[c-nsp] split dns local view for the router

2010-04-17 Thread luismi
I have configure 2 "ip dns view" profiles: one is for our internal dns -called corp- and the other one is the default view. I also configured: ip dns server view-group corp For some reason when I do ping some_machine, the router is using the default view, avoiding the internal dns servers and I d

[c-nsp] 12.2SRC6 available

2010-03-14 Thread luismi
I just see it. Anyone here testing it? :D ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] Thread out the mailling list about Procera PacketLogic product (good and bad experiences, as well comments)

2010-03-10 Thread luismi
Hi there, We are evaluating the idea to the deploy here a Procera device. I would like to hear, share and discuss about Procera products. I would like to talk also about Packeteer > Procera migration, common features, advantages or disadvantages... So is there is anyone here working with it, I wo

Re: [c-nsp] Cisco 7201 -- Differences between the 12."2" images and the usual 12.4/15 images?

2010-03-08 Thread luismi
my 2 cents Cisco IOS Software Release 12.2(33)SRC http://www.cisco.com/en/US/prod/collateral/iosswrel/ps8802/ps6970/ps1838/prod_presentation0900aecd8072c43a.pdf El lun, 08-03-2010 a las 09:32 -0600, P C escribió: > I'm deploying a Cisco 7200 series router. I've used ISRs in the past many > times

Re: [c-nsp] 7600 redistribution on 12.2SRD

2010-03-05 Thread luismi
We saw this week something strange with eigrp, all nodes were able to see them with "topo" command but they were not learning routes from neighbours, we needed to do some "cler ip ro vrf ABCD *" in several vrfs. I dont know if it is related. Details here: 7600-PFC3C 122-33.SRC5 El mié, 03-03-201

Re: [c-nsp] ip igmp join-group x.x.x.x

2010-02-24 Thread luismi
Ah! ok interesting :D El mié, 24-02-2010 a las 14:35 +0100, Marian Ďurkovič escribió: > On Wed, Feb 24, 2010 at 01:52:37PM +0100, luismi wrote: > > Be aware of the command, I dont know the behaviour of your platform, but > > in our 7206 npe-g2 we have issues with it. Multicast vide

Re: [c-nsp] ip igmp join-group x.x.x.x

2010-02-24 Thread luismi
Be aware of the command, I dont know the behaviour of your platform, but in our 7206 npe-g2 we have issues with it. Multicast video and audio was broken because the command makes the multicast to be "process switched" , if my memory is ok. El lun, 22-02-2010 a las 22:40 +, Vladislav Vasilev es

[c-nsp] multicast udlr experiences?

2010-02-21 Thread luismi
Is there anyone using multicast udlr? I would like to hear about experiences, and how to deploy properly becuase the documentation I found is a bit confused for me. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/lis

[c-nsp] ip source guard in the switch layer without DHCP

2010-02-10 Thread luismi
According with this link http://www.packetlife.net/blog/2009/may/25/ip-source-guard-without-dhcp/ It is possible to deploy "ip source guard" without dhcp environment. I think it could be interesting for some parts of our network here. The problem is that the configuration is... SW(config)#ip sour

[c-nsp] PGM and multicast

2010-02-08 Thread luismi
Is there anyone here using multicast and PGM? We have several multicast services -video and audio streams- and sometimes we use to have incidents because the service is not ok, and we would like to deploy PGM to have more control. So, my questions are... Is possible to manage the rx buffer of the

Re: [c-nsp] Radius solution for VPN Concentrator and 802.1x

2010-01-21 Thread luismi
sults- the Radiator solution. But as I told in my first email I am still doing a research to take the best decision :D El jue, 21-01-2010 a las 13:40 +0100, Frederic LOUI escribió: > Hi Luismi, > > Freeradius is a good alternative and can be used to cover all the needs > you men

[c-nsp] Radius solution for VPN Concentrator and 802.1x

2010-01-21 Thread luismi
Hi all, I am looking for a Radius solution to configure on it the user accounts of the users of the VPN Concentrator 3030 we have here -that is the primary goal-. In the future I would like to use the same radius for 802.1x in the wireless network and maybe some captive portals or similar. The ra

