From arnolditya at hotmail.com Wed Apr 1 01:30:10 2009 From: arnolditya at hotmail.com (arnoldus Subiyanto) Date: Wed, 1 Apr 2009 13:30:10 +0800 Subject: [c-nsp] BGP convergence Message-ID: Hello.. I'am is new member here.. My name aditya from bali-indonesia.. I want to conduct research to examine the speed of convergence in BGP. What's his friends all know that there is software that can be used to view the update process of the BGP routing table. things that i want to know is : 1. Large table; 2. Large memory is used; 3. Speed peering; 4. AS-PATH length Or in cisco router have command to see that ? One more,, whether there is a standard speed needed to make a BGP router convergence? thanks for your help .. _________________________________________________________________ See all the ways you can stay connected to friends and family http://www.microsoft.com/windows/windowslive/default.aspx From gert at greenie.muc.de Wed Apr 1 02:22:09 2009 From: gert at greenie.muc.de (Gert Doering) Date: Wed, 1 Apr 2009 08:22:09 +0200 Subject: [c-nsp] 3750/3750E stack upgrade downtime? In-Reply-To: <1238536244.3604.0.camel@localhost.localdomain> References: <49D1297B.2080106@utc.edu> <1238445916.4440.7.camel@localhost.localdomain> <1238536244.3604.0.camel@localhost.localdomain> Message-ID: <20090401062209.GG290@greenie.muc.de> Hi, On Tue, Mar 31, 2009 at 11:50:44PM +0200, Peter Rathlev wrote: > On Tue, 2009-03-31 at 22:44 +0200, Dirk-Jan van Helmond wrote: > > I've asked my accountmanager @Cisco, so you please ask yours. Maybe if > > we ask kind enough, they will think about it ;) > > Yeah, that usually works like a charm. Remember BFD for SVIs? ;-) Gah. I had all forgotten about it... gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From sandmaier at schlund.net Wed Apr 1 02:44:33 2009 From: sandmaier at schlund.net (Jan Sandmaier) Date: Wed, 01 Apr 2009 08:44:33 +0200 Subject: [c-nsp] 10GE card for 7609 In-Reply-To: References: <863386.41277.qm@web44809.mail.sp1.yahoo.com> Message-ID: <49D30D51.4060304@schlund.net> Geoffrey Pendery schrieb: > The stuff we've been reading (look at "Supervisor Engines Supported" > on the data sheets for "Cisco Catalyst 6500 Series 10 Gigabit Ethernet > Interface Modules", or browse the line cards for the 7600, or go into > Configurator tool) claims that the RSP 720 won't support the X6704 or > X6708 10 Gig "LAN" cards, only the SIP/SPA/ES "WAN" type cards. > > I don't mean to kick off a big "6500 vs 7600" storm again, but does > anyone know if this is incorrect? > Can we buy a new 7609-S chassis, put a new RSP 720 in it, put 7600 IOS > on that Sup, then plug in a WS-X6708-10G-3C and have it work? > X6708-10G-3C works definitly. X6704 also. You have to check the release notes or software advisor for the suitable IOS. Jan > > -Geoff > > > On Mon, Mar 30, 2009 at 4:41 AM, Mark Tech wrote: > >> Hi >> I have a prospect for a 10G upstream customer and Upstream ISP connections. I would need to connect these into our 7609s running RSP 720-3CXL's, at the moment I have found that the WS-X6704-10GE card may be suitable. >> >> My technical requirements are: >> 10Gbps line rate >> IPv4 >> Able to handle full Internet routing table >> Potentially IPv6 and MPLS in the future >> >> With the WS-X6704-10GE, there seems to be several options that are available with it i.e. >> >> Memory Option: >> MEM-XCEF720-256M >> Catalyst 6500 256MB DDR, xCEF720 (67xx interface, DFC3A) >> MEM-XCEF720-512M >> Cat 6500 512MB DDR, xCEF720 (67xx interface, DFC3A/DFC3B) >> MEM-XCEF720-1GB >> Catalyst 6500 1GB DDR, xCEF720 (67xx interface, DFC3BXL) >> >> ==================================================== >> Distributed Forwarding Card Option >> >> WS-F6700-CFC >> Catalyst 6500 Central Fwd Card for WS-X67xx modules >> WS-F6700-DFC3B >> Catalyst 6500 Dist Fwd Card, 256K Routes for WS-X67xx >> WS-F6700-DFC3A >> Catalyst 6500 Dist Fwd Card for WS-X67xx modules >> WS-F6700-DFC3BXL >> Catalyst 6500 Dist Fwd Card- 3BXL, for WS-X67xx >> WS-F6700-DFC3C >> Catalyst 6500 Dist Fwd Card for WS-X67xx modules >> WS-F6700-DFC3CXL >> Catalyst 6500 Dist Fwd Card- 3CXL, for WS-X67xx >> >> I assume that I would need MEM-XCEF720-1GB and WS-F6700-DFC3CXL? >> >> Regards >> >> Mark >> >> >> >> >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > -- Jan Sandmaier Network Engineer 1und1 Internet AG Mail: jan.sandmaier at 1und1.de Brauerstrasse 48 Tel.: +49 721/91374-4213 D-76135 Karlsruhe Fax : +49 721/91374-212 http://www.1und1.de (AS8560) Handelsregister Amtsgericht Montabaur, HRB 6484 USt-IdNr. DE811247114 Vorstand: Henning Ahlert, Ralph Dommermuth, Matthias Ehrlich, Thomas Gottschlich, Matthias Greve, Robert Hoffmann, Markus Huhn, Oliver Mauss, Achim Weiss Aufsichtsratsvorsitzender: Michael Scheeren From asad747 at cyber.net.pk Wed Apr 1 03:56:04 2009 From: asad747 at cyber.net.pk (Asad Ul-Islam) Date: Wed, 01 Apr 2009 12:56:04 +0500 Subject: [c-nsp] Problem with L2TP !! Message-ID: <002801c9b29f$4e94d250$ebbe76f0$@net.pk> Dear friends! I am trying to establish a L2TP tunnel between a LAC (Which is also Acting as BRAS) and LNS (Which is also acting as BRAS). User ---------[Cisco 3640 LAC]----- IP Cloud-------[Cisco 3845 LNS] The problem I am facing is that the scenario is working fine as long as I am using user account created locally on LNS. However as soon as I enable radius parameters, LAC stops establishing tunnel with LNS and connects the user on LAC as pppoe user. After investigation I have found that If I remove following line from the configuration L2TP Tunnels works perfectly fine; aaa authorization network default group radius Can someone tell me Why its happening?? Since I am using @domain in user ids for L2TP users, LAC should not even refer to Radius. And I need this aaa authorization parameter since both my LAC and LNS also have PPPoE users terminated on them. Following is my LAC and LNS configuration after including my radius parameteres, same configuration works fine without radius parameters. LAC Configuration aaa authentication login default local aaa authentication ppp default group radius local aaa authorization network default group radius local aaa accounting delay-start aaa accounting session-duration ntp-adjusted aaa accounting update periodic 15 aaa accounting network default start-stop group radius aaa nas port extended aaa session-id common ! ip cef vpdn enable vpdn multihop ! vpdn-group 1 request-dialin protocol l2tp multihop hostname DSL-LNS domain cybernet initiate-to ip 1.1.1.1 source-ip 2.2.2.2 local name DSL-LAC no l2tp tunnel authentication ! bba-group pppoe global virtual-template 1 ! interface Serial2/1 description *** Connected to LNS *** ip address 2.2.2.2 255.255.255.252 encapsulation ppp interface ATM3/0.2 multipoint pvc vpdn 0/36 encapsulation aal5snap protocol pppoe group global interface Virtual-Template1 ip unnumbered Serial2/1 peer default ip address pool home-dsl ppp authentication pap LNS Configuration aaa authentication login default local aaa authentication ppp default group radius local aaa authorization network default group radius aaa accounting delay-start aaa accounting session-duration ntp-adjusted aaa accounting update periodic 15 aaa session-id common ! vpdn enable vpdn multihop ! vpdn-group 1 accept-dialin protocol l2tp virtual-template 1 terminate-from hostname DSL-LAC local name DSL-LNS lcp renegotiation on-mismatch no l2tp tunnel authentication ! interface GigabitEthernet0/1.7 description *** LAC Management *** encapsulation dot1Q 7 ip address 1.1.1.1 255.255.255.252 ! interface Virtual-Template1 ip unnumbered GigabitEthernet0/1.7 peer default ip address pool PPPoE ppp authentication pap From alex at alexfisher.me.uk Wed Apr 1 05:42:52 2009 From: alex at alexfisher.me.uk (Alexander Fisher) Date: Wed, 1 Apr 2009 10:42:52 +0100 Subject: [c-nsp] dhcprelay regression on latest pix 515 firmware (8.0.4) Message-ID: <5449aac20904010242q65b3cbd3o69e7ee56c95d749@mail.gmail.com> Hi I've uncovered a problem with the latest pix 515 firmware (asa-8.0.4) which didn't exist in 8.0.3. The dhcprelay function no longer works in some circumstances. Specifically, I can no longer do automated linux client installs over the network (FAI). The initial dhcp at pxeboot time works fine, but the later dhcp operation after kernel boot fails. The client sends a DHCP Request and this gets relayed to the server without problems, but the returned DHCP Ack is not forwarded back to the client. Turning on debug dhcprelay error etc gives... DHCPRA: relay binding created for client 001d.09fa.6f13. DHCPD: setting giaddr to 192.168.63.1. dhcpd_forward_request: request from 001d.09fa.6f13 forwarded to shadowcat. DHCPD/RA: Punt shadowcat/17152 --> 192.168.63.1/17152 to CP DHCPRA: Received a BOOTREPLY from interface 2 DHCPRA: relay binding found for client 001d.09fa.6f13. DHCPRA: Adding rule to allow client to respond using offered address dmz2 DHCPRA: forwarding reply to client 001d.09fa.6f13. DHCPRA: relay binding found for client 001d.09fa.6f13. DHCPD: setting giaddr to 192.168.63.1. dhcpd_forward_request: request from 001d.09fa.6f13 forwarded to shadowcat. DHCPD/RA: Punt shadowcat/17152 --> 192.168.63.1/17152 to CP DHCPRA: Received a BOOTREPLY from interface 2 DHCPRA: relay binding found for client 001d.09fa.6f13. DHCPRA: exchange complete - relay binding deleted for client 001d.09fa.6f13. DHCPD: returned relay binding 192.168.63.1/001d.09fa.6f13 to address pool. dhcpd_destroy_binding() removing NP rule for client 192.168.63.1 DHCPRA: forwarding reply to client 001d.09fa.6f13. DHCPRA: Can't Create binding DHCPD: setting giaddr to 192.168.63.1. dhcpd_forward_request: request from 001d.09fa.6f13 forwarded to shadowcat. DHCPD/RA: Punt shadowcat/17152 --> 192.168.63.1/17152 to CP DHCPRA: Received a BOOTREPLY from interface 2 DHCPRA: dhcp_relay_agent_receiver:can't find binding DHCPRA: Can't Create binding DHCPD: setting giaddr to 192.168.63.1. dhcpd_forward_request: request from 001d.09fa.6f13 forwarded to shadowcat. DHCPD/RA: Punt shadowcat/17152 --> 192.168.63.1/17152 to CP DHCPRA: Received a BOOTREPLY from interface 2 DHCPRA: dhcp_relay_agent_receiver:can't find binding DHCPRA: Can't Create binding DHCPD: setting giaddr to 192.168.63.1. dhcpd_forward_request: request from 001d.09fa.6f13 forwarded to shadowcat. DHCPD/RA: Punt shadowcat/17152 --> 192.168.63.1/17152 to CP DHCPRA: Received a BOOTREPLY from interface 2 DHCPRA: dhcp_relay_agent_receiver:can't find binding Googling turned up nothing, so hopefully this post might be of help to someone. Does anybody know what could cause the "DHCPRA: Can't Create binding" error? Kind Regards, Alex From lists at memetic.org Wed Apr 1 05:12:03 2009 From: lists at memetic.org (Adam Armstrong) Date: Wed, 01 Apr 2009 10:12:03 +0100 Subject: [c-nsp] 6500/7600 Pseudowires Message-ID: <49D32FE3.9050806@memetic.org> Hi All, I have a pseudowire running between an IX and my peering router in another country. There's a SIP600 in a 7606/SUP7203B at the far end facing the IX and a WS-X6748-GE-TX + DFC3B in a 7613/SUP7203B at this end facing the peering router. The local 7613 is connected to the remote 7606 with a pair of long GE links. Occasionally something along the chain reflects a couple of frames back to the IX, who shuts the port down automatically (killing off all of my peering sessions!) Has anyone had anything similar, and found out the cause for it? I can verify that neither the IS-IS route to the 7606 nor the LSP for the pseudowire was changed during the issue. Thanks, adam. From linux.yahoo at gmail.com Wed Apr 1 06:26:16 2009 From: linux.yahoo at gmail.com (Manu Chao) Date: Wed, 1 Apr 2009 12:26:16 +0200 Subject: [c-nsp] how to filter some specific logging message Message-ID: <7100ed370904010326n1e1a28b1i5def36ee24348037@mail.gmail.com> Is it possible to filter some specific syslog message with logging filter command or with logging discriminator? There are some "cosmetic" bugs that I need to filter... Example: i don't want the specific message message including "fem" to be sent to my remote syslog server. I try that configuration but no way :( may be a syntax problem may be not possible to filter? logging discriminator nolog msg-body drops *fem logging host x.x.x.x discriminator nolog Thanks for your help From ioan.branet at gmail.com Wed Apr 1 06:29:14 2009 From: ioan.branet at gmail.com (Ioan Branet) Date: Wed, 1 Apr 2009 13:29:14 +0300 Subject: [c-nsp] Cisco 3750 high CPU utilization HL3U bkgrd] In-Reply-To: <257d19980903310543n644d75fdsff69326f6bc1ca2f@mail.gmail.com> References: <257d19980903310543n644d75fdsff69326f6bc1ca2f@mail.gmail.com> Message-ID: <257d19980904010329p640a27b5yf9c5fbdf47ed98e6@mail.gmail.com> Hello All, Have you encountered a similar situation? Thank you, On Tue, Mar 31, 2009 at 3:43 PM, Ioan Branet wrote: > Hello, > > We have many Cisco 3750 switches in our network which have high CPU > utilization.It seems that the process that cause this high load is:HL3U > bkgrd process. > > The problem is solved after a reload but appears again after 3-4 months. > > We changed also the IOS but with no results. > > It seems that it is a bug but I am not very sure. > > > > sh processes cpu sorted | ex 0.00 > CPU utilization for five seconds: 99%/28%; one minute: 85%; five minutes: > 81% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > 108 389775804 4389443 88799 57.57% 40.01% 39.39% 0 HL3U bkgrd > proce > 58 11854779 72185839 164 3.50% 2.77% 2.31% 0 HLFM address > lea > 292 689 192 3588 1.91% 0.33% 0.07% 1 Virtual > Exec 47 12845296 2142151 5996 1.11% 1.00% 1.04% 0 FE > free chunk 245 17376827 532655 32623 0.63% 0.51% 0.52% 0 > MFI LFD Stats Pr > 107 5476276 58476944 93 0.63% 0.62% 0.58% 0 Hulc LED > Process > 74 768210 21312879 36 0.31% 0.09% 0.08% 0 hpm main > process > 135 6540410 20282165 322 0.15% 0.18% 0.22% 0 IP > Input 143 3566619 27781902 128 0.15% 0.24% 0.20% 0 > Spanning Tree 45 1004640 128285520 7 0.15% 0.15% 0.13% > 0 Fifo Error Detec > 138 1152329 2735155 421 0.15% 0.13% 0.12% 0 PI MATM Aging > Pr > > > sh version > Cisco IOS Software, C3750ME Software (C3750ME-I5-M), Version 12.2(37)SE1, > RELEASE SOFTWARE (fc1) > Copyright (c) 1986-2007 by Cisco Systems, Inc. > Compiled Thu 05-Jul-07 20:06 by antonino > Image text-base: 0x00003000, data-base: 0x0163F400 > > ROM: Bootstrap program is C3750 boot loader > BOOTLDR: C3750ME Boot Loader (C3750ME-HBOOT-M) Version 12.1(14r)AX, RELEASE > SOFTWARE (fc1) > > vic102 uptime is 4 weeks, 4 days, 10 hours, 9 minutes > System returned to ROM by power-on > System restarted at 03:01:54 GMT Fri Feb 27 2009 > System image file is "flash:c3750me-i5-mz.122-37.SE1.bin" > > cisco ME-C3750-24TE (PowerPC405) processor (revision F0) with > 118784K/12280K bytes of memory. > Processor board ID CAT1043NM05 > Last reset from power-on > 8 Virtual Ethernet interfaces > 24 FastEthernet interfaces > 4 Gigabit Ethernet interfaces > The password-recovery mechanism is enabled. > > 1024K bytes of flash-simulated non-volatile configuration memory. > Base ethernet MAC Address : 00:19:E8:87:23:00 > Motherboard assembly number : 73-9938-04 > Motherboard serial number : CAT104356B7 > Model revision number : F0 > Motherboard revision number : A0 > Model number : ME-C3750-24TE-M > Daughterboard assembly number : 73-9939-02 > Daughterboard serial number : CAT104355CQ > System serial number : CAT1043NM05 > Top Assembly Part Number : 800-25952-04 > Top Assembly Revision Number : C0 > Version ID : V05 > CLEI Code Number : COM1510ARA > Daughterboard revision number : A0 > Hardware Board Revision Number : 0x09 > > > Switch Ports Model SW Version SW > Image ------ ----- ----- ---------- > ---------- * 1 28 ME-C3750-24TE > 12.2(37)SE1 C3750ME-I5-M > Configuration register is 0xF > > #sh memory | i HL > 030C8118 0000005000 030C804C 030C94CC 001 -------- -------- 005CF8E4 HLFM > MAC > 030C94CC 0000000808 030C8118 030C9820 001 -------- -------- 005CF93C HLFM > IP > 0320A434 0000000808 0320A008 0320A788 001 -------- -------- 00CB2F74 > HL3U_IPV4_TABLE_CHUNK > 0320A788 0000020000 0320A434 0320F5D4 001 -------- -------- 00CB2F9C > HL3U_FIB_TYPE_CHUNK > 0320F5D4 0000032768 0320A788 03217600 001 -------- -------- 00CB2FC4 > HL3U_MPATH_ADJ_TYPE_CHUNK > 03217600 0000000808 0320F5D4 03217954 001 -------- -------- 00CB2FEC > HL3U_FIB_WITH_ADJ_OR_TCAM_FAIL_CHUNK > 03217954 0000002000 03217600 03218150 001 -------- -------- 00CB3014 > HL3U_COVERING_FIB_CHUNK > 03218150 0000000808 03217954 032184A4 001 -------- -------- 00CB303C > HL3U_ARP_HRPC_THROTTLE_CHUNKS > 032184A4 0000000432 03218150 03218680 001 -------- -------- 00CB3064 > HL3U_HSRP_RETRY_CHUNKS > 03218680 0000000808 032184A4 032189D4 001 -------- -------- 00CB308C > HL3U_PROXY_ARP_CHUNKS > 032189D4 0000000432 03218680 03218BB0 001 -------- -------- 00CB30B4 > HL3U_QUERIER_INFO_CHUNKS > 03218BB0 0000003620 032189D4 03219A00 001 -------- -------- 00CB30DC > HL3U_ICMP_REDIRECT_Q_CHUNK > 03219A00 0000000296 03218BB0 03219B54 001 -------- -------- 00CB3104 > HL3U_OUT_ACL_FULL_CHUNKS > 032F2BCC 0000000960 032F252C 032F2FB8 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 0330BD38 0000000176 0330B698 0330BE14 001 -------- -------- 00B18A5C > HL2MCM > 0330C174 0000000160 0330C0C0 0330C240 001 -------- -------- 01622A8C > HL2MCM > 036F9C6C 0000000972 036F9A8C 036FA064 001 -------- -------- 00CB7108 > HL3U_FIB_WITH_ > 036FA064 0000000872 036F9C6C 036FA3F8 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 0390629C 0000000024 03906258 039062E0 001 -------- -------- 00B1AFAC > HL2MCM > 039906D8 0000001292 0399008C 03990C10 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03993CC4 0000000808 03993690 03994018 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 0399C258 0000001476 0399BC14 0399C848 001 -------- -------- 00CB7108 > HL3U_FIB_WITH_ > 0399C964 0000005000 0399C848 0399DD18 001 -------- -------- 005CB1E0 HLFM > MAC > 03A0A610 0000001096 03A0A3EC 03A0AA84 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03A2B8E4 0000000808 03A2B858 03A2BC38 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03A2BC38 0000000872 03A2B8E4 03A2BFCC 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03A2E864 0000007768 03A2E624 03A306E8 001 -------- -------- 005CB1E0 HLFM > MAC > 03A30D28 0000000808 03A30CBC 03A3107C 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03A92BD4 0000000808 03A92590 03A92F28 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03EE36A8 0000005000 03EE3634 03EE4A5C 001 -------- -------- 005CB1E0 HLFM > MAC > 03F24DCC 0000001008 03F24D54 03F251E8 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03F43C34 0000008200 03F43BE8 03F45C68 001 -------- -------- 005CB1E0 HLFM > MAC > 03F4C260 0000000808 03F4C1CC 03F4C5B4 001 -------- -------- 005CB5B8 HLFM > IP > 03F85410 0000000808 03F84DBC 03F85764 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03F85EF0 0000001008 03F85764 03F8630C 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03F872A8 0000001288 03F86F08 03F877DC 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03FEBD34 0000000808 03FEB5A8 03FEC088 001 -------- -------- 00CB7108 > HL3U_FIB_WITH_ > 03FEC088 0000001076 03FEBD34 03FEC4E8 001 -------- -------- 00CB7108 > HL3U_FIB_WITH_ > 03FEEF64 0000000808 03FEE7D8 03FEF2B8 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03FEF2B8 0000000832 03FEEF64 03FEF624 001 -------- -------- 00CBE090 > HL3U_FIB_WITH_ > 03FF05F0 0000005944 03FF04FC 03FF1D54 001 -------- -------- 005CB1E0 HLFM > MAC > > > #sh sdm prefer > The current template is "desktop routing" template. > The selected template optimizes the resources in > the switch to support this level of features for > 8 routed interfaces and 1024 VLANs. > > number of unicast mac addresses: 3K > number of IPv4 IGMP groups + multicast routes: 1K > number of IPv4 unicast routes: 11K > number of directly-connected IPv4 hosts: 3K > number of indirect IPv4 routes: 8K > number of IPv4 policy based routing aces: 0.5K > number of IPv4/MAC qos aces: 0.5K > number of IPv4/MAC security aces: 1K > > Mar 31 12:48:11: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:48:17: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:48:28: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:48:46: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:49:00: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:49:47: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:50:39: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:51:02: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:51:34: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:51:55: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:53:11: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:53:25: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:53:37: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:54:36: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:56:44: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 12:57:48: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 13:02:22: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 13:02:48: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 13:03:56: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 13:07:31: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > Mar 31 13:30:37: %OCE-3-MISSING_HANDLER_FOR_SW_OBJ_TYPE: Missing handler > for 'non choice oce get next' function for type Midchain > > > On other 3750 from our network: > > sh processes cpu sorted | ex 0.00 > CPU utilization for five seconds: 43%/2%; one minute: 58%; five minutes: > 59% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > 108 2635783702 47442165 55558 30.55% 48.37% 49.28% 0 HL3U bkgrd > proce > 294 500 2692 185 3.19% 0.55% 0.13% 1 Virtual > Exec 47 296813504 43714587 6789 1.43% 1.70% 1.74% 0 FE > free chunk 107 58156203 265066803 219 0.63% 0.42% 0.37% 0 > Hulc LED Process > 247 88726248 2800468 31682 0.47% 0.45% 0.47% 0 MFI LFD Stats > Pr > 117 3310849 6664259 496 0.15% 0.04% 0.03% 0 HRPC qos > request > 135 8065160 45776840 176 0.15% 0.07% 0.04% 0 IP > Input 243 28572622 56335656 507 0.15% 0.17% 0.18% 0 > ISIS Upd > #sh ver > Cisco IOS Software, C3750ME Software (C3750ME-I5-M), Version 12.2(37)SE1, > RELEASE SOFTWARE (fc1) > Copyright (c) 1986-2007 by Cisco Systems, Inc. > Compiled Thu 05-Jul-07 20:06 by antonino > Image text-base: 0x00003000, data-base: 0x0163F400 > > ROM: Bootstrap program is C3750 boot loader > BOOTLDR: C3750ME Boot Loader (C3750ME-HBOOT-M) Version 12.1(14r)AX, RELEASE > SOFTWARE (fc1) > > rom101 uptime is 27 weeks, 5 days, 18 hours, 13 minutes > System returned to ROM by power-on > System restarted at 20:03:10 CETDST Wed Sep 17 2008 > System image file is "flash:c3750me-i5-mz.122-37.SE1.bin" > > cisco ME-C3750-24TE (PowerPC405) processor (revision F0) with > 118784K/12280K bytes of memory. > Processor board ID CAT1111NLH3 > Last reset from power-on > 3 Virtual Ethernet interfaces > 24 FastEthernet interfaces > 4 Gigabit Ethernet interfaces > The password-recovery mechanism is enabled. > > 1024K bytes of flash-simulated non-volatile configuration memory. > Base ethernet MAC Address : 00:1B:2B:E6:4B:00 > Motherboard assembly number : 73-9938-04 > Motherboard serial number : CAT11115HNX > Model revision number : F0 > Motherboard revision number : B0 > Model number : ME-C3750-24TE-M > Daughterboard assembly number : 73-9939-02 > Daughterboard serial number : CAT11115KVD > System serial number : CAT1111NLH3 > Top Assembly Part Number : 800-25952-04 > Top Assembly Revision Number : C0 > Version ID : V05 > CLEI Code Number : COM1510ARA > Daughterboard revision number : A0 > Hardware Board Revision Number : 0x09 > > > Switch Ports Model SW Version SW > Image ------ ----- ----- ---------- > ---------- * 1 28 ME-C3750-24TE > 12.2(37)SE1 C3750ME-I5-M > Configuration register is 0xF > Do you have any idea what is the root cause of this issue? > > > > > Thnak you, > > -- > Ioan Branet > > -- Ioan Branet CCIE #23474 R&S From ip at ioshints.info Wed Apr 1 06:55:52 2009 From: ip at ioshints.info (Ivan Pepelnjak) Date: Wed, 1 Apr 2009 12:55:52 +0200 Subject: [c-nsp] how to filter some specific logging message In-Reply-To: <7100ed370904010326n1e1a28b1i5def36ee24348037@mail.gmail.com> References: <7100ed370904010326n1e1a28b1i5def36ee24348037@mail.gmail.com> Message-ID: <002f01c9b2b8$6d5f0480$0a00000a@nil.si> The "drops" keyword expects a regular expression. You should use "fem" instead of "*fem" (or maybe ".*fem"). Ivan http://www.ioshints.info/about http://blog.ioshints.info/ > -----Original Message----- > From: Manu Chao [mailto:linux.yahoo at gmail.com] > Sent: Wednesday, April 01, 2009 12:26 PM > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] how to filter some specific logging message > > Is it possible to filter some specific syslog message with > logging filter command or with logging discriminator? > > There are some "cosmetic" bugs that I need to filter... > > Example: i don't want the specific message message including > "fem" to be sent to my remote syslog server. > > I try that configuration but no way :( may be a syntax > problem may be not possible to filter? > > logging discriminator nolog msg-body drops *fem logging host > x.x.x.x discriminator nolog > > Thanks for your help > > From achatz at forthnet.gr Wed Apr 1 10:50:01 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Wed, 01 Apr 2009 17:50:01 +0300 Subject: [c-nsp] SXI1 is out Message-ID: <49D37F19.4060201@forthnet.gr> ...but release notes haven't been updated yet. I'm having a maintenance window tomorrow and i was planning to upgrade 3 6500s from SXF9 to SXI, but since SXI1 came out, i'm thinking of moving directly to it. Anyone know what is fixed from SXI to SXI1? PS: I was running SXI in a lab for a few weeks without any major issues. -- Tassos From jared at puck.nether.net Wed Apr 1 11:02:02 2009 From: jared at puck.nether.net (Jared Mauch) Date: Wed, 1 Apr 2009 11:02:02 -0400 Subject: [c-nsp] SXI1 is out In-Reply-To: <49D37F19.4060201@forthnet.gr> References: <49D37F19.4060201@forthnet.gr> Message-ID: <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> On Apr 1, 2009, at 10:50 AM, Tassos Chatzithomaoglou wrote: > ...but release notes haven't been updated yet. > > I'm having a maintenance window tomorrow and i was planning to > upgrade 3 6500s from SXF9 to SXI, but since SXI1 came out, i'm > thinking of moving directly to it. Anyone know what is fixed from > SXI to SXI1? > > PS: I was running SXI in a lab for a few weeks without any major > issues. I know this image has 4-byte ASN support and fixes for at least one bgp related bug. I've been toying with it for a few hours now with no significant problems. I know at least one of my bugs did not make it to SXI1 making the modular unusable in our environment. - Jared From oboehmer at cisco.com Wed Apr 1 11:08:21 2009 From: oboehmer at cisco.com (Oliver Boehmer (oboehmer)) Date: Wed, 1 Apr 2009 17:08:21 +0200 Subject: [c-nsp] Problem with L2TP !! In-Reply-To: <002801c9b29f$4e94d250$ebbe76f0$@net.pk> References: <002801c9b29f$4e94d250$ebbe76f0$@net.pk> Message-ID: <70B7A1CCBFA5C649BD562B6D9F7ED7840723AEAE@xmb-ams-333.emea.cisco.com> > Dear friends! > > I am trying to establish a L2TP tunnel between a LAC (Which is also > Acting as BRAS) and LNS (Which is also acting as BRAS). > > User ---------[Cisco 3640 LAC]----- IP Cloud-------[Cisco 3845 LNS] > > The problem I am facing is that the scenario is working fine as long > as I am using user account created locally on LNS. However as soon > as I enable radius parameters, LAC stops establishing tunnel with LNS > and connects the user on LAC as pppoe user. After investigation I > have found that If I remove following line from the configuration > L2TP Tunnels works perfectly fine; > aaa authorization network default group radius > > Can someone tell me Why its happening?? Since I am using @domain in > user ids for L2TP users, LAC should not even refer to Radius. And I > need this aaa authorization parameter since both my LAC and LNS also > have PPPoE users terminated on them. well, you need to decide whether you want to authorize via Radius or not. If you are using domains, you can define cybernet Password = "cisco" Service-Type = Outbound-User, cisco-avpair = "vpdn:tunnel-id=DSL-LNS", cisco-avpair = "vpdn:tunnel-type=l2tp", cisco-avpair = "vpdn:ip-addresses=1.1.1.1", cisco-avpair = "vpdn:source-ip=2.2.2.2" Once you configure vpdn multihop (turning the LNS into a LAC), the node will perform network authorization for all connections, including for users with domains. There is a special authorization for domains where the domain will be authorized with Radius (using the fixed "cisco" password), and if the profile exists, the LAC/LNS will search for tunnel information and forward the session (if found). If there is no domain/tunnel profile, the LAC/LNS will authorize the full username to terminate the session locally. Hope this helps.. oli From justin at justinshore.com Wed Apr 1 11:57:36 2009 From: justin at justinshore.com (Justin Shore) Date: Wed, 01 Apr 2009 10:57:36 -0500 Subject: [c-nsp] Bridging DS1s from Overture ISGs back to Cisco channelized DS3 interfaces Message-ID: <49D38EF0.5050307@justinshore.com> Has anyone ever successfully terminated a group of bonded DS1s from an Overture device such as an ISG 140 back to a PA-MC-2T3-EC? Talking to Overture's support they're saying that even though they use MLPPP they also require the use of BCP (Bridge Control Protocol) which I personally hadn't heard of until today. They're saying that I need to be able to pass 1Q tagged frames down the MLPPP bundle to the ISG on the remote end. The SE they have onsite here has a document that shows an example config but it apparently requires IP routing to be disabled (no ip routing). That's not cool. That kind of defeats the purpose of buying a shiny new router if you have to turn off routing... So has anyone ever bridged DS1s between a Cisco and Overture box? Why would routing have to be disabled for BCP to work? Thanks Justin From MLouis at nwnit.com Wed Apr 1 12:33:04 2009 From: MLouis at nwnit.com (Mike Louis) Date: Wed, 1 Apr 2009 12:33:04 -0400 Subject: [c-nsp] SXI1 is out In-Reply-To: <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> References: <49D37F19.4060201@forthnet.gr> <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> Message-ID: SXI didn't support Netflow export from a VRF other than the global table. The command option wasn't available in the ip flow export command syntax. Here is what I am seeing in SXI 6509(config)#ip flow-export destination 10.1.1.3 9996 ? The vrf flag was available in SXH. Has that been fixed in SXI1? Mike Louis Senior Solutions Architect CCIE #17082 (R&S) -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jared Mauch Sent: Wednesday, April 01, 2009 11:02 AM To: Tassos Chatzithomaoglou Cc: cisco-nsp Subject: Re: [c-nsp] SXI1 is out On Apr 1, 2009, at 10:50 AM, Tassos Chatzithomaoglou wrote: > ...but release notes haven't been updated yet. > > I'm having a maintenance window tomorrow and i was planning to > upgrade 3 6500s from SXF9 to SXI, but since SXI1 came out, i'm > thinking of moving directly to it. Anyone know what is fixed from > SXI to SXI1? > > PS: I was running SXI in a lab for a few weeks without any major > issues. I know this image has 4-byte ASN support and fixes for at least one bgp related bug. I've been toying with it for a few hours now with no significant problems. I know at least one of my bugs did not make it to SXI1 making the modular unusable in our environment. - Jared _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ Note: This message and any attachments is intended solely for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, legally privileged, confidential, and/or exempt from disclosure. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the original sender immediately by telephone or return email and destroy or delete this message along with any attachments immediately. From p.mayers at imperial.ac.uk Wed Apr 1 12:40:33 2009 From: p.mayers at imperial.ac.uk (Phil Mayers) Date: Wed, 01 Apr 2009 17:40:33 +0100 Subject: [c-nsp] SXI1 is out In-Reply-To: References: <49D37F19.4060201@forthnet.gr> <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> Message-ID: <49D39901.7090903@imperial.ac.uk> Mike Louis wrote: > SXI didn't support Netflow export from a VRF other than the global table. The command option wasn't available in the ip flow export command syntax. > > Here is what I am seeing in SXI > > 6509(config)#ip flow-export destination 10.1.1.3 9996 ? > > > The vrf flag was available in SXH. It didn't work properly in SXH. It only exported MSFC-switched flows. > > Has that been fixed in SXI1? > From MLouis at nwnit.com Wed Apr 1 12:42:46 2009 From: MLouis at nwnit.com (Mike Louis) Date: Wed, 1 Apr 2009 12:42:46 -0400 Subject: [c-nsp] SXI1 is out In-Reply-To: <49D39901.7090903@imperial.ac.uk> References: <49D37F19.4060201@forthnet.gr> <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> <49D39901.7090903@imperial.ac.uk> Message-ID: Good to know. I didn't it much in SXH, just installed SXH enough long enough to see the command was there. We had a multi-VRF deployment and SXH crashed and went to ROMMON once we configured 3 or more EIGRP AS #s in VRF-Lite deployment. We had to go to SXI for stability with EIGRP and VRF-lite. Then we lost Netflow commands again outside the global VRF. Mike -----Original Message----- From: Phil Mayers [mailto:p.mayers at imperial.ac.uk] Sent: Wednesday, April 01, 2009 12:41 PM To: Mike Louis Cc: Jared Mauch; Tassos Chatzithomaoglou; cisco-nsp Subject: Re: [c-nsp] SXI1 is out Mike Louis wrote: > SXI didn't support Netflow export from a VRF other than the global table. The command option wasn't available in the ip flow export command syntax. > > Here is what I am seeing in SXI > > 6509(config)#ip flow-export destination 10.1.1.3 9996 ? > > > The vrf flag was available in SXH. It didn't work properly in SXH. It only exported MSFC-switched flows. > > Has that been fixed in SXI1? > Note: This message and any attachments is intended solely for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, legally privileged, confidential, and/or exempt from disclosure. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the original sender immediately by telephone or return email and destroy or delete this message along with any attachments immediately. From lists.james.edwards at gmail.com Wed Apr 1 12:44:04 2009 From: lists.james.edwards at gmail.com (james edwards) Date: Wed, 1 Apr 2009 10:44:04 -0600 Subject: [c-nsp] Problems bringing up BGP session Message-ID: I moved the BGP session to a new router for my Quagga route server. It was working before the move but now it comes up, the RS gets all the routes and in ~5 mins. the session goes down. This looks like bug CSCsv33977. I can't apply the workaround as I do not have the command "dont-capability-negotiate": Enter configuration commands, one per line. End with CNTL/Z. edge-router1(config)#router bgp 22523 edge-router1(config-router)#neighbor 198.59.128.243 ? activate Enable the Address Family for this Neighbor advertise-map specify route-map for conditional advertisement advertisement-interval Minimum interval between sending BGP routing updates allowas-in Accept as-path with my AS present in it capability Advertise capability to the peer default-originate Originate default route to this neighbor description Neighbor specific description disable-connected-check one-hop away EBGP peer using loopback address distribute-list Filter updates to/from this neighbor dmzlink-bw Propagate the DMZ link bandwidth ebgp-multihop Allow EBGP neighbors not on directly connected networks fall-over session fall on peer route lost filter-list Establish BGP filters ha-mode high availability mode inherit Inherit a template local-as Specify a local-as number maximum-prefix Maximum number of prefixes accepted from this peer next-hop-self Disable the next hop calculation for this neighbor next-hop-unchanged Propagate next hop unchanged for iBGP paths to this neighbor password Set a password peer-group Member of the peer-group prefix-list Filter updates to/from this neighbor remote-as Specify a BGP neighbor remove-private-as Remove private AS number from outbound updates route-map Apply route map to neighbor route-reflector-client Configure a neighbor as Route Reflector client send-community Send Community attribute to this neighbor send-label Send NLRI + MPLS Label to this peer shutdown Administratively shut down this neighbor soft-reconfiguration Per neighbor soft reconfiguration soo Site-of-Origin extended community timers BGP per neighbor timers translate-update Translate Update to MBGP format transport Transport options ttl-security BGP ttl security check unsuppress-map Route-map to selectively unsuppress suppressed routes update-source Source of routing updates version Set the BGP version to match a neighbor weight Set default weight for routes from this neighbor Cisco Router is running c7200p-adventerprisek9-mz.122-33.SRC2.bin Config looks like this: neighbor 198.59.128.243 remote-as 22523 neighbor 198.59.128.243 description iBGP WITH HOMER neighbor 198.59.128.243 shutdown neighbor 198.59.128.243 update-source Loopback1 neighbor 198.59.128.243 next-hop-self neighbor 198.59.128.243 prefix-list DENY-ALL-ROUTES in Logs: Apr 1 10:14:44.062 mdt: %BGP-5-ADJCHANGE: neighbor 198.59.128.243 Up Apr 1 10:18:23.462 mdt: %SYS-5-CONFIG_I: Configured from console by james on vty0 (198.59.128.254) Apr 1 10:21:44.765 mdt: %BGP-5-ADJCHANGE: neighbor 198.59.128.243 Down BGP Notification sent Apr 1 10:21:44.765 mdt: %BGP-3-NOTIFICATION: sent to neighbor 198.59.128.243 4/0 (hold time expired) 0 bytes Apr 1 10:21:49 mdt: BGP notification suppress timer expired, old send notification: Apr 1 10:21:49 mdt: BGP April 01 16:20:49.913: BGP: 198.59.128.243 passive send NOTIFICATION 2/8 (no supported AFI/SAFI) afi 0 safi 0 Any clues ? James H. Edwards Senior Network Systems Administrator Judicial Information Division jedwards at nmcourts.gov From lists.james.edwards at gmail.com Wed Apr 1 13:51:04 2009 From: lists.james.edwards at gmail.com (james edwards) Date: Wed, 1 Apr 2009 11:51:04 -0600 Subject: [c-nsp] Problems bringing up BGP session In-Reply-To: <9E07F8717FE8BC4FBAE6860F61EA6C1D022B259F@spsrvmail03.nec.br> References: <9E07F8717FE8BC4FBAE6860F61EA6C1D022B259F@spsrvmail03.nec.br> Message-ID: On Wed, Apr 1, 2009 at 11:08 AM, Leonardo Gama Souza < leonardo.souza at nec.com.br> wrote: > Hi... > Try again. > It is a hidden command. > > Thanks, yep it was there. But is did not fix my problem: pr 1 11:40:44.351 mdt: %BGP-5-ADJCHANGE: neighbor 198.59.128.243 Up Apr 1 11:47:44.994 mdt: %BGP-5-ADJCHANGE: neighbor 198.59.128.243 Down BGP Notification sent Apr 1 11:47:44.994 mdt: %BGP-3-NOTIFICATION: sent to neighbor 198.59.128.243 4/0 (hold time expired) 0 bytes Apr 1 11:48:20 mdt: BGP notification suppress timer expired, old send notification: Apr 1 11:48:20 mdt: BGP April 01 17:47:21.208: BGP: 198.59.128.243 passive send NOTIFICATION 2/8 (no supported AFI/SAFI) afi 1 safi 1 james From jared at puck.nether.net Wed Apr 1 14:01:21 2009 From: jared at puck.nether.net (Jared Mauch) Date: Wed, 1 Apr 2009 14:01:21 -0400 Subject: [c-nsp] SXI1 is out In-Reply-To: References: <49D37F19.4060201@forthnet.gr> <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> <49D39901.7090903@imperial.ac.uk> Message-ID: <4B862218-6A6C-4ACB-8231-DC6887750485@puck.nether.net> netflow on the 65xx is broken enough i'm surprised it gave you any data of value. - jared On Apr 1, 2009, at 12:42 PM, Mike Louis wrote: > Good to know. I didn't it much in SXH, just installed SXH enough > long enough to see the command was there. We had a multi-VRF > deployment and SXH crashed and went to ROMMON once we configured 3 > or more EIGRP AS #s in VRF-Lite deployment. We had to go to SXI for > stability with EIGRP and VRF-lite. Then we lost Netflow commands > again outside the global VRF. > > Mike > > > -----Original Message----- > From: Phil Mayers [mailto:p.mayers at imperial.ac.uk] > Sent: Wednesday, April 01, 2009 12:41 PM > To: Mike Louis > Cc: Jared Mauch; Tassos Chatzithomaoglou; cisco-nsp > Subject: Re: [c-nsp] SXI1 is out > > Mike Louis wrote: >> SXI didn't support Netflow export from a VRF other than the global >> table. The command option wasn't available in the ip flow export >> command syntax. >> >> Here is what I am seeing in SXI >> >> 6509(config)#ip flow-export destination 10.1.1.3 9996 ? >> >> >> The vrf flag was available in SXH. > > It didn't work properly in SXH. It only exported MSFC-switched flows. > >> >> Has that been fixed in SXI1? >> > > > Note: This message and any attachments is intended solely for the > use of the individual or entity to which it is addressed and may > contain information that is non-public, proprietary, legally > privileged, confidential, and/or exempt from disclosure. If you are > not the intended recipient, you are hereby notified that any use, > dissemination, distribution, or copying of this communication is > strictly prohibited. If you have received this communication in > error, please notify the original sender immediately by telephone or > return email and destroy or delete this message along with any > attachments immediately. From leonardo.souza at nec.com.br Wed Apr 1 13:08:19 2009 From: leonardo.souza at nec.com.br (Leonardo Gama Souza) Date: Wed, 1 Apr 2009 14:08:19 -0300 Subject: [c-nsp] RES: Problems bringing up BGP session In-Reply-To: References: Message-ID: <9E07F8717FE8BC4FBAE6860F61EA6C1D022B259F@spsrvmail03.nec.br> Hi... Try again. It is a hidden command. -----Mensagem original----- De: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] Em nome de james edwards Enviada em: quarta-feira, 1 de abril de 2009 13:44 Para: cisco-nsp at puck.nether.net Assunto: [c-nsp] Problems bringing up BGP session I moved the BGP session to a new router for my Quagga route server. It was working before the move but now it comes up, the RS gets all the routes and in ~5 mins. the session goes down. This looks like bug CSCsv33977. I can't apply the workaround as I do not have the command "dont-capability-negotiate": Enter configuration commands, one per line. End with CNTL/Z. edge-router1(config)#router bgp 22523 edge-router1(config-router)#neighbor 198.59.128.243 ? activate Enable the Address Family for this Neighbor advertise-map specify route-map for conditional advertisement advertisement-interval Minimum interval between sending BGP routing updates allowas-in Accept as-path with my AS present in it capability Advertise capability to the peer default-originate Originate default route to this neighbor description Neighbor specific description disable-connected-check one-hop away EBGP peer using loopback address distribute-list Filter updates to/from this neighbor dmzlink-bw Propagate the DMZ link bandwidth ebgp-multihop Allow EBGP neighbors not on directly connected networks fall-over session fall on peer route lost filter-list Establish BGP filters ha-mode high availability mode inherit Inherit a template local-as Specify a local-as number maximum-prefix Maximum number of prefixes accepted from this peer next-hop-self Disable the next hop calculation for this neighbor next-hop-unchanged Propagate next hop unchanged for iBGP paths to this neighbor password Set a password peer-group Member of the peer-group prefix-list Filter updates to/from this neighbor remote-as Specify a BGP neighbor remove-private-as Remove private AS number from outbound updates route-map Apply route map to neighbor route-reflector-client Configure a neighbor as Route Reflector client send-community Send Community attribute to this neighbor send-label Send NLRI + MPLS Label to this peer shutdown Administratively shut down this neighbor soft-reconfiguration Per neighbor soft reconfiguration soo Site-of-Origin extended community timers BGP per neighbor timers translate-update Translate Update to MBGP format transport Transport options ttl-security BGP ttl security check unsuppress-map Route-map to selectively unsuppress suppressed routes update-source Source of routing updates version Set the BGP version to match a neighbor weight Set default weight for routes from this neighbor Cisco Router is running c7200p-adventerprisek9-mz.122-33.SRC2.bin Config looks like this: neighbor 198.59.128.243 remote-as 22523 neighbor 198.59.128.243 description iBGP WITH HOMER neighbor 198.59.128.243 shutdown neighbor 198.59.128.243 update-source Loopback1 neighbor 198.59.128.243 next-hop-self neighbor 198.59.128.243 prefix-list DENY-ALL-ROUTES in Logs: Apr 1 10:14:44.062 mdt: %BGP-5-ADJCHANGE: neighbor 198.59.128.243 Up Apr 1 10:18:23.462 mdt: %SYS-5-CONFIG_I: Configured from console by james on vty0 (198.59.128.254) Apr 1 10:21:44.765 mdt: %BGP-5-ADJCHANGE: neighbor 198.59.128.243 Down BGP Notification sent Apr 1 10:21:44.765 mdt: %BGP-3-NOTIFICATION: sent to neighbor 198.59.128.243 4/0 (hold time expired) 0 bytes Apr 1 10:21:49 mdt: BGP notification suppress timer expired, old send notification: Apr 1 10:21:49 mdt: BGP April 01 16:20:49.913: BGP: 198.59.128.243 passive send NOTIFICATION 2/8 (no supported AFI/SAFI) afi 0 safi 0 Any clues ? James H. Edwards Senior Network Systems Administrator Judicial Information Division jedwards at nmcourts.gov _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From marco at linuxgoeroe.dhs.org Wed Apr 1 13:44:21 2009 From: marco at linuxgoeroe.dhs.org (Marco van den Bovenkamp) Date: Wed, 01 Apr 2009 19:44:21 +0200 Subject: [c-nsp] SXI1 is out In-Reply-To: References: <49D37F19.4060201@forthnet.gr> <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> Message-ID: <49D3A7F5.10105@linuxgoeroe.dhs.org> Mike Louis wrote: > SXI didn't support Netflow export from a VRF other than the global table. The command option wasn't available in the ip flow export command syntax. > > Here is what I am seeing in SXI > > 6509(config)#ip flow-export destination 10.1.1.3 9996 ? > > > The vrf flag was available in SXH. > > Has that been fixed in SXI1? Probably not. I ran into the same thing when trying to run NetFlow on a number of ME6524s. SXH had it, SXI didn't. TAC said: 'It wasn't fully functional in SXH and worked only for software flows. It's removed in SXI and there are no plans to bring it back'. Bummer :-( Regards, Marco. From ralvarez.list at gmail.com Wed Apr 1 16:10:31 2009 From: ralvarez.list at gmail.com (=?iso-8859-1?Q?Ram=F3n_Alvarez_R.?=) Date: Wed, 1 Apr 2009 14:10:31 -0600 Subject: [c-nsp] Unknown Multicast Traffic cause High CPU In-Reply-To: <30697BA326C8DC4B863C69C819A56DED490D25@ORION.enitel.net> References: <30697BA326C8DC4B863C69C819A56DED490D25@ORION.enitel.net> Message-ID: <24CEC61E8ADF4403A8B14AA6617CC4D3@ADMONPC> Hello, We have a metrothernet customer using vlan 993, we are experimenting high CPU usage by unknown multicast traffic coming from this vlan id 993 and this expand over several switches on the network, but when we remove the vlan from some pop sites the behavior stop. After that we add the vlan id, again, and the behavior is normal. We setup a multicast filter to this equipment but this issue is showing every few days. The multicast filter is: ip igmp profile 1 range 224.0.0.0 239.255.255.255 interface FastEthernet2/30 switchport access vlan 704 switchport trunk encapsulation dot1q switchport trunk allowed vlan 100,199,269,270,291,292,378,379,474,475,535,536 switchport trunk allowed vlan add 615-620,677,678,703-705,715-735,805,826,829 switchport trunk allowed vlan add 856,864,867,869,890,916,922,943,958,992,993 switchport trunk allowed vlan add 996,1108-1110,1120-1122,1183-1185,1353,1354 switchport trunk allowed vlan add 1363,1364,1375,1376,2513,2514 switchport mode trunk switchport nonegotiate no cdp enable spanning-tree portfast spanning-tree bpdufilter enable spanning-tree bpduguard enable ip igmp filter 1 SW_4503#sh processes cpu | e 0.0 CPU utilization for five seconds: 99%/0%; one minute: 98%; five minutes: 91% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 30 17955901802907757383 617 69.35% 68.33% 63.77% 0 Cat4k Mgmt LoPri 71 7245976 48021324 150 2.00% 2.31% 2.12% 0 MRD 72 42231304 74816636 564 23.11% 21.86% 20.34% 0 IGMPSN SW_4503#sh ip igmp snooping mrouter Vlan ports ---- ----- 993 Fa2/30(dynamic), Gi3/2(dynamic) SW_4503#sh run int fa2/30 Building configuration... Current configuration : 681 bytes ! interface FastEthernet2/30 switchport access vlan 704 switchport trunk encapsulation dot1q switchport trunk allowed vlan 100,199,269,270,291,292,378,379,474,475,535,536 switchport trunk allowed vlan add 615-620,677,678,703-705,715-735,805,826,829 switchport trunk allowed vlan add 856,864,867,869,890,916,922,943,958,992,993 switchport trunk allowed vlan add 996,1108-1110,1120-1122,1183-1185,1353,1354 switchport trunk allowed vlan add 1363,1364,1375,1376,2513,2514 switchport mode trunk switchport nonegotiate no cdp enable spanning-tree portfast spanning-tree bpdufilter enable spanning-tree bpduguard enable ip igmp filter 1 end SW_4503#conf ter Enter configuration commands, one per line. End with CNTL/Z. SW_4503(config)#int fa2/30 SW_4503(config-if)# switchport trunk allowed vlan remove 993 SW_4503# SW_4503#sh processes cpu | e 0.0 CPU utilization for five seconds: 14%/0%; one minute: 82%; five minutes: 89% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 29 2352303324 512512734 4589 2.87% 3.54% 3.72% 0 Cat4k Mgmt HiPri 30 17956380562907774138 617 8.63% 56.76% 61.92% 0 Cat4k Mgmt LoPri 72 42246460 74829450 564 0.71% 17.40% 19.51% 0 IGMPSN 115 41220440 58103914 709 0.47% 0.14% 0.12% 0 SNMP ENGINE From charles at thewybles.com Wed Apr 1 16:20:11 2009 From: charles at thewybles.com (Charles Wyble) Date: Wed, 01 Apr 2009 13:20:11 -0700 Subject: [c-nsp] Unknown Multicast Traffic cause High CPU In-Reply-To: <24CEC61E8ADF4403A8B14AA6617CC4D3@ADMONPC> References: <30697BA326C8DC4B863C69C819A56DED490D25@ORION.enitel.net> <24CEC61E8ADF4403A8B14AA6617CC4D3@ADMONPC> Message-ID: <49D3CC7B.9010404@thewybles.com> What does a network packet dump tell you? From peter at rathlev.dk Wed Apr 1 16:25:31 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Wed, 01 Apr 2009 22:25:31 +0200 Subject: [c-nsp] SXI1 is out In-Reply-To: <4B862218-6A6C-4ACB-8231-DC6887750485@puck.nether.net> References: <49D37F19.4060201@forthnet.gr> <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> <49D39901.7090903@imperial.ac.uk> <4B862218-6A6C-4ACB-8231-DC6887750485@puck.nether.net> Message-ID: <1238617531.5087.6.camel@localhost.localdomain> On Wed, 2009-04-01 at 14:01 -0400, Jared Mauch wrote: > netflow on the 65xx is broken enough i'm surprised it gave you any > data of value. Hm, I thought it worked okay. Out of curiosity, what should one be careful about with it, if one's network was dominated by 6500s? We only use it for troubleshooting though, so precision is less important for us if that's the problem. Regards, Peter From lists.james.edwards at gmail.com Wed Apr 1 16:36:34 2009 From: lists.james.edwards at gmail.com (james edwards) Date: Wed, 1 Apr 2009 14:36:34 -0600 Subject: [c-nsp] HWIC-1GE-SFP hot insert ? Message-ID: Does anyone know if this module can be hot inserted ? Cisco says SFP's can be hot inserted but I can't find anything about the HWIC-1GE-SFP itself. Thanks, -- James H. Edwards Senior Network Systems Administrator Judicial Information Division jedwards at nmcourts.gov From gabszabo at cisco.com Wed Apr 1 16:38:47 2009 From: gabszabo at cisco.com (Gabor Szabo (gabszabo)) Date: Wed, 1 Apr 2009 22:38:47 +0200 Subject: [c-nsp] 10GE card for 7609 In-Reply-To: <49D30D51.4060304@schlund.net> References: <863386.41277.qm@web44809.mail.sp1.yahoo.com> <49D30D51.4060304@schlund.net> Message-ID: RSP720 supervisor is supported from 12.2(33)SRB and supports X6704 from the beginning. X6708 is supported from 12.2(33)SRC for both SUP720 and RSP720 in the SR train. Regards, Gabor -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jan Sandmaier Sent: 2009. ?prilis 1. 8:45 To: Geoffrey Pendery Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] 10GE card for 7609 Geoffrey Pendery schrieb: > The stuff we've been reading (look at "Supervisor Engines Supported" > on the data sheets for "Cisco Catalyst 6500 Series 10 Gigabit Ethernet > Interface Modules", or browse the line cards for the 7600, or go into > Configurator tool) claims that the RSP 720 won't support the X6704 or > X6708 10 Gig "LAN" cards, only the SIP/SPA/ES "WAN" type cards. > > I don't mean to kick off a big "6500 vs 7600" storm again, but does > anyone know if this is incorrect? > Can we buy a new 7609-S chassis, put a new RSP 720 in it, put 7600 IOS > on that Sup, then plug in a WS-X6708-10G-3C and have it work? > X6708-10G-3C works definitly. X6704 also. You have to check the release notes or software advisor for the suitable IOS. Jan > > -Geoff > > > On Mon, Mar 30, 2009 at 4:41 AM, Mark Tech wrote: > >> Hi >> I have a prospect for a 10G upstream customer and Upstream ISP connections. I would need to connect these into our 7609s running RSP 720-3CXL's, at the moment I have found that the WS-X6704-10GE card may be suitable. >> >> My technical requirements are: >> 10Gbps line rate >> IPv4 >> Able to handle full Internet routing table >> Potentially IPv6 and MPLS in the future >> >> With the WS-X6704-10GE, there seems to be several options that are available with it i.e. >> >> Memory Option: >> MEM-XCEF720-256M >> Catalyst 6500 256MB DDR, xCEF720 (67xx interface, DFC3A) >> MEM-XCEF720-512M >> Cat 6500 512MB DDR, xCEF720 (67xx interface, DFC3A/DFC3B) >> MEM-XCEF720-1GB >> Catalyst 6500 1GB DDR, xCEF720 (67xx interface, DFC3BXL) >> >> ==================================================== >> Distributed Forwarding Card Option >> >> WS-F6700-CFC >> Catalyst 6500 Central Fwd Card for WS-X67xx modules >> WS-F6700-DFC3B >> Catalyst 6500 Dist Fwd Card, 256K Routes for WS-X67xx >> WS-F6700-DFC3A >> Catalyst 6500 Dist Fwd Card for WS-X67xx modules >> WS-F6700-DFC3BXL >> Catalyst 6500 Dist Fwd Card- 3BXL, for WS-X67xx >> WS-F6700-DFC3C >> Catalyst 6500 Dist Fwd Card for WS-X67xx modules >> WS-F6700-DFC3CXL >> Catalyst 6500 Dist Fwd Card- 3CXL, for WS-X67xx >> >> I assume that I would need MEM-XCEF720-1GB and WS-F6700-DFC3CXL? >> >> Regards >> >> Mark >> >> >> >> >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > -- Jan Sandmaier Network Engineer 1und1 Internet AG Mail: jan.sandmaier at 1und1.de Brauerstrasse 48 Tel.: +49 721/91374-4213 D-76135 Karlsruhe Fax : +49 721/91374-212 http://www.1und1.de (AS8560) Handelsregister Amtsgericht Montabaur, HRB 6484 USt-IdNr. DE811247114 Vorstand: Henning Ahlert, Ralph Dommermuth, Matthias Ehrlich, Thomas Gottschlich, Matthias Greve, Robert Hoffmann, Markus Huhn, Oliver Mauss, Achim Weiss Aufsichtsratsvorsitzender: Michael Scheeren _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From c-nsp at djvh.nl Wed Apr 1 17:31:20 2009 From: c-nsp at djvh.nl (Dirk-Jan van Helmond) Date: Wed, 1 Apr 2009 23:31:20 +0200 Subject: [c-nsp] 3750/3750E stack upgrade downtime? In-Reply-To: <20090401081546.GE74388@ronin.4ever.de> References: <49D1297B.2080106@utc.edu> <1238445916.4440.7.camel@localhost.localdomain> <20090401081546.GE74388@ronin.4ever.de> Message-ID: <37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> I'd rather live in cable-hell than use pass-trough modules.... On Apr 1, 2009, at 10:15 , Elmar K. Bins wrote: > Dirk, > > c-nsp at djvh.nl (Dirk-Jan van Helmond) wrote: > >> We're thinking about getting some Cisco CBS 3110 blade switches to >> aggeregate the interfaces from the bladeservers. The CBS3110 can >> stack >> and is factually just an 3750 in a blade enclosure and has the same >> roadmap as the 3750. >> I would very much like to have ISSU on these switches, otherwise an >> IOS upgrade means downtime for an entire bladechassis, which is >> unacceptable. >> Unfortunately ISSU is not supported and not on the roadmap :( >> >> I've asked my accountmanager @Cisco, so you please ask yours. Maybe >> if >> we ask kind enough, they will think about it ;) > > Your best bet might be to buy pass-through modules and use a couple > of unstacked 3750s (or 3560s)...it's also a hell of a lot cheaper. > > Elmar. From lowen at pari.edu Wed Apr 1 17:31:24 2009 From: lowen at pari.edu (Lamar Owen) Date: Wed, 1 Apr 2009 17:31:24 -0400 Subject: [c-nsp] HWIC-1GE-SFP hot insert ? In-Reply-To: References: Message-ID: <200904011731.25332.lowen@pari.edu> On Wednesday 01 April 2009 16:36:34 james edwards wrote: > Does anyone know if this module can be hot inserted ? Cisco says SFP's can > be hot inserted > but I can't find anything about the HWIC-1GE-SFP itself. AFAIK, and according to the panel on the 3845 here, OIR is not supported by any WIC or HWIC. -- Lamar Owen Chief Information Officer Pisgah Astronomical Research Institute 1 PARI Drive Rosman, NC 28772 http://www.pari.edu From elmi at 4ever.de Wed Apr 1 17:44:17 2009 From: elmi at 4ever.de (Elmar K. Bins) Date: Wed, 1 Apr 2009 23:44:17 +0200 Subject: [c-nsp] 3750/3750E stack upgrade downtime? In-Reply-To: <37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> References: <49D1297B.2080106@utc.edu> <1238445916.4440.7.camel@localhost.localdomain> <20090401081546.GE74388@ronin.4ever.de> <37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> Message-ID: <20090401214417.GL74388@ronin.4ever.de> c-nsp at djvh.nl (Dirk-Jan van Helmond) wrote: > I'd rather live in cable-hell than use pass-trough modules.... Then, please: Good luck with your account manager. Oh, and someone tell me as soon as the 3750s do ISSU... From ralvarez.list at gmail.com Wed Apr 1 18:16:22 2009 From: ralvarez.list at gmail.com (=?iso-8859-1?Q?Ram=F3n_Alvarez_R.?=) Date: Wed, 1 Apr 2009 16:16:22 -0600 Subject: [c-nsp] Unknown Multicast Traffic cause High CPU References: <30697BA326C8DC4B863C69C819A56DED490D25@ORION.enitel.net> <24CEC61E8ADF4403A8B14AA6617CC4D3@ADMONPC> <49D3CC7B.9010404@thewybles.com> Message-ID: <6356F99CD8104F89B63CE9FE163770FD@ADMONPC> Charles, In this case we didn't do a packet dump due the network is equipment have the cpu very high and this affect several equipments at the same time due this behavior do not allow to made additional testing. The equipments are cat4503, cat6506 and cat3750. Thanks, -----Mensaje original----- De: Charles Wyble [mailto:charles at thewybles.com] Enviado el: mi?rcoles, 01 de abril de 2009 02:20 p.m. Para: "Ram?n Alvarez R." CC: cisco-nsp at puck.nether.net Asunto: Re: [c-nsp] Unknown Multicast Traffic cause High CPU What does a network packet dump tell you? From tvarriale at comcast.net Wed Apr 1 18:28:24 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Wed, 1 Apr 2009 17:28:24 -0500 Subject: [c-nsp] 3750/3750E stack upgrade downtime? References: <49D1297B.2080106@utc.edu><1238445916.4440.7.camel@localhost.localdomain><20090401081546.GE74388@ronin.4ever.de><37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> <20090401214417.GL74388@ronin.4ever.de> Message-ID: <2F47563BDFE542548FB2A78C99E5723F@flamdt01> The 6500 barely supports it. In fact, I don't know any customers running mod due to the train wreck it is. Anyone here running mod successfully? If so, how long? But, you can upgrade separate 3750 members and do one switch at a time today. What does ISSU get you on the 3750? tv ----- Original Message ----- From: "Elmar K. Bins" To: "Dirk-Jan van Helmond" Cc: "cisco-nsp" Sent: Wednesday, April 01, 2009 4:44 PM Subject: Re: [c-nsp] 3750/3750E stack upgrade downtime? > c-nsp at djvh.nl (Dirk-Jan van Helmond) wrote: > >> I'd rather live in cable-hell than use pass-trough modules.... > > Then, please: Good luck with your account manager. Oh, and someone > tell me as soon as the 3750s do ISSU... > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From vegasnetman at gmail.com Wed Apr 1 18:35:46 2009 From: vegasnetman at gmail.com (Ozar) Date: Wed, 1 Apr 2009 15:35:46 -0700 Subject: [c-nsp] Pseudowire and EtherChannel Message-ID: <8cd002180904011535n13d9327w1e6ed31c5050e367@mail.gmail.com> Quick question on PS and EtherChannel. Lets say I have customer who needs 2 gig from A to Z that I am going to transport by Pseudowire... Should I etherchannel the ports and make my xconnect in the Port Channel interface, or just transport each gig interface separately, and customer handles all the aggregation? Thanks, Ozar From chris at netops.t3com.net Wed Apr 1 18:08:20 2009 From: chris at netops.t3com.net (Chris Wallace) Date: Wed, 1 Apr 2009 18:08:20 -0400 Subject: [c-nsp] IP Address management software In-Reply-To: References: Message-ID: <7ADF655F-D80E-4AD4-A02B-205D4F8CC1CB@netops.t3com.net> IPPlan here as well... If you are running an RWHOIS server there is also a nice script that someone wrote to automatically pull the data from IPPlan and build the RWHOIS data files. http://gregsowell.com/?p=223 On Mar 31, 2009, at 4:17 AM, Gary Roberton wrote: > Hello all > > What IP address management software do you use to control the > allocation of > subnets to your customers/department? > > Thanks > > Gary > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From jeff-kell at utc.edu Wed Apr 1 19:39:17 2009 From: jeff-kell at utc.edu (Jeff Kell) Date: Wed, 01 Apr 2009 19:39:17 -0400 Subject: [c-nsp] 3750/3750E stack upgrade downtime? In-Reply-To: <2F47563BDFE542548FB2A78C99E5723F@flamdt01> References: <49D1297B.2080106@utc.edu><1238445916.4440.7.camel@localhost.localdomain><20090401081546.GE74388@ronin.4ever.de><37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> <20090401214417.GL74388@ronin.4ever.de> <2F47563BDFE542548FB2A78C99E5723F@flamdt01> Message-ID: <49D3FB25.6050703@utc.edu> Tony Varriale wrote: > But, you can upgrade separate 3750 members and do one switch at a time > today. You can? Doesn't the "reload" crash the whole stack? Jeff From kloch at kl.net Wed Apr 1 19:46:38 2009 From: kloch at kl.net (Kevin Loch) Date: Wed, 01 Apr 2009 19:46:38 -0400 Subject: [c-nsp] SXI1 is out In-Reply-To: <1238617531.5087.6.camel@localhost.localdomain> References: <49D37F19.4060201@forthnet.gr> <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> <49D39901.7090903@imperial.ac.uk> <4B862218-6A6C-4ACB-8231-DC6887750485@puck.nether.net> <1238617531.5087.6.camel@localhost.localdomain> Message-ID: <49D3FCDE.7080705@kl.net> Peter Rathlev wrote: > On Wed, 2009-04-01 at 14:01 -0400, Jared Mauch wrote: >> netflow on the 65xx is broken enough i'm surprised it gave you any >> data of value. > > Hm, I thought it worked okay. Out of curiosity, what should one be > careful about with it, if one's network was dominated by 6500s? > > We only use it for troubleshooting though, so precision is less > important for us if that's the problem. I wouldn't use it for accounting but with the right sampling it can be used to see how much traffic you are sending to/from other ASN's. I use: mls sampling packet-based 1024 8192 Which gives a convenient ~1000 conversion factor from indicated bandwidth to actual. - Kevin From David at hughes.com.au Wed Apr 1 19:01:47 2009 From: David at hughes.com.au (David Hughes) Date: Thu, 2 Apr 2009 09:01:47 +1000 Subject: [c-nsp] SXI1 is out In-Reply-To: <4B862218-6A6C-4ACB-8231-DC6887750485@puck.nether.net> References: <49D37F19.4060201@forthnet.gr> <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> <49D39901.7090903@imperial.ac.uk> <4B862218-6A6C-4ACB-8231-DC6887750485@puck.nether.net> Message-ID: <6AE6AC4E-61BA-4437-BC58-B3C9485B4671@Hughes.com.au> Is anyone happily using per-interface NDE on SXI? That would be a huge leap in usefulness. David ... On 02/04/2009, at 4:01 AM, Jared Mauch wrote: > netflow on the 65xx is broken enough i'm surprised it gave you any > data of value. > > - jared From jmaimon at ttec.com Wed Apr 1 21:09:50 2009 From: jmaimon at ttec.com (Joe Maimon) Date: Wed, 01 Apr 2009 21:09:50 -0400 Subject: [c-nsp] vrf aware cluster-id Message-ID: <49D4105E.6020002@ttec.com> Running 124T to take advantage of per vrf bgp router id so that the router can have "loopback" bgp connections. However, route-reflector-client is not taking effect, the neighbor reports denied CLUSTER_LIST loop. Apparently cluster-id needs to be vrf aware as well for this to work. Is this in the offing or am I on the wrong track? Thanks, Joe From alex.wilkinson at dsto.defence.gov.au Wed Apr 1 22:57:57 2009 From: alex.wilkinson at dsto.defence.gov.au (Wilkinson, Alex) Date: Thu, 2 Apr 2009 10:57:57 +0800 Subject: [c-nsp] SXI1 is out In-Reply-To: <49D37F19.4060201@forthnet.gr> References: <49D37F19.4060201@forthnet.gr> Message-ID: <20090402025756.GE2351@stlux503.dsto.defence.gov.au> 0n Wed, Apr 01, 2009 at 05:50:01PM +0300, Tassos Chatzithomaoglou wrote: >...but release notes haven't been updated yet. >I'm having a maintenance window tomorrow and i was planning to upgrade 3 6500s from SXF9 to SXI, but since SXI1 came >out, i'm thinking of moving directly to it. Anyone know what is fixed from SXI to SXI1? What is SXI1 ? -aW IMPORTANT: This email remains the property of the Australian Defence Organisation and is subject to the jurisdiction of section 70 of the CRIMES ACT 1914. If you have received this email in error, you are requested to contact the sender and delete the email. From achatz at forthnet.gr Thu Apr 2 01:13:22 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Thu, 02 Apr 2009 08:13:22 +0300 Subject: [c-nsp] WS-X6724-SFP & SXI = high cpu usage? Message-ID: <49D44972.9010202@forthnet.gr> Anyone running SXI with a WS-X6724-SFP module (DFC or non DFC), showing high cpu usage due to the fw_lcp process? 6500#remote command module 1 sh proc cpu sort | exc 0.00 CPU utilization for five seconds: 32%/1%; one minute: 31%; five minutes: 31% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 187 1949496 613964 3175 31.19% 30.47% 30.45% 0 fw_lcp process 6500#sh platform hardware capacity cpu CPU Resources CPU utilization: Module 5 seconds 1 minute 5 minutes 1 28% / 0% 28% 28% 6 RP 1% / 1% 1% 1% 6 SP 18% / 0% 15% 14% 6500#sh mod Mod Ports Card Type Model Serial No. --- ----- -------------------------------------- ------------------ ----------- 1 24 CEF720 24 port 1000mb SFP WS-X6724-SFP XXXXXXXXXXX 6 2 Supervisor Engine 720 (Active) WS-SUP720-3B XXXXXXXXXXX SXH, SXF do not seem to have this problem. -- Tassos From achatz at forthnet.gr Thu Apr 2 01:31:02 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Thu, 02 Apr 2009 08:31:02 +0300 Subject: [c-nsp] WS-X6724-SFP & SXI = high cpu usage? In-Reply-To: <49D44972.9010202@forthnet.gr> References: <49D44972.9010202@forthnet.gr> Message-ID: <49D44D96.2000904@forthnet.gr> ...small correction : a DFC must be present -- Tassos Tassos Chatzithomaoglou wrote on 02/04/2009 08:13: > Anyone running SXI with a WS-X6724-SFP module (DFC or non DFC), showing > high cpu usage due to the fw_lcp process? > > > 6500#remote command module 1 sh proc cpu sort | exc 0.00 > > CPU utilization for five seconds: 32%/1%; one minute: 31%; five minutes: > 31% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > 187 1949496 613964 3175 31.19% 30.47% 30.45% 0 fw_lcp > process > > > 6500#sh platform hardware capacity cpu > CPU Resources > CPU utilization: Module 5 seconds 1 minute 5 > minutes > 1 28% / 0% > 28% 28% > 6 RP 1% / 1% > 1% 1% > 6 SP 18% / 0% > 15% 14% > 6500#sh mod > Mod Ports Card Type Model > Serial No. > --- ----- -------------------------------------- ------------------ > ----------- > 1 24 CEF720 24 port 1000mb SFP WS-X6724-SFP > XXXXXXXXXXX > 6 2 Supervisor Engine 720 (Active) WS-SUP720-3B > XXXXXXXXXXX > > > SXH, SXF do not seem to have this problem. > From gert at greenie.muc.de Thu Apr 2 02:04:22 2009 From: gert at greenie.muc.de (Gert Doering) Date: Thu, 2 Apr 2009 08:04:22 +0200 Subject: [c-nsp] SXI1 is out In-Reply-To: <6AE6AC4E-61BA-4437-BC58-B3C9485B4671@Hughes.com.au> References: <49D37F19.4060201@forthnet.gr> <718BAA5A-B96A-462E-98A3-55C9D059A532@puck.nether.net> <49D39901.7090903@imperial.ac.uk> <4B862218-6A6C-4ACB-8231-DC6887750485@puck.nether.net> <6AE6AC4E-61BA-4437-BC58-B3C9485B4671@Hughes.com.au> Message-ID: <20090402060422.GH290@greenie.muc.de> Hi, On Thu, Apr 02, 2009 at 09:01:47AM +1000, David Hughes wrote: > Is anyone happily using per-interface NDE on SXI? That would be a > huge leap in usefulness. We do (SXH3a and SXI) and it works. That is, we haven't uncovered any nasties yet, and the amount of data is matching our expectations. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From illcritikz at gmail.com Thu Apr 2 02:10:04 2009 From: illcritikz at gmail.com (Ben Steele) Date: Thu, 2 Apr 2009 16:40:04 +1030 Subject: [c-nsp] SXI1 is out In-Reply-To: <20090402025756.GE2351@stlux503.dsto.defence.gov.au> References: <49D37F19.4060201@forthnet.gr> <20090402025756.GE2351@stlux503.dsto.defence.gov.au> Message-ID: <4422cf660904012310l1eb2839cx71c9d494eb85c9d7@mail.gmail.com> In fear of prosecution from section 70 of the CRIMES ACT 1914 I will simply say it is the successor to SXI, the SX series is an IOS available for the 6500 Platform. http://www.cisco.com/en/US/prod/collateral/iosswrel/ps8802/ps6970/ps6017/ps9673/product_bulletin_c25-503086.html Ben On Thu, Apr 2, 2009 at 1:27 PM, Wilkinson, Alex < alex.wilkinson at dsto.defence.gov.au> wrote: > > 0n Wed, Apr 01, 2009 at 05:50:01PM +0300, Tassos Chatzithomaoglou wrote: > > >...but release notes haven't been updated yet. > >I'm having a maintenance window tomorrow and i was planning to upgrade > 3 6500s from SXF9 to SXI, but since SXI1 came > >out, i'm thinking of moving directly to it. Anyone know what is fixed > from SXI to SXI1? > > What is SXI1 ? > > -aW > > IMPORTANT: This email remains the property of the Australian Defence > Organisation and is subject to the jurisdiction of section 70 of the CRIMES > ACT 1914. If you have received this email in error, you are requested to > contact the sender and delete the email. > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From ras at e-gerbil.net Thu Apr 2 03:24:23 2009 From: ras at e-gerbil.net (Richard A Steenbergen) Date: Thu, 2 Apr 2009 02:24:23 -0500 Subject: [c-nsp] SXI1 is out In-Reply-To: <4422cf660904012310l1eb2839cx71c9d494eb85c9d7@mail.gmail.com> References: <49D37F19.4060201@forthnet.gr> <20090402025756.GE2351@stlux503.dsto.defence.gov.au> <4422cf660904012310l1eb2839cx71c9d494eb85c9d7@mail.gmail.com> Message-ID: <20090402072423.GR51443@gerbil.cluepon.net> On Thu, Apr 02, 2009 at 04:40:04PM +1030, Ben Steele wrote: > In fear of prosecution from section 70 of the CRIMES ACT 1914 I will simply > say it is the successor to SXI, the SX series is an IOS available for the > 6500 Platform. I still say the name "SXI1" is a sexual harassment complaint just waiting to happen. :) -- Richard A Steenbergen http://www.e-gerbil.net/ras GPG Key ID: 0xF8B12CBC (7535 7F59 8204 ED1F CC1C 53AF 4C41 5ECA F8B1 2CBC) From elmi at 4ever.de Thu Apr 2 03:48:32 2009 From: elmi at 4ever.de (Elmar K. Bins) Date: Thu, 2 Apr 2009 09:48:32 +0200 Subject: [c-nsp] Pseudowire and EtherChannel In-Reply-To: <8cd002180904011535n13d9327w1e6ed31c5050e367@mail.gmail.com> References: <8cd002180904011535n13d9327w1e6ed31c5050e367@mail.gmail.com> Message-ID: <20090402074832.GM74388@ronin.4ever.de> vegasnetman at gmail.com (Ozar) wrote: > Lets say I have customer who needs 2 gig from A to Z that I am going to > transport by Pseudowire... > > Should I etherchannel the ports and make my xconnect in the Port Channel > interface, or just transport each gig interface separately, and customer > handles all the aggregation? I would not count on the packets arriving in-order. Pseudowire is usually based on MPLS-switching, but it could also be tunnelled. I'd do some dynamic routing including Multipath (for the balancing) on the links. From peter at rathlev.dk Thu Apr 2 04:25:08 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 02 Apr 2009 10:25:08 +0200 Subject: [c-nsp] 3750/3750E stack upgrade downtime? In-Reply-To: <49D3FB25.6050703@utc.edu> References: <49D1297B.2080106@utc.edu> <1238445916.4440.7.camel@localhost.localdomain> <20090401081546.GE74388@ronin.4ever.de> <37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> <20090401214417.GL74388@ronin.4ever.de> <2F47563BDFE542548FB2A78C99E5723F@flamdt01> <49D3FB25.6050703@utc.edu> Message-ID: <1238660708.3408.2.camel@localhost.localdomain> On Wed, 2009-04-01 at 19:39 -0400, Jeff Kell wrote: > Tony Varriale wrote: > > But, you can upgrade separate 3750 members and do one switch at a time > > today. > > You can? Doesn't the "reload" crash the whole stack? If anybody knows how to do this we need to know. :-) When I have tried, the first switch to reload will never become active since it has version incompatibilities. So you can't reload the second, since there aren't any to take over. Not without downtime at least. Regards, Peter From hegedus.gabor at euroway.hu Thu Apr 2 04:36:35 2009 From: hegedus.gabor at euroway.hu (Hegedus Gabor) Date: Thu, 02 Apr 2009 10:36:35 +0200 Subject: [c-nsp] c3560, priv-lvl=15, authorization level problem Message-ID: <49D47913.5020902@euroway.hu> Hi all! I have a problem: I want use aaa authentication with radius in c3560, I try to authenticate my user to the priv level 15. The authentication is succes, but the user is just on the level 1. radius send back the priv-lvl=15, I can see in the radius debug. the configurations of the radius and the switch are correct, because I have c2960 with the same configuration, and the priv-level 15 authentication works on it. here is my config sample: aaa group server radius rad_group server *.*.*.* auth-port 1812 acct-port 1813 aaa authentication login method_line group rad_group local aaa authentication enable default group rad_group enable aaa authorization console aaa authorization exec method_line if-authenticated group rad_group local aaa session-id common line vty 0 4 authorization exec method_line login authentication method_line radius-server attribute 6 on-for-login-auth radius-server attribute 32 include-in-access-req radius-server attribute 32 include-in-accounting-req radius-server attribute 25 access-request include radius-server host *.*.*.* auth-port 1812 acct-port 1813 key * debug log: Apr 2 10:29:54.547 MET: RADIUS: Received from id 1645/*.*.*.*:1812, Access-Accept, len 91 Apr 2 10:29:54.547 MET: RADIUS: authenticator 96 55 55 96 42 75 94 F0 - 72 55 71 BA 55 51 35 D2 Apr 2 10:29:54.547 MET: RADIUS: Unsupported [87] 6 Apr 2 10:29:54.547 MET: RADIUS: 74 74 79 32 [tty2] Apr 2 10:29:54.547 MET: RADIUS: Service-Type [6] 6 Administrative [6] Apr 2 10:29:54.547 MET: RADIUS: Vendor, Cisco [26] 25 Apr 2 10:29:54.547 MET: RADIUS: Cisco AVpair [1] 19 "shell:priv-lvl=15" Apr 2 10:29:54.547 MET: RADIUS: Reply-Message [18] 34 Apr 2 10:29:54.547 MET: RADIUS: 0A 25 20 52 61 64 69 75 73 20 41 75 74 68 65 6E [?? Radius Authen] Apr 2 10:29:54.547 MET: RADIUS: 74 69 63 61 74 69 6F 6E 20 73 75 63 63 65 73 73 [tication success] Apr 2 10:29:54.547 MET: RADIUS: saved authorization data for user 2430320 at 27437E8 Apr 2 10:29:54.547 MET: AAA/AUTHEN (971040830): status = PASS Apr 2 10:29:54.547 MET: tty2 AAA/AUTHOR/EXEC (3224620906): Port='tty2' list='method_line' service=EXEC Apr 2 10:29:54.547 MET: AAA/AUTHOR/EXEC: tty2 (3224620906) user='XXXXXX' Apr 2 10:29:54.547 MET: tty2 AAA/AUTHOR/EXEC (3224620906): send AV service=shell Apr 2 10:29:54.547 MET: tty2 AAA/AUTHOR/EXEC (3224620906): send AV cmd* Apr 2 10:29:54.547 MET: tty2 AAA/AUTHOR/EXEC (3224620906): found list "method_line" Apr 2 10:29:54.547 MET: tty2 AAA/AUTHOR/EXEC (3224620906): Method=IF_AUTHEN Apr 2 10:29:54.547 MET: AAA/AUTHOR (3224620906): Post authorization status = PASS_ADD Apr 2 10:29:54.547 MET: AAA/AUTHOR/EXEC: Authorization successful please help me, thank you! br, Gabor From ardabalkanay at gmail.com Thu Apr 2 06:45:23 2009 From: ardabalkanay at gmail.com (Arda Balkanay) Date: Thu, 2 Apr 2009 13:45:23 +0300 Subject: [c-nsp] Pseudowire and EtherChannel In-Reply-To: <20090402074832.GM74388@ronin.4ever.de> References: <8cd002180904011535n13d9327w1e6ed31c5050e367@mail.gmail.com> <20090402074832.GM74388@ronin.4ever.de> Message-ID: <9af987420904020345u74024293t10a3baef94aa2b5d@mail.gmail.com> you can configure xconnect at portchannel interfaces. But for load-balance ether-channel makes load balance as follows: c076_01#sh etherchannel load-balance EtherChannel Load-Balancing Configuration: dst-mac mpls label-ip EtherChannel Load-Balancing Addresses Used Per-Protocol: Non-IP: Destination MAC address IPv4: Destination MAC address IPv6: Destination MAC address (routed packets) Destination IP address (bridged packets) MPLS: Label or IP c076_01# For eompls you can only make load balance with label. I'm not sure if it is mpls header (with exp bits) or just the label value but if it is just the label value, you can not load balance that traffic in my opinion, if it is mpls header you can load balance by changing exp bits according to the volume of traffic but it is not the real load balancing it is just a work around. Please correct me if I am wrong. Kind Regards Arda On Thu, Apr 2, 2009 at 10:48 AM, Elmar K. Bins wrote: > vegasnetman at gmail.com (Ozar) wrote: > > > Lets say I have customer who needs 2 gig from A to Z that I am going to > > transport by Pseudowire... > > > > Should I etherchannel the ports and make my xconnect in the Port Channel > > interface, or just transport each gig interface separately, and customer > > handles all the aggregation? > > I would not count on the packets arriving in-order. Pseudowire is usually > based on MPLS-switching, but it could also be tunnelled. > > I'd do some dynamic routing including Multipath (for the balancing) on > the links. > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From James.Munroe at gnb.ca Thu Apr 2 07:42:52 2009 From: James.Munroe at gnb.ca (Munroe, James (DSS/MAS)) Date: Thu, 2 Apr 2009 08:42:52 -0300 Subject: [c-nsp] WS-X6724-SFP & SXI = high cpu usage? In-Reply-To: <49D44972.9010202@forthnet.gr> References: <49D44972.9010202@forthnet.gr> Message-ID: <458B3EC21E4A3044998E917199AACB2F01A646D5@GNBEX02.gnb.ca> I've got two 6509's with WS-X6724-SFP (w/ CFC) running SXI and I'm not seeing that problem: 6509 #1: XX#sh mod Mod Ports Card Type Model Serial No. --- ----- -------------------------------------- ------------------ ----------- 1 24 CEF720 24 port 1000mb SFP WS-X6724-SFP XX#remote command module 1 sh proc cpu sort CPU utilization for five seconds: 0%/0%; one minute: 1%; five minutes: 1% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 187 13802188 547904699 25 0.15% 0.19% 0.18% 0 fw_lcp process 1 0 3 0 0.00% 0.00% 0.00% 0 Chunk Manager 2 204 1277786 0 0.00% 0.00% 0.00% 0 Load Meter 3 4 779932 0 0.00% 0.00% 0.00% 0 MFI LFD Timer Pr 5 0 10 0 0.00% 0.00% 0.00% 0 IPC ISSU Dispatc 4 0 43 0 0.00% 0.00% 0.00% 0 Retransmission o XX#sh platform hardware capacity cpu CPU Resources CPU utilization: Module 5 seconds 1 minute 5 minutes 1 0% / 0% 1% 1% 6509 #2: XY#remote command module 2 sh proc cpu sort CPU utilization for five seconds: 0%/0%; one minute: 1%; five minutes: 1% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 187 10049120 536549944 18 0.15% 0.17% 0.15% 0 fw_lcp process XY#sh platform hardware capacity cpu CPU Resources CPU utilization: Module 5 seconds 1 minute 5 minutes 2 2% / 0% 1% 1% Jim -----Original Message----- From: Tassos Chatzithomaoglou [mailto:achatz at forthnet.gr] Sent: Thursday, April 02, 2009 2:13 AM To: cisco-nsp Subject: [c-nsp] WS-X6724-SFP & SXI = high cpu usage? Anyone running SXI with a WS-X6724-SFP module (DFC or non DFC), showing high cpu usage due to the fw_lcp process? 6500#remote command module 1 sh proc cpu sort | exc 0.00 CPU utilization for five seconds: 32%/1%; one minute: 31%; five minutes: 31% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 187 1949496 613964 3175 31.19% 30.47% 30.45% 0 fw_lcp process 6500#sh platform hardware capacity cpu CPU Resources CPU utilization: Module 5 seconds 1 minute 5 minutes 1 28% / 0% 28% 28% 6 RP 1% / 1% 1% 1% 6 SP 18% / 0% 15% 14% 6500#sh mod Mod Ports Card Type Model Serial No. --- ----- -------------------------------------- ------------------ ----------- 1 24 CEF720 24 port 1000mb SFP WS-X6724-SFP XXXXXXXXXXX 6 2 Supervisor Engine 720 (Active) WS-SUP720-3B XXXXXXXXXXX SXH, SXF do not seem to have this problem. -- Tassos From acm at axians.de Thu Apr 2 08:25:51 2009 From: acm at axians.de (Cheikh-Moussa Ahmad) Date: Thu, 2 Apr 2009 14:25:51 +0200 Subject: [c-nsp] 4948 MAX Arp entries Message-ID: Hi Guys, I have searched a lot of sites and unfortunately didn't find a answer. Can someone tell me, how much arp entries (adjacencies) a 4948 switch can handle ? For L2 switching it can has up to 32K or the 4948-10g up to 55k entries, but I could not find anything about the max arp entries. As far as I know this arp entries or adjacencies are stored in TCAM. So the 4948 series can have 64k entries in the TCAM. Am I right, when I say : TCAM 64K = 32K IPv4 unicast routes 32K Unicast arp entries (adjacencies) What about the acls and qos configuration ? These are also stored in TCAM, right ? So if this right, then I never reach this, what I can found on the datasheets of the switches : * Unicast and multicast routing entries: 32,000 * Policers: 512 ingress and 512 egress * Access control list (ACL) and QoS entries: 32,000 Could it be that all these features share the same TCAM ? I'am little bit confused. Regards, Ahmad Ahmad Cheikh-Moussa Consultant Business Unit Carrier & Service Provider AXIANS NK Networks & Services GmbH Fischertwiete 2, Chilehaus A 20095 Hamburg Tel.: +49 40 237 899 - 72 Fax: +49 40 237 899 - 69 Ahmad.cheikh-moussa at axians.de Acheikh-moussa at axians.de acm at axians.de www.axians.com -------------- next part -------------- Sitz der NK Networks & Services GmbH: Von-der-Wettern-Stra?e 15, 51149 K?ln Registergericht: Amtsgericht K?ln, Registernummer HRB 30805 Gesch?ftsf?hrer: Tonis R?sche From peter.nyamukusa at africaonline.co.tz Thu Apr 2 08:23:36 2009 From: peter.nyamukusa at africaonline.co.tz (Peter Nyamukusa) Date: Thu, 2 Apr 2009 15:23:36 +0300 (EAT) Subject: [c-nsp] IP Address management software In-Reply-To: Message-ID: <7988720.651238675012717.JavaMail.peter@petergunz> Hi Gary, you can try this http://www.brownkid.net/NorthStar/ cheers, -- Peter Nyamukusa Technical Manager Africa Online (T) Ltd. Tel: +255 (22) 211 6090 Fax:+255 (22) 211 6089 Email: peter.nyamukusa at africaonline.co.tz A member of the Telkom South Africa Group ----- Original Message ----- From: "Gary Roberton" To: cisco-nsp at puck.nether.net Sent: Tuesday, March 31, 2009 11:17:50 AM GMT +03:00 Iraq Subject: [c-nsp] IP Address management software Hello all What IP address management software do you use to control the allocation of subnets to your customers/department? Thanks Gary _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From nockhi at gmail.com Thu Apr 2 10:14:58 2009 From: nockhi at gmail.com (Asif Gul Khan) Date: Thu, 2 Apr 2009 19:14:58 +0500 Subject: [c-nsp] IP Address management software In-Reply-To: <7988720.651238675012717.JavaMail.peter@petergunz> References: <7988720.651238675012717.JavaMail.peter@petergunz> Message-ID: PHPIP works lyk charm for us...n the best part it..its an open source! http://www.phpip.net/console.php On Thu, Apr 2, 2009 at 5:23 PM, Peter Nyamukusa < peter.nyamukusa at africaonline.co.tz> wrote: > Hi Gary, > you can try this > > http://www.brownkid.net/NorthStar/ > > cheers, > > -- > > > Peter Nyamukusa > > Technical Manager > Africa Online (T) Ltd. > Tel: +255 (22) 211 6090 > Fax:+255 (22) 211 6089 > Email: peter.nyamukusa at africaonline.co.tz > > > A member of the Telkom South Africa Group > > ----- Original Message ----- > From: "Gary Roberton" > To: cisco-nsp at puck.nether.net > Sent: Tuesday, March 31, 2009 11:17:50 AM GMT +03:00 Iraq > Subject: [c-nsp] IP Address management software > > Hello all > > What IP address management software do you use to control the allocation of > subnets to your customers/department? > > Thanks > > Gary > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From chris at chrisserafin.com Thu Apr 2 11:59:25 2009 From: chris at chrisserafin.com (ChrisSerafin) Date: Thu, 02 Apr 2009 10:59:25 -0500 Subject: [c-nsp] VRF-lite question on RD's Message-ID: <49D4E0DD.1050904@chrisserafin.com> I have 3 VRF's on a CE router: ip vrf xxx-General rd 1:10 route-target export 1:10 route-target import 1:10 ! ip vrf xxx-Guest rd 1:30 route-target export 1:30 route-target import 1:30 ! ip vrf xxx-Voice rd 1:20 route-target export 1:20 route-target import 1:20 I just got 3 new VRF's from the ISP confgured, and I'm wondering what numbers I need to have for the 'rd' and 'route-target xxport' commands...? Are these arbitrary, come from the ISP, or can I just use 40, 50, and 60? Thanks, chris From bennetb at gmail.com Thu Apr 2 12:08:44 2009 From: bennetb at gmail.com (Brandon Bennett) Date: Thu, 2 Apr 2009 10:08:44 -0600 Subject: [c-nsp] SXI1 is out In-Reply-To: <20090402072423.GR51443@gerbil.cluepon.net> References: <49D37F19.4060201@forthnet.gr> <20090402025756.GE2351@stlux503.dsto.defence.gov.au> <4422cf660904012310l1eb2839cx71c9d494eb85c9d7@mail.gmail.com> <20090402072423.GR51443@gerbil.cluepon.net> Message-ID: So anyone try out an ISSU upgrade from SXI to SXI1 yet? I'd really like to see if it works as advertised. -Brandon From bennetb at gmail.com Thu Apr 2 12:23:14 2009 From: bennetb at gmail.com (Brandon Bennett) Date: Thu, 2 Apr 2009 10:23:14 -0600 Subject: [c-nsp] VRF-lite question on RD's In-Reply-To: <49D4E0DD.1050904@chrisserafin.com> References: <49D4E0DD.1050904@chrisserafin.com> Message-ID: My guess is they are doing vrf-lite and using frame-relay or dot1q to bring these 3 VRFs to you. Which means the RD (used for MPLS L3VPNs) are only locally significant in the case of vrf-lite and are arbitrary numbers. It would be nice if Cisco didn't require RD's for vrf-lite cause they service no purpose. Now the import and export statements in vrf-lite also serve no purpose, but also not required. Interesting that they exist in the config. As long as no interfaces are configured with 'mpls ip' and you don't have a 'address-family vpnv4' configured under BGP those values are meaningless outside of the local router. HTH, Brandon On Thu, Apr 2, 2009 at 9:59 AM, ChrisSerafin wrote: > I have 3 VRF's on a CE router: > > > > ip vrf xxx-General > rd 1:10 > route-target export 1:10 > route-target import 1:10 > ! > ip vrf xxx-Guest > rd 1:30 > route-target export 1:30 > route-target import 1:30 > ! > ip vrf xxx-Voice > rd 1:20 > route-target export 1:20 > route-target import 1:20 > > I just got 3 new VRF's from the ISP confgured, and I'm wondering what > numbers I need to have for the 'rd' and 'route-target xxport' commands...? > Are these arbitrary, come from the ISP, or can I just use 40, 50, and 60? > > > Thanks, > > chris > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From oboehmer at cisco.com Thu Apr 2 12:30:18 2009 From: oboehmer at cisco.com (Oliver Boehmer (oboehmer)) Date: Thu, 2 Apr 2009 18:30:18 +0200 Subject: [c-nsp] c3560, priv-lvl=15, authorization level problem In-Reply-To: <49D47913.5020902@euroway.hu> References: <49D47913.5020902@euroway.hu> Message-ID: <70B7A1CCBFA5C649BD562B6D9F7ED7840727DD67@xmb-ams-333.emea.cisco.com> Hegedus Gabor <> wrote on Thursday, April 02, 2009 10:37: > Hi all! > > I have a problem: > > I want use aaa authentication with radius in c3560, I try to > authenticate my user to the priv level 15. > The authentication is succes, but the user is just on the level 1. > > radius send back the priv-lvl=15, I can see in the radius debug. > > the configurations of the radius and the switch are correct, because > I have c2960 with the same configuration, and the priv-level 15 > authentication works on it. > > here is my config sample: > > aaa authentication login method_line group rad_group local > aaa authorization exec method_line if-authenticated group rad_group why do you use if-authenticated before radius? if-authenticated method succeeds if the user is authenticated, so it doesn't even bother checking radius attributes for authorization information. Please try aaa authorization exec method_line group rad_group if-authenticated or aaa authorization exec method_line group rad_group local whatever fallback method you want to use.. oli From sthaug at nethelp.no Thu Apr 2 12:30:52 2009 From: sthaug at nethelp.no (sthaug at nethelp.no) Date: Thu, 02 Apr 2009 18:30:52 +0200 (CEST) Subject: [c-nsp] VRF-lite question on RD's In-Reply-To: <49D4E0DD.1050904@chrisserafin.com> References: <49D4E0DD.1050904@chrisserafin.com> Message-ID: <20090402.183052.112623136.sthaug@nethelp.no> > I just got 3 new VRF's from the ISP confgured, and I'm wondering what > numbers I need to have for the 'rd' and 'route-target xxport' > commands...? Are these arbitrary, come from the ISP, or can I just use > 40, 50, and 60? As long as you're using VRF-lite and not full MPLS, they are arbitrary in the sense that they're not part of any protocol between you and the ISP. Steinar Haug, Nethelp consulting, sthaug at nethelp.no From oboehmer at cisco.com Thu Apr 2 12:32:16 2009 From: oboehmer at cisco.com (Oliver Boehmer (oboehmer)) Date: Thu, 2 Apr 2009 18:32:16 +0200 Subject: [c-nsp] VRF-lite question on RD's In-Reply-To: <49D4E0DD.1050904@chrisserafin.com> References: <49D4E0DD.1050904@chrisserafin.com> Message-ID: <70B7A1CCBFA5C649BD562B6D9F7ED7840727DD6C@xmb-ams-333.emea.cisco.com> ChrisSerafin <> wrote on Thursday, April 02, 2009 17:59: > I have 3 VRF's on a CE router: > > > > ip vrf xxx-General > rd 1:10 > route-target export 1:10 > route-target import 1:10 > ! > ip vrf xxx-Guest > rd 1:30 > route-target export 1:30 > route-target import 1:30 > ! > ip vrf xxx-Voice > rd 1:20 > route-target export 1:20 > route-target import 1:20 > > I just got 3 new VRF's from the ISP confgured, and I'm wondering what > numbers I need to have for the 'rd' and 'route-target xxport' > commands...? Are these arbitrary, come from the ISP, or can I just use > 40, 50, and 60? In a vrf-lite environment, RDs are local to the router, so you can pick any (as long as it's unique on the router). you only need route-target if you're running BGP on the node to leak routes from one VRF to another.. doesn't look like you're doing any leaking, so I don't think you need any route-targets oli From chris at chrisserafin.com Thu Apr 2 12:32:16 2009 From: chris at chrisserafin.com (ChrisSerafin) Date: Thu, 02 Apr 2009 11:32:16 -0500 Subject: [c-nsp] VRF-lite question on RD's In-Reply-To: References: <49D4E0DD.1050904@chrisserafin.com> Message-ID: <49D4E890.1010108@chrisserafin.com> I spoke too soon. I found this right after posting http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.1/20ew/configuration/guide/vrf.pdf Switch(config-vrf)# rd route-distinguisher Creates a VRF table by specifying a route distinguisher. Enter either an AS number and an arbitrary number (xxx:y) or an IP address and arbitrary number (A.B.C.D:y). Step 5 Switch(config-vrf)# route-target {export | import | both} route-target-ext-community Creates a list of import, export, or import and export route target communities for the specified VRF. Enter either an AS system number and an arbitrary number (xxx:y) or an IP address and an arbitrary number (A.B.C.D:y). Note This command is effective only if BGP is running. Step 6 Switch(config-vrf)# import map route-map (Optional) Associates a route map with the VRF. I just added different numbers and they came right up. THANKS! Brandon Bennett wrote: > My guess is they are doing vrf-lite and using frame-relay or dot1q to > bring these 3 VRFs to you. Which means the RD (used for MPLS L3VPNs) > are only locally significant in the case of vrf-lite and are arbitrary > numbers. It would be nice if Cisco didn't require RD's for vrf-lite > cause they service no purpose. > > Now the import and export statements in vrf-lite also serve no > purpose, but also not required. Interesting that they exist in the > config. > > As long as no interfaces are configured with 'mpls ip' and you don't > have a 'address-family vpnv4' configured under BGP those values are > meaningless outside of the local router. > > HTH, > > Brandon > > On Thu, Apr 2, 2009 at 9:59 AM, ChrisSerafin > wrote: > > I have 3 VRF's on a CE router: > > > > ip vrf xxx-General > rd 1:10 > route-target export 1:10 > route-target import 1:10 > ! > ip vrf xxx-Guest > rd 1:30 > route-target export 1:30 > route-target import 1:30 > ! > ip vrf xxx-Voice > rd 1:20 > route-target export 1:20 > route-target import 1:20 > > I just got 3 new VRF's from the ISP confgured, and I'm wondering > what numbers I need to have for the 'rd' and 'route-target xxport' > commands...? Are these arbitrary, come from the ISP, or can I just > use 40, 50, and 60? > > > Thanks, > > chris > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > ------------------------------------------------------------------------ > > > No virus found in this incoming message. > Checked by AVG - www.avg.com > Version: 8.0.238 / Virus Database: 270.11.38/2037 - Release Date: 04/02/09 06:09:00 > > From chris at chrisserafin.com Thu Apr 2 12:36:59 2009 From: chris at chrisserafin.com (ChrisSerafin) Date: Thu, 02 Apr 2009 11:36:59 -0500 Subject: [c-nsp] VRF-lite question on RD's In-Reply-To: <70B7A1CCBFA5C649BD562B6D9F7ED7840727DD6C@xmb-ams-333.emea.cisco.com> References: <49D4E0DD.1050904@chrisserafin.com> <70B7A1CCBFA5C649BD562B6D9F7ED7840727DD6C@xmb-ams-333.emea.cisco.com> Message-ID: <49D4E9AB.90206@chrisserafin.com> Oliver Boehmer (oboehmer) wrote: > ChrisSerafin <> wrote on Thursday, April 02, 2009 17:59: > > >> I have 3 VRF's on a CE router: >> >> >> >> ip vrf xxx-General >> rd 1:10 >> route-target export 1:10 >> route-target import 1:10 >> ! >> ip vrf xxx-Guest >> rd 1:30 >> route-target export 1:30 >> route-target import 1:30 >> ! >> ip vrf xxx-Voice >> rd 1:20 >> route-target export 1:20 >> route-target import 1:20 >> >> I just got 3 new VRF's from the ISP confgured, and I'm wondering what >> numbers I need to have for the 'rd' and 'route-target xxport' >> commands...? Are these arbitrary, come from the ISP, or can I just use >> 40, 50, and 60? >> > > In a vrf-lite environment, RDs are local to the router, so you can pick > any (as long as it's unique on the router). you only need route-target > if you're running BGP on the node to leak routes from one VRF to > another.. doesn't look like you're doing any leaking, so I don't think > you need any route-targets > > oli > Excellent explanation, thank you! > ------------------------------------------------------------------------ > > > No virus found in this incoming message. > Checked by AVG - www.avg.com > Version: 8.0.238 / Virus Database: 270.11.38/2037 - Release Date: 04/02/09 06:09:00 > > From rshughes at gmail.com Thu Apr 2 14:09:35 2009 From: rshughes at gmail.com (Ryan Hughes) Date: Thu, 2 Apr 2009 14:09:35 -0400 Subject: [c-nsp] SXI1 is out In-Reply-To: References: <49D37F19.4060201@forthnet.gr> <20090402025756.GE2351@stlux503.dsto.defence.gov.au> <4422cf660904012310l1eb2839cx71c9d494eb85c9d7@mail.gmail.com> <20090402072423.GR51443@gerbil.cluepon.net> Message-ID: I believe that SXI introduces eFSU and not ISSU - which requires a linecard reload if the line card is not supported. * http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/issu_efsu.html The following modules support eFSU preload: ?WS-X67*xx* modules ?SIP-400 and SIP-600 I think we're still waiting on ISSU which is curiously not mentioned in the SXI1 release notes - maybe still on the dev/bug table? But I'm with Brandon - anyone give it a go yet? Ryan On Thu, Apr 2, 2009 at 12:08 PM, Brandon Bennett wrote: > So anyone try out an ISSU upgrade from SXI to SXI1 yet? I'd really like > to > see if it works as advertised. > > -Brandon > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From A.L.M.Buxey at lboro.ac.uk Thu Apr 2 17:07:46 2009 From: A.L.M.Buxey at lboro.ac.uk (A.L.M.Buxey at lboro.ac.uk) Date: Thu, 2 Apr 2009 22:07:46 +0100 Subject: [c-nsp] SXI1 is out In-Reply-To: References: <49D37F19.4060201@forthnet.gr> <20090402025756.GE2351@stlux503.dsto.defence.gov.au> <4422cf660904012310l1eb2839cx71c9d494eb85c9d7@mail.gmail.com> <20090402072423.GR51443@gerbil.cluepon.net> Message-ID: <20090402210746.GB23687@lboro.ac.uk> Hi, > So anyone try out an ISSU upgrade from SXI to SXI1 yet? I'd really like to > see if it works as advertised. hmmm, good call - I may have to check this out as when we did our SXF and SXH to SXI upgrade it thought it had been done via ISSU (why? dont know - hopefully fixed in SXI1 !) and therefore borked our dual sup720 setups which led to 3 other issues. alan From tvarriale at comcast.net Thu Apr 2 18:58:41 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Thu, 2 Apr 2009 17:58:41 -0500 Subject: [c-nsp] 3750/3750E stack upgrade downtime? References: <49D1297B.2080106@utc.edu><1238445916.4440.7.camel@localhost.localdomain><20090401081546.GE74388@ronin.4ever.de><37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> <20090401214417.GL74388@ronin.4ever.de> <2F47563BDFE542548FB2A78C99E5723F@flamdt01> <49D3FB25.6050703@utc.edu> Message-ID: <4340918886AC4B07AD08DC4DE8A740E0@flamdt01> Sure. You can reload certain members too. tv ----- Original Message ----- From: "Jeff Kell" To: "Tony Varriale" ; "'NSP List'" Sent: Wednesday, April 01, 2009 6:39 PM Subject: Re: [c-nsp] 3750/3750E stack upgrade downtime? > Tony Varriale wrote: >> But, you can upgrade separate 3750 members and do one switch at a time >> today. > > You can? Doesn't the "reload" crash the whole stack? > > Jeff From James.Baker at chelmer.co.nz Thu Apr 2 19:10:05 2009 From: James.Baker at chelmer.co.nz (James Baker) Date: Fri, 3 Apr 2009 12:10:05 +1300 Subject: [c-nsp] 3750/3750E stack upgrade downtime? In-Reply-To: <4340918886AC4B07AD08DC4DE8A740E0@flamdt01> References: <49D1297B.2080106@utc.edu><1238445916.4440.7.camel@localhost.localdomain><20090401081546.GE74388@ronin.4ever.de><37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> <20090401214417.GL74388@ronin.4ever.de><2F47563BDFE542548FB2A78C99E5723F@flamdt01><49D3FB25.6050703@utc.edu> <4340918886AC4B07AD08DC4DE8A740E0@flamdt01> Message-ID: <64396C74FCE435468BE2AF5A73F9C2FDCE07A3@chmaexch.chelmer.co.nz> ime reload on the master does the whole stack reload on the slave does the slave reload slot X does the slot (if done on the master will only take down the master) -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Tony Varriale Sent: Friday, 3 April 2009 11:59 a.m. To: 'NSP List' Subject: Re: [c-nsp] 3750/3750E stack upgrade downtime? Sure. You can reload certain members too. tv ----- Original Message ----- From: "Jeff Kell" To: "Tony Varriale" ; "'NSP List'" Sent: Wednesday, April 01, 2009 6:39 PM Subject: Re: [c-nsp] 3750/3750E stack upgrade downtime? > Tony Varriale wrote: >> But, you can upgrade separate 3750 members and do one switch at a time >> today. > > You can? Doesn't the "reload" crash the whole stack? > > Jeff _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ ---------- The information contained in this e-mail and any attachments is confidential and is intended for the attention and use of the named addressee(s) only. Any views expressed in this message are those of the individual sender and may not necessarily reflect the views of Chelmer Limited. ##################################################################################### This e-mail message has been scanned for Viruses and Content and cleared by NetIQ MailMarshal ##################################################################################### From rshughes at gmail.com Thu Apr 2 19:51:16 2009 From: rshughes at gmail.com (Ryan Hughes) Date: Thu, 2 Apr 2009 19:51:16 -0400 Subject: [c-nsp] Redundant switch fabric In-Reply-To: <49D259C1.3020901@usgs.gov> References: <49D24A2E.8010200@usgs.gov> <980303CA84BD4FAC978E53062A1EFE1A@flamdt01> <49D259C1.3020901@usgs.gov> Message-ID: To clarify the issue on the upgrade from 4.0.4 to 4.1.3 - there was more of a "distribution" error in that the CMP module was shipped read-only. Required assistance from a DE to resolve and work around which basically involved flashing the rom to make it read-write and then I was able to upgrade the CMP manually. This same problem appeared on a different and separate customer's gear at roughly the same time. Required the same fix so more than likely it was a "bad lot" type scenario. Service impacting? Not at all. Absolutely stupid and frustrating? Absolutely. Ryan On Tue, Mar 31, 2009 at 1:58 PM, Justin C. Darby wrote: > We had issues with 4.0(?) releases, mostly related to strange behavior of a > few features (dhcp relay, DAI, port security, etc) that required a full > reload after a software upgrade to clear up completely. 4.1(?) has been fine > so far, and the last upgrade we did was 4.1(2) to 4.1(4) and it went through > without any downtime. We skipped over 4.1(3) since we never got around to > scheduling it. > > Justin > > > Tony Varriale wrote: > >> I've had a colleague run into an issue going to 4.1.3 (long story but it's >> intrusive either way you slice it and is how all boxes are). What was your >> upgrade from and to? >> >> tv >> ----- Original Message ----- From: "Justin C. Darby" >> To: "Brad Hedlund" >> Cc: >> Sent: Tuesday, March 31, 2009 11:51 AM >> Subject: Re: [c-nsp] Redundant switch fabric >> >> >> Mike, >>> >>> Just to chime in here a bit with some experience - we've had Nexus 7K >>> switch backplane modules fail - unless you are pushing near 100% backplane >>> utilization you don't even notice until it emails you or your config >>> monitoring program notices the failed module. In recent NX-OS releases, In >>> Service Software Upgrades are working properly 100% of the time for us, and >>> outside of the fact it can take 3-4 hours to upgrade a fully loaded switch, >>> there's no real downtime if you've got working port redundancy across >>> modules, and modules only go down one at a time like they're supposed to. >>> >>> Considering how distributed and redundant components of the switch are - >>> it's pretty unlikely you'd run into huge redundancy problems with any single >>> component. I don't have enough N7K's to play with Virtual Port Channels >>> (vPCs), but it'd be interesting to see if they have any issues when >>> upgrading switches. vPCs can add extreme (and usable) redundancy to >>> multi-chassis design, if you want to go a step farther. >>> >>> Justin >>> >>> P.S. Comments made here are my own and should not in any way be >>> considered an endorsement by the U.S. Federal Government. >>> >>> Brad Hedlund wrote: >>> >>>> Mike, >>>> The 6500 and 4500 have the "switch fabric" on the supervisor engines, so >>>> by >>>> having dual supervisors, you in effect have a redundant fabric. >>>> >>>> The 6748 actually has 4 traces, each 20G. 2 traces connect to the >>>> active >>>> supervisor containing the active switch fabric. The remaining 2 traces >>>> are >>>> standby connections to the standby supervisor/fabric. So, when a >>>> supervisor >>>> engine and its fabric fails, the 2 standby traces are enabled and the >>>> full >>>> 40G of bandwidth remains. You never, under normal circumstances, have >>>> only >>>> a single trace active on 6748. Newer versions of IOS provide a "hot >>>> standby" fabric feature which allows this fabric trace switch over to >>>> happen >>>> faster - roughly 50ms. >>>> >>>> For the best in redundant designs, consider the Nexus 7000, where the >>>> switch >>>> fabric is decoupled from the supervisor engines into a series redundant >>>> "fabric modules" installed into the back of the switch. Should a >>>> supervisor >>>> engine fail in Nexus 7000 there is ZERO impact to the switch fabric, >>>> because >>>> the supervisor engine does not forward data plane traffic. >>>> >>>> Cheers, >>>> >>>> Brad Hedlund >>>> bhedlund at cisco.com >>>> http://www.internetworkexpert.org >>>> >>>> >>>> On 3/31/09 9:05 AM, "Mike Louis" wrote: >>>> >>>> >>>> I have a solution design that requires redundant switch fabrics. I am >>>>> interpreting this beyond just have redundant supervisors meaning >>>>> redundant >>>>> backplanes on the switch cards. Do the 6500 and 4500 support redundant >>>>> fabrics? Will a 6748 function with one trace failed? >>>>> ________________________________ >>>>> Note: This message and any attachments is intended solely for the use >>>>> of the >>>>> individual or entity to which it is addressed and may contain >>>>> information that >>>>> is non-public, proprietary, legally privileged, confidential, and/or >>>>> exempt >>>>> from disclosure. If you are not the intended recipient, you are hereby >>>>> notified that any use, dissemination, distribution, or copying of this >>>>> communication is strictly prohibited. If you have received this >>>>> communication >>>>> in error, please notify the original sender immediately by telephone or >>>>> return >>>>> email and destroy or delete this message along with any attachments >>>>> immediately. >>>>> _______________________________________________ >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>>> >>>>> >>>> >>>> >>>> >>>> _______________________________________________ >>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>> >>>> >>> _______________________________________________ >>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>> >> >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From peter at rathlev.dk Thu Apr 2 20:20:28 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Fri, 03 Apr 2009 02:20:28 +0200 Subject: [c-nsp] 3750/3750E stack upgrade downtime? In-Reply-To: <4340918886AC4B07AD08DC4DE8A740E0@flamdt01> References: <49D1297B.2080106@utc.edu> <1238445916.4440.7.camel@localhost.localdomain> <20090401081546.GE74388@ronin.4ever.de> <37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> <20090401214417.GL74388@ronin.4ever.de> <2F47563BDFE542548FB2A78C99E5723F@flamdt01> <49D3FB25.6050703@utc.edu> <4340918886AC4B07AD08DC4DE8A740E0@flamdt01> Message-ID: <1238718028.6115.48.camel@localhost.localdomain> On Thu, 2009-04-02 at 17:58 -0500, Tony Varriale wrote: > Sure. > > You can reload certain members too. You can reload it yes, but you can't upgrade it during this reload. If a member comes up with another version than the master it is either automatically downgraded or placed in a disabled state. And you can't reload the master without taking down the whole stack. So you can't upgrade the stack w/o downtime. I really wish you could though. :-( Regards, Peter From tvarriale at comcast.net Thu Apr 2 20:26:36 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Thu, 2 Apr 2009 19:26:36 -0500 Subject: [c-nsp] 3750/3750E stack upgrade downtime? References: <49D1297B.2080106@utc.edu> <1238445916.4440.7.camel@localhost.localdomain> <20090401081546.GE74388@ronin.4ever.de> <37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> <20090401214417.GL74388@ronin.4ever.de> <2F47563BDFE542548FB2A78C99E5723F@flamdt01> <49D3FB25.6050703@utc.edu> <4340918886AC4B07AD08DC4DE8A740E0@flamdt01> <1238718028.6115.48.camel@localhost.localdomain> Message-ID: You can reload the master without doing the whole stack. tv ----- Original Message ----- From: "Peter Rathlev" To: "Tony Varriale" Cc: "cisco-nsp" Sent: Thursday, April 02, 2009 7:20 PM Subject: Re: [c-nsp] 3750/3750E stack upgrade downtime? > On Thu, 2009-04-02 at 17:58 -0500, Tony Varriale wrote: >> Sure. >> >> You can reload certain members too. > > You can reload it yes, but you can't upgrade it during this reload. If a > member comes up with another version than the master it is either > automatically downgraded or placed in a disabled state. > > And you can't reload the master without taking down the whole stack. > > So you can't upgrade the stack w/o downtime. I really wish you could > though. :-( > > Regards, > Peter > > From ray at oneunified.net Thu Apr 2 22:46:16 2009 From: ray at oneunified.net (Ray Burkholder) Date: Thu, 2 Apr 2009 23:46:16 -0300 Subject: [c-nsp] Open Source solution to deploy a radius server against Cisco devices? In-Reply-To: <49B65BBF.5000204@thingy.com> References: <1236449092.8327.12.camel@dsba-ipso><49B336CE.3090608@umn.edu> <60C56285-9584-478B-A7CD-C402CBF2ED82@Hughes.com.au> <20090309090932.GB14149@lboro.ac.uk> <1236594848.10690.1.camel@dsba-ipso> <49B65BBF.5000204@thingy.com> Message-ID: > Jon Lewis wrote: > > Another option is Cistron Radius > http://www.radius.cistron.nl/ which > > is probably going to be pretty similar to Freeradius, since > the latter > > is apparently a fork of the former. > > > > Radiator is perl, so you get the 'source code', but it's not open > > source and you do need to buy a license to use it. > The perl aspect also makes it pretty easy to add new > functionality or backends too (assuming you have some perl > experience!) - we added some stuff to restrict what IP > addresses could appear in a Framed-IP-Address entry in about > an hour or so, for example. > FreeRadius has an in-process perl module for handling authetication, authorization, accouting pre and post processing. By filling in the skeleton, it is pretty easy to get customizations done. I had to work a bit with the radius.conf files to get things in the right order, but things worked out nicely. It provides a mechanism for returning customized vendor attributes such as the Framed-IP-Address attribute. -- Scanned for viruses and dangerous content at http://www.oneunified.net and is believed to be clean. From ariemer at wesenergy.com.au Fri Apr 3 00:50:03 2009 From: ariemer at wesenergy.com.au (Aaron Riemer) Date: Fri, 3 Apr 2009 12:50:03 +0800 Subject: [c-nsp] Monitoring External Web Server Message-ID: <0867622C64B50C4B878AB45C95F43F1106A1D55B@MAILWA01.wesenergy.local> Hey guys, We have a requirement to monitor the external availability of a web server that hangs off our ASA DMZ interface. I was thinking of running an IP SLA probe from our external router to test the web requests but I was wondering if anyone had done something with EEM that could possibly try to establish a TCP connection to the web server and report the statistics somehow. I don't want to place a machine outside for the monitoring so would prefer to do it from our router if possible. Any thoughts? Thanks, Aaron. LEGAL DISCLAIMER: This message contains confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system. If you are not the intended recipient you are notified that disclosing, copying, distributing or taking any action in reliance on the contents of this information is strictly prohibited. From mtinka at globaltransit.net Fri Apr 3 02:00:52 2009 From: mtinka at globaltransit.net (Mark Tinka) Date: Fri, 3 Apr 2009 14:00:52 +0800 Subject: [c-nsp] IS-IS LSP Generation/Expiry + Database Optimization - Issue - Update! In-Reply-To: <70B7A1CCBFA5C649BD562B6D9F7ED78406EFE053@xmb-ams-333.emea.cisco.com> References: <200902221357.04134.mtinka@globaltransit.net> <200902222330.46372.mtinka@globaltransit.net> <70B7A1CCBFA5C649BD562B6D9F7ED78406EFE053@xmb-ams-333.emea.cisco.com> Message-ID: <200904031400.52618.mtinka@globaltransit.net> Hi all. So this turned out to be a bug with iSPF in IS-IS. TAC have filed bug ID CSCsy75784. Although first found in 12.2(33)SRC3, this issue affects all versions of SRC, SRD, as well as a few other trains. Cheers, Mark. -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 835 bytes Desc: This is a digitally signed message part. URL: From peter at rathlev.dk Fri Apr 3 04:18:31 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Fri, 03 Apr 2009 10:18:31 +0200 Subject: [c-nsp] 3750/3750E stack upgrade downtime? In-Reply-To: References: <49D1297B.2080106@utc.edu> <1238445916.4440.7.camel@localhost.localdomain> <20090401081546.GE74388@ronin.4ever.de> <37FF646A-6ED6-4331-9AF3-341953AB03B4@djvh.nl> <20090401214417.GL74388@ronin.4ever.de> <2F47563BDFE542548FB2A78C99E5723F@flamdt01> <49D3FB25.6050703@utc.edu> <4340918886AC4B07AD08DC4DE8A740E0@flamdt01> <1238718028.6115.48.camel@localhost.localdomain> Message-ID: <1238746711.3786.56.camel@localhost.localdomain> On Thu, 2009-04-02 at 19:26 -0500, Tony Varriale wrote: > You can reload the master without doing the whole stack. Well, that would select a new master. And this new master has to be running the same software version as the current master, otherwise it would not be able to participate in the stack in the first place. The unit undergoing a reload will not be able to join the stack if it comes up with a new software version. If you know a way of upgrading a 3750 stack without downtime I'd very much like to know; it's a pain for us the way we do it now. :-) Regards, Peter From jgiles at e-dialog.com Fri Apr 3 08:27:10 2009 From: jgiles at e-dialog.com (Jason Giles) Date: Fri, 3 Apr 2009 08:27:10 -0400 Subject: [c-nsp] WS-X6724-SFP & SXI = high cpu usage? In-Reply-To: <458B3EC21E4A3044998E917199AACB2F01A646D5@GNBEX02.gnb.ca> References: <49D44972.9010202@forthnet.gr> <458B3EC21E4A3044998E917199AACB2F01A646D5@GNBEX02.gnb.ca> Message-ID: <5A178C06739A4F4AA21613701E0AD440060C2E97@corp-exc2.ad.e-dialog.com> Not seeing it with the DFC here and sup720-10g. 2 24 CEF720 24 port 1000mb SFP WS-X6724-SFP 2 Distributed Forwarding Card WS-F6700-DFC3C #sho ver Cisco IOS Software, s72033_rp Software (s72033_rp-ADVIPSERVICESK9_WAN-M), Version 12.2(33)SXI, RELEASE SOFTWARE (fc2) CAT6509E-A.BO3#sho plat hardw capa cpu CPU Resources CPU utilization: Module 5 seconds 1 minute 5 minutes 2 3% / 1% 5% 5% CAT6509E-A.BO3#remote command module 2 sh proc cpu sort CPU utilization for five seconds: 4%/1%; one minute: 5%; five minutes: 5% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 192 55227132 1474322 37459 1.59% 1.55% 1.58% 0 Vlan Statistics 238 8745604 741155 11800 0.55% 0.29% 0.29% 0 Hardware API bac 200 8391396 270173484 31 0.39% 0.23% 0.21% 0 fw_lcp process -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Munroe, James (DSS/MAS) Sent: Thursday, April 02, 2009 7:43 AM To: Tassos Chatzithomaoglou; cisco-nsp Subject: Re: [c-nsp] WS-X6724-SFP & SXI = high cpu usage? I've got two 6509's with WS-X6724-SFP (w/ CFC) running SXI and I'm not seeing that problem: 6509 #1: XX#sh mod Mod Ports Card Type Model Serial No. --- ----- -------------------------------------- ------------------ ----------- 1 24 CEF720 24 port 1000mb SFP WS-X6724-SFP XX#remote command module 1 sh proc cpu sort CPU utilization for five seconds: 0%/0%; one minute: 1%; five minutes: 1% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 187 13802188 547904699 25 0.15% 0.19% 0.18% 0 fw_lcp process 1 0 3 0 0.00% 0.00% 0.00% 0 Chunk Manager 2 204 1277786 0 0.00% 0.00% 0.00% 0 Load Meter 3 4 779932 0 0.00% 0.00% 0.00% 0 MFI LFD Timer Pr 5 0 10 0 0.00% 0.00% 0.00% 0 IPC ISSU Dispatc 4 0 43 0 0.00% 0.00% 0.00% 0 Retransmission o XX#sh platform hardware capacity cpu CPU Resources CPU utilization: Module 5 seconds 1 minute 5 minutes 1 0% / 0% 1% 1% 6509 #2: XY#remote command module 2 sh proc cpu sort CPU utilization for five seconds: 0%/0%; one minute: 1%; five minutes: 1% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 187 10049120 536549944 18 0.15% 0.17% 0.15% 0 fw_lcp process XY#sh platform hardware capacity cpu CPU Resources CPU utilization: Module 5 seconds 1 minute 5 minutes 2 2% / 0% 1% 1% Jim -----Original Message----- From: Tassos Chatzithomaoglou [mailto:achatz at forthnet.gr] Sent: Thursday, April 02, 2009 2:13 AM To: cisco-nsp Subject: [c-nsp] WS-X6724-SFP & SXI = high cpu usage? Anyone running SXI with a WS-X6724-SFP module (DFC or non DFC), showing high cpu usage due to the fw_lcp process? 6500#remote command module 1 sh proc cpu sort | exc 0.00 CPU utilization for five seconds: 32%/1%; one minute: 31%; five minutes: 31% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 187 1949496 613964 3175 31.19% 30.47% 30.45% 0 fw_lcp process 6500#sh platform hardware capacity cpu CPU Resources CPU utilization: Module 5 seconds 1 minute 5 minutes 1 28% / 0% 28% 28% 6 RP 1% / 1% 1% 1% 6 SP 18% / 0% 15% 14% 6500#sh mod Mod Ports Card Type Model Serial No. --- ----- -------------------------------------- ------------------ ----------- 1 24 CEF720 24 port 1000mb SFP WS-X6724-SFP XXXXXXXXXXX 6 2 Supervisor Engine 720 (Active) WS-SUP720-3B XXXXXXXXXXX SXH, SXF do not seem to have this problem. -- Tassos _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From paul at paulstewart.org Fri Apr 3 09:03:07 2009 From: paul at paulstewart.org (Paul Stewart) Date: Fri, 3 Apr 2009 09:03:07 -0400 Subject: [c-nsp] BGP Cease - Connection collision resolution Message-ID: <000c01c9b45c$88bbf4e0$9a33dea0$@org> On a peering session we started getting the following: %BGP-3-NOTIFICATION: received from neighbor 198.32.XXX.XX 6/7 (cease) 0 bytes This all started when we "upgraded" to 12.2(18)SXF16 it seems or at least the timeline matches up.. So, I've discovered that 6/7 means "Connection collision resolution" - does anyone know what that means in English? ;) We have rebuilt our session and the peer has done the same thing. a Google search tells me what it means by definition but no real solution. Thanks, Paul From jloiacon at csc.com Fri Apr 3 10:14:52 2009 From: jloiacon at csc.com (Joe Loiacono) Date: Fri, 3 Apr 2009 10:14:52 -0400 Subject: [c-nsp] Monitoring External Web Server In-Reply-To: <0867622C64B50C4B878AB45C95F43F1106A1D55B@MAILWA01.wesenergy.local> Message-ID: If you want to go commercial, we use a software-as-a-service (SAAS) product called Gomez. You periodically contact your server from browser-client nodes on their backbone. You can also execute scripts from these nodes that will walk through your web-site in a pre-determined way. The pricing model is based on a 'cost per measurement' subscription where a measurement is an access of a web-site from a test node. If you do it hourly, that would be 24 per day, etc. Joe "Aaron Riemer" Sent by: cisco-nsp-bounces at puck.nether.net 04/03/2009 12:50 AM To cc Subject [c-nsp] Monitoring External Web Server Hey guys, We have a requirement to monitor the external availability of a web server that hangs off our ASA DMZ interface. I was thinking of running an IP SLA probe from our external router to test the web requests but I was wondering if anyone had done something with EEM that could possibly try to establish a TCP connection to the web server and report the statistics somehow. I don't want to place a machine outside for the monitoring so would prefer to do it from our router if possible. Any thoughts? Thanks, Aaron. LEGAL DISCLAIMER: This message contains confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system. If you are not the intended recipient you are notified that disclosing, copying, distributing or taking any action in reliance on the contents of this information is strictly prohibited. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From fweimer at bfk.de Fri Apr 3 09:51:25 2009 From: fweimer at bfk.de (Florian Weimer) Date: Fri, 03 Apr 2009 15:51:25 +0200 Subject: [c-nsp] BGP Cease - Connection collision resolution In-Reply-To: <000c01c9b45c$88bbf4e0$9a33dea0$@org> (Paul Stewart's message of "Fri, 3 Apr 2009 09:03:07 -0400") References: <000c01c9b45c$88bbf4e0$9a33dea0$@org> Message-ID: <82vdplx2ua.fsf@mid.bfk.de> * Paul Stewart: > So, I've discovered that 6/7 means "Connection collision resolution" - does > anyone know what that means in English? ;) In general, it means that both peers successfully established a TCP connection, and one connection was closed. This happens from time to time and does not indicate a problem. (Or do you mean what it means for this specific IOS version? Sorry, in this case I have to pass.) -- Florian Weimer BFK edv-consulting GmbH http://www.bfk.de/ Kriegsstra?e 100 tel: +49-721-96201-1 D-76133 Karlsruhe fax: +49-721-96201-99 From paul at paulstewart.org Fri Apr 3 10:41:49 2009 From: paul at paulstewart.org (Paul Stewart) Date: Fri, 3 Apr 2009 10:41:49 -0400 Subject: [c-nsp] BGP Cease - Connection collision resolution In-Reply-To: <82vdplx2ua.fsf@mid.bfk.de> References: <000c01c9b45c$88bbf4e0$9a33dea0$@org> <82vdplx2ua.fsf@mid.bfk.de> Message-ID: <002201c9b46a$53146b70$f93d4250$@org> Thanks.... what's happening (and perhaps I should have explained this a bit better) is the session is starting to become established and then dropping. This is repeated every 30-60 seconds over and over and the BGP session never actually establishes. Take care, Paul -----Original Message----- From: Florian Weimer [mailto:fweimer at bfk.de] Sent: Friday, April 03, 2009 9:51 AM To: Paul Stewart Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] BGP Cease - Connection collision resolution * Paul Stewart: > So, I've discovered that 6/7 means "Connection collision resolution" - does > anyone know what that means in English? ;) In general, it means that both peers successfully established a TCP connection, and one connection was closed. This happens from time to time and does not indicate a problem. (Or do you mean what it means for this specific IOS version? Sorry, in this case I have to pass.) -- Florian Weimer BFK edv-consulting GmbH http://www.bfk.de/ Kriegsstra?e 100 tel: +49-721-96201-1 D-76133 Karlsruhe fax: +49-721-96201-99 From steve at ibctech.ca Fri Apr 3 11:02:53 2009 From: steve at ibctech.ca (Steve Bertrand) Date: Fri, 03 Apr 2009 11:02:53 -0400 Subject: [c-nsp] BGP Cease - Connection collision resolution In-Reply-To: <002201c9b46a$53146b70$f93d4250$@org> References: <000c01c9b45c$88bbf4e0$9a33dea0$@org> <82vdplx2ua.fsf@mid.bfk.de> <002201c9b46a$53146b70$f93d4250$@org> Message-ID: <49D6251D.6090802@ibctech.ca> Paul Stewart wrote: > Thanks.... what's happening (and perhaps I should have explained this a bit > better) is the session is starting to become established and then dropping. > This is repeated every 30-60 seconds over and over and the BGP session never > actually establishes. Paul, Does the session stabilize if you put one neighbor (at a time) into passive mode? Steve From paul at paulstewart.org Fri Apr 3 11:08:24 2009 From: paul at paulstewart.org (Paul Stewart) Date: Fri, 3 Apr 2009 11:08:24 -0400 Subject: [c-nsp] BGP Cease - Connection collision resolution In-Reply-To: <49D61683.3010100@utc.fr> References: <000c01c9b45c$88bbf4e0$9a33dea0$@org> <49D61683.3010100@utc.fr> Message-ID: <002301c9b46e$09940e70$1cbc2b50$@org> Thank you - but what is the solution to my problem or is there one? By the sounds of it I need to change out the IOS to a new version....;) -----Original Message----- From: Christophe Fillot [mailto:cf at utc.fr] Sent: Friday, April 03, 2009 10:01 AM To: Paul Stewart Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] BGP Cease - Connection collision resolution Paul Stewart wrote: Hi, > On a peering session we started getting the following: > > > > %BGP-3-NOTIFICATION: received from neighbor 198.32.XXX.XX 6/7 (cease) 0 > bytes > > > > This all started when we "upgraded" to 12.2(18)SXF16 it seems or at least > the timeline matches up.. > > > > So, I've discovered that 6/7 means "Connection collision resolution" - does > anyone know what that means in English? ;) We have rebuilt our session and > the peer has done the same thing. a Google search tells me what it means by > definition but no real solution. > > > From RFC 4271: 6.8. BGP Connection Collision Detection If a pair of BGP speakers try to establish a BGP connection with each other simultaneously, then two parallel connections well be formed. If the source IP address used by one of these connections is the same as the destination IP address used by the other, and the destination IP address used by the first connection is the same as the source IP address used by the other, connection collision has occurred. In the event of connection collision, one of the connections MUST be closed. [...] Closing the BGP connection (that results from the collision resolution procedure) is accomplished by sending the NOTIFICATION message with the Error Code Cease. From vijay.ramcharan at verizonbusiness.com Fri Apr 3 11:05:15 2009 From: vijay.ramcharan at verizonbusiness.com (Ramcharan, Vijay A) Date: Fri, 03 Apr 2009 15:05:15 +0000 Subject: [c-nsp] Monitoring External Web Server In-Reply-To: <0867622C64B50C4B878AB45C95F43F1106A1D55B@MAILWA01.wesenergy.local> Message-ID: <8171C8272CE8FE4A8F5BFF8A97CE6AB367068F@ASHEVS006.mcilink.com> Aaron, I have not delved into EEM but from what I have read about it and its support for TCL, it's entirely possible that you can: 1) Create a TCL script to test your web server with a GET or other method (see http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/ v3.00_A1/configuration/slb/guide/script.html 2) Read the response and perform the appropriate action with EEM (send email, syslog etc) I don't know that such a solution exists already but I believe it is certainly possible to do what you are asking, esp since it's only for one server. Vijay Ramcharan -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Aaron Riemer Sent: April 03, 2009 00:50 To: cisco-nsp at puck.nether.net Subject: [c-nsp] Monitoring External Web Server Hey guys, We have a requirement to monitor the external availability of a web server that hangs off our ASA DMZ interface. I was thinking of running an IP SLA probe from our external router to test the web requests but I was wondering if anyone had done something with EEM that could possibly try to establish a TCP connection to the web server and report the statistics somehow. I don't want to place a machine outside for the monitoring so would prefer to do it from our router if possible. Any thoughts? Thanks, Aaron. LEGAL DISCLAIMER: This message contains confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system. If you are not the intended recipient you are notified that disclosing, copying, distributing or taking any action in reliance on the contents of this information is strictly prohibited. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ ______________________________________________________________________ This e-mail has been scanned by Verizon Managed Email Content Service, using Skeptic(tm) technology powered by MessageLabs. For more information on Verizon Managed Email Content Service, visit http://www.verizonbusiness.com. ______________________________________________________________________ From jloiacon at csc.com Fri Apr 3 11:25:37 2009 From: jloiacon at csc.com (Joe Loiacono) Date: Fri, 3 Apr 2009 11:25:37 -0400 Subject: [c-nsp] Monitoring External Web Server In-Reply-To: Message-ID: Forgot to mention that you control everything from their web-site (hence SAAS) which makes it very easy. You could resell the service ... http://www.gomez.com/ Joe Loiacono/CIV/CSC at CSC Sent by: cisco-nsp-bounces at puck.nether.net 04/03/2009 10:14 AM To "Aaron Riemer" cc cisco-nsp-bounces at puck.nether.net, cisco-nsp at puck.nether.net Subject Re: [c-nsp] Monitoring External Web Server If you want to go commercial, we use a software-as-a-service (SAAS) product called Gomez. You periodically contact your server from browser-client nodes on their backbone. You can also execute scripts from these nodes that will walk through your web-site in a pre-determined way. The pricing model is based on a 'cost per measurement' subscription where a measurement is an access of a web-site from a test node. If you do it hourly, that would be 24 per day, etc. Joe "Aaron Riemer" Sent by: cisco-nsp-bounces at puck.nether.net 04/03/2009 12:50 AM To cc Subject [c-nsp] Monitoring External Web Server Hey guys, We have a requirement to monitor the external availability of a web server that hangs off our ASA DMZ interface. I was thinking of running an IP SLA probe from our external router to test the web requests but I was wondering if anyone had done something with EEM that could possibly try to establish a TCP connection to the web server and report the statistics somehow. I don't want to place a machine outside for the monitoring so would prefer to do it from our router if possible. Any thoughts? Thanks, Aaron. LEGAL DISCLAIMER: This message contains confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system. If you are not the intended recipient you are notified that disclosing, copying, distributing or taking any action in reliance on the contents of this information is strictly prohibited. