Re: [c-nsp] Port Channel Speed

2015-05-11 Thread ryanL
i think he means the port channel is showing as 10GE, even though he's got 2x10GE interfaces in the bundle. On Mon, May 11, 2015 at 9:18 AM, Justin M. Streiner strei...@cluebyfour.org wrote: On Mon, 11 May 2015, sathish kumar Ippani wrote: Here when we checked the sh int portchannel 1. it

Re: [c-nsp] asa 5510, remote access vpn, resources across lan-to-lan

2014-09-02 Thread ryanL
Kougoulos john.kougou...@gmail.com Date: Monday, 1 September 2014 16:24 To: ryanL ryan.lan...@gmail.com Cc: cisco-nsp@puck.nether.net NSP cisco-nsp@puck.nether.net Subject: Re: [c-nsp] asa 5510, remote access vpn, resources across lan-to-lan Resent-From: Steve Housego steve.hous...@it-ps.com

[c-nsp] asa 5510, remote access vpn, resources across lan-to-lan

2014-09-01 Thread ryanL
hi, i'm hopefully going to find someone who's done this before, or who has better google-fu than me. asa is not my strong suit. i have users vpn'ing (ipsec) into one 5510, accessing various corp resources there. the vpn pool isn't routed - i just nat it to one of the various inside interfaces

Re: [c-nsp] Stacking 3750X vs diverse 4948E

2012-05-22 Thread ryanL
on a similar note, how do people address the situation of a server doing bond0 to two different top of rack switches, and a switch uplink fails? in this situation, the two tor switches are not connected (i dislike spanning tree). the bond0 interface can't see that uplink failure, and would

Re: [c-nsp] FWSM ACL présidence ? ACL not blocking traffic

2012-04-25 Thread ryanL
what access-list commit mode are you using? my preferred practice is manual commit mode, but make changes on tftp server to acl and then upload entire acl with copy tftp running. at the start of the script is access-list mode manual and clear configure access-list blah. at the end of the script

[c-nsp] mac flapping on 6509 between core and fwsm

2012-04-19 Thread ryanL
does anyone know what would cause this? po30 uplinks to a core router, and po579 is the internal etherchannel assignment for the fwsm. the fwsm is bridging. the 6509 is spanning-tree root for the vlan. vl1250 is the outside interface. the mac in question is core router, configured as po30.1250.

Re: [c-nsp] mac flapping on 6509 between core and fwsm

2012-04-19 Thread ryanL
On Thu, Apr 19, 2012 at 5:54 PM, Randy randy_94...@yahoo.com wrote: --- On Thu, 4/19/12, Mario Ruiz mruiz...@gmail.com wrote: Who is reporting the mac-flaps - the 6509 with fwsm OR fwsm itself? it appears that you are seeing it on the 6509 that has the fwsm? if that is the case, the an

Re: [c-nsp] ISSU on VSS

2011-06-21 Thread ryanL
there is indeed ISSU for VSS, even with single supervisor models. i recently upgraded from sxi2a to sxi6 with no noticeable impact if you do it right. that said, you do lose 50% of your cluster capacity. so i guess it depends on your interpretation/requirement for ISSU ;-) on the flip, i can

Re: [c-nsp] MLS rate limit logging ??

2011-03-31 Thread ryanL
+1. i fought in vain for this as well. there's no way that i know of to see if the limiters are being hit, other than some likely hidden command. would love to know if someone has it! On Thu, Mar 31, 2011 at 10:35 AM, Jeff Fitzwater jf...@princeton.edu wrote: Is there a way to log MLS

Re: [c-nsp] Serial lead

2011-03-29 Thread ryanL
screen /dev/tty still works ;-) otherwise: http://www.furrysoft.de/?page=goserial On Tue, Mar 29, 2011 at 12:26 PM, Wil Schultz wschu...@bsdboy.com wrote: On Mar 29, 2011, at 6:41 AM, christopher.mar...@usc-bt.com christopher.mar...@usc-bt.com wrote: but when connected to a FreeBSD laptop

Re: [c-nsp] Is this QoS config possible in 7600 with WS-X6724-SFP?

2011-03-27 Thread ryanL
we've had success putting voice into the priority queue on 6724 ports, but in a routed topology. you still might want to look into these port-level features: priority-queue queue-limit x priority-queue cos-map x On Sat, Mar 26, 2011 at 4:12 PM, Peter Olsson p...@leissner.se wrote: We usually

Re: [c-nsp] Duplicate the packets

2011-03-25 Thread ryanL
sounds like windows NLB or something to me...? so a combination of static arp addressing perhaps to a multicast mac address, and disable any igmp snooping? it isn't really multicast, per se. you are being a bit vague... perhaps intentionally. (fair enough). On Fri, Mar 25, 2011 at 4:02 AM,