Re: [c-nsp] IP Packet Debug - FIB errors

2010-01-19 Thread luismi
I dont think so, "debug ip packet" is ok if you use a very specific ACL, IMHO. I found very dangerous "debug ip nat detailed", I saw 7200 down because of that command without too many nat :-P El mar, 19-01-2010 a las 12:24 +, Dobbins, Roland escribió: > On Jan 19, 2010, at 6:25 PM, Andre Scho

Re: [c-nsp] cisco-nsp Digest, Vol 86, Issue 48

2010-01-19 Thread luismi
I have this and I have accounting: aaa authentication attempts login 2 aaa authentication login default group tac-plus local-case aaa authentication login console group tac-plus local-case aaa authentication enable default enable aaa authorization console aaa authorization exec default group tacac

Re: [c-nsp] IP/VC 3526 serial port is not showing anything

2010-01-13 Thread luismi
the factory set at 115200. > > Jason > > -Original Message- > From: cisco-nsp-boun...@puck.nether.net > [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of luismi > Sent: Tuesday, January 12, 2010 10:21 AM > To: cisco-nsp@puck.nether.net > Subject: [c-nsp]

[c-nsp] IP/VC 3526 serial port is not showing anything

2010-01-12 Thread luismi
Hi all, We take a Cisco IP/VC 3526 from one of our racks. We tried to access to it over the serial port with 9600 8N1 -as the documentation says- and it didn't work. We also have an alarm in the from but we were not able to find the relation with it in the documentation. As far as we read the pro

[c-nsp] cisco cube or a solution based on asterisk?

2009-12-23 Thread luismi
Hi all, I would like to deploy a VoIP PBX here with also SIP trunk options to multiple VoIP Providers. As far as I know Cisco Cube just support 1 SIP Trunk -I thought to remember that in one version out there it supported more but I didn't find that information again so maybe I am wrong about it-

[c-nsp] Experiences with 12.4.15T11 (before: Re: 12.4 IOS recommendation for 7206 )

2009-12-21 Thread luismi
Platform 7206VXR NPE-G2, any serious problem with that IOS? El lun, 14-12-2009 a las 16:49 -0800, Derick Winkworth escribió: > Agreed on the 12.4(15)T train. Pick the latest release of this. > > No new features have been introduced in this "train" since T7 or T8 I > believe. Going forward, a

Re: [c-nsp] "ip verify header drop-tiny-fragment" command

2009-12-11 Thread luismi
It is 7200 :] El vie, 11-12-2009 a las 13:57 +0100, luismi escribió: > Hi all, > > Can anyone tell me the impact of configure "ip verify header > drop-tiny-fragment" in a router running 12.2src5? > > The routers is running several VRFs, and I don't if t

[c-nsp] "ip verify header drop-tiny-fragment" command

2009-12-11 Thread luismi
Hi all, Can anyone tell me the impact of configure "ip verify header drop-tiny-fragment" in a router running 12.2src5? The routers is running several VRFs, and I don't if this command applies to all vrfs. Neither I found documentation how can I see that the command is doing what is expected, or

Re: [c-nsp] Cisco Pagent IOS

2009-12-11 Thread luismi
Not Found The requested URL /matrix was not found on this server. Apache/2.2.3 (Red Hat) Server at external.net.ic.ac.uk Port 80 El jue, 10-12-2009 a las 11:03 +, Phil Mayers escribió: > Hansen, Ulrich Vestergaard B.

Re: [c-nsp] Network Configuration and Generation Management

2009-12-04 Thread luismi
www.ziptie.org could help you El vie, 04-12-2009 a las 15:34 -0500, chip escribió: > Hi all, > > I'm looking for input on applications to generate configuration and manage > network devices for a fairly large base of devices (>2000). Specifically > for routers and switches, not so much linux or

Re: [c-nsp] Using SNMP to monitor NAT usage...

