Re: [c-nsp] CSRv & VXLAN

2015-09-24 Thread Luan Nguyen
While we are on this... Is OTV still Cisco Proprietary? And still ASR1K and Nexus 7K support from Cisco side? Wouldn't it better to use L2TPv3 - and MACSEC if need to? On Thu, Sep 24, 2015 at 2:40 PM, Luis Anzola wrote: > Find below a very handy guide for the CSR1Kv and OTV: > > > http://www.cis

Re: [c-nsp] Cisco IOS XRv (Virtual ASR9k)

2015-08-17 Thread Luan Nguyen
--- > From: Roland Dobbins > To: cisco-nsp@puck.nether.net > Cc: > Date: Tue, 18 Aug 2015 01:37:48 +0700 > Subject: Re: [c-nsp] Cisco IOS XRv (Virtual ASR9k) > On 18 Aug 2015, at 1:36, Luan Nguyen wrote: > > > Thanks Harold...but from the link that Roland sent...there'

Re: [c-nsp] Cisco IOS XRv (Virtual ASR9k)

2015-08-17 Thread Luan Nguyen
> > > Le 2015-08-17 14:08, « cisco-nsp on behalf of Luan Nguyen » > a > écrit : > > >Nice...thanks 5.3.1 is nice. > >though i don't think people will have access to the file exchange? the > >public link only has 5.1.2 > > > >On Mon, A

Re: [c-nsp] Cisco IOS XRv (Virtual ASR9k)

2015-08-17 Thread Luan Nguyen
Nice...thanks 5.3.1 is nice. though i don't think people will have access to the file exchange? the public link only has 5.1.2 On Mon, Aug 17, 2015 at 2:00 PM, Tim Densmore < tdensm...@tarpit.cybermesa.com> wrote: > > https://upload.cisco.com/cgi-bin/swc/fileexg/main.cgi?CONTYPES=Cisco-IOS-XRv >

[c-nsp] CCIE Party pickup line

2015-06-01 Thread Luan Nguyen
In the Washington DC area, there's the HOV slug-lines where you can pick up people for HOV, is there one for CCIE Party? :) We have a big team going this year and not enough CCIEs to get all in...anyone going solo, kindly drop me an email offlist? :) Thanks. Regards, -lmn _

[c-nsp] ASR1000v Loopback interface

2015-02-23 Thread Luan Nguyen
Hello, anyone use the loopback interface on the ASR 1000v to terminate VPN/DMVPN tunnel? How does the loopback interface on the ASR1000v related to the VMWare resources? say if i already have the max 10 vnics mapped to 10 gigethernet interfaces on the asr1000v, how does the loopback interface come

Re: [c-nsp] Packet Fragmentation

2015-02-12 Thread Luan Nguyen
If you're lucky to have a provider like NTT, who supports 5000 MTU within their backbone, for site to site vpn, you could just jack up your MTU setting on all tunnel-related interfaces to say 5000 MTU and avoid fragmentation altogether. On Thu, Feb 12, 2015 at 2:15 PM, Roland Dobbins wrote: > On

Re: [c-nsp] Primer for IOS-XR

2014-12-16 Thread Luan Nguyen
Best place to be: https://supportforums.cisco.com/community/5996/xr-os-and-platforms Document tab as well as Blog tab will get you expert at IOS-XR in no time. On Tue, Dec 16, 2014 at 10:49 AM, Scott Granados wrote: > > Good morning, > > I have recently been exposed to some of the ASR hardware fo

[c-nsp] QSFP 40G breakout cable

2014-09-15 Thread Luan Nguyen
Hi folks, Anyone from the northern VA area has a couple extra of these? I'd like to borrow for a couple days to see if they work in other vendors' equipment? Believe it or not, Cisco' s one is much cheaper. Thanks! rg/lmn ___ cisco-nsp mailing list ci

[c-nsp] Using Cisco Learning Credits for ccie lab

2013-11-08 Thread Luan Nguyen
Hi folks, Can you use Cisco Learning Credits for ccie lab payment? seems like you can't but not sure if your Cisco Account Manager can do something about that? Also, where do people get exam voucher from? Is that something your Cisco Account team can provide? We have some Cisco Learning Credits, a

[c-nsp] Cisco ASA 8.4.7

2013-10-09 Thread Luan Nguyen
Hi folks, With the newest advisory for the ASA: http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20131009-asa We are thinking of going uniform with Cisco ASA 8.4.7. Looking at the Resolved Caveats, lots of them got fixed: http://www.cisco.com/en/US/docs/security/asa/a

Re: [c-nsp] DMVPN/mGRE on L3VPN - anyone experience issues with encapsulation overhead/MTU?

