Re: [c-nsp] 6509/SUP720-3BXL with Enhanced FlexWAN issue.. Anyideas?

2011-07-10 Thread Robert VanOrmer
Could be the following: CSCec17803 Symptom: After inserting a FlexWAN module in a Supervisor 720 system and saving the config, the the FlexWAN config is lost on next reload. Conditions: The problem is seen with Cat6k-Sup720/RP running 12.2(14r)S9 rommon version. Workaround: After saving the conf

Re: [c-nsp] Constant output drops on etherchannel

2011-01-14 Thread Robert VanOrmer
I am experiencing a very similar issue on the C3750E platform w/ 12.2(52)SE. We have 5 switches in a cluster, port-channeled with (2) Gig interfaces L2 to distro (6500's) with excessive output drops even at low utilization. No QoS enabled. I am using the Cisco TwinGig Converter Modules for uplink

Re: [c-nsp] Good way of finding unauthorized network elements/

2009-10-30 Thread Robert VanOrmer
This may be out of your budget, but the Cisco WLCs + WCS do a great job of this. WCS will identify rogue access points and also identify if the AP is "on-net" or just rogue. It also has a containment feature that works very effectively in quarantining APs and making them difficult / impossible to

Re: [c-nsp] Disabling ssh v1 on IOS

2009-08-10 Thread Robert VanOrmer
>Date: Mon, 10 Aug 2009 21:47:40 +0100 >From: Alan Buxey >To: Robert VanOrmer >Cc: cisco-nsp@puck.nether.net >Subject: Re: [c-nsp] Disabling ssh v1 on IOS >Message-ID: <20090810204740.gb16...@lboro.ac.uk> >Content-Type: text/plain; charset=us-ascii > &g

[c-nsp] Disabling ssh v1 on IOS

2009-08-10 Thread Robert VanOrmer
Anyone know of a way to disable an IOS device 12.2(18)SXF15a in test) from accepting SSH v1 connections and maintaining SSH v2 sessions? I want to be able to connect to the device, but with SSHv2 only. I haven't found any option for this. ___ cisco-nsp

Re: [c-nsp] Humor: Cisco announces end of BGP

2009-07-29 Thread Robert VanOrmer
Verizon: IPv6! We do have a IPv6 transport from Verizon, granted. (1) good luck globally routing your /48 outside of VZB land, they won't do it unless your providing a /32, and if you have been delegated any address space from an RIR, (2) good luck getting delegated addressing from Verizon's ch

[c-nsp] Qos on IPSec + GRE tunnel with sup720-3bxl

2009-06-15 Thread Robert VanOrmer
I am having an interesting challenge in getting a QoS policy that is supported / works across a IPSec + GRE tunnel running 12.2(18)SXF (Sup720-3bxl, ws-svc-ipsec-1, flexwan with DS3). I am not trying to do anything overly complex.. really just want to make sure RTP or EF tagged frames make it, and