Re: [c-nsp] IOS XR RPL Matching on neighbor IP/ASN

2021-11-22 Thread Sascha E. Pollok via cisco-nsp
--- Begin Message --- Moin Gert, if (neighbor-asn '12731') then # Announce this one prefix only, if receiving neighbor is in ASN 12731 done elseif (neighbor-ip '192.168.1.1') then # Announce this one prefix only, if receiving neighbor is 192.168.1.1 done endif Not

[c-nsp] IOS XR RPL Matching on neighbor IP/ASN

2021-11-19 Thread Sascha E. Pollok via cisco-nsp
--- Begin Message --- Hello people, I searched several IOS XR routing policy language documentations and also opened a TAC case but still searching an answer to the question: Is it possible to match on a neighbor's IP address or ASN inside a condition? So for example if I have a route-policy

Re: [c-nsp] Question about ASA IPSEC peer monitoring

2021-11-04 Thread Sascha E. Pollok via cisco-nsp
--- Begin Message --- Okay I think I solved this one myself. > I am querying a Cisco ASA with SNMP for IPSEC peers I am using > 1.3.6.1.4.1.9.9.171.1.2.3.1.7 from CISCO-IPSEC-FLOW-MONITOR-MIB which shows all peer > addresses. However, one is missing. And the only difference I find is that this

[c-nsp] Question about ASA IPSEC peer monitoring

2021-11-04 Thread Sascha E. Pollok via cisco-nsp
--- Begin Message --- Hi all, I am querying a Cisco ASA with SNMP for IPSEC peers I am using 1.3.6.1.4.1.9.9.171.1.2.3.1.7 from CISCO-IPSEC-FLOW-MONITOR-MIB which shows all peer addresses. However, one is missing. And the only difference I find is that this one is using NAT-T. Is anyone aware

Re: [c-nsp] big uptime - what you got ?

2020-02-10 Thread Sascha E. Pollok via cisco-nsp
--- Begin Message --- >> Holy cow! Beat that >> >> dsw2-4503#sh ver | in uptime >> >> dsw2-4503 uptime is 11 years, 2 weeks, 1 day, 23 hours, 3 minutes >> >> dsw2-4503#sh ver | in IOS >> >> Cisco IOS Software, Catalyst 4500 L3 Switch Software (cat4500-IPBASEK9-M), >> Version 12.2(31)SGA1, RELEASE

[c-nsp] Nexus 3000k (N3K-C3064PQ-10GE) SFP ports "stuck" - Maybe i2c problem?

2018-12-11 Thread Sascha E. Pollok
Dear People, I come in peace. But with a problem on a good old N3K-C3064PQ-10GE switch which works like a charm but got some ports "stuck" with their transceiver information and I am wondering if anyone experienced that before: - Ports in the area of 17-23 (roughly) do not update transceiver

Re: [c-nsp] 3750G Switch

2018-12-08 Thread Sascha E. Pollok
Hi Harry, > Trying to upgrade a 3750G from IOS c3750e-universalk9-mz.150-2.SE10.bin to > a latest version c3750e-universalk9-mz.152-4.E7.bin, and I am getting the following error: > > > Error loading "flash: c3750e-universalk9-mz.152-4.E7.bin > > > Interrupt within 5 seconds to abort boot

Re: [c-nsp] ASR1K forwarding failures on 10G SPA's

2016-10-07 Thread Sascha E. Pollok
for the SR. Was your case resolved? > > -- Stephen > > On 2016-10-04 5:15 PM, Sascha E. Pollok wrote: >> (Not replying to the list but all folks who joined the discussion) >> >> Hi Stephen, >> >> the drops were high or the input queue? What we've seen bef

Re: [c-nsp] Cat 3750E w/ MAC learning disabled shutting port?

2015-04-25 Thread Sascha E. Pollok
Hi Lukas, hi Blake, et al, me again. I noticed I have not been completely honest with you guys :) I am looking for an explanation for a strange port flap that I experienced this afternoon and out of desperation (and because I can not find an answer on Cisco, Google, you name it and I am not

[c-nsp] Cat 3750E w/ MAC learning disabled shutting port?