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From cf at utc.fr Fri Apr 3 11:30:52 2009 From: cf at utc.fr (Christophe Fillot) Date: Fri, 03 Apr 2009 17:30:52 +0200 Subject: [c-nsp] BGP Cease - Connection collision resolution In-Reply-To: <002301c9b46e$09940e70$1cbc2b50$@org> References: <000c01c9b45c$88bbf4e0$9a33dea0$@org> <49D61683.3010100@utc.fr> <002301c9b46e$09940e70$1cbc2b50$@org> Message-ID: <49D62BAC.6090100@utc.fr> Paul Stewart wrote: > Thank you - but what is the solution to my problem or is there one? By the > sounds of it I need to change out the IOS to a new version....;) > In theory this should resolve automatically, but it is abnormal if your session never establishes. If this began to happen with 12.2(18)SXF16 and if there was no config change, I guess it is a problem with this specific IOS release. What is the router on the remote side ? From cf at utc.fr Fri Apr 3 10:00:35 2009 From: cf at utc.fr (Christophe Fillot) Date: Fri, 03 Apr 2009 16:00:35 +0200 Subject: [c-nsp] BGP Cease - Connection collision resolution In-Reply-To: <000c01c9b45c$88bbf4e0$9a33dea0$@org> References: <000c01c9b45c$88bbf4e0$9a33dea0$@org> Message-ID: <49D61683.3010100@utc.fr> Paul Stewart wrote: Hi, > On a peering session we started getting the following: > > > > %BGP-3-NOTIFICATION: received from neighbor 198.32.XXX.XX 6/7 (cease) 0 > bytes > > > > This all started when we "upgraded" to 12.2(18)SXF16 it seems or at least > the timeline matches up.. > > > > So, I've discovered that 6/7 means "Connection collision resolution" - does > anyone know what that means in English? ;) We have rebuilt our session and > the peer has done the same thing. a Google search tells me what it means by > definition but no real solution. > > > From RFC 4271: 6.8. BGP Connection Collision Detection If a pair of BGP speakers try to establish a BGP connection with each other simultaneously, then two parallel connections well be formed. If the source IP address used by one of these connections is the same as the destination IP address used by the other, and the destination IP address used by the first connection is the same as the source IP address used by the other, connection collision has occurred. In the event of connection collision, one of the connections MUST be closed. [...] Closing the BGP connection (that results from the collision resolution procedure) is accomplished by sending the NOTIFICATION message with the Error Code Cease. From elmi at 4ever.de Fri Apr 3 11:31:29 2009 From: elmi at 4ever.de (Elmar K. Bins) Date: Fri, 3 Apr 2009 17:31:29 +0200 Subject: [c-nsp] Too dumb for SLB on ASR1Ks? Message-ID: <20090403153128.GA12333@ronin.4ever.de> Maybe someone can point me to a document that helps me through - or Rodney cuts in and tells me it's a bug ;) I have the following pretty simple (stripped down) configuration which does work on a 7201 and does not work on the ASR1000... (Yes, on the ASR the interface has 0/0/0 instead of 0/0 *g*) 7201 image is 12.4(4)XD10 IPBase ASR1K image is a derivative of 12.2(33)XNB (experimental version with a bugfix) Tests with standard 12.2(33)XNB1 failed as well. Feature set is AdvancedEnterpriseK9 on the ASR. If there's a hint that work has been done on SLB in newer releases, I'm willing to try that... Any idea very much appreciated here - I'm pretty much stuck and am not sure whether I'm looking at my stupidity or a bug. Yours, Elmar. ================================================================ ip slb serverfarm FARM-DNS real 10.10.236.12 inservice ! ip slb vserver VS-DNS virtual 10.10.237.53 udp 53 serverfarm FARM-DNS sticky 5 idle 5 delay 1 inservice ! ip slb vserver VS-DNS-TCP virtual 10.10.237.53 tcp dns serverfarm FARM-DNS sticky 10 idle 10 inservice ! interface GigabitEthernet0/0 no ip address load-interval 30 duplex auto speed auto media-type sfp negotiation auto ! interface GigabitEthernet0/0.701 encapsulation dot1Q 701 ip address 10.10.235.1 255.255.255.0 ! interface GigabitEthernet0/0.702 encapsulation dot1Q 702 ip address 10.10.236.1 255.255.255.0 ================================================================ From paul at paulstewart.org Fri Apr 3 12:02:13 2009 From: paul at paulstewart.org (Paul Stewart) Date: Fri, 3 Apr 2009 12:02:13 -0400 Subject: [c-nsp] BGP Cease - Connection collision resolution In-Reply-To: <49D62BAC.6090100@utc.fr> References: <000c01c9b45c$88bbf4e0$9a33dea0$@org> <49D61683.3010100@utc.fr> <002301c9b46e$09940e70$1cbc2b50$@org> <49D62BAC.6090100@utc.fr> Message-ID: <002a01c9b475$8e12a650$aa37f2f0$@org> Thank you - unfortunately I do not know about the equipment on the other side but it was working perfectly up til the IOS release. This release also seems to have reintroduced the ttl-security bug that was happening a couple of releases back...;( The folks on the other side of the link tell me I'm the only peer they are experiencing this issue with... Take care, Paul -----Original Message----- From: Christophe Fillot [mailto:cf at utc.fr] Sent: Friday, April 03, 2009 11:31 AM To: Paul Stewart Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] BGP Cease - Connection collision resolution Paul Stewart wrote: > Thank you - but what is the solution to my problem or is there one? By the > sounds of it I need to change out the IOS to a new version....;) > In theory this should resolve automatically, but it is abnormal if your session never establishes. If this began to happen with 12.2(18)SXF16 and if there was no config change, I guess it is a problem with this specific IOS release. What is the router on the remote side ? From ddunkin at netos.net Fri Apr 3 16:09:51 2009 From: ddunkin at netos.net (Darryl Dunkin) Date: Fri, 3 Apr 2009 13:09:51 -0700 Subject: [c-nsp] BGP Cease - Connection collision resolution In-Reply-To: <002a01c9b475$8e12a650$aa37f2f0$@org> References: <000c01c9b45c$88bbf4e0$9a33dea0$@org> <49D61683.3010100@utc.fr><002301c9b46e$09940e70$1cbc2b50$@org> <49D62BAC.6090100@utc.fr> <002a01c9b475$8e12a650$aa37f2f0$@org> Message-ID: <56F5BC5F404CF84896C447397A1AAF20D19835@MAIL.nosi.netos.com> Have you checked the capabilities being negotiated with that peer to see if anything new was negotiated up after the change? -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Paul Stewart Sent: Friday, April 03, 2009 09:02 To: 'Christophe Fillot' Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] BGP Cease - Connection collision resolution Thank you - unfortunately I do not know about the equipment on the other side but it was working perfectly up til the IOS release. This release also seems to have reintroduced the ttl-security bug that was happening a couple of releases back...;( The folks on the other side of the link tell me I'm the only peer they are experiencing this issue with... Take care, Paul -----Original Message----- From: Christophe Fillot [mailto:cf at utc.fr] Sent: Friday, April 03, 2009 11:31 AM To: Paul Stewart Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] BGP Cease - Connection collision resolution Paul Stewart wrote: > Thank you - but what is the solution to my problem or is there one? By the > sounds of it I need to change out the IOS to a new version....;) > In theory this should resolve automatically, but it is abnormal if your session never establishes. If this began to happen with 12.2(18)SXF16 and if there was no config change, I guess it is a problem with this specific IOS release. What is the router on the remote side ? _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From tdurack at gmail.com Fri Apr 3 16:14:40 2009 From: tdurack at gmail.com (Tim Durack) Date: Fri, 3 Apr 2009 16:14:40 -0400 Subject: [c-nsp] same-router tunnel loopback Message-ID: <9e246b4d0904031314p5db46d44uf8dac478cc22ae05@mail.gmail.com> Using a same-router tunnel loopback to move traffic between global and vrf on a SUP720: rtr-1#sh run int tun254 Building configuration... Current configuration : 251 bytes ! interface Tunnel254 vrf forwarding v101 ip address 10.1.0.254 255.255.255.254 ip mtu 1500 ipv6 address FE80:0:1970::254 link-local ipv6 address xxxx:0:1970::254/127 ipv6 enable tunnel source Loopback254 tunnel destination 169.254.0.255 end rtr-1#sh run int tun255 Building configuration... Current configuration : 230 bytes ! interface Tunnel255 ip address 10.1.0.255 255.255.255.254 ip mtu 1500 ipv6 address FE80:0:1970::255 link-local ipv6 address xxxx:0:1970::255/127 ipv6 enable tunnel source Loopback255 tunnel destination 169.254.0.254 end Works for ipv4: rtr-1#ping 10.1.0.254 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10.1.0.254, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 4/4/8 ms But not ipv6: rtr-1#ping ipv6 xxxx:0:1970::254 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to xxxx:0:1970::254, timeout is 2 seconds: ..... Success rate is 0 percent (0/5) What am I doing wrong? From charles at thewybles.com Fri Apr 3 17:01:08 2009 From: charles at thewybles.com (Charles Wyble) Date: Fri, 03 Apr 2009 14:01:08 -0700 Subject: [c-nsp] Monitoring External Web Server In-Reply-To: References: Message-ID: <49D67914.2000207@thewybles.com> I would strongly recommend keynote over gomez. It's what a lot of folks use. Gomez has some interesting features, but I found them harder to work with. Pingdom is also a popular choice. Or you could just use nagios or other monitoring tools.... do you have any sort of network management/monitoring now? If so it's highly likely you can add a probe for an HTTP service. In fact I wouldn't recommend testing from the router, as that may be a false positive (think someone changes an ACL and it's broken from everywhere but the router). So often you will want monitoring of both the "front channel" and the "back channel". Really don't know enough about your architecture to be sure. I'm basing this on the architecture I have used at multiple organizations, where one has a DMZ/Vlan and a management VLAN, with servers having a NIC in each. Joe Loiacono wrote: > Forgot to mention that you control everything from their web-site (hence > SAAS) which makes it very easy. You could resell the service ... > > http://www.gomez.com/ > > > > > Joe Loiacono/CIV/CSC at CSC > Sent by: cisco-nsp-bounces at puck.nether.net > 04/03/2009 10:14 AM > > To > "Aaron Riemer" > cc > cisco-nsp-bounces at puck.nether.net, cisco-nsp at puck.nether.net > Subject > Re: [c-nsp] Monitoring External Web Server > > > > > > > If you want to go commercial, we use a software-as-a-service (SAAS) > product called Gomez. You periodically contact your server from > browser-client nodes on their backbone. You can also execute scripts from > these nodes that will walk through your web-site in a pre-determined way. > > The pricing model is based on a 'cost per measurement' subscription where > a measurement is an access of a web-site from a test node. If you do it > hourly, that would be 24 per day, etc. > > Joe > > > > > "Aaron Riemer" > Sent by: cisco-nsp-bounces at puck.nether.net > 04/03/2009 12:50 AM > > To > > cc > > Subject > [c-nsp] Monitoring External Web Server > > > > > > > Hey guys, > > We have a requirement to monitor the external availability of a web > server that hangs off our ASA DMZ interface. I was thinking of running > an IP SLA probe from our external router to test the web requests but I > was wondering if anyone had done something with EEM that could possibly > try to establish a TCP connection to the web server and report the > statistics somehow. I don't want to place a machine outside for the > monitoring so would prefer to do it from our router if possible. > > Any thoughts? > > Thanks, > > Aaron. > > LEGAL DISCLAIMER: This message contains confidential information and is > intended only for the individual named. If you are not the named addressee > > you should not disseminate, distribute or copy this e-mail. Please notify > the sender immediately by e-mail if you have received this e-mail by > mistake and delete this e-mail from your system. If you are not the > intended recipient you are notified that disclosing, copying, distributing > > or taking any action in reliance on the contents of this information is > strictly prohibited. > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From justin at justinshore.com Fri Apr 3 17:11:40 2009 From: justin at justinshore.com (Justin Shore) Date: Fri, 03 Apr 2009 16:11:40 -0500 Subject: [c-nsp] Emulating the L2 aspect of VPLS with VRF-lite Message-ID: <49D67B8C.9090204@justinshore.com> Sorry for the length. I have another Friday mind-bender. We're going into an agreement with a new customer to replace their existing shared radio infrastructure with several bonded PtP DS1s at a number of sites and a DS3 at a main site. The owner of the radios infrastructure currently places the WAN-facing interface of all of this customer's routers into a common VLAN (ie all WAN-facing routers have a connected route to a like interface on all other WAN routers). The customer currently establishes IPSec-protected GRE tunnels from each router to every other router using the connected interfaces. Then they run EIGRP over top of the GRE tunnels. The radio links emulate the L2 aspect of VPLS or an E-LAN service with that simple little VLAN. I'm trying to do something similar with completely different hardware. I can't reach any of these sites with VLAN-capable hardware yet. Most of the sites are getting several bonded DS1s. One main site is getting a DS3 over Overture (Ethernet bridged over the DS3 and handed off as Ethernet on both ends; the 7206 gets it as a sub-int on a GigE port). My initial thought was to put each of the customer's MLPPP interfaces as well as the GigE sub-int for the Ethernet site into a VRF. Each separate interface would be a /30 and I'd be a routed hop in the middle inside of their VRF (everything comes back ultimately to a single 7200). They could tunnel across me if they wanted with a few additional statics to populate the RIB with next-hop information of the other routers. I'm confident that this would work however I think there may be a better way that minimizes our potential involvement in the middle. Thinking about it a bit more I decided that I could provide a L2 service by making each of the MLPPP interfaces and the GigE sub-int unnumbered up to a common loopback. Each customer WAN-facing interface would be addressed from a common subnet. They should then also be able to directly communicate with one another across the loopback and establish routing adjacencies and/or build GRE tunnels with the hosts in that common connected route. That's where I'm at right now. I have 2 test routers with a DS1 bundle on each back to the 7200. Each bundle is in the customer VRF. I have another router doing Ethernet into a 4948 access switchport. That unique VLAN gets trunked up to the 7200 on an on-board GigE interface. The corresponding sub-int on the 7200 is in the customer VRF and is unnumbered back to the dedicated customer loopback. The only error I got in the process was when I did the unnumbered on the sub-int. 003018: Apr 3 13:15:29 CDT: %OSPF-4-NO_IPADDRESS_ON_INT: No IP address for interface GigabitEthernet0/2.1001 That's just OSPF whining and shouldn't be a problem. I set up OSPF on all WAN-facing interfaces on the CE lab routers. For grins I also set up OSPF inside the VRF on the PE. I can ping between the DS1 routers and the 7200. However I can not ping the Ethernet CE router from anywhere. I also can not establish OSPF adjacencies between any of the CEs or the PE. Debugging the OSPF packets I see packets going out from the CEs but nothing coming in. From the PE I see nothing at all. Should this ip unnumbered design work? Any idea what's dropping the OSPF packets along the way? I'm working on the problem while typing this and I have an update on what I wrote above. I now have OSPF adjacencies between the DS1 CPEs and the 7200. It turns out I needed to put the MLPPP interface into the VRF as well even though the ip unnumbered interface as in the VRF already. However this points out a problem. I am unable to establish an adjacency between the DS1 CPEs. The CPEs only claim to see OSPF packets from the 7200. Is that normal? I also just noticed that I can no longer ping between DS1 CPEs. I'm not sure if this isn't being consistent or I should call it a day. I should be able to do the VRF with the L3 hop in the middle if nothing else. I'd rather that be my fall-back position though. Any other suggestions on how to accomplish this would be much appreciated. I'm sure there are other ways to do something similar. Thanks Justin From illcritikz at gmail.com Fri Apr 3 19:37:24 2009 From: illcritikz at gmail.com (Ben Steele) Date: Sat, 4 Apr 2009 10:07:24 +1030 Subject: [c-nsp] Too dumb for SLB on ASR1Ks? In-Reply-To: <20090403153128.GA12333@ronin.4ever.de> References: <20090403153128.GA12333@ronin.4ever.de> Message-ID: <4422cf660904031637x7b694144h4159cf61e2dd4ab6@mail.gmail.com> What part exactly doesn't work? just the load balancing? do you have IP connectivity ok to your real servers? how is that virtual IP being sent to the box? it's not listed anywhere in your configuration on how 10.10.237.x gets to the box. On Sat, Apr 4, 2009 at 2:01 AM, Elmar K. Bins wrote: > Maybe someone can point me to a document that helps me through - or > Rodney cuts in and tells me it's a bug ;) > > I have the following pretty simple (stripped down) configuration > which does work on a 7201 and does not work on the ASR1000... > > (Yes, on the ASR the interface has 0/0/0 instead of 0/0 *g*) > > 7201 image is 12.4(4)XD10 IPBase > > ASR1K image is a derivative of 12.2(33)XNB (experimental version with a > bugfix) > Tests with standard 12.2(33)XNB1 failed as well. > Feature set is AdvancedEnterpriseK9 on the ASR. > If there's a hint that work has been done on SLB in newer > releases, I'm willing to try that... > > Any idea very much appreciated here - I'm pretty much stuck > and am not sure whether I'm looking at my stupidity or a bug. > > Yours, > Elmar. > > > ================================================================ > > ip slb serverfarm FARM-DNS > real 10.10.236.12 > inservice > ! > ip slb vserver VS-DNS > virtual 10.10.237.53 udp 53 > serverfarm FARM-DNS > sticky 5 > idle 5 > delay 1 > inservice > ! > ip slb vserver VS-DNS-TCP > virtual 10.10.237.53 tcp dns > serverfarm FARM-DNS > sticky 10 > idle 10 > inservice > ! > interface GigabitEthernet0/0 > no ip address > load-interval 30 > duplex auto > speed auto > media-type sfp > negotiation auto > ! > interface GigabitEthernet0/0.701 > encapsulation dot1Q 701 > ip address 10.10.235.1 255.255.255.0 > ! > interface GigabitEthernet0/0.702 > encapsulation dot1Q 702 > ip address 10.10.236.1 255.255.255.0 > > ================================================================ > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From danletkeman at gmail.com Fri Apr 3 21:10:09 2009 From: danletkeman at gmail.com (Dan Letkeman) Date: Fri, 3 Apr 2009 20:10:09 -0500 Subject: [c-nsp] aironet disable ssid when no lan connection Message-ID: Hello, Is there a command on an 1131ag aironet ap that allows you to disable the ssid broadcast if there is no lan connection to the ap? Thanks, Dan. From mhuff at ox.com Sat Apr 4 00:30:37 2009 From: mhuff at ox.com (Matthew Huff) Date: Sat, 4 Apr 2009 00:30:37 -0400 Subject: [c-nsp] aironet disable ssid when no lan connection In-Reply-To: Message-ID: Will "station-role root access-point fallback track fa 0" under the radio interface work for you? On 4/3/09 9:10 PM, "Dan Letkeman" wrote: Hello, Is there a command on an 1131ag aironet ap that allows you to disable the ssid broadcast if there is no lan connection to the ap? Thanks, Dan. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From gert at greenie.muc.de Sat Apr 4 04:56:52 2009 From: gert at greenie.muc.de (Gert Doering) Date: Sat, 4 Apr 2009 10:56:52 +0200 Subject: [c-nsp] same-router tunnel loopback In-Reply-To: <9e246b4d0904031314p5db46d44uf8dac478cc22ae05@mail.gmail.com> References: <9e246b4d0904031314p5db46d44uf8dac478cc22ae05@mail.gmail.com> Message-ID: <20090404085652.GR290@greenie.muc.de> Hi, On Fri, Apr 03, 2009 at 04:14:40PM -0400, Tim Durack wrote: > Using a same-router tunnel loopback to move traffic between global and > vrf on a SUP720: One small but essential bit is missing: what IOS version? Are you sure the IOS you use supports IPv6 VRF (this was added MUCH later than IPv4 VRF)? (Maybe it's just the /127 - try with /124 or /64, just to be sure) gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From elmi at 4ever.de Sat Apr 4 07:02:47 2009 From: elmi at 4ever.de (Elmar K. Bins) Date: Sat, 4 Apr 2009 13:02:47 +0200 Subject: [c-nsp] Too dumb for SLB on ASR1Ks? In-Reply-To: <4422cf660904031637x7b694144h4159cf61e2dd4ab6@mail.gmail.com> References: <20090403153128.GA12333@ronin.4ever.de> <4422cf660904031637x7b694144h4159cf61e2dd4ab6@mail.gmail.com> Message-ID: <20090404110247.GB29526@ronin.4ever.de> illcritikz at gmail.com (Ben Steele) wrote: > What part exactly doesn't work? just the load balancing? do you have IP > connectivity ok to your real servers? how is that virtual IP being sent to > the box? it's not listed anywhere in your configuration on how 10.10.237.x > gets to the box. This is the lab setup; you can count on routing being alright - connectivity among all parts of the setup is working, and I reconfigured the servers myself (UNIX guys usually get netmasks etc. wrong *g*). You can also see this from the drop-in replacement (7201) working perfectly in the setup. The point is that the ASR receives the packets but doesn't push them on. They do not appear in any statistics (SLB or port) and they do not appear on the wire or on the target server. There are two things that would help my cause, one being an idea whether someone else successfully or unsuccessfully used SLB on ASRs (or the info about serious trouble there). Then I'd like to compare configs; maybe I forgot some magic word. There is no documentation for SLB on IOS XE to be found, so I'd be happy about pointers towards recipes or HowTos, since 7*** configs don't seem to work - provided it's not some crazy bug that keeps the ASR from pushing the packets on. Thanks for any insight, Elmar. > On Sat, Apr 4, 2009 at 2:01 AM, Elmar K. Bins wrote: > > > Maybe someone can point me to a document that helps me through - or > > Rodney cuts in and tells me it's a bug ;) > > > > I have the following pretty simple (stripped down) configuration > > which does work on a 7201 and does not work on the ASR1000... > > > > (Yes, on the ASR the interface has 0/0/0 instead of 0/0 *g*) > > > > 7201 image is 12.4(4)XD10 IPBase > > > > ASR1K image is a derivative of 12.2(33)XNB (experimental version with a > > bugfix) > > Tests with standard 12.2(33)XNB1 failed as well. > > Feature set is AdvancedEnterpriseK9 on the ASR. > > If there's a hint that work has been done on SLB in newer > > releases, I'm willing to try that... > > > > Any idea very much appreciated here - I'm pretty much stuck > > and am not sure whether I'm looking at my stupidity or a bug. > > > > Yours, > > Elmar. > > > > > > ================================================================ > > > > ip slb serverfarm FARM-DNS > > real 10.10.236.12 > > inservice > > ! > > ip slb vserver VS-DNS > > virtual 10.10.237.53 udp 53 > > serverfarm FARM-DNS > > sticky 5 > > idle 5 > > delay 1 > > inservice > > ! > > ip slb vserver VS-DNS-TCP > > virtual 10.10.237.53 tcp dns > > serverfarm FARM-DNS > > sticky 10 > > idle 10 > > inservice > > ! > > interface GigabitEthernet0/0 > > no ip address > > load-interval 30 > > duplex auto > > speed auto > > media-type sfp > > negotiation auto > > ! > > interface GigabitEthernet0/0.701 > > encapsulation dot1Q 701 > > ip address 10.10.235.1 255.255.255.0 > > ! > > interface GigabitEthernet0/0.702 > > encapsulation dot1Q 702 > > ip address 10.10.236.1 255.255.255.0 > > > > ================================================================ From jared at puck.nether.net Sat Apr 4 08:27:30 2009 From: jared at puck.nether.net (Jared Mauch) Date: Sat, 4 Apr 2009 08:27:30 -0400 Subject: [c-nsp] aironet disable ssid when no lan connection In-Reply-To: References: Message-ID: <60BEAE40-CA38-4FAA-9ABE-BE72AC682402@puck.nether.net> I'm guessing he wants: AP1121-Attic(config-if)#station-role root fallback ? repeater Become a repeater shutdown Shutdown the radio the 'shutdown' option. - Jared On Apr 4, 2009, at 12:30 AM, Matthew Huff wrote: > Will "station-role root access-point fallback track fa 0" under the > radio interface work for you? > > > On 4/3/09 9:10 PM, "Dan Letkeman" wrote: > > Hello, > > Is there a command on an 1131ag aironet ap that allows you to disable > the ssid broadcast if there is no lan connection to the ap? > > Thanks, > Dan. > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From danletkeman at gmail.com Sat Apr 4 14:36:33 2009 From: danletkeman at gmail.com (Dan Letkeman) Date: Sat, 4 Apr 2009 13:36:33 -0500 Subject: [c-nsp] aironet disable ssid when no lan connection In-Reply-To: References: Message-ID: I think the shutdown command would work. Thanks! On Fri, Apr 3, 2009 at 11:30 PM, Matthew Huff wrote: > Will "station-role root access-point fallback track fa 0" ?under the radio interface work for you? > > > On 4/3/09 9:10 PM, "Dan Letkeman" wrote: > > Hello, > > Is there a command on an 1131ag aironet ap that allows you to disable > the ssid broadcast if there is no lan connection to the ap? > > Thanks, > Dan. > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > From oboehmer at cisco.com Sat Apr 4 14:51:34 2009 From: oboehmer at cisco.com (Oliver Boehmer (oboehmer)) Date: Sat, 4 Apr 2009 20:51:34 +0200 Subject: [c-nsp] L2TPv3 password keeps changing In-Reply-To: <49D2AAE8.3030503@corp.sonic.net> References: <44417CD2F19FEA4F885088340A71D33201B4F41D@mail.office.dansketelecom.com> <49D2AAE8.3030503@corp.sonic.net> Message-ID: <70B7A1CCBFA5C649BD562B6D9F7ED7840727E3E7@xmb-ams-333.emea.cisco.com> I only found CSCso12545 (l2tp-class encrypted password recalculated after every 'show run'), but without any resolution so far.. Feel free to contact TAC. oli Jared Gillis <> wrote on Wednesday, April 01, 2009 01:45: > I'm seeing this behavior as well on a 7204VXR, and google only turns > up two threads on c-nsp that have no replies. > Is this expected? Is there a workaround? > > Lars Lystrup Christensen wrote: >> >> >> Hi all, >> >> >> >> When configuring L2TPv3 on one of our routers, I've noticed that the >> password keeps changing all the time, even tough the configuration >> has not been altered. >> >> >> >> The router is a 1811 running 12.4(6)T11 Advanced IP Services. >> >> ______________________________________ >> >> Med venlig hilsen / Kind regards >> >> Lars Lystrup Christensen >> Director of Engineering, CCIE(tm) #20292 >> >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ From oboehmer at cisco.com Sat Apr 4 15:12:48 2009 From: oboehmer at cisco.com (Oliver Boehmer (oboehmer)) Date: Sat, 4 Apr 2009 21:12:48 +0200 Subject: [c-nsp] MTU settings on GSR linecard 3GE-GBIC-SC In-Reply-To: <49D0C905.4030903@schlund.net> References: <49D0C905.4030903@schlund.net> Message-ID: <70B7A1CCBFA5C649BD562B6D9F7ED7840727E3EB@xmb-ams-333.emea.cisco.com> Jan Sandmaier <> wrote on Monday, March 30, 2009 15:29: > Hi, > > does anybody know the reason why I can configure a 9180 byte MTU on > port 0 and 1 on a GSR 3-port Gigabit Ethernet port (3GE-GBIC-SC) but > only 4470 byte on the third port. I use IOS 12.0(32)S12 and > 12.0(31)S6. this is a hardware limitiation on the FPGA (limited RX Fifo buffers) on this Engine2 LC. Max MTU on the third port depends on the settings on the other two, so you can't even go up to 4470 if you set the first to 9k.. oli From tdurack at gmail.com Sat Apr 4 19:29:02 2009 From: tdurack at gmail.com (Tim Durack) Date: Sat, 4 Apr 2009 19:29:02 -0400 Subject: [c-nsp] same-router tunnel loopback In-Reply-To: <20090404085652.GR290@greenie.muc.de> References: <9e246b4d0904031314p5db46d44uf8dac478cc22ae05@mail.gmail.com> <20090404085652.GR290@greenie.muc.de> Message-ID: <9e246b4d0904041629i7fd97176obf8097ee2b4d2390@mail.gmail.com> On Sat, Apr 4, 2009 at 4:56 AM, Gert Doering wrote: > Hi, > > On Fri, Apr 03, 2009 at 04:14:40PM -0400, Tim Durack wrote: >> Using a same-router tunnel loopback to move traffic between global and >> vrf on a SUP720: > > One small but essential bit is missing: what IOS version? Are you sure > the IOS you use supports IPv6 VRF (this was added MUCH later than IPv4 VRF)? SXI. IPv6 AF works fine in the VRFs, just not across the tunnel. > (Maybe it's just the /127 - try with /124 or /64, just to be sure) That crossed my mind. Didn't try it yet. Tim:> From eng_mssk at hotmail.com Sun Apr 5 05:40:34 2009 From: eng_mssk at hotmail.com (Mohammad Khalil) Date: Sun, 5 Apr 2009 12:40:34 +0300 Subject: [c-nsp] show inventory Message-ID: Hey all i issue the command show inventory on some devices and no output is there and the other is ok any ideas ? _________________________________________________________________ More than messages?check out the rest of the Windows Live?. http://www.microsoft.com/windows/windowslive/ From werner at trans.net Sun Apr 5 07:44:42 2009 From: werner at trans.net (Werner Detter) Date: Sun, 05 Apr 2009 13:44:42 +0200 Subject: [c-nsp] bgp_cpu2timeout and %LINK-4-NOMAC In-Reply-To: <49C0EB08.8020604@trans.net> References: <49C0EB08.8020604@trans.net> Message-ID: <49D899AA.2020904@trans.net> Hi, > *Mar 18 11:35:04.091: bgp_cpu2timeout: seconds: 30000, slot: 3 for 5: 0% and 1: 0% > *Mar 18 11:35:34.875: bgp_cpu2timeout: seconds: 30000, slot: 3 for 5: 0% and 1: 0% > > %LINK-4-NOMAC: A random default MAC address of 0000.0c82.a9fb has > been chosen. Ensure that this address is unique, or specify MAC > addresses for commands (such as 'novell routing') that allow the > use of this address as a default Messages gone since I've changed the 7206VXR-Chassis. bye, Werner From raymondh.nsp at gmail.com Sun Apr 5 09:45:48 2009 From: raymondh.nsp at gmail.com (raymondh (NSP)) Date: Sun, 5 Apr 2009 21:45:48 +0800 Subject: [c-nsp] show inventory In-Reply-To: References: Message-ID: <06657F64-46A5-4F79-8337-EBE498AC74BA@gmail.com> try this. sh invent raw --raymondh On Apr 5, 2009, at 5:40 PM, Mohammad Khalil wrote: > > Hey all > > i issue the command show inventory on some devices and no output is > there and the other is ok > > any ideas ? > > _________________________________________________________________ > More than messages?check out the rest of the Windows Live?. > http://www.microsoft.com/windows/windowslive/ > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From tedm at toybox.placo.com Sun Apr 5 11:24:44 2009 From: tedm at toybox.placo.com (Ted Mittelstaedt) Date: Sun, 05 Apr 2009 08:24:44 -0700 Subject: [c-nsp] Monitoring External Web Server In-Reply-To: <0867622C64B50C4B878AB45C95F43F1106A1D55B@MAILWA01.wesenergy.local> References: <0867622C64B50C4B878AB45C95F43F1106A1D55B@MAILWA01.wesenergy.local> Message-ID: <49D8CD3C.1020709@toybox.placo.com> Aaron Riemer wrote: > Hey guys, > > We have a requirement to monitor the external availability of a web > server that hangs off our ASA DMZ interface. I was thinking of running > an IP SLA probe from our external router to test the web requests but I > was wondering if anyone had done something with EEM that could possibly > try to establish a TCP connection to the web server and report the > statistics somehow. I don't want to place a machine outside for the > monitoring so would prefer to do it from our router if possible. > > Any thoughts? > You won't get true monitoring unless you place 2 machines on the outside and put a modem in one and run sendpage software on it - OR use a commercial service. I run paging software under FreeBSD running on an old P200 machine. I had to try several different modems before getting one that worked right with the software. The reason you need this is that if your Internet connection goes down your router cannot page you that there's a problem. The reason you need 2 machines is that if one of the monitoring systems goes offline. In my setup both systems monitor each other. I also monitor a few major websites (google, etc.) to make sure we still have connectivity. The only problem I have now is when my cell phone battery dies. ;-) Ted From musmanashraf at gmail.com Sun Apr 5 13:59:02 2009 From: musmanashraf at gmail.com (M Usman Ashraf) Date: Sun, 5 Apr 2009 22:59:02 +0500 Subject: [c-nsp] CISCO ACS 4.2 command pattern matching Message-ID: <9149d2410904051059u4a3d7d2h5894d495481be4e6@mail.gmail.com> Hi List, I have been testing pattern matching with ACS shell command auth sets and it doesn't seem to work like the ACS documentation says. Quote from the Cisco ACS user guide: *For permit or deny command arguments, ACS applies pattern matching. That is, the argument permit wid matches any argument that contains the string wid. Thus, for example, permit wid would allow not only the argument wid but also the arguments anywid and widget.* *To limit the extent of pattern matching you can add the following expressions:* *? Dollarsign ($)* *?Expresses that the argument must end with what has gone before. Thus permit wid$ would match wid or anywid, but not widget.* *? Caret (^)* *?Expresses that the argument must begin with what follows. Thus permit ^wid would match wid or widget, but not anywid. You can combine these expressions to specify absolute matching. In the example given, you would use permit ^wid$ to ensure that only wid was permitted, and not anywid or widget.* *To permit or deny commands that carry no arguments, you can use absolute matching to specify the null argument condition. For example, you use permit ^$ to permit a command with no arguments. Alternatively, entering permit has the same effect. You can use either method, with the Permit Unmatched Args option unchecked, to match and, therefore, permit or deny commands that have no agrument.* ---------------------------------------------------------------------------------------- So from this I take that if I want to deny configuration of certain interfaces say Loopback0, while allowing configuration of Loopback99, I will, permit "interface" , with the sub-command arguments: permit*^Loopback99$ *, unmatched commands are "deny" and "Permit Unmatched Args" is unchecked. Thinking that would allow the command interface Loopback99 but actually the "interface Loopback99" commands, fails authorization. On the other side, if I permit *^Loopback* only, all loopbacks get permitted. It seems like the "^" pattern matching works but the "$" doesn't. Anyone have any experience with pattern matching that can help me out? -- Regards, M Usman Ashraf From peter at rathlev.dk Sun Apr 5 15:40:09 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Sun, 05 Apr 2009 21:40:09 +0200 Subject: [c-nsp] CISCO ACS 4.2 command pattern matching In-Reply-To: <9149d2410904051059u4a3d7d2h5894d495481be4e6@mail.gmail.com> References: <9149d2410904051059u4a3d7d2h5894d495481be4e6@mail.gmail.com> Message-ID: <1238960409.3675.16.camel@localhost.localdomain> On Sun, 2009-04-05 at 22:59 +0500, M Usman Ashraf wrote: > So from this I take that if I want to deny configuration of certain > interfaces say Loopback0, while allowing configuration of Loopback99, > I will, permit "interface" , with the sub-command arguments: > permit*^Loopback99$*, unmatched commands are "deny" and "Permit > Unmatched Args" is unchecked. > > Thinking that would allow the command interface Loopback99 but > actually the "interface Loopback99" commands, fails authorization. On > the other side, if I permit *^Loopback* only, all loopbacks get > permitted. It seems like the "^" pattern matching works but the "$" > doesn't. Anyone have any experience with pattern matching that can > help me out? -- Your TACACS+ log should tell you the reason, even the ACS must have one. ;-) The reason could be that many end points add an explicit "" string to the request. If that is the case you would have to allow this instead: permit "^Loopback99 $" Regards, Peter From david at hughes.com.au Sun Apr 5 20:00:06 2009 From: david at hughes.com.au (David Hughes) Date: Mon, 6 Apr 2009 10:00:06 +1000 Subject: [c-nsp] Pseudowire and EtherChannel In-Reply-To: <8cd002180904011535n13d9327w1e6ed31c5050e367@mail.gmail.com> References: <8cd002180904011535n13d9327w1e6ed31c5050e367@mail.gmail.com> Message-ID: <52F11FED-208A-4130-A744-2F8CC5970E4E@hughes.com.au> We have Multi Gig etherchannel bundles being delivered over multiple port-based xconnects and it works just fine. The only tricky bit is realising then you lose link at the far end (there's no link-loss signaling on the pw). You'll need to run UDLD in aggressive mode so that a failed circuit is removed from the bundle. David ... On 02/04/2009, at 8:35 AM, Ozar wrote: > Quick question on PS and EtherChannel. > > Lets say I have customer who needs 2 gig from A to Z that I am going > to > transport by Pseudowire... > > Should I etherchannel the ports and make my xconnect in the Port > Channel > interface, or just transport each gig interface separately, and > customer > handles all the aggregation? From ler762 at gmail.com Sun Apr 5 22:58:56 2009 From: ler762 at gmail.com (Lee) Date: Sun, 5 Apr 2009 22:58:56 -0400 Subject: [c-nsp] 10GE card for 7609 In-Reply-To: <20090331201210.GF51443@gerbil.cluepon.net> References: <863386.41277.qm@web44809.mail.sp1.yahoo.com> <20090330151600.GA408@roxanne.org> <49D1BE37.8060402@skoal.name> <20090331074620.GV290@greenie.muc.de> <49D1CDD4.3080301@skoal.name> <20090331201210.GF51443@gerbil.cluepon.net> Message-ID: On 3/31/09, Richard A Steenbergen wrote: > On Tue, Mar 31, 2009 at 10:01:24AM +0200, Gergely Antal wrote: > >> I meant that you can not push 40G out of a 6704 >> even with a dfc attached to it.But you can do it with a 6708 >> with 1:1 subscription. > > Worse, some days you can't even get 7G in from a single port on a 6704 > with the other 3 ports unused. We routinely have problems with ingress > interface overruns or egress interface output queue overflows on 6704 > in that traffic range, and DFC doesn't make any difference. > > It seems like it is head of line blocking, and TAC's only answer is > "those things have no buffers, buy a 6708". We had a TAC case for input queue drops on a 6704 port - they told us it's a hardware limitation. When traffic is switched between two ports leading to the same asic you're limited to about 8Gb per port. Regards, Lee From asad747 at cyber.net.pk Mon Apr 6 01:05:40 2009 From: asad747 at cyber.net.pk (Asad Ul-Islam) Date: Mon, 06 Apr 2009 10:05:40 +0500 Subject: [c-nsp] client mac address on LNS?? Message-ID: <003501c9b675$547f7d80$fd7e7880$@net.pk> Dear Friends! I have a setup in which DSL users connect to a LNS via L2TP. Everything is working fine, however on LNS I am not receiving any MAC address for the DSL Users( Type PPPoVPDN). This is my standard crucial requirement for generating several reports for management purposes. Can someone tell me if it is possible to get Mac-address for the VPDN users??? I am getting mac-address for PPPoE type users which are terminated on my BRAS. Attach is the debug output for both LNS and BRAS which shows that mac-address field is missing in LNS output. ######### LNS output (domain stripping is used) ########## Apr 6 04:29:47.020: RADIUS(00001037): Send Access-Request to 10.10.10.10:3312 id 1645/44, len 123 Apr 6 04:29:47.020: RADIUS: Framed-Protocol [7] 6 PPP [1] Apr 6 04:29:47.020: RADIUS: User-Name [1] 11 "testuser7" Apr 6 04:29:47.020: RADIUS: User-Password [2] 18 * Apr 6 04:29:47.020: RADIUS: NAS-Port [5] 6 370 Apr 6 04:29:47.020: RADIUS: NAS-Port-Id [87] 17 "Uniq-Sess-ID370" Apr 6 04:29:47.020: RADIUS: Connect-Info [77] 9 "1920000" Apr 6 04:29:47.020: RADIUS: NAS-Port-Type [61] 6 Virtual [5] Apr 6 04:29:47.020: RADIUS: Service-Type [6] 6 Framed [2] Apr 6 04:29:47.020: RADIUS: NAS-IP-Address [4] 6 1.1.1.1 Apr 6 04:29:47.020: RADIUS: Acct-Session-Id [44] 18 "CAA36E5A00001058" Apr 6 04:29:47.308: RADIUS: Received from id 1645/44 10.10.10.10:3312, Access-Accept, len 37 Apr 6 04:29:47.308: RADIUS: Class [25] 5 Apr 6 04:29:47.308: RADIUS: 50 49 4E [PIN] Apr 6 04:29:47.308: RADIUS: Service-Type [6] 6 Framed [2] Apr 6 04:29:47.308: RADIUS: Framed-Protocol [7] 6 PPP [1] Apr 6 04:31:47.100: RADIUS(00001038): Received from id 1645/45 Apr 6 04:31:47.100: VT[Vi3.1]:Request took 0 msec, 0 msec processing time Apr 6 04:31:47.100: uid:371 Tnl/Sn 58894/504 L2TP: Virtual interface created for testuser7 at best-dsl bandwidth 1920 Kbps Apr 6 04:31:47.100: Vi3.1 Tnl/Sn 58894/504 L2TP: Virtual interface created for testuser7 at best-dsl, bandwidth 1920 Kbps Apr 6 04:31:47.100: Vi3.1 Tnl/Sn 58894/504 L2TP: VPDN session up Apr 6 04:31:47.220: RADIUS/ENCODE(00001038):Orig. component type = VPDN Cisco-3845-L2TP-LNS#show users Interface User Mode Idle Peer Address Vi3.1 testuser7 at best-ds PPPoVPDN - 1.1.1.233 ######### BRAS output ########## *Mar 1 00:13:15.367: RADIUS(00000009): Send Access-Request to 10.10.10.10:3312 id 1645/6, len 167 *Mar 1 00:13:15.367: RADIUS: Vendor, Cisco [26] 41 *Mar 1 00:13:15.367: RADIUS: Cisco AVpair [1] 35 "client-mac-address=000f.a392.4bef" *Mar 1 00:13:15.367: RADIUS: Framed-Protocol [7] 6 PPP [1] *Mar 1 00:13:15.367: RADIUS: User-Name [1] 11 "testuser6" *Mar 1 00:13:15.367: RADIUS: User-Password [2] 18 * *Mar 1 00:13:15.367: RADIUS: NAS-Port-Type [61] 6 Virtual [5] *Mar 1 00:13:15.367: RADIUS: Vendor, Cisco [26] 18 *Mar 1 00:13:15.367: RADIUS: cisco-nas-port [2] 12 "3/0/0/0.36" *Mar 1 00:13:15.367: RADIUS: NAS-Port [5] 6 805306404 *Mar 1 00:13:15.367: RADIUS: Service-Type [6] 6 Framed [2] *Mar 1 00:13:15.371: RADIUS: NAS-IP-Address [4] 6 1.1.1.1 *Mar 1 00:13:15.371: RADIUS: Acct-Session-Id [44] 29 "3/0/0/0.36_CAA3693A0000000E" *Mar 1 00:13:15.519: RADIUS: Received from id 1645/6 10.10.10.10:3312, Access-Accept, len 37 *Mar 1 00:13:15.519: RADIUS: Class [25] 5 *Mar 1 00:13:15.519: RADIUS: 50 49 4E [PIN] *Mar 1 00:13:15.519: RADIUS: Service-Type [6] 6 Framed [2] *Mar 1 00:13:15.519: RADIUS: Framed-Protocol [7] 6 PPP [1] *Mar 1 00:13:15.523: RADIUS(00000009): Received from id 1645/6 *Mar 1 00:13:15.643: RADIUS/ENCODE(00000009):Orig. component type = PPoE Cisc-3640-BRAS-And-L2TP-LAC# show user Interface User Mode Idle Peer Address Vi2.1 testuser6 PPPoE 00:03:25 2.2.2.244 Best Regards, Asad Ul-Islam From farhan at cyber.net.pk Mon Apr 6 03:28:45 2009 From: farhan at cyber.net.pk (Farhan Ali Khan) Date: Mon, 06 Apr 2009 12:28:45 +0500 Subject: [c-nsp] IP Address management software In-Reply-To: References: <7988720.651238675012717.JavaMail.peter@petergunz> Message-ID: <01ee01c9b689$51c1cd00$a370a3ca@IBMB733624712D> Try the followings, 1) http://iptrack.sourceforge.net/ 2) http://www.sofotex.com/IPMaster-:-IP-Address-Management-Software-download_L3 7927.html Paid but awasome 3) http://www.manageengine.com/products/oputils/address-monitoring-tools.html Regards Farhan Ali Khan On Thu, Apr 2, 2009 at 5:23 PM, Peter Nyamukusa < peter.nyamukusa at africaonline.co.tz> wrote: > Hi Gary, > you can try this > > http://www.brownkid.net/NorthStar/ > > cheers, > > -- > > > Peter Nyamukusa > > Technical Manager > Africa Online (T) Ltd. > Tel: +255 (22) 211 6090 > Fax:+255 (22) 211 6089 > Email: peter.nyamukusa at africaonline.co.tz > > > A member of the Telkom South Africa Group > > ----- Original Message ----- > From: "Gary Roberton" > To: cisco-nsp at puck.nether.net > Sent: Tuesday, March 31, 2009 11:17:50 AM GMT +03:00 Iraq > Subject: [c-nsp] IP Address management software > > Hello all > > What IP address management software do you use to control the > allocation of subnets to your customers/department? > > Thanks > > Gary > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From ariemer at wesenergy.com.au Mon Apr 6 03:33:57 2009 From: ariemer at wesenergy.com.au (Aaron Riemer) Date: Mon, 6 Apr 2009 15:33:57 +0800 Subject: [c-nsp] Monitoring External Web Server In-Reply-To: <49D8CD3C.1020709@toybox.placo.com> References: <0867622C64B50C4B878AB45C95F43F1106A1D55B@MAILWA01.wesenergy.local> <49D8CD3C.1020709@toybox.placo.com> Message-ID: <0867622C64B50C4B878AB45C95F43F1106A1DA1F@MAILWA01.wesenergy.local> Thanks for the tips guys. Aaron. -----Original Message----- From: Ted Mittelstaedt [mailto:tedm at toybox.placo.com] Sent: Sunday, 5 April 2009 11:25 PM To: Aaron Riemer Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] Monitoring External Web Server Aaron Riemer wrote: > Hey guys, > > We have a requirement to monitor the external availability of a web > server that hangs off our ASA DMZ interface. I was thinking of running > an IP SLA probe from our external router to test the web requests but I > was wondering if anyone had done something with EEM that could possibly > try to establish a TCP connection to the web server and report the > statistics somehow. I don't want to place a machine outside for the > monitoring so would prefer to do it from our router if possible. > > Any thoughts? > You won't get true monitoring unless you place 2 machines on the outside and put a modem in one and run sendpage software on it - OR use a commercial service. I run paging software under FreeBSD running on an old P200 machine. I had to try several different modems before getting one that worked right with the software. The reason you need this is that if your Internet connection goes down your router cannot page you that there's a problem. The reason you need 2 machines is that if one of the monitoring systems goes offline. In my setup both systems monitor each other. I also monitor a few major websites (google, etc.) to make sure we still have connectivity. The only problem I have now is when my cell phone battery dies. ;-) Ted LEGAL DISCLAIMER: This message contains confidential information and is intended only for the individual named. If you are not the named addressee you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately by e-mail if you have received this e-mail by mistake and delete this e-mail from your system. If you are not the intended recipient you are notified that disclosing, copying, distributing or taking any action in reliance on the contents of this information is strictly prohibited. From mdado at Airspan.com Mon Apr 6 04:00:20 2009 From: mdado at Airspan.com (Mohammed Dado) Date: Mon, 6 Apr 2009 09:00:20 +0100 Subject: [c-nsp] show inventory In-Reply-To: <06657F64-46A5-4F79-8337-EBE498AC74BA@gmail.com> References: <06657F64-46A5-4F79-8337-EBE498AC74BA@gmail.com> Message-ID: Also try this: show inventory raw slot Regards, Mohammed Dado. -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of raymondh (NSP) Sent: 05 April 2009 15:46 To: Mohammad Khalil Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] show inventory try this. sh invent raw --raymondh On Apr 5, 2009, at 5:40 PM, Mohammad Khalil wrote: > > Hey all > > i issue the command show inventory on some devices and no output is > there and the other is ok > > any ideas ? > > _________________________________________________________________ > More than messages-check out the rest of the Windows Live(tm). > http://www.microsoft.com/windows/windowslive/ > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From eng_mssk at hotmail.com Mon Apr 6 08:08:15 2009 From: eng_mssk at hotmail.com (Mohammad Khalil) Date: Mon, 6 Apr 2009 15:08:15 +0300 Subject: [c-nsp] show inventory In-Reply-To: References: <06657F64-46A5-4F79-8337-EBE498AC74BA@gmail.com> Message-ID: the problem with the command show inventory or show inventory raw that its not supported on ever IOS images so there is show c7200 (For VXRs) and show tech as well show diag can be helpful as well > From: mdado at Airspan.com > To: raymondh.nsp at gmail.com; eng_mssk at hotmail.com > CC: cisco-nsp at puck.nether.net > Date: Mon, 6 Apr 2009 09:00:20 +0100 > Subject: RE: [c-nsp] show inventory > > Also try this: > > show inventory raw slot > > > Regards, > Mohammed Dado. > > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of raymondh (NSP) > Sent: 05 April 2009 15:46 > To: Mohammad Khalil > Cc: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] show inventory > > try this. > > sh invent raw > > > --raymondh > > On Apr 5, 2009, at 5:40 PM, Mohammad Khalil wrote: > > > > > Hey all > > > > i issue the command show inventory on some devices and no output is > > there and the other is ok > > > > any ideas ? > > > > _________________________________________________________________ > > More than messages-check out the rest of the Windows Live(tm). > > http://www.microsoft.com/windows/windowslive/ > > _______________________________________________ > > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ _________________________________________________________________ Show them the way! Add maps and directions to your party invites. http://www.microsoft.com/windows/windowslive/products/events.aspx From david.freedman at uk.clara.net Mon Apr 6 09:12:14 2009 From: david.freedman at uk.clara.net (David Freedman) Date: Mon, 06 Apr 2009 14:12:14 +0100 Subject: [c-nsp] Emulating the L2 aspect of VPLS with VRF-lite In-Reply-To: <49D67B8C.9090204@justinshore.com> References: <49D67B8C.9090204@justinshore.com> Message-ID: <49D9FFAE.10907@uk.clara.net> > Thinking about it a bit more I decided that I could provide a L2 > service by making each of the MLPPP interfaces and the GigE sub-int > unnumbered up to a common loopback. Each customer WAN-facing interface > would be addressed from a common subnet. They should then also be able > to directly communicate with one another across the loopback and > establish routing adjacencies and/or build GRE tunnels with the hosts in > that common connected route. Not quite sure how next-hop address resolution would work here, if you expend the subnet masks such that all devices exist on the same subnet, you will need some kind of address resolution to work, for instance, the CPE on the DS1s will need to have a connected route to the subnet, the 7200 will have to have static routes (or IPCP learnt) to each endpoint on the DS1s and also some kind of ARP for the HQ site. I would personally go for the L3 (VRF) solution as it is simplest to manage and troubleshoot, I would imagine it has about the same overhead on the router as any L2 solution you could come up with using this 7200, If you really want to do L2, consider bridging (IRB, but v.cpu intensive) or l2connect with interworking between the MLPPP bundles and sub-sub interfaces of the GigE, (I would imagine you can do QinQ on this right?) if not consider dropping the Ethernet component and going for a straight DS3 with frame PVCs. This design of course requires that all traffic passes through the HQ site. Dave. > > That's where I'm at right now. I have 2 test routers with a DS1 bundle > on each back to the 7200. Each bundle is in the customer VRF. I have > another router doing Ethernet into a 4948 access switchport. That > unique VLAN gets trunked up to the 7200 on an on-board GigE interface. > The corresponding sub-int on the 7200 is in the customer VRF and is > unnumbered back to the dedicated customer loopback. The only error I > got in the process was when I did the unnumbered on the sub-int. > > 003018: Apr 3 13:15:29 CDT: %OSPF-4-NO_IPADDRESS_ON_INT: No IP address > for interface GigabitEthernet0/2.1001 > > That's just OSPF whining and shouldn't be a problem. I set up OSPF on > all WAN-facing interfaces on the CE lab routers. For grins I also set > up OSPF inside the VRF on the PE. I can ping between the DS1 routers > and the 7200. However I can not ping the Ethernet CE router from > anywhere. I also can not establish OSPF adjacencies between any of the > CEs or the PE. Debugging the OSPF packets I see packets going out from > the CEs but nothing coming in. From the PE I see nothing at all. > > Should this ip unnumbered design work? Any idea what's dropping the > OSPF packets along the way? > > I'm working on the problem while typing this and I have an update on > what I wrote above. I now have OSPF adjacencies between the DS1 CPEs > and the 7200. It turns out I needed to put the MLPPP interface into the > VRF as well even though the ip unnumbered interface as in the VRF > already. However this points out a problem. I am unable to establish > an adjacency between the DS1 CPEs. The CPEs only claim to see OSPF > packets from the 7200. Is that normal? I also just noticed that I can > no longer ping between DS1 CPEs. I'm not sure if this isn't being > consistent or I should call it a day. > > I should be able to do the VRF with the L3 hop in the middle if nothing > else. I'd rather that be my fall-back position though. Any other > suggestions on how to accomplish this would be much appreciated. I'm > sure there are other ways to do something similar. > > Thanks > Justin > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From david.freedman at uk.clara.net Mon Apr 6 09:12:14 2009 From: david.freedman at uk.clara.net (David Freedman) Date: Mon, 06 Apr 2009 14:12:14 +0100 Subject: [c-nsp] Emulating the L2 aspect of VPLS with VRF-lite In-Reply-To: <49D67B8C.9090204@justinshore.com> References: <49D67B8C.9090204@justinshore.com> Message-ID: <49D9FFAE.10907@uk.clara.net> > Thinking about it a bit more I decided that I could provide a L2 > service by making each of the MLPPP interfaces and the GigE sub-int > unnumbered up to a common loopback. Each customer WAN-facing interface > would be addressed from a common subnet. They should then also be able > to directly communicate with one another across the loopback and > establish routing adjacencies and/or build GRE tunnels with the hosts in > that common connected route. Not quite sure how next-hop address resolution would work here, if you expend the subnet masks such that all devices exist on the same subnet, you will need some kind of address resolution to work, for instance, the CPE on the DS1s will need to have a connected route to the subnet, the 7200 will have to have static routes (or IPCP learnt) to each endpoint on the DS1s and also some kind of ARP for the HQ site. I would personally go for the L3 (VRF) solution as it is simplest to manage and troubleshoot, I would imagine it has about the same overhead on the router as any L2 solution you could come up with using this 7200, If you really want to do L2, consider bridging (IRB, but v.cpu intensive) or l2connect with interworking between the MLPPP bundles and sub-sub interfaces of the GigE, (I would imagine you can do QinQ on this right?) if not consider dropping the Ethernet component and going for a straight DS3 with frame PVCs. This design of course requires that all traffic passes through the HQ site. Dave. > > That's where I'm at right now. I have 2 test routers with a DS1 bundle > on each back to the 7200. Each bundle is in the customer VRF. I have > another router doing Ethernet into a 4948 access switchport. That > unique VLAN gets trunked up to the 7200 on an on-board GigE interface. > The corresponding sub-int on the 7200 is in the customer VRF and is > unnumbered back to the dedicated customer loopback. The only error I > got in the process was when I did the unnumbered on the sub-int. > > 003018: Apr 3 13:15:29 CDT: %OSPF-4-NO_IPADDRESS_ON_INT: No IP address > for interface GigabitEthernet0/2.1001 > > That's just OSPF whining and shouldn't be a problem. I set up OSPF on > all WAN-facing interfaces on the CE lab routers. For grins I also set > up OSPF inside the VRF on the PE. I can ping between the DS1 routers > and the 7200. However I can not ping the Ethernet CE router from > anywhere. I also can not establish OSPF adjacencies between any of the > CEs or the PE. Debugging the OSPF packets I see packets going out from > the CEs but nothing coming in. From the PE I see nothing at all. > > Should this ip unnumbered design work? Any idea what's dropping the > OSPF packets along the way? > > I'm working on the problem while typing this and I have an update on > what I wrote above. I now have OSPF adjacencies between the DS1 CPEs > and the 7200. It turns out I needed to put the MLPPP interface into the > VRF as well even though the ip unnumbered interface as in the VRF > already. However this points out a problem. I am unable to establish > an adjacency between the DS1 CPEs. The CPEs only claim to see OSPF > packets from the 7200. Is that normal? I also just noticed that I can > no longer ping between DS1 CPEs. I'm not sure if this isn't being > consistent or I should call it a day. > > I should be able to do the VRF with the L3 hop in the middle if nothing > else. I'd rather that be my fall-back position though. Any other > suggestions on how to accomplish this would be much appreciated. I'm > sure there are other ways to do something similar. > > Thanks > Justin > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From rekordmeister at gmail.com Mon Apr 6 09:22:18 2009 From: rekordmeister at gmail.com (MKS) Date: Mon, 6 Apr 2009 13:22:18 +0000 Subject: [c-nsp] SIP-400 and 10GbE SPA Message-ID: Hi There According to cisco SIP-400 can "Ability to run 4 GE line rate for 64-byte packets, and OC-48 line rate for 48-byte packets for POS, HDLC, etc. with select services" https://www.cisco.com/en/US/prod/collateral/routers/ps368/product_data_sheet0900aecd8027c9e6.html Can someone please clarify what exactly this means. Also if I put a 10GbE SPA into a SIP-400 what is the expected performance of that? Thanks //MKS From jcartier at acs.on.ca Mon Apr 6 10:28:09 2009 From: jcartier at acs.on.ca (Jeff Cartier) Date: Mon, 6 Apr 2009 10:28:09 -0400 Subject: [c-nsp] ME3750 Dropping LDP Message-ID: I've got a ME3750 in the field and it appears to be randomly dropping LDP neighbors every few days. Any have any experience using this platform within a MPLS model? Thanks! From rick at woofpaws.com Mon Apr 6 10:51:40 2009 From: rick at woofpaws.com (Rick Ernst) Date: Mon, 6 Apr 2009 07:51:40 -0700 (PDT) Subject: [c-nsp] Getting ready to pull the trigger: RSP720/SUP720 Message-ID: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> The stars are starting to come into alignment and I'm about ready to order equipment for a network refresh. I currently have a edge/core/aggregation model with 7206VXR/NPE-G1 at the edge, 7500/RSP16/GEIP+ in the core, and various aggregation devices from 5500/RSM to 7500/RSP8 and dialup, DSL, etc. We are migrating from OC-3 to GigE at our edge. We currently push about 300mbs in each direction and that is expected to grow by at least 100mbs this year. The rate of growth has increased dramatically. I'm planning on collapsing the border/core into a pair of 7600/Sup720-3BXLs, and it looks like they will be almost idle with this amount of load. The problem I am running into is spec'ing the aggregation layer. Almost all of our traffic is ethernet now, and all the interfaces need bi-drectional rate-limiting/traffic-shaping/policing. We have a variable bandwidth model and need to cap traffic at 1Mbs granularity. 1,5, and 10Mbs connections are common, and 20,50,100Mbs connections exist with a 200Mbs pipe in process. The only traffic management I have used in the past is Cisco's rate-limit, and it is very CPU intensive. I'm trying to find out if a Sup720/RSP720 can handle hundreds of interfaces, each being rate-limited in some manner. The Cisco data sheet is vague about "some features" and "QoS" in hardware, but isn't specific about what features are in hardware. Is the Sup720 (RSP720 a better answer?) sufficient? Is traffic-management in hardware, and should I be looking at rate-limit or some different mechanism? The network itself is otherwise pretty low-touch. My intent is to "just move the bits", but I also use uRPF with a BGP blackhole system for IDS. Note: I'd like to keep as much of the equipment the same to simplify sparing, configuration, etc. Thanks! From jlewis at lewis.org Mon Apr 6 11:12:00 2009 From: jlewis at lewis.org (Jon Lewis) Date: Mon, 6 Apr 2009 11:12:00 -0400 (EDT) Subject: [c-nsp] Getting ready to pull the trigger: RSP720/SUP720 In-Reply-To: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> References: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> Message-ID: On Mon, 6 Apr 2009, Rick Ernst wrote: > I'm planning on collapsing the border/core into a pair of > 7600/Sup720-3BXLs, and it looks like they will be almost idle with this > amount of load. That really depends on the features you enable. Try doing full netflow on a sup720 doing a few hundred mbit's of traffic, and they're suddenly not so mighty. > The problem I am running into is spec'ing the aggregation layer. Almost > all of our traffic is ethernet now, and all the interfaces need > bi-drectional rate-limiting/traffic-shaping/policing. We have a variable > bandwidth model and need to cap traffic at 1Mbs granularity. 1,5, and > 10Mbs connections are common, and 20,50,100Mbs connections exist with a > 200Mbs pipe in process. We've been using 3550's for years for this, as they have the ability to police in both directions, per port, at whatever granularity you like. The 3560, which was supposed to be an improvement/replacement for the 3550 lost this ability, which really shocked me when I configured my first one. It can do per-port output shaping, but the granularity kind of blows. You're limited to 1/N * port rate, where N is an integer from 0 to 65535. This gives plenty (actually a huge waste of range) of granularity at the low end of bandwidth, but at the high end, you're limited to full rate, 50%, 33%, 25%, 20%, etc. If I'm wrong here, I'd love to hear it and be told how to limit a 100mbit port to say 40mbit/s. ---------------------------------------------------------------------- Jon Lewis | I route Senior Network Engineer | therefore you are Atlantic Net | _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________ From skeeve at eintellego.net Mon Apr 6 11:16:39 2009 From: skeeve at eintellego.net (Skeeve Stevens) Date: Tue, 7 Apr 2009 01:16:39 +1000 Subject: [c-nsp] Break out a VLAN from a QinQ? Message-ID: <292AF25E62B8894C921B893B53A19D97394469DFF3@BUSINESSEX.business.ad> Hey all, Does Cisco have any switches which can: a) Break out a VLAN from within a QinQ trunk b) Renumber VLAN's pulled from such a trunk c) Renumber VLAN's in general There seems to me such little info out there on QinQ! ...Skeeve -- Skeeve Stevens, CEO/Technical Director eintellego Pty Ltd - The Networking Specialists skeeve at eintellego.net / www.eintellego.net Phone: 1300 753 383, Fax: (+612) 8572 9954 Cell +61 (0)414 753 383 / skype://skeeve -- NOC, NOC, who's there? Disclaimer: Limits of Liability and Disclaimer: This message is for the named person's use only. It may contain sensitive and private proprietary or legally privileged information. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient. eintellego Pty Ltd and each legal entity in the Tefilah Pty Ltd group of companies reserve the right to monitor all e-mail communications through its networks. Any views expressed in this message are those of the individual sender, except where the message states otherwise and the sender is authorised to state them to be the views of any such entity. Any reference to costs, fee quotations, contractual transactions and variations to contract terms is subject to separate confirmation in writing signed by an authorised representative of eintellego. Whilst all efforts are made to safeguard inbound and outbound e-mails, we cannot guarantee that attachments are virus-free or compatible with your systems and do not accept any liability in respect of viruses or computer problems experienced. From md at bts.sk Mon Apr 6 12:11:17 2009 From: md at bts.sk (Marian =?utf-8?B?xI51cmtvdmnEjQ==?=) Date: Mon, 6 Apr 2009 18:11:17 +0200 Subject: [c-nsp] 10GE card for 7609 In-Reply-To: References: <863386.41277.qm@web44809.mail.sp1.yahoo.com> <20090330151600.GA408@roxanne.org> <49D1BE37.8060402@skoal.name> <20090331074620.GV290@greenie.muc.de> <49D1CDD4.3080301@skoal.name> <20090331201210.GF51443@gerbil.cluepon.net> Message-ID: <20090406161117.GA56528@bts.sk> On Sun, Apr 05, 2009 at 10:58:56PM -0400, Lee wrote: > On 3/31/09, Richard A Steenbergen wrote: > > On Tue, Mar 31, 2009 at 10:01:24AM +0200, Gergely Antal wrote: > > > >> I meant that you can not push 40G out of a 6704 > >> even with a dfc attached to it.But you can do it with a 6708 > >> with 1:1 subscription. > > > > Worse, some days you can't even get 7G in from a single port on a 6704 > > with the other 3 ports unused. We routinely have problems with ingress > > interface overruns or egress interface output queue overflows on 6704 > > in that traffic range, and DFC doesn't make any difference. > > > > It seems like it is head of line blocking, and TAC's only answer is > > "those things have no buffers, buy a 6708". > > We had a TAC case for input queue drops on a 6704 port - they told us > it's a hardware limitation. When traffic is switched between two > ports leading to the same asic you're limited to about 8Gb per port. ??? This is definitely possible with 6704 and SXI: TenGigabitEthernet2/1 is up, line protocol is up (connected) Last clearing of "show interface" counters 00:04:57 Input queue: 0/2000/0 (size/max/drops); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 30 second input rate 9900042000 bits/sec, 137227 packets/sec 30 second output rate 0 bits/sec, 0 packets/sec TenGigabitEthernet2/2 is up, line protocol is up (connected) Last clearing of "show interface" counters 00:04:55 Input queue: 0/2000/0 (size/max/drops); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 30 second input rate 0 bits/sec, 0 packets/sec 30 second output rate 9900041000 bits/sec, 137226 packets/sec No single packet drop in 5 minutes, and the traffic is switched locally in the ASIC - not going out to fabric: #show fabric utilization slot channel speed Ingress % Egress % 2 0 20G 0 0 2 1 20G 0 0 This is on WS-SUP720-3B system with WS-X6704-10GE + WS-F6700-CFC. With kind regards, M. From david.freedman at uk.clara.net Mon Apr 6 12:15:16 2009 From: david.freedman at uk.clara.net (David Freedman) Date: Mon, 06 Apr 2009 17:15:16 +0100 Subject: [c-nsp] Break out a VLAN from a QinQ? In-Reply-To: <292AF25E62B8894C921B893B53A19D97394469DFF3@BUSINESSEX.business.ad> References: <292AF25E62B8894C921B893B53A19D97394469DFF3@BUSINESSEX.business.ad> Message-ID: Skeeve Stevens wrote: > Hey all, > > Does Cisco have any switches which can: > > a) Break out a VLAN from within a QinQ trunk > b) Renumber VLAN's pulled from such a trunk > c) Renumber VLAN's in general Vlan rewriting has been available for some time now, but alas, there are many restrictions and these are h/w dependent (i.e one re-write map per asic, not port) If you have the cash to spare on 7600 and ES20/ES40/ES+ you can make use the "Carrier Ethernet" featureset (http://www.cisco.com/en/US/docs/ios/cether/configuration/guide/ce_mst_evc_bd_ps6922_TSD_Products_Configuration_Guide_Chapter.html) to dynamically modify and steer frames as they arrive (think of it as a kind of route-map , but for ethernet) , this is commonly referred to as "EVC functionality" (EVC = Ethernet Virtual Circuit) http://www.cisco.com/en/US/docs/routers/7600/install_config/ES20_config_guide/SRD/baldcsm.html provides a quick summary of this: Router(config-if-srv)#rewrite ingress tag {push {dot1q vlan-id | dot1q vlan-id second-dot1q vlan-id | dot1ad vlan-id dot1q vlan-id} | pop {1 | 2} | translate {1-to-1 {dot1q vlan-id | dot1ad vlan-id}| 2-to-1 dot1q vlan-id | dot1ad vlan-id}| 1-to-2 {dot1q vlan-id second-dot1q vlan-id | dot1ad vlan-id dot1q vlan-id} | 2-to-2 {dot1q vlan-id second-dot1q vlan-id | dot1ad vlan-id dot1q vlan-id}} [symmetric] Great syntax huh? :) Dave. > > There seems to me such little info out there on QinQ! > > ...Skeeve > > -- > Skeeve Stevens, CEO/Technical Director > eintellego Pty Ltd - The Networking Specialists > skeeve at eintellego.net / www.eintellego.net > Phone: 1300 753 383, Fax: (+612) 8572 9954 > Cell +61 (0)414 753 383 / skype://skeeve > -- > NOC, NOC, who's there? > > Disclaimer: Limits of Liability and Disclaimer: This message is for the named person's use only. It may contain sensitive and private proprietary or legally privileged information. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient. eintellego Pty Ltd and each legal entity in the Tefilah Pty Ltd group of companies reserve the right to monitor all e-mail communications through its networks. Any views expressed in this message are those of the individual sender, except where the message states otherwise and the sender is authorised to state them to be the views of any such entity. Any reference to costs, fee quotations, contractual transactions and variations to contract terms is subject to separate > confirmation in writing signed by an authorised representative of eintellego. Whilst all efforts are made to safeguard inbound and outbound e-mails, we cannot guarantee that attachments are! > virus-free or compatible with your systems and do not accept any liability in respect of viruses or computer problems experienced. > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From p.mayers at imperial.ac.uk Mon Apr 6 12:17:05 2009 From: p.mayers at imperial.ac.uk (Phil Mayers) Date: Mon, 06 Apr 2009 17:17:05 +0100 Subject: [c-nsp] Getting ready to pull the trigger: RSP720/SUP720 In-Reply-To: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> References: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> Message-ID: <49DA2B01.3000608@imperial.ac.uk> Rick Ernst wrote: > The stars are starting to come into alignment and I'm about ready to > order equipment for a network refresh. > > I currently have a edge/core/aggregation model with 7206VXR/NPE-G1 at the > edge, 7500/RSP16/GEIP+ in the core, and various aggregation devices from > 5500/RSM to 7500/RSP8 and dialup, DSL, etc. We are migrating from OC-3 to > GigE at our edge. > > We currently push about 300mbs in each direction and that is expected to > grow by at least 100mbs this year. The rate of growth has increased > dramatically. > > I'm planning on collapsing the border/core into a pair of > 7600/Sup720-3BXLs, and it looks like they will be almost idle with this > amount of load. > > The problem I am running into is spec'ing the aggregation layer. Almost > all of our traffic is ethernet now, and all the interfaces need > bi-drectional rate-limiting/traffic-shaping/policing. We have a variable > bandwidth model and need to cap traffic at 1Mbs granularity. 1,5, and > 10Mbs connections are common, and 20,50,100Mbs connections exist with a > 200Mbs pipe in process. > > The only traffic management I have used in the past is Cisco's rate-limit, > and it is very CPU intensive. I'm trying to find out if a Sup720/RSP720 > can handle hundreds of interfaces, each being rate-limited in some manner. > The Cisco data sheet is vague about "some features" and "QoS" in > hardware, but isn't specific about what features are in hardware. > > Is the Sup720 (RSP720 a better answer?) sufficient? Is traffic-management > in hardware, and should I be looking at rate-limit or some different > mechanism? QoS on the 6500/7600 platform is a pretty involved topic. You will want to read up on it carefully. See: http://www.cisco.com/en/US/docs/routers/7600/ios/12.2SR/configuration/guide/qos.html Assuming you're talking about "LAN" lincards e.g. 67xx series, then: * qos is done in hardware * the capabilities are reasonable, but limited and a bit complex because it's done in hardware * the capabilities depend on the exact model of linecard - some have fewer queues, smaller buffers, only 6708 support ingress DSCP mapping to queues etc. In particular, you want to watch ingress rate limiting very carefully. My (limited) understanding is that it'll be tricky to do what you want. From asturluismi at gmail.com Mon Apr 6 12:18:04 2009 From: asturluismi at gmail.com (luismi) Date: Mon, 06 Apr 2009 18:18:04 +0200 Subject: [c-nsp] EEM event-manager and "event none" question. Message-ID: <1239034684.13422.5.camel@dsba-ipso> I have this code... event manager applet A-EU-UP event track 10 state up action 1.0 syslog msg "Track 10 Up. Houston we don't have a problem" action 2.0 cli command "enable" action 3.0 cli command "conf t" action 4.0 cli command "" I tried to execute... # event manager run A-EU-UP Embedded Event Manager policy EU-ACEL-BACKUP-OFF not registered with event none Event Detector What is the reason for that message? Looks like the EEM code is not running. As far as I can read at documentation found with google, I need "event none" at the beginning of the applet, but, what is the reason for it? When "event none" must be used? From saku+cisco-nsp at ytti.fi Mon Apr 6 12:24:00 2009 From: saku+cisco-nsp at ytti.fi (Saku Ytti) Date: Mon, 6 Apr 2009 19:24:00 +0300 Subject: [c-nsp] 10GE card for 7609 In-Reply-To: <20090406161117.GA56528@bts.sk> References: <863386.41277.qm@web44809.mail.sp1.yahoo.com> <20090330151600.GA408@roxanne.org> <49D1BE37.8060402@skoal.name> <20090331074620.GV290@greenie.muc.de> <49D1CDD4.3080301@skoal.name> <20090331201210.GF51443@gerbil.cluepon.net> <20090406161117.GA56528@bts.sk> Message-ID: <20090406162400.GA16201@mx.ytti.net> On (2009-04-06 18:11 +0200), Marian ?urkovi? wrote: > > We had a TAC case for input queue drops on a 6704 port - they told us > > it's a hardware limitation. When traffic is switched between two > > ports leading to the same asic you're limited to about 8Gb per port. > > This is definitely possible with 6704 and SXI: > TenGigabitEthernet2/1 is up, line protocol is up (connected) > 30 second input rate 9900042000 bits/sec, 137227 packets/sec > TenGigabitEthernet2/2 is up, line protocol is up (connected) > 30 second output rate 9900041000 bits/sec, 137226 packets/sec When I tested it traffic inside single channel was worst alternative. 3. Topologies used I used four different topologies: a) anritsu --darkfibre-- ten7/1:7600:ten7/3 --darkfibre-- anritsu b) anritsu --darkfibre-- ten7/1:7600:ten4/1 --darkfibre-- anritsu c) anritsu --darkfibre-- ten7/1:7600:ten7/2 --darkfibre-- anritsu d) anr -dark- ten9/3:7600:ten9/2 -dwdm- ten4/1:7600:ten7/1 -dark- anr 4. Pure IP performance 4.1 no features configured, plain IP routing a) 67bytes and above is linerate in both directions b) 65bytes and above is linerate in both directions c) 64bytes does 87.5% of linerate, rate appraoches 100% as size grows, but is both bps and pps bound, so no configuration of packet size and interval got 100%. d) 67bytes and above is linerate in boh directions This was in mid 2006 with 6704 and CFC running SRA. ACL's and Policers didn't affect forwarding, uRPF did affect slightly. -- ++ytti From rossella at chemeketa.edu Mon Apr 6 12:22:08 2009 From: rossella at chemeketa.edu (Rossella Mariotti-Jones) Date: Mon, 6 Apr 2009 09:22:08 -0700 Subject: [c-nsp] two ISPs, two routers, one firewall - bgp question In-Reply-To: References: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> Message-ID: Hello all, I have a question regarding this scenario: http://www.cisco.com/en/US/tech/tk365/technologies_configuration_example 09186a00800945bf.shtml#conf5 My R2 link to ISP is 100M R1 link to ISP is a DS3 If my firewall has a default route of 192.168.21.2 and I have a 10M download going with AS300, my firewall is going to send out my traffic through its default gateway which is 192.168.21.2, R2 knows through iBGP that R1 is the best path to AS300, so it sends the traffic to R1, traffic coming back goes through R1, R2, firewall to get to the client, so basically in this case the link between my firewall and R2 is taken up twice. Am I understanding this correctly? Thanks everyone in advance. rossella -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jon Lewis Sent: Monday, April 06, 2009 8:12 AM To: Rick Ernst Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] Getting ready to pull the trigger: RSP720/SUP720 On Mon, 6 Apr 2009, Rick Ernst wrote: > I'm planning on collapsing the border/core into a pair of > 7600/Sup720-3BXLs, and it looks like they will be almost idle with this > amount of load. That really depends on the features you enable. Try doing full netflow on a sup720 doing a few hundred mbit's of traffic, and they're suddenly not so mighty. > The problem I am running into is spec'ing the aggregation layer. Almost > all of our traffic is ethernet now, and all the interfaces need > bi-drectional rate-limiting/traffic-shaping/policing. We have a variable > bandwidth model and need to cap traffic at 1Mbs granularity. 1,5, and > 10Mbs connections are common, and 20,50,100Mbs connections exist with a > 200Mbs pipe in process. We've been using 3550's for years for this, as they have the ability to police in both directions, per port, at whatever granularity you like. The 3560, which was supposed to be an improvement/replacement for the 3550 lost this ability, which really shocked me when I configured my first one. It can do per-port output shaping, but the granularity kind of blows. You're limited to 1/N * port rate, where N is an integer from 0 to 65535. This gives plenty (actually a huge waste of range) of granularity at the low end of bandwidth, but at the high end, you're limited to full rate, 50%, 33%, 25%, 20%, etc. If I'm wrong here, I'd love to hear it and be told how to limit a 100mbit port to say 40mbit/s. ---------------------------------------------------------------------- Jon Lewis | I route Senior Network Engineer | therefore you are Atlantic Net | _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________ _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From pl+list at pmacct.net Mon Apr 6 11:45:43 2009 From: pl+list at pmacct.net (Paolo Lucente) Date: Mon, 6 Apr 2009 16:45:43 +0100 Subject: [c-nsp] SIP-400 and 10GbE SPA In-Reply-To: References: Message-ID: <20090406154543.GA18747@london.pmacct.net> Hi MKS, the performance you get really depends on the average size of the traffic mix you push through the card. The vendor is providing you with the 64-bytes packets scenario, then the scaling exercise to see whether it fits your scenario it's up to you. Also translated you should certainly not expect a SIP-400 to scale 10GE line-rate with an average traffic size of 64 bytes. If this is acceptable to your setup, then you just need to find the average traffic size for the specific scenario with some basic traffic analysis (NetFlow ?), see whether you fit, take some margin (for all sort of inconveniences), etc. Otherwise you might want to look at some different hardware solution (SIP-600 ?). Cheers, Paolo On Mon, Apr 06, 2009 at 01:22:18PM +0000, MKS wrote: > Hi There > > According to cisco SIP-400 can > "Ability to run 4 GE line rate for 64-byte packets, and OC-48 line > rate for 48-byte packets for POS, HDLC, etc. with select services" > https://www.cisco.com/en/US/prod/collateral/routers/ps368/product_data_sheet0900aecd8027c9e6.html > > Can someone please clarify what exactly this means. > > Also if I put a 10GbE SPA into a SIP-400 what is the expected > performance of that? > > Thanks > //MKS From rekordmeister at gmail.com Mon Apr 6 12:30:37 2009 From: rekordmeister at gmail.com (MKS) Date: Mon, 6 Apr 2009 16:30:37 +0000 Subject: [c-nsp] SIP-400 and 10GbE SPA In-Reply-To: <20090406154543.GA18747@london.pmacct.net> References: <20090406154543.GA18747@london.pmacct.net> Message-ID: OK let me put it this way Does someone know what to expect from this card @ 1500byte packets or some "standard" IMIX. Does it matter if the interface is doing mpls or just IP? Thanks On Mon, Apr 6, 2009 at 3:45 PM, Paolo Lucente wrote: > Hi MKS, > > the performance you get really depends on the average size > of the traffic mix you push through the card. The vendor is > providing you with the 64-bytes packets scenario, then the > scaling exercise to see whether it fits your scenario it's > up to you. Also translated you should certainly not expect > a SIP-400 to scale 10GE line-rate with an average traffic > size of 64 bytes. > > If this is acceptable to your setup, then you just need to > find the average traffic size for the specific scenario with > some basic traffic analysis (NetFlow ?), see whether you fit, > take some margin (for all sort of inconveniences), etc. > > Otherwise you might want to look at some different hardware > solution (SIP-600 ?). > > Cheers, > Paolo > > > On Mon, Apr 06, 2009 at 01:22:18PM +0000, MKS wrote: >> Hi There >> >> According to cisco SIP-400 can >> "Ability to run 4 GE line rate for 64-byte packets, and OC-48 line >> rate for 48-byte packets for POS, HDLC, etc. with select services" >> https://www.cisco.com/en/US/prod/collateral/routers/ps368/product_data_sheet0900aecd8027c9e6.html >> >> Can someone please clarify what exactly this means. >> >> Also if I put a 10GbE SPA into a SIP-400 what is the expected >> performance of that? >> >> Thanks >> //MKS > > From raymondh.nsp at gmail.com Mon Apr 6 12:31:05 2009 From: raymondh.nsp at gmail.com (raymondh (NSP)) Date: Tue, 7 Apr 2009 00:31:05 +0800 Subject: [c-nsp] SIP-400 and 10GbE SPA In-Reply-To: References: Message-ID: The SIP-400 supports up to 2.5G. (Other words 01 x STM-16 + some other low speed stuff) Cheers. --raymondh at home-zzz On Apr 6, 2009, at 9:22 PM, MKS wrote: > Hi There > > According to cisco SIP-400 can > "Ability to run 4 GE line rate for 64-byte packets, and OC-48 line > rate for 48-byte packets for POS, HDLC, etc. with select services" > https://www.cisco.com/en/US/prod/collateral/routers/ps368/product_data_sheet0900aecd8027c9e6.html > > Can someone please clarify what exactly this means. > > Also if I put a 10GbE SPA into a SIP-400 what is the expected > performance of that? > > Thanks > //MKS > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From musmanashraf at gmail.com Mon Apr 6 12:45:24 2009 From: musmanashraf at gmail.com (M Usman Ashraf) Date: Mon, 6 Apr 2009 21:45:24 +0500 Subject: [c-nsp] CISCO ACS 4.2 command pattern matching In-Reply-To: <1238960409.3675.16.camel@localhost.localdomain> References: <9149d2410904051059u4a3d7d2h5894d495481be4e6@mail.gmail.com> <1238960409.3675.16.camel@localhost.localdomain> Message-ID: <9149d2410904060945n4b900cb6ua652c90b40ffbf5@mail.gmail.com> Thanks Peter.You were right, explicit "" was missing. It is ok now. On Mon, Apr 6, 2009 at 12:40 AM, Peter Rathlev wrote: > On Sun, 2009-04-05 at 22:59 +0500, M Usman Ashraf wrote: > > So from this I take that if I want to deny configuration of certain > > interfaces say Loopback0, while allowing configuration of Loopback99, > > I will, permit "interface" , with the sub-command arguments: > > permit*^Loopback99$*, unmatched commands are "deny" and "Permit > > Unmatched Args" is unchecked. > > > > Thinking that would allow the command interface Loopback99 but > > actually the "interface Loopback99" commands, fails authorization. On > > the other side, if I permit *^Loopback* only, all loopbacks get > > permitted. It seems like the "^" pattern matching works but the "$" > > doesn't. Anyone have any experience with pattern matching that can > > help me out? -- > > Your TACACS+ log should tell you the reason, even the ACS must have > one. ;-) > > The reason could be that many end points add an explicit "" string > to the request. If that is the case you would have to allow this > instead: > > permit "^Loopback99 $" > > Regards, > Peter > > > -- Regards, M Usman Ashraf From achatz at forthnet.gr Mon Apr 6 12:49:07 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Mon, 06 Apr 2009 19:49:07 +0300 Subject: [c-nsp] EEM event-manager and "event none" question. In-Reply-To: <1239034684.13422.5.camel@dsba-ipso> References: <1239034684.13422.5.camel@dsba-ipso> Message-ID: <49DA3283.1030101@forthnet.gr> Event none is used if you want to manually run the eem applet, like you tried to do. In your case (i guess you need to test your applet), you can create a 2nd applet that uses event none and just sets the track 10 state to up (action 1.0 track set 10 state up). That way you can run the 2nd applet manually which in turn should trigger the 1st applet to run automatically. Just keep an eye on any other consequences this manual track state change might have on your router. -- Tassos luismi wrote on 06/04/2009 19:18: > I have this code... > > event manager applet A-EU-UP > event track 10 state up > action 1.0 syslog msg "Track 10 Up. Houston we don't have a problem" > action 2.0 cli command "enable" > action 3.0 cli command "conf t" > action 4.0 cli command "" > > I tried to execute... > # event manager run A-EU-UP > Embedded Event Manager policy EU-ACEL-BACKUP-OFF not registered with > event none Event Detector > > What is the reason for that message? > Looks like the EEM code is not running. > As far as I can read at documentation found with google, I need "event > none" at the beginning of the applet, but, what is the reason for it? > When "event none" must be used? > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From peter at rathlev.dk Mon Apr 6 12:52:22 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Mon, 06 Apr 2009 18:52:22 +0200 Subject: [c-nsp] Getting ready to pull the trigger: RSP720/SUP720 In-Reply-To: References: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> Message-ID: <1239036742.4684.33.camel@localhost.localdomain> On Mon, 2009-04-06 at 07:51 -0700, Rick Ernst wrote: > The problem I am running into is spec'ing the aggregation layer. > Almost all of our traffic is ethernet now, and all the interfaces need > bi-drectional rate-limiting/traffic-shaping/policing. We have a > variable bandwidth model and need to cap traffic at 1Mbs granularity. > 1,5, and 10Mbs connections are common, and 20,50,100Mbs connections > exist with a 200Mbs pipe in process. ES20 line cards for the 7600 might fit your purpose: http://www.cisco.com/en/US/prod/collateral/routers/ps368/product_data_sheet0900aecd8057f3ad.html http://tinyurl.com/3jc8mx The hardware forwarding switches can't really shape very well on LAN card interfaces. You can use token bucket policing, and the "SRR" enabled interfaces can do some crude "timeslot" shaping, but real buffered shaping isn't possible AFAIK. On Mon, 2009-04-06 at 11:12 -0400, Jon Lewis wrote: > On Mon, 6 Apr 2009, Rick Ernst wrote: > > I'm planning on collapsing the border/core into a pair of > > 7600/Sup720-3BXLs, and it looks like they will be almost idle with > > this amount of load. > > That really depends on the features you enable. Try doing full > netflow on a sup720 doing a few hundred mbit's of traffic, and they're > suddenly not so mighty. Sorry if I repeat myself, but I don't understand this problem. We export netflow from Sup720-3Bs often carrying >1 Gbit/s and the processor hardly seems to notice. And it's with an if-full flowmask. We're still on SXF but I sincerely hope SXH/SXI behave the same way for us. Am I missing something here? Regards, Peter From rick at woofpaws.com Mon Apr 6 12:54:31 2009 From: rick at woofpaws.com (Rick Ernst) Date: Mon, 6 Apr 2009 09:54:31 -0700 (PDT) Subject: [c-nsp] Getting ready to pull the trigger: RSP720/SUP720 In-Reply-To: References: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> Message-ID: <47617.69.30.17.85.1239036871.squirrel@www.woofpaws.com> On Mon, April 6, 2009 08:12, Jon Lewis wrote: > On Mon, 6 Apr 2009, Rick Ernst wrote: > >> I'm planning on collapsing the border/core into a pair of >> 7600/Sup720-3BXLs, and it looks like they will be almost idle with this >> amount of load. > > That really depends on the features you enable. Try doing full netflow on > a sup720 doing a few hundred mbit's of traffic, and they're suddenly not > so mighty. Yikes! Does DFC on the linecards mitigate this? I'm also looking specifically at the Sup720/MSFC3/PFC3BLX. >> The problem I am running into is spec'ing the aggregation layer. Almost >> all of our traffic is ethernet now, and all the interfaces need >> bi-drectional rate-limiting/traffic-shaping/policing. We have a >> variable >> bandwidth model and need to cap traffic at 1Mbs granularity. 1,5, and >> 10Mbs connections are common, and 20,50,100Mbs connections exist with a >> 200Mbs pipe in process. > > We've been using 3550's for years for this, as they have the ability to > police in both directions, per port, at whatever granularity you like. > The 3560, which was supposed to be an improvement/replacement for the 3550 > lost this ability, which really shocked me when I configured my first one. > It can do per-port output shaping, but the granularity kind of blows. > You're limited to 1/N * port rate, where N is an integer from 0 to 65535. > This gives plenty (actually a huge waste of range) of granularity at the > low end of bandwidth, but at the high end, you're limited to full rate, > 50%, 33%, 25%, 20%, etc. If I'm wrong here, I'd love to hear it and be > told how to limit a 100mbit port to say 40mbit/s. It looks like the 3550 has been EOLd for a couple of years. Does the 3750 (non-Metro) or other comparable switch carry the same functionality? Does the switch itself need to be doing IP on the port to provide rate-liming? Input shaping is where my major concern is since these would be deployed where traffic is heavily weighted on inbound (from-the-customer). Thanks! From ip at ioshints.info Mon Apr 6 12:59:19 2009 From: ip at ioshints.info (Ivan Pepelnjak) Date: Mon, 6 Apr 2009 18:59:19 +0200 Subject: [c-nsp] EEM event-manager and "event none" question. In-Reply-To: <1239034684.13422.5.camel@dsba-ipso> References: <1239034684.13422.5.camel@dsba-ipso> Message-ID: <006e01c9b6d9$07af0980$0a00000a@nil.si> An EEM applet can be triggered only by a single condition. If you want to trigger it from the command line (with the "event man run" command), it cannot be triggered by anything else, so it must have "event none" pseudo-trigger. The "event none" is used to indicate that "no trigger" is actually what you want to do (as opposed to "I forgot to specify the trigger"). Ivan http://www.ioshints.info/about http://blog.ioshints.info/ > -----Original Message----- > From: luismi [mailto:asturluismi at gmail.com] > Sent: Monday, April 06, 2009 6:18 PM > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] EEM event-manager and "event none" question. > > I have this code... > > event manager applet A-EU-UP > event track 10 state up > action 1.0 syslog msg "Track 10 Up. Houston we don't have a problem" > action 2.0 cli command "enable" > action 3.0 cli command "conf t" > action 4.0 cli command "" > > I tried to execute... > # event manager run A-EU-UP > Embedded Event Manager policy EU-ACEL-BACKUP-OFF not > registered with event none Event Detector > > What is the reason for that message? > Looks like the EEM code is not running. > As far as I can read at documentation found with google, I > need "event none" at the beginning of the applet, but, what > is the reason for it? > When "event none" must be used? > > > > > From ip at ioshints.info Mon Apr 6 13:05:55 2009 From: ip at ioshints.info (Ivan Pepelnjak) Date: Mon, 6 Apr 2009 19:05:55 +0200 Subject: [c-nsp] two ISPs, two routers, one firewall - bgp question In-Reply-To: References: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> Message-ID: <006f01c9b6d9$f3f50790$0a00000a@nil.si> Outbound traffic traverses the DMZ segment twice (FW -> R2 -> R1). Inbound traffic traverses the DMZ segment once (R2 -> FW). The difference is that FW has no idea where to send the traffic (follows default route), whereas R2 knows the internal network is reachable through the FW. Hope this helps Ivan http://www.ioshints.info/about http://blog.ioshints.info/ > -----Original Message----- > From: Rossella Mariotti-Jones [mailto:rossella at chemeketa.edu] > Sent: Monday, April 06, 2009 6:22 PM > To: cisco-nsp at puck.nether.net > Cc: cisco-nsp at puck.nether.net > Subject: [c-nsp] two ISPs, two routers, one firewall - bgp question > > Hello all, I have a question regarding this scenario: > http://www.cisco.com/en/US/tech/tk365/technologies_configurati > on_example > 09186a00800945bf.shtml#conf5 > > My R2 link to ISP is 100M > R1 link to ISP is a DS3 > > If my firewall has a default route of 192.168.21.2 and I > have a 10M download going with AS300, my firewall is going to > send out my traffic through its default gateway which is > 192.168.21.2, R2 knows through iBGP that R1 is the best path > to AS300, so it sends the traffic to R1, traffic coming back > goes through R1, R2, firewall to get to the client, so > basically in this case the link between my firewall and R2 is > taken up twice. Am I understanding this correctly? Thanks > everyone in advance. > > rossella > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jon Lewis > Sent: Monday, April 06, 2009 8:12 AM > To: Rick Ernst > Cc: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] Getting ready to pull the trigger: RSP720/SUP720 > > On Mon, 6 Apr 2009, Rick Ernst wrote: > > > I'm planning on collapsing the border/core into a pair of > > 7600/Sup720-3BXLs, and it looks like they will be almost idle with > this > > amount of load. > > That really depends on the features you enable. Try doing > full netflow on a sup720 doing a few hundred mbit's of > traffic, and they're suddenly not > > so mighty. > > > The problem I am running into is spec'ing the aggregation layer. > Almost > > all of our traffic is ethernet now, and all the interfaces need > > bi-drectional rate-limiting/traffic-shaping/policing. We have a > variable > > bandwidth model and need to cap traffic at 1Mbs > granularity. 1,5, and > > 10Mbs connections are common, and 20,50,100Mbs connections > exist with > a > > 200Mbs pipe in process. > > We've been using 3550's for years for this, as they have the > ability to police in both directions, per port, at whatever > granularity you like. > The 3560, which was supposed to be an improvement/replacement > for the 3550 lost this ability, which really shocked me when > I configured my first one. > It can do per-port output shaping, but the granularity kind of blows. > You're limited to 1/N * port rate, where N is an integer from > 0 to 65535. > This gives plenty (actually a huge waste of range) of > granularity at the > > low end of bandwidth, but at the high end, you're limited to > full rate, 50%, 33%, 25%, 20%, etc. If I'm wrong here, I'd > love to hear it and be told how to limit a 100mbit port to > say 40mbit/s. > > ---------------------------------------------------------------------- > Jon Lewis | I route > Senior Network Engineer | therefore you are > Atlantic Net | > _________ http://www.lewis.org/~jlewis/pgp for PGP public > key_________ _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > From musmanashraf at gmail.com Mon Apr 6 13:09:13 2009 From: musmanashraf at gmail.com (M Usman Ashraf) Date: Mon, 6 Apr 2009 22:09:13 +0500 Subject: [c-nsp] EEM event-manager and "event none" question. In-Reply-To: <1239034684.13422.5.camel@dsba-ipso> References: <1239034684.13422.5.camel@dsba-ipso> Message-ID: <9149d2410904061009x730a3788u68a687e6b0c19783@mail.gmail.com> Hi, You have to use "event none", under "event manager applet A-EU-UP", if you want to do so. On Mon, Apr 6, 2009 at 9:18 PM, luismi wrote: > I have this code... > > event manager applet A-EU-UP > event track 10 state up > action 1.0 syslog msg "Track 10 Up. Houston we don't have a problem" > action 2.0 cli command "enable" > action 3.0 cli command "conf t" > action 4.0 cli command "" > > I tried to execute... > # event manager run A-EU-UP > Embedded Event Manager policy EU-ACEL-BACKUP-OFF not registered with > event none Event Detector > > What is the reason for that message? > Looks like the EEM code is not running. > As far as I can read at documentation found with google, I need "event > none" at the beginning of the applet, but, what is the reason for it? > When "event none" must be used? > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > -- Regards, M Usman Ashraf From asturluismi at gmail.com Mon Apr 6 13:10:58 2009 From: asturluismi at gmail.com (luismi) Date: Mon, 06 Apr 2009 19:10:58 +0200 Subject: [c-nsp] EEM event-manager and "event none" question. In-Reply-To: <49DA3283.1030101@forthnet.gr> References: <1239034684.13422.5.camel@dsba-ipso> <49DA3283.1030101@forthnet.gr> Message-ID: <1239037858.13422.17.camel@dsba-ipso> I just did a test right now. The appelt is running ok without "event none" as expected, seems to be that is monitoring the track 10 without more manual intervention as I can see in the output of "sh track 10" El lun, 06-04-2009 a las 19:49 +0300, Tassos Chatzithomaoglou escribi?: > Event none is used if you want to manually run the eem applet, like you tried to do. > > In your case (i guess you need to test your applet), you can create a 2nd applet that uses event none and just sets the > track 10 state to up (action 1.0 track set 10 state up). > That way you can run the 2nd applet manually which in turn should trigger the 1st applet to run automatically. > Just keep an eye on any other consequences this manual track state change might have on your router. > > -- > Tassos > > luismi wrote on 06/04/2009 19:18: > > I have this code... > > > > event manager applet A-EU-UP > > event track 10 state up > > action 1.0 syslog msg "Track 10 Up. Houston we don't have a problem" > > action 2.0 cli command "enable" > > action 3.0 cli command "conf t" > > action 4.0 cli command "" > > > > I tried to execute... > > # event manager run A-EU-UP > > Embedded Event Manager policy EU-ACEL-BACKUP-OFF not registered with > > event none Event Detector > > > > What is the reason for that message? > > Looks like the EEM code is not running. > > As far as I can read at documentation found with google, I need "event > > none" at the beginning of the applet, but, what is the reason for it? > > When "event none" must be used? > > > > > > > > _______________________________________________ > > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > From tdurack at gmail.com Mon Apr 6 16:02:20 2009 From: tdurack at gmail.com (Tim Durack) Date: Mon, 6 Apr 2009 16:02:20 -0400 Subject: [c-nsp] same-router tunnel loopback In-Reply-To: <9e246b4d0904041629i7fd97176obf8097ee2b4d2390@mail.gmail.com> References: <9e246b4d0904031314p5db46d44uf8dac478cc22ae05@mail.gmail.com> <20090404085652.GR290@greenie.muc.de> <9e246b4d0904041629i7fd97176obf8097ee2b4d2390@mail.gmail.com> Message-ID: <9e246b4d0904061302l1f2c5ad7rec292c3b986052cd@mail.gmail.com> >> (Maybe it's just the /127 - try with /124 or /64, just to be sure) Tried a /112, same problem. I wonder if the issue is recirculation. I already need "mls mpls tunnel-recir" to support IPv4 traffic crossing the tunnel. Given that IPv6 requires recirculation for regular forwarding, is there a limit to the amount of recirc that can take place? Perhaps I'm trying to do something weird that no one else has tried... Tim:> From lists at memetic.org Mon Apr 6 16:18:23 2009 From: lists at memetic.org (Adam Armstrong) Date: Mon, 06 Apr 2009 21:18:23 +0100 Subject: [c-nsp] client mac address on LNS?? In-Reply-To: <003501c9b675$547f7d80$fd7e7880$@net.pk> References: <003501c9b675$547f7d80$fd7e7880$@net.pk> Message-ID: <49DA638F.6070106@memetic.org> Why aren't you just using the username for accounting? > Dear Friends! > > > > I have a setup in which DSL users connect to a LNS via L2TP. Everything is > working fine, however on LNS I am not receiving any MAC address for the DSL > Users( Type PPPoVPDN). This is my standard crucial requirement for > generating several reports for management purposes. > > > > Can someone tell me if it is possible to get Mac-address for the VPDN > users??? I am getting mac-address for PPPoE type users which are terminated > on my BRAS. > > > > Attach is the debug output for both LNS and BRAS which shows that > mac-address field is missing in LNS output. > > > > ######### LNS output (domain stripping is used) ########## > > > > Apr 6 04:29:47.020: RADIUS(00001037): Send Access-Request to > 10.10.10.10:3312 id 1645/44, len 123 > > Apr 6 04:29:47.020: RADIUS: Framed-Protocol [7] 6 PPP > [1] > > Apr 6 04:29:47.020: RADIUS: User-Name [1] 11 "testuser7" > > Apr 6 04:29:47.020: RADIUS: User-Password [2] 18 * > > Apr 6 04:29:47.020: RADIUS: NAS-Port [5] 6 370 > > > Apr 6 04:29:47.020: RADIUS: NAS-Port-Id [87] 17 > "Uniq-Sess-ID370" > > Apr 6 04:29:47.020: RADIUS: Connect-Info [77] 9 "1920000" > > Apr 6 04:29:47.020: RADIUS: NAS-Port-Type [61] 6 Virtual > [5] > > Apr 6 04:29:47.020: RADIUS: Service-Type [6] 6 Framed > [2] > > Apr 6 04:29:47.020: RADIUS: NAS-IP-Address [4] 6 1.1.1.1 > > > Apr 6 04:29:47.020: RADIUS: Acct-Session-Id [44] 18 > "CAA36E5A00001058" > > Apr 6 04:29:47.308: RADIUS: Received from id 1645/44 10.10.10.10:3312, > Access-Accept, len 37 > > Apr 6 04:29:47.308: RADIUS: Class [25] 5 > > Apr 6 04:29:47.308: RADIUS: 50 49 4E > [PIN] > > Apr 6 04:29:47.308: RADIUS: Service-Type [6] 6 Framed > [2] > > Apr 6 04:29:47.308: RADIUS: Framed-Protocol [7] 6 PPP > [1] > > Apr 6 04:31:47.100: RADIUS(00001038): Received from id 1645/45 > > Apr 6 04:31:47.100: VT[Vi3.1]:Request took 0 msec, 0 msec processing time > > Apr 6 04:31:47.100: uid:371 Tnl/Sn 58894/504 L2TP: Virtual interface > created for testuser7 at best-dsl bandwidth 1920 Kbps > > Apr 6 04:31:47.100: Vi3.1 Tnl/Sn 58894/504 L2TP: Virtual interface created > for testuser7 at best-dsl, bandwidth 1920 Kbps > > Apr 6 04:31:47.100: Vi3.1 Tnl/Sn 58894/504 L2TP: VPDN session up > > Apr 6 04:31:47.220: RADIUS/ENCODE(00001038):Orig. component type = VPDN > > > > > > Cisco-3845-L2TP-LNS#show users > > > > Interface User Mode Idle Peer Address > > Vi3.1 testuser7 at best-ds PPPoVPDN - 1.1.1.233 > > > > ######### BRAS output ########## > > > > *Mar 1 00:13:15.367: RADIUS(00000009): Send Access-Request to > 10.10.10.10:3312 id 1645/6, len 167 > > *Mar 1 00:13:15.367: RADIUS: Vendor, Cisco [26] 41 > > *Mar 1 00:13:15.367: RADIUS: Cisco AVpair [1] 35 > "client-mac-address=000f.a392.4bef" > > *Mar 1 00:13:15.367: RADIUS: Framed-Protocol [7] 6 PPP > [1] > > *Mar 1 00:13:15.367: RADIUS: User-Name [1] 11 "testuser6" > > *Mar 1 00:13:15.367: RADIUS: User-Password [2] 18 * > > *Mar 1 00:13:15.367: RADIUS: NAS-Port-Type [61] 6 Virtual > [5] > > *Mar 1 00:13:15.367: RADIUS: Vendor, Cisco [26] 18 > > *Mar 1 00:13:15.367: RADIUS: cisco-nas-port [2] 12 "3/0/0/0.36" > > *Mar 1 00:13:15.367: RADIUS: NAS-Port [5] 6 805306404 > > > *Mar 1 00:13:15.367: RADIUS: Service-Type [6] 6 Framed > [2] > > *Mar 1 00:13:15.371: RADIUS: NAS-IP-Address [4] 6 1.1.1.1 > > > *Mar 1 00:13:15.371: RADIUS: Acct-Session-Id [44] 29 > "3/0/0/0.36_CAA3693A0000000E" > > *Mar 1 00:13:15.519: RADIUS: Received from id 1645/6 10.10.10.10:3312, > Access-Accept, len 37 > > *Mar 1 00:13:15.519: RADIUS: Class [25] 5 > > *Mar 1 00:13:15.519: RADIUS: 50 49 4E > [PIN] > > *Mar 1 00:13:15.519: RADIUS: Service-Type [6] 6 Framed > [2] > > *Mar 1 00:13:15.519: RADIUS: Framed-Protocol [7] 6 PPP > [1] > > *Mar 1 00:13:15.523: RADIUS(00000009): Received from id 1645/6 > > *Mar 1 00:13:15.643: RADIUS/ENCODE(00000009):Orig. component type = PPoE > > > > > > Cisc-3640-BRAS-And-L2TP-LAC# show user > > > > Interface User Mode Idle Peer Address > > Vi2.1 testuser6 PPPoE 00:03:25 2.2.2.244 > > > > > > > > Best Regards, > > > > Asad Ul-Islam > > > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From billw at waveform.net Mon Apr 6 16:34:34 2009 From: billw at waveform.net (Bill Wichers) Date: Mon, 6 Apr 2009 16:34:34 -0400 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 Message-ID: I have a strange problem getting an Etherchannel link betweek a 7507 and a Cat 4006. Basically everything works, but the two FE interfaces on the 7507 (both in the same VIP) keep dropping their "full-duplex" config and reporting "unknown duplex" instead. Traffic works across the link, load is about the same on both member links, only the weird duplex problem - which is causing some errors to show on the port. Config on the switch is very simple: set port speed 2/1-2 100 set port duplex 2/1-2 full set trunk 2/1 on dot1q 1-1005,1025-4094 set trunk 2/2 on dot1q 1-1005,1025-4094 set port channel 2/1-2 mode on Just two FE interfaces in the group. Config on the router isn't very complicated either: interface Port-channel1 no ip address load-interval 30 hold-queue 150 in ! interface FastEthernet1/0/0 description EC to core switch 2/1 no ip address channel-group 1 ! interface FastEthernet1/1/0 description EC to core switch 2/2 no ip address channel-group 1 ! There are a few virtual interfaces on the port-channel using 802.1q tags and they all seem to work, they're setup the usual way of "port-channel 1.123 / encap dot1q 123 ... etc. Router is running 12.2(6a), cat is running 8.4(8)GLX. There is no fancy L3 blade in the cat. It seems like the router is just loosing the 'full-duplex' part of the config of the two member links and aside from that everything seems to work. Any ideas? -Bill From mksmith at adhost.com Mon Apr 6 18:05:20 2009 From: mksmith at adhost.com (Michael K. Smith - Adhost) Date: Mon, 6 Apr 2009 15:05:20 -0700 Subject: [c-nsp] same-router tunnel loopback In-Reply-To: <9e246b4d0904061302l1f2c5ad7rec292c3b986052cd@mail.gmail.com> References: <9e246b4d0904031314p5db46d44uf8dac478cc22ae05@mail.gmail.com><20090404085652.GR290@greenie.muc.de><9e246b4d0904041629i7fd97176obf8097ee2b4d2390@mail.gmail.com> <9e246b4d0904061302l1f2c5ad7rec292c3b986052cd@mail.gmail.com> Message-ID: <17838240D9A5544AAA5FF95F8D52031605D17479@ad-exh01.adhost.lan> -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Tim Durack Sent: Monday, April 06, 2009 1:02 PM To: cisco-nsp at puck.nether.net Cc: Gert Doering Subject: Re: [c-nsp] same-router tunnel loopback >> (Maybe it's just the /127 - try with /124 or /64, just to be sure) Tried a /112, same problem. I wonder if the issue is recirculation. I already need "mls mpls tunnel-recir" to support IPv4 traffic crossing the tunnel. Given that IPv6 requires recirculation for regular forwarding, is there a limit to the amount of recirc that can take place? Perhaps I'm trying to do something weird that no one else has tried... [Michael K. Smith - Adhost] Do you need the "tunnel mode ipv6ip" on the tunnel interface perhaps? Regards, Mike From p.mayers at imperial.ac.uk Mon Apr 6 18:45:18 2009 From: p.mayers at imperial.ac.uk (Phil Mayers) Date: Mon, 6 Apr 2009 23:45:18 +0100 Subject: [c-nsp] Getting ready to pull the trigger: RSP720/SUP720 In-Reply-To: <1239036742.4684.33.camel@localhost.localdomain> References: <46659.69.30.17.85.1239029500.squirrel@www.woofpaws.com> <1239036742.4684.33.camel@localhost.localdomain> Message-ID: <20090406224518.GA12346@wildfire.net.ic.ac.uk> On Mon, Apr 06, 2009 at 05:52:22PM +0100, Peter Rathlev wrote: >> > this amount of load. >> >> That really depends on the features you enable. Try doing full >> netflow on a sup720 doing a few hundred mbit's of traffic, and they're >> suddenly not so mighty. > >Sorry if I repeat myself, but I don't understand this problem. We export >netflow from Sup720-3Bs often carrying >1 Gbit/s and the processor >hardly seems to notice. And it's with an if-full flowmask. We're still >on SXF but I sincerely hope SXH/SXI behave the same way for us. > >Am I missing something here? I am assuming Jon has a lot of flows. We too run if-full on multiple tens of gigabits, with no issues (and on-3B, not XL), but I guess it depends on your traffic mix. From ler762 at gmail.com Mon Apr 6 19:47:11 2009 From: ler762 at gmail.com (Lee) Date: Mon, 6 Apr 2009 19:47:11 -0400 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 In-Reply-To: References: Message-ID: My experience has been that setting the speed and duplex on a catalyst switch stops it from doing auto-negotiation. So with the switch ports set to 100/full I'd expect the 7500 ports to come up as 100/half. But we don't have any cat4006s at work.. I don't know if they do auto-negotiation even if the port speed and duplex is configured, Lee On 4/6/09, Bill Wichers wrote: > I have a strange problem getting an Etherchannel link betweek a 7507 and > a Cat 4006. Basically everything works, but the two FE interfaces on the > 7507 (both in the same VIP) keep dropping their "full-duplex" config and > reporting "unknown duplex" instead. Traffic works across the link, load > is about the same on both member links, only the weird duplex problem - > which is causing some errors to show on the port. > > > > Config on the switch is very simple: > > > > set port speed 2/1-2 100 > > set port duplex 2/1-2 full > > > > set trunk 2/1 on dot1q 1-1005,1025-4094 > > set trunk 2/2 on dot1q 1-1005,1025-4094 > > set port channel 2/1-2 mode on > > > > Just two FE interfaces in the group. > > > > Config on the router isn't very complicated either: > > > > interface Port-channel1 > > no ip address > > load-interval 30 > > hold-queue 150 in > > ! > > interface FastEthernet1/0/0 > > description EC to core switch 2/1 > > no ip address > > channel-group 1 > > ! > > interface FastEthernet1/1/0 > > description EC to core switch 2/2 > > no ip address > > channel-group 1 > > ! > > > > There are a few virtual interfaces on the port-channel using 802.1q tags > and they all seem to work, they're setup the usual way of "port-channel > 1.123 / encap dot1q 123 ... etc. > > > > Router is running 12.2(6a), cat is running 8.4(8)GLX. There is no fancy > L3 blade in the cat. It seems like the router is just loosing the > 'full-duplex' part of the config of the two member links and aside from > that everything seems to work. Any ideas? > > > > -Bill > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From sf at lists.esoteric.ca Mon Apr 6 21:12:11 2009 From: sf at lists.esoteric.ca (Stephen Fulton) Date: Mon, 06 Apr 2009 21:12:11 -0400 Subject: [c-nsp] SIP-400 and 10GbE SPA In-Reply-To: References: Message-ID: <49DAA86B.5070306@lists.esoteric.ca> According to the SIP/SPA compatibility matrix: http://www.cisco.com/en/US/docs/interfaces_modules/shared_port_adapters/install_upgrade/7600series/76intro.html#wp1131939 The SPA-1X10GE-L-V2 is compatible with SIP-400. As always, verify with your Cisco SE. -- Stephen MKS wrote: > Hi There > > According to cisco SIP-400 can > "Ability to run 4 GE line rate for 64-byte packets, and OC-48 line > rate for 48-byte packets for POS, HDLC, etc. with select services" > https://www.cisco.com/en/US/prod/collateral/routers/ps368/product_data_sheet0900aecd8027c9e6.html > > Can someone please clarify what exactly this means. > > Also if I put a 10GbE SPA into a SIP-400 what is the expected > performance of that? > > Thanks > //MKS > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From asad747 at cyber.net.pk Mon Apr 6 23:49:35 2009 From: asad747 at cyber.net.pk (Asad Ul-Islam) Date: Tue, 07 Apr 2009 08:49:35 +0500 Subject: [c-nsp] client mac address on LNS?? In-Reply-To: <49DA638F.6070106@memetic.org> References: <003501c9b675$547f7d80$fd7e7880$@net.pk> <49DA638F.6070106@memetic.org> Message-ID: <001e01c9b733$de42baa0$9ac82fe0$@net.pk> We do accounting on usernames obviously. But client-mac-address is our policy requirement for generating certain security related reports. -----Original Message----- From: Adam Armstrong [mailto:lists at memetic.org] Sent: Tuesday, April 07, 2009 1:18 AM To: Asad Ul-Islam Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] client mac address on LNS?? Why aren't you just using the username for accounting? > Dear Friends! > > > > I have a setup in which DSL users connect to a LNS via L2TP. Everything is > working fine, however on LNS I am not receiving any MAC address for the DSL > Users( Type PPPoVPDN). This is my standard crucial requirement for > generating several reports for management purposes. > > > > Can someone tell me if it is possible to get Mac-address for the VPDN > users??? I am getting mac-address for PPPoE type users which are terminated > on my BRAS. > > > > Attach is the debug output for both LNS and BRAS which shows that > mac-address field is missing in LNS output. > > > > ######### LNS output (domain stripping is used) ########## > > > > Apr 6 04:29:47.020: RADIUS(00001037): Send Access-Request to > 10.10.10.10:3312 id 1645/44, len 123 > > Apr 6 04:29:47.020: RADIUS: Framed-Protocol [7] 6 PPP > [1] > > Apr 6 04:29:47.020: RADIUS: User-Name [1] 11 "testuser7" > > Apr 6 04:29:47.020: RADIUS: User-Password [2] 18 * > > Apr 6 04:29:47.020: RADIUS: NAS-Port [5] 6 370 > > > Apr 6 04:29:47.020: RADIUS: NAS-Port-Id [87] 17 > "Uniq-Sess-ID370" > > Apr 6 04:29:47.020: RADIUS: Connect-Info [77] 9 "1920000" > > Apr 6 04:29:47.020: RADIUS: NAS-Port-Type [61] 6 Virtual > [5] > > Apr 6 04:29:47.020: RADIUS: Service-Type [6] 6 Framed > [2] > > Apr 6 04:29:47.020: RADIUS: NAS-IP-Address [4] 6 1.1.1.1 > > > Apr 6 04:29:47.020: RADIUS: Acct-Session-Id [44] 18 > "CAA36E5A00001058" > > Apr 6 04:29:47.308: RADIUS: Received from id 1645/44 10.10.10.10:3312, > Access-Accept, len 37 > > Apr 6 04:29:47.308: RADIUS: Class [25] 5 > > Apr 6 04:29:47.308: RADIUS: 50 49 4E > [PIN] > > Apr 6 04:29:47.308: RADIUS: Service-Type [6] 6 Framed > [2] > > Apr 6 04:29:47.308: RADIUS: Framed-Protocol [7] 6 PPP > [1] > > Apr 6 04:31:47.100: RADIUS(00001038): Received from id 1645/45 > > Apr 6 04:31:47.100: VT[Vi3.1]:Request took 0 msec, 0 msec processing time > > Apr 6 04:31:47.100: uid:371 Tnl/Sn 58894/504 L2TP: Virtual interface > created for testuser7 at best-dsl bandwidth 1920 Kbps > > Apr 6 04:31:47.100: Vi3.1 Tnl/Sn 58894/504 L2TP: Virtual interface created > for testuser7 at best-dsl, bandwidth 1920 Kbps > > Apr 6 04:31:47.100: Vi3.1 Tnl/Sn 58894/504 L2TP: VPDN session up > > Apr 6 04:31:47.220: RADIUS/ENCODE(00001038):Orig. component type = VPDN > > > > > > Cisco-3845-L2TP-LNS#show users > > > > Interface User Mode Idle Peer Address > > Vi3.1 testuser7 at best-ds PPPoVPDN - 1.1.1.233 > > > > ######### BRAS output ########## > > > > *Mar 1 00:13:15.367: RADIUS(00000009): Send Access-Request to > 10.10.10.10:3312 id 1645/6, len 167 > > *Mar 1 00:13:15.367: RADIUS: Vendor, Cisco [26] 41 > > *Mar 1 00:13:15.367: RADIUS: Cisco AVpair [1] 35 > "client-mac-address=000f.a392.4bef" > > *Mar 1 00:13:15.367: RADIUS: Framed-Protocol [7] 6 PPP > [1] > > *Mar 1 00:13:15.367: RADIUS: User-Name [1] 11 "testuser6" > > *Mar 1 00:13:15.367: RADIUS: User-Password [2] 18 * > > *Mar 1 00:13:15.367: RADIUS: NAS-Port-Type [61] 6 Virtual > [5] > > *Mar 1 00:13:15.367: RADIUS: Vendor, Cisco [26] 18 > > *Mar 1 00:13:15.367: RADIUS: cisco-nas-port [2] 12 "3/0/0/0.36" > > *Mar 1 00:13:15.367: RADIUS: NAS-Port [5] 6 805306404 > > > *Mar 1 00:13:15.367: RADIUS: Service-Type [6] 6 Framed > [2] > > *Mar 1 00:13:15.371: RADIUS: NAS-IP-Address [4] 6 1.1.1.1 > > > *Mar 1 00:13:15.371: RADIUS: Acct-Session-Id [44] 29 > "3/0/0/0.36_CAA3693A0000000E" > > *Mar 1 00:13:15.519: RADIUS: Received from id 1645/6 10.10.10.10:3312, > Access-Accept, len 37 > > *Mar 1 00:13:15.519: RADIUS: Class [25] 5 > > *Mar 1 00:13:15.519: RADIUS: 50 49 4E > [PIN] > > *Mar 1 00:13:15.519: RADIUS: Service-Type [6] 6 Framed > [2] > > *Mar 1 00:13:15.519: RADIUS: Framed-Protocol [7] 6 PPP > [1] > > *Mar 1 00:13:15.523: RADIUS(00000009): Received from id 1645/6 > > *Mar 1 00:13:15.643: RADIUS/ENCODE(00000009):Orig. component type = PPoE > > > > > > Cisc-3640-BRAS-And-L2TP-LAC# show user > > > > Interface User Mode Idle Peer Address > > Vi2.1 testuser6 PPPoE 00:03:25 2.2.2.244 > > > > > > > > Best Regards, > > > > Asad Ul-Islam > > > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From tedm at toybox.placo.com Tue Apr 7 01:11:23 2009 From: tedm at toybox.placo.com (Ted Mittelstaedt) Date: Mon, 06 Apr 2009 22:11:23 -0700 Subject: [c-nsp] Router failure - config lost? In-Reply-To: <49BE24F9.4010903@gmx.de> References: <49BE24F9.4010903@gmx.de> Message-ID: <49DAE07B.9080901@toybox.placo.com> Garry wrote: > Hi * > > I've got something of a question that's not necessarily a clear > technical problem or config problem ... rather just scoping as to > whether other people have come across this, too ... > > We have a customer who has some 400+ locations. All of these are > connected to the central office via an MPLS-based network, using aDSL > lines. Every location has an identical 876-W-G-E-k9 router, with (apart > from DSL username and IP address) identical config. This network has now > been in operation for something like 18 months, and is working nicely. > > Now, on average 1-2 locations per month go down, losing DSL > connectivity, and even a power-cycle and DSL port reset by the > DSL-provider won't work, at which point we configure a replacement > router and send it out. We usually get the defective router back for > analysis, and apart from a hand full of cases in which the routers where > physically damaged (lightning, spikes on the power supply etc.), most of > the defective routers have simply lost their configuration file. On one > occasion, the whole router flash was cleared, removing the IOS. On yet > another occasion, I think we found the stock config file (the one with > the large header, "cisco" login etc.) on the router (which I thought was > really weird). > > In all those cases, we have opted to re-use the router, if for nothing > else than to see whether it was an actual hardware defect ... to date, > no router has shown that behavior twice (we track the ser#). > > As for the configs/routers themselves, the locations do not have any > username/pw to log in to the routers. External access shouldn't be > possible, as the network itself has no direct Internet connectivity. > > Has anybody else here ever experienced effects like this? > Yes, with the 827-4V Exact same symptoms, flash wiped, including the nvram - fortunately someone put a page up somewhere explaining how to recover a wiped nvram. Putting the thing behind a VERY good UPS might help. You also want to put a surge suppressor on the telephone line the DSL signal is coming in on. Beyond that, cheap router, whaddayah expect? I gave up on the all-in-one 8xx DSL solutions on DSL ages ago. Today I send out separate DSL modems in bridged mode and use ethernet-to-ethernet routers. If the DSL modem goes tits up it's cheap enough to just overnight another one out and tell them to throw away the modem. Ted From pigsign.pykota at gmail.com Tue Apr 7 03:03:54 2009 From: pigsign.pykota at gmail.com (Darren Yang) Date: Tue, 7 Apr 2009 15:03:54 +0800 Subject: [c-nsp] How can enable PfR PIRO function on IOS 12.4(24)T Message-ID: Hi, The Cisco introduced PfR can support OSPF as parent route on IOS 12.4(24)T and this term is PIRO(Protocol Independent Route Optimization). Detail link this: http://www.cisco.com/en/US/docs/ios/oer/configuration/guide/oer-trf_rte_ctl.html#wp1060987 But when I use 12.4(24)T in Cisco 1812 module, I didn't see any PIRO information can support OSPF when I type 'sh oer master prefix', like below... #sh oer master prefix 192.168.1.2/32 DEFAULT* 92 172.17.11.254 Tu11 U U U 0 0 0 0 N N N N 1 1 #sh ip route ospf O 192.168.1.0/24 [110/11] via 10.0.0.1, 02:46:06, Tunnel11 [110/11] via 10.1.1.1, 02:46:06, Tunnel12 Before 12.4(24)T, I use static route as parent route and it works well. But I really want to use OSPF as PfR parent route because static route would make route fail when gateway couldn't arrive. Anyone have idea about this ? Thanks and Regards, Pigsign From md at bts.sk Tue Apr 7 03:37:49 2009 From: md at bts.sk (=?UTF-8?Q?Marian_=C4=8Eurkovi=C4=8D?=) Date: Tue, 7 Apr 2009 09:37:49 +0200 Subject: [c-nsp] 10GE card for 7609 In-Reply-To: <20090406162400.GA16201@mx.ytti.net> References: <863386.41277.qm@web44809.mail.sp1.yahoo.com> <20090330151600.GA408@roxanne.org> <49D1BE37.8060402@skoal.name> <20090331074620.GV290@greenie.muc.de> <49D1CDD4.3080301@skoal.name> <20090331201210.GF51443@gerbil.cluepon.net> <20090406161117.GA56528@bts.sk> <20090406162400.GA16201@mx.ytti.net> Message-ID: <20090407070909.M61817@bts.sk> On Mon, 6 Apr 2009 19:24:00 +0300, Saku Ytti wrote > 3. Topologies used > c) anritsu --darkfibre-- ten7/1:7600:ten7/2 --darkfibre-- anritsu > > 4. Pure IP performance > 4.1 no features configured, plain IP routing > c) 64bytes does 87.5% of linerate, rate appraoches 100% as size grows, This is expected result - it's the 26 Mpps limit in Janus ASIC. > but is both bps and pps bound, so no configuration of packet size > and interval got 100%. That is strange. There is no bandwidth limitation between the ports and Janus, so it looks like something was broken in older IOS versions. M. From lists at memetic.org Tue Apr 7 05:25:26 2009 From: lists at memetic.org (Adam Armstrong) Date: Tue, 07 Apr 2009 10:25:26 +0100 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 In-Reply-To: References: Message-ID: <49DB1C06.60506@memetic.org> Lee wrote: > My experience has been that setting the speed and duplex on a catalyst > switch stops it from doing auto-negotiation. So with the switch ports > set to 100/full I'd expect the 7500 ports to come up as 100/half. But > we don't have any cat4006s at work.. I don't know if they do > auto-negotiation even if the port speed and duplex is configured, > Setting duplex disables autonegiotation (setting speed doesn't disable duplex negotiation). When you force duplex on a port, the port stops participating in the autonegitation and forces itself to the setting you give it. This causes the opposite port (if it's autonegotiating) to drop always to half duplex. As a general rule, you shouldn't force the duplex on a port unless the autonegotiation fails! (as it does on some quite old hardware) adam. From gert at greenie.muc.de Tue Apr 7 05:42:08 2009 From: gert at greenie.muc.de (Gert Doering) Date: Tue, 7 Apr 2009 11:42:08 +0200 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 In-Reply-To: <49DB1C06.60506@memetic.org> References: <49DB1C06.60506@memetic.org> Message-ID: <20090407094208.GZ290@greenie.muc.de> Hi, On Tue, Apr 07, 2009 at 10:25:26AM +0100, Adam Armstrong wrote: > As a general rule, you shouldn't force the duplex on a port unless the > autonegotiation fails! (as it does on some quite old hardware) ... and the context of *this* discussion is likely involving PA-FE-TX's, which are "quite old hardware", and cannot do any sort of autoneg. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From A.L.M.Buxey at lboro.ac.uk Tue Apr 7 05:52:59 2009 From: A.L.M.Buxey at lboro.ac.uk (A.L.M.Buxey at lboro.ac.uk) Date: Tue, 7 Apr 2009 10:52:59 +0100 Subject: [c-nsp] cisco IOS ip helper-address and MADCAP Message-ID: <20090407095259.GC25441@lboro.ac.uk> hi, just a quick question to peak some folks interest on a monday morning....and since I didnt get an answer from google et al. does anyone know if cisco 'ip helper-address' can deal with MADCAP (multicast address assignment via DHCP - also known in some circles as MDHCP)? I know there is very little server support for this - it seems, currently, that only microsoft DHCP server can deal with this type of request - I want to know that if such a server was deployed then would the requests from other VLANs reach it as they currently do with standard DHCP (we use ISC DHCPD) alan From lists at memetic.org Tue Apr 7 05:55:33 2009 From: lists at memetic.org (Adam Armstrong) Date: Tue, 07 Apr 2009 10:55:33 +0100 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 In-Reply-To: <20090407094208.GZ290@greenie.muc.de> References: <49DB1C06.60506@memetic.org> <20090407094208.GZ290@greenie.muc.de> Message-ID: <49DB2315.5010806@memetic.org> Gert Doering wrote: > Hi, > > On Tue, Apr 07, 2009 at 10:25:26AM +0100, Adam Armstrong wrote: > >> As a general rule, you shouldn't force the duplex on a port unless the >> autonegotiation fails! (as it does on some quite old hardware) >> > > ... and the context of *this* discussion is likely involving PA-FE-TX's, > which are "quite old hardware", and cannot do any sort of autoneg. > True, so the ports should probably be nailed to full at both sides. adam. From cklam at ias.edu Tue Apr 7 08:57:38 2009 From: cklam at ias.edu (Christina Klam) Date: Tue, 07 Apr 2009 08:57:38 -0400 Subject: [c-nsp] Squid cannot see wccp traffic through GRE Tunnel Message-ID: <49DB4DC2.4070509@ias.edu> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 All, We have been having some problems with wccpv2 working through a GRE tunnel between a 6504e (version s3223-ipservicesk9_wan-mz.122-33.SXI.bin) and a Squid server (RHEL5). The tunnel is up; and we an see GRE traffic on both sides. WCCP is up as well. But, when we try to redirect wccp traffic to the Squid server, the Squid server never receives it. We are not having this problem on a separate network where we are using wccp but not though a GRE tunnel. Any ideas? interface Tunnel2 description GRE_Squid ip address 172.16.X.Y 255.255.255.252 ip wccp web-cache redirect out tunnel source Loopback1 tunnel destination 172.16.C.C end interface Loopback1 ip address 172.16.X.A 255.255.255.255 ip wccp web-cache redirect out ip flow ingress Internet facing interface: interface Vlan3 description #Uplink_Packeteer_Nitroguard_FW# ip address 172.16.X.X 255.255.255.0 ip wccp web-cache redirect out ip wccp web-cache redirect in ip flow ingress gateway-resnet#sh ip wccp web-cache detail WCCP Client information: WCCP Client ID: 172.16.X.Z Protocol Version: 2.0 State: Usable Redirection: GRE Packet Return: GRE Assignment: HASH Initial Hash Info: 00000000000000000000000000000000 00000000000000000000000000000000 Assigned Hash Info: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF Hash Allotment: 256 (100.00%) Packets s/w Redirected: 0 Connect Time: 01:21:48 Bypassed Packets Process: 0 CEF: 0 Errors: 0 gateway-resnet#sh int tunn 2 Tunnel2 is up, line protocol is up Hardware is Tunnel Description: GRE_Squid Internet address is 172.16.X.Y/30 MTU 17868 bytes, BW 100 Kbit, DLY 50000 usec, reliability 255/255, txload 1/255, rxload 1/255 Encapsulation TUNNEL, loopback not set Keepalive not set Tunnel source 172.16.X.A (Loopback1), destination 172.16.C.C Tunnel protocol/transport GRE/IP Key disabled, sequencing disabled Checksumming of packets disabled Tunnel TTL 255, Fast tunneling enabled Tunnel transport MTU 1476 bytes Last input 00:00:00, output 00:00:00, output hang never Last clearing of "show interface" counters never Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/0 (size/max) 5 minute input rate 0 bits/sec, 0 packets/sec 5 minute output rate 0 bits/sec, 0 packets/sec L2 Switched: ucast: 0 pkt, 0 bytes - mcast: 0 pkt, 0 bytes L3 in Switched: ucast: 0 pkt, 0 bytes - mcast: 0 pkt, 0 bytes mcast L3 out Switched: ucast: 0 pkt, 0 bytes mcast: 0 pkt, 0 bytes 226578 packets input, 47805578 bytes, 0 no buffer Received 0 broadcasts (0 IP multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort 114505 packets output, 23682296 bytes, 0 underruns 0 output errors, 0 collisions, 0 interface resets 0 output buffer failures, 0 output buffers swapped out sh log: Mar 11 14:58:09 172.16.X.X 1654: Mar 11 14:58:08.985 EST: %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> 64.233.161.147(0), 3 packets Mar 11 14:58:09 172.16.X.X 1655: Mar 11 14:58:08.989 EST: %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> 209.85.133.101(0), 3 packets Mar 11 14:59:10 172.16.X.X 1658: Mar 11 14:59:09.013 EST: %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> 209.85.133.102(0), 2 packets Squid ACL: Extended IP access list SquidProxy 10 permit tcp host 172.16.A.A any log 20 permit tcp host 172.16.B.B any log (1220 matches) 30 deny ip any any (118 matches) Thank you, - -- Christina -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iQEVAwUBSdtNwt9pUgshfvqBAQKrnwgAh9TciUhv2kEdF8bgPJ/fzqU3gf33JD3F BLlHXCVOdWNz7TmcFqWc7+jkbEtkOJ89/MFH6pD7zwzwRUfauH2O66Fwg8eJVYgO qh4GTbwWwU0rFJ7IUhUQNDlN5Yw4zQtvMKaQmfOvNIGgp77eLj7E9PkPw0lBu7+E O6qt1HCjASPpUVlh6onH6sVz3gjxuhYshkN+O8qO+Bt6uSNUQKit5JqrZ4vZkVWw Syx/SN5DhwPpqQ5MSoyDLwvq41x8cfZ59C/+cnfNW9Sgv7XXMYJhnyO5mYBPhb8W y1zwNtzI19l/x9DNPQeXlvV24jACkx3YD3471CYsJL8X5smDdF28HQ== =XCEq -----END PGP SIGNATURE----- From adrian at creative.net.au Tue Apr 7 09:38:57 2009 From: adrian at creative.net.au (Adrian Chadd) Date: Tue, 7 Apr 2009 21:38:57 +0800 Subject: [c-nsp] Squid cannot see wccp traffic through GRE Tunnel In-Reply-To: <49DB4DC2.4070509@ias.edu> References: <49DB4DC2.4070509@ias.edu> Message-ID: <20090407133857.GE2446@skywalker.creative.net.au> On Tue, Apr 07, 2009, Christina Klam wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > All, > > We have been having some problems with wccpv2 working through a GRE > tunnel between a 6504e (version > s3223-ipservicesk9_wan-mz.122-33.SXI.bin) and a Squid server (RHEL5). > The tunnel is up; and we an see GRE traffic on both sides. WCCP is up Error - don't use a GRE tunnel with a 65xx series switch. > as well. But, when we try to redirect wccp traffic to the Squid > server, the Squid server never receives it. We are not having this > problem on a separate network where we are using wccp but not though a > GRE tunnel. Any ideas? Don't use GRE redirection/return. Use L2 redirection and return. Use mask assignment rather than hash assignment. The traffic will then stay 100% in the hardware path. Anyway, for GRE redirection, you don't configure up a tunnel on the Cisco router - the router just prepends the GRE packet header onto it. Adrian > > interface Tunnel2 > description GRE_Squid > ip address 172.16.X.Y 255.255.255.252 > ip wccp web-cache redirect out > tunnel source Loopback1 > tunnel destination 172.16.C.C > end > > interface Loopback1 > ip address 172.16.X.A 255.255.255.255 > ip wccp web-cache redirect out > ip flow ingress > > Internet facing interface: > interface Vlan3 > description #Uplink_Packeteer_Nitroguard_FW# > ip address 172.16.X.X 255.255.255.0 > ip wccp web-cache redirect out > ip wccp web-cache redirect in > ip flow ingress > > gateway-resnet#sh ip wccp web-cache detail > WCCP Client information: > WCCP Client ID: 172.16.X.Z > Protocol Version: 2.0 > State: Usable > Redirection: GRE > Packet Return: GRE > Assignment: HASH > Initial Hash Info: 00000000000000000000000000000000 > 00000000000000000000000000000000 > Assigned Hash Info: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF > FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF > Hash Allotment: 256 (100.00%) > Packets s/w Redirected: 0 > Connect Time: 01:21:48 > Bypassed Packets > Process: 0 > CEF: 0 > Errors: 0 > > gateway-resnet#sh int tunn 2 > Tunnel2 is up, line protocol is up > Hardware is Tunnel > Description: GRE_Squid > Internet address is 172.16.X.Y/30 > MTU 17868 bytes, BW 100 Kbit, DLY 50000 usec, > reliability 255/255, txload 1/255, rxload 1/255 > Encapsulation TUNNEL, loopback not set > Keepalive not set > Tunnel source 172.16.X.A (Loopback1), destination 172.16.C.C > Tunnel protocol/transport GRE/IP > Key disabled, sequencing disabled > Checksumming of packets disabled > Tunnel TTL 255, Fast tunneling enabled > Tunnel transport MTU 1476 bytes > Last input 00:00:00, output 00:00:00, output hang never > Last clearing of "show interface" counters never > Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0 > Queueing strategy: fifo > Output queue: 0/0 (size/max) > 5 minute input rate 0 bits/sec, 0 packets/sec > 5 minute output rate 0 bits/sec, 0 packets/sec > L2 Switched: ucast: 0 pkt, 0 bytes - mcast: 0 pkt, 0 bytes > L3 in Switched: ucast: 0 pkt, 0 bytes - mcast: 0 pkt, 0 bytes mcast > L3 out Switched: ucast: 0 pkt, 0 bytes mcast: 0 pkt, 0 bytes > 226578 packets input, 47805578 bytes, 0 no buffer > Received 0 broadcasts (0 IP multicasts) > 0 runts, 0 giants, 0 throttles > 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort > 114505 packets output, 23682296 bytes, 0 underruns > 0 output errors, 0 collisions, 0 interface resets > 0 output buffer failures, 0 output buffers swapped out > > sh log: > Mar 11 14:58:09 172.16.X.X 1654: Mar 11 14:58:08.985 EST: > %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> > 64.233.161.147(0), 3 packets > Mar 11 14:58:09 172.16.X.X 1655: Mar 11 14:58:08.989 EST: > %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> > 209.85.133.101(0), 3 packets > Mar 11 14:59:10 172.16.X.X 1658: Mar 11 14:59:09.013 EST: > %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> > 209.85.133.102(0), 2 packets > > Squid ACL: > Extended IP access list SquidProxy > 10 permit tcp host 172.16.A.A any log > 20 permit tcp host 172.16.B.B any log (1220 matches) > 30 deny ip any any (118 matches) > > > Thank you, > > - -- Christina > > > > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.5 (MingW32) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iQEVAwUBSdtNwt9pUgshfvqBAQKrnwgAh9TciUhv2kEdF8bgPJ/fzqU3gf33JD3F > BLlHXCVOdWNz7TmcFqWc7+jkbEtkOJ89/MFH6pD7zwzwRUfauH2O66Fwg8eJVYgO > qh4GTbwWwU0rFJ7IUhUQNDlN5Yw4zQtvMKaQmfOvNIGgp77eLj7E9PkPw0lBu7+E > O6qt1HCjASPpUVlh6onH6sVz3gjxuhYshkN+O8qO+Bt6uSNUQKit5JqrZ4vZkVWw > Syx/SN5DhwPpqQ5MSoyDLwvq41x8cfZ59C/+cnfNW9Sgv7XXMYJhnyO5mYBPhb8W > y1zwNtzI19l/x9DNPQeXlvV24jACkx3YD3471CYsJL8X5smDdF28HQ== > =XCEq > -----END PGP SIGNATURE----- > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ -- - Xenion - http://www.xenion.com.au/ - VPS Hosting - Commercial Squid Support - - $25/pm entry-level VPSes w/ capped bandwidth charges available in WA - From juliano_luz at sicredi.com.br Tue Apr 7 09:55:01 2009 From: juliano_luz at sicredi.com.br (Juliano Luz - Sicredi) Date: Tue, 7 Apr 2009 10:55:01 -0300 Subject: [c-nsp] RES: Squid cannot see wccp traffic through GRE Tunnel In-Reply-To: <49DB4DC2.4070509@ias.edu> References: <49DB4DC2.4070509@ias.edu> Message-ID: <004c01c9b788$727deba0$5779c2e0$@com.br> Maybe a problem related to MTU size? Check http://www.cisco.com/en/US/tech/tk827/tk369/technologies_tech_note09186a0080 093f1f.shtml -----Mensagem original----- De: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] Em nome de Christina Klam Enviada em: ter?a-feira, 7 de abril de 2009 09:58 Para: cisco-nsp at puck.nether.net Assunto: [c-nsp] Squid cannot see wccp traffic through GRE Tunnel -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 All, We have been having some problems with wccpv2 working through a GRE tunnel between a 6504e (version s3223-ipservicesk9_wan-mz.122-33.SXI.bin) and a Squid server (RHEL5). The tunnel is up; and we an see GRE traffic on both sides. WCCP is up as well. But, when we try to redirect wccp traffic to the Squid server, the Squid server never receives it. We are not having this problem on a separate network where we are using wccp but not though a GRE tunnel. Any ideas? interface Tunnel2 description GRE_Squid ip address 172.16.X.Y 255.255.255.252 ip wccp web-cache redirect out tunnel source Loopback1 tunnel destination 172.16.C.C end interface Loopback1 ip address 172.16.X.A 255.255.255.255 ip wccp web-cache redirect out ip flow ingress Internet facing interface: interface Vlan3 description #Uplink_Packeteer_Nitroguard_FW# ip address 172.16.X.X 255.255.255.0 ip wccp web-cache redirect out ip wccp web-cache redirect in ip flow ingress gateway-resnet#sh ip wccp web-cache detail WCCP Client information: WCCP Client ID: 172.16.X.Z Protocol Version: 2.0 State: Usable Redirection: GRE Packet Return: GRE Assignment: HASH Initial Hash Info: 00000000000000000000000000000000 00000000000000000000000000000000 Assigned Hash Info: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF Hash Allotment: 256 (100.00%) Packets s/w Redirected: 0 Connect Time: 01:21:48 Bypassed Packets Process: 0 CEF: 0 Errors: 0 gateway-resnet#sh int tunn 2 Tunnel2 is up, line protocol is up Hardware is Tunnel Description: GRE_Squid Internet address is 172.16.X.Y/30 MTU 17868 bytes, BW 100 Kbit, DLY 50000 usec, reliability 255/255, txload 1/255, rxload 1/255 Encapsulation TUNNEL, loopback not set Keepalive not set Tunnel source 172.16.X.A (Loopback1), destination 172.16.C.C Tunnel protocol/transport GRE/IP Key disabled, sequencing disabled Checksumming of packets disabled Tunnel TTL 255, Fast tunneling enabled Tunnel transport MTU 1476 bytes Last input 00:00:00, output 00:00:00, output hang never Last clearing of "show interface" counters never Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/0 (size/max) 5 minute input rate 0 bits/sec, 0 packets/sec 5 minute output rate 0 bits/sec, 0 packets/sec L2 Switched: ucast: 0 pkt, 0 bytes - mcast: 0 pkt, 0 bytes L3 in Switched: ucast: 0 pkt, 0 bytes - mcast: 0 pkt, 0 bytes mcast L3 out Switched: ucast: 0 pkt, 0 bytes mcast: 0 pkt, 0 bytes 226578 packets input, 47805578 bytes, 0 no buffer Received 0 broadcasts (0 IP multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort 114505 packets output, 23682296 bytes, 0 underruns 0 output errors, 0 collisions, 0 interface resets 0 output buffer failures, 0 output buffers swapped out sh log: Mar 11 14:58:09 172.16.X.X 1654: Mar 11 14:58:08.985 EST: %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> 64.233.161.147(0), 3 packets Mar 11 14:58:09 172.16.X.X 1655: Mar 11 14:58:08.989 EST: %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> 209.85.133.101(0), 3 packets Mar 11 14:59:10 172.16.X.X 1658: Mar 11 14:59:09.013 EST: %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> 209.85.133.102(0), 2 packets Squid ACL: Extended IP access list SquidProxy 10 permit tcp host 172.16.A.A any log 20 permit tcp host 172.16.B.B any log (1220 matches) 30 deny ip any any (118 matches) Thank you, - -- Christina -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iQEVAwUBSdtNwt9pUgshfvqBAQKrnwgAh9TciUhv2kEdF8bgPJ/fzqU3gf33JD3F BLlHXCVOdWNz7TmcFqWc7+jkbEtkOJ89/MFH6pD7zwzwRUfauH2O66Fwg8eJVYgO qh4GTbwWwU0rFJ7IUhUQNDlN5Yw4zQtvMKaQmfOvNIGgp77eLj7E9PkPw0lBu7+E O6qt1HCjASPpUVlh6onH6sVz3gjxuhYshkN+O8qO+Bt6uSNUQKit5JqrZ4vZkVWw Syx/SN5DhwPpqQ5MSoyDLwvq41x8cfZ59C/+cnfNW9Sgv7XXMYJhnyO5mYBPhb8W y1zwNtzI19l/x9DNPQeXlvV24jACkx3YD3471CYsJL8X5smDdF28HQ== =XCEq -----END PGP SIGNATURE----- As informacoes contidas neste e-mail e anexos podem ser confidenciais e privilegiadas, protegidas por sigilo legal. Qualquer forma de utilizacao deste documento depende de autorizacao do emissor, sujeito as penalidades cabiveis. O emissor utiliza o recurso somente para fins profissionais, eximindo o empregador de responsabilidades por uso pessoal ou improprio. Se esta mensagem foi recebida por engano, o conteudo deve ser apagado e o remetente avisado imediatamente, atraves de resposta a este e-mail. From alasdairm at gmail.com Tue Apr 7 10:22:04 2009 From: alasdairm at gmail.com (Alasdair McWilliam) Date: Tue, 7 Apr 2009 15:22:04 +0100 Subject: [c-nsp] BGP across continents Message-ID: Hi, I am setting up a multihomed hosting centre in Europe. As part of the service offered we will be providing Disaster Recovery services, using our ability to re-route customer IP prefixes, through to another hosting centre in Canada. We have a requirement for some prefixes within our net block to always be available in Canada, and some to always be available in Europe. So, I am wondering if someone can clarify my thoughts re. the AS numbers required for this: can I use the same ASN at both locations (both of which will have different upstreams) or will they reject prefixes from one another? For example, Canada will see a prefix from Europe with the same ASN in the AS-Path and drop it. Likewise Europe will drop Canada prefixes because it can see the same AS in the AS-Path. Is there any way around this or is the only option to request a second ASN? Cheers Alasdair From jjsurlenet at hotmail.fr Tue Apr 7 10:23:54 2009 From: jjsurlenet at hotmail.fr (JJ JJ) Date: Tue, 7 Apr 2009 16:23:54 +0200 Subject: [c-nsp] remove In-Reply-To: <20090407133857.GE2446@skywalker.creative.net.au> References: <49DB4DC2.4070509@ias.edu> <20090407133857.GE2446@skywalker.creative.net.au> Message-ID: remove > Date: Tue, 7 Apr 2009 21:38:57 +0800 > From: adrian at creative.net.au > To: cklam at ias.edu > CC: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] Squid cannot see wccp traffic through GRE Tunnel > > On Tue, Apr 07, 2009, Christina Klam wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > All, > > > > We have been having some problems with wccpv2 working through a GRE > > tunnel between a 6504e (version > > s3223-ipservicesk9_wan-mz.122-33.SXI.bin) and a Squid server (RHEL5). > > The tunnel is up; and we an see GRE traffic on both sides. WCCP is up > > Error - don't use a GRE tunnel with a 65xx series switch. > > > as well. But, when we try to redirect wccp traffic to the Squid > > server, the Squid server never receives it. We are not having this > > problem on a separate network where we are using wccp but not though a > > GRE tunnel. Any ideas? > > Don't use GRE redirection/return. Use L2 redirection and return. > Use mask assignment rather than hash assignment. The traffic will > then stay 100% in the hardware path. > > Anyway, for GRE redirection, you don't configure up a tunnel on the Cisco > router - the router just prepends the GRE packet header onto it. > > > > > Adrian > > > > > interface Tunnel2 > > description GRE_Squid > > ip address 172.16.X.Y 255.255.255.252 > > ip wccp web-cache redirect out > > tunnel source Loopback1 > > tunnel destination 172.16.C.C > > end > > > > interface Loopback1 > > ip address 172.16.X.A 255.255.255.255 > > ip wccp web-cache redirect out > > ip flow ingress > > > > Internet facing interface: > > interface Vlan3 > > description #Uplink_Packeteer_Nitroguard_FW# > > ip address 172.16.X.X 255.255.255.0 > > ip wccp web-cache redirect out > > ip wccp web-cache redirect in > > ip flow ingress > > > > gateway-resnet#sh ip wccp web-cache detail > > WCCP Client information: > > WCCP Client ID: 172.16.X.Z > > Protocol Version: 2.0 > > State: Usable > > Redirection: GRE > > Packet Return: GRE > > Assignment: HASH > > Initial Hash Info: 00000000000000000000000000000000 > > 00000000000000000000000000000000 > > Assigned Hash Info: FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF > > FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF > > Hash Allotment: 256 (100.00%) > > Packets s/w Redirected: 0 > > Connect Time: 01:21:48 > > Bypassed Packets > > Process: 0 > > CEF: 0 > > Errors: 0 > > > > gateway-resnet#sh int tunn 2 > > Tunnel2 is up, line protocol is up > > Hardware is Tunnel > > Description: GRE_Squid > > Internet address is 172.16.X.Y/30 > > MTU 17868 bytes, BW 100 Kbit, DLY 50000 usec, > > reliability 255/255, txload 1/255, rxload 1/255 > > Encapsulation TUNNEL, loopback not set > > Keepalive not set > > Tunnel source 172.16.X.A (Loopback1), destination 172.16.C.C > > Tunnel protocol/transport GRE/IP > > Key disabled, sequencing disabled > > Checksumming of packets disabled > > Tunnel TTL 255, Fast tunneling enabled > > Tunnel transport MTU 1476 bytes > > Last input 00:00:00, output 00:00:00, output hang never > > Last clearing of "show interface" counters never > > Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0 > > Queueing strategy: fifo > > Output queue: 0/0 (size/max) > > 5 minute input rate 0 bits/sec, 0 packets/sec > > 5 minute output rate 0 bits/sec, 0 packets/sec > > L2 Switched: ucast: 0 pkt, 0 bytes - mcast: 0 pkt, 0 bytes > > L3 in Switched: ucast: 0 pkt, 0 bytes - mcast: 0 pkt, 0 bytes mcast > > L3 out Switched: ucast: 0 pkt, 0 bytes mcast: 0 pkt, 0 bytes > > 226578 packets input, 47805578 bytes, 0 no buffer > > Received 0 broadcasts (0 IP multicasts) > > 0 runts, 0 giants, 0 throttles > > 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort > > 114505 packets output, 23682296 bytes, 0 underruns > > 0 output errors, 0 collisions, 0 interface resets > > 0 output buffer failures, 0 output buffers swapped out > > > > sh log: > > Mar 11 14:58:09 172.16.X.X 1654: Mar 11 14:58:08.985 EST: > > %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> > > 64.233.161.147(0), 3 packets > > Mar 11 14:58:09 172.16.X.X 1655: Mar 11 14:58:08.989 EST: > > %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> > > 209.85.133.101(0), 3 packets > > Mar 11 14:59:10 172.16.X.X 1658: Mar 11 14:59:09.013 EST: > > %SEC-6-IPACCESSLOGP: list Squid permitted tcp 172.16.B.B(0) -> > > 209.85.133.102(0), 2 packets > > > > Squid ACL: > > Extended IP access list SquidProxy > > 10 permit tcp host 172.16.A.A any log > > 20 permit tcp host 172.16.B.B any log (1220 matches) > > 30 deny ip any any (118 matches) > > > > > > Thank you, > > > > - -- Christina > > > > > > > > > > -----BEGIN PGP SIGNATURE----- > > Version: GnuPG v1.4.5 (MingW32) > > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > > > iQEVAwUBSdtNwt9pUgshfvqBAQKrnwgAh9TciUhv2kEdF8bgPJ/fzqU3gf33JD3F > > BLlHXCVOdWNz7TmcFqWc7+jkbEtkOJ89/MFH6pD7zwzwRUfauH2O66Fwg8eJVYgO > > qh4GTbwWwU0rFJ7IUhUQNDlN5Yw4zQtvMKaQmfOvNIGgp77eLj7E9PkPw0lBu7+E > > O6qt1HCjASPpUVlh6onH6sVz3gjxuhYshkN+O8qO+Bt6uSNUQKit5JqrZ4vZkVWw > > Syx/SN5DhwPpqQ5MSoyDLwvq41x8cfZ59C/+cnfNW9Sgv7XXMYJhnyO5mYBPhb8W > > y1zwNtzI19l/x9DNPQeXlvV24jACkx3YD3471CYsJL8X5smDdF28HQ== > > =XCEq > > -----END PGP SIGNATURE----- > > > > > _______________________________________________ > > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > -- > - Xenion - http://www.xenion.com.au/ - VPS Hosting - Commercial Squid Support - > - $25/pm entry-level VPSes w/ capped bandwidth charges available in WA - > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ _________________________________________________________________ In?dit ! Des Emotic?nes D?jant?es! Installez les dans votre Messenger ! http://www.ilovemessenger.fr/Emoticones/EmoticonesDejantees.aspx From jzp-cnsp at rsuc.gweep.net Tue Apr 7 10:30:41 2009 From: jzp-cnsp at rsuc.gweep.net (Joe Provo) Date: Tue, 7 Apr 2009 10:30:41 -0400 Subject: [c-nsp] BGP across continents In-Reply-To: References: Message-ID: <20090407143039.GA47565@gweep.net> On Tue, Apr 07, 2009 at 03:22:04PM +0100, Alasdair McWilliam wrote: [snip] > Is there any way around this or is the only option to request a second ASN? Among the "give you enough rope" options, "neighbor allowas-in"; use with caution. There are many other options, including to build tunnels between the sites and treat them as a logical single entity. -- RSUC / GweepNet / Spunk / FnB / Usenix / SAGE From rodunn at cisco.com Tue Apr 7 11:46:47 2009 From: rodunn at cisco.com (Rodney Dunn) Date: Tue, 7 Apr 2009 11:46:47 -0400 Subject: [c-nsp] NAT on ASR1000 Message-ID: <20090407154647.GQ20028@rtp-cse-489.cisco.com> Few bugs still being worked through but the 72xx and 76xx croaked under the load: ASR1002ESP10#sh proc cpu sort | excl 0.00 CPU utilization for five seconds: 0%/0%; one minute: 0%; five minutes: 0% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process ASR1002ESP10#sh ip nat stat Total active translations: 92367 (80 static, 92287 dynamic; 92287 extended) Outside interfaces: GigabitEthernet0/0/0, Tunnel1 Inside interfaces: GigabitEthernet0/0/1, GigabitEthernet0/0/2 Hits: 0 Misses: 0 CEF Translated packets: 0, CEF Punted packets: 0 Expired translations: 87400847 that's on 12.2(33)XNC and I just filed one bug. CSCsy93931 ASRNAT does not do FIN/RST/SYN timeout when no-payload keyword used My first work on the box with NAT but this thing seems pretty impressive. Anyone else using it for high scale nat yet? Rodney From emanuel.popa at gmail.com Tue Apr 7 11:51:44 2009 From: emanuel.popa at gmail.com (Emanuel Popa) Date: Tue, 7 Apr 2009 18:51:44 +0300 Subject: [c-nsp] carrier router models comparison Message-ID: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> hi there, due to the increase in traffic volume in the last couple of years we need to really think about the future of the network. we have deployed and we are managing a 50GE multi-ring topology network with Cisco 7600 routers. i don't want to get into more details about ring topology restrictions, platform limitations regarding wire speed, huge problems with ether-channels or unpredictable load balancing behaviour. we've been using these chassis since 2004 starting with STM-16 lines and the PQ ratio looks pretty good so far. coming back to nowadays, 40GE or 100GE is not available yet, and even if it was, the price would be probably unaffordable. and now the question pops: what is the next step? the best answer is of course a mix of multiple 10GE lines with traffic engineering and partial mesh topology and 100GE ready chassis. first thing that comes to mind is the CRS-1 platform, but it is really expensive: from under 15K per 10GE port with the Cisco 7600 you have to pay more than 75K per 10GE port with the CRS-1. so we have to take into consideration what are the alternatives. i will try a short comparison: - Cisco CRS-1 16 Slot --- max 64 x 10GE --- max 32 links in a bundle --- 40Gbps per slot --- 100GE ready --- multi-chassis ready --- 10.920W max power --- 723kg max weight --- full rack space --- $5.115.000,00/chassis --- $79.921,88/10GE - Juniper T1600 --- max 64 x 10GE --- max 16 links in a bundle --- 100Gbps per slot --- 100GE ready --- multi-chassis ready --- 8.352W max power --- 274,88kg max weight --- 1/2 rack space --- $6.547.000,00/chassis --- $102.296,88/10GE - Brocade/ Foundry NetIron XMR 16000 --- max 64 x 10GE --- max 32 links in a bundle --- 50Gbps per slot --- 100GE ready (* only full slots) --- single-chassis --- 5.572W max power --- 107,00kg max weight --- 1/3 rack space --- $567.515,00/chassis --- $8.867,42/10GE I've also been looking at Huawei, Alcatel and HP gear but haven't been able to find a device to support more than 24 x 10GE ports in a single chassis. Here's what I'm trying to figure out: 1. are there any other devices on the market with same hardware capabilities? 