Re: [c-nsp] Cisco working as PPPoE Server

2016-08-15 Thread Sam Silvester
On Tue, Aug 16, 2016 at 4:38 AM, James Bensley wrote: > I would say ASR9001, try to avoid ASR1000 series for this if you can. > > Hi James, What makes you say that? I've had good success over the years with the ASR1k series for PPP (L2TP and PPPoE) termination so interested in any perceived adva

Re: [c-nsp] trouble with link aggregation on WS-X6716-10GE

2016-03-09 Thread Sam Thomas via cisco-nsp
--- Begin Message --- The command you're looking for is no mls qos channel-consistency on your port-channel interface. istr you will need to remove/re-add the interface in "A" port-channel. On Wednesday, March 9, 2016 10:00 AM, Nick Cutting wrote: I have seen this before on a 6500 Hav

Re: [c-nsp] Cisco 7201 (G2) Traffic Performance (High CPU Utilization)

2014-10-15 Thread Sam Silvester
As with others, it's been a while since I've worked on this platform (we were running 12.2SR train generally). Having said that, I agree that for some reason the 7201 did show higher CPU for the same traffic level as other platforms - but as mentioned we found it levelled off with increasing traff

Re: [c-nsp] ASR 1002-X as LNS

2014-10-14 Thread Sam Silvester
Speaking for my own experience, it wasn't a problem. From memory we had to change one RADIUS attribute we were using for shaping I believe (we were using an older attribute that caused a full VAI to be created, updating that fixed it). We don't do PBR however. One thing I would suggest however - i

Re: [c-nsp] Does "backup interface" gratuitous ARP?

2014-08-13 Thread Sam Stickland
Hello again, Thinking about this, if you've used overlapping IPv4 addresses with "backup interface" it must had sent a gratuitous ARP. Otherwise you would had experienced quite the network outage waiting for the neighbors device ARP entry to timeout, no? Sam On Wed, Aug 13,

Re: [c-nsp] Does "backup interface" gratuitous ARP?

2014-08-13 Thread Sam Stickland
Hi, On Wed, Aug 13, 2014 at 6:14 PM, Gert Doering wrote: > Hi, > > On Wed, Aug 13, 2014 at 04:44:49PM +0100, Sam Stickland wrote: > > I'm exploring redundancy possibilities for a router hand off without a > > dynamic routing protocol. It's ugly and I'm not

[c-nsp] Does "backup interface" gratuitous ARP?

2014-08-13 Thread Sam Stickland
. I don't have test hardware to hand and I can't simulate this in GNS because ethernet interfaces are permanently up in dynamips. Regards, Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/list

Re: [c-nsp] TACACS+ exec authorisation no working on Cisco 2960CG

2014-07-30 Thread Sam Stickland
I prefer being able to see the commands via "sh log" rather than have to go digging around a TACACS server :) Sam On Wed, Jul 30, 2014 at 4:30 PM, Javier Henderson (javier) wrote: > You already got some good advice on this, I’d like to add a couple of > comments. > > S

[c-nsp] TACACS+ exec authorisation no working on Cisco 2960CG

2014-07-30 Thread Sam Stickland
792887694): status = GETPASS 002068: *Mar 1 01:22:19.291 UTC: AAA/AUTHEN/CONT (3792887694): Method=ENABLE 002069: *Mar 1 01:22:19.306 UTC: AAA/AUTHEN (3792887694): status = PASS 002070: *Mar 1 01:22:19.306 UTC: AAA/MEMORY: free_user (0x3D24224) user='NULL' ruser='

[c-nsp] Something for the weekend - a comedy film about networking...

