Re: [c-nsp] ASA 8.4 NAT weirdness...

2013-02-17 Thread Garrett Skjelstad
More configurable comes with a price. I'd rather have the extra bulk of configuration with the option for more complexity, rather than a second piece of hardware when those complex situations arise. Sent from my iPhone 5 On Feb 17, 2013, at 14:18, "Terry Baranski" wrote: > On Sunday, Feb 17

Re: [c-nsp] ASA 8.4 NAT weirdness...

2013-02-18 Thread Garrett Skjelstad
Meh. Everyone always complains when software changes. THAT is the universal law. Change is constant. Adapt and find the new cheese. =) -Garrett On Sun, Feb 17, 2013 at 4:50 PM, Terry Baranski < terry.baranski.l...@gmail.com> wrote: > On Sunday, Feb 17 2013, Garrett Skjels

[c-nsp] Software Advisor Issues?

2013-02-20 Thread Garrett Skjelstad
The software advisor for me has been broken the past few days (looking to compare a 28xx 12.4.10C to a 12.4T release) I can get all the way to selecting the hardware and pressing "next" and then it just goes out to lunch. I've tried multiple browsers, multiple PCs and no avail. Has anyone else be

Re: [c-nsp] VPN - restricted split tunnel? (newbie alert)

2013-02-28 Thread Garrett Skjelstad
Don't forget ACLs have permits and denies, and work in an ordered list... Permit (tunnel) the ones you want, deny (split) the ones you don't. External or internal IPs doesn't matter, an ACE is an ACE. -Garrett Sent from my iPhone 5 On Feb 28, 2013, at 6:55, Ricardo Stella wrote: > > I would

Re: [c-nsp] Meraki? is anyone there testing it?

2013-09-10 Thread Garrett Skjelstad
We are testing various uses and and in certain cases already deploying it extensively. Sent from my (old) iPhone5 On Sep 10, 2013, at 11:58, Luis Miguel Cruz Miranda wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > I just saw a service/product line from Cisco called Meraki. > Look

Re: [c-nsp] Help: attach a service-policy to an interface, without knowing which one is already attached

2014-03-11 Thread Garrett Skjelstad
Why not frequently pull the config using the config-copy-MiB, link and store the interface & service-policy in a DB (or I guess CSV) and use that? I suppose you could also just in time pull the config, but for every transaction that would suck. You do need TFTP access for this... Sent from my

Re: [c-nsp] 4500X in VSS - Upgrading IOS XE

2016-04-05 Thread Garrett Skjelstad
Why would you need to disconnect the VSS link? We've upgraded them successfully from 3.6 to 3.7 without disconnecting the VSS links and reloading them individually. On Tue, Apr 5, 2016 at 2:22 PM, CiscoNSP List wrote: > > Hi Everyone(Sent this to the list yesterday, but it still hasnt shown up?

Re: [c-nsp] 4500X in VSS - Upgrading IOS XE

2016-04-06 Thread Garrett Skjelstad
non ISSU upgrade)which sounded like a very unusual requirement > lol.hence my question here. > > > cheers > > > From: Garrett Skjelstad > Sent: Wednesday, 6 April 2016 8:35 AM > To: CiscoNSP List > Cc: cisco-nsp@puck.nether

Re: [c-nsp] Stop IP Fragmentation attck

2016-04-26 Thread Garrett Skjelstad
Now he reads the article... No, you can run BGP just on your edge, doesn't need to include provider. On Apr 26, 2016 13:41, "Satish Patel" wrote: > Roland, > > Let's say I like your S/RTBH but does it require my ISP support this? > > On Tue, Apr 26, 2016 at 1:54 PM, Roland Dobbins > wrote: > >

Re: [c-nsp] QinQ layer 3 port channel

2016-05-01 Thread Garrett Skjelstad
So you want to run some sort of link aggregation on top of a standard dot1q frame type? On May 1, 2016 18:01, "Wes Smith" wrote: > Hi > I have two sites connected by l2 vlan trunk. > On the A end, the A-client switch has multiple gig ports connecting to the > "A" core/pe. > > On the B end, the "B

Re: [c-nsp] Cisco ASA vpn hairpin

2016-09-05 Thread Garrett Skjelstad
without configs, how can anyone help you? Post sanitized pertinent information. (ACLs, P1/P2 informations) On Mon, Sep 5, 2016 at 3:55 PM, Pavel Dimow wrote: > Hi guys, > > I have a big problem in my setup and I don't know how to solve it plus it's > urgent :( > > I have ASA1 and ASA2 and L2L I

Re: [c-nsp] VPN IPsec and NAT

2016-10-12 Thread Garrett Skjelstad
Post relevant sanitized phase2 configurations. Mainly your ACLs. On Oct 12, 2016 04:37, "Tseveendorj Ochirlantuu" wrote: > Hello > > I'm new to site to site IPsec VPN and also ASA 5505 firewall. > > My site to site IPsec VPN tunnel established between SiteA to SiteB. And > can ping IP behind fi

Re: [c-nsp] Nexus 7700

2017-12-01 Thread Garrett Skjelstad
We've had 8.1.1 running now for ~9 months without issue. On Mon, Nov 27, 2017 at 1:50 PM, Scott Voll wrote: > What are others running on their 77xx's? > > 6.2.16 is the starred release but is over a year and a half old. and there > is an .18 version too (but not starred). > > 8.2.1 is very new.