2. why the huge difference between foundry and cisco/juniper? 3. if foundry is so cheap why hasn't it gathered more market share? instead it was bought by brocade a while ago... 4. is the netiron really a carrier router more than a carrier switch? anybody experienced it? 5. how does the software perform when comparing with IOS XR and JunOS? Please, any comments are welcomed. Best regards, Manu From elmi at 4ever.de Tue Apr 7 12:01:15 2009 From: elmi at 4ever.de (Elmar K. Bins) Date: Tue, 7 Apr 2009 18:01:15 +0200 Subject: [c-nsp] Too dumb for SLB on ASR1Ks? In-Reply-To: <20090403153128.GA12333@ronin.4ever.de> References: <20090403153128.GA12333@ronin.4ever.de> Message-ID: <20090407160115.GX29526@ronin.4ever.de> So far, I have gotten only the one response to my question. What would be the suggestion? "Ask Cisco for configuration help?" "Create a bug id?" Any ideas/guidance? I'm under the impression my basic config should be working but it doesn't... You know, any input etc... Elmar. From achatz at forthnet.gr Tue Apr 7 12:02:52 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Tue, 07 Apr 2009 19:02:52 +0300 Subject: [c-nsp] NAT on ASR1000 In-Reply-To: <20090407154647.GQ20028@rtp-cse-489.cisco.com> References: <20090407154647.GQ20028@rtp-cse-489.cisco.com> Message-ID: <49DB792C.6080507@forthnet.gr> Rodney, can you do a "sh plat soft stat contr br"? -- Tassos Rodney Dunn wrote on 07/04/2009 18:46: > Few bugs still being worked through but the 72xx and 76xx croaked > under the load: > > ASR1002ESP10#sh proc cpu sort | excl 0.00 > CPU utilization for five seconds: 0%/0%; one minute: 0%; five minutes: 0% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > ASR1002ESP10#sh ip nat stat > Total active translations: 92367 (80 static, 92287 dynamic; 92287 extended) > Outside interfaces: > GigabitEthernet0/0/0, Tunnel1 > Inside interfaces: > GigabitEthernet0/0/1, GigabitEthernet0/0/2 > Hits: 0 Misses: 0 > CEF Translated packets: 0, CEF Punted packets: 0 > Expired translations: 87400847 > > > that's on 12.2(33)XNC and I just filed one bug. > > CSCsy93931 ASRNAT does not do FIN/RST/SYN timeout when no-payload keyword used > > > My first work on the box with NAT but this thing seems pretty impressive. > > Anyone else using it for high scale nat yet? > > Rodney > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From achatz at forthnet.gr Tue Apr 7 12:20:41 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Tue, 07 Apr 2009 19:20:41 +0300 Subject: [c-nsp] carrier router models comparison In-Reply-To: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> References: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> Message-ID: <49DB7D59.1030006@forthnet.gr> Besides your choices, ASR 9000 should be out soon (its IOS XR Software is already available). -- Tassos Emanuel Popa wrote on 07/04/2009 18:51: > hi there, > > due to the increase in traffic volume in the last couple of years we > need to really think about the future of the network. we have deployed > and we are managing a 50GE multi-ring topology network with Cisco 7600 > routers. i don't want to get into more details about ring topology > restrictions, platform limitations regarding wire speed, huge problems > with ether-channels or unpredictable load balancing behaviour. we've > been using these chassis since 2004 starting with STM-16 lines and the > PQ ratio looks pretty good so far. > > coming back to nowadays, 40GE or 100GE is not available yet, and even > if it was, the price would be probably unaffordable. and now the > question pops: what is the next step? the best answer is of course a > mix of multiple 10GE lines with traffic engineering and partial mesh > topology and 100GE ready chassis. first thing that comes to mind is > the CRS-1 platform, but it is really expensive: from under 15K per > 10GE port with the Cisco 7600 you have to pay more than 75K per 10GE > port with the CRS-1. so we have to take into consideration what are > the alternatives. i will try a short comparison: > > - Cisco CRS-1 16 Slot > --- max 64 x 10GE > --- max 32 links in a bundle > --- 40Gbps per slot > --- 100GE ready > --- multi-chassis ready > --- 10.920W max power > --- 723kg max weight > --- full rack space > --- $5.115.000,00/chassis > --- $79.921,88/10GE > > - Juniper T1600 > --- max 64 x 10GE > --- max 16 links in a bundle > --- 100Gbps per slot > --- 100GE ready > --- multi-chassis ready > --- 8.352W max power > --- 274,88kg max weight > --- 1/2 rack space > --- $6.547.000,00/chassis > --- $102.296,88/10GE > > - Brocade/ Foundry NetIron XMR 16000 > --- max 64 x 10GE > --- max 32 links in a bundle > --- 50Gbps per slot > --- 100GE ready (* only full slots) > --- single-chassis > --- 5.572W max power > --- 107,00kg max weight > --- 1/3 rack space > --- $567.515,00/chassis > --- $8.867,42/10GE > > I've also been looking at Huawei, Alcatel and HP gear but haven't been > able to find a device to support more than 24 x 10GE ports in a single > chassis. > > Here's what I'm trying to figure out: > > 1. are there any other devices on the market with same hardware capabilities? > > 2. why the huge difference between foundry and cisco/juniper? > > 3. if foundry is so cheap why hasn't it gathered more market share? > instead it was bought by brocade a while ago... > > 4. is the netiron really a carrier router more than a carrier switch? > anybody experienced it? > > 5. how does the software perform when comparing with IOS XR and JunOS? > > Please, any comments are welcomed. > > Best regards, > Manu > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From r.tahina at moov.mg Tue Apr 7 11:36:23 2009 From: r.tahina at moov.mg (RAZAFINDRATSIFA Rivo Tahina) Date: Tue, 07 Apr 2009 18:36:23 +0300 Subject: [c-nsp] upload to 2 upstreams Message-ID: <7.0.1.0.2.20090407183213.04f15628@moov.mg> Hi all, We have two upstreams and our upload traffic is load balanced between them, when one of them is down, how can I do to send all output to the one which is still up? Regards. From SMESIATO at petro-canada.ca Tue Apr 7 11:53:16 2009 From: SMESIATO at petro-canada.ca (Mesiatowsky, Shawn) Date: Tue, 7 Apr 2009 11:53:16 -0400 Subject: [c-nsp] Packet Loss on 6513 Message-ID: <259E69AA141E7640822757CAB3EBC70F18B1D0DBE8@MSG-M1P1.pcacorp.net> We currently have 2 6513's in our core, and we have seen packet loss on our network. I was trying to locate the source of the packet loss. We did see some input queue drops on the SVI's and physical interfaces. I had increased our queue size on the vlan interfaces to 500, and our packet drops on the svi's decreased signifigantly. Now I am trying to figure out why there is packet loss on the physical interfaces. We have a sup 720, and our line cards are WS-X6724-SFP and WS-X6748-SFP. Here is a sample of an interface with high drops GigabitEthernet2/23 is up, line protocol is up (connected) Hardware is C6k 1000Mb 802.3, address is 001a.2f68.7bc2 (bia 001a.2f68.7bc2) MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 38/255, rxload 32/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex, 1000Mb/s, media type is SX input flow-control is off, output flow-control is off Clock mode is auto ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:31, output hang never Last clearing of "show interface" counters 1d00h Input queue: 0/2000/91560/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 5 minute input rate 126671000 bits/sec, 28888 packets/sec 5 minute output rate 151605000 bits/sec, 26499 packets/sec 942611654 packets input, 633784740348 bytes, 0 no buffer Received 7319979 broadcasts (6903850 multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 91560 overrun, 0 ignored 0 watchdog, 0 multicast, 0 pause input 0 input packets with dribble condition detected 891230426 packets output, 579042873963 bytes, 0 underruns 0 output errors, 0 collisions, 0 interface resets 0 babbles, 0 late collision, 0 deferred 0 lost carrier, 0 no carrier, 0 PAUSE output 0 output buffer failures, 0 output buffers swapped out I also looked at the utilization of this interface with our snmp tool, and utilixzation of this interface never went over %40 I also noticed the following, and was not sure if this was completely accurate: show platform hardware capacity interface Interface Resources Interface drops: Module Total drops: Tx Rx Highest drop port: Tx Rx 1 0 466 0 1 2 0 154228 0 23 3 0 123 0 1 4 0 190102 0 21 5 0 446318 0 21 7 3940684041 0 1 0 9 0 34280 0 7 10 0 5 0 42 11 0 433 0 46 12 0 1686 0 44 13 66042 119859 1 1 Interface buffer sizes: Module Bytes: Tx buffer Rx buffer 1 1221120 152000 2 1221120 152000 3 1221120 152000 4 1221120 152000 5 1221120 152000 6 1221120 152000 9 1221120 152000 10 1221120 152000 11 1221120 152000 12 1221120 152000 13 1221120 152000 Does this mean that 3940684041 packets were dropped on the egress queue on the sup? Does this seem extremly high, and shat can cause this? Thanks for your help ________________________________ This email communication is intended as a private communication for the sole use of the primary addressee and those individuals listed for copies in the original message. The information contained in this email is private and confidential and If you are not an intended recipient you are hereby notified that copying, forwarding or other dissemination or distribution of this communication by any means is prohibited. If you are not specifically authorized to receive this email and if you believe that you received it in error please notify the original sender immediately. We honour similar requests relating to the privacy of email communications. Cette communication par courrier ?lectronique est une communication priv?e ? l'usage exclusif du destinataire principal ainsi que des personnes dont les noms figurent en copie. Les renseignements contenus dans ce courriel sont confidentiels et si vous n'?tes pas le destinataire pr?vu, vous ?tes avis?, par les pr?sentes que toute reproduction, transfert ou autre forme de diffusion de cette communication par quelque moyen que ce soit est interdite. Si vous n'?tes pas sp?cifiquement autoris? ? recevoir ce courriel ou si vous croyez l'avoir re?u par erreur, veuillez en aviser l'exp?diteur original imm?diatement. Nous respectons les demandes similaires qui touchent la confidentialit? des communications par courrier ?lectronique. From sethm at rollernet.us Tue Apr 7 12:51:59 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Tue, 07 Apr 2009 09:51:59 -0700 Subject: [c-nsp] Too dumb for SLB on ASR1Ks? In-Reply-To: <20090407160115.GX29526@ronin.4ever.de> References: <20090403153128.GA12333@ronin.4ever.de> <20090407160115.GX29526@ronin.4ever.de> Message-ID: <49DB84AF.1040602@rollernet.us> Elmar K. Bins wrote: > So far, I have gotten only the one response to my question. > > What would be the suggestion? "Ask Cisco for configuration > help?" "Create a bug id?" Any ideas/guidance? I'm under the > impression my basic config should be working but it doesn't... > > You know, any input etc... > Open a TAC case. If it's not supported someone should know. (Although it could take weeks like the time I threw an IPv6 question at TAC.) If it is supported and it's broken, they should be able to open a bug. I'd help more since I use IOS SLB a lot, but I just don't have an ASR1000 as much as I wish I did. ;) ~Seth From sethm at rollernet.us Tue Apr 7 12:55:19 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Tue, 07 Apr 2009 09:55:19 -0700 Subject: [c-nsp] Packet Loss on 6513 In-Reply-To: <259E69AA141E7640822757CAB3EBC70F18B1D0DBE8@MSG-M1P1.pcacorp.net> References: <259E69AA141E7640822757CAB3EBC70F18B1D0DBE8@MSG-M1P1.pcacorp.net> Message-ID: <49DB8577.2060805@rollernet.us> Mesiatowsky, Shawn wrote: > We currently have 2 6513's in our core, and we have seen packet loss on our network. I was trying to locate the source of the packet loss. We did see some input queue drops on the SVI's and physical interfaces. I had increased our queue size on the vlan interfaces to 500, and our packet drops on the svi's decreased signifigantly. Now I am trying to figure out why there is packet loss on the physical interfaces. We have a sup 720, and our line cards are WS-X6724-SFP and WS-X6748-SFP. > Check your TCAM utilization. ~Seth From rodunn at cisco.com Tue Apr 7 12:56:47 2009 From: rodunn at cisco.com (Rodney Dunn) Date: Tue, 7 Apr 2009 12:56:47 -0400 Subject: [c-nsp] NAT on ASR1000 In-Reply-To: <49DB792C.6080507@forthnet.gr> References: <20090407154647.GQ20028@rtp-cse-489.cisco.com> <49DB792C.6080507@forthnet.gr> Message-ID: <20090407165647.GA22725@rtp-cse-489.cisco.com> sh plat software status control-processor brief Load Average Slot Status 1-Min 5-Min 15-Min RP0 Healthy 0.00 0.04 0.01 ESP0 Healthy 0.00 0.00 0.00 SIP0 Healthy 0.02 0.02 0.00 Memory (kB) Slot Status Total Used (Pct) Free (Pct) Committed (Pct) RP0 Healthy 3711920 1525468 (36%) 2186452 (52%) 2438180 (59%) ESP0 Healthy 2024492 527680 (25%) 1496812 (71%) 2807552 (133%) SIP0 Healthy 480084 287860 (54%) 192224 (36%) 199468 (38%) CPU Utilization Slot CPU User System Nice Idle IRQ SIRQ IOwait RP0 0 2.15 1.54 0.00 96.25 0.01 0.03 0.00 ESP0 0 0.57 0.60 0.00 98.80 0.00 0.01 0.00 SIP0 0 0.30 0.41 0.00 99.25 0.00 0.01 0.00 It's a live network I worked on over the weekend. It's a pretty high rate short lived session network. We set the timeouts down: ip nat translation timeout 1800 ip nat translation tcp-timeout 900 ip nat translation udp-timeout 150 ip nat translation dns-timeout 30 show platform hardware cpp active infrastructure exmem statistics and there is a lot of QFP memory left: Type: Name: IRAM, CPP: 0 Total: 134217728 InUse: 4779008 Free: 128974848 Free protected: 463872 Free unprotected: 0 Lowest free water mark: 129438720 Largest free block: 99537920 Type: Name: DRAM, CPP: 0 Total: 402653184 InUse: 190609408 Free: 209715200 Free protected: 598016 Free unprotected: 1730560 Lowest free water mark: 212043776 Largest free block: 210233344 On Tue, Apr 07, 2009 at 07:02:52PM +0300, Tassos Chatzithomaoglou wrote: > Rodney, can you do a "sh plat soft stat contr br"? > > -- > Tassos > > Rodney Dunn wrote on 07/04/2009 18:46: > >Few bugs still being worked through but the 72xx and 76xx croaked > >under the load: > > > >ASR1002ESP10#sh proc cpu sort | excl 0.00 > >CPU utilization for five seconds: 0%/0%; one minute: 0%; five minutes: 0% > > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > >ASR1002ESP10#sh ip nat stat > >Total active translations: 92367 (80 static, 92287 dynamic; 92287 extended) > >Outside interfaces: > > GigabitEthernet0/0/0, Tunnel1 > >Inside interfaces: > > GigabitEthernet0/0/1, GigabitEthernet0/0/2 > >Hits: 0 Misses: 0 > >CEF Translated packets: 0, CEF Punted packets: 0 > >Expired translations: 87400847 > > > > > >that's on 12.2(33)XNC and I just filed one bug. > > > >CSCsy93931 ASRNAT does not do FIN/RST/SYN timeout when no-payload keyword > >used > > > > > >My first work on the box with NAT but this thing seems pretty impressive. > > > >Anyone else using it for high scale nat yet? > > > >Rodney > > > > > >_______________________________________________ > >cisco-nsp mailing list cisco-nsp at puck.nether.net > >https://puck.nether.net/mailman/listinfo/cisco-nsp > >archive at http://puck.nether.net/pipermail/cisco-nsp/ > > From SMESIATO at petro-canada.ca Tue Apr 7 12:11:29 2009 From: SMESIATO at petro-canada.ca (Mesiatowsky, Shawn) Date: Tue, 7 Apr 2009 12:11:29 -0400 Subject: [c-nsp] Packet Loss on 6513 Message-ID: <259E69AA141E7640822757CAB3EBC70F18B1D0DBE9@MSG-M1P1.pcacorp.net> We currently have 2 6513's in our core, and we have seen packet loss on our network. I was trying to locate the source of the packet loss. We did see some input queue drops on the SVI's and physical interfaces. I had increased our queue size on the vlan interfaces to 500, and our packet drops on the svi's decreased signifigantly. Now I am trying to figure out why there is packet loss on the physical interfaces. We have a sup 720, and our line cards are WS-X6724-SFP and WS-X6748-SFP. Here is a sample of an interface with high drops GigabitEthernet2/23 is up, line protocol is up (connected) Hardware is C6k 1000Mb 802.3, address is 001a.2f68.7bc2 (bia 001a.2f68.7bc2) MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 38/255, rxload 32/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex, 1000Mb/s, media type is SX input flow-control is off, output flow-control is off Clock mode is auto ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:31, output hang never Last clearing of "show interface" counters 1d00h Input queue: 0/2000/91560/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 5 minute input rate 126671000 bits/sec, 28888 packets/sec 5 minute output rate 151605000 bits/sec, 26499 packets/sec 942611654 packets input, 633784740348 bytes, 0 no buffer Received 7319979 broadcasts (6903850 multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 91560 overrun, 0 ignored 0 watchdog, 0 multicast, 0 pause input 0 input packets with dribble condition detected 891230426 packets output, 579042873963 bytes, 0 underruns 0 output errors, 0 collisions, 0 interface resets 0 babbles, 0 late collision, 0 deferred 0 lost carrier, 0 no carrier, 0 PAUSE output 0 output buffer failures, 0 output buffers swapped out I also looked at the utilization of this interface with our snmp tool, and utilixzation of this interface never went over %40 I also noticed the following, and was not sure if this was completely accurate: show platform hardware capacity interface Interface Resources Interface drops: Module Total drops: Tx Rx Highest drop port: Tx Rx 1 0 466 0 1 2 0 154228 0 23 3 0 123 0 1 4 0 190102 0 21 5 0 446318 0 21 7 3940684041 0 1 0 9 0 34280 0 7 10 0 5 0 42 11 0 433 0 46 12 0 1686 0 44 13 66042 119859 1 1 Interface buffer sizes: Module Bytes: Tx buffer Rx buffer 1 1221120 152000 2 1221120 152000 3 1221120 152000 4 1221120 152000 5 1221120 152000 6 1221120 152000 9 1221120 152000 10 1221120 152000 11 1221120 152000 12 1221120 152000 13 1221120 152000 Does this mean that 3940684041 packets were dropped on the egress queue on the sup? Does this seem extremly high, and shat can cause this? Thanks for your help ________________________________ This email communication is intended as a private communication for the sole use of the primary addressee and those individuals listed for copies in the original message. The information contained in this email is private and confidential and If you are not an intended recipient you are hereby notified that copying, forwarding or other dissemination or distribution of this communication by any means is prohibited. If you are not specifically authorized to receive this email and if you believe that you received it in error please notify the original sender immediately. We honour similar requests relating to the privacy of email communications. Cette communication par courrier ?lectronique est une communication priv?e ? l'usage exclusif du destinataire principal ainsi que des personnes dont les noms figurent en copie. Les renseignements contenus dans ce courriel sont confidentiels et si vous n'?tes pas le destinataire pr?vu, vous ?tes avis?, par les pr?sentes que toute reproduction, transfert ou autre forme de diffusion de cette communication par quelque moyen que ce soit est interdite. Si vous n'?tes pas sp?cifiquement autoris? ? recevoir ce courriel ou si vous croyez l'avoir re?u par erreur, veuillez en aviser l'exp?diteur original imm?diatement. Nous respectons les demandes similaires qui touchent la confidentialit? des communications par courrier ?lectronique. From rodunn at cisco.com Tue Apr 7 13:00:37 2009 From: rodunn at cisco.com (Rodney Dunn) Date: Tue, 7 Apr 2009 13:00:37 -0400 Subject: [c-nsp] Too dumb for SLB on ASR1Ks? In-Reply-To: <20090407160115.GX29526@ronin.4ever.de> References: <20090403153128.GA12333@ronin.4ever.de> <20090407160115.GX29526@ronin.4ever.de> Message-ID: <20090407170037.GB22725@rtp-cse-489.cisco.com> I just asked one of the platform PM's. It's not supported on ASR1k. Rodney On Tue, Apr 07, 2009 at 06:01:15PM +0200, Elmar K. Bins wrote: > So far, I have gotten only the one response to my question. > > What would be the suggestion? "Ask Cisco for configuration > help?" "Create a bug id?" Any ideas/guidance? I'm under the > impression my basic config should be working but it doesn't... > > You know, any input etc... > > Elmar. > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From yanf787 at yahoo.com Tue Apr 7 13:02:55 2009 From: yanf787 at yahoo.com (Yan Filyurin) Date: Tue, 7 Apr 2009 10:02:55 -0700 (PDT) Subject: [c-nsp] NAT on ASR1000 In-Reply-To: <49DB792C.6080507@forthnet.gr> References: <20090407154647.GQ20028@rtp-cse-489.cisco.com> <49DB792C.6080507@forthnet.gr> Message-ID: <946159.23396.qm@web54009.mail.re2.yahoo.com> At certain point of time, I was testing NAT with just test tools, sending various forms of raw TCP, UDP and just IP traffic. I was able to get about 150k simultaneous translations at 2Gbps doing very low packet sizes. I definitely remember doing it with IMIX. I do remember seeing issues with BFD when NAT was enabled and a number of IPSec issues. But I think most of these issues have been fixed. There were also some issues with show commands, but that goes back to 2.2.1. This device is perfect for NAT. 7200 G2 is the next best thing and definitely better than 7600. G2 could easily do 100k translations at about 500% Mbps, but with 60% CPU. Maybe easily isn't the right word, but still. I can give more details offline. Yan ________________________________ From: Tassos Chatzithomaoglou To: Rodney Dunn Cc: cisco-nsp at puck.nether.net Sent: Tuesday, April 7, 2009 12:02:52 PM Subject: Re: [c-nsp] NAT on ASR1000 Rodney, can you do a "sh plat soft stat contr br"? -- Tassos Rodney Dunn wrote on 07/04/2009 18:46: > Few bugs still being worked through but the 72xx and 76xx croaked > under the load: > > ASR1002ESP10#sh proc cpu sort | excl 0.00 > CPU utilization for five seconds: 0%/0%; one minute: 0%; five minutes: 0% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process ASR1002ESP10#sh ip nat stat > Total active translations: 92367 (80 static, 92287 dynamic; 92287 extended) > Outside interfaces: > GigabitEthernet0/0/0, Tunnel1 > Inside interfaces: GigabitEthernet0/0/1, GigabitEthernet0/0/2 > Hits: 0 Misses: 0 > CEF Translated packets: 0, CEF Punted packets: 0 > Expired translations: 87400847 > > > that's on 12.2(33)XNC and I just filed one bug. > > CSCsy93931 ASRNAT does not do FIN/RST/SYN timeout when no-payload keyword used > > > My first work on the box with NAT but this thing seems pretty impressive. > > Anyone else using it for high scale nat yet? > > Rodney > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From clane1875 at gmail.com Tue Apr 7 16:22:47 2009 From: clane1875 at gmail.com (Chris Lane) Date: Tue, 7 Apr 2009 16:22:47 -0400 Subject: [c-nsp] Cisco 3750 ME %SCHED-3-THRASHING Message-ID: <2e1cd850904071322v4252f143n3334d96b9d94e4da@mail.gmail.com> All,Please help me identify why my 3750ME is throwing these errors. %SCHED-3-THRASHING: Process thrashing on watched message event. -Process= "SSH Process", ipl= 6, pid= 98 -Traceback= 2E4424 2E4B70 D0C404 D0C78C ED455C ED4FE8 ED5A44 ED657C ED6650 CBE0C8 CBE32C CBEA68 CBE914 29BD4C ED996C EDA25b I have looked up on google: Cisco isn't very helpful and says its cleared with 122.25S. http://supportwiki.cisco.com/ViewWiki/index.php/The_"SCHED-3-THRASHING:_Process_thrashing_on_watched"_error_message_and_traceback_errors_appear_in_Catalyst_3750_series_switches I am running 122-46.SE.bin uptime is 1week Any help would be greatly appreciated. -- //CL From leonardo.souza at nec.com.br Tue Apr 7 16:50:22 2009 From: leonardo.souza at nec.com.br (Leonardo Gama Souza) Date: Tue, 7 Apr 2009 17:50:22 -0300 Subject: [c-nsp] RES: Packet Loss on 6513 In-Reply-To: <49DB8577.2060805@rollernet.us> References: <259E69AA141E7640822757CAB3EBC70F18B1D0DBE8@MSG-M1P1.pcacorp.net> <49DB8577.2060805@rollernet.us> Message-ID: <9E07F8717FE8BC4FBAE6860F61EA6C1D022E542E@spsrvmail03.nec.br> Mesiatowsky, Shawn wrote: > We currently have 2 6513's in our core, and we have seen packet loss on our network. I was trying to locate the source of the packet loss. We did see some input queue drops on the SVI's and physical interfaces. I had increased our queue size on the vlan interfaces to 500, and our packet drops on the svi's decreased signifigantly. Now I am trying to figure out why there is packet loss on the physical interfaces. We have a sup 720, and our line cards are WS-X6724-SFP and WS-X6748-SFP. > http://puck.nether.net/pipermail/cisco-nsp/2004-November/014366.html It is a good start. []?s From billw at waveform.net Tue Apr 7 17:23:17 2009 From: billw at waveform.net (Bill Wichers) Date: Tue, 7 Apr 2009 17:23:17 -0400 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 In-Reply-To: <49DB2315.5010806@memetic.org> References: <49DB1C06.60506@memetic.org> <20090407094208.GZ290@greenie.muc.de> <49DB2315.5010806@memetic.org> Message-ID: [snip] > > ... and the context of *this* discussion is likely involving PA-FE-TX's, > > which are "quite old hardware", and cannot do any sort of autoneg. > > > True, so the ports should probably be nailed to full at both sides. Correct, they are PA-FE-TX's. There are two such PAs in a VIP2-50, and those are running the port channel. We use the 7507 as a DoS mitigator since the CPU on the VIP can't handle typical DoS traffic very well and effectively self-limits DoS traffic flow to around 20-30Mb/s or so. For "normal" traffic it can do around 150ish Mb/s or so usually without trouble. The packet size makes all the difference :-) I typically set both ends (router and switch) of these links to 100/full since I've seen weird autonegotiation problems before. This works just fine for individual FE links, but as soon as I bring up the Etherchannel group both member links on the router end drop back to "unknown duplex" (which the switch says is 100/half), and I can't figure out why my "full-duplex" config entry on each port magically disappears as soon as the Etherchannel group is brought up. That's the weird problem I'm trying to figure out... -Bill From alasdairm at gmail.com Tue Apr 7 17:34:16 2009 From: alasdairm at gmail.com (Alasdair McWilliam) Date: Tue, 7 Apr 2009 22:34:16 +0100 Subject: [c-nsp] BGP across continents In-Reply-To: <5493710CC8A944FBA14A84C16722685A@Toshiba> References: <5493710CC8A944FBA14A84C16722685A@Toshiba> Message-ID: <8669CB1B-EDD9-49D5-9561-DDAF9D2C1D4F@gmail.com> Hello, I did think about GRE tunnels but GRE would still need to know about the tunnel destination interfaces. I guess I could get around that by using the IP address of the ISP interfaces on the border routers, but each router will have a link to 2 upstreams, so I'd have to look at that from a resilience perspective. Our border routers are ASR 1002 + ESP5, both will have GE interfaces to two providers (4 links, 2 providers). I'm also expecting about 10Mbps consistently between Europe and Canada even without any customer being in "disaster" mode. Any indication of how the ASR1002 + ESP5 will handle this? (I've not actually got my hands on an ASR yet so am not too sure how they will fare. However from the white papers I've read and from what others have said I'm quite hopeful they will last for years to come! ;) Provider wise, Canada and Europe will not share the same providers at all. I'm personally thinking of going with two ASNs to keep it completely clean, but need to look at the commercials around that from a RIPE/ARIN perspective. Thanks very much Alasdair On 7 Apr 2009, at 18:50, Scott Granados wrote: > There's the allow AS option or you could set up GRE tunnels between > sites and build a mesh. If you use the same carrier in both > locations you could use the no-export option and play with more > specifics / traffic engineering on that level as well. Remember > though if you start pushing to much traffic over the GRE you're > likely to have CPU load issues. (depending on hardware) > > > ----- Original Message ----- From: "Alasdair McWilliam" > > To: > Sent: Tuesday, April 07, 2009 7:22 AM > Subject: [c-nsp] BGP across continents > > >> Hi, >> >> I am setting up a multihomed hosting centre in Europe. As part of the >> service offered we will be providing Disaster Recovery services, >> using >> our ability to re-route customer IP prefixes, through to another >> hosting centre in Canada. >> >> We have a requirement for some prefixes within our net block to >> always >> be available in Canada, and some to always be available in Europe. >> So, >> I am wondering if someone can clarify my thoughts re. the AS numbers >> required for this: can I use the same ASN at both locations (both of >> which will have different upstreams) or will they reject prefixes >> from >> one another? For example, Canada will see a prefix from Europe with >> the same ASN in the AS-Path and drop it. Likewise Europe will drop >> Canada prefixes because it can see the same AS in the AS-Path. >> >> Is there any way around this or is the only option to request a >> second ASN? >> >> Cheers >> Alasdair >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ > From justin at justinshore.com Tue Apr 7 17:53:17 2009 From: justin at justinshore.com (Justin Shore) Date: Tue, 07 Apr 2009 16:53:17 -0500 Subject: [c-nsp] GigE sub-int won't come up Message-ID: <49DBCB4D.8040207@justinshore.com> I'm trying to add a simple sub-int to a built-in GigE interface on a 7206VXR G2. I already have several sub-ints on the same interface and they're working great (typing this email across one of them). However when I added a new sub-int it refused to come up and I can't figure out why. Here's the physical interface config: interface GigabitEthernet0/2 description TO 4948-1.amherst Gi1/45 no ip address duplex auto speed 1000 media-type sfp negotiation auto Very simple. Here's the sub-int config: interface GigabitEthernet0/2.999 description Acme LAN PoC encapsulation dot1Q 999 ip vrf forwarding acme-elan ip address 100.100.100.13 255.255.255.252 Also very simple. The other sub-ints aren't in VRFs but I doubt if that would be a problem here (could be but I doubt it). GigabitEthernet0/2.999 100.100.100.13 YES manual down down I was using VLAN 1001 for the lab test but switched to 999 after thinking that perhaps 1001 was used internally on the 7200 (I don't think it is but just in case); still no go. The VRF is up. I have MLPPP bundle in it and they're working on the same 7206. I'm running 12.4(15)T7. It appears to stay up/up until I define the 1Q VLAN ID on the sub-int. Then it goes down/down. Oddly enough the sub-int doesn't go back to up/up (when the 1Q VLAN is removed) after going down/down (when the 1Q VLAN is assigned). What in the world would keep a sub-int on an Ethernet interface from coming up? I'm not even sure what debug options are available for something like this. Connected to Gi0/2 is a 4948 and that VLAN is permitted across the trunk. Thoughts? I'm sure someone will noticed my error right off but I sure can't find it. Thanks Justin From streiner at cluebyfour.org Tue Apr 7 18:30:39 2009 From: streiner at cluebyfour.org (Justin M. Streiner) Date: Tue, 7 Apr 2009 18:30:39 -0400 (EDT) Subject: [c-nsp] GigE sub-int won't come up In-Reply-To: <49DBCB4D.8040207@justinshore.com> References: <49DBCB4D.8040207@justinshore.com> Message-ID: On Tue, 7 Apr 2009, Justin Shore wrote: > What in the world would keep a sub-int on an Ethernet interface from coming > up? I'm not even sure what debug options are available for something like > this. Connected to Gi0/2 is a 4948 and that VLAN is permitted across the > trunk. Is there an active access port in VLAN 999 on the 4948, or somewhere downstream of it, assuming any neccessary trunking at the site is already in place? I've seen VLANs not come up before, until there is actually a host in the VLAN. jms From rick at woofpaws.com Tue Apr 7 19:10:20 2009 From: rick at woofpaws.com (Rick Ernst) Date: Tue, 7 Apr 2009 16:10:20 -0700 (PDT) Subject: [c-nsp] MLS and accelerated switching Message-ID: <54204.69.30.17.85.1239145820.squirrel@www.woofpaws.com> I'm still working on developing a network design for our ethernet core to best balance the cost/value of "just moving bits". The core is currently a pair of 7507/RSP16/GEIP+ routers running as BGP route-reflectors between the border and aggregation layers. The 7507s (and GEIPs) don't have the horsepower to move much more than about 400Mbs each with current ACLs, NetFlow, and BGP. If the processing were to move to an MLS or accelerated fabric, with just the high-touch bits touching the RSP, it seems like there is still a lot of performance available without going to an "overpowered" 7600/Sup720. It looks like the 6500 Sup-2 supports 128K MLS entries. Based on my NetFlow analysis, I get the following breakdown of unique IPs per time period: Time Unique IPs ----- ----- 15min 320K 5min 150K 90sec 90K 45sec 70K 30sec 55K 15sec 35K If I understand MLS and aging correctly, I should be able to set MLS aging to 45 seconds and MLS flow to destination, and have at least some room for growth. Am I interpreting my data correctly and understanding MLS properly? Will MLS churn at such a short interval cause its own problems? To alter the question slightly; is there a switching platform that could use the RSP16s as a router-on-a-stick to handle >= 1Gbs/2Mpps? Thanks, From justin at justinshore.com Tue Apr 7 19:12:30 2009 From: justin at justinshore.com (Justin Shore) Date: Tue, 07 Apr 2009 18:12:30 -0500 Subject: [c-nsp] GigE sub-int won't come up In-Reply-To: References: <49DBCB4D.8040207@justinshore.com> Message-ID: <49DBDDDE.9010904@justinshore.com> Justin M. Streiner wrote: > Is there an active access port in VLAN 999 on the 4948, or somewhere > downstream of it, assuming any neccessary trunking at the site is > already in place? I've seen VLANs not come up before, until there is > actually a host in the VLAN. There is an active switchport in 999 currently and 1001 before I switched to 999. I don't know that the 4948 could be the problem though. I've seen VLANs not come up until a port in the VLAN was active as well but that's normally on a switch or a router with a switchport (ISR w/ a Ethernet HWIC for example). There isn't a mechanism to advertise VLANs or their local status across a trunk that I'm aware of (with VTP disabled at least). VTP is transparent on the 4948 and not configurable on the 7206. I should be able to configure a dozen 1Q sub-ints on a router's interface and have them be up/up regardless of whether it's configured for use on the connected switch. At least I'm pretty sure I should be able to. What silly thing am I missing? Maybe it will come to me after consuming chips and salsa. Thanks for the info Justin From dale.shaw+cisco-nsp at gmail.com Tue Apr 7 19:41:06 2009 From: dale.shaw+cisco-nsp at gmail.com (Dale Shaw) Date: Wed, 8 Apr 2009 09:41:06 +1000 Subject: [c-nsp] 7200/NPE-G2 field notices Message-ID: <3329cbb40904071641j4cc9ab12o7d68e10ea6bb3351@mail.gmail.com> In case you missed 'em.. Title: Updated Cisco Field Notice: FN - 62535 - NPE-G2, Incompatibility With Lower-Revision VXR Series Chassis With Specific Port Adaptors - RMA required URL: http://www.cisco.com/en/US/customer/ts/fn/620/fn62535.html Title: Updated Cisco Field Notice: FN - 62514 - C7200-JC-PA - Certain Jacket Cards with PA installed on 7200VXR may have infrequent system crashes due to PCI Bus Error, Software Forced Crash, WDT Reset error - RMA required URL: http://www.cisco.com/en/US/customer/ts/fn/620/fn62514.html cheers, Dale From pshem.k at gmail.com Tue Apr 7 20:51:35 2009 From: pshem.k at gmail.com (Pshem Kowalczyk) Date: Wed, 8 Apr 2009 12:51:35 +1200 Subject: [c-nsp] ASR1004 - ipv6 static route in a vrf Message-ID: <20fe625b0904071751o10fd57f8p4991d548f5e64bd1@mail.gmail.com> Hi, I'm playing with an ASR1004 to test some ipv6 capabilities. For some reason I can't seem to get a static route working: ASR1(config)#ipv6 route vrf Public 2407:7000::/32 Null0 ASR1(config)#do sh ipv6 route vrf Public IPv6 Routing Table - Public - 1 entries Codes: C - Connected, L - Local, S - Static, U - Per-user Static route B - BGP, R - RIP, I1 - ISIS L1, I2 - ISIS L2 IA - ISIS interarea, IS - ISIS summary, D - EIGRP, EX - EIGRP external O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2 ON1 - OSPF NSSA ext 1, ON2 - OSPF NSSA ext 2 L FF00::/8 [0/0] via Null0, receive If I assign the /32 to an interface, even a loopback, I can see in the routing table. I have 'ipv6 unicast-routing' in the config and 'ipv6 cef distributed' - but this one seems to be on by default. But CEF doesn't know anything about the prefix either: ASR1#sh ipv6 cef vrf Public 2407:7000::/32 %Prefix not found any ideas? kind regards Pshem From pshem.k at gmail.com Tue Apr 7 21:13:04 2009 From: pshem.k at gmail.com (Pshem Kowalczyk) Date: Wed, 8 Apr 2009 13:13:04 +1200 Subject: [c-nsp] ASR1004 - ipv6 static route in a vrf In-Reply-To: <20fe625b0904071751o10fd57f8p4991d548f5e64bd1@mail.gmail.com> References: <20fe625b0904071751o10fd57f8p4991d548f5e64bd1@mail.gmail.com> Message-ID: <20fe625b0904071813g5b82f6b9sb1dffa27715490fa@mail.gmail.com> It was simpler then I though - there has to be at least one interface with ipv6 configured for the static route to work. kind regards Pshem From gsgranados at comcast.net Tue Apr 7 21:36:23 2009 From: gsgranados at comcast.net (Scott Granados) Date: Tue, 7 Apr 2009 18:36:23 -0700 Subject: [c-nsp] rate limiting pointers? Message-ID: <4F659EDCBCCC440DAD49883F36BDE65A@Toshiba> Since the topic of rate limiting came up... I have a 7206VXR NPE-300 and 2 switches (2960 and 3550). I plan on setting up a trunk from the 7206 to the 3500 and break out via vlans as you'd expect. What are some good methods for rate limiting the individual ports on the access switches? I'm open to other hardware but this is more of a lab / personal environment so solutions for the listed hardware would be appreciated. Could someone also suggest some good foundation type reading for rate limiting and practices? Thank you Scott From nick.geyer at eds.com Tue Apr 7 21:54:57 2009 From: nick.geyer at eds.com (Geyer, Nick) Date: Wed, 8 Apr 2009 11:54:57 +1000 Subject: [c-nsp] BGP across continents In-Reply-To: <8669CB1B-EDD9-49D5-9561-DDAF9D2C1D4F@gmail.com> References: <5493710CC8A944FBA14A84C16722685A@Toshiba> <8669CB1B-EDD9-49D5-9561-DDAF9D2C1D4F@gmail.com> Message-ID: <83027F7A5EB4D6449A1393A94E4D41DA04D856C6@aubwm232.apac.corp.eds.com> I have rolled out ASR1002/ESP5's as border routers in a few places now and they perform fantastically. Doing BGP, bogon filtering and basic ACL's, the highest usage ones I have running in production at the moment push up to ~200Mbps sustained and the routers don't even blink at it. Definitely a good platform for the intended purpose, and kudos to Cisco for not trying to cram it full of features at initial release, IOS XE actually looks like a decent and stable platform =) -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Alasdair McWilliam Sent: Wednesday, 8 April 2009 7:34 AM To: Scott Granados Cc: Cisco NSP Subject: Re: [c-nsp] BGP across continents *snip* Any indication of how the ASR1002 + ESP5 will handle this? (I've not actually got my hands on an ASR yet so am not too sure how they will fare. However from the white papers I've read and from what others have said I'm quite hopeful they will last for years to come! ;) Thanks very much Alasdair On 7 Apr 2009, at 18:50, Scott Granados wrote: > There's the allow AS option or you could set up GRE tunnels between > sites and build a mesh. If you use the same carrier in both > locations you could use the no-export option and play with more > specifics / traffic engineering on that level as well. Remember > though if you start pushing to much traffic over the GRE you're > likely to have CPU load issues. (depending on hardware) > > > ----- Original Message ----- From: "Alasdair McWilliam" > > To: > Sent: Tuesday, April 07, 2009 7:22 AM > Subject: [c-nsp] BGP across continents > > >> Hi, >> >> I am setting up a multihomed hosting centre in Europe. As part of the >> service offered we will be providing Disaster Recovery services, >> using >> our ability to re-route customer IP prefixes, through to another >> hosting centre in Canada. >> >> We have a requirement for some prefixes within our net block to >> always >> be available in Canada, and some to always be available in Europe. >> So, >> I am wondering if someone can clarify my thoughts re. the AS numbers >> required for this: can I use the same ASN at both locations (both of >> which will have different upstreams) or will they reject prefixes >> from >> one another? For example, Canada will see a prefix from Europe with >> the same ASN in the AS-Path and drop it. Likewise Europe will drop >> Canada prefixes because it can see the same AS in the AS-Path. >> >> Is there any way around this or is the only option to request a >> second ASN? >> >> Cheers >> Alasdair >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From gregariouspearl at gmail.com Wed Apr 8 00:36:07 2009 From: gregariouspearl at gmail.com (Muhammad Salman Zahid) Date: Wed, 8 Apr 2009 09:36:07 +0500 Subject: [c-nsp] rate limiting pointers? In-Reply-To: <4F659EDCBCCC440DAD49883F36BDE65A@Toshiba> References: <4F659EDCBCCC440DAD49883F36BDE65A@Toshiba> Message-ID: <44c523750904072136u5c3c82c0scf20d47d5c2e3241@mail.gmail.com> Dear Scott, Read & try the following: Step 1: Define ACL for desired IP Pools Step 2: Define a Packet classification criteria Class-map match-all description Control plane normal traffic match access-group name Step 3: Define a Service Policy policy-map class police cir conform-action set-dscp-transmit default exceed-action drop violate-action drop Step 4: Enter service policy on control plane interface service-policy input service-policy output ip access-list extended [ABC] ip access-list extended [XYZ] class-map match-all [NAME1]=== NAME1=ABC (so easily remember) match access-group name [ABC] class-map match-all [NAME2]=== NAME2=XYZ (so easily remember) match access-group name [XYZ] policy-map [POLICY NAME] class [ABC] put rate limit class [XYZ] put rate limit Regards, MSZ On Wed, Apr 8, 2009 at 6:36 AM, Scott Granados wrote: > Since the topic of rate limiting came up... > > I have a 7206VXR NPE-300 and 2 switches (2960 and 3550). > > I plan on setting up a trunk from the 7206 to the 3500 and break out via > vlans as you'd expect. What are some good methods for rate limiting the > individual ports on the access switches? > > I'm open to other hardware but this is more of a lab / personal environment > so solutions for the listed hardware would be appreciated. Could someone > also suggest some good foundation type reading for rate limiting and > practices? > > Thank you > Scott > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > -- "Death is no the greatest loss in life .... The greatest loss is what dies inside you while U live...!" From ying-xiang at 163.com Wed Apr 8 01:22:45 2009 From: ying-xiang at 163.com (ying-xiang) Date: Wed, 8 Apr 2009 13:22:45 +0800 (CST) Subject: [c-nsp] about eompls on 7609 Message-ID: <24825069.914261239168165588.JavaMail.coremail@bj163app105.163.com> hi? following is my topology brief? SwitchA---PE1?7609-1?---PE2?7609-2?---SwitchB Both switchA and switchB are configured a vlan100 to achieve layer two transport through EoMPLS and they works without any issue but i got an error when i tried to set the same vlan id on the PEs could anyone explain this for me ? looking forward to your reply. From gert at greenie.muc.de Wed Apr 8 02:44:41 2009 From: gert at greenie.muc.de (Gert Doering) Date: Wed, 8 Apr 2009 08:44:41 +0200 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 In-Reply-To: References: <20090407094208.GZ290@greenie.muc.de> <49DB2315.5010806@memetic.org> Message-ID: <20090408064441.GE290@greenie.muc.de> Hi, On Tue, Apr 07, 2009 at 05:23:17PM -0400, Bill Wichers wrote: > I typically set both ends (router and switch) of these links to 100/full > since I've seen weird autonegotiation problems before. This works just > fine for individual FE links, but as soon as I bring up the Etherchannel > group both member links on the router end drop back to "unknown duplex" > (which the switch says is 100/half), and I can't figure out why my > "full-duplex" config entry on each port magically disappears as soon as > the Etherchannel group is brought up. That's the weird problem I'm > trying to figure out... A switch connected to a PA-FE-TX will never be able to figure out the duplex settings on the PA-FE - because the PA can't tell it. So you'll always have to manually configure both sides for the desired duplex settings. Now, in your case, I think you'll need to do some experimenting - set the switch to 100/full, run cisco ping tests (1000+ packets) - set the switch to 100/half, run cisco ping tests (1000+ packets) if you get packet loss, you have a duplex mismatch... If the setup *works* when set to 100/full, I'd classify the "unknown duplex" thing as an artifact on the 7500 - given that the PA-FE cannot autonegotiate, maybe the high-level code is just telling this to you "we don't know what's the underlying physics". If the setup needs 100/half on the switch side, I'd open a TAC case. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From sethm at rollernet.us Wed Apr 8 03:14:52 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Wed, 08 Apr 2009 00:14:52 -0700 Subject: [c-nsp] T3 or Ethernet delivery? Message-ID: <49DC4EEC.3070001@rollernet.us> One of my carriers has given me a choice for a new circuit delivery: T3 or Ethernet. My outside world circuit experience is all non-Ethernet, so I have a few questions the sales group wasn't able to answer. I'd love to hear some real world experience. The cost difference between the two is not significant enough to be the sole deciding factor and I'm not using pure-Ethernet platforms so it's just a matter of adding the right interface card. How do you detect a "down" condition on Ethernet? My experience is that the interface could be up/up because Ethernet doesn't know about anything further down the line and ends up throwing packets into a magical black hole. Or worse, secret packet loss. Can you even troubleshoot Ethernet? Normally if I'm seeing something like out of frame errors or AIS, I can say "hey, there's a problem and it's X". It scares me to think of opening trouble tickets as "it's broken and I can't really tell you why". With a T3 I can be fairly certain that if there aren't any alarms that my end is happily talking to the other end. How does one accomplish the same with Ethernet? A periodic "ping" seems rather ambiguous as a health check. Since this is an outside world connection (i.e. I'm not in a colo) the slightly lower cost and convenience factor of Ethernet doesn't override my desire to stick with a T3 for its management properties and the sleeping good at night feeling I get knowing there are no alarms. My gut tells me to stick with it even though Ethernet delivery is what all the cool kids are doing these days, so any insight is appreciated. Thanks! ~Seth From r.tahina at moov.mg Wed Apr 8 03:31:16 2009 From: r.tahina at moov.mg (RAZAFINDRATSIFA Rivo Tahina) Date: Wed, 08 Apr 2009 10:31:16 +0300 Subject: [c-nsp] upload to 2 upstreams In-Reply-To: <3c605ce10904072144q43079751i149e425a27d15ee7@mail.gmail.co m> References: <7.0.1.0.2.20090407183213.04f15628@moov.mg> <3c605ce10904072144q43079751i149e425a27d15ee7@mail.gmail.com> Message-ID: <7.0.1.0.2.20090408102917.042f2bf0@moov.mg> Yes it's BGP. At 07:44 08/04/2009, Aftab Siddiqui wrote: >What routing protocol you are runnging with your upstream. It should >be BGP I guess. > >On Tue, Apr 7, 2009 at 8:36 PM, RAZAFINDRATSIFA Rivo Tahina ><r.tahina at moov.mg> wrote: >Hi all, > >We have two upstreams and our upload traffic is load balanced >between them, when one of them is down, how can I do to send all >output to the one which is still up? > >Regards. >_______________________________________________ >cisco-nsp mailing >list cisco-nsp at puck.nether.net >https://puck.nether.net/mailman/listinfo/cisco-nsp >archive at >http://puck.nether.net/pipermail/cisco-nsp/ > > > > >-- >Regards, > >Aftab A. Siddiqui From aj at sneep.net Wed Apr 8 03:05:41 2009 From: aj at sneep.net (Alastair Johnson) Date: Wed, 08 Apr 2009 15:05:41 +0800 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 In-Reply-To: References: <49DB1C06.60506@memetic.org> <20090407094208.GZ290@greenie.muc.de> <49DB2315.5010806@memetic.org> Message-ID: <49DC4CC5.1030106@sneep.net> Bill Wichers wrote: > I typically set both ends (router and switch) of these links to 100/full > since I've seen weird autonegotiation problems before. This works just > fine for individual FE links, but as soon as I bring up the Etherchannel > group both member links on the router end drop back to "unknown duplex" > (which the switch says is 100/half), and I can't figure out why my > "full-duplex" config entry on each port magically disappears as soon as > the Etherchannel group is brought up. That's the weird problem I'm > trying to figure out... My experience with 7500 and Etherchannel, particularly if it's across multiple PA is to just give up. I was never able to keep it running reliably under 12.0S, whether the the other end was a C2924 or C4006. Best case is it would work for a while, then some magic duplex problem would pop up and make it explode spectacularly - usually after a reload or an OIR or other CxBus restart, and occasionally after DCEF dying... Usually it would involve one end being in FDX, the other end being in HDX or no-duplex at all - despite both ends being configured for 100/Full. I hope you have better luck, but I wouldn't count on it. ISTR that 12.0 mainline and some of the sub-tree variants (12.1E?) had slightly less problematic issues with it. aj From Ian.Mackinnon at lumison.net Wed Apr 8 04:11:10 2009 From: Ian.Mackinnon at lumison.net (Ian MacKinnon) Date: Wed, 8 Apr 2009 09:11:10 +0100 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <49DC4EEC.3070001@rollernet.us> References: <49DC4EEC.3070001@rollernet.us> Message-ID: Hi Seth, I think the world is moving to ethernet for what traditionally was a leased line, so you are only going to see more of it. Don't forget in your cost calculations the CPE line card, compare the cost of a router (or switch) with a spare Ethernet port and one with a 2Meg serial card. Also don't forget the cost of spares for each and every different serial card you need. Yes, you are right you will see traffic blackholed, the interface is up/up, but there is no end to end connectivity. Ian > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- > bounces at puck.nether.net] On Behalf Of Seth Mattinen > Sent: 08 April 2009 08:15 > To: cisco-nsp > Subject: [c-nsp] T3 or Ethernet delivery? > > One of my carriers has given me a choice for a new circuit delivery: T3 > or Ethernet. My outside world circuit experience is all non-Ethernet, > so > I have a few questions the sales group wasn't able to answer. I'd love > to hear some real world experience. The cost difference between the two > is not significant enough to be the sole deciding factor and I'm not > using pure-Ethernet platforms so it's just a matter of adding the right > interface card. > > How do you detect a "down" condition on Ethernet? My experience is that > the interface could be up/up because Ethernet doesn't know about > anything further down the line and ends up throwing packets into a > magical black hole. Or worse, secret packet loss. > > Can you even troubleshoot Ethernet? Normally if I'm seeing something > like out of frame errors or AIS, I can say "hey, there's a problem and > it's X". It scares me to think of opening trouble tickets as "it's > broken and I can't really tell you why". > > With a T3 I can be fairly certain that if there aren't any alarms that > my end is happily talking to the other end. How does one accomplish the > same with Ethernet? A periodic "ping" seems rather ambiguous as a > health > check. > > Since this is an outside world connection (i.e. I'm not in a colo) the > slightly lower cost and convenience factor of Ethernet doesn't override > my desire to stick with a T3 for its management properties and the > sleeping good at night feeling I get knowing there are no alarms. My > gut > tells me to stick with it even though Ethernet delivery is what all the > cool kids are doing these days, so any insight is appreciated. Thanks! > > ~Seth > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ -- This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. If you have received this email in error please notify the sender. Any offers or quotation of service are subject to formal specification. Errors and omissions excepted. Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of Lumison and nPlusOne. Finally, the recipient should check this email and any attachments for the presence of viruses. Lumison and nPlusOne accept no liability for any damage caused by any virus transmitted by this email. From justin at justinshore.com Wed Apr 8 04:19:31 2009 From: justin at justinshore.com (Justin Shore) Date: Wed, 08 Apr 2009 03:19:31 -0500 Subject: [c-nsp] GigE sub-int won't come up In-Reply-To: <49DBDDDE.9010904@justinshore.com> References: <49DBCB4D.8040207@justinshore.com> <49DBDDDE.9010904@justinshore.com> Message-ID: <49DC5E13.6050502@justinshore.com> Justin Shore wrote: > Justin M. Streiner wrote: >> Is there an active access port in VLAN 999 on the 4948, or somewhere >> downstream of it, assuming any neccessary trunking at the site is >> already in place? I've seen VLANs not come up before, until there is >> actually a host in the VLAN. > > There is an active switchport in 999 currently and 1001 before I > switched to 999. I don't know that the 4948 could be the problem > though. I've seen VLANs not come up until a port in the VLAN was active > as well but that's normally on a switch or a router with a switchport > (ISR w/ a Ethernet HWIC for example). There isn't a mechanism to > advertise VLANs or their local status across a trunk that I'm aware of > (with VTP disabled at least). VTP is transparent on the 4948 and not > configurable on the 7206. I should be able to configure a dozen 1Q > sub-ints on a router's interface and have them be up/up regardless of > whether it's configured for use on the connected switch. At least I'm > pretty sure I should be able to. I had what was supposed to be a quick maintenance window tonight to bump the code rev on the 7200 and reboot. I also did a minor rev update on the 4948. I rebooted the 4948 first but after 10m it still hadn't come back up (I don't have OOB access to anything in that POP). The 7200 hadn't seen the interfaces come up. I went ahead and did the 7200 while I was getting my things together to drive to that POP. The 7200 never came back up either. Joy. Once I got onsite I found that both devices were in fact running. The problem was that the GigE links on the 7200 wouldn't come up. Both the physical GigE interfaces and all their sub-ints were all up/down. I started opening a TAC case at that point. While the TAC operator waded through the tech options to try and figure out how to assign my case I thought about the problem some more, what Justin wrote earlier and my response about no VTP or VTP-like protocols in use jumped out at me. I checked the config and sure enough I had CFM and OAM (partially?) configured. Don't they share link information including VLAN info? I need to do more research on it and move the config to a lab environment. As soon as I removed the CFM and OAM config from the 7200 the GigE links came up. Not only that but all the sub-ints came up that I'd been fighting earlier. My broken CFM or OAM or both config is what caused all these problems. I was working with CFM and OAM after attending some MetroE training in SJC. At the time my gear wasn't in production but now it is and I hadn't removed the config. Does anyone have any good docs that clearly explain how to properly configure CFM, OAM and LMI? I've found lots of docs that talk about it but none are terribly clear on exactly how to implement it and what's the BCP in certain environments. Clearly what I was doing before wasn't right. How to troubleshoot these protocols would also be very helpful. Had I known that this is what was keeping the interface facing the 4948 down I could have fixed it from my recliner instead of taking a roadtrip to a remote POP. Thanks for the info Justin From emanuel.popa at gmail.com Wed Apr 8 04:28:26 2009 From: emanuel.popa at gmail.com (Emanuel Popa) Date: Wed, 8 Apr 2009 11:28:26 +0300 Subject: [c-nsp] carrier router models comparison In-Reply-To: <49DB7D59.1030006@forthnet.gr> References: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> <49DB7D59.1030006@forthnet.gr> Message-ID: <4981ce080904080128u2c54312apb7917ec5759a0335@mail.gmail.com> hi tassos, i'm really scared when using a fairly new platform with a fairly new software version. i would prefer paying more money for a more stable device. and this fear of mine goes back to the SRB2 version for the Cisco 7600 which is the worst thing that could happen for the 7600. anyways, the platform is not even well documented on cisco.com so it can not be included in our business case. i expect a management decision ASAP as our links are pretty congested on single failures as we speak. regards, manu 2009/4/7 Tassos Chatzithomaoglou : > Besides your choices, ASR 9000 should be out soon (its IOS XR Software is > already available). > > -- > Tassos > > Emanuel Popa wrote on 07/04/2009 18:51: >> >> hi there, >> >> due to the increase in traffic volume in the last couple of years we >> need to really think about the future of the network. we have deployed >> and we are managing a 50GE multi-ring topology network with Cisco 7600 >> routers. i don't want to get into more details about ring topology >> restrictions, platform limitations regarding wire speed, huge problems >> with ether-channels or unpredictable load balancing behaviour. we've >> been using these chassis since 2004 starting with STM-16 lines and the >> PQ ratio looks pretty good so far. >> >> coming back to nowadays, 40GE or 100GE is not available yet, and even >> if it was, the price would be probably unaffordable. and now the >> question pops: what is the next step? the best answer is of course a >> mix of multiple 10GE lines with traffic engineering and partial mesh >> topology and 100GE ready chassis. first thing that comes to mind is >> the CRS-1 platform, but it is really expensive: from under 15K per >> 10GE port with the Cisco 7600 you have to pay more than 75K per 10GE >> port with the CRS-1. so we have to take into consideration what are >> the alternatives. i will try a short comparison: >> >> - Cisco CRS-1 16 Slot >> --- max 64 x 10GE >> --- max 32 links in a bundle >> --- 40Gbps per slot >> --- 100GE ready >> --- multi-chassis ready >> --- 10.920W max power >> --- 723kg max weight >> --- full rack space >> --- $5.115.000,00/chassis >> --- $79.921,88/10GE >> >> - Juniper T1600 >> --- max 64 x 10GE >> --- max 16 links in a bundle >> --- 100Gbps per slot >> --- 100GE ready >> --- multi-chassis ready >> --- 8.352W max power >> --- 274,88kg max weight >> --- 1/2 rack space >> --- $6.547.000,00/chassis >> --- $102.296,88/10GE >> >> - Brocade/ Foundry NetIron XMR 16000 >> --- max 64 x 10GE >> --- max 32 links in a bundle >> --- 50Gbps per slot >> --- 100GE ready (* only full slots) >> --- single-chassis >> --- 5.572W max power >> --- 107,00kg max weight >> --- 1/3 rack space >> --- $567.515,00/chassis >> --- $8.867,42/10GE >> >> I've also been looking at Huawei, Alcatel and HP gear but haven't been >> able to find a device to support more than 24 x 10GE ports in a single >> chassis. >> >> Here's what I'm trying to figure out: >> >> 1. are there any other devices on the market with same hardware >> capabilities? >> >> 2. why the huge difference between foundry and cisco/juniper? >> >> 3. if foundry is so cheap why hasn't it gathered more market share? >> instead it was bought by brocade a while ago... >> >> 4. is the netiron really a carrier router more than a carrier switch? >> anybody experienced it? >> >> 5. how does the software perform when comparing with IOS XR and JunOS? >> >> Please, any comments are welcomed. >> >> Best regards, >> Manu >> _______________________________________________ >> cisco-nsp mailing list ?cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > From sam_mailinglists at spacething.org Wed Apr 8 06:26:06 2009 From: sam_mailinglists at spacething.org (Sam Stickland) Date: Wed, 08 Apr 2009 11:26:06 +0100 Subject: [c-nsp] Max length of 9600 serial over CAT5e Message-ID: <49DC7BBE.50906@spacething.org> Hi, What's the maximum length of you can run async-serial (9600 baud) over CAT5e (from a terminal server to console port). My google-fu has failed me. Sam From richard.halfpenny at exa-networks.co.uk Wed Apr 8 07:31:38 2009 From: richard.halfpenny at exa-networks.co.uk (Richard Halfpenny) Date: Wed, 08 Apr 2009 12:31:38 +0100 Subject: [c-nsp] Max length of 9600 serial over CAT5e In-Reply-To: <49DC7BBE.50906@spacething.org> References: <49DC7BBE.50906@spacething.org> Message-ID: <49DC8B1A.2000501@exa-networks.co.uk> Sam Stickland wrote: > Hi, > > What's the maximum length of you can run async-serial (9600 baud) > over CAT5e (from a terminal server to console port). > > My google-fu has failed me. If I remember correctly, the spec for RS-232 says the maximum capacitance of a cable can be 2500pF at 20kbps. A Cat5e of approx 46pF / metre would give you a maximum length of 54 metres. At 9600bps you could probably drive slightly longer. Rich -- Network Operations Exa Networks Ltd :: AS30740 richard.halfpenny at exa-networks.co.uk From deric.kwok2000 at gmail.com Wed Apr 8 08:09:39 2009 From: deric.kwok2000 at gmail.com (Deric Kwok) Date: Wed, 8 Apr 2009 08:09:39 -0400 Subject: [c-nsp] 2600 series for 100M Message-ID: <40d8a95a0904080509t3955662bod20a1fc36b8353c9@mail.gmail.com> Hi Do you know Cisco 2651XM is fine for 100M network? If the memory is 256M, it is ok? Can it support Virtual private network, VLAN and new tcsh command? i check the ios is "C2600 Software (C2600-ENTSERVICESK9-M), Version 12.3(23)" Do I need to buy any extra memory? Thank you From gert at greenie.muc.de Wed Apr 8 08:54:50 2009 From: gert at greenie.muc.de (Gert Doering) Date: Wed, 8 Apr 2009 14:54:50 +0200 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <49DC4EEC.3070001@rollernet.us> References: <49DC4EEC.3070001@rollernet.us> Message-ID: <20090408125450.GL290@greenie.muc.de> Hi, On Wed, Apr 08, 2009 at 12:14:52AM -0700, Seth Mattinen wrote: > How do you detect a "down" condition on Ethernet? My experience is that > the interface could be up/up because Ethernet doesn't know about > anything further down the line and ends up throwing packets into a > magical black hole. Or worse, secret packet loss. Run a routing protocol over it. [..] > With a T3 I can be fairly certain that if there aren't any alarms that > my end is happily talking to the other end. How does one accomplish the > same with Ethernet? A periodic "ping" seems rather ambiguous as a health > check. Not necessarily so - even on a T3, you can have bad cables going just one way, so you might have packet loss in your transmit direction. The provider would see (CRC) errors, but you might not see anything. So you'll need to run ping... (And yes, I know how you feel. But the price difference between the gear for SDH 2.4 Gbit equipment vs. 2 x 1Gbit ethernet links was so overwhelming that we decided to go for ethernet... and for the same price, we even got *two* links, so "no single point of failure") gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From cchurc05 at harris.com Wed Apr 8 08:54:20 2009 From: cchurc05 at harris.com (Church, Charles) Date: Wed, 8 Apr 2009 07:54:20 -0500 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <49DC4EEC.3070001@rollernet.us> References: <49DC4EEC.3070001@rollernet.us> Message-ID: -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Seth Mattinen Sent: Wednesday, April 08, 2009 3:15 AM To: cisco-nsp Subject: [c-nsp] T3 or Ethernet delivery? >How do you detect a "down" condition on Ethernet? My experience is that >the interface could be up/up because Ethernet doesn't know about >anything further down the line and ends up throwing packets into a >magical black hole. Or worse, secret packet loss. Object tracking can take care of this. Or a dynamic routing protocol (no connectivity, no neighbor). You just need to be more careful in your QoS. A routed ethernet port has far more flexibility than a simple switch port on most platforms. You'll probably want to shape/police your traffic outbound if your provided BW is exactly 10, 100, or gig. From rshughes at gmail.com Wed Apr 8 09:09:50 2009 From: rshughes at gmail.com (Ryan Hughes) Date: Wed, 8 Apr 2009 09:09:50 -0400 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <20090408125450.GL290@greenie.muc.de> References: <49DC4EEC.3070001@rollernet.us> <20090408125450.GL290@greenie.muc.de> Message-ID: Generally my experience with Ethernet handoffs has been hit or miss depending on what the carrier is delivering for the hand off - I've dealt with some gear as you alluded to that doesn't down the CE hand off when the circuit goes which turns into an interesting game of routing protocol timers and EEM/IP SLA for neighbor tracking. I've also run into situations where its best to traffic shape the port to the CIR you're getting the provider on sub-rate Ethernet hand offs (you're only paying for 45mb and you negotiating the physical to a gig with their gear). But yeah - the price and cost saving of not needing certain interface line card for hand off is undeniable and has to be taken serious. Ryan On Wed, Apr 8, 2009 at 8:54 AM, Gert Doering wrote: > Hi, > > On Wed, Apr 08, 2009 at 12:14:52AM -0700, Seth Mattinen wrote: > > How do you detect a "down" condition on Ethernet? My experience is that > > the interface could be up/up because Ethernet doesn't know about > > anything further down the line and ends up throwing packets into a > > magical black hole. Or worse, secret packet loss. > > Run a routing protocol over it. > > [..] > > With a T3 I can be fairly certain that if there aren't any alarms that > > my end is happily talking to the other end. How does one accomplish the > > same with Ethernet? A periodic "ping" seems rather ambiguous as a health > > check. > > Not necessarily so - even on a T3, you can have bad cables going just > one way, so you might have packet loss in your transmit direction. The > provider would see (CRC) errors, but you might not see anything. > > So you'll need to run ping... > > (And yes, I know how you feel. But the price difference between the > gear for SDH 2.4 Gbit equipment vs. 2 x 1Gbit ethernet links was so > overwhelming that we decided to go for ethernet... and for the same > price, we even got *two* links, so "no single point of failure") > > gert > -- > USENET is *not* the non-clickable part of WWW! > // > www.muc.de/~gert/ > Gert Doering - Munich, Germany > gert at greenie.muc.de > fax: +49-89-35655025 > gert at net.informatik.tu-muenchen.de > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From jeff at ocjtech.us Wed Apr 8 09:18:32 2009 From: jeff at ocjtech.us (Jeffrey Ollie) Date: Wed, 8 Apr 2009 08:18:32 -0500 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <49DC4EEC.3070001@rollernet.us> References: <49DC4EEC.3070001@rollernet.us> Message-ID: <935ead450904080618k15aa5c2bo23acf3dac7005e9c@mail.gmail.com> On Wed, Apr 8, 2009 at 2:14 AM, Seth Mattinen wrote: > One of my carriers has given me a choice for a new circuit delivery: T3 > or Ethernet. I would go for Ethernet in a heartbeat. > The cost difference between the two > is not significant enough to be the sole deciding factor and I'm not > using pure-Ethernet platforms so it's just a matter of adding the right > interface card. The cost difference on a ~40Mb/s circuit might not be much different delivered via T3 or Ethernet, but what about anything faster? Ethernet readily scales to 1Gb/s and 10Gb/s is not unreasonable these days. 40Gb/s and 100Gb/s Ethernet will be here in a year or two. Even if you start out with a 100Mb/s Ethernet port you won't have to bond interfaces or move to more expensive electronics to go past ~40Mb/s. > How do you detect a "down" condition on Ethernet? My experience is that > the interface could be up/up because Ethernet doesn't know about > anything further down the line and ends up throwing packets into a > magical black hole. Or worse, secret packet loss. There's nothing unique to Ethernet about that... > Can you even troubleshoot Ethernet? Normally if I'm seeing something > like out of frame errors or AIS, I can say "hey, there's a problem and > it's X". It scares me to think of opening trouble tickets as "it's > broken and I can't really tell you why". Stick a PC directly onto your WAN connection (or stick a switch in there and use port spanning) and run Wireshark. Try that with a T3 connection. > With a T3 I can be fairly certain that if there aren't any alarms that > my end is happily talking to the other end. How does one accomplish the > same with Ethernet? The Ethernet protocol includes CRC checks so most hardware will detect packet errors. Sure, the CRC isn't perfect and you can construct pathological examples where corrupted packets will pass the CRC checks but > A periodic "ping" seems rather ambiguous as a health > check. You'd want to do something like this anyway, since the alarms on a T3 are only a layer 1 check, pings check to make sure that things are working at least up through layer 3. As others have stated, running a dynamic routing protocol across the link gives even more assurance that packets aren't going into a black hole. -- Jeff Ollie From ler762 at gmail.com Wed Apr 8 09:20:30 2009 From: ler762 at gmail.com (Lee) Date: Wed, 8 Apr 2009 09:20:30 -0400 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <49DC4EEC.3070001@rollernet.us> References: <49DC4EEC.3070001@rollernet.us> Message-ID: For us, price =is= the deciding factor. A 45Mb ethernet service costs us much less than a real T3. We replaced a T3 circuit with a 45Mb ethernet service and then discovered that the RTT went from 12ms on the T3 to 39ms on the ethernet circuit. Much discussion with the provider about re-engineering the circuit to get the RTT down and then much more waiting for them to schedule a service window ... and we've now got a 35ms RTT. Another 'gotcha' is MTU size. It's trivially easy to run IPSec over a T3 without fragmenting packets. Ethernet however... we ended up dumping one provider because they (w|c)ouldn't give us more than a 1524 [?not sure] byte MTU. A nice thing about getting ethernet service is that more bandwidth is just a phone call away. We bumped the speed up from 45 to 100Mb and are still paying less for the 100Mb ethernet service than we were for the T3. Still have that 35ms RTT though.. Input access lists that end with "deny ip any any log-input" are your friend. We just brought up a new circuit & I was seeing strange stuff hitting our router. Call the provider (who is my new love - the person answering the phone was the person that fixed the problem ... while I was on the phone!! ), give 'em the offending IP address and get told it's a pure L2 network on their side. *sigh* change the access-list from log to log-input, give him the offending MAC address, he finds the offending box & fixes the config. If you care at all about keeping your data private, put everything inside an IPSec tunnel. You have no idea who/what else is on that same ethernet circuit. If you care at all about throwing your packets into a black-hole, run a routing protocol over the tunnel. If you care at all about actually using the bandwidth you're paying for, get the hardware crypto accelerator card for your platform. > ... It scares me to think of opening trouble tickets as "it's > broken and I can't really tell you why". Welcome to user-land :) Just remember to act like a real user and lie when they ask you to reboot the box & see if that fixes the problem. HTH, Lee On 4/8/09, Seth Mattinen wrote: > One of my carriers has given me a choice for a new circuit delivery: T3 > or Ethernet. My outside world circuit experience is all non-Ethernet, so > I have a few questions the sales group wasn't able to answer. I'd love > to hear some real world experience. The cost difference between the two > is not significant enough to be the sole deciding factor and I'm not > using pure-Ethernet platforms so it's just a matter of adding the right > interface card. > > How do you detect a "down" condition on Ethernet? My experience is that > the interface could be up/up because Ethernet doesn't know about > anything further down the line and ends up throwing packets into a > magical black hole. Or worse, secret packet loss. > > Can you even troubleshoot Ethernet? Normally if I'm seeing something > like out of frame errors or AIS, I can say "hey, there's a problem and > it's X". It scares me to think of opening trouble tickets as "it's > broken and I can't really tell you why". > > With a T3 I can be fairly certain that if there aren't any alarms that > my end is happily talking to the other end. How does one accomplish the > same with Ethernet? A periodic "ping" seems rather ambiguous as a health > check. > > Since this is an outside world connection (i.e. I'm not in a colo) the > slightly lower cost and convenience factor of Ethernet doesn't override > my desire to stick with a T3 for its management properties and the > sleeping good at night feeling I get knowing there are no alarms. My gut > tells me to stick with it even though Ethernet delivery is what all the > cool kids are doing these days, so any insight is appreciated. Thanks! > > ~Seth > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From ler762 at gmail.com Wed Apr 8 09:38:14 2009 From: ler762 at gmail.com (Lee) Date: Wed, 8 Apr 2009 09:38:14 -0400 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 In-Reply-To: References: <49DB1C06.60506@memetic.org> <20090407094208.GZ290@greenie.muc.de> <49DB2315.5010806@memetic.org> Message-ID: On 4/7/09, Bill Wichers wrote: > [snip] >> > ... and the context of *this* discussion is likely involving PA-FE-TX's, >> > which are "quite old hardware", and cannot do any sort of autoneg. >> > >> True, so the ports should probably be nailed to full at both sides. > > Correct, they are PA-FE-TX's. There are two such PAs in a VIP2-50, and > those are running the port channel. <.. snip ..> > > I typically set both ends (router and switch) of these links to 100/full > since I've seen weird autonegotiation problems before. This works just > fine for individual FE links, but as soon as I bring up the Etherchannel > group both member links on the router end drop back to "unknown duplex" Can you configure the etherchannel group interface as 100/full? Lee From andreir at gmail.com Wed Apr 8 10:01:19 2009 From: andreir at gmail.com (Andrei Radu) Date: Wed, 8 Apr 2009 17:01:19 +0300 Subject: [c-nsp] carrier router models comparison In-Reply-To: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> References: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> Message-ID: <74206b240904080701t75420f7dqd1298597e246008c@mail.gmail.com> Hello Manu, Well the Foundry MLX/XMR is a layer 2 switching platform that evolved into a layer 3 switching platform that evolved into a mpls switching platform much like the 6500/7600. The MLX and XMR are basically the same hardware sold as the core switching platform and the core routing platform (rings a bell ?). Also much like the 6500/7600 it has a TCAM based forwarding engine, as opposed to the programmable ASIC the make up the CRS or the Juniper forwarding engines, which in itself holds many limitations. So you really are comparing apples and pears when comparing the CRS/T-series with the XMR (or the 7600 for that matter). This pretty much explains the price difference. The software pretty similar to IOS (not XR) at least at the CLI level, don't know about the internals. If you follow the foundry-nsp mailing list, and also the ams-ix mailing list you will see that Foundry has their share of software bugs, ranging from "normal" to forwarding entries disappearing from the hardware fib. Also if I remember correctly the MLX/XMRs are 40G/slot and not 50G/slot (although the platform is 100G/slot ready, actually decix decided to migrate it's core to the Foundry MLX 32000 because Force10 is having trouble going to 100G/slot). Hope this helps. Maybe the nanog or the f-nsp folks have a little more info for you. On Tue, Apr 7, 2009 at 6:51 PM, Emanuel Popa wrote: > hi there, > > due to the increase in traffic volume in the last couple of years we > need to really think about the future of the network. we have deployed > and we are managing a 50GE multi-ring topology network with Cisco 7600 > routers. i don't want to get into more details about ring topology > restrictions, platform limitations regarding wire speed, huge problems > with ether-channels or unpredictable load balancing behaviour. we've > been using these chassis since 2004 starting with STM-16 lines and the > PQ ratio looks pretty good so far. > > coming back to nowadays, 40GE or 100GE is not available yet, and even > if it was, the price would be probably unaffordable. and now the > question pops: what is the next step? the best answer is of course a > mix of multiple 10GE lines with traffic engineering and partial mesh > topology and 100GE ready chassis. first thing that comes to mind is > the CRS-1 platform, but it is really expensive: from under 15K per > 10GE port with the Cisco 7600 you have to pay more than 75K per 10GE > port with the CRS-1. so we have to take into consideration what are > the alternatives. i will try a short comparison: > > - Cisco CRS-1 16 Slot > --- max 64 x 10GE > --- max 32 links in a bundle > --- 40Gbps per slot > --- 100GE ready > --- multi-chassis ready > --- 10.920W max power > --- 723kg max weight > --- full rack space > --- $5.115.000,00/chassis > --- $79.921,88/10GE > > - Juniper T1600 > --- max 64 x 10GE > --- max 16 links in a bundle > --- 100Gbps per slot > --- 100GE ready > --- multi-chassis ready > --- 8.352W max power > --- 274,88kg max weight > --- 1/2 rack space > --- $6.547.000,00/chassis > --- $102.296,88/10GE > > - Brocade/ Foundry NetIron XMR 16000 > --- max 64 x 10GE > --- max 32 links in a bundle > --- 50Gbps per slot > --- 100GE ready (* only full slots) > --- single-chassis > --- 5.572W max power > --- 107,00kg max weight > --- 1/3 rack space > --- $567.515,00/chassis > --- $8.867,42/10GE > > I've also been looking at Huawei, Alcatel and HP gear but haven't been > able to find a device to support more than 24 x 10GE ports in a single > chassis. > > Here's what I'm trying to figure out: > > 1. are there any other devices on the market with same hardware capabilities? > > 2. why the huge difference between foundry and cisco/juniper? > > 3. if foundry is so cheap why hasn't it gathered more market share? > instead it was bought by brocade a while ago... > > 4. is the netiron really a carrier router more than a carrier switch? > anybody experienced it? > > 5. how does the software perform when comparing with IOS XR and JunOS? > > Please, any comments are welcomed. > > Best regards, > Manu > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > -- Andrei "2+2=5, for extremely large values of 2 !" From SMESIATO at petro-canada.ca Wed Apr 8 10:07:39 2009 From: SMESIATO at petro-canada.ca (Mesiatowsky, Shawn) Date: Wed, 8 Apr 2009 08:07:39 -0600 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <49DC4EEC.3070001@rollernet.us> References: <49DC4EEC.3070001@rollernet.us> Message-ID: <259E69AA141E7640822757CAB3EBC70F18B1D0DBED@MSG-M1P1.pcacorp.net> to detect a failure when the link is still up, you can use ip sla to ping the downstream router. You can then use embedded event manager to track your sla and trigger an event upon failure. The event could be to email you, send an snmp trap, or run a tcl script such as changing static routes. The embedded event manager in IOS is very powerful. -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Seth Mattinen Sent: Wednesday, April 08, 2009 1:15 AM To: cisco-nsp Subject: [c-nsp] T3 or Ethernet delivery? One of my carriers has given me a choice for a new circuit delivery: T3 or Ethernet. My outside world circuit experience is all non-Ethernet, so I have a few questions the sales group wasn't able to answer. I'd love to hear some real world experience. The cost difference between the two is not significant enough to be the sole deciding factor and I'm not using pure-Ethernet platforms so it's just a matter of adding the right interface card. How do you detect a "down" condition on Ethernet? My experience is that the interface could be up/up because Ethernet doesn't know about anything further down the line and ends up throwing packets into a magical black hole. Or worse, secret packet loss. Can you even troubleshoot Ethernet? Normally if I'm seeing something like out of frame errors or AIS, I can say "hey, there's a problem and it's X". It scares me to think of opening trouble tickets as "it's broken and I can't really tell you why". With a T3 I can be fairly certain that if there aren't any alarms that my end is happily talking to the other end. How does one accomplish the same with Ethernet? A periodic "ping" seems rather ambiguous as a health check. Since this is an outside world connection (i.e. I'm not in a colo) the slightly lower cost and convenience factor of Ethernet doesn't override my desire to stick with a T3 for its management properties and the sleeping good at night feeling I get knowing there are no alarms. My gut tells me to stick with it even though Ethernet delivery is what all the cool kids are doing these days, so any insight is appreciated. Thanks! ~Seth _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ This email communication is intended as a private communication for the sole use of the primary addressee and those individuals listed for copies in the original message. The information contained in this email is private and confidential and If you are not an intended recipient you are hereby notified that copying, forwarding or other dissemination or distribution of this communication by any means is prohibited. If you are not specifically authorized to receive this email and if you believe that you received it in error please notify the original sender immediately. We honour similar requests relating to the privacy of email communications. Cette communication par courrier ?lectronique est une communication priv?e ? l'usage exclusif du destinataire principal ainsi que des personnes dont les noms figurent en copie. Les renseignements contenus dans ce courriel sont confidentiels et si vous n'?tes pas le destinataire pr?vu, vous ?tes avis?, par les pr?sentes que toute reproduction, transfert ou autre forme de diffusion de cette communication par quelque moyen que ce soit est interdite. Si vous n'?tes pas sp?cifiquement autoris? ? recevoir ce courriel ou si vous croyez l'avoir re?u par erreur, veuillez en aviser l'exp?diteur original imm?diatement. Nous respectons les demandes similaires qui touchent la confidentialit? des communications par courrier ?lectronique. From jlewis at lewis.org Wed Apr 8 10:08:10 2009 From: jlewis at lewis.org (Jon Lewis) Date: Wed, 8 Apr 2009 10:08:10 -0400 (EDT) Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <935ead450904080618k15aa5c2bo23acf3dac7005e9c@mail.gmail.com> References: <49DC4EEC.3070001@rollernet.us> <935ead450904080618k15aa5c2bo23acf3dac7005e9c@mail.gmail.com> Message-ID: On Wed, 8 Apr 2009, Jeffrey Ollie wrote: >> How do you detect a "down" condition on Ethernet? My experience is that >> the interface could be up/up because Ethernet doesn't know about >> anything further down the line and ends up throwing packets into a >> magical black hole. Or worse, secret packet loss. > > There's nothing unique to Ethernet about that... No, but with ethernet, it's more likely that there's going to be a layer 2 "local device" (i.e. a switch) which you connect to, but the layer 3 next hop is somewhere off on the providers network in another building. When the network breaks somewhere between the provider's L3 next hop and your location, you'll still be up/up, but have no connectivity. With BGP, you might tune the timers shorter than default so that such a break gets noticed sooner. With a T3, BGP would find out about the break as soon as the interface went down. With ethernet, it's also somewhat easier for your provider to screw things up. I've dealt with several instances where a carrier managed to combine multiple customer VLANs and mix traffic to/from unrelated customers. I've seen similar things once on a DS3 though, so it's not impossible there...just much less likely. Ethernet is generally much cheaper for interfaces. ---------------------------------------------------------------------- Jon Lewis | I route Senior Network Engineer | therefore you are Atlantic Net | _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________ From jason at fidelityaccess.com Wed Apr 8 10:11:57 2009 From: jason at fidelityaccess.com (Jason Gintert) Date: Wed, 08 Apr 2009 10:11:57 -0400 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: Message-ID: I would go with Ethernet services just for the sheer flexibility. With regard to your concerns of monitoring link state, you can use Ethernet demarcation devices such as the ISG 2X series from Overture to solve that. Think of it as an Ethernet "Smart Jack". It provides some pretty neat testing capabilities (looping, layer 2 ping, etc) and can do things like fault propagation per EVC. This means you can have a heartbeat across a VLAN (you'll need Ethernet Demarcation devices on either side) so if the heartbeat between devices is lost on the network side it can drop interface state to your equipment facing ports. Lastly, there are some great SLA tools to verify your provider is giving you the service that you are paying for. I recommend them highly. http://www.overturenetworks.com/products/name/ISG2x.html Jason > Date: Wed, 08 Apr 2009 00:14:52 -0700 > From: Seth Mattinen > Subject: [c-nsp] T3 or Ethernet delivery? > To: cisco-nsp > Message-ID: <49DC4EEC.3070001 at rollernet.us> > Content-Type: text/plain; charset=UTF-8 > > One of my carriers has given me a choice for a new circuit delivery: T3 > or Ethernet. My outside world circuit experience is all non-Ethernet, so > I have a few questions the sales group wasn't able to answer. I'd love > to hear some real world experience. The cost difference between the two > is not significant enough to be the sole deciding factor and I'm not > using pure-Ethernet platforms so it's just a matter of adding the right > interface card. > > How do you detect a "down" condition on Ethernet? My experience is that > the interface could be up/up because Ethernet doesn't know about > anything further down the line and ends up throwing packets into a > magical black hole. Or worse, secret packet loss. > > Can you even troubleshoot Ethernet? Normally if I'm seeing something > like out of frame errors or AIS, I can say "hey, there's a problem and > it's X". It scares me to think of opening trouble tickets as "it's > broken and I can't really tell you why". > > With a T3 I can be fairly certain that if there aren't any alarms that > my end is happily talking to the other end. How does one accomplish the > same with Ethernet? A periodic "ping" seems rather ambiguous as a health > check. > > Since this is an outside world connection (i.e. I'm not in a colo) the > slightly lower cost and convenience factor of Ethernet doesn't override > my desire to stick with a T3 for its management properties and the > sleeping good at night feeling I get knowing there are no alarms. My gut > tells me to stick with it even though Ethernet delivery is what all the > cool kids are doing these days, so any insight is appreciated. Thanks! > > ~Seth From dudepron at gmail.com Wed Apr 8 10:32:11 2009 From: dudepron at gmail.com (Aaron) Date: Wed, 8 Apr 2009 10:32:11 -0400 Subject: [c-nsp] SIP-400 and 10GbE SPA In-Reply-To: <49DAA86B.5070306@lists.esoteric.ca> References: <49DAA86B.5070306@lists.esoteric.ca> Message-ID: <480dad640904080732t1746096aie1c92ba31f712b21@mail.gmail.com> It might be supported but you don't get 10GB with it. Aaron On Mon, Apr 6, 2009 at 21:12, Stephen Fulton wrote: > According to the SIP/SPA compatibility matrix: > > > http://www.cisco.com/en/US/docs/interfaces_modules/shared_port_adapters/install_upgrade/7600series/76intro.html#wp1131939 > > The SPA-1X10GE-L-V2 is compatible with SIP-400. > > As always, verify with your Cisco SE. > > -- Stephen > > > MKS wrote: > >> Hi There >> >> According to cisco SIP-400 can >> "Ability to run 4 GE line rate for 64-byte packets, and OC-48 line >> rate for 48-byte packets for POS, HDLC, etc. with select services" >> >> https://www.cisco.com/en/US/prod/collateral/routers/ps368/product_data_sheet0900aecd8027c9e6.html >> >> Can someone please clarify what exactly this means. >> >> Also if I put a 10GbE SPA into a SIP-400 what is the expected >> performance of that? >> >> Thanks >> //MKS >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From dudepron at gmail.com Wed Apr 8 10:42:46 2009 From: dudepron at gmail.com (Aaron) Date: Wed, 8 Apr 2009 10:42:46 -0400 Subject: [c-nsp] Max length of 9600 serial over CAT5e In-Reply-To: <49DC8B1A.2000501@exa-networks.co.uk> References: <49DC7BBE.50906@spacething.org> <49DC8B1A.2000501@exa-networks.co.uk> Message-ID: <480dad640904080742v3c7ed5a2g36d662f9782c99cd@mail.gmail.com> Nom. Capacitance @ 1 KHz:15 pF/ft. for cat 5e On Wed, Apr 8, 2009 at 07:31, Richard Halfpenny < richard.halfpenny at exa-networks.co.uk> wrote: > Sam Stickland wrote: > >> Hi, >> >> What's the maximum length of you can run async-serial (9600 baud) >> over CAT5e (from a terminal server to console port). >> >> My google-fu has failed me. >> > > If I remember correctly, the spec for RS-232 says the maximum capacitance > of a cable can be 2500pF at 20kbps. A Cat5e of approx 46pF / metre would > give you a maximum length of 54 metres. At 9600bps you could probably drive > slightly longer. > > Rich > > -- > Network Operations > Exa Networks Ltd :: AS30740 > richard.halfpenny at exa-networks.co.uk > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From dudepron at gmail.com Wed Apr 8 11:25:42 2009 From: dudepron at gmail.com (Aaron) Date: Wed, 8 Apr 2009 11:25:42 -0400 Subject: [c-nsp] 2600 series for 100M In-Reply-To: <40d8a95a0904080509t3955662bod20a1fc36b8353c9@mail.gmail.com> References: <40d8a95a0904080509t3955662bod20a1fc36b8353c9@mail.gmail.com> Message-ID: <480dad640904080825o3f1103dj9ec0c595cf614172@mail.gmail.com> You don't say want services you are planning on running. Full-bgp? That would have an impact on memory requirements. On Wed, Apr 8, 2009 at 08:09, Deric Kwok wrote: > Hi > > Do you know Cisco 2651XM is fine for 100M network? > > If the memory is 256M, it is ok? > > Can it support Virtual private network, VLAN and new tcsh command? > > i check the ios is "C2600 Software (C2600-ENTSERVICESK9-M), Version > 12.3(23)" > > Do I need to buy any extra memory? > > Thank you > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From psirt at cisco.com Wed Apr 8 12:01:39 2009 From: psirt at cisco.com (Cisco Systems Product Security Incident Response Team) Date: Wed, 8 Apr 2009 12:01:39 -0400 Subject: [c-nsp] Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances Message-ID: <200904081201.asa@psirt.cisco.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA Adaptive Security Appliance and Cisco PIX Security Appliances Advisory ID: cisco-sa-20090408-asa http://www.cisco.com/warp/public/707/cisco-sa-20090408-asa.shtml Revision 1.0 For Public Release 2009 April 08 1600 UTC (GMT) Summary ======= Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. This security advisory outlines the details of these vulnerabilities: * VPN Authentication Bypass when Account Override Feature is Used vulnerability * Crafted HTTP packet denial of service (DoS) vulnerability * Crafted TCP Packet DoS vulnerability * Crafted H.323 packet DoS vulnerability * SQL*Net packet DoS vulnerability * Access control list (ACL) bypass vulnerability Workarounds are available for some of the vulnerabilities. This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20090408-asa.shtml. Affected Products ================= Vulnerable Products +------------------ The following is a list of the products affected by each vulnerability as described in detail within this advisory. VPN Authentication Bypass Vulnerability +-------------------------------------- Cisco ASA or Cisco PIX security appliances that are configured for IPsec or SSL-based remote access VPN and have the Override Account Disabled feature enabled are affected by this vulnerability. Note: The Override Account Disabled feature was introduced in Cisco ASA software version 7.1(1). Cisco ASA and PIX software versions 7.1, 7.2, 8.0, and 8.1 are affected by this vulnerability. This feature is disabled by default. Crafted HTTP Packet DoS Vulnerability +------------------------------------ Cisco ASA security appliances may experience a device reload that can be triggered by a series of crafted HTTP packets, when configured for SSL VPNs or when configured to accept Cisco Adaptive Security Device Manager (ASDM) connections. Only Cisco ASA software versions 8.0 and 8.1 are affected by this vulnerability. Crafted TCP Packet DoS Vulnerability +----------------------------------- Cisco ASA and Cisco PIX security appliances may experience a memory leak that can be triggered by a series of crafted TCP packets. Cisco ASA and Cisco PIX security appliances running versions 7.0, 7.1, 7.2, 8.0, and 8.1 are affected when configured for any of the following features: * SSL VPNs * ASDM Administrative Access * Telnet Access * SSH Access * Cisco Tunneling Control Protocol (cTCP) for Remote Access VPNs * Virtual Telnet * Virtual HTTP * Transport Layer Security (TLS) Proxy for Encrypted Voice Inspection * Cut-Through Proxy for Network Access * TCP Intercept Crafted H.323 Packet DoS Vulnerability +------------------------------------- Cisco ASA and Cisco PIX security appliances may experience a device reload that can be triggered by a series of crafted H.323 packets, when H.323 inspection is enabled. H.323 inspection is enabled by default. Cisco ASA and Cisco PIX software versions 7.0, 7.1, 7.2, 8.0, and 8.1 are affected by this vulnerability. SQL*Net Packet DoS Vulnerability +------------------------------- Cisco ASA and Cisco PIX security appliances may experience a device reload that can be triggered by a series of SQL*Net packets, when SQL*Net inspection is enabled. SQL*Net inspection is enabled by default. Cisco ASA and Cisco PIX software versions 7.2, 8.0, and 8.1 are affected by this vulnerability. Access Control List Bypass Vulnerability +--------------------------------------- A vulnerability exists in the Cisco ASA and Cisco PIX security appliances that may allow traffic to bypass the implicit deny behavior at the end of ACLs that are configured within the device. Cisco ASA and Cisco PIX software versions 7.0, 7.1, 7.2, and 8.0 are affected by this vulnerability. Determination of Software Versions +--------------------------------- The "show version" command-line interface (CLI) command can be used to determine whether a vulnerable version of the Cisco PIX or Cisco ASA software is running. The following example shows a Cisco ASA Adaptive Security Appliance that runs software version 8.0(4): ASA#show version Cisco Adaptive Security Appliance Software Version 8.0(4) Device Manager Version 6.0(1) The following example shows a Cisco PIX security appliance that runs software version 8.0(4): PIX#show version Cisco PIX Security Appliance Software Version 8.0(4) Device Manager Version 5.2(3) Customers who use Cisco ASDM to manage their devices can find the software version displayed in the table in the login window or in the upper left corner of the ASDM window. Products Confirmed Not Vulnerable +-------------------------------- The Cisco Firewall Services Module (FWSM) for Cisco Catalyst 6500 Series switches and Cisco 7600 Series routers and Cisco VPN 3000 Series Concentrators are not affected by any of these vulnerabilities. Cisco PIX Security Appliance Software versions 6.x are not affected by any of these vulnerabilities. No other Cisco products are currently known to be affected by these vulnerabilities. Details ======= This Security Advisory describes multiple distinct vulnerabilities. These vulnerabilities are independent of each other. VPN Authentication Bypass Vulnerability +-------------------------------------- The Cisco ASA or Cisco PIX security appliance can be configured to override an account-disabled indication from a AAA server and allow the user to log on anyway. However, the user must provide the correct credentials in order to login to the VPN. A vulnerability exists in the Cisco ASA and Cisco PIX security appliances where VPN users can bypass authentication when the override account feature is enabled. Note: The override account feature was introduced in Cisco ASA software version 7.1(1). The override account feature is enabled with the "override-account-disable" command in "tunnel-group general-attributes" configuration mode, as shown in the following example. The following example allows overriding the "account-disabled" indicator from the AAA server for the WebVPN tunnel group "testgroup": hostname(config)#tunnel-group testgroup type webvpn hostname(config)#tunnel-group testgroup general-attributes hostname(config-tunnel-general)#override-account-disable Note: The override account feature is disabled by default. This vulnerability is documented in Cisco Bug ID CSCsx47543 and has been assigned Common Vulnerabilities and Exposures (CVE) identifiers CVE-2009-1155. Crafted HTTP Packet DoS Vulnerability +------------------------------------ A crafted SSL or HTTP packet may cause a DoS condition on a Cisco ASA device that is configured to terminate SSL VPN connections. This vulnerability can also be triggered to any interface where ASDM access is enabled. A successful attack may result in a reload of the device. A TCP three-way handshake is not needed to exploit this vulnerability. This vulnerability is documented in Cisco Bug ID CSCsv52239 and has been assigned Common Vulnerabilities and Exposures (CVE) identifiers CVE-2009-1156. Crafted TCP Packet DoS Vulnerability +----------------------------------- A crafted TCP packet may cause a memory leak on a Cisco ASA or Cisco PIX device. A successful attack may result in a sustained DoS condition. A Cisco ASA device configured for any of the following features is affected: * SSL VPNs * ASDM Administrative Access * Telnet Access * SSH Access * cTCP for Remote Access VPNs * Virtual Telnet * Virtual HTTP * TLS Proxy for Encrypted Voice Inspection * Cut-Through Proxy for Network Access * TCP Intercept Note: This vulnerability may be triggered when crafted packets are sent to any TCP based service that terminates on the affected device. The vulnerability may also be triggered via transient traffic only if the TCP intercept features has been enabled. A TCP three-way handshake is not needed to exploit this vulnerability. This vulnerability is documented in Cisco Bug ID CSCsy22484 and has been assigned Common Vulnerabilities and Exposures (CVE) identifiers CVE-2009-1157. Crafted H.323 Packet DoS Vulnerability +------------------------------------- A crafted H.323 packet may cause a DoS condition on a Cisco ASA device that is configured with H.323 inspection. H.323 inspection is enabled by default. A successful attack may result in a reload of the device. A TCP three-way handshake is not needed to exploit this vulnerability. This vulnerability is documented in Cisco Bug ID CSCsx32675 and has been assigned Common Vulnerabilities and Exposures (CVE) identifiers CVE-2009-1158. SQL*Net Packet DoS Vulnerability +------------------------------- The SQL*Net protocol consists of different packet types are handled by the security appliance to make the data stream appear consistent to the Oracle version 7.x and earlier implementations on either side of the Cisco ASA and Cisco PIX security appliances. A series of SQL*Net packets may cause a denial of service condition on a Cisco ASA and Cisco PIX device that is configured with SQL*Net inspection. SQL*Net inspection is enabled by default. A successful attack may result in a reload of the device. The default port assignment for SQL*Net is TCP port 1521. This is the value used by Oracle for SQL*Net. Please note the "class-map" command can be used in the Cisco ASA or Cisco PIX to apply SQL*Net inspection to a range of different port numbers. A TCP three-way handshake is needed to exploit this vulnerability. The requirement of a TCP three way handshake significantly reduces the possibility of exploitation using packets with spoofed source addresses. This vulnerability is documented in Cisco Bug ID CSCsw51809 and has been assigned Common Vulnerabilities and Exposures (CVE) identifiers CVE-2009-1159. Access Control List Bypass Vulnerability +--------------------------------------- Access lists have an implicit deny behavior that is applied to packets that have not matched any of the permit or deny ACEs in an ACL and reach the end of the ACL. This implicit deny is there by design, does not require any configuration and can be understood as an implicit ACE that denies all traffic reaching the end of the ACL. A vulnerability exists in the Cisco ASA and Cisco PIX that may allow traffic to bypass the implicit deny ACE. Note: This behavior only impacts the implicit deny statement on any ACL applied on the device. Access control lists with explicit deny statements are not affected by this vulnerability. This vulnerability is experienced in very rare occasions and extremely hard to reproduce. You can trace the lifespan of a packet through the security appliance to see whether the packet is operating correctly with the packet tracer tool. The "packet-tracer" command provides detailed information about the packets and how they are processed by the security appliance. If a command from the configuration did not cause the packet to drop, the "packet-tracer" command will provide information about the cause in an easily readable manner. You can use this feature to see if the implicit deny on an ACL is not taking effect. The following example shows that the implicit deny is bypassed (result = ALLOW): ... Phase: 2 Type: ACCESS-LIST Subtype: Result: ALLOW Config: Implicit Rule Additional Information: Forward Flow based lookup yields rule: in id=0x1a09d350, priority=1, domain=permit, deny=false hits=1144595557, user_data=0x0, cs_id=0x0, l3_type=0x8 src mac=0000.0000.0000, mask=0000.0000.0000 dst mac=0000.0000.0000, mask=0000.0000.0000 This vulnerability is documented in Cisco Bug ID CSCsq91277 and has been assigned Common Vulnerabilities and Exposures (CVE) identifiers CVE-2009-1160. Vulnerability Scoring Details +---------------------------- Cisco has provided scores for the vulnerabilities in this advisory based on the Common Vulnerability Scoring System (CVSS). The CVSS scoring in this Security Advisory is done in accordance with CVSS version 2.0. CVSS is a standards-based scoring method that conveys vulnerability severity and helps determine urgency and priority of response. Cisco has provided a base and temporal score. Customers can then compute environmental scores to assist in determining the impact of the vulnerability in individual networks. Cisco has provided an FAQ to answer additional questions regarding CVSS at: http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html Cisco has also provided a CVSS calculator to help compute the environmental impact for individual networks at: http://intellishield.cisco.com/security/alertmanager/cvss * AAA account-override-ignore allows VPN session without correct password (CSCsx47543) CVSS Base Score - 7.8 Access Vector - Network Access Complexity - Low Authentication - None Confidentiality Impact - Complete Integrity Impact - None Availability Impact - None CVSS Temporal Score - 6.8 Exploitability - High Remediation Level - Official-Fix Report Confidence - Confirmed * Cisco ASA may crash with certain HTTP packets (CSCsv52239) CVSS Base Score - 7.8 Access Vector - Network Access Complexity - Low Authentication - None Confidentiality Impact - None Integrity Impact - None Availability Impact - Complete CVSS Temporal Score - 6.4 Exploitability - Functional Remediation Level - Official-Fix Report Confidence - Confirmed * Cisco ASA may crash after processing certain TCP packets (CSCsy22484) CVSS Base Score - 7.8 Access Vector - Network Access Complexity - Low Authentication - None Confidentiality Impact - None Integrity Impact - None Availability Impact - Complete CVSS Temporal Score - 6.4 Exploitability - Functional Remediation Level - Official-Fix Report Confidence - Confirmed * Crafted H.323 packet may cause ASA to reload (CSCsx32675) CVSS Base Score - 7.8 Access Vector - Network Access Complexity - Low Authentication - None Confidentiality Impact - None Integrity Impact - None Availability Impact - Complete CVSS Temporal Score - 6.4 Exploitability - Functional Remediation Level - Official-Fix Report Confidence - Confirmed * sqlnet traffic causes traceback with inspection configured (CSCsw51809) CVSS Base Score - 7.8 Access Vector - Network Access Complexity - Low Authentication - None Confidentiality Impact - None Integrity Impact - None Availability Impact - Complete CVSS Temporal Score - 6.4 Exploitability - High Remediation Level - Official-Fix Report Confidence - Confirmed * ACL Misbehavior in Cisco ASA (CSCsq91277) CVSS Base Score - 4.3 Access Vector - Network Access Complexity - Medium Authentication - None Confidentiality Impact - Partial Integrity Impact - None Availability Impact - None CVSS Temporal Score - 3.6 Exploitability - Functional Remediation Level - Official-Fix Report Confidence - Confirmed Impact ====== Successful exploitation of the VPN Authentication Bypass when Account Override Feature is Used vulnerability may allow an attacker to successfully connect to the Cisco ASA via remote access IPSec or SSL-based VPN. The Denial of Service (DoS) vulnerabilities may cause a reload of the affected device. Repeated exploitation could result in a sustained DoS condition. Successful exploitation of the ACL bypass vulnerability may allow an attacker to access resources that should be protected by the Cisco ASA. Software Versions and Fixes =========================== When considering software upgrades, also consult http://www.cisco.com/go/psirt and any subsequent advisories to determine exposure and a complete upgrade solution. In all cases, customers should exercise caution to be certain the devices to be upgraded contain sufficient memory and that current hardware and software configurations will continue to be supported properly by the new release. If the information is not clear, contact the Cisco Technical Assistance Center (TAC) or your contracted maintenance provider for assistance. The following table contains the first fixed software release of each vulnerability. The "Recommended Release" row indicates the releases which have fixes for all the published vulnerabilities at the time of this Advisory. A device running a version of the given release in a specific row (less than the First Fixed Release) is known to be vulnerable. Cisco recommends upgrading to a release equal to or later than the release in the "Recommended Release" row of the table. +------------------------------------------------------+ | | Affected | First | Recommended | | Vulnerability | Release | Fixed | Release | | | | Version | | |----------------+----------+------------+-------------| | | 7.0 | Not | 7.0(8)6 | | VPN | | vulnerable | | |Authentication |----------+------------+-------------| | Bypass when | 7.1 | 7.1(2)82 | 7.1(2)82 | |Account |----------+------------+-------------| | Override | 7.2 | 7.2(4)27 | 7.2(4)30 | |Feature is |----------+------------+-------------| | Used | 8.0 | 8.0(4)25 | 8.0(4)28 | |Vulnerability |----------+------------+-------------| | | 8.1 | 8.1(2)15 | 8.1(2)19 | |----------------+----------+------------+-------------| | | 7.0 | Not | 7.0(8)6 | | | | vulnerable | | | |----------+------------+-------------| | | 7.1 | Not | 7.1(2)82 | | Crafted HTTP | | vulnerable | | |packet DoS |----------+------------+-------------| | Vulnerability | 7.2 | Not | 7.2(4)30 | | | | vulnerable | | | |----------+------------+-------------| | | 8.0 | 8.0(4)25 | 8.0(4)28 | | |----------+------------+-------------| | | 8.1 | 8.1(2)15 | 8.1(2)16 | |----------------+----------+------------+-------------| | | 7.0 | 7.0(8)6 | 7.0(8)6 | | |----------+------------+-------------| | | 7.1 | 7.1(2)82 | 7.1(2)82 | |Crafted TCP |----------+------------+-------------| | Packet DoS | 7.2 | 7.2(4)30 | 7.2(4)30 | |Vulnerability |----------+------------+-------------| | | 8.0 | 8.0(4)28 | 8.0(4)28 | | |----------+------------+-------------| | | 8.1 | 8.1(2)19 | 8.1(2)19 | |----------------+----------+------------+-------------| | | 7.0 | 7.0(8)6 | 7.0(8)6 | | |----------+------------+-------------| | | 7.1 | 7.1(2)82 | 7.1(2)82 | |Crafted H.323 |----------+------------+-------------| | packet DoS | 7.2 | 7.2(4)26 | 7.2(4)30 | |Vulnerability |----------+------------+-------------| | | 8.0 | 8.0(4)24 | 8.0(4)28 | | |----------+------------+-------------| | | 8.1 | 8.1(2)14 | 8.1(2)19 | |----------------+----------+------------+-------------| | | 7.0 | Not | 7.0(8)6 | | | | vulnerable | | | |----------+------------+-------------| | | 7.1 | Not | 7.1(2)82 | | Crafted SQL | | vulnerable | | |packet DoS |----------+------------+-------------| | vulnerability | 7.2 | 7.2(4)26 | 7.2(4)30 | | |----------+------------+-------------| | | 8.0 | 8.0(4)22 | 8.0(4)28 | | |----------+------------+-------------| | | 8.1 | 8.1(2)12 | 8.1(2)19 | |----------------+----------+------------+-------------| | | 7.0 | 7.0(8)1 | 7.0(8)6 | | |----------+------------+-------------| | | 7.1 | 7.1(2)74 | 7.1(2)82 | |Access control |----------+------------+-------------| | list (ACL) | 7.2 | 7.2(4)9 | 7.2(4)30 | |bypass |----------+------------+-------------| | vulnerability | 8.0 | 8.0(4)5 | 8.0(4)28 | | |----------+------------+-------------| | | 8.1 | Not | 8.1(2)19 | | | | vulnerable | | +------------------------------------------------------+ Fixed Cisco ASA software can be downloaded from: http://www.cisco.com/pcgi-bin/tablebuild.pl/ASAPSIRT Fixed Cisco PIX software can be downloaded from: http://www.cisco.com/pcgi-bin/tablebuild.pl/PIXPSIRT Workarounds =========== This Security Advisory describes multiple distinct vulnerabilities. These vulnerabilities and their respective workarounds are independent of each other. VPN Authentication Bypass Vulnerability +-------------------------------------- The override account feature is enabled with the "override-account-disable" command in "tunnel-group general-attributes" configuration mode. As a workaround, disable this feature using the "no override-account-disable" command. Crafted HTTP Packet DoS Vulnerability +------------------------------------ Devices configured for SSL VPN (clientless or client-based) or accepting ASDM management connections are vulnerable. Note: IPSec clients are not vulnerable to this vulnerability. If SSL VPN (clientless or client-based) is not used, administrators should make sure that ASDM connections are only allowed from trusted hosts. To identify the IP addresses from which the security appliance accepts HTTPS connections for ASDM, configure the "http" command for each trusted host address or subnet. The following example, shows how a trusted host with IP address 192.168.1.100 is added to the configuration: hostname(config)# http 192.168.1.100 255.255.255.255 Crafted TCP Packet DoS Vulnerability +----------------------------------- There are no workarounds for this vulnerability. Crafted H.323 Packet DoS Vulnerability +------------------------------------- H.323 inspection should be disabled if it is not needed. Temporarily disabling the feature will mitigate this vulnerability. H.323 inspection can be disabled with the command "no inspect h323". SQL*Net Packet DoS Vulnerability +------------------------------- SQL*Net inspection should be disabled if it is not needed. Temporarily disabling the feature will mitigate this vulnerability. SQL*Net inspection can be disabled with the command "no inspect sqlnet". Access Control List (ACL) Bypass Vulnerability +--------------------------------------------- As a workaround, remove the "access-group" line applied on the interface where the ACL is configured and re-apply it. For example: ASA(config)#no access-group acl-inside in interface inside ASA(config)#access-group acl-inside in interface inside In the previous example the access group called "acl-inside" is removed and reapplied to the inside interface. Alternatively, you can add an explicit "deny ip any any" line in the bottom of the ACL applied on that interface. For example: ASA(config)#access-list 100 deny ip any any In the previous example, an explicit deny for all IP traffic is added at the end of "access-list 100". Additional mitigations that can be deployed on Cisco devices within the network are available in the Cisco Applied Mitigation Bulletin companion document for this advisory, which is available at the following link: http://www.cisco.com/warp/public/707/cisco-amb-20090408-asa.shtml. Obtaining Fixed Software ======================== Cisco has released free software updates that address these vulnerabilities. Prior to deploying software, customers should consult their maintenance provider or check the software for feature set compatibility and known issues specific to their environment. Customers may only install and expect support for the feature sets they have purchased. By installing, downloading, accessing or otherwise using such software upgrades, customers agree to be bound by the terms of Cisco's software license terms found at http://www.cisco.com/en/US/products/prod_warranties_item09186a008088e31f.html, or as otherwise set forth at Cisco.com Downloads at http://www.cisco.com/public/sw-center/sw-usingswc.shtml. Do not contact psirt at cisco.com or security-alert at cisco.com for software upgrades. Customers with Service Contracts +------------------------------- Customers with contracts should obtain upgraded software through their regular update channels. For most customers, this means that upgrades should be obtained through the Software Center on Cisco's worldwide website at http://www.cisco.com. Customers using Third Party Support Organizations +------------------------------------------------ Customers whose Cisco products are provided or maintained through prior or existing agreements with third-party support organizations, such as Cisco Partners, authorized resellers, or service providers should contact that support organization for guidance and assistance with the appropriate course of action in regards to this advisory. The effectiveness of any workaround or fix is dependent on specific customer situations, such as product mix, network topology, traffic behavior, and organizational mission. Due to the variety of affected products and releases, customers should consult with their service provider or support organization to ensure any applied workaround or fix is the most appropriate for use in the intended network before it is deployed. Customers without Service Contracts +---------------------------------- Customers who purchase direct from Cisco but do not hold a Cisco service contract, and customers who purchase through third-party vendors but are unsuccessful in obtaining fixed software through their point of sale should acquire upgrades by contacting the Cisco Technical Assistance Center (TAC). TAC contacts are as follows. * +1 800 553 2447 (toll free from within North America) * +1 408 526 7209 (toll call from anywhere in the world) * e-mail: tac at cisco.com Customers should have their product serial number available and be prepared to give the URL of this notice as evidence of entitlement to a free upgrade. Free upgrades for non-contract customers must be requested through the TAC. Refer to http://www.cisco.com/en/US/support/tsd_cisco_worldwide_contacts.html for additional TAC contact information, including localized telephone numbers, and instructions and e-mail addresses for use in various languages. Exploitation and Public Announcements ===================================== The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability described in this advisory. The crafted TCP packet DoS vulnerability was discovered and reported to Cisco by Gregory W. MacPherson and Robert J. Combo from Verizon Business. The ACL bypass vulnerability was reported to Cisco by Jon Ramsey and Jeff Jarmoc from SecureWorks. The Cisco PSIRT greatly appreciates the opportunity to work with researchers on security vulnerabilities, and welcomes the opportunity to review and assist in product reports. All other vulnerabilities were found during internal testing and during the resolution of customer service requests. Status of this Notice: FINAL ============================ THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME. A stand-alone copy or Paraphrase of the text of this document that omits the distribution URL in the following section is an uncontrolled copy, and may lack important information or contain factual errors. Distribution ============ This advisory is posted on Cisco's worldwide website at: http://www.cisco.com/warp/public/707/cisco-sa-20090408-asa.shtml In addition to worldwide web posting, a text version of this notice is clear-signed with the Cisco PSIRT PGP key and is posted to the following e-mail and Usenet news recipients. * cust-security-announce at cisco.com * first-bulletins at lists.first.org * bugtraq at securityfocus.com * vulnwatch at vulnwatch.org * cisco at spot.colorado.edu * cisco-nsp at puck.nether.net * full-disclosure at lists.grok.org.uk * comp.dcom.sys.cisco at newsgate.cisco.com Future updates of this advisory, if any, will be placed on Cisco's worldwide website, but may or may not be actively announced on mailing lists or newsgroups. Users concerned about this problem are encouraged to check the above URL for any updates. Revision History ================ +------------------------------------------------------------+ | Revision 1.0 | 2009-April-08 | Initial public release. | +------------------------------------------------------------+ Cisco Security Procedures ========================= Complete information on reporting security vulnerabilities in Cisco products, obtaining assistance with security incidents, and registering to receive security information from Cisco, is available on Cisco's worldwide website at http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html. This includes instructions for press inquiries regarding Cisco security notices. All Cisco security advisories are available at http://www.cisco.com/go/psirt. +-------------------------------------------------------------------- Copyright 2008-2009 Cisco Systems, Inc. All rights reserved. +-------------------------------------------------------------------- Updated: Apr 08, 2009 Document ID: 109974 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkncyUMACgkQ86n/Gc8U/uBS1ACeP7Toj7XSKuo/eaLfK6K4Gqzc Q8EAn2anUwiQH4xV5NoNVt+3JiKn2LXQ =Xi7D -----END PGP SIGNATURE----- From peter at rathlev.dk Wed Apr 8 12:03:41 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Wed, 08 Apr 2009 18:03:41 +0200 Subject: [c-nsp] about eompls on 7609 In-Reply-To: <24825069.914261239168165588.JavaMail.coremail@bj163app105.163.com> References: <24825069.914261239168165588.JavaMail.coremail@bj163app105.163.com> Message-ID: <1239206621.3496.4.camel@localhost.localdomain> On Wed, 2009-04-08 at 13:22 +0800, ying-xiang wrote: > following is my topology brief? > > SwitchA---PE1?7609-1?---PE2?7609-2?