2013-05-10 Thread Sam Stickland
I think some of you might get enjoyment out of this... After four and a half years and around 5,000 man hours we finally finished our feature film comedy about networking. If nothing else I think this must be the only film in existence that has eight CCIEs in the cast and a song about EIGRP :) I'

Re: [c-nsp] Sup2T - poor netflow performance

2013-03-27 Thread Sam
tflow and NDE limits (to be honest the limits never dropped a single export so far). -- sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Sup2T - poor netflow performance

2013-03-26 Thread Sam
ocess will yield, or pause, the export process by reducing or even cutting off NDE. When CPU utilization is reduced, NDE gradually returns to a normal level. ( http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/white_paper_c11-652021.html ) You might also want to sample. -- sam O

[c-nsp] Need help with leaking routes from the "main table" to vrf tables

2012-07-12 Thread Sam
erver Thanks Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] 7600 w/ WS-SUP720-3B IOS 15.x

2012-06-28 Thread sam-ml
You should use 15.1(3)S as it has extended support. We run it on a number of devices with no issues so far. -- sam > 15.1s should be fine. > > Sent from my HTC One™ X > > - Reply message - > From: "Xu Hu" > To: "N. Max Pierson" > Cc: "C

Re: [c-nsp] ASR9K limitations

2012-06-28 Thread Sam Silvester
es, apart from wishing IOS-XR ran on more things (7600s anybody?) Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] Help with ACL Rule

2012-05-19 Thread Sam
more then 1 access-list to an interface Access-list 101 in Access-list 102 in Etc So I can share acl 102 on multiple interfaces Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp

Re: [c-nsp] ASR1004 slot/backplane/capacity question

2012-05-08 Thread Sam Silvester
On Wed, May 9, 2012 at 6:26 AM, David H wrote: > Hi all, I've got a few general questions about the ASR.  On Cisco's > site sometimes I see reference to the 1004 having a 20 gig capacity, > other times 40.  Will the 1004 accept the ESP-40 and SIP40 interface > cards to get to 40 gigs or is the max

Re: [c-nsp] Cisco CSS 11501 Load Balancers

2011-05-31 Thread Sam Hall
Hi there Can anyone help on the below questions? Thanks a million Sam The Logic Group Enterprises Limited. Logic House, Waterfront Business Park, Fleet Road, Fleet, Hampshire, GU51 3SB, United Kingdom. Registered in England. Registered No. 2609323 The information in this email and any

[c-nsp] Cisco CSS 11501 Load Balancers

2011-05-27 Thread Sam Hall
URL 3. IP address, protocol, port, URL 4. IP address, protocol, port 5. IP address, protocol 6. IP address 7. Protocol, port, URL 8. Protocol, port * Protocol Sam Hall Senior Network Engineer direct +44 (0)1252 644 287 email sam.h...@the-logic-group.com<mailto:fsam.h...@the-logic-group.com&g

[c-nsp] Regular Expression Load Balancing

2011-03-10 Thread Sam Hall
ollowing: * xml * soap * iso8583 * obs * apacs Any ideas would be very helpful, if the CSS isn't up for the job, any other load balancers suggestions would be welcome... Thanks in advance Sam Hall Senior Network Engineer direct +44 (0)1252 644 287 email sam.h...@the-logi

Re: [c-nsp] 6500 IGMP snooping database now bound to MAC address and not switchport?

2011-02-09 Thread Sam Stickland
Hi Ben, We aren't using port-channels towards the servers. However, I've just seen another issue on a 3560 where IGMP joins/reports aren't replicated to the SPAN session. This has got me wondering if the server was reissuing the join all along but I simply failed to capture it.

Re: [c-nsp] 6500 IGMP snooping database now bound to MAC address and not switchport?

2011-02-09 Thread Sam Stickland
On 9 Feb 2011, at 17:51, Phil Mayers wrote: > On 09/02/11 16:57, Sam Stickland wrote: >> All, >> >> I encountered some strange, but beneficial, behaviour in the lab. We >> connected a server with teamed NICs to two 6500s running SXH2a. The >> NIC teaming is a

[c-nsp] 6500 IGMP snooping database now bound to MAC address and not switchport?

