Re: [c-nsp] nexus 7K COPP ARP traffic?

2015-10-01 Thread schilling
is enabled by default. The default system-defined CoPP policy rate limits ARP broadcast packets bound for the supervisor module. The default system-defined CoPP policy prevents an ARP broadcast storm from affecting the control plane traffic but does not affect bridged packets. Best, Schilling

Re: [c-nsp] Is Inter-AS option B supported on Catalyst 6500 SXI code?

2012-03-28 Thread schilling
Thanks all for the advice. I figured out with TAC. The label is filtered by my label advertisement filter. Schilling On Wed, Mar 28, 2012 at 12:49 PM, Saku Ytti s...@ytti.fi wrote: On (2012-03-27 14:00 -0400), schilling wrote: I am trying to have catalyst 6500 w/ sup720 3BXL with 12.2(33

[c-nsp] Is Inter-AS option B supported on Catalyst 6500 SXI code?

2012-03-27 Thread schilling
I am trying to have catalyst 6500 w/ sup720 3BXL with 12.2(33)SXI5 to support ASBR exchanging VPN-IPv4, but 6500 is not allocating labels for prefixes learned from eBGP over address family vpnv4. Does anybody ever have this working? Any catch? Thanks, Schilling

Re: [c-nsp] Is Inter-AS option B supported on Catalyst 6500 SXI code?

2012-03-27 Thread schilling
In my case, I happened to have the vrf and route-target configured on the ASBR. schilling On Tue, Mar 27, 2012 at 2:12 PM, Brandon Ewing nicot...@warningg.com wrote: On Tue, Mar 27, 2012 at 02:00:17PM -0400, schilling wrote: I am trying to have catalyst 6500 w/ sup720 3BXL with 12.2(33)SXI5

Re: [c-nsp] Private VLANs for customer isolation on sup720/12.2(33)

2011-04-19 Thread schilling
vlan, and the end with access vlan 141 to be promisc port. So you have to use a loopback cable and two ports. Foundry/Brocade is the same way too. Schilling On Tue, Apr 19, 2011 at 9:38 AM, Phil Mayers p.may...@imperial.ac.uk wrote: All, We've got a pair of Cisco 6500/sup720 serving as our

Re: [c-nsp] Large scale central services VRF, best practice?

2011-03-18 Thread schilling
import 1:3 ! ip vrf Central_Services rd 1:3 route-target both 1:3 route-target import 1:1 route-target import 1:2 Schilling On Fri, Mar 18, 2011 at 9:04 AM, Peter Rathlev pe...@rathlev.dk wrote: Is there any smart way configure an MPLS VPN network for a central

Re: [c-nsp] GRE tunnel flapping every 15 minutes

2011-02-16 Thread schilling
destination. I am now leaning toward routing issue within Comcast or cable modem issue. Thanks, Schilling On Wed, Feb 16, 2011 at 2:36 PM, Quinn Kuzmich lostinmos...@gmail.com wrote:  I had a similar issue with one of my tunnels, and it turned out to be bad hardware on one end. Q On Mon, Feb 14

[c-nsp] GRE tunnel flapping every 15 minutes

2011-02-14 Thread schilling
. Just upgraded the ISR871 to be running latest c870-advipservicesk9-mz.124-24.T4.bin, but the issue persists. We already tried reboot the modem and reboot the switch. Any insight? Thanks, Schilling ___ cisco-nsp mailing list cisco-nsp@puck.nether.net

Re: [c-nsp] EoMPLS or VPLS loop prevention/storm control

2011-02-10 Thread schilling
Thanks all for the insights and recommendations. I really appreciate it. Schilling On Wed, Feb 9, 2011 at 3:26 PM, Nick Hilliard n...@foobar.org wrote: On 09/02/2011 19:10, schilling wrote: I am familiar with these features. I talked with Cisco TAC several times, they are not recommending

[c-nsp] EoMPLS or VPLS loop prevention/storm control

2011-02-09 Thread schilling
will happen if we have a loop in one of the VLAN? The simple loop is to have a dump switch, connected two ports of it together. Thanks, Schilling ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive

Re: [c-nsp] EoMPLS or VPLS loop prevention/storm control

2011-02-09 Thread schilling
address might be helpful, but will not be useful for a hub. So there is no good way to prevent rogue hub/switch from messing with our network? So the best we can do is to reduce the fault domain, if something messed up, just let it mess up a small area of network? Schilling On Wed, Feb 9, 2011 at 1

Re: [c-nsp] Opinions about the next 6500/7600

2011-02-05 Thread schilling
support. Schilling On Sat, Feb 5, 2011 at 4:51 PM, Gert Doering g...@greenie.muc.de wrote: Hi, On Sat, Feb 05, 2011 at 12:35:48PM +, Nick Hilliard wrote: [ 6500 ] Personally, I'm not sad to see it replaced. Well, neither am I - but then, I don't really want to buy three different boxes