---SwitchB > > Both switchA and switchB are configured a vlan100 to achieve layer two > transport through EoMPLS and they works without any issue > but i got an error when i tried to set the same vlan id on the PEs > could anyone explain this for me ? You really should post the error you got, that would make it much easier to answer the question. :-) The 7600 cannot have VLAN ID overlap between interfaces on LAN cards. This means that using a VLAN on a subinterface, as you do with subint-EoMPLS, means you cannot also perform regular switching of this VLAN. It's a platform limitation. Regards, Peter From Mike.Anning at chep.com Wed Apr 8 12:15:51 2009 From: Mike.Anning at chep.com (Anning, Mike) Date: Wed, 8 Apr 2009 17:15:51 +0100 Subject: [c-nsp] show dot11 network-map In-Reply-To: <9e246b4d0904061302l1f2c5ad7rec292c3b986052cd@mail.gmail.com> Message-ID: Anyone know if the show dot11 network-map output on 1200 series access points shows either; 1. neighbouring access points it can see over the dot11 radio interface 2. neighbouring access points it can see over the wire within the same subnet I am thinking option 2 but cannot find anything conclusive. Many thanks in advance Mike Company Registration number: 197807; Place of Registration: England; Registered office address: Weybridge Business Park, Addlestone Road, Addlestone, Surrey, KT15 2UP Confidentiality Notice: This message, together with its annexes, contains information to be deemed strictly confidential, that may be legally privileged and is destined only to the addressee(s) identified above who only may use, copy and, under his/their responsibility, further disseminate it. If anyone received this message by mistake or reads it without entitlement is forewarned that keeping, copying, disseminating or distributing this message to persons other than the addressee(s) is strictly forbidden and is asked to transmit it immediately to the sender and to erase the original message received. Thank you. Please consider the environment before you print this message. Thank you. From billw at waveform.net Wed Apr 8 12:58:49 2009 From: billw at waveform.net (Bill Wichers) Date: Wed, 8 Apr 2009 12:58:49 -0400 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <49DC4EEC.3070001@rollernet.us> References: <49DC4EEC.3070001@rollernet.us> Message-ID: I've found that some carriers consider Ethernet something of a "toy" whereas TDM and SONET circuits are considered more "mission critical". Basically our local engineering gusy say that the Ethernet links are just a "bunch of jumpers in COs", and by that they mean a single link patched through to where it needs to go with no protection or management anywhere. The T3 links, while not always path diverse, are typically at least provisioned as 4 fiber handoffs within the carrier's network so you at least have some protection against a dead optic. This seems to be especially an issue for intercity links since the T3s are typically protected around a ring between the cities and the Ethernet rarely, if ever, is protected at all. This is just the ILEC (ATT here) though, most of the CLECs offer protection options for their Ethernet offerings. Personally I've been burned before with carriers not provisioning circuits as "protected" as one would expect (which includes TDM/SONET links). I try to keep all our core links on our own fiber where we control the physical routing and protection, but we have a few remote POPs that are not economical to build fiber to and those are the ones with the leased links. I'm not a big fan of Ethernet for the links to these POPs, but the Ethernet links we use from our gear to the customer premises do tend to work OK. Regarding monitoring, use a routing protocol that has keepalives to detect an outage. If you are using a switch you can probably determine link state on the circuit too (although this probably won't give you an indication of end-to-end circuit status since the carrier probably has a switch serving you that will give you a link regardless of the "rest" of the circuit working). -Bill > One of my carriers has given me a choice for a new circuit delivery: T3 > or Ethernet. My outside world circuit experience is all non-Ethernet, so > I have a few questions the sales group wasn't able to answer. I'd love > to hear some real world experience. The cost difference between the two > is not significant enough to be the sole deciding factor and I'm not > using pure-Ethernet platforms so it's just a matter of adding the right > interface card. > > How do you detect a "down" condition on Ethernet? My experience is that > the interface could be up/up because Ethernet doesn't know about > anything further down the line and ends up throwing packets into a > magical black hole. Or worse, secret packet loss. > > Can you even troubleshoot Ethernet? Normally if I'm seeing something > like out of frame errors or AIS, I can say "hey, there's a problem and > it's X". It scares me to think of opening trouble tickets as "it's > broken and I can't really tell you why". > > With a T3 I can be fairly certain that if there aren't any alarms that > my end is happily talking to the other end. How does one accomplish the > same with Ethernet? A periodic "ping" seems rather ambiguous as a health > check. > > Since this is an outside world connection (i.e. I'm not in a colo) the > slightly lower cost and convenience factor of Ethernet doesn't override > my desire to stick with a T3 for its management properties and the > sleeping good at night feeling I get knowing there are no alarms. My gut > tells me to stick with it even though Ethernet delivery is what all the > cool kids are doing these days, so any insight is appreciated. Thanks! > > ~Seth > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From billw at waveform.net Wed Apr 8 13:03:30 2009 From: billw at waveform.net (Bill Wichers) Date: Wed, 8 Apr 2009 13:03:30 -0400 Subject: [c-nsp] Max length of 9600 serial over CAT5e In-Reply-To: <49DC8B1A.2000501@exa-networks.co.uk> References: <49DC7BBE.50906@spacething.org> <49DC8B1A.2000501@exa-networks.co.uk> Message-ID: RS-232 has more limitations than just cable capacitance. RS-232 is a single-ended communication protocol (on the physical level), so it's noise immunity is not very good. This is especially a problem if you're running the cable in an electrically noisy environment (like a cable tray or wiring closet(s), etc.). If you need to run a long distance, why not just convert your RS-232 signal to RS-422 where you can safely run a 9600bps signal out to over a kilometer? All you need is a 2 pair cable, ideally with a shield, provided you don't need hardware flow control. The converters are usually cheap, maybe $50 or so per end unless you need electrical isolation. -Bill > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- > bounces at puck.nether.net] On Behalf Of Richard Halfpenny > Sent: Wednesday, April 08, 2009 7:32 AM > To: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] Max length of 9600 serial over CAT5e > > Sam Stickland wrote: > > Hi, > > > > What's the maximum length of you can run async-serial (9600 baud) > > over CAT5e (from a terminal server to console port). > > > > My google-fu has failed me. > > If I remember correctly, the spec for RS-232 says the maximum > capacitance of a cable can be 2500pF at 20kbps. A Cat5e of approx 46pF > / metre would give you a maximum length of 54 metres. At 9600bps you > could probably drive slightly longer. > > Rich > > -- > Network Operations > Exa Networks Ltd :: AS30740 > richard.halfpenny at exa-networks.co.uk > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From mohacsi at niif.hu Wed Apr 8 13:05:55 2009 From: mohacsi at niif.hu (Mohacsi Janos) Date: Wed, 8 Apr 2009 19:05:55 +0200 (CEST) Subject: [c-nsp] 2600 series for 100M In-Reply-To: <40d8a95a0904080509t3955662bod20a1fc36b8353c9@mail.gmail.com> References: <40d8a95a0904080509t3955662bod20a1fc36b8353c9@mail.gmail.com> Message-ID: According to Cisco: 265x(XM) is capable for the following performance for IP packets: in CEF switching: 40000 PPS and around 21 Mbps Janos Mohacsi Network Engineer, Research Associate, Head of Network Planning and Projects NIIF/HUNGARNET, HUNGARY Key 70EF9882: DEC2 C685 1ED4 C95A 145F 4300 6F64 7B00 70EF 9882 On Wed, 8 Apr 2009, Deric Kwok wrote: > Hi > > Do you know Cisco 2651XM is fine for 100M network? > > If the memory is 256M, it is ok? > > Can it support Virtual private network, VLAN and new tcsh command? > > i check the ios is "C2600 Software (C2600-ENTSERVICESK9-M), Version > 12.3(23)" > > Do I need to buy any extra memory? > > Thank you > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From sethm at rollernet.us Wed Apr 8 13:36:56 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Wed, 08 Apr 2009 10:36:56 -0700 Subject: [c-nsp] Max length of 9600 serial over CAT5e In-Reply-To: References: <49DC7BBE.50906@spacething.org> <49DC8B1A.2000501@exa-networks.co.uk> Message-ID: <49DCE0B8.3070403@rollernet.us> Bill Wichers wrote: > RS-232 has more limitations than just cable capacitance. RS-232 is a > single-ended communication protocol (on the physical level), so it's > noise immunity is not very good. This is especially a problem if you're > running the cable in an electrically noisy environment (like a cable > tray or wiring closet(s), etc.). > > If you need to run a long distance, why not just convert your RS-232 > signal to RS-422 where you can safely run a 9600bps signal out to over a > kilometer? All you need is a 2 pair cable, ideally with a shield, > provided you don't need hardware flow control. The converters are > usually cheap, maybe $50 or so per end unless you need electrical > isolation. > I'll second the 422. It's not worth running 232 for long distances. The converter cost is trivial. Plus if you're stuck running serial through a 1/2" conduit not having that DB9 connector makes the job so much easier. ~Seth From sethm at rollernet.us Wed Apr 8 13:48:46 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Wed, 08 Apr 2009 10:48:46 -0700 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: References: <49DC4EEC.3070001@rollernet.us> Message-ID: <49DCE37E.4070908@rollernet.us> Bill Wichers wrote: > I've found that some carriers consider Ethernet something of a "toy" > whereas TDM and SONET circuits are considered more "mission critical". > Basically our local engineering gusy say that the Ethernet links are > just a "bunch of jumpers in COs", and by that they mean a single link > patched through to where it needs to go with no protection or management > anywhere. The T3 links, while not always path diverse, are typically at > least provisioned as 4 fiber handoffs within the carrier's network so > you at least have some protection against a dead optic. This seems to be > especially an issue for intercity links since the T3s are typically > protected around a ring between the cities and the Ethernet rarely, if > ever, is protected at all. This is just the ILEC (ATT here) though, most > of the CLECs offer protection options for their Ethernet offerings. Good to know; mine is going a POP in another state since where I am isn't exactly a major stop on the internet for anyone to put an L3 POP in state. > Personally I've been burned before with carriers not provisioning > circuits as "protected" as one would expect (which includes TDM/SONET > links). I try to keep all our core links on our own fiber where we > control the physical routing and protection, but we have a few remote > POPs that are not economical to build fiber to and those are the ones > with the leased links. I'm not a big fan of Ethernet for the links to > these POPs, but the Ethernet links we use from our gear to the customer > premises do tend to work OK. > > Regarding monitoring, use a routing protocol that has keepalives to > detect an outage. If you are using a switch you can probably determine > link state on the circuit too (although this probably won't give you an > indication of end-to-end circuit status since the carrier probably has a > switch serving you that will give you a link regardless of the "rest" of > the circuit working). > I probably should have mentioned that I will be running BGP. I have an existing multihomed network and this circuit will be just adding another transit circuit. For added fun, they're going to use some circa 1997 existing fiber equipment (thus qualifying for lit building pricing), complete with a blinking "fault" light on one side of the ring. I will make them aware of that before I sign anything. ;) ~Seth From sethm at rollernet.us Wed Apr 8 13:48:44 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Wed, 08 Apr 2009 10:48:44 -0700 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: References: <49DC4EEC.3070001@rollernet.us> <935ead450904080618k15aa5c2bo23acf3dac7005e9c@mail.gmail.com> Message-ID: <49DCE37C.1030809@rollernet.us> Jon Lewis wrote: > On Wed, 8 Apr 2009, Jeffrey Ollie wrote: > >>> How do you detect a "down" condition on Ethernet? My experience is that >>> the interface could be up/up because Ethernet doesn't know about >>> anything further down the line and ends up throwing packets into a >>> magical black hole. Or worse, secret packet loss. >> >> There's nothing unique to Ethernet about that... > > No, but with ethernet, it's more likely that there's going to be a layer > 2 "local device" (i.e. a switch) which you connect to, but the layer 3 > next hop is somewhere off on the providers network in another building. > When the network breaks somewhere between the provider's L3 next hop and > your location, you'll still be up/up, but have no connectivity. With > BGP, you might tune the timers shorter than default so that such a break > gets noticed sooner. With a T3, BGP would find out about the break as > soon as the interface went down. In my case the next L3 hop is going to be in another state. For example with Sprint, I'm in Reno, NV and their router is in Stockton, CA. As far as the actual equipment, it will be an HWIC-1FE (HWIC-1GE-SFP if fiber) or NM-1T3/E3 in a 3800. ~Seth From sethm at rollernet.us Wed Apr 8 13:54:29 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Wed, 08 Apr 2009 10:54:29 -0700 Subject: [c-nsp] 2600 series for 100M In-Reply-To: <40d8a95a0904080509t3955662bod20a1fc36b8353c9@mail.gmail.com> References: <40d8a95a0904080509t3955662bod20a1fc36b8353c9@mail.gmail.com> Message-ID: <49DCE4D5.6030708@rollernet.us> Deric Kwok wrote: > Hi > > Do you know Cisco 2651XM is fine for 100M network? You aren't likely to get line rate 100 meg out of it. > If the memory is 256M, it is ok? > > Can it support Virtual private network, VLAN and new tcsh command? It'll do crypto (slowly). You'll need a crypto AIM if you're going to do anything serious with it. > i check the ios is "C2600 Software (C2600-ENTSERVICESK9-M), Version > 12.3(23)" > > Do I need to buy any extra memory? > 256MB is the maximum for that platform. You'll only have access to the lower 128 since the other half is used to hold the decompressed IOS image. Sounds weird, but it gives you more free memory, although not like one would expect if you've never used a 2600XM before. ~Seth From raa at opusnet.com Wed Apr 8 14:03:40 2009 From: raa at opusnet.com (Ruben Alvarez) Date: Wed, 8 Apr 2009 11:03:40 -0700 Subject: [c-nsp] Ping priority on Cisco devices Message-ID: <004901c9b874$59596e00$0c0c4a00$@com> All, I've heard that Cisco devices handle ICMP at a low priority. I found one post describing it handled in process-switching and not fast-switching. Does anyone have an article that explains that process and is it configurable? The reason I ask is I see about 4% packet loss when I ping devices in our broadband aggregation network. From the CPE to the router there is none, from my workstation to the router there is none, but if I ping the whole path I get a fairly consistent 4% loss. I can't find any congestion or errors. Ping from my workstation to the CPE are a consistent 60ms, aside from the 4% loss. Thanks. From peter at rathlev.dk Wed Apr 8 14:48:57 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Wed, 08 Apr 2009 20:48:57 +0200 Subject: [c-nsp] 2600 series for 100M In-Reply-To: <49DCE4D5.6030708@rollernet.us> References: <40d8a95a0904080509t3955662bod20a1fc36b8353c9@mail.gmail.com> <49DCE4D5.6030708@rollernet.us> Message-ID: <1239216537.3496.12.camel@localhost.localdomain> On Wed, 2009-04-08 at 10:54 -0700, Seth Mattinen wrote: > > Can it support Virtual private network, VLAN and new tcsh command? > > It'll do crypto (slowly). You'll need a crypto AIM if you're going to do > anything serious with it. Agreed. We had a 2651XM with a single GRE+IPSec tunnel once and it was able to forward no more than around 10-15 mbps with 3DES and no AIM. Regards, Peter From oboehmer at cisco.com Wed Apr 8 15:06:02 2009 From: oboehmer at cisco.com (Oliver Boehmer (oboehmer)) Date: Wed, 8 Apr 2009 21:06:02 +0200 Subject: [c-nsp] Ping priority on Cisco devices In-Reply-To: <004901c9b874$59596e00$0c0c4a00$@com> References: <004901c9b874$59596e00$0c0c4a00$@com> Message-ID: <70B7A1CCBFA5C649BD562B6D9F7ED784072CC389@xmb-ams-333.emea.cisco.com> Ruben Alvarez <> wrote on Wednesday, April 08, 2009 20:04: > All, > > I've heard that Cisco devices handle ICMP at a low priority. I found > one post describing it handled in process-switching and not > fast-switching. Does anyone have an article that explains that > process and is it configurable? Pings *to* the router are processed in process switching (as all/most other packets destined to the router itself). Pings *through* the router are switched like all others. > The reason I ask is I see about 4% packet loss when I ping devices in > our broadband aggregation network. From the CPE to the router there > is none, from my workstation to the router there is none, but if I > ping the whole path I get a fairly consistent 4% loss. I can't find > any congestion or errors. Ping from my workstation to the CPE are a > consistent 60ms, aside from the 4% loss. don't know what could be causing this. I would try to troubleshoot in which direction the packets are lost, and troubleshoot further.. but sounds strange.. oli From sf at lists.esoteric.ca Wed Apr 8 15:43:57 2009 From: sf at lists.esoteric.ca (Stephen Fulton) Date: Wed, 08 Apr 2009 15:43:57 -0400 Subject: [c-nsp] SIP-400 and EoMPLS, VPLS and H-VPLS Message-ID: <49DCFE7D.9090205@lists.esoteric.ca> According to the SIP/SPA configuration guide for the 7600, the SIP-400 with a SPA-2X1GE-V2 or a SPA-5X1GE-V2, can use individual ports in either a core-facing or edge facing role in MPLS. Can someone please confirm this? Thanks, -- Stephen From sethm at rollernet.us Wed Apr 8 15:54:22 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Wed, 08 Apr 2009 12:54:22 -0700 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: <49DC4EEC.3070001@rollernet.us> References: <49DC4EEC.3070001@rollernet.us> Message-ID: <49DD00EE.9030806@rollernet.us> A big thank you to everyone who shared their wisdom. I'm going to go back and ask them how they plan on delivering the circuit. If it is TDM all the way up to the building and the difference is purely which card they put in their shelf to hand it off to me, then there's not much point in paying extra for the T3. ~Seth From eng_mssk at hotmail.com Wed Apr 8 17:39:47 2009 From: eng_mssk at hotmail.com (Mohammad Khalil) Date: Thu, 9 Apr 2009 00:39:47 +0300 Subject: [c-nsp] DNS Tool Message-ID: Hey all is there any tool that can monitor the DNS behavior ?? for example , the resolving process and if there are any errors ?? Thanks _________________________________________________________________ Drag n? drop?Get easy photo sharing with Windows Live? Photos. http://www.microsoft.com/windows/windowslive/products/photos.aspx From walter.keen at RainierConnect.net Wed Apr 8 17:42:50 2009 From: walter.keen at RainierConnect.net (Walter Keen) Date: Wed, 08 Apr 2009 14:42:50 -0700 Subject: [c-nsp] DNS Tool In-Reply-To: References: Message-ID: <49DD1A5A.2020001@rainierconnect.net> Could you elaborate a little? We use Nagios to monitor other things, and use a DNS check plugin that simply does a dns query and reports if it successfully got an answer. I think there are other ones that will compare the answer to a known good answer you supply (wouldn't work well with something like Google.com or yahoo.com that does a lot of round robin entries) Mohammad Khalil wrote: > Hey all > is there any tool that can monitor the DNS behavior ?? > for example , the resolving process and if there are any errors ?? > > Thanks > > _________________________________________________________________ > Drag n? drop?Get easy photo sharing with Windows Live? Photos. > > http://www.microsoft.com/windows/windowslive/products/photos.aspx > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From stevend at uidaho.edu Wed Apr 8 17:45:05 2009 From: stevend at uidaho.edu (Dodd, Steven) Date: Wed, 8 Apr 2009 14:45:05 -0700 Subject: [c-nsp] DNS Tool In-Reply-To: References: Message-ID: <4C0A1E4AB1B97642AFB097A8CDA0B223DCD3C9@EXVS1.its.uidaho.edu> Without knowing more about what you are specifically trying to accomplish, dig is the tool you are looking for. -Steve -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Mohammad Khalil Sent: Wednesday, April 08, 2009 2:40 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] DNS Tool Hey all is there any tool that can monitor the DNS behavior ?? for example , the resolving process and if there are any errors ?? Thanks _________________________________________________________________ Drag n' drop-Get easy photo sharing with Windows Live(tm) Photos. http://www.microsoft.com/windows/windowslive/products/photos.aspx _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From tedm at toybox.placo.com Wed Apr 8 17:48:29 2009 From: tedm at toybox.placo.com (Ted Mittelstaedt) Date: Wed, 08 Apr 2009 14:48:29 -0700 Subject: [c-nsp] Ping priority on Cisco devices In-Reply-To: <004901c9b874$59596e00$0c0c4a00$@com> References: <004901c9b874$59596e00$0c0c4a00$@com> Message-ID: <49DD1BAD.6020604@toybox.placo.com> Ruben Alvarez wrote: > All, > > I've heard that Cisco devices handle ICMP at a low priority. I found one > post describing it handled in process-switching and not fast-switching. > Does anyone have an article that explains that process and is it > configurable? > > The reason I ask is I see about 4% packet loss when I ping devices in our > broadband aggregation network. From the CPE to the router there is none, > from my workstation to the router there is none, but if I ping the whole > path I get a fairly consistent 4% loss. I can't find any congestion or > errors. Ping from my workstation to the CPE are a consistent 60ms, aside > from the 4% loss. > > Thanks. > > What model is your router and can you post a config? What is CPU utilization on the router? What is memory utilization on the router? Ted From eng_mssk at hotmail.com Wed Apr 8 17:49:34 2009 From: eng_mssk at hotmail.com (Mohammad Khalil) Date: Thu, 9 Apr 2009 00:49:34 +0300 Subject: [c-nsp] DNS Tool In-Reply-To: <49DD1A5A.2020001@rainierconnect.net> References: <49DD1A5A.2020001@rainierconnect.net> Message-ID: We are facing some browsing problems , so we want to make sure that our DNS servers are resolving well using tools other than nslookup > Date: Wed, 8 Apr 2009 14:42:50 -0700 > From: walter.keen at rainierconnect.net > To: eng_mssk at hotmail.com > CC: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] DNS Tool > > Could you elaborate a little? > > We use Nagios to monitor other things, and use a DNS check plugin that > simply does a dns query and reports if it successfully got an answer. I > think there are other ones that will compare the answer to a known good > answer you supply (wouldn't work well with something like Google.com or > yahoo.com that does a lot of round robin entries) > > Mohammad Khalil wrote: > > Hey all > > is there any tool that can monitor the DNS behavior ?? > > for example , the resolving process and if there are any errors ?? > > > > Thanks > > > > _________________________________________________________________ > > Drag n? drop?Get easy photo sharing with Windows Live? Photos. > > > > http://www.microsoft.com/windows/windowslive/products/photos.aspx > > _______________________________________________ > > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > _________________________________________________________________ Show them the way! Add maps and directions to your party invites. http://www.microsoft.com/windows/windowslive/products/events.aspx From malitsky at netabn.com Wed Apr 8 17:59:20 2009 From: malitsky at netabn.com (Michael Malitsky) Date: Wed, 8 Apr 2009 16:59:20 -0500 Subject: [c-nsp] rate limiting pointers? In-Reply-To: References: Message-ID: <79AF0C3901752A49881FE4CB31F7AA4001450AFE@abn-borg2.NETABN.LOCAL> Generally speaking, Muhammad is correct. From personal experience, you are going to find a lot of limitations on the switching platform when you try to implement this, though. The switching platforms vary significantly in their abilities to classify traffic and police in different directions. Off the top of my head, I am not sure whether the 2960 supports policing at all. 3550 does, with significant limitations. I can share more specific experiences offline. As an alternative, consider doing the straightforward "rate-limit input | output ..." on the subinterfaces on the 7200. Works like a champ (assuming the CPU can keep up of course) and is just 2 lines to set up vs the MQC on the switch. Sincerely, Michael Malitsky > Date: Wed, 8 Apr 2009 09:36:07 +0500 > From: Muhammad Salman Zahid > Subject: Re: [c-nsp] rate limiting pointers? > To: Scott Granados > Cc: cisco-nsp at puck.nether.net > Message-ID: > <44c523750904072136u5c3c82c0scf20d47d5c2e3241 at mail.gmail.com> > Content-Type: text/plain; charset=ISO-8859-1 > > Dear Scott, > > Read & try the following: > > > Step 1: Define ACL for desired IP Pools > Step 2: Define a Packet classification criteria > Class-map match-all > description Control plane normal traffic > match access-group name > > Step 3: Define a Service Policy > policy-map > class > police cir > conform-action set-dscp-transmit default exceed-action drop violate- > action > drop > > Step 4: Enter service policy on control plane interface > service-policy input > service-policy output > > ip access-list extended [ABC] > ip access-list extended [XYZ] > class-map match-all [NAME1]=== NAME1=ABC (so easily remember) > match access-group name [ABC] > class-map match-all [NAME2]=== NAME2=XYZ (so easily remember) > match access-group name [XYZ] > policy-map [POLICY NAME] > class [ABC] > put rate limit > class [XYZ] > put rate limit > Regards, > MSZ > On Wed, Apr 8, 2009 at 6:36 AM, Scott Granados > wrote: > > > Since the topic of rate limiting came up... > > > > I have a 7206VXR NPE-300 and 2 switches (2960 and 3550). > > > > I plan on setting up a trunk from the 7206 to the 3500 and break out > via > > vlans as you'd expect. What are some good methods for rate limiting > the > > individual ports on the access switches? > > > > I'm open to other hardware but this is more of a lab / personal > environment > > so solutions for the listed hardware would be appreciated. Could > someone > > also suggest some good foundation type reading for rate limiting and > > practices? > > > > Thank you > > Scott > > _______________________________________________ > > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > > > > -- > "Death is no the greatest loss in life .... > The greatest loss is what dies inside > you while U live...!" From peter at rathlev.dk Wed Apr 8 19:09:53 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 09 Apr 2009 01:09:53 +0200 Subject: [c-nsp] DNS Tool In-Reply-To: References: Message-ID: <1239232193.6594.1.camel@localhost.localdomain> On Thu, 2009-04-09 at 00:39 +0300, Mohammad Khalil wrote: > is there any tool that can monitor the DNS behavior ?? > for example , the resolving process and if there are any errors ?? If you want to monitor this from a Cisco device, IP SLA Monitor "type dns" is the thing to search for. It can do DNS lookups and tell you how long it took. Regards, Peter From billw at waveform.net Wed Apr 8 19:59:09 2009 From: billw at waveform.net (Bill Wichers) Date: Wed, 8 Apr 2009 19:59:09 -0400 Subject: [c-nsp] Odd Etherchannel behavior between 7507 and cat 4006 In-Reply-To: References: <49DB1C06.60506@memetic.org> <20090407094208.GZ290@greenie.muc.de> <49DB2315.5010806@memetic.org> Message-ID: [snip] > > I typically set both ends (router and switch) of these links to 100/full > > since I've seen weird autonegotiation problems before. This works just > > fine for individual FE links, but as soon as I bring up the Etherchannel > > group both member links on the router end drop back to "unknown duplex" > > Can you configure the etherchannel group interface as 100/full? *That* did it! Thanks! I had not thought of trying it on the etherchannel group since I'd already set it on the underlying member links. Now all I have to do is figure out why traffic balance is something like 5%/95% between the two member links. I think there are some legacy config entries in the switch regarding static MACs that might be causing this though. -Bill From paul at paulstewart.org Wed Apr 8 19:44:57 2009 From: paul at paulstewart.org (Paul Stewart) Date: Wed, 8 Apr 2009 19:44:57 -0400 Subject: [c-nsp] Supervisor Failover - Speed question Message-ID: <000001c9b8a4$0689eee0$139dcca0$@org> Hi there. We have 7606's with dual Sup720-3BXL. I'm investigating how to get the fastest possible failover if/when a supervisor fails. Current config looks like this: my state = 13 -ACTIVE peer state = 8 -STANDBY HOT Mode = Duplex Unit = Primary Unit ID = 5 Redundancy Mode (Operational) = sso Redundancy Mode (Configured) = sso Redundancy State = sso Maintenance Mode = Disabled Communications = Up client count = 78 client_notification_TMR = 30000 milliseconds keep_alive TMR = 9000 milliseconds keep_alive count = 0 keep_alive threshold = 18 RF debug mask = 0x0 -- redundancy keepalive-enable mode sso main-cpu auto-sync running-config Is there any way to get a failover to less than 30 seconds an example? We find currently it's 2-3 minutes for failover it seems.. Thanks, Paul From david at hughes.com.au Wed Apr 8 21:15:09 2009 From: david at hughes.com.au (David Hughes) Date: Thu, 9 Apr 2009 11:15:09 +1000 Subject: [c-nsp] T3 or Ethernet delivery? In-Reply-To: References: <49DC4EEC.3070001@rollernet.us> <935ead450904080618k15aa5c2bo23acf3dac7005e9c@mail.gmail.com> Message-ID: <3E4FE00F-97AE-47DE-9F2F-4B0EA453E005@hughes.com.au> On 09/04/2009, at 12:08 AM, Jon Lewis wrote: > With BGP, you might tune the timers shorter than default so that > such a break gets noticed sooner. With a T3, BGP would find out > about the break as soon as the interface went down. BGP with BFD would work well for this. It's not as clean as losing link, but it'll pick up the fault reasonably quickly. David ... From fwissue at gmail.com Wed Apr 8 21:53:52 2009 From: fwissue at gmail.com (Michael Lee) Date: Wed, 8 Apr 2009 18:53:52 -0700 Subject: [c-nsp] Supervisor Failover - Speed question In-Reply-To: <000001c9b8a4$0689eee0$139dcca0$@org> References: <000001c9b8a4$0689eee0$139dcca0$@org> Message-ID: <709a72990904081853x5d3ead97la962d3e86213b1ca@mail.gmail.com> did you try enable nsf if it is possible? there are some limitation on mpls-te On Wed, Apr 8, 2009 at 4:44 PM, Paul Stewart wrote: > Hi there. > > > > We have 7606's with dual Sup720-3BXL. I'm investigating how to get the > fastest possible failover if/when a supervisor fails. > > > > Current config looks like this: > > > > my state = 13 -ACTIVE > > peer state = 8 -STANDBY HOT > > Mode = Duplex > > Unit = Primary > > Unit ID = 5 > > > > Redundancy Mode (Operational) = sso > > Redundancy Mode (Configured) = sso > > Redundancy State = sso > > Maintenance Mode = Disabled > > Communications = Up > > > > client count = 78 > > client_notification_TMR = 30000 milliseconds > > keep_alive TMR = 9000 milliseconds > > keep_alive count = 0 > > keep_alive threshold = 18 > > RF debug mask = 0x0 > > > > -- > > > > redundancy > > keepalive-enable > > mode sso > > main-cpu > > auto-sync running-config > > > > > > > > Is there any way to get a failover to less than 30 seconds an example? We > find currently it's 2-3 minutes for failover it seems.. > > > > Thanks, > > > > Paul > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From dcp at dcptech.com Wed Apr 8 21:16:26 2009 From: dcp at dcptech.com (David Prall) Date: Wed, 8 Apr 2009 21:16:26 -0400 Subject: [c-nsp] Supervisor Failover - Speed question In-Reply-To: <000001c9b8a4$0689eee0$139dcca0$@org> References: <000001c9b8a4$0689eee0$139dcca0$@org> Message-ID: <008d01c9b8b0$d0aaa910$71fffb30$@com> Do all linecards also have DFC's? Do you have nsf/graceful-restart configured for all routing protocols? What linecards are you using? David -- http://dcp.dcptech.com > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- > bounces at puck.nether.net] On Behalf Of Paul Stewart > Sent: Wednesday, April 08, 2009 7:45 PM > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] Supervisor Failover - Speed question > > Hi there. > > > > We have 7606's with dual Sup720-3BXL. I'm investigating how to get the > fastest possible failover if/when a supervisor fails. > > > > Current config looks like this: > > > > my state = 13 -ACTIVE > > peer state = 8 -STANDBY HOT > > Mode = Duplex > > Unit = Primary > > Unit ID = 5 > > > > Redundancy Mode (Operational) = sso > > Redundancy Mode (Configured) = sso > > Redundancy State = sso > > Maintenance Mode = Disabled > > Communications = Up > > > > client count = 78 > > client_notification_TMR = 30000 milliseconds > > keep_alive TMR = 9000 milliseconds > > keep_alive count = 0 > > keep_alive threshold = 18 > > RF debug mask = 0x0 > > > > -- > > > > redundancy > > keepalive-enable > > mode sso > > main-cpu > > auto-sync running-config > > > > > > > > Is there any way to get a failover to less than 30 seconds an example? > We > find currently it's 2-3 minutes for failover it seems.. > > > > Thanks, > > > > Paul > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From chris.garzon at gmail.com Wed Apr 8 22:22:05 2009 From: chris.garzon at gmail.com (Dracul) Date: Thu, 9 Apr 2009 10:22:05 +0800 Subject: [c-nsp] video,voip and internet over DSL (converged) Message-ID: <876789290904081922te84a61ev1da8dff3f198b322@mail.gmail.com> Hi list, is it feasible to broadcast video/voip + internet over DSL like lets say I deploy a cisco DSLAM infra in a 20 storey building. It would run over a media server solution and a VOIP network. I am not sure if this would be a stable solution considering I want to broadcast HD and SD alike plus VOIP and internet to boot. Any cons? like noise level or quality of the video or quality of bandwidth etc. because DSL transport is just running over copper right? Or would I be better off running fibre? But of course cost will then quantify the use of DSL. regards, Chris From sf at lists.esoteric.ca Wed Apr 8 22:27:11 2009 From: sf at lists.esoteric.ca (Stephen Fulton) Date: Wed, 08 Apr 2009 22:27:11 -0400 Subject: [c-nsp] SIP-400 and EoMPLS, VPLS and H-VPLS In-Reply-To: <49DCFE7D.9090205@lists.esoteric.ca> References: <49DCFE7D.9090205@lists.esoteric.ca> Message-ID: <49DD5CFF.7090403@lists.esoteric.ca> For the archives, the answer from my SE is yes, the SIP-400/SPA-(2|5)X1GE-V2 can appropriate in a core and edge facing role, on a per-port basis. -- Stephen Stephen Fulton wrote: > According to the SIP/SPA configuration guide for the 7600, the SIP-400 > with a SPA-2X1GE-V2 or a SPA-5X1GE-V2, can use individual ports in > either a core-facing or edge facing role in MPLS. Can someone please > confirm this? > > Thanks, > > -- Stephen > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From ml at kenweb.org Wed Apr 8 23:15:34 2009 From: ml at kenweb.org (ML) Date: Wed, 08 Apr 2009 23:15:34 -0400 Subject: [c-nsp] Odd multicast behavior from an ME3400 Message-ID: <49DD6856.6020402@kenweb.org> Using an IneoQuest cricket we've been trying to find out why multicast video streams are breaking up. Using an ME3400 as an access device these are our symptoms: 3 x MPEG4 HD streams (8-10MBps each) come through fine. Add one more stream and the Cricket says we've got problems. On aggregate this about 40Mbps/3500pps with four streams. However with *10* standard def MPEG2 streams (~84Mbps/7500pps). Everything looks good according to the Cricket. If the access device is a 3560 we can pull twice as many MPEG4-HD streams without issue. We've already verified the content is good from the source (pulling twice as many stream as a customer would ever pull) now it's down to the ME3400s in the access layer. When looking at the interface counters there is not a single error of any kind. "show buffers" shows no changes in buffer misses during and after the point where video breaks down on the MPEG4-HD streams. When the Cricket's video monitor point is a gigabit port (via a GLC-T, albeit the Cricket monitor port is 100Mb) we can pull four streams with problems but the error rate is reduced. We are using the IPBASE image. Tried several versions 12.2(25)SEG1, 12.2(44)SE no difference. The multicast config is basic at the access layer. Just default config for IGMP snooping on the multicast VLAN with immediate-leave. I used the Bug Toolkit but nothing stood out to me as an open/fixed bug with our symptoms. Is there a troubleshooting step I'm missing here? Thanks From ATolstykh at integrysgroup.com Wed Apr 8 23:19:08 2009 From: ATolstykh at integrysgroup.com (Tolstykh, Andrew) Date: Wed, 8 Apr 2009 22:19:08 -0500 Subject: [c-nsp] Packet Loss on 6513 In-Reply-To: <259E69AA141E7640822757CAB3EBC70F18B1D0DBE9@MSG-M1P1.pcacorp.net> References: <259E69AA141E7640822757CAB3EBC70F18B1D0DBE9@MSG-M1P1.pcacorp.net> Message-ID: What is connected to your SUP-720 Gi7/1 interface? Can you post the output of 'show int gi7/1'? -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Mesiatowsky, Shawn Sent: Tuesday, April 07, 2009 11:11 AM To: 'cisco-nsp at puck.nether.net' Subject: [c-nsp] Packet Loss on 6513 We currently have 2 6513's in our core, and we have seen packet loss on our network. I was trying to locate the source of the packet loss. We did see some input queue drops on the SVI's and physical interfaces. I had increased our queue size on the vlan interfaces to 500, and our packet drops on the svi's decreased signifigantly. Now I am trying to figure out why there is packet loss on the physical interfaces. We have a sup 720, and our line cards are WS-X6724-SFP and WS-X6748-SFP. Here is a sample of an interface with high drops GigabitEthernet2/23 is up, line protocol is up (connected) Hardware is C6k 1000Mb 802.3, address is 001a.2f68.7bc2 (bia 001a.2f68.7bc2) MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 38/255, rxload 32/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex, 1000Mb/s, media type is SX input flow-control is off, output flow-control is off Clock mode is auto ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:31, output hang never Last clearing of "show interface" counters 1d00h Input queue: 0/2000/91560/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 5 minute input rate 126671000 bits/sec, 28888 packets/sec 5 minute output rate 151605000 bits/sec, 26499 packets/sec 942611654 packets input, 633784740348 bytes, 0 no buffer Received 7319979 broadcasts (6903850 multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 91560 overrun, 0 ignored 0 watchdog, 0 multicast, 0 pause input 0 input packets with dribble condition detected 891230426 packets output, 579042873963 bytes, 0 underruns 0 output errors, 0 collisions, 0 interface resets 0 babbles, 0 late collision, 0 deferred 0 lost carrier, 0 no carrier, 0 PAUSE output 0 output buffer failures, 0 output buffers swapped out I also looked at the utilization of this interface with our snmp tool, and utilixzation of this interface never went over %40 I also noticed the following, and was not sure if this was completely accurate: show platform hardware capacity interface Interface Resources Interface drops: Module Total drops: Tx Rx Highest drop port: Tx Rx 1 0 466 0 1 2 0 154228 0 23 3 0 123 0 1 4 0 190102 0 21 5 0 446318 0 21 7 3940684041 0 1 0 9 0 34280 0 7 10 0 5 0 42 11 0 433 0 46 12 0 1686 0 44 13 66042 119859 1 1 Interface buffer sizes: Module Bytes: Tx buffer Rx buffer 1 1221120 152000 2 1221120 152000 3 1221120 152000 4 1221120 152000 5 1221120 152000 6 1221120 152000 9 1221120 152000 10 1221120 152000 11 1221120 152000 12 1221120 152000 13 1221120 152000 Does this mean that 3940684041 packets were dropped on the egress queue on the sup? Does this seem extremly high, and shat can cause this? Thanks for your help ________________________________ This email communication is intended as a private communication for the sole use of the primary addressee and those individuals listed for copies in the original message. The information contained in this email is private and confidential and If you are not an intended recipient you are hereby notified that copying, forwarding or other dissemination or distribution of this communication by any means is prohibited. If you are not specifically authorized to receive this email and if you believe that you received it in error please notify the original sender immediately. We honour similar requests relating to the privacy of email communications. Cette communication par courrier ?lectronique est une communication priv?e ? l'usage exclusif du destinataire principal ainsi que des personnes dont les noms figurent en copie. Les renseignements contenus dans ce courriel sont confidentiels et si vous n'?tes pas le destinataire pr?vu, vous ?tes avis?, par les pr?sentes que toute reproduction, transfert ou autre forme de diffusion de cette communication par quelque moyen que ce soit est interdite. Si vous n'?tes pas sp?cifiquement autoris? ? recevoir ce courriel ou si vous croyez l'avoir re?u par erreur, veuillez en aviser l'exp?diteur original imm?diatement. Nous respectons les demandes similaires qui touchent la confidentialit? des communications par courrier ?lectronique. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From aftab.siddiqui at gmail.com Thu Apr 9 00:37:26 2009 From: aftab.siddiqui at gmail.com (Aftab Siddiqui) Date: Thu, 9 Apr 2009 09:37:26 +0500 Subject: [c-nsp] video,voip and internet over DSL (converged) In-Reply-To: <876789290904081922te84a61ev1da8dff3f198b322@mail.gmail.com> References: <876789290904081922te84a61ev1da8dff3f198b322@mail.gmail.com> Message-ID: <3c605ce10904082137j31fb89c7j1cc3239642ffc00c@mail.gmail.com> Hello Chris, Before deployment you have to consider certain point: - What flavour of DSL you will be using either ADSL2, ADSL2+ or VDSL. They have different reach and different bandwidth capacity. - What will be used for backhauling the DSLAM to CO. - Will it be internet-TV or IPTV? if IPTV than it will be multicast over the network. (I persume it is IPTV) - How many HD and SD channel you are planning to put on the network? HD takes approx 8mbps and SD approx 2mbps. DSL can be used for such type of services and in normal copper condition (but you have to test) it will provide the desired services. On Thu, Apr 9, 2009 at 7:22 AM, Dracul wrote: > Hi list, > > is it feasible to broadcast video/voip + internet over DSL like lets say I > deploy a cisco DSLAM infra in a 20 storey building. It would run over a > media server solution and a VOIP network. I am not sure if this would be a > stable solution considering I want to broadcast HD and SD alike plus VOIP > and internet to boot. > > Any cons? like noise level or quality of the video or quality of bandwidth > etc. because DSL transport is just running over copper right? Or would I be > better off running fibre? But of course cost will then quantify the use of > DSL. > > regards, > Chris > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > -- Regards, Aftab A. Siddiqui From pigsign.pykota at gmail.com Thu Apr 9 01:11:30 2009 From: pigsign.pykota at gmail.com (Darren Yang) Date: Thu, 9 Apr 2009 13:11:30 +0800 Subject: [c-nsp] How can enable PfR PIRO function on IOS 12.4(24)T Message-ID: Hi, The Cisco introduced PfR can support OSPF as parent route on IOS 12.4(24)T and this term is PIRO(Protocol Independent Route Optimization). Detail link this: http://www.cisco.com/en/US/docs/ios/oer/configuration/guide/oer-trf_rte_ctl.html#wp1060987 But when I use 12.4(24)T in Cisco 1812 module, I didn't see any PIRO information can support OSPF when I type 'sh oer master prefix', like below... #sh oer master prefix 192.168.1.2/32 DEFAULT* 92 172.17.11.254 Tu11 U U U 0 0 0 0 N N N N 1 1 #sh ip route ospf O 192.168.1.0/24 [110/11] via 10.0.0.1, 02:46:06, Tunnel11 [110/11] via 10.1.1.1, 02:46:06, Tunnel12 Before 12.4(24)T, I use static route as parent route and it works well. But I really want to use OSPF as PfR parent route because static route would make route fail when gateway couldn't arrive. Anyone have idea about this ? Thanks and Regards, Pigsign From ecralar at hotmail.com Thu Apr 9 03:26:03 2009 From: ecralar at hotmail.com (Alex) Date: Thu, 9 Apr 2009 08:26:03 +0100 Subject: [c-nsp] Odd multicast behavior from an ME3400 References: <49DD6856.6020402@kenweb.org> Message-ID: I think you are missing a couple of steps. Packet count and capture. The multicast streams are UDP, are they? If so then: 1/ count packets sent on source and and packets received on independent receiver (not on switch) 2/ capture stream and verify UDP checksum (udp.checksum_bad == 1 in Wireshark display filter). You will need a powerful PC with lots of RAM and fast disk. HTH Rgds Alex ----- Original Message ----- From: "ML" To: Sent: Thursday, April 09, 2009 4:15 AM Subject: [c-nsp] Odd multicast behavior from an ME3400 > Using an IneoQuest cricket we've been trying to find out why multicast > video streams are breaking up. > > Using an ME3400 as an access device these are our symptoms: > > 3 x MPEG4 HD streams (8-10MBps each) come through fine. > Add one more stream and the Cricket says we've got problems. > On aggregate this about 40Mbps/3500pps with four streams. > > However with *10* standard def MPEG2 streams (~84Mbps/7500pps). > Everything looks good according to the Cricket. > > If the access device is a 3560 we can pull twice as many MPEG4-HD streams > without issue. > > > We've already verified the content is good from the source (pulling twice > as many stream as a customer would ever pull) > now it's down to the ME3400s in the access layer. > > When looking at the interface counters there is not a single error of any > kind. "show buffers" shows no changes in buffer misses > during and after the point where video breaks down on the MPEG4-HD > streams. > > When the Cricket's video monitor point is a gigabit port (via a GLC-T, > albeit the Cricket monitor port is 100Mb) we can pull four streams with > problems but the error rate is reduced. > > We are using the IPBASE image. Tried several versions 12.2(25)SEG1, > 12.2(44)SE no difference. > > The multicast config is basic at the access layer. Just default config > for IGMP snooping on the multicast VLAN with immediate-leave. > > I used the Bug Toolkit but nothing stood out to me as an open/fixed bug > with our symptoms. > > Is there a troubleshooting step I'm missing here? > > Thanks > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From wllmjbs at gmail.com Thu Apr 9 03:36:08 2009 From: wllmjbs at gmail.com (William Jobs) Date: Thu, 9 Apr 2009 10:36:08 +0300 Subject: [c-nsp] Service Deployment Message-ID: Hi, I'm looking for GUI tool that can be used to easily deploy the following services on a large scale, over Cisco hardware: - Layer 3 MPLS VPNs - Layer 2 MPLS VPNs - Any Transport over MPLS - VPLS One option I had come across was Cisco's IP Solutions Centre. Has anyone had any experience using this product and can it handle our requirements? I'd also be open to other solutions/products. Any help would be appreciated. Thanks. From blahu77 at gmail.com Thu Apr 9 04:25:42 2009 From: blahu77 at gmail.com (Mateusz Blaszczyk) Date: Thu, 9 Apr 2009 09:25:42 +0100 Subject: [c-nsp] carrier router models comparison In-Reply-To: <74206b240904080701t75420f7dqd1298597e246008c@mail.gmail.com> References: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> <74206b240904080701t75420f7dqd1298597e246008c@mail.gmail.com> Message-ID: <383357750904090125t302139f8o1d836243dc484010@mail.gmail.com> What's the difference between 40g/slot and 100g/slot ready ? Is it like "vista ready"? I would assume (wrongly?) that this is a hw limit? Best Regards, -mat -- pgp-key 0x1C655CAB From techconfig at yahoo.com Thu Apr 9 07:15:29 2009 From: techconfig at yahoo.com (Mark Tech) Date: Thu, 9 Apr 2009 04:15:29 -0700 (PDT) Subject: [c-nsp] Rate limit Physical interface GSR Message-ID: <69329.43725.qm@web44814.mail.sp1.yahoo.com> Hi I would like to cap a physical GE interface to 100mbps whist running vlans through it on a GSR i.e. interface GigabitEthernet0/0/6 ?no ip address ?no ip directed-broadcast ?rate-limit input 100032000 12504000 12504000 conform-action transmit exceed-action drop ?rate-limit output 100032000 12504000 12504000 conform-action transmit exceed-action drop ?no negotiation auto ! interface GigabitEthernet0/0/6.2 ?encapsulation dot1Q 2 ?ip vrf forwarding test ?ip address 10.1.1.5 255.255.255.252 ?no ip directed-broadcast ?no cdp enable ! interface GigabitEthernet0/0/6.3 ?encapsulation dot1Q 3 ?ip vrf forwarding test2 ?ip address 10.1.1.1 255.255.255.252 ?no ip directed-broadcast ?no cdp enable ! .................etc However when I apply? the rate-limit command on GE0/0/6, I don't see any drop in traffic. Actually I have set up a throughput test through GigabitEthernet0/0/6.2 running at 1Gbps which I can see through sh int GigabitEthernet0/0/6 which does not drop to 100Mbps once the rate-limit is added Is there a way to cap this aggregate interface? Regards Mark From sandmaier at schlund.net Thu Apr 9 07:31:45 2009 From: sandmaier at schlund.net (Jan Sandmaier) Date: Thu, 09 Apr 2009 13:31:45 +0200 Subject: [c-nsp] etherchannel load-balancing on "4 Port ISE Gigabit Ethernet"? Message-ID: <49DDDCA1.4060506@schlund.net> Hi, does anybody know how load-balancing in an etherchannel works on a "4 Port ISE Gigabit Ethernet" for Cisco 12000 in detail? I have the following problem: I configured an etherchannel consisting of two GigabitEthernet ports on the same linecard. Only one port is utilized (see show command below). There is no inbound traffic and the outbound traffic originates from various prefixes to basically 3 prefixes. I have a cisco 12010/PRP with IOS 12.0(31)S6. sh interfaces port-channel 1 load ID bits/sec pack/sec ---------- ------------ ---------- PortCh1 Tx 149655000 24926 Rx 0 0 Members (%) bits/sec pack/sec ---------- --- ------------ ---------- Gi1/0 Tx 99 149643000 24919 Rx 54 0 0 Gi1/1 Tx 1 11000 8 Rx 46 0 0 The configuration is: interface Port-channel1 bandwidth 2000000 ip address x.x.x.x 255.255.255.252 ip access-group 188 in ip access-group 189 out no ip redirects no ip unreachables no ip directed-broadcast no ip proxy-arp ip route-cache flow sampled load-interval 30 channel-group minimum active 1 no channel-group bandwidth control-propagation interface GigabitEthernet1/0 no negotiation auto channel-group 1 no cdp enable ! interface GigabitEthernet1/1 negotiation auto channel-group 1 no cdp enable Is there a fundamental problem with this scenario? Thanks, Jan From geoff at pendery.net Thu Apr 9 08:29:03 2009 From: geoff at pendery.net (Geoffrey Pendery) Date: Thu, 9 Apr 2009 07:29:03 -0500 Subject: [c-nsp] Supervisor Failover - Speed question In-Reply-To: <000001c9b8a4$0689eee0$139dcca0$@org> References: <000001c9b8a4$0689eee0$139dcca0$@org> Message-ID: Yes, failover shouldn't take 2-3 minutes. I've personally observed it as less than one second in several test environments. But I imagine it's highly dependent on the details. What it your criteria for measuring it as done? Are you pinging from a host on one port of the chassis to another? One network to another, routed across the 7600? Pinging the supervisor's loopback address? Looking at routing protocol adjacencies in neighbored routers? As others have mentioned, if you're running a routing protocol like EIGRP or OSPF, adding "nsf" in the config for that protocol will likely help to maintain forwarding during the failover, though not technically speeding up the failover itself. Could you elaborate a bit on what traffic you're seeing down for a few minutes? -Geoff On Wed, Apr 8, 2009 at 6:44 PM, Paul Stewart wrote: > Hi there. > > > > We have 7606's with dual Sup720-3BXL. ?I'm investigating how to get the > fastest possible failover if/when a supervisor fails. > > > > Current config looks like this: > > > > ? ? ? my state = 13 -ACTIVE > > ? ? peer state = 8 ?-STANDBY HOT > > ? ? ? ? ? Mode = Duplex > > ? ? ? ? ? Unit = Primary > > ? ? ? ?Unit ID = 5 > > > > Redundancy Mode (Operational) = sso > > Redundancy Mode (Configured) ?= sso > > Redundancy State ? ? ? ? ? ? ?= sso > > ? ? Maintenance Mode = Disabled > > ?Communications = Up > > > > ? client count = 78 > > ?client_notification_TMR = 30000 milliseconds > > ? ? ? ? ?keep_alive TMR = 9000 milliseconds > > ? ? ? ?keep_alive count = 0 > > ? ?keep_alive threshold = 18 > > ? ? ? ? ? RF debug mask = 0x0 > > > > -- > > > > redundancy > > ?keepalive-enable > > ?mode sso > > ?main-cpu > > ?auto-sync running-config > > > > > > > > Is there any way to get a failover to less than 30 seconds an example? ?We > find currently it's 2-3 minutes for failover it seems.. > > > > Thanks, > > > > Paul > > > > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From drew.weaver at thenap.com Thu Apr 9 08:42:01 2009 From: drew.weaver at thenap.com (Drew Weaver) Date: Thu, 9 Apr 2009 05:42:01 -0700 Subject: [c-nsp] best way to network servers with management (iLO/IPMI) Message-ID: Hi there, I am trying to come up with the best way to network servers that have out-of-band management such as the baseboard management controllers in many enterprise servers. Ideally, I would like to be able to assign the management device a RFC 1918 IP, have the actual server be on a different subnet altogether but use a shared port. I know that BMCs generally can use VLAN tagging, but I'm really not sure how I can do all of this with just one port. The 'easy' way is to simply assign a dedicated NIC to the management device and run another cable, but I'm not sure that is the best way to do it. Does anyone have any experience handling the networking side of large server deployments of servers with management capabilities? thanks, -Drew From networkstuff.training at gmail.com Thu Apr 9 08:49:36 2009 From: networkstuff.training at gmail.com (Swati Sharma) Date: Thu, 9 Apr 2009 18:19:36 +0530 Subject: [c-nsp] No route drops packets : 117964064 Message-ID: <8a93d4b30904090549w6367541di30ac41e2744c6c0@mail.gmail.com> Hi, I can see many drops bcos of no route available....it looks strange as this is mpls vpn network (knows abt loopback) and yes Internet routing table is available here. But if some issue on Internet drop should be on peering router... is it a sec. hack efforts!!! RP/0/RP0/CPU0:crs1#sh cef drops CEF Drop Statistics Node: 0/0/CPU0 Unresolved drops packets : 0 Unsupported drops packets : 0 Null0 drops packets : 0 No route drops packets : 22372 No Adjacency drops packets : 0 Checksum error drops packets : 0 RPF drops packets : 0 RPF suppressed drops packets : 0 RP destined drops packets : 0 Node: 0/2/CPU0 Unresolved drops packets : 0 Unsupported drops packets : 218221 Null0 drops packets : 359357 * No route drops packets : 117964064* No Adjacency drops packets : 0 Checksum error drops packets : 0 RPF drops packets : 0 RPF suppressed drops packets : 0 RP destined drops packets : 0 Node: 0/RP0/CPU0 Unresolved drops packets : 0 Unsupported drops packets : 0 Null0 drops packets : 0 No route drops packets : 2662 No Adjacency drops packets : 0 Checksum error drops packets : 0 RPF drops packets : 0 RPF suppressed drops packets : 0 RP destined drops packets : 0 Regards, From achatz at forthnet.gr Thu Apr 9 08:51:38 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Thu, 09 Apr 2009 15:51:38 +0300 Subject: [c-nsp] NAT on ASR1000 In-Reply-To: <20090407165647.GA22725@rtp-cse-489.cisco.com> References: <20090407154647.GQ20028@rtp-cse-489.cisco.com> <49DB792C.6080507@forthnet.gr> <20090407165647.GA22725@rtp-cse-489.cisco.com> Message-ID: <49DDEF5A.5060602@forthnet.gr> We're also evaluating the ASR platform and besides 4 new bugs and 3 not supported features we have found, performance-wise ASR seems like a little monster. RLS5 or RLS6 will probably be our first production release. On the other hand, online documentation is missing a lot of stuff :( While trying to stress the CPU, i was somewhat disappointed by the fact that "sh parser dump exec | i something-that-does-not-exist" makes the CPU go nuts for over 1 hour! IOS should include an option in order to produce a warning after x minutes of cli-command-given-but-no-output-returned. -- Tassos Rodney Dunn wrote on 07/04/2009 19:56: > sh plat software status control-processor brief > Load Average > Slot Status 1-Min 5-Min 15-Min > RP0 Healthy 0.00 0.04 0.01 > ESP0 Healthy 0.00 0.00 0.00 > SIP0 Healthy 0.02 0.02 0.00 > > Memory (kB) > Slot Status Total Used (Pct) Free (Pct) Committed (Pct) > RP0 Healthy 3711920 1525468 (36%) 2186452 (52%) 2438180 (59%) > ESP0 Healthy 2024492 527680 (25%) 1496812 (71%) 2807552 (133%) > SIP0 Healthy 480084 287860 (54%) 192224 (36%) 199468 (38%) > > CPU Utilization > Slot CPU User System Nice Idle IRQ SIRQ IOwait > RP0 0 2.15 1.54 0.00 96.25 0.01 0.03 0.00 > ESP0 0 0.57 0.60 0.00 98.80 0.00 0.01 0.00 > SIP0 0 0.30 0.41 0.00 99.25 0.00 0.01 0.00 > > > It's a live network I worked on over the weekend. It's a pretty high > rate short lived session network. > > We set the timeouts down: > > ip nat translation timeout 1800 > ip nat translation tcp-timeout 900 > ip nat translation udp-timeout 150 > ip nat translation dns-timeout 30 > > show platform hardware cpp active infrastructure exmem statistics > > and there is a lot of QFP memory left: > > Type: Name: IRAM, CPP: 0 > Total: 134217728 > InUse: 4779008 > Free: 128974848 > Free protected: 463872 > Free unprotected: 0 > Lowest free water mark: 129438720 > Largest free block: 99537920 > Type: Name: DRAM, CPP: 0 > Total: 402653184 > InUse: 190609408 > Free: 209715200 > Free protected: 598016 > Free unprotected: 1730560 > Lowest free water mark: 212043776 > Largest free block: 210233344 > > On Tue, Apr 07, 2009 at 07:02:52PM +0300, Tassos Chatzithomaoglou wrote: >> Rodney, can you do a "sh plat soft stat contr br"? >> >> -- >> Tassos >> >> Rodney Dunn wrote on 07/04/2009 18:46: >>> Few bugs still being worked through but the 72xx and 76xx croaked >>> under the load: >>> >>> ASR1002ESP10#sh proc cpu sort | excl 0.00 >>> CPU utilization for five seconds: 0%/0%; one minute: 0%; five minutes: 0% >>> PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process >>> ASR1002ESP10#sh ip nat stat >>> Total active translations: 92367 (80 static, 92287 dynamic; 92287 extended) >>> Outside interfaces: >>> GigabitEthernet0/0/0, Tunnel1 >>> Inside interfaces: >>> GigabitEthernet0/0/1, GigabitEthernet0/0/2 >>> Hits: 0 Misses: 0 >>> CEF Translated packets: 0, CEF Punted packets: 0 >>> Expired translations: 87400847 >>> >>> >>> that's on 12.2(33)XNC and I just filed one bug. >>> >>> CSCsy93931 ASRNAT does not do FIN/RST/SYN timeout when no-payload keyword >>> used >>> >>> >>> My first work on the box with NAT but this thing seems pretty impressive. >>> >>> Anyone else using it for high scale nat yet? >>> >>> Rodney >>> >>> >>> _______________________________________________ >>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>> > From rdobbins at cisco.com Thu Apr 9 09:13:08 2009 From: rdobbins at cisco.com (Roland Dobbins) Date: Thu, 9 Apr 2009 21:13:08 +0800 Subject: [c-nsp] best way to network servers with management (iLO/IPMI) In-Reply-To: References: Message-ID: <68D02AC4-8F1B-4D48-92D4-482F4936ACEF@cisco.com> On Apr 9, 2009, at 8:42 PM, Drew Weaver wrote: > Ideally, I would like to be able to assign the management device a > RFC 1918 IP, have the actual server be on a different subnet > altogether but use a shared port. This isn't a good idea because of fate-sharing - you want your OOB management network to be isolated and bulletproof, and totally unaffected by any problems on the production side. You should use separate NICs, with separate cables, plugged into a separate physical network (unless you're using N7K switches with VDCs, in which case you can safely run the management network on a separate VDC on the same hardware, given the control- and management-plane isolation). ----------------------------------------------------------------------- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott From oboehmer at cisco.com Thu Apr 9 09:59:05 2009 From: oboehmer at cisco.com (Oliver Boehmer (oboehmer)) Date: Thu, 9 Apr 2009 15:59:05 +0200 Subject: [c-nsp] Rate limit Physical interface GSR In-Reply-To: <69329.43725.qm@web44814.mail.sp1.yahoo.com> References: <69329.43725.qm@web44814.mail.sp1.yahoo.com> Message-ID: <70B7A1CCBFA5C649BD562B6D9F7ED7840731DF99@xmb-ams-333.emea.cisco.com> Mark Tech <> wrote on Thursday, April 09, 2009 13:15: > Hi > I would like to cap a physical GE interface to 100mbps whist running > vlans through it on a GSR i.e. > [...] > > However when I apply? the rate-limit command on GE0/0/6, I don't see > any drop in traffic. Actually I have set up a throughput test through > GigabitEthernet0/0/6.2 running at 1Gbps which I can see through sh > int GigabitEthernet0/0/6 which does not drop to 100Mbps once the > rate-limit is added > > Is there a way to cap this aggregate interface? On Engine3/5 linecards, you can use policy-map gig-out class class-default police 1000000000 ! int gig0/0/6 service-policy output gig-out ! int gig0/0/6. ... You can also use "match vlan" classes to provide differentiated treatment for vlans.. oli From oboehmer at cisco.com Thu Apr 9 10:02:19 2009 From: oboehmer at cisco.com (Oliver Boehmer (oboehmer)) Date: Thu, 9 Apr 2009 16:02:19 +0200 Subject: [c-nsp] etherchannel load-balancing on "4 Port ISE GigabitEthernet"? In-Reply-To: <49DDDCA1.4060506@schlund.net> References: <49DDDCA1.4060506@schlund.net> Message-ID: <70B7A1CCBFA5C649BD562B6D9F7ED7840731DFA1@xmb-ams-333.emea.cisco.com> Jan Sandmaier <> wrote on Thursday, April 09, 2009 13:32: > Hi, > > does anybody know how load-balancing in an etherchannel works on a "4 > Port ISE Gigabit Ethernet" for Cisco 12000 in detail? > > I have the following problem: I configured an etherchannel consisting > of two GigabitEthernet ports on the same linecard. Only one port is > utilized (see show command below). There is no inbound traffic and the > outbound traffic originates from various prefixes to basically 3 > prefixes. load-sharing over a link bundle is pretty much identical to "regular" Layer 3 CEF load-sharing. So you need to use a large enough number of flows (i.e. pairs). oli From vijay.ramcharan at verizonbusiness.com Thu Apr 9 10:02:11 2009 From: vijay.ramcharan at verizonbusiness.com (Ramcharan, Vijay A) Date: Thu, 09 Apr 2009 14:02:11 +0000 Subject: [c-nsp] best way to network servers with management (iLO/IPMI) In-Reply-To: <68D02AC4-8F1B-4D48-92D4-482F4936ACEF@cisco.com> Message-ID: <8171C8272CE8FE4A8F5BFF8A97CE6AB36CB770@ASHEVS006.mcilink.com> I second that approach. We use it for our builds whenever possible. You really do want your oob mgmt solution to be as isolated as possible from failures on the production side of things. We usually build a mgmt silo to accommodate out of band connectivity; with one or more fixed-configuration switches depending on site size and budget, firewall and ISR router. A separate circuit for remote connectivity as well with failover to IPSec/DMVPN. It's obviously more expensive but it sure goes a long way in reducing visits to customer sites. ilo ports used to be simpler, 1 ilo port connected to one mgmt switch port. With blade chassis and the move there to reduce cabling, blades can now share one physical ilo port on their chassis/enclosure. However, that still doesn't change mgmt connectivity as you still would want to have this single physical connection on a mgmt switch. Vijay Ramcharan -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Roland Dobbins Sent: April 09, 2009 09:13 To: Cisco-nsp Subject: Re: [c-nsp] best way to network servers with management (iLO/IPMI) On Apr 9, 2009, at 8:42 PM, Drew Weaver wrote: > Ideally, I would like to be able to assign the management device a > RFC 1918 IP, have the actual server be on a different subnet > altogether but use a shared port. This isn't a good idea because of fate-sharing - you want your OOB management network to be isolated and bulletproof, and totally unaffected by any problems on the production side. You should use separate NICs, with separate cables, plugged into a separate physical network (unless you're using N7K switches with VDCs, in which case you can safely run the management network on a separate VDC on the same hardware, given the control- and management-plane isolation). ----------------------------------------------------------------------- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ ______________________________________________________________________ This e-mail has been scanned by Verizon Managed Email Content Service, using Skeptic(tm) technology powered by MessageLabs. For more information on Verizon Managed Email Content Service, visit http://www.verizonbusiness.com. ______________________________________________________________________ From techconfig at yahoo.com Thu Apr 9 10:19:38 2009 From: techconfig at yahoo.com (Mark Tech) Date: Thu, 9 Apr 2009 07:19:38 -0700 (PDT) Subject: [c-nsp] Rate limit Physical interface GSR In-Reply-To: <70B7A1CCBFA5C649BD562B6D9F7ED7840731DF99@xmb-ams-333.emea.cisco.com> References: <69329.43725.qm@web44814.mail.sp1.yahoo.com> <70B7A1CCBFA5C649BD562B6D9F7ED7840731DF99@xmb-ams-333.emea.cisco.com> Message-ID: <362613.58951.qm@web44812.mail.sp1.yahoo.com> Hi Oli Thanks for that. I have tried that however I still see the interface as unaffected interface GigabitEthernet0/0/6 ?no ip address ?no ip directed-broadcast ?no negotiation auto ?service-policy input gig-in ?service-policy output gig-out policy-map gig-out ? class class-default ?? police 64000 4470 4470 policy-map gig-in ? class class-default ?? police 64000 4470 4470 GigabitEthernet0/0/6 is up, line protocol is up ? ? 5 minute input rate 915130000 bits/sec, 417475 packets/sec ? 5 minute output rate 915116000 bits/sec, 417467 packets/sec The sub-interfaces are in vrfs, will that affect this? Cheers Mark ? ----- Original Message ---- From: Oliver Boehmer (oboehmer) To: Mark Tech ; cisco-nsp at puck.nether.net Sent: Thursday, April 9, 2009 2:59:05 PM Subject: RE: [c-nsp] Rate limit Physical interface GSR Mark Tech <> wrote on Thursday, April 09, 2009 13:15: > Hi > I would like to cap a physical GE interface to 100mbps whist running > vlans through it on a GSR i.e. > [...] > > However when I apply? the rate-limit command on GE0/0/6, I don't see > any drop in traffic. Actually I have set up a throughput test through > GigabitEthernet0/0/6.2 running at 1Gbps which I can see through sh > int GigabitEthernet0/0/6 which does not drop to 100Mbps once the > rate-limit is added? ? > > Is there a way to cap this aggregate interface? On Engine3/5 linecards, you can use policy-map gig-out class class-default ? police 1000000000 ! int gig0/0/6 service-policy output gig-out ! int gig0/0/6. ... You can also use "match vlan" classes to provide differentiated treatment for vlans.. ??? oli From oboehmer at cisco.com Thu Apr 9 10:33:43 2009 From: oboehmer at cisco.com (Oliver Boehmer (oboehmer)) Date: Thu, 9 Apr 2009 16:33:43 +0200 Subject: [c-nsp] Rate limit Physical interface GSR In-Reply-To: <362613.58951.qm@web44812.mail.sp1.yahoo.com> References: <69329.43725.qm@web44814.mail.sp1.yahoo.com> <70B7A1CCBFA5C649BD562B6D9F7ED7840731DF99@xmb-ams-333.emea.cisco.com> <362613.58951.qm@web44812.mail.sp1.yahoo.com> Message-ID: <70B7A1CCBFA5C649BD562B6D9F7ED7840731DFCD@xmb-ams-333.emea.cisco.com> Hmm, can you replace the class-default with something like class-map all-vlans match vlan x y z ... where x y z match your vlan IDs, and see if this changes things? What does "show policy-map int gig0/0/6" say? What type of linecard engine is this? E5/SIP? vrf shouldn't make a difference.. oli Mark Tech wrote on Thursday, April 09, 2009 16:20: > Hi Oli > > Thanks for that. I have tried that however I still see the interface > as unaffected > > interface GigabitEthernet0/0/6 > ?no ip address > ?no ip directed-broadcast > ?no negotiation auto > ?service-policy input gig-in > ?service-policy output gig-out > > policy-map gig-out > ? class class-default > ?? police 64000 4470 4470 > > policy-map gig-in > ? class class-default > ?? police 64000 4470 4470 > > GigabitEthernet0/0/6 is up, line protocol is up > > ? 5 minute input rate 915130000 bits/sec, 417475 packets/sec > ? 5 minute output rate 915116000 bits/sec, 417467 packets/sec > > > The sub-interfaces are in vrfs, will that affect this? > > Cheers > > Mark > > > > > ----- Original Message ---- > From: Oliver Boehmer (oboehmer) > To: Mark Tech ; cisco-nsp at puck.nether.net > Sent: Thursday, April 9, 2009 2:59:05 PM > Subject: RE: [c-nsp] Rate limit Physical interface GSR > > Mark Tech <> wrote on Thursday, April 09, 2009 13:15: > >> Hi >> I would like to cap a physical GE interface to 100mbps whist running >> vlans through it on a GSR i.e. >> > [...] >> >> However when I apply? the rate-limit command on GE0/0/6, I don't see >> any drop in traffic. Actually I have set up a throughput test through >> GigabitEthernet0/0/6.2 running at 1Gbps which I can see through sh >> int GigabitEthernet0/0/6 which does not drop to 100Mbps once the >> rate-limit is added >> >> Is there a way to cap this aggregate interface? > > On Engine3/5 linecards, you can use > > policy-map gig-out > class class-default > ? police 1000000000 > ! > int gig0/0/6 > service-policy output gig-out > ! > int gig0/0/6. > ... > > You can also use "match vlan" classes to provide differentiated > treatment for vlans.. > > ??? oli From MatlockK at exempla.org Thu Apr 9 09:56:09 2009 From: MatlockK at exempla.org (Matlock, Kenneth L) Date: Thu, 9 Apr 2009 07:56:09 -0600 Subject: [c-nsp] best way to network servers with management (iLO/IPMI) In-Reply-To: <68D02AC4-8F1B-4D48-92D4-482F4936ACEF@cisco.com> References: <68D02AC4-8F1B-4D48-92D4-482F4936ACEF@cisco.com> Message-ID: <4288131ED5E3024C9CD4782CECCAD2C7065D3474@LMC-MAIL2.exempla.org> I agree. We completely isolate the ILO onto it's own discrete network. We supply Cisco 2950/2960's at the top of each rack, and it's on it's own RFC1918 IP block. Each ILO gets it's own /27, not related at all to the IP blocks the main servers use. The 2950/2960's then plug into a distribution pair, unrelated to the distribution layer the real NIC connectivity goes through. Now, I realize not a lot of companies have that luxury, so compromises sometimes have to be made. Ken Matlock Network Analyst Exempla Healthcare (303) 467-4671 matlockk at exempla.org -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Roland Dobbins Sent: Thursday, April 09, 2009 7:13 AM To: Cisco-nsp Subject: Re: [c-nsp] best way to network servers with management (iLO/IPMI) On Apr 9, 2009, at 8:42 PM, Drew Weaver wrote: > Ideally, I would like to be able to assign the management device a > RFC 1918 IP, have the actual server be on a different subnet > altogether but use a shared port. This isn't a good idea because of fate-sharing - you want your OOB management network to be isolated and bulletproof, and totally unaffected by any problems on the production side. You should use separate NICs, with separate cables, plugged into a separate physical network (unless you're using N7K switches with VDCs, in which case you can safely run the management network on a separate VDC on the same hardware, given the control- and management-plane isolation). ----------------------------------------------------------------------- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From techconfig at yahoo.com Thu Apr 9 10:56:19 2009 From: techconfig at yahoo.com (Mark Tech) Date: Thu, 9 Apr 2009 07:56:19 -0700 (PDT) Subject: [c-nsp] Rate limit Physical interface GSR In-Reply-To: <70B7A1CCBFA5C649BD562B6D9F7ED7840731DFCD@xmb-ams-333.emea.cisco.com> References: <69329.43725.qm@web44814.mail.sp1.yahoo.com> <70B7A1CCBFA5C649BD562B6D9F7ED7840731DF99@xmb-ams-333.emea.cisco.com> <362613.58951.qm@web44812.mail.sp1.yahoo.com> <70B7A1CCBFA5C649BD562B6D9F7ED7840731DFCD@xmb-ams-333.emea.cisco.com> Message-ID: <639983.88123.qm@web44803.mail.sp1.yahoo.com> Hi tried the vlan policy map with standard and hierarchical but get the same issue when applying to an interface policy-map gig-out ? class all-vlans ?? police 64000 4470 4470 policy-map parent-gig-out ? class class-default ?? service-policy gig-out class-map match-all all-vlans ? match vlan? 1-4095 (config)#int gigabitEthernet 0/0/6 (config-if)#service-policy output parent-gig-out % 'match vlan/pseudowire' not supported in gig-out The GSR cards? are 12000-SIP-601 and?SPA-10X1GE-V2 ----- Original Message ---- From: Oliver Boehmer (oboehmer) To: Mark Tech ; cisco-nsp at puck.nether.net Sent: Thursday, April 9, 2009 3:33:43 PM Subject: RE: [c-nsp] Rate limit Physical interface GSR Hmm, can you replace the class-default with something like class-map all-vlans match vlan x y z ... where x y z match your vlan IDs, and see if this changes things? What does "show policy-map int gig0/0/6" say? What type of linecard engine is this? E5/SIP? vrf shouldn't make a difference.. ??? oli Mark Tech wrote on Thursday, April 09, 2009 16:20: > Hi Oli > > Thanks for that. I have tried that however I still see the interface > as unaffected > > interface GigabitEthernet0/0/6 > ?no ip address > ?no ip directed-broadcast > ?no negotiation auto > ?service-policy input gig-in > ?service-policy output gig-out > > policy-map gig-out > ? class class-default > ?? police 64000 4470 4470 > > policy-map gig-in > ? class class-default > ?? police 64000 4470 4470 > > GigabitEthernet0/0/6 is up, line protocol is up > > ? 5 minute input rate 915130000 bits/sec, 417475 packets/sec > ? 5 minute output rate 915116000 bits/sec, 417467 packets/sec > > > The sub-interfaces are in vrfs, will that affect this? > > Cheers > > Mark > > > > > ----- Original Message ---- > From: Oliver Boehmer (oboehmer) > To: Mark Tech ; cisco-nsp at puck.nether.net > Sent: Thursday, April 9, 2009 2:59:05 PM > Subject: RE: [c-nsp] Rate limit Physical interface GSR > > Mark Tech <> wrote on Thursday, April 09, 2009 13:15: > >> Hi >> I would like to cap a physical GE interface to 100mbps whist running >> vlans through it on a GSR i.e. >> > [...] >> >> However when I apply? the rate-limit command on GE0/0/6, I don't see >> any drop in traffic. Actually I have set up a throughput test through >> GigabitEthernet0/0/6.2 running at 1Gbps which I can see through sh >> int GigabitEthernet0/0/6 which does not drop to 100Mbps once the >> rate-limit is added >> >> Is there a way to cap this aggregate interface? > > On Engine3/5 linecards, you can use > > policy-map gig-out > class class-default > ? police 1000000000 > ! > int gig0/0/6 > service-policy output gig-out > ! > int gig0/0/6. > ... > > You can also use "match vlan" classes to provide differentiated > treatment for vlans.. > > ??? oli From frnkblk at iname.com Thu Apr 9 11:20:55 2009 From: frnkblk at iname.com (Frank Bulk) Date: Thu, 9 Apr 2009 10:20:55 -0500 Subject: [c-nsp] video,voip and internet over DSL (converged) In-Reply-To: <876789290904081922te84a61ev1da8dff3f198b322@mail.gmail.com> References: <876789290904081922te84a61ev1da8dff3f198b322@mail.gmail.com> Message-ID: The hardest part to IPTV is not the technical aspect, but establishing contracts with the content providers, and additionally, encryption. If you can address those issues (first), then the next steps will be clear. There's a lot of middleware vendors out there, but I'm not sure any of them are interested in a single MDU, even though it's large. You may want to talk to VideoFurnace, which does a lot for HigherEd. Frank -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Dracul Sent: Wednesday, April 08, 2009 9:22 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] video,voip and internet over DSL (converged) Hi list, is it feasible to broadcast video/voip + internet over DSL like lets say I deploy a cisco DSLAM infra in a 20 storey building. It would run over a media server solution and a VOIP network. I am not sure if this would be a stable solution considering I want to broadcast HD and SD alike plus VOIP and internet to boot. Any cons? like noise level or quality of the video or quality of bandwidth etc. because DSL transport is just running over copper right? Or would I be better off running fibre? But of course cost will then quantify the use of DSL. regards, Chris _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From sethm at rollernet.us Thu Apr 9 12:20:34 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Thu, 09 Apr 2009 09:20:34 -0700 Subject: [c-nsp] best way to network servers with management (iLO/IPMI) In-Reply-To: <68D02AC4-8F1B-4D48-92D4-482F4936ACEF@cisco.com> References: <68D02AC4-8F1B-4D48-92D4-482F4936ACEF@cisco.com> Message-ID: <49DE2052.6080609@rollernet.us> Roland Dobbins wrote: > > On Apr 9, 2009, at 8:42 PM, Drew Weaver wrote: > >> Ideally, I would like to be able to assign the management device a RFC >> 1918 IP, have the actual server be on a different subnet altogether >> but use a shared port. > > This isn't a good idea because of fate-sharing - you want your OOB > management network to be isolated and bulletproof, and totally > unaffected by any problems on the production side. You should use > separate NICs, with separate cables, plugged into a separate physical > network (unless you're using N7K switches with VDCs, in which case you > can safely run the management network on a separate VDC on the same > hardware, given the control- and management-plane isolation). > Sometimes you just don't have a choice. I have two older Dell servers that only give you the option of a shared ethernet port for their onboard IPMI, take it or leave it. So I just put the port on a trunk: interface FastEthernet0/3 switchport trunk encapsulation dot1q switchport trunk native vlan 4 switchport trunk allowed vlan 1,2,4,1002-1005 switchport mode trunk spanning-tree portfast Where VLAN2 is the management network and VLAN4 is the server network. You could put the smallest switch you can find that understand vlans in front of each server and break the two vlans out to individual untagged ports, but you'll still need the trunk to get to the server. ~Seth From tedm at toybox.placo.com Thu Apr 9 12:32:11 2009 From: tedm at toybox.placo.com (Ted Mittelstaedt) Date: Thu, 09 Apr 2009 09:32:11 -0700 Subject: [c-nsp] DNS Tool In-Reply-To: References: <49DD1A5A.2020001@rainierconnect.net> Message-ID: <49DE230B.2020802@toybox.placo.com> Without having a more detailed explanation of what browsing problems your having, it's difficult to give any more specific advice, but here goes: 1) browsers cache DNS lookups, so if your having repetitive lookups fail off the same browser session, it's not actually a DNS problem even though it might seem like one. 2) client operating systems also cache DNS lookups so if your having repetitive lookups fail off multiple browser sessions it's not actually a DNS problem even though it might seem like one. 3) if lookups work fine with nslookup but appear to fail in the browser it's not actually a DNS problem 4) If you override your client OS DNS server IP addresses with your ISP's DNS server IP addresses and you have lookup problems it's not actually a DNS problem. I think you probably are starting to get the picture here - many things that people -think- are DNS problems actually aren't. As long as your being coy about what the exact problem is, your not going to get much useful advice from us. There's no need to be embarassed, all of us have gone through these kinds of problems before, often of our own making. Practially all "DNS problems" I've ever troubleshot turned out to be layer-2 problems, not DNS problems. Just a thought. Ted Mohammad Khalil wrote: > We are facing some browsing problems , so we want to make sure that our DNS servers are resolving well using tools other than nslookup > >> Date: Wed, 8 Apr 2009 14:42:50 -0700 >> From: walter.keen at rainierconnect.net >> To: eng_mssk at hotmail.com >> CC: cisco-nsp at puck.nether.net >> Subject: Re: [c-nsp] DNS Tool >> >> Could you elaborate a little? >> >> We use Nagios to monitor other things, and use a DNS check plugin that >> simply does a dns query and reports if it successfully got an answer. I >> think there are other ones that will compare the answer to a known good >> answer you supply (wouldn't work well with something like Google.com or >> yahoo.com that does a lot of round robin entries) >> >> Mohammad Khalil wrote: >>> Hey all >>> is there any tool that can monitor the DNS behavior ?? >>> for example , the resolving process and if there are any errors ?? >>> >>> Thanks >>> >>> _________________________________________________________________ >>> Drag n? drop?Get easy photo sharing with Windows Live? Photos. >>> >>> http://www.microsoft.com/windows/windowslive/products/photos.aspx >>> _______________________________________________ >>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > > _________________________________________________________________ > Show them the way! Add maps and directions to your party invites. > http://www.microsoft.com/windows/windowslive/products/events.aspx > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From rdobbins at cisco.com Thu Apr 9 12:32:24 2009 From: rdobbins at cisco.com (Roland Dobbins) Date: Fri, 10 Apr 2009 00:32:24 +0800 Subject: [c-nsp] best way to network servers with management (iLO/IPMI) In-Reply-To: <49DE2052.6080609@rollernet.us> References: <68D02AC4-8F1B-4D48-92D4-482F4936ACEF@cisco.com> <49DE2052.6080609@rollernet.us> Message-ID: On Apr 10, 2009, at 12:20 AM, Seth Mattinen wrote: > I have two older Dell servers that only give you the option of a > shared ethernet port for their > onboard IPMI, take it or leave it. So, you can use the built-in port for that, and insert another NIC for use on the production side, yes? ;> ----------------------------------------------------------------------- Roland Dobbins // +852.9133.2844 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott From sethm at rollernet.us Thu Apr 9 13:26:53 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Thu, 09 Apr 2009 10:26:53 -0700 Subject: [c-nsp] best way to network servers with management (iLO/IPMI) In-Reply-To: References: <68D02AC4-8F1B-4D48-92D4-482F4936ACEF@cisco.com> <49DE2052.6080609@rollernet.us> Message-ID: <49DE2FDD.1000704@rollernet.us> Roland Dobbins wrote: > > On Apr 10, 2009, at 12:20 AM, Seth Mattinen wrote: > >> I have two older Dell servers that only give you the option of a >> shared ethernet port for their >> onboard IPMI, take it or leave it. > > So, you can use the built-in port for that, and insert another NIC for > use on the production side, yes? > One could, but the single PCI-X (yes there's one and only one, not two) slot is taken by a RAID card and the other onboard GE port is being used for SAN access. ;) For the OP, yes, do use a dedicated port even though it can drastically expand your cabling and switching needs if you have a lot of servers. Port sharing is a horrible, horrible hack. ~Seth From cisco-nsp at natecarlson.com Thu Apr 9 13:16:33 2009 From: cisco-nsp at natecarlson.com (Nate Carlson) Date: Thu, 9 Apr 2009 12:16:33 -0500 (CDT) Subject: [c-nsp] best way to network servers with management (iLO/IPMI) In-Reply-To: References: Message-ID: On Thu, 9 Apr 2009, Drew Weaver wrote: > Ideally, I would like to be able to assign the management device a RFC > 1918 IP, have the actual server be on a different subnet altogether but > use a shared port. I know that BMCs generally can use VLAN tagging, but > I'm really not sure how I can do all of this with just one port. Yeah, you can.. enable VLAN trunking on the port, set your native VLAN to whatever you want the OS's main interface to be on, allow the VLAN you want management on as tagged, and set up your IPMI card to tag on that VLAN. Works fine. The OS can still get at the management VLAN, though, if you enable VLAN tagging on the OS-level and set up an interface on that VLAN. > The 'easy' way is to simply assign a dedicated NIC to the management > device and run another cable, but I'm not sure that is the best way to > do it. ..however, it is always my recommendation to use a dedicated NIC if you can. I've seen lots of issues with IPMI cards and shared interfaces.. for example, with many of the Supermicro motherboard and ipmi combos, when you assign an IP to the shared interface under Linux, all the sudden the IPMI stops working. Ooops. I think this is fixed in 2.6.27+, but still.. With the dedicated NIC, it's usually a completely isolated PHY, etc, so no matter what happens to the system itself, you can still get at IPMI, unless you lose power to that interface card. From raa at opusnet.com Thu Apr 9 14:34:16 2009 From: raa at opusnet.com (Ruben Alvarez) Date: Thu, 9 Apr 2009 11:34:16 -0700 Subject: [c-nsp] Ping priority on Cisco devices In-Reply-To: <49DD1BAD.6020604@toybox.placo.com> References: <004901c9b874$59596e00$0c0c4a00$@com> <49DD1BAD.6020604@toybox.placo.com> Message-ID: <004a01c9b941$caa789c0$5ff69d40$@com> Hi, Thanks for the reply. It running at ~18% cpu and is a 7206vxr w/NPE300. This morning the loss cleared up. I didn't collect enough data yesterday to really get to the bottom of this, so I'll drop it as a Qwest megahost issue. -----Original Message----- From: Ted Mittelstaedt [mailto:tedm at toybox.placo.com] Sent: Wednesday, April 08, 2009 2:48 PM To: Ruben Alvarez Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] Ping priority on Cisco devices Ruben Alvarez wrote: > All, > > I've heard that Cisco devices handle ICMP at a low priority. I found one > post describing it handled in process-switching and not fast-switching. > Does anyone have an article that explains that process and is it > configurable? > > The reason I ask is I see about 4% packet loss when I ping devices in our > broadband aggregation network. From the CPE to the router there is none, > from my workstation to the router there is none, but if I ping the whole > path I get a fairly consistent 4% loss. I can't find any congestion or > errors. Ping from my workstation to the CPE are a consistent 60ms, aside > from the 4% loss. > > Thanks. > > What model is your router and can you post a config? What is CPU utilization on the router? What is memory utilization on the router? Ted From fwc at mt.net Thu Apr 9 14:05:53 2009 From: fwc at mt.net (Forrest W. Christian) Date: Thu, 09 Apr 2009 12:05:53 -0600 Subject: [c-nsp] Sonet "hard" patterns for testing Message-ID: <49DE3901.1030807@mt.net> I just got bit by a problem with scrambling not being on on a POS OC3 with a upstream provider... (Long story - provisioning person at provider had no clue... insisted that it wasn't needed). Symptom of course was certain files just not being able to be transfered past a certain point - where the file contained patterns not possible to transmit across a non-scrambled POS circuit. Took me a while to find it, though, because normal ping packets of course go through just fine, 100% of the time. In testing this, though, I would have loved to have some payloads for ping packets which weren't sendable on a non-scrambled POS circuit.. and probably other underlying circuits also. Sort of a set of "difficult" packets to try to send. Google has not been my friend in this regard... probably not using the right keywords, if the data exists out there at all. Ideas? -forrest From billw at waveform.net Thu Apr 9 19:38:23 2009 From: billw at waveform.net (Bill Wichers) Date: Thu, 9 Apr 2009 19:38:23 -0400 Subject: [c-nsp] Sonet "hard" patterns for testing In-Reply-To: <49DE3901.1030807@mt.net> References: <49DE3901.1030807@mt.net> Message-ID: The problem data strings are usually either strings that match control codes or long sequences of either all ones or all zeroes. If too many bits go by without any transitions it is possible for the receiver to loose sync with the network. You might want to just try a packet of all zeroes or ones as an experiment. You might try looking up one of the earlier documents detailing the SONET specification. There used to be a lot more concern for timing and jitter and the like than there is now, which I think is due to better time bases in modern gear making many of those issues less of a problem. I'd try looking for things like "jitter" and "clocking" in your search. While those might not key in on what you're looking for directly, they're likely to find you information that also includes some of what you're looking for. -Bill > I just got bit by a problem with scrambling not being on on a POS OC3 > with a upstream provider... (Long story - provisioning person at > provider had no clue... insisted that it wasn't needed). Symptom of > course was certain files just not being able to be transfered past a > certain point - where the file contained patterns not possible to > transmit across a non-scrambled POS circuit. Took me a while to find > it, though, because normal ping packets of course go through just fine, > 100% of the time. > > In testing this, though, I would have loved to have some payloads for > ping packets which weren't sendable on a non-scrambled POS circuit.. and > probably other underlying circuits also. Sort of a set of "difficult" > packets to try to send. > > Google has not been my friend in this regard... probably not using the > right keywords, if the data exists out there at all. > > Ideas? > > -forrest From hegedus.gabor at euroway.hu Fri Apr 10 05:09:32 2009 From: hegedus.gabor at euroway.hu (Hegedus Gabor) Date: Fri, 10 Apr 2009 11:09:32 +0200 Subject: [c-nsp] c861w wifi problem: reached max retries Message-ID: <49DF0CCC.4050103@euroway.hu> Hi all! I have a problem! I see this log in my c861W ap: Apr 10 06:48:42: %DOT11-6-ROAMED: Station 001f.0000.f4ab Roamed to 001d.70d0.0001 Apr 10 06:48:42: %DOT11-4-MAXRETRIES: Packet to client 001f.3b20.f4ab reached max retries, removing the client Apr 10 06:49:14: %DOT11-6-ROAMED: Station 001f.0000.f4ab Roamed to 001d.7060.0002 Apr 10 06:59:46: %DOT11-6-ASSOC: Interface Dot11Radio0, Station 001f.0000.f4ab Reassociated KEY_MGMT[WPAv2] Apr 10 07:00:23: %DOT11-6-ROAMED: Station 001f.0000.f4ab Roamed to 001d.70d0.0001 Apr 10 07:00:23: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 001f.3b20.f4ab Apr 10 07:00:23: %DOT11-4-MAXRETRIES: Packet to client 001f.0000.f4ab reached max retries, removing the client Apr 10 07:07:08: %DOT11-6-ASSOC: Interface Dot11Radio0, Station 001f.0000.f4ab Reassociated KEY_MGMT[WPAv2-CP] Apr 10 07:07:38: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 001f.0000.f4ab Reason: Sending station has left the BSS Apr 10 07:31:33: %DOT11-6-ASSOC: Interface Dot11Radio0, Station 001f.0000.f4ab Reassociated KEY_MGMT[WPAv2-CP] Apr 10 07:32:03: %DOT11-6-DISASSOC: Interface Dot11Radio0, Deauthenticating Station 001f.0000.f4ab Reason: Sending station has left the BSS Apr 10 07:36:59: %DOT11-4-MAXRETRIES: Packet to client 001f.0000.f4ab reached max retries, removing the client Apr 10 07:36:59: Client 001f.0000.f4ab failed: reached maximum retries What is the problem? cisco says: Explanation: This error message indicates that the access point attempts to poll the client a certain number of times, but does not receive a response. Therefore, the client is removed from the association table. This issue is commonly seen when the client and access point are attempting to communicate in a noisy RF environment. Recommended Action: To resolve this issue, run a carrier busy test on the access point to determine if there is excessive noise in the radio channel spectrum. Attempt to alleviate any unwanted noise. For more information, refer to the "Performing a Carrier Busy Test" section on page 6-26 . In Carrier Busy test, there is nothing ostentatious. software version: (AP801-K9W7-M), Version 12.4(10b)JA3, I use the 5 devices in WDS, roaming works, current wireless channel: 13 Any idea what is the problem? If I use WDS, do all of the APs in the WDS domain have to use the same channel or not? Thank you for help guys. Gabor I send you a sample of the configuration: dot11 ssid test vlan 1 authentication open eap method_clients authentication network-eap method_clients authentication key-management wpa version 2 accounting method_clients ! interface Dot11Radio0 no ip address no ip route-cache ! encryption vlan 1 mode ciphers tkip ! encryption vlan 2 mode ciphers tkip ! ssid test ! ssid test2 ! station-role root no dot11 extension aironet ! From justin at justinshore.com Fri Apr 10 11:14:10 2009 From: justin at justinshore.com (Justin Shore) Date: Fri, 10 Apr 2009 10:14:10 -0500 Subject: [c-nsp] OT: SNMP Trap manager recommendation Message-ID: <49DF6242.4090301@justinshore.com> I'm in need of a decent SNMP Trap manager that scales and is free (OSS) or cheap. I currently Nagios for my NMS and Cacti for data collection and graphing so clearly I'm a fan of OSS solutions. I read an article several years ago in the now defunct SysAdmin magazine on tying in SNMP-TT into Nagios. Is there a better way? I need to collect traps from Hatteras equipment mainly but once I have it I'm sure I'll use it for other things as well. My searches have so far turned up JFFNMS, OpenNMS, Mila NetWhistler, NetCool (expensive?) and a few others. There's also the GroundWork fork of Nagios and other OSS tools that may be useful. Any recommendations? Thanks Justin From danletkeman at gmail.com Fri Apr 10 11:30:08 2009 From: danletkeman at gmail.com (Dan Letkeman) Date: Fri, 10 Apr 2009 10:30:08 -0500 Subject: [c-nsp] passive ftp static nat Message-ID: Hello, I'm having trouble logging into our ftp server from an external source. It works when you set the client to active mode, but passive mode always hangs. 2821, IOS Firewall Relevant config: ip inspect name SDM_LOW ftp interface GigabitEthernet0/0 ip address 10.10.10.1 255.255.255.252 ip nat inside ! ! interface FastEthernet0/0/3 description Internet switchport access vlan 800 bandwidth 10000 no cdp enable ! ! interface Vlan800 description Internet bandwidth 10000 ip address 64.x.x.1 255.255.255.224 ip access-group firewall in no ip redirects no ip unreachables no ip proxy-arp ip flow ingress ip nat outside ip inspect SDM_LOW out ip virtual-reassembly no mop enabled ! ! ip nat pool 152 64.x.x.1 64.x.x.1 netmask 255.255.255.224 ip nat inside source list internet-152 pool 152 overload ip nat inside source static tcp 172.16.0.24 21 64.x.x.1 21 extendable ip nat inside source static tcp 172.16.0.24 80 64.x.x.1 80 extendable ! ip access-list extended firewall permit tcp any host 64.x.x.1 eq ftp deny ip any any log ! ip access-list extended internet-152 permit tcp host 172.16.0.24 any I have tried adding: "permit tcp any host 64.x.x.1 gt 1024 established" to the firewall acl, but it still does not seem to connect from a passive ftp client. Dan. From justin at justinshore.com Fri Apr 10 11:41:37 2009 From: justin at justinshore.com (Justin Shore) Date: Fri, 10 Apr 2009 10:41:37 -0500 Subject: [c-nsp] OT: Service provider-oriented QoS training Message-ID: <49DF68B1.70900@justinshore.com> I'm in need of a SP-oriented QoS training class. We're just starting to deploy voice over G.SHDSL and bonded DS1s and are reaching out to more businesses than ever before. My meager QoS knowledge (I can spell it and talk real big) isn't cutting it anymore. I need guidance on QoS in an MPLS core, in a MetroE environment, re-coloring untrusted traffic at the edge, SP-provided voice and video (IPTV), edge product offerings that include certain QoS parameters (QoS for VoIP, gaming, etc), etc. The docs and books don't seem to be cutting it for me. I'm sure they're fine for someone with a solid background in QoS but I'm afraid that doesn't describe me. I'll pick it up I'm sure if I can spend a few days with an instructor in a classroom setting away from the phone (my phone at least). Any suggestions? The closest thing I've been able to find is the "Advanced Cisco Quality of Service" class from GlobalKnowledge, but it appears to be aimed more towards enterprises. http://www.globalknowledge.com/training/course.asp?pageid=9&courseid=9368&catid=206&country=United+States On a slightly different topic, what does everyone use for monitoring voice quality for VoIP customers? Something that can capture calls and either hand us Wireshark-readable packet dumps or break it down in a web GUI for the non-Wireshark savvy to use would be great. EdgeMarc has their EdgeView server with call quality monitoring features that look good but I'm pretty sure that it requires their CPE as well which is really not what we need or want. What else is out there that SP's use for IP soft switches? Thanks Justin From tedm at toybox.placo.com Fri Apr 10 13:06:54 2009 From: tedm at toybox.placo.com (Ted Mittelstaedt) Date: Fri, 10 Apr 2009 10:06:54 -0700 Subject: [c-nsp] Ping priority on Cisco devices In-Reply-To: <004a01c9b941$caa789c0$5ff69d40$@com> References: <004901c9b874$59596e00$0c0c4a00$@com> <49DD1BAD.6020604@toybox.placo.com> <004a01c9b941$caa789c0$5ff69d40$@com> Message-ID: <49DF7CAE.3010002@toybox.placo.com> Hi Ruben, If you running 12.3 or later IOS I'd suggest backreving to 12.2. fast switching is a problematical thing in the newer IOS on these older CPU cards. I'd guess that even if you have ip cef defined in your config, that cef isn't actually running. what does show ip cef, show cef day? IOS 12.1/12.2 is about the newest most people go on the NPE300 Ted Ruben Alvarez wrote: > Hi, > > Thanks for the reply. It running at ~18% cpu and is a 7206vxr w/NPE300. > This morning the loss cleared up. I didn't collect enough data yesterday to > really get to the bottom of this, so I'll drop it as a Qwest megahost issue. > > -----Original Message----- > From: Ted Mittelstaedt [mailto:tedm at toybox.placo.com] > Sent: Wednesday, April 08, 2009 2:48 PM > To: Ruben Alvarez > Cc: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] Ping priority on Cisco devices > > Ruben Alvarez wrote: > >> All, >> >> I've heard that Cisco devices handle ICMP at a low priority. I found one >> post describing it handled in process-switching and not fast-switching. >> Does anyone have an article that explains that process and is it >> configurable? >> >> The reason I ask is I see about 4% packet loss when I ping devices in our >> broadband aggregation network. From the CPE to the router there is none, >> from my workstation to the router there is none, but if I ping the whole >> path I get a fairly consistent 4% loss. I can't find any congestion or >> errors. Ping from my workstation to the CPE are a consistent 60ms, aside >> from the 4% loss. >> >> Thanks. >> >> >> > What model is your router and can you post a config? > > What is CPU utilization on the router? What is memory utilization on > the router? > > Ted > > From rubensk at gmail.com Fri Apr 10 14:10:04 2009 From: rubensk at gmail.com (Rubens Kuhl) Date: Fri, 10 Apr 2009 15:10:04 -0300 Subject: [c-nsp] OT: SNMP Trap manager recommendation In-Reply-To: <49DF6242.4090301@justinshore.com> References: <49DF6242.4090301@justinshore.com> Message-ID: <6bb5f5b10904101110k1adbee70pc144d671a164d82f@mail.gmail.com> > My searches have so far turned up JFFNMS, OpenNMS, Mila NetWhistler, NetCool > (expensive?) and a few others. ?There's also the GroundWork fork of Nagios > and other OSS tools that may be useful. On the "few others" section, Castlerock's SNMPc is a nice, cheap product we are very fond of. What's Up Gold and Solarwinds ipMonitor and Orion NPM might also fit one's budget, but no direct experience on those. Rubens From awain567 at yahoo.com Fri Apr 10 14:16:27 2009 From: awain567 at yahoo.com (Alex Wa) Date: Fri, 10 Apr 2009 11:16:27 -0700 (PDT) Subject: [c-nsp] RSPAN VLAN filter & TCAM issue Message-ID: <796193.38319.qm@web58008.mail.re3.yahoo.com> Hi guys, ? We're receiving this log message when trying to apply a vlan filter to a RSPAN VLAN. ? Apr 10 13:36:08.580: %FM-4-TCAM_ENTRY: Hardware TCAM entry capacity exceeded Apr 10 13:36:08.580: %FM-2-VACL_FAILURE: Interface Vlan100 traffic will not comply with VACLs in ingress direction(s) ? We don't have any access list applied to any interface except the VLAN filter , and in total 16 access-lists. the sh tcam counts is below (when the output was taken the vlan filter wasn't applied) ? ?????????? Used??????? Free??????? Percent Used?????? Reserved ?????????? ----??????? ----??????? ------------?????? -------- ?Labels:????? 2???????? 510??????????? 0 ACL_TCAM ? Masks:????? 2??????? 4094??????????? 0???????????????????? 0 Entries:???? 16?????? 32752??????????? 0???????????????????? 0 QOS_TCAM ? Masks:????? 0??????? 4096??????????? 0???????????????????? 0 Entries:????? 0?????? 32768??????????? 0???????????????????? 0 ??? LOU:????? 0????????? 64??????????? 0 ? ANDOR:????? 0????????? 16??????????? 0 ? ORAND:????? 1????????? 15??????????? 6 ??? ADJ:????? 0??????? 1024??????????? 0? ? Cisco's error decoder recomends to delete unused access list but we can't reduce no more and 16 acess lists ?is a normal, if not low, amount . ? any hint ? ? thanks in advance, Alejandro Wainshtok From bdikici at gmail.com Fri Apr 10 18:55:09 2009 From: bdikici at gmail.com (Burak Dikici) Date: Sat, 11 Apr 2009 01:55:09 +0300 Subject: [c-nsp] BGP Multihoming and syncronous traffic flow for the different traffic types Message-ID: ISP-1 ISP-2 same country ISP outside of country ISP | | | | | | | | | | | | | | | | ---------- My router (Cisco 7600)-------- | | | User's real subnet (for example 50.50.0.0) Hello , I have got two different ISPs connections from my router. One of the ISP is in my country (local ISP) , other IPS is in the different country. Here are the requiremets ; If the traffic is p2p and if it goes to the outside of the country , use ISP-2. And the return of this traffic will come from the ISP-2 link. (syncronous traffic flow) The other traffic types will use the ISP-1 connection. For example , maybe p2p traffic goes inside of the country. Use ISP-1 connection for this type of traffic as well. How can i differentiate the traffic goes to the inside of the country , or the outside of the country ? The users have got real ip addresses. (Nearly 10.000 users.) To catch the p2p traffic , i think we have to use NBAR. To route the different kind of traffic types , i think we have to use PBR. For this kind of request , i can use NATing on the ISP-2 link. But , is this cause any problem for this type of connection on the Cisco 7600 model router ? Is NAT doing on the Cisco 7600 router by software based or hardware based ? For complete scenario , we have to use NAT , PBR and NBAR. Is that cause any problem on the Cisco 7600 router , what about performance ? Could you give me an idea how can it be done ? Kind Regards... Burak Dikici From acm at axians.de Sat Apr 11 08:51:09 2009 From: acm at axians.de (Cheikh-Moussa Ahmad) Date: Sat, 11 Apr 2009 14:51:09 +0200 Subject: [c-nsp] 4948 MAX Arp entries In-Reply-To: References: Message-ID: Hi Guys, it looks like my question wasn't that easy. Anyone knowing a good link, where to find more specific informations about TCAM ? Regards, Ahmad > -----Urspr?ngliche Nachricht----- > Von: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- > bounces at puck.nether.net] Im Auftrag von Cheikh-Moussa Ahmad > Gesendet: Donnerstag, 2. April 2009 14:26 > An: cisco-nsp at puck.nether.net > Betreff: [c-nsp] 4948 MAX Arp entries > > Hi Guys, > > I have searched a lot of sites and unfortunately didn't find a answer. > Can someone tell me, how much arp entries (adjacencies) a 4948 switch > can handle ? > For L2 switching it can has up to 32K or the 4948-10g up to 55k entries, > but I could not > find anything about the max arp entries. As far as I know this arp > entries or adjacencies > are stored in TCAM. So the 4948 series can have 64k entries in the TCAM. > > Am I right, when I say : > TCAM 64K = > 32K IPv4 unicast routes > 32K Unicast arp entries (adjacencies) > > What about the acls and qos configuration ? These are also stored in > TCAM, right ? > So if this right, then I never reach this, what I can found on the > datasheets of the > switches : > * Unicast and multicast routing entries: 32,000 > * Policers: 512 ingress and 512 egress > * Access control list (ACL) and QoS entries: 32,000 > > Could it be that all these features share the same TCAM ? > I'am little bit confused. > > Regards, > Ahmad > > > > > Ahmad Cheikh-Moussa > Consultant > Business Unit Carrier & Service Provider > > AXIANS > NK Networks & Services GmbH > Fischertwiete 2, Chilehaus A > 20095 Hamburg > > Tel.: +49 40 237 899 - 72 > Fax: +49 40 237 899 - 69 > > Ahmad.cheikh-moussa at axians.de > Acheikh-moussa at axians.de > acm at axians.de > www.axians.com > Sitz der NK Networks & Services GmbH: Von-der-Wettern-Stra?e 15, 51149 K?ln Registergericht: Amtsgericht K?ln, Registernummer HRB 30805 Gesch?ftsf?hrer: Tonis R?sche From bdikici at gmail.com Sat Apr 11 11:39:49 2009 From: bdikici at gmail.com (Burak Dikici) Date: Sat, 11 Apr 2009 18:39:49 +0300 Subject: [c-nsp] BGP Multihoming and syncronous traffic flow for the different traffic types In-Reply-To: References: Message-ID: P2P is peer to peer traffic. Peer to peer traffic to the outside of the country , it will go over the ISP-2 link , and the return traffic of this connection will come back through the same ISP-2 link. My clients are using the real ip addresses. If i advertise their subnet from the ISP-1 with BGP to the outside world , the outside world knows them via the ISP-1 link and the their return traffic will come through the ISP-1 link. I catch the outside of the country with p2p traffic with NBAR and route this traffic to the ISP-2 with PBR , what about the return traffic of this connection ? At this point the NATing comes in the play. The outside of the country with p2p traffic's source ip address will be NATed to the ISP-2 NAT pool addresses. And this NAT pool addresses will be advertise with BGP only to the ISP-2 link. Therefore , the outside world knows this addresses only through the ISP-2 and the return traffic of this connection will come back through the ISP-2 link , it is symmetrical traffic flow for the outside of the country with p2p traffic. Am i right ? How can it be done without using the NAT ? Regards... On Sat, Apr 11, 2009 at 1:55 AM, Burak Dikici wrote: > ISP-1 > ISP-2 > same country ISP outside of country ISP > | | > | | > | | > | | > | | > | | > | | > | | > ---------- My router (Cisco 7600)-------- > | > | > | > User's real subnet (for example 50.50.0.0) > > > > Hello , > > I have got two different ISPs connections from my router. One of the ISP is > in my country (local ISP) , other IPS is in the different country. Here are > the requiremets ; > > If the traffic is p2p and if it goes to the outside of the country , use > ISP-2. And the return of this traffic will come from the ISP-2 link. > (syncronous traffic flow) > > The other traffic types will use the ISP-1 connection. For example , maybe > p2p traffic goes inside of the country. Use ISP-1 connection for this type > of traffic as well. > > How can i differentiate the traffic goes to the inside of the country , or > the outside of the country ? > > The users have got real ip addresses. (Nearly 10.000 users.) To catch the > p2p traffic , i think we have to use NBAR. To route the different kind of > traffic types , i think we have to use PBR. For this kind of request , i can > use NATing on the ISP-2 link. But , is this cause any problem for this type > of connection on the Cisco 7600 model router ? Is NAT doing on the Cisco > 7600 router by software based or hardware based ? For complete scenario , we > have to use NAT , PBR and NBAR. Is that cause any problem on the Cisco 7600 > router , what about performance ? Could you give me an idea how can it be > done ? Kind Regards... > > Burak Dikici From lists at hojmark.org Sat Apr 11 16:54:06 2009 From: lists at hojmark.org (Asbjorn Hojmark - Lists) Date: Sat, 11 Apr 2009 22:54:06 +0200 Subject: [c-nsp] 4948 MAX Arp entries In-Reply-To: References: Message-ID: <50F3D441178E4472814BD21298295A77@hojmark.net> > What about the acls and qos configuration ? These are also > stored in TCAM, right ? It's separate TCAM, described in http://tinyurl.com/cu4a9o (http://www.cisco.com/en/US/products/hw/switches/ps663/products_tech_note091 86a008054a499.shtml) -A From frnkblk at iname.com Sun Apr 12 01:38:01 2009 From: frnkblk at iname.com (Frank Bulk) Date: Sun, 12 Apr 2009 00:38:01 -0500 Subject: [c-nsp] NAT on ASR1000 In-Reply-To: <20090407154647.GQ20028@rtp-cse-489.cisco.com> References: <20090407154647.GQ20028@rtp-cse-489.cisco.com> Message-ID: Could the ASR1000 be the box that Cisco recommends for carrier IPv6 NAT (i.e. IPv6 to IPv4 translations)? Frank -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Rodney Dunn Sent: Tuesday, April 07, 2009 10:47 AM To: cisco-nsp at puck.nether.net Subject: [c-nsp] NAT on ASR1000 Few bugs still being worked through but the 72xx and 76xx croaked under the load: ASR1002ESP10#sh proc cpu sort | excl 0.00 CPU utilization for five seconds: 0%/0%; one minute: 0%; five minutes: 0% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process ASR1002ESP10#sh ip nat stat Total active translations: 92367 (80 static, 92287 dynamic; 92287 extended) Outside interfaces: GigabitEthernet0/0/0, Tunnel1 Inside interfaces: GigabitEthernet0/0/1, GigabitEthernet0/0/2 Hits: 0 Misses: 0 CEF Translated packets: 0, CEF Punted packets: 0 Expired translations: 87400847 that's on 12.2(33)XNC and I just filed one bug. CSCsy93931 ASRNAT does not do FIN/RST/SYN timeout when no-payload keyword used My first work on the box with NAT but this thing seems pretty impressive. Anyone else using it for high scale nat yet? Rodney _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From frnkblk at iname.com Sun Apr 12 02:00:57 2009 From: frnkblk at iname.com (Frank Bulk) Date: Sun, 12 Apr 2009 01:00:57 -0500 Subject: [c-nsp] OT: Service provider-oriented QoS training In-Reply-To: <49DF68B1.70900@justinshore.com> References: <49DF68B1.70900@justinshore.com> Message-ID: Lots of tools out there, you get as much as you want to pay for: - if you're doing PacketCable VoIP, then the Tektronix product (through their Minacom acquistion) seems the right fit. The Arris eMTAs also have lots of stats that are queryable via SNMP or the CLI. - Brix-line of products now part of EXFO - Empirix's Hammer - if you're serving an enterprise, then Cisco's IP SLA may be a fit There's more here: http://www.voip-info.org/wiki/view/How+To+Debug+and+Troubleshoot+VOIP RTCP XR (RFC 3611) is the standard you want to take advantage of, if the CPE supports it. The ability for the product to extract/obtain metrics from your softswitch will totally depend if the vendor has done the integration work. Frank -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Justin Shore Sent: Friday, April 10, 2009 10:42 AM To: 'Cisco-nsp' Subject: [c-nsp] OT: Service provider-oriented QoS training On a slightly different topic, what does everyone use for monitoring voice quality for VoIP customers? Something that can capture calls and either hand us Wireshark-readable packet dumps or break it down in a web GUI for the non-Wireshark savvy to use would be great. EdgeMarc has their EdgeView server with call quality monitoring features that look good but I'm pretty sure that it requires their CPE as well which is really not what we need or want. What else is out there that SP's use for IP soft switches? Thanks Justin _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From piotr.nowacki at interia.pl Sun Apr 12 05:06:19 2009 From: piotr.nowacki at interia.pl (Piotr Nowacki) Date: Sun, 12 Apr 2009 10:06:19 +0100 Subject: [c-nsp] OT: SNMP Trap manager recommendation In-Reply-To: <49DF6242.4090301@justinshore.com> References: <49DF6242.4090301@justinshore.com> Message-ID: <20090412090619.GA3842@i-194-106-50-219> On Fri, Apr 10, 2009 at 10:14:10AM -0500, Justin Shore wrote: > I'm in need of a decent SNMP Trap manager that scales and is free (OSS) > or cheap. I currently Nagios for my NMS and Cacti for data collection > and graphing so clearly I'm a fan of OSS solutions. I read an article > several years ago in the now defunct SysAdmin magazine on tying in > SNMP-TT into Nagios. Is there a better way? I need to collect traps > from Hatteras equipment mainly but once I have it I'm sure I'll use it > for other things as well. > > My searches have so far turned up JFFNMS, OpenNMS, Mila NetWhistler, > NetCool (expensive?) and a few others. There's also the GroundWork fork > of Nagios and other OSS tools that may be useful. > > Any recommendations? Thanks > Justin Hi, take a look at Opsview (www.opsview.org) It is basically nagios with heavily patched NDO and Java frontend. It does support basic SNMP Traps processing. Peter From sami.joseph at gmail.com Sun Apr 12 07:45:13 2009 From: sami.joseph at gmail.com (Sami Joseph) Date: Sun, 12 Apr 2009 13:45:13 +0200 Subject: [c-nsp] Testing reachability Message-ID: <9da37ec40904120445y51a94a4fmdc38c84f134eb703@mail.gmail.com> Network Management Gurus, I have an Enterprise network and my NMS is showing interfaces on some devices as down and that is because it keeps checking their availability with snmp/ping and if one response is missed then it considers the interface as down and needs to acknowledge/clearing the alarm in order to remove it. I would like to know why that response is missed so we can fix it. Is there a tool that can give me a detailed report that can help me troubleshoot this? Regards, Sam From aftab.siddiqui at gmail.com Sun Apr 12 09:16:05 2009 From: aftab.siddiqui at gmail.com (Aftab Siddiqui) Date: Sun, 12 Apr 2009 18:16:05 +0500 Subject: [c-nsp] Testing reachability In-Reply-To: <9da37ec40904120445y51a94a4fmdc38c84f134eb703@mail.gmail.com> References: <9da37ec40904120445y51a94a4fmdc38c84f134eb703@mail.gmail.com> Message-ID: <3c605ce10904120616k5959bd02ua9009d8b2b1df5aa@mail.gmail.com> There could be several reasons for a packet drop on particualr in some point in time. It could be coz of high traffic utilization or may be coz of high cpu utilization incase of a system process. There is no general rule for troubleshooting that's why placing the NMS is very critical with in the enterprise network. For a start if you have snmp enabled devices than start polling the switch/router ports for traffic (mrtg) and CPU. It will definately help to drill down the problem. On 12/04/2009, Sami Joseph wrote: > Network Management Gurus, > > I have an Enterprise network and my NMS is showing interfaces on some > devices as down and that is because it keeps checking their availability > with snmp/ping and if one response is missed then it considers the interface > as down and needs to acknowledge/clearing the alarm in order to remove it. > > I would like to know why that response is missed so we can fix it. Is there > a tool that can give me a detailed report that can help me troubleshoot > this? > > Regards, > Sam > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > -- Regards, Aftab A. Siddiqui From david.freedman at uk.clara.net Sun Apr 12 10:06:48 2009 From: david.freedman at uk.clara.net (David Freedman) Date: Sun, 12 Apr 2009 15:06:48 +0100 Subject: [c-nsp] 12.4(T) feature oddness Message-ID: <1BD38DD97E9BEB40A599BFCCED93CC7F4780D5@EXVS01.claranet.local> I've been looking at doing some EEM stuff with client kit using latest 12.4(T) and have come across some feature oddness. It appears that, you can not make outgoing ISDN calls without using the ADVANCED ENTERPRISE license (using ADVANCED IP will give you obscure messages such as "Outgoing Call id XXXX Blocked") This is fine and dandy, however, am deploying some EEM applets on the CPE which I would like to respond to SNMP traps which are sent from events on the CPE and looped back to itself (I don't want to rely on logging for event triggers in case there is a logging storm and I miss the messages), in such case, I need the trap receiver or "snmp-server manager" command which ONLY appears to be present in ADVANCED IP and not ADVANCED ENTERPRISE Does anybody know a way around this sillyness? The box in question is an 876 on which I am compelled to run technology train (I do not believe there is mainline support for 876 yet?) thanks in advance Dave. ------------------------------------------------ David Freedman Group Network Engineering Claranet Limited http://www.clara.net From zivl at gilat.net Sun Apr 12 10:58:43 2009 From: zivl at gilat.net (Ziv Leyes) Date: Sun, 12 Apr 2009 17:58:43 +0300 Subject: [c-nsp] OT: Service provider-oriented QoS training In-Reply-To: <5c7a3dff-6cb1-4c47-8977-6d8058c74118@exch2k7.gilat.local> References: <49DF68B1.70900@justinshore.com> <5c7a3dff-6cb1-4c47-8977-6d8058c74118@exch2k7.gilat.local> Message-ID: You may want to take a look at what RADCOM's Omni-Q has to offer on this field -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Frank Bulk Sent: Sunday, April 12, 2009 9:01 AM To: 'Justin Shore'; 'Cisco-nsp' Subject: Re: [c-nsp] OT: Service provider-oriented QoS training Lots of tools out there, you get as much as you want to pay for: - if you're doing PacketCable VoIP, then the Tektronix product (through their Minacom acquistion) seems the right fit. The Arris eMTAs also have lots of stats that are queryable via SNMP or the CLI. - Brix-line of products now part of EXFO - Empirix's Hammer - if you're serving an enterprise, then Cisco's IP SLA may be a fit There's more here: http://www.voip-info.org/wiki/view/How+To+Debug+and+Troubleshoot+VOIP RTCP XR (RFC 3611) is the standard you want to take advantage of, if the CPE supports it. The ability for the product to extract/obtain metrics from your softswitch will totally depend if the vendor has done the integration work. Frank -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Justin Shore Sent: Friday, April 10, 2009 10:42 AM To: 'Cisco-nsp' Subject: [c-nsp] OT: Service provider-oriented QoS training On a slightly different topic, what does everyone use for monitoring voice quality for VoIP customers? Something that can capture calls and either hand us Wireshark-readable packet dumps or break it down in a web GUI for the non-Wireshark savvy to use would be great. EdgeMarc has their EdgeView server with call quality monitoring features that look good but I'm pretty sure that it requires their CPE as well which is really not what we need or want. What else is out there that SP's use for IP soft switches? Thanks Justin _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ ************************************************************************************ This footnote confirms that this email message has been scanned by PineApp Mail-SeCure for the presence of malicious code, vandals & computer viruses. ************************************************************************************ From charles at thewybles.com Sun Apr 12 12:29:08 2009 From: charles at thewybles.com (Charles Wyble) Date: Sun, 12 Apr 2009 09:29:08 -0700 Subject: [c-nsp] Testing reachability In-Reply-To: <3c605ce10904120616k5959bd02ua9009d8b2b1df5aa@mail.gmail.com> References: <9da37ec40904120445y51a94a4fmdc38c84f134eb703@mail.gmail.com> <3c605ce10904120616k5959bd02ua9009d8b2b1df5aa@mail.gmail.com> Message-ID: <49E216D4.5030503@thewybles.com> Lower you NMS sensitivity. Only have it alert after n failures in n time. I do this with nagios. It has an algorithm which causes it to change the level of checking dynamically based on if their is a failure or not. Aftab Siddiqui wrote: > There could be several reasons for a packet drop on particualr in some > point in time. It could be coz of high traffic utilization or may be > coz of high cpu utilization incase of a system process. There is no > general rule for troubleshooting that's why placing the NMS is very > critical with in the enterprise network. > > For a start if you have snmp enabled devices than start polling the > switch/router ports for traffic (mrtg) and CPU. > > It will definately help to drill down the problem. > > On 12/04/2009, Sami Joseph wrote: >> Network Management Gurus, >> >> I have an Enterprise network and my NMS is showing interfaces on some >> devices as down and that is because it keeps checking their availability >> with snmp/ping and if one response is missed then it considers the interface >> as down and needs to acknowledge/clearing the alarm in order to remove it. >> >> I would like to know why that response is missed so we can fix it. Is there >> a tool that can give me a detailed report that can help me troubleshoot >> this? >> >> Regards, >> Sam >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > > From chris.garzon at gmail.com Sun Apr 12 22:56:42 2009 From: chris.garzon at gmail.com (Dracul) Date: Mon, 13 Apr 2009 10:56:42 +0800 Subject: [c-nsp] video,voip and internet over DSL (converged) In-Reply-To: <223F626EF40847739E6B7BB120FAAC5B@Toshiba> References: <876789290904081922te84a61ev1da8dff3f198b322@mail.gmail.com> <223F626EF40847739E6B7BB120FAAC5B@Toshiba> Message-ID: <876789290904121956q2713f8b8g5573cf2fba8c255b@mail.gmail.com> Thanks all! I'll take into consideration all your inputs. Another thing. will the CPU processing power of each DSLAM be enough or do I also need to distribute its load, like not filling up a DSLAM's ports to its limit, maybe 70% only per floor of the building? regards, chris On Fri, Apr 10, 2009 at 12:01 AM, Scott Granados wrote: > DSL will work but you'll need the right flavor. > > You could set different PVC's with different QOS and characteristics but > bottom line you'll need enough pipe to make this work. I believe it's > something on the order of 6 - 8 megabits for HD and 1-3 for sd. > I've heard although I've never used it personally that the ATT Uverse > offering works similar to this with ADSL2+ on the last few feet in to the > home. > > > ----- Original Message ----- From: "Dracul" > To: > Sent: Wednesday, April 08, 2009 7:22 PM > Subject: [c-nsp] video,voip and internet over DSL (converged) > > > Hi list, >> >> is it feasible to broadcast video/voip + internet over DSL like lets say >> I >> deploy a cisco DSLAM infra in a 20 storey building. It would run over a >> media server solution and a VOIP network. I am not sure if this would be a >> stable solution considering I want to broadcast HD and SD alike plus VOIP >> and internet to boot. >> >> Any cons? like noise level or quality of the video or quality of bandwidth >> etc. because DSL transport is just running over copper right? Or would I >> be >> better off running fibre? But of course cost will then quantify the use of >> DSL. >> >> regards, >> Chris >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> >> __________ Information from ESET NOD32 Antivirus, version of virus >> signature database 3995 (20090408) __________ >> >> The message was checked by ESET NOD32 Antivirus. >> >> http://www.eset.com >> >> >> >> > From scubacuda at gmail.com Mon Apr 13 00:22:19 2009 From: scubacuda at gmail.com (Rogelio) Date: Sun, 12 Apr 2009 21:22:19 -0700 Subject: [c-nsp] OT: SNMP Trap manager recommendation In-Reply-To: <20090412090619.GA3842@i-194-106-50-219> References: <49DF6242.4090301@justinshore.com> <20090412090619.GA3842@i-194-106-50-219> Message-ID: <49E2BDFB.5020908@gmail.com> Piotr Nowacki wrote: >> Justin > Hi, > take a look at Opsview (www.opsview.org) > It is basically nagios with heavily patched NDO and Java frontend. > It does support basic SNMP Traps processing. OpenNMS might also do what you need. see this URL http://www.opennms.org/index.php/Event_Configuration_How-To particularly this section on traps using the trapd process http://www.opennms.org/index.php/Event_Configuration_How-To#SNMP_Traps There in eventconf.xml you can write up the details on how you'd like to trap things and convert them into something more user friendly. (Which is what you're trying to do, right?) HTH From acm at axians.de Mon Apr 13 07:33:53 2009 From: acm at axians.de (Cheikh-Moussa Ahmad) Date: Mon, 13 Apr 2009 13:33:53 +0200 Subject: [c-nsp] 4948 MAX Arp entries In-Reply-To: <50F3D441178E4472814BD21298295A77@hojmark.net> References: <50F3D441178E4472814BD21298295A77@hojmark.net> Message-ID: Hi Asbjorn, thanks for the link. That means this is right, because acl and qos use a separate TCAM. TCAM 64K = 32K IPv4 unicast routes 32K Unicast arp entries (adjacencies) Thanks, Ahmad > -----Urspr?ngliche Nachricht----- > Von: Asbjorn Hojmark - Lists [mailto:lists at hojmark.org] > Gesendet: Samstag, 11. April 2009 22:54 > An: Cheikh-Moussa Ahmad > Cc: cisco-nsp at puck.nether.net > Betreff: RE: [c-nsp] 4948 MAX Arp entries > > > What about the acls and qos configuration ? These are also > > stored in TCAM, right ? > > It's separate TCAM, described in http://tinyurl.com/cu4a9o > > (http://www.cisco.com/en/US/products/hw/switches/ps663/products_tech_not > e091 > 86a008054a499.shtml) > > -A Sitz der NK Networks & Services GmbH: Von-der-Wettern-Stra?e 15, 51149 K?ln Registergericht: Amtsgericht K?ln, Registernummer HRB 30805 Gesch?ftsf?hrer: Tonis R?sche From deric.kwok2000 at gmail.com Mon Apr 13 07:35:48 2009 From: deric.kwok2000 at gmail.com (Deric Kwok) Date: Mon, 13 Apr 2009 07:35:48 -0400 Subject: [c-nsp] 2600 vs 2800 series different Message-ID: <40d8a95a0904130435h372d686aie18645da6239899a@mail.gmail.com> Hi What is different between 2600 and 2800 router? I check it is just 100 different in ebay Does 2800 also have feature as 2600? if yet Does 3500 Router also have same feature as 2600? Does 2800 support VPN, tcsh command and vlan? Thank you From plunin at gmail.com Mon Apr 13 08:27:05 2009 From: plunin at gmail.com (Pavel Lunin) Date: Mon, 13 Apr 2009 16:27:05 +0400 Subject: [c-nsp] NAT on ACE Message-ID: <49E32F99.6010701@gmail.com> Hi experts, Who thinks what about an idea of using Cisco ACE module for 6500/7600 as a NAT device for a huge enterprise network? I am looking for a device which would be capable to NAT traffic for a network of several thousand desktops + an enterprise-scale data center: up to 5 Gbps of traffic totally. Local sales say it is a nice idea to use ACE. The price is also very attractive in compare with any classic stateful firewall solution. But I myself have absolutely no experience with ACE and am also afraid nothing goes free. At least in Cisco world :) Skimming through Cisco's datasheets it seems like ACE is rather a kind of load balancer, SSL accelerator, L7 proxy, etc. This functions are usually done in software. However ACE's NAT capabilities, announced by the vendor, should require lots of expensive hardware, just as any firewall does. So where is the trick? Does anyone have real life experience with NAT on ACE module? Should we go there? Let's assume we don't need any other firewall features, only NAT. Thank you. -- Kind regards, Pavel From peter at rathlev.dk Mon Apr 13 10:02:17 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Mon, 13 Apr 2009 16:02:17 +0200 Subject: [c-nsp] 2600 vs 2800 series different In-Reply-To: <40d8a95a0904130435h372d686aie18645da6239899a@mail.gmail.com> References: <40d8a95a0904130435h372d686aie18645da6239899a@mail.gmail.com> Message-ID: <1239631337.3480.10.camel@localhost.localdomain> On Mon, 2009-04-13 at 07:35 -0400, Deric Kwok wrote: > What is different between 2600 and 2800 router? > > I check it is just 100 different in ebay > > Does 2800 also have feature as 2600? if yet > Does 3500 Router also have same feature as 2600? > Does 2800 support VPN, tcsh command and vlan? The 2800 is the successor to the 2600. The last 2600 models were announced EoS from march 2007. The 2800 is likely to support more features than the 2600. It at least supports IPSec, tclsh and 802.1Q VLANs with the correct IOS, though the IPSec handling benifits from accellerator modules. Regards, Peter From arievayner at gmail.com Mon Apr 13 11:44:37 2009 From: arievayner at gmail.com (Arie Vayner) Date: Mon, 13 Apr 2009 18:44:37 +0300 Subject: [c-nsp] NAT on ACE In-Reply-To: <49E32F99.6010701@gmail.com> References: <49E32F99.6010701@gmail.com> Message-ID: <20b13c6b0904130844n924aba3t96cb7d46a0055f40@mail.gmail.com> Pavel, ACE can do this, but you need to take a look also at other performance metrics such as maximal session number (which could be very different for the same BW rate for different session profiles). Also, you need to make sure that more advanced features you may need are available and are scalable enough (like static mappings etc). You should also think about features like NetFlow and routing It could be a good idea to actually split the NAT functionality of the enterprise and the data center as their level of redundancy, features and traffic profiles are quite different. Arie On Mon, Apr 13, 2009 at 3:27 PM, Pavel Lunin wrote: > Hi experts, > > Who thinks what about an idea of using Cisco ACE module for 6500/7600 as a > NAT device for a huge enterprise network? > > I am looking for a device which would be capable to NAT traffic for a > network of several thousand desktops + an enterprise-scale data center: up > to 5 Gbps of traffic totally. Local sales say it is a nice idea to use ACE. > The price is also very attractive in compare with any classic stateful > firewall solution. But I myself have absolutely no experience with ACE and > am also afraid nothing goes free. At least in Cisco world :) > > Skimming through Cisco's datasheets it seems like ACE is rather a kind of > load balancer, SSL accelerator, L7 proxy, etc. This functions are usually > done in software. However ACE's NAT capabilities, announced by the vendor, > should require lots of expensive hardware, just as any firewall does. > > So where is the trick? Does anyone have real life experience with NAT on > ACE module? Should we go there? Let's assume we don't need any other > firewall features, only NAT. > > Thank you. > > -- > Kind regards, > Pavel > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From jmkeller at houseofzen.org Mon Apr 13 11:25:16 2009 From: jmkeller at houseofzen.org (James Michael Keller) Date: Mon, 13 Apr 2009 11:25:16 -0400 Subject: [c-nsp] Verizon's PIP service In-Reply-To: References: Message-ID: <49E3595C.6060005@houseofzen.org> Verizon's PIP (as of a few years ago, been a while since I left) was using a dedicated backbone and POPs (Inherited from the MCI merger) for the PIP service. One of the downsides was there where limited POPs compared to the access network offerings. Customer connections are just access lines into the POPs. The local loops will ride the local carrier into the local POP, this often caused fairly long back-haul connections if there wasn't a POP close enough. Especially if customers where running diverse POP connections into sites for redundancy. So unless they have had to bring on third party POP sites, after the local loop it will be all Verizon controlled. You would need to confirm the current configuration with your sales team, but I haven't had to terminate into anything other then a Verizon owned POP in the US or Western Europe yet. -- James Michael Keller D W wrote: > Anyone happen to know if Verizon relies on any 3rd party service providers (using inter-AS MP-BGP, ATOM, etc.) for their PIP (MPLS based private IP) service? I'm trying to figure out which service providers have a national reach and fully contain/control their own MPLS clouds without relying on one another for transport. > > > > Thanks, > > Dave > > _________________________________________________________________ > Windows Live?: Life without walls. > http://windowslive.com/explore?ocid=TXT_TAGLM_WL_allup_1a_explore_032009 > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From jmkeller at houseofzen.org Mon Apr 13 11:51:12 2009 From: jmkeller at houseofzen.org (James Michael Keller) Date: Mon, 13 Apr 2009 11:51:12 -0400 Subject: [c-nsp] Opinions of DDoS appliances, other techniques, most notably Cisco Guard In-Reply-To: References: <725C9117-BE48-468B-A39E-B69347853BAB@cisco.com> <04670DB7-99B1-4F55-8DDD-9C036F93E4AF@cisco.com> <49BD9755.6060608@justinshore.com> Message-ID: <49E35F70.3090209@houseofzen.org> Yes, I've crushed a MARS 110 unit with netflow data from around 200 devices. Cisco recommended we switch to a dedicated netflow collector and then feed the consolidated sessions into MARS rather then have MARS directly take all the raw netflows (ie layer3 switch flow and router flow having duplicate data for the same flow). We're on the last 5.x build version before 6.x. Getting ready to re-build it from a 6.x disk and see if the new SQL backend helps with some of that until we get a dedicated netflow box in. --- James Michael Keller Ryan Hughes wrote: > MARS really isn't positioned to be a Netflow anomaly detection with the > likes of Arbor and others previously mentioned. It's simply a feature that's > in there to help bring into perspective of what's going on with your Cisco > infrastructure from a threat perspective. And I would definitely be careful > with the amount of logs and Netflow that you send to the device as you can > definitely cause it to choke whereby the device isn't storing enough events > for proper correlation. > > On Sun, Mar 15, 2009 at 8:03 PM, Justin Shore wrote: > > >> Roland Dobbins wrote: >> >> >>> On Mar 16, 2009, at 12:39 AM, Roland Dobbins wrote: >>> >>> Arbor Peakflow SP, Narus Insight Manager, and Lancope StealthWatch Xe are >>> >>>> three commercial NetFlow-based anomaly-detection systems. >>>> >>>> >>> I forgot to add Q1 Labs Q1Radar, and I believe NetQoS now have an >>> anomaly-detection module, as well, though I've not seen it. >>> >>> >> How about MARS? I'm trying to get a pair of IDSM2s returned (they don't >> work right on 7600s) in exchange for a MARS 110R appliance. That's roughly >> the same price. I'm planning on using it for log analysis. Would its >> Netflow abilities be useful here? >> >> Justin >> >> >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From walter.keen at RainierConnect.net Mon Apr 13 12:24:30 2009 From: walter.keen at RainierConnect.net (Walter Keen) Date: Mon, 13 Apr 2009 09:24:30 -0700 Subject: [c-nsp] carrier router models comparison In-Reply-To: <383357750904090125t302139f8o1d836243dc484010@mail.gmail.com> References: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> <74206b240904080701t75420f7dqd1298597e246008c@mail.gmail.com> <383357750904090125t302139f8o1d836243dc484010@mail.gmail.com> Message-ID: <49E3673E.1040705@rainierconnect.net> Backplane speed per slot I would imagine. Imagine the 7600 and it's 10-port 10Ge card. If it only has 40gb on the backplane or fabric for that slot... well... lets hope all 10 ports aren't utilized to 100% at all times, It's a little over 2:1 over-subscription for the example I gave. Mateusz Blaszczyk wrote: > What's the difference between 40g/slot and 100g/slot ready ? > Is it like "vista ready"? > > I would assume (wrongly?) that this is a hw limit? > > Best Regards, > > -mat > > From sethm at rollernet.us Mon Apr 13 13:16:02 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Mon, 13 Apr 2009 10:16:02 -0700 Subject: [c-nsp] 2600 vs 2800 series different In-Reply-To: <40d8a95a0904130435h372d686aie18645da6239899a@mail.gmail.com> References: <40d8a95a0904130435h372d686aie18645da6239899a@mail.gmail.com> Message-ID: <49E37352.9000601@rollernet.us> Deric Kwok wrote: > Hi > > What is different between 2600 and 2800 router? > > I check it is just 100 different in ebay > > Does 2800 also have feature as 2600? if yet > > Does 3500 Router also have same feature as 2600? > > Does 2800 support VPN, tcsh command and vlan? > Did you try reading the data sheet? http://cisco.com/en/US/prod/collateral/routers/ps5854/ps5882/product_data_sheet0900aecd8016fa68_ps5854_Products_Data_Sheet.html ~Seth From raymondh.nsp at gmail.com Mon Apr 13 13:30:37 2009 From: raymondh.nsp at gmail.com (raymondh (NSP)) Date: Tue, 14 Apr 2009 01:30:37 +0800 Subject: [c-nsp] Opinions of DDoS appliances, other techniques, most notably Cisco Guard In-Reply-To: <49E35F70.3090209@houseofzen.org> References: <725C9117-BE48-468B-A39E-B69347853BAB@cisco.com> <04670DB7-99B1-4F55-8DDD-9C036F93E4AF@cisco.com> <49BD9755.6060608@justinshore.com> <49E35F70.3090209@houseofzen.org> Message-ID: <60DD6789-8261-4A37-8C8E-8268C30C7018@gmail.com> Personally, if cost isn't an issue and you're expecting to sink high volume of traffic, I'd suggest that you go for Peakflow SP together with TMS (It's still ranked as one of the better ones among the rest). Else the ADM + AGM should work well enough. Generally for the MARS boxes, I'd propose the same concept to have a dedicated collector and forward it. --raymondh On Apr 13, 2009, at 11:51 PM, James Michael Keller wrote: > Yes, I've crushed a MARS 110 unit with netflow data from around 200 > devices. Cisco recommended we switch to a dedicated netflow > collector and then feed the consolidated sessions into MARS rather > then have MARS directly take all the raw netflows (ie layer3 switch > flow and router flow having duplicate data for the same flow). > > We're on the last 5.x build version before 6.x. Getting ready to > re-build it from a 6.x disk and see if the new SQL backend helps > with some of that until we get a dedicated netflow box in. > > --- > James Michael Keller > > > > Ryan Hughes wrote: >> MARS really isn't positioned to be a Netflow anomaly detection with >> the >> likes of Arbor and others previously mentioned. It's simply a >> feature that's >> in there to help bring into perspective of what's going on with >> your Cisco >> infrastructure from a threat perspective. And I would definitely be >> careful >> with the amount of logs and Netflow that you send to the device as >> you can >> definitely cause it to choke whereby the device isn't storing >> enough events >> for proper correlation. >> >> On Sun, Mar 15, 2009 at 8:03 PM, Justin Shore >> wrote: >> >> >>> Roland Dobbins wrote: >>> >>> >>>> On Mar 16, 2009, at 12:39 AM, Roland Dobbins wrote: >>>> >>>> Arbor Peakflow SP, Narus Insight Manager, and Lancope >>>> StealthWatch Xe are >>>> >>>>> three commercial NetFlow-based anomaly-detection systems. >>>>> >>>>> >>>> I forgot to add Q1 Labs Q1Radar, and I believe NetQoS now have an >>>> anomaly-detection module, as well, though I've not seen it. >>>> >>>> >>> How about MARS? I'm trying to get a pair of IDSM2s returned (they >>> don't >>> work right on 7600s) in exchange for a MARS 110R appliance. >>> That's roughly >>> the same price. I'm planning on using it for log analysis. Would >>> its >>> Netflow abilities be useful here? >>> >>> Justin >>> >>> >>> _______________________________________________ >>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>> >>> >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From blahu77 at gmail.com Mon Apr 13 15:33:09 2009 From: blahu77 at gmail.com (Mateusz Blaszczyk) Date: Mon, 13 Apr 2009 20:33:09 +0100 Subject: [c-nsp] carrier router models comparison In-Reply-To: <49E3673E.1040705@rainierconnect.net> References: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> <74206b240904080701t75420f7dqd1298597e246008c@mail.gmail.com> <383357750904090125t302139f8o1d836243dc484010@mail.gmail.com> <49E3673E.1040705@rainierconnect.net> Message-ID: <383357750904131233g1150df4ao268138063321cff1@mail.gmail.com> Okay, But if I imagine crs-1 (my favorite example) with same limitation (currently) of 40g per slot I don't see how it is 100G ready. Some say that its because they will introduce 100g switching matrix concurrently to new 100 LC, I am not 100% conviced that it satisfies "100G ready" label. For me ready is now, crs-1/7600 is 40g ready but not 100g. It may never be. That's why I don't understand position of this platform comparing to asr9k... Best Regards, -mat 2009/4/13 Walter Keen : > Backplane speed per slot I would imagine. > > Imagine the 7600 and it's 10-port 10Ge card. ? If it only has 40gb on > the backplane or fabric for that slot... well... lets hope all 10 ports > aren't utilized to 100% at all times, It's a little over 2:1 > over-subscription for the example I gave. > > Mateusz Blaszczyk wrote: >> What's the difference between 40g/slot and 100g/slot ready ? >> Is it like "vista ready"? >> >> I would assume (wrongly?) that this is a hw limit? >> >> Best Regards, >> >> -mat >> >> > > -- pgp-key 0x1C655CAB From raa at opusnet.com Mon Apr 13 18:46:29 2009 From: raa at opusnet.com (Ruben Alvarez) Date: Mon, 13 Apr 2009 15:46:29 -0700 Subject: [c-nsp] Ping priority on Cisco devices In-Reply-To: <49DF7CAE.3010002@toybox.placo.com> References: <004901c9b874$59596e00$0c0c4a00$@com> <49DD1BAD.6020604@toybox.placo.com> <004a01c9b941$caa789c0$5ff69d40$@com> <49DF7CAE.3010002@toybox.placo.com> Message-ID: <005101c9bc89$afcbf2d0$0f63d870$@com> Hi I did figure it out today. It was my fault there was a null route on that router. The Virtual interfaces for each DSL customer will create a /32 route on the router and most of the time OSPF had a route. But intermittently, those routes would drop and the ICMP would drop too. I've since removed the null route and it's rock solid. Thanks. -----Original Message----- From: Ted Mittelstaedt [mailto:tedm at toybox.placo.com] Sent: Friday, April 10, 2009 10:07 AM To: Ruben Alvarez Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] Ping priority on Cisco devices Hi Ruben, If you running 12.3 or later IOS I'd suggest backreving to 12.2. fast switching is a problematical thing in the newer IOS on these older CPU cards. I'd guess that even if you have ip cef defined in your config, that cef isn't actually running. what does show ip cef, show cef day? IOS 12.1/12.2 is about the newest most people go on the NPE300 Ted Ruben Alvarez wrote: > Hi, > > Thanks for the reply. It running at ~18% cpu and is a 7206vxr w/NPE300. > This morning the loss cleared up. I didn't collect enough data yesterday to > really get to the bottom of this, so I'll drop it as a Qwest megahost issue. > > -----Original Message----- > From: Ted Mittelstaedt [mailto:tedm at toybox.placo.com] > Sent: Wednesday, April 08, 2009 2:48 PM > To: Ruben Alvarez > Cc: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] Ping priority on Cisco devices > > Ruben Alvarez wrote: > >> All, >> >> I've heard that Cisco devices handle ICMP at a low priority. I found one >> post describing it handled in process-switching and not fast-switching. >> Does anyone have an article that explains that process and is it >> configurable? >> >> The reason I ask is I see about 4% packet loss when I ping devices in our >> broadband aggregation network. From the CPE to the router there is none, >> from my workstation to the router there is none, but if I ping the whole >> path I get a fairly consistent 4% loss. I can't find any congestion or >> errors. Ping from my workstation to the CPE are a consistent 60ms, aside >> from the 4% loss. >> >> Thanks. >> >> >> > What model is your router and can you post a config? > > What is CPU utilization on the router? What is memory utilization on > the router? > > Ted > > From charles.regan at gmail.com Mon Apr 13 19:58:49 2009 From: charles.regan at gmail.com (Charles Regan) Date: Mon, 13 Apr 2009 20:58:49 -0300 Subject: [c-nsp] VLAN and switch and ? In-Reply-To: References: <40d8a95a0903041344v5ebf64ffk1288300312ed7371@mail.gmail.com> <40d8a95a0903041435n51afa718qe90074f2f957ca1c@mail.gmail.com> Message-ID: For those interested here is how I made it work. I bought two 3550 switch. ISP----Wireless-BH#1----3550#1----Fiber----2950----3550#2----Wireless-BH#2----ISPClients On the 3550#1 the port connected to Wireless-Backhaul1 I've used the following command. ?switchport access vlan xx ?switchport mode dot1q-tunnel ?l2protocol-tunnel cdp ?l2protocol-tunnel stp ?l2protocol-tunnel vtp ?spanning-tree bpdufilter enable Same thing on the 3550#2 Everything works perfectly. On Wed, Mar 4, 2009 at 7:35 PM, Deric Kwok wrote: >> Hi >> >> I only have l2tp configuration in linux router. Here is below. >> >> Pls note that i don't know Jeff suggestion how?L2tp works out in your >> network >> it looks like his suggestion is same as L2tp so that I post to ask him >> >> I only know this l2tp worked in my setting before when doing in DSL >> >> HTH >> ! >> interface Ethernet0 >> ?no ip address >> ?speed 1000 >> ?duplex full >> ! >> interface Ethernet0.120 >> ?description vlan120 >> ?ip address 10.0.0.6 255.255.255.252 >> ! >> interface Ethernet0.130 >> ?description vlan130 >> ?ip address 10.0.0.74 255.255.255.252 >> ! >> interface Ethernet0.140 >> ?description vlan140 >> ?ip address 10.0.0.54 255.255.255.252 >> ! >> ! >> interface Tunnel1 >> ?description vlan120 >> ?tunnel mode l2tp >> ?tunnel peer name xxxx >> ?tunnel local name deric >> ?tunnel key kwok >> ?tunnel virtual-template 1 >> ! >> interface Tunnel2 >> ?description vlan130 >> ?tunnel mode l2tp >> ?tunnel peer name xxxx >> ?tunnel local name deric >> ?tunnel key kwok >> ?tunnel virtual-template 1 >> ! >> interface Tunnel3 >> ?description vlan140 >> ?tunnel mode l2tp >> ?tunnel peer name xxxx >> ?tunnel local name deric >> ?tunnel key kwok >> ?tunnel virtual-template 1 >> ! >> >> >> >> On Wed, Mar 4, 2009 at 4:48 PM, Charles Regan >> wrote: >>> >>> There's now way my switch will support L2TP. >>> >>> How would you setup VLAN in this setup. >>> >>> ISP needs to pass all his vlan (switchport mode trunk) >>> I don't want ISP to have access to my network ... (swictchport access >>> vlan 500, on both end ?) >>> I want Internet acces from this ISP from his BackHaul1. ?