2013-10-09 Thread Luan Nguyen
People do this all the time: GRE/IPSEC back up to MPLS VPN. Lots of service providers have managed service that does this for you. With modern hardware, fragmentation shouldn't be a big deal. Most providers have end to end jumbo frame so just need to be mindful of who does and who don't. Good luck.

Re: [c-nsp] XRv (xr on a server)

2013-10-03 Thread Luan Nguyen
Seriously doubt that it would be free. On Thu, Oct 3, 2013 at 11:02 AM, Jason Lixfeld wrote: > This should be free. > > On 2013-10-03, at 10:55 AM, Oliver Garraux wrote: > > > I will be really really interested to see what they do pricing wise on > > VIRL. Hope its nothing crazy, I would love

Re: [c-nsp] XRv (xr on a server)

2013-10-03 Thread Luan Nguyen
Did someone get a chance to download whatever under XRv? it's "page not available" currently. If i remember correctly, my SE said you have to pay for it. Beta is going right now and the list is long i was told. You have a better chance of getting it from being leaked out then get on the beta. Was

Re: [c-nsp] asr1001 4 full bgp feed

2013-08-01 Thread Luan Nguyen
Do you know if you can do IPSEC with that as well? Or you would need additional $10K IPSEC license? Can it also do limited NAT? If so, what is the number before you add the 2M license? Can you run 1 RP2 with XE while the other IOS? Assuming they do have IOS for ASR and features compatible (bug cras

[c-nsp] Bad console port - Cisco ASA 5540

2013-05-15 Thread Luan Nguyen
Hi folks, I have a couple of ASA 5540s that I couldn't console into: the cursor just blinks. I tried all the baud rates listed but still no joy. These, I won't be able to RMA them. Any tricks to get the console to work? Thanks in advance. Regards, -lmn __

Re: [c-nsp] Sup2T rate limit

2013-04-25 Thread Luan Nguyen
gt; From: cisco-nsp [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of > Luan Nguyen > Sent: Sunday, April 21, 2013 10:04 AM > To: cisco-nsp@puck.nether.net > Subject: [c-nsp] Sup2T rate limit > > Hi folks, > > From what I've been reading, I could do the followi

[c-nsp] Sup2T rate limit

2013-04-21 Thread Luan Nguyen
Hi folks, >From what I've been reading, I could do the following to rate limit a vlan to 100M class-map match-all rate match any policy-map rate class rate police 1 3200 conform transmit exceed drop int vlan99 service-policy input rate But show policy-map interface vlan99 detail doesn't

Re: [c-nsp] GRE tunnel over Internet

2012-12-06 Thread Luan Nguyen
People run all sorts of routing protocols over the IPSEC/GRE tunnel successfully (yeah, IPSEC to be more secure)...must be some configuration errors then... r/g -lmn On Thu, Dec 6, 2012 at 12:46 PM, Chris Lane wrote: > We are working on setting up a test where we run a GRE tunnel across the >

Re: [c-nsp] FDDI card for 7200 VXR

2010-10-28 Thread Luan Nguyen
On Thu, Oct 28, 2010 at 3:19 PM, Justin M. Streiner wrote: > On Thu, 28 Oct 2010, Luan Nguyen wrote: > > I guess I have to look into buying a 7200 as well. >> > > Not knowing your situation or needs, would it make more sense to replace > the FDDI gear with something t

Re: [c-nsp] FDDI card for 7200 VXR

2010-10-28 Thread Luan Nguyen
Thanks guys. I guess I have to look into buying a 7200 as well. Regards, -Luan On Thu, Oct 28, 2010 at 2:25 PM, Mikael Abrahamsson wrote: > On Thu, 28 Oct 2010, Luan Nguyen wrote: > > Hi folks, >> >> Anyone has a FDDI PA VIP2 card for the 7200VXR series router that I ca

[c-nsp] FDDI card for 7200 VXR

2010-10-28 Thread Luan Nguyen
Hi folks, Anyone has a FDDI PA VIP2 card for the 7200VXR series router that I can buy? Thanks. -Luan ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/c