2015-04-24 Thread Sascha E. Pollok
Hello people, I am looking for an explanation for a strange port flap that I experienced this afternoon and out of desperation (and because I can not find an answer on Cisco, Google, you name it and I am not yet desperate enough to open a TAC case) I am posting here. Here is the situation:

Re: [c-nsp] Cat 3750E w/ MAC learning disabled shutting port?

2015-04-24 Thread Sascha E. Pollok
Hi Lukas, hi Blake, Is it the only up port participating in that vlan? On Fri, Apr 24, 2015 at 8:40 AM, Lukas Tribus luky...@hotmail.com wrote: Hello people, I am looking for an explanation for a strange port flap that I experienced this afternoon and out of desperation (and because I can

Re: [c-nsp] AS-path access-list

2015-03-29 Thread Sascha E. Pollok
M K, I have several BGP uplinks with full routing table , there is a specific AS number that I want the upload to it to use a certain link/neighbor , can i use as-path access-list to do that ? yes. ___ cisco-nsp mailing list

Re: [c-nsp] 10Gb+ Core w/ Netflow

2015-03-16 Thread Sascha E. Pollok
Hello Guys, What about the Cisco 6880-X in this respect? Does anybody use this box as a BGP edge in an ethernet only environment? I’m curious about the real world performance of this box, looking at number of BGP peers, convergence, etc. That's an x86 platform: Cisco C6880-X-LE ( Intel(R)

Re: [c-nsp] Cisco C6880-X-NEBS-PAK

2015-01-15 Thread Sascha E. Pollok
Hi Tim, Am 15.01.2015 um 16:37 schrieb Tim Durack: Can anybody point me to documentation for the Cisco C6880-X-NEBS-PAK Mandatory Air Dam? Not sure what the air dam looks like, or how to install it... good point! I just had to buy one for some Euros. If you find out what it actually is

[c-nsp] Strange corrupt DNS Cache in IOS

2014-08-15 Thread Sascha E. Pollok
Hello networking fellows! We are trying to find the cause of a corrupt local DNS cache of a Cisco 1803 running 15.1(4)M8 (also appeared on 12.4something - 15.1 ist just a desperate attempt of solving). The router acts as a local DNS resolver for locally connected clients using ip dns

Re: [c-nsp] Strange corrupt DNS Cache in IOS

2014-08-15 Thread Sascha E. Pollok
[mailto:ja...@puck.nether.net] Sent: Friday, August 15, 2014 9:42 AM To: Frank Bulk Cc: Sascha E. Pollok; cisco-nsp@puck.nether.net Subject: Re: [c-nsp] Strange corrupt DNS Cache in IOS On Aug 15, 2014, at 10:34 AM, Frank Bulk frnk...@iname.com wrote: Don't use a router as a DNS resolver

Re: [c-nsp] OSPF Adjacencies

2010-05-13 Thread Sascha E. Pollok
Shake, Output from show ip ospf interface are as folows FastEthernet0/0 is up, line protocol is up Internet Address loopback ip , Area 0 ^ This isn't an unnumbered interface by any chance? Or is that just a typo? What about MTU on both sides? And what does the

Re: [c-nsp] OSPF Adjacencies

2010-05-12 Thread Sascha E. Pollok
Sascha, Output show ip ospf  [...] As Peter already said, I was asking for the output of show ip ospf interface. It will show us whether something like a passive-nterface causes your problem. Thanks Sascha___ cisco-nsp mailing list

Re: [c-nsp] OSPF Adjacencies

2010-05-11 Thread Sascha E. Pollok
Hello Shake, Having a problem whereby ospf adjacencies are not forming. a debug on ospf ajacencies is also not showing any thing show ip protocols shows ospf as beign identified and as beign configured. have tested by removing any authentication keys but nothing. Running on a cisco 2621