2011-02-09 Thread Sam Stickland
x27;t find this documented anywhere, so I'd hate to rely on this behaviour. Has anyone else heard of this? Regards, Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://

Re: [c-nsp] PVLAN Question

2011-01-12 Thread Sam Evans
end with access vlan 141 to be promisc port. So you have to use a > loopback cable and two ports. Foundry/Brocade is the same way too. > > Schilling > > On Tue, Jan 11, 2011 at 7:57 PM, Sam Evans wrote: > > All, > > > > I am trying to do a PVLAN implementation

[c-nsp] PVLAN Question

2011-01-11 Thread Sam Evans
All, I am trying to do a PVLAN implementation on one switch in a distribution / access switch environment. Ideally, I'd like to just be able to use the 'isolated' command but we have a few devices that will need to talk to port neighbors, so the PVLAN community would work well. My challenge here

Re: [c-nsp] using the first and last ip address of a range > /24 in a local pool

2010-07-25 Thread Sam Silvester
On Tue, Jul 20, 2010 at 8:16 AM, Tassos Chatzithomaoglou wrote: > Has anyone met any issues with .0 and .255 as host addresses? > I've tried it before and found that apart from some broken implementations, the biggest issue seemed to be certain Internet banking sites that seemed to view traffic f

Re: [c-nsp] QoS and the Catalyst 4506e

2010-06-09 Thread Sam Stickland
t; Direct Connect: 137*131747*8 > Email spfis...@dps.k12.oh.us > > > >>> Sam Stickland 6/8/2010 5:25 PM >>> > Hi Steve, > > I can't see any mention of aggregate policers for the Sup 6, but I could be > being blind: > > > http://www.cisco.com/en/US/part

Re: [c-nsp] QoS and the Catalyst 4506e

2010-06-08 Thread Sam Stickland
want it on. There is no equivalent to the tx-queue, think of each class entry in the policy map as a queue. You can make one of the eight possible classes an LLQ by configuring 'priority' under the class entry. Regards, Sam On Tue, Jun 8, 2010 at 9:51 PM, Steven Pfister wrote: &

Re: [c-nsp] Faster iBGP convergance: Tune the timers or use Fast Peering Session Deactivation?

2010-06-08 Thread Sam Stickland
On Tue, Jun 8, 2010 at 7:31 PM, Richard A Steenbergen wrote: > On Tue, Jun 08, 2010 at 05:14:58PM +0100, Sam Stickland wrote: > > All, > > > > I'd appreciate any feedback people have on tuning iBGP for faster > > convergence, particularly dead peer detection for i

[c-nsp] Faster iBGP convergance: Tune the timers or use Fast Peering Session Deactivation?

2010-06-08 Thread Sam Stickland
remove it opposed to a productive TAC case being endeavoured. Has anyone got any experience they can share? Regards, Sam [1] Nexthop Tracking has the same limitation, the route never becomes invalid in the presence of a shorter-match. ___ cisco-nsp ma

Re: [c-nsp] QoS and the Catalyst 4506e

2010-06-08 Thread Sam Stickland
le. Check cisco.com for more information. Regards, Sam On Tue, Jun 8, 2010 at 1:35 PM, Steven Pfister wrote: > Looks like a sup6e (model #: WS-X45-SUP6-E). > > Steve Pfister > Technical Coordinator, > The Office of Information Technology > Dayton Public Schools > 115 S. Ludl

[c-nsp] ES40 OIR feedback

2009-10-07 Thread Sam Vuillaume
Hi guys, I'm planning to do an ES40 online insertion into 7600 Chassis pretty soon. Cisco say those card are OIR, however i've heard some bad experience during the online insertion. Any feedback to provide to me? My management is now worrried Those PE's are MPLS P/PE

[c-nsp] testing physical links between production and non-production switches

2009-07-22 Thread sam avi
evel test. Once this goes ahead ok, then I plan to shut down the ports and later configure them as standard L2 ports. Any comments? Is there any other way I can do such an interim test in a "safe" way, i.e without affecting other produc

Re: [c-nsp] WS-X6716-10G local switching and etherchanneling

2009-07-03 Thread Sam Stickland
Thanks the reply Tim, Are the port's similarly oversubscribed on the 6708, or can line-rate be achieved between ports 1-4 & 5-6? Sam Tim Stevenson wrote: Sam, please see inline below: At 04:38 AM 7/2/2009, Sam Stickland contended: Hi, I've read: http://www.cisco.