2009-12-04 Thread luismi
It could very interesting to have historic RRD files with the behaviour of the NAT and, try to cross info with issues or customer problems. Do you know if it is possible to count over snmp the "nat exhausted" problems? El vie, 04-12-2009 a las 14:58 -0500, Rodney Dunn escribió: > How many of you a

Re: [c-nsp] IOS Version for 7206VXR

2009-12-04 Thread luismi
12.2SRC5 here, so far so good El vie, 04-12-2009 a las 14:21 -0500, Matthew Huff escribió: > I've been pretty happy with 12.4(24)T2. We are doing bgp, access-list, > etc...but not ospf.. > > 12.4(24)T fixed a lot of bugs in bgp and T2 seems stable. > > > > > > Matthew Huff | One

[c-nsp] menu at cisco with arguments

2009-12-02 Thread luismi
Hi there, is possible to create menus in the Cisco IOS and ask for an argument? I would like to see is there any option to see something like this in the IOS: - 1 - Ping Select option: 1 Enter IPv4 address to do ping: - Regards. ___

[c-nsp] Netflow in 2960 and 3750?

2009-11-26 Thread luismi
Hi all, is there any option to connect one 2960 and one 3570 to netflow collector? I was doing a research but I didn't find anything about it yet ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp ar

Re: [c-nsp] reverse path filtering doesn't seem to work

2009-11-23 Thread luismi
try "debug ip cef drops verify" and "debug ip cef drops suppressed-verify" so you can see what is going on inside the router with urpf El vie, 20-11-2009 a las 06:12 -0800, Mike escribió: > above static route should be enough to tell 'ip verify' to > allow x.x.74.0/29 as a source on this interfac

[c-nsp] TCL script to check empty ACL in PBR

2009-11-23 Thread luismi
Before start to think how I could do that... Is there anyone here with a TCL script to check if an ACL is empty so it is detroying the PBR sequence? Regards. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/

[c-nsp] Recommended steps to avoid 100% CPU while executing "debug ip nat"

2009-11-19 Thread luismi
Hi all, We have executed this morning "debug ip nat" in a 7206VXR with ver bad results. The router was overloaded for a while and at the end we needed to reboot it. I was doing some research but I would like to hear from you too. As a plan we have deployed CoPP configuration for management traffi

Re: [c-nsp] BDF over port-channels?

2009-11-18 Thread luismi
Channels. > > > > Workaround: Do not enter the bfd interval command on > > EtherChannel and EtherChannel member interfaces. > > > > > > It's still not clear whether it's supported on SRD (and ES cards) or will > > be supported in the future...

Re: [c-nsp] BDF over port-channels?

2009-11-18 Thread luismi
d port, or with L2 VLANs switched on top of it? > > Arie > > -Original Message- > From: cisco-nsp-boun...@puck.nether.net > [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of luismi > Sent: Tuesday, November 17, 2009 19:11 > To: Gert Doering > Cc: cisco-nsp@

Re: [c-nsp] BDF over port-channels?

2009-11-17 Thread luismi
t; On Tue, Nov 17, 2009 at 01:20:58PM +0100, luismi wrote: > > I wrote it in a previous email but here is again :D > > > > 7200 npe-g2 and 7600 rsp720-pfc3 > > These are very very *VERY* different platforms... > > > I am using 12.2SRC but it is not supported

Re: [c-nsp] BDF over port-channels?

2009-11-17 Thread luismi
009 at 11:01:48AM +0100, luismi wrote: > > I see a message like "BDF not supported over port-channels" in my > > routers. > > Which IOS version is that? On what platform? > > You could be a bit more proactive in your questions... this makes it > mu

Re: [c-nsp] BDF over port-channels?