Re: [c-nsp] All RRs down

2010-05-10 Thread Sascha E. Pollok
Hello Nam, I have a small network running IBGP with 2 designated route reflectors. Everything now is working fine. My question is that, if the 2 RRs are down for some reasons, can other routers in the cluster keep forwarding packets during the down time of RRs? In other words, will routing

Re: [c-nsp] same mac for different ip addr

2010-04-20 Thread Sascha E. Pollok
Hello Arne, Can someone give me an answer on this. We have a platform that run on Redhat EntR5.3 and uses subinterfaces. I seem that the platform sends the same MAC for all interfaces. What happens in the arp table on the default gateway. Does it keep track of all ip address or does it

[c-nsp] Good old Cisco 828 and HSRP

2010-04-19 Thread Sascha E. Pollok
Hello people, I am currently configuring a quite old Cisco 828 G.SHDSL router. It is currently running 12.4(25b) IP. The feature navigator says it does support HSRP but obviously it does not as the CLI does not offer any standby command on Ethernet0. Does anyone have hands-on-expriences

Re: [c-nsp] Good old Cisco 828 and HSRP

2010-04-19 Thread Sascha E. Pollok
Thank you, Shimol! Sascha On Mon, 19 Apr 2010, Shimol Shah wrote: You need plus feature set for HSRP on 828. On 4/19/10 9:50 AM, Sascha E. Pollok wrote: Hello people, I am currently configuring a quite old Cisco 828 G.SHDSL router. It is currently running 12.4(25b) IP. The feature

Re: [c-nsp] REAL Cisco 2960 bugs

2010-04-09 Thread Sascha E. Pollok
On Fri, 9 Apr 2010, Jan Gregor wrote: Fan1 is not rotating: http://www.chronix.org/muchy/ Enjoy :). Ye flipping gods! Did you put honey into that power supply? Oh dear. Sascha ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] BGP announcing route with no subnet mask

2010-04-07 Thread Sascha E. Pollok
Hello Andy, ip route 193.x.x.0 255.255.255.0 Null0 200 tag 200 [...] CSW01#sh ip bgp neighbors border router peer IP advertised-routes | i 193.x.x.0 * 193.x.x.00.0.0.0 0 32768 i The route is visible via one transit provider + our peers (showing the correct /24

Re: [c-nsp] BGP - Multihop across igp network

2010-04-06 Thread Sascha E. Pollok
Hello Paul, Connected to these 7600's we have a pair of 6500's not doing BGP (however participating in OSPF as all our boxes do) Connected off one of the 6500's we have a 3825 at a customer site The customer who is connected to a 3825 wants a full BGP feed from us. So, I created a pair of

Re: [c-nsp] BGP - Multihop across igp network

2010-04-06 Thread Sascha E. Pollok
redistribution (or iBGP stuff) from there. Let the relevant access routers get to know about the routes from where the routes are originally learned through eBGP. But thats just my way of doing it. Good luck! Sascha -Original Message- From: Sascha E. Pollok [mailto:nsp-l...@pollok.net

Re: [c-nsp] CRC16 in 'show cont fia' on GSR 12810

2010-03-31 Thread Sascha E. Pollok
Hello Drew, Slot: 18 19 20 21 22 Name:sfc0 sfc1 sfc2 sfc3 sfc4 los0 0 0 0 0 state OffOffOffOffOff

Re: [c-nsp] CRC16 in 'show cont fia' on GSR 12810

2010-03-31 Thread Sascha E. Pollok
temporarily and we haven't seen that message again, so I can only deduce that possibly Slot 21 is bad and hopefully not SLOT 1 =) was that sh contr fia you posted as seen from slot 1? i.e. execute-on sl 1 sh contr fia ? Sascha -Drew -Original Message- From: Sascha E. Pollok [mailto:nsp