[c-nsp] WS-X6716-10G local switching and etherchanneling

2009-07-02 Thread Sam Stickland
roups of 8 ports will need to traverse the switch fabric? On a similar note, if I create an etherchannel between two 6716-10G's will a module favour forwarding out of it's locally attached channel member? Regards, Sam ___ cisco-nsp mai

Re: [c-nsp] CPU comparison - bridge vs. route on 7206?

2009-07-02 Thread Sam Stickland
ke sure you are using 64 bit counters in MRTG or you will never record more than 114Mbps (the MRTG graph will wrap). (Probably you already know this, but I was struck by the similarity between ~110Mbps and 114Mbps). Sam ___ cisco-nsp mailing

Re: [c-nsp] DNS rewrite & global capabilities

2009-06-29 Thread Sam Stickland
to the issues denoted above. Roland, This seems to imply that the servers would need a second interface for management, with static routes over-riding the default? Is this your preferred approach? Sam ___ cisco-nsp mailing list cisco-nsp

[c-nsp] Cisco 4900M onboard X2 and twingig convertors

2009-06-22 Thread Sam Stickland
n the onboard slots. Thanks, Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Nexus V1000 - Feedback?

2009-06-10 Thread Sam Stickland
___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Nexus V1000 - Feedback?

2009-06-10 Thread Sam Stickland
___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Nexus V1000 - Feedback?

2009-06-09 Thread Sam Stickland
teful ACLs and no inspection so I'm not sure it's really that useful? Sam Sam Stickland wrote: Hi, Has anyone here deployed the Nexus V1000? I'm interested in feedback (good, back or indifferent). Thanks, Sam ___ cisco-nsp mai

[c-nsp] Nexus V1000 - Feedback?

2009-06-01 Thread Sam Stickland
Hi, Has anyone here deployed the Nexus V1000? I'm interested in feedback (good, back or indifferent). Thanks, Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at

[c-nsp] Max length of 9600 serial over CAT5e

2009-04-08 Thread Sam Stickland
Hi, What's the maximum length of you can run async-serial (9600 baud) over CAT5e (from a terminal server to console port). My google-fu has failed me. Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/ma

Re: [c-nsp] Names of various cisco operating systems

2009-03-20 Thread Sam Stickland
ing system name. A Catalyst 4948 runs 'IOS', an Cat5500 ran 'CatOS', but an FWSM simply runs 'Version 3.2(10)'? Does the operating system itself actually have an offical name on these platforms? (e.g. once upon a time PIX's ran Finesse) Sam Justin Shore wrote: S

[c-nsp] Names of various cisco operating systems

2009-03-20 Thread Sam Stickland
a name, but what on earth is the operating system called on these: Application Content Module Firewall Services Module ASA (version 8+) Content Content Switch I can obviously called them whatever I like (e.g. Os: CSS ; Version: 7.50.0.04), but if there are offical names I'

Re: [c-nsp] Buggy interface counters in12.2(33)SB2 ?

2009-03-10 Thread Sam Stickland
Sam Stickland wrote: Hey guys, It looks like we are seeing bogus interface counters (SNMP and CLI) in 12.2(33)SB2 on a 7304 NSE150. I'm just trying good ol' bog standard MRTG to rule out our monitoring systems, but I'm curious if anyone else has seen this? MRTG just start

[c-nsp] Buggy interface counters in12.2(33)SB2 ?

2009-03-10 Thread Sam Stickland
Hey guys, It looks like we are seeing bogus interface counters (SNMP and CLI) in 12.2(33)SB2 on a 7304 NSE150. I'm just trying good ol' bog standard MRTG to rule out our monitoring systems, but I'm curious if anyone else has s

Re: [c-nsp] packet loss between adjacent ciscos

2009-03-01 Thread Sam Tilders
Quoting Mark Tinka : On Friday 27 February 2009 01:28:30 pm Sam Tilders wrote: So, I was wondering if this sounds familiar to anyone or if there is anything someone might be able to suggest to further investigate or resolve this issue. Does this affect all other traffic running across this

[c-nsp] packet loss between adjacent ciscos

2009-02-26 Thread Sam Tilders
s anything someone might be able to suggest to further investigate or resolve this issue. I'd appreciate any advice that can be given. Regards, - Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cis

[c-nsp] Sam Hall is out of the office.