Re: [c-nsp] Network mapping...again

2010-08-12 Thread Luan Nguyen
If money is not an issue, then I would suggest OPNET NetMapper. We had them come in and did a demo. We like it. Regards, -lmn -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of John Neiberger Sent: Thursday, August 12, 2010

Re: [c-nsp] Mysterious tunnel interfaces

2010-08-12 Thread Luan Nguyen
I have those ISR2 (M1) as well as ASR1002 running DMVPN and don't have those ghost tunnels. Must be for some other services such as multicast. Try to remove them with no interface tunnel 0, and I think the router will tell you why you couldn't. Regards, -Luan -Original Message- From: ci

Re: [c-nsp] Zone Based Firewall default-class

2010-07-09 Thread Luan Nguyen
Maybe class-default only allow traffic initiate from the zone and not return traffic? Check your log again... Try your "Or", and try upgrade to T3 see if that makes a different. -- Luan Nguyen Chesapeake NetCraf

Re: [c-nsp] Redistributing External EIGRP routes through MPLS vpn

2010-05-18 Thread Luan Nguyen
EIGRP configuration to see if you have thing like eigrp stub connected :) - Luan Nguyen Chesapeake NetCraftsmen, LLC. - -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Beha

Re: [c-nsp] DMVPN scalability question on the 28XX ISR's

2010-04-21 Thread Luan Nguyen
ezp.ods.org] Sent: Wednesday, April 21, 2010 2:04 PM To: Luan Nguyen; 'Engelhard'; rod...@cisco.com; Erik Witkop Cc: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] DMVPN scalability question on the 28XX ISR's On Wed, 21 Apr 2010 06:35:37 -0700, Luan Nguyen wrote: > In this case, a

Re: [c-nsp] DMVPN scalability question on the 28XX ISR's

2010-04-21 Thread Luan Nguyen
Like someone else said, if you don't have to run dynamic routing protocol, then ODR or static would do wonder. In this case, a dual hub (loadshare/backup) for 1000+ spokes would be just fine. With EIGRP, you could safely do 500+ spokes per ASR. A few years back, either Cisco did some tests and fo

Re: [c-nsp] Remote Parking Gates VPN to Campus Network with 3G

2010-04-13 Thread Luan Nguyen
oud. 30 CPEs DMVPN shouldn't be a concern provisioning/managing wise. ------- Luan Nguyen Chesapeake NetCraftsmen, LLC. - -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net]

Re: [c-nsp] cost community alternatives

2010-04-12 Thread Luan Nguyen
Try using the offset list command. Regards, - Luan Nguyen Chesapeake NetCraftsmen, LLC. -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Pan

Re: [c-nsp] Cisco 3750 High CPU

2010-04-07 Thread Luan Nguyen
This link should provide some guidance regarding HULC running process. http://www.cisco.com/en/US/products/hw/switches/ps5023/products_tech_note091 86a00807213f5.shtml -Luan -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf O

Re: [c-nsp] VAM2+ Performance

2010-03-17 Thread Luan Nguyen
/IPSEC with ~90%CPU The VSA has much better performance BTW. Regards, - Luan Nguyen Chesapeake NetCraftsmen, LLC. - -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf

Re: [c-nsp] MPLS VPN Running BGP w/ failover IPSec VPN Over Internet

2010-01-26 Thread Luan Nguyen
t net file. - Luan Nguyen Chesapeake NetCraftsmen, LLC. [Web] http://www.netcraftsmen.net [AIM/YIM/GTalk] luancnc - -Original Message- From: Jason LeBlanc [mailto:jasonlebl...@gmail.com] Sent: Tuesday, January 26, 2010 7:48 PM To: Luan Nguyen

Re: [c-nsp] MPLS VPN Running BGP w/ failover IPSec VPN Over Internet

2010-01-26 Thread Luan Nguyen
.etc. With GNS3/Dynagen, you could probably test this whole thing out in your labtop. ------- Luan Nguyen Chesapeake NetCraftsmen, LLC. [Web] http://www.netcraftsmen.net --- -Original Message- From: cisco-nsp-boun...@