(switchport >>> access vlan 500, on my gateway router ?) >>> >>> >>> >>> On Wed, Mar 4, 2009 at 5:48 PM, Charles Regan >>> wrote: >>> > On Wed, Mar 4, 2009 at 5:47 PM, Charles Regan >>> > wrote: >>> >> There's now way my switch will support L2TP. >>> >> >>> >> How would you setup VLAN in this setup. >>> >> >>> >> ISP needs to pass all his vlan (switchport mode trunk) >>> >> I don't want ISP to have access to my network ... (swictchport access >>> >> vlan 500, on both end ?) >>> >> I want Internet acces from this ISP from his BackHaul1. ?(switchport >>> >> access vlan 500, on my gateway router ?) >>> >> >>> >> >>> >> >>> >> On Wed, Mar 4, 2009 at 5:44 PM, Deric Kwok >>> >> wrote: >>> >>> look like L2TP. >>> >>> >>> >>> Can I know why use it intead of typically vlan? >>> >>> >>> >>> Thank you >>> >>> >>> >>> On Wed, Mar 4, 2009 at 10:14 AM, Jeff Fitzwater >>> >>> wrote: >>> >>>> >>> >>>> Look at layer 2 tunneling for your switches. ?You would assign tunnel >>> >>>> vlan >>> >>>> ID and ISP would send tagged traffic into tunnel (Q in Q) and traffic >>> >>>> would >>> >>>> exit tunnel where ever needed. ? When you assign a port as a tunnel >>> >>>> port, it >>> >>>> becomes a tunnel-input and tunnel-output. ? You can have as many >>> >>>> tunnel >>> >>>> ports as you need. ?The ISP can now send what ever VLANs they want >>> >>>> and you >>> >>>> do not need to change anything. >>> >>>> Read the doc and be aware of oversized packet handling within tunnel >>> >>>> switches. >>> >>>> >>> >>>> >>> >>>> Jeff Fitzwater >>> >>>> OIT Network Systems >>> >>>> Princeton University >>> >>>> >>> >>>> On Mar 4, 2009, at 9:46 AM, Charles Regan wrote: >>> >>>> >>> >>>>> Good Morning, >>> >>>>> >>> >>>>> I'll try to explain what I want to do... We are LOCAL NETWORK in >>> >>>>> this >>> >>>>> graphic. >>> >>>>> The ISP wants to use our fiber link to connect to his wireless >>> >>>>> customer. >>> >>>>> We also want internet access from his Wireless Backhaul1. >>> >>>>> ISP also use VLAN on his customer subscriber modules. >>> >>>>> >>> >>>>> How would you configure 2924 Switch and 2960 Switch, so that >>> >>>>> everything is transparent from my side and his side ? >>> >>>>> I don't want him to call me to add a new VLAN on our switch. >>> >>>>> >>> >>>>> >>> >>>>> ISP ---Wireless BackHaul1 -- 2924 Switch ---- FIBER ---- 2960 Switch >>> >>>>> ---- Wireless Backhaul2 ---- Access Point ---- Wireless subscriber >>> >>>>> modules >>> >>>>> ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? | >>> >>>>> ? ? ? ? ? ?| >>> >>>>> ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? | >>> >>>>> ? ? ? ? ? ?| >>> >>>>> ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? | >>> >>>>> ? ? ? ? ? ?| >>> >>>>> ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? | >>> >>>>> ? ? ? ? ? ?| >>> >>>>> ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? | >>> >>>>> ? ? ? ? ? ?| >>> >>>>> ? ? ? ? ? ? ? ? ? ? ? ? ? ?LOCAL NETWORK ? ? ? ? ? ?LOCAL NETWORK >>> >>>>> >>> >>>>> >>> >>>>> Will something like this work ? >>> >>>>> switchport access vlan 500 >>> >>>>> switchport trunk encapsulation dot1q >>> >>>>> switchport mode trunk >>> >>>>> _______________________________________________ >>> >>>>> cisco-nsp mailing list ?cisco-nsp at puck.nether.net >>> >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>> >>>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>> >>>> >>> >>>> _______________________________________________ >>> >>>> cisco-nsp mailing list ?cisco-nsp at puck.nether.net >>> >>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>> >>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>> >>> >>> >>> >>> >> >>> > >>> _______________________________________________ >>> cisco-nsp mailing list ?cisco-nsp at puck.nether.net >>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> >> > From networkstuff.training at gmail.com Tue Apr 14 01:17:02 2009 From: networkstuff.training at gmail.com (Swati Sharma) Date: Tue, 14 Apr 2009 10:47:02 +0530 Subject: [c-nsp] rpr-plus switchover Message-ID: <8a93d4b30904132217p6d41d9bct139e3e865d5e09a8@mail.gmail.com> Hi, I am testing rpr-plus and could see links up in less then 1 sec but ping resume only after 47 sec.... I understand with rpr-plus we get more then 30 sec of ping drop, still when all links are up and adj is up, why there is a ping drop? 6500.LAB-sdby> Standby console disabled 6500.LAB-sdby> *Apr 14 05:03:28.909 UTC: %PFREDUN-SP-STDBY-6-ACTIVE: Initializing as ACTIVE processor *Apr 14 05:03:29.121 UTC: %SYS-SP-STDBY-3-LOGGER_FLUSHED: System was paused for 00:00:00 to ensure console debugging output. *Apr 14 05:03:31.873 UTC: %TDP-5-INFO: default: TDP ID removed *Apr 14 05:03:31.988 UTC: %C6KPWR-SP-4-PSOK: power supply 1 turned on. *Apr 14 05:03:31.996 UTC: %C6KPWR-SP-4-PSOK: power supply 2 turned on. *Apr 14 05:03:32.276 UTC: %FABRIC-SP-5-FABRIC_MODULE_ACTIVE: The Switch Fabric Module in slot 5 became active. *Apr 14 05:03:33.799 UTC: %OIR-SP-6-INSCARD: Card inserted in slot 5, interfaces are now online 00:00:01: BaseBoard Index:156 00:00:02: DaughterBoard Index:208 (Centralized Forwarding Card) 00:00:02: Gemini Rev#: 3 Firmware compiled 18-Oct-07 14:48 by integ Build [100] 00:00:04: %SYS-CFC1-5-RESTART: System restarted -- Cisco Internetwork Operating System Software IOS (tm) c6lc2 Software (c6lc2-SP-M), Version 12.2(18)SXF12a, RELEASE SOFTWARE (fc1) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2008 by cisco Systems, Inc. Compiled Thu 10-Jan-08 23:53 by kellythw *Nov 30 00:00:02.167: *CFC1: Currently running ROMMON from S (Gold) region* Apr 14 05:03:40.783 UTC: %DIAG-SP-6-RUN_COMPLETE: Module 1: Running Complete Diagnostics... Apr 14 05:03:42.179 UTC: %DIAG-SP-6-DIAG_OK: Module 1: Passed Online Diagnostics Apr 14 05:03:44.548 UTC: %OIR-SP-6-INSCARD: Card inserted in slot 1, interfaces are now online Apr 14 05:03:47.469 UTC: %DTP-SP-5-TRUNKPORTON: Port Gi1/1 has become dot1q trunk Apr 14 05:03:47.985 UTC: %DTP-SP-5-TRUNKPORTON: Port Gi1/3 has become dot1q trunk Apr 14 05:03:50.631 UTC: %DTP-SP-5-TRUNKPORTON: Port Gi1/18 has become isl trunk *Apr 14 05:03:57.157 UTC: %STANDBY-6-STATECHANGE: Vlan100 Group 1 state Listen -> Active 6500.LAB> 6500.LAB>en Password: 6500.LAB# *Apr 14 05:04:14.981 UTC: %CLNS-5-ADJCHANGE: ISIS: Adjacency to 0100.7409.0004 (GigabitEthernet1/23) Up, new adjacency *Apr 14 05:04:15.065 UTC: %CLNS-5-ADJCHANGE: ISIS: Adjacency to 0100.7409.0002 (GigabitEthernet1/24) Up, new adjacency *Apr 14 05:04:21.969 UTC: %LDP-5-NBRCHG: LDP Neighbor 10.74.90.4:0 is UP *Apr 14 05:04:22.529 UTC: %LDP-5-NBRCHG: LDP Neighbor 10.74.90.2:0 is UP *Apr 14 05:04:23.321 UTC: %BGP-5-ADJCHANGE: neighbor 10.74.90.4 Up *Apr 14 05:04:25.049 UTC: %BGP-5-ADJCHANGE: neighbor 10.74.90.2 Up *Apr 14 05:04:45.369 UTC: %STANDBY-6-STATECHANGE: Vlan1503 Group 10 state Standby -> Active Apr 14 05:06:21.515 UTC: %PFREDUN-SP-6-ACTIVE: Standby initializing for RPR-PLUS mode Apr 14 05:06:21.711 UTC: %SYS-SP-3-LOGGER_FLUSHED: System was paused for 00:00:00 to ensure console debugging output. Apr 14 05:06:23.464 UTC: %PFINIT-SP-5-CONFIG_SYNC: Sync'ing the startup configuration to the standby Router. 6500.LAB# Regards, From gert at greenie.muc.de Tue Apr 14 02:07:46 2009 From: gert at greenie.muc.de (Gert Doering) Date: Tue, 14 Apr 2009 08:07:46 +0200 Subject: [c-nsp] rpr-plus switchover In-Reply-To: <8a93d4b30904132217p6d41d9bct139e3e865d5e09a8@mail.gmail.com> References: <8a93d4b30904132217p6d41d9bct139e3e865d5e09a8@mail.gmail.com> Message-ID: <20090414060746.GK290@greenie.muc.de> Hi, On Tue, Apr 14, 2009 at 10:47:02AM +0530, Swati Sharma wrote: > I am testing rpr-plus and could see links up in less then 1 sec but ping > resume only after 47 sec.... I understand with rpr-plus we get more then 30 > sec of ping drop, still when all links are up and adj is up, why there is a > ping drop? Spanning-Tree? gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From ATolstykh at integrysgroup.com Tue Apr 14 10:31:57 2009 From: ATolstykh at integrysgroup.com (Tolstykh, Andrew) Date: Tue, 14 Apr 2009 09:31:57 -0500 Subject: [c-nsp] passive ftp static nat In-Reply-To: References: Message-ID: Dan, In addition to the outbound CBAC inspection map you also need to create another "ip inspect cbac_in" map (add ftp/data app inspection) and apply it in the inbound direction on SVI VL800. Andrew Tolstykh Senior Network Analyst Integrys Business Support, LLC atolstykh at integrysgroup.com (312) 240-3652 -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Dan Letkeman Sent: Friday, April 10, 2009 10:30 AM To: cisco-nsp Subject: [c-nsp] passive ftp static nat Hello, I'm having trouble logging into our ftp server from an external source. It works when you set the client to active mode, but passive mode always hangs. 2821, IOS Firewall Relevant config: ip inspect name SDM_LOW ftp interface GigabitEthernet0/0 ip address 10.10.10.1 255.255.255.252 ip nat inside ! ! interface FastEthernet0/0/3 description Internet switchport access vlan 800 bandwidth 10000 no cdp enable ! ! interface Vlan800 description Internet bandwidth 10000 ip address 64.x.x.1 255.255.255.224 ip access-group firewall in no ip redirects no ip unreachables no ip proxy-arp ip flow ingress ip nat outside ip inspect SDM_LOW out ip virtual-reassembly no mop enabled ! ! ip nat pool 152 64.x.x.1 64.x.x.1 netmask 255.255.255.224 ip nat inside source list internet-152 pool 152 overload ip nat inside source static tcp 172.16.0.24 21 64.x.x.1 21 extendable ip nat inside source static tcp 172.16.0.24 80 64.x.x.1 80 extendable ! ip access-list extended firewall permit tcp any host 64.x.x.1 eq ftp deny ip any any log ! ip access-list extended internet-152 permit tcp host 172.16.0.24 any I have tried adding: "permit tcp any host 64.x.x.1 gt 1024 established" to the firewall acl, but it still does not seem to connect from a passive ftp client. Dan. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From petelists at templin.org Tue Apr 14 10:54:06 2009 From: petelists at templin.org (Pete Templin) Date: Tue, 14 Apr 2009 09:54:06 -0500 Subject: [c-nsp] GSR OC3 Eng0 to Eng3 Message-ID: <49E4A38E.2050601@templin.org> List, We're seeing some odd issues on a transport OC3c between two POPs. We had a variety of failures at the Z end with two different Engine 0 4xOC3 cards, so we swapped out to an Engine 3 4xOC3 card. We're now seeing randomly-timed OSPF issues, as well as LOTS of PSE (positive stuff events) in the POS controllers. According to the Cisco troubleshooting docs, the likely causes boil down to degraded/dirty/too-strong link or clocking issues. At the Z end, it's a 10m run from the carrier FTP (with their DDM2000 in the same rack) to our router. We started with a back-to-back SC-SC coupler and a 1m SC-LC jumper so we could make the connector transition. We've switched it for a properly-connectorized jumper from FTP to card, with no change. We've tried multiple ports on the card, no change. We've asked the carrier to investigate, since they hand off to another carrier "in the middle" to get to the A end. Any thoughts on what to look for? Pete From lowen at pari.edu Tue Apr 14 11:32:25 2009 From: lowen at pari.edu (Lamar Owen) Date: Tue, 14 Apr 2009 11:32:25 -0400 Subject: [c-nsp] GSR OC3 Eng0 to Eng3 In-Reply-To: <49E4A38E.2050601@templin.org> References: <49E4A38E.2050601@templin.org> Message-ID: <200904141132.25902.lowen@pari.edu> On Tuesday 14 April 2009 10:54:06 Pete Templin wrote: > Any thoughts on what to look for? I'm running a 12012 with engine 0 4xOC3c cards here. The first thing I look for when this sort of things occurs is 'clock source line' in the configuration. I have swapped ports around before and forgotten to change the 'clock source internal' to 'clock source line' for the WAN OC3's, since I'm also using IR SM OC3's on campus over dark fiber (thus 'clock source internal' on both ends of those). This presents itself as random up/down-down/up events when one or both ends of the WAN OC3 are accidentally set clock source internal. Clock source line is supposed to be the default, incidentally. I don't have an ISE 4xOC3 LC to try with for the OSPF flapping issues, sorry. It's also possible the ADM is sending you a too-hot signal; you can simulate an attenuator for testing by slightly pulling the SC for the receive out; this simulates an air-gap attenuator. If you can get an improvement with a slight air-gap, it may be too hot from them to you, and you'll need to attenuate. Have your read http://www.cisco.com/en/US/tech/tk482/tk607/technologies_tech_note09186a008009464b.shtml (Troubleshooting PSE and NSE Events on POS Interfaces)? A Positive Stuff Event indicates a clock slip somewhere. (or the other things you mentioned; seems you have likely read this already.....) The most revealing line of this is that the POS LC's themselves do not do any stuffing, and those path PSE's are being reported by the SONET cloud. So it could be the interstital hop clock slipping. -- Lamar Owen Chief Information Officer Pisgah Astronomical Research Institute 1 PARI Drive Rosman, NC 28772 http://www.pari.edu From mtinka at globaltransit.net Tue Apr 14 11:00:31 2009 From: mtinka at globaltransit.net (Mark Tinka) Date: Tue, 14 Apr 2009 23:00:31 +0800 Subject: [c-nsp] carrier router models comparison In-Reply-To: <4981ce080904080128u2c54312apb7917ec5759a0335@mail.gmail.com> References: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> <49DB7D59.1030006@forthnet.gr> <4981ce080904080128u2c54312apb7917ec5759a0335@mail.gmail.com> Message-ID: <200904142300.32633.mtinka@globaltransit.net> On Wednesday 08 April 2009 04:28:26 pm Emanuel Popa wrote: > i'm really scared when using a fairly new platform with a > fairly new software version. Agree. I think the ASR9000 code is quite new. As you say, documentation is scarce, but I'm not sure IOS XR is prime time for typical edge services (and more). Heck, we're still trying to let the ASR1000 catch up :-). The 7200 has set quite a benchmark, but then again, the joys of doing things in hardware, new boxes, new code, e.t.c. Mark. -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 835 bytes Desc: This is a digitally signed message part. URL: From petelists at templin.org Tue Apr 14 11:44:41 2009 From: petelists at templin.org (Pete Templin) Date: Tue, 14 Apr 2009 10:44:41 -0500 Subject: [c-nsp] GSR OC3 Eng0 to Eng3 In-Reply-To: <200904141132.25902.lowen@pari.edu> References: <49E4A38E.2050601@templin.org> <200904141132.25902.lowen@pari.edu> Message-ID: <49E4AF69.2020305@templin.org> Lamar Owen wrote: > The first thing I look for when this sort of things occurs is 'clock source > line' in the configuration. Already checked. > It's also possible the ADM is sending you a too-hot signal; you can simulate > an attenuator for testing by slightly pulling the SC for the receive out; this > simulates an air-gap attenuator. If you can get an improvement with a slight > air-gap, it may be too hot from them to you, and you'll need to attenuate. Is it possible for the signal to be too hot for an Engine 3 card, while not too hot for an Engine 0 card? We had none of these OSPF events before switching cards. Unfortunately, I wasn't checking for PSE before. > Have your read > http://www.cisco.com/en/US/tech/tk482/tk607/technologies_tech_note09186a008009464b.shtml > (Troubleshooting PSE and NSE Events on POS Interfaces)? A Positive Stuff Event > indicates a clock slip somewhere. (or the other things you mentioned; seems > you have likely read this already.....) Yep, read that. > The most revealing line of this is that the POS LC's themselves do not do any > stuffing, and those path PSE's are being reported by the SONET cloud. So it > could be the interstital hop clock slipping. My suspicion is the carrier-carrier handoff, though I'm quick to remind myself that the OSPF problems only showed up when we switched cards. pt From rekordmeister at gmail.com Tue Apr 14 11:48:36 2009 From: rekordmeister at gmail.com (MKS) Date: Tue, 14 Apr 2009 15:48:36 +0000 Subject: [c-nsp] SRC on 7200 Message-ID: Hi list What's your experience with SRC or SRC3 on 7200, is it stable as a MPLS PE? Regards MKS From jcdarby at usgs.gov Tue Apr 14 12:18:32 2009 From: jcdarby at usgs.gov (Justin C. Darby) Date: Tue, 14 Apr 2009 11:18:32 -0500 Subject: [c-nsp] carrier router models comparison In-Reply-To: <200904142300.32633.mtinka@globaltransit.net> References: <4981ce080904070851h6381d4f0qf35885793e959087@mail.gmail.com> <49DB7D59.1030006@forthnet.gr> <4981ce080904080128u2c54312apb7917ec5759a0335@mail.gmail.com> <200904142300.32633.mtinka@globaltransit.net> Message-ID: <49E4B758.4020904@usgs.gov> To chime in a little bit here on the bleeding edge comments - we jumped on the Nexus 7K pretty early on (shortly after GA), as we would otherwise have spent about as much investing in new 6500's, our budget wasn't going to allow for replacing equipment for at least 5 years, and we were jumping on 10 Gigabit storage/LAN at this site so it had a clear advantage for us. NX-OS has got its share of bugs, but the switch has never failed outright to do its job and it forwards packets as configured for us, though we were quite aware it was a good idea to keep its initial deployment pretty simple and we spent a couple months building up the configuration and testing. I don't know how much you'd want to throw an ASR9000 into wide-area deployment immediately, but if you have a need it addresses well, I don't see why you couldn't get it to work based on my experience with the other Cisco bleeding edge OS (and probably a little bit of pre-sales engineering to go over your design). Of course, the documentation for NX-OS pre-launch was amazingly well organized. But, different business unit, I guess. I haven't done more than glance at the XR docs but things seem very similar to NX-OS docs, which is pretty good compared to the old IOS docs that are scattered everywhere. Justin P.S. This message contains personal comments and should not be considered an endorsement of the US Federal Government. :) Mark Tinka wrote: > On Wednesday 08 April 2009 04:28:26 pm Emanuel Popa wrote: > > >> i'm really scared when using a fairly new platform with a >> fairly new software version. >> > > Agree. I think the ASR9000 code is quite new. > > As you say, documentation is scarce, but I'm not sure IOS XR > is prime time for typical edge services (and more). Heck, > we're still trying to let the ASR1000 catch up :-). > > The 7200 has set quite a benchmark, but then again, the joys > of doing things in hardware, new boxes, new code, e.t.c. > > Mark. > > > ------------------------------------------------------------------------ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From lists.james.edwards at gmail.com Tue Apr 14 12:46:47 2009 From: lists.james.edwards at gmail.com (james edwards) Date: Tue, 14 Apr 2009 10:46:47 -0600 Subject: [c-nsp] Possible timing problems Message-ID: This is on the 3700 and a DS3 card. Looks like I am losing timing, which is derived from the line. I have searched on "clock change..." and have not pulled anything up at Cisco. I am not taking any errors. I wish there was a clock slip counter. Any ideas ? Apr 14 02:23:06.295 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to up Apr 14 02:23:06: clock change done for int ATM1/0 Apr 14 02:23:07: clock change removed for int ATM1/0 Apr 14 02:23:08: clock change done for int ATM1/0 Apr 14 02:23:10.299 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to down Apr 14 02:23:59: clock change removed for int ATM1/0 Apr 14 02:24:01.302 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to up Apr 14 02:24:01: clock change done for int ATM1/0 Apr 14 02:24:03.302 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to down Apr 14 02:26:46: clock change removed for int ATM1/0 Apr 14 02:26:48.318 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to up Apr 14 02:26:49.318 MST: %LINEPROTO-5-UPDOWN: Line protocol on Interface ATM1/0, changed state to up Apr 14 02:53:59: clock change done for int ATM1/0 xxxxx_3700#sho controll | in clock TX and RX clocks detected. Clock Source INTERNAL (but the source of this clock is derived from LINE) Roswell_3700#sho controll atm1/0 | in error-free LCV error-free secs 875335 DS3: F/M-bit error-free secs 875342 DS3: parity error-free secs 875335 DS3: path parity error-free secs 875335 T3/E3: excessive zeros error-free secs 875335 DS3/E3: G.832 FEBE error-free secs 868416 uncorrectable HEC error-free secs 875406 xxxx_3700# -- James H. Edwards Senior Network Systems Administrator Judicial Information Division jedwards at nmcourts.gov From lowen at pari.edu Tue Apr 14 12:54:25 2009 From: lowen at pari.edu (Lamar Owen) Date: Tue, 14 Apr 2009 12:54:25 -0400 Subject: [c-nsp] GSR OC3 Eng0 to Eng3 In-Reply-To: <49E4AF69.2020305@templin.org> References: <49E4A38E.2050601@templin.org> Message-ID: <200904141254.25427.lowen@pari.edu> On Tuesday 14 April 2009 11:44:41 Pete Templin wrote: > Lamar Owen wrote: > > It's also possible the ADM is sending you a too-hot signal; you can > > simulate an attenuator for testing by slightly pulling the SC for the > > receive out; this simulates an air-gap attenuator. If you can get an > > improvement with a slight air-gap, it may be too hot from them to you, > > and you'll need to attenuate. > Is it possible for the signal to be too hot for an Engine 3 card, while > not too hot for an Engine 0 card? We had none of these OSPF events > before switching cards. Unfortunately, I wasn't checking for PSE before. Hmm, engine 3 is using an SFF transceiver, but engine 0 an SC transceiver, so I would guess it's possible. Although the link budgets and power levels are documented as being the same ( http://www.cisco.com/en/US/docs/routers/12000/gsr_linecards/pos_lc/installation/guide/16412pos.html#wp652319 ). Both are intermediate reach cards, right? The engine 3 isn't a long reach by chance? I'm successfully using a 10 meter OC3 SM IR link between a 7609 OSM and an engine 0 4xOC3 IR, and it just works. > > So it could be the interstital hop clock slipping. > My suspicion is the carrier-carrier handoff, though I'm quick to remind > myself that the OSPF problems only showed up when we switched cards. What sort of failures prompted the card switch? -- Lamar Owen Chief Information Officer Pisgah Astronomical Research Institute 1 PARI Drive Rosman, NC 28772 http://www.pari.edu From petelists at templin.org Tue Apr 14 14:01:55 2009 From: petelists at templin.org (Pete Templin) Date: Tue, 14 Apr 2009 13:01:55 -0500 Subject: [c-nsp] GSR OC3 Eng0 to Eng3 In-Reply-To: <200904141254.25427.lowen@pari.edu> References: <49E4A38E.2050601@templin.org> <200904141254.25427.lowen@pari.edu> Message-ID: <49E4CF93.2030306@templin.org> Lamar Owen wrote: > What sort of failures prompted the card switch? Ugh. Card #1 went offline following an IOS upgrade reboot. Syslog messages suggested memory problems. After being swapped out, a reseat of the memory brought the card back to life as a hot spare. Card #2 began misbehaving with its one and only live link during the last NANOG. 'hw-mod slot X shutdown' and a removal of that brought the card back to life, but only for a few days. Card #1 and #2 were swapped. Then Card #1 began a few instances of random blackholing. After a reboot, it went offline again. Reseating memory didn't bring it back to life this time, so a memory swap with Card #2 was necessary. Both are in the dumpster now. Some other Engine 0 cards are soon to be freed up; I'm unfortunately tempted to roll back to one of those. pt From dudepron at gmail.com Tue Apr 14 14:38:15 2009 From: dudepron at gmail.com (Aaron) Date: Tue, 14 Apr 2009 14:38:15 -0400 Subject: [c-nsp] GSR OC3 Eng0 to Eng3 In-Reply-To: <49E4CF93.2030306@templin.org> References: <49E4A38E.2050601@templin.org> <200904141254.25427.lowen@pari.edu> <49E4CF93.2030306@templin.org> Message-ID: <480dad640904141138s76903cb0p7f93d20bf1de5733@mail.gmail.com> The ends of each fiber should be treated independently as far as signal strength. One side might indeed be stronger. On the E3 side, are the other ports plugged into a different system? I think that version slaves off of port 0 for all the ports for clocking. PSE are not really an issue but are an annoyance. Aaron On Tue, Apr 14, 2009 at 14:01, Pete Templin wrote: > Lamar Owen wrote: > > What sort of failures prompted the card switch? >> > > Ugh. Card #1 went offline following an IOS upgrade reboot. Syslog > messages suggested memory problems. After being swapped out, a reseat of > the memory brought the card back to life as a hot spare. > > Card #2 began misbehaving with its one and only live link during the last > NANOG. 'hw-mod slot X shutdown' and a removal of that brought the card back > to life, but only for a few days. Card #1 and #2 were swapped. > > Then Card #1 began a few instances of random blackholing. After a reboot, > it went offline again. Reseating memory didn't bring it back to life this > time, so a memory swap with Card #2 was necessary. > > Both are in the dumpster now. Some other Engine 0 cards are soon to be > freed up; I'm unfortunately tempted to roll back to one of those. > > pt > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From dudepron at gmail.com Tue Apr 14 14:40:34 2009 From: dudepron at gmail.com (Aaron) Date: Tue, 14 Apr 2009 14:40:34 -0400 Subject: [c-nsp] Possible timing problems In-Reply-To: References: Message-ID: <480dad640904141140s1ed4ef5fu3a9574170c03e2c9@mail.gmail.com> Why are you configured for internal and not line clocking? On Tue, Apr 14, 2009 at 12:46, james edwards wrote: > This is on the 3700 and a DS3 card. Looks like I am losing timing, which is > derived from the line. > I have searched on "clock change..." and have not pulled anything up at > Cisco. I am not taking any errors. > I wish there was a clock slip counter. > > Any ideas ? > > > > Apr 14 02:23:06.295 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to > up > Apr 14 02:23:06: clock change done for int ATM1/0 > Apr 14 02:23:07: clock change removed for int ATM1/0 > Apr 14 02:23:08: clock change done for int ATM1/0 > Apr 14 02:23:10.299 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to > down > Apr 14 02:23:59: clock change removed for int ATM1/0 > Apr 14 02:24:01.302 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to > up > Apr 14 02:24:01: clock change done for int ATM1/0 > Apr 14 02:24:03.302 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to > down > Apr 14 02:26:46: clock change removed for int ATM1/0 > Apr 14 02:26:48.318 MST: %LINK-3-UPDOWN: Interface ATM1/0, changed state to > up > Apr 14 02:26:49.318 MST: %LINEPROTO-5-UPDOWN: Line protocol on Interface > ATM1/0, changed state to up > Apr 14 02:53:59: clock change done for int ATM1/0 > > > xxxxx_3700#sho controll | in clock > TX and RX clocks detected. > Clock Source INTERNAL (but the source of this clock is derived from > LINE) > > Roswell_3700#sho controll atm1/0 | in error-free > LCV error-free secs 875335 > DS3: F/M-bit error-free secs 875342 > DS3: parity error-free secs 875335 > DS3: path parity error-free secs 875335 > T3/E3: excessive zeros error-free secs 875335 > DS3/E3: G.832 FEBE error-free secs 868416 > uncorrectable HEC error-free secs 875406 > xxxx_3700# > > > -- > James H. Edwards > Senior Network Systems Administrator > Judicial Information Division > jedwards at nmcourts.gov > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From petelists at templin.org Tue Apr 14 14:43:18 2009 From: petelists at templin.org (Pete Templin) Date: Tue, 14 Apr 2009 13:43:18 -0500 Subject: [c-nsp] GSR OC3 Eng0 to Eng3 In-Reply-To: <480dad640904141138s76903cb0p7f93d20bf1de5733@mail.gmail.com> References: <49E4A38E.2050601@templin.org> <200904141254.25427.lowen@pari.edu> <49E4CF93.2030306@templin.org> <480dad640904141138s76903cb0p7f93d20bf1de5733@mail.gmail.com> Message-ID: <49E4D946.2070505@templin.org> Aaron wrote: > The ends of each fiber should be treated independently as far as signal > strength. One side might indeed be stronger. We changed a router card, and now we're seeing PSE on both ends. If the E3 card is stronger, I can accept that we're overdriving the carrier's gear, causing issues to be seen at the other end, but if we follow the same logic shouldn't the card also _accept_ a stronger signal (and therefore not take PSE due to the wider margin)? > On the E3 side, are the other ports plugged into a different system? I > think that version slaves off of port 0 for all the ports for clocking. This is the only link in the card. Problems were the same whether it was in port 0, port 1, or as currently in port 2. I've also gotten an offlist response which showed me how to adjust the timing sources at the card level. > PSE are not really an issue but are an annoyance. We're seeing OSPFv3 issues that seem to coincide with times when the PSE rate is perhaps highest. We're also seeing far more than the Cisco troubleshooting doc says is allowable, figure a million per day. pt From denyipanyany at gmail.com Tue Apr 14 15:50:46 2009 From: denyipanyany at gmail.com (Deny IP Any Any) Date: Tue, 14 Apr 2009 15:50:46 -0400 Subject: [c-nsp] failover stability of ASA 8.0 code Message-ID: I'm looking for general real-world experiences of stability of a fail over ASA cluster running 8.0.x code. At least in earlier 8.0 codes, we ran into several failover-specific bugs, and am hoping things are smoother now. -- deny ip any any (4393649193 matches) From tvarriale at comcast.net Tue Apr 14 16:30:17 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Tue, 14 Apr 2009 15:30:17 -0500 Subject: [c-nsp] failover stability of ASA 8.0 code References: Message-ID: <179C3A6094024824830413BC9B0A8429@flamdt01> Working fine here on a lot of 8.0(3) boxes. What code were you running and what problems did you have? tv ----- Original Message ----- From: "Deny IP Any Any" To: Sent: Tuesday, April 14, 2009 2:50 PM Subject: [c-nsp] failover stability of ASA 8.0 code > I'm looking for general real-world experiences of stability of a fail > over ASA cluster running 8.0.x code. At least in earlier 8.0 codes, we > ran into several failover-specific bugs, and am hoping things are > smoother now. > > -- > deny ip any any (4393649193 matches) > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From jason at lixfeld.ca Tue Apr 14 18:22:03 2009 From: jason at lixfeld.ca (Jason Lixfeld) Date: Tue, 14 Apr 2009 18:22:03 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? Message-ID: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> We have a box with the above specifications in production. 4 interfaces are being used; 2 ATM, 2 GigE. SLOT 0 (RP/LC 0 ): Route Processor Route Memory: MEM-GRP-512= SLOT 2 (RP/LC 2 ): 4 port ATM Over SONET OC12c/STM-4c Multi Mode Processor Memory: MEM-GRP/LC-256= Packet Memory: MEM-LC1-PKT-256= L3 Engine: 2 - Backbone OC48 (2.5 Gbps) SLOT 5 (RP/LC 5 ): 3 Port Gigabit Ethernet Processor Memory: MEM-GRP/LC-256= Packet Memory: MEM-LC1-PKT-256= L3 Engine: 2 - Backbone OC48 (2.5 Gbps) For the life of us, we can't seem to get any more than 60Mbps sustained across the ATM testing with iperf, so we're just trying to figure out if the GSR just can't push any more than what it's doing or if there's something else afoot. CPU doesn't seem to be running too hot: CPU utilization for five seconds: 6%/0%; one minute: 20%; five minutes: 19% Interface utilization seems reasonable. bdr1.nyc-hudson-12008#show int a2/0 load Interface bits/sec pack/sec -------------------- ------------ ---------- AT2/0 Tx 48464000 14099 Rx 104808000 18012 bdr1.nyc-hudson-12008#show int a2/1 load Interface bits/sec pack/sec -------------------- ------------ ---------- AT2/1 Tx 57581000 13032 Rx 116319000 14466 bdr1.nyc-hudson-12008#show int g5/0 load Interface bits/sec pack/sec -------------------- ------------ ---------- Gi5/0 Tx 56851000 8981 Rx 35082000 7833 bdr1.nyc-hudson-12008#show int g5/1 load Interface bits/sec pack/sec -------------------- ------------ ---------- Gi5/1 Tx 166072000 23424 Rx 70951000 19116 bdr1.nyc-hudson-12008# Total Throughput: 656128000 Total PPS: 118963 Average Size (B): 689.4 We've done our due diligence to ensure the bits of the network between the test machine and the ATM can support 100Mbps, so we're fairly confident that our test setup is adequate. We can get ~97Mbps across other portions of the network (riding GE and 10GE on completely different devices). Are we pushing this thing to it's limits taking into consideration the packet size vs. total throughput and total pps? From john.douglas at gmail.com Tue Apr 14 18:31:51 2009 From: john.douglas at gmail.com (john douglas) Date: Wed, 15 Apr 2009 08:31:51 +1000 Subject: [c-nsp] Catalyst 3750 RxQ2 buffers failures Message-ID: <5c846eaf0904141531o60826084va6791315c1b5de70@mail.gmail.com> Hi All, I have a variety of Catalyst 29xx/35xx/65xx/37xx switches and all my 3750 seem to be incrementing "RxQ2 buffers" failures in interface buffers pools. If I am to understand correctly public buffer pools will be used as a fallback so there is no performance hit and I do not need to concern myself with this counter incrementing .... but just wondering since this seems to happen on the 3 x 3750 we have and nothing else if anyone has any ideas why ? Eg Switch#sh buf | b RxQ2 RxQ2 buffers, 2040 bytes (total 128, permanent 128): 1 in free list (0 min, 128 max allowed) 17212436 hits, 134472 fallbacks, 0 trims, 0 created 134472 failures (0 no memory) -jd From rgolodner at infratection.com Tue Apr 14 19:31:37 2009 From: rgolodner at infratection.com (Richard Golodner) Date: Tue, 14 Apr 2009 18:31:37 -0500 Subject: [c-nsp] Possible timing problems In-Reply-To: References: Message-ID: <004901c9bd59$2875af30$79610d90$@com> James said today: > Clock Source INTERNAL (but the source of this clock is derived from LINE) Change this config so that timing is supplied by line (telco) rather than INTERNAL. Richard From bdikici at gmail.com Tue Apr 14 19:45:57 2009 From: bdikici at gmail.com (Burak Dikici) Date: Wed, 15 Apr 2009 02:45:57 +0300 Subject: [c-nsp] Classify geographical traffic with BGP Message-ID: Hello , I have got one internet router running BGP , and this router has got connections with two different ISPs. One of the ISP is local for my country and the other ISP's location is outside of my country. I want to classify geographical traffic with BGP. For example , local traffic to my country will go through ISP-1 (local ISP) , outside traffic to my country will go through ISP-2 (outside of my country ISP). What i have to do to achieve that kind of configuration ? If i have to use AS path filter , how can i find the local ISP AS path numbers and how can i configure AS path filter for this request ? Is that enough using the as-path filter just for the national ISP or should i use it for international ISP also ? If i use AS-path filter for both ISP connections , what will happen to redundancy ? I mean , for example i filter national AS numbers at the international ISP connection and deny them. Secondly , i filter national AS numbers at the national ISP connection , permit them and the other AS numbers will be denied. In this situation , what will happen if the local ISP connection goes down ? Because of filtering of the national AS numbers at the international ISP connection , the BGP table doesn't take any updates from the local AS numbers. I hope , i could explain the situation correctly. Kind Regards... Burak Dikici From walter.keen at RainierConnect.net Tue Apr 14 19:53:24 2009 From: walter.keen at RainierConnect.net (Walter Keen) Date: Tue, 14 Apr 2009 16:53:24 -0700 Subject: [c-nsp] Classify geographical traffic with BGP In-Reply-To: References: Message-ID: <49E521F4.4000705@rainierconnect.net> If you are not advertising any space, I would imagine an AS path filter on ISP-1 (limited to 1 or 2 hops, if that works for you) and no AS path filter on ISP-2 would do the trick. You would want a floating static default route(s) for outbound traffic redundancy. Now, if you are advertising space, as path prepending may be one way to go as far as inbound traffic goes, but it gets messy in a situation like this one. If you prepend your AS number too many times out ISP1, then traffic you may have wanted to come in ISP1 may see ISP2 as a closer route (less AS hops). Burak Dikici wrote: > Hello , > > I have got one internet router running BGP , and this router has got > connections with two different ISPs. One of the ISP is local for my country > and the other ISP's location is outside of my country. I want to classify > geographical traffic with BGP. For example , local traffic to my country > will go through ISP-1 (local ISP) , outside traffic to my country will go > through ISP-2 (outside of my country ISP). What i have to do to achieve that > kind of configuration ? If i have to use AS path filter , how can i find the > local ISP AS path numbers and how can i configure AS path filter for this > request ? Is that enough using the as-path filter just for the national ISP > or should i use it for international ISP also ? > > If i use AS-path filter for both ISP connections , what will happen to > redundancy ? I mean , for example i filter national AS numbers at the > international ISP connection and deny them. Secondly , i filter national AS > numbers at the national ISP connection , permit them and the other AS > numbers will be denied. In this situation , what will happen if the local > ISP connection goes down ? Because of filtering of the national AS numbers > at the international ISP connection , the BGP table doesn't take any updates > from the local AS numbers. I hope , i could explain the situation correctly. > > > Kind Regards... > > Burak Dikici > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From paul.stainton at talktalk.net Tue Apr 14 19:23:22 2009 From: paul.stainton at talktalk.net (Paul Stainton) Date: Wed, 15 Apr 2009 00:23:22 +0100 Subject: [c-nsp] 3550 as a internet distribution switch Message-ID: <000001c9bd58$00e9e4f0$0514a8c0@support> Hi, Is this possible? I want to configure a 3550 as follows, 1 port as a default gateway, this will be connected to a internet router. e.g. a WAN connection Any number of other the other ports to be assigned an IP address that can be connected to a cable NAT Router and all outbound traffic be sent to the default gateway of the 3350 e.g. Vlan 2 WAN connection to the internet assigned an IP address of the internet router Vlan 3, assign IP address 192.168.1.1 255.255.255.0, therefore a cable NAT router can be connected to this Vlan which could have the IP address 192.168.1.2 Default Gateway 192.168.1.1 All internet traffic will then be directed from the cable Nat router to 192.168.1.2, to 19.168.1.1 on Vlan 3 which in turn will forward the internet traffic to vlan 2 the WAN connection and out to the internet router Vlan 4 assign IP address 192.168.2.1 255.25.255.0 then as above except for the 192.168.2 subnet Vlan 5 assign IP address 192.168.3.1 etc, etc Have tried several ways but can never get out on the internet. Any help would be appreciated. Regards Paul Stainton From ml at t-b-o-h.net Tue Apr 14 19:07:56 2009 From: ml at t-b-o-h.net (Tuc at T-B-O-H) Date: Tue, 14 Apr 2009 19:07:56 -0400 (EDT) Subject: [c-nsp] %SYS-2-INTSCHED: 'suspend' at level 3 -Process= "Virtual Exec" Message-ID: <200904142307.n3EN7uos036699@vjofn.tucs-beachin-obx-house.com> Hi, I'm suddenly getting : Apr 14 17:27:21 EDT: %SYS-2-INTSCHED: 'suspend' at level 3 -Process= "Virtual Exec", ipl= 3, pid= 136 -Traceback= 0x6049A4C4 0x605D94CC 0x605A55C4 0x625BFDD0 0x60E67FD0 0x60E68DA8 0x625BFD84 0x60E62804 0x60E3D8E0 0x604DAD28 0x604F6FB4 0x60598000 0x60597FE4 I'd like to say I didn't make any changes, but I've slowly been tearing apart my config because one of my upstreams changed how things work so now I'm basically running bare bones here. I have IPSLA running but it isn't used for routing decisions. Any idea where to start looking? Thanks, Tuc From mksmith at adhost.com Tue Apr 14 20:10:30 2009 From: mksmith at adhost.com (Michael K. Smith - Adhost) Date: Tue, 14 Apr 2009 17:10:30 -0700 Subject: [c-nsp] 3550 as a internet distribution switch In-Reply-To: <000001c9bd58$00e9e4f0$0514a8c0@support> References: <000001c9bd58$00e9e4f0$0514a8c0@support> Message-ID: <17838240D9A5544AAA5FF95F8D52031605D17C65@ad-exh01.adhost.lan> Hello Paul: Hi, Is this possible? I want to configure a 3550 as follows, 1 port as a default gateway, this will be connected to a internet router. e.g. a WAN connection Any number of other the other ports to be assigned an IP address that can be connected to a cable NAT Router and all outbound traffic be sent to the default gateway of the 3350 [Michael K. Smith - Adhost] It doesn't appear that NAT is supported on the 3550, so you would have to use valid IP's on all of your Layer 3 connections for this to work. See: http://www.cisco.com/en/US/products/hw/switches/ps646/products_configura tion_guide_chapter09186a00801cdf37.html Regards, Mike From bdikici at gmail.com Tue Apr 14 20:15:55 2009 From: bdikici at gmail.com (Burak Dikici) Date: Wed, 15 Apr 2009 03:15:55 +0300 Subject: [c-nsp] Classify geographical traffic with BGP In-Reply-To: <49E521F4.4000705@rainierconnect.net> References: <49E521F4.4000705@rainierconnect.net> Message-ID: By the way i wonder , how can it be done symmetrical traffic flow in this scenario ? Local traffic goes from local ISP and the return traffic comes back through local ISP. Outside of the country traffic goes from international IPS and the return traffic comes back through internaional ISP. I don't want to cause any asymmetrical traffic flow between different ISPs and my site. On Wed, Apr 15, 2009 at 2:53 AM, Walter Keen wrote: > If you are not advertising any space, I would imagine an AS path filter > on ISP-1 (limited to 1 or 2 hops, if that works for you) and no AS path > filter on ISP-2 would do the trick. You would want a floating static > default route(s) for outbound traffic redundancy. > > Now, if you are advertising space, as path prepending may be one way to > go as far as inbound traffic goes, but it gets messy in a situation like > this one. If you prepend your AS number too many times out ISP1, then > traffic you may have wanted to come in ISP1 may see ISP2 as a closer > route (less AS hops). > > Burak Dikici wrote: > > Hello , > > > > I have got one internet router running BGP , and this router has got > > connections with two different ISPs. One of the ISP is local for my > country > > and the other ISP's location is outside of my country. I want to classify > > geographical traffic with BGP. For example , local traffic to my country > > will go through ISP-1 (local ISP) , outside traffic to my country will go > > through ISP-2 (outside of my country ISP). What i have to do to achieve > that > > kind of configuration ? If i have to use AS path filter , how can i find > the > > local ISP AS path numbers and how can i configure AS path filter for this > > request ? Is that enough using the as-path filter just for the national > ISP > > or should i use it for international ISP also ? > > > > If i use AS-path filter for both ISP connections , what will happen to > > redundancy ? I mean , for example i filter national AS numbers at the > > international ISP connection and deny them. Secondly , i filter national > AS > > numbers at the national ISP connection , permit them and the other AS > > numbers will be denied. In this situation , what will happen if the local > > ISP connection goes down ? Because of filtering of the national AS > numbers > > at the international ISP connection , the BGP table doesn't take any > updates > > from the local AS numbers. I hope , i could explain the situation > correctly. > > > > > > Kind Regards... > > > > Burak Dikici > > _______________________________________________ > > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > > From hiromasa.sekiguchi at ctc-g.co.jp Tue Apr 14 22:54:57 2009 From: hiromasa.sekiguchi at ctc-g.co.jp (Hiromasa Sekiguchi) Date: Wed, 15 Apr 2009 11:54:57 +0900 Subject: [c-nsp] WS-X6748-SFP temperature sensor Message-ID: <49E54C81.2090909@ctc-g.co.jp> Hi all, Does WS-X6748-SFP have temperature sensor? Can we confirm it on cisco web site? Regards, Hiromasa From engel.labiro at gmail.com Wed Apr 15 01:10:17 2009 From: engel.labiro at gmail.com (Engelhard Labiro) Date: Wed, 15 Apr 2009 14:10:17 +0900 Subject: [c-nsp] WS-X6748-SFP temperature sensor In-Reply-To: <49E54C81.2090909@ctc-g.co.jp> References: <49E54C81.2090909@ctc-g.co.jp> Message-ID: <74b0c3330904142210o55b7abbfna3ab101ac5c61ac6@mail.gmail.com> Couldn`t find doco on cisco that state it has a temp.sensor..but "sh env" of the module indicates that the chassis is able to show the temp. of the card. sh module Mod Ports Card Type Mode --- ----- -------------------------------------- ------------------ 1 8 CEF720 8 port 10GE with DFC WS-X6708-10GE 2 8 CEF720 8 port 10GE with DFC WS-X6708-10GE 3 48 CEF720 48 port 1000mb SFP WS-X6748-SFP 4 48 CEF720 48 port 10/100/1000mb Ethernet WS-X6748-GE-TX 5 2 Supervisor Engine 720 (Active) WS-SUP720-3B xxxxx>sh environment temperature module 3 module 3 outlet temperature: 50C module 3 inlet temperature: 36C module 3 device-1 temperature: 36C module 3 device-2 temperature: 46C 2009/4/15 Hiromasa Sekiguchi : > Hi all, > > Does WS-X6748-SFP have temperature sensor? > > Can we confirm it on cisco web site? > > Regards, > Hiromasa > > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From Moens at carrier2carrier.com Wed Apr 15 02:28:07 2009 From: Moens at carrier2carrier.com (Martin Moens) Date: Wed, 15 Apr 2009 08:28:07 +0200 Subject: [c-nsp] WS-X6748-SFP temperature sensor In-Reply-To: <74b0c3330904142210o55b7abbfna3ab101ac5c61ac6@mail.gmail.com> Message-ID: <42F0C766A9A8DB47B5E86CA64738DC8B0190610F@bilbo.bdhz.c2c.local> Do a snmpwalk on 1.3.6.1.4.1.9.9.13.1.3.1, this gives info on all the temp sensors in the box. Martin On Wednesday, 15 April, 2009 07:10 Engelhard Labiro <> wrote: > Couldn`t find doco on cisco that state it has a temp.sensor..but > "sh env" of the module indicates that the chassis is able to show the > temp. of the card. > > sh module > Mod Ports Card Type Mode > --- ----- -------------------------------------- ------------------ > 1 8 CEF720 8 port 10GE with DFC WS-X6708-10GE > 2 8 CEF720 8 port 10GE with DFC WS-X6708-10GE > 3 48 CEF720 48 port 1000mb SFP WS-X6748-SFP > 4 48 CEF720 48 port 10/100/1000mb Ethernet WS-X6748-GE-TX > 5 2 Supervisor Engine 720 (Active) WS-SUP720-3B > > xxxxx>sh environment temperature module 3 > module 3 outlet temperature: 50C > module 3 inlet temperature: 36C > module 3 device-1 temperature: 36C > module 3 device-2 temperature: 46C > > 2009/4/15 Hiromasa Sekiguchi : >> Hi all, >> >> Does WS-X6748-SFP have temperature sensor? >> >> Can we confirm it on cisco web site? >> >> Regards, >> Hiromasa >> >> _______________________________________________ >> cisco-nsp mailing list ?cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From wyatt.eliasson at gmail.com Wed Apr 15 02:47:15 2009 From: wyatt.eliasson at gmail.com (Wyatt Mattias Gyllenvarg) Date: Wed, 15 Apr 2009 08:47:15 +0200 Subject: [c-nsp] ME3400-24FS 12.2(46)SE METROIPACCESS with no MLS QOS commands Message-ID: <994752fe0904142347n65ed4960ife3125d3eb29fce9@mail.gmail.com> Hi all! I've been racking my brain over this for a day now. I have a multicast stream that I have marked with a DSCP value close at the core of my net. I subscribe too it in an ME3400-24FS (12.2(46)SE METROIPACCESS). The problem is that the switch, contrary too documentation, has no "mls qos" commands. Neither global nor interface commands. I haven't found any reference too this "change" anywhere. So, how do I get it too trust the DSCP values it on the uplink port so I can reserve bandwidth for it on the outgoing port. Best regards Mattias Gyllenvarg From wyatt.eliasson at gmail.com Wed Apr 15 04:02:15 2009 From: wyatt.eliasson at gmail.com (Wyatt Mattias Gyllenvarg) Date: Wed, 15 Apr 2009 10:02:15 +0200 Subject: [c-nsp] ME3400-24FS 12.2(46)SE METROIPACCESS with no MLS QOS commands In-Reply-To: <200904150752.n3F7qPgC018835@ns.gastabud.com> References: <994752fe0904142347n65ed4960ife3125d3eb29fce9@mail.gmail.com> <200904150752.n3F7qPgC018835@ns.gastabud.com> Message-ID: <994752fe0904150102x762f562ep3d34327fb20fa3b1@mail.gmail.com> Hi Claes I figured that something like that would work, but it seems a like a stretch compared too "mls qos trust". I will run a version of your config for the time being. Thanks Mattias Gyllenvarg 2009/4/15 Claes Jansson : > Hi Mattias! > > I've been in the same position as you are now :-) But I finally solved it with the following config... The key is the input service-policy on the uplink interface it seems... > > ! > class-map match-any video > match ip dscp af41 > class-map match-any voice > match ip dscp ef > ! > policy-map uplink-in > class video > set dscp af41 > class voice > set dscp ef > ! > interface GigabitEthernet0/1 > port-type nni > switchport mode trunk > service-policy input uplink-in > ! > > And then for the customer interfaces i attach a policy-map that looks like this... > > // Shaping customer internet trafic at 10Mbit/s > ! > policy-map 10out > class voice > priority > police cir 3000000 > class video > shape average 50000000 > class class-default > shape average 10000000 > ! > > Best regards. > > //Claes Jansson > > At 08:47 2009-04-15, you wrote: >>Hi all! >> >>I've been racking my brain over this for a day now. >> >>I have a multicast stream that I have marked with a DSCP value close >>at the core of my net. >>I subscribe too it in an ME3400-24FS (12.2(46)SE METROIPACCESS). >> >>The problem is that the switch, contrary too documentation, has no >>"mls qos" commands. >>Neither global nor interface commands. I haven't found any reference >>too this "change" anywhere. >> >>So, how do I get it too trust the DSCP values it on the uplink port so >>I can reserve bandwidth for it on the outgoing port. >> >>Best regards >>Mattias Gyllenvarg >>_______________________________________________ >>cisco-nsp mailing list cisco-nsp at puck.nether.net >>https://puck.nether.net/mailman/listinfo/cisco-nsp >>archive at http://puck.nether.net/pipermail/cisco-nsp/ > > From achatz at forthnet.gr Wed Apr 15 04:03:36 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Wed, 15 Apr 2009 11:03:36 +0300 Subject: [c-nsp] ME3400-24FS 12.2(46)SE METROIPACCESS with no MLS QOS commands In-Reply-To: <994752fe0904142347n65ed4960ife3125d3eb29fce9@mail.gmail.com> References: <994752fe0904142347n65ed4960ife3125d3eb29fce9@mail.gmail.com> Message-ID: <49E594D8.2040808@forthnet.gr> Mattias, I believe the default mode is to not change the CoS/DSCP of packets, so you shouldn't have any problem. Also, you can use a policy-map under the interface if you want to modify the above. -- Tassos Wyatt Mattias Gyllenvarg wrote on 15/04/2009 09:47: > Hi all! > > I've been racking my brain over this for a day now. > > I have a multicast stream that I have marked with a DSCP value close > at the core of my net. > I subscribe too it in an ME3400-24FS (12.2(46)SE METROIPACCESS). > > The problem is that the switch, contrary too documentation, has no > "mls qos" commands. > Neither global nor interface commands. I haven't found any reference > too this "change" anywhere. > > So, how do I get it too trust the DSCP values it on the uplink port so > I can reserve bandwidth for it on the outgoing port. > > Best regards > Mattias Gyllenvarg > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From adrian.minta at gmail.com Wed Apr 15 05:36:31 2009 From: adrian.minta at gmail.com (Adrian Minta) Date: Wed, 15 Apr 2009 12:36:31 +0300 Subject: [c-nsp] ME3400 uRPF Message-ID: <49E5AA9F.9010400@gmail.com> According to "Cisco ME 3400 data sheet" http://tinyurl.com/yphgj5 the switch support uRPF with METROIPACCESS image, but I get the following error: switch(config)#interface GigabitEthernet0/2 switch(config-if)#ip verify unicast reverse-path % ip verify configuration not supported on interface Gi0/2 - verification not supported by hardware Does anyone knows the magic needed to make uRPF work on this switch ? System image file is "flash:me340x-metroipaccess-mz.122-40.SE/me340x-metroipaccess-mz.122-40.SE.bin" cisco ME-3400G-12CS-A (PowerPC405) processor (revision C0) with 118784K/12280K bytes of memory. Interface GigabitEthernet0/2 is in routed mode (no switchport). -- Best regards, Adrian Minta From johns.stanly at gmail.com Wed Apr 15 06:07:13 2009 From: johns.stanly at gmail.com (Stanly Johns) Date: Wed, 15 Apr 2009 13:07:13 +0300 Subject: [c-nsp] VTY Lines Message-ID: Hi there, even after clearing the vty lines they were still there. I was unable to telnet to the router. I had to restart the router to clear all the lines. any clue what could be the reason ? thanks. Perimeter#sh users Line User Host(s) Idle Location * 0 con 0 idle 00:00:00 322 vty 0 idle 5w1d 190.42.12.218 323 vty 1 idle 5w0d client-201.230.86.15.speedy.net.pe 324 vty 2 idle 3w5d 151.56.21.165 325 vty 3 idle 2w4d client-190.40.212.198.speedy.net.pe 326 vty 4 idle 1w5d 84.36.28.19 Interface User Mode Idle Peer Address Perimeter# Perimeter#clear line vty 2 [confirm] [OK] Perimeter# Perimeter#sh users Line User Host(s) Idle Location * 0 con 0 idle 00:00:00 322 vty 0 idle 5w1d 190.42.12.218 323 vty 1 idle 5w0d client-201.230.86.15.speedy.net.pe 324 vty 2 idle 3w5d 151.56.21.165 325 vty 3 idle 2w4d client-190.40.212.198.speedy.net.pe 326 vty 4 idle 1w5d 84.36.28.19 Interface User Mode Idle Peer Address line con 0 stopbits 1 line aux 0 stopbits 1 line vty 0 4 password 7 login ! scheduler allocate 20000 1000 ! end Perimeter# From achatz at forthnet.gr Wed Apr 15 06:50:24 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Wed, 15 Apr 2009 13:50:24 +0300 Subject: [c-nsp] ME3400 uRPF In-Reply-To: <49E5AA9F.9010400@gmail.com> References: <49E5AA9F.9010400@gmail.com> Message-ID: <49E5BBF0.60804@forthnet.gr> uRPF is for VRFs in the ME-3400 (strange, isn't it?) -- Tassos Adrian Minta wrote on 15/04/2009 12:36: > According to "Cisco ME 3400 data sheet" http://tinyurl.com/yphgj5 the > switch support uRPF with METROIPACCESS image, but I get the following > error: > switch(config)#interface GigabitEthernet0/2 > switch(config-if)#ip verify unicast reverse-path > % ip verify configuration not supported on interface Gi0/2 > - verification not supported by hardware > > Does anyone knows the magic needed to make uRPF work on this switch ? > > System image file is > "flash:me340x-metroipaccess-mz.122-40.SE/me340x-metroipaccess-mz.122-40.SE.bin" > > cisco ME-3400G-12CS-A (PowerPC405) processor (revision C0) with > 118784K/12280K bytes of memory. > > Interface GigabitEthernet0/2 is in routed mode (no switchport). > From wyatt.eliasson at gmail.com Wed Apr 15 08:09:12 2009 From: wyatt.eliasson at gmail.com (Wyatt Mattias Gyllenvarg) Date: Wed, 15 Apr 2009 14:09:12 +0200 Subject: [c-nsp] ME3400-24FS 12.2(46)SE METROIPACCESS with no MLS QOS commands In-Reply-To: <49E594D8.2040808@forthnet.gr> References: <994752fe0904142347n65ed4960ife3125d3eb29fce9@mail.gmail.com> <49E594D8.2040808@forthnet.gr> Message-ID: <994752fe0904150509wc5008d6oa850b35029e39a35@mail.gmail.com> Hey All Thanks for your answers. Here is the end result. The equivalent config for "mls qos trust dscp" on a physical interface on a ME3400 is. policy-map uplink class class-default set dscp dscp interface gix/y service-policy input uplink User friendly clue was: me3400(config-pmap-c)#set dscp ? dscp Set packet dscp from dscp Enjoy Mattias Gyllenvarg 2009/4/15 Tassos Chatzithomaoglou : > Mattias, > > I believe the default mode is to not change the CoS/DSCP of packets, so you > shouldn't have any problem. > Also, you can use a policy-map under the interface if you want to modify the > above. > > > -- > Tassos > > > Wyatt Mattias Gyllenvarg wrote on 15/04/2009 09:47: >> >> Hi all! >> >> I've been racking my brain over this for a day now. >> >> I have a multicast stream that I have marked with a DSCP value close >> at the core of my net. >> I subscribe too it in an ME3400-24FS (12.2(46)SE METROIPACCESS). >> >> The problem is that the switch, contrary too documentation, has no >> "mls qos" commands. >> Neither global nor interface commands. I haven't found any reference >> too this "change" anywhere. >> >> So, how do I get it too trust the DSCP values it on the uplink port so >> I can reserve bandwidth for it on the outgoing port. >> >> Best regards >> Mattias Gyllenvarg >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From wp at null0.nl Wed Apr 15 09:26:44 2009 From: wp at null0.nl (Wouter Prins) Date: Wed, 15 Apr 2009 15:26:44 +0200 Subject: [c-nsp] VTY Lines In-Reply-To: References: Message-ID: Hi Stanly, You have to use 'disconnect x' to clear a vty terminal, 'clear x' is for async lines. 2009/4/15 Stanly Johns > Hi there, > > even after clearing the vty lines they were still there. I was unable to > telnet to the router. > > I had to restart the router to clear all the lines. > > any clue what could be the reason ? > > thanks. > > Perimeter#sh users > Line User Host(s) Idle Location > * 0 con 0 idle 00:00:00 > 322 vty 0 idle 5w1d 190.42.12.218 > 323 vty 1 idle 5w0d > client-201.230.86.15.speedy.net.pe > 324 vty 2 idle 3w5d 151.56.21.165 > 325 vty 3 idle 2w4d > client-190.40.212.198.speedy.net.pe > 326 vty 4 idle 1w5d 84.36.28.19 > > Interface User Mode Idle Peer Address > > Perimeter# > Perimeter#clear line vty 2 > [confirm] > [OK] > Perimeter# > Perimeter#sh users > Line User Host(s) Idle Location > * 0 con 0 idle 00:00:00 > 322 vty 0 idle 5w1d 190.42.12.218 > 323 vty 1 idle 5w0d > client-201.230.86.15.speedy.net.pe > 324 vty 2 idle 3w5d 151.56.21.165 > 325 vty 3 idle 2w4d > client-190.40.212.198.speedy.net.pe > 326 vty 4 idle 1w5d 84.36.28.19 > > Interface User Mode Idle Peer Address > > line con 0 > stopbits 1 > line aux 0 > stopbits 1 > line vty 0 4 > password 7 > > login > ! > scheduler allocate 20000 1000 > ! > end > > Perimeter# > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > -- Wouter Prins wp at null0.nl 0x301FA912 From networkstuff.training at gmail.com Wed Apr 15 09:34:00 2009 From: networkstuff.training at gmail.com (Swati Sharma) Date: Wed, 15 Apr 2009 19:04:00 +0530 Subject: [c-nsp] rpr-plus switchover In-Reply-To: <20090414060746.GK290@greenie.muc.de> References: <8a93d4b30904132217p6d41d9bct139e3e865d5e09a8@mail.gmail.com> <20090414060746.GK290@greenie.muc.de> Message-ID: <8a93d4b30904150634h64754234ra5d5c345c362f911@mail.gmail.com> it's rapid pvst, should not take time..... Regards, On Tue, Apr 14, 2009 at 11:37 AM, Gert Doering wrote: > Hi, > > On Tue, Apr 14, 2009 at 10:47:02AM +0530, Swati Sharma wrote: > > I am testing rpr-plus and could see links up in less then 1 sec but ping > > resume only after 47 sec.... I understand with rpr-plus we get more then > 30 > > sec of ping drop, still when all links are up and adj is up, why there is > a > > ping drop? > > Spanning-Tree? > > gert > -- > USENET is *not* the non-clickable part of WWW! > // > www.muc.de/~gert/ > Gert Doering - Munich, Germany > gert at greenie.muc.de > fax: +49-89-35655025 > gert at net.informatik.tu-muenchen.de > From petelists at templin.org Wed Apr 15 10:04:30 2009 From: petelists at templin.org (Pete Templin) Date: Wed, 15 Apr 2009 09:04:30 -0500 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> Message-ID: <49E5E96E.4010508@templin.org> Jason Lixfeld wrote: > CPU doesn't seem to be running too hot: > > CPU utilization for five seconds: 6%/0%; one minute: 20%; five minutes: 19% That's probably your xRP CPU. You should check the LC CPU too. I wouldn't suspect they'll be the root of the issue, but worth checking early in your troubleshooting: core1-dlls#execute-on ? all All slots slot Command is executed on slot(s) in this chassis standby Command is executed on standby RP core1-dlls#execute-on all ? LINE Commmand to be executed on another slot core1-dlls#execute-on all sh proc c s | e 0.0.% ========= Line Card (Slot 4) ========= CPU utilization for five seconds: 0%/0%; one minute: 17%; five minutes: 17% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process ========= Line Card (Slot 6) ========= CPU utilization for five seconds: 16%/0%; one minute: 17%; five minutes: 17% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 74 76749624 21406230 3585 15.80% 15.91% 16.13% 0 TAG Stats Backgr ========= Line Card (Slot 9) ========= CPU utilization for five seconds: 10%/0%; one minute: 8%; five minutes: 8% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 87 2118639296 11728520 180642 10.55% 8.53% 8.50% 0 TAG Stats Backgr ========= Line Card (Slot 11) ========= CPU utilization for five seconds: 38%/0%; one minute: 17%; five minutes: 16% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 81 3951889484 21237909 186078 37.51% 16.39% 15.87% 0 TAG Stats Backgr ========= Line Card (Slot 12) ========= CPU utilization for five seconds: 0%/0%; one minute: 17%; five minutes: 18% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process ========= Line Card (Slot 15) ========= CPU utilization for five seconds: 28%/0%; one minute: 18%; five minutes: 17% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 73 4065388572 21247058 191339 27.60% 16.47% 15.95% 0 TAG Stats Backgr core1-dlls# pt From jason at lixfeld.ca Wed Apr 15 10:11:31 2009 From: jason at lixfeld.ca (Jason Lixfeld) Date: Wed, 15 Apr 2009 10:11:31 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <49E5E96E.4010508@templin.org> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <49E5E96E.4010508@templin.org> Message-ID: <0E61DBC7-BBE6-4B50-9D92-538F0929EB82@lixfeld.ca> On 15-Apr-09, at 10:04 AM, Pete Templin wrote: > Jason Lixfeld wrote: > >> CPU doesn't seem to be running too hot: >> CPU utilization for five seconds: 6%/0%; one minute: 20%; five >> minutes: 19% > > That's probably your xRP CPU. You should check the LC CPU too. I > wouldn't suspect they'll be the root of the issue, but worth > checking early in your troubleshooting: Indeed, that was the output from the GRP-B. LC CPUs are all low: bdr1.nyc-hudson-12008#execute-on all show proc cpu | e 0.00%__0.00%__0.00% ========= Line Card (Slot 2) ========= CPU utilization for five seconds: 0%/0%; one minute: 1%; five minutes: 1% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 6 63893752 3776360 16919 0.00% 0.25% 0.22% 0 Check heaps 14 6394916 533472 11987 0.00% 0.11% 0.11% 0 TAG Stats Backgr 28 867620 43608352 19 0.00% 0.03% 0.00% 0 Per- Second Jobs 39 6240812 523012 11932 0.23% 0.02% 0.00% 0 Per- minute Jobs 53 24959116 33061010 754 0.00% 0.07% 0.06% 0 LC COS STAT 60 146006316 776594 188012 0.00% 0.95% 0.52% 0 TBM sanity proce 74 14368544 170371373 84 0.00% 0.04% 0.04% 0 CEF LC IPC Backg ========= Line Card (Slot 5) ========= CPU utilization for five seconds: 0%/0%; one minute: 1%; five minutes: 1% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 6 63893584 3776593 16918 0.00% 0.19% 0.21% 0 Check heaps 14 6426820 533474 12047 0.00% 0.11% 0.11% 0 TAG Stats Backgr 28 2928124 34305135 85 0.00% 0.03% 0.05% 0 Per- Second Jobs 55 24968788 33048944 755 0.15% 0.08% 0.06% 0 LC COS STAT 63 80102964 184468966 434 0.07% 0.08% 0.11% 0 Queue Mgr 64 144607816 776602 186212 0.00% 0.40% 0.43% 0 TBM sanity proce 78 14642052 170365691 85 0.07% 0.01% 0.02% 0 CEF LC IPC Backg bdr1.nyc-hudson-12008# From john at johnlange.ca Wed Apr 15 10:10:11 2009 From: john at johnlange.ca (John Lange) Date: Wed, 15 Apr 2009 09:10:11 -0500 Subject: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T Message-ID: <1239804611.5644.6.camel@linux-2sym> I'm looking for some configuration examples for a Cisco 871w in a dual-wan environment. Physically the box only has one of the ports labelled for a WAN port but is it possible to configure one of the other ports as another external interface? Internally they all just show up as FastEthernet ports 0-4. One port would be DSL with PPPOE and the other would be simple DHCP (cable modem). Version: Cisco IOS Software, C870 Software (C870-ADVIPSERVICESK9-M), Version 12.4(24)T Regards, -- John Lange http://www.johnlange.ca From Steven.Glogger at swisscom.com Wed Apr 15 10:19:51 2009 From: Steven.Glogger at swisscom.com (Steven.Glogger at swisscom.com) Date: Wed, 15 Apr 2009 16:19:51 +0200 Subject: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T In-Reply-To: <1239804611.5644.6.camel@linux-2sym> References: <1239804611.5644.6.camel@linux-2sym> Message-ID: <1FC8A0BAFBBD9749BB1F06010D23C8A5869959FC@sg000035.corproot.net> did you tried to use vlans? afaik those 870series router allows up to 5 vlans to be configured. fa4 can be (ip-)addressed directly, afaik. -steven -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of John Lange Sent: Wednesday, April 15, 2009 4:10 PM To: Cisco NSP Subject: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T I'm looking for some configuration examples for a Cisco 871w in a dual-wan environment. Physically the box only has one of the ports labelled for a WAN port but is it possible to configure one of the other ports as another external interface? Internally they all just show up as FastEthernet ports 0-4. One port would be DSL with PPPOE and the other would be simple DHCP (cable modem). Version: Cisco IOS Software, C870 Software (C870-ADVIPSERVICESK9-M), Version 12.4(24)T Regards, -- John Lange http://www.johnlange.ca _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From synack at live.com Wed Apr 15 10:24:01 2009 From: synack at live.com (Darin Herteen) Date: Wed, 15 Apr 2009 09:24:01 -0500 Subject: [c-nsp] Using Cisco 3825 as Firewall Replacement Message-ID: I have a customer who's firewall recently bricked and is unusable. This device had previously served as a VPN to their LAN from the outside world, restricted access between internal VLAN's, and provided NAT for internal addresses to reach the internet. They happened to have a Cisco 3825 laying around and I've been attempting to get this router configured to duplicate the functionality of the now deceased firewall. The customer is requesting the following setup: VLAN 2 must not have internet access or access to VLAN 41 VLAN 42 must have internet access but no access to VLAN 41 VLAN 41 must have internet access and allowed access to VLAN's 2 and 42 My intent has been to use Reflexive Access Control List(s) to allow traffic originating from VLAN 41 into VLAN 2 & 42 and back. But numerous configuration attempts seem to break the NAT for VLAN 41 & 42, but according to customer internal segmentation of VLAN's appeared to work as requested but have since removed the RACL to restore connectivity. The 3825 is currently configured as follows: interface GigabitEthernet0/0.2 encapsulation dot1Q 2 ip address 192.168.15.254 255.255.240.0 no cdp enable interface GigabitEthernet0/0.41 encapsulation dot1Q 41 ip address 192.168.31.254 255.255.240.0 ip nat inside ip virtual-reassembly no cdp enable interface GigabitEthernet0/0.42 encapsulation dot1Q 42 ip address 192.168.47.254 255.255.240.0 ip nat inside ip virtual-reassembly no cdp enable interface GigabitEthernet0/1.30 encapsulation dot1Q 30 ip address x.x.x.137 255.255.255.248 ip nat outside ip virtual-reassembly no cdp enable crypto map SDM_CMAP_1 ip nat inside source route-map SDM_RMAP_1 interface GigabitEthernet0/1.30 overload route-map SDM_RMAP_1 permit 1 match ip address 100 access-list 100 remark SDM_ACL Category=2 access-list 100 deny ip 192.168.32.0 0.0.15.255 10.0.0.0 0.0.0.15 access-list 100 deny ip 192.168.16.0 0.0.15.255 10.0.0.0 0.0.0.15 access-list 100 deny ip 192.168.0.0 0.0.15.255 10.0.0.0 0.0.0.15 access-list 100 deny ip any 10.0.0.0 0.0.0.15 access-list 100 permit ip 192.168.16.0 0.0.15.255 any access-list 100 permit ip 192.168.0.0 0.0.15.255 any The 3825 is running the following IOS: (C3825-ADVIPSERVICESK9-M), Version 12.4(23) Does anybody have any recommendations or advice to offer regarding this setup and whether or not it can be accomplished. Thanks in advance, Darin Herteen _________________________________________________________________ Windows Live?: Keep your life in sync. http://windowslive.com/explore?ocid=TXT_TAGLM_WL_allup_1a_explore_042009 From luan at netcraftsmen.net Wed Apr 15 10:24:07 2009 From: luan at netcraftsmen.net (Luan Nguyen) Date: Wed, 15 Apr 2009 10:24:07 -0400 Subject: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T In-Reply-To: <1239804611.5644.6.camel@linux-2sym> References: <1239804611.5644.6.camel@linux-2sym> Message-ID: <00a001c9bdd5$d653f540$82fbdfc0$@net> You could put Fa0 into a VLAN and use that for the cable modem connection. There's no option for "no switchport" and turn it into a layer 3 interface. Regards, ---------------------------------------------------------------------------- --------- Luan Nguyen Chesapeake NetCraftsmen, LLC. [Web] http://www.netcraftsmen.net ------------------------------------------------------------------------ -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of John Lange Sent: Wednesday, April 15, 2009 10:10 AM To: Cisco NSP Subject: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T I'm looking for some configuration examples for a Cisco 871w in a dual-wan environment. Physically the box only has one of the ports labelled for a WAN port but is it possible to configure one of the other ports as another external interface? Internally they all just show up as FastEthernet ports 0-4. One port would be DSL with PPPOE and the other would be simple DHCP (cable modem). Version: Cisco IOS Software, C870 Software (C870-ADVIPSERVICESK9-M), Version 12.4(24)T Regards, -- John Lange http://www.johnlange.ca _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From jeff at ocjtech.us Wed Apr 15 10:35:01 2009 From: jeff at ocjtech.us (Jeffrey Ollie) Date: Wed, 15 Apr 2009 09:35:01 -0500 Subject: [c-nsp] Using Cisco 3825 as Firewall Replacement In-Reply-To: References: Message-ID: <935ead450904150735k21fe994fqe7e2670c2624ee45@mail.gmail.com> On Wed, Apr 15, 2009 at 9:24 AM, Darin Herteen wrote: > > I have a customer who's firewall recently bricked and is unusable. This > device had previously served as a VPN to their LAN from the outside > world, restricted access between internal VLAN's, and provided NAT for > internal addresses to reach the internet. They happened to have a Cisco > 3825 laying around and I've been attempting to get this router > configured to duplicate the functionality of the now deceased firewall. > [...] > Does anybody have any recommendations or advice to offer regarding this setup and whether or not it can be accomplished. The 3825 is a fairly nice router, but it can't handle a lot of throughput. I don't recall the exact specs (and can't find on a quick search), but I think that it can only handle <100Mb/s. That seems kinda low but I think it wasn't really designed as a packet pusher, but instead is designed as a platform for services like VoIP etc. It'll can probably be configured to do what you want, but I'm sure you'll be disappointed with the performance, especially for LAN->LAN traffic. -- Jeff Ollie From dan at beanfield.com Wed Apr 15 09:49:18 2009 From: dan at beanfield.com (Dan Armstrong) Date: Wed, 15 Apr 2009 09:49:18 -0400 Subject: [c-nsp] ME3400 uRPF In-Reply-To: <49E5AA9F.9010400@gmail.com> References: <49E5AA9F.9010400@gmail.com> Message-ID: <90376FE6-12CC-453D-A144-2CE65B912884@beanfield.com> It doesn't. I so wish it did, but no dice. On 15-Apr-09, at 5:36 AM, Adrian Minta wrote: > According to "Cisco ME 3400 data sheet" http://tinyurl.com/yphgj5 > the switch support uRPF with METROIPACCESS image, but I get the > following error: > switch(config)#interface GigabitEthernet0/2 > switch(config-if)#ip verify unicast reverse-path > % ip verify configuration not supported on interface Gi0/2 > - verification not supported by hardware > > Does anyone knows the magic needed to make uRPF work on this switch ? > > System image file is "flash:me340x-metroipaccess-mz.122-40.SE/me340x- > metroipaccess-mz.122-40.SE.bin" > cisco ME-3400G-12CS-A (PowerPC405) processor (revision C0) with > 118784K/12280K bytes of memory. > > Interface GigabitEthernet0/2 is in routed mode (no switchport). > > -- > Best regards, > Adrian Minta > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From dudepron at gmail.com Wed Apr 15 10:52:23 2009 From: dudepron at gmail.com (Aaron) Date: Wed, 15 Apr 2009 10:52:23 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <0E61DBC7-BBE6-4B50-9D92-538F0929EB82@lixfeld.ca> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <49E5E96E.4010508@templin.org> <0E61DBC7-BBE6-4B50-9D92-538F0929EB82@lixfeld.ca> Message-ID: <480dad640904150752p17fcb73foe15f1a4def68d244@mail.gmail.com> whats the traffic flow? whats the input and the output? On Wed, Apr 15, 2009 at 10:11, Jason Lixfeld wrote: > > On 15-Apr-09, at 10:04 AM, Pete Templin wrote: > > Jason Lixfeld wrote: >> >> CPU doesn't seem to be running too hot: >>> CPU utilization for five seconds: 6%/0%; one minute: 20%; five minutes: >>> 19% >>> >> >> That's probably your xRP CPU. You should check the LC CPU too. I >> wouldn't suspect they'll be the root of the issue, but worth checking early >> in your troubleshooting: >> > > Indeed, that was the output from the GRP-B. LC CPUs are all low: > > bdr1.nyc-hudson-12008#execute-on all show proc cpu | e 0.00%__0.00%__0.00% > ========= Line Card (Slot 2) ========= > > CPU utilization for five seconds: 0%/0%; one minute: 1%; five minutes: 1% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > 6 63893752 3776360 16919 0.00% 0.25% 0.22% 0 Check heaps > 14 6394916 533472 11987 0.00% 0.11% 0.11% 0 TAG Stats > Backgr > 28 867620 43608352 19 0.00% 0.03% 0.00% 0 Per-Second > Jobs > 39 6240812 523012 11932 0.23% 0.02% 0.00% 0 Per-minute > Jobs > 53 24959116 33061010 754 0.00% 0.07% 0.06% 0 LC COS STAT > 60 146006316 776594 188012 0.00% 0.95% 0.52% 0 TBM sanity > proce > 74 14368544 170371373 84 0.00% 0.04% 0.04% 0 CEF LC IPC > Backg > > ========= Line Card (Slot 5) ========= > > CPU utilization for five seconds: 0%/0%; one minute: 1%; five minutes: 1% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > 6 63893584 3776593 16918 0.00% 0.19% 0.21% 0 Check heaps > 14 6426820 533474 12047 0.00% 0.11% 0.11% 0 TAG Stats > Backgr > 28 2928124 34305135 85 0.00% 0.03% 0.05% 0 Per-Second > Jobs > 55 24968788 33048944 755 0.15% 0.08% 0.06% 0 LC COS STAT > 63 80102964 184468966 434 0.07% 0.08% 0.11% 0 Queue Mgr > 64 144607816 776602 186212 0.00% 0.40% 0.43% 0 TBM sanity > proce > 78 14642052 170365691 85 0.07% 0.01% 0.02% 0 CEF LC IPC > Backg > > bdr1.nyc-hudson-12008# > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From jason at lixfeld.ca Wed Apr 15 10:58:01 2009 From: jason at lixfeld.ca (Jason Lixfeld) Date: Wed, 15 Apr 2009 10:58:01 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <480dad640904150752p17fcb73foe15f1a4def68d244@mail.gmail.com> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <49E5E96E.4010508@templin.org> <0E61DBC7-BBE6-4B50-9D92-538F0929EB82@lixfeld.ca> <480dad640904150752p17fcb73foe15f1a4def68d244@mail.gmail.com> Message-ID: On 15-Apr-09, at 10:52 AM, Aaron wrote: > whats the traffic flow? whats the input and the output? bdr1.nyc-hudson-12008#show int a2/0 load Interface bits/sec pack/sec -------------------- ------------ ---------- AT2/0 Tx 48464000 14099 Rx 104808000 18012 bdr1.nyc-hudson-12008#show int a2/1 load Interface bits/sec pack/sec -------------------- ------------ ---------- AT2/1 Tx 57581000 13032 Rx 116319000 14466 bdr1.nyc-hudson-12008#show int g5/0 load Interface bits/sec pack/sec -------------------- ------------ ---------- Gi5/0 Tx 56851000 8981 Rx 35082000 7833 bdr1.nyc-hudson-12008#show int g5/1 load Interface bits/sec pack/sec -------------------- ------------ ---------- Gi5/1 Tx 166072000 23424 Rx 70951000 19116 bdr1.nyc-hudson-12008# So: Total Throughput: 656128000 Total PPS: 118963 Average Size (B): 689.4 From john at johnlange.ca Wed Apr 15 11:02:00 2009 From: john at johnlange.ca (John Lange) Date: Wed, 15 Apr 2009 10:02:00 -0500 Subject: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T In-Reply-To: <00a001c9bdd5$d653f540$82fbdfc0$@net> References: <1239804611.5644.6.camel@linux-2sym> <00a001c9bdd5$d653f540$82fbdfc0$@net> Message-ID: <1239807720.5644.10.camel@linux-2sym> On Wed, 2009-04-15 at 10:24 -0400, Luan Nguyen wrote: > You could put Fa0 into a VLAN and use that for the cable modem > connection. Ok, that's what I figured would work. Any suggestions for how to make the dual-wan work in a type of fail-over setup? All of my searching turns up plenty of hits for hardware failover (dual-PIX setups) but I can't find any example configs for dual-wan on a single device. I must be using the wrong search terms? I'm fairly new to cisco and am not certified so any hints as to which IOS commands/configs can be used to detect fail-over would be great. Thanks, -- John Lange http://www.johnlange.ca From mtinka at globaltransit.net Wed Apr 15 06:07:56 2009 From: mtinka at globaltransit.net (Mark Tinka) Date: Wed, 15 Apr 2009 18:07:56 +0800 Subject: [c-nsp] 12.2(33)SRC*/SRD* Watchdog NMI Timeout Crash/BFD Issue Message-ID: <200904151808.07070.mtinka@globaltransit.net> Hi all. So we've been going back and forth on this issue with TAC, and I recall posting a few comments about it online several months back. Here's an update for the archives and anyone that's interested: So TAC and I initially worked through bug ID CSCek75694 (Crash in Pseudo Preemption handler when BFD is configured) which linked over to bug ID CSCsq32269 (C7200 crash due to watchdog nmi). TAC came back to say this issue was fixed in 12.2(33)SRC3, as well as other trains. However, this was not to be... So we logged another case with TAC after SRC3 crashed on us the exact same way. We seem to have made some progress - bug ID CSCsz05181 (stack corruption crash with BFD configured) has just been filed. To summarize, when BFD is enabled and some commands are run on a regular basis, e.g., show bootvar" and "show c7200", the router crashes. It is not guaranteed that the router will crash when these circumstances all come together, but the more often the commands are run, the greater the chance of the router crashing. In our case, the regular execution of these commands is due to RANCID, hence the eventual cause of the crash. The current workaround is to disable BFD (for us, RANCID takes higher priority). But that's not all - we were wondering why, while the SRC* code for the NPE-G2 and 7201 are vulnerable to this bug, they have never once crashed, with BFD enabled and RANCID querying these platforms. Well, it turns out this issue only affects MIPS-based processors. While the issue isn't exactly BFD-specific, currently, BFD is the only feature known to trigger it. The reason the NPE-G2 and 7201 are not affected is because these platforms do not use MIPS processors. Still no news on which release will carry the (final) fix, but I'm hoping SRC5 at least :-). SRD4 is also affected, for anyone that's running it. Suggest not to run BFD on this code, for the time being (particularly on the NPE-G1). Cheers, Mark. -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 835 bytes Desc: This is a digitally signed message part. URL: From lowen at pari.edu Wed Apr 15 11:34:34 2009 From: lowen at pari.edu (Lamar Owen) Date: Wed, 15 Apr 2009 11:34:34 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> Message-ID: <200904151134.34595.lowen@pari.edu> On Tuesday 14 April 2009 18:22:03 Jason Lixfeld wrote: > For the life of us, we can't seem to get any more than 60Mbps > sustained across the ATM testing with iperf, so we're just trying to > figure out if the GSR just can't push any more than what it's doing or > if there's something else afoot. [snip] > We've done our due diligence to ensure the bits of the network between > the test machine and the ATM can support 100Mbps, so we're fairly Hmm, 60mb/s using a 100mb/s connected box sounds about right. To really strain an OC12 you need a gigabit connected tester that can really do a gigabit of traffic. Or multiple test PC's. I have a 12012 here in production, and have some of the kit necessary to test point to point ATM connections (including a Catalyst 8540MSR with OC12, ARM, and gigabit cards), and have a 4xOC12/ATM/MM, but it will be a few days before I could have the time to set up a test to see if the 12012 is limited. The LC engines on the ATM card and the 3GE card will be the limiting factor, and those cards are rated for line rate on four simultaneous OC12's or line rate on two GigE (can't do full line rate on all three with a 2.5Gb/s fabric connection). The GRP CPU is not involved in the data plane on a GSR; the LC engine CPU's/ASICs do dCEF and talk directly over the fabric. Unless you have serious fabric issues preventing full bandwidth, in which case you have bigger problems. So I'd first check to see if your iperf test box can really generate sufficient traffic. What sort of ATM switch or router is on the other end of those multimode short reach OC12's? What sort of router is terminating them? How are your PVC's set up? From mtinka at globaltransit.net Wed Apr 15 11:46:01 2009 From: mtinka at globaltransit.net (Mark Tinka) Date: Wed, 15 Apr 2009 23:46:01 +0800 Subject: [c-nsp] SRC on 7200 In-Reply-To: References: Message-ID: <200904152346.30087.mtinka@globaltransit.net> On Tuesday 14 April 2009 11:48:36 pm MKS wrote: > What's your experience with SRC or SRC3 on 7200, is it > stable as a MPLS PE? A number of bugs - the worst of which, for us, is a system crash when running BFD on an NPE-G1. NPE-G2's and 7201's are unaffected. Issue as yet unfixed (please look at an e-mail I just sent on this). Enabling Flexible Netflow on an interface while in production also crashes the box, but this is fixed in SRC3. That said, consider SRC3 as a minimum. Lots of interesting features and quite comprehensive, but still a relatively "young" code base. Mark. -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 835 bytes Desc: This is a digitally signed message part. URL: From luan at netcraftsmen.net Wed Apr 15 11:56:58 2009 From: luan at netcraftsmen.net (Luan Nguyen) Date: Wed, 15 Apr 2009 11:56:58 -0400 Subject: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T In-Reply-To: <1239807720.5644.10.camel@linux-2sym> References: <1239804611.5644.6.camel@linux-2sym> <00a001c9bdd5$d653f540$82fbdfc0$@net> <1239807720.5644.10.camel@linux-2sym> Message-ID: <00f501c9bde2$cefee680$6cfcb380$@net> Basically you should look for reliable static routing using object tracking http://www.cisco.com/en/US/docs/ios/12_3/12_3x/12_3xe/feature/guide/dbackupx .html An ICMP echo probe is created to monitor the GW of the primary interface. The probe sends an ICMP echo every 5 seconds, and runs indefinitely: ip sla 2147483647 icmp-echo x.x.x.x(GW) source-ip x.x.x.x1 [PRIMARY ADDRESS] timeout 1000 frequency 5 ip sla schedule 2147483647 life forever start-time now An object tracking rule is created to track the echo probe with a delay of 20 seconds - in case of just link flapping and not a real failure: ! track 300 rtr 2147483647 reachability delay down 20 ! A route map is created to send the ICMP echo packets out the primary WAN interface only when it is up but sends the packets to a null0 interface when the primary interface fails. ! ip access-list extended object-track permit icmp host x.x.x.x1 host x.x.x.x ! route-map OT permit 300 match ip address object-track set ip next-hop x.x.x.x set interface Null0 ! A default route is set out the primary interface. Another default route is set out the secondary interface but at a higher cost. ip route 0.0.0.0 0.0.0.0 x.x.x.x track 300 ip route 0.0.0.0 0.0.0.0 y.y.y.y 250 ! HTH. Regards, ---------------------------------------------------------------------------- --------- Luan Nguyen Chesapeake NetCraftsmen, LLC. [Web] http://www.netcraftsmen.net ------------------------------------------------------------------------ -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of John Lange Sent: Wednesday, April 15, 2009 11:02 AM To: 'Cisco NSP' Subject: Re: [c-nsp] Dual WAN on Cisco IOS 12.4(24)T On Wed, 2009-04-15 at 10:24 -0400, Luan Nguyen wrote: > You could put Fa0 into a VLAN and use that for the cable modem > connection. Ok, that's what I figured would work. Any suggestions for how to make the dual-wan work in a type of fail-over setup? All of my searching turns up plenty of hits for hardware failover (dual-PIX setups) but I can't find any example configs for dual-wan on a single device. I must be using the wrong search terms? I'm fairly new to cisco and am not certified so any hints as to which IOS commands/configs can be used to detect fail-over would be great. Thanks, -- John Lange http://www.johnlange.ca _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From cgriffin at ufl.edu Wed Apr 15 12:02:42 2009 From: cgriffin at ufl.edu (Chris Griffin) Date: Wed, 15 Apr 2009 12:02:42 -0400 Subject: [c-nsp] SRC on 7200 In-Reply-To: <200904152346.30087.mtinka@globaltransit.net> References: <200904152346.30087.mtinka@globaltransit.net> Message-ID: <49E60522.6040801@ufl.edu> Also watch out for CSCsy58115. BGP memory leak if you have any idle/active peers. We are still going through the full scope of this bug and how to get around it. Thanks Chris Mark Tinka wrote: > On Tuesday 14 April 2009 11:48:36 pm MKS wrote: > >> What's your experience with SRC or SRC3 on 7200, is it >> stable as a MPLS PE? > > A number of bugs - the worst of which, for us, is a system > crash when running BFD on an NPE-G1. NPE-G2's and 7201's are > unaffected. Issue as yet unfixed (please look at an e-mail I > just sent on this). > > Enabling Flexible Netflow on an interface while in > production also crashes the box, but this is fixed in SRC3. > > That said, consider SRC3 as a minimum. Lots of interesting > features and quite comprehensive, but still a relatively > "young" code base. > > Mark. > > > ------------------------------------------------------------------------ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ -- Chris Griffin cgriffin at ufl.edu Sr. Network Engineer - CCNP Phone: (352) 273-1051 CNS - Network Services Fax: (352) 392-9440 University of Florida/FLR Gainesville, FL 32611 From jason at lixfeld.ca Wed Apr 15 12:11:10 2009 From: jason at lixfeld.ca (Jason Lixfeld) Date: Wed, 15 Apr 2009 12:11:10 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <200904151134.34595.lowen@pari.edu> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <200904151134.34595.lowen@pari.edu> Message-ID: <4E072EE9-04F5-4C83-BBCA-B8584E2AB44A@lixfeld.ca> On 15-Apr-09, at 11:34 AM, Lamar Owen wrote: > On Tuesday 14 April 2009 18:22:03 Jason Lixfeld wrote: >> For the life of us, we can't seem to get any more than 60Mbps >> sustained across the ATM testing with iperf, so we're just trying to >> figure out if the GSR just can't push any more than what it's doing >> or >> if there's something else afoot. > [snip] >> We've done our due diligence to ensure the bits of the network >> between >> the test machine and the ATM can support 100Mbps, so we're fairly > > Hmm, 60mb/s using a 100mb/s connected box sounds about right. To > really > strain an OC12 you need a gigabit connected tester that can really > do a > gigabit of traffic. Or multiple test PC's. In this case, I can iperf 97Mbps between two machines connected together at 100Mb. > I have a 12012 here in production, and have some of the kit > necessary to test > point to point ATM connections (including a Catalyst 8540MSR with > OC12, ARM, > and gigabit cards), and have a 4xOC12/ATM/MM, but it will be a few > days before > I could have the time to set up a test to see if the 12012 is limited. We've been wrestling with this for weeks now, but haven't had the means to be able to compare our results to anyone else to see whether or not we're an anomaly, so what's another day or four :) > The LC > engines on the ATM card and the 3GE card will be the limiting > factor, and > those cards are rated for line rate on four simultaneous OC12's or > line rate > on two GigE (can't do full line rate on all three with a 2.5Gb/s > fabric > connection). The load is really low, so I'd be very surprised if it was an LC limitation, but what do I know: bdr1.nyc-hudson-12008#show int a2/0 load Interface bits/sec pack/sec -------------------- ------------ ---------- AT2/0 Tx 48464000 14099 Rx 104808000 18012 bdr1.nyc-hudson-12008#show int a2/1 load Interface bits/sec pack/sec -------------------- ------------ ---------- AT2/1 Tx 57581000 13032 Rx 116319000 14466 bdr1.nyc-hudson-12008#show int g5/0 load Interface bits/sec pack/sec -------------------- ------------ ---------- Gi5/0 Tx 56851000 8981 Rx 35082000 7833 bdr1.nyc-hudson-12008#show int g5/1 load Interface bits/sec pack/sec -------------------- ------------ ---------- Gi5/1 Tx 166072000 23424 Rx 70951000 19116 bdr1.nyc-hudson-12008# So: Total Throughput: 656128000 Total PPS: 118963 Average Size (B): 689.4 > The GRP CPU is not involved in the data plane on a GSR; the LC > engine CPU's/ASICs do dCEF and talk directly over the fabric. > Unless you have > serious fabric issues preventing full bandwidth, in which case you > have bigger > problems. Again, the bandwidth going over the entire box is like 650Mbps spread more or less evenly across the two LCs. > So I'd first check to see if your iperf test box can really generate > sufficient > traffic. Here's one of the tests we've done, and we were able to get ~97Mbps here: Macbook Pro -> Linksys 100Mb -> 1811 -> 7609 -> 10GE -> 7609 -> 3550 - > PC 100Mb NIC. > What sort of ATM switch or router is on the other end of those > multimode short > reach OC12's? What sort of router is terminating them? How are > your PVC's > set up? A2/0 and A2/1 on the GSR connect to two ports on a Fore ASX200BX. The ASX200BX connects into the provider's SONET network. On the Z side, we're taking the OC12 into a Fore ASX1000. ATM2/0.100 (vpi/vci 0/100) on side A ultimately terminates on an OSM-2OC12-ATM-MM in 7609-A on side Z. ATM2/1.110 (vpi/vci 0/110) on side A ultimately terminates on an OSM-2OC12-ATM-MM in 7609-B on side Z. 7609-A and 7609-B on the Z side are connected by an OC12 ATM on own own dark fiber. Fores at the A and Z side are both clean as a whistle. No error seconds anywhere. > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From steve.mcnamara at gmail.com Wed Apr 15 12:14:15 2009 From: steve.mcnamara at gmail.com (Steve McNamara) Date: Wed, 15 Apr 2009 17:14:15 +0100 Subject: [c-nsp] Using Cisco 3825 as Firewall Replacement In-Reply-To: <935ead450904150735k21fe994fqe7e2670c2624ee45@mail.gmail.com> References: <935ead450904150735k21fe994fqe7e2670c2624ee45@mail.gmail.com> Message-ID: <494a4f80904150914jd9b0e06s4b9422d147d34c4a@mail.gmail.com> Darin, Sounds like the IOS zone based firewall might be applicable to what you are after - there is support for NAT. http://www.cisco.com/en/US/products/ps6441/products_feature_guide09186a008060f6dd.html Note: I haven't configured this before so YMMV :-) Steve On Wed, Apr 15, 2009 at 15:35, Jeffrey Ollie wrote: > On Wed, Apr 15, 2009 at 9:24 AM, Darin Herteen wrote: >> >> I have a customer who's firewall recently bricked and is unusable. This >> device had previously served as a VPN to their LAN from the outside >> world, restricted access between internal VLAN's, and provided NAT for >> internal addresses to reach the internet. They happened to have a Cisco >> 3825 laying around and I've been attempting to get this router >> configured to duplicate the functionality of the now deceased firewall. >> [...] >> Does anybody have any recommendations or advice to offer regarding this setup and whether or not it can be accomplished. > > The 3825 is a fairly nice router, but it can't handle a lot of > throughput. ?I don't recall the exact specs (and can't find on a quick > search), but I think that it can only handle <100Mb/s. ?That seems > kinda low but I think it wasn't really designed as a packet pusher, > but instead is designed as a platform for services like VoIP etc. > It'll can probably be configured to do what you want, but I'm sure > you'll be disappointed with the performance, especially for LAN->LAN > traffic. > > -- > Jeff Ollie > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From lowen at pari.edu Wed Apr 15 13:11:25 2009 From: lowen at pari.edu (Lamar Owen) Date: Wed, 15 Apr 2009 13:11:25 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <4E072EE9-04F5-4C83-BBCA-B8584E2AB44A@lixfeld.ca> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> Message-ID: <200904151311.26201.lowen@pari.edu> On Wednesday 15 April 2009 12:11:10 Jason Lixfeld wrote: > Again, the bandwidth going over the entire box is like 650Mbps spread > more or less evenly across the two LCs. Just a quick comment on this statement, and then in a few days I'll see if I can't set up a back-to-back test with the 12012 here. I don't have any Fore switches, but I do have the Catalyst 8540MSR, and I have a few 3Com Corebuilder 7000HD's with OC12 linecards, so I can set up a lab easily enough. I even have some of the ForeRunner HE622 OC12 ATM cards to pop in a server to generate traffic. I actually need to be testing the OC12 stuff anyway, since I have some multimode fiber runs that are too long for GigE but short enough to do OC12 multimode (550m is limit for 1000Base-LX on multimode 62.5 um even with mode- conditioning cables, and 800m is the limit for OC12 over the same fiber, and these links are in the mid 700's), so this is something I actually NEED to do at some point in time to upgrade those links from 100Base-FX; that's actually where the 8540MSR is getting deployed, to bridge/route some GigE over four OC12 links. But, back to the 12012, in full-bandwidth mode, the fabric is theoretically capable of giving 2.4Gb/s to each linecard. In quarter-bandwidth mode, you get 622Mb/s to each linecard. What does 'show controllers fia' tell you? Only engine 0 cards are supposed to run in quarter-bandwidth mode, but, given all the other 'undocumented' things about the GSR, who knows? (undocumented things like 'show fabric' for instance). I'm not even sure the 12008 can be set up in quarter bandwidth mode; the 12012 can, though. Also, last question, what IOS are you running? If you're not on 12.0(32)S12, you can be, even without a service contract, by filing a free upgrade request with TAC and reference either the September 24, 2008 security advisories or the latest March 25th advisory bundle. From jdevane at switchnap.com Wed Apr 15 12:44:27 2009 From: jdevane at switchnap.com (Jim Devane) Date: Wed, 15 Apr 2009 09:44:27 -0700 Subject: [c-nsp] VTY Lines In-Reply-To: Message-ID: <10188D798B596E4585DEAEAC62596D234237DF87@WATERFORD.switchnet.nv> Well, restarting the router will do it, when that is not as feasible you can try: Sh tcp br to get the TCB address, then clear that out with cle ip tcp tcb XXXXX Router# sh tcp br TCB Local Address Foreign Address (state) 5AEE7990 2.2.2.2.179 2.2.2.3.17492 ESTAB 58F2E668 2.2.2.2.22 lifebook.11004 ESTAB Router# cle ip tcp tcb 58F2E668 Take care to enter the right address, otherwise you may get some BGP messages for good measure. = ) HTH, Jim -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Stanly Johns Sent: Wednesday, April 15, 2009 3:07 AM To: cisco-nsp at puck.nether.net Subject: [c-nsp] VTY Lines Hi there, even after clearing the vty lines they were still there. I was unable to telnet to the router. I had to restart the router to clear all the lines. any clue what could be the reason ? thanks. Perimeter#sh users Line User Host(s) Idle Location * 0 con 0 idle 00:00:00 322 vty 0 idle 5w1d 190.42.12.218 323 vty 1 idle 5w0d client-201.230.86.15.speedy.net.pe 324 vty 2 idle 3w5d 151.56.21.165 325 vty 3 idle 2w4d client-190.40.212.198.speedy.net.pe 326 vty 4 idle 1w5d 84.36.28.19 Interface User Mode Idle Peer Address Perimeter# Perimeter#clear line vty 2 [confirm] [OK] Perimeter# Perimeter#sh users Line User Host(s) Idle Location * 0 con 0 idle 00:00:00 322 vty 0 idle 5w1d 190.42.12.218 323 vty 1 idle 5w0d client-201.230.86.15.speedy.net.pe 324 vty 2 idle 3w5d 151.56.21.165 325 vty 3 idle 2w4d client-190.40.212.198.speedy.net.pe 326 vty 4 idle 1w5d 84.36.28.19 Interface User Mode Idle Peer Address line con 0 stopbits 1 line aux 0 stopbits 1 line vty 0 4 password 7 login ! scheduler allocate 20000 1000 ! end Perimeter# _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From peter at rathlev.dk Wed Apr 15 13:30:42 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Wed, 15 Apr 2009 19:30:42 +0200 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <4E072EE9-04F5-4C83-BBCA-B8584E2AB44A@lixfeld.ca> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <200904151134.34595.lowen@pari.edu> <4E072EE9-04F5-4C83-BBCA-B8584E2AB44A@lixfeld.ca> Message-ID: <1239816642.14908.6.camel@localhost.localdomain> On Wed, 2009-04-15 at 12:11 -0400, Jason Lixfeld wrote: > In this case, I can iperf 97Mbps between two machines connected > together at 100Mb. > Here's one of the tests we've done, and we were able to get ~97Mbps > here: > > Macbook Pro -> Linksys 100Mb -> 1811 -> 7609 -> 10GE -> 7609 -> 3550 - > > PC 100Mb NIC. This may or may not be relevant, but depending on how much extra latency the 12008 introduces you might still have a client side limitation doing TCP. Reasonable TCP window sizes and effective sender side congestion control are needed. How much latency end-to-end in the setup with/without the 12008? Making IPerf use a defined load in a UDP stream (e.g. 100 Mbps) and then measuring the loss would overcome this limitation of course. Regards, Peter From jason at lixfeld.ca Wed Apr 15 13:31:24 2009 From: jason at lixfeld.ca (Jason Lixfeld) Date: Wed, 15 Apr 2009 13:31:24 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <200904151311.26201.lowen@pari.edu> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <200904151311.26201.lowen@pari.edu> Message-ID: <009401DE-1293-42F0-A8CB-17BA5B658209@lixfeld.ca> On 15-Apr-09, at 1:11 PM, Lamar Owen wrote: > But, back to the 12012, in full-bandwidth mode, the fabric is > theoretically > capable of giving 2.4Gb/s to each linecard. In quarter-bandwidth > mode, you > get 622Mb/s to each linecard. What does 'show controllers fia' tell > you? Only > engine 0 cards are supposed to run in quarter-bandwidth mode, but, > given all > the other 'undocumented' things about the GSR, who knows? > (undocumented > things like 'show fabric' for instance). I'm not even sure the > 12008 can be > set up in quarter bandwidth mode; the 12012 can, though. show cont fia tells me that 0s are a good thing ;) bdr1.nyc-hudson-12008#show controllers fia Fabric configuration: 2.4Gbps bandwidth, redundant fabric Master Scheduler: Slot 17 Backup Scheduler: Slot 16 Fab epoch no 0 Halt count 0 From Fabric FIA Errors ----------------------- redund fifo parity 0 redund overflow 0 cell drops 0 crc32 lkup parity 0 cell parity 0 crc32 0 Switch cards present 0x001F Slots 16 17 18 19 20 Switch cards monitored 0x001F Slots 16 17 18 19 20 Slot: 16 17 18 19 20 Name: csc0 csc1 sfc0 sfc1 sfc2 -------- -------- -------- -------- -------- los 0 0 0 0 0 state Off Off Off Off Off crc16 0 0 0 0 0 To Fabric FIA Errors ----------------------- sca not pres 0 req error 0 uni fifo overflow 0 grant parity 0 multi req 0 uni fifo undrflow 0 cntrl parity 0 uni req 0 crc32 lkup parity 0 multi fifo 0 empty dst req 0 handshake error 0 cell parity 0 bdr1.nyc-hudson-12008# > Also, last question, what IOS are you running? If you're not on > 12.0(32)S12, > you can be, even without a service contract, by filing a free > upgrade request > with TAC and reference either the September 24, 2008 security > advisories or > the latest March 25th advisory bundle. We're on S8, not S12. Anything sticking out about the S8 vs. S12, or just trying to make sure the yard is clean? From jason at lixfeld.ca Wed Apr 15 13:42:08 2009 From: jason at lixfeld.ca (Jason Lixfeld) Date: Wed, 15 Apr 2009 13:42:08 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <1239816642.14908.6.camel@localhost.localdomain> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <200904151134.34595.lowen@pari.edu> <4E072EE9-04F5-4C83-BBCA-B8584E2AB44A@lixfeld.ca> <1239816642.14908.6.camel@localhost.localdomain> Message-ID: <786E3613-1B62-4ACE-AAEC-FC69889E07D2@lixfeld.ca> On 15-Apr-09, at 1:30 PM, Peter Rathlev wrote: > This may or may not be relevant, but depending on how much extra > latency > the 12008 introduces you might still have a client side limitation > doing > TCP. Reasonable TCP window sizes and effective sender side congestion > control are needed. Good advice. Didn't consider that. > How much latency end-to-end in the setup with/without the 12008? 12ms (Toronto to New York and back) with the 12008. Haven't hair pinned a port on the New York Fore yet, so can't determine latency without the 12008. > Making IPerf use a defined load in a UDP stream (e.g. 100 Mbps) and > then > measuring the loss would overcome this limitation of course. I'd happily test that, however we don't have a machine on-site in New York, unless you (or anyone else, for that matter ;)) happen to have a box hanging off NYIIX that I could dump traffic to over our NYIIX link. > Regards, > Peter > > > From DLasher at newedgenetworks.com Wed Apr 15 13:12:32 2009 From: DLasher at newedgenetworks.com (Lasher, Donn) Date: Wed, 15 Apr 2009 10:12:32 -0700 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <200904151134.34595.lowen@pari.edu> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <200904151134.34595.lowen@pari.edu> Message-ID: -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Lamar Owen Sent: Wednesday, April 15, 2009 8:35 AM To: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? >The GRP CPU is not involved in the data plane on a GSR; the LC >engine CPU's/ASICs do dCEF and talk directly over the fabric. Unless you have >serious fabric issues preventing full bandwidth, in which case you have bigger >problems. Depending on the protocol / encaps / engine age / packet-size, you may see very high CPU loads preventing line rates on certain cards. Try, as an example, (Engine0 GIG-E card + MPLS Labeling + QoS + ACL's). You'll see much higher CPU doing that, than say, the same thing on an Engine3 GIG-E card. From lowen at pari.edu Wed Apr 15 14:58:38 2009 From: lowen at pari.edu (Lamar Owen) Date: Wed, 15 Apr 2009 14:58:38 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <786E3613-1B62-4ACE-AAEC-FC69889E07D2@lixfeld.ca> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> Message-ID: <200904151458.39229.lowen@pari.edu> On Wednesday 15 April 2009 13:42:08 Jason Lixfeld wrote: > On 15-Apr-09, at 1:30 PM, Peter Rathlev wrote: > > How much latency end-to-end in the setup with/without the 12008? > 12ms (Toronto to New York and back) with the 12008. Haven't hair > pinned a port on the New York Fore yet, so can't determine latency > without the 12008. Incidentally, the 'show fabric' undocumented command shows internal latencies across the fabric. The ATM SAR tax may be hitting you, too. From jason at lixfeld.ca Wed Apr 15 18:35:40 2009 From: jason at lixfeld.ca (Jason Lixfeld) Date: Wed, 15 Apr 2009 18:35:40 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <200904151458.39229.lowen@pari.edu> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <200904151458.39229.lowen@pari.edu> Message-ID: <87C6535E-34F1-451D-BD4F-B1E2CB5340AF@lixfeld.ca> On 15-Apr-09, at 2:58 PM, Lamar Owen wrote: > Incidentally, the 'show fabric' undocumented command shows internal > latencies > across the fabric. Highest latency on the fabric is 84ms, over two months ago. > The ATM SAR tax may be hitting you, too. Not being an ATM guru, I hope someone will clue-bat me if I get too far gone with my calculations below... An ATM cell payload is 48 bytes long. On top of each cell, there's a 5 byte ATM header. If my average packet size is 690 bytes, one packet would be stuffed into 15 cells. Each of those 15 cells would have an additional 5 bytes of overhead for the header. So, 5 bytes header for 15 cells = 75 bytes per 1 690 byte packet = 765 bytes/6120 bits. At the time the sample was taken, I was pulling in 27131pps over my two GSR ATM interfaces and pushing 32478pps over the same two interfaces. If my cell tax calculations are right, that would equal 166041720bps in and 198765360bps out across the GSR, but equally importantly, that would equal the same amount being put over the OC12 to Toronto. Correct me if I'm wrong, but based on this estimation, ATM cell tax wouldn't be an issue, would it? From David at Hughes.com.au Wed Apr 15 20:00:08 2009 From: David at Hughes.com.au (David Hughes) Date: Thu, 16 Apr 2009 10:00:08 +1000 Subject: [c-nsp] Nexus 5K FCoE to FC breakout Message-ID: Hi Seeing as this is all bleeding edge, I'd be very interested in any first hand experiences with breaking out FCoE to traditional FC via an N5K. Is it working OK? Are you running it as a switch or in NPV mode? How's the interop with your FC fabric (and who's gear are you using for FC switching). Whos CNA's are downstream of the N5K? Any thoughts, observations etc you can share about this brave new world would be greatly appreciated? Thanks David ... From jcdarby at usgs.gov Wed Apr 15 20:21:07 2009 From: jcdarby at usgs.gov (Justin C Darby) Date: Wed, 15 Apr 2009 20:21:07 -0400 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: References: Message-ID: Hello David, This is entirely my personal opinion and I'm sure some folks in the Nexus BU at Cisco would hit me for saying this given the chance. Unless you are using legacy FC devices, hold off on the 5K for this. The reason I say this is because a new class of storage devices and HBA's that use 10GbE native are hitting the market. Some vendors are mostly there, others not at all. I beleive QLogic has HBA's available for this, and I know the major storage vendors are working on bringing FCoE storage devices to market. You've also got alternatives to FCoE that can use 10GbE for native transport now (iSCSI/ATA-over-Ethernet/etc). The operating cost (relative to performance) of using 10GbE to do FCoE native are considerably more advantageous than just consolidating 4xFC onto 10GbE. However, if you've already got a bunch of FC gear and you want to consolidate the transport, there are people using 5K's for this (though I am not one of them), and given my experience with the 7K i am sure it'll work out as designed. Have fun, Justin P.S. Opinions here are my own, not the views of the U.S. Government, etc. -----cisco-nsp-bounces at puck.nether.net wrote: ----- To: "Cisco NSP ((E-mail))'" From: David Hughes Sent by: cisco-nsp-bounces at puck.nether.net Date: 04/15/2009 07:07PM Subject: [c-nsp] Nexus 5K FCoE to FC breakout Hi Seeing as this is all bleeding edge, I'd be very interested in any first hand experiences with breaking out FCoE to traditional FC via an N5K. Is it working OK? Are you running it as a switch or in NPV mode? How's the interop with your FC fabric (and who's gear are you using for FC switching). Whos CNA's are downstream of the N5K? Any thoughts, observations etc you can share about this brave new world would be greatly appreciated? Thanks David ... _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From ibrahim.abozaid at gmail.com Wed Apr 15 22:22:38 2009 From: ibrahim.abozaid at gmail.com (Ibrahim Abo Zaid) Date: Thu, 16 Apr 2009 04:22:38 +0200 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <87C6535E-34F1-451D-BD4F-B1E2CB5340AF@lixfeld.ca> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> <200904151458.39229.lowen@pari.edu> <87C6535E-34F1-451D-BD4F-B1E2CB5340AF@lixfeld.ca> Message-ID: Dear Jason I think ATM cell tax will be about 13% on average based on the following ATM cell tax is composed of 2 parts 1- ATM over-header (5 bytes for each 53 byte cell and that is a fixed percnt ) 2- cell padding which depends packet distribution so ATM overhead will be 5/53 = ~ 4% and cell padding can be calculated as IP Packet size is 690 bytes will be padded with 30 bytes and transported as 720 bytes (15 cell x 48 payload size) so padding percentage will be ~ 9% (30 / 720 ) so overall ATM cell tax will be 13% based on the given packet size and for sure it will vary for other packet size values best regards --Ibrahim On Thu, Apr 16, 2009 at 12:35 AM, Jason Lixfeld wrote: > > On 15-Apr-09, at 2:58 PM, Lamar Owen wrote: > > Incidentally, the 'show fabric' undocumented command shows internal >> latencies >> across the fabric. >> > > Highest latency on the fabric is 84ms, over two months ago. > > The ATM SAR tax may be hitting you, too. >> > > Not being an ATM guru, I hope someone will clue-bat me if I get too far > gone with my calculations below... > > An ATM cell payload is 48 bytes long. On top of each cell, there's a 5 > byte ATM header. > > If my average packet size is 690 bytes, one packet would be stuffed into 15 > cells. Each of those 15 cells would have an additional 5 bytes of overhead > for the header. > > So, 5 bytes header for 15 cells = 75 bytes per 1 690 byte packet = 765 > bytes/6120 bits. > > At the time the sample was taken, I was pulling in 27131pps over my two GSR > ATM interfaces and pushing 32478pps over the same two interfaces. If my > cell tax calculations are right, that would equal 166041720bps in and > 198765360bps out across the GSR, but equally importantly, that would equal > the same amount being put over the OC12 to Toronto. > > Correct me if I'm wrong, but based on this estimation, ATM cell tax > wouldn't be an issue, would it? > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From yevgeniy.voloshin at gmail.com Wed Apr 15 23:53:59 2009 From: yevgeniy.voloshin at gmail.com (Yevgeniy Voloshin) Date: Thu, 16 Apr 2009 07:53:59 +0400 Subject: [c-nsp] VTY Lines In-Reply-To: References: Message-ID: <49E6ABD7.4030402@gmail.com> Hi, I have the same problem on ME-C3750-24TE with Cisco IOS Software -> C3750ME Software (C3750ME-I5-M), Version 12.2(44)SE, RELEASE SOFTWARE (fc1) In 'sh tcp brief | i \.2[23]' output nothing about telnet ports. But all vty lines busy: Line User Host(s) Idle Location * 0 con 0 idle 00:00:00 1 vty 0 idle 1y11w xxx.xxx.xxx.xxx 2 vty 1 idle 1y11w xxx.xxx.xxx.xxx 3 vty 2 idle 1y11w xxx.xxx.xxx.xxx 4 vty 3 idle 1y11w xxx.xxx.xxx.xxx 5 vty 4 idle 1y11w xxx.xxx.xxx.xxx 6 vty 5 idle 1y11w xxx.xxx.xxx.xxx 7 vty 6 idle 1y11w xxx.xxx.xxx.xxx 8 vty 7 idle 41w5d xxx.xxx.xxx.xxx 9 vty 8 idle 34w5d xxx.xxx.xxx.xxx 10 vty 9 idle 34w5d xxx.xxx.xxx.xxx 11 vty 10 idle 31w0d xxx.xxx.xxx.xxx 12 vty 11 idle 17w2d xxx.xxx.xxx.xxx 13 vty 12 idle 16w6d xxx.xxx.xxx.xxx 14 vty 13 idle 16w6d xxx.xxx.xxx.xxx 15 vty 14 idle 2w2d xxx.xxx.xxx.xxx 16 vty 15 idle 2w2d xxx.xxx.xxx.xxx So right now I am waiting MW to reload box with IOS upgrade. --- Yev. From bdikici at gmail.com Thu Apr 16 00:11:56 2009 From: bdikici at gmail.com (Burak Dikici) Date: Thu, 16 Apr 2009 07:11:56 +0300 Subject: [c-nsp] Classify geographical traffic with BGP In-Reply-To: <3e4b8fe10904150617v39f7198fsde71acb4af8cd218@mail.gmail.com> References: <49E521F4.4000705@rainierconnect.net> <3e4b8fe10904141923y28c023edt8407055824e39adc@mail.gmail.com> <3e4b8fe10904150617v39f7198fsde71acb4af8cd218@mail.gmail.com> Message-ID: Hi Rich , I am thinking on my international ISP community options. I have tired before the as path prepending configuration with my international ISP. But as a result , i was still getting some inbound traffic through international ISP. If i use their community options , for example if i advetise my subnet with "send-community" option and 1106 for x6 times prepending , is this option going to solve the unwanted inbound traffic problem ? ( http://www.db.ripe.net/whois?form_type=simple&full_query_string=&searchtext=AS29259&do_search=Search did you remember this address ? :) ) I think that if the as path prepending configuration works well , the inbound traffic to my AS through international ISP will be used as backup state. But , as you know in my scenario for example just international traffic goes from international ISP and come back through the same link. What do you say , am i thinking wrong ? Regards... Burak Dikici On Wed, Apr 15, 2009 at 4:17 PM, Rich Davies wrote: > Burak, > > Yes sorry if i wasnt clear. Basically you can apply the route map for > your session to provider A to change the local pref on those learned > prefixes. You could leave the session to provider B untouched (no route > map inbound or outbound) and you will achieve "some" traffic changes since > you're tagging specific prefixes to send to provider A and they would not go > to provider B (out of country). > > > -Rich > > > On Wed, Apr 15, 2009 at 2:45 AM, Burak Dikici wrote: > >> Hi Rich , >> >> Sorry about my last reply. I couldn't catch the note in your previous >> message. You said ; >> >> "Notice I am not applying a route-map to the other BGP session (3.3.3.3, >> AS 33333) because all these routes get their default values (local pref of >> 100, less preferrable). The route map will allow all the other prefixes >> there is no implicit deny, it merely tags routes matching ACL 10 with local >> pref 150." >> >> >> >> >> On Wed, Apr 15, 2009 at 9:34 AM, Burak Dikici wrote: >> >>> Hi Rich , >>> >>> What do you think about this command ? >>> >>> "neighbor 3.3.3.3 description PROVIDER_B_OUTSIDE_COUNTRY" >>> >>> This command doesn't have any direction. >>> >>> Burak >>> >>> >>> >>> On Wed, Apr 15, 2009 at 5:23 AM, Rich Davies wrote: >>> >>>> Burak, >>>> >>>> BTW this line should not have been in my example: >>>> >>>> neighbor 2.2.2.2 route-map PROVIDER_A_INSIDE_COUNTRY out >>>> >>>> Definately do not want to tag outbound routes in that method as they do >>>> not originate from you (Doh!!). >>>> >>>> >>>> -Rich >>>> >>>> On Tue, Apr 14, 2009 at 8:15 PM, Burak Dikici wrote: >>>> >>>>> By the way i wonder , how can it be done symmetrical traffic flow in >>>>> this >>>>> scenario ? Local traffic goes from local ISP and the return traffic >>>>> comes >>>>> back through local ISP. Outside of the country traffic goes from >>>>> international IPS and the return traffic comes back through >>>>> internaional >>>>> ISP. I don't want to cause any asymmetrical traffic flow between >>>>> different >>>>> ISPs and my site. >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> On Wed, Apr 15, 2009 at 2:53 AM, Walter Keen < >>>>> walter.keen at rainierconnect.net >>>>> > wrote: >>>>> >>>>> > If you are not advertising any space, I would imagine an AS path >>>>> filter >>>>> > on ISP-1 (limited to 1 or 2 hops, if that works for you) and no AS >>>>> path >>>>> > filter on ISP-2 would do the trick. You would want a floating static >>>>> > default route(s) for outbound traffic redundancy. >>>>> > >>>>> > Now, if you are advertising space, as path prepending may be one way >>>>> to >>>>> > go as far as inbound traffic goes, but it gets messy in a situation >>>>> like >>>>> > this one. If you prepend your AS number too many times out ISP1, >>>>> then >>>>> > traffic you may have wanted to come in ISP1 may see ISP2 as a closer >>>>> > route (less AS hops). >>>>> > >>>>> > Burak Dikici wrote: >>>>> > > Hello , >>>>> > > >>>>> > > I have got one internet router running BGP , and this router has >>>>> got >>>>> > > connections with two different ISPs. One of the ISP is local for my >>>>> > country >>>>> > > and the other ISP's location is outside of my country. I want to >>>>> classify >>>>> > > geographical traffic with BGP. For example , local traffic to my >>>>> country >>>>> > > will go through ISP-1 (local ISP) , outside traffic to my country >>>>> will go >>>>> > > through ISP-2 (outside of my country ISP). What i have to do to >>>>> achieve >>>>> > that >>>>> > > kind of configuration ? If i have to use AS path filter , how can i >>>>> find >>>>> > the >>>>> > > local ISP AS path numbers and how can i configure AS path filter >>>>> for this >>>>> > > request ? Is that enough using the as-path filter just for the >>>>> national >>>>> > ISP >>>>> > > or should i use it for international ISP also ? >>>>> > > >>>>> > > If i use AS-path filter for both ISP connections , what will >>>>> happen to >>>>> > > redundancy ? I mean , for example i filter national AS numbers at >>>>> the >>>>> > > international ISP connection and deny them. Secondly , i filter >>>>> national >>>>> > AS >>>>> > > numbers at the national ISP connection , permit them and the other >>>>> AS >>>>> > > numbers will be denied. In this situation , what will happen if the >>>>> local >>>>> > > ISP connection goes down ? Because of filtering of the national AS >>>>> > numbers >>>>> > > at the international ISP connection , the BGP table doesn't take >>>>> any >>>>> > updates >>>>> > > from the local AS numbers. I hope , i could explain the situation >>>>> > correctly. >>>>> > > >>>>> > > >>>>> > > Kind Regards... >>>>> > > >>>>> > > Burak Dikici >>>>> > > _______________________________________________ >>>>> > > cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>> > > https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>> > > archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>>> > > >>>>> > >>>>> > >>>>> _______________________________________________ >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>>> >>>> >>>> >>> >> > From chris.garzon at gmail.com Thu Apr 16 00:18:53 2009 From: chris.garzon at gmail.com (Dracul) Date: Thu, 16 Apr 2009 12:18:53 +0800 Subject: [c-nsp] VTY Lines In-Reply-To: <49E6ABD7.4030402@gmail.com> References: <49E6ABD7.4030402@gmail.com> Message-ID: <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> If you are running a critical network without the convenience of rebooting, Jim's Router# cle ip tcp tcb 58F2E668 worked for me but take note some IOS use the Router#clear tcp tcb (without the 'ip') regards, chris 2009/4/16 Yevgeniy Voloshin > Hi, > > I have the same problem on ME-C3750-24TE with Cisco IOS Software -> C3750ME > Software (C3750ME-I5-M), Version 12.2(44)SE, RELEASE SOFTWARE (fc1) > > In 'sh tcp brief | i \.2[23]' output nothing about telnet ports. But all > vty lines busy: > Line User Host(s) Idle Location > * 0 con 0 idle 00:00:00 1 vty 0 > idle 1y11w xxx.xxx.xxx.xxx > 2 vty 1 idle 1y11w xxx.xxx.xxx.xxx > 3 vty 2 idle 1y11w xxx.xxx.xxx.xxx > 4 vty 3 idle 1y11w xxx.xxx.xxx.xxx > 5 vty 4 idle 1y11w xxx.xxx.xxx.xxx > 6 vty 5 idle 1y11w xxx.xxx.xxx.xxx > 7 vty 6 idle 1y11w xxx.xxx.xxx.xxx > 8 vty 7 idle 41w5d xxx.xxx.xxx.xxx > 9 vty 8 idle 34w5d xxx.xxx.xxx.xxx > 10 vty 9 idle 34w5d xxx.xxx.xxx.xxx > 11 vty 10 idle 31w0d xxx.xxx.xxx.xxx > 12 vty 11 idle 17w2d xxx.xxx.xxx.xxx > 13 vty 12 idle 16w6d xxx.xxx.xxx.xxx > 14 vty 13 idle 16w6d xxx.xxx.xxx.xxx > 15 vty 14 idle 2w2d xxx.xxx.xxx.xxx > 16 vty 15 idle 2w2d xxx.xxx.xxx.xxx > > > So right now I am waiting MW to reload box with IOS upgrade. > > > --- > Yev. > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From brhedlun at cisco.com Thu Apr 16 00:25:45 2009 From: brhedlun at cisco.com (Brad Hedlund) Date: Wed, 15 Apr 2009 23:25:45 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: Message-ID: If "legacy FC devices" means FC attached storage arrays, well that would be just about everything out there today. Current and next generation C-N-A's do not operate any differently in how FC attached storage is accessed (via a Nexus 5K with FC uplinks). Even with FCoE attached storage the Nexus 5K is still a key piece of the server access architecture. iSCSI at 10GE has its challenges as there is an order of magnitude increase in TCP processing requirements at 10GE vs. 1GE, 10x more buffers required for TCP windowing for sustained 10GE throughput under latency, 10x more packets-per-second requiring TCP offload processing. All of which drives up the cost of the 10GE iSCSI HBA. Not all 10GE iSCSI HBA's may have these resources, so it will be interesting to see how those adapters perform under varying latencies and varying loads vs. FCoE. FCoE does not have the TCP processing overhead and leverages the hardware capabilities of the Nexus 5000 to provide the lossless transport to storage, regardless if the array is FC or FCoE attached. Cheers, Brad Hedlund bhedlund at cisco.com http://www.internetworkexpert.org On 4/15/09 7:21 PM, "Justin C Darby" wrote: > > Hello David, > > This is entirely my personal opinion and I'm sure some folks in the Nexus > BU at Cisco would hit me for saying this given the chance. > > Unless you are using legacy FC devices, hold off on the 5K for this. The > reason I say this is because a new class of storage devices and HBA's that > use 10GbE native are hitting the market. Some vendors are mostly there, > others not at all. I beleive QLogic has HBA's available for this, and I > know the major storage vendors are working on bringing FCoE storage devices > to market. You've also got alternatives to FCoE that can use 10GbE for > native transport now (iSCSI/ATA-over-Ethernet/etc). > > The operating cost (relative to performance) of using 10GbE to do FCoE > native are considerably more advantageous than just consolidating 4xFC onto > 10GbE. However, if you've already got a bunch of FC gear and you want to > consolidate the transport, there are people using 5K's for this (though I > am not one of them), and given my experience with the 7K i am sure it'll > work out as designed. > > Have fun, > Justin > > P.S. Opinions here are my own, not the views of the U.S. Government, etc. > > -----cisco-nsp-bounces at puck.nether.net wrote: ----- > To: "Cisco NSP ((E-mail))'" > From: David Hughes > Sent by: cisco-nsp-bounces at puck.nether.net > Date: 04/15/2009 07:07PM > Subject: [c-nsp] Nexus 5K FCoE to FC breakout > > Hi Seeing as this is all bleeding edge, I'd be very interested in any > first hand experiences with breaking out FCoE to traditional FC via an > N5K. Is it working OK? Are you running it as a switch or in NPV mode? > How's the interop with your FC fabric (and who's gear are you using for > FC switching). Whos CNA's are downstream of the N5K? Any thoughts, > observations etc you can share about this brave new world would be > greatly appreciated? Thanks David ... > _______________________________________________ cisco-nsp mailing list > cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp archive at > http://puck.nether.net/pipermail/cisco-nsp/ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From ltd at cisco.com Thu Apr 16 00:39:04 2009 From: ltd at cisco.com (Lincoln Dale) Date: Thu, 16 Apr 2009 14:39:04 +1000 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: References: Message-ID: <49E6B668.6000001@cisco.com> g'day Dave, i'll reply, because i can , David Hughes wrote: > Seeing as this is all bleeding edge, I'd be very interested in any > first hand experiences with breaking out FCoE to traditional FC via an > N5K. Is it working OK? of course, i'll be biased here, but - yes - no issues with it working just fine. a big part of saying this is that NX-OS is SAN-OS which has been field-proven over the years to be a sound reliable basis for SAN switching. > Are you running it as a switch or in NPV mode? i know of multiple production networks running it both ways, in NPV and as a traditional ISL (E_Port). again, the 'code' to run both is the same as the code on Cisco MDS. > How's the interop with your FC fabric (and who's gear are you using > for FC switching). Cisco supports standards-based interop. i guess with NPV the intent is that its a F_Port so should be no interop challenges there anyway. > Whos CNA's are downstream of the N5K? you can choose Q or E variety today. > Any thoughts, observations etc you can share about this brave new > world would be greatly appreciated? i'll let others comment on that part. cheers, lincoln. > > > Thanks > > David > ... > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From engel.labiro at gmail.com Thu Apr 16 02:33:47 2009 From: engel.labiro at gmail.com (Engelhard Labiro) Date: Thu, 16 Apr 2009 15:33:47 +0900 Subject: [c-nsp] VTY Lines In-Reply-To: <49E6ABD7.4030402@gmail.com> References: <49E6ABD7.4030402@gmail.com> Message-ID: <62D4BBB1-19AA-4584-B96A-B1EFA92C899D@gmail.com> Is this bug or just config under vty that disabled session timeout? Do you have entry "exec timeout 0 0" at line vty? On 2009/04/16, at 12:53, Yevgeniy Voloshin wrote: > Hi, > > I have the same problem on ME-C3750-24TE with Cisco IOS Software -> > C3750ME Software (C3750ME-I5-M), Version 12.2(44)SE, RELEASE > SOFTWARE (fc1) > > In 'sh tcp brief | i \.2[23]' output nothing about telnet ports. But > all vty lines busy: > Line User Host(s) Idle Location > * 0 con 0 idle 00:00:00 1 vty > 0 idle 1y11w xxx.xxx.xxx.xxx > 2 vty 1 idle 1y11w xxx.xxx.xxx.xxx > 3 vty 2 idle 1y11w xxx.xxx.xxx.xxx > 4 vty 3 idle 1y11w xxx.xxx.xxx.xxx > 5 vty 4 idle 1y11w xxx.xxx.xxx.xxx > 6 vty 5 idle 1y11w xxx.xxx.xxx.xxx > 7 vty 6 idle 1y11w xxx.xxx.xxx.xxx > 8 vty 7 idle 41w5d xxx.xxx.xxx.xxx > 9 vty 8 idle 34w5d xxx.xxx.xxx.xxx > 10 vty 9 idle 34w5d xxx.xxx.xxx.xxx > 11 vty 10 idle 31w0d xxx.xxx.xxx.xxx > 12 vty 11 idle 17w2d xxx.xxx.xxx.xxx > 13 vty 12 idle 16w6d xxx.xxx.xxx.xxx > 14 vty 13 idle 16w6d xxx.xxx.xxx.xxx > 15 vty 14 idle 2w2d xxx.xxx.xxx.xxx > 16 vty 15 idle 2w2d xxx.xxx.xxx.xxx > > > So right now I am waiting MW to reload box with IOS upgrade. > > > --- > Yev. > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From hegedus.gabor at euroway.hu Thu Apr 16 03:56:00 2009 From: hegedus.gabor at euroway.hu (Hegedus Gabor) Date: Thu, 16 Apr 2009 09:56:00 +0200 Subject: [c-nsp] VPN 3000 certificate based S2S Message-ID: <49E6E490.6000302@euroway.hu> Hi all! I don't find answer to my question on the net. My problem is the following: I have a cisco VPN 3000 device, and we want site-2-site vpn with this device. I got the root CA cert and I added it successfully. I have our certificate what is in coded format .p12 file with password. How can I install this p12 file, because only cert request is allowed on the VPN concentrator, I can't upload(install) my cert simply. I tried it on ASA, and it works good, i can install root ca and my ca both on it. I don't want send cert request to the root ca, cos I already have all cert file. What can I do with my p12 ? convert it to what? What are extensions and file formats the vpn3000 look out in identity cert section? any suggestion? thank you, Gabor From David at hughes.com.au Thu Apr 16 04:29:07 2009 From: David at hughes.com.au (David Hughes) Date: Thu, 16 Apr 2009 18:29:07 +1000 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: References: Message-ID: <0FADF09F-90F9-4E9A-8AC4-070A604B53F0@hughes.com.au> Hi Justin, On 16/04/2009, at 10:21 AM, Justin C Darby wrote: > Unless you are using legacy FC devices, hold off on the 5K for this. > The > reason I say this is because a new class of storage devices and > HBA's that > use 10GbE native are hitting the market. Some vendors are mostly > there, > others not at all. I haven't seen much activity on the native FCoE storage front yet. Hanging storage directly off a N7K (when there are FCoE linecards for it) is the perfect solution but that's a way off. There isn't even multi-hop support for FCoE yet so doing a "real" FCoE end-to-end solution is not going to happen too soon. It all sounds very cool but I think the paint is still quite wet on this stuff. FCoE to FC break- out looks like a reasonable intermediary step. Do you have details on native FCoE storage offerings? Thanks David ... From eric at atlantech.net Thu Apr 16 08:46:51 2009 From: eric at atlantech.net (Eric Van Tol) Date: Thu, 16 Apr 2009 08:46:51 -0400 Subject: [c-nsp] VTY Lines In-Reply-To: <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> Message-ID: <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- > bounces at puck.nether.net] On Behalf Of Dracul > Sent: Thursday, April 16, 2009 12:19 AM > To: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] VTY Lines > > If you are running a critical network without the convenience of > rebooting, > Jim's Router# cle ip tcp tcb 58F2E668 worked for me > > but take note some IOS use the Router#clear tcp tcb (without the 'ip') > > regards, > chris If you can't gain access to the CLI, it is possible to reset vty TCP sessions using SNMP, assuming you have a read-write string configured on the device. I personally don't know the procedure, but there are tools out there such as the Solarwinds Engineers Edition toolset that let you do this. If anyone knows the right procedure, maybe they can post it here. -evt From ler762 at gmail.com Thu Apr 16 09:08:03 2009 From: ler762 at gmail.com (Lee) Date: Thu, 16 Apr 2009 09:08:03 -0400 Subject: [c-nsp] VTY Lines In-Reply-To: <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> Message-ID: On 4/16/09, Eric Van Tol wrote: >> -----Original Message----- >> From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- >> bounces at puck.nether.net] On Behalf Of Dracul >> Sent: Thursday, April 16, 2009 12:19 AM >> To: cisco-nsp at puck.nether.net >> Subject: Re: [c-nsp] VTY Lines >> >> If you are running a critical network without the convenience of >> rebooting, >> Jim's Router# cle ip tcp tcb 58F2E668 worked for me >> >> but take note some IOS use the Router#clear tcp tcb (without the 'ip') >> >> regards, >> chris > > If you can't gain access to the CLI, it is possible to reset vty TCP > sessions using SNMP, assuming you have a read-write string configured on the > device. I personally don't know the procedure, but there are tools out > there such as the Solarwinds Engineers Edition toolset that let you do this. > If anyone knows the right procedure, maybe they can post it here. How to Detect and Clear Hung TCP Connections using SNMP http://www.cisco.com/en/US/tech/tk648/tk362/technologies_problem_troubleshooting09186a00802b93ef.shtml From alijawad1 at gmail.com Thu Apr 16 10:16:58 2009 From: alijawad1 at gmail.com (Ali Jawad) Date: Thu, 16 Apr 2009 07:16:58 -0700 Subject: [c-nsp] Cisco router randomly not serving DHCP responses Message-ID: Hi I got a Cisco router, it is also the DHCP server of my network the detail are below. For some reason the server randomly stops serving IPs to workstations, even a repair conection does not work. Some computers have a valid IP but it does not get renewed. Router#show version Cisco IOS Software, 2800 Software (C2800NM-ADVIPSERVICESK9-M), Version 12.4(17b) , RELEASE SOFTWARE (fc2) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2008 by Cisco Systems, Inc. Compiled Tue 26-Feb-08 01:46 by prod_rel_team ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1) I did enable debug and I got : Adding to the above I got the following debug info...as you can see below the mac address 0016.d490.8e9a is trying to get an IP but it is getting the answer..DHCPD: Allocate an address without class information while 0100.40f4.9689 got 192.168.0.204 Router# *Apr 16 14:36:43.375: DHCPD: DHCPDISCOVER received from client 0016.d490.8e9a on interface FastEthernet0/1. *Apr 16 14:36:43.375: DHCPD: Allocate an address without class information (192. 168.0.0) *Apr 16 14:36:43.647: %HA_EM-6-LOG: CLIAccounting: terminal monitor *Apr 16 14:37:00.535: DHCPD: DHCPDISCOVER received from client 0016.d490.8e9a on interface FastEthernet0/1. *Apr 16 14:37:00.535: DHCPD: Allocate an address without class information (192. 168.0.0) *Apr 16 14:37:05.375: DHCPD: DHCPDISCOVER received from client 0016.d490.8e9a on interface FastEthernet0/1. *Apr 16 14:37:05.379: DHCPD: Allocate an address without class information (192. 168.0.0) *Apr 16 14:37:16.375: DHCPD: DHCPDISCOVER received from client 0016.d490.8e9a on interface FastEthernet0/1. *Apr 16 14:37:16.375: DHCPD: Allocate an address without class information (192. 168.0.0) *Apr 16 14:37:29.375: DHCPD: DHCPDISCOVER received from client 0016.d490.8e9a on interface FastEthernet0/1. *Apr 16 14:37:29.379: DHCPD: Allocate an address without class information (192. 168.0.0) *Apr 16 14:37:42.375: DHCPD: DHCPDISCOVER received from client 0016.d490.8e9a on interface FastEthernet0/1. *Apr 16 14:37:42.375: DHCPD: Allocate an address without class information (192. 168.0.0) *Apr 16 14:37:43.551: DHCPD: DHCPINFORM received from client 0100.40f4.9689.ec ( 192.168.0.204). *Apr 16 14:37:43.551: DHCPD: Sending DHCPACK to client 0100.40f4.9689.ec(192.16 8.0.204). *Apr 16 14:37:43.551: DHCPD: unicasting BOOTREPLY to client 0040.f496.89ec (192. 168.0.204). *Apr 16 14:37:46.555: DHCPD: DHCPINFORM received from client 0100.40f4.9689.ec ( 192.168.0.204). *Apr 16 14:37:46.555: DHCPD: Sending DHCPACK to client 0100.40f4.9689.ec(192.16 8.0.204). *Apr 16 14:37:46.555: DHCPD: unicasting BOOTREPLY to client 0040.f496.89ec (192. 168.0.204). *Apr 16 14:38:00.371: DHCPD: DHCPDISCOVER received from client 0016.d490.8e9a on interface FastEthernet0/1. *Apr 16 14:38:00.371: DHCPD: Allocate an address without class information (192. 168.0.0) *Apr 16 14:38:07.115: DHCPD: DHCPINFORM received from client 0100.1676.6d3b.5e ( 192.168.0.182). *Apr 16 14:38:07.115: DHCPD: Sending DHCPACK to client 0100.1676.6d3b.5e (192.16 8.0.182). *Apr 16 14:38:07.115: DHCPD: unicasting BOOTREPLY to client 0016.766d.3b5e (192. 168.0.182). *Apr 16 14:38:10.115: DHCPD: DHCPINFORM received from client 0100.1676.6d3b.5e ( 192.168.0.182). *Apr 16 14:38:10.115: DHCPD: Sending DHCPACK to client 0100.1676.6d3b.5e (192.16 8.0.182). *Apr 16 14:38:10.115: DHCPD: unicasting BOOTREPLY to client 0016.766d.3b5e (192. 168.0.182). Please advice. The pool is: #show ip dhcp pool Pool centrale : Utilization mark (high/low) : 100 / 0 Subnet size (first/next) : 0 / 0 Total addresses : 254 Leased addresses : 143 Pending event : none 1 subnet is currently in the pool : Current index IP address range Leased addr 0.0.0.0 192.168.0.1 - 192.168.0.254 143 From frosya84 at mail.ru Thu Apr 16 10:50:30 2009 From: frosya84 at mail.ru (=?koi8-r?Q?=EF=CC=D8=C7=C1_=F2=D5=D6=C1=CE=D3=CB=C1=D1?