Re: [c-nsp] Core layer device n7004 vs n9396px

2018-01-17 Thread Garrett Skjelstad
+1 to your comment about not using ACI-designed switches with NX-OS. I too, was burned by this during a migratory period. On Jan 16, 2018 15:59, "Igor Sukhomlinov" wrote: +1 to question about routing. Terminating uplinks from an ISP on a switch is generally not the best approach. Not that it wil

Re: [c-nsp] Nexus 3048 airflow configuration

2018-03-15 Thread Garrett Skjelstad
I think it would most likely just be easier on equipment to label a direction of airflow on the chassis to bring visibility to this (I don't recall seeing this on Nexus). Although, come to think about it, I'm pretty sure it has direction of airflow in the hardware installation guide... I personall

Re: [c-nsp] NBAR2

2018-05-25 Thread Garrett Skjelstad
Bumped for shared interest. On Fri, May 25, 2018, 06:51 Chuck Church wrote: > All, > > I'm curious if anyone is using NBAR2 with a recent protocol pack to > identify Office 365 traffic, specifically the ability to differentiate > between Outlook, Skype, and OneDrive traffic when it's TCP/44

Re: [c-nsp] Multi-homed ASA with a virtual interface for IPSec termination

2018-05-29 Thread Garrett Skjelstad
I have a few hundred tunnels on some ASR1002X's no problem MPLS over DMVPN I, too, would hesitate to use an ASA/NGFW as an IPSec headend for S2S. -Garrett On Tue, May 29, 2018, 13:37 Gert Doering wrote: > Hi, > > On Tue, May 29, 2018 at 01:47:14PM +0100, Nick Hilliard wrote: > > Juniper SRX h

Re: [c-nsp] choosing a switch.... cat6500 vs cat6800

2018-07-07 Thread Garrett Skjelstad
We have 20+ 6807 w/ SUP-2Ts and have been running them for 3.5 years. The code has gotten progressively better, admittingly though, it was garbage the first year. Just our experience. On Jul 7, 2018 15:51, "Eli Kagan via cisco-nsp" wrote: -- Forwarded message -- From: Eli Kag

Re: [c-nsp] What causes mac table relearning?

2018-10-22 Thread Garrett Skjelstad
Yes, TCN is where I would start, MST is famous for this as well. On Wed, Oct 17, 2018, 14:32 Mike wrote: > Hi, > > > I have a network consisting of 3560g switches and I do not run > spanning tree in this network. I have noticed a symptom when a vlan > trunk interface goes down/up, all mac

Re: [c-nsp] Cisco ASA 5512x VPN to Cradlepoint

2018-12-19 Thread Garrett Skjelstad
Certificates or PSK? On Tue, Dec 18, 2018, 10:48 Lee Starnes Hello All, > > Does anyone have any good links on how to best setup an IPSec VPN tunnel > from an ASA to a Cradlepoint that is on an LTE connection with a Dynamic > IP? I have all the configuration for the Cradlepoint side done, but hav

Re: [c-nsp] N3K: "VPC peer keep-alive receive has failed"

2018-12-27 Thread Garrett Skjelstad
Different VPC domains, yes? On Thu, Dec 27, 2018, 02:58 Manuel Guesdon Hi, > > I have a strange problem with Nexus N3K and QinQ tunnel. > > > I've configured 2 Nexus 3064 with VPC. It works well for monthes. > > Recently I've added a port-channel in dot1q-tunnel mode (the 1st one in > this > mode

Re: [c-nsp] Non-disruptive Nexus 77xx upgrade

2019-03-15 Thread Garrett Skjelstad
Do you just want to know duration? Single supervisor or multiple? On Fri, Mar 15, 2019, 13:21 Scott Voll wrote: > What does a Non-disruptive Nexus 77xx upgrade look like to a single homed > device, attached to it? > > TIA > > Scott > ___ > cisco-nsp m

Re: [c-nsp] 6800 ISSU issue

2019-04-22 Thread Garrett Skjelstad
We had similar issues. The best way we found to correct it was to do individual module resets just prior to running ISSU. After "hw-module reset"-ing all the supers, one at a time, we were able to ISSU without issue. On Mon, Apr 22, 2019, 05:50 Chuck Church wrote: > All, > >Ran into an

Re: [c-nsp] cisco ACL filter outbound only

2020-09-15 Thread Garrett Skjelstad
As with all things... Try and it and find out gns3.com or https://developer.cisco.com/modeling-labs/ or Production -GarrettSkj On Tue, Sep 15, 2020 at 9:11 AM Brian Turnbow via cisco-nsp < cisco-nsp@puck.nether.net> wrote: > > > > -- Forwarded message -- > From: Brian Turnbow >

Re: [c-nsp] Cisco Cat4500 Quad Sup VSS ISSU IOS Upgrade

2021-03-12 Thread Garrett Skjelstad
I know this is an awful answer, but just don't do ISSU on them. 😅 Most of my experiences come from quad Sup8s in the same chassis. We have been running 3.11.1 for the past 49 weeks, since our last cycle, which is 12/18 months. The biggest ISSUe (lol) with it, is just the sheer number of jumps bac

Re: [c-nsp] Cisco Cat4500 Quad Sup VSS ISSU IOS Upgrade

2021-03-13 Thread Garrett Skjelstad
engines. > I mean, is there a benefit to using "issu > loadverion/runversion/acceptversion/commitversion" process vs just loading > the software and reloading manually? > > Thanks, > Eli > > > > > > > On Friday, March 12, 2021, 04:08:25 PM EST, Garre