2009-11-17 Thread luismi
I see a message like "BDF not supported over port-channels" in my routers. Also "sh bfd ..." doesn't show anything. El mar, 17-11-2009 a las 10:54 +0100, Gert Doering escribió: > Hi, > > On Tue, Nov 17, 2009 at 10:31:00AM +0100, luismi wrote: > > Did you

Re: [c-nsp] how not to write a release note

2009-11-17 Thread luismi
I can't believe it, I need to check it. > Still not as funny as this one: > > CSCso05336 > > Symptoms: A Cisco 1811 router reloads when trying to connect to > irc.freenode.net during the first 36 hours following a reload. > > Conditions: The symptom is observed only in the first 36 hours > fol

Re: [c-nsp] BDF over port-channels?

2009-11-17 Thread luismi
Did you try it' El dom, 15-11-2009 a las 20:19 +0100, Gert Doering escribió: > Hi, > > On Sun, Nov 15, 2009 at 03:12:24PM +0100, luismi wrote: > > Is it supported in any IOS? > > Does anyone if it is going to be supported in the future? > > On 7600s, it shoul

Re: [c-nsp] BDF over port-channels?

2009-11-15 Thread luismi
7200 npe-g2 and 7600 rsp720-pfc3 El dom, 15-11-2009 a las 16:16 +0100, Arie Vayner (avayner) escribió: > Which platforms? > Arie > > -Original Message- > From: cisco-nsp-boun...@puck.nether.net > [mailto:cisco-nsp-boun...@puck.nether.net] On Behalf Of luismi > Sent

[c-nsp] BDF over port-channels?

2009-11-15 Thread luismi
Is it supported in any IOS? Does anyone if it is going to be supported in the future? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] IRIS Project

2009-11-15 Thread luismi
IS there anyone in this mailing list involved with the IRIS project? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Interface descriptions - what do you put in?

2009-11-05 Thread luismi
Area code - critical value - description - remote port [port-cX] Area code: [ip|sys|rf] are responsible of the end device critical value: 00 total service disruption for the customers 01 partial service disruption for the customers - some customers are working others not or the service is degr

[c-nsp] 12.2.33 SRC5 experiences?

2009-10-16 Thread luismi
how is the ios, any bug sev1 or interesting? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] AUDIT

2009-10-07 Thread luismi
nipper and rat (router audito tool) El mié, 07-10-2009 a las 13:20 +0530, jack daniels escribió: > Dear Group, > > I have been assigned to do AUDIT ( LAN / WAN ) for a NETWORK comprising of > devices 2950 , 3750 , 4500 , 2800 , 2600 , 7206 VXR . Please advice which > commands showuld I need to c

[c-nsp] Cisco 3750 Stack less disruptive EtherChannel configuration

2009-10-06 Thread luismi
Hi, We had a problem with a stack 3750 here and the configuration is.. Stack (2x3750) === FEC === SW 2960 It is a cross etherchannel configuration. 3750 is not working with L3 mode at all. The FEC config is "mode on". So, one the 3750 had a problem yesterday and it creates disruption in the con

[c-nsp] Recommendations for IOS 12.4T for 7206VXR NPE-G2

2009-10-06 Thread luismi
Any recommendation? Technologies used: BGP, EIGRP.VRF, RACL, ACL, uRPF, AAA, GRE. EtherChannel ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] OT: Juniper JTAC software download assistance - blown away by good customer service

2009-10-03 Thread luismi
Juniper has also great disccounts for certifications from 100%!! :D http://www.juniper.net/us/en/training/fasttrack/ El sáb, 03-10-2009 a las 14:58 +, Ramcharan, Vijay A escribió: > Like most other folks these days, I'm somewhat jaded when it comes to > expecting customer requests that fall o

[c-nsp] sliding window quota

2009-10-01 Thread luismi
Hi all, Any product from Cisco -or not- to manage sliding window BW quotas? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] Maybe Off.topic... VoIP wholesale carriers or just for south america

2009-09-29 Thread luismi
Hi, This an off-topic issue, sorry about it. I would like to know if you know some VoIP wholesale carriers or just for south america. Something like flowroute.com Thanks in advance and sorry by this email again. ___ cisco-nsp mailing list cisco-nsp@pu

Re: [c-nsp] IOS for 7206VXR, SRD2a or SRC4?