=) Date: Thu, 16 Apr 2009 18:50:30 +0400 Subject: [c-nsp] SNMP MIB for NetFlow TCAM utilization (Ruzhanskaya Olga) Message-ID: Hello List! Maybe someone have already decided this problem. We need to watch for TCAM utilization for NetFlow via the SNMP. But I haven't find SNMP MIB dedicated for this situation:-( We've tried to find it in this groups: CISCO-NETFLOW-MIB, CISCO-SWITCH-ENGINE-MIB.. There are nothing for NetFlow TCAM utilization. Any idea? Best regards, Olga From jcdarby at usgs.gov Thu Apr 16 11:06:48 2009 From: jcdarby at usgs.gov (Justin C Darby) Date: Thu, 16 Apr 2009 11:06:48 -0400 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: <0FADF09F-90F9-4E9A-8AC4-070A604B53F0@hughes.com.au> References: <0FADF09F-90F9-4E9A-8AC4-070A604B53F0@hughes.com.au>, Message-ID: Unfortunately, no. Outside of multiple vendors promising it's coming soon, it's been smoke and mirrors. I think the major players up front are going to be EMC and NetApp, with NetApp in theory having devices on the market right now I haven't seen yet. ( http://www.netapp.com/us/products/protocols/fcoe/ ) We're actually using in-house built ATA-over-Ethernet devices which have similar advantages, but this isn't very 'enterprisey' - this was us trying to find a way to deal with extreme I/O loads on giant Oracle databases (which are now back to being CPU bound for the first time in years). They also beat the heck out of 4x FC interfaces, preforming at 600-800MB/s, for most of our applications under load. There are a bunch of people jumping all over this, but I haven't seen results quite yet, I'm just expecting to see them this year. The existence of HBA's means its coming - Cisco's UCS design actually counts on having FCoE 10GbE HBA's if what I'm reading about them is correct. Justin -----David Hughes wrote: ----- To: Justin C Darby From: David Hughes Date: 04/16/2009 05:40AM cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] Nexus 5K FCoE to FC breakout Hi Justin, On 16/04/2009, at 10:21 AM, Justin C Darby wrote: > Unless you are using legacy FC devices, hold off on the 5K for this. > The > reason I say this is because a new class of storage devices and > HBA's that > use 10GbE native are hitting the market. Some vendors are mostly > there, > others not at all. I haven't seen much activity on the native FCoE storage front yet. Hanging storage directly off a N7K (when there are FCoE linecards for it) is the perfect solution but that's a way off. There isn't even multi-hop support for FCoE yet so doing a "real" FCoE end-to-end solution is not going to happen too soon. It all sounds very cool but I think the paint is still quite wet on this stuff. FCoE to FC break- out looks like a reasonable intermediary step. Do you have details on native FCoE storage offerings? Thanks David ... From largent at ai.net Thu Apr 16 12:48:24 2009 From: largent at ai.net (L'argent) Date: Thu, 16 Apr 2009 12:48:24 -0400 Subject: [c-nsp] 3560E wire-speed or not? Message-ID: <49E76158.6020005@ai.net> Quick question regarding whether a 3560E is wire-speed or not. According to the Cisco website here: http://www.cisco.com/en/US/products/ps7078/prod_models_comparison.html For example, I don't see how a 3560E-12D and a 3560-12SD can both be wirespeed when their max PPS is different only by a factor of 2. The PPS numbers (unless I've done my math wrong) seem to imply *not* wirespeed. However on the product data sheets and the video introduction it says "wirespeed". Such as here: http://www.youtube.com/watch?v=ake-nsGcwd8 and http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps7078/product_data_sheet0900aecd805bac22.html Anything conclusive anyone can share with me? Our application is to aggregate several 1Gb/s VLANs onto 10G and back. The QOS/buffering problems others have mentioned shouldn't be an issue for this, but I'd rather not run into any exotic TCAM forwarding limitations that some how modify the wire-speed classification. Thanks in advance, LA From bdikici at gmail.com Thu Apr 16 13:52:24 2009 From: bdikici at gmail.com (Burak Dikici) Date: Thu, 16 Apr 2009 20:52:24 +0300 Subject: [c-nsp] Classify geographical traffic with BGP In-Reply-To: <3e4b8fe10904160707l1568eff8s439c59bc45004019@mail.gmail.com> References: <49E521F4.4000705@rainierconnect.net> <3e4b8fe10904141923y28c023edt8407055824e39adc@mail.gmail.com> <3e4b8fe10904150617v39f7198fsde71acb4af8cd218@mail.gmail.com> <3e4b8fe10904160707l1568eff8s439c59bc45004019@mail.gmail.com> Message-ID: Hi Rich , With this configuration , i am still getting inbound traffic from germany_isp i didn't use "neighbor send-community" command in the configuration , is that couse any problem ? When i control the my advertised route from the at&t router , it is looking prepended. router bgp 5555 neighbor GERMANY_ISP_IP_ADDRESS remote-as 29259 neighbor GERMANY_ISP_IP_ADDRESS description Germany_ISP address-family ipv4 no synchronization neighbor GERMANY_ISP_IP_ADDRESS activate neighbor GERMANY_ISP_IP_ADDRESS route-map AS_path_prepend_for_germany_ISP out neighbor GERMANY_ISP_IP_ADDRESS filter-list 10 out ! ip as-path access-list 10 permit ^$ ! route-map AS_path_prepend_for_germany_ISP permit 10 match ip address 54 set as-path prepend 5555 5555 5555 ! route-map AS_path_prepend_for_germany_ISP permit 20 By the way , what is the difference between the configs ; *!!!!! CONFIG-1 !!!!!* route-map AS_path_prepend_for_germany_ISP permit 10 match ip address 54 set as-path prepend 5555 5555 ! route-map AS_path_prepend_for_germany_ISP permit 20 router bgp 5555 neighbor GERMANY_ISP_IP_ADDRESS route-map AS_path_prepend_for_germany_ISP out *!!!!! CONFIG-2 !!!!!* route-map AS_PREPENDING permit 10 set community 29259:1101 router bgp 5555 neighbor GERMANY_ISP_IP_ADDRESS route-map AS_PREPENDING out neighbor GERMANY_ISP_IP_ADDRESS send-community On Thu, Apr 16, 2009 at 5:07 PM, Rich Davies wrote: > Burak, > > Yes you are on the right track. If you use your internernational ISP's > pre-designated BGP communities you can cause them to apply the 6x prepending > that you desire to cause unwanted traffic not to enter your international > link (due to more "false" as-hops to the destination network/prefix). Your > in-country link/ISP will have the more desirable route due to less as-hops > (inbound to your network) so essentially yes your international link will > act as a backup link. > > Good luck! > > > -Rich > > > > On Thu, Apr 16, 2009 at 12:11 AM, Burak Dikici wrote: > >> Hi Rich , >> >> I am thinking on my international ISP community options. I have tired >> before the as path prepending configuration with my international ISP. But >> as a result , i was still getting some inbound traffic through international >> ISP. If i use their community options , for example if i advetise my >> subnet with "send-community" option and 1106 for x6 times prepending , is >> this option going to solve the unwanted inbound traffic problem ? >> ( >> http://www.db.ripe.net/whois?form_type=simple&full_query_string=&searchtext=AS29259&do_search=Search >> did you remember this address ? :) ) >> >> I think that if the as path prepending configuration works well , the >> inbound traffic to my AS through international ISP will be used as backup >> state. But , as you know in my scenario >> for example just international traffic goes from international ISP and >> come back through the same link. What do you say , am i thinking wrong ? >> >> Regards... >> >> Burak Dikici >> >> >> >> >> >> >> On Wed, Apr 15, 2009 at 4:17 PM, Rich Davies wrote: >> >>> Burak, >>> >>> Yes sorry if i wasnt clear. Basically you can apply the route map for >>> your session to provider A to change the local pref on those learned >>> prefixes. You could leave the session to provider B untouched (no route >>> map inbound or outbound) and you will achieve "some" traffic changes since >>> you're tagging specific prefixes to send to provider A and they would not go >>> to provider B (out of country). >>> >>> >>> -Rich >>> >>> >>> On Wed, Apr 15, 2009 at 2:45 AM, Burak Dikici wrote: >>> >>>> Hi Rich , >>>> >>>> Sorry about my last reply. I couldn't catch the note in your previous >>>> message. You said ; >>>> >>>> "Notice I am not applying a route-map to the other BGP session (3.3.3.3, >>>> AS 33333) because all these routes get their default values (local pref of >>>> 100, less preferrable). The route map will allow all the other prefixes >>>> there is no implicit deny, it merely tags routes matching ACL 10 with local >>>> pref 150." >>>> >>>> >>>> >>>> >>>> On Wed, Apr 15, 2009 at 9:34 AM, Burak Dikici wrote: >>>> >>>>> Hi Rich , >>>>> >>>>> What do you think about this command ? >>>>> >>>>> "neighbor 3.3.3.3 description PROVIDER_B_OUTSIDE_COUNTRY" >>>>> >>>>> This command doesn't have any direction. >>>>> >>>>> Burak >>>>> >>>>> >>>>> >>>>> On Wed, Apr 15, 2009 at 5:23 AM, Rich Davies wrote: >>>>> >>>>>> Burak, >>>>>> >>>>>> BTW this line should not have been in my example: >>>>>> >>>>>> neighbor 2.2.2.2 route-map PROVIDER_A_INSIDE_COUNTRY out >>>>>> >>>>>> Definately do not want to tag outbound routes in that method as they >>>>>> do not originate from you (Doh!!). >>>>>> >>>>>> >>>>>> -Rich >>>>>> >>>>>> On Tue, Apr 14, 2009 at 8:15 PM, Burak Dikici wrote: >>>>>> >>>>>>> By the way i wonder , how can it be done symmetrical traffic flow in >>>>>>> this >>>>>>> scenario ? Local traffic goes from local ISP and the return traffic >>>>>>> comes >>>>>>> back through local ISP. Outside of the country traffic goes from >>>>>>> international IPS and the return traffic comes back through >>>>>>> internaional >>>>>>> ISP. I don't want to cause any asymmetrical traffic flow between >>>>>>> different >>>>>>> ISPs and my site. >>>>>>> >>>>>>> >>>>>>> >>>>>>> >>>>>>> >>>>>>> On Wed, Apr 15, 2009 at 2:53 AM, Walter Keen < >>>>>>> walter.keen at rainierconnect.net >>>>>>> > wrote: >>>>>>> >>>>>>> > If you are not advertising any space, I would imagine an AS path >>>>>>> filter >>>>>>> > on ISP-1 (limited to 1 or 2 hops, if that works for you) and no AS >>>>>>> path >>>>>>> > filter on ISP-2 would do the trick. You would want a floating >>>>>>> static >>>>>>> > default route(s) for outbound traffic redundancy. >>>>>>> > >>>>>>> > Now, if you are advertising space, as path prepending may be one >>>>>>> way to >>>>>>> > go as far as inbound traffic goes, but it gets messy in a situation >>>>>>> like >>>>>>> > this one. If you prepend your AS number too many times out ISP1, >>>>>>> then >>>>>>> > traffic you may have wanted to come in ISP1 may see ISP2 as a >>>>>>> closer >>>>>>> > route (less AS hops). >>>>>>> > >>>>>>> > Burak Dikici wrote: >>>>>>> > > Hello , >>>>>>> > > >>>>>>> > > I have got one internet router running BGP , and this router >>>>>>> has got >>>>>>> > > connections with two different ISPs. One of the ISP is local for >>>>>>> my >>>>>>> > country >>>>>>> > > and the other ISP's location is outside of my country. I want to >>>>>>> classify >>>>>>> > > geographical traffic with BGP. For example , local traffic to my >>>>>>> country >>>>>>> > > will go through ISP-1 (local ISP) , outside traffic to my country >>>>>>> will go >>>>>>> > > through ISP-2 (outside of my country ISP). What i have to do to >>>>>>> achieve >>>>>>> > that >>>>>>> > > kind of configuration ? If i have to use AS path filter , how can >>>>>>> i find >>>>>>> > the >>>>>>> > > local ISP AS path numbers and how can i configure AS path filter >>>>>>> for this >>>>>>> > > request ? Is that enough using the as-path filter just for the >>>>>>> national >>>>>>> > ISP >>>>>>> > > or should i use it for international ISP also ? >>>>>>> > > >>>>>>> > > If i use AS-path filter for both ISP connections , what will >>>>>>> happen to >>>>>>> > > redundancy ? I mean , for example i filter national AS numbers at >>>>>>> the >>>>>>> > > international ISP connection and deny them. Secondly , i filter >>>>>>> national >>>>>>> > AS >>>>>>> > > numbers at the national ISP connection , permit them and the >>>>>>> other AS >>>>>>> > > numbers will be denied. In this situation , what will happen if >>>>>>> the local >>>>>>> > > ISP connection goes down ? Because of filtering of the national >>>>>>> AS >>>>>>> > numbers >>>>>>> > > at the international ISP connection , the BGP table doesn't take >>>>>>> any >>>>>>> > updates >>>>>>> > > from the local AS numbers. I hope , i could explain the situation >>>>>>> > correctly. >>>>>>> > > >>>>>>> > > >>>>>>> > > Kind Regards... >>>>>>> > > >>>>>>> > > Burak Dikici >>>>>>> > > _______________________________________________ >>>>>>> > > cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>>>> > > https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>>>> > > archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>>>>> > > >>>>>>> > >>>>>>> > >>>>>>> _______________________________________________ >>>>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>>>>> >>>>>> >>>>>> >>>>> >>>> >>> >> > From bitkraft at gmail.com Thu Apr 16 14:45:36 2009 From: bitkraft at gmail.com (Brian Spade) Date: Thu, 16 Apr 2009 11:45:36 -0700 Subject: [c-nsp] SNMP MIB for NetFlow TCAM utilization (Ruzhanskaya Olga) In-Reply-To: References: Message-ID: <505b616c0904161145p5cf92aa8k8942c548cdafeffa@mail.gmail.com> Try: Flow learn failures (.1.3.6.1.4.1.9.9.97.1.4.1.1.6) /bs 2009/4/16 ????? ????????? > > Hello List! > > Maybe someone have already decided this problem. > > We need to watch for TCAM utilization for NetFlow via the SNMP. > But I haven't find SNMP MIB dedicated for this situation:-( > We've tried to find it in this groups: > CISCO-NETFLOW-MIB, CISCO-SWITCH-ENGINE-MIB.. > There are nothing for NetFlow TCAM utilization. > > Any idea? > > Best regards, > Olga > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From rick at woofpaws.com Thu Apr 16 14:59:03 2009 From: rick at woofpaws.com (Rick Ernst) Date: Thu, 16 Apr 2009 11:59:03 -0700 (PDT) Subject: [c-nsp] CPU utilization - "media converter" vs "bump in the cable" Message-ID: <38154.69.30.17.85.1239908343.squirrel@www.woofpaws.com> I was a bit surprised to see that a 7206VXR/NPE-G1 running at the same CPU utilization on both an ethernet upstream with ~300mbs (in+out) running through it and an OC-3 upstream with about 100mbs through it. Multiple upstreams for the same ASN, essentially the same configuration (other than IP addresses). All running BGP with full tables to different upstreams. Is the NPE-G1 very non-linear in CPU load or (my guess) that the OC-3 upstreams are spending more time rewriting the packet headers from OC-3 to ethernet. I'd like to better understand what is going on for capacity/scalability planning. Thanks, Rick From peter at rathlev.dk Thu Apr 16 15:05:37 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 16 Apr 2009 21:05:37 +0200 Subject: [c-nsp] C6kSup720 "LAN ONLY" vs. "WAN" Message-ID: <1239908737.3608.5.camel@localhost.localdomain> Hi, Could anybody explain to me where I can find some official documentation about the differences between a "LAN ONLY" and a WAN image for the Sup720? E.g. the difference between these two images: s72033-advipservicesk9-mz.122-33.SXI1.bin s72033-advipservicesk9_wan-mz.122-33.SXI1.bin The former is a meagre 59MB where the latter takes up 90MB. I've assumed that certain WAN modules like OSM cannot run in the "LAN ONLY" image, but I'd love to know where I could know exactly what can and cannot run in the "LAN ONLY" image. Thank you. Peter From brhedlun at cisco.com Thu Apr 16 15:33:10 2009 From: brhedlun at cisco.com (Brad Hedlund) Date: Thu, 16 Apr 2009 14:33:10 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: Message-ID: On 4/16/09 10:06 AM, "Justin C Darby" wrote: > We're actually using in-house built ATA-over-Ethernet devices which have > similar advantages, but this isn't very 'enterprisey' Sounds very cool! I look forward to learning more about this ATA-over-Ethernet. > Cisco's UCS design actually > counts on having FCoE 10GbE HBA's if what I'm reading about them is > correct. Cisco UCS has standard PCIe mezzanine form factor 10GE adapters that support any over-Ethernet access to storage ... iSCSI, NAS, FCoE. Once at the UCS Manager, native FC uplinks are available for connecting to existing FC SANs. Cheers, Brad Hedlund bhedlund at cisco.com http://www.internetworkexpert.org From peter at rathlev.dk Thu Apr 16 15:35:52 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 16 Apr 2009 21:35:52 +0200 Subject: [c-nsp] C6k 6708 Input drops Message-ID: <1239910552.3608.36.camel@localhost.localdomain> I really hate to ask this question, since input drops/discards and micro bursts have been discussed so much. I just can't grasp this. The question is: what are "input drops" that don't show up in "counters errors" or "queueing", but do show up in "show platform hardware capacity interfaces"? Recently we started seeing "input drops" on a 6708 card in Cat6500 running SXF. The other end is the exact samer and the connection in both ends is 10G LR running 5m to a DWDM circuit carrying it ~50 km. It's a L3 (no switchport) MPLS link. The errors appear every twenty minutes very precisely and every time about 100 packets are dropped "all at once" as far as I can tell. I don't understand how one end could send micro bursts faster than the other end could send them when interfaces are similar. (We're also working on tracking the source/finding out what it is of course.) The link is hardly used; we're talking peaks of about 40-50 kpps and 400-600 Mbit/s when looking a 5 min Cacti graphs. The other end doesn't report any errors. It started appearing at a time where we had just _removed_ some traffic from this link logically. I don't assume it's related to link layer problems so we haven't tried replacing anything yet for the same reason. A "show interface counters errors" shows (almost) nothing: xxx-1#sh int te6/5 ... Input queue: 1/75/121167/12 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 30 second input rate 215774000 bits/sec, 31160 packets/sec 30 second output rate 317290000 bits/sec, 33704 packets/sec L2 Switched: ucast: 69130383 pkt, 6313188185 bytes - mcast: 11526118 pkt, 1281021706 bytes L3 in Switched: ucast: 617967640725 pkt, 514240136083975 bytes - mcast: 0 pkt, 0 bytes mcast L3 out Switched: ucast: 589404552537 pkt, 526530456915283 bytes mcast: 0 pkt, 0 bytes 618049766059 packets input, 514245988339000 bytes, 0 no buffer Received 15285284 broadcasts (0 IP multicasts) 0 runts, 349752298 giants, 1785 throttles 14 input errors, 14 CRC, 2 frame, 0 overrun, 0 ignored 0 watchdog, 0 multicast, 0 pause input 0 input packets with dribble condition detected 590212510115 packets output, 531857495170458 bytes, 0 underruns 0 output errors, 0 collisions, 2 interface resets 0 babbles, 0 late collision, 0 deferred 0 lost carrier, 0 no carrier, 0 PAUSE output 0 output buffer failures, 0 output buffers swapped out xxx-1# xxx-1#sh int te6/5 counters errors Load for five secs: 6%/3%; one minute: 4%; five minutes: 4% Time source is NTP, 21:19:04.267 CEST Thu Apr 16 2009 Port Align-Err FCS-Err Xmit-Err Rcv-Err UnderSize OutDiscards Te6/5 0 14 0 14 0 0 Port Single-Col Multi-Col Late-Col Excess-Col Carri-Sen Runts Giants Te6/5 0 0 0 0 0 0 350685137 Port SQETest-Err Deferred-Tx IntMacTx-Err IntMacRx-Err Symbol-Err Te6/5 0 0 0 0 2 xxx-1# xxx-1#sh queueing int te6/5 ... Packets dropped on Receive: BPDU packets: 0 queue dropped [cos-map] --------------------------------------------- 1 0 [0 1 2 3 4 5 6 7 ] 2 0 [] 3 0 [] 4 0 [] 5 0 [] 6 0 [] 7 0 [] 8 0 [] xxx-1#sh pl hard cap fabric Load for five secs: 1%/0%; one minute: 5%; five minutes: 5% Time source is NTP, 21:28:56.577 CEST Thu Apr 16 2009 Switch Fabric Resources Bus utilization: current: 0%, peak was 0% at 21:28:47 CEST Thu Apr 16 2009 Fabric utilization: Ingress Egress Module Chanl Speed rate peak rate peak 1 0 20G 0% 4% @00:08 11Oct08 0% 4% @20:47 24Aug08 1 1 20G 0% 10% @09:36 28Feb09 0% 8% @13:25 28Jul08 2 0 20G 0% 0% 0% 1% @06:38 18Jul08 2 1 20G 1% 9% @13:25 28Jul08 0% 10% @02:05 13Feb09 4 0 20G 0% 2% @11:43 15Sep08 0% 4% @19:35 22Feb09 5 0 20G 0% 5% @09:16 03Sep08 0% 5% @09:16 03Sep08 6 0 20G 0% 11% @10:46 08Apr09 0% 14% @03:09 21Feb09 6 1 20G 0% 15% @12:31 26Jan09 1% 14% @12:32 26Jan09 Switching mode: Module Switching mode 1 compact 2 compact 4 compact 5 compact 6 compact xxx-1#sh pl hard cap interface Load for five secs: 8%/4%; one minute: 6%; five minutes: 5% Time source is NTP, 21:30:12.802 CEST Thu Apr 16 2009 Interface Resources Interface drops: Module Total drops: Tx Rx Highest drop port: Tx Rx 1 1843 16 13 41 2 105657 0 13 0 4 0 1 0 1 6 0 121269 0 5 Interface buffer sizes: Module Bytes: Tx buffer Rx buffer 1 1221120 173504 2 1221120 173504 4 1221120 173504 6 91889216 109296640 xxx-1# Maybe I should just become a gardener instead... :-) Thanks, Peter From A.L.M.Buxey at lboro.ac.uk Thu Apr 16 16:39:40 2009 From: A.L.M.Buxey at lboro.ac.uk (A.L.M.Buxey at lboro.ac.uk) Date: Thu, 16 Apr 2009 21:39:40 +0100 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: References: Message-ID: <20090416203940.GA12774@lboro.ac.uk> Hi, > > We're actually using in-house built ATA-over-Ethernet devices which have > > similar advantages, but this isn't very 'enterprisey' > > Sounds very cool! I look forward to learning more about this > ATA-over-Ethernet. Linux has supported ATAoE for some time - http://aoetools.sourceforge.net/ http://support.coraid.com/support/linux/EtherDrive-2.6-HOWTO.html very handy technology for some purposes alan From paulzugnoni at gmail.com Thu Apr 16 18:56:07 2009 From: paulzugnoni at gmail.com (Paul Zugnoni) Date: Thu, 16 Apr 2009 15:56:07 -0700 Subject: [c-nsp] need help about switch cisco 4 9 4 8 In-Reply-To: <49A030E9.5040009@kenweb.org> References: <753ED4F9715A45ABADBDB9DC23C1FCA8@int.convex.pt> <28011.1317.qm@web57404.mail.re1.yahoo.com> <5E3C7A341C9C41F5BD5FE75FC12704B1@int.convex.pt> <49A030E9.5040009@kenweb.org> Message-ID: <75032a710904161556m1590ec95jf09843eaae3db285@mail.gmail.com> fwiw, (nearly 2 months later) on our 4948: "boot system flash cat4500-ipbasek9-mz.122-31.SGA8.bin" with a config-register of 0x2102 resulted in the switch booting into rommon mode, with an error message on the console that the device was not specified. Upon removing that configuration statement and replacing it with the following one, the 4948 booted as expected: boot system flash bootflash:cat4500-ipbasek9-mz.122-31.SGA8.bin << notice the specification of bootflash: in front of the image name. Paul On Sat, Feb 21, 2009 at 9:50 AM, ML wrote: > Antonio Soares wrote: > >> Since you don't have a "boot system flash" statement in your config, you >> need a config-register = 0x2101. This way it will load the >> first available image in the bootflash. >> >> Regards, >> >> Antonio Soares, CCIE #18473 (R&S) >> amsoares at netcabo.pt >> >> >> > > > Just recently we had an issue where a 4924 wouldn't load our desired IOS > image under any combination of "boot system {flash:|bootflash:} commands we > could think of. Only solution was to erase all but the desired image. > It was a roll the dice hope you don't critically fail situation. > > Config register 0x2101. > > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From alex.wilkinson at dsto.defence.gov.au Thu Apr 16 18:44:05 2009 From: alex.wilkinson at dsto.defence.gov.au (Wilkinson, Alex) Date: Fri, 17 Apr 2009 06:44:05 +0800 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: References: Message-ID: <20090416224405.GA26216@stlux503.dsto.defence.gov.au> 0n Thu, Apr 16, 2009 at 11:06:48AM -0400, Justin C Darby wrote: >We're actually using in-house built ATA-over-Ethernet devices which have >similar advantages, but this isn't very 'enterprisey' - this was us trying >to find a way to deal with extreme I/O loads on giant Oracle databases >(which are now back to being CPU bound for the first time in years). They >also beat the heck out of 4x FC interfaces, preforming at 600-800MB/s, for >most of our applications under load. There are a bunch of people jumping This sounds interesting. Care to share a nutshell summary of how you are doing this ? -aW IMPORTANT: This email remains the property of the Australian Defence Organisation and is subject to the jurisdiction of section 70 of the CRIMES ACT 1914. If you have received this email in error, you are requested to contact the sender and delete the email. From lowen at pari.edu Thu Apr 16 22:45:52 2009 From: lowen at pari.edu (Lamar Owen) Date: Thu, 16 Apr 2009 22:45:52 -0400 Subject: [c-nsp] GSR12008|GRP-B|4OC12/ATM-MM-SC|3GE-GBIC-SC throughput? In-Reply-To: <200904151134.34595.lowen@pari.edu> References: <9DEF078C-1D8D-4F81-BB77-E4A40E4E7BE6@lixfeld.ca> Message-ID: <200904162245.52805.lowen@pari.edu> On Wednesday 15 April 2009 11:34:34 Lamar Owen wrote: > On Tuesday 14 April 2009 18:22:03 Jason Lixfeld wrote: > > For the life of us, we can't seem to get any more than 60Mbps > > sustained across the ATM testing with iperf, so we're just trying to > > figure out if the GSR just can't push any more than what it's doing or > > if there's something else afoot. > I have a 12012 here in production, and have some of the kit necessary to > test point to point ATM connections (including a Catalyst 8540MSR with > OC12, ARM, and gigabit cards), and have a 4xOC12/ATM/MM, but it will be a > few days before I could have the time to set up a test to see if the 12012 > is limited. Ok, had a little time today, so got some data. Setup: Dell Inspiron 600m w/ Gigabit ethernet, running Fedora 10's iperf to a server, which is a CentOS 4 VM on an eight-way Opteron VMware ESX system (Dell PowerEdge 6950). GSR has a 4xOC12 MM ATM card. Other ATM OC12 endpoint is a Catalyst 8540CSR with an OC12 ATM MM uplink card and a dual GigE card (while I have an 8540MSR, the setup is more complex with the MSR than with the CSR with the ATM uplink, and I wanted the simplest possible setup to see if the GSR was a limiter). As the server is in production, I left it attached to the server farm core Extreme Summit1i's, which are GigE-attached to the 12012 GSR. In the topology below, I only list one Summit1i, but there are two in an ESRP setup. Topology: 600m <-->8540CSR GigabitEthernet10/0/0 via 1000Base-T GBIC 8540CSR ATM0/0/0.1 (VPI/VCI 1/17 PVC) <--> 12012 ATM7/0.1 (VPI/VCI 1/17 PVC) 12012 GigabitEthernet4/0 <--> Extreme Summit1i port 8 Extreme Summit1i port 1 <--> Dell 6950 ESX server GE1. 12012 and the Summit1i are in production (the 12012 is the working side of our APS protected OC3 WAN link, and the Summit1i is half of the server farm core), and had other traffic, with variable traffic on the VM during test. I'm pretty happy with how much traffic the Dell 600m laptop generated, by the way! 12012 ATM7 is a 4xOC12 ATM MM LC, 8540CSR ATM0/0/0 is a Catalyst 8540 OC12 ATM uplink module. IOS on 12012 is 12.0(32)S12, on the 8540CSR it's 12.1(27b)E3 12012 has two GRP-B's. Data: 12012 throughput at peak: pari-gsr-12#sh int atm7/0 load Interface bits/sec pack/sec -------------------- ------------ ---------- AT7/0 Tx 206605000 24617 Rx 354535000 34717 pari-gsr-12# 8540CSR throughput at peak: sr1-8540c-1>sh int atm0/0/0 summ *: interface is up IHQ: pkts in input hold queue IQD: pkts dropped from input queue OHQ: pkts in output hold queue OQD: pkts dropped from output queue RXBS: rx rate (bits/sec) RXPS: rx rate (pkts/sec) TXBS: tx rate (bits/sec) TXPS: tx rate (pkts/sec) TRTL: throttle count Interface IHQ IQD OHQ OQD RXBS RXPS TXBS TXPS TRTL ------------------------------------------------------------------------ * ATM0/0/0 0 0 0 0 207281000 24491 353708000 34530 * ATM0/0/0.1 - - - - - - - - - NOTE:No separate counters are maintained for subinterfaces Hence Details of subinterface are not shown sr1-8540c-1> Output of iperf at client (Dell Inspiron 600m, Pentium M 1.8GHz, Fedora 10), slightly sanitized: [root at localhost ~]# iperf --client esx-host -t 720 --dualtest ------------------------------------------------------------ Server listening on TCP port 5001 TCP window size: 85.3 KByte (default) ------------------------------------------------------------ ------------------------------------------------------------ Client connecting to esx-host, TCP port 5001 TCP window size: 16.0 KByte (default) ------------------------------------------------------------ [ 5] local 10.250.132.30 port 46676 connected with esx-host port 5001 [ 4] local 10.250.132.30 port 5001 connected with esx-host port 45629 [ ID] Interval Transfer Bandwidth [ 4] 0.0-719.9 sec 18.0 GBytes 215 Mbits/sec [ ID] Interval Transfer Bandwidth [ 5] 0.0-720.0 sec 31.3 GBytes 374 Mbits/sec [root at localhost ~]# Output of iperf on server (2vCPU VM on a four-way dual core Opteron 2.8GHz Dell 6950 ESX 3.5U3; VM running CentOS 4): [root at esx-host ~]# iperf --server ------------------------------------------------------------ Server listening on TCP port 5001 TCP window size: 85.3 KByte (default) ------------------------------------------------------------ [ 4] local esx-host port 5001 connected with 10.250.132.30 port 46676 ------------------------------------------------------------ Client connecting to 10.250.132.30, TCP port 5001 TCP window size: 16.0 KByte (default) ------------------------------------------------------------ [ 5] local esx-host port 45629 connected with 10.250.132.30 port 5001 Waiting for server threads to complete. Interrupt again to force quit. [ ID] Interval Transfer Bandwidth [ 5] 0.0-720.0 sec 18.0 GBytes 215 Mbits/sec [ ID] Interval Transfer Bandwidth [ 4] 0.0-720.1 sec 31.3 GBytes 374 Mbits/sec [root at esx-host ~]# Port configs: GSR: interface ATM7/0 no ip address no ip directed-broadcast atm clock INTERNAL no atm enable-ilmi-trap no atm ilmi-keepalive ! interface ATM7/0.1 point-to-point ip address 10.250.132.25 255.255.255.252 no ip directed-broadcast no atm enable-ilmi-trap snmp trap link-status pvc 1/17 ! ! Catalyst 8540CSR: interface ATM0/0/0 no ip address atm clock INTERNAL sonet ais-shut arp timeout 900 ! interface ATM0/0/0.1 point-to-point ip address 10.250.132.26 255.255.255.252 pvc 1/17 ! ! That is pretty good throughput for a single workstation attaching over a GigE throttled through an ATM OC12 with AAL5 overhead (SAR, VPI/VCI cell tax, etc) to a fairly busy server. You might find http://www.osti.gov/bridge/servlets/purl/764365-05obbP/native/764365.pdf and http://www-didc.lbl.gov/Talks/GBN.final.pdf to be interesting reading. In light of LBNL's experience, detailed in those two papers, I'm very happy indeed with the results of the laptop test. Hope that helps. From jcdarby at usgs.gov Thu Apr 16 22:59:22 2009 From: jcdarby at usgs.gov (Justin C Darby) Date: Thu, 16 Apr 2009 22:59:22 -0400 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: <20090416224405.GA26216@stlux503.dsto.defence.gov.au> References: <20090416224405.GA26216@stlux503.dsto.defence.gov.au>, Message-ID: Sure. I'm going to try to be really brief and as funny as possible for what was really a traumatic experience last year trying to deal with helping a technology group that was and is undergoing massive growth. :) This is slightly OT but, well, this is c-nsp and I'm sure some of you somewhere are dealing with storage I/O issues and can appreciate. I am now near the end of a 12 step process.. Step 1: Install Blade server chassis. Populate with blades. Step 2: Spend a month tuning PL/SQL apps deployed to Blades. Realize you can't make any more progress because you are I/O bound. Curse Blade servers for having limited I/O connectivity options. Step 2.5: Realize you can't spend $300,000 on a Fiber Channel deployment while also meeting the rest of your yearly deliverables. Step 3: Calculate your average I/O bandwidth and IOPS load for your application into how many hard drives you need spinning (in my case, I've got 48 7200 RPM 1TB SATA drives - we do data warehousing, mostly, on huge datasets). Step 4: Find a way to attach all of these drives to something you can install Linux and 10 Gigabit Ethernet adapters into. Make sure you aren't oversubscribing the PCIe bandwidth. Make sure you have some kind of redundancy and backup strategy. Step 5: Make sure your 'something' supports NUMA and configure Linux to use the various Zero Copy I/O mechanisms at the kernel level (more recent 2.6.x). Partition your drives (LVM or otherwise), and tune the page cache of each one for your expected targets. Step 6: Install vblade. http://aoetools.sourceforge.net/ .. be sure to increase the AoE buffer count on native 10GbE networks. This takes trial and error and depends on your hardware and switch buffer sizes. Step 7: Install 10GbE native ethernet switches and adapters into your Blade chassis and servers. Set MTU to 9000. Step 8: Attach your storage device to your 10GbE LAN. Step 9: Configure clients. Watch your I/O channel widen to 600+ MB/s. If you did this right, your storage server will pretty easily hit over 90% utilization of its 10GbE adapters across all attached clients. Notice that generating client I/O demand much higher is pretty difficult. Step 9.5: ... Unless you use the NetXen cards IBM sells for Bladecenter H, in which case you will see maybe 450MB/s on clients because they don't support an MTU size greater than 8000. Curse IBM and NetXen. Step 10: Optional? :) Buy a Nexus 7000-series 10GbE switch so you can do this on a much larger scale given how amazingly well it all worked compared to how much you spent. If you work in a cash strapped group (like I do), you may wind up ordering this to replace the pile of bargain basement 1GbE 6500's you've got while you budget in your 10GbE modules for next year. Step 10.5: Curse about how much 10GbE costs, then remember how much Fiber Channel costs. Step 11: Become the official networks and storage guy in your group since, somehow, all of this worked out. Thank the gods you've been working in telecoms for years so none of this was beyond you. Step 12: Realize maintaining all of these yourself is a lot of work and it'd be REALLY REALLY NICE if some FCoE vendors started releasing native FCoE hardware and maybe got them on GSA or into SEWP so I, er, you can start comparing options. (Someone at Cisco - copy and paste this line to your FCoE partners, thanks! *ahem*) :) As an amendment to Step 9.5, IBM now sells Broadcom chips in 10GbE cards for Bladecenter H. I haven't used them, yet, though I will still say the following: These work better. And support 9000-byte MTU's. They can not possibly be worse. Buy these instead. Also, the Blade Networks Technologies 10GbE switch for the Bladecenter H is pretty decent for what it does, but there are days I wish I had a nice Cisco CLI and feature set to work on with them like I do the Gigabit Cisco switches I've got going for LAN. Justin P.S. Personal comments, not governments, etc. -----cisco-nsp-bounces at puck.nether.net wrote: ----- To: cisco-nsp at puck.nether.net From: "Wilkinson, Alex" Sent by: cisco-nsp-bounces at puck.nether.net Date: 04/16/2009 07:37PM Subject: Re: [c-nsp] Nexus 5K FCoE to FC breakout 0n Thu, Apr 16, 2009 at 11:06:48AM -0400, Justin C Darby wrote: >We're actually using in-house built ATA-over-Ethernet devices which have >similar advantages, but this isn't very 'enterprisey' - this was us trying >to find a way to deal with extreme I/O loads on giant Oracle databases >(which are now back to being CPU bound for the first time in years). They >also beat the heck out of 4x FC interfaces, preforming at 600-800MB/s, for >most of our applications under load. There are a bunch of people jumping This sounds interesting. Care to share a nutshell summary of how you are doing this ? -aW IMPORTANT: This email remains the property of the Australian Defence Organisation and is subject to the jurisdiction of section 70 of the CRIMES ACT 1914. If you have received this email in error, you are requested to contact the sender and delete the email. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From mtinka at globaltransit.net Thu Apr 16 22:34:08 2009 From: mtinka at globaltransit.net (Mark Tinka) Date: Fri, 17 Apr 2009 10:34:08 +0800 Subject: [c-nsp] IS-IS LSP Generation/Expiry + Database Optimization - Issue - Update! In-Reply-To: <70B7A1CCBFA5C649BD562B6D9F7ED78406EFE053@xmb-ams-333.emea.cisco.com> References: <200902221357.04134.mtinka@globaltransit.net> <200902222330.46372.mtinka@globaltransit.net> <70B7A1CCBFA5C649BD562B6D9F7ED78406EFE053@xmb-ams-333.emea.cisco.com> Message-ID: <200904171034.09576.mtinka@globaltransit.net> Hi all. Just an update for the archives and folk interested: TAC came back with an explanation (and solution) to this issue. The issue is that pseudonode link state PDU's don't have MT- ID's for v6, while non-pseudonodes do. The iSPF bug in the code doesn't handle pseudonode LSP changes for non-base topologies correctly. Typically, during an iSPF run, changes to the pseudonode are applied to all topologies even though the pseudonode LSP's, themselves, don't contain any MT-ID's for v6. However, this bug creates a situation where, during an iSPF calculation for the v6 topology (MT-IPv6), iSPF would only calculate for changes that contain MT-ID's. As such, it would skip any changes for the pseudonode, leading to the incorrect SPF result. The workarounds: disable multi-topologies and run a single topology or disable iSPF (both iSPF and multi-topologies should be enabled for the issue to present). TAC say a fix for this issue will be available in the next release of SRD as well as SRC5. In our case, our pseudonodes in our main PoP are 6500/SUP720-3BXL's running SX*. However, as concerns these switches themselves, this isn't a problem as SX* doesn't support iSPF for v6. TAC did mention, though, that if/when SX* does support iSPF for v6, this fix will be incorporated. Cheers, Mark. -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 835 bytes Desc: This is a digitally signed message part. URL: From jcdarby at usgs.gov Thu Apr 16 23:35:28 2009 From: jcdarby at usgs.gov (Justin C Darby) Date: Thu, 16 Apr 2009 23:35:28 -0400 Subject: [c-nsp] Ethernet over DWDM Message-ID: Anyone care to share any experiences related to running Ethernet over DWDM? I'm not talking huge Carrier Ethernet deployments, more like enterprise LAN-to-LAN connectivity. Particularly, any information at all related to point-to-point DWDM circuits would be great. Examples: Are you InterLATA or IntraLATA, what speeds, which technology (gigabit or 10 gigabit if Ethernet), distance, what carrier, general location, and if you want to throw out a rough number, how much are you paying for it? I know all about CapEx savings with DWDM - that's why I'm looking this way. I'm wondering about actual circuit costs and looking for general ideas of who's doing what with it. My needs are US-centric, but don't let that stop you if you have something to contribute. For the record, I won't be sharing any of the details of these results with anyone, just the rough aggregate data, if you are so inclined to be concerned. Thanks, Justin From md at bts.sk Fri Apr 17 03:20:03 2009 From: md at bts.sk (Marian =?utf-8?B?xI51cmtvdmnEjQ==?=) Date: Fri, 17 Apr 2009 09:20:03 +0200 Subject: [c-nsp] 3560E wire-speed or not? In-Reply-To: <49E76158.6020005@ai.net> References: <49E76158.6020005@ai.net> Message-ID: <20090417072003.GA74569@bts.sk> On Thu, Apr 16, 2009 at 12:48:24PM -0400, L'argent wrote: > Quick question regarding whether a 3560E is wire-speed or not. > > According to the Cisco website here: > http://www.cisco.com/en/US/products/ps7078/prod_models_comparison.html > > For example, I don't see how a 3560E-12D and a 3560-12SD can both be > wirespeed when their max PPS is different only by a factor of 2. All 3560E models except 3560E-12D are wirespeed. 3560E-12D consists of three 4*10GE wirespeed blocks, but bandwidth between those blocks is limited. M. From frosya84 at mail.ru Fri Apr 17 04:02:39 2009 From: frosya84 at mail.ru (=?koi8-r?Q?=EF=CC=D8=C7=C1_=F2=D5=D6=C1=CE=D3=CB=C1=D1?=) Date: Fri, 17 Apr 2009 12:02:39 +0400 Subject: [c-nsp] =?koi8-r?b?U05NUCBNSUIgZm9yIE5ldEZsb3cgVENBTSB1dGlsaXph?= =?koi8-r?b?dGlvbg==?= Message-ID: Thanks But it will show that the table is already full, will not it? I am interesting to see the processof filling the table.. Best regards, Olga From shariq.qam at gmail.com Fri Apr 17 05:03:28 2009 From: shariq.qam at gmail.com (shariq qamar) Date: Fri, 17 Apr 2009 14:33:28 +0530 Subject: [c-nsp] route origin Message-ID: <171b010e0904170203r6d06426bn1b5ff214d7815960@mail.gmail.com> Hi Techies , i have doubt on the origin of route which we learn from juniper routers . i believe juniper router tag only one origin on all the routers which they are learning from connetced BGP neighbours it can be either , egp , incomplete or igp , by default it is igp . anybuddy have any idea on this , because in cisco router origin by default never changes and it shows you prefixes with different origin with which they belongs , but in juniper i didnt find this . any comments ???????? -- Regards, Shariq Qamar, From chaz at chaz6.com Fri Apr 17 05:45:00 2009 From: chaz at chaz6.com (Chris Hills) Date: Fri, 17 Apr 2009 11:45:00 +0200 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: References: <20090416224405.GA26216@stlux503.dsto.defence.gov.au>, Message-ID: <49E84F9C.8060104@chaz6.com> On 17/04/09 04:59, Justin C Darby wrote: > Step 10.5: Curse about how much 10GbE costs, then remember how much Fiber > Channel costs. Yet still you do not hear of much use of Infiniband. I believe at the 2X rate (i.e. 10Gbs) it is cheaper than 10GbE. Did you consider using it when embarking upon your approach? From md at bts.sk Fri Apr 17 06:20:43 2009 From: md at bts.sk (Marian =?utf-8?B?xI51cmtvdmnEjQ==?=) Date: Fri, 17 Apr 2009 12:20:43 +0200 Subject: [c-nsp] C6k 6708 Input drops In-Reply-To: <1239910552.3608.36.camel@localhost.localdomain> References: <1239910552.3608.36.camel@localhost.localdomain> Message-ID: <20090417102043.GA80447@bts.sk> On Thu, Apr 16, 2009 at 09:35:52PM +0200, Peter Rathlev wrote: > I really hate to ask this question, since input drops/discards and micro > bursts have been discussed so much. I just can't grasp this. > > The question is: what are "input drops" that don't show up in "counters > errors" or "queueing", but do show up in "show platform hardware > capacity interfaces"? > > Recently we started seeing "input drops" on a 6708 card in Cat6500 > running SXF. The other end is the exact samer and the connection in both > ends is 10G LR running 5m to a DWDM circuit carrying it ~50 km. It's a > L3 (no switchport) MPLS link. > > The errors appear every twenty minutes very precisely and every time > about 100 packets are dropped "all at once" as far as I can tell. I > don't understand how one end could send micro bursts faster than the > other end could send them when interfaces are similar. Input drops on L3 interfaces include also drops seen by the RP. These are not happening on the physical 10GE interface, but on the CPU's input queue. Try looking for traffic directed to the switch itself (SNMP, routing protocols etc) or traffic which is being punted to CPU for some reason. M. From sthaug at nethelp.no Fri Apr 17 06:21:45 2009 From: sthaug at nethelp.no (sthaug at nethelp.no) Date: Fri, 17 Apr 2009 12:21:45 +0200 (CEST) Subject: [c-nsp] route origin In-Reply-To: <171b010e0904170203r6d06426bn1b5ff214d7815960@mail.gmail.com> References: <171b010e0904170203r6d06426bn1b5ff214d7815960@mail.gmail.com> Message-ID: <20090417.122145.74682536.sthaug@nethelp.no> > i have doubt on the origin of route which we learn from juniper routers . > i believe juniper router tag only one origin on all the routers which they > are learning from connetced BGP neighbours > it can be either , egp , incomplete or igp , by default it is igp . Unless you have an explicit policy to set/change the origin on the Juniper side, the Juniper router won't change the origin. Here is an example from a Cisco router which has received all its routes from Juniper routers: Network Next Hop Metric LocPrf Weight Path * i4.128.0.0/9 193.75.0.79 0 100 0 3356 i *>i 193.75.0.79 0 100 0 3356 i *>i4.224.56.0/24 193.75.0.70 13331 100 0 3549 7018 ? * i 193.75.0.79 100 0 1299 7018 ? * i47.16.0.0/14 193.75.0.79 100 0 1299 4323 8153 7099 e *>i 193.75.0.70 13332 100 0 3549 4323 8153 7099 e Steinar Haug, Nethelp consulting, sthaug at nethelp.no From zhqasmi at cyber.net.pk Fri Apr 17 07:08:54 2009 From: zhqasmi at cyber.net.pk (Amjad Ul Hasnain Qasmi) Date: Fri, 17 Apr 2009 17:08:54 +0600 Subject: [c-nsp] route origin In-Reply-To: <171b010e0904170203r6d06426bn1b5ff214d7815960@mail.gmail.com> References: <171b010e0904170203r6d06426bn1b5ff214d7815960@mail.gmail.com> Message-ID: <008c01c9bf4c$e68279a0$b3876ce0$@net.pk> Origin attribute is not changed when you advertise a route from BGP table to any peer. The difference in juniper and cisco implementation is, in cisco when you redistribute other routing protocol (is-is, ospf) into bgp it set route origin to unknown"?" while juniper by default exports them as IGP "I". /Amjad Qasmi. -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of shariq qamar Sent: Friday, April 17, 2009 3:03 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] route origin Hi Techies , i have doubt on the origin of route which we learn from juniper routers . i believe juniper router tag only one origin on all the routers which they are learning from connetced BGP neighbours it can be either , egp , incomplete or igp , by default it is igp . anybuddy have any idea on this , because in cisco router origin by default never changes and it shows you prefixes with different origin with which they belongs , but in juniper i didnt find this . any comments ???????? -- Regards, Shariq Qamar, _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From brhedlun at cisco.com Fri Apr 17 09:01:39 2009 From: brhedlun at cisco.com (Brad Hedlund (brhedlun)) Date: Fri, 17 Apr 2009 08:01:39 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: <49E84F9C.8060104@chaz6.com> References: <20090416224405.GA26216@stlux503.dsto.defence.gov.au>, <49E84F9C.8060104@chaz6.com> Message-ID: <991F9EEF-6363-4035-82FE-7FEAA8AD5083@cisco.com> Not sure about Infiniband, but costs for 10GE server access have come down to ~$800/port. Not bad considering 1GE is ~$300/port (on a good switch). Sent from my iPhone Brad Hedlund, CCIE 5530 Cisco Systems, Inc. Consulting System Engineer Data Center (773) 695-8226 On Apr 17, 2009, at 4:51 AM, "Chris Hills" wrote: > On 17/04/09 04:59, Justin C Darby wrote: >> Step 10.5: Curse about how much 10GbE costs, then remember how much >> Fiber >> Channel costs. > > Yet still you do not hear of much use of Infiniband. I believe at > the 2X rate (i.e. 10Gbs) it is cheaper than 10GbE. Did you consider > using it when embarking upon your approach? > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From hegedus.gabor at euroway.hu Fri Apr 17 09:28:22 2009 From: hegedus.gabor at euroway.hu (Hegedus Gabor) Date: Fri, 17 Apr 2009 15:28:22 +0200 Subject: [c-nsp] VPN 3000 certificate based S2S In-Reply-To: <49E6E490.6000302@euroway.hu> References: <49E6E490.6000302@euroway.hu> Message-ID: <49E883F6.80305@euroway.hu> any Idea? Hegedus Gabor wrote: > Hi all! > > I don't find answer to my question on the net. > > My problem is the following: > > > I have a cisco VPN 3000 device, and we want site-2-site vpn with this > device. > I got the root CA cert and I added it successfully. > I have our certificate what is in coded format .p12 file with password. > > How can I install this p12 file, because only cert request is allowed > on the VPN concentrator, I can't upload(install) my cert simply. I > tried it on ASA, and it works good, i can install root ca and my ca > both on it. > > I don't want send cert request to the root ca, cos I already have all > cert file. > > What can I do with my p12 ? convert it to what? What are extensions > and file formats the vpn3000 look out in identity cert section? > > any suggestion? > > > thank you, Gabor > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From rens at autempspourmoi.be Fri Apr 17 08:43:24 2009 From: rens at autempspourmoi.be (Rens) Date: Fri, 17 Apr 2009 14:43:24 +0200 Subject: [c-nsp] L2TPv3 with MTU difference Message-ID: <7A41C87ED8454252B78FF92B8C87205A@EU.corp.clearwire.com> Hi, I have an OSPF broadcast configured with several routers. Some of the routers have a higher MTU then others so I use ip ospf mtu ignore on all the neighbours. (to compensate with the fragmentation at higher bandwidths) I have routers with mtu 1600 and others have the default 1500 because of FastEthernet interfaces I have a L2TPv3 tunnel that runs over this IP network, when I configure a tunnel between a router that has 1600 & 1500 mtu I can't pass any frames of 1518 When doing 1518, the tester that is connected to the router that does 1600 is receiving them, but the tester that is connected to the router that does 1500 isn't receiving anything. When I lower it to 1280 it works again. All help welcome Regards, Rens From peter at rathlev.dk Fri Apr 17 10:31:43 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Fri, 17 Apr 2009 16:31:43 +0200 Subject: [c-nsp] C6k 6708 Input drops In-Reply-To: <9683A1EFE9214446A78BDA9EA8AF79DC9DBDECAF@NEUBOS3ES816CLS.nunet.neu.edu> References: <1239910552.3608.36.camel@localhost.localdomain> <20090417102043.GA80447@bts.sk> <9683A1EFE9214446A78BDA9EA8AF79DC9DBDECAF@NEUBOS3ES816CLS.nunet.neu.edu> Message-ID: <1239978703.3861.38.camel@localhost.localdomain> On Fri, 2009-04-17 at 12:20 +0200, Marian ?urkovi? wrote: > Input drops on L3 interfaces include also drops seen by the RP. > These are not happening on the physical 10GE interface, but on the > CPU's input queue. Try looking for traffic directed to the switch > itself (SNMP, routing protocols etc) or traffic which is being punted > to CPU for some reason. On Fri, 2009-04-17 at 09:41 -0400, Dhingra, Anand wrote: > I am not sure why... but for some odd reason cisco only has a 75 > packet buffer per interface going to the CPU. That was just the pieces of information I needed. I adjusted the hold-queue from 75 to 256 packets and the drops are now gone. Only thing left is to find out what those bursts are that the switch punts. But I'm very glad that there was an (easy to understand) explanation. :-) Thank you both of you! Regards, Peter From jcdarby at usgs.gov Fri Apr 17 10:56:55 2009 From: jcdarby at usgs.gov (Justin C Darby) Date: Fri, 17 Apr 2009 10:56:55 -0400 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: <49E84F9C.8060104@chaz6.com> References: <49E84F9C.8060104@chaz6.com>, <20090416224405.GA26216@stlux503.dsto.defence.gov.au>, Message-ID: AFAIK, 2x FC is 2.125 GBps (~200MB/s), we were quoting 4x FC as a comparison - 4.25GBps / ~400 MB/s. The 10GbE solution is a lot faster and at the time cost less than us deploying 4x FC. This was also a year ago. 4x FC was our top capability with Bladecenter H at the time. Justin -----cisco-nsp-bounces at puck.nether.net wrote: ----- To: cisco-nsp at puck.nether.net From: Chris Hills Sent by: cisco-nsp-bounces at puck.nether.net Date: 04/17/2009 04:51AM cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] Nexus 5K FCoE to FC breakout On 17/04/09 04:59, Justin C Darby wrote: > Step 10.5: Curse about how much 10GbE costs, then remember how much Fiber > Channel costs. Yet still you do not hear of much use of Infiniband. I believe at the 2X rate (i.e. 10Gbs) it is cheaper than 10GbE. Did you consider using it when embarking upon your approach? _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From tvarriale at comcast.net Fri Apr 17 11:23:57 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Fri, 17 Apr 2009 10:23:57 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout References: <49E84F9C.8060104@chaz6.com>, <20090416224405.GA26216@stlux503.dsto.defence.gov.au>, Message-ID: <49BF57CF89E84AE0B71D0395574BB310@flamdt01> It's still 4gbps FC with the CNAs. tv ----- Original Message ----- From: "Justin C Darby" To: Cc: Sent: Friday, April 17, 2009 9:56 AM Subject: Re: [c-nsp] Nexus 5K FCoE to FC breakout > > AFAIK, 2x FC is 2.125 GBps (~200MB/s), we were quoting 4x FC as a > comparison - 4.25GBps / ~400 MB/s. > > The 10GbE solution is a lot faster and at the time cost less than us > deploying 4x FC. This was also a year ago. 4x FC was our top capability > with Bladecenter H at the time. > > Justin > > -----cisco-nsp-bounces at puck.nether.net wrote: ----- > To: cisco-nsp at puck.nether.net > From: Chris Hills > Sent by: cisco-nsp-bounces at puck.nether.net > Date: 04/17/2009 04:51AM > cc: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] Nexus 5K FCoE to FC breakout > > On 17/04/09 04:59, Justin C Darby wrote: > Step 10.5: Curse about how much > 10GbE costs, then remember how much Fiber > Channel costs. Yet still you > do not hear of much use of Infiniband. I believe at the 2X rate (i.e. > 10Gbs) it is cheaper than 10GbE. Did you consider using it when embarking > upon your approach? _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp archive at > http://puck.nether.net/pipermail/cisco-nsp/ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From brhedlun at cisco.com Fri Apr 17 12:27:02 2009 From: brhedlun at cisco.com (Brad Hedlund) Date: Fri, 17 Apr 2009 11:27:02 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: <49BF57CF89E84AE0B71D0395574BB310@flamdt01> Message-ID: True, for the current generation (Gen1) Emulex and Qlogic C-N-A's. Gen2 adapters (available soon) are not restricted to 4gbps, there is more flexibility up to the full 10G. On 4/17/09 10:23 AM, "Tony Varriale" wrote: > It's still 4gbps FC with the CNAs. Brad Hedlund bhedlund at cisco.com http://www.internetworkexpert.org From gert at greenie.muc.de Fri Apr 17 12:49:20 2009 From: gert at greenie.muc.de (Gert Doering) Date: Fri, 17 Apr 2009 18:49:20 +0200 Subject: [c-nsp] CPU utilization - "media converter" vs "bump in the cable" In-Reply-To: <38154.69.30.17.85.1239908343.squirrel@www.woofpaws.com> References: <38154.69.30.17.85.1239908343.squirrel@www.woofpaws.com> Message-ID: <20090417164920.GX290@greenie.muc.de> Hi, On Thu, Apr 16, 2009 at 11:59:03AM -0700, Rick Ernst wrote: > I was a bit surprised to see that a 7206VXR/NPE-G1 running at the same CPU > utilization on both an ethernet upstream with ~300mbs (in+out) running > through it and an OC-3 upstream with about 100mbs through it. GigE is wired directly to the CPU (part of the CPU, actually) while PA modules are PCI based. So it wouldn't surprise me if GigE based things take a lot less CPU on the NPE-G1. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From tvarriale at comcast.net Fri Apr 17 13:20:02 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Fri, 17 Apr 2009 12:20:02 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout References: Message-ID: <73C8458323674E879355A98BA28A910B@flamdt01> Even when they do come out, there's won't be tons of benefit yet. Most of the SANs I see today are 4gbps and are having a tough time justifying going to 8. tv ----- Original Message ----- From: "Brad Hedlund" To: "Tony Varriale" ; Sent: Friday, April 17, 2009 11:27 AM Subject: Re: [c-nsp] Nexus 5K FCoE to FC breakout > True, for the current generation (Gen1) Emulex and Qlogic C-N-A's. > Gen2 adapters (available soon) are not restricted to 4gbps, there is more > flexibility up to the full 10G. > > On 4/17/09 10:23 AM, "Tony Varriale" wrote: > >> It's still 4gbps FC with the CNAs. > > > > Brad Hedlund > bhedlund at cisco.com > http://www.internetworkexpert.org > From brhedlun at cisco.com Fri Apr 17 13:41:24 2009 From: brhedlun at cisco.com (Brad Hedlund) Date: Fri, 17 Apr 2009 12:41:24 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: <73C8458323674E879355A98BA28A910B@flamdt01> Message-ID: To your point, exceeding 4gbps per C-N-A is nice but doesn't top the list of major benefits for Gen2. What does top the list is a single chip architecture providing a smaller size and lower power footprint, which also works nicely for blade server mezzanine form factors. Benefits for C-N-A's are largely centered around cost and efficiency optimizations, rather than performance optimizations. On 4/17/09 12:20 PM, "Tony Varriale" wrote: > Even when they do come out, there's won't be tons of benefit yet. Most of > the SANs I see today are 4gbps and are having a tough time justifying going > to 8. Brad Hedlund bhedlund at cisco.com http://www.internetworkexpert.org From tvarriale at comcast.net Fri Apr 17 15:27:16 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Fri, 17 Apr 2009 14:27:16 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout References: Message-ID: <7CD18D03B4D44CFC86FD19E6C69C45F4@flamdt01> Gen 1 already offers this. :) tv ----- Original Message ----- From: "Brad Hedlund" To: "Tony Varriale" ; Sent: Friday, April 17, 2009 12:41 PM Subject: Re: [c-nsp] Nexus 5K FCoE to FC breakout > To your point, exceeding 4gbps per C-N-A is nice but doesn't top the list > of > major benefits for Gen2. > What does top the list is a single chip architecture providing a smaller > size and lower power footprint, which also works nicely for blade server > mezzanine form factors. > > Benefits for C-N-A's are largely centered around cost and efficiency > optimizations, rather than performance optimizations. > > > On 4/17/09 12:20 PM, "Tony Varriale" wrote: > >> Even when they do come out, there's won't be tons of benefit yet. Most >> of >> the SANs I see today are 4gbps and are having a tough time justifying >> going >> to 8. > > > > Brad Hedlund > bhedlund at cisco.com > http://www.internetworkexpert.org > > > > From brhedlun at cisco.com Fri Apr 17 15:52:06 2009 From: brhedlun at cisco.com (Brad Hedlund) Date: Fri, 17 Apr 2009 14:52:06 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: <7CD18D03B4D44CFC86FD19E6C69C45F4@flamdt01> Message-ID: Not sure what you are specifically referring to but Gen1 C-N-A's are based on 3 chip's (1) Eth, (1) FC, (1) DCE "Menlo". As a result, Gen1 cards are long and do not fit in most 1RU systems. The power draw of the 3 chip design is around 21W. Gen2 C-N-A's combine the functionality of all three chips into 1 custom ASIC. As a result Gen2's will fit in 1RU systems and power draw is in the low teens. Lots of buzz about this can be found on Emulex and Qlogic websites. The Emulex and Qlogic mezz C-N-A's initially available for Cisco UCS are based on the Gen1 design. Maybe that is what you are referring to? Cheers, Brad Hedlund bhedlund at cisco.com http://www.internetworkexpert.org On 4/17/09 2:27 PM, "Tony Varriale" wrote: > Gen 1 already offers this. :) > > tv From justin at justinshore.com Fri Apr 17 16:09:09 2009 From: justin at justinshore.com (Justin Shore) Date: Fri, 17 Apr 2009 15:09:09 -0500 Subject: [c-nsp] need help about switch cisco 4 9 4 8 In-Reply-To: <75032a710904161556m1590ec95jf09843eaae3db285@mail.gmail.com> References: <753ED4F9715A45ABADBDB9DC23C1FCA8@int.convex.pt> <28011.1317.qm@web57404.mail.re1.yahoo.com> <5E3C7A341C9C41F5BD5FE75FC12704B1@int.convex.pt> <49A030E9.5040009@kenweb.org> <75032a710904161556m1590ec95jf09843eaae3db285@mail.gmail.com> Message-ID: <49E8E1E5.7020802@justinshore.com> I've learned to always specify the full path to the image you want to load. It's safer than assuming that rommon will find the image on its own on the assortment of drives that the newer, larger devices have these days. Justin Paul Zugnoni wrote: > fwiw, (nearly 2 months later) on our 4948: > "boot system flash cat4500-ipbasek9-mz.122-31.SGA8.bin" with a > config-register of 0x2102 resulted in the switch booting into rommon mode, > with an error message on the console that the device was not specified. > > Upon removing that configuration statement and replacing it with the > following one, the 4948 booted as expected: > boot system flash bootflash:cat4500-ipbasek9-mz.122-31.SGA8.bin << notice > the specification of bootflash: in front of the image name. From amsoares at netcabo.pt Fri Apr 17 16:40:27 2009 From: amsoares at netcabo.pt (Antonio Soares) Date: Fri, 17 Apr 2009 21:40:27 +0100 Subject: [c-nsp] C6k 6708 Input drops In-Reply-To: <1239978703.3861.38.camel@localhost.localdomain> References: <1239910552.3608.36.camel@localhost.localdomain><20090417102043.GA80447@bts.sk><9683A1EFE9214446A78BDA9EA8AF79DC9DBDECAF@NEUBOS3ES816CLS.nunet.neu.edu> <1239978703.3861.38.camel@localhost.localdomain> Message-ID: <8812BD4AE16D4601BA90D9938AE7E353@int.convex.pt> I had the same type of problem weeks ago with 6704-10GE cards and i increased the input queue from the default to 2000 packets. But even with this change, i'm still getting input drops: +++++++++++++++++++++++ Input queue: 0/2000/259854/259783 (size/max/drops/flushes); Total output drops: 9766 Queueing strategy: fifo Output queue: 0/40 (size/max) 30 second input rate 3422174000 bits/sec, 616164 packets/sec 30 second output rate 4781032000 bits/sec, 752303 packets/sec L2 Switched: ucast: 3042490 pkt, 445190705 bytes - mcast: 701412 pkt, 55025811 bytes L3 in Switched: ucast: 1443288206417 pkt, 1002589303485288 bytes - mcast: 0 pkt, 0 bytes mcast L3 out Switched: ucast: 1777516490092 pkt, 1475677965625289 bytes mcast: 0 pkt, 0 bytes 1443204358757 packets input, 1002494751199418 bytes, 0 no buffer Received 755421 broadcasts (701411 IP multicasts) 0 runts, 0 giants, 0 throttles 18 input errors, 9 CRC, 9 frame, 0 overrun, 0 ignored 0 watchdog, 0 multicast, 0 pause input 0 input packets with dribble condition detected 1777485270815 packets output, 1475594581103091 bytes, 0 underruns 0 output errors, 0 collisions, 0 interface resets 0 babbles, 0 late collision, 0 deferred 0 lost carrier, 0 no carrier, 0 PAUSE output 0 output buffer failures, 0 output buffers swapped out +++++++++++++++++++++++ And sometimes the IGP adjacency goes down and i only can correlate with these input drops. I'm running 12.2(18)SXF15a. I have the impression that even using the maximum value allowed won't solve the issue. I'm now thinking about adjusting the SPD values in order to, at least, avoid the IGP issue. Comments are appreciated. Thanks. Antonio Soares, CCIE #18473 (R&S) amsoares at netcabo.pt -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Peter Rathlev Sent: sexta-feira, 17 de Abril de 2009 15:32 To: Dhingra, Anand; Marian ?urkovi? Cc: cisco-nsp Subject: Re: [c-nsp] C6k 6708 Input drops On Fri, 2009-04-17 at 12:20 +0200, Marian ?urkovi? wrote: > Input drops on L3 interfaces include also drops seen by the RP. > These are not happening on the physical 10GE interface, but on the > CPU's input queue. Try looking for traffic directed to the switch > itself (SNMP, routing protocols etc) or traffic which is being punted > to CPU for some reason. On Fri, 2009-04-17 at 09:41 -0400, Dhingra, Anand wrote: > I am not sure why... but for some odd reason cisco only has a 75 > packet buffer per interface going to the CPU. That was just the pieces of information I needed. I adjusted the hold-queue from 75 to 256 packets and the drops are now gone. Only thing left is to find out what those bursts are that the switch punts. But I'm very glad that there was an (easy to understand) explanation. :-) Thank you both of you! Regards, Peter _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From tvarriale at comcast.net Fri Apr 17 16:43:09 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Fri, 17 Apr 2009 15:43:09 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout References: Message-ID: <1607B013034B476DB444860E7B575546@flamdt01> I honestly do not know anyone putting these into 1U systems. But, part (but not all) of the reference is to UCS. The inital green pitch on the CNA is that the SFP+ draws less power than x2 or XENPAK. Every server has to have a FC and *gig NIC. At this point that's the savings along with one card. The pitch to move from gen 1 to 2 to save another ~10W per card isn't being made yet. Anyways, I believe the original discussion was about speed. tv ----- Original Message ----- From: "Brad Hedlund" To: "Tony Varriale" ; Sent: Friday, April 17, 2009 2:52 PM Subject: Re: [c-nsp] Nexus 5K FCoE to FC breakout > Not sure what you are specifically referring to but Gen1 C-N-A's are based > on 3 chip's (1) Eth, (1) FC, (1) DCE "Menlo". > As a result, Gen1 cards are long and do not fit in most 1RU systems. The > power draw of the 3 chip design is around 21W. > Gen2 C-N-A's combine the functionality of all three chips into 1 custom > ASIC. As a result Gen2's will fit in 1RU systems and power draw is in the > low teens. Lots of buzz about this can be found on Emulex and Qlogic > websites. > > The Emulex and Qlogic mezz C-N-A's initially available for Cisco UCS are > based on the Gen1 design. Maybe that is what you are referring to? > > Cheers, > > Brad Hedlund > bhedlund at cisco.com > http://www.internetworkexpert.org > > > On 4/17/09 2:27 PM, "Tony Varriale" wrote: > >> Gen 1 already offers this. :) >> >> tv > > From brhedlun at cisco.com Fri Apr 17 17:16:43 2009 From: brhedlun at cisco.com (Brad Hedlund) Date: Fri, 17 Apr 2009 16:16:43 -0500 Subject: [c-nsp] Nexus 5K FCoE to FC breakout In-Reply-To: <1607B013034B476DB444860E7B575546@flamdt01> Message-ID: On 4/17/09 3:43 PM, "Tony Varriale" wrote: > I honestly do not know anyone putting these into 1U systems. Primary reason for this is because current Gen1 C-N-A's simply do not fit in 1RU systems. Where 2-4RU systems are purchased for the primary reason of adapter real estate, the Gen2 C-N-A's offer a path to 1RU. > The inital green pitch on the CNA is that the SFP+ draws less power than x2 > or XENPAK. Not to mention less power in connecting to the server to one access layer switch fabric, rather than two. > The pitch to move from gen 1 to 2 to save another ~10W per card isn't being > made yet. Right, the pitch is largely: "same price, smaller, more capabilities, and oh by the way, less power". > Anyways, I believe the original discussion was about speed. Of which there is no disadvantage in C-N-A's ... which lead us to this tangent :) Brad Hedlund bhedlund at cisco.com http://www.internetworkexpert.org From neilding2000 at gmail.com Fri Apr 17 22:04:17 2009 From: neilding2000 at gmail.com (Neil d) Date: Fri, 17 Apr 2009 22:04:17 -0400 Subject: [c-nsp] cisco command to show 10GE module type? Message-ID: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> Hi all, Is there any command to show what kind of Xenpak 10G module in the 6704-10GE card? from cisco website, there're a bunch of them: Cisco XENPAK-10GB-CX4: . ? Cisco XENPAK-10GB-LX4: ? Cisco XENPAK-10GB-LRM: ? Cisco XENPAK-10GB-SR: ? Cisco XENPAK-10GB-LR / -LR+: ? Cisco XENPAK-10GB-ER / -ER+ ? Cisco XENPAK-10GB-ZR: ? Cisco XENPAK-10GB-LW (WAN PHY): question is, how do I know which type is installed in the LC? any command to check this instead of going onsite to check? TIA/Neil From wmaton at ryouko.imsb.nrc.ca Fri Apr 17 22:10:04 2009 From: wmaton at ryouko.imsb.nrc.ca (William F. Maton Sotomayor) Date: Fri, 17 Apr 2009 22:10:04 -0400 (EDT) Subject: [c-nsp] cisco command to show 10GE module type? In-Reply-To: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> References: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> Message-ID: On Fri, 17 Apr 2009, Neil d wrote: > Is there any command to show what kind of Xenpak 10G module in the 6704-10GE > card? from cisco website, there're a bunch of them: [snip] > question is, how do I know which type is installed in the LC? any command to > check this instead of going onsite to check? "show inventory" may help. wfms From neilding2000 at gmail.com Fri Apr 17 22:14:41 2009 From: neilding2000 at gmail.com (Neil d) Date: Fri, 17 Apr 2009 22:14:41 -0400 Subject: [c-nsp] cisco command to show 10GE module type? In-Reply-To: References: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> Message-ID: <68f87c470904171914k2cf5459dr1ebaa473c4458a65@mail.gmail.com> no good, I've already tried this, but it only show you the linecard type in each slot, what I want to know is the Xenpak module type in each 10GE port. On Fri, Apr 17, 2009 at 10:10 PM, William F. Maton Sotomayor < wmaton at ryouko.imsb.nrc.ca> wrote: > On Fri, 17 Apr 2009, Neil d wrote: > > Is there any command to show what kind of Xenpak 10G module in the >> 6704-10GE >> card? from cisco website, there're a bunch of them: >> > [snip] > >> question is, how do I know which type is installed in the LC? any command >> to >> check this instead of going onsite to check? >> > > "show inventory" may help. > > wfms > From neilding2000 at gmail.com Fri Apr 17 22:17:50 2009 From: neilding2000 at gmail.com (Neil d) Date: Fri, 17 Apr 2009 22:17:50 -0400 Subject: [c-nsp] cisco command to show 10GE module type? In-Reply-To: <68f87c470904171914k2cf5459dr1ebaa473c4458a65@mail.gmail.com> References: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> <68f87c470904171914k2cf5459dr1ebaa473c4458a65@mail.gmail.com> Message-ID: <68f87c470904171917w4c677a52pd50cd84fe7b2b942@mail.gmail.com> oh, a show inventory raw seems work.... On Fri, Apr 17, 2009 at 10:14 PM, Neil d wrote: > no good, I've already tried this, but it only show you the linecard type in > each slot, what I want to know is the Xenpak module type in each 10GE port. > > > On Fri, Apr 17, 2009 at 10:10 PM, William F. Maton Sotomayor < > wmaton at ryouko.imsb.nrc.ca> wrote: > >> On Fri, 17 Apr 2009, Neil d wrote: >> >> Is there any command to show what kind of Xenpak 10G module in the >>> 6704-10GE >>> card? from cisco website, there're a bunch of them: >>> >> [snip] >> >>> question is, how do I know which type is installed in the LC? any command >>> to >>> check this instead of going onsite to check? >>> >> >> "show inventory" may help. >> >> wfms >> > > From rrichardson at iodatacenters.com Fri Apr 17 22:20:20 2009 From: rrichardson at iodatacenters.com (Richardson, Robert) Date: Fri, 17 Apr 2009 19:20:20 -0700 Subject: [c-nsp] cisco command to show 10GE module type? In-Reply-To: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> References: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> Message-ID: <57F018B226E004449B318DAF71A6014656F63D382D@IO-SCD-EX-M-01.corp.iodatacenters.com> Try: show interface status show inventory Thanks, Robert M. Richardson -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Neil d Sent: Friday, April 17, 2009 7:04 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] cisco command to show 10GE module type? Hi all, Is there any command to show what kind of Xenpak 10G module in the 6704-10GE card? from cisco website, there're a bunch of them: Cisco XENPAK-10GB-CX4: . * Cisco XENPAK-10GB-LX4: * Cisco XENPAK-10GB-LRM: * Cisco XENPAK-10GB-SR: * Cisco XENPAK-10GB-LR / -LR+: * Cisco XENPAK-10GB-ER / -ER+ * Cisco XENPAK-10GB-ZR: * Cisco XENPAK-10GB-LW (WAN PHY): question is, how do I know which type is installed in the LC? any command to check this instead of going onsite to check? TIA/Neil _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From engel.labiro at gmail.com Sat Apr 18 00:41:57 2009 From: engel.labiro at gmail.com (Engelhard Labiro) Date: Sat, 18 Apr 2009 13:41:57 +0900 Subject: [c-nsp] cisco command to show 10GE module type? In-Reply-To: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> References: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> Message-ID: Use command "show int status" Sent from my iPhone On 2009/04/18, at 11:04, Neil d wrote: > Hi all, > > Is there any command to show what kind of Xenpak 10G module in the > 6704-10GE > card? from cisco website, there're a bunch of them: > > Cisco XENPAK-10GB-CX4: . > ? Cisco XENPAK-10GB-LX4: > ? Cisco XENPAK-10GB-LRM: > ? Cisco XENPAK-10GB-SR: > ? Cisco XENPAK-10GB-LR / -LR+: > ? Cisco XENPAK-10GB-ER / -ER+ > ? Cisco XENPAK-10GB-ZR: > ? Cisco XENPAK-10GB-LW (WAN PHY): > > question is, how do I know which type is installed in the LC? any > command to > check this instead of going onsite to check? > > TIA/Neil > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From ler762 at gmail.com Sat Apr 18 06:22:53 2009 From: ler762 at gmail.com (Lee) Date: Sat, 18 Apr 2009 06:22:53 -0400 Subject: [c-nsp] C6k 6708 Input drops In-Reply-To: <8812BD4AE16D4601BA90D9938AE7E353@int.convex.pt> References: <1239910552.3608.36.camel@localhost.localdomain> <20090417102043.GA80447@bts.sk> <9683A1EFE9214446A78BDA9EA8AF79DC9DBDECAF@NEUBOS3ES816CLS.nunet.neu.edu> <1239978703.3861.38.camel@localhost.localdomain> <8812BD4AE16D4601BA90D9938AE7E353@int.convex.pt> Message-ID: We weren't losing adjacencies, but were seeing lots of input queue drops on a few 6704 ports configured as layer3 interfaces. Bumping the input queue size up to 4096 didn't make any difference, nor did changing the input queue size on all vlan+L3 interfaces to 4096 (which should have automatically adjusted spd thresholds) make any difference. But adding this got rid of almost all the drops: ip spd queue max-threshold 1000 ip spd queue min-threshold 998 I don't remember getting an answer from Cisco about why the spd thresholds weren't automatically adjusted on a 6500. I tried changing the input q size on all interfaces on a 7200 & spd thresholds were automatically adjusted. Dunno why it doesn't work on a 6500. Lee On 4/17/09, Antonio Soares wrote: > I had the same type of problem weeks ago with 6704-10GE cards and i > increased the input queue from the default to 2000 packets. But > even with this change, i'm still getting input drops: > > +++++++++++++++++++++++ > Input queue: 0/2000/259854/259783 (size/max/drops/flushes); Total output > drops: 9766 > Queueing strategy: fifo > Output queue: 0/40 (size/max) > 30 second input rate 3422174000 bits/sec, 616164 packets/sec > 30 second output rate 4781032000 bits/sec, 752303 packets/sec > L2 Switched: ucast: 3042490 pkt, 445190705 bytes - mcast: 701412 pkt, > 55025811 bytes > L3 in Switched: ucast: 1443288206417 pkt, 1002589303485288 bytes - mcast: > 0 pkt, 0 bytes mcast > L3 out Switched: ucast: 1777516490092 pkt, 1475677965625289 bytes mcast: 0 > pkt, 0 bytes > 1443204358757 packets input, 1002494751199418 bytes, 0 no buffer > Received 755421 broadcasts (701411 IP multicasts) > 0 runts, 0 giants, 0 throttles > 18 input errors, 9 CRC, 9 frame, 0 overrun, 0 ignored > 0 watchdog, 0 multicast, 0 pause input > 0 input packets with dribble condition detected > 1777485270815 packets output, 1475594581103091 bytes, 0 underruns > 0 output errors, 0 collisions, 0 interface resets > 0 babbles, 0 late collision, 0 deferred > 0 lost carrier, 0 no carrier, 0 PAUSE output > 0 output buffer failures, 0 output buffers swapped out > +++++++++++++++++++++++ > > And sometimes the IGP adjacency goes down and i only can correlate with > these input drops. I'm running 12.2(18)SXF15a. > > I have the impression that even using the maximum value allowed won't solve > the issue. > > I'm now thinking about adjusting the SPD values in order to, at least, avoid > the IGP issue. > > Comments are appreciated. > > > > Thanks. > > Antonio Soares, CCIE #18473 (R&S) > amsoares at netcabo.pt > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Peter Rathlev > Sent: sexta-feira, 17 de Abril de 2009 15:32 > To: Dhingra, Anand; Marian ?urkovi? > Cc: cisco-nsp > Subject: Re: [c-nsp] C6k 6708 Input drops > > On Fri, 2009-04-17 at 12:20 +0200, Marian ?urkovi? wrote: >> Input drops on L3 interfaces include also drops seen by the RP. >> These are not happening on the physical 10GE interface, but on the >> CPU's input queue. Try looking for traffic directed to the switch >> itself (SNMP, routing protocols etc) or traffic which is being punted >> to CPU for some reason. > > On Fri, 2009-04-17 at 09:41 -0400, Dhingra, Anand wrote: >> I am not sure why... but for some odd reason cisco only has a 75 >> packet buffer per interface going to the CPU. > > That was just the pieces of information I needed. I adjusted the hold-queue > from 75 to 256 packets and the drops are now gone. > > Only thing left is to find out what those bursts are that the switch punts. > But I'm very glad that there was an (easy to understand) > explanation. :-) > > Thank you both of you! > > Regards, > Peter > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From nick.jon.griffin at gmail.com Sat Apr 18 10:21:09 2009 From: nick.jon.griffin at gmail.com (Nick Griffin) Date: Sat, 18 Apr 2009 09:21:09 -0500 Subject: [c-nsp] cisco command to show 10GE module type? In-Reply-To: References: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> Message-ID: can you use "show interface capabilities"? On Fri, Apr 17, 2009 at 11:41 PM, Engelhard Labiro wrote: > Use command "show int status" > > Sent from my iPhone > > > On 2009/04/18, at 11:04, Neil d wrote: > > Hi all, >> >> Is there any command to show what kind of Xenpak 10G module in the >> 6704-10GE >> card? from cisco website, there're a bunch of them: >> >> Cisco XENPAK-10GB-CX4: . >> ? Cisco XENPAK-10GB-LX4: >> ? Cisco XENPAK-10GB-LRM: >> ? Cisco XENPAK-10GB-SR: >> ? Cisco XENPAK-10GB-LR / -LR+: >> ? Cisco XENPAK-10GB-ER / -ER+ >> ? Cisco XENPAK-10GB-ZR: >> ? Cisco XENPAK-10GB-LW (WAN PHY): >> >> question is, how do I know which type is installed in the LC? any command >> to >> check this instead of going onsite to check? >> >> TIA/Neil >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From pwu828 at gmail.com Sat Apr 18 15:39:10 2009 From: pwu828 at gmail.com (PW) Date: Sun, 19 Apr 2009 05:39:10 +1000 Subject: [c-nsp] RSTP Learning State Message-ID: Hi Everyone, It would be great if someone can help me out here... I've got a situation here with 4 switches (a mix of 2960/3550), all running RSTP (rapid-pvst). The setup: Switch C --------- Switch B ======= Switch A | | | | Switch D --------------| Basically a triangle setup BCD, and a dual link between AB. Switch A is the root, and when the primary link between AB fails, the root port of B goes down, transitions to ALT link almost instanteously. However, the spanning tree recalculation that occurs in the triangle BCD baffles me... I see links between Switch B, C and D transitions into the Learning state for 15 seconds! I thought RSTP should be sub-second failover for P2P links, so I'm not sure why this 15 seconds is coming up... The spanning tree state under normal operation: Switch A: Fa0/1 Desg FWD 36 128.1 P2p (Secondary to B) Fa0/2 Desg FWD 4 128.2 P2p (Primary to B) Switch B: Fa0/1 Desg FWD 5000 128.1 P2p (to D) Fa0/2 Altn BLK 200 128.2 P2p (Secondary to A) Fa0/3 Root FWD 5 128.3 P2p (Primary to A) Fa0/4 Desg FWD 19 128.4 P2p (to C) Switch C: Fa0/1 Altn BLK 200 128.1 P2p (to D) Fa0/2 Root FWD 10 128.2 P2p (to B) Switch D: Fa0/1 Desg FWD 400 128.1 P2p (to C) Fa0/2 Root FWD 10 128.2 P2p (to B) There is nothing fancy about the RSTP configuration but setting port costs to reflect the desired primary path. Ports are all trunk ports, without "spanning-tree portfast trunk" configured. My questions are: - Why are the ports in Learning state for 15 secs? - Is it possible to reduce/eliminate this 15 secs? Any help will be much appreciated! Thanks. PW From jensenja at gmail.com Sun Apr 19 02:37:38 2009 From: jensenja at gmail.com (John Jensen) Date: Sat, 18 Apr 2009 23:37:38 -0700 Subject: [c-nsp] cisco command to show 10GE module type? In-Reply-To: References: <68f87c470904171904w7aa4ce04x492c728bd9c8baef@mail.gmail.com> Message-ID: <6de481d10904182337r43330883qe0ae45b5a0195c6d@mail.gmail.com> "show int status" will give you the transceiver type, if you want more gory details, you can use "show idprom int x/x" which will give you the serial and more info of a particular transceiver. -JJ On Sat, Apr 18, 2009 at 7:21 AM, Nick Griffin wrote: > can you use "show interface capabilities"? > > On Fri, Apr 17, 2009 at 11:41 PM, Engelhard Labiro > wrote: > >> Use command "show int status" >> >> Sent from my iPhone >> >> >> On 2009/04/18, at 11:04, Neil d wrote: >> >> ?Hi all, >>> >>> Is there any command to show what kind of Xenpak 10G module in the >>> 6704-10GE >>> card? from cisco website, there're a bunch of them: >>> >>> Cisco XENPAK-10GB-CX4: . >>> ? Cisco XENPAK-10GB-LX4: >>> ? Cisco XENPAK-10GB-LRM: >>> ? Cisco XENPAK-10GB-SR: >>> ? Cisco XENPAK-10GB-LR / -LR+: >>> ? Cisco XENPAK-10GB-ER / -ER+ >>> ? Cisco XENPAK-10GB-ZR: >>> ? Cisco XENPAK-10GB-LW (WAN PHY): >>> >>> question is, how do I know which type is installed in the LC? any command >>> to >>> check this instead of going onsite to check? >>> >>> TIA/Neil >>> _______________________________________________ >>> cisco-nsp mailing list ?cisco-nsp at puck.nether.net >>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>> >> _______________________________________________ >> cisco-nsp mailing list ?cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From jensenja at gmail.com Sun Apr 19 03:05:30 2009 From: jensenja at gmail.com (John Jensen) Date: Sun, 19 Apr 2009 00:05:30 -0700 Subject: [c-nsp] C6kSup720 "LAN ONLY" vs. "WAN" In-Reply-To: <1239908737.3608.5.camel@localhost.localdomain> References: <1239908737.3608.5.camel@localhost.localdomain> Message-ID: <6de481d10904190005n3d8aa34aj42c9bf909bfd7920@mail.gmail.com> I checked Cisco's feature navigator and couldn't find any differences in supported features between the images, so maybe the differences are only in hardware support. -JJ On Thu, Apr 16, 2009 at 12:05 PM, Peter Rathlev wrote: > Hi, > > Could anybody explain to me where I can find some official documentation > about the differences between a "LAN ONLY" and a WAN image for the > Sup720? E.g. the difference between these two images: > > s72033-advipservicesk9-mz.122-33.SXI1.bin > s72033-advipservicesk9_wan-mz.122-33.SXI1.bin > > The former is a meagre 59MB where the latter takes up 90MB. I've assumed > that certain WAN modules like OSM cannot run in the "LAN ONLY" image, > but I'd love to know where I could know exactly what can and cannot run > in the "LAN ONLY" image. > > Thank you. > Peter > > > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From jensenja at gmail.com Sun Apr 19 03:12:08 2009 From: jensenja at gmail.com (John Jensen) Date: Sun, 19 Apr 2009 00:12:08 -0700 Subject: [c-nsp] VTY Lines In-Reply-To: References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> Message-ID: <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> I was under the impression that the "service tcp-keepalives-in" and "service tcp-keepalives-out" commands will prevent this from happening to your VTYs. -JJ On Thu, Apr 16, 2009 at 6:08 AM, Lee wrote: > On 4/16/09, Eric Van Tol wrote: >>> -----Original Message----- >>> From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- >>> bounces at puck.nether.net] On Behalf Of Dracul >>> Sent: Thursday, April 16, 2009 12:19 AM >>> To: cisco-nsp at puck.nether.net >>> Subject: Re: [c-nsp] VTY Lines >>> >>> If you are running a critical network without the convenience of >>> rebooting, >>> Jim's Router# cle ip tcp tcb 58F2E668 worked for me >>> >>> but take note some IOS use the Router#clear tcp tcb ?(without the 'ip') >>> >>> regards, >>> chris >> >> If you can't gain access to the CLI, it is possible to reset vty TCP >> sessions using SNMP, assuming you have a read-write string configured on the >> device. ?I personally don't know the procedure, but there are tools out >> there such as the Solarwinds Engineers Edition toolset that let you do this. >> ?If anyone knows the right procedure, maybe they can post it here. > > How to Detect and Clear Hung TCP Connections using SNMP > > http://www.cisco.com/en/US/tech/tk648/tk362/technologies_problem_troubleshooting09186a00802b93ef.shtml > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From achatz at forthnet.gr Sun Apr 19 08:34:07 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Sun, 19 Apr 2009 15:34:07 +0300 Subject: [c-nsp] C6kSup720 "LAN ONLY" vs. "WAN" In-Reply-To: <6de481d10904190005n3d8aa34aj42c9bf909bfd7920@mail.gmail.com> References: <1239908737.3608.5.camel@localhost.localdomain> <6de481d10904190005n3d8aa34aj42c9bf909bfd7920@mail.gmail.com> Message-ID: <49EB1A3F.80509@forthnet.gr> According to Software Advisor you need the wan image for OSM cards (like you said). Interestingly enough, SIPs/SPAs do not seem to need it. Nevertheless, it's hard to believe that OSMs are responsible for the additional 33% of -compressed- code! -- Tassos John Jensen wrote on 19/04/2009 10:05: > I checked Cisco's feature navigator and couldn't find any differences > in supported features between the images, so maybe the differences are > only in hardware support. > > -JJ > > On Thu, Apr 16, 2009 at 12:05 PM, Peter Rathlev wrote: >> Hi, >> >> Could anybody explain to me where I can find some official documentation >> about the differences between a "LAN ONLY" and a WAN image for the >> Sup720? E.g. the difference between these two images: >> >> s72033-advipservicesk9-mz.122-33.SXI1.bin >> s72033-advipservicesk9_wan-mz.122-33.SXI1.bin >> >> The former is a meagre 59MB where the latter takes up 90MB. I've assumed >> that certain WAN modules like OSM cannot run in the "LAN ONLY" image, >> but I'd love to know where I could know exactly what can and cannot run >> in the "LAN ONLY" image. >> >> Thank you. >> Peter >> >> >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From ler762 at gmail.com Sun Apr 19 08:53:48 2009 From: ler762 at gmail.com (Lee) Date: Sun, 19 Apr 2009 08:53:48 -0400 Subject: [c-nsp] VTY Lines In-Reply-To: <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> Message-ID: On 4/19/09, John Jensen wrote: > I was under the impression that the "service tcp-keepalives-in" and > "service tcp-keepalives-out" commands will prevent this from happening > to your VTYs. No necessarily. Tcp keepalives will only kill a connection if the other side doesn't answer. But what happens when your Ciscoworks machine has a bad script that never exits? Every minutes it ssh's in and leaves the connection open. Router sends a keepalive, CW answers, VTY stays open. After a while all the VTYs are in use.. What I'd like to know is what extra protection "service tcp-keepalives-in" gives you that the exec-timeout on the VTYs doesn't. Lee > > -JJ > > On Thu, Apr 16, 2009 at 6:08 AM, Lee wrote: >> On 4/16/09, Eric Van Tol wrote: >>>> -----Original Message----- >>>> From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- >>>> bounces at puck.nether.net] On Behalf Of Dracul >>>> Sent: Thursday, April 16, 2009 12:19 AM >>>> To: cisco-nsp at puck.nether.net >>>> Subject: Re: [c-nsp] VTY Lines >>>> >>>> If you are running a critical network without the convenience of >>>> rebooting, >>>> Jim's Router# cle ip tcp tcb 58F2E668 worked for me >>>> >>>> but take note some IOS use the Router#clear tcp tcb (without the 'ip') >>>> >>>> regards, >>>> chris >>> >>> If you can't gain access to the CLI, it is possible to reset vty TCP >>> sessions using SNMP, assuming you have a read-write string configured on >>> the >>> device. I personally don't know the procedure, but there are tools out >>> there such as the Solarwinds Engineers Edition toolset that let you do >>> this. >>> If anyone knows the right procedure, maybe they can post it here. >> >> How to Detect and Clear Hung TCP Connections using SNMP >> >> http://www.cisco.com/en/US/tech/tk648/tk362/technologies_problem_troubleshooting09186a00802b93ef.shtml >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> From peter at rathlev.dk Sun Apr 19 09:25:51 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Sun, 19 Apr 2009 15:25:51 +0200 Subject: [c-nsp] C6kSup720 "LAN ONLY" vs. "WAN" In-Reply-To: <49EB1A3F.80509@forthnet.gr> References: <1239908737.3608.5.camel@localhost.localdomain> <6de481d10904190005n3d8aa34aj42c9bf909bfd7920@mail.gmail.com> <49EB1A3F.80509@forthnet.gr> Message-ID: <1240147551.3574.2.camel@localhost.localdomain> On Sun, 2009-04-19 at 15:34 +0300, Tassos Chatzithomaoglou wrote: > According to Software Advisor you need the wan image for OSM cards > (like you said). Interestingly enough, SIPs/SPAs do not seem to need > it. Nevertheless, it's hard to believe that OSMs are responsible for > the additional 33% of -compressed- code! I tried asking our SE and he replied that FlexWAN, FlexWAN Enhanced, OSM, SIP and IPSec SPA all need the WAN images. No link for any documentation stating this though. :-| But do SIP cards work in "LAN ONLY" images? Regards, Peter From ross at kallisti.us Sun Apr 19 10:47:40 2009 From: ross at kallisti.us (Ross Vandegrift) Date: Sun, 19 Apr 2009 10:47:40 -0400 Subject: [c-nsp] RSTP Learning State In-Reply-To: References: Message-ID: <20090419144740.GA12025@kallisti.us> On Sun, Apr 19, 2009 at 05:39:10AM +1000, PW wrote: > Switch A is the root, and when the primary link between AB fails, the root > port of B goes down, transitions to ALT link almost instanteously. > > However, the spanning tree recalculation that occurs in the triangle BCD > baffles me... I see links between Switch B, C and D transitions into the > Learning state for 15 seconds! > I thought RSTP should be sub-second failover for P2P links, so I'm not sure > why this 15 seconds is coming up... A useful analogy is given in 802.1D. When the root priority of a bridge changes, a cut is placed in the network at all of the non-root ports on the bridge that changed. Each iteration of the STP vector propogation process pushes the cut out to the next bridge. This process repeats until it reaches the edge ports of the extended LAN. For each port, the bridge computes a vector that represents that port's priority to be the root port. When you change Switch A's root port, the priority vector for the downstream ports changes, meaning that the downstream bridges need to engage loop prevention to ensure that any loops in the new topology are detected before bringing the ports into the forwarding state. > My questions are: > - Why are the ports in Learning state for 15 secs? > - Is it possible to reduce/eliminate this 15 secs? The delay is crucial for STP's ability to detect and migitage transient loops that may form during the computation of the new logical topology. You could try tuning your forward delay (the unit of time STP delays before moving forward in the port state machine), but you need to be careful. Too short, and you'll have ports moving to forwarding before the loops are removed. Looking at your topology, it doesn't make much sense for Switch A to be the root. Think about the analogy given above - you want to minimize the maximal distance from the root bridge to the edge ports. That'll reduce your total convergence time. Switch B is just extra distance toward the root. To understand why STP has this behavior, imagine that Switch C had a backup link to Switch A. In this case, Switch C needs to be careful about its root port. Switch C and Switch B need to make sure they agree on what the port states should be, else you'll cause a loop between A, B, and C. -- Ross Vandegrift ross at kallisti.us "If the fight gets hot, the songs get hotter. If the going gets tough, the songs get tougher." --Woody Guthrie From danletkeman at gmail.com Sun Apr 19 14:07:55 2009 From: danletkeman at gmail.com (Dan Letkeman) Date: Sun, 19 Apr 2009 13:07:55 -0500 Subject: [c-nsp] 2821 hardware compatibility Message-ID: Hello, I'm looking at putting in some WIC-1ADSL cards into a 2821 router. I would need to put in 6 of them, but the 2821 only has 4 onboard slots and I was wondering if the NM-2E2W is compatible with a 2821 router so I can add the last two? Thanks Dan. From dale.shaw+cisco-nsp at gmail.com Sun Apr 19 19:53:33 2009 From: dale.shaw+cisco-nsp at gmail.com (Dale Shaw) Date: Mon, 20 Apr 2009 09:53:33 +1000 Subject: [c-nsp] VTY Lines In-Reply-To: References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> Message-ID: <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> Hi Lee, On Sun, Apr 19, 2009 at 10:53 PM, Lee wrote: > What I'd like to know is what extra protection "service > tcp-keepalives-in" gives you that the exec-timeout on the VTYs > doesn't. Hmm, I guess it might come in useful if you're accessing the vty line via a firewall with particularly aggressive idle TCP session timers? Having said that though, it's not like "service tcp-keepalives (in|out)" can be tuned. The DocCD is quiet on how often the keepalives are sent, too. Old thread: http://puck.nether.net/pipermail/cisco-nsp/2004-July/011508.html <--- is that you? :-) cheers, Dale From zardoz at hotblack.net Sun Apr 19 20:56:33 2009 From: zardoz at hotblack.net (Tristan Gulyas) Date: Mon, 20 Apr 2009 10:56:33 +1000 Subject: [c-nsp] Easy way to configure/build new switches? Message-ID: Hi all, We currently do a lot of provisioning of new Cisco 3750G switches. This seems to be a progressive, ongoing thing. At present, when we receive a new switch, we need to: * Upgrade firmware (currently 12.2(50)SE crypto, switches typically ship with 12.2(35)SE5) * Place our config on the switch * Configure vlan for management, IP address for management * Set first switch in stack to priority 15 (not in the config in a "show run") * Confgure VTP * Change SDM template for dual IPv4/IPv6. * Configure uplinks (and optionally downlinks) At present, we do a lot of copying/pasting from a template page which is prone to error. Upgrading the firmware on these switches is also tedious and slow. Is there a tool or method we could use to quick provision these switches, say, if we could automatically get the new firmware/config template from a TFTP server? What concerns me is the lines that aren't actually present in the config, i.e. stack priority settings and VTP. thanks, Tristan From hsa at ntt.net.id Mon Apr 20 00:11:41 2009 From: hsa at ntt.net.id (Henry Sarumpaet) Date: Mon, 20 Apr 2009 11:11:41 +0700 Subject: [c-nsp] Feature support. Message-ID: <49EBF5FD.9060100@ntt.net.id> Hi all, In case some cisco folks hanging around, does anyone know does cisco will support SPA-8X1FE-TX-V2 with etherchannel ? its a expensive card anyway :) -- regards hsa From skeeve at eintellego.net Mon Apr 20 01:21:57 2009 From: skeeve at eintellego.net (Skeeve Stevens) Date: Mon, 20 Apr 2009 15:21:57 +1000 Subject: [c-nsp] X2 to GigE Message-ID: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> Hey All, I am looking at using a HP 10GbE switch with X2 slots.... but only X2 - no GigE. I want to uplink this into a Cisco switch - SFP slot. Since Cisco uses X2 as well, I am wondering if there is any X2 devices that I can put into the HP that can cross connect into a SFP GigE slot on a Cisco. ...Skeeve -- Skeeve Stevens, CEO/Technical Director eintellego Pty Ltd - The Networking Specialists skeeve at eintellego.net / www.eintellego.net Phone: 1300 753 383, Fax: (+612) 8572 9954 Cell +61 (0)414 753 383 / skype://skeeve -- NOC, NOC, who's there? Disclaimer: Limits of Liability and Disclaimer: This message is for the named person's use only. It may contain sensitive and private proprietary or legally privileged information. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient. eintellego Pty Ltd and each legal entity in the Tefilah Pty Ltd group of companies reserve the right to monitor all e-mail communications through its networks. Any views expressed in this message are those of the individual sender, except where the message states otherwise and the sender is authorised to state them to be the views of any such entity. Any reference to costs, fee quotations, contractual transactions and variations to contract terms is subject to separate confirmation in writing signed by an authorised representative of eintellego. Whilst all efforts are made to safeguard inbound and outbound e-mails, we cannot guarantee that attachments are virus-free or compatible with your systems and do not accept any liability in respect of viruses or computer problems experienced. From ltd at cisco.com Mon Apr 20 02:29:42 2009 From: ltd at cisco.com (Lincoln Dale) Date: Mon, 20 Apr 2009 16:29:42 +1000 Subject: [c-nsp] X2 to GigE In-Reply-To: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> Message-ID: <49EC1656.2050109@cisco.com> Skeeve Stevens wrote: > Hey All, > > I am looking at using a HP 10GbE switch with X2 slots.... but only X2 - no GigE. > > I want to uplink this into a Cisco switch - SFP slot. > > Since Cisco uses X2 as well, I am wondering if there is any X2 devices that I can put into the HP that can cross connect into a SFP GigE slot on a Cisco. > Steve, you'd not understanding layer 1 here. * GBIC, X2, SFP, Xenpak, SFP+, XFP are transceiver types. * LC/SC are cable connector types for optics * MM (FDDI grade, OM1, OM2, OM3), SM are fiber types. SFP is generally used for gigabit (1G), X2 is generally used for 10G. from a cabling perspective if this is all local within a single site then generally it would be MM fiber, if its new, suggest you go with OM3. can't remember connector type on X2, think its SC like a GBIC? if so, then a LC/SC patch will connect the two. but you'd probably need a 10G interface to connect it in, which implies something on the Cisco end that is SFP+, X2, SFP, Xenpak. i.e. NOT SFP. cheers, lincoln. From peter at rathlev.dk Mon Apr 20 02:35:18 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Mon, 20 Apr 2009 08:35:18 +0200 Subject: [c-nsp] VTY Lines In-Reply-To: <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> Message-ID: <1240209318.3386.7.camel@localhost.localdomain> On Mon, 2009-04-20 at 09:53 +1000, Dale Shaw wrote: > Having said that though, it's not like "service tcp-keepalives > (in|out)" can be tuned. The DocCD is quiet on how often the keepalives > are sent, too. By default TCP keep-alives should be in at least 2 hour intervals as per RFC 1122 4.2.3.6; I think most implementations follow this. But same RFC says that the interval MUST be configurable. :-) Regards, Peter From phil.pierotti at gmail.com Mon Apr 20 02:37:51 2009 From: phil.pierotti at gmail.com (Phil Pierotti) Date: Mon, 20 Apr 2009 16:37:51 +1000 Subject: [c-nsp] X2 to GigE In-Reply-To: <49EC1656.2050109@cisco.com> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> Message-ID: <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> I'm guessing that Skeeve is looking for the HP equivalent of this delightful module from Cisco: http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps7077/product_data_sheet0900aecd805bbee3.html Phil P On Mon, Apr 20, 2009 at 4:29 PM, Lincoln Dale wrote: > Skeeve Stevens wrote: > >> Hey All, >> >> I am looking at using a HP 10GbE switch with X2 slots.... but only X2 - no >> GigE. >> >> I want to uplink this into a Cisco switch - SFP slot. >> >> Since Cisco uses X2 as well, I am wondering if there is any X2 devices >> that I can put into the HP that can cross connect into a SFP GigE slot on a >> Cisco. >> >> > Steve, > > you'd not understanding layer 1 here. > > * GBIC, X2, SFP, Xenpak, SFP+, XFP are transceiver types. > * LC/SC are cable connector types for optics > * MM (FDDI grade, OM1, OM2, OM3), SM are fiber types. > > SFP is generally used for gigabit (1G), X2 is generally used for 10G. > from a cabling perspective if this is all local within a single site then > generally it would be MM fiber, if its new, suggest you go with OM3. > can't remember connector type on X2, think its SC like a GBIC? if so, then > a LC/SC patch will connect the two. > > but you'd probably need a 10G interface to connect it in, which implies > something on the Cisco end that is SFP+, X2, SFP, Xenpak. i.e. NOT SFP. > > > cheers, > > lincoln. > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From ltd at cisco.com Mon Apr 20 02:58:47 2009 From: ltd at cisco.com (Lincoln Dale) Date: Mon, 20 Apr 2009 16:58:47 +1000 Subject: [c-nsp] X2 to GigE In-Reply-To: <200904201452.44559.mtinka@globaltransit.net> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <200904201452.44559.mtinka@globaltransit.net> Message-ID: <49EC1D27.5000702@cisco.com> Mark Tinka wrote: > On Monday 20 April 2009 02:29:42 pm Lincoln Dale wrote: > > >> but you'd probably need a 10G interface to connect it in, >> which implies something on the Cisco end that is SFP+, >> X2, SFP, Xenpak. i.e. NOT SFP. >> > ^^^ > ^^^ <= guessing you meant XFP :-). > forgot the + on SFP+. :) cheers, lincoln. From skeeve at eintellego.net Mon Apr 20 03:11:21 2009 From: skeeve at eintellego.net (Skeeve Stevens) Date: Mon, 20 Apr 2009 17:11:21 +1000 Subject: [c-nsp] X2 to GigE In-Reply-To: <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> Message-ID: <292AF25E62B8894C921B893B53A19D97394469E0B3@BUSINESSEX.business.ad> That is EXACTLY what I am looking for! Basically.. How do I get a HP Switch with 6 * 10GbE X2 slots into a normal Cisco GigE network... ...Skeeve -- Skeeve Stevens, CEO/Technical Director eintellego Pty Ltd - The Networking Specialists skeeve at eintellego.net / www.eintellego.net Phone: 1300 753 383, Fax: (+612) 8572 9954 Cell +61 (0)414 753 383 / skype://skeeve -- NOC, NOC, who's there? Disclaimer: Limits of Liability and Disclaimer: This message is for the named person's use only. It may contain sensitive and private proprietary or legally privileged information. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient. eintellego Pty Ltd and each legal entity in the Tefilah Pty Ltd group of companies reserve the right to monitor all e-mail communications through its networks. Any views expressed in this message are those of the individual sender, except where the message states otherwise and the sender is authorised to state them to be the views of any such entity. Any reference to costs, fee quotations, contractual transactions and variations to contract terms is subject to separate confirmation in writing signed by an authorised representative of eintellego. Whilst all efforts are made to safeguard inbound and outbound e-mails, we cannot guarantee that attachments are virus-free or compatible with your systems and do not accept any liability in respect of viruses or computer problems experienced. From: Phil Pierotti [mailto:phil.pierotti at gmail.com] Sent: Monday, 20 April 2009 4:38 PM To: Lincoln Dale Cc: Skeeve Stevens; cisco-nsp at puck.nether.net Subject: Re: [c-nsp] X2 to GigE I'm guessing that Skeeve is looking for the HP equivalent of this delightful module from Cisco: http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps7077/product_data_sheet0900aecd805bbee3.html Phil P On Mon, Apr 20, 2009 at 4:29 PM, Lincoln Dale > wrote: Skeeve Stevens wrote: Hey All, I am looking at using a HP 10GbE switch with X2 slots.... but only X2 - no GigE. I want to uplink this into a Cisco switch - SFP slot. Since Cisco uses X2 as well, I am wondering if there is any X2 devices that I can put into the HP that can cross connect into a SFP GigE slot on a Cisco. Steve, you'd not understanding layer 1 here. * GBIC, X2, SFP, Xenpak, SFP+, XFP are transceiver types. * LC/SC are cable connector types for optics * MM (FDDI grade, OM1, OM2, OM3), SM are fiber types. SFP is generally used for gigabit (1G), X2 is generally used for 10G. from a cabling perspective if this is all local within a single site then generally it would be MM fiber, if its new, suggest you go with OM3. can't remember connector type on X2, think its SC like a GBIC? if so, then a LC/SC patch will connect the two. but you'd probably need a 10G interface to connect it in, which implies something on the Cisco end that is SFP+, X2, SFP, Xenpak. i.e. NOT SFP. cheers, lincoln. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From ltd at cisco.com Mon Apr 20 03:13:51 2009 From: ltd at cisco.com (Lincoln Dale) Date: Mon, 20 Apr 2009 17:13:51 +1000 Subject: [c-nsp] X2 to GigE In-Reply-To: <292AF25E62B8894C921B893B53A19D97394469E0B3@BUSINESSEX.business.ad> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> <292AF25E62B8894C921B893B53A19D97394469E0B3@BUSINESSEX.business.ad> Message-ID: <49EC20AF.5000105@cisco.com> deploy a Cisco 10G switch? if you're after an access switch for the datacenter, Nexus 5010 isn't a bad place to start. under $1K/port for 20 x line rate 10G ports. cheers, lincoln. Skeeve Stevens wrote: > > That is EXACTLY what I am looking for! > > > > Basically.. How do I get a HP Switch with 6 * 10GbE X2 slots into a > normal Cisco GigE network... > > > > ...Skeeve > > > > -- > > Skeeve Stevens, CEO/Technical Director > > eintellego Pty Ltd - The Networking Specialists > > skeeve at eintellego.net / www.eintellego.net > > Phone: 1300 753 383, Fax: (+612) 8572 9954 > > Cell +61 (0)414 753 383 / skype://skeeve > > -- > > NOC, NOC, who's there? > > > > Disclaimer: Limits of Liability and Disclaimer: This message is for > the named person's use only. It may contain sensitive and private > proprietary or legally privileged information. You must not, directly > or indirectly, use, disclose, distribute, print, or copy any part of > this message if you are not the intended recipient. eintellego Pty Ltd > and each legal entity in the Tefilah Pty Ltd group of companies > reserve the right to monitor all e-mail communications through its > networks. Any views expressed in this message are those of the > individual sender, except where the message states otherwise and the > sender is authorised to state them to be the views of any such entity. > Any reference to costs, fee quotations, contractual transactions and > variations to contract terms is subject to separate confirmation in > writing signed by an authorised representative of eintellego. Whilst > all efforts are made to safeguard inbound and outbound e-mails, we > cannot guarantee that attachments are virus-free or compatible with > your systems and do not accept any liability in respect of viruses or > computer problems experienced. > > > > *From:* Phil Pierotti [mailto:phil.pierotti at gmail.com] > *Sent:* Monday, 20 April 2009 4:38 PM > *To:* Lincoln Dale > *Cc:* Skeeve Stevens; cisco-nsp at puck.nether.net > *Subject:* Re: [c-nsp] X2 to GigE > > > > I'm guessing that Skeeve is looking for the HP equivalent of this > delightful module from Cisco: > > > > http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps7077/product_data_sheet0900aecd805bbee3.html > > > > Phil P > > On Mon, Apr 20, 2009 at 4:29 PM, Lincoln Dale > wrote: > > Skeeve Stevens wrote: > > Hey All, > > I am looking at using a HP 10GbE switch with X2 slots.... but only X2 > - no GigE. > > I want to uplink this into a Cisco switch - SFP slot. > > Since Cisco uses X2 as well, I am wondering if there is any X2 devices > that I can put into the HP that can cross connect into a SFP GigE slot > on a Cisco. > > > Steve, > > you'd not understanding layer 1 here. > > * GBIC, X2, SFP, Xenpak, SFP+, XFP are transceiver types. > * LC/SC are cable connector types for optics > * MM (FDDI grade, OM1, OM2, OM3), SM are fiber types. > > SFP is generally used for gigabit (1G), X2 is generally used for 10G. > from a cabling perspective if this is all local within a single site > then generally it would be MM fiber, if its new, suggest you go with OM3. > can't remember connector type on X2, think its SC like a GBIC? if so, > then a LC/SC patch will connect the two. > > but you'd probably need a 10G interface to connect it in, which > implies something on the Cisco end that is SFP+, X2, SFP, Xenpak. > i.e. NOT SFP. > > > cheers, > > lincoln. > > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > From skeeve at eintellego.net Mon Apr 20 03:15:13 2009 From: skeeve at eintellego.net (Skeeve Stevens) Date: Mon, 20 Apr 2009 17:15:13 +1000 Subject: [c-nsp] X2 to GigE In-Reply-To: <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> Message-ID: <292AF25E62B8894C921B893B53A19D97394469E0B5@BUSINESSEX.business.ad> Actually, what are the chance of these working in a HP? Btw... the switch I am looking at is the HP ProCurve Switch 6410cl I know this is a Cisco list, but I am wanting to put this into a Cisco network and need to uplink it into 3560G's -- Skeeve Stevens, CEO/Technical Director eintellego Pty Ltd - The Networking Specialists skeeve at eintellego.net / www.eintellego.net Phone: 1300 753 383, Fax: (+612) 8572 9954 Cell +61 (0)414 753 383 / skype://skeeve -- NOC, NOC, who's there? Disclaimer: Limits of Liability and Disclaimer: This message is for the named person's use only. It may contain sensitive and private proprietary or legally privileged information. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient. eintellego Pty Ltd and each legal entity in the Tefilah Pty Ltd group of companies reserve the right to monitor all e-mail communications through its networks. Any views expressed in this message are those of the individual sender, except where the message states otherwise and the sender is authorised to state them to be the views of any such entity. Any reference to costs, fee quotations, contractual transactions and variations to contract terms is subject to separate confirmation in writing signed by an authorised representative of eintellego. Whilst all efforts are made to safeguard inbound and outbound e-mails, we cannot guarantee that attachments are virus-free or compatible with your systems and do not accept any liability in respect of viruses or computer problems experienced. From: Phil Pierotti [mailto:phil.pierotti at gmail.com] Sent: Monday, 20 April 2009 4:38 PM To: Lincoln Dale Cc: Skeeve Stevens; cisco-nsp at puck.nether.net Subject: Re: [c-nsp] X2 to GigE I'm guessing that Skeeve is looking for the HP equivalent of this delightful module from Cisco: http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps7077/product_data_sheet0900aecd805bbee3.html Phil P On Mon, Apr 20, 2009 at 4:29 PM, Lincoln Dale > wrote: Skeeve Stevens wrote: Hey All, I am looking at using a HP 10GbE switch with X2 slots.... but only X2 - no GigE. I want to uplink this into a Cisco switch - SFP slot. Since Cisco uses X2 as well, I am wondering if there is any X2 devices that I can put into the HP that can cross connect into a SFP GigE slot on a Cisco. Steve, you'd not understanding layer 1 here. * GBIC, X2, SFP, Xenpak, SFP+, XFP are transceiver types. * LC/SC are cable connector types for optics * MM (FDDI grade, OM1, OM2, OM3), SM are fiber types. SFP is generally used for gigabit (1G), X2 is generally used for 10G. from a cabling perspective if this is all local within a single site then generally it would be MM fiber, if its new, suggest you go with OM3. can't remember connector type on X2, think its SC like a GBIC? if so, then a LC/SC patch will connect the two. but you'd probably need a 10G interface to connect it in, which implies something on the Cisco end that is SFP+, X2, SFP, Xenpak. i.e. NOT SFP. cheers, lincoln. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From skeeve at eintellego.net Mon Apr 20 03:22:03 2009 From: skeeve at eintellego.net (Skeeve Stevens) Date: Mon, 20 Apr 2009 17:22:03 +1000 Subject: [c-nsp] X2 to GigE In-Reply-To: <49EC20AF.5000105@cisco.com> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> <292AF25E62B8894C921B893B53A19D97394469E0B3@BUSINESSEX.business.ad> <49EC20AF.5000105@cisco.com> Message-ID: <292AF25E62B8894C921B893B53A19D97394469E0B8@BUSINESSEX.business.ad> Yeah nice switch... would love it, but way way too over budget for this project.... and only need 4-5 ports... So 9k vs 20k -- Skeeve Stevens, CEO/Technical Director eintellego Pty Ltd - The Networking Specialists skeeve at eintellego.net / www.eintellego.net Phone: 1300 753 383, Fax: (+612) 8572 9954 Cell +61 (0)414 753 383 / skype://skeeve -- NOC, NOC, who's there? Disclaimer: Limits of Liability and Disclaimer: This message is for the named person's use only. It may contain sensitive and private proprietary or legally privileged information. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient. eintellego Pty Ltd and each legal entity in the Tefilah Pty Ltd group of companies reserve the right to monitor all e-mail communications through its networks. Any views expressed in this message are those of the individual sender, except where the message states otherwise and the sender is authorised to state them to be the views of any such entity. Any reference to costs, fee quotations, contractual transactions and variations to contract terms is subject to separate confirmation in writing signed by an authorised representative of eintellego. Whilst all efforts are made to safeguard inbound and outbound e-mails, we cannot guarantee that attachments are virus-free or compatible with your systems and do not accept any liability in respect of viruses or computer problems experienced. From: Lincoln Dale [mailto:ltd at cisco.com] Sent: Monday, 20 April 2009 5:14 PM To: Skeeve Stevens Cc: Phil Pierotti; cisco-nsp at puck.nether.net Subject: Re: [c-nsp] X2 to GigE deploy a Cisco 10G switch? if you're after an access switch for the datacenter, Nexus 5010 isn't a bad place to start. under $1K/port for 20 x line rate 10G ports. cheers, lincoln. Skeeve Stevens wrote: That is EXACTLY what I am looking for! Basically.. How do I get a HP Switch with 6 * 10GbE X2 slots into a normal Cisco GigE network... ...Skeeve -- Skeeve Stevens, CEO/Technical Director eintellego Pty Ltd - The Networking Specialists skeeve at eintellego.net / www.eintellego.net Phone: 1300 753 383, Fax: (+612) 8572 9954 Cell +61 (0)414 753 383 / skype://skeeve -- NOC, NOC, who's there? Disclaimer: Limits of Liability and Disclaimer: This message is for the named person's use only. It may contain sensitive and private proprietary or legally privileged information. You must not, directly or indirectly, use, disclose, distribute, print, or copy any part of this message if you are not the intended recipient. eintellego Pty Ltd and each legal entity in the Tefilah Pty Ltd group of companies reserve the right to monitor all e-mail communications through its networks. Any views expressed in this message are those of the individual sender, except where the message states otherwise and the sender is authorised to state them to be the views of any such entity. Any reference to costs, fee quotations, contractual transactions and variations to contract terms is subject to separate confirmation in writing signed by an authorised representative of eintellego. Whilst all efforts are made to safeguard inbound and outbound e-mails, we cannot guarantee that attachments are virus-free or compatible with your systems and do not accept any liability in respect of viruses or computer problems experienced. From: Phil Pierotti [mailto:phil.pierotti at gmail.com] Sent: Monday, 20 April 2009 4:38 PM To: Lincoln Dale Cc: Skeeve Stevens; cisco-nsp at puck.nether.net Subject: Re: [c-nsp] X2 to GigE I'm guessing that Skeeve is looking for the HP equivalent of this delightful module from Cisco: http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps7077/product_data_sheet0900aecd805bbee3.html Phil P On Mon, Apr 20, 2009 at 4:29 PM, Lincoln Dale > wrote: Skeeve Stevens wrote: Hey All, I am looking at using a HP 10GbE switch with X2 slots.... but only X2 - no GigE. I want to uplink this into a Cisco switch - SFP slot. Since Cisco uses X2 as well, I am wondering if there is any X2 devices that I can put into the HP that can cross connect into a SFP GigE slot on a Cisco. Steve, you'd not understanding layer 1 here. * GBIC, X2, SFP, Xenpak, SFP+, XFP are transceiver types. * LC/SC are cable connector types for optics * MM (FDDI grade, OM1, OM2, OM3), SM are fiber types. SFP is generally used for gigabit (1G), X2 is generally used for 10G. from a cabling perspective if this is all local within a single site then generally it would be MM fiber, if its new, suggest you go with OM3. can't remember connector type on X2, think its SC like a GBIC? if so, then a LC/SC patch will connect the two. but you'd probably need a 10G interface to connect it in, which implies something on the Cisco end that is SFP+, X2, SFP, Xenpak. i.e. NOT SFP. cheers, lincoln. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From sethm at rollernet.us Mon Apr 20 03:30:28 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Mon, 20 Apr 2009 00:30:28 -0700 Subject: [c-nsp] X2 to GigE In-Reply-To: <292AF25E62B8894C921B893B53A19D97394469E0B5@BUSINESSEX.business.ad> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> <292AF25E62B8894C921B893B53A19D97394469E0B5@BUSINESSEX.business.ad> Message-ID: <49EC2494.3090909@rollernet.us> Skeeve Stevens wrote: > Actually, what are the chance of these working in a HP? > None. It looks like a converter, but it's not, it's a convenience to access wiring on the backplane Cisco added to let you use this module until you're ready for 10 gig. ~Seth From mtinka at globaltransit.net Mon Apr 20 02:52:43 2009 From: mtinka at globaltransit.net (Mark Tinka) Date: Mon, 20 Apr 2009 14:52:43 +0800 Subject: [c-nsp] X2 to GigE In-Reply-To: <49EC1656.2050109@cisco.com> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> Message-ID: <200904201452.44559.mtinka@globaltransit.net> On Monday 20 April 2009 02:29:42 pm Lincoln Dale wrote: > but you'd probably need a 10G interface to connect it in, > which implies something on the Cisco end that is SFP+, > X2, SFP, Xenpak. i.e. NOT SFP. ^^^ ^^^ <= guessing you meant XFP :-). Cheers, Mark. -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 835 bytes Desc: This is a digitally signed message part. URL: From zivl at gilat.net Mon Apr 20 03:35:38 2009 From: zivl at gilat.net (Ziv Leyes) Date: Mon, 20 Apr 2009 10:35:38 +0300 Subject: [c-nsp] Easy way to configure/build new switches? In-Reply-To: References: Message-ID: It's all possible to do with TFTP, you could load the firmware and startup-config to a TFTP server, then from the new switch pull them both, but it will still have to be quite "interactive" with someone that knows how to do it. -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Tristan Gulyas Sent: Monday, April 20, 2009 3:57 AM To: cisco-nsp at puck.nether.net Subject: [c-nsp] Easy way to configure/build new switches? Hi all, We currently do a lot of provisioning of new Cisco 3750G switches. This seems to be a progressive, ongoing thing. At present, when we receive a new switch, we need to: * Upgrade firmware (currently 12.2(50)SE crypto, switches typically ship with 12.2(35)SE5) * Place our config on the switch * Configure vlan for management, IP address for management * Set first switch in stack to priority 15 (not in the config in a "show run") * Confgure VTP * Change SDM template for dual IPv4/IPv6. * Configure uplinks (and optionally downlinks) At present, we do a lot of copying/pasting from a template page which is prone to error. Upgrading the firmware on these switches is also tedious and slow. Is there a tool or method we could use to quick provision these switches, say, if we could automatically get the new firmware/config template from a TFTP server? What concerns me is the lines that aren't actually present in the config, i.e. stack priority settings and VTP. thanks, Tristan _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ ************************************************************************************ This footnote confirms that this email message has been scanned by PineApp Mail-SeCure for the presence of malicious code, vandals & computer viruses. ************************************************************************************ ************************************************************************************ This footnote confirms that this email message has been scanned by PineApp Mail-SeCure for the presence of malicious code, vandals & computer viruses. ************************************************************************************ From zivl at gilat.net Mon Apr 20 03:40:28 2009 From: zivl at gilat.net (Ziv Leyes) Date: Mon, 20 Apr 2009 10:40:28 +0300 Subject: [c-nsp] Classify geographical traffic with BGP In-Reply-To: References: Message-ID: One possible option is to peer with your country's internet exchange point where all other "local" internet providers might be peering to as well, this way, the "local" traffic would be always preferred via the IX peer, and all the rest is aparently "international" therefore going out to your international ISP -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Burak Dikici Sent: Wednesday, April 15, 2009 2:46 AM To: cisco-nsp at puck.nether.net Subject: [c-nsp] Classify geographical traffic with BGP Hello , I have got one internet router running BGP , and this router has got connections with two different ISPs. One of the ISP is local for my country and the other ISP's location is outside of my country. I want to classify geographical traffic with BGP. For example , local traffic to my country will go through ISP-1 (local ISP) , outside traffic to my country will go through ISP-2 (outside of my country ISP). What i have to do to achieve that kind of configuration ? If i have to use AS path filter , how can i find the local ISP AS path numbers and how can i configure AS path filter for this request ? Is that enough using the as-path filter just for the national ISP or should i use it for international ISP also ? If i use AS-path filter for both ISP connections , what will happen to redundancy ? I mean , for example i filter national AS numbers at the international ISP connection and deny them. Secondly , i filter national AS numbers at the national ISP connection , permit them and the other AS numbers will be denied. In this situation , what will happen if the local ISP connection goes down ? Because of filtering of the national AS numbers at the international ISP connection , the BGP table doesn't take any updates from the local AS numbers. I hope , i could explain the situation correctly. Kind Regards... Burak Dikici _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ ************************************************************************************ This footnote confirms that this email message has been scanned by PineApp Mail-SeCure for the presence of malicious code, vandals & computer viruses. ************************************************************************************ ************************************************************************************ This footnote confirms that this email message has been scanned by PineApp Mail-SeCure for the presence of malicious code, vandals & computer viruses. ************************************************************************************ From jcovini at free.fr Mon Apr 20 03:50:33 2009 From: jcovini at free.fr (jcovini at free.fr) Date: Mon, 20 Apr 2009 09:50:33 +0200 Subject: [c-nsp] X2 to GigE In-Reply-To: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> Message-ID: <1240213833.49ec294941657@imp.free.fr> Selon Skeeve Stevens : > Hey All, > > I am looking at using a HP 10GbE switch with X2 slots.... but only X2 - no > GigE. Why not using a Procurve 5406 with some J8707A modules (x4 port 10G slots) and J8436A transceivers (10-GbE X2-SC SR Optics), which runs fine with 50u MMF ? Jerome Covini From gert at greenie.muc.de Mon Apr 20 08:19:50 2009 From: gert at greenie.muc.de (Gert Doering) Date: Mon, 20 Apr 2009 14:19:50 +0200 Subject: [c-nsp] X2 to GigE In-Reply-To: <292AF25E62B8894C921B893B53A19D97394469E0B5@BUSINESSEX.business.ad> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> <292AF25E62B8894C921B893B53A19D97394469E0B5@BUSINESSEX.business.ad> Message-ID: <20090420121950.GK290@greenie.muc.de> Hi, On Mon, Apr 20, 2009 at 05:15:13PM +1000, Skeeve Stevens wrote: > Actually, what are the chance of these working in a HP? Zero. Cisco twingig is using extra conncetions in the X2 slot for the gigE connections. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From clinton at scripty.com Mon Apr 20 09:42:58 2009 From: clinton at scripty.com (Clinton Work) Date: Mon, 20 Apr 2009 07:42:58 -0600 Subject: [c-nsp] VTY Lines In-Reply-To: <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> Message-ID: <49EC7BE2.60100@scripty.com> Sound like a bug similiar to CSCee62455. From experience with the bug, once all the VTY lines are locked up, the console port would not respond either. The only way to clear the VTY lines was with SNMP, but it would cause crashes from time to time. "service tcp-keepaliaves in/out" didn't help either. Clinton. Dale Shaw wrote: > Hmm, I guess it might come in useful if you're accessing the vty line > via a firewall with particularly aggressive idle TCP session timers? > > Having said that though, it's not like "service tcp-keepalives > (in|out)" can be tuned. The DocCD is quiet on how often the keepalives > are sent, too. > > From servet.erkun at doruk.net.tr Mon Apr 20 09:55:30 2009 From: servet.erkun at doruk.net.tr (=?iso-8859-9?Q?Servet_Erk=FCn?=) Date: Mon, 20 Apr 2009 16:55:30 +0300 Subject: [c-nsp] Cisco 2960 series switch MLS Qos Support Message-ID: <005901c9c1bf$aac19f20$06050505@HSS.local> hi guys Do you have any idea? Does cisco 2960 series switch suppory MLS Qos on it's interface? it uses c2960-lanbase-mz.122-35.SE5 IOS, you can see my policy configuration below. mls qos aggregate-policer 2M 2000000 50000 exceed-action drop class-map match-all 2M match access-group 100 policy-map 512K class 2M police aggregate 2M access-list 100 permit ip any any interface GigabitEthernet0/8 switchport access vlan 848 service-policy input 2M i check policy-map with "show policy-map interface" command, but i can not see any matching about this policy #sh policy-map interface gi 0/8 GigabitEthernet0/8 Service-policy input: 2M Class-map: 2M (match-all) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: access-group 100 Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any 0 packets, 0 bytes 5 minute rate 0 bps From pshuleski at gmail.com Mon Apr 20 10:00:54 2009 From: pshuleski at gmail.com (Pete S.) Date: Mon, 20 Apr 2009 10:00:54 -0400 Subject: [c-nsp] Easy way to configure/build new switches? In-Reply-To: References: Message-ID: <50f158990904200700o1f1729ecnec698c6b3e257802@mail.gmail.com> It would be fairly trivial to write a php/perl script to build a config, based on your template and questions about settings. Even make it into a skeleton webpage if you dont like the CLI. Then store the output into a tftp dir. Go into the switch, give it an IP. copy tftp://x.x.x.x/filename.txt startup-config reload. --Pete On Sun, Apr 19, 2009 at 8:56 PM, Tristan Gulyas wrote: > Hi all, > > We currently do a lot of provisioning of new Cisco 3750G switches. ?This > seems to be a progressive, ongoing thing. > > At present, when we receive a new switch, we need to: > > * Upgrade firmware (currently 12.2(50)SE crypto, switches typically ship > with 12.2(35)SE5) > * Place our config on the switch > * Configure vlan for management, IP address for management > * Set first switch in stack to priority 15 (not in the config in a "show > run") > * Confgure VTP > * Change SDM template for dual IPv4/IPv6. > * Configure uplinks (and optionally downlinks) > > At present, we do a lot of copying/pasting from a template page which is > prone to error. ?Upgrading the firmware on these switches is also tedious > and slow. > > Is there a tool or method we could use to quick provision these switches, > say, if we could automatically get the new firmware/config template from a > TFTP server? ?What concerns me is the lines that aren't actually present in > the config, i.e. stack priority settings and VTP. > > thanks, > Tristan > > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From lowen at pari.edu Mon Apr 20 11:53:25 2009 From: lowen at pari.edu (Lamar Owen) Date: Mon, 20 Apr 2009 11:53:25 -0400 Subject: [c-nsp] C6kSup720 "LAN ONLY" vs. "WAN" In-Reply-To: <49EB1A3F.80509@forthnet.gr> References: <1239908737.3608.5.camel@localhost.localdomain> Message-ID: <200904201153.25986.lowen@pari.edu> On Sunday 19 April 2009 08:34:07 Tassos Chatzithomaoglou wrote: > According to Software Advisor you need the wan image for OSM cards (like > you said). Interestingly enough, SIPs/SPAs do not seem to need it. > Nevertheless, it's hard to believe that OSMs are responsible for the > additional 33% of -compressed- code! OSM's have a whole processor on board that needs IOS software loaded; PXF stuff, etc. Some of this is in the bootflash for the OSM, but some (or even most) is loaded from the IOS image. I'm assuming FlexWAN is similar, but I don't have a FlexWAN to try with. Also, there are protocols that are only used for WAN, things like APS and such. And you can't trust Feature Navigator to tell you; try comparing the images for 12.2(18)SXF16 on a 7600 Sup2MSFC2 versus the same IOS on a Catalyst 6500 Sup2MSFC2 (same sup/msfc, should have same features, no?) to see what I mean. Here's a 'show ver' and some other informative commands run from an OSM console showing the special IOS running on the OSM's processor, the location of the PXF microcode, and the differences in the system: filesystem seen from the RP and the CWAN proc: dc-7609-1# attach 3 Entering CONSOLE for slot 3 Type "^C^C^C" to end this session CWTLC-Slot3>enable CWTLC-Slot3#sh ver Cisco Internetwork Operating System Software IOS (tm) cwtlc Software (cwtlc-DW-M), Version 12.2(18)SXF16, RELEASE SOFTWARE (fc2) Technical Support: http://www.cisco.com/techsupport Copyright (c) 1986-2009 by cisco Systems, Inc. Compiled Tue 03-Mar-09 14:24 by kellythw Image text-base: 0x60011038, data-base: 0x60700000 ROM: System Bootstrap, Version 12.1(5r)E, ENGG RELEASE (fc1) ROM: cwtlc Software (cwtlc-DW-M), Version 12.2(18)SXF16, RELEASE SOFTWARE (fc2) CWTLC-Slot3 uptime is 3 weeks, 1 day, 22 hours, 16 minutes System returned to ROM by power-on System restarted at 17:24:16 UTC Sat Mar 28 2009 Running default software cisco CWAN Toaster Linecard (R7000) processor (revision 0xFF) with 245760K/16384K bytes of memory. Processor board ID , TMC Ucode version: 0.0 R7000 CPU at 262Mhz, Implementation 0x27, Rev 3.3, 256KB L2 Cache Last reset from power-on PXF processor tmc0 is running. 1 FastEthernet/IEEE 802.3 interface 4 Packet over SONET network interfaces Configuration register is 0x101 CWTLC-Slot3#sh microcode Microcode images for downloadable hardware HW Type Microcode image names ------------------------------------------ pxf default system:pxf/ucode0 CWTLC-Slot3#dir system: Directory of system:/ 2 dr-x 0 memory 12 dr-x 0 pxf 1 -rw- 695 running-config No space information available CWTLC-Slot3# CWTLC-Slot3# CWTLC-Slot3# Terminate IPC console session? [confirm] dc-7609-1#sh microcode ^ % Invalid input detected at '^' marker. dc-7609-1#dir system: Directory of system:/ 2 dr-x 0 memory 1 -rw- 10176 running-config 12 dr-x 0 vfiles No space information available dc-7609-1# From bfarouk52 at yahoo.com Mon Apr 20 11:30:28 2009 From: bfarouk52 at yahoo.com (Belal Farouk) Date: Mon, 20 Apr 2009 08:30:28 -0700 (PDT) Subject: [c-nsp] c7201 error SFP is missing [0] Message-ID: <179270.35479.qm@web32403.mail.mud.yahoo.com> I tried to install 12.4(X)T on this chassis to support PA-MC-2T3-EC. "Show fac status" gives me the following: Router#sh facility-alarm sta System Totals Critical: 1 Major: 0 Minor: 0 Source Severity Description [Index] ------ -------- ------------------- SFP Slot 0/3 CRITICAL SFP is missing [0] Cisco version SFP is in and interface is UP and UP. Router#sh int g0/3 GigabitEthernet0/3 is up, line protocol is up Hardware is i82546, address is 0024.97a6.ee17 (bia 0024.97a6.ee17) Internet address is 11.0.2.1/24 MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 1/255, rxload 1/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex, 1000Mb/s, link type is autonegotiation, media type is LX output flow-control is XON, input flow-control is XON Research on bug didn't find any. There is one reported as chipset i82546 on g0/3 was missing many IOS command to retrieve information CSCsq58662. The other ports are regular NPE-G2 chipset. Any one come about this problem and what was the resolution from Cisco. Thanks, From ler762 at gmail.com Mon Apr 20 13:07:27 2009 From: ler762 at gmail.com (Lee) Date: Mon, 20 Apr 2009 13:07:27 -0400 Subject: [c-nsp] VTY Lines In-Reply-To: <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> Message-ID: Hi Dale, On 4/19/09, Dale Shaw wrote: > Hi Lee, > > On Sun, Apr 19, 2009 at 10:53 PM, Lee wrote: >> What I'd like to know is what extra protection "service >> tcp-keepalives-in" gives you that the exec-timeout on the VTYs >> doesn't. > > Hmm, I guess it might come in useful if you're accessing the vty line > via a firewall with particularly aggressive idle TCP session timers? It probably would.. I went at it from the other direction tho; set the keepalive time on my ssh client to 10 minutes. > Having said that though, it's not like "service tcp-keepalives > (in|out)" can be tuned. The DocCD is quiet on how often the keepalives > are sent, too. I don't remember seeing anything on how often keepalives are sent either - just that sessions were killed after 5 minutes with no answer. > Old thread: > http://puck.nether.net/pipermail/cisco-nsp/2004-July/011508.html > <--- is that you? :-) Yup, that's me :) Discretion being the better part of valor, etc., etc., I use a non-work email address now. Regards, Lee From ras at e-gerbil.net Mon Apr 20 13:20:22 2009 From: ras at e-gerbil.net (Richard A Steenbergen) Date: Mon, 20 Apr 2009 12:20:22 -0500 Subject: [c-nsp] X2 to GigE In-Reply-To: <49EC2494.3090909@rollernet.us> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> <292AF25E62B8894C921B893B53A19D97394469E0B5@BUSINESSEX.business.ad> <49EC2494.3090909@rollernet.us> Message-ID: <20090420172022.GQ51443@gerbil.cluepon.net> On Mon, Apr 20, 2009 at 12:30:28AM -0700, Seth Mattinen wrote: > None. It looks like a converter, but it's not, it's a convenience to > access wiring on the backplane Cisco added to let you use this module > until you're ready for 10 gig. Speaking of converters, has anyone seen the upcoming Cisco X2 to SFP+ converter module? Now if only they made something useful like a XENPAK to XFP converter instead. :) -- Richard A Steenbergen http://www.e-gerbil.net/ras GPG Key ID: 0xF8B12CBC (7535 7F59 8204 ED1F CC1C 53AF 4C41 5ECA F8B1 2CBC) From ler762 at gmail.com Mon Apr 20 13:26:12 2009 From: ler762 at gmail.com (Lee) Date: Mon, 20 Apr 2009 13:26:12 -0400 Subject: [c-nsp] VTY Lines In-Reply-To: <49EC7BE2.60100@scripty.com> References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> <49EC7BE2.60100@scripty.com> Message-ID: On 4/20/09, Clinton Work wrote: > > Sound like a bug similiar to CSCee62455. From experience with the bug, > once all the VTY lines are locked up, the console port would not respond > either. The only way to clear the VTY lines was with SNMP, but it would > cause crashes from time to time. "service tcp-keepaliaves in/out" > didn't help either. Another one of my "could someone please explain why" things is how come "service tcp-keepalives in/out" is considered a "best practice" and having a much more restrictive ACL on vty 4 isn't? We've got something like this on all routers: access-list 100 permit ip 10.1.1.0 0.0.0.255 any access-list 104 permit ip host 10.1.1.10 any line vty 0 3 access-class 100 in line vty 4 access-class 104 in Which means every single router fails when you put the config through RAT :( Lee > > Clinton. > > Dale Shaw wrote: >> Hmm, I guess it might come in useful if you're accessing the vty line >> via a firewall with particularly aggressive idle TCP session timers? >> >> Having said that though, it's not like "service tcp-keepalives >> (in|out)" can be tuned. The DocCD is quiet on how often the keepalives >> are sent, too. >> >> > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From RYAN.BRAULT at illinois.gov Mon Apr 20 15:02:10 2009 From: RYAN.BRAULT at illinois.gov (Brault, Ryan) Date: Mon, 20 Apr 2009 14:02:10 -0500 Subject: [c-nsp] Cisco 2960 series switch MLS Qos Support In-Reply-To: <005901c9c1bf$aac19f20$06050505@HSS.local> References: <005901c9c1bf$aac19f20$06050505@HSS.local> Message-ID: Can't speak to a 2960 specifically, but a 3560 will not show any hits on a "show policy-map interface". I believe that's the case with this whole family of switches. I *think* the best you can do is a "show mls qos interface statistics". Ryan Brault -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Servet Erk?n Sent: Monday, April 20, 2009 8:56 AM To: cisco-nsp at puck.nether.net Subject: [c-nsp] Cisco 2960 series switch MLS Qos Support hi guys Do you have any idea? Does cisco 2960 series switch suppory MLS Qos on it's interface? it uses c2960-lanbase-mz.122-35.SE5 IOS, you can see my policy configuration below. mls qos aggregate-policer 2M 2000000 50000 exceed-action drop class-map match-all 2M match access-group 100 policy-map 512K class 2M police aggregate 2M access-list 100 permit ip any any interface GigabitEthernet0/8 switchport access vlan 848 service-policy input 2M i check policy-map with "show policy-map interface" command, but i can not see any matching about this policy #sh policy-map interface gi 0/8 GigabitEthernet0/8 Service-policy input: 2M Class-map: 2M (match-all) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: access-group 100 Class-map: class-default (match-any) 0 packets, 0 bytes 5 minute offered rate 0 bps, drop rate 0 bps Match: any 0 packets, 0 bytes 5 minute rate 0 bps _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From SMESIATO at petro-canada.ca Mon Apr 20 15:58:56 2009 From: SMESIATO at petro-canada.ca (Mesiatowsky, Shawn) Date: Mon, 20 Apr 2009 15:58:56 -0400 Subject: [c-nsp] Easy way to configure/build new switches? In-Reply-To: References: Message-ID: <259E69AA141E7640822757CAB3EBC70F18C1C1FD8C@MSG-M1P1.pcacorp.net> We use HP Datacenter automation center, formerly opsware. It is great for provisioning equipment, standardizing your IOS, policy compliance, and auditing. I highly recommend this tool https://h10078.www1.hp.com/cda/hpms/display/main/hpms_content.jsp?zn=bto&cp=1-11-271-273_4000_100__ -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Tristan Gulyas Sent: Sunday, April 19, 2009 6:57 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] Easy way to configure/build new switches? Hi all, We currently do a lot of provisioning of new Cisco 3750G switches. This seems to be a progressive, ongoing thing. At present, when we receive a new switch, we need to: * Upgrade firmware (currently 12.2(50)SE crypto, switches typically ship with 12.2(35)SE5) * Place our config on the switch * Configure vlan for management, IP address for management * Set first switch in stack to priority 15 (not in the config in a "show run") * Confgure VTP * Change SDM template for dual IPv4/IPv6. * Configure uplinks (and optionally downlinks) At present, we do a lot of copying/pasting from a template page which is prone to error. Upgrading the firmware on these switches is also tedious and slow. Is there a tool or method we could use to quick provision these switches, say, if we could automatically get the new firmware/config template from a TFTP server? What concerns me is the lines that aren't actually present in the config, i.e. stack priority settings and VTP. thanks, Tristan _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ This email communication is intended as a private communication for the sole use of the primary addressee and those individuals listed for copies in the original message. The information contained in this email is private and confidential and If you are not an intended recipient you are hereby notified that copying, forwarding or other dissemination or distribution of this communication by any means is prohibited. If you are not specifically authorized to receive this email and if you believe that you received it in error please notify the original sender immediately. We honour similar requests relating to the privacy of email communications. Cette communication par courrier ?lectronique est une communication priv?e ? l'usage exclusif du destinataire principal ainsi que des personnes dont les noms figurent en copie. Les renseignements contenus dans ce courriel sont confidentiels et si vous n'?tes pas le destinataire pr?vu, vous ?tes avis?, par les pr?sentes que toute reproduction, transfert ou autre forme de diffusion de cette communication par quelque moyen que ce soit est interdite. Si vous n'?tes pas sp?cifiquement autoris? ? recevoir ce courriel ou si vous croyez l'avoir re?u par erreur, veuillez en aviser l'exp?diteur original imm?diatement. Nous respectons les demandes similaires qui touchent la confidentialit? des communications par courrier ?lectronique. From andy.saykao at staff.netspace.net.au Mon Apr 20 18:22:06 2009 From: andy.saykao at staff.netspace.net.au (Andy Saykao) Date: Tue, 21 Apr 2009 08:22:06 +1000 Subject: [c-nsp] QoS Lab Recommendations Message-ID: <56F211C5E3F24F47B103EA1B253822BE03654D25@vic-cr-ex1.staff.netspace.net.au> Hi All, I'm looking for some QoS hands on labs to try out - does any body have any recommendations or reference material I can use? I've got all the hardware to pretty much set up any lab I want. Is there a way or some program I can use to create (simulate) congestion on a link in a lab set up? Thanks. Andy This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. Please notify the sender immediately by email if you have received this email by mistake and delete this email from your system. Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the organisation. Finally, the recipient should check this email and any attachments for the presence of viruses. The organisation accepts no liability for any damage caused by any virus transmitted by this email. From charles at thewybles.com Mon Apr 20 18:38:03 2009 From: charles at thewybles.com (Charles Wyble) Date: Mon, 20 Apr 2009 15:38:03 -0700 Subject: [c-nsp] QoS Lab Recommendations In-Reply-To: <56F211C5E3F24F47B103EA1B253822BE03654D25@vic-cr-ex1.staff.netspace.net.au> References: <56F211C5E3F24F47B103EA1B253822BE03654D25@vic-cr-ex1.staff.netspace.net.au> Message-ID: <49ECF94B.4080602@thewybles.com> Well perhaps start with the GNS3 labs to get an idea of various topologies? Andy Saykao wrote: > Hi All, > > I'm looking for some QoS hands on labs to try out - does any body have > any recommendations or reference material I can use? I've got all the > hardware to pretty much set up any lab I want. > > Is there a way or some program I can use to create (simulate) congestion > on a link in a lab set up? > > Thanks. > > Andy > > This email and any files transmitted with it are confidential and intended > solely for the use of the individual or entity to whom they are addressed. > Please notify the sender immediately by email if you have received this > email by mistake and delete this email from your system. Please note that > any views or opinions presented in this email are solely those of the > author and do not necessarily represent those of the organisation. > Finally, the recipient should check this email and any attachments for > the presence of viruses. The organisation accepts no liability for any > damage caused by any virus transmitted by this email. > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From mtinka at globaltransit.net Mon Apr 20 22:19:04 2009 From: mtinka at globaltransit.net (Mark Tinka) Date: Tue, 21 Apr 2009 10:19:04 +0800 Subject: [c-nsp] c7201 error SFP is missing [0] In-Reply-To: <179270.35479.qm@web32403.mail.mud.yahoo.com> References: <179270.35479.qm@web32403.mail.mud.yahoo.com> Message-ID: <200904211019.06282.mtinka@globaltransit.net> On Monday 20 April 2009 11:30:28 pm Belal Farouk wrote: > Source Severity Description [Index] > ------ -------- ------------------- > SFP Slot 0/3 CRITICAL SFP is missing [0] We've seen this in our logs, both on the NPE-G2 and 7201 - code is 12.2(33)SRC3 or earlier. It hasn't caused any real problems, so we haven't really followed up on it with TAC. Maybe we should :-). Cheers, Mark. -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 835 bytes Desc: This is a digitally signed message part. URL: From Steven.Glogger at swisscom.com Tue Apr 21 02:21:57 2009 From: Steven.Glogger at swisscom.com (Steven.Glogger at swisscom.com) Date: Tue, 21 Apr 2009 08:21:57 +0200 Subject: [c-nsp] QoS Lab Recommendations In-Reply-To: <56F211C5E3F24F47B103EA1B253822BE03654D25@vic-cr-ex1.staff.netspace.net.au> References: <56F211C5E3F24F47B103EA1B253822BE03654D25@vic-cr-ex1.staff.netspace.net.au> Message-ID: <1FC8A0BAFBBD9749BB1F06010D23C8A58711BD3A@sg000035.corproot.net> you should try to get the CCIE labs / workbooks from internetwork expert - especially volume II version 5.0 beta has really good QoS stuff in there. -steven -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Andy Saykao Sent: Tuesday, April 21, 2009 12:22 AM To: cisco-nsp at puck.nether.net Subject: [c-nsp] QoS Lab Recommendations Hi All, I'm looking for some QoS hands on labs to try out - does any body have any recommendations or reference material I can use? I've got all the hardware to pretty much set up any lab I want. Is there a way or some program I can use to create (simulate) congestion on a link in a lab set up? Thanks. Andy This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. Please notify the sender immediately by email if you have received this email by mistake and delete this email from your system. Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the organisation. Finally, the recipient should check this email and any attachments for the presence of viruses. The organisation accepts no liability for any damage caused by any virus transmitted by this email. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From rinse.kloek at isp.solcon.nl Tue Apr 21 03:02:37 2009 From: rinse.kloek at isp.solcon.nl (Rinse Kloek) Date: Tue, 21 Apr 2009 09:02:37 +0200 Subject: [c-nsp] QoS Lab Recommendations In-Reply-To: <56F211C5E3F24F47B103EA1B253822BE03654D25@vic-cr-ex1.staff.netspace.net.au> References: <56F211C5E3F24F47B103EA1B253822BE03654D25@vic-cr-ex1.staff.netspace.net.au> Message-ID: <49ED6F8D.8030308@isp.solcon.nl> For congestion tests, Spirent Smartbits hardware in combination with SmartFlow, is your best friend. Andy Saykao schreef: > Hi All, > > I'm looking for some QoS hands on labs to try out - does any body have > any recommendations or reference material I can use? I've got all the > hardware to pretty much set up any lab I want. > > Is there a way or some program I can use to create (simulate) congestion > on a link in a lab set up? > > Thanks. > > Andy > > This email and any files transmitted with it are confidential and intended > solely for the use of the individual or entity to whom they are addressed. > Please notify the sender immediately by email if you have received this > email by mistake and delete this email from your system. Please note that > any views or opinions presented in this email are solely those of the > author and do not necessarily represent those of the organisation. > Finally, the recipient should check this email and any attachments for > the presence of viruses. The organisation accepts no liability for any > damage caused by any virus transmitted by this email. > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From md at bts.sk Tue Apr 21 03:16:17 2009 From: md at bts.sk (=?UTF-8?Q?Marian_=C4=8Eurkovi=C4=8D?=) Date: Tue, 21 Apr 2009 09:16:17 +0200 Subject: [c-nsp] X2 to GigE In-Reply-To: <20090420172022.GQ51443@gerbil.cluepon.net> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> <292AF25E62B8894C921B893B53A19D97394469E0B5@BUSINESSEX.business.ad> <49EC2494.3090909@rollernet.us> <20090420172022.GQ51443@gerbil.cluepon.net> Message-ID: <20090421070341.M23196@bts.sk> On Mon, 20 Apr 2009 12:20:22 -0500, Richard A Steenbergen wrote > On Mon, Apr 20, 2009 at 12:30:28AM -0700, Seth Mattinen wrote: > > None. It looks like a converter, but it's not, it's a convenience to > > access wiring on the backplane Cisco added to let you use this module > > until you're ready for 10 gig. > > Speaking of converters, has anyone seen the upcoming Cisco X2 to SFP+ > converter module? Now if only they made something useful like a XENPAK > to XFP converter instead. :) There's a patent covering exactly this: http://www.patentgenius.com/patent/7488121.html It envisages any XAUI into any XFI module conversion options, which will be really great. M. From A.L.M.Buxey at lboro.ac.uk Tue Apr 21 04:00:23 2009 From: A.L.M.Buxey at lboro.ac.uk (A.L.M.Buxey at lboro.ac.uk) Date: Tue, 21 Apr 2009 09:00:23 +0100 Subject: [c-nsp] X2 to GigE In-Reply-To: <20090421070341.M23196@bts.sk> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <49EC1656.2050109@cisco.com> <5574b2240904192337r6e8a94a9i437dda00bd8906c6@mail.gmail.com> <292AF25E62B8894C921B893B53A19D97394469E0B5@BUSINESSEX.business.ad> <49EC2494.3090909@rollernet.us> <20090420172022.GQ51443@gerbil.cluepon.net> <20090421070341.M23196@bts.sk> Message-ID: <20090421080023.GD7227@lboro.ac.uk> Hi, > There's a patent covering exactly this: > > http://www.patentgenius.com/patent/7488121.html > > It envisages any XAUI into any XFI module conversion options, which will be > really great. why is there a patent granted for this? its obvious. now what'll happen is noone will make such adapters because they'd have to pay a patent fee/royalty. we desperately need to return to open specification and patent-free connectivity. alan From jcovini at free.fr Tue Apr 21 04:21:57 2009 From: jcovini at free.fr (jcovini at free.fr) Date: Tue, 21 Apr 2009 10:21:57 +0200 Subject: [c-nsp] X2 to GigE In-Reply-To: <1240213833.49ec294941657@imp.free.fr> References: <292AF25E62B8894C921B893B53A19D97394469E0AE@BUSINESSEX.business.ad> <1240213833.49ec294941657@imp.free.fr> Message-ID: <1240302117.49ed822590737@imp.free.fr> > Selon Skeeve Stevens : > > > Hey All, > > > > I am looking at using a HP 10GbE switch with X2 slots.... but only X2 - no > > GigE. > > Why not using a Procurve 5406 with some J8707A modules (x4 port 10G slots) > and > J8436A transceivers (10-GbE X2-SC SR Optics), which runs fine with 50u MMF ? > > Jerome Covini I did not notice at first that you wanted to uplink the Procurve to a Cisco _GigE_. So better disregard my answer. From cordmacleod at gmail.com Tue Apr 21 17:43:00 2009 From: cordmacleod at gmail.com (Cord MacLeod) Date: Tue, 21 Apr 2009 14:43:00 -0700 Subject: [c-nsp] routing multicast between vlans on a 3560 Message-ID: <560972D1-79EB-4912-ADDB-BDF18205898B@gmail.com> I'm curious as to the effects of multicast routing between vlans on a 3560. Are there any major performance hits? The devices are at around 10% CPU right now, so I'm not particularly worried. Also, I've seen some examples of how to do this from Cisco's website, http://www.cisco.com/en/US/tech/tk828/technologies_tech_note09186a0080094821.shtml . I've not worked much with multicast in the past, so this is somewhat new territory for me. Anything else I'm not thinking of that I should be aware of? From listacct at genhex.net Tue Apr 21 21:04:49 2009 From: listacct at genhex.net (Jeff Crowe) Date: Tue, 21 Apr 2009 21:04:49 -0400 Subject: [c-nsp] VLAN bridging on 3560 Message-ID: <000001c9c2e6$56376f70$02a64e50$@net> Hi all, I don't know if this is even possible but I'll try and make it work none the less! I am trying to bridge 4 vlans (reduced to 2 vlans for now to get working) together on a 3560 to allow a sudo transparent transport for a customer. The VLANs are delivered to me from a third party provider as dot1q vlans and all arrive on the same trunk port on the 3560. I have created the VLAN and SVI for each connection. In each SVI I have added bridge-group 2 to the configuration to each of the 4 svi's I would like to see bridged. I have bridge 2 protocol vlan-bridge configured as well as bridge irb in the configuration. The customer has a flat network of 192.168.0.x/24 configured on their equipment at each site and need to contact a host at site A. I am not able to get any response from each end point via the bridge, but if I place an IP on the SVI, I can pass traffic on each separate SVI. Mac addresses only appear on each vlan and not on the bridge group. # show bridge 2 group Bridge Group 2 is running the VLAN Bridge compatible Spanning Tree protocol Port 2280 (Vlan212) of bridge group 2 is forwarding Port 2282 (Vlan214) of bridge group 2 is forwarding interface Vlan212 no ip address bridge-group 2 end ! interface Vlan214 no ip address bridge-group 2 end Any idea's where I should start looking for clues? Regards, Jeff. From justin at justinshore.com Tue Apr 21 23:27:16 2009 From: justin at justinshore.com (Justin Shore) Date: Tue, 21 Apr 2009 22:27:16 -0500 Subject: [c-nsp] VTY Lines In-Reply-To: References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> <49EC7BE2.60100@scripty.com> Message-ID: <49EE8E94.7060503@justinshore.com> Lee wrote: > line vty 0 3 > access-class 100 in > line vty 4 > access-class 104 in > > Which means every single router fails when you put the config through RAT :( I went round and round with a security guy who audited our gear once over that. He made a huge stink over how we didn't have have passwords on our VTYs, con and aux ports. He took everything RAT had to say as gospel, as if there was no other (or better) way to address a security issue. We use AAA on all interfaces including con0. I have TACACS+ set up with local auth as the backup (and only one user account on the devices which I've gone to great lengths to protect). Aux is explicitly disabled. He just didn't get it. Sure I could add the password command to the VTY to appease him even though it wouldn't do a damn thing with AAA enabled. I didn't though and I used the password stink as part of my justification that RAT really only points out common and basic security problems and doesn't take into account any of the numerous ways of mitigating those problems with more advanced methods. In the end the audit was dropped. The actual problems in the audit were addressed. Any RAT fluff was ignored. There were several other things like that but the line passwords were the most obvious to even a non-technical person. While my installs may not be perfect, they are far better than average. I don't need someone second-guessing my work with a tool like RAT. Justin From justin at justinshore.com Wed Apr 22 00:09:54 2009 From: justin at justinshore.com (Justin Shore) Date: Tue, 21 Apr 2009 23:09:54 -0500 Subject: [c-nsp] c7201 error SFP is missing [0] In-Reply-To: <200904211019.06282.mtinka@globaltransit.net> References: <179270.35479.qm@web32403.mail.mud.yahoo.com> <200904211019.06282.mtinka@globaltransit.net> Message-ID: <49EE9892.7010309@justinshore.com> Mark Tinka wrote: > On Monday 20 April 2009 11:30:28 pm Belal Farouk wrote: > >> Source Severity Description [Index] >> ------ -------- ------------------- >> SFP Slot 0/3 CRITICAL SFP is missing [0] > > We've seen this in our logs, both on the NPE-G2 and 7201 - > code is 12.2(33)SRC3 or earlier. > > It hasn't caused any real problems, so we haven't really > followed up on it with TAC. Maybe we should :-). I see the same thing on a 7201 that I have had trouble with. I'm running 12.4(24)T. Gi0/3 has a SFP-GE-S in it. The link I had trouble with was Gi0/0 though. 0/0, 0/1 and 0/3 all show the error. 0 and 1 are actually RJ45 so I suppose this could be expected, though I'd prefer that the media-type command disable the SFP check on those interfaces. The problem I had was on gi0/3 with MTUs going out via copper onto a fiber media converter. It worked fine for several months and then one day it wigged out on me and started silently dropping jumbo frames. I have another 7201 with single-strand optics in Gi0/0 and 0/1. 0/2 and 0/3 are SX, same as above. 0/3 shows the error. Gi0/3 on the 7201 is the product of taking one of the unused PCI buses that would be servicing PA slots in a VXR chassis and turning it into a GigE interface. Justin From peter at rathlev.dk Wed Apr 22 01:06:24 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Wed, 22 Apr 2009 07:06:24 +0200 Subject: [c-nsp] VLAN bridging on 3560 In-Reply-To: <000001c9c2e6$56376f70$02a64e50$@net> References: <000001c9c2e6$56376f70$02a64e50$@net> Message-ID: <1240376784.3427.6.camel@localhost.localdomain> On Tue, 2009-04-21 at 21:04 -0400, Jeff Crowe wrote: > I don't know if this is even possible but I'll try and make it work > none the less! > > I am trying to bridge 4 vlans (reduced to 2 vlans for now to get > working) together on a 3560 to allow a sudo transparent transport for > a customer. ... The 3560 doesn't support regular bridging, only "fallback bridging" that generally just works for non-IP. http://www.cisco.com/en/US/docs/switches/lan/catalyst3560/software/release/12.2_46_se/configuration/guide/swfallbk.html http://tinyurl.com/d27d2u You could use a "real" router to do it, like a 2800. Alternatively, if you can accept that the spanning trees collapse, you can melt together the VLANs with to access ports loop to each other and members of each VLAN. You have to be a little careful though. Regards, Peter From lists at quux.de Wed Apr 22 05:51:33 2009 From: lists at quux.de (Jens Link) Date: Wed, 22 Apr 2009 11:51:33 +0200 Subject: [c-nsp] VTY Lines In-Reply-To: <49EE8E94.7060503@justinshore.com> (Justin Shore's message of "Tue\, 21 Apr 2009 22\:27\:16 -0500") References: <49E6ABD7.4030402@gmail.com> <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> <49EC7BE2.60100@scripty.com> <49EE8E94.7060503@justinshore.com> Message-ID: <87ab69qamy.fsf@laphroiag.quux.de> Justin Shore writes: > While my installs may not be perfect, they are far better than > average. I don't need someone second-guessing my work with a tool like > RAT. Agreed. But (IIRC) you can write your own rules for RAT. Combine this with rancid and you have a great way of finding thing you may have forgotten to configure. cheers, Jens -- ------------------------------------------------------------------------- | Foelderichstr. 40 | 13595 Berlin, Germany | +49-151-18721264 | | http://www.quux.de | http://blog.quux.de | jabber: jenslink at guug.de | ------------------------------------------------------------------------- From nick.jon.griffin at gmail.com Wed Apr 22 10:10:01 2009 From: nick.jon.griffin at gmail.com (Nick Griffin) Date: Wed, 22 Apr 2009 09:10:01 -0500 Subject: [c-nsp] GSS and ACE Message-ID: Does anyone know if you can use or even would want to use a GSS appliance without an ACE Module or Appliance? I like the idea of having data center redundancy/global site selection, however I'm not so sure the load balancing features of the ACE appliance are yet a requirement for a particular design I am working with is worth the cost. Thanks in advance. Nick Griffin From jcdarby at usgs.gov Wed Apr 22 10:39:18 2009 From: jcdarby at usgs.gov (Justin C Darby) Date: Wed, 22 Apr 2009 10:39:18 -0400 Subject: [c-nsp] GSS and ACE In-Reply-To: References: Message-ID: Nick, The primary benefit to these things, AFAIK, is the ACE integration for load balancing. I'm pretty sure there are other options (mostly software) available to do the same DNS load balancing without ACE's, but - ACE's are a great way to add redundancy to a site, and GSS+ACE can handle load balancing across many access points with integrated service monitoring and the like. Doing that without a device like the ACE is pretty complicated. Justin -----cisco-nsp-bounces at puck.nether.net wrote: ----- To: "cisco-nsp at puck.nether.net" From: Nick Griffin Sent by: cisco-nsp-bounces at puck.nether.net Date: 04/22/2009 09:18AM Subject: [c-nsp] GSS and ACE Does anyone know if you can use or even would want to use a GSS appliance without an ACE Module or Appliance? I like the idea of having data center redundancy/global site selection, however I'm not so sure the load balancing features of the ACE appliance are yet a requirement for a particular design I am working with is worth the cost. Thanks in advance. Nick Griffin _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From nick.jon.griffin at gmail.com Wed Apr 22 10:45:44 2009 From: nick.jon.griffin at gmail.com (Nick Griffin) Date: Wed, 22 Apr 2009 09:45:44 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: References: Message-ID: So say I had 2 datacenter locations geographically disperse and I'm not running BGP. I have similar web and smtp servers at each locations. I'm not so much concerned that traffic gets load balanced to a cluster of servers when traffic enters a particular data center (which is an ACE application), instead I'm concerned about D/R. Say I lose DataCenter 1, I want some DNS magic to take place to say that mail.mydomain.com has moved from 10.1.1.5 to 10.1.2.5 at Data Center 2. Does that make sense? On Wed, Apr 22, 2009 at 9:39 AM, Justin C Darby wrote: > > Nick, > > The primary benefit to these things, AFAIK, is the ACE integration for load > balancing. I'm pretty sure there are other options (mostly software) > available to do the same DNS load balancing without ACE's, but - ACE's are > a great way to add redundancy to a site, and GSS+ACE can handle load > balancing across many access points with integrated service monitoring and > the like. Doing that without a device like the ACE is pretty complicated. > > Justin > > -----cisco-nsp-bounces at puck.nether.net wrote: ----- > To: "cisco-nsp at puck.nether.net" > From: Nick Griffin > Sent by: cisco-nsp-bounces at puck.nether.net > Date: 04/22/2009 09:18AM > Subject: [c-nsp] GSS and ACE > > Does anyone know if you can use or even would want to use a GSS appliance > without an ACE Module or Appliance? I like the idea of having data center > redundancy/global site selection, however I'm not so sure the load > balancing features of the ACE appliance are yet a requirement for a > particular design I am working with is worth the cost. Thanks in advance. > Nick Griffin _______________________________________________ cisco-nsp > mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp archive at > http://puck.nether.net/pipermail/cisco-nsp/ > > From eric at roxanne.org Wed Apr 22 10:50:15 2009 From: eric at roxanne.org (Eric Gauthier) Date: Wed, 22 Apr 2009 10:50:15 -0400 Subject: [c-nsp] GSS and ACE In-Reply-To: References: Message-ID: <20090422145015.GA16677@roxanne.org> We're interested in the same sort of question. In our case, we have server groups who already handle local load balancing internally within their clusters. My group, the network team, wants to provide load balancing and automatic failover of traffic between our two campus data centers but we don't need the load piece nor, given the distributed nature of our campus, is it easy to force all traffic through a set of LB's before deciding which center should receive the traffic. Eric :) On Wed, Apr 22, 2009 at 09:45:44AM -0500, Nick Griffin wrote: > So say I had 2 datacenter locations geographically disperse and I'm not > running BGP. I have similar web and smtp servers at each locations. I'm not > so much concerned that traffic gets load balanced to a cluster of servers > when traffic enters a particular data center (which is an ACE application), > instead I'm concerned about D/R. Say I lose DataCenter 1, I want some DNS > magic to take place to say that mail.mydomain.com has moved from 10.1.1.5 to > 10.1.2.5 at Data Center 2. Does that make sense? > > > On Wed, Apr 22, 2009 at 9:39 AM, Justin C Darby wrote: > > > > > Nick, > > > > The primary benefit to these things, AFAIK, is the ACE integration for load > > balancing. I'm pretty sure there are other options (mostly software) > > available to do the same DNS load balancing without ACE's, but - ACE's are > > a great way to add redundancy to a site, and GSS+ACE can handle load > > balancing across many access points with integrated service monitoring and > > the like. Doing that without a device like the ACE is pretty complicated. > > > > Justin > > > > -----cisco-nsp-bounces at puck.nether.net wrote: ----- > > To: "cisco-nsp at puck.nether.net" > > From: Nick Griffin > > Sent by: cisco-nsp-bounces at puck.nether.net > > Date: 04/22/2009 09:18AM > > Subject: [c-nsp] GSS and ACE > > > > Does anyone know if you can use or even would want to use a GSS appliance > > without an ACE Module or Appliance? I like the idea of having data center > > redundancy/global site selection, however I'm not so sure the load > > balancing features of the ACE appliance are yet a requirement for a > > particular design I am working with is worth the cost. Thanks in advance. > > Nick Griffin _______________________________________________ cisco-nsp > > mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp archive at > > http://puck.nether.net/pipermail/cisco-nsp/ > > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From rdobbins at cisco.com Wed Apr 22 11:05:53 2009 From: rdobbins at cisco.com (Roland Dobbins) Date: Wed, 22 Apr 2009 23:05:53 +0800 Subject: [c-nsp] GSS and ACE In-Reply-To: <20090422145015.GA16677@roxanne.org> References: <20090422145015.GA16677@roxanne.org> Message-ID: On Apr 22, 2009, at 10:50 PM, Eric Gauthier wrote: > We're interested in the same sort of question. You can play all kinds of DNS games with GSS based upon load (via probes), perceived topological distance, up/down status, et. al. It has some DNS DoS self-defense mechanisms built in, too. There are some open-source tools which can be used to do various types of clustering/redirection/etc., as well: ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott From nick.jon.griffin at gmail.com Wed Apr 22 11:10:16 2009 From: nick.jon.griffin at gmail.com (Nick Griffin) Date: Wed, 22 Apr 2009 10:10:16 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: <8793293D-6420-4C09-96C0-2DDC62088FFD@cisco.com> References: <8793293D-6420-4C09-96C0-2DDC62088FFD@cisco.com> Message-ID: Right, my question was does it require ACE appliance or modules to work? I have the need for Global Site Selection, however I don't I need the application level load balancing at this point that is offered by the ACE. Also, are there any ties to particular vendor DNS servers, ie CNR? Gracias, Nick Griffin On Wed, Apr 22, 2009 at 9:52 AM, Roland Dobbins wrote: > > On Apr 22, 2009, at 10:45 PM, Nick Griffin wrote: > > Does that make sense? >> > > Sure - GSS does that. > > ----------------------------------------------------------------------- > Roland Dobbins > > Our dreams are still big; it's just the future that got small. > > -- Jason Scott > > From cisco-nsp at slepicka.net Wed Apr 22 11:12:59 2009 From: cisco-nsp at slepicka.net (James Slepicka) Date: Wed, 22 Apr 2009 10:12:59 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: References: Message-ID: <49EF33FB.90304@slepicka.net> You can use the GSS without an ACE (or CSS, or IOS-SLB...). You'll be limited to the basic keepalive checks (icmp ping, http head, etc.) to detect site availability; you won't be able to make load-based decisions, for example, but it will otherwise work fine. I just use the http head check for a couple of web sites where a basic up/down check is all that's required (though I also use scripted KALs where more complex decisions need to be made). James Nick Griffin wrote: > Does anyone know if you can use or even would want to use a GSS appliance > without an ACE Module or Appliance? I like the idea of having data center > redundancy/global site selection, however I'm not so sure the load > balancing features of the ACE appliance are yet a requirement for a > particular design I am working with is worth the cost. > Thanks in advance. > > Nick Griffin > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From rdobbins at cisco.com Wed Apr 22 11:21:42 2009 From: rdobbins at cisco.com (Roland Dobbins) Date: Wed, 22 Apr 2009 23:21:42 +0800 Subject: [c-nsp] GSS and ACE In-Reply-To: References: <8793293D-6420-4C09-96C0-2DDC62088FFD@cisco.com> Message-ID: On Apr 22, 2009, at 11:10 PM, Nick Griffin wrote: > Right, my question was does it require ACE appliance or modules to > work? No, can work independently, no problem. > Also, are there any ties to particular vendor DNS servers, ie CNR? It can hook into CNR, and is also its own DNS server (can work with anything else, too, obviously, through delegation). ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott From nick.jon.griffin at gmail.com Wed Apr 22 11:33:44 2009 From: nick.jon.griffin at gmail.com (Nick Griffin) Date: Wed, 22 Apr 2009 10:33:44 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: References: <8793293D-6420-4C09-96C0-2DDC62088FFD@cisco.com> Message-ID: Great, thanks to all. So am I to assume if I have X Data Centers, I need 1xX GSS's for redundancy? In other words if I had 2 sites and one GSS and the GSS is at the site that lost internet connectivity, its not going to do me much good. TIA On Wed, Apr 22, 2009 at 10:21 AM, Roland Dobbins wrote: > > On Apr 22, 2009, at 11:10 PM, Nick Griffin wrote: > > Right, my question was does it require ACE appliance or modules to work? >> > > No, can work independently, no problem. > > Also, are there any ties to particular vendor DNS servers, ie CNR? >> > > > It can hook into CNR, and is also its own DNS server (can work with > anything else, too, obviously, through delegation). > > ----------------------------------------------------------------------- > Roland Dobbins // +852.6904.8571 mobile > > Our dreams are still big; it's just the future that got small. > > -- Jason Scott > > _______________________________________________ > > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From tvarriale at comcast.net Wed Apr 22 11:34:20 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Wed, 22 Apr 2009 10:34:20 -0500 Subject: [c-nsp] GSS and ACE References: Message-ID: <6CB129AE25E44B14BAD3DC157E3B0C4F@flamdt01> I can't say I've ever done this but the GSS does have the ability to probe other devices/brands via SNMP. Also, there is good scripting capability. So, my initial answer is yes. Keep in mind, GSS isn't a "real" DNS server. It's more of a DNS proxy... tv ----- Original Message ----- From: "Nick Griffin" To: Sent: Wednesday, April 22, 2009 9:10 AM Subject: [c-nsp] GSS and ACE > Does anyone know if you can use or even would want to use a GSS appliance > without an ACE Module or Appliance? I like the idea of having data center > redundancy/global site selection, however I'm not so sure the load > balancing features of the ACE appliance are yet a requirement for a > particular design I am working with is worth the cost. > Thanks in advance. > > Nick Griffin > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From robbie.jacka at regions.com Wed Apr 22 11:39:19 2009 From: robbie.jacka at regions.com (robbie.jacka at regions.com) Date: Wed, 22 Apr 2009 10:39:19 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: Message-ID: Saying that the GSS is it's own DNS server isn't quite right - while it performs DNS resolution for configured host records (based on rules), I don't believe that it can recurse on behalf of a client, nor can it actually perform AXFRs, as far as I am aware. In other words, it does some DNS-related functions exceptionally well (rules, monitoring, etc) it does not do others at all. -- robbie Roland Dobbins To Sent by: Cisco-nsp cisco-nsp-bounces @puck.nether.net cc Subject 04/22/2009 10:30 Re: [c-nsp] GSS and ACE AM On Apr 22, 2009, at 11:10 PM, Nick Griffin wrote: > Right, my question was does it require ACE appliance or modules to > work? No, can work independently, no problem. > Also, are there any ties to particular vendor DNS servers, ie CNR? It can hook into CNR, and is also its own DNS server (can work with anything else, too, obviously, through delegation). ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From rdobbins at cisco.com Wed Apr 22 12:00:55 2009 From: rdobbins at cisco.com (Roland Dobbins) Date: Thu, 23 Apr 2009 00:00:55 +0800 Subject: [c-nsp] GSS and ACE In-Reply-To: References: <8793293D-6420-4C09-96C0-2DDC62088FFD@cisco.com> Message-ID: <26639FCD-78B5-41BF-898F-2C06DFA5CD65@cisco.com> On Apr 22, 2009, at 11:33 PM, Nick Griffin wrote: > Great, thanks to all. So am I to assume if I have X Data Centers, I > need 1xX > GSS's for redundancy? I'd put a cluster of 2 at each IDC, something like that. ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott From rdobbins at cisco.com Wed Apr 22 12:01:50 2009 From: rdobbins at cisco.com (Roland Dobbins) Date: Thu, 23 Apr 2009 00:01:50 +0800 Subject: [c-nsp] GSS and ACE In-Reply-To: References: Message-ID: <703EE2AB-67D5-424C-9236-11D284B2D7F4@cisco.com> On Apr 22, 2009, at 11:39 PM, robbie.jacka at regions.com wrote: > . In other words, it does some > DNS-related functions exceptionally well (rules, monitoring, etc) it > does > not do others at all. You're right - I should've said, ". . . task-specific, limited-subset DNS server." Good catch! ;> ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott From rdobbins at cisco.com Wed Apr 22 12:03:26 2009 From: rdobbins at cisco.com (Roland Dobbins) Date: Thu, 23 Apr 2009 00:03:26 +0800 Subject: [c-nsp] GSS and ACE In-Reply-To: <6CB129AE25E44B14BAD3DC157E3B0C4F@flamdt01> References: <6CB129AE25E44B14BAD3DC157E3B0C4F@flamdt01> Message-ID: On Apr 22, 2009, at 11:34 PM, Tony Varriale wrote: > I can't say I've ever done this but the GSS does have the ability to > probe other devices/brands via SNMP. Also, there is good scripting > capability. Yes on both counts. It's actually a neat little box. Not many folks seem to know about it, but it's surprisingly useful, and most of the features make operational sense (note that the 'anycast' feature is not in fact anycast as is commonly understood, heh). ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott From vijay.ramcharan at verizonbusiness.com Wed Apr 22 12:22:48 2009 From: vijay.ramcharan at verizonbusiness.com (Ramcharan, Vijay A) Date: Wed, 22 Apr 2009 16:22:48 +0000 Subject: [c-nsp] GSS and ACE In-Reply-To: <703EE2AB-67D5-424C-9236-11D284B2D7F4@cisco.com> Message-ID: <8171C8272CE8FE4A8F5BFF8A97CE6AB37EEB5D@ASHEVS006.mcilink.com> You can always do F5 GTM if you need a full fledged DNS server (runs BIND I think). Vijay Ramcharan -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Roland Dobbins Sent: April 22, 2009 12:02 To: Cisco-nsp Subject: Re: [c-nsp] GSS and ACE On Apr 22, 2009, at 11:39 PM, robbie.jacka at regions.com wrote: > . In other words, it does some > DNS-related functions exceptionally well (rules, monitoring, etc) it > does > not do others at all. You're right - I should've said, ". . . task-specific, limited-subset DNS server." Good catch! ;> ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ ______________________________________________________________________ This e-mail has been scanned by Verizon Managed Email Content Service, using Skeptic(tm) technology powered by MessageLabs. For more information on Verizon Managed Email Content Service, visit http://www.verizonbusiness.com. ______________________________________________________________________ From robbie.jacka at regions.com Wed Apr 22 12:26:26 2009 From: robbie.jacka at regions.com (robbie.jacka at regions.com) Date: Wed, 22 Apr 2009 11:26:26 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: Message-ID: Agreed. The learning curve on it is roughly equivalent to SVR4, but once you've gotten the basics down, it's a remarkably awesome device. -- robbie Roland Dobbins To Sent by: Cisco-nsp cisco-nsp-bounces @puck.nether.net cc Subject 04/22/2009 11:22 Re: [c-nsp] GSS and ACE AM On Apr 22, 2009, at 11:34 PM, Tony Varriale wrote: > I can't say I've ever done this but the GSS does have the ability to > probe other devices/brands via SNMP. Also, there is good scripting > capability. Yes on both counts. It's actually a neat little box. Not many folks seem to know about it, but it's surprisingly useful, and most of the features make operational sense (note that the 'anycast' feature is not in fact anycast as is commonly understood, heh). ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From robbie.jacka at regions.com Wed Apr 22 12:38:08 2009 From: robbie.jacka at regions.com (robbie.jacka at regions.com) Date: Wed, 22 Apr 2009 11:38:08 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: <8171C8272CE8FE4A8F5BFF8A97CE6AB37EEB5D@ASHEVS006.mcilink.com> Message-ID: or purchase the appropriate CNR licensing for the GSS and install it. the basic box license just isn't really a full fledged DNS server, but can have CNR and/or the cisco guard anti-DDoS functionality installed on it. -- robbie "Ramcharan, Vijay A" Sent by: cc cisco-nsp-bounces @puck.nether.net Subject Re: [c-nsp] GSS and ACE 04/22/2009 11:34 AM You can always do F5 GTM if you need a full fledged DNS server (runs BIND I think). Vijay Ramcharan -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Roland Dobbins Sent: April 22, 2009 12:02 To: Cisco-nsp Subject: Re: [c-nsp] GSS and ACE On Apr 22, 2009, at 11:39 PM, robbie.jacka at regions.com wrote: > . In other words, it does some > DNS-related functions exceptionally well (rules, monitoring, etc) it > does > not do others at all. You're right - I should've said, ". . . task-specific, limited-subset DNS server." Good catch! ;> ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ ______________________________________________________________________ This e-mail has been scanned by Verizon Managed Email Content Service, using Skeptic(tm) technology powered by MessageLabs. For more information on Verizon Managed Email Content Service, visit http://www.verizonbusiness.com. ______________________________________________________________________ _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From ncnet at sbcglobal.net Wed Apr 22 12:30:51 2009 From: ncnet at sbcglobal.net (Larry Stites) Date: Wed, 22 Apr 2009 09:30:51 -0700 Subject: [c-nsp] GSS and ACE In-Reply-To: Message-ID: We recently supplied (4) ACE20-MOD-K9 to a customer overseas for $17k/ea. These units were previously owned spares, unused, box opened to inspect contents. All units were complete with sealed software package and EULA paperwork. The customer had a problem with recognition of the card in 6509 running SUP720-3BXL. The solution was IOS 12.2(18)SXF4 for ACE support in 6500/SUP720. They were running 12.2-18.SXD7 and according to the requirements, they needed 12.2-18.SXF or newer and 12.2-33.SXI or newer for it to run in virtual switch mode. The ACE20-MOD-K9 run in order of release; A, B, C, D, E, F, G, H, I etc. etc. Customer was running D and the specs on Cisco?s site say they need F. Note Supervisor Engine 32 does not support ACE10-6500-K9 or ACE20-MOD-K9. I am also including the link down below so you can look at it yourself. There is a section for the ACE modules in there. If you are interested take a look at this cut and paste: Application Control Engine (ACE) Module Product ID (append "=" for spares) Power Required Product Description Minimum Software Versions ACE10-6500-K9 ACE20-MOD-K9 5.23 A at 42 V Application Control Engine (ACE) module Note With releases earlier than Release 12.2(33)SXI, not supported in virtual switch mode. With Supervisor Engine 720-10GE 12.2(33)SXH With Supervisor Engine 720 12.2(18)SXF4 ACE10-6500-K9 and ACE20-MOD-K9 run their own software?See these publications: http://www.cisco.com/en/US/products/ps6906/tsd_products_support_model_home.h tml See the ACE10-6500-K9 and ACE20-MOD-K9 software release notes for information about the minimum required service module software version. http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/release /notes/ol_14271.html#wp2982155 Best regards, Larry E. Stites Northern California Networks, Inc. CA LIC# 2004 SR KH 100-484111 Nevada City, CA 95959 cell 530 320 4194 land 530 265 2588 ncnet at sbcglobal.net IM: LESGGN on 4/22/09 7:10 AM, Nick Griffin wrote: > Does anyone know if you can use or even would want to use a GSS appliance > without an ACE Module or Appliance? I like the idea of having data center > redundancy/global site selection, however I'm not so sure the load > balancing features of the ACE appliance are yet a requirement for a > particular design I am working with is worth the cost. > Thanks in advance. > > Nick Griffin > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From ayourtch at gmail.com Wed Apr 22 16:40:25 2009 From: ayourtch at gmail.com (Andrew Yourtchenko) Date: Wed, 22 Apr 2009 22:40:25 +0200 Subject: [c-nsp] VTY Lines In-Reply-To: <49EE8E94.7060503@justinshore.com> References: <876789290904152118u451d667bmb0d6873725de22a4@mail.gmail.com> <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> <49EC7BE2.60100@scripty.com> <49EE8E94.7060503@justinshore.com> Message-ID: <530c5af60904221340t49c22609t9655543d8cf0c190@mail.gmail.com> On Wed, Apr 22, 2009 at 5:27 AM, Justin Shore wrote: > on all interfaces including con0. I have TACACS+ set up with local auth as > the backup (and only one user account on the devices which I've gone to > great lengths to protect). Aux is explicitly disabled. He just didn't get > it. Sure I could add the password command to the VTY to appease him even I'd venture to think it was more about trying to prevent the potential corner cases. Of course there is a lot of preconditions for that "line of the defense" to be hit - but it all depends. After all, most of us have an insurance for the case of the proverbial "being hit by a bus" - even though those are the events we all carefully try to avoid. (Or so I would hope:-) Back to the original post - without the version hard to tell, but I've seen CSCsc70644 causing similar symptoms. If that does not match, I'd say open up a case so the TAC folks take a closer look. cheers, andrew From Jay.Murphy at state.nm.us Wed Apr 22 17:13:05 2009 From: Jay.Murphy at state.nm.us (Murphy, Jay, DOH) Date: Wed, 22 Apr 2009 15:13:05 -0600 Subject: [c-nsp] Replacement for a Catalyst 4006? Message-ID: Anyone from this forum replaced (I'm sure) or fork-lifted an upgrade to something greater than the suggested upgrade path for a Catalyst 4006?? Responses welcomed. Jay Murphy IP Network Specialist NM State Government IT Services Division PSB - IP Network Operations Santa F?, New M?xico 87502 "We move the information that moves your world." P Please consider the environment before printing e-mail Confidentiality Notice: This e-mail, including all attachments is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure or distribution is prohibited unless specifically provided under the New Mexico Inspection of Public Records Act. If you are not the intended recipient, please contact the sender and destroy all copies of this message. -- This email has been scanned by the Sybari - Antigen Email System. From felixnkansah at gmail.com Wed Apr 22 17:45:25 2009 From: felixnkansah at gmail.com (Felix Nkansah) Date: Wed, 22 Apr 2009 21:45:25 +0000 Subject: [c-nsp] Automatically Synchronize IOS Router Configurations? Message-ID: <18dba4e50904221445o49a6da3aubb9ccc2d1927551a@mail.gmail.com> Hi Team, I am prospecting a short contract from a client (an ISP) who wants to redesign their internal and edge networks. Among other things, their requirement is for their HSRP or GLBP routers to automatically synchronize their running configurations. So that when configurations changes are made on the active router, it is replicated onto the standby box (like is done on Cisco firewall appliances in failover mode). During my meeting with the client to define their requirements, I explained that I am not aware of any functionality to automatically synchronize running configs between two IOS routers just because they are in an HSRP or GLBP group. However, I have just received an official requirements definition (contract terms) from the client and that requirement is stated in bold characters. Was wondering if I have been missing any such feature in IOS routers for this long? Many thanks, Felix From tvarriale at comcast.net Wed Apr 22 18:19:57 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Wed, 22 Apr 2009 17:19:57 -0500 Subject: [c-nsp] Replacement for a Catalyst 4006? References: Message-ID: What are the requirements? Quite honestly, I'm trying to forget anything 400x :) tv ----- Original Message ----- From: "Murphy, Jay, DOH" To: Sent: Wednesday, April 22, 2009 4:13 PM Subject: [c-nsp] Replacement for a Catalyst 4006? Anyone from this forum replaced (I'm sure) or fork-lifted an upgrade to something greater than the suggested upgrade path for a Catalyst 4006?? Responses welcomed. Jay Murphy IP Network Specialist NM State Government IT Services Division PSB - IP Network Operations Santa F?, New M?xico 87502 "We move the information that moves your world." P Please consider the environment before printing e-mail Confidentiality Notice: This e-mail, including all attachments is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure or distribution is prohibited unless specifically provided under the New Mexico Inspection of Public Records Act. If you are not the intended recipient, please contact the sender and destroy all copies of this message. -- This email has been scanned by the Sybari - Antigen Email System. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From tvarriale at comcast.net Wed Apr 22 18:22:54 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Wed, 22 Apr 2009 17:22:54 -0500 Subject: [c-nsp] GSS and ACE References: Message-ID: Not sure if this is a question or a statement...but... I would look to run high SXF (12?) or SXH1. Note, some folks are having issues with SXH so it really depends on their load out and features. As for VSS, you shouldn't really be running SXH VSS. SXI or higher only please. :) tv ----- Original Message ----- From: "Larry Stites" To: "Nick Griffin" ; Sent: Wednesday, April 22, 2009 11:30 AM Subject: Re: [c-nsp] GSS and ACE We recently supplied (4) ACE20-MOD-K9 to a customer overseas for $17k/ea. These units were previously owned spares, unused, box opened to inspect contents. All units were complete with sealed software package and EULA paperwork. The customer had a problem with recognition of the card in 6509 running SUP720-3BXL. The solution was IOS 12.2(18)SXF4 for ACE support in 6500/SUP720. They were running 12.2-18.SXD7 and according to the requirements, they needed 12.2-18.SXF or newer and 12.2-33.SXI or newer for it to run in virtual switch mode. The ACE20-MOD-K9 run in order of release; A, B, C, D, E, F, G, H, I etc. etc. Customer was running D and the specs on Cisco?s site say they need F. Note Supervisor Engine 32 does not support ACE10-6500-K9 or ACE20-MOD-K9. I am also including the link down below so you can look at it yourself. There is a section for the ACE modules in there. If you are interested take a look at this cut and paste: Application Control Engine (ACE) Module Product ID (append "=" for spares) Power Required Product Description Minimum Software Versions ACE10-6500-K9 ACE20-MOD-K9 5.23 A at 42 V Application Control Engine (ACE) module Note With releases earlier than Release 12.2(33)SXI, not supported in virtual switch mode. With Supervisor Engine 720-10GE 12.2(33)SXH With Supervisor Engine 720 12.2(18)SXF4 ACE10-6500-K9 and ACE20-MOD-K9 run their own software publications: http://www.cisco.com/en/US/products/ps6906/tsd_products_support_model_home.h tml See the ACE10-6500-K9 and ACE20-MOD-K9 software release notes for information about the minimum required service module software version. http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/release /notes/ol_14271.html#wp2982155 Best regards, Larry E. Stites Northern California Networks, Inc. CA LIC# 2004 SR KH 100-484111 Nevada City, CA 95959 cell 530 320 4194 land 530 265 2588 ncnet at sbcglobal.net IM: LESGGN on 4/22/09 7:10 AM, Nick Griffin wrote: > Does anyone know if you can use or even would want to use a GSS appliance > without an ACE Module or Appliance? I like the idea of having data center > redundancy/global site selection, however I'm not so sure the load > balancing features of the ACE appliance are yet a requirement for a > particular design I am working with is worth the cost. > Thanks in advance. > > Nick Griffin > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From tvarriale at comcast.net Wed Apr 22 18:25:04 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Wed, 22 Apr 2009 17:25:04 -0500 Subject: [c-nsp] GSS and ACE References: <6CB129AE25E44B14BAD3DC157E3B0C4F@flamdt01> Message-ID: <296AF95FA44442B3AA97523A85358AEA@flamdt01> Yeah, good boxes. A lot of the functionality was already in the CSSes but stripped in the ACE. :) I've only done them with ACE and just a couple. That market is dominated by someone else. :) tv ----- Original Message ----- From: "Roland Dobbins" To: "Cisco-nsp" Sent: Wednesday, April 22, 2009 11:03 AM Subject: Re: [c-nsp] GSS and ACE > > On Apr 22, 2009, at 11:34 PM, Tony Varriale wrote: > >> I can't say I've ever done this but the GSS does have the ability to >> probe other devices/brands via SNMP. Also, there is good scripting >> capability. > > > Yes on both counts. > > It's actually a neat little box. Not many folks seem to know about it, > but it's surprisingly useful, and most of the features make operational > sense (note that the 'anycast' feature is not in fact anycast as is > commonly understood, heh). > > ----------------------------------------------------------------------- > Roland Dobbins // +852.6904.8571 mobile > > Our dreams are still big; it's just the future that got small. > > -- Jason Scott > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From tvarriale at comcast.net Wed Apr 22 18:27:08 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Wed, 22 Apr 2009 17:27:08 -0500 Subject: [c-nsp] Automatically Synchronize IOS Router Configurations? References: <18dba4e50904221445o49a6da3aubb9ccc2d1927551a@mail.gmail.com> Message-ID: Doesn't really exist AFAIK. You would have to script something maybe through EEM and/or management. Note the CSSes have this but it's just a canned script. :) tv ----- Original Message ----- From: "Felix Nkansah" To: Sent: Wednesday, April 22, 2009 4:45 PM Subject: [c-nsp] Automatically Synchronize IOS Router Configurations? > Hi Team, > I am prospecting a short contract from a client (an ISP) who wants to > redesign their internal and edge networks. > > Among other things, their requirement is for their HSRP or GLBP routers to > automatically synchronize their running configurations. > > So that when configurations changes are made on the active router, it is > replicated onto the standby box (like is done on Cisco firewall appliances > in failover mode). > > During my meeting with the client to define their requirements, I > explained > that I am not aware of any functionality to automatically synchronize > running configs between two IOS routers just because they are in an HSRP > or > GLBP group. > > However, I have just received an official requirements definition > (contract > terms) from the client and that requirement is stated in bold characters. > > Was wondering if I have been missing any such feature in IOS routers for > this long? > > Many thanks, > > Felix > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From graham at g-rock.net Wed Apr 22 18:38:43 2009 From: graham at g-rock.net (Graham Wooden) Date: Wed, 22 Apr 2009 17:38:43 -0500 Subject: [c-nsp] Automatically Synchronize IOS Router Configurations? In-Reply-To: <18dba4e50904221445o49a6da3aubb9ccc2d1927551a@mail.gmail.com> Message-ID: Sync between each other? Yeah, you will have to look at something external, something that would have write perms (like through SNMP or AAA). Maybe a tacacs+ system can do this? I know there are products/scripts that can tftp off / snmp read the config and store them off. There maybe a push mechanism as well? But you are correct - just because they are in a HSRP standby group, doesn't mean that they can replicate. And with good reason too - there are somethings you *don't* want to replicate, and a blanket copy-over would be bad.... HTH, -graham On 4/22/09 4:45 PM, "Felix Nkansah" wrote: > Hi Team, > I am prospecting a short contract from a client (an ISP) who wants to > redesign their internal and edge networks. > > Among other things, their requirement is for their HSRP or GLBP routers to > automatically synchronize their running configurations. > > So that when configurations changes are made on the active router, it is > replicated onto the standby box (like is done on Cisco firewall appliances > in failover mode). > > During my meeting with the client to define their requirements, I explained > that I am not aware of any functionality to automatically synchronize > running configs between two IOS routers just because they are in an HSRP or > GLBP group. > > However, I have just received an official requirements definition (contract > terms) from the client and that requirement is stated in bold characters. > > Was wondering if I have been missing any such feature in IOS routers for > this long? > > Many thanks, > > Felix > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From lists at memetic.org Wed Apr 22 19:16:03 2009 From: lists at memetic.org (Adam Armstrong) Date: Thu, 23 Apr 2009 00:16:03 +0100 Subject: [c-nsp] Automatically Synchronize IOS Router Configurations? In-Reply-To: References: Message-ID: <49EFA533.7010707@memetic.org> Graham Wooden wrote: > Sync between each other? Yeah, you will have to look at something external, > something that would have write perms (like through SNMP or AAA). Maybe a > tacacs+ system can do this? I know there are products/scripts that can tftp > off / snmp read the config and store them off. There maybe a push mechanism > as well? > > But you are correct - just because they are in a HSRP standby group, doesn't > mean that they can replicate. And with good reason too - there are > somethings you *don't* want to replicate, and a blanket copy-over would be > bad.... > Not to mention that unlike a firewall, there should be relatively few changes to a router. Assuming it's not doing filtering/NAT or other things requiring lots of changes, of course. If it's just a case of adding a new VLAN/Subinterface and putting an IP in it and the VLAN/Subif/IP scheme is predictable, I guess it could be easily scripted via snmp/tftp or telnet/ssh(+clogin?) We do something similar for blanket config changes like ACLs and BGP peers. It works quite well, but if we had time to do it by hand to so many devices we'd probably prefer to... adam. From brhedlun at cisco.com Wed Apr 22 23:00:24 2009 From: brhedlun at cisco.com (Brad Hedlund) Date: Wed, 22 Apr 2009 22:00:24 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: Message-ID: On 4/22/09 10:39 AM, "robbie.jacka at regions.com" wrote: > Saying that the GSS is it's own DNS server isn't quite right Not true. GSS can also operate entirely as a full blown DNS server. "Using software versions 2.0 through 3.0(x), GSS product capabilities have been enhanced to allow the GSS to migrate to the top level of the DNS hierarchy" http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/g ss4400series/v3.1/configuration/cli/gslb/guide/Intro.html#wp1264301 Cheers Brad Hedlund bhedlund at cisco.com http://www.internetworkexpert.org From ianh at chime.net.au Wed Apr 22 23:07:47 2009 From: ianh at chime.net.au (Ian Henderson) Date: Thu, 23 Apr 2009 11:07:47 +0800 Subject: [c-nsp] Automatically Synchronize IOS Router Configurations? In-Reply-To: <18dba4e50904221445o49a6da3aubb9ccc2d1927551a@mail.gmail.com> References: <18dba4e50904221445o49a6da3aubb9ccc2d1927551a@mail.gmail.com> Message-ID: <100362309621454DAA534950B17E55DB011631552F85@isp-per-exc01.win2k.iinet.net.au> Felix Nkansah wrote on 2009-04-23: > Among other things, their requirement is for their HSRP or GLBP routers > to automatically synchronize their running configurations. You could avoid the problem entirely, but still meet the objective by using VSS? Rgds, - I. -- Ian Henderson, CCIE #14721 Senior Network Engineer, iiNet Limited From hank at efes.iucc.ac.il Thu Apr 23 00:26:17 2009 From: hank at efes.iucc.ac.il (Hank Nussbacher) Date: Thu, 23 Apr 2009 07:26:17 +0300 Subject: [c-nsp] GSS and ACE In-Reply-To: <26639FCD-78B5-41BF-898F-2C06DFA5CD65@cisco.com> References: <8793293D-6420-4C09-96C0-2DDC62088FFD@cisco.com> Message-ID: <5.1.0.14.2.20090423072449.00aef970@efes.iucc.ac.il> At 12:00 AM 23-04-09 +0800, Roland Dobbins wrote: >On Apr 22, 2009, at 11:33 PM, Nick Griffin wrote: > >>Great, thanks to all. So am I to assume if I have X Data Centers, I >>need 1xX >>GSS's for redundancy? > > >I'd put a cluster of 2 at each IDC, something like that. Why 2 at each IDC? Since each box acts as a backup for the other, if IDC #1 goes down - then the GSS at IDC #2 takes over. What benefit, other than to Cisco share value, would someone get to having 2x GSS at each IDC? -Hank From hank at efes.iucc.ac.il Thu Apr 23 00:37:04 2009 From: hank at efes.iucc.ac.il (Hank Nussbacher) Date: Thu, 23 Apr 2009 07:37:04 +0300 Subject: [c-nsp] GSS and ACE In-Reply-To: References: Message-ID: <5.1.0.14.2.20090423072656.00b235a0@efes.iucc.ac.il> At 09:45 AM 22-04-09 -0500, Nick Griffin wrote: >So say I had 2 datacenter locations geographically disperse and I'm not >running BGP. I have similar web and smtp servers at each locations. I'm not >so much concerned that traffic gets load balanced to a cluster of servers >when traffic enters a particular data center (which is an ACE application), >instead I'm concerned about D/R. Say I lose DataCenter 1, I want some DNS >magic to take place to say that mail.mydomain.com has moved from 10.1.1.5 to >10.1.2.5 at Data Center 2. Does that make sense? In addition to the GSS solutions which has been discussed here, there are outsourced solutions that essentially do the same thing. Neustar (used to be UltraDNS): http://www.ultradns.com/solutions/traffic.html [See Sitebacker] Level3: http://www.level3.com/brochures/e_brochures/ITM_brochure_C.pdf [ITM service] Akamai: http://www.akamai.com/html/technology/products/gtm.html [GTM service] Each has different bells and whistles as well as different pricing based on DNS load, but in general, the cost of a single GSS should provide you with their service for at least a year. The benefits are you don't have to manage the GSS and the service is outsourced to those who maintain 10-20 globally disparate DNS servers and who hopefully know how to run the service in a bullet-proof manner. Regards, Hank From rdobbins at cisco.com Thu Apr 23 00:50:28 2009 From: rdobbins at cisco.com (Roland Dobbins) Date: Thu, 23 Apr 2009 12:50:28 +0800 Subject: [c-nsp] GSS and ACE In-Reply-To: <5.1.0.14.2.20090423072449.00aef970@efes.iucc.ac.il> References: <8793293D-6420-4C09-96C0-2DDC62088FFD@cisco.com> <5.1.0.14.2.20090423072449.00aef970@efes.iucc.ac.il> Message-ID: <86D3E086-B5DD-49E3-BB45-BC3C5F26040F@cisco.com> On Apr 23, 2009, at 12:26 PM, Hank Nussbacher wrote: > Why 2 at each IDC? Since each box acts as a backup for the other, > if IDC #1 goes down - then the GSS at IDC #2 takes over. Because if IDC #1 goes offline entirely, your DNS for whatever services you're running are now hanging by a single thread in IDC #2, until IDC #1 comes back up. > What benefit, other than to Cisco share value, would someone get to > having 2x GSS at each IDC? See above. I'm not a salesman, I derive no benefit from suggesting folks overload on GSSes. From an availability standpoint, that's simply my considered professional opinion, YMMV. ----------------------------------------------------------------------- Roland Dobbins // +852.6904.8571 mobile Our dreams are still big; it's just the future that got small. -- Jason Scott From reuben-cisco-nsp at reub.net Thu Apr 23 00:47:33 2009 From: reuben-cisco-nsp at reub.net (Reuben Farrelly) Date: Thu, 23 Apr 2009 14:47:33 +1000 Subject: [c-nsp] Automatically Synchronize IOS Router Configurations? In-Reply-To: <100362309621454DAA534950B17E55DB011631552F85@isp-per-exc01.win2k.iinet.net.au> References: <18dba4e50904221445o49a6da3aubb9ccc2d1927551a@mail.gmail.com> <100362309621454DAA534950B17E55DB011631552F85@isp-per-exc01.win2k.iinet.net.au> Message-ID: <49EFF2E5.1070502@reub.net> On 23/04/2009 1:07 PM, Ian Henderson wrote: > Felix Nkansah wrote on 2009-04-23: > >> Among other things, their requirement is for their HSRP or GLBP routers >> to automatically synchronize their running configurations. > > You could avoid the problem entirely, but still meet the objective by using VSS? How about using the "archive" commands in IOS to remotely copy the config off the router every time it was saved, something like this: archive log config path tftp://192.168.10.10:/configs/router/router-confg write-memory ...and then run a kron (yes Kron not Cron) job on the router to periodically copy the config from that tftp location into startup? Then if you wanted to get especially fancy then have an event manager (EEM) script on router 2 which upon detecting that the other router was down, would send an email alert off, initiate a reload 60 seconds later and come up with the config from router 1 which was in startup-config? I'd be wary of implementing that step without a lot of testing, but it might work for you... Reuben From tseveendorj at gmail.com Thu Apr 23 02:17:58 2009 From: tseveendorj at gmail.com (Tseveendorj) Date: Thu, 23 Apr 2009 14:17:58 +0800 Subject: [c-nsp] SNMP OID of 3825 router Message-ID: <49F00816.30101@gmail.com> Hello, How do I know logged user on 3825 by SNMP ? Really appreciate for any help. Sincerely, Tseveen. From engel.labiro at gmail.com Thu Apr 23 04:06:09 2009 From: engel.labiro at gmail.com (Engelhard Labiro) Date: Thu, 23 Apr 2009 17:06:09 +0900 Subject: [c-nsp] SNMP OID of 3825 router In-Reply-To: <49F00816.30101@gmail.com> References: <49F00816.30101@gmail.com> Message-ID: <51D68322-E2AF-43A6-9F90-B6CCCF06B326@gmail.com> Try "SNMP object navigator" at cisco.com's Tools&Resources. On Apr 23, 2009, at 3:17 PM, Tseveendorj wrote: > Hello, > > How do I know logged user on 3825 by SNMP ? > > Really appreciate for any help. > > Sincerely, > Tseveen. > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From chaz at chaz6.com Thu Apr 23 09:27:33 2009 From: chaz at chaz6.com (Chris Hills) Date: Thu, 23 Apr 2009 15:27:33 +0200 Subject: [c-nsp] Automatically Synchronize IOS Router Configurations? In-Reply-To: <18dba4e50904221445o49a6da3aubb9ccc2d1927551a@mail.gmail.com> References: <18dba4e50904221445o49a6da3aubb9ccc2d1927551a@mail.gmail.com> Message-ID: On 22/04/09 23:45, Felix Nkansah wrote: > Hi Team, > I am prospecting a short contract from a client (an ISP) who wants to > redesign their internal and edge networks. > > Among other things, their requirement is for their HSRP or GLBP routers to > automatically synchronize their running configurations. > > So that when configurations changes are made on the active router, it is > replicated onto the standby box (like is done on Cisco firewall appliances > in failover mode). > > During my meeting with the client to define their requirements, I explained > that I am not aware of any functionality to automatically synchronize > running configs between two IOS routers just because they are in an HSRP or > GLBP group. > > However, I have just received an official requirements definition (contract > terms) from the client and that requirement is stated in bold characters. > > Was wondering if I have been missing any such feature in IOS routers for > this long? > > Many thanks, > > Felix If that functionality is not explicitly available, the way I would proceed is to write the configuration first to a configuration store, then to the standby host, and finally to the live host. This would make sure that records are up to date, and any potential configuration errors are discovered before going into production. From tvarriale at comcast.net Thu Apr 23 10:02:56 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Thu, 23 Apr 2009 09:02:56 -0500 Subject: [c-nsp] GSS and ACE References: Message-ID: <63516B148FED440F980D3F71B162779C@flamdt01> The GSS is definitely not that. If you use it with CNR, yes. Since CNR is that product, shazam. But as said in my previous post, GSS still isn't a DNS server...it's more like a proxy. tv ----- Original Message ----- From: "Brad Hedlund" To: ; "Roland Dobbins" Cc: "Cisco-nsp" ; Sent: Wednesday, April 22, 2009 10:00 PM Subject: Re: [c-nsp] GSS and ACE > > On 4/22/09 10:39 AM, "robbie.jacka at regions.com" > wrote: > >> Saying that the GSS is it's own DNS server isn't quite right > > Not true. GSS can also operate entirely as a full blown DNS server. > > > "Using software versions 2.0 through 3.0(x), GSS product capabilities have > been enhanced to allow the GSS to migrate to the top level of the DNS > hierarchy" > > http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/g > ss4400series/v3.1/configuration/cli/gslb/guide/Intro.html#wp1264301 > > > > Cheers > > Brad Hedlund > bhedlund at cisco.com > http://www.internetworkexpert.org > > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From robbie.jacka at regions.com Thu Apr 23 10:13:17 2009 From: robbie.jacka at regions.com (robbie.jacka at regions.com) Date: Thu, 23 Apr 2009 09:13:17 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: <63516B148FED440F980D3F71B162779C@flamdt01> Message-ID: installing CNR on a GSS does not make it GSS a DNS server, much as sticking a feather up your rear does not make you a chicken. :D as tony stated, CNR is still a separate product - it's simply installed *on* the GSS. a good product, to be sure - but with attendant licensing needs. -- robbie "Tony Varriale" To Sent by: "Cisco-nsp" cisco-nsp-bounces @puck.nether.net cc Subject 04/23/2009 09:09 Re: [c-nsp] GSS and ACE AM The GSS is definitely not that. If you use it with CNR, yes. Since CNR is that product, shazam. But as said in my previous post, GSS still isn't a DNS server...it's more like a proxy. tv ----- Original Message ----- From: "Brad Hedlund" To: ; "Roland Dobbins" Cc: "Cisco-nsp" ; Sent: Wednesday, April 22, 2009 10:00 PM Subject: Re: [c-nsp] GSS and ACE > > On 4/22/09 10:39 AM, "robbie.jacka at regions.com" > wrote: > >> Saying that the GSS is it's own DNS server isn't quite right > > Not true. GSS can also operate entirely as a full blown DNS server. > > > "Using software versions 2.0 through 3.0(x), GSS product capabilities have > been enhanced to allow the GSS to migrate to the top level of the DNS > hierarchy" > > http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/g > ss4400series/v3.1/configuration/cli/gslb/guide/Intro.html#wp1264301 > > > > Cheers > > Brad Hedlund > bhedlund at cisco.com > http://www.internetworkexpert.org > > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From nick.jon.griffin at gmail.com Thu Apr 23 10:16:38 2009 From: nick.jon.griffin at gmail.com (Nick Griffin) Date: Thu, 23 Apr 2009 09:16:38 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: <63516B148FED440F980D3F71B162779C@flamdt01> References: <63516B148FED440F980D3F71B162779C@flamdt01> Message-ID: Thanks to everyone for responding. Very valuable information! Nick Griffin On Thu, Apr 23, 2009 at 9:02 AM, Tony Varriale wrote: > The GSS is definitely not that. > > If you use it with CNR, yes. Since CNR is that product, shazam. > > But as said in my previous post, GSS still isn't a DNS server...it's more > like a proxy. > > tv > ----- Original Message ----- From: "Brad Hedlund" > To: ; "Roland Dobbins" > Cc: "Cisco-nsp" ; < > cisco-nsp-bounces at puck.nether.net> > Sent: Wednesday, April 22, 2009 10:00 PM > Subject: Re: [c-nsp] GSS and ACE > > > >> On 4/22/09 10:39 AM, "robbie.jacka at regions.com" > > >> wrote: >> >> Saying that the GSS is it's own DNS server isn't quite right >>> >> >> Not true. GSS can also operate entirely as a full blown DNS server. >> >> >> "Using software versions 2.0 through 3.0(x), GSS product capabilities have >> been enhanced to allow the GSS to migrate to the top level of the DNS >> hierarchy" >> >> >> http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/g >> ss4400series/v3.1/configuration/cli/gslb/guide/Intro.html#wp1264301 >> >> >> >> Cheers >> >> Brad Hedlund >> bhedlund at cisco.com >> http://www.internetworkexpert.org >> >> >> >> >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From brhedlun at cisco.com Thu Apr 23 10:31:23 2009 From: brhedlun at cisco.com (Brad Hedlund) Date: Thu, 23 Apr 2009 09:31:23 -0500 Subject: [c-nsp] GSS and ACE In-Reply-To: Message-ID: On 4/23/09 9:13 AM, "robbie.jacka at regions.com" wrote: > installing CNR on a GSS does not make it GSS a DNS server, much as sticking > a feather up your rear does not make you a chicken. :D > > as tony stated, CNR is still a separate product - it's simply installed > *on* the GSS. a good product, to be sure - but with attendant licensing > needs. > -- > robbie Point taken. True, you need the appropriate licenses. However the fact remains that you can consolidate DNS and GSLB onto one appliance, the GSS 4492R. Cheers Brad Hedlund bhedlund at cisco.com http://www.internetworkexpert.org From panocisco77 at gmail.com Thu Apr 23 10:41:56 2009 From: panocisco77 at gmail.com (Renelson Panosky) Date: Thu, 23 Apr 2009 10:41:56 -0400 Subject: [c-nsp] Cisco Standard closet Message-ID: <16e2ac180904230741g3c419887s64882e6235bd9d06@mail.gmail.com> Hello List Can anybody tell me anything about a cisco Standard closet? They are redoing the closet at my job and i am gathering some information, anything would help for instance website, phone number etc... Renelson From billbuhlman at yahoo.com Thu Apr 23 11:13:13 2009 From: billbuhlman at yahoo.com (Bill Buhlman) Date: Thu, 23 Apr 2009 08:13:13 -0700 (PDT) Subject: [c-nsp] Cisco Standard closet Message-ID: <17803.47139.qm@web43141.mail.sp1.yahoo.com> We have always used TIA/EIA standards documents for data center, MDF,IDF. TIA-568, TIA-569, TIA-570, TIA-606, TIA-942. Available from http://global.ihs.com/ ? Bill --- On Thu, 4/23/09, Renelson Panosky wrote: From: Renelson Panosky Subject: [c-nsp] Cisco Standard closet To: cisco-nsp at puck.nether.net Date: Thursday, April 23, 2009, 7:41 AM Hello List Can anybody tell me anything about a cisco Standard closet? They are redoing the closet at my job and i am gathering some information, anything would help for instance website, phone number etc... Renelson _______________________________________________ cisco-nsp mailing list? cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From mduksa at gmail.com Thu Apr 23 12:33:29 2009 From: mduksa at gmail.com (Marlon Duksa) Date: Thu, 23 Apr 2009 09:33:29 -0700 Subject: [c-nsp] number of VRFs on Cisco Cat/7600 Message-ID: I found this in Cisco documentation under the title "OSPF Support for Unlimited Software VRFs per Provider Edge Router" : "The OSPF Support for Unlimited Software VRFs per Provider Edge Router feature allows for an approximate range of 300 to 10,000 VRFs, depending on the particular platform and on the applications, processes, and protocols that are currently running on the platform." 10,000 VRF? 7600/Cat have a limitation of 4K internal VLANs and each L3 VPN (MPLS) takes one of those, up to 512 L3 VPNs. After 512 L3 VPNs it takes 2 internal VLANs. This would max out L3 VPNs on 7600/Cat to less than 3K. I assume that L3 VPN = VRF. Does anyone know how they arrived to this 10K VRFs number? It just does not make sense. Thanks, Marlon From lukasz at bromirski.net Thu Apr 23 13:18:09 2009 From: lukasz at bromirski.net (=?ISO-8859-2?Q?=A3ukasz_Bromirski?=) Date: Thu, 23 Apr 2009 19:18:09 +0200 Subject: [c-nsp] number of VRFs on Cisco Cat/7600 In-Reply-To: References: Message-ID: <49F0A2D1.7030501@bromirski.net> On 2009-04-23 18:33, Marlon Duksa wrote: > I found this in Cisco documentation under the title "OSPF Support > for Unlimited Software VRFs per Provider Edge Router" : > > "The OSPF Support for Unlimited Software VRFs per Provider Edge > Router feature allows for an approximate range of 300 to 10,000 VRFs, > depending on the particular platform and on the applications, > processes, and protocols that are currently running on the > platform." > > 10,000 VRF? > > 7600/Cat have a limitation of 4K internal VLANs and each L3 VPN > (MPLS) takes one of those, up to 512 L3 VPNs. After 512 L3 VPNs it > takes 2 internal VLANs. > > This would max out L3 VPNs on 7600/Cat to less than 3K. I assume that > L3 VPN = VRF. > > Does anyone know how they arrived to this 10K VRFs number? It just > does not make sense. The 7600 router is not the only platform in Cisco portfolio that supports VRFs. Also, the IOS and the quote deal more than with scalability than real example of production environment. -- "Don't expect me to cry for all the | ?ukasz Bromirski reasons you had to die" -- Kurt Cobain | http://lukasz.bromirski.net From lists at memetic.org Thu Apr 23 13:20:28 2009 From: lists at memetic.org (Adam Armstrong) Date: Thu, 23 Apr 2009 18:20:28 +0100 Subject: [c-nsp] number of VRFs on Cisco Cat/7600 In-Reply-To: References: Message-ID: <49F0A35C.2090601@memetic.org> Marlon Duksa wrote: > I found this in Cisco documentation under the title "OSPF Support for > Unlimited Software VRFs per > Provider Edge Router" : > > "The OSPF Support for Unlimited Software VRFs per Provider Edge Router > feature allows for an > approximate range of 300 to 10,000 VRFs, depending on the particular > platform and on the applications, > processes, and protocols that are currently running on the platform." > > 10,000 VRF? > > 7600/Cat have a limitation of 4K internal VLANs and each L3 VPN (MPLS) takes > one of those, up to 512 L3 VPNs. After 512 L3 VPNs it takes 2 internal > VLANs. > > This would max out L3 VPNs on 7600/Cat to less than 3K. I assume that L3 VPN > = VRF. > > Does anyone know how they arrived to this 10K VRFs number? It just does not > make sense. Unlimited *software* VRFs? adam. From ler762 at gmail.com Thu Apr 23 13:21:17 2009 From: ler762 at gmail.com (Lee) Date: Thu, 23 Apr 2009 13:21:17 -0400 Subject: [c-nsp] network audit was: VTY Lines Message-ID: On 4/21/09, Justin Shore wrote: > Lee wrote: >> line vty 0 3 >> access-class 100 in >> line vty 4 >> access-class 104 in >> >> Which means every single router fails when you put the config through RAT >> :( > > I went round and round with a security guy who audited our gear once > over that. He made a huge stink over how we didn't have have passwords > on our VTYs, con and aux ports. He took everything RAT had to say as > gospel, as if there was no other (or better) way to address a security > issue. <.. snip ..> He just didn't get it. I'd love to make it a requirement that network auditors have to actually know something about networking. We've got a service support contract w/ Cisco that includes a network audit; those are useful. What our security office is doing now... well, it is forcing me to take a detailed look at all the configs, so it's not a complete waste of time. > ... I used the password stink as part of > my justification that RAT really only points out common and basic > security problems and doesn't take into account any of the numerous ways > of mitigating those problems with more advanced methods. In the end the > audit was dropped. Dropping an audit has never been an option where I've worked. Preventing an audit from turning into nothing more than a bureaucratic paper-shuffling exercise is the best I can hope for. <.. snip ..> > While my installs may not be perfect, they are far better than average. > I don't need someone second-guessing my work with a tool like RAT. s/need someone/need a clueless someone/ and I'd agree. I've been in a few meetings where the auditor wasn't able to justify their findings with anything better than claiming "it's a best practice". I just looked at http://checklists.nist.gov/ncp.cfm?repository again and the only accepted Cisco IOS benchmark that has an automated tool is CIS. That they were able to get their tool accepted by the USG is impressive. That they haven't updated it since it's release is regrettable. Regards, Lee From ler762 at gmail.com Thu Apr 23 13:32:25 2009 From: ler762 at gmail.com (Lee) Date: Thu, 23 Apr 2009 13:32:25 -0400 Subject: [c-nsp] VTY Lines In-Reply-To: <87ab69qamy.fsf@laphroiag.quux.de> References: <2C05E949E19A9146AF7BDF9D44085B863527941244@exchange.aoihq.local> <6de481d10904190012n61ab655eo70d43b61457c6c3a@mail.gmail.com> <3329cbb40904191653r43c2c77bie0c31fb88eec92b6@mail.gmail.com> <49EC7BE2.60100@scripty.com> <49EE8E94.7060503@justinshore.com> <87ab69qamy.fsf@laphroiag.quux.de> Message-ID: On 4/22/09, Jens Link wrote: > Justin Shore writes: > >> While my installs may not be perfect, they are far better than >> average. I don't need someone second-guessing my work with a tool like >> RAT. > > Agreed. But (IIRC) you can write your own rules for RAT. Combine this > with rancid and you have a great way of finding thing you may have > forgotten to configure. Yes, but an auditor isn't going to allow your own rules for RAT so you're still stuck with justifying every 'failure' RAT comes up with. I tried sending them feedback a few years ago & got a very nice rejection reply. Maybe including patches with my feedback will work better this time.. Lee From arl at nordicom.tele.dk Thu Apr 23 13:43:15 2009 From: arl at nordicom.tele.dk (Arne Larsen) Date: Thu, 23 Apr 2009 19:43:15 +0200 Subject: [c-nsp] vs isdn calling number via radius Message-ID: Hi all. Does anyone know if it's possible to append calling number on an as5300 via an radius attribute. I'm making large scale dialout and I need to chanage the calling number depending on who'm I'm calling. /Arne -- Jeg beskyttes af den gratis SPAMfighter til privatbrugere. Den har indtil videre sparet mig for at f? 2277 spam-mails. Betalende brugere f?r ikke denne besked i deres e-mails. Hent gratis SPAMfighter her: http://www.spamfighter.com/lda From clane1875 at gmail.com Thu Apr 23 13:51:20 2009 From: clane1875 at gmail.com (Chris Lane) Date: Thu, 23 Apr 2009 13:51:20 -0400 Subject: [c-nsp] 3750 High Cpu IP Input Message-ID: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> Having a high cpu with my 3750 not in stack. sh proc cpu | exclude 0.00 CPU utilization for five seconds: 68%/43%; one minute: 69%; five minutes: 70% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 168 40336940 92166921 437 15.49% 15.76% 15.97% 0 IP Input WS-C3750-48TS 12.2(35)SE2 C3750-ADVIPSERVICESK According to some old threads this was a bug in some older IOS which was fixed in 12.2(25) Egress port is quiet: 5 minute input rate 11171000 bits/sec, 1353 packets/sec 5 minute output rate 2821000 bits/sec, 681 packets/sec Sure i can upgrade IOS! Looking to know WHY this box is so hot! Thanks -- //CL From nockhi at gmail.com Thu Apr 23 14:04:04 2009 From: nockhi at gmail.com (Asif Gul Khan) Date: Fri, 24 Apr 2009 00:04:04 +0600 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> Message-ID: If that was hot, than mine is already burnt :) Cisco-4006#sh proc cpu | i IP In CPU utilization for five seconds: 40%/0%; one minute: 49%; five minutes: 48% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 27 11102394522491179868 445 38.07% 40.50% 39.38% 0 IP Input sh version shows: IOS (tm) Catalyst 4000 L3 Switch Software (cat4000-IS-M), Version 12.1(8a)EW1, EARLY DEPLOYMENT RELEASE SOFTWARE (fc1) Does IOS Upgrade really solves this cpu prob??? On Thu, Apr 23, 2009 at 11:51 PM, Chris Lane wrote: > Having a high cpu with my 3750 not in stack. sh proc cpu | exclude 0.00 > CPU utilization for five seconds: 68%/43%; one minute: 69%; five minutes: > 70% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > 168 40336940 92166921 437 15.49% 15.76% 15.97% 0 IP Input > > WS-C3750-48TS 12.2(35)SE2 C3750-ADVIPSERVICESK > > According to some old threads this was a bug in some older IOS which was > fixed in 12.2(25) > > Egress port is quiet: > 5 minute input rate 11171000 bits/sec, 1353 packets/sec > 5 minute output rate 2821000 bits/sec, 681 packets/sec > > Sure i can upgrade IOS! > Looking to know WHY this box is so hot! > > Thanks > > -- > //CL > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From mksmith at adhost.com Thu Apr 23 15:46:28 2009 From: mksmith at adhost.com (Michael K. Smith - Adhost) Date: Thu, 23 Apr 2009 12:46:28 -0700 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> Message-ID: <17838240D9A5544AAA5FF95F8D52031605EC0F03@ad-exh01.adhost.lan> Subject: [c-nsp] 3750 High Cpu IP Input Having a high cpu with my 3750 not in stack. sh proc cpu | exclude 0.00 CPU utilization for five seconds: 68%/43%; one minute: 69%; five minutes: 70% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 168 40336940 92166921 437 15.49% 15.76% 15.97% 0 IP Input WS-C3750-48TS 12.2(35)SE2 C3750-ADVIPSERVICESK According to some old threads this was a bug in some older IOS which was fixed in 12.2(25) ---- [Michael K. Smith - Adhost] Do you have cef enabled? Mike From SteveMc at netservicesplc.com Thu Apr 23 15:03:13 2009 From: SteveMc at netservicesplc.com (Steve McCrory) Date: Thu, 23 Apr 2009 20:03:13 +0100 Subject: [c-nsp] Problems with multiple VPDN hops Message-ID: <1C15FB264A06794F8BDE2120972B51C1050E280A@netexch04.ad.netservicesplc.com> We have ADSL tails coming into our network from several BT L2TP tunnels terminating on Cisco LNS routers (7301s) We normally either terminate the sessions locally on our first LNS routers or forward the sessions, using Radius attributes to other LNS routers (our's our wholesale customers). What we would like to achieve is to take the L2TP tunnels from BT and forward them twice across our network as such: End User<--pppoa-->BT<--L2TP-->LNS1<--L2TP-->LNS2<--L2TP-->LNS3 As mentioned above, we normally terminate users on LNS1 and assign IP addresses, or forward the sessions to LNS2. We would like to establish an additional tunnel to LNS3 but so far have found this difficult and the sessions seem to stall, in a sort of half-authenticated state on LNS 2. We are using Radius to apply the forwarding rules, which we have configured as follows: # First hop from LNS1 to LNS2 DEFAULT NAS-IP-Address !~ "\^213\.130\.147\.56\$", User-Name =~ "-shapetest at work\$", Auth-Type := Accept Framed-Protocol = PPP, Service-Type = Framed-User, Tunnel-Type := "L2TP", Tunnel-Medium-Type := "IP", Tunnel-Client-Auth-ID := "brantest", Tunnel-Server-Endpoint := "213.130.147.56", Tunnel-Password := "oNi6egXZ" # Second hop forwards from LNS2 to LNS3 DEFAULT NAS-IP-Address =~ "\^213\.130\.147\.56\$", User-Name =~ "-shapetest at work\$", Auth-Type := Accept Framed-Protocol = PPP, Service-Type = Framed-User, Tunnel-Type := "L2TP", Tunnel-Medium-Type := "IP", Tunnel-Client-Auth-ID := "netservint", Tunnel-Server-Endpoint := "213.130.145.50", Tunnel-Password := "oNi6egXZ" We also have the following vpdn groups configured on our LNS routers: LNS2: vpdn-group test1 accept-dialin protocol l2tp virtual-template 2 terminate-from hostname test1 source-ip 213.130.147.56 lcp renegotiation on-mismatch l2tp tunnel password 7 XXXXXXXXXX l2tp tunnel receive-window 10 LNS3: vpdn-group test2 accept-dialin protocol l2tp virtual-template 1 terminate-from hostname test2 source-ip 213.130.145.50 lcp renegotiation always l2tp tunnel password 7 XXXXXXXXX l2tp tunnel receive-window 10 What I'd like to know is if it's possible to use radius to essentially switch packets from one L2TP tunnel into another when they reach LNS2. We know that the VPDN and Radius configuration are correct on LNS2 because we can successfully terminate sessions on this router and assign IP addresses Thanks Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- From peter at rathlev.dk Thu Apr 23 16:01:16 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 23 Apr 2009 22:01:16 +0200 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> Message-ID: <1240516876.3396.3.camel@localhost.localdomain> On Thu, 2009-04-23 at 13:51 -0400, Chris Lane wrote: > Having a high cpu with my 3750 not in stack. sh proc cpu | exclude 0.00 > CPU utilization for five seconds: 68%/43%; one minute: 69%; five minutes: > 70% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > 168 40336940 92166921 437 15.49% 15.76% 15.97% 0 IP Input > > WS-C3750-48TS 12.2(35)SE2 C3750-ADVIPSERVICESK > > According to some old threads this was a bug in some older IOS which was > fixed in 12.2(25) > > Egress port is quiet: > 5 minute input rate 11171000 bits/sec, 1353 packets/sec > 5 minute output rate 2821000 bits/sec, 681 packets/sec > > Sure i can upgrade IOS! > Looking to know WHY this box is so hot! When you see the box spending processor time in "IP Input" it's because it cannot hardware switch the traffic it moves. This is (almost) always a bad thing when you're looking at a L3 switch. There can be several reasons for this. Features not supported in hardware (= most features, e.g. GRE or NAT) is one possible thing. TCAM starvation/overflow could also make the box do software switching. It depends on your configuration. Has it always done this? Regards, Peter From clane1875 at gmail.com Thu Apr 23 16:15:39 2009 From: clane1875 at gmail.com (Chris Lane) Date: Thu, 23 Apr 2009 16:15:39 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <1240516876.3396.3.camel@localhost.localdomain> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> Message-ID: <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> The 3750 doesn't support GRE from what i have read ? No NAT either, strictly L3. This box has been in production for over a year and doesn't really do to much as you can see from my orig thread it moves about 11MB. This just started late last night yet we didn't add any new customer nor did anybody even touch switch as the device is remote. I read in an older thread regarding same thing that the person rebooted and of course it resolved issue. I am planning to do that Early tomorrow am, but i really want to know what the heck is causing this. Yes CEF is running. Thanks to all for input. On Thu, Apr 23, 2009 at 4:01 PM, Peter Rathlev wrote: > On Thu, 2009-04-23 at 13:51 -0400, Chris Lane wrote: > > Having a high cpu with my 3750 not in stack. sh proc cpu | exclude 0.00 > > CPU utilization for five seconds: 68%/43%; one minute: 69%; five minutes: > > 70% > > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > > 168 40336940 92166921 437 15.49% 15.76% 15.97% 0 IP Input > > > > WS-C3750-48TS 12.2(35)SE2 C3750-ADVIPSERVICESK > > > > According to some old threads this was a bug in some older IOS which was > > fixed in 12.2(25) > > > > Egress port is quiet: > > 5 minute input rate 11171000 bits/sec, 1353 packets/sec > > 5 minute output rate 2821000 bits/sec, 681 packets/sec > > > > Sure i can upgrade IOS! > > Looking to know WHY this box is so hot! > > When you see the box spending processor time in "IP Input" it's because > it cannot hardware switch the traffic it moves. This is (almost) always > a bad thing when you're looking at a L3 switch. > > There can be several reasons for this. Features not supported in > hardware (= most features, e.g. GRE or NAT) is one possible thing. TCAM > starvation/overflow could also make the box do software switching. > > It depends on your configuration. Has it always done this? > > Regards, > Peter > > > -- //CL From peter at rathlev.dk Thu Apr 23 16:41:11 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 23 Apr 2009 22:41:11 +0200 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> Message-ID: <1240519271.3396.9.camel@localhost.localdomain> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane wrote: > This box has been in production for over a year and doesn't really do > to much as you can see from my orig thread it moves about 11MB. > > This just started late last night yet we didn't add any new customer > nor did anybody even touch switch as the device is remote. > > I read in an older thread regarding same thing that the person > rebooted and of course it resolved issue. I am planning to do that > Early tomorrow am, but > i really want to know what the heck is causing this. > > Yes CEF is running. What about TCAM utilisation ("show platform tcam utilization")? Regards, Peter From leigh.bogardis at aciernet.com Thu Apr 23 16:52:06 2009 From: leigh.bogardis at aciernet.com (Leigh Bogardis -Aciernet) Date: Thu, 23 Apr 2009 22:52:06 +0200 Subject: [c-nsp] Broken pin on a backplane Message-ID: <49F0D4F6.8050204@aciernet.com> Hi, has anyone had any experience replacing a broken pin on a backplane of a Catalyst 6500 chassis? I've been banging my head against a brick wall trying to obtain a pin replacement/insertion tool from Molex, so was wondering if anyone had seen this/done this repair themselves. Allegedly, client says it was already bent when the chassis was delivered... ahem. thanks in advance. LB From everton at lab.ipaccess.diveo.net.br Thu Apr 23 17:05:10 2009 From: everton at lab.ipaccess.diveo.net.br (Everton da Silva Marques) Date: Thu, 23 Apr 2009 18:05:10 -0300 Subject: [c-nsp] SNMP OIDs for packet counters in 7600/6500 "show ibc | i bytes" Message-ID: <20090423210509.GA32724@diveo.net.br> Hi, Please point out the SNMP OIDs (if any) for reading the packet counters displayed as output of "show ibc | i bytes": 7609#show ibc | i bytes 1412947 packets input, 202902968 bytes 1993797 packets output, 2079729842 bytes 7609# Platform is 7609/Sup720-3BXL/IOS SXF. Thanks a lot, Everton From clane1875 at gmail.com Thu Apr 23 19:09:11 2009 From: clane1875 at gmail.com (Chris Lane) Date: Thu, 23 Apr 2009 19:09:11 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <1240519271.3396.9.camel@localhost.localdomain> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> Message-ID: <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> sh platform tcam utilization CAM Utilization for ASIC# 0 Max Used Masks/Values Masks/values Unicast mac addresses: 784/6272 37/235 IPv4 IGMP groups + multicast routes: 144/1152 6/26 IPv4 unicast directly-connected routes: 784/6272 37/235 IPv4 unicast indirectly-connected routes: 272/2176 52/326 IPv4 policy based routing aces: 0/0 0/0 IPv4 qos aces: 528/528 18/18 IPv4 security aces: 1024/1024 57/57 Note: Allocation of TCAM entries per feature uses a complex algorithm. The above information is meant to provide an abstract view of the current TCAM utilization Hope this helps. On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev wrote: > On Thu, 2009-04-23 at 16:15 -0400, Chris Lane wrote: > > This box has been in production for over a year and doesn't really do > > to much as you can see from my orig thread it moves about 11MB. > > > > This just started late last night yet we didn't add any new customer > > nor did anybody even touch switch as the device is remote. > > > > I read in an older thread regarding same thing that the person > > rebooted and of course it resolved issue. I am planning to do that > > Early tomorrow am, but > > i really want to know what the heck is causing this. > > > > Yes CEF is running. > > What about TCAM utilisation ("show platform tcam utilization")? > > Regards, > Peter > > > -- //CL From pshem.k at gmail.com Thu Apr 23 19:40:53 2009 From: pshem.k at gmail.com (Pshem Kowalczyk) Date: Fri, 24 Apr 2009 11:40:53 +1200 Subject: [c-nsp] Problems with multiple VPDN hops In-Reply-To: <1C15FB264A06794F8BDE2120972B51C1050E280A@netexch04.ad.netservicesplc.com> References: <1C15FB264A06794F8BDE2120972B51C1050E280A@netexch04.ad.netservicesplc.com> Message-ID: <20fe625b0904231640x33624e1bx7862e69088a8bc2d@mail.gmail.com> Hi, {cut} > > What I'd like to know is if it's possible to use radius to essentially > switch packets from one L2TP tunnel into another when they reach LNS2. > > > > We know that the VPDN and Radius configuration are correct on LNS2 > because we can successfully terminate sessions on this router and assign > IP addresses > We have a very similar setup with multiple 7301 as the devices in the middle. Works like a charm. In your radius config above I've noticed that you use the same NAS-IP-Address twice - is that a typo? kind regards Pshem From andy.saykao at staff.netspace.net.au Thu Apr 23 22:58:30 2009 From: andy.saykao at staff.netspace.net.au (Andy Saykao) Date: Fri, 24 Apr 2009 12:58:30 +1000 Subject: [c-nsp] Question about Multiple Spanning Tee (MST) Message-ID: <56F211C5E3F24F47B103EA1B253822BE03654D39@vic-cr-ex1.staff.netspace.net.au> Hi All, Our switch network needs to be migrated from PVST+ to MST in order for our Cisco switches to be able to speak RSTP to some non-cisco switches. Given that we have a few hundred vlans configured, is there some best practice to determine how many instances we need or can we basically do whatever we want? For example: Option 1/ If we have 500 vlans, do we split them into two instances (instance 1 vlan 1-250 and instance 2 vlan 251-500). Options2/ Or would you split the vlans up based on their business requirements. Eg: vlan 1,10,100 Marketing-related vlans, vlan 2,20,200 Sales-related vlans - therefore create instance 1 vlan 1,10,100 and instance 2 vlan 2,20,200??? Secondly, what if you went with option 2, and added a new vlan into Marketing (eg: vlan 1000). Would you have to manually update the spanning-tree mst config on all MST switches to include the new vlan in the instance??? Thanks. Andy This email and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. Please notify the sender immediately by email if you have received this email by mistake and delete this email from your system. Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the organisation. Finally, the recipient should check this email and any attachments for the presence of viruses. The organisation accepts no liability for any damage caused by any virus transmitted by this email. From engel.labiro at gmail.com Thu Apr 23 23:22:40 2009 From: engel.labiro at gmail.com (Engelhard Labiro) Date: Fri, 24 Apr 2009 12:22:40 +0900 Subject: [c-nsp] SNMP OIDs for packet counters in 7600/6500 "show ibc | i bytes" In-Reply-To: <20090423210509.GA32724@diveo.net.br> References: <20090423210509.GA32724@diveo.net.br> Message-ID: Have you tried "snmpwalk" to your router to retrieve all available values there? Piping those may get you to similar counter. On Apr 24, 2009, at 6:05 AM, Everton da Silva Marques wrote: > Hi, > > Please point out the SNMP OIDs (if any) for reading > the packet counters displayed as output of > "show ibc | i bytes": > > 7609#show ibc | i bytes > 1412947 packets input, 202902968 bytes > 1993797 packets output, 2079729842 bytes > 7609# > > Platform is 7609/Sup720-3BXL/IOS SXF. > > Thanks a lot, > Everton > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From clinton at scripty.com Thu Apr 23 23:50:03 2009 From: clinton at scripty.com (Clinton Work) Date: Thu, 23 Apr 2009 21:50:03 -0600 Subject: [c-nsp] Question about Multiple Spanning Tee (MST) In-Reply-To: <56F211C5E3F24F47B103EA1B253822BE03654D39@vic-cr-ex1.staff.netspace.net.au> References: <56F211C5E3F24F47B103EA1B253822BE03654D39@vic-cr-ex1.staff.netspace.net.au> Message-ID: <49F136EB.2000900@scripty.com> Generally, you want to split your vlans between the MST instances based upon administrative control. All the vlans in a particular instance have to share the same spanning tree topology. I would put vlans into difference instances based upon the following. a) in-band mgmt vlan b) splitting vlans into two or more groups which will have different blocking points in order to implement load sharing c) groups of vlans where you want to have independent control so you can change the blocking point without affecting the MST instances. This could be grouped based upon departments or vlan function (Internet, DMZ, Enterprise, ...). You may have a requirement to have red and blue vlans take diverse links (if possible) across the switched network. I would come up with a MST instance plan that covers all the vlans you might want to use so your not modifying the MST configuration all the time. Clinton. Andy Saykao wrote: > Hi All, > > For example: > > Option 1/ If we have 500 vlans, do we split them into two instances > (instance 1 vlan 1-250 and instance 2 vlan 251-500). > > Options2/ Or would you split the vlans up based on their business > requirements. > Eg: vlan 1,10,100 Marketing-related vlans, vlan 2,20,200 Sales-related > vlans - therefore create instance 1 vlan 1,10,100 and instance 2 vlan > 2,20,200??? > > Secondly, what if you went with option 2, and added a new vlan into > Marketing (eg: vlan 1000). Would you have to manually update the > spanning-tree mst config on all MST switches to include the new vlan in > the instance??? > > Thanks. > > Andy > > > -- ================================================================== Clinton Work Airdrie, AB From dale.shaw+cisco-nsp at gmail.com Fri Apr 24 00:38:01 2009 From: dale.shaw+cisco-nsp at gmail.com (Dale Shaw) Date: Fri, 24 Apr 2009 14:38:01 +1000 Subject: [c-nsp] The dreaded microburst - definition and troubleshooting Message-ID: <3329cbb40904232138i3c45ac87va2138a787685cc02@mail.gmail.com> Hi all, Is there a universally agreed upon definition for a 'microburst'? Is there a defined time measurement - i.e. 5ms, 10ms, 50ms, 100ms, 1000ms - during which a certain bps or pps threshold must be met/exceeded? Does anyone have any tips for troubleshooting microbursts, particularly in relation to the c7200 platform exhibiting "no buff" drops? We're going to capture some data (w/SPAN on an adjacent switch) but it would be nice to be able to look at the data and somehow marry it up with incrementing drop counters on the affected c7200 interface. It would be nice to be able to explain such drops like "within the measurement window, we saw traffic at bps/pps rate x, and we know that anything beyond bps/pps rate y will result in drops". I suppose it's platform-specific, but how does one come up with an accurate benchmark? Is such precision just wishful thinking in the murky world of microbursts? :-) cheers, Dale From foulks at falconbroadband.net Fri Apr 24 01:12:47 2009 From: foulks at falconbroadband.net (Brian Foulks) Date: Thu, 23 Apr 2009 23:12:47 -0600 Subject: [c-nsp] pingalias with a variable Message-ID: <1754452a.e2415064.81dbd00@webmail.vanion.com> Hello, We have a Cisco network that utilizes DMVPN. When our operators use ping, they have to use the extended ping command because ping tries to go out the T1 interface instead of the tunnel. Is there a way to make an alias command for ping that would allow us to type any IP and it automatically be set with the source of the router's loopback? Thanks, Brian From gkg at gmx.de Fri Apr 24 01:44:06 2009 From: gkg at gmx.de (Garry) Date: Fri, 24 Apr 2009 07:44:06 +0200 Subject: [c-nsp] Recommendation - reconfiguring full-mesh VPN network Message-ID: <49F151A6.3090305@gmx.de> Hi, We've more or less taken over configuration and support of a customer network. It is made up of several microwave links, with 2800 series routers at the points in between. Lower layer EIGRP routing, with VPN tunnel on top to secure the actual content. Sites have dual VLANs for voice and data, though no multi-vlan on the actual backbone. They have now started rolling out additional routers for new links, which of course makes configuration a pain, as the company that originally set up the network (when there were only 4 stations) had configured a full mesh VPN connections. Needless to say I'd prefer to throw that out in favor of a more service-friendly setup ... I briefly thought about DMVPN or GET-VPN ... but believe just encrypting everything on a hop-by-hop basis would be the more logical way to go ... that way, I could just move the routing to the encrypted layer ... once a new site needs to be configured, all I need to touch is the new router and the one it is connected to ... Any recommendations? Tnx, -garry From peter at rathlev.dk Fri Apr 24 02:31:13 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Fri, 24 Apr 2009 08:31:13 +0200 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> Message-ID: <1240554673.3352.5.camel@localhost.localdomain> On Thu, 2009-04-23 at 19:09 -0400, Chris Lane wrote: > sh platform tcam utilization > > CAM Utilization for ASIC# 0 Max Used ... Hm... nothing there (unless the other ASICs show dissimilar results). If the problem is punted traffic, maybe "show ip cef switching statistics feature" can tell you what it is. It could also be traffic directed at the switch itself of course. Regards, Peter From SteveMc at netservicesplc.com Fri Apr 24 03:41:20 2009 From: SteveMc at netservicesplc.com (Steve McCrory) Date: Fri, 24 Apr 2009 08:41:20 +0100 Subject: [c-nsp] Problems with multiple VPDN hops In-Reply-To: <20fe625b0904231640x33624e1bx7862e69088a8bc2d@mail.gmail.com> References: <1C15FB264A06794F8BDE2120972B51C1050E280A@netexch04.ad.netservicesplc.com> <20fe625b0904231640x33624e1bx7862e69088a8bc2d@mail.gmail.com> Message-ID: <1C15FB264A06794F8BDE2120972B51C1050E2821@netexch04.ad.netservicesplc.com> Hi Pshem, Thanks for your reply. Having the same NAS-IP-Address in both rules is not a typo. In the first rule, we are saying 'If the NAS IP Address is NOT equal to 213.130.147.56 then apply the following rule' In the second rule, we are saying 'If the NAS IP Address IS equal to 213.130.147.56 then apply the following rule' Based on this information, do you have any further suggestions and are you able to supply example configs of your own setup? Thanks Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -----Original Message----- From: Pshem Kowalczyk [mailto:pshem.k at gmail.com] Sent: 24 April 2009 00:41 To: Steve McCrory Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] Problems with multiple VPDN hops Hi, {cut} > > What I'd like to know is if it's possible to use radius to essentially > switch packets from one L2TP tunnel into another when they reach LNS2. > > > > We know that the VPDN and Radius configuration are correct on LNS2 > because we can successfully terminate sessions on this router and assign > IP addresses > We have a very similar setup with multiple 7301 as the devices in the middle. Works like a charm. In your radius config above I've noticed that you use the same NAS-IP-Address twice - is that a typo? kind regards Pshem -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- From drrtuy at ya.ru Fri Apr 24 04:06:35 2009 From: drrtuy at ya.ru (junior) Date: Fri, 24 Apr 2009 11:06:35 +0300 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> Message-ID: <49F1730B.5000705@ya.ru> Chris Lane wrote: > Having a high cpu with my 3750 not in stack. sh proc cpu | exclude 0.00 > CPU utilization for five seconds: 68%/43%; one minute: 69%; five minutes: > 70% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > 168 40336940 92166921 437 15.49% 15.76% 15.97% 0 IP Input > > WS-C3750-48TS 12.2(35)SE2 C3750-ADVIPSERVICESK > > According to some old threads this was a bug in some older IOS which was > fixed in 12.2(25) > > Egress port is quiet: > 5 minute input rate 11171000 bits/sec, 1353 packets/sec > 5 minute output rate 2821000 bits/sec, 681 packets/sec > > Sure i can upgrade IOS! > Looking to know WHY this box is so hot! I would like to advice this document. Hope it will help you. http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/troubleshooting/cpu_util.html#wp1026038 WBR Roman A. Nozdrin From ip at ioshints.info Fri Apr 24 04:06:07 2009 From: ip at ioshints.info (Ivan Pepelnjak) Date: Fri, 24 Apr 2009 10:06:07 +0200 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <1240516876.3396.3.camel@localhost.localdomain> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> Message-ID: <004b01c9c4b3$89fbf230$0a00000a@nil.si> Your CPU is @ 70%, 25% of those spent in interrupt (CEF) packet switching (the difference between 68% and 43% in the five-second figures), yet the IP Input uses only 16%. There might be something else going on? Ivan http://www.ioshints.info/about http://blog.ioshints.info/ > -----Original Message----- > From: Peter Rathlev [mailto:peter at rathlev.dk] > Sent: Thursday, April 23, 2009 10:01 PM > To: Chris Lane > Cc: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] 3750 High Cpu IP Input > > On Thu, 2009-04-23 at 13:51 -0400, Chris Lane wrote: > > Having a high cpu with my 3750 not in stack. sh proc cpu | exclude > > 0.00 CPU utilization for five seconds: 68%/43%; one minute: > 69%; five minutes: > > 70% > > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min > TTY Process > > 168 40336940 92166921 437 15.49% 15.76% 15.97% > 0 IP Input > > > > WS-C3750-48TS 12.2(35)SE2 C3750-ADVIPSERVICESK > > > > According to some old threads this was a bug in some older > IOS which > > was fixed in 12.2(25) > > > > Egress port is quiet: > > 5 minute input rate 11171000 bits/sec, 1353 packets/sec > > 5 minute output rate 2821000 bits/sec, 681 packets/sec > > > > Sure i can upgrade IOS! > > Looking to know WHY this box is so hot! > > When you see the box spending processor time in "IP Input" > it's because it cannot hardware switch the traffic it moves. > This is (almost) always a bad thing when you're looking at a > L3 switch. > > There can be several reasons for this. Features not supported > in hardware (= most features, e.g. GRE or NAT) is one > possible thing. TCAM starvation/overflow could also make the > box do software switching. > > It depends on your configuration. Has it always done this? > > Regards, > Peter > > > > From b.turnbow at twt.it Fri Apr 24 04:19:10 2009 From: b.turnbow at twt.it (Brian Turnbow) Date: Fri, 24 Apr 2009 10:19:10 +0200 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com><1240516876.3396.3.camel@localhost.localdomain><2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com><1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> Message-ID: You can use show controller cpu to help see whats going to the cpu Make sure you have no ip redirects and no proxy arp on all the interfaces. How many routed interfaces do you have ? The output below for "max" is for 8 routed interfaces if you have more you should change to the desktop switching template. With your roughly your values for indirectly connected routes and 13 ip interfaces on a box I needed to switch the template "sdm prefer routing" requies reload. Regards Brian -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Chris Lane Sent: venerd? 24 aprile 2009 1.09 To: Peter Rathlev Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] 3750 High Cpu IP Input sh platform tcam utilization CAM Utilization for ASIC# 0 Max Used Masks/Values Masks/values Unicast mac addresses: 784/6272 37/235 IPv4 IGMP groups + multicast routes: 144/1152 6/26 IPv4 unicast directly-connected routes: 784/6272 37/235 IPv4 unicast indirectly-connected routes: 272/2176 52/326 IPv4 policy based routing aces: 0/0 0/0 IPv4 qos aces: 528/528 18/18 IPv4 security aces: 1024/1024 57/57 Note: Allocation of TCAM entries per feature uses a complex algorithm. The above information is meant to provide an abstract view of the current TCAM utilization Hope this helps. On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev wrote: > On Thu, 2009-04-23 at 16:15 -0400, Chris Lane wrote: > > This box has been in production for over a year and doesn't really do > > to much as you can see from my orig thread it moves about 11MB. > > > > This just started late last night yet we didn't add any new customer > > nor did anybody even touch switch as the device is remote. > > > > I read in an older thread regarding same thing that the person > > rebooted and of course it resolved issue. I am planning to do that > > Early tomorrow am, but > > i really want to know what the heck is causing this. > > > > Yes CEF is running. > > What about TCAM utilisation ("show platform tcam utilization")? > > Regards, > Peter > > > -- //CL _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From achatz at forthnet.gr Fri Apr 24 04:39:50 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Fri, 24 Apr 2009 11:39:50 +0300 Subject: [c-nsp] pingalias with a variable In-Reply-To: <1754452a.e2415064.81dbd00@webmail.vanion.com> References: <1754452a.e2415064.81dbd00@webmail.vanion.com> Message-ID: <49F17AD6.70600@forthnet.gr> Not the most elegant solution.... event manager applet PING event cli pattern "ping" sync no skip yes action 1.0 cli command "enable" action 2.0 cli command "$_cli_msg source loopback0" action 3.0 syslog msg "$_cli_result" ! If you have latest IOS, you can use "puts" instead of "syslog" for the output, so you don't need to have "term mon" turned on. Probably Ivan could come out with a better solution based on TCL ;) -- Tassos Brian Foulks wrote on 24/04/2009 08:12: > Hello, > > We have a Cisco network that utilizes DMVPN. When > our operators use ping, they have to use the > extended ping command because ping tries to go out > the T1 interface instead of the tunnel. Is there a > way to make an alias command for ping that would > allow us to type any IP and it automatically be set > with the source of the router's loopback? > > Thanks, > > Brian > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From clane1875 at gmail.com Fri Apr 24 05:12:45 2009 From: clane1875 at gmail.com (Chris Lane) Date: Fri, 24 Apr 2009 05:12:45 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <1240554673.3352.5.camel@localhost.localdomain> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> <1240554673.3352.5.camel@localhost.localdomain> Message-ID: <2e1cd850904240212o7d4889f8pbb91ecaaac348d9f@mail.gmail.com> sh ip cef switching statistics feature IPv4 CEF input features: Feature Drop Consume Punt Punt2Host Gave route Total 0 0 0 0 0 IPv4 CEF output features: Feature Drop Consume Punt Punt2Host New i/f Total 0 0 0 0 0 IPv4 CEF post-encap features: Feature Drop Consume Punt Punt2Host New i/f Total 0 0 0 0 0 IPv4 CEF for us features: Feature Drop Consume Punt Punt2Host New i/f Total 0 0 0 0 0 On Fri, Apr 24, 2009 at 2:31 AM, Peter Rathlev wrote: > On Thu, 2009-04-23 at 19:09 -0400, Chris Lane wrote: > > sh platform tcam utilization > > > > CAM Utilization for ASIC# 0 Max Used > ... > > Hm... nothing there (unless the other ASICs show dissimilar results). If > the problem is punted traffic, maybe "show ip cef switching statistics > feature" can tell you what it is. > > It could also be traffic directed at the switch itself of course. > > Regards, > Peter > > > > -- //CL From clane1875 at gmail.com Fri Apr 24 05:16:13 2009 From: clane1875 at gmail.com (Chris Lane) Date: Fri, 24 Apr 2009 05:16:13 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <1240554673.3352.5.camel@localhost.localdomain> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> <1240554673.3352.5.camel@localhost.localdomain> Message-ID: <2e1cd850904240216g3605c7fascd679c053649029b@mail.gmail.com> I just punted the device. Still same. Here is more info that i hope can help. sh proc cpu | exclude 0.0 CPU utilization for five seconds: 92%/66%; one minute: 90%; five minutes: 78% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 51 9075 27626 328 1.59% 1.36% 1.17% 0 Fifo Error Detec 97 9372 655 14308 1.59% 2.36% 1.21% 1 SSH Process 115 42273 13055 3238 6.22% 6.23% 5.53% 0 Hulc LED Process 123 1125 139 8093 0.15% 0.15% 0.13% 0 HQM Stack Proces 136 5432 597 9098 0.79% 0.71% 0.64% 0 PI MATM Aging Pr 168 66522 342852 194 10.54% 9.76% 8.61% 0 IP Input ------ sh proc cpu | exclude 0.0 CPU utilization for five seconds: 92%/66%; one minute: 90%; five minutes: 78% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 51 9026 27523 327 1.59% 1.36% 1.17% 0 Fifo Error Detec 97 9314 651 14307 1.59% 2.36% 1.21% 1 SSH Process 115 42156 13006 3241 6.22% 6.23% 5.53% 0 Hulc LED Process 123 1117 138 8094 0.15% 0.15% 0.13% 0 HQM Stack Proces 136 5414 595 9099 0.79% 0.71% 0.64% 0 PI MATM Aging Pr 168 66256 341597 193 10.54% 9.76% 8.61% 0 IP Input On Fri, Apr 24, 2009 at 2:31 AM, Peter Rathlev wrote: > On Thu, 2009-04-23 at 19:09 -0400, Chris Lane wrote: > > sh platform tcam utilization > > > > CAM Utilization for ASIC# 0 Max Used > ... > > Hm... nothing there (unless the other ASICs show dissimilar results). If > the problem is punted traffic, maybe "show ip cef switching statistics > feature" can tell you what it is. > > It could also be traffic directed at the switch itself of course. > > Regards, > Peter > > > > -- //CL From clane1875 at gmail.com Fri Apr 24 05:17:28 2009 From: clane1875 at gmail.com (Chris Lane) Date: Fri, 24 Apr 2009 05:17:28 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> Message-ID: <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> sh controllers cpu-interface ASIC Rxbiterr Rxunder Fwdctfix Txbuflos Rxbufloc Rxbufdrain ------------------------------------------------------------------------- ASIC0 0 0 0 0 0 0 ASIC1 0 0 0 0 0 0 cpu-queue-frames retrieved dropped invalid hol-block stray ----------------- ---------- ---------- ---------- ---------- ---------- rpc 0 0 0 0 0 stp 1807 0 0 0 0 ipc 0 0 0 0 0 routing protocol 1516326 0 0 0 0 L2 protocol 27 0 0 0 0 remote console 0 0 0 0 0 sw forwarding 915 0 0 0 0 host 2014 0 0 0 0 broadcast 1766 0 0 0 0 cbt-to-spt 0 0 0 0 0 igmp snooping 1518651 0 0 0 0 icmp 45 0 0 0 0 logging 0 0 0 0 0 rpf-fail 0 0 0 0 0 queue14 0 0 0 0 0 cpu heartbeat 14116 0 0 0 0 ODD i have disabled IGMP SNOOPING... On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow wrote: > You can use show controller cpu to help see whats going to the cpu > Make sure you have no ip redirects and no proxy arp on all the interfaces. > How many routed interfaces do you have ? > The output below for "max" is for 8 routed interfaces if you have more you > should change to the desktop switching template. > With your roughly your values for indirectly connected routes and 13 ip > interfaces on a box I needed to switch the template "sdm prefer routing" > requies reload. > > Regards > > Brian > > > > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto: > cisco-nsp-bounces at puck.nether.net] On Behalf Of Chris Lane > Sent: venerd? 24 aprile 2009 1.09 > To: Peter Rathlev > Cc: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] 3750 High Cpu IP Input > > sh platform tcam utilization > > CAM Utilization for ASIC# 0 Max Used > Masks/Values Masks/values > > Unicast mac addresses: 784/6272 37/235 > IPv4 IGMP groups + multicast routes: 144/1152 6/26 > IPv4 unicast directly-connected routes: 784/6272 37/235 > IPv4 unicast indirectly-connected routes: 272/2176 52/326 > IPv4 policy based routing aces: 0/0 0/0 > IPv4 qos aces: 528/528 18/18 > IPv4 security aces: 1024/1024 57/57 > > Note: Allocation of TCAM entries per feature uses > a complex algorithm. The above information is meant > to provide an abstract view of the current TCAM utilization > > Hope this helps. > > On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev wrote: > > > On Thu, 2009-04-23 at 16:15 -0400, Chris Lane wrote: > > > This box has been in production for over a year and doesn't really do > > > to much as you can see from my orig thread it moves about 11MB. > > > > > > This just started late last night yet we didn't add any new customer > > > nor did anybody even touch switch as the device is remote. > > > > > > I read in an older thread regarding same thing that the person > > > rebooted and of course it resolved issue. I am planning to do that > > > Early tomorrow am, but > > > i really want to know what the heck is causing this. > > > > > > Yes CEF is running. > > > > What about TCAM utilisation ("show platform tcam utilization")? > > > > Regards, > > Peter > > > > > > > > > -- > //CL > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > -- //CL From clane1875 at gmail.com Fri Apr 24 05:52:57 2009 From: clane1875 at gmail.com (Chris Lane) Date: Fri, 24 Apr 2009 05:52:57 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904240212o7d4889f8pbb91ecaaac348d9f@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> <1240554673.3352.5.camel@localhost.localdomain> <2e1cd850904240212o7d4889f8pbb91ecaaac348d9f@mail.gmail.com> Message-ID: <2e1cd850904240252s7b4ad300qe8562d48e8d12846@mail.gmail.com> sh proc cpu | exclude 0.00 CPU utilization for five seconds: 88%/63%; one minute: 89%; five minutes: 89% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 4 6029 389 15498 1.11% 0.16% 0.12% 0 Check heaps 9 2883 5699 505 0.15% 0.06% 0.07% 0 ARP Input * 51 40119 129588 309 0.63% 1.22% 1.27% 0 Fifo Error Detec* 67 2973 78578 37 0.15% 0.10% 0.08% 0 HLFM address ret 81 16566 41729 396 0.79% 0.43% 0.43% 0 hpm main process *115 190582 60871 3130 6.86% 6.03% 6.01% 0 Hulc LED Process* 123 5054 576 8774 0.31% 0.19% 0.16% 0 HQM Stack Proces 136 25648 2746 9340 1.27% 0.77% 0.74% 0 PI MATM Aging Pr 1*68 308273 1603815 192 9.10% 9.49% 9.82% 0 IP Input * * * *Cisco doc reads the HULC LED is a possible link flapping yet nothing in logs indicate.* * * On Fri, Apr 24, 2009 at 5:12 AM, Chris Lane wrote: > sh ip cef switching statistics feature > IPv4 CEF input features: > Feature Drop Consume Punt Punt2Host Gave > route > Total 0 0 0 0 > 0 > > IPv4 CEF output features: > Feature Drop Consume Punt Punt2Host New > i/f > Total 0 0 0 0 > 0 > > IPv4 CEF post-encap features: > Feature Drop Consume Punt Punt2Host New > i/f > Total 0 0 0 0 > 0 > > IPv4 CEF for us features: > Feature Drop Consume Punt Punt2Host New > i/f > Total 0 0 0 0 > 0 > > > > On Fri, Apr 24, 2009 at 2:31 AM, Peter Rathlev wrote: > >> On Thu, 2009-04-23 at 19:09 -0400, Chris Lane wrote: >> > sh platform tcam utilization >> > >> > CAM Utilization for ASIC# 0 Max Used >> ... >> >> Hm... nothing there (unless the other ASICs show dissimilar results). If >> the problem is punted traffic, maybe "show ip cef switching statistics >> feature" can tell you what it is. >> >> It could also be traffic directed at the switch itself of course. >> >> Regards, >> Peter >> >> >> >> > > > -- > //CL > -- //CL From ross at kallisti.us Fri Apr 24 07:04:43 2009 From: ross at kallisti.us (Ross Vandegrift) Date: Fri, 24 Apr 2009 07:04:43 -0400 Subject: [c-nsp] Forcing all HSRP interfaces to failover Message-ID: <20090424110443.GA26907@kallisti.us> Hi everyone, Is there any good way to have IOS abdicate the active status on all of its HSRP interfaces? Of course I could change each of a few thousand SVIs, but I'd like a better way. The only thing I can come up with is to create an unnumbered loopback just to use as a tracking target. Admin down that interface when you want to take down one of the routers for maintenance. Has anyone ever done something similar? Any better ideas? -- Ross Vandegrift ross at kallisti.us "If the fight gets hot, the songs get hotter. If the going gets tough, the songs get tougher." --Woody Guthrie From b.turnbow at twt.it Fri Apr 24 07:21:41 2009 From: b.turnbow at twt.it (Brian Turnbow) Date: Fri, 24 Apr 2009 13:21:41 +0200 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> Message-ID: how many routed interfaces do you have ( sh ip int brief with ip addresses ) ? if more than 8 change the sdm template to routing you can use sh platform ip unicast failed route to see if routes are failing to be programmed into tcam Brian ________________________________ From: Chris Lane [mailto:clane1875 at gmail.com] Sent: venerd? 24 aprile 2009 11.17 To: Brian Turnbow Cc: Peter Rathlev; cisco-nsp at puck.nether.net Subject: Re: [c-nsp] 3750 High Cpu IP Input sh controllers cpu-interface ASIC Rxbiterr Rxunder Fwdctfix Txbuflos Rxbufloc Rxbufdrain ------------------------------------------------------------------------- ASIC0 0 0 0 0 0 0 ASIC1 0 0 0 0 0 0 cpu-queue-frames retrieved dropped invalid hol-block stray ----------------- ---------- ---------- ---------- ---------- ---------- rpc 0 0 0 0 0 stp 1807 0 0 0 0 ipc 0 0 0 0 0 routing protocol 1516326 0 0 0 0 L2 protocol 27 0 0 0 0 remote console 0 0 0 0 0 sw forwarding 915 0 0 0 0 host 2014 0 0 0 0 broadcast 1766 0 0 0 0 cbt-to-spt 0 0 0 0 0 igmp snooping 1518651 0 0 0 0 icmp 45 0 0 0 0 logging 0 0 0 0 0 rpf-fail 0 0 0 0 0 queue14 0 0 0 0 0 cpu heartbeat 14116 0 0 0 0 ODD i have disabled IGMP SNOOPING... On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow wrote: You can use show controller cpu to help see whats going to the cpu Make sure you have no ip redirects and no proxy arp on all the interfaces. How many routed interfaces do you have ? The output below for "max" is for 8 routed interfaces if you have more you should change to the desktop switching template. With your roughly your values for indirectly connected routes and 13 ip interfaces on a box I needed to switch the template "sdm prefer routing" requies reload. Regards Brian -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Chris Lane Sent: venerd? 24 aprile 2009 1.09 To: Peter Rathlev Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] 3750 High Cpu IP Input sh platform tcam utilization CAM Utilization for ASIC# 0 Max Used Masks/Values Masks/values Unicast mac addresses: 784/6272 37/235 IPv4 IGMP groups + multicast routes: 144/1152 6/26 IPv4 unicast directly-connected routes: 784/6272 37/235 IPv4 unicast indirectly-connected routes: 272/2176 52/326 IPv4 policy based routing aces: 0/0 0/0 IPv4 qos aces: 528/528 18/18 IPv4 security aces: 1024/1024 57/57 Note: Allocation of TCAM entries per feature uses a complex algorithm. The above information is meant to provide an abstract view of the current TCAM utilization Hope this helps. On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev wrote: > On Thu, 2009-04-23 at 16:15 -0400, Chris Lane wrote: > > This box has been in production for over a year and doesn't really do > > to much as you can see from my orig thread it moves about 11MB. > > > > This just started late last night yet we didn't add any new customer > > nor did anybody even touch switch as the device is remote. > > > > I read in an older thread regarding same thing that the person > > rebooted and of course it resolved issue. I am planning to do that > > Early tomorrow am, but > > i really want to know what the heck is causing this. > > > > Yes CEF is running. > > What about TCAM utilisation ("show platform tcam utilization")? > > Regards, > Peter > > > -- //CL _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ -- //CL From p.mayers at imperial.ac.uk Fri Apr 24 07:30:27 2009 From: p.mayers at imperial.ac.uk (Phil Mayers) Date: Fri, 24 Apr 2009 12:30:27 +0100 Subject: [c-nsp] Forcing all HSRP interfaces to failover In-Reply-To: <20090424110443.GA26907@kallisti.us> References: <20090424110443.GA26907@kallisti.us> Message-ID: <49F1A2D3.9060209@imperial.ac.uk> Ross Vandegrift wrote: > Hi everyone, > > Is there any good way to have IOS abdicate the active status on all of > its HSRP interfaces? Of course I could change each of a few thousand > SVIs, but I'd like a better way. > > The only thing I can come up with is to create an unnumbered loopback > just to use as a tracking target. Admin down that interface when you > want to take down one of the routers for maintenance. What platform/IOS? Under later IOS e.g. SXH/SXI on 6500 you can track the tracking "objects". We do this: track 10 interface Vlan4000 ip routing track 11 interface Vlan4001 ip routing track 100 stub-object default-state up track 101 list boolean or object 10 object 11 int VlanXX standby 0 track 100 decrement 4 standby 0 track 101 decrement 4 standby 0 preempt delay reload 180 ...and then do: conf t track 100 default-state down ...or use an EEM script to put the tracking object "down". Obviously the EEM script opens up a load more possibilities. Note you can also do this: int VlanXX standby 0 track 100 shutdown ...which will shutdown the HSRP group, but you'll then have to wait for the timers to expire - I prefer the priority decrement with appropriate pre-empt statements on the standby/master. Some versions of IOS have HSRP "follow groups": http://www.cisco.com/en/US/docs/ios/ipapp/configuration/guide/ipapp_hsrp.html#wp1055821 ...but on the switch platforms e.g. 6500 this seems to work with sub-ints only, not SVIs. Sigh. From clane1875 at gmail.com Fri Apr 24 07:35:18 2009 From: clane1875 at gmail.com (Chris Lane) Date: Fri, 24 Apr 2009 07:35:18 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> Message-ID: <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> 1 routed interface.sh platform ip unicast failed route Total of 0 covering fib entries Thanks for reply.. I checked earlier regarding sdm. Its the same on all of my 3750's i have about 20 of them throughout the states, this is probably the quietest one in regards to bandwidth and services. On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow wrote: > how many routed interfaces do you have ( sh ip int brief with ip > addresses ) ? > if more than 8 change the sdm template to routing > > you can use sh platform ip unicast failed route to see if routes are > failing to be programmed into tcam > > Brian > > > > > ------------------------------ > *From:* Chris Lane [mailto:clane1875 at gmail.com] > *Sent:* venerd? 24 aprile 2009 11.17 > *To:* Brian Turnbow > *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net > > *Subject:* Re: [c-nsp] 3750 High Cpu IP Input > > sh controllers cpu-interface > ASIC Rxbiterr Rxunder Fwdctfix Txbuflos Rxbufloc Rxbufdrain > ------------------------------------------------------------------------- > ASIC0 0 0 0 0 0 0 > ASIC1 0 0 0 0 0 0 > > > cpu-queue-frames retrieved dropped invalid hol-block stray > ----------------- ---------- ---------- ---------- ---------- ---------- > rpc 0 0 0 0 0 > stp 1807 0 0 0 0 > ipc 0 0 0 0 0 > routing protocol 1516326 0 0 0 0 > L2 protocol 27 0 0 0 0 > remote console 0 0 0 0 0 > sw forwarding 915 0 0 0 0 > host 2014 0 0 0 0 > broadcast 1766 0 0 0 0 > cbt-to-spt 0 0 0 0 0 > igmp snooping 1518651 0 0 0 0 > icmp 45 0 0 0 0 > logging 0 0 0 0 0 > rpf-fail 0 0 0 0 0 > queue14 0 0 0 0 0 > cpu heartbeat 14116 0 0 0 0 > > ODD i have disabled IGMP SNOOPING... > > On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow wrote: > >> You can use show controller cpu to help see whats going to the cpu >> Make sure you have no ip redirects and no proxy arp on all the interfaces. >> How many routed interfaces do you have ? >> The output below for "max" is for 8 routed interfaces if you have more you >> should change to the desktop switching template. >> With your roughly your values for indirectly connected routes and 13 ip >> interfaces on a box I needed to switch the template "sdm prefer routing" >> requies reload. >> >> Regards >> >> Brian >> >> >> >> >> -----Original Message----- >> From: cisco-nsp-bounces at puck.nether.net [mailto: >> cisco-nsp-bounces at puck.nether.net] On Behalf Of Chris Lane >> Sent: venerd? 24 aprile 2009 1.09 >> To: Peter Rathlev >> Cc: cisco-nsp at puck.nether.net >> Subject: Re: [c-nsp] 3750 High Cpu IP Input >> >> sh platform tcam utilization >> >> CAM Utilization for ASIC# 0 Max Used >> Masks/Values Masks/values >> >> Unicast mac addresses: 784/6272 37/235 >> IPv4 IGMP groups + multicast routes: 144/1152 6/26 >> IPv4 unicast directly-connected routes: 784/6272 37/235 >> IPv4 unicast indirectly-connected routes: 272/2176 52/326 >> IPv4 policy based routing aces: 0/0 0/0 >> IPv4 qos aces: 528/528 18/18 >> IPv4 security aces: 1024/1024 57/57 >> >> Note: Allocation of TCAM entries per feature uses >> a complex algorithm. The above information is meant >> to provide an abstract view of the current TCAM utilization >> >> Hope this helps. >> >> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev wrote: >> >> > On Thu, 2009-04-23 at 16:15 -0400, Chris Lane wrote: >> > > This box has been in production for over a year and doesn't really do >> > > to much as you can see from my orig thread it moves about 11MB. >> > > >> > > This just started late last night yet we didn't add any new customer >> > > nor did anybody even touch switch as the device is remote. >> > > >> > > I read in an older thread regarding same thing that the person >> > > rebooted and of course it resolved issue. I am planning to do that >> > > Early tomorrow am, but >> > > i really want to know what the heck is causing this. >> > > >> > > Yes CEF is running. >> > >> > What about TCAM utilisation ("show platform tcam utilization")? >> > >> > Regards, >> > Peter >> > >> > >> > >> >> >> -- >> //CL >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > > > > -- > //CL > -- //CL From clane1875 at gmail.com Fri Apr 24 07:44:18 2009 From: clane1875 at gmail.com (Chris Lane) Date: Fri, 24 Apr 2009 07:44:18 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <49F1A655.5020505@ya.ru> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> Message-ID: <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> sh ip traffic IP statistics: Rcvd: 37788273 total, 24253 local destination 0 format errors, 0 checksum errors, 9771492 bad hop count 0 unknown protocol, 27979860 not a gateway 0 security failures, 0 bad options, 7762670 with options Opts: 0 end, 0 nop, 0 basic security, 0 loose source route 0 timestamp, 0 extended security, 0 record route 0 stream ID, 0 strict source route, 7762670 alert, 0 cipso, 0 ump 0 other Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble 0 fragmented, 0 couldn't fragment Bcast: 2884 received, 87 sent Mcast: 2334 received, 2209 sent Sent: 24621 generated, 8328118 forwarded Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency 69 no route, 0 unicast RPF, 0 forced drop 0 options denied, 0 source IP address zero ICMP statistics: Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 unreachable 9560 echo, 0 echo reply, 0 mask requests, 0 mask replies, 0 quench 0 parameter, 0 timestamp, 0 info request, 0 other 0 irdp solicitations, 0 irdp advertisements Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply 0 mask requests, 0 mask replies, 0 quench, 0 timestamp 0 info reply, 47 time exceeded, 0 parameter problem 0 irdp solicitations, 0 irdp advertisements TCP statistics: Rcvd: 7710 total, 8 checksum errors, 1 no port Sent: 6762 total UDP statistics: Rcvd: 4615 total, 0 checksum errors, 1430 no port Sent: 2909 total, 0 forwarded broadcasts IP-EIGRP statistics: Rcvd: 0 total Sent: 0 total BGP statistics: Rcvd: 162 total, 1 opens, 0 notifications, 1 updates 160 keepalives, 0 route-refresh, 0 unrecognized Sent: 159 total, 1 opens, 0 notifications, 0 updates 158 keepalives, 0 route-refresh PIMv2 statistics: Sent/Received Total: 0/0, 0 checksum errors, 0 format errors Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, Hellos: 0/0 Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 State-Refresh: 0/0 IGMP statistics: Sent/Received Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: 0/0, PIM: 0/0 OSPF statistics: Rcvd: 2363 total, 0 checksum errors 1900 hello, 12 database desc, 2 link state req 345 link state updates, 104 link state acks Sent: 2231 total 1904 hello, 11 database desc, 4 link state req 223 link state updates, 89 link state acks ARP statistics: Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse Drop due to input queue full: 0 Thanks for looking. On Fri, Apr 24, 2009 at 7:45 AM, junior wrote: > Hi, > > Did You check TAC cases? > Can You post this switch current configuration with sh ip traffic command > output? > > WBR > Roman A. Nozdrin > > Chris Lane wrote: > >> 1 routed interface.sh platform ip unicast failed route >> Total of 0 covering fib entries >> >> Thanks for reply.. I checked earlier regarding sdm. >> Its the same on all of my 3750's i have about 20 of them throughout the >> states, this is probably the quietest one in regards to bandwidth and >> services. >> >> >> >> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow wrote: >> >> how many routed interfaces do you have ( sh ip int brief with ip >>> addresses ) ? >>> if more than 8 change the sdm template to routing >>> >>> you can use sh platform ip unicast failed route to see if routes are >>> failing to be programmed into tcam >>> >>> Brian >>> >>> >>> >>> >>> ------------------------------ >>> *From:* Chris Lane [mailto:clane1875 at gmail.com] >>> *Sent:* venerd? 24 aprile 2009 11.17 >>> >>> *To:* Brian Turnbow >>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net >>> >>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input >>> >>> sh controllers cpu-interface >>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos Rxbufloc Rxbufdrain >>> ------------------------------------------------------------------------- >>> ASIC0 0 0 0 0 0 0 >>> ASIC1 0 0 0 0 0 0 >>> >>> >>> cpu-queue-frames retrieved dropped invalid hol-block stray >>> ----------------- ---------- ---------- ---------- ---------- ---------- >>> rpc 0 0 0 0 0 >>> stp 1807 0 0 0 0 >>> ipc 0 0 0 0 0 >>> routing protocol 1516326 0 0 0 0 >>> L2 protocol 27 0 0 0 0 >>> remote console 0 0 0 0 0 >>> sw forwarding 915 0 0 0 0 >>> host 2014 0 0 0 0 >>> broadcast 1766 0 0 0 0 >>> cbt-to-spt 0 0 0 0 0 >>> igmp snooping 1518651 0 0 0 0 >>> icmp 45 0 0 0 0 >>> logging 0 0 0 0 0 >>> rpf-fail 0 0 0 0 0 >>> queue14 0 0 0 0 0 >>> cpu heartbeat 14116 0 0 0 0 >>> >>> ODD i have disabled IGMP SNOOPING... >>> >>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow wrote: >>> >>> You can use show controller cpu to help see whats going to the cpu >>>> Make sure you have no ip redirects and no proxy arp on all the >>>> interfaces. >>>> How many routed interfaces do you have ? >>>> The output below for "max" is for 8 routed interfaces if you have more >>>> you >>>> should change to the desktop switching template. >>>> With your roughly your values for indirectly connected routes and 13 ip >>>> interfaces on a box I needed to switch the template "sdm prefer routing" >>>> requies reload. >>>> >>>> Regards >>>> >>>> Brian >>>> >>>> >>>> >>>> >>>> -----Original Message----- >>>> From: cisco-nsp-bounces at puck.nether.net [mailto: >>>> cisco-nsp-bounces at puck.nether.net] On Behalf Of Chris Lane >>>> Sent: venerd? 