Re: [c-nsp] Cisco NAC - SSO Issues

2009-09-15 Thread Luan Nguyen
I would suggest opening a TAC case. Also, for NAC related problem, the cleanacc...@listserv.muohio.edu would be a better place to ask questions. Regards, -- Luan Nguyen Chesapeake NetCraftsmen, LLC. [Web] http://www.netcraftsmen.net

Re: [c-nsp] NAT Global to FVRF

2009-08-20 Thread Luan Nguyen
I think the problem is because your VRF Red doesn't have route to the LAN. If [LAN] is switch, then you could try to create a route in VRF Red for the LAN network with the next hop is the IP address of the switch. Regards, Luan Nguyen Chesapeake NetCraftsmen

Re: [c-nsp] OT: Internet Web Caching Solution

2009-08-13 Thread Luan Nguyen
remote site and the Internet, or as a push client receiving content from a central site. Hope that help. Regards, -- Luan Nguyen Chesapeake NetCraftsmen, LLC. http://www.netcraftsmen.net - -Original Message- From: cisco-nsp

Re: [c-nsp] Route redistribution and selection

2009-08-13 Thread Luan Nguyen
You might want to check this link out: http://wiki.nil.com/Multihomed_MPLS_VPN_sites_running_EIGRP Regards, --- Luan Nguyen Chesapeake NetCraftsmen, LLC. http://www.netcraftsmen.net -- -Original Message- From: cisco-nsp-boun

Re: [c-nsp] GRE/NAT ?

2009-07-31 Thread Luan Nguyen
So you are talking about NAT after GRE? You certainly could NAT and then GRE-encapsulated the NATTED traffic? Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. http://www.netcraftsmen.net -Original Message- From

Re: [c-nsp] GRE/NAT ?

2009-07-31 Thread Luan Nguyen
No? I remember doing overlapping RFC1918 sites for GRE/IPSEC VPN. Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. http://www.netcraftsmen.net --- -Original Message- From: cisco-nsp-boun...@puck.nether.net

Re: [c-nsp] DMVPN and OSPF

2009-07-30 Thread Luan Nguyen
, --- Luan Nguyen Chesapeake NetCraftsmen, LLC. http://www.netcraftsmen.net -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Jay Nakamura Sent: Thursday, July 30, 2009 1:55 PM

Re: [c-nsp] 7206VXRG2 performance question

2009-07-28 Thread Luan Nguyen
DMVPN/EIGRP. You could do direct spoke-spoke communication as well. Regards, - Luan Nguyen Chesapeake NetCraftsmen, LLC. http://www.netcraftsmen.net -Original Message- From: cisco-nsp-boun...@puck.nether.net

Re: [c-nsp] ASA Static Translations / DNS Doctoring

2009-07-17 Thread Luan Nguyen
Very creative use of secondary addresses! :) Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. http://www.netcraftsmen.net -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun

Re: [c-nsp] ASA Static Translations / DNS Doctoring

2009-07-17 Thread Luan Nguyen
, --- Luan Nguyen Chesapeake NetCraftsmen, LLC. http://www.netcraftsmen.net - -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Clue Store Sent: Friday, July 17, 2009 12:47 PM To: cisco-nsp

Re: [c-nsp] Global Route Leaking on same PE

2009-06-16 Thread Luan Nguyen
You could also use a GRE tunnel for the connection as well. Jeff is right that this topic keeps coming up every so often. I wonder why Cisco won't just make this easier for people. -- Luan Nguyen Chesapeake NetCraftsmen, LLC.

Re: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T

2009-04-15 Thread Luan Nguyen
300 ip route 0.0.0.0 0.0.0.0 y.y.y.y 250 ! HTH. Regards, - Luan Nguyen Chesapeake NetCraftsmen, LLC. [Web] http://www.netcraftsmen.net

Re: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T

2009-04-15 Thread Luan Nguyen
You could put Fa0 into a VLAN and use that for the cable modem connection. There's no option for "no switchport" and turn it into a layer 3 interface. Regards, ----- Luan Nguyen Chesapeake NetCraft

Re: [c-nsp] cisco AnyConnect - cisco 877

2009-03-18 Thread Luan Nguyen
There's a configuration guide here: http://www.cisco.com/en/US/products/ps6496/products_configuration_example091 86a0080720346.shtml According to, 877 should be supported. Regards, - Luan Nguyen Chesa