2008-09-12 Thread Sam Hall
I will be out of the office starting 05/09/2008 and will not return until 18/09/2008. I will respond to your message when I return. Kind Regards * Disclaimer: This electronic mail, together with any attachments,

[c-nsp] FWSM 3.1(9) corrupting TCP SYN-ACKs when timestamps are enabled

2008-09-06 Thread Sam Stickland
slates the returning SYN-ACK (from the webserver), causing the client to drop the SYN-ACK. SYNs without the timestamp options don't cause a problem. The problem seems to be isolated to two inside interfaces (in two different contexts), but they both NAT translate into the same insi

[c-nsp] Graphing service response times on Cisco Content Engine

2008-08-21 Thread Sam Stickland
on: Application and Content Networking System Software Hardware Version: ce565-5.4.5.7 Application and Content Networking System Software Software Release 5.4.5 (build b7 Mar 26 2007) Thanks, Sam ___ cisco-nsp mailing list cisco-nsp@p

Re: [c-nsp] Spanning VRFs and seeing my own MAC address on a 4948

2008-08-05 Thread Sam Stickland
Lincoln Dale wrote: Sam Stickland wrote: Hi, We have a pair of 4948s and some DDOS devices configured in this topology (this is an inheritated design btw!): SW1 SVI ---VLANA-- SW2 SVI | | DDOS Std DDOS Act | | SW1 (L2) --VLANB-- SW2 (L2) X

Re: [c-nsp] Spanning VRFs and seeing my own MAC address on a 4948

2008-08-05 Thread Sam Stickland
Phil Mayers wrote: Sam Stickland wrote: Hi, We have a pair of 4948s and some DDOS devices configured in this topology (this is an inheritated design btw!): SW1 SVI ---VLANA-- SW2 SVI | | DDOS Std DDOS Act | | SW1 (L2) --VLANB-- SW2 (L2) X

[c-nsp] Spanning VRFs and seeing my own MAC address on a 4948

2008-08-05 Thread Sam Stickland
es. Is my thinking correct? Is their another way? Thanks, Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] Dont let it happen to you...

2008-07-30 Thread Sam Hall
http://supportwiki.cisco.com/ViewWiki/index.php/Catalyst_3550_switch_reloads_and_gives_the_%22EXPRESS_SETUP-6-CONFIG_IS_RESET%22_error_message_when_the_mode_button_is_pressed_for_a_longer_time_during_a_password_recovery Sam Sam Hall Robert Wiseman & Sons Ext: 6655 Tel: +44 (0)1355 27

Re: [c-nsp] Polling module status in the absence of STACK-MIB

2008-07-28 Thread Sam Stickland
Ha, I've been looking for this for a week, and then just after I send the email I finally find it. http://www.oidview.com/mibs/9/CISCO-ENTITY-FRU-CONTROL-MIB.html cefcModuleOperStatus 1.3.6.1.4.1.9.9.117.1.2.1.1.2 Sam Sam Stickland wrote: Hi, Does anyone know of a way to SNMP pol

[c-nsp] Polling module status in the absence of STACK-MIB

2008-07-28 Thread Sam Stickland
Annoying the ENTITY-MIB also only contains the one single trap, entConfigChange, so these devices don't look to be able to generate module down traps either. Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/ma

Re: [c-nsp] Reconstructing a spanning-tree break

2008-07-21 Thread Sam Stickland
d_ the TCN on. I can't find any information to support this hyposis. The name "topology change" also suggests that it could be looking at the TC bit in BPDUs, not the TCNs. If anyone can explain this to me I will be very grateful, Sam (I'm actually beginning to suspect that

[c-nsp] Reconstructing a spanning-tree break

2008-07-21 Thread Sam Stickland
L3 switches, running HSRP. Oridinarily SW4 is active and SW3 is standby, but for a period of time both went active. Can anyone explain what happened here? Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] FWSM with multiple vlans, NAT quandry...

