our router stat here #sh mem HeadTotal(b) Used(b) Free(b) Lowest(b) Largest(b) Processor 63F362C0 9235733

[c-nsp] Fwd: VLAN 1 through routed ports

2009-01-09 Thread Engelhard Labiro
On Fri, Jan 9, 2009 at 2:22 AM, Justin Shore wrote: > And by all means DO NOT USE VLAN 1. That's what bit me in the ass last > night. An unconfigured 7600 LAN port with switchport, mode access and no > access vlan defined was a piece in the puzzle of the cluster that was my > evening last night

Re: [c-nsp] RSP4 as route server? - seeking suggestions and opinions

2008-12-20 Thread Engelhard Labiro
Just FYI , recently our 7206VXR (w NPE225) 256MB could not handle 2 BGP full routes (total around 40k routes) from provider. The router generated not enough memories and disabled its CEF. On Sat, Dec 20, 2008 at 11:30 PM, Ang Kah Yik wrote: > Hi all, > > Would an RSP4 (256MB RAM) from a 7505 be a