Re: [c-nsp] 7206 NON VXR

2009-03-17 Thread Luan Nguyen
NPE-225 I think is the max you could go. Regards, - Luan Nguyen Chesapeake NetCraftsmen, LLC. [Web] http://www.netcraftsmen.net

Re: [c-nsp] GET-VPN and BGP

2009-02-27 Thread Luan Nguyen
f the customer already used GRE/IPSEC, then in my opinion, it's easier to migrate into DMVPN than GET-VPN. Regards, - Luan Nguyen Chesapeake NetCraftsmen, LLC. [Web] http://www.netcraftsmen.net [Blog]

Re: [c-nsp] VRF and STATIC ROUTE to GLOBAL

2009-02-23 Thread Luan Nguyen
gards, Luan Nguyen Chesapeake NetCraftsmen, LLC. [Web] http://www.netcraftsmen.net [Blog] http://cnc-networksecurity.blogspot.com/ [Mobile] 703-953-9116 + -Original Message- From: cisco-nsp-boun...@puck.nethe

[c-nsp] AIM-SSL-3 card on 2811

2009-01-21 Thread Luan Nguyen
Hi folks, Anyone tried the SSL-3 VPN encryption card on a 2800 series before? Thanks. Luan Nguyen Chesapeake NetCraftsmen, LLC. [W] http://www.netcraftsmen.net <http://www.netcraftsmen.net/> [M] l...@netcraftsmen.net [Blog] http://cnc-networksecurity.blogsp

Re: [c-nsp] Acceptance Test Procedure for New Cisco Devices

2009-01-20 Thread Luan Nguyen
Going a bit further...how's about looking at those benchmarking RFCs http://www.ietf.org/html.charters/bmwg-charter.html In particular http://www.ietf.org/rfc/rfc2544.txt for the 1861 and http://www.ietf.org/rfc/rfc3511.txt for the ASA Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. [W]

Re: [c-nsp] Forcing dhcp lease renewal

2009-01-16 Thread Luan Nguyen
Things point to Cradlepoint don't they? I've used Digi ConnectPort with lots of success. Or go with the 3G-Wireless HWIC card or ask VzW for a static IP address. The last thing would be to use object tracking in conjunction with EEM to solve your problem. Regards, Luan Nguyen

Re: [c-nsp] site-to-site vpn, ipsec-gre, 2811/HSEC

2009-01-07 Thread Luan Nguyen
Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. [W] http://www.netcraftsmen.net [M] l...@netcraftsmen.net [Blog] http://cnc-networksecurity.blogspot.com/ -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Mark Kent Sent:

Re: [c-nsp] Cisco Software Client -> Router VPN issue.

2009-01-05 Thread Luan Nguyen
Uhm, that's split-tunneling. If you want to use internet at the router site then follow this guide: http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_configuration _example09186a008073b06b.shtml Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. [W] http://www.netcraftsmen.net

Re: [c-nsp] Cisco Software Client -> Router VPN issue.

2009-01-05 Thread Luan Nguyen
Create ACL 101 permit 10.0.0.0 0.0.0.255 any Then under the " crypto isakmp client configuration group SomeVPN" Add "ACL 101" Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. [W] http://www.netcraftsmen.net [M] l...@netcraftsmen.net [Blog] http://cnc-networks

Re: [c-nsp] HWIC-4T1/E1

2008-12-19 Thread Luan Nguyen
, but it looks like any other serial T1/E1 interfaces. Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: cisco-nsp-boun...@puck.nether.net [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of Justin Shore Sent: Friday, December 19, 2008

Re: [c-nsp] MPLS-VPN migration

2008-12-17 Thread Luan Nguyen
ork [tunnel interface ip network] area 0 ! router bgp 65535 address-family ipv4 vrf CUSTOMER1 redistribute ospf 1 vrf CUSTOMER1 route-map redis-ospf-to-bgp-vrf Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: Tim Durack [mailto:t

Re: [c-nsp] MPLS-VPN migration

2008-12-17 Thread Luan Nguyen
destination x.x.x.x If you have a lot of customers (a lot of VRFs), then maybe try DMVPN configuration with the global being the hub and each spokes in their own unique VRF...just a thought :) Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From

Re: [c-nsp] Rate limiting but on packet count not bandwidth

2008-12-17 Thread Luan Nguyen
Maybe give storm-control with pps keyword a try. http://www.cisco.com/en/US/docs/switches/lan/catalyst3550/software/release/1 2.2_25_see/configuration/guide/swtrafc.html#wp1241484 Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: cisco-nsp