2009-09-21 Thread luismi
ld try this one > first.. > > > > > > > > ______ > From: luismi > To: Gert Doering > Cc: "cisco-nsp@puck.nether.net" > Sent: Monday, September 21, 2009 5:25:43 AM > Subject: Re: [

Re: [c-nsp] IOS for 7206VXR, SRD2a or SRC4?

2009-09-21 Thread luismi
yes, I know we are going to use... EIGRP, BGP, ACL, PBR, reflexive ACLs, HSRP, GRE tunnels, multicast, VRFs, EEM, SLA, SNMP, Netflow... I would like to go also for BFD, OSPF and/or MP-BGP in the future. ___ cisco-nsp mailing list cisco-nsp@puck.nether

[c-nsp] IOS for 7206VXR, SRD2a or SRC4?

2009-09-21 Thread luismi
Hi all, Any recommendation of an IOS for a 7206VXR? I was using the features navigator and I saw that SRD2a and SRC4 are mostly the same so, what are the differences between both of them? Thanks in advance. ___ cisco-nsp mailing list cisco-nsp@puck.ne

[c-nsp] service policy and reflexive ACL

2009-09-14 Thread luismi
Hi, We have a design issue here. We are not able to apply ACLs to create a reflexive ACL, so we are thinking on the idea to apply a outbound service policy in an interface and then build a reflexibe ACL based on the ACL matches of the service policy. Platform is 7600 Is that possible? ___

[c-nsp] PBR, order of operations for "set" directives ?

2009-09-09 Thread luismi
Hi all, We have an small issue here and we have over the table some workarounds and one them is related with the order of operations of the "set" directives under a route-map used for policy routing. In fact we would like to apply a code like this: route-map selectvrf permit 10 match ip address

Re: [c-nsp] Leaking specific routes from a VRF

2009-09-08 Thread luismi
Thanks for all the emails, we have created some code here with success :-D Thanks agains to everyone for the time and attention. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://p

Re: [c-nsp] Leaking specific routes from a VRF

2009-09-07 Thread luismi
Hi all, We are doing some tests here with the code provided by Tomas. We have several questions that we were not able to find a proper answer over internet that we would like to share with you to see if we can understand everything correctly: a) "ip prefix-list" has a parameter called "le" so we

Re: [c-nsp] Management stuff in VRFs

2009-09-02 Thread luismi
I have everything splitted. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] SXI, TACACS+ in VRF

2009-09-02 Thread luismi
did you tried "test aaa" command? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Leaking specific routes from a VRF

2009-09-02 Thread luismi
Many thanks :-D ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Leaking specific routes from a VRF

2009-09-02 Thread luismi
Hi all, I am interested too in this issue. Can you send some code as an example to see how it works? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cis

[c-nsp] PBR + ACL is not working as expected in a 7600

2009-08-28 Thread luismi
Hi all, We have here this configuration in the ACL: ip access-list extended AM_Pilotos_vuelta_acelerada permit tcp 88.84.89.240 0.0.0.3 any gt 1024 permit tcp 88.84.89.240 0.0.0.3 any eq ftp www With this config, the www traffic received on Gi1/1 doesn't match the acl (ftp www ACL) so the tra

Re: [c-nsp] %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Quick mode failed with peer at 11.22.33.44

2009-08-27 Thread luismi
First of all, Thanks to everyone, after a detailed review of my Cisco config as well several coffee I fixed it. The problem was some errors in the ACLs related with the crypto map. Now everything is ok :-D Thanks again. ___ cisco-nsp mailing list cis

[c-nsp] %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Quick mode failed with peer at 11.22.33.44

2009-08-27 Thread luismi
Hi all, I just configured a cisco 1841 to create a ipsec vpn against another network (exactly against a PFSense box) and I am seeing a lot messages like %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Quick mode failed with peer at 11.22.33.44 %CRYPTO-6-IKMP_MODE_FAILURE: Processing of Quick mode f

