Re: [c-nsp] DNS amplification

2013-03-16 Thread Steven Fischer
yes - and it presumes your DNS servers are based on Linux and use IPTables. http://www.cryptonizer.com/dnsamp.html http://serverfault.com/questions/418810/public-facing-recursive-dns-servers-iptables-rules http://sf-alpha.bjgang.org/wordpress/2013/01/iptables-for-common-dns-amplification-attack-

Re: [c-nsp] Cisco TAC issues - can someone from Cisco enlighten me on this?

2009-09-21 Thread Steven Fischer
iguration/guide/nm_logging_count.html On Mon, Sep 21, 2009 at 10:00 AM, Mark Tinka wrote: > On Monday 21 September 2009 09:31:48 pm Steven Fischer > wrote: > > > as an aside, the TAC engineer (Indian engineer #4) stuck > > with it, and has found the bug that was causing the > > meltdow

Re: [c-nsp] Cisco TAC issues - can someone from Cisco enlighten me on this?

2009-09-21 Thread Steven Fischer
as an aside, the TAC engineer (Indian engineer #4) stuck with it, and has found the bug that was causing the meltdown. Credit certainly needs to be given for that. On Mon, Sep 21, 2009 at 4:24 AM, Alan Buxey wrote: > hi, > > the webex option is worrying when you have a core failure > (and there

[c-nsp] MST spanning-tree

2009-07-23 Thread Steven Fischer
When we relocated our data center, we opted to deploy MST as the spanning-tree protocol, given that our data center is almost exclusively layer 2, we have a lot of vlans, and that number is only going to grow. We have two spanning-tree MST instances, 1 and 2, and each contains the vlans that are e

Re: [c-nsp] 4510 reporting dozens of config changes throughout the day...

2009-06-08 Thread Steven Fischer
doing a compare, I found a single config element, "ip ssh logging events" that was present on the device generating the messages, but not on the 4510 that isn't. Removed it, and will see what that does. On Mon, Jun 8, 2009 at 5:36 AM, Tom Lanyon wrote: > On 08/06/2009, at 6:53 PM, David Freedma

Re: [c-nsp] 4510 reporting dozens of config changes throughout the day...

2009-06-07 Thread Steven Fischer
nether.net [mailto: > cisco-nsp-boun...@puck.nether.net] On Behalf Of Steven Fischer > Sent: Sunday, June 07, 2009 10:48 PM > To: cisco-nsp@puck.nether.net > Subject: [c-nsp] 4510 reporting dozens of config changes throughout the > day... > > I have a 4510 in our environment th

[c-nsp] 4510 reporting dozens of config changes throughout the day...

2009-06-07 Thread Steven Fischer
I have a 4510 in our environment that is reporting literally dozens of changes to the running configuration throughout the day - days on which I am certain no changes have been made to it - the syslog message is given with the header - AUDIT-5-RUN_CONFIG. Cisco's support site doesn't give me a wh

Re: [c-nsp] spanning-tree bpduguard vs. bpdufilter

2009-03-26 Thread Steven Fischer
On Thu, Mar 26, 2009 at 4:29 PM, wrote: > Hi, > > > spanning-tree bpduguard enable > > spanning-tree bpdufilter enable > > > > Thinking this recommendation came from Cisco Works, it follows that this > > would make sense to do, right? As some more information on the effect of > > these commands

[c-nsp] spanning-tree bpduguard vs. bpdufilter

2009-03-26 Thread Steven Fischer
When deploying our new network a few months ago, we set up Cisco Works to manage it. Cisco Works detected and flagged the lack of the following commands as configuration errors: spanning-tree bpduguard enable spanning-tree bpdufilter enable Thinking this recommendation came from Cisco Works, it

[c-nsp] weird OSPF behavior

2009-02-26 Thread Steven Fischer
I am seeing weird behavior on OSPF between a 2811 Router, and a 4510R switch. A number of google searches on this came up empty. It appears as if OSPF is dropping with the following message on hourly intervals, sometimes one hour, sometime two hours, sometimes three hours. 005840: Feb 26 15:28:05