Re: [c-nsp] CRC16 in 'show cont fia' on GSR 12810

2010-03-31 Thread Sascha E. Pollok
in non-redundant fabric mode. Sascha On 2010-03-31 12:29, Sascha E. Pollok wrote: was that sh contr fia you posted as seen from slot 1? i.e. execute-on sl 1 sh contr fia ? Sascha ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https

Re: [c-nsp] Older gear and IPv6 (fwd)

2010-03-29 Thread Sascha E. Pollok
I've heart from a SE, that only Engine 5 linecards do IPv6 in hardware. Engine 3 as well. Correct. Engine 3 like the 4GE-SFP-LC= work perfectly well. I would like to add that we had severe problems with Engine 2 linecards (3GE-GBIC-SC=) some time ago which seem to drop communication

Re: [c-nsp] GSR: 3GE-GBIC-SC v4 traffic influenced by v6 traffic?

2010-02-26 Thread Sascha E. Pollok
Hello Jan, thanks for your reply. It sheds some light on that annoying problem. forwarding IPv4 traffic or AT LEAST stops responding to ICMP Echo (directed to the interface IP) or loses IP protocols like LDP or OSPF which could point to problems GRP/PRP - Interface. It seems like this happens

Re: [c-nsp] strange behavior over MPLS network - remote desktop won't work

2009-05-31 Thread Sascha E. Pollok
Chris, The mpls MTU over the gige wireless backbone between the POPs was MTU1500. I will change that to 1538 and see what happens. try to do the 1500 Byte pings between the PEs with DF bit set. I'd rather test the connectivity at 1500 bytes before trying to tweak something. Also, what kind

Re: [c-nsp] Weird Error Message in 'sho ver' on GSR after upgrade

2007-11-15 Thread Sascha E. Pollok
Mike, hm... I am not too sure but afaik the MBUS is a CAN bus. Could you do a show mbus can-error ? And maybe try a clear mbus-statistics afterwards. Regards Sascha On Thu, 15 Nov 2007, Michael K. Smith - Adhost wrote: Hello All: I just upgraded from 12.0(28)S to 12.0(32)S8 on a 12008 and

[c-nsp] OSPF - Invalid length - Is this an attack?

2007-11-08 Thread Sascha E. Pollok
Nov 6 18:16:00 CET: %OSPF-4-BADLENGTH: Invalid length 10246 in OSPF packet type 208 from 218.104.98.100 (ID 37.68.117.149), GigabitEthernet15/0 IPs are far from our network ranges. Gig15/0 is backbone facing. Anyone with an idea what could be causing this? Thanks Sascha

Re: [c-nsp] Help with simple QoS configuration

2007-11-07 Thread Sascha E. Pollok
at least. If you have another way please let me know as well. Otis Sascha E. Pollok wrote: Folks, maybe someone could push me into the right direction for some QoS related stuff. We have a setup like this: 7206VXR| 100M |c2811| .1q | 3548XL | Access Router

Re: [c-nsp] Removing VTP Server switch

2007-11-06 Thread Sascha E. Pollok
On Tue, Nov 06, 2007 at 03:38:21PM +1100, Kurt Bales wrote: I am a big fan of VTP. This will change over time :) Yesterdaaay. VTP probs seemed so faaar awayy.. [..] I guess my question is, can I simply change every switch to transparent mode, and all will will operate happly, or will I

Re: [c-nsp] Recovering from disabled break squence

2007-11-06 Thread Sascha E. Pollok
i have messed up my router (3640) with a config-reg value of 0x3922 disabling the break sequence. Now, I am unable to get into ROMMON mode to change IOS. The current IOS does not detect my Ethernet module. Also, when I try to enter config mode it says: Routerenable % No password set

[c-nsp] VRF-aware VRRP

2007-11-05 Thread Sascha E. Pollok
Good day folks, can anyone of you point me to the appropriate information whether VRF-aware VRRP is supported in IOS or not? I noticed today that the same IP address as floating VRRP IP can not be configured on several interfaces even when they are in different VRFs. Thanks Sascha