Re: [c-nsp] 32 bit ASN

2008-12-17 Thread Luan Nguyen
Here's an old post on this topic: http://puck.nether.net/pipermail/cisco-nsp/2008-August/053334.html Also, I heard it's going to be implemented beginning 12.5T Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: cisc

Re: [c-nsp] DMVPN - HUB VRF Aware - Spokes no VRFs

2008-11-17 Thread Luan Nguyen
you have a few customers and want to consolidate them into a single hub router, then I would just add the tunnels into their own VRFs, the spokes can be left alone. Depends on the routing protocol you use, and what access you want to give, you need to route inter/intra VRFs accordingly at the hub.

Re: [c-nsp] VSS SRND

2008-11-17 Thread Luan Nguyen
/docs/solutions/Enterprise/Data_Center/DC_Infra2_5 /DCI_SRND.pdf Which give lots of design guides on VSS. Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Pavel Skovajsa Sent: M

Re: [c-nsp] PIX 6.x Site2Site with dynamic IP?

2008-11-06 Thread Luan Nguyen
Just change your A end to use dynamic map. http://www.cisco.com/en/US/products/sw/secursw/ps2308/products_configuration _example09186a0080094680.shtml Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

Re: [c-nsp] Cisco 881 3G Router Experiences

2008-11-06 Thread Luan Nguyen
IPSEC tunnel mode without DMVPN as well, just make sure the other side configured for dynamic crypto map. Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Thu

Re: [c-nsp] BGP Question

2008-11-06 Thread Luan Nguyen
Neighbor allowas-in Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Stephens, Jamie A Sent: Thursday, November 06, 2008 9:18 AM To: cisco-nsp Subject: [c-nsp] BGP Question Is there a

Re: [c-nsp] ipsec over gre with nhrp

2008-11-05 Thread Luan Nguyen
-aes 256 esp-sha-hmac mode transport ! crypto ipsec profile foo set transform-set TEST set pfs group5 ! Int tun202 No crypto map tunnel protection ipsec profile foo Then route over the tunnel accordingly...intstead of using ACL to match traffic. Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC

Re: [c-nsp] IPSec Remote Access VPN getting Addresses from the DHCP

2008-11-05 Thread Luan Nguyen
Maybe try using the global commands no vpn-addr-assign local no vpn-addr-assign aaa vpn-addr-assign dhcp And under tunnel-group COMPANY-TUNNEL-GROUP general-attributes Add: default-group-policy COMPANY-REMOTE-ACCESS Regards, Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net

Re: [c-nsp] HWIC-3G-* experience?

2008-11-04 Thread Luan Nguyen
it's directly from the MPLS cloud, they still have to route around and around in their networks since Internet and MPLS are from Verizon Business. Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

Re: [c-nsp] Order-of-operations question about "adjust-mss" and crypto...

2008-10-31 Thread Luan Nguyen
ww.cisco.com/en/US/tech/tk827/tk369/technologies_white_paper09186a00 800d6979.shtml#t3 Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net (blog) http://ccie-security.blogspot.com/ (e) [EMAIL PROTECTED] (aim/yahoo): luancnc -Original Message- From: [EMAIL PROTECTED]

Re: [c-nsp] ctr+break sequence and Cisco 3500

2008-10-28 Thread Luan Nguyen
http://www.cisco.com/en/US/products/hw/switches/ps628/products_password_reco very09186a0080094184.shtml Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net (e) [EMAIL PROTECTED] (aim/yahoo): luancnc -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On

Re: [c-nsp] ACL's on policy-map - No hits?

2008-10-17 Thread Luan Nguyen
software/releas e/12.2_37_se/release/notes/OL12616.html Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Thursday, October 16, 2008 8:38 PM To: cisco-nsp@puck.nether.