2008-07-14 Thread Sam Stickland
Hi Jeff, I'm not sure I understand the problem with identity NAT (no nat-control). It does default to all interfaces, but the ACL checks will happen before the NAT translation is built so you can control your access there? Sam Jeff Kell wrote: I seem to have backed myself into a corne

Re: [c-nsp] Telnet FROM a PIX Appliance?

2008-07-12 Thread Sam Stickland
;t exist is not enough people want/ask for it. Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Shutting Down Catalyst 6509?

2008-07-05 Thread Sam Stickland
/installation/note/aceinote.html#wp42206 * Step 1 Before you remove the module from the chassis, enter the no power enable module command in configure mode at the switch or router CLI to properly shut down the module to prevent data loss. Sam

Re: [c-nsp] Quick spanning-tree and bridge-group question

2008-07-04 Thread Sam Stickland
Sam Stickland wrote: Peter Rathlev wrote: Isn't port priority the last thing the Spanning Tree Algorithm looks at? AFAIK the selection of root port should be, in order: Root Bridge ID, Port Path Cost, Sending Bridge ID and at last Sending Port ID, which is Port Priority and Port Index.

Re: [c-nsp] Quick spanning-tree and bridge-group question

2008-07-04 Thread Sam Stickland
e identifier on the BVI :| ) Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Quick spanning-tree and bridge-group question

2008-07-04 Thread Sam Stickland
ge IDs before the port priority? Isn't this supposed to be the other way around? Sam R1#sh spanning-tree Bridge group 10 is executing the ieee compatible Spanning Tree protocol Bridge Identifier has priority 32768, address 0013.8050.b191 Configured hello time 2, max age 20, forward de

[c-nsp] Quick spanning-tree and bridge-group question

2008-07-04 Thread Sam Stickland
port id is 128.21, designated path cost 38 Timers: message age 3, forward delay 0, hold 0 Number of transitions to forwarding state: 2 BPDU: sent 470, received 9930 Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.n

Re: [c-nsp] Telnet FROM a PIX Appliance?

2008-07-04 Thread Sam Stickland
emory. So when saying ASA above I'm also referring to the PIX on 7.x or 8.x code. My understanding is that the 7.x code is the same on the PIXes and the ASA; but version 8.x on the ASA is a rewrite built on top of a Linux kernel, whereas 8.x is still based on the old c

Re: [c-nsp] Telnet FROM a PIX Appliance?

2008-07-01 Thread Sam Stickland
such a port, and it's not. It's nice to be able to troubleshoot problems in chunks. Sam Reuben Farrelly wrote: You also can't ssh from a PIX, but you can of course ssh to it. So it's not IMHO likely to be a case of "telnet being insecure", but avoiding -all- client

[c-nsp] Capture expressions on an FWSM (was Re: Telnet FROM a PIX Appliance?)

2008-06-30 Thread Sam Stickland
of a packet in a capture does prove it's existence". Perhaps there is a cisco documentation on this, listing known caveats and limitations? Sam tv - Original Message - From: "Higham, Josh" <[EMAIL PROTECTED]> To: Sent: Monday, June 30, 2008 10:41 AM Subjec

Re: [c-nsp] Telnet FROM a PIX Appliance?

2008-06-30 Thread Sam Stickland
ad of the correct one. (Remember, even with "no nat-control" the firewall still maintains a translation table, and this will be checked before the routing table). "ip verify unicast reverse-path" helps prevent this. Sam ___ cisco-nsp m

Re: [c-nsp] Telnet FROM a PIX Appliance?