Re: [c-nsp] PVLAN Question

2011-01-11 Thread schilling
end of the loopback cable will be access vlan 141. You can then set vlan 141 to be your primary vlan, and the end with access vlan 141 to be promisc port. So you have to use a loopback cable and two ports. Foundry/Brocade is the same way too. Schilling On Tue, Jan 11, 2011 at 7:57 PM, Sam Evans

Re: [c-nsp] Site to Site VPN using ASA and far end with dynamic peer

2011-01-06 Thread schilling
You have ASA/IOS routers on the branch office, right? Cisco Easy VPN Remote Client might be what you are looking for. You can use client mode or network extension mode according to your need. http://www.cisco.com/en/US/products/sw/secursw/ps5299/index.html Schilling On Thu, Jan 6, 2011 at 6:46

Re: [c-nsp] Storm-Control on server switch uplinks.

2010-08-26 Thread schilling
%*1000,1000,1000/(64*8) = 1562 pps 174 0.16%*1000,1000,1000/(64*8) = 3152 pps 350 0.48% 9456 pps 1051pps Which one do you think make more sense? Schilling On Tue, Aug 24, 2010 at 4:27 AM, Saku Ytti s...@ytti.fi wrote: On (2010

[c-nsp] Remote Parking Gates VPN to Campus Network with 3G

2010-04-13 Thread schilling
thought on any device with integrated VPN client and 3G? Or what will you do with similar project? Thanks, Schilling ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net

Re: [c-nsp] Remote Parking Gates VPN to Campus Network with 3G

2010-04-13 Thread schilling
We talked about 880s, but the environmental operating rage of nonoperating temperature -4 to 149F is not that promising give that we are in Florida :-) and these parking gates are exposed outside and in a mental box. Schilling On Tue, Apr 13, 2010 at 10:29 AM, Luan Nguyen l...@netcraftsmen.net

Re: [c-nsp] BGP to OSPF redistribution

2010-01-13 Thread schilling
I don't think sham link will work in this case either. You are running ebgp with provider A? You are only concerned that your ibgp routes from other sites, right? change the ibgp administrative distance to be lower than 110 might work for you. Schilling On Wed, Jan 13, 2010 at 4:03 PM, null

[c-nsp] Is Nachi Worm Mitigation Measure Still Necessary in Campus?

2009-05-27 Thread schilling
, it is recommended to have the ip route-cache policy command on the interface. This increases the performance of PBR. warning Warning:�Microsoft Windows tracert utility uses 92-byte sized ICMP packets. Using PBR to filter those packets causes the tracert utility not to work. Thanks, Schilling

Re: [c-nsp] Blocking bad users based on MAC Address

2009-03-24 Thread schilling
You can just do mac-address-table static 0016.6f99.9e61 vlan 3030 drop. Schilling On Tue, Mar 24, 2009 at 3:42 PM, Rick Coloccia coloc...@geneseo.edu wrote: Is anyone doing anything like this in a Catalyst 6500?  I'm running a sup 720 with ios 12.2(33)SXH4. I have a bad user that I need

Re: [c-nsp] SXI high cpu usage and rp inband SPAN feature not available

2009-03-17 Thread schilling
My bad. The RP SPAN is available on SXI. It turns out that the existing monitor session will not have type option available. I configured to have a monitor session 1 destination interface first as it is for SXF before trying the monitor session 1 ? Schilling On Mon, Mar 16, 2009 at 4:42 PM

[c-nsp] SXI high cpu usage and rp inband SPAN feature not available

2009-03-16 Thread schilling
SPAN source VLAN test#remote login switch Trying Switch ... Entering CONSOLE for Switch Type ^C^C^C to end this session test-sp#monitor ? elog Event-logging control commands event-trace Control event tracing test-sp#test monitor ? crash test crash Schilling

[c-nsp] Cisco ACL Manager 1.6 Broke after enable MPLS

2009-03-13 Thread schilling
-loopbacks-only Then enabled mpls ip on backbone vlans. I sniffed the traffic of working one, ACL manager is using snmp and tftp to change the router configuration in our environment. Could somebody give some insight on this? Thanks. Schilling

Re: [c-nsp] Export routes from VRF to the global routing table

2009-03-03 Thread schilling
If you have loopback cable on the same router, or vlan between two different routers, you could potentially run a IGP routing protocol for example ospf on the same network while using different context/process on each end to exchange routes. Schilling On Mon, Mar 2, 2009 at 8:08 PM