Re: [c-nsp] OK, what is a cheap and dirty hack to test a port

2008-10-15 Thread Luan Nguyen
-Original Message- From: Ted Mittelstaedt [mailto:[EMAIL PROTECTED] Sent: Wednesday, October 15, 2008 12:01 PM To: Luan Nguyen; cisco-nsp@puck.nether.net Subject: RE: [c-nsp] OK, what is a cheap and dirty hack to test a port > -Original Message- > From: Luan Nguyen [

Re: [c-nsp] OK, what is a cheap and dirty hack to test a port

2008-10-15 Thread Luan Nguyen
they are cross connected by the DACS at the central office. Verizon said they have to be in sync. Something must have happen for them to be out of sync after all these years. Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: Paul G. Timmins [mailto:[

Re: [c-nsp] OK, what is a cheap and dirty hack to test a port

2008-10-15 Thread Luan Nguyen
they break in the circuit for testing. Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Lamar Owen Sent: Wednesday, October 15, 2008 10:37 AM To: cisco-nsp@puck.nether.net Subject: Re: [c-nsp] OK,

Re: [c-nsp] OK, what is a cheap and dirty hack to test a port

2008-10-15 Thread Luan Nguyen
It's on fiber. I asked if we could get network timing from them, but they said no, not on this type of circuit. Also, this circuit has been working for years with the same setting :) Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [

Re: [c-nsp] OK, what is a cheap and dirty hack to test a port

2008-10-15 Thread Luan Nguyen
out the rate of your line. They swapped one smart jack, but that didn't help, so they will swap the other today. Hopefully that will do it. Good information here about troubleshooting T1 http://www.informit.com/library/content.aspx?b=Troubleshooting_Remote_Access &seqNum=61 Luan N

Re: [c-nsp] Fwd: NAT in VRF

2008-10-09 Thread Luan Nguyen
Yes you can. I used to do that with 2 VRF-Lites on 2 DMVPN tunnels. Platform doesn't make any different. Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gary Roberton Sent: Thu

Re: [c-nsp] MPLS and IPSEC co-working (reviving an old thread)

2008-10-05 Thread Luan Nguyen
s6537/ps6586/ps6635/ps7 180/product_data_sheet0900aecd80582067.html. The CE-to-CE routing remains the same, with added security. - Luan Nguyen Chesa

Re: [c-nsp] Propagating a default route...

2008-09-30 Thread Luan Nguyen
Perhaps set a static route for xx.xx.xx.xx (where you get your default route) in your server? - Luan Nguyen Senior Network Engineer Mobile: 703-953

Re: [c-nsp] SA-VAM2+ usage problem?

2008-09-30 Thread Luan Nguyen
0% CPU :) Luan --------- Luan Nguyen Senior Network Engineer Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net - -Original Message---

Re: [c-nsp] IP-VPN CE-PE local pref problem

2008-09-30 Thread Luan Nguyen
- Luan Nguyen Senior Network Engineer Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net

Re: [c-nsp] SA-VAM2+ usage problem?

2008-09-30 Thread Luan Nguyen
. - Luan Nguyen Senior Network Engineer Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net

Re: [c-nsp] Debugging Cisco VPN Client Software ... Is it even possible ?

2008-09-23 Thread Luan Nguyen
- Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL

Re: [c-nsp] GRE over IPSec

2008-09-19 Thread Luan Nguyen
the ASA address and z.z.z.z is your router behind it. -Luan - Luan Nguyen Chesapeake NetCraftsmen, LLC. www.NetCraftsmen.net

Re: [c-nsp] Cisco NAC

2008-09-16 Thread Luan Nguyen
First try Cisco: http://www.cisco.com/en/US/products/ps6128/tsd_products_support_series_home. html http://cisconac.blogspot.com/ One of my coworker's blog - he's excellent with NAC deployment. http://cnc-networksecurity.blogspot.com/ Mailing list: http://listserv.muohio.edu/scripts/wa.exe?A0=cl

Re: [c-nsp] Using CA certificates and pre-shared keys on the same box

2008-09-10 Thread Luan Nguyen
You could try to configure 2 ISAKMP profiles: one use CA, one use pre-shared. Then configure 2 IPSEC profiles accordingly. -Luan -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Wednesday, September 10, 2008 10:07 AM To: cisco-ns

[c-nsp] Advertising NAT pool using OSPF on the ASA

2008-06-12 Thread Luan Nguyen
Hello, According to this document: http://www.cisco.com/en/US/docs/security/asa/asa72/configuration/guide/cfgna t.html#wp1042725 If you NAT to a pool of address, then this pool of address will be advertise to the upstream router automatically. I have the set up: Router5---outside-ASA-in