Re: [c-nsp] Audit tool for Cisco Config files

2009-08-27 Thread luismi
http://unix.freshmeat.net/projects/nipper ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] dns resolution not working with vrfs

2009-08-25 Thread luismi
#ping vrf FW2INET www.google.es Translating "www.google.es"...domain server (199.45.32.40) [OK] Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 64.233.169.99, timeout is 2 seconds: ! Success rate is 100 percent (5/5), round-trip min/avg/max = 116/119/120 ms quite interestin

[c-nsp] route-map based on NBAR to control passive ftp

2009-08-25 Thread luismi
Hi all, We have here an issue regarding PBR. We are not able -so far until right now- to change the routing policy using as a condition the passive ftp traffic. In other words... - Active FTP is being forwarded to vrf A by a "set vrf" condition (pretty easy using ACLs for TCP 20 and 21 ports) - P

Re: [c-nsp] Invitation to connect on LinkedIn

2009-08-25 Thread luismi
This should be notified to "fail blog" X-D ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] dns resolution not working with vrfs

2009-08-25 Thread luismi
Hi all, I tried this code: ip domain-lookup source-interface Port-channel1.92 ip name-server vrf FW2INET 199.45.32.40 ip name-server vrf FW2INET 151.202.0.85 ip name-server vrf FW2INET 151.202.0.84 And the test is... #ping www.google.es Translating "www.google.es"...domain server (255.255.255.255

Re: [c-nsp] Etherchannel between 2x2960 and 1x7600

2009-08-11 Thread luismi
I take note about your idea but I never worked with bvi interfaces and I should check that before in the lab. Thanks anyway :D ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://pu

Re: [c-nsp] Etherchannel between 2x2960 and 1x7600

2009-08-11 Thread luismi
Ok, thanks for the info, I think we will continue with our actual topology for a while :-D ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Etherchannel between 2x2960 and 1x7600

2009-08-11 Thread luismi
2960 doesn't support stack as far as I know. it could support cluster, I think. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Etherchannel between 2x2960 and 1x7600

2009-08-11 Thread luismi
Well, I would like to see if it could be possible to improve the HA, I didn't expect that 2960 had support for this idea. So far, the schema we have here is working ok without FEC. Just want to know if we could do it better. ___ cisco-nsp mailing list

[c-nsp] Etherchannel between 2x2960 and 1x7600

2009-08-11 Thread luismi
Hi all, I would like to know if it is possible to create an etherchannel between just 1 router 7600 and 2 switches 2960 connected between them by a trunk. The schema would be 2960---\ | \ Trunk FEC7600 | / 2960---/ Is it possible?

Re: [c-nsp] TACACs access filtered by device

2009-08-07 Thread luismi
Yes! seems to be pretty simple I will try it today :-D ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] TACACs access filtered by device

2009-08-07 Thread luismi
Hi, We don't use here ACS, just tacacs-server over linux. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

[c-nsp] TACACs access filtered by device

2009-08-07 Thread luismi
Hi, We have here several Cisco devices and I would like to know if it is possible to filter who get access to some specific devices using the tacacs.conf file or the AAA configuration inside the devices. Is that possible? ___ cisco-nsp mailing list ci

Re: [c-nsp] Counters for null0?

2009-08-05 Thread luismi
Yes it is being translated by NAT for sure, I am 110% sure about that. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Counters for null0?

2009-08-05 Thread luismi
Yes, this is a NAT scenario, maybe that is the reason. So far the router is working ok, and the service is ok too. So "null" value must be related with NAT or something similar. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.ne

Re: [c-nsp] Counters for null0?

2009-08-05 Thread luismi
I just configure a router here to use it but it is quite strange because I can see correct traffic routed to "null", and I didn't expect to see that, I don't think it is correct. #sho ip cache flow | incl Null Fa0/1.1 10.55.0.32 Null 208.67.222.222 11 0A2A 0035 1 Fa0/1.1

Re: [c-nsp] Counters for null0?