Re: [c-nsp] Redistribution on ASA Firewall using route-map

2009-02-26 Thread schilling
Yes, you can do the prefix-list. Schilling On Thu, Feb 26, 2009 at 12:32 PM, tkacprzyn...@spencerstuart.com wrote: Hello, I'm trying to accomplish redistribution between two OSPF processes (100 and 175) using a route-map with an access-list on an ASA 8.0. Can't seem to get it working

Re: [c-nsp] VRF and STATIC ROUTE to GLOBAL

2009-02-23 Thread schilling
. Existing more specific traffic will be routed in your VRF ESNET, and non specific are dropped. Schilling On Mon, Feb 23, 2009 at 10:55 AM, Jeff Fitzwater jf...@princeton.eduwrote: This question was posted earlier, before I opened ticket with CISCO. Router is 6500 with 720-CXL running SXI code. 1

Re: [c-nsp] VRF and STATIC ROUTE to GLOBAL

2009-02-23 Thread schilling
. Schilling On Mon, Feb 23, 2009 at 2:41 PM, Jeff Fitzwater jf...@princeton.edu wrote: On Feb 23, 2009, at 1:59 PM, schilling wrote: I am not clear about your route-map match subs, set vrf. If your two specific subnets are in one campus core, you need to put them in to VRF ESNET by ip

Re: [c-nsp] Mpls Troubleshooting Question

2009-02-23 Thread schilling
check no ip unreachable on the PE interface? I got bite once. verify the LSP? Ivan's blog for rescue :-) http://wiki.nil.com/PE-to-PE_troubleshooting_in_MPLS_VPN_networks Schilling On Mon, Feb 23, 2009 at 4:51 PM, Rocker Feller rocker.rockerfel...@gmail.com wrote: Hi, I work in an ISP

[c-nsp] Cisco Hard Copy Configuration Guides and Command References

2009-02-11 Thread schilling
printed materials from Cisco with no charge given that we have a lot of cisco equipments and smartnet? Thanks. Schilling ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http

Re: [c-nsp] VRF and BGP ?

2009-02-10 Thread schilling
support static route. Schilling On Tue, Feb 10, 2009 at 1:29 AM, JH Cockburn ccie15...@gmail.com wrote: Hi All, We had a similar situation where we had to create an internet vrf and leak/connect that to the global routing table. So we had a couple of interfaces belonging to the internet vrf

Re: [c-nsp] MPLS-VPN migration

2008-12-26 Thread schilling
from one VRF to another? Thanks. Schilling On Thu, Dec 18, 2008 at 3:12 AM, Aaron Daniels - Lists li...@daniels.id.auwrote: We just tackled this one in our organisation. 2 Gotchas. 1. Router-id must be different between peers, make sure your code supports vrf specific router-id. 2. iBGP

[c-nsp] PACL RACL and SPAN in Catalyst 6500?

2008-05-20 Thread schilling
remove the same ACL from L3 SVI and apply it to physical interface as PACL, then span the SVI, will we be able to get spanned traffic after the PACL? Thanks. Schilling ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https://puck.nether.net/mailman

Re: [c-nsp] Port Traceroute utility?

2007-11-06 Thread schilling
http://traceproto.sourceforge.net/ Traceproto is a traceroute replacement written in c that allows the user to specify the protocol and port to trace to. It currently supports tcp, udp, and icmp traces with the possibility of others in the future. On 11/6/07, Peter Fiers [EMAIL PROTECTED] wrote:

Re: [c-nsp] Redundant default route, without round-robin routing

2007-09-28 Thread schilling
implemented by a route-map. If customer border routers are directly connected, things are very hard to go wrong. schilling On 9/27/07, Dario [EMAIL PROTECTED] wrote: Dear all, I've configured something similar a few days ago with one customer running OSPF as internal protocol. We've

[c-nsp] TCP throttle on directly connected 10G 9000 MTU 8940 MSS

2007-07-12 Thread schilling
04 07 WRR 04 08 Priority 01 show queueing did not show any drop on any queue. on vlan input queue, there is some drops/flushes, but no any drops. Any suggestion will be greatly appreciated. schilling

Re: [c-nsp] ip multicast boundary

2007-06-20 Thread schilling
Here is my multicast boundary: ip access-list standard multicast-boundary deny 224.0.1.39 deny 224.0.1.40 deny 239.0.0.0 0.255.255.255 permit any any Please refer to http://www.abilene.iu.edu/i2network/multicast-cookbook.html schilling On 6/20/07, Sergey Velikanov [Intelsoft] [EMAIL

[c-nsp] Recommendation needed for 2G compact flash card used for Catalyst 6500 SUP720-3BXL

2007-06-20 Thread schilling
Hi, Would sombody recommend some brands of 2G compact flash? It will be used for SUP720-3BXL on catalyst 6500 series. Please also share non compatible 2G flash experience. Thanks. schilling ___ cisco-nsp mailing list cisco-nsp@puck.nether.net https