[c-nsp] Analog Dial backup AND dialin management using the same external modem

2008-06-11 Thread Luan Nguyen
Hello, Anyone using an analog modem connected to an AUX port for dial backup? In case your T1 primary link fails? The hard part is: Can you use that modem for dialin to manage your router when not using the Dial backup? Thanks. Luan Nguyen http

Re: [c-nsp] asa ipsec problem

2008-06-04 Thread Luan Nguyen
I have 7.2.2 and using your config along with http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805e8c80.shtml everything is working fine for me. -lmn P.S It's nice to see Peter ventures down CPE lane :) On Tue, Jun 3, 2008 at 6:49 AM, Sergey Alexanov

Re: [c-nsp] ACL making me insane

2008-06-03 Thread Luan Nguyen
Enno Rey <[EMAIL PROTECTED]> wrote: > Hi, > > On Tue, Jun 03, 2008 at 01:37:30PM -0400, Luan Nguyen wrote: > > The problem is when someone contacted your protectedserver, you need to > > allow the counter flow of that. > > For example, you need to have: permit t

Re: [c-nsp] ACL making me insane

2008-06-03 Thread Luan Nguyen
The problem is when someone contacted your protectedserver, you need to allow the counter flow of that. For example, you need to have: permit tcp host PROTECTEDSERVER eq 80 any gt 1024 so that the web counter flow will work (counter flow of this line: permit tcp any host PROTECTEDSERVER eq 80) -

Re: [c-nsp] EIGRP vs BGP route selection

2008-05-22 Thread Luan Nguyen
You have to have EIGRP redistribute into BGP as well? Once in the BGP table, local redistribute routes will have a weight of 32768 which will be prefered over the EBGP weight of 0. I remember reading over at the Netpro forum and someone said that it's a racing condition: EIGRP converge faster and

Re: [c-nsp] 2801 bandwidth limiting

2008-04-24 Thread Luan Nguyen
I would say you need to use CBWFQ for this. Create an ACL match everything or whatever interested you out of your network and assigned to a class-map, then create a policy map policy-map out class out bandwidth 10M shape peak 13M interface WAN service out out -lmn On Thu, Apr 24, 2008 at 6:48 PM,

Re: [c-nsp] BGP with yourself...

2008-04-24 Thread Luan Nguyen
Very interesting. I have a problem with having an ethernet in global doing NAT over a VRF, and the vrf doesn't know how to get to the ethernet LAN segment in the global. I was thinking of just doing:" ip route vrf whatever 1.1.1.0 255.255.255.0 3.3.3.3 global, where 3.3.3.3 is just some bogus none

Re: [c-nsp] BFD state remains in "AdminDown"

2008-02-27 Thread Luan Nguyen
Don't think that 12.4.15T3 has VRF support for BFD. Maybe try 12.2.33SRC (depends on what kind of routers you have) I had a configuration like that and didn't work for me. Mine isn't a PE-CE kind so didn't bother with SRC code. -lmn On Wed, Feb 27, 2008 at 11:34 PM, Stephen Fulton <[EMAIL PROTECT

Re: [c-nsp] What is "pv" in "show ip arp"?

2008-02-21 Thread Luan Nguyen
My guess would be "private-vlan" Can you do a "show vlan private-vlan" and see? -lmn On Thu, Feb 21, 2008 at 10:30 AM, Christian Bering <[EMAIL PROTECTED]> wrote: > Hi all, > > When a "show ip arp" shows the following: > > Protocol Address Age (min) Hardware Addr Type Interface >

Re: [c-nsp] redundant VPNs

2008-02-20 Thread Luan Nguyen
1800/2800 should have no problem handling T1 VPN. Use AIM-SSL1/SSL2 encryption cards for them. Tag on Zone-base FW and IOS IPS and your customer should feel "safe" :) -lmn On Feb 20, 2008 11:48 AM, Adam Greene <[EMAIL PROTECTED]> wrote: > Hi, > > A customer of ours has two sites, one with an 1

[c-nsp] EtherChannel support on Onboard Gigabit Ethernet ports of 3800 series?

2008-02-19 Thread Luan Nguyen
Hello, Has anyone successfully used port-channel on a 3800 series router before? I could configure it, and it seems to be okay. I haven't try to see if it actually load-share traffics, but a simple ping test /shutdown one interface works fine. But according to Cisco, this is not supported? htt

  1   2   >