2009-08-05 Thread luismi
Yes, but I just can see the "output" counters growing up. Quite strange since null0 is not generating traffic and it has configured "no ip unreachables". El mié, 05-08-2009 a las 12:47 +0200, Arie Vayner (avayner) escribió: > Did you try looking at "show interface null0"? > I am not sure it works,

[c-nsp] Counters for null0?

2009-08-05 Thread luismi
Hi, is there any way to see how much traffic is going to null0 interface? I configured several routes to be forwarded to null0 and I would like to have some info about how much traffic is going there. If the IOS doesn't provide any information about it... is it possible to obtain that information u

[c-nsp] QoS Bandwidth Estimation feature in IOS

2009-07-10 Thread luismi
Is anyone here using "QoS Bandwidth Estimation"? I just ask it because I think it could be useful for our network here but I don't see clear how it works and I would like to share some dudes I have. As far as I understand, if I have this code: Router(config)# policy-map my-policy Router(config-p

Re: [c-nsp] Free NMS Tools

2009-07-03 Thread luismi
HMMM quite interesting... We use here NMIS. El sáb, 27-06-2009 a las 18:11 +0100, Adam Armstrong escribió: > > Dear All, > > > > Currently I looking for NMS ( Network Monitoring) tools which is Free Open > > source base. > > I need you suggestion. Currently I have more then 100 Cisco Routers and

[c-nsp] maybe a buffers issue, code to apply?

2009-06-23 Thread luismi
Hi all, We have some packet here in a 7206vxr -just moving around 60mbps-, it shows some problems with "sh buffers" I was using the output interpreter but it doesn't report the code neccesary to apply to the router, neither I can use "buffer tune automatic" since it is not supported in this IOS (

Re: [c-nsp] Any problems w/ 3750 IOS 12.2(46)SE?

2009-06-04 Thread luismi
What we saw with 12.2.(46) was a corruption of the "ifindex" file. We will go for 12.2(50) El mar, 02-06-2009 a las 16:45 +0930, Tom Lanyon escribió: > We are seeing consistent low TCP throughput over a dual gig > etherchannel between two stacks of 3x 3750G + 1x 3750E and > intermittent delays

Re: [c-nsp] Interface descriptions - what do you put in?

2009-05-25 Thread luismi
What we do here Area Code - Severity - Description Example: A - 00 - Gi0/1 FEC12 SW8 BT_Internet Where... A is IP team 00 is total service disruption if interface is down Gi0/1 FEC12 SW8 BT_Internet, remote end of the cable as type of traffic inside El vie, 22-05-2009 a las 07:00

Re: [c-nsp] 7600 eigrp offset-list problem

2009-05-13 Thread luismi
Same IOS here, similar code... We use under address-family... offset-list 0 out 25 Port-channel1.xxx We will take a look to the config after a reboot. We didn't reboot the router yet. Do you know if it is a well know bug? Did you open a SR to ask for a reason for this behaviour? El mié, 13-05

Re: [c-nsp] EEM event-manager and "event none" question.

2009-04-07 Thread luismi
te up). > That way you can run the 2nd applet manually which in turn should trigger the > 1st applet to run automatically. > Just keep an eye on any other consequences this manual track state change > might have on your router. > > -- > Tassos > > luismi wrote on 06/04/2009

[c-nsp] EEM event-manager and "event none" question.

2009-04-06 Thread luismi
I have this code... event manager applet A-EU-UP event track 10 state up action 1.0 syslog msg "Track 10 Up. Houston we don't have a problem" action 2.0 cli command "enable" action 3.0 cli command "conf t" action 4.0 cli command "" I tried to execute... # event manager run A-EU-UP Embedded

[c-nsp] IPSec tunnel between Cisco router and PFSense firewall.

2009-03-31 Thread luismi
Is there anyone with a template to connect a Cisco router to a PFSense firewall using IPSec? Well, I think any other template would be a good start point too. Thanks in advance. ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.