2008-06-30 Thread Sam Stickland
scroll backwards in the config this has long been on my wish-list. But it's not possible unfortunately. Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipe

Re: [c-nsp] RSVP and split-horizon

2008-06-30 Thread Sam Stickland
Oliver Boehmer (oboehmer) wrote: Sam Stickland <> wrote on Monday, June 30, 2008 12:48 PM: Hi, Is there some way to disable/work-around RSVPs split horizon checks? Currently it will log messages like this when receiving path requests on the same interface it needs to forward out of:

Re: [c-nsp] RSVP and split-horizon

2008-06-30 Thread Sam Stickland
Oliver Boehmer (oboehmer) wrote: Sam Stickland <> wrote on Monday, June 30, 2008 12:48 PM: Hi, Is there some way to disable/work-around RSVPs split horizon checks? Currently it will log messages like this when receiving path requests on the same interface it needs to forward out of:

Re: [c-nsp] real time polling & graphing

2008-06-30 Thread Sam Stickland
list a few times. Put a policer on the link, but with the exceed and violate actions set to transmit. Now by adjusting Tc (or at least knowing - it's fixed to 125ms on some platforms) you can see what rate it is overrunning on time intervals quite a bit smaller than you can graph via SNMP.

[c-nsp] RSVP and split-horizon

2008-06-30 Thread Sam Stickland
t I'm trying to understand my options. Thanks, Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] IPSec troubles

2008-06-17 Thread Sam Hall
slot: 0, conn_id: 4210, crypto-map: IPSEC sa timing: remaining key lifetime (kB/sec): (3825000/2844) IV size: 16 bytes replay detection support: Y Crypto map tag: ras_map, seq num: 6, local addr: FW1 Sam Sam Hall Robert Wiseman & Sons Ext: 6655 Tel:

Re: [c-nsp] Maximum number of routes on Cisco 7301 NSE100

2008-06-11 Thread Sam Stickland
1 CWAN LTL PW info 0x412517881481472 12342 Init 0x41B3D2F413759204095 PM vlan non trunk portlist 0x40FBD4201063744 67 List Elements Sam On 7/06/2008, at 12:57 AM, Sam Stickland wrote: Sam Stickland wrote: Hi, Does anyone know what the maximum number of (

Re: [c-nsp] Maximum number of routes on Cisco 7301 NSE100

2008-06-10 Thread Sam Stickland
(Just forwarding this helpful answer back to the list so it hits the archives) Kevin Graham wrote: Does anyone know what the maximum number of (IPv4 unicast) routes these can take? They have 512MB of RAM, which I believe is the maximum for this model. Presumably you mean 7304? nse100#s

Re: [c-nsp] SAA History

2008-06-06 Thread Sam Stickland
Thanks Arie, That certainly clears up some of my understanding of the history commands. Unfortunately it also seems to concern my suspisions that you can't create circular history buffers, or retrieve this information via SNMP. Sam Arie Vayner (avayner) wrote: Sam, Take a look here:

Re: [c-nsp] Maximum number of routes on Cisco 7301 NSE100

2008-06-06 Thread Sam Stickland
Sam Stickland wrote: Hi, Does anyone know what the maximum number of (IPv4 unicast) routes these can take? They have 512MB of RAM, which I believe is the maximum for this model. Actually, I should clarify. We need to know if it can take two full feeds in a VRF (VRF lite, with minimal

[c-nsp] Maximum number of routes on Cisco 7301 NSE100

2008-06-06 Thread Sam Stickland
Hi, Does anyone know what the maximum number of (IPv4 unicast) routes these can take? They have 512MB of RAM, which I believe is the maximum for this model. Thanks, Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net

Re: [c-nsp] Giving customers access to your gear.

2008-06-04 Thread Sam Stickland
). There's nothing wrong with running BGP with your customers - just make sure you have adequate prefix-filters and max-prefix-counts set. Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archi

Re: [c-nsp] Giving customers access to your gear.

2008-06-04 Thread Sam Stickland
eam providers) actually asked to have SNMP RO access to our end of the BGP handoff. Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] SAA History

2008-06-03 Thread Sam Stickland
keep load off the management station, but it will - hopefully - mean that statistics won't be lost during a network outage. Is this possible? It looks to me that not only do the history buckets not wrap, but that the history buckets can't actually be

Re: [c-nsp] Something I was thinking about whilst idle the other day.