Re: [c-nsp] IP Address management software

2009-03-31 Thread luismi
e Bertrand escribió: > luismi wrote: > > We use here IPPlan. > > Us too. The only drawback is that it doesn't handle IPv6. > > Steve ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailma

Re: [c-nsp] IP Address management software

2009-03-31 Thread luismi
We use here IPPlan. El mar, 31-03-2009 a las 09:17 +0100, Gary Roberton escribió: > Hello all > > What IP address management software do you use to control the allocation of > subnets to your customers/department? > > Thanks > > Gary > ___ > cisco-nsp

Re: [c-nsp] 3750/3750E stack upgrade downtime?

2009-03-30 Thread luismi
Hi Peter, I agree with you but in that case you loose the option to use cross-etherchannel against the stack :-/ El lun, 30-03-2009 a las 22:45 +0200, Peter Rathlev escribió: > On Mon, 2009-03-30 at 16:20 -0400, Jeff Kell wrote: > > Is there any way to "roll" an upgrade out to a 3750 stack witho

Re: [c-nsp] Network Drawing tool

2009-03-18 Thread luismi
http://www.pacestar.com/lanflow/index.html I was working with it, it is cheap and IMHO very good software The only problem is that it doesn't support Visio stencils :-P I don't know if Pacestar guys have change that in the latest versions. El mar, 17-03-2009 a las 20:53 +0200, Mohammad Khalil esc

[c-nsp] Recommendation? USB to serial adapter working without problems under linux

2009-03-17 Thread luismi
Hi all, Any recommendation about a usb to serial adapter? We work with linux here in our laptops and some of the adapters we used in the past got stuck when they receive too much info very quickly (for example, messages from console) so I would like to know if you have some idea about any model or

Re: [c-nsp] Open Source solution to deploy a radius server against Cisco devices?

2009-03-09 Thread luismi
Hi all, As I can see there is just two options over the table: Freeradius and Radiator. Is there anyone here with any of them working against VPN Concentrators? I ask that because it would be the primary goal of the radius. El lun, 09-03-2009 a las 09:09 +, a.l.m.bu...@lboro.ac.uk escribió:

[c-nsp] Open Source solution to deploy a radius server against Cisco devices?

2009-03-07 Thread luismi
Hi all, I am looking for an open source solution to deploy some radius in our network. The primary goal is to connect to those radius to provide auth services: - The VPN Concentrators and vpn accounts (we would move all the vpn accounts info to the radius) - Validate ip http auth-proxy users Radi

Re: [c-nsp] Disabling "enable" command for users at privilege 0

2009-03-07 Thread luismi
Thanks it works perfectly for me :D El sáb, 07-03-2009 a las 02:27 +, Antonio Soares escribió: > privilege exec level 1 enable ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http:

[c-nsp] Disabling "enable" command for users at privilege 0

2009-03-06 Thread luismi
Is possible to disable "enable" command for users at privilege 0? ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] strange message at boot "Can't insert config node for vrf=default"

2009-03-03 Thread luismi
El mar, 03-03-2009 a las 12:13 -0500, Jared Mauch escribió: > On Tue, Mar 03, 2009 at 06:01:32PM +0100, luismi wrote: > > Hi all, > > > > I have here a 2960 switch with 12.2(46) lan base. > > After the switche has booted correctly I can see.. > > > > [..

[c-nsp] strange message at boot "Can't insert config node for vrf=default"

2009-03-03 Thread luismi
Hi all, I have here a 2960 switch with 12.2(46) lan base. After the switche has booted correctly I can see.. [...] % Can't insert config node for vrf=default Press RETURN to get started! What is the reason for the message "Can't insert config node for vrf=default"? Any idea? Thanks

[c-nsp] 3750 or 3560?

2009-01-13 Thread luismi
Hi, I have a stack based on two 3750 and a 2960 connected to that stack using a cross etherchannel. I have now a requirement and I need PVLANs but they are not supported in the 2960 (as far as I was reading at cisco.com) So, I am thinking on replace the 2960 but I am not sure if I should replace

  1   2   >