2008-03-20 Thread Sam Stickland
A few things that would make my day-to-day life a litlte bit easier, that I really don't think are that hard: A text pager that lets you scroll backwards Outbound telnet from FWSMs/PIXs (to check port connectivity) "Show running-config all" for showing full configuration (including defaults).

Re: [c-nsp] Software Advisor Error

2007-12-11 Thread Sam Hall
than an alternate (firefox for example). Also clear your cache and delete any cookies. If this fails to work you can open a TAC case on-line or contact us on the following numbers and we will assist you further. http://www.cisco.com/web/siteassets/contacts/ Sam Sam Hall Robert Wiseman

[c-nsp] Finding SNMP trap source via SNMP

2007-12-06 Thread Sam Stickland
terfaces specified in the trap-sources would reveal this. Is there a way to retrieve "snmp-server trap-source xxx" via SNMP? (Preferabaly via just the R/O community, I realise I could get the entire config and scub it). Sam ___ cisco-nsp mail

Re: [c-nsp] Broadcast storm control

2007-11-06 Thread Sam Stickland
Saku Ytti wrote: > On (2007-11-06 16:56 +), Sam Stickland wrote: > > >> switchport port-security >> switchport port-security maximum x >> switchport port-security aging time 5 >> switchport port-security violation restrict >> >> Port security d

Re: [c-nsp] Broadcast storm control

2007-11-06 Thread Sam Stickland
tchport port-security maximum x switchport port-security aging time 5 switchport port-security violation restrict Port security doesn't permamently learn MAC addresses unless "switchport port-security mac-address sticky" is set, and setting the aging time to 5 matches the def

Re: [c-nsp] BFD feedback?

2007-10-24 Thread Sam Stickland
OSPF adjacency with each other (full mesh). This means that there is a full mesh of BFD neighbors also. If the link from SW1 to R3 goes down BFD will detect this and take down the appropiate OSPF neighbors. If BFD shut the interface down instead it would also sever the commu

[c-nsp] 12.2(18)SFX10a and 11

2007-10-18 Thread Sam Stickland
/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsj92874>—Catalyst 6500 May Not Send linkup/linkdown SNMP Traps and may reload" when 10 only contains bug fixes is a little worrying ;) ) Sam ___ cisco-nsp mailing list c

[c-nsp] Introducing Detective Cisco...

2007-09-07 Thread Sam Stickland
a bit higher than the timescale allowed for, but it still hopefully made a cohesive story (with a vertiable shedload of in-jokes for techies!). So we proudly give you Redistribution, a labour of love and we hope that you enjoy watching it as much as we enjoyed making it. Sam &a

Re: [c-nsp] SNMP question

2007-04-10 Thread Sam Stickland
Hi, Gert Doering wrote: > Hi, > > On Wed, Apr 04, 2007 at 03:46:27PM +0100, Sam Stickland wrote: > >>> I've run some testing, and different Cisco platforms update the >>> SNMP-viewable >>> counters at different intervals. >>>

Re: [c-nsp] SNMP question

2007-04-04 Thread Sam Stickland
Gert Doering wrote: > Hi, > > On Mon, Apr 02, 2007 at 06:17:06PM +0100, Sam Stickland wrote: > >> Can anyone answer this question from a college of mine? >> >> "Afternoon all. Does anyone know anything about the minimum poll period >> for an OID on a C

[c-nsp] SNMP question

2007-04-02 Thread Sam Stickland
ver been able to find any documentation on this. If anyone can shed any light on this - oh so fascinating subject - I would be most grateful." Thanks, Sam ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/list

Re: [c-nsp] FWSM Question

2007-03-25 Thread Sam Stickland
stions but this has to be the most > confusing situation I've ran into before...;) > > Paul > Hi Paul, You shouldn't need an SVI to make this work, but you'll still need to create the VLAN on the MSFC. Without the SVI for VLAN 95 what does "sh vlan id brief&quo