24 aprile 2009 1.09 >>>> To: Peter Rathlev >>>> Cc: cisco-nsp at puck.nether.net >>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input >>>> >>>> sh platform tcam utilization >>>> >>>> CAM Utilization for ASIC# 0 Max Used >>>> Masks/Values Masks/values >>>> >>>> Unicast mac addresses: 784/6272 37/235 >>>> IPv4 IGMP groups + multicast routes: 144/1152 6/26 >>>> IPv4 unicast directly-connected routes: 784/6272 37/235 >>>> IPv4 unicast indirectly-connected routes: 272/2176 52/326 >>>> IPv4 policy based routing aces: 0/0 0/0 >>>> IPv4 qos aces: 528/528 18/18 >>>> IPv4 security aces: 1024/1024 57/57 >>>> >>>> Note: Allocation of TCAM entries per feature uses >>>> a complex algorithm. The above information is meant >>>> to provide an abstract view of the current TCAM utilization >>>> >>>> Hope this helps. >>>> >>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev >>>> wrote: >>>> >>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane wrote: >>>>> >>>>>> This box has been in production for over a year and doesn't really do >>>>>> to much as you can see from my orig thread it moves about 11MB. >>>>>> >>>>>> This just started late last night yet we didn't add any new customer >>>>>> nor did anybody even touch switch as the device is remote. >>>>>> >>>>>> I read in an older thread regarding same thing that the person >>>>>> rebooted and of course it resolved issue. I am planning to do that >>>>>> Early tomorrow am, but >>>>>> i really want to know what the heck is causing this. >>>>>> >>>>>> Yes CEF is running. >>>>>> >>>>> What about TCAM utilisation ("show platform tcam utilization")? >>>>> >>>>> Regards, >>>>> Peter >>>>> >>>>> >>>>> >>>>> >>>> -- >>>> //CL >>>> _______________________________________________ >>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>> >>>> >>> >>> -- >>> //CL >>> >>> >> >> >> > -- //CL From jcartier at acs.on.ca Fri Apr 24 08:02:32 2009 From: jcartier at acs.on.ca (Jeff Cartier) Date: Fri, 24 Apr 2009 08:02:32 -0400 Subject: [c-nsp] Looking for c7300-k91p-mz.122-28.SB1 Message-ID: Is anyone running this IOS or has a copy set aside?... From achatz at forthnet.gr Fri Apr 24 08:11:42 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Fri, 24 Apr 2009 15:11:42 +0300 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <1240516876.3396.3.camel@localhost.localdomain> <2e1cd850904231315k5cd2a31axe6742364b556db82@mail.gmail.com> <1240519271.3396.9.camel@localhost.localdomain> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> Message-ID: <49F1AC7E.30005@forthnet.gr> Maybe try "ip options drop" for a while (you might drop legitimate traffic!) to see if that makes a difference. -- Tassos Chris Lane wrote on 24/04/2009 14:44: > sh ip traffic > IP statistics: > Rcvd: 37788273 total, 24253 local destination > 0 format errors, 0 checksum errors, 9771492 bad hop count > 0 unknown protocol, 27979860 not a gateway > 0 security failures, 0 bad options, 7762670 with options > Opts: 0 end, 0 nop, 0 basic security, 0 loose source route > 0 timestamp, 0 extended security, 0 record route > 0 stream ID, 0 strict source route, 7762670 alert, 0 cipso, 0 ump > 0 other > Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble > 0 fragmented, 0 couldn't fragment > Bcast: 2884 received, 87 sent > Mcast: 2334 received, 2209 sent > Sent: 24621 generated, 8328118 forwarded > Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency > 69 no route, 0 unicast RPF, 0 forced drop > 0 options denied, 0 source IP address zero > > ICMP statistics: > Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 unreachable > 9560 echo, 0 echo reply, 0 mask requests, 0 mask replies, 0 quench > 0 parameter, 0 timestamp, 0 info request, 0 other > 0 irdp solicitations, 0 irdp advertisements > Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply > 0 mask requests, 0 mask replies, 0 quench, 0 timestamp > 0 info reply, 47 time exceeded, 0 parameter problem > 0 irdp solicitations, 0 irdp advertisements > > TCP statistics: > Rcvd: 7710 total, 8 checksum errors, 1 no port > Sent: 6762 total > > UDP statistics: > Rcvd: 4615 total, 0 checksum errors, 1430 no port > Sent: 2909 total, 0 forwarded broadcasts > > IP-EIGRP statistics: > Rcvd: 0 total > Sent: 0 total > > BGP statistics: > Rcvd: 162 total, 1 opens, 0 notifications, 1 updates > 160 keepalives, 0 route-refresh, 0 unrecognized > Sent: 159 total, 1 opens, 0 notifications, 0 updates > 158 keepalives, 0 route-refresh > > PIMv2 statistics: Sent/Received > Total: 0/0, 0 checksum errors, 0 format errors > Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, Hellos: > 0/0 > Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 > Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 > State-Refresh: 0/0 > > IGMP statistics: Sent/Received > Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 > Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 > DVMRP: 0/0, PIM: 0/0 > > OSPF statistics: > Rcvd: 2363 total, 0 checksum errors > 1900 hello, 12 database desc, 2 link state req > 345 link state updates, 104 link state acks > > Sent: 2231 total > 1904 hello, 11 database desc, 4 link state req > 223 link state updates, 89 link state acks > > ARP statistics: > Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other > Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse > Drop due to input queue full: 0 > > Thanks for looking. > > On Fri, Apr 24, 2009 at 7:45 AM, junior wrote: > >> Hi, >> >> Did You check TAC cases? >> Can You post this switch current configuration with sh ip traffic command >> output? >> >> WBR >> Roman A. Nozdrin >> >> Chris Lane wrote: >> >>> 1 routed interface.sh platform ip unicast failed route >>> Total of 0 covering fib entries >>> >>> Thanks for reply.. I checked earlier regarding sdm. >>> Its the same on all of my 3750's i have about 20 of them throughout the >>> states, this is probably the quietest one in regards to bandwidth and >>> services. >>> >>> >>> >>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow wrote: >>> >>> how many routed interfaces do you have ( sh ip int brief with ip >>>> addresses ) ? >>>> if more than 8 change the sdm template to routing >>>> >>>> you can use sh platform ip unicast failed route to see if routes are >>>> failing to be programmed into tcam >>>> >>>> Brian >>>> >>>> >>>> >>>> >>>> ------------------------------ >>>> *From:* Chris Lane [mailto:clane1875 at gmail.com] >>>> *Sent:* venerde( 24 aprile 2009 11.17 >>>> >>>> *To:* Brian Turnbow >>>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net >>>> >>>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input >>>> >>>> sh controllers cpu-interface >>>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos Rxbufloc Rxbufdrain >>>> ------------------------------------------------------------------------- >>>> ASIC0 0 0 0 0 0 0 >>>> ASIC1 0 0 0 0 0 0 >>>> >>>> >>>> cpu-queue-frames retrieved dropped invalid hol-block stray >>>> ----------------- ---------- ---------- ---------- ---------- ---------- >>>> rpc 0 0 0 0 0 >>>> stp 1807 0 0 0 0 >>>> ipc 0 0 0 0 0 >>>> routing protocol 1516326 0 0 0 0 >>>> L2 protocol 27 0 0 0 0 >>>> remote console 0 0 0 0 0 >>>> sw forwarding 915 0 0 0 0 >>>> host 2014 0 0 0 0 >>>> broadcast 1766 0 0 0 0 >>>> cbt-to-spt 0 0 0 0 0 >>>> igmp snooping 1518651 0 0 0 0 >>>> icmp 45 0 0 0 0 >>>> logging 0 0 0 0 0 >>>> rpf-fail 0 0 0 0 0 >>>> queue14 0 0 0 0 0 >>>> cpu heartbeat 14116 0 0 0 0 >>>> >>>> ODD i have disabled IGMP SNOOPING... >>>> >>>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow wrote: >>>> >>>> You can use show controller cpu to help see whats going to the cpu >>>>> Make sure you have no ip redirects and no proxy arp on all the >>>>> interfaces. >>>>> How many routed interfaces do you have ? >>>>> The output below for "max" is for 8 routed interfaces if you have more >>>>> you >>>>> should change to the desktop switching template. >>>>> With your roughly your values for indirectly connected routes and 13 ip >>>>> interfaces on a box I needed to switch the template "sdm prefer routing" >>>>> requies reload. >>>>> >>>>> Regards >>>>> >>>>> Brian >>>>> >>>>> >>>>> >>>>> >>>>> -----Original Message----- >>>>> From: cisco-nsp-bounces at puck.nether.net [mailto: >>>>> cisco-nsp-bounces at puck.nether.net] On Behalf Of Chris Lane >>>>> Sent: venerde( 24 aprile 2009 1.09 >>>>> To: Peter Rathlev >>>>> Cc: cisco-nsp at puck.nether.net >>>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input >>>>> >>>>> sh platform tcam utilization >>>>> >>>>> CAM Utilization for ASIC# 0 Max Used >>>>> Masks/Values Masks/values >>>>> >>>>> Unicast mac addresses: 784/6272 37/235 >>>>> IPv4 IGMP groups + multicast routes: 144/1152 6/26 >>>>> IPv4 unicast directly-connected routes: 784/6272 37/235 >>>>> IPv4 unicast indirectly-connected routes: 272/2176 52/326 >>>>> IPv4 policy based routing aces: 0/0 0/0 >>>>> IPv4 qos aces: 528/528 18/18 >>>>> IPv4 security aces: 1024/1024 57/57 >>>>> >>>>> Note: Allocation of TCAM entries per feature uses >>>>> a complex algorithm. The above information is meant >>>>> to provide an abstract view of the current TCAM utilization >>>>> >>>>> Hope this helps. >>>>> >>>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev >>>>> wrote: >>>>> >>>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane wrote: >>>>>>> This box has been in production for over a year and doesn't really do >>>>>>> to much as you can see from my orig thread it moves about 11MB. >>>>>>> >>>>>>> This just started late last night yet we didn't add any new customer >>>>>>> nor did anybody even touch switch as the device is remote. >>>>>>> >>>>>>> I read in an older thread regarding same thing that the person >>>>>>> rebooted and of course it resolved issue. I am planning to do that >>>>>>> Early tomorrow am, but >>>>>>> i really want to know what the heck is causing this. >>>>>>> >>>>>>> Yes CEF is running. >>>>>>> >>>>>> What about TCAM utilisation ("show platform tcam utilization")? >>>>>> >>>>>> Regards, >>>>>> Peter >>>>>> >>>>>> >>>>>> >>>>>> >>>>> -- >>>>> //CL >>>>> _______________________________________________ >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>>> >>>>> >>>> -- >>>> //CL >>>> >>>> >>> >>> > > From peter at rathlev.dk Fri Apr 24 08:23:13 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Fri, 24 Apr 2009 14:23:13 +0200 Subject: [c-nsp] Forcing all HSRP interfaces to failover In-Reply-To: <20090424110443.GA26907@kallisti.us> References: <20090424110443.GA26907@kallisti.us> Message-ID: <1240575793.3518.48.camel@localhost.localdomain> On Fri, 2009-04-24 at 07:04 -0400, Ross Vandegrift wrote: > Is there any good way to have IOS abdicate the active status on all of > its HSRP interfaces? Of course I could change each of a few thousand > SVIs, but I'd like a better way. > > The only thing I can come up with is to create an unnumbered loopback > just to use as a tracking target. Admin down that interface when you > want to take down one of the routers for maintenance. > > Has anyone ever done something similar? Any better ideas? That's exactly what we do, use an unnumbered Loopback interface for this. It works fine and is very simple to configure. Don't know of any smarter way. Regards, Peter From clane1875 at gmail.com Fri Apr 24 09:26:11 2009 From: clane1875 at gmail.com (Chris Lane) Date: Fri, 24 Apr 2009 09:26:11 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> Message-ID: <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> Richard Gallagher found that it was one of my customers sending mcast packets with a TTL 1. Tried adding ACL's to lower CPU but this didn't fix. We shutdown Vlan to verify and CPU came down 40% to adequate levels. I have a call into out customer notifying them to fix. Thanks to all for your input Regards Chris 2009/4/24 Chris Lane > Yes with a high preference. > > 2009/4/24 junior > > Hello. >> >> Does this switch have default route? >> >> Chris Lane wrote: >> >>> sh ip traffic IP statistics: >>> Rcvd: 37788273 total, 24253 local destination >>> 0 format errors, 0 checksum errors, 9771492 bad hop count >>> 0 unknown protocol, 27979860 not a gateway >>> 0 security failures, 0 bad options, 7762670 with options >>> Opts: 0 end, 0 nop, 0 basic security, 0 loose source route >>> 0 timestamp, 0 extended security, 0 record route >>> 0 stream ID, 0 strict source route, 7762670 alert, 0 cipso, 0 ump >>> 0 other >>> Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble >>> 0 fragmented, 0 couldn't fragment >>> Bcast: 2884 received, 87 sent >>> Mcast: 2334 received, 2209 sent >>> Sent: 24621 generated, 8328118 forwarded >>> Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency >>> 69 no route, 0 unicast RPF, 0 forced drop >>> 0 options denied, 0 source IP address zero >>> >>> ICMP statistics: >>> Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 unreachable >>> 9560 echo, 0 echo reply, 0 mask requests, 0 mask replies, 0 quench >>> 0 parameter, 0 timestamp, 0 info request, 0 other >>> 0 irdp solicitations, 0 irdp advertisements >>> Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply >>> 0 mask requests, 0 mask replies, 0 quench, 0 timestamp >>> 0 info reply, 47 time exceeded, 0 parameter problem >>> 0 irdp solicitations, 0 irdp advertisements >>> >>> TCP statistics: >>> Rcvd: 7710 total, 8 checksum errors, 1 no port >>> Sent: 6762 total >>> >>> UDP statistics: >>> Rcvd: 4615 total, 0 checksum errors, 1430 no port >>> Sent: 2909 total, 0 forwarded broadcasts >>> >>> IP-EIGRP statistics: >>> Rcvd: 0 total >>> Sent: 0 total >>> >>> BGP statistics: >>> Rcvd: 162 total, 1 opens, 0 notifications, 1 updates >>> 160 keepalives, 0 route-refresh, 0 unrecognized >>> Sent: 159 total, 1 opens, 0 notifications, 0 updates >>> 158 keepalives, 0 route-refresh >>> >>> PIMv2 statistics: Sent/Received >>> Total: 0/0, 0 checksum errors, 0 format errors >>> Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, Hellos: >>> 0/0 >>> Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 >>> Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 >>> State-Refresh: 0/0 >>> >>> IGMP statistics: Sent/Received >>> Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 >>> Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: 0/0, PIM: >>> 0/0 >>> >>> OSPF statistics: >>> Rcvd: 2363 total, 0 checksum errors >>> 1900 hello, 12 database desc, 2 link state req >>> 345 link state updates, 104 link state acks >>> >>> Sent: 2231 total >>> 1904 hello, 11 database desc, 4 link state req >>> 223 link state updates, 89 link state acks >>> >>> ARP statistics: >>> Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other >>> Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse >>> Drop due to input queue full: 0 >>> >>> Thanks for looking. >>> >>> On Fri, Apr 24, 2009 at 7:45 AM, junior >> drrtuy at ya.ru>> wrote: >>> >>> Hi, >>> >>> Did You check TAC cases? >>> Can You post this switch current configuration with sh ip traffic >>> command output? >>> >>> WBR >>> Roman A. Nozdrin >>> >>> Chris Lane wrote: >>> >>> 1 routed interface.sh platform ip unicast failed route >>> Total of 0 covering fib entries >>> >>> Thanks for reply.. I checked earlier regarding sdm. >>> Its the same on all of my 3750's i have about 20 of them >>> throughout the >>> states, this is probably the quietest one in regards to >>> bandwidth and >>> services. >>> >>> >>> >>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow >> > wrote: >>> >>> how many routed interfaces do you have ( sh ip int brief >>> with ip >>> addresses ) ? >>> if more than 8 change the sdm template to routing >>> >>> you can use sh platform ip unicast failed route to see if >>> routes are >>> failing to be programmed into tcam >>> >>> Brian >>> >>> >>> >>> >>> ------------------------------ >>> *From:* Chris Lane [mailto:clane1875 at gmail.com >>> ] >>> *Sent:* venerd? 24 aprile 2009 11.17 >>> >>> *To:* Brian Turnbow >>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net >>> >>> >>> >>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input >>> >>> sh controllers cpu-interface >>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos Rxbufloc >>> Rxbufdrain >>> >>> ------------------------------------------------------------------------- >>> ASIC0 0 0 0 0 0 >>> 0 >>> ASIC1 0 0 0 0 0 >>> 0 >>> >>> >>> cpu-queue-frames retrieved dropped invalid hol-block >>> stray >>> ----------------- ---------- ---------- ---------- >>> ---------- ---------- >>> rpc 0 0 0 0 >>> 0 >>> stp 1807 0 0 0 >>> 0 >>> ipc 0 0 0 0 >>> 0 >>> routing protocol 1516326 0 0 0 >>> 0 >>> L2 protocol 27 0 0 0 >>> 0 >>> remote console 0 0 0 0 >>> 0 >>> sw forwarding 915 0 0 0 >>> 0 >>> host 2014 0 0 0 >>> 0 >>> broadcast 1766 0 0 0 >>> 0 >>> cbt-to-spt 0 0 0 0 >>> 0 >>> igmp snooping 1518651 0 0 0 >>> 0 >>> icmp 45 0 0 0 >>> 0 >>> logging 0 0 0 0 >>> 0 >>> rpf-fail 0 0 0 0 >>> 0 >>> queue14 0 0 0 0 >>> 0 >>> cpu heartbeat 14116 0 0 0 >>> 0 >>> >>> ODD i have disabled IGMP SNOOPING... >>> >>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow >>> > wrote: >>> >>> You can use show controller cpu to help see whats >>> going to the cpu >>> Make sure you have no ip redirects and no proxy arp on >>> all the interfaces. >>> How many routed interfaces do you have ? >>> The output below for "max" is for 8 routed interfaces if >>> you have more you >>> should change to the desktop switching template. >>> With your roughly your values for indirectly connected >>> routes and 13 ip >>> interfaces on a box I needed to switch the template "sdm >>> prefer routing" >>> requies reload. >>> >>> Regards >>> >>> Brian >>> >>> >>> >>> >>> -----Original Message----- >>> From: cisco-nsp-bounces at puck.nether.net >>> [mailto: >>> cisco-nsp-bounces at puck.nether.net >>> ] On Behalf Of >>> Chris Lane >>> Sent: venerd? 24 aprile 2009 1.09 >>> To: Peter Rathlev >>> Cc: cisco-nsp at puck.nether.net >>> >>> Subject: Re: [c-nsp] 3750 High Cpu IP Input >>> >>> sh platform tcam utilization >>> >>> CAM Utilization for ASIC# 0 Max >>> Used >>> Masks/Values >>> Masks/values >>> >>> Unicast mac addresses: 784/6272 >>> 37/235 >>> IPv4 IGMP groups + multicast routes: 144/1152 >>> 6/26 >>> IPv4 unicast directly-connected routes: 784/6272 >>> 37/235 >>> IPv4 unicast indirectly-connected routes: 272/2176 >>> 52/326 >>> IPv4 policy based routing aces: 0/0 >>> 0/0 >>> IPv4 qos aces: 528/528 >>> 18/18 >>> IPv4 security aces: 1024/1024 >>> 57/57 >>> >>> Note: Allocation of TCAM entries per feature uses >>> a complex algorithm. The above information is meant >>> to provide an abstract view of the current TCAM >>> utilization >>> >>> Hope this helps. >>> >>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev >>> > wrote: >>> >>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane wrote: >>> >>> This box has been in production for over a year >>> and doesn't really do >>> to much as you can see from my orig thread it >>> moves about 11MB. >>> >>> This just started late last night yet we didn't >>> add any new customer >>> nor did anybody even touch switch as the device >>> is remote. >>> >>> I read in an older thread regarding same thing >>> that the person >>> rebooted and of course it resolved issue. I am >>> planning to do that >>> Early tomorrow am, but >>> i really want to know what the heck is causing >>> this. >>> >>> Yes CEF is running. >>> >>> What about TCAM utilisation ("show platform tcam >>> utilization")? >>> >>> Regards, >>> Peter >>> >>> >>> >>> >>> -- >>> //CL >>> _______________________________________________ >>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>> >>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>> >>> >>> >>> -- >>> //CL >>> >>> >>> >>> >>> >>> >>> >>> >>> -- >>> //CL >>> >> >> > > > -- > //CL > -- //CL From rodunn at cisco.com Fri Apr 24 09:31:36 2009 From: rodunn at cisco.com (Rodney Dunn) Date: Fri, 24 Apr 2009 09:31:36 -0400 Subject: [c-nsp] The dreaded microburst - definition and troubleshooting In-Reply-To: <3329cbb40904232138i3c45ac87va2138a787685cc02@mail.gmail.com> References: <3329cbb40904232138i3c45ac87va2138a787685cc02@mail.gmail.com> Message-ID: <20090424133136.GC1234@rtp-cse-489.cisco.com> On Fri, Apr 24, 2009 at 02:38:01PM +1000, Dale Shaw wrote: > Hi all, > > Is there a universally agreed upon definition for a 'microburst'? None that I have ever seen because it's all relative. > > Is there a defined time measurement - i.e. 5ms, 10ms, 50ms, 100ms, > 1000ms - during which a certain bps or pps threshold must be > met/exceeded? No because it's dependent on the features and traffic profiles through the entire box. > > Does anyone have any tips for troubleshooting microbursts, > particularly in relation to the c7200 platform exhibiting "no buff" > drops? We're going to capture some data (w/SPAN on an adjacent switch) > but it would be nice to be able to look at the data and somehow marry > it up with incrementing drop counters on the affected c7200 interface. #1 issue with this box as high speed switches have been connected to them. What does 'show c7200' say? > > It would be nice to be able to explain such drops like "within the > measurement window, we saw traffic at bps/pps rate x, and we know that > anything beyond bps/pps rate y will result in drops". The best you could get is that the rx ring, IIRC from 'show controller', is 128. If you overrun that you will see an overrun/drop. There are a lot of internal complexities to how interrupts are handled for high speed switching in software. It's not perfect. There are times when interrupts need to be disabled and any short time is enough to overrun the rx ring. I worked with the BU to try and increase that rx ring depth but it was much more complex than it appears to make that happen. s> I suppose it's platform-specific, but how does one come up with an > accurate benchmark? Is such precision just wishful thinking in the > murky world of microbursts? :-) Honestly, wishful thinking. It varies by plaform, feature configuration, user interaction, etc. Rodney > > cheers, > Dale > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From rgallagh at cisco.com Fri Apr 24 09:37:30 2009 From: rgallagh at cisco.com (Richard Gallagher) Date: Fri, 24 Apr 2009 14:37:30 +0100 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <2e1cd850904231609g35e91aa1r9c19393b4dbfcb24@mail.gmail.com> <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> Message-ID: Input queue was full of packets like this: Buffer information for RxQ3 buffer at 0x2E792F0 data_area 0x7BB2AB0, refcount 1, next 0x2E7E210, flags 0x200 linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) inputtime 00:00:00.000 (elapsed never) outputtime 00:00:00.000 (elapsed never), oqnumber 65535 datagramstart 0x7BB2AF6, datagramsize 82, maximum size 2196 mac_start 0x7BB2AF6, addr_start 0x7BB2AF6, info_start 0x0 network_start 0x7BB2B04, transport_start 0x7BB2B18, caller_pc 0x6D1024 source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: 1, TOS: 0 prot: 17, source port 58064, destination port 5355 Buffer information for RxQFB buffer at 0x2672BB0 data_area 0x758C35C, refcount 1, next 0x263960C, flags 0x200 linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) inputtime 00:00:00.000 (elapsed never) outputtime 00:00:00.000 (elapsed never), oqnumber 65535 datagramstart 0x758C3A2, datagramsize 64, maximum size 2196 mac_start 0x758C3A2, addr_start 0x758C3A2, info_start 0x0 network_start 0x758C3B0, transport_start 0x0, caller_pc 0x6D1024 source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: 1, TOS: 0 prot: 17, source port 58064, destination port 5355 These TTL=1 are causing the high CPU. On 24 Apr 2009, at 14:26, Chris Lane wrote: > Richard Gallagher found that it was one of my customers sending mcast > packets with a TTL 1. Tried adding ACL's to lower CPU but this > didn't fix. > We shutdown Vlan to verify and CPU came down 40% to adequate levels. > > I have a call into out customer notifying them to fix. > > Thanks to all for your input > > Regards > Chris > > 2009/4/24 Chris Lane > >> Yes with a high preference. >> >> 2009/4/24 junior >> >> Hello. >>> >>> Does this switch have default route? >>> >>> Chris Lane wrote: >>> >>>> sh ip traffic IP statistics: >>>> Rcvd: 37788273 total, 24253 local destination >>>> 0 format errors, 0 checksum errors, 9771492 bad hop count >>>> 0 unknown protocol, 27979860 not a gateway >>>> 0 security failures, 0 bad options, 7762670 with options >>>> Opts: 0 end, 0 nop, 0 basic security, 0 loose source route >>>> 0 timestamp, 0 extended security, 0 record route >>>> 0 stream ID, 0 strict source route, 7762670 alert, 0 >>>> cipso, 0 ump >>>> 0 other >>>> Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble >>>> 0 fragmented, 0 couldn't fragment >>>> Bcast: 2884 received, 87 sent >>>> Mcast: 2334 received, 2209 sent >>>> Sent: 24621 generated, 8328118 forwarded >>>> Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency >>>> 69 no route, 0 unicast RPF, 0 forced drop >>>> 0 options denied, 0 source IP address zero >>>> >>>> ICMP statistics: >>>> Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 >>>> unreachable >>>> 9560 echo, 0 echo reply, 0 mask requests, 0 mask replies, 0 >>>> quench >>>> 0 parameter, 0 timestamp, 0 info request, 0 other >>>> 0 irdp solicitations, 0 irdp advertisements >>>> Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply >>>> 0 mask requests, 0 mask replies, 0 quench, 0 timestamp >>>> 0 info reply, 47 time exceeded, 0 parameter problem >>>> 0 irdp solicitations, 0 irdp advertisements >>>> >>>> TCP statistics: >>>> Rcvd: 7710 total, 8 checksum errors, 1 no port >>>> Sent: 6762 total >>>> >>>> UDP statistics: >>>> Rcvd: 4615 total, 0 checksum errors, 1430 no port >>>> Sent: 2909 total, 0 forwarded broadcasts >>>> >>>> IP-EIGRP statistics: >>>> Rcvd: 0 total >>>> Sent: 0 total >>>> >>>> BGP statistics: >>>> Rcvd: 162 total, 1 opens, 0 notifications, 1 updates >>>> 160 keepalives, 0 route-refresh, 0 unrecognized >>>> Sent: 159 total, 1 opens, 0 notifications, 0 updates >>>> 158 keepalives, 0 route-refresh >>>> >>>> PIMv2 statistics: Sent/Received >>>> Total: 0/0, 0 checksum errors, 0 format errors >>>> Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, >>>> Hellos: >>>> 0/0 >>>> Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 >>>> Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 >>>> State-Refresh: 0/0 >>>> >>>> IGMP statistics: Sent/Received >>>> Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 >>>> Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: >>>> 0/0, PIM: >>>> 0/0 >>>> >>>> OSPF statistics: >>>> Rcvd: 2363 total, 0 checksum errors >>>> 1900 hello, 12 database desc, 2 link state req >>>> 345 link state updates, 104 link state acks >>>> >>>> Sent: 2231 total >>>> 1904 hello, 11 database desc, 4 link state req >>>> 223 link state updates, 89 link state acks >>>> >>>> ARP statistics: >>>> Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other >>>> Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse >>>> Drop due to input queue full: 0 >>>> >>>> Thanks for looking. >>>> >>>> On Fri, Apr 24, 2009 at 7:45 AM, junior >>> drrtuy at ya.ru>> wrote: >>>> >>>> Hi, >>>> >>>> Did You check TAC cases? >>>> Can You post this switch current configuration with sh ip traffic >>>> command output? >>>> >>>> WBR >>>> Roman A. Nozdrin >>>> >>>> Chris Lane wrote: >>>> >>>> 1 routed interface.sh platform ip unicast failed route >>>> Total of 0 covering fib entries >>>> >>>> Thanks for reply.. I checked earlier regarding sdm. >>>> Its the same on all of my 3750's i have about 20 of them >>>> throughout the >>>> states, this is probably the quietest one in regards to >>>> bandwidth and >>>> services. >>>> >>>> >>>> >>>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow >>> > wrote: >>>> >>>> how many routed interfaces do you have ( sh ip int brief >>>> with ip >>>> addresses ) ? >>>> if more than 8 change the sdm template to routing >>>> >>>> you can use sh platform ip unicast failed route to see >>>> if >>>> routes are >>>> failing to be programmed into tcam >>>> >>>> Brian >>>> >>>> >>>> >>>> >>>> ------------------------------ >>>> *From:* Chris Lane [mailto:clane1875 at gmail.com >>>> ] >>>> *Sent:* venerd? 24 aprile 2009 11.17 >>>> >>>> *To:* Brian Turnbow >>>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net >>>> >>>> >>>> >>>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input >>>> >>>> sh controllers cpu-interface >>>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos >>>> Rxbufloc >>>> Rxbufdrain >>>> >>>> ------------------------------------------------------------------------- >>>> ASIC0 0 0 0 0 0 >>>> 0 >>>> ASIC1 0 0 0 0 0 >>>> 0 >>>> >>>> >>>> cpu-queue-frames retrieved dropped invalid hol- >>>> block >>>> stray >>>> ----------------- ---------- ---------- ---------- >>>> ---------- ---------- >>>> rpc 0 0 0 0 >>>> 0 >>>> stp 1807 0 0 0 >>>> 0 >>>> ipc 0 0 0 0 >>>> 0 >>>> routing protocol 1516326 0 0 0 >>>> 0 >>>> L2 protocol 27 0 0 0 >>>> 0 >>>> remote console 0 0 0 0 >>>> 0 >>>> sw forwarding 915 0 0 0 >>>> 0 >>>> host 2014 0 0 0 >>>> 0 >>>> broadcast 1766 0 0 0 >>>> 0 >>>> cbt-to-spt 0 0 0 0 >>>> 0 >>>> igmp snooping 1518651 0 0 0 >>>> 0 >>>> icmp 45 0 0 0 >>>> 0 >>>> logging 0 0 0 0 >>>> 0 >>>> rpf-fail 0 0 0 0 >>>> 0 >>>> queue14 0 0 0 0 >>>> 0 >>>> cpu heartbeat 14116 0 0 0 >>>> 0 >>>> >>>> ODD i have disabled IGMP SNOOPING... >>>> >>>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow >>>> > wrote: >>>> >>>> You can use show controller cpu to help see whats >>>> going to the cpu >>>> Make sure you have no ip redirects and no proxy arp >>>> on >>>> all the interfaces. >>>> How many routed interfaces do you have ? >>>> The output below for "max" is for 8 routed >>>> interfaces if >>>> you have more you >>>> should change to the desktop switching template. >>>> With your roughly your values for indirectly >>>> connected >>>> routes and 13 ip >>>> interfaces on a box I needed to switch the template >>>> "sdm >>>> prefer routing" >>>> requies reload. >>>> >>>> Regards >>>> >>>> Brian >>>> >>>> >>>> >>>> >>>> -----Original Message----- >>>> From: cisco-nsp-bounces at puck.nether.net >>>> [mailto: >>>> cisco-nsp-bounces at puck.nether.net >>>> ] On >>>> Behalf Of >>>> Chris Lane >>>> Sent: venerd? 24 aprile 2009 1.09 >>>> To: Peter Rathlev >>>> Cc: cisco-nsp at puck.nether.net >>>> >>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input >>>> >>>> sh platform tcam utilization >>>> >>>> CAM Utilization for ASIC# 0 Max >>>> Used >>>> Masks/ >>>> Values >>>> Masks/values >>>> >>>> Unicast mac addresses: >>>> 784/6272 >>>> 37/235 >>>> IPv4 IGMP groups + multicast routes: >>>> 144/1152 >>>> 6/26 >>>> IPv4 unicast directly-connected routes: >>>> 784/6272 >>>> 37/235 >>>> IPv4 unicast indirectly-connected routes: >>>> 272/2176 >>>> 52/326 >>>> IPv4 policy based routing aces: 0/0 >>>> 0/0 >>>> IPv4 qos aces: >>>> 528/528 >>>> 18/18 >>>> IPv4 security aces: >>>> 1024/1024 >>>> 57/57 >>>> >>>> Note: Allocation of TCAM entries per feature uses >>>> a complex algorithm. The above information is meant >>>> to provide an abstract view of the current TCAM >>>> utilization >>>> >>>> Hope this helps. >>>> >>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev >>>> > wrote: >>>> >>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane >>>> wrote: >>>> >>>> This box has been in production for over a >>>> year >>>> and doesn't really do >>>> to much as you can see from my orig thread it >>>> moves about 11MB. >>>> >>>> This just started late last night yet we >>>> didn't >>>> add any new customer >>>> nor did anybody even touch switch as the >>>> device >>>> is remote. >>>> >>>> I read in an older thread regarding same >>>> thing >>>> that the person >>>> rebooted and of course it resolved issue. I >>>> am >>>> planning to do that >>>> Early tomorrow am, but >>>> i really want to know what the heck is >>>> causing >>>> this. >>>> >>>> Yes CEF is running. >>>> >>>> What about TCAM utilisation ("show platform tcam >>>> utilization")? >>>> >>>> Regards, >>>> Peter >>>> >>>> >>>> >>>> >>>> -- >>>> //CL >>>> _______________________________________________ >>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>> >>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>> archive at http://puck.nether.net/pipermail/cisco- >>>> nsp/ >>>> >>>> >>>> >>>> -- >>>> //CL >>>> >>>> >>>> >>>> >>>> >>>> >>>> >>>> >>>> -- >>>> //CL >>>> >>> >>> >> >> >> -- >> //CL >> > > > > -- > //CL > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From ler762 at gmail.com Fri Apr 24 10:01:08 2009 From: ler762 at gmail.com (Lee) Date: Fri, 24 Apr 2009 10:01:08 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> Message-ID: > These TTL=1 are causing the high CPU. Just out of curiousity, would adding "ip multicast ttl-threshold 3" and/or "no ip unreachable" on the interface reduce cpu usage? Lee On 4/24/09, Richard Gallagher wrote: > Input queue was full of packets like this: > > Buffer information for RxQ3 buffer at 0x2E792F0 > data_area 0x7BB2AB0, refcount 1, next 0x2E7E210, flags 0x200 > linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 > if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) > inputtime 00:00:00.000 (elapsed never) > outputtime 00:00:00.000 (elapsed never), oqnumber 65535 > datagramstart 0x7BB2AF6, datagramsize 82, maximum size 2196 > mac_start 0x7BB2AF6, addr_start 0x7BB2AF6, info_start 0x0 > network_start 0x7BB2B04, transport_start 0x7BB2B18, caller_pc > 0x6D1024 > > source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: 1, > TOS: 0 prot: 17, source port 58064, destination port 5355 > > Buffer information for RxQFB buffer at 0x2672BB0 > data_area 0x758C35C, refcount 1, next 0x263960C, flags 0x200 > linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 > if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) > inputtime 00:00:00.000 (elapsed never) > outputtime 00:00:00.000 (elapsed never), oqnumber 65535 > datagramstart 0x758C3A2, datagramsize 64, maximum size 2196 > mac_start 0x758C3A2, addr_start 0x758C3A2, info_start 0x0 > network_start 0x758C3B0, transport_start 0x0, caller_pc 0x6D1024 > > source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: 1, > TOS: 0 prot: 17, source port 58064, destination port 5355 > > These TTL=1 are causing the high CPU. > > > On 24 Apr 2009, at 14:26, Chris Lane wrote: > >> Richard Gallagher found that it was one of my customers sending mcast >> packets with a TTL 1. Tried adding ACL's to lower CPU but this >> didn't fix. >> We shutdown Vlan to verify and CPU came down 40% to adequate levels. >> >> I have a call into out customer notifying them to fix. >> >> Thanks to all for your input >> >> Regards >> Chris >> >> 2009/4/24 Chris Lane >> >>> Yes with a high preference. >>> >>> 2009/4/24 junior >>> >>> Hello. >>>> >>>> Does this switch have default route? >>>> >>>> Chris Lane wrote: >>>> >>>>> sh ip traffic IP statistics: >>>>> Rcvd: 37788273 total, 24253 local destination >>>>> 0 format errors, 0 checksum errors, 9771492 bad hop count >>>>> 0 unknown protocol, 27979860 not a gateway >>>>> 0 security failures, 0 bad options, 7762670 with options >>>>> Opts: 0 end, 0 nop, 0 basic security, 0 loose source route >>>>> 0 timestamp, 0 extended security, 0 record route >>>>> 0 stream ID, 0 strict source route, 7762670 alert, 0 >>>>> cipso, 0 ump >>>>> 0 other >>>>> Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble >>>>> 0 fragmented, 0 couldn't fragment >>>>> Bcast: 2884 received, 87 sent >>>>> Mcast: 2334 received, 2209 sent >>>>> Sent: 24621 generated, 8328118 forwarded >>>>> Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency >>>>> 69 no route, 0 unicast RPF, 0 forced drop >>>>> 0 options denied, 0 source IP address zero >>>>> >>>>> ICMP statistics: >>>>> Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 >>>>> unreachable >>>>> 9560 echo, 0 echo reply, 0 mask requests, 0 mask replies, 0 >>>>> quench >>>>> 0 parameter, 0 timestamp, 0 info request, 0 other >>>>> 0 irdp solicitations, 0 irdp advertisements >>>>> Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply >>>>> 0 mask requests, 0 mask replies, 0 quench, 0 timestamp >>>>> 0 info reply, 47 time exceeded, 0 parameter problem >>>>> 0 irdp solicitations, 0 irdp advertisements >>>>> >>>>> TCP statistics: >>>>> Rcvd: 7710 total, 8 checksum errors, 1 no port >>>>> Sent: 6762 total >>>>> >>>>> UDP statistics: >>>>> Rcvd: 4615 total, 0 checksum errors, 1430 no port >>>>> Sent: 2909 total, 0 forwarded broadcasts >>>>> >>>>> IP-EIGRP statistics: >>>>> Rcvd: 0 total >>>>> Sent: 0 total >>>>> >>>>> BGP statistics: >>>>> Rcvd: 162 total, 1 opens, 0 notifications, 1 updates >>>>> 160 keepalives, 0 route-refresh, 0 unrecognized >>>>> Sent: 159 total, 1 opens, 0 notifications, 0 updates >>>>> 158 keepalives, 0 route-refresh >>>>> >>>>> PIMv2 statistics: Sent/Received >>>>> Total: 0/0, 0 checksum errors, 0 format errors >>>>> Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, >>>>> Hellos: >>>>> 0/0 >>>>> Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 >>>>> Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 >>>>> State-Refresh: 0/0 >>>>> >>>>> IGMP statistics: Sent/Received >>>>> Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 >>>>> Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: >>>>> 0/0, PIM: >>>>> 0/0 >>>>> >>>>> OSPF statistics: >>>>> Rcvd: 2363 total, 0 checksum errors >>>>> 1900 hello, 12 database desc, 2 link state req >>>>> 345 link state updates, 104 link state acks >>>>> >>>>> Sent: 2231 total >>>>> 1904 hello, 11 database desc, 4 link state req >>>>> 223 link state updates, 89 link state acks >>>>> >>>>> ARP statistics: >>>>> Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other >>>>> Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse >>>>> Drop due to input queue full: 0 >>>>> >>>>> Thanks for looking. >>>>> >>>>> On Fri, Apr 24, 2009 at 7:45 AM, junior >>>> drrtuy at ya.ru>> wrote: >>>>> >>>>> Hi, >>>>> >>>>> Did You check TAC cases? >>>>> Can You post this switch current configuration with sh ip traffic >>>>> command output? >>>>> >>>>> WBR >>>>> Roman A. Nozdrin >>>>> >>>>> Chris Lane wrote: >>>>> >>>>> 1 routed interface.sh platform ip unicast failed route >>>>> Total of 0 covering fib entries >>>>> >>>>> Thanks for reply.. I checked earlier regarding sdm. >>>>> Its the same on all of my 3750's i have about 20 of them >>>>> throughout the >>>>> states, this is probably the quietest one in regards to >>>>> bandwidth and >>>>> services. >>>>> >>>>> >>>>> >>>>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow >>>> > wrote: >>>>> >>>>> how many routed interfaces do you have ( sh ip int brief >>>>> with ip >>>>> addresses ) ? >>>>> if more than 8 change the sdm template to routing >>>>> >>>>> you can use sh platform ip unicast failed route to see >>>>> if >>>>> routes are >>>>> failing to be programmed into tcam >>>>> >>>>> Brian >>>>> >>>>> >>>>> >>>>> >>>>> ------------------------------ >>>>> *From:* Chris Lane [mailto:clane1875 at gmail.com >>>>> ] >>>>> *Sent:* venerd? 24 aprile 2009 11.17 >>>>> >>>>> *To:* Brian Turnbow >>>>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net >>>>> >>>>> >>>>> >>>>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input >>>>> >>>>> sh controllers cpu-interface >>>>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos >>>>> Rxbufloc >>>>> Rxbufdrain >>>>> >>>>> ------------------------------------------------------------------------- >>>>> ASIC0 0 0 0 0 0 >>>>> 0 >>>>> ASIC1 0 0 0 0 0 >>>>> 0 >>>>> >>>>> >>>>> cpu-queue-frames retrieved dropped invalid hol- >>>>> block >>>>> stray >>>>> ----------------- ---------- ---------- ---------- >>>>> ---------- ---------- >>>>> rpc 0 0 0 0 >>>>> 0 >>>>> stp 1807 0 0 0 >>>>> 0 >>>>> ipc 0 0 0 0 >>>>> 0 >>>>> routing protocol 1516326 0 0 0 >>>>> 0 >>>>> L2 protocol 27 0 0 0 >>>>> 0 >>>>> remote console 0 0 0 0 >>>>> 0 >>>>> sw forwarding 915 0 0 0 >>>>> 0 >>>>> host 2014 0 0 0 >>>>> 0 >>>>> broadcast 1766 0 0 0 >>>>> 0 >>>>> cbt-to-spt 0 0 0 0 >>>>> 0 >>>>> igmp snooping 1518651 0 0 0 >>>>> 0 >>>>> icmp 45 0 0 0 >>>>> 0 >>>>> logging 0 0 0 0 >>>>> 0 >>>>> rpf-fail 0 0 0 0 >>>>> 0 >>>>> queue14 0 0 0 0 >>>>> 0 >>>>> cpu heartbeat 14116 0 0 0 >>>>> 0 >>>>> >>>>> ODD i have disabled IGMP SNOOPING... >>>>> >>>>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow >>>>> > wrote: >>>>> >>>>> You can use show controller cpu to help see whats >>>>> going to the cpu >>>>> Make sure you have no ip redirects and no proxy arp >>>>> on >>>>> all the interfaces. >>>>> How many routed interfaces do you have ? >>>>> The output below for "max" is for 8 routed >>>>> interfaces if >>>>> you have more you >>>>> should change to the desktop switching template. >>>>> With your roughly your values for indirectly >>>>> connected >>>>> routes and 13 ip >>>>> interfaces on a box I needed to switch the template >>>>> "sdm >>>>> prefer routing" >>>>> requies reload. >>>>> >>>>> Regards >>>>> >>>>> Brian >>>>> >>>>> >>>>> >>>>> >>>>> -----Original Message----- >>>>> From: cisco-nsp-bounces at puck.nether.net >>>>> [mailto: >>>>> cisco-nsp-bounces at puck.nether.net >>>>> ] On >>>>> Behalf Of >>>>> Chris Lane >>>>> Sent: venerd? 24 aprile 2009 1.09 >>>>> To: Peter Rathlev >>>>> Cc: cisco-nsp at puck.nether.net >>>>> >>>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input >>>>> >>>>> sh platform tcam utilization >>>>> >>>>> CAM Utilization for ASIC# 0 Max >>>>> Used >>>>> Masks/ >>>>> Values >>>>> Masks/values >>>>> >>>>> Unicast mac addresses: >>>>> 784/6272 >>>>> 37/235 >>>>> IPv4 IGMP groups + multicast routes: >>>>> 144/1152 >>>>> 6/26 >>>>> IPv4 unicast directly-connected routes: >>>>> 784/6272 >>>>> 37/235 >>>>> IPv4 unicast indirectly-connected routes: >>>>> 272/2176 >>>>> 52/326 >>>>> IPv4 policy based routing aces: 0/0 >>>>> 0/0 >>>>> IPv4 qos aces: >>>>> 528/528 >>>>> 18/18 >>>>> IPv4 security aces: >>>>> 1024/1024 >>>>> 57/57 >>>>> >>>>> Note: Allocation of TCAM entries per feature uses >>>>> a complex algorithm. The above information is meant >>>>> to provide an abstract view of the current TCAM >>>>> utilization >>>>> >>>>> Hope this helps. >>>>> >>>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev >>>>> > wrote: >>>>> >>>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane >>>>> wrote: >>>>> >>>>> This box has been in production for over a >>>>> year >>>>> and doesn't really do >>>>> to much as you can see from my orig thread it >>>>> moves about 11MB. >>>>> >>>>> This just started late last night yet we >>>>> didn't >>>>> add any new customer >>>>> nor did anybody even touch switch as the >>>>> device >>>>> is remote. >>>>> >>>>> I read in an older thread regarding same >>>>> thing >>>>> that the person >>>>> rebooted and of course it resolved issue. I >>>>> am >>>>> planning to do that >>>>> Early tomorrow am, but >>>>> i really want to know what the heck is >>>>> causing >>>>> this. >>>>> >>>>> Yes CEF is running. >>>>> >>>>> What about TCAM utilisation ("show platform tcam >>>>> utilization")? >>>>> >>>>> Regards, >>>>> Peter >>>>> >>>>> >>>>> >>>>> >>>>> -- >>>>> //CL >>>>> _______________________________________________ >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>> >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>> archive at http://puck.nether.net/pipermail/cisco- >>>>> nsp/ >>>>> >>>>> >>>>> >>>>> -- >>>>> //CL >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> >>>>> -- >>>>> //CL >>>>> >>>> >>>> >>> >>> >>> -- >>> //CL >>> >> >> >> >> -- >> //CL >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From clane1875 at gmail.com Fri Apr 24 10:07:11 2009 From: clane1875 at gmail.com (Chris Lane) Date: Fri, 24 Apr 2009 10:07:11 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> Message-ID: <2e1cd850904240707l6a4b317cub337002cccbe64b2@mail.gmail.com> nterface Vlan217 description CUSTOMER A ip address x.x.x.x.x ip access-group 178 in no ip redirects no ip unreachables no ip proxy-arp ip multicast ttl-threshold 3 shcpu CPU utilization for five seconds: 92%/51%; one minute: 92%; five minutes: 92% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 9 14412 39169 367 0.95% 0.19% 0.08% 0 ARP Input 51 155152 901076 172 2.55% 0.92% 0.93% 0 Fifo Error Detec 67 12541 522329 24 0.15% 0.07% 0.05% 0 HLFM address ret 115 622003 413812 1503 7.34% 7.52% 7.49% 0 Hulc LED Process 136 166229 17815 9330 0.63% 0.60% 0.60% 0 PI MATM Aging Pr 168 5892258 12519191 470 25.23% 23.54% 24.45% 0 IP Input 171 32572 45322 718 0.15% 0.13% 0.12% 0 Spanning Tree thanks for input 2009/4/24 Lee > > These TTL=1 are causing the high CPU. > > Just out of curiousity, would adding "ip multicast ttl-threshold 3" > and/or "no ip unreachable" on the interface reduce cpu usage? > > Lee > > > On 4/24/09, Richard Gallagher wrote: > > Input queue was full of packets like this: > > > > Buffer information for RxQ3 buffer at 0x2E792F0 > > data_area 0x7BB2AB0, refcount 1, next 0x2E7E210, flags 0x200 > > linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 > > if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) > > inputtime 00:00:00.000 (elapsed never) > > outputtime 00:00:00.000 (elapsed never), oqnumber 65535 > > datagramstart 0x7BB2AF6, datagramsize 82, maximum size 2196 > > mac_start 0x7BB2AF6, addr_start 0x7BB2AF6, info_start 0x0 > > network_start 0x7BB2B04, transport_start 0x7BB2B18, caller_pc > > 0x6D1024 > > > > source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: 1, > > TOS: 0 prot: 17, source port 58064, destination port 5355 > > > > Buffer information for RxQFB buffer at 0x2672BB0 > > data_area 0x758C35C, refcount 1, next 0x263960C, flags 0x200 > > linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 > > if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) > > inputtime 00:00:00.000 (elapsed never) > > outputtime 00:00:00.000 (elapsed never), oqnumber 65535 > > datagramstart 0x758C3A2, datagramsize 64, maximum size 2196 > > mac_start 0x758C3A2, addr_start 0x758C3A2, info_start 0x0 > > network_start 0x758C3B0, transport_start 0x0, caller_pc 0x6D1024 > > > > source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: 1, > > TOS: 0 prot: 17, source port 58064, destination port 5355 > > > > These TTL=1 are causing the high CPU. > > > > > > On 24 Apr 2009, at 14:26, Chris Lane wrote: > > > >> Richard Gallagher found that it was one of my customers sending mcast > >> packets with a TTL 1. Tried adding ACL's to lower CPU but this > >> didn't fix. > >> We shutdown Vlan to verify and CPU came down 40% to adequate levels. > >> > >> I have a call into out customer notifying them to fix. > >> > >> Thanks to all for your input > >> > >> Regards > >> Chris > >> > >> 2009/4/24 Chris Lane > >> > >>> Yes with a high preference. > >>> > >>> 2009/4/24 junior > >>> > >>> Hello. > >>>> > >>>> Does this switch have default route? > >>>> > >>>> Chris Lane wrote: > >>>> > >>>>> sh ip traffic IP statistics: > >>>>> Rcvd: 37788273 total, 24253 local destination > >>>>> 0 format errors, 0 checksum errors, 9771492 bad hop count > >>>>> 0 unknown protocol, 27979860 not a gateway > >>>>> 0 security failures, 0 bad options, 7762670 with options > >>>>> Opts: 0 end, 0 nop, 0 basic security, 0 loose source route > >>>>> 0 timestamp, 0 extended security, 0 record route > >>>>> 0 stream ID, 0 strict source route, 7762670 alert, 0 > >>>>> cipso, 0 ump > >>>>> 0 other > >>>>> Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble > >>>>> 0 fragmented, 0 couldn't fragment > >>>>> Bcast: 2884 received, 87 sent > >>>>> Mcast: 2334 received, 2209 sent > >>>>> Sent: 24621 generated, 8328118 forwarded > >>>>> Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency > >>>>> 69 no route, 0 unicast RPF, 0 forced drop > >>>>> 0 options denied, 0 source IP address zero > >>>>> > >>>>> ICMP statistics: > >>>>> Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 > >>>>> unreachable > >>>>> 9560 echo, 0 echo reply, 0 mask requests, 0 mask replies, 0 > >>>>> quench > >>>>> 0 parameter, 0 timestamp, 0 info request, 0 other > >>>>> 0 irdp solicitations, 0 irdp advertisements > >>>>> Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply > >>>>> 0 mask requests, 0 mask replies, 0 quench, 0 timestamp > >>>>> 0 info reply, 47 time exceeded, 0 parameter problem > >>>>> 0 irdp solicitations, 0 irdp advertisements > >>>>> > >>>>> TCP statistics: > >>>>> Rcvd: 7710 total, 8 checksum errors, 1 no port > >>>>> Sent: 6762 total > >>>>> > >>>>> UDP statistics: > >>>>> Rcvd: 4615 total, 0 checksum errors, 1430 no port > >>>>> Sent: 2909 total, 0 forwarded broadcasts > >>>>> > >>>>> IP-EIGRP statistics: > >>>>> Rcvd: 0 total > >>>>> Sent: 0 total > >>>>> > >>>>> BGP statistics: > >>>>> Rcvd: 162 total, 1 opens, 0 notifications, 1 updates > >>>>> 160 keepalives, 0 route-refresh, 0 unrecognized > >>>>> Sent: 159 total, 1 opens, 0 notifications, 0 updates > >>>>> 158 keepalives, 0 route-refresh > >>>>> > >>>>> PIMv2 statistics: Sent/Received > >>>>> Total: 0/0, 0 checksum errors, 0 format errors > >>>>> Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, > >>>>> Hellos: > >>>>> 0/0 > >>>>> Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 > >>>>> Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 > >>>>> State-Refresh: 0/0 > >>>>> > >>>>> IGMP statistics: Sent/Received > >>>>> Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 > >>>>> Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: > >>>>> 0/0, PIM: > >>>>> 0/0 > >>>>> > >>>>> OSPF statistics: > >>>>> Rcvd: 2363 total, 0 checksum errors > >>>>> 1900 hello, 12 database desc, 2 link state req > >>>>> 345 link state updates, 104 link state acks > >>>>> > >>>>> Sent: 2231 total > >>>>> 1904 hello, 11 database desc, 4 link state req > >>>>> 223 link state updates, 89 link state acks > >>>>> > >>>>> ARP statistics: > >>>>> Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other > >>>>> Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse > >>>>> Drop due to input queue full: 0 > >>>>> > >>>>> Thanks for looking. > >>>>> > >>>>> On Fri, Apr 24, 2009 at 7:45 AM, junior >>>>> drrtuy at ya.ru>> wrote: > >>>>> > >>>>> Hi, > >>>>> > >>>>> Did You check TAC cases? > >>>>> Can You post this switch current configuration with sh ip traffic > >>>>> command output? > >>>>> > >>>>> WBR > >>>>> Roman A. Nozdrin > >>>>> > >>>>> Chris Lane wrote: > >>>>> > >>>>> 1 routed interface.sh platform ip unicast failed route > >>>>> Total of 0 covering fib entries > >>>>> > >>>>> Thanks for reply.. I checked earlier regarding sdm. > >>>>> Its the same on all of my 3750's i have about 20 of them > >>>>> throughout the > >>>>> states, this is probably the quietest one in regards to > >>>>> bandwidth and > >>>>> services. > >>>>> > >>>>> > >>>>> > >>>>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow < > b.turnbow at twt.it > >>>>> > wrote: > >>>>> > >>>>> how many routed interfaces do you have ( sh ip int brief > >>>>> with ip > >>>>> addresses ) ? > >>>>> if more than 8 change the sdm template to routing > >>>>> > >>>>> you can use sh platform ip unicast failed route to see > >>>>> if > >>>>> routes are > >>>>> failing to be programmed into tcam > >>>>> > >>>>> Brian > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> ------------------------------ > >>>>> *From:* Chris Lane [mailto:clane1875 at gmail.com > >>>>> ] > >>>>> *Sent:* venerd? 24 aprile 2009 11.17 > >>>>> > >>>>> *To:* Brian Turnbow > >>>>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net > >>>>> > >>>>> > >>>>> > >>>>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input > >>>>> > >>>>> sh controllers cpu-interface > >>>>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos > >>>>> Rxbufloc > >>>>> Rxbufdrain > >>>>> > >>>>> > ------------------------------------------------------------------------- > >>>>> ASIC0 0 0 0 0 0 > >>>>> 0 > >>>>> ASIC1 0 0 0 0 0 > >>>>> 0 > >>>>> > >>>>> > >>>>> cpu-queue-frames retrieved dropped invalid hol- > >>>>> block > >>>>> stray > >>>>> ----------------- ---------- ---------- ---------- > >>>>> ---------- ---------- > >>>>> rpc 0 0 0 0 > >>>>> 0 > >>>>> stp 1807 0 0 0 > >>>>> 0 > >>>>> ipc 0 0 0 0 > >>>>> 0 > >>>>> routing protocol 1516326 0 0 0 > >>>>> 0 > >>>>> L2 protocol 27 0 0 0 > >>>>> 0 > >>>>> remote console 0 0 0 0 > >>>>> 0 > >>>>> sw forwarding 915 0 0 0 > >>>>> 0 > >>>>> host 2014 0 0 0 > >>>>> 0 > >>>>> broadcast 1766 0 0 0 > >>>>> 0 > >>>>> cbt-to-spt 0 0 0 0 > >>>>> 0 > >>>>> igmp snooping 1518651 0 0 0 > >>>>> 0 > >>>>> icmp 45 0 0 0 > >>>>> 0 > >>>>> logging 0 0 0 0 > >>>>> 0 > >>>>> rpf-fail 0 0 0 0 > >>>>> 0 > >>>>> queue14 0 0 0 0 > >>>>> 0 > >>>>> cpu heartbeat 14116 0 0 0 > >>>>> 0 > >>>>> > >>>>> ODD i have disabled IGMP SNOOPING... > >>>>> > >>>>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow > >>>>> > wrote: > >>>>> > >>>>> You can use show controller cpu to help see whats > >>>>> going to the cpu > >>>>> Make sure you have no ip redirects and no proxy arp > >>>>> on > >>>>> all the interfaces. > >>>>> How many routed interfaces do you have ? > >>>>> The output below for "max" is for 8 routed > >>>>> interfaces if > >>>>> you have more you > >>>>> should change to the desktop switching template. > >>>>> With your roughly your values for indirectly > >>>>> connected > >>>>> routes and 13 ip > >>>>> interfaces on a box I needed to switch the template > >>>>> "sdm > >>>>> prefer routing" > >>>>> requies reload. > >>>>> > >>>>> Regards > >>>>> > >>>>> Brian > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> -----Original Message----- > >>>>> From: cisco-nsp-bounces at puck.nether.net > >>>>> [mailto: > >>>>> cisco-nsp-bounces at puck.nether.net > >>>>> ] On > >>>>> Behalf Of > >>>>> Chris Lane > >>>>> Sent: venerd? 24 aprile 2009 1.09 > >>>>> To: Peter Rathlev > >>>>> Cc: cisco-nsp at puck.nether.net > >>>>> > >>>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input > >>>>> > >>>>> sh platform tcam utilization > >>>>> > >>>>> CAM Utilization for ASIC# 0 Max > >>>>> Used > >>>>> Masks/ > >>>>> Values > >>>>> Masks/values > >>>>> > >>>>> Unicast mac addresses: > >>>>> 784/6272 > >>>>> 37/235 > >>>>> IPv4 IGMP groups + multicast routes: > >>>>> 144/1152 > >>>>> 6/26 > >>>>> IPv4 unicast directly-connected routes: > >>>>> 784/6272 > >>>>> 37/235 > >>>>> IPv4 unicast indirectly-connected routes: > >>>>> 272/2176 > >>>>> 52/326 > >>>>> IPv4 policy based routing aces: 0/0 > >>>>> 0/0 > >>>>> IPv4 qos aces: > >>>>> 528/528 > >>>>> 18/18 > >>>>> IPv4 security aces: > >>>>> 1024/1024 > >>>>> 57/57 > >>>>> > >>>>> Note: Allocation of TCAM entries per feature uses > >>>>> a complex algorithm. The above information is meant > >>>>> to provide an abstract view of the current TCAM > >>>>> utilization > >>>>> > >>>>> Hope this helps. > >>>>> > >>>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev > >>>>> > wrote: > >>>>> > >>>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane > >>>>> wrote: > >>>>> > >>>>> This box has been in production for over a > >>>>> year > >>>>> and doesn't really do > >>>>> to much as you can see from my orig thread it > >>>>> moves about 11MB. > >>>>> > >>>>> This just started late last night yet we > >>>>> didn't > >>>>> add any new customer > >>>>> nor did anybody even touch switch as the > >>>>> device > >>>>> is remote. > >>>>> > >>>>> I read in an older thread regarding same > >>>>> thing > >>>>> that the person > >>>>> rebooted and of course it resolved issue. I > >>>>> am > >>>>> planning to do that > >>>>> Early tomorrow am, but > >>>>> i really want to know what the heck is > >>>>> causing > >>>>> this. > >>>>> > >>>>> Yes CEF is running. > >>>>> > >>>>> What about TCAM utilisation ("show platform tcam > >>>>> utilization")? > >>>>> > >>>>> Regards, > >>>>> Peter > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> -- > >>>>> //CL > >>>>> _______________________________________________ > >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net > >>>>> > >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp > >>>>> archive at http://puck.nether.net/pipermail/cisco- > >>>>> nsp/ > >>>>> > >>>>> > >>>>> > >>>>> -- > >>>>> //CL > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> -- > >>>>> //CL > >>>>> > >>>> > >>>> > >>> > >>> > >>> -- > >>> //CL > >>> > >> > >> > >> > >> -- > >> //CL > >> _______________________________________________ > >> cisco-nsp mailing list cisco-nsp at puck.nether.net > >> https://puck.nether.net/mailman/listinfo/cisco-nsp > >> archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > > _______________________________________________ > > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > -- //CL From dale.shaw+cisco-nsp at gmail.com Fri Apr 24 10:08:00 2009 From: dale.shaw+cisco-nsp at gmail.com (Dale Shaw) Date: Sat, 25 Apr 2009 00:08:00 +1000 Subject: [c-nsp] The dreaded microburst - definition and troubleshooting In-Reply-To: <20090424133136.GC1234@rtp-cse-489.cisco.com> References: <3329cbb40904232138i3c45ac87va2138a787685cc02@mail.gmail.com> <20090424133136.GC1234@rtp-cse-489.cisco.com> Message-ID: <3329cbb40904240707l1bbdb7e2gc1829ee930156dda@mail.gmail.com> Hi Rodney, Thanks for the response. On Fri, Apr 24, 2009 at 11:31 PM, Rodney Dunn wrote: > On Fri, Apr 24, 2009 at 02:38:01PM +1000, Dale Shaw wrote: >> Does anyone have any tips for troubleshooting microbursts, >> particularly in relation to the c7200 platform exhibiting "no buff" >> drops? We're going to capture some data (w/SPAN on an adjacent switch) >> but it would be nice to be able to look at the data and somehow marry >> it up with incrementing drop counters on the affected c7200 interface. > > #1 issue with this box as high speed switches have been connected to them. > > What does 'show c7200' say? The c7200 interface exhibiting the problem (Fa0/0) is configured with two dot1q subints and is doing traffic interception/redirection with WCCP (for WAAS). This means it's handling pre-optimised ingress traffic, GRE encapsulating and forwarding to the WAE back out via the same interface, then dealing with the post-optimised, GRE-encapsulated traffic again on ingress. interface FastEthernet0/0 description LAN Interface no ip address duplex full speed 100 ! interface FastEthernet0/0.80 description WAN Opt VLAN encapsulation dot1Q 80 ip address 192.168.1.3 255.255.255.0 no ip redirects no ip proxy-arp ip wccp redirect exclude in delay 1000 standby 1 ip 192.168.1.1 standby 1 priority 120 standby 1 preempt standby 1 track 1 decrement 50 ! interface FastEthernet0/0.82 description Data VLAN encapsulation dot1Q 82 native ip address 10.65.130.73 255.255.255.248 no ip redirects no ip proxy-arp ip wccp 61 redirect in ip nbar protocol-discovery ip pim sparse-mode ip tcp adjust-mss 1360 service-policy input MARKER I know it's far from ideal, but am I likely to see an improvement if I move away from the dot1q subint and provide connectivity to the WAEs via a dedicated c7200 interface? The router would still be handling the same amount of traffic, but it wouldn't all be on the same interface. I'm not familiar enough with c7200 architecture to know what impact, if any, this would have. If that doesn't work, I'm going to have to try and shift WCCP. I think we're asking these NPE-400s to do a bit too much work. Fa0/0, in this case, is nailed up at 100-full. It connects to a 10/100/1000 switchport on a WS-X6148-GE-TX line card (c6509-SUP2) but that's nailed up at 100-full too. We're running 12.4(15)T7 'show c7200' and 'sh controllers' output follows router#sh c7200 Network IO Interrupt Throttling: throttle count=0, timer count=0 active=0, configured=0 netint usec=4000, netint mask usec=200 Midplane EEPROM: Hardware revision 2.9 Board revision A0 Serial number 34188728 Part number 73-3223-12 Test history 0x0 RMA number 00-00-00 MAC Pool Size 1024 MAC Addr Base 0017.59a6.9a00 Chassis Model 0x6 EEPROM format version 1 EEPROM contents (hex): 0x00: 01 06 02 09 02 09 AD B8 49 0C 97 0C 00 17 59 A6 0x10: 9A 00 04 00 00 00 00 00 05 12 06 50 00 00 FF 00 0x20: 65 9C 2F 88 65 48 00 00 65 A3 E3 68 60 1F C8 3C 0x30: 00 00 00 00 00 00 0F A0 00 00 00 C8 00 00 01 BB C7206VXR CPU EEPROM: Hardware Revision : 2.0 Top Assy. Part Number : 800-08136-09 Part Number : 73-5308-09 Board Revision : A0 PCB Serial Number : 34613217 RMA History : 00 Fab Version : 02 Fab Part Number : 28-4086-02 Product (FRU) Number : NPE-400 Deviation Number : 0-0 EEPROM format version 4 EEPROM contents (hex): 0x00: 04 FF 40 01 F8 41 02 00 C0 46 03 20 00 1F C8 09 0x10: 82 49 14 BC 09 42 41 30 C1 8B 33 34 36 31 33 32 0x20: 31 37 00 00 00 04 00 02 02 85 1C 0F F6 02 CB 87 0x30: 4E 50 45 2D 34 30 30 80 00 00 00 00 FF FF FF FF 0x40: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0x50: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0x60: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 0x70: FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF TLB entries (43/64 used): Virt Address range Phy Address range Attributes 0x4B000000:0x4B1FFFFF 0x14B000000:0x14B1FFFFF CacheMode=2, RW, Valid 0x4B200000:0x4B3FFFFF 0x14B200000:0x14B3FFFFF CacheMode=2, RW, Valid 0x10000000:0x10001FFF 0x100000000:0x100001FFF CacheMode=2, RW, Valid 0x40000000:0x41FFFFFF 0x040000000:0x041FFFFFF CacheMode=2, RW, Valid 0x44000000:0x45FFFFFF 0x044000000:0x045FFFFFF CacheMode=2, RW, Valid 0x3C000000:0x3C7FFFFF 0x048000000:0x0487FFFFF CacheMode=2, RW, Valid 0x3C800000:0x3CFFFFFF 0x048800000:0x048FFFFFF CacheMode=2, RW, Valid 0x3D000000:0x3D7FFFFF 0x04D000000:0x04D7FFFFF CacheMode=2, RW, Valid 0x3D800000:0x3DFFFFFF 0x049000000:0x0497FFFFF CacheMode=2, RW, Invalid 0x3E000000:0x3E7FFFFF 0x04D800000:0x04DFFFFFF CacheMode=2, RW, Invalid 0x3E800000:0x3EFFFFFF 0x049800000:0x049FFFFFF CacheMode=2, RW, Invalid 0x3F000000:0x3F7FFFFF 0x04E000000:0x04E7FFFFF CacheMode=2, RW, Invalid 0x1FC00000:0x1FC7FFFF 0x01FC00000:0x01FC7FFFF CacheMode=2, RO, Valid 0x1E000000:0x1E1FFFFF 0x01E000000:0x01E1FFFFF CacheMode=2, RW, Valid 0x1E800000:0x1E9FFFFF 0x01E800000:0x01E9FFFFF CacheMode=2, RW, Valid 0x60000000:0x61FFFFFF 0x000000000:0x001FFFFFF CacheMode=3, RO, Valid 0x62000000:0x627FFFFF 0x002000000:0x0027FFFFF CacheMode=3, RO, Valid 0x62800000:0x62FFFFFF 0x002800000:0x002FFFFFF CacheMode=3, RO, Valid 0x63000000:0x631FFFFF 0x003000000:0x0031FFFFF CacheMode=3, RO, Valid 0x63200000:0x6327FFFF 0x003200000:0x00327FFFF CacheMode=3, RO, Valid 0x63280000:0x63287FFF 0x003280000:0x003287FFF CacheMode=3, RO, Valid 0x63288000:0x63289FFF 0x003288000:0x003289FFF CacheMode=3, RO, Valid 0x6328A000:0x6328BFFF 0x00328A000:0x00328BFFF CacheMode=3, RO, Valid 0x6328C000:0x6328DFFF 0x00328C000:0x00328DFFF CacheMode=3, RO, Valid 0x6328E000:0x6328FFFF 0x00328E000:0x00328FFFF CacheMode=3, RW, Valid 0x63290000:0x63297FFF 0x003290000:0x003297FFF CacheMode=3, RW, Valid 0x63298000:0x6329FFFF 0x003298000:0x00329FFFF CacheMode=3, RW, Valid 0x632A0000:0x632BFFFF 0x0032A0000:0x0032BFFFF CacheMode=3, RW, Valid 0x632C0000:0x632DFFFF 0x0032C0000:0x0032DFFFF CacheMode=3, RW, Valid 0x632E0000:0x632FFFFF 0x0032E0000:0x0032FFFFF CacheMode=3, RW, Valid 0x63300000:0x6337FFFF 0x003300000:0x00337FFFF CacheMode=3, RW, Valid 0x63380000:0x633FFFFF 0x003380000:0x0033FFFFF CacheMode=3, RW, Valid 0x63400000:0x635FFFFF 0x003400000:0x0035FFFFF CacheMode=3, RW, Valid 0x63600000:0x637FFFFF 0x003600000:0x0037FFFFF CacheMode=3, RW, Valid 0x63800000:0x63FFFFFF 0x003800000:0x003FFFFFF CacheMode=3, RW, Valid 0x64000000:0x65FFFFFF 0x004000000:0x005FFFFFF CacheMode=3, RW, Valid 0x66000000:0x67FFFFFF 0x006000000:0x007FFFFFF CacheMode=3, RW, Valid 0x68000000:0x69FFFFFF 0x008000000:0x009FFFFFF CacheMode=3, RW, Valid 0x6A000000:0x6BFFFFFF 0x00A000000:0x00BFFFFFF CacheMode=3, RW, Valid 0x6C000000:0x6DFFFFFF 0x00C000000:0x00DFFFFFF CacheMode=3, RW, Valid 0x6E000000:0x6FFFFFFF 0x00E000000:0x00FFFFFFF CacheMode=3, RW, Valid 0x0E000000:0x0FFFFFFF 0x00E000000:0x00FFFFFFF CacheMode=2, RW, Valid 0x7E000000:0x7FFFFFFF 0x00E000000:0x00FFFFFFF CacheMode=0, RW, Valid It is normal operation to have both Valid and Invalid TLB entries. System was restarted by reload at 17:48:27 AEDT Tue Nov 18 2008 7200 Software (C7200-IK9S-M), Version 12.3(17b), RELEASE SOFTWARE (fc2) Technical Support: http://www.cisco.com/techsupport Compiled Tue 07-Mar-06 06:02 by dchih Image text-base: 0x60008AF4, data-base: 0x61EC0000 Current trace buffer contents: FP: 0x6437C568, RA: 0x608090B0 FP: 0x6437C568, RA: 0x607ED1E4 FP: 0x6437C580, RA: 0x6080F178 FP: 0x6437C620, RA: 0x607543D0 FP: 0x6437C748, RA: 0x60741894 FP: 0x6437C7A8, RA: 0x607530B4 FP: 0x6437C838, RA: 0x607D156C FP: 0x6437C850, RA: 0x607D1550 0 spurious cache errors detected. System Controller Network Interrupts Wrapper is NOT installed Registered Interrupts: Level Mask Count Data Interrupt Handler router#sh controllers Interface FastEthernet0/0 (idb 0x65DB5294) Hardware is i82543 (Livengood) A2 network link is up Config is 100MB, Full Duplex loopback type is none 10/100 PHY is enabled (MII mode) i82543 (Livengood) MAC registers: CTRL =0x02F41945, STATUS=0x00000B43, CTRL_X=0x00004C30, IMS =0x00000096 RCTL =0x00428032, RDBAL =0x0E16A000, RDBAH =0x00000000, RDLEN =0x00000800 RDH =0x00000075, RDT =0x00000074, RDTR =0x00000000 TCTL =0x000400FA, TDBAL =0x0E16B000, TDBAH =0x00000000, TDLEN =0x00001000 TDH =0x0000009F, TDT =0x0000009F, TIPG =0x00600806 ETT =0x00000000, TXDMAC=0x00000001 TXCW =0x00000000, RXCW =0x0C000000, FCRTH =0x00000000, FCRTL =0x00000000 FCAH =0x00000100, FCAL =0x00C28001, FCT =0x00008808, FCTTV =0x00000000 RDFH =0x00000A69, RDFT =0x00000A69, RDFPC =0x00000000 TDFH =0x00001E26, TDFT =0x00001E26, TDFPC =0x00000000 RX is normal, enabled TX is normal, enabled Device status = full-duplex, link up Device Speed = 100Mbps PHY registers: PHY is LXT970A Register 0x00: 2100 780D 7810 0003 0000 0000 0000 Register 0x10: 0100 0000 4000 0000 38C8 PHY says Link is UP, Speed 100Mbps, Full-Duplex PCI configuration registers: bus_no=0, device_no=8 DeviceID=0x1001, VendorID=0x8086, Command=0x0156, Status=0x0220 Class=0x02/0x00/0x00, Revision=0x02, LatencyTimer=0xFC, CacheLineSize=0x10 BaseAddr0=0x48100000, BaseAddr1=0x00000000, MaxLat=0x00, MinGnt=0xFF SubsysDeviceID=0x1001, SubsysVendorID=0x8086 Cap_Ptr=0x00000000 Retry/TRDY Timeout=0x00000000 PMC=0x00220001 PMCSR=0x00000000 i82543 (Livengood) Internal Driver Information: lc_ip_turbo_fs=0x600868C0, ip_routecache=0x11(dfs=0/mdfs=0) i82543_ds=0x65DB633C, registers=0x3C100000 rx cache size=400, rx cache end=400, rx_nobuffer=0 max_mtu=1528 Software MAC address filter(hash:length/addr/mask/hits): need_af_check = 1 0x00: 0 ffff.ffff.ffff 0000.0000.0000 135 0x0D: 0 0000.0c07.ac01 0000.0000.0000 56149 0x51: 0 0017.59a6.9a08 0000.0000.0000 305314914 0x54: 0 0100.5e00.000a 0000.0000.0000 190377 0x5C: 0 0100.5e00.0002 0000.0000.0000 384371 0xC0: 0 0100.0ccc.cccc 0000.0000.0000 46805 0xC0: 1 0180.c200.0002 0000.0000.0000 0 0xC5: 0 0180.c200.0007 0000.0000.0000 0 0x00: 0 0100.5e7f.ffff 0000.007f.ffff 60189 ring sizes: RX=128, TX=256 rxring=0x7E16A000, shadow=0x65DB6B88, head=117, rx_buf_size=512 txring=0x0E16B000, shadow=0x65DB6DBC, head=159, tail=159 chip_state=2, pci_rev=2 tx_count=0, tx_limited=0 (256) rx_overrun=0, rx_seq=0, rx_no_enp=0, rx_discard=0, filtered_pak=162769521 throttled=13, enabled=13, disabled=0, bypassed=13 reset=8(init=1, check=0, restart=7, pci=0), auto_restart=14 link_reset=0, tx_carrier_loss=6, fatal_tx_err=0 isl_err=0, wait_for_last_tdt=0, rx_stuck=1 tx_stuck=0, rx_max_spin=1 rx_bad_particle=0 HW addr filter: 0x65DB75F0, ISL disabled, Promiscuous mode multicast Entry= 0: Addr=0017.59A6.9A08 Entry= 1: Addr=0000.0C07.AC01 (All other entries are empty) i82543 (Livengood) Statistics CRC error 0 Symbol error 0 Missed Packets 719 Single Collision 0 Excessive Coll 0 Multiple Coll 0 Late Coll 0 Collision 0 Defer 0 Receive Length 0 Alignment Error 0 XON RX 0 XON TX 0 XOFF RX 0 XOFF TX 0 FC RX Unsupport 0 Packet RX (64) 13563418 Packet RX (127) 18327661 Packet RX (255) 8217287 Packet RX (511) 1510002 Packet RX (1023) 1767407 Packet RX (1522) 26906138 Good Packet RX 70291913 Broadcast RX 2 Multicast RX 62049 Good Packet TX 70447613 Good Octets RX.H 9 Good Octets RX.L 1564940356 Good Octets TX.H 10 Good Octets TX.L 3694682720 RX No Buff 67464 RX Undersize 0 RX Fragment 0 RX Oversize 0 RX Octets High 9 RX Octets Low 1565724152 TX Octets High 10 TX Octets Low 3694682720 TX Packet 70447613 RX Packet 70292632 TX Broadcast 0 TX Multicast 28464 Packet TX (64) 4748294 Packet TX (127) 21231320 Packet TX (255) 12186114 Packet TX (511) 1520516 Packet TX (1023) 2137052 Packet TX (1522) 28624317 TX Underruns 0 TX No CRS 38972007 RX Error Count 0 RX DMA Underruns 0 RX Carrier Ext 0 TCP Segmentation 0 TCP Seg Failed 0 Interface FastEthernet0/1 (idb 0x65DC2CD0) Hardware is i82543 (Livengood) A2 network link is up Config is 100MB, Full Duplex loopback type is none 10/100 PHY is enabled (MII mode) i82543 (Livengood) MAC registers: CTRL =0x02F41945, STATUS=0x00000F47, CTRL_X=0x00004C20, IMS =0x00000096 RCTL =0x00428022, RDBAL =0x0E1FD000, RDBAH =0x00000000, RDLEN =0x00000800 RDH =0x00000004, RDT =0x00000003, RDTR =0x00000000 TCTL =0x000400FA, TDBAL =0x0E1FE000, TDBAH =0x00000000, TDLEN =0x00001000 TDH =0x00000029, TDT =0x00000029, TIPG =0x00600806 ETT =0x00000000, TXDMAC=0x00000001 TXCW =0x00000000, RXCW =0x0C000000, FCRTH =0x00000000, FCRTL =0x00000000 FCAH =0x00000100, FCAL =0x00C28001, FCT =0x00008808, FCTTV =0x00000000 RDFH =0x000009E4, RDFT =0x000009E4, RDFPC =0x00000000 TDFH =0x00001F4E, TDFT =0x00001F4E, TDFPC =0x00000000 RX is normal, enabled TX is normal, enabled Device status = full-duplex, link up Device Speed = 100Mbps PHY registers: PHY is LXT970A Register 0x00: 2100 780D 7810 0003 0000 0000 0000 Register 0x10: 0100 0000 4000 0000 38C8 PHY says Link is UP, Speed 100Mbps, Full-Duplex PCI configuration registers: bus_no=0, device_no=6 DeviceID=0x1001, VendorID=0x8086, Command=0x0156, Status=0x0220 Class=0x02/0x00/0x00, Revision=0x02, LatencyTimer=0xFC, CacheLineSize=0x10 BaseAddr0=0x480C0000, BaseAddr1=0x00000000, MaxLat=0x00, MinGnt=0xFF SubsysDeviceID=0x1001, SubsysVendorID=0x8086 Cap_Ptr=0x00000000 Retry/TRDY Timeout=0x00000000 PMC=0x00220001 PMCSR=0x00000000 i82543 (Livengood) Internal Driver Information: lc_ip_turbo_fs=0x60093448, ip_routecache=0x11(dfs=0/mdfs=0) i82543_ds=0x65DC3D78, registers=0x3C0C0000 rx cache size=400, rx cache end=272, rx_nobuffer=0 max_mtu=1524 Software MAC address filter(hash:length/addr/mask/hits): need_af_check = 0 0x00: 0 ffff.ffff.ffff 0000.0000.0000 0 0x5F: 0 0017.59a6.9a06 0000.0000.0000 0 0xC0: 0 0100.0ccc.cccc 0000.0000.0000 0 0xC0: 1 0180.c200.0002 0000.0000.0000 0 0xC5: 0 0180.c200.0007 0000.0000.0000 0 ring sizes: RX=128, TX=256 rxring=0x7E1FD000, shadow=0x65DC4484, head=4, rx_buf_size=512 txring=0x0E1FE000, shadow=0x65DC46B8, head=41, tail=41 chip_state=2, pci_rev=2 tx_count=0, tx_limited=0 (256) rx_overrun=0, rx_seq=0, rx_no_enp=0, rx_discard=0, filtered_pak=0 throttled=1, enabled=1, disabled=0, bypassed=1 reset=4(init=1, check=0, restart=3, pci=0), auto_restart=8 link_reset=0, tx_carrier_loss=4, fatal_tx_err=0 isl_err=0, wait_for_last_tdt=0, rx_stuck=0 tx_stuck=0, rx_max_spin=1 rx_bad_particle=0 HW addr filter: 0x65DC4EEC, ISL disabled, Promiscuous mode disabled Entry= 0: Addr=0017.59A6.9A06 (All other entries are empty) i82543 (Livengood) Statistics CRC error 0 Symbol error 0 Missed Packets 0 Single Collision 0 Excessive Coll 0 Multiple Coll 0 Late Coll 0 Collision 0 Defer 0 Receive Length 0 Alignment Error 0 XON RX 0 XON TX 0 XOFF RX 0 XOFF TX 0 FC RX Unsupport 0 Packet RX (64) 1026 Packet RX (127) 914277 Packet RX (255) 77694152 Packet RX (511) 4609759 Packet RX (1023) 3504433 Packet RX (1522) 20045246 Good Packet RX 106768893 Broadcast RX 204 Multicast RX 196430 Good Packet TX 96892247 Good Octets RX.H 10 Good Octets RX.L 2525156738 Good Octets TX.H 5 Good Octets TX.L 588858278 RX No Buff 0 RX Undersize 0 RX Fragment 0 RX Oversize 0 RX Octets High 10 RX Octets Low 2525156738 TX Octets High 5 TX Octets Low 588858278 TX Packet 96892247 RX Packet 106768893 TX Broadcast 1 TX Multicast 216009 Packet TX (64) 1179286 Packet TX (127) 6071664 Packet TX (255) 79435131 Packet TX (511) 3733686 Packet TX (1023) 1481209 Packet TX (1522) 4991271 TX Underruns 0 TX No CRS 94699765 RX Error Count 0 RX DMA Underruns 0 RX Carrier Ext 0 TCP Segmentation 0 TCP Seg Failed 0 Interface FastEthernet2/0 (idb 0x672A2638) Hardware is i82543 (Livengood) A2 network link is up Config is 100MB, Full Duplex loopback type is none 10/100 PHY is enabled (MII mode) i82543 (Livengood) MAC registers: CTRL =0x03C01945, STATUS=0x0000094F, CTRL_X=0x00004F00, IMS =0x00000096 RCTL =0x00428022, RDBAL =0x0E39D000, RDBAH =0x00000000, RDLEN =0x00000800 RDH =0x0000004F, RDT =0x0000004E, RDTR =0x00000000 TCTL =0x000400FA, TDBAL =0x0E3A1000, TDBAH =0x00000000, TDLEN =0x00001000 TDH =0x0000007D, TDT =0x0000007D, TIPG =0x00600806 ETT =0x00000000, TXDMAC=0x00000001 TXCW =0x00000000, RXCW =0x0C000000, FCRTH =0x00000000, FCRTL =0x00000000 FCAH =0x00000100, FCAL =0x00C28001, FCT =0x00008808, FCTTV =0x00000000 RDFH =0x000015D8, RDFT =0x000015D8, RDFPC =0x00000000 TDFH =0x00001E22, TDFT =0x00001E22, TDFPC =0x00000000 RX is normal, enabled TX is normal, enabled Device status = full-duplex, link up Device Speed = 100Mbps PHY registers: PHY is LXT971 Register 0x00: 2100 780D 0013 78E2 0000 0081 0004 2001 Register 0x08: 0000 ---- ---- ---- ---- ---- ---- ---- Register 0x10: 0100 4600 0000 0000 0450 ---- ---- ---- Register 0x18: ---- ---- ---- ---- ---- ---- 0000 PHY says Link is UP, Speed 100Mbps, Full-Duplex PCI configuration registers: bus_no=11, device_no=0 DeviceID=0x1001, VendorID=0x8086, Command=0x0156, Status=0x0220 Class=0x02/0x00/0x00, Revision=0x02, LatencyTimer=0xFC, CacheLineSize=0x10 BaseAddr0=0x4D000004, BaseAddr1=0x00000000, MaxLat=0x00, MinGnt=0xFF SubsysDeviceID=0x1001, SubsysVendorID=0x8086 Cap_Ptr=0x00000000 Retry/TRDY Timeout=0x00000000 PMC=0x00220001 PMCSR=0x00000000 i82543 (Livengood) Internal Driver Information: lc_ip_turbo_fs=0x60093448, ip_routecache=0x11(dfs=0/mdfs=0) i82543_ds=0x673A87D4, registers=0x3D000000 rx cache size=400, rx cache end=272, rx_nobuffer=0 max_mtu=1524 Software MAC address filter(hash:length/addr/mask/hits): need_af_check = 0 0x00: 0 ffff.ffff.ffff 0000.0000.0000 0 0x61: 0 0017.59a6.9a38 0000.0000.0000 0 0xC0: 0 0180.c200.0002 0000.0000.0000 0 0xC5: 0 0180.c200.0007 0000.0000.0000 0 ring sizes: RX=128, TX=256 rxring=0x7E39D000, shadow=0x673A7EF0, head=79, rx_buf_size=512 txring=0x0E3A1000, shadow=0x673A0168, head=125, tail=125 chip_state=2, pci_rev=2 tx_count=0, tx_limited=1 (8) rx_overrun=0, rx_seq=0, rx_no_enp=0, rx_discard=0, filtered_pak=0 throttled=1, enabled=1, disabled=0, bypassed=1 reset=4(init=1, check=0, restart=3, pci=0), auto_restart=6 link_reset=0, tx_carrier_loss=3, fatal_tx_err=0 isl_err=0, wait_for_last_tdt=0, rx_stuck=0 tx_stuck=0, rx_max_spin=1 rx_bad_particle=0 HW addr filter: 0x672F766C, ISL disabled, Promiscuous mode disabled Entry= 0: Addr=0017.59A6.9A38 (All other entries are empty) i82543 (Livengood) Statistics CRC error 0 Symbol error 0 Missed Packets 0 Single Collision 0 Excessive Coll 0 Multiple Coll 0 Late Coll 0 Collision 0 Defer 0 Receive Length 0 Alignment Error 0 XON RX 0 XON TX 0 XOFF RX 0 XOFF TX 0 FC RX Unsupport 0 Packet RX (64) 4040 Packet RX (127) 2807671 Packet RX (255) 55589026 Packet RX (511) 4866446 Packet RX (1023) 3828454 Packet RX (1522) 19751658 Good Packet RX 86847295 Broadcast RX 4040 Multicast RX 0 Good Packet TX 85432995 Good Octets RX.H 8 Good Octets RX.L 2446545550 Good Octets TX.H 4 Good Octets TX.L 1397221784 RX No Buff 100 RX Undersize 0 RX Fragment 0 RX Oversize 0 RX Octets High 8 RX Octets Low 2446545550 TX Octets High 4 TX Octets Low 1397221784 TX Packet 85432995 RX Packet 86847295 TX Broadcast 0 TX Multicast 324 Packet TX (64) 490162 Packet TX (127) 3843085 Packet TX (255) 67813988 Packet TX (511) 4766731 Packet TX (1023) 1828288 Packet TX (1522) 6690741 TX Underruns 0 TX No CRS 81360792 RX Error Count 0 RX DMA Underruns 0 RX Carrier Ext 0 TCP Segmentation 0 TCP Seg Failed 0 Interface FastEthernet2/1 (idb 0x672B2C80) Hardware is i82543 (Livengood) A2 network link is up Config is Auto Speed, Auto Duplex loopback type is none 10/100 PHY is enabled (MII mode) i82543 (Livengood) MAC registers: Cannot display registers while Controller is in shutdown state! PHY registers: PHY is UNKNOWN (0x0) Link is Unknown, Speed is Unknown, Duplex Mode is Unknown PCI configuration registers: bus_no=11, device_no=1 DeviceID=0x1001, VendorID=0x8086, Command=0x0156, Status=0x0220 Class=0x02/0x00/0x00, Revision=0x02, LatencyTimer=0xFC, CacheLineSize=0x10 BaseAddr0=0x4D020004, BaseAddr1=0x00000000, MaxLat=0x00, MinGnt=0xFF SubsysDeviceID=0x1001, SubsysVendorID=0x8086 Cap_Ptr=0x00000000 Retry/TRDY Timeout=0x00000000 PMC=0x00220001 PMCSR=0x00000000 i82543 (Livengood) Internal Driver Information: lc_ip_turbo_fs=0x600868C0, ip_routecache=0x11(dfs=0/mdfs=0) i82543_ds=0x673A6BD8, registers=0x3D020000 pool is UNKNOWN, rx_nobuffer=0 Interface not initialised properly: Try shut cmd, followed by no shut cmd on the interface max_mtu=1524 Software MAC address filter(hash:length/addr/mask/hits): need_af_check = 0 0x00: 0 ffff.ffff.ffff 0000.0000.0000 0 0x60: 0 0017.59a6.9a39 0000.0000.0000 0 0xC0: 0 0100.0ccc.cccc 0000.0000.0000 0 0xC0: 1 0180.c200.0002 0000.0000.0000 0 0xC5: 0 0180.c200.0007 0000.0000.0000 0 ring sizes: RX=128, TX=256 rxring=0x7E3A3000, shadow=0x672F5B30, head=0, rx_buf_size=512 txring=0x0E3A4000, shadow=0x672F6740, head=0, tail=0 chip_state=3, pci_rev=2 tx_count=0, tx_limited=0 (256) rx_overrun=0, rx_seq=0, rx_no_enp=0, rx_discard=0, filtered_pak=0 throttled=0, enabled=0, disabled=0, bypassed=0 reset=1(init=1, check=0, restart=0, pci=0), auto_restart=0 link_reset=0, tx_carrier_loss=0, fatal_tx_err=0 isl_err=0, wait_for_last_tdt=0, rx_stuck=0 tx_stuck=0, rx_max_spin=1 rx_bad_particle=0 HW addr filter: 0x67400E48, ISL disabled, Promiscuous mode disabled Entry= 0: Addr=0017.59A6.9A39 (All other entries are empty) i82543 (Livengood) Statistics CRC error 0 Symbol error 0 Missed Packets 0 Single Collision 0 Excessive Coll 0 Multiple Coll 0 Late Coll 0 Collision 0 Defer 0 Receive Length 0 Alignment Error 0 XON RX 0 XON TX 0 XOFF RX 0 XOFF TX 0 FC RX Unsupport 0 Packet RX (64) 0 Packet RX (127) 0 Packet RX (255) 0 Packet RX (511) 0 Packet RX (1023) 0 Packet RX (1522) 0 Good Packet RX 0 Broadcast RX 0 Multicast RX 0 Good Packet TX 0 Good Octets RX.H 0 Good Octets RX.L 0 Good Octets TX.H 0 Good Octets TX.L 0 RX No Buff 0 RX Undersize 0 RX Fragment 0 RX Oversize 0 RX Octets High 0 RX Octets Low 0 TX Octets High 0 TX Octets Low 0 TX Packet 0 RX Packet 0 TX Broadcast 0 TX Multicast 0 Packet TX (64) 0 Packet TX (127) 0 Packet TX (255) 0 Packet TX (511) 0 Packet TX (1023) 0 Packet TX (1522) 0 TX Underruns 0 TX No CRS 0 RX Error Count 0 RX DMA Underruns 0 RX Carrier Ext 0 TCP Segmentation 0 TCP Seg Failed 0 From cchurc05 at harris.com Fri Apr 24 10:29:36 2009 From: cchurc05 at harris.com (Church, Charles) Date: Fri, 24 Apr 2009 09:29:36 -0500 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904240707l6a4b317cub337002cccbe64b2@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com><2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com><49F1A655.5020505@ya.ru><2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com><49F1AAF7.2000807@ya.ru><2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com><2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> <2e1cd850904240707l6a4b317cub337002cccbe64b2@mail.gmail.com> Message-ID: Just curious. What kind of PPS was this multicast traffic? Was the fact that it was multicast the big issue, or just the TTL itself? Chuck -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Chris Lane Sent: Friday, April 24, 2009 10:07 AM To: Lee Cc: Richard Gallagher; cisco-nsp Subject: Re: [c-nsp] 3750 High Cpu IP Input nterface Vlan217 description CUSTOMER A ip address x.x.x.x.x ip access-group 178 in no ip redirects no ip unreachables no ip proxy-arp ip multicast ttl-threshold 3 shcpu CPU utilization for five seconds: 92%/51%; one minute: 92%; five minutes: 92% PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process 9 14412 39169 367 0.95% 0.19% 0.08% 0 ARP Input 51 155152 901076 172 2.55% 0.92% 0.93% 0 Fifo Error Detec 67 12541 522329 24 0.15% 0.07% 0.05% 0 HLFM address ret 115 622003 413812 1503 7.34% 7.52% 7.49% 0 Hulc LED Process 136 166229 17815 9330 0.63% 0.60% 0.60% 0 PI MATM Aging Pr 168 5892258 12519191 470 25.23% 23.54% 24.45% 0 IP Input 171 32572 45322 718 0.15% 0.13% 0.12% 0 Spanning Tree thanks for input 2009/4/24 Lee > > These TTL=1 are causing the high CPU. > > Just out of curiousity, would adding "ip multicast ttl-threshold 3" > and/or "no ip unreachable" on the interface reduce cpu usage? > > Lee > > > On 4/24/09, Richard Gallagher wrote: > > Input queue was full of packets like this: > > > > Buffer information for RxQ3 buffer at 0x2E792F0 > > data_area 0x7BB2AB0, refcount 1, next 0x2E7E210, flags 0x200 > > linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 > > if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) > > inputtime 00:00:00.000 (elapsed never) > > outputtime 00:00:00.000 (elapsed never), oqnumber 65535 > > datagramstart 0x7BB2AF6, datagramsize 82, maximum size 2196 > > mac_start 0x7BB2AF6, addr_start 0x7BB2AF6, info_start 0x0 > > network_start 0x7BB2B04, transport_start 0x7BB2B18, caller_pc > > 0x6D1024 > > > > source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: 1, > > TOS: 0 prot: 17, source port 58064, destination port 5355 > > > > Buffer information for RxQFB buffer at 0x2672BB0 > > data_area 0x758C35C, refcount 1, next 0x263960C, flags 0x200 > > linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 > > if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) > > inputtime 00:00:00.000 (elapsed never) > > outputtime 00:00:00.000 (elapsed never), oqnumber 65535 > > datagramstart 0x758C3A2, datagramsize 64, maximum size 2196 > > mac_start 0x758C3A2, addr_start 0x758C3A2, info_start 0x0 > > network_start 0x758C3B0, transport_start 0x0, caller_pc 0x6D1024 > > > > source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: 1, > > TOS: 0 prot: 17, source port 58064, destination port 5355 > > > > These TTL=1 are causing the high CPU. > > > > > > On 24 Apr 2009, at 14:26, Chris Lane wrote: > > > >> Richard Gallagher found that it was one of my customers sending mcast > >> packets with a TTL 1. Tried adding ACL's to lower CPU but this > >> didn't fix. > >> We shutdown Vlan to verify and CPU came down 40% to adequate levels. > >> > >> I have a call into out customer notifying them to fix. > >> > >> Thanks to all for your input > >> > >> Regards > >> Chris > >> > >> 2009/4/24 Chris Lane > >> > >>> Yes with a high preference. > >>> > >>> 2009/4/24 junior > >>> > >>> Hello. > >>>> > >>>> Does this switch have default route? > >>>> > >>>> Chris Lane wrote: > >>>> > >>>>> sh ip traffic IP statistics: > >>>>> Rcvd: 37788273 total, 24253 local destination > >>>>> 0 format errors, 0 checksum errors, 9771492 bad hop count > >>>>> 0 unknown protocol, 27979860 not a gateway > >>>>> 0 security failures, 0 bad options, 7762670 with options > >>>>> Opts: 0 end, 0 nop, 0 basic security, 0 loose source route > >>>>> 0 timestamp, 0 extended security, 0 record route > >>>>> 0 stream ID, 0 strict source route, 7762670 alert, 0 > >>>>> cipso, 0 ump > >>>>> 0 other > >>>>> Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble > >>>>> 0 fragmented, 0 couldn't fragment > >>>>> Bcast: 2884 received, 87 sent > >>>>> Mcast: 2334 received, 2209 sent > >>>>> Sent: 24621 generated, 8328118 forwarded > >>>>> Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency > >>>>> 69 no route, 0 unicast RPF, 0 forced drop > >>>>> 0 options denied, 0 source IP address zero > >>>>> > >>>>> ICMP statistics: > >>>>> Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 > >>>>> unreachable > >>>>> 9560 echo, 0 echo reply, 0 mask requests, 0 mask replies, 0 > >>>>> quench > >>>>> 0 parameter, 0 timestamp, 0 info request, 0 other > >>>>> 0 irdp solicitations, 0 irdp advertisements > >>>>> Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply > >>>>> 0 mask requests, 0 mask replies, 0 quench, 0 timestamp > >>>>> 0 info reply, 47 time exceeded, 0 parameter problem > >>>>> 0 irdp solicitations, 0 irdp advertisements > >>>>> > >>>>> TCP statistics: > >>>>> Rcvd: 7710 total, 8 checksum errors, 1 no port > >>>>> Sent: 6762 total > >>>>> > >>>>> UDP statistics: > >>>>> Rcvd: 4615 total, 0 checksum errors, 1430 no port > >>>>> Sent: 2909 total, 0 forwarded broadcasts > >>>>> > >>>>> IP-EIGRP statistics: > >>>>> Rcvd: 0 total > >>>>> Sent: 0 total > >>>>> > >>>>> BGP statistics: > >>>>> Rcvd: 162 total, 1 opens, 0 notifications, 1 updates > >>>>> 160 keepalives, 0 route-refresh, 0 unrecognized > >>>>> Sent: 159 total, 1 opens, 0 notifications, 0 updates > >>>>> 158 keepalives, 0 route-refresh > >>>>> > >>>>> PIMv2 statistics: Sent/Received > >>>>> Total: 0/0, 0 checksum errors, 0 format errors > >>>>> Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, > >>>>> Hellos: > >>>>> 0/0 > >>>>> Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 > >>>>> Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 > >>>>> State-Refresh: 0/0 > >>>>> > >>>>> IGMP statistics: Sent/Received > >>>>> Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 > >>>>> Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: > >>>>> 0/0, PIM: > >>>>> 0/0 > >>>>> > >>>>> OSPF statistics: > >>>>> Rcvd: 2363 total, 0 checksum errors > >>>>> 1900 hello, 12 database desc, 2 link state req > >>>>> 345 link state updates, 104 link state acks > >>>>> > >>>>> Sent: 2231 total > >>>>> 1904 hello, 11 database desc, 4 link state req > >>>>> 223 link state updates, 89 link state acks > >>>>> > >>>>> ARP statistics: > >>>>> Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other > >>>>> Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse > >>>>> Drop due to input queue full: 0 > >>>>> > >>>>> Thanks for looking. > >>>>> > >>>>> On Fri, Apr 24, 2009 at 7:45 AM, junior >>>>> drrtuy at ya.ru>> wrote: > >>>>> > >>>>> Hi, > >>>>> > >>>>> Did You check TAC cases? > >>>>> Can You post this switch current configuration with sh ip traffic > >>>>> command output? > >>>>> > >>>>> WBR > >>>>> Roman A. Nozdrin > >>>>> > >>>>> Chris Lane wrote: > >>>>> > >>>>> 1 routed interface.sh platform ip unicast failed route > >>>>> Total of 0 covering fib entries > >>>>> > >>>>> Thanks for reply.. I checked earlier regarding sdm. > >>>>> Its the same on all of my 3750's i have about 20 of them > >>>>> throughout the > >>>>> states, this is probably the quietest one in regards to > >>>>> bandwidth and > >>>>> services. > >>>>> > >>>>> > >>>>> > >>>>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow < > b.turnbow at twt.it > >>>>> > wrote: > >>>>> > >>>>> how many routed interfaces do you have ( sh ip int brief > >>>>> with ip > >>>>> addresses ) ? > >>>>> if more than 8 change the sdm template to routing > >>>>> > >>>>> you can use sh platform ip unicast failed route to see > >>>>> if > >>>>> routes are > >>>>> failing to be programmed into tcam > >>>>> > >>>>> Brian > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> ------------------------------ > >>>>> *From:* Chris Lane [mailto:clane1875 at gmail.com > >>>>> ] > >>>>> *Sent:* venerd? 24 aprile 2009 11.17 > >>>>> > >>>>> *To:* Brian Turnbow > >>>>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net > >>>>> > >>>>> > >>>>> > >>>>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input > >>>>> > >>>>> sh controllers cpu-interface > >>>>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos > >>>>> Rxbufloc > >>>>> Rxbufdrain > >>>>> > >>>>> > ------------------------------------------------------------------------- > >>>>> ASIC0 0 0 0 0 0 > >>>>> 0 > >>>>> ASIC1 0 0 0 0 0 > >>>>> 0 > >>>>> > >>>>> > >>>>> cpu-queue-frames retrieved dropped invalid hol- > >>>>> block > >>>>> stray > >>>>> ----------------- ---------- ---------- ---------- > >>>>> ---------- ---------- > >>>>> rpc 0 0 0 0 > >>>>> 0 > >>>>> stp 1807 0 0 0 > >>>>> 0 > >>>>> ipc 0 0 0 0 > >>>>> 0 > >>>>> routing protocol 1516326 0 0 0 > >>>>> 0 > >>>>> L2 protocol 27 0 0 0 > >>>>> 0 > >>>>> remote console 0 0 0 0 > >>>>> 0 > >>>>> sw forwarding 915 0 0 0 > >>>>> 0 > >>>>> host 2014 0 0 0 > >>>>> 0 > >>>>> broadcast 1766 0 0 0 > >>>>> 0 > >>>>> cbt-to-spt 0 0 0 0 > >>>>> 0 > >>>>> igmp snooping 1518651 0 0 0 > >>>>> 0 > >>>>> icmp 45 0 0 0 > >>>>> 0 > >>>>> logging 0 0 0 0 > >>>>> 0 > >>>>> rpf-fail 0 0 0 0 > >>>>> 0 > >>>>> queue14 0 0 0 0 > >>>>> 0 > >>>>> cpu heartbeat 14116 0 0 0 > >>>>> 0 > >>>>> > >>>>> ODD i have disabled IGMP SNOOPING... > >>>>> > >>>>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow > >>>>> > wrote: > >>>>> > >>>>> You can use show controller cpu to help see whats > >>>>> going to the cpu > >>>>> Make sure you have no ip redirects and no proxy arp > >>>>> on > >>>>> all the interfaces. > >>>>> How many routed interfaces do you have ? > >>>>> The output below for "max" is for 8 routed > >>>>> interfaces if > >>>>> you have more you > >>>>> should change to the desktop switching template. > >>>>> With your roughly your values for indirectly > >>>>> connected > >>>>> routes and 13 ip > >>>>> interfaces on a box I needed to switch the template > >>>>> "sdm > >>>>> prefer routing" > >>>>> requies reload. > >>>>> > >>>>> Regards > >>>>> > >>>>> Brian > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> -----Original Message----- > >>>>> From: cisco-nsp-bounces at puck.nether.net > >>>>> [mailto: > >>>>> cisco-nsp-bounces at puck.nether.net > >>>>> ] On > >>>>> Behalf Of > >>>>> Chris Lane > >>>>> Sent: venerd? 24 aprile 2009 1.09 > >>>>> To: Peter Rathlev > >>>>> Cc: cisco-nsp at puck.nether.net > >>>>> > >>>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input > >>>>> > >>>>> sh platform tcam utilization > >>>>> > >>>>> CAM Utilization for ASIC# 0 Max > >>>>> Used > >>>>> Masks/ > >>>>> Values > >>>>> Masks/values > >>>>> > >>>>> Unicast mac addresses: > >>>>> 784/6272 > >>>>> 37/235 > >>>>> IPv4 IGMP groups + multicast routes: > >>>>> 144/1152 > >>>>> 6/26 > >>>>> IPv4 unicast directly-connected routes: > >>>>> 784/6272 > >>>>> 37/235 > >>>>> IPv4 unicast indirectly-connected routes: > >>>>> 272/2176 > >>>>> 52/326 > >>>>> IPv4 policy based routing aces: 0/0 > >>>>> 0/0 > >>>>> IPv4 qos aces: > >>>>> 528/528 > >>>>> 18/18 > >>>>> IPv4 security aces: > >>>>> 1024/1024 > >>>>> 57/57 > >>>>> > >>>>> Note: Allocation of TCAM entries per feature uses > >>>>> a complex algorithm. The above information is meant > >>>>> to provide an abstract view of the current TCAM > >>>>> utilization > >>>>> > >>>>> Hope this helps. > >>>>> > >>>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev > >>>>> > wrote: > >>>>> > >>>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane > >>>>> wrote: > >>>>> > >>>>> This box has been in production for over a > >>>>> year > >>>>> and doesn't really do > >>>>> to much as you can see from my orig thread it > >>>>> moves about 11MB. > >>>>> > >>>>> This just started late last night yet we > >>>>> didn't > >>>>> add any new customer > >>>>> nor did anybody even touch switch as the > >>>>> device > >>>>> is remote. > >>>>> > >>>>> I read in an older thread regarding same > >>>>> thing > >>>>> that the person > >>>>> rebooted and of course it resolved issue. I > >>>>> am > >>>>> planning to do that > >>>>> Early tomorrow am, but > >>>>> i really want to know what the heck is > >>>>> causing > >>>>> this. > >>>>> > >>>>> Yes CEF is running. > >>>>> > >>>>> What about TCAM utilisation ("show platform tcam > >>>>> utilization")? > >>>>> > >>>>> Regards, > >>>>> Peter > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> -- > >>>>> //CL > >>>>> _______________________________________________ > >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net > >>>>> > >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp > >>>>> archive at http://puck.nether.net/pipermail/cisco- > >>>>> nsp/ > >>>>> > >>>>> > >>>>> > >>>>> -- > >>>>> //CL > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> > >>>>> -- > >>>>> //CL > >>>>> > >>>> > >>>> > >>> > >>> > >>> -- > >>> //CL > >>> > >> > >> > >> > >> -- > >> //CL > >> _______________________________________________ > >> cisco-nsp mailing list cisco-nsp at puck.nether.net > >> https://puck.nether.net/mailman/listinfo/cisco-nsp > >> archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > > _______________________________________________ > > cisco-nsp mailing list cisco-nsp at puck.nether.net > > https://puck.nether.net/mailman/listinfo/cisco-nsp > > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > -- //CL _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From md at bts.sk Fri Apr 24 10:54:16 2009 From: md at bts.sk (Marian =?utf-8?B?xI51cmtvdmnEjQ==?=) Date: Fri, 24 Apr 2009 16:54:16 +0200 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: References: <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> Message-ID: <20090424145416.GA8500@bts.sk> On Fri, Apr 24, 2009 at 10:01:08AM -0400, Lee wrote: > > These TTL=1 are causing the high CPU. Yes, those are not HW switched but punted to CPU in order to generate TTL_Exceeded ICMP message. Not sure if there's any knob to discard them silently. > Just out of curiousity, would adding "ip multicast ttl-threshold 3" Beware, this is real evil. On most switch platforms this will completely disable HW forwarding of multicast packets and punt them *all* to CPU. M. From ler762 at gmail.com Fri Apr 24 11:06:48 2009 From: ler762 at gmail.com (Lee) Date: Fri, 24 Apr 2009 11:06:48 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <2e1cd850904240707l6a4b317cub337002cccbe64b2@mail.gmail.com> References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> <2e1cd850904240707l6a4b317cub337002cccbe64b2@mail.gmail.com> Message-ID: Too bad the multicast ttl-thresold doesn't work. Does your access-list 178 block traffic to 224.0.0.252? Lee On 4/24/09, Chris Lane wrote: > nterface Vlan217 > description CUSTOMER A > ip address x.x.x.x.x > ip access-group 178 in > no ip redirects > no ip unreachables > no ip proxy-arp > ip multicast ttl-threshold 3 > > shcpu > CPU utilization for five seconds: 92%/51%; one minute: 92%; five minutes: > 92% > PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process > 9 14412 39169 367 0.95% 0.19% 0.08% 0 ARP Input > > 51 155152 901076 172 2.55% 0.92% 0.93% 0 Fifo Error > Detec > 67 12541 522329 24 0.15% 0.07% 0.05% 0 HLFM address > ret > 115 622003 413812 1503 7.34% 7.52% 7.49% 0 Hulc LED > Process > 136 166229 17815 9330 0.63% 0.60% 0.60% 0 PI MATM > Aging > Pr > 168 5892258 12519191 470 25.23% 23.54% 24.45% 0 IP Input > > 171 32572 45322 718 0.15% 0.13% 0.12% 0 Spanning > Tree > > thanks for input > 2009/4/24 Lee > >> > These TTL=1 are causing the high CPU. >> >> Just out of curiousity, would adding "ip multicast ttl-threshold 3" >> and/or "no ip unreachable" on the interface reduce cpu usage? >> >> Lee >> >> >> On 4/24/09, Richard Gallagher wrote: >> > Input queue was full of packets like this: >> > >> > Buffer information for RxQ3 buffer at 0x2E792F0 >> > data_area 0x7BB2AB0, refcount 1, next 0x2E7E210, flags 0x200 >> > linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 >> > if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) >> > inputtime 00:00:00.000 (elapsed never) >> > outputtime 00:00:00.000 (elapsed never), oqnumber 65535 >> > datagramstart 0x7BB2AF6, datagramsize 82, maximum size 2196 >> > mac_start 0x7BB2AF6, addr_start 0x7BB2AF6, info_start 0x0 >> > network_start 0x7BB2B04, transport_start 0x7BB2B18, caller_pc >> > 0x6D1024 >> > >> > source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: >> > 1, >> > TOS: 0 prot: 17, source port 58064, destination port 5355 >> > >> > Buffer information for RxQFB buffer at 0x2672BB0 >> > data_area 0x758C35C, refcount 1, next 0x263960C, flags 0x200 >> > linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 >> > if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) >> > inputtime 00:00:00.000 (elapsed never) >> > outputtime 00:00:00.000 (elapsed never), oqnumber 65535 >> > datagramstart 0x758C3A2, datagramsize 64, maximum size 2196 >> > mac_start 0x758C3A2, addr_start 0x758C3A2, info_start 0x0 >> > network_start 0x758C3B0, transport_start 0x0, caller_pc 0x6D1024 >> > >> > source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: >> > 1, >> > TOS: 0 prot: 17, source port 58064, destination port 5355 >> > >> > These TTL=1 are causing the high CPU. >> > >> > >> > On 24 Apr 2009, at 14:26, Chris Lane wrote: >> > >> >> Richard Gallagher found that it was one of my customers sending mcast >> >> packets with a TTL 1. Tried adding ACL's to lower CPU but this >> >> didn't fix. >> >> We shutdown Vlan to verify and CPU came down 40% to adequate levels. >> >> >> >> I have a call into out customer notifying them to fix. >> >> >> >> Thanks to all for your input >> >> >> >> Regards >> >> Chris >> >> >> >> 2009/4/24 Chris Lane >> >> >> >>> Yes with a high preference. >> >>> >> >>> 2009/4/24 junior >> >>> >> >>> Hello. >> >>>> >> >>>> Does this switch have default route? >> >>>> >> >>>> Chris Lane wrote: >> >>>> >> >>>>> sh ip traffic IP statistics: >> >>>>> Rcvd: 37788273 total, 24253 local destination >> >>>>> 0 format errors, 0 checksum errors, 9771492 bad hop count >> >>>>> 0 unknown protocol, 27979860 not a gateway >> >>>>> 0 security failures, 0 bad options, 7762670 with options >> >>>>> Opts: 0 end, 0 nop, 0 basic security, 0 loose source route >> >>>>> 0 timestamp, 0 extended security, 0 record route >> >>>>> 0 stream ID, 0 strict source route, 7762670 alert, 0 >> >>>>> cipso, 0 ump >> >>>>> 0 other >> >>>>> Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble >> >>>>> 0 fragmented, 0 couldn't fragment >> >>>>> Bcast: 2884 received, 87 sent >> >>>>> Mcast: 2334 received, 2209 sent >> >>>>> Sent: 24621 generated, 8328118 forwarded >> >>>>> Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency >> >>>>> 69 no route, 0 unicast RPF, 0 forced drop >> >>>>> 0 options denied, 0 source IP address zero >> >>>>> >> >>>>> ICMP statistics: >> >>>>> Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 >> >>>>> unreachable >> >>>>> 9560 echo, 0 echo reply, 0 mask requests, 0 mask replies, 0 >> >>>>> quench >> >>>>> 0 parameter, 0 timestamp, 0 info request, 0 other >> >>>>> 0 irdp solicitations, 0 irdp advertisements >> >>>>> Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply >> >>>>> 0 mask requests, 0 mask replies, 0 quench, 0 timestamp >> >>>>> 0 info reply, 47 time exceeded, 0 parameter problem >> >>>>> 0 irdp solicitations, 0 irdp advertisements >> >>>>> >> >>>>> TCP statistics: >> >>>>> Rcvd: 7710 total, 8 checksum errors, 1 no port >> >>>>> Sent: 6762 total >> >>>>> >> >>>>> UDP statistics: >> >>>>> Rcvd: 4615 total, 0 checksum errors, 1430 no port >> >>>>> Sent: 2909 total, 0 forwarded broadcasts >> >>>>> >> >>>>> IP-EIGRP statistics: >> >>>>> Rcvd: 0 total >> >>>>> Sent: 0 total >> >>>>> >> >>>>> BGP statistics: >> >>>>> Rcvd: 162 total, 1 opens, 0 notifications, 1 updates >> >>>>> 160 keepalives, 0 route-refresh, 0 unrecognized >> >>>>> Sent: 159 total, 1 opens, 0 notifications, 0 updates >> >>>>> 158 keepalives, 0 route-refresh >> >>>>> >> >>>>> PIMv2 statistics: Sent/Received >> >>>>> Total: 0/0, 0 checksum errors, 0 format errors >> >>>>> Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, >> >>>>> Hellos: >> >>>>> 0/0 >> >>>>> Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 >> >>>>> Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 >> >>>>> State-Refresh: 0/0 >> >>>>> >> >>>>> IGMP statistics: Sent/Received >> >>>>> Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 >> >>>>> Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: >> >>>>> 0/0, PIM: >> >>>>> 0/0 >> >>>>> >> >>>>> OSPF statistics: >> >>>>> Rcvd: 2363 total, 0 checksum errors >> >>>>> 1900 hello, 12 database desc, 2 link state req >> >>>>> 345 link state updates, 104 link state acks >> >>>>> >> >>>>> Sent: 2231 total >> >>>>> 1904 hello, 11 database desc, 4 link state req >> >>>>> 223 link state updates, 89 link state acks >> >>>>> >> >>>>> ARP statistics: >> >>>>> Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other >> >>>>> Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse >> >>>>> Drop due to input queue full: 0 >> >>>>> >> >>>>> Thanks for looking. >> >>>>> >> >>>>> On Fri, Apr 24, 2009 at 7:45 AM, junior > >>>>> drrtuy at ya.ru>> wrote: >> >>>>> >> >>>>> Hi, >> >>>>> >> >>>>> Did You check TAC cases? >> >>>>> Can You post this switch current configuration with sh ip traffic >> >>>>> command output? >> >>>>> >> >>>>> WBR >> >>>>> Roman A. Nozdrin >> >>>>> >> >>>>> Chris Lane wrote: >> >>>>> >> >>>>> 1 routed interface.sh platform ip unicast failed route >> >>>>> Total of 0 covering fib entries >> >>>>> >> >>>>> Thanks for reply.. I checked earlier regarding sdm. >> >>>>> Its the same on all of my 3750's i have about 20 of them >> >>>>> throughout the >> >>>>> states, this is probably the quietest one in regards to >> >>>>> bandwidth and >> >>>>> services. >> >>>>> >> >>>>> >> >>>>> >> >>>>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow < >> b.turnbow at twt.it >> >>>>> > wrote: >> >>>>> >> >>>>> how many routed interfaces do you have ( sh ip int brief >> >>>>> with ip >> >>>>> addresses ) ? >> >>>>> if more than 8 change the sdm template to routing >> >>>>> >> >>>>> you can use sh platform ip unicast failed route to see >> >>>>> if >> >>>>> routes are >> >>>>> failing to be programmed into tcam >> >>>>> >> >>>>> Brian >> >>>>> >> >>>>> >> >>>>> >> >>>>> >> >>>>> ------------------------------ >> >>>>> *From:* Chris Lane [mailto:clane1875 at gmail.com >> >>>>> ] >> >>>>> *Sent:* venerd? 24 aprile 2009 11.17 >> >>>>> >> >>>>> *To:* Brian Turnbow >> >>>>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net >> >>>>> >> >>>>> >> >>>>> >> >>>>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input >> >>>>> >> >>>>> sh controllers cpu-interface >> >>>>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos >> >>>>> Rxbufloc >> >>>>> Rxbufdrain >> >>>>> >> >>>>> >> ------------------------------------------------------------------------- >> >>>>> ASIC0 0 0 0 0 0 >> >>>>> 0 >> >>>>> ASIC1 0 0 0 0 0 >> >>>>> 0 >> >>>>> >> >>>>> >> >>>>> cpu-queue-frames retrieved dropped invalid hol- >> >>>>> block >> >>>>> stray >> >>>>> ----------------- ---------- ---------- ---------- >> >>>>> ---------- ---------- >> >>>>> rpc 0 0 0 0 >> >>>>> 0 >> >>>>> stp 1807 0 0 0 >> >>>>> 0 >> >>>>> ipc 0 0 0 0 >> >>>>> 0 >> >>>>> routing protocol 1516326 0 0 0 >> >>>>> 0 >> >>>>> L2 protocol 27 0 0 0 >> >>>>> 0 >> >>>>> remote console 0 0 0 0 >> >>>>> 0 >> >>>>> sw forwarding 915 0 0 0 >> >>>>> 0 >> >>>>> host 2014 0 0 0 >> >>>>> 0 >> >>>>> broadcast 1766 0 0 0 >> >>>>> 0 >> >>>>> cbt-to-spt 0 0 0 0 >> >>>>> 0 >> >>>>> igmp snooping 1518651 0 0 0 >> >>>>> 0 >> >>>>> icmp 45 0 0 0 >> >>>>> 0 >> >>>>> logging 0 0 0 0 >> >>>>> 0 >> >>>>> rpf-fail 0 0 0 0 >> >>>>> 0 >> >>>>> queue14 0 0 0 0 >> >>>>> 0 >> >>>>> cpu heartbeat 14116 0 0 0 >> >>>>> 0 >> >>>>> >> >>>>> ODD i have disabled IGMP SNOOPING... >> >>>>> >> >>>>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow >> >>>>> > wrote: >> >>>>> >> >>>>> You can use show controller cpu to help see whats >> >>>>> going to the cpu >> >>>>> Make sure you have no ip redirects and no proxy arp >> >>>>> on >> >>>>> all the interfaces. >> >>>>> How many routed interfaces do you have ? >> >>>>> The output below for "max" is for 8 routed >> >>>>> interfaces if >> >>>>> you have more you >> >>>>> should change to the desktop switching template. >> >>>>> With your roughly your values for indirectly >> >>>>> connected >> >>>>> routes and 13 ip >> >>>>> interfaces on a box I needed to switch the template >> >>>>> "sdm >> >>>>> prefer routing" >> >>>>> requies reload. >> >>>>> >> >>>>> Regards >> >>>>> >> >>>>> Brian >> >>>>> >> >>>>> >> >>>>> >> >>>>> >> >>>>> -----Original Message----- >> >>>>> From: cisco-nsp-bounces at puck.nether.net >> >>>>> [mailto: >> >>>>> cisco-nsp-bounces at puck.nether.net >> >>>>> ] On >> >>>>> Behalf Of >> >>>>> Chris Lane >> >>>>> Sent: venerd? 24 aprile 2009 1.09 >> >>>>> To: Peter Rathlev >> >>>>> Cc: cisco-nsp at puck.nether.net >> >>>>> >> >>>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input >> >>>>> >> >>>>> sh platform tcam utilization >> >>>>> >> >>>>> CAM Utilization for ASIC# 0 Max >> >>>>> Used >> >>>>> Masks/ >> >>>>> Values >> >>>>> Masks/values >> >>>>> >> >>>>> Unicast mac addresses: >> >>>>> 784/6272 >> >>>>> 37/235 >> >>>>> IPv4 IGMP groups + multicast routes: >> >>>>> 144/1152 >> >>>>> 6/26 >> >>>>> IPv4 unicast directly-connected routes: >> >>>>> 784/6272 >> >>>>> 37/235 >> >>>>> IPv4 unicast indirectly-connected routes: >> >>>>> 272/2176 >> >>>>> 52/326 >> >>>>> IPv4 policy based routing aces: 0/0 >> >>>>> 0/0 >> >>>>> IPv4 qos aces: >> >>>>> 528/528 >> >>>>> 18/18 >> >>>>> IPv4 security aces: >> >>>>> 1024/1024 >> >>>>> 57/57 >> >>>>> >> >>>>> Note: Allocation of TCAM entries per feature uses >> >>>>> a complex algorithm. The above information is meant >> >>>>> to provide an abstract view of the current TCAM >> >>>>> utilization >> >>>>> >> >>>>> Hope this helps. >> >>>>> >> >>>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev >> >>>>> > wrote: >> >>>>> >> >>>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane >> >>>>> wrote: >> >>>>> >> >>>>> This box has been in production for over a >> >>>>> year >> >>>>> and doesn't really do >> >>>>> to much as you can see from my orig thread it >> >>>>> moves about 11MB. >> >>>>> >> >>>>> This just started late last night yet we >> >>>>> didn't >> >>>>> add any new customer >> >>>>> nor did anybody even touch switch as the >> >>>>> device >> >>>>> is remote. >> >>>>> >> >>>>> I read in an older thread regarding same >> >>>>> thing >> >>>>> that the person >> >>>>> rebooted and of course it resolved issue. I >> >>>>> am >> >>>>> planning to do that >> >>>>> Early tomorrow am, but >> >>>>> i really want to know what the heck is >> >>>>> causing >> >>>>> this. >> >>>>> >> >>>>> Yes CEF is running. >> >>>>> >> >>>>> What about TCAM utilisation ("show platform tcam >> >>>>> utilization")? >> >>>>> >> >>>>> Regards, >> >>>>> Peter >> >>>>> >> >>>>> >> >>>>> >> >>>>> >> >>>>> -- >> >>>>> //CL >> >>>>> _______________________________________________ >> >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >> >>>>> >> >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >> >>>>> archive at http://puck.nether.net/pipermail/cisco- >> >>>>> nsp/ >> >>>>> >> >>>>> >> >>>>> >> >>>>> -- >> >>>>> //CL >> >>>>> >> >>>>> >> >>>>> >> >>>>> >> >>>>> >> >>>>> >> >>>>> >> >>>>> >> >>>>> -- >> >>>>> //CL >> >>>>> >> >>>> >> >>>> >> >>> >> >>> >> >>> -- >> >>> //CL >> >>> >> >> >> >> >> >> >> >> -- >> >> //CL >> >> _______________________________________________ >> >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > >> > _______________________________________________ >> > cisco-nsp mailing list cisco-nsp at puck.nether.net >> > https://puck.nether.net/mailman/listinfo/cisco-nsp >> > archive at http://puck.nether.net/pipermail/cisco-nsp/ >> > >> > > > > -- > //CL > From ler762 at gmail.com Fri Apr 24 11:09:31 2009 From: ler762 at gmail.com (Lee) Date: Fri, 24 Apr 2009 11:09:31 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <20090424145416.GA8500@bts.sk> References: <2e1cd850904240217u367f87ck55a7a71c843be2c5@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> <20090424145416.GA8500@bts.sk> Message-ID: On 4/24/09, Marian ?urkovi? wrote: > On Fri, Apr 24, 2009 at 10:01:08AM -0400, Lee wrote: >> > These TTL=1 are causing the high CPU. > > Yes, those are not HW switched but punted to CPU in order to generate > TTL_Exceeded ICMP message. Not sure if there's any knob to discard > them silently. I thought that's what "no ip unreachable" was for.. >> Just out of curiousity, would adding "ip multicast ttl-threshold 3" > > Beware, this is real evil. On most switch platforms this will completely > disable HW forwarding of multicast packets and punt them *all* to CPU. oops... shows how much I know Thanks, Lee From vijay.ramcharan at verizonbusiness.com Fri Apr 24 11:29:13 2009 From: vijay.ramcharan at verizonbusiness.com (Ramcharan, Vijay A) Date: Fri, 24 Apr 2009 15:29:13 +0000 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: Message-ID: <8171C8272CE8FE4A8F5BFF8A97CE6AB3841539@ASHEVS006.mcilink.com> Last I checked "no ip unreachables" breaks PMTUD which can be fine in your environment or cause other serious problems. Vijay Ramcharan -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Lee Sent: April 24, 2009 11:10 To: Marian ?urkovi? Cc: Chris Lane; Richard Gallagher; cisco-nsp Subject: Re: [c-nsp] 3750 High Cpu IP Input On 4/24/09, Marian ?urkovi? wrote: > On Fri, Apr 24, 2009 at 10:01:08AM -0400, Lee wrote: >> > These TTL=1 are causing the high CPU. > > Yes, those are not HW switched but punted to CPU in order to generate > TTL_Exceeded ICMP message. Not sure if there's any knob to discard > them silently. I thought that's what "no ip unreachable" was for.. >> Just out of curiousity, would adding "ip multicast ttl-threshold 3" > > Beware, this is real evil. On most switch platforms this will completely > disable HW forwarding of multicast packets and punt them *all* to CPU. oops... shows how much I know Thanks, Lee _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ ______________________________________________________________________ This e-mail has been scanned by Verizon Managed Email Content Service, using Skeptic? technology powered by MessageLabs. For more information on Verizon Managed Email Content Service, visit http://www.verizonbusiness.com. ______________________________________________________________________ From chris at chrisserafin.com Fri Apr 24 11:45:09 2009 From: chris at chrisserafin.com (ChrisSerafin) Date: Fri, 24 Apr 2009 10:45:09 -0500 Subject: [c-nsp] 3750 Stack Weird 'Failure' Message-ID: <49F1DE85.6090603@chrisserafin.com> I have a stack of 3750's with 4 members, and after an IOS upgarde to 12.2(50), the stack rebooted and one of the members just keeps rebooting, and the logs show the member keeps joining and then getting removed from the stack. I would say this is related to the new IOS, but the reason for the IOS upgrade was that it was running a super old version of code, and the statck 'was unstable' per the client. So an IOS upgarde was the first thing I wanted to try... So I reboot the stack from the master switch, leave the 'bad' switch unplugged for 30 seconds and then plug it in, so that it waits for the 'bad' member to boot during the master switch stack election process, and then all of the switches come up fine......weird. Anyone heard of this? Crash dump file was found but it was from the old version of IOS. Thanks From ler762 at gmail.com Fri Apr 24 11:51:42 2009 From: ler762 at gmail.com (Lee) Date: Fri, 24 Apr 2009 11:51:42 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: <8171C8272CE8FE4A8F5BFF8A97CE6AB3841539@ASHEVS006.mcilink.com> References: <8171C8272CE8FE4A8F5BFF8A97CE6AB3841539@ASHEVS006.mcilink.com> Message-ID: On 4/24/09, Ramcharan, Vijay A wrote: > Last I checked "no ip unreachables" breaks PMTUD which can be fine in your > environment or cause other serious problems. Earlier Q&A in the thread: > how many routed interfaces do you have ( sh ip int brief with ip addresses ) ? > > 1 routed interface. Is "no ip unreachables" going to break PMTUD on that box? Lee > > Vijay Ramcharan > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Lee > Sent: April 24, 2009 11:10 > To: Marian ?urkovi? > Cc: Chris Lane; Richard Gallagher; cisco-nsp > Subject: Re: [c-nsp] 3750 High Cpu IP Input > > On 4/24/09, Marian ?urkovi? wrote: >> On Fri, Apr 24, 2009 at 10:01:08AM -0400, Lee wrote: >>> > These TTL=1 are causing the high CPU. >> >> Yes, those are not HW switched but punted to CPU in order to generate >> TTL_Exceeded ICMP message. Not sure if there's any knob to discard >> them silently. > > I thought that's what "no ip unreachable" was for.. > > >>> Just out of curiousity, would adding "ip multicast ttl-threshold 3" >> >> Beware, this is real evil. On most switch platforms this will completely >> disable HW forwarding of multicast packets and punt them *all* to CPU. > > oops... shows how much I know > > Thanks, > Lee > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > ______________________________________________________________________ > This e-mail has been scanned by Verizon Managed Email Content Service, using > Skeptic technology powered by MessageLabs. For more information on Verizon > Managed Email Content Service, visit http://www.verizonbusiness.com. > ______________________________________________________________________ > From jlewis at lewis.org Fri Apr 24 12:14:47 2009 From: jlewis at lewis.org (Jon Lewis) Date: Fri, 24 Apr 2009 12:14:47 -0400 (EDT) Subject: [c-nsp] 6500 SXD7b VRRP issue Message-ID: I just searched bug toolkit and didn't see anything similar, but has anyone else had issues with VRRP "freaking out" with 6500s running s72033-pk9sv-mz.122-18.SXD7b.bin? Last night, we lost connectivity to one of our BGP providers. 10 seconds after the %BGP-5-ADJCHANGE: neighbor x.x.x.x Down BGP Notification sent %BGP-3-NOTIFICATION: sent to neighbor x.x.x.x 4/0 (hold time expired) 0 bytes all the interfaces on this router running VRRP started having their states change from backup to master to backup every few seconds. After about 40 seconds of this, it settled down and all the VRRP states went back to their original state. While this was going on, the other 6500 participating in the VRRPs (which was the master) logged nothing and thought it was the master the whole time. None of the VRRPs are tracking anything, so I don't see why a BGP peer going down should cause any VRRP state changes. I've seen VRRP do this before (not caused by a BGP peer state change) and have never tracked down the cause. I'm probably going to upgrade to SXI in the very near future and hope that fixes whatever the problem is. ---------------------------------------------------------------------- Jon Lewis | I route Senior Network Engineer | therefore you are Atlantic Net | _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________ From achatz at forthnet.gr Fri Apr 24 12:23:47 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Fri, 24 Apr 2009 19:23:47 +0300 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> <2e1cd850904240707l6a4b317cub337002cccbe64b2@mail.gmail.com> Message-ID: <49F1E793.6010109@forthnet.gr> Maybe "ip multicast boundary" can help you. http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swmcast.html#wp1033764 -- Tassos Lee wrote on 24/04/2009 18:06: > Too bad the multicast ttl-thresold doesn't work. Does your > access-list 178 block traffic to 224.0.0.252? > > Lee > > > On 4/24/09, Chris Lane wrote: >> nterface Vlan217 >> description CUSTOMER A >> ip address x.x.x.x.x >> ip access-group 178 in >> no ip redirects >> no ip unreachables >> no ip proxy-arp >> ip multicast ttl-threshold 3 >> >> shcpu >> CPU utilization for five seconds: 92%/51%; one minute: 92%; five minutes: >> 92% >> PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process >> 9 14412 39169 367 0.95% 0.19% 0.08% 0 ARP Input >> >> 51 155152 901076 172 2.55% 0.92% 0.93% 0 Fifo Error >> Detec >> 67 12541 522329 24 0.15% 0.07% 0.05% 0 HLFM address >> ret >> 115 622003 413812 1503 7.34% 7.52% 7.49% 0 Hulc LED >> Process >> 136 166229 17815 9330 0.63% 0.60% 0.60% 0 PI MATM >> Aging >> Pr >> 168 5892258 12519191 470 25.23% 23.54% 24.45% 0 IP Input >> >> 171 32572 45322 718 0.15% 0.13% 0.12% 0 Spanning >> Tree >> >> thanks for input >> 2009/4/24 Lee >> >>>> These TTL=1 are causing the high CPU. >>> Just out of curiousity, would adding "ip multicast ttl-threshold 3" >>> and/or "no ip unreachable" on the interface reduce cpu usage? >>> >>> Lee >>> >>> >>> On 4/24/09, Richard Gallagher wrote: >>>> Input queue was full of packets like this: >>>> >>>> Buffer information for RxQ3 buffer at 0x2E792F0 >>>> data_area 0x7BB2AB0, refcount 1, next 0x2E7E210, flags 0x200 >>>> linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 >>>> if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) >>>> inputtime 00:00:00.000 (elapsed never) >>>> outputtime 00:00:00.000 (elapsed never), oqnumber 65535 >>>> datagramstart 0x7BB2AF6, datagramsize 82, maximum size 2196 >>>> mac_start 0x7BB2AF6, addr_start 0x7BB2AF6, info_start 0x0 >>>> network_start 0x7BB2B04, transport_start 0x7BB2B18, caller_pc >>>> 0x6D1024 >>>> >>>> source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: >>>> 1, >>>> TOS: 0 prot: 17, source port 58064, destination port 5355 >>>> >>>> Buffer information for RxQFB buffer at 0x2672BB0 >>>> data_area 0x758C35C, refcount 1, next 0x263960C, flags 0x200 >>>> linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 >>>> if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) >>>> inputtime 00:00:00.000 (elapsed never) >>>> outputtime 00:00:00.000 (elapsed never), oqnumber 65535 >>>> datagramstart 0x758C3A2, datagramsize 64, maximum size 2196 >>>> mac_start 0x758C3A2, addr_start 0x758C3A2, info_start 0x0 >>>> network_start 0x758C3B0, transport_start 0x0, caller_pc 0x6D1024 >>>> >>>> source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, ttl: >>>> 1, >>>> TOS: 0 prot: 17, source port 58064, destination port 5355 >>>> >>>> These TTL=1 are causing the high CPU. >>>> >>>> >>>> On 24 Apr 2009, at 14:26, Chris Lane wrote: >>>> >>>>> Richard Gallagher found that it was one of my customers sending mcast >>>>> packets with a TTL 1. Tried adding ACL's to lower CPU but this >>>>> didn't fix. >>>>> We shutdown Vlan to verify and CPU came down 40% to adequate levels. >>>>> >>>>> I have a call into out customer notifying them to fix. >>>>> >>>>> Thanks to all for your input >>>>> >>>>> Regards >>>>> Chris >>>>> >>>>> 2009/4/24 Chris Lane >>>>> >>>>>> Yes with a high preference. >>>>>> >>>>>> 2009/4/24 junior >>>>>> >>>>>> Hello. >>>>>>> Does this switch have default route? >>>>>>> >>>>>>> Chris Lane wrote: >>>>>>> >>>>>>>> sh ip traffic IP statistics: >>>>>>>> Rcvd: 37788273 total, 24253 local destination >>>>>>>> 0 format errors, 0 checksum errors, 9771492 bad hop count >>>>>>>> 0 unknown protocol, 27979860 not a gateway >>>>>>>> 0 security failures, 0 bad options, 7762670 with options >>>>>>>> Opts: 0 end, 0 nop, 0 basic security, 0 loose source route >>>>>>>> 0 timestamp, 0 extended security, 0 record route >>>>>>>> 0 stream ID, 0 strict source route, 7762670 alert, 0 >>>>>>>> cipso, 0 ump >>>>>>>> 0 other >>>>>>>> Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble >>>>>>>> 0 fragmented, 0 couldn't fragment >>>>>>>> Bcast: 2884 received, 87 sent >>>>>>>> Mcast: 2334 received, 2209 sent >>>>>>>> Sent: 24621 generated, 8328118 forwarded >>>>>>>> Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency >>>>>>>> 69 no route, 0 unicast RPF, 0 forced drop >>>>>>>> 0 options denied, 0 source IP address zero >>>>>>>> >>>>>>>> ICMP statistics: >>>>>>>> Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 >>>>>>>> unreachable >>>>>>>> 9560 echo, 0 echo reply, 0 mask requests, 0 mask replies, 0 >>>>>>>> quench >>>>>>>> 0 parameter, 0 timestamp, 0 info request, 0 other >>>>>>>> 0 irdp solicitations, 0 irdp advertisements >>>>>>>> Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply >>>>>>>> 0 mask requests, 0 mask replies, 0 quench, 0 timestamp >>>>>>>> 0 info reply, 47 time exceeded, 0 parameter problem >>>>>>>> 0 irdp solicitations, 0 irdp advertisements >>>>>>>> >>>>>>>> TCP statistics: >>>>>>>> Rcvd: 7710 total, 8 checksum errors, 1 no port >>>>>>>> Sent: 6762 total >>>>>>>> >>>>>>>> UDP statistics: >>>>>>>> Rcvd: 4615 total, 0 checksum errors, 1430 no port >>>>>>>> Sent: 2909 total, 0 forwarded broadcasts >>>>>>>> >>>>>>>> IP-EIGRP statistics: >>>>>>>> Rcvd: 0 total >>>>>>>> Sent: 0 total >>>>>>>> >>>>>>>> BGP statistics: >>>>>>>> Rcvd: 162 total, 1 opens, 0 notifications, 1 updates >>>>>>>> 160 keepalives, 0 route-refresh, 0 unrecognized >>>>>>>> Sent: 159 total, 1 opens, 0 notifications, 0 updates >>>>>>>> 158 keepalives, 0 route-refresh >>>>>>>> >>>>>>>> PIMv2 statistics: Sent/Received >>>>>>>> Total: 0/0, 0 checksum errors, 0 format errors >>>>>>>> Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, >>>>>>>> Hellos: >>>>>>>> 0/0 >>>>>>>> Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 >>>>>>>> Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 >>>>>>>> State-Refresh: 0/0 >>>>>>>> >>>>>>>> IGMP statistics: Sent/Received >>>>>>>> Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 >>>>>>>> Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: >>>>>>>> 0/0, PIM: >>>>>>>> 0/0 >>>>>>>> >>>>>>>> OSPF statistics: >>>>>>>> Rcvd: 2363 total, 0 checksum errors >>>>>>>> 1900 hello, 12 database desc, 2 link state req >>>>>>>> 345 link state updates, 104 link state acks >>>>>>>> >>>>>>>> Sent: 2231 total >>>>>>>> 1904 hello, 11 database desc, 4 link state req >>>>>>>> 223 link state updates, 89 link state acks >>>>>>>> >>>>>>>> ARP statistics: >>>>>>>> Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other >>>>>>>> Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse >>>>>>>> Drop due to input queue full: 0 >>>>>>>> >>>>>>>> Thanks for looking. >>>>>>>> >>>>>>>> On Fri, Apr 24, 2009 at 7:45 AM, junior >>>>>>> drrtuy at ya.ru>> wrote: >>>>>>>> >>>>>>>> Hi, >>>>>>>> >>>>>>>> Did You check TAC cases? >>>>>>>> Can You post this switch current configuration with sh ip traffic >>>>>>>> command output? >>>>>>>> >>>>>>>> WBR >>>>>>>> Roman A. Nozdrin >>>>>>>> >>>>>>>> Chris Lane wrote: >>>>>>>> >>>>>>>> 1 routed interface.sh platform ip unicast failed route >>>>>>>> Total of 0 covering fib entries >>>>>>>> >>>>>>>> Thanks for reply.. I checked earlier regarding sdm. >>>>>>>> Its the same on all of my 3750's i have about 20 of them >>>>>>>> throughout the >>>>>>>> states, this is probably the quietest one in regards to >>>>>>>> bandwidth and >>>>>>>> services. >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow < >>> b.turnbow at twt.it >>>>>>>> > wrote: >>>>>>>> >>>>>>>> how many routed interfaces do you have ( sh ip int brief >>>>>>>> with ip >>>>>>>> addresses ) ? >>>>>>>> if more than 8 change the sdm template to routing >>>>>>>> >>>>>>>> you can use sh platform ip unicast failed route to see >>>>>>>> if >>>>>>>> routes are >>>>>>>> failing to be programmed into tcam >>>>>>>> >>>>>>>> Brian >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> ------------------------------ >>>>>>>> *From:* Chris Lane [mailto:clane1875 at gmail.com >>>>>>>> ] >>>>>>>> *Sent:* venerde( 24 aprile 2009 11.17 >>>>>>>> >>>>>>>> *To:* Brian Turnbow >>>>>>>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input >>>>>>>> >>>>>>>> sh controllers cpu-interface >>>>>>>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos >>>>>>>> Rxbufloc >>>>>>>> Rxbufdrain >>>>>>>> >>>>>>>> >>> ------------------------------------------------------------------------- >>>>>>>> ASIC0 0 0 0 0 0 >>>>>>>> 0 >>>>>>>> ASIC1 0 0 0 0 0 >>>>>>>> 0 >>>>>>>> >>>>>>>> >>>>>>>> cpu-queue-frames retrieved dropped invalid hol- >>>>>>>> block >>>>>>>> stray >>>>>>>> ----------------- ---------- ---------- ---------- >>>>>>>> ---------- ---------- >>>>>>>> rpc 0 0 0 0 >>>>>>>> 0 >>>>>>>> stp 1807 0 0 0 >>>>>>>> 0 >>>>>>>> ipc 0 0 0 0 >>>>>>>> 0 >>>>>>>> routing protocol 1516326 0 0 0 >>>>>>>> 0 >>>>>>>> L2 protocol 27 0 0 0 >>>>>>>> 0 >>>>>>>> remote console 0 0 0 0 >>>>>>>> 0 >>>>>>>> sw forwarding 915 0 0 0 >>>>>>>> 0 >>>>>>>> host 2014 0 0 0 >>>>>>>> 0 >>>>>>>> broadcast 1766 0 0 0 >>>>>>>> 0 >>>>>>>> cbt-to-spt 0 0 0 0 >>>>>>>> 0 >>>>>>>> igmp snooping 1518651 0 0 0 >>>>>>>> 0 >>>>>>>> icmp 45 0 0 0 >>>>>>>> 0 >>>>>>>> logging 0 0 0 0 >>>>>>>> 0 >>>>>>>> rpf-fail 0 0 0 0 >>>>>>>> 0 >>>>>>>> queue14 0 0 0 0 >>>>>>>> 0 >>>>>>>> cpu heartbeat 14116 0 0 0 >>>>>>>> 0 >>>>>>>> >>>>>>>> ODD i have disabled IGMP SNOOPING... >>>>>>>> >>>>>>>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow >>>>>>>> > wrote: >>>>>>>> >>>>>>>> You can use show controller cpu to help see whats >>>>>>>> going to the cpu >>>>>>>> Make sure you have no ip redirects and no proxy arp >>>>>>>> on >>>>>>>> all the interfaces. >>>>>>>> How many routed interfaces do you have ? >>>>>>>> The output below for "max" is for 8 routed >>>>>>>> interfaces if >>>>>>>> you have more you >>>>>>>> should change to the desktop switching template. >>>>>>>> With your roughly your values for indirectly >>>>>>>> connected >>>>>>>> routes and 13 ip >>>>>>>> interfaces on a box I needed to switch the template >>>>>>>> "sdm >>>>>>>> prefer routing" >>>>>>>> requies reload. >>>>>>>> >>>>>>>> Regards >>>>>>>> >>>>>>>> Brian >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> -----Original Message----- >>>>>>>> From: cisco-nsp-bounces at puck.nether.net >>>>>>>> [mailto: >>>>>>>> cisco-nsp-bounces at puck.nether.net >>>>>>>> ] On >>>>>>>> Behalf Of >>>>>>>> Chris Lane >>>>>>>> Sent: venerde( 24 aprile 2009 1.09 >>>>>>>> To: Peter Rathlev >>>>>>>> Cc: cisco-nsp at puck.nether.net >>>>>>>> >>>>>>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input >>>>>>>> >>>>>>>> sh platform tcam utilization >>>>>>>> >>>>>>>> CAM Utilization for ASIC# 0 Max >>>>>>>> Used >>>>>>>> Masks/ >>>>>>>> Values >>>>>>>> Masks/values >>>>>>>> >>>>>>>> Unicast mac addresses: >>>>>>>> 784/6272 >>>>>>>> 37/235 >>>>>>>> IPv4 IGMP groups + multicast routes: >>>>>>>> 144/1152 >>>>>>>> 6/26 >>>>>>>> IPv4 unicast directly-connected routes: >>>>>>>> 784/6272 >>>>>>>> 37/235 >>>>>>>> IPv4 unicast indirectly-connected routes: >>>>>>>> 272/2176 >>>>>>>> 52/326 >>>>>>>> IPv4 policy based routing aces: 0/0 >>>>>>>> 0/0 >>>>>>>> IPv4 qos aces: >>>>>>>> 528/528 >>>>>>>> 18/18 >>>>>>>> IPv4 security aces: >>>>>>>> 1024/1024 >>>>>>>> 57/57 >>>>>>>> >>>>>>>> Note: Allocation of TCAM entries per feature uses >>>>>>>> a complex algorithm. The above information is meant >>>>>>>> to provide an abstract view of the current TCAM >>>>>>>> utilization >>>>>>>> >>>>>>>> Hope this helps. >>>>>>>> >>>>>>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev >>>>>>>> > wrote: >>>>>>>> >>>>>>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane >>>>>>>> wrote: >>>>>>>> >>>>>>>> This box has been in production for over a >>>>>>>> year >>>>>>>> and doesn't really do >>>>>>>> to much as you can see from my orig thread it >>>>>>>> moves about 11MB. >>>>>>>> >>>>>>>> This just started late last night yet we >>>>>>>> didn't >>>>>>>> add any new customer >>>>>>>> nor did anybody even touch switch as the >>>>>>>> device >>>>>>>> is remote. >>>>>>>> >>>>>>>> I read in an older thread regarding same >>>>>>>> thing >>>>>>>> that the person >>>>>>>> rebooted and of course it resolved issue. I >>>>>>>> am >>>>>>>> planning to do that >>>>>>>> Early tomorrow am, but >>>>>>>> i really want to know what the heck is >>>>>>>> causing >>>>>>>> this. >>>>>>>> >>>>>>>> Yes CEF is running. >>>>>>>> >>>>>>>> What about TCAM utilisation ("show platform tcam >>>>>>>> utilization")? >>>>>>>> >>>>>>>> Regards, >>>>>>>> Peter >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> -- >>>>>>>> //CL >>>>>>>> _______________________________________________ >>>>>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>>>>> >>>>>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>>>>> archive at http://puck.nether.net/pipermail/cisco- >>>>>>>> nsp/ >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> -- >>>>>>>> //CL >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> -- >>>>>>>> //CL >>>>>>>> >>>>>>> >>>>>> >>>>>> -- >>>>>> //CL >>>>>> >>>>> >>>>> >>>>> -- >>>>> //CL >>>>> _______________________________________________ >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>> _______________________________________________ >>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>> >> >> >> -- >> //CL >> > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From ler762 at gmail.com Fri Apr 24 12:26:38 2009 From: ler762 at gmail.com (Lee) Date: Fri, 24 Apr 2009 12:26:38 -0400 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> <2e1cd850904240707l6a4b317cub337002cccbe64b2@mail.gmail.com> Message-ID: Thanks for the info Lee On 4/24/09, Richard Gallagher wrote: > It does block these packets, but this does not effect the CPU, they > are still punted, nothing can be done about this. > > There is no rate-limiter either on this platform, on the 6k we have: > > - mls rate-limit all ttl-failure > > Best case is going to be stop the sources sending, not many other > options. > > Rich > > On 24 Apr 2009, at 16:06, Lee wrote: > >> Too bad the multicast ttl-thresold doesn't work. Does your >> access-list 178 block traffic to 224.0.0.252? >> >> Lee >> >> >> On 4/24/09, Chris Lane wrote: >>> nterface Vlan217 >>> description CUSTOMER A >>> ip address x.x.x.x.x >>> ip access-group 178 in >>> no ip redirects >>> no ip unreachables >>> no ip proxy-arp >>> ip multicast ttl-threshold 3 >>> >>> shcpu >>> CPU utilization for five seconds: 92%/51%; one minute: 92%; five >>> minutes: >>> 92% >>> PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process >>> 9 14412 39169 367 0.95% 0.19% 0.08% 0 ARP >>> Input >>> >>> 51 155152 901076 172 2.55% 0.92% 0.93% 0 Fifo >>> Error >>> Detec >>> 67 12541 522329 24 0.15% 0.07% 0.05% 0 HLFM >>> address >>> ret >>> 115 622003 413812 1503 7.34% 7.52% 7.49% 0 Hulc >>> LED >>> Process >>> 136 166229 17815 9330 0.63% 0.60% 0.60% 0 PI MATM >>> Aging >>> Pr >>> 168 5892258 12519191 470 25.23% 23.54% 24.45% 0 IP >>> Input >>> >>> 171 32572 45322 718 0.15% 0.13% 0.12% 0 >>> Spanning >>> Tree >>> >>> thanks for input >>> 2009/4/24 Lee >>> >>>>> These TTL=1 are causing the high CPU. >>>> >>>> Just out of curiousity, would adding "ip multicast ttl-threshold 3" >>>> and/or "no ip unreachable" on the interface reduce cpu usage? >>>> >>>> Lee >>>> >>>> >>>> On 4/24/09, Richard Gallagher wrote: >>>>> Input queue was full of packets like this: >>>>> >>>>> Buffer information for RxQ3 buffer at 0x2E792F0 >>>>> data_area 0x7BB2AB0, refcount 1, next 0x2E7E210, flags 0x200 >>>>> linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 >>>>> if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) >>>>> inputtime 00:00:00.000 (elapsed never) >>>>> outputtime 00:00:00.000 (elapsed never), oqnumber 65535 >>>>> datagramstart 0x7BB2AF6, datagramsize 82, maximum size 2196 >>>>> mac_start 0x7BB2AF6, addr_start 0x7BB2AF6, info_start 0x0 >>>>> network_start 0x7BB2B04, transport_start 0x7BB2B18, caller_pc >>>>> 0x6D1024 >>>>> >>>>> source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, >>>>> ttl: >>>>> 1, >>>>> TOS: 0 prot: 17, source port 58064, destination port 5355 >>>>> >>>>> Buffer information for RxQFB buffer at 0x2672BB0 >>>>> data_area 0x758C35C, refcount 1, next 0x263960C, flags 0x200 >>>>> linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 >>>>> if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) >>>>> inputtime 00:00:00.000 (elapsed never) >>>>> outputtime 00:00:00.000 (elapsed never), oqnumber 65535 >>>>> datagramstart 0x758C3A2, datagramsize 64, maximum size 2196 >>>>> mac_start 0x758C3A2, addr_start 0x758C3A2, info_start 0x0 >>>>> network_start 0x758C3B0, transport_start 0x0, caller_pc 0x6D1024 >>>>> >>>>> source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, >>>>> ttl: >>>>> 1, >>>>> TOS: 0 prot: 17, source port 58064, destination port 5355 >>>>> >>>>> These TTL=1 are causing the high CPU. >>>>> >>>>> >>>>> On 24 Apr 2009, at 14:26, Chris Lane wrote: >>>>> >>>>>> Richard Gallagher found that it was one of my customers sending >>>>>> mcast >>>>>> packets with a TTL 1. Tried adding ACL's to lower CPU but this >>>>>> didn't fix. >>>>>> We shutdown Vlan to verify and CPU came down 40% to adequate >>>>>> levels. >>>>>> >>>>>> I have a call into out customer notifying them to fix. >>>>>> >>>>>> Thanks to all for your input >>>>>> >>>>>> Regards >>>>>> Chris >>>>>> >>>>>> 2009/4/24 Chris Lane >>>>>> >>>>>>> Yes with a high preference. >>>>>>> >>>>>>> 2009/4/24 junior >>>>>>> >>>>>>> Hello. >>>>>>>> >>>>>>>> Does this switch have default route? >>>>>>>> >>>>>>>> Chris Lane wrote: >>>>>>>> >>>>>>>>> sh ip traffic IP statistics: >>>>>>>>> Rcvd: 37788273 total, 24253 local destination >>>>>>>>> 0 format errors, 0 checksum errors, 9771492 bad hop count >>>>>>>>> 0 unknown protocol, 27979860 not a gateway >>>>>>>>> 0 security failures, 0 bad options, 7762670 with options >>>>>>>>> Opts: 0 end, 0 nop, 0 basic security, 0 loose source route >>>>>>>>> 0 timestamp, 0 extended security, 0 record route >>>>>>>>> 0 stream ID, 0 strict source route, 7762670 alert, 0 >>>>>>>>> cipso, 0 ump >>>>>>>>> 0 other >>>>>>>>> Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble >>>>>>>>> 0 fragmented, 0 couldn't fragment >>>>>>>>> Bcast: 2884 received, 87 sent >>>>>>>>> Mcast: 2334 received, 2209 sent >>>>>>>>> Sent: 24621 generated, 8328118 forwarded >>>>>>>>> Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency >>>>>>>>> 69 no route, 0 unicast RPF, 0 forced drop >>>>>>>>> 0 options denied, 0 source IP address zero >>>>>>>>> >>>>>>>>> ICMP statistics: >>>>>>>>> Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 >>>>>>>>> unreachable >>>>>>>>> 9560 echo, 0 echo reply, 0 mask requests, 0 mask >>>>>>>>> replies, 0 >>>>>>>>> quench >>>>>>>>> 0 parameter, 0 timestamp, 0 info request, 0 other >>>>>>>>> 0 irdp solicitations, 0 irdp advertisements >>>>>>>>> Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply >>>>>>>>> 0 mask requests, 0 mask replies, 0 quench, 0 timestamp >>>>>>>>> 0 info reply, 47 time exceeded, 0 parameter problem >>>>>>>>> 0 irdp solicitations, 0 irdp advertisements >>>>>>>>> >>>>>>>>> TCP statistics: >>>>>>>>> Rcvd: 7710 total, 8 checksum errors, 1 no port >>>>>>>>> Sent: 6762 total >>>>>>>>> >>>>>>>>> UDP statistics: >>>>>>>>> Rcvd: 4615 total, 0 checksum errors, 1430 no port >>>>>>>>> Sent: 2909 total, 0 forwarded broadcasts >>>>>>>>> >>>>>>>>> IP-EIGRP statistics: >>>>>>>>> Rcvd: 0 total >>>>>>>>> Sent: 0 total >>>>>>>>> >>>>>>>>> BGP statistics: >>>>>>>>> Rcvd: 162 total, 1 opens, 0 notifications, 1 updates >>>>>>>>> 160 keepalives, 0 route-refresh, 0 unrecognized >>>>>>>>> Sent: 159 total, 1 opens, 0 notifications, 0 updates >>>>>>>>> 158 keepalives, 0 route-refresh >>>>>>>>> >>>>>>>>> PIMv2 statistics: Sent/Received >>>>>>>>> Total: 0/0, 0 checksum errors, 0 format errors >>>>>>>>> Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, >>>>>>>>> Hellos: >>>>>>>>> 0/0 >>>>>>>>> Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 >>>>>>>>> Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 >>>>>>>>> State-Refresh: 0/0 >>>>>>>>> >>>>>>>>> IGMP statistics: Sent/Received >>>>>>>>> Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 >>>>>>>>> Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: >>>>>>>>> 0/0, PIM: >>>>>>>>> 0/0 >>>>>>>>> >>>>>>>>> OSPF statistics: >>>>>>>>> Rcvd: 2363 total, 0 checksum errors >>>>>>>>> 1900 hello, 12 database desc, 2 link state req >>>>>>>>> 345 link state updates, 104 link state acks >>>>>>>>> >>>>>>>>> Sent: 2231 total >>>>>>>>> 1904 hello, 11 database desc, 4 link state req >>>>>>>>> 223 link state updates, 89 link state acks >>>>>>>>> >>>>>>>>> ARP statistics: >>>>>>>>> Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other >>>>>>>>> Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse >>>>>>>>> Drop due to input queue full: 0 >>>>>>>>> >>>>>>>>> Thanks for looking. >>>>>>>>> >>>>>>>>> On Fri, Apr 24, 2009 at 7:45 AM, junior >>>>>>>> drrtuy at ya.ru>> wrote: >>>>>>>>> >>>>>>>>> Hi, >>>>>>>>> >>>>>>>>> Did You check TAC cases? >>>>>>>>> Can You post this switch current configuration with sh ip >>>>>>>>> traffic >>>>>>>>> command output? >>>>>>>>> >>>>>>>>> WBR >>>>>>>>> Roman A. Nozdrin >>>>>>>>> >>>>>>>>> Chris Lane wrote: >>>>>>>>> >>>>>>>>> 1 routed interface.sh platform ip unicast failed route >>>>>>>>> Total of 0 covering fib entries >>>>>>>>> >>>>>>>>> Thanks for reply.. I checked earlier regarding sdm. >>>>>>>>> Its the same on all of my 3750's i have about 20 of them >>>>>>>>> throughout the >>>>>>>>> states, this is probably the quietest one in regards to >>>>>>>>> bandwidth and >>>>>>>>> services. >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow < >>>> b.turnbow at twt.it >>>>>>>>> > wrote: >>>>>>>>> >>>>>>>>> how many routed interfaces do you have ( sh ip int >>>>>>>>> brief >>>>>>>>> with ip >>>>>>>>> addresses ) ? >>>>>>>>> if more than 8 change the sdm template to routing >>>>>>>>> >>>>>>>>> you can use sh platform ip unicast failed route to >>>>>>>>> see >>>>>>>>> if >>>>>>>>> routes are >>>>>>>>> failing to be programmed into tcam >>>>>>>>> >>>>>>>>> Brian >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> ------------------------------ >>>>>>>>> *From:* Chris Lane [mailto:clane1875 at gmail.com >>>>>>>>> ] >>>>>>>>> *Sent:* venerd? 24 aprile 2009 11.17 >>>>>>>>> >>>>>>>>> *To:* Brian Turnbow >>>>>>>>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input >>>>>>>>> >>>>>>>>> sh controllers cpu-interface >>>>>>>>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos >>>>>>>>> Rxbufloc >>>>>>>>> Rxbufdrain >>>>>>>>> >>>>>>>>> >>>> ------------------------------------------------------------------------- >>>>>>>>> ASIC0 0 0 0 >>>>>>>>> 0 0 >>>>>>>>> 0 >>>>>>>>> ASIC1 0 0 0 >>>>>>>>> 0 0 >>>>>>>>> 0 >>>>>>>>> >>>>>>>>> >>>>>>>>> cpu-queue-frames retrieved dropped invalid >>>>>>>>> hol- >>>>>>>>> block >>>>>>>>> stray >>>>>>>>> ----------------- ---------- ---------- ---------- >>>>>>>>> ---------- ---------- >>>>>>>>> rpc 0 0 0 0 >>>>>>>>> 0 >>>>>>>>> stp 1807 0 0 0 >>>>>>>>> 0 >>>>>>>>> ipc 0 0 0 0 >>>>>>>>> 0 >>>>>>>>> routing protocol 1516326 0 0 0 >>>>>>>>> 0 >>>>>>>>> L2 protocol 27 0 0 0 >>>>>>>>> 0 >>>>>>>>> remote console 0 0 0 0 >>>>>>>>> 0 >>>>>>>>> sw forwarding 915 0 0 0 >>>>>>>>> 0 >>>>>>>>> host 2014 0 0 0 >>>>>>>>> 0 >>>>>>>>> broadcast 1766 0 0 0 >>>>>>>>> 0 >>>>>>>>> cbt-to-spt 0 0 0 0 >>>>>>>>> 0 >>>>>>>>> igmp snooping 1518651 0 0 0 >>>>>>>>> 0 >>>>>>>>> icmp 45 0 0 0 >>>>>>>>> 0 >>>>>>>>> logging 0 0 0 0 >>>>>>>>> 0 >>>>>>>>> rpf-fail 0 0 0 0 >>>>>>>>> 0 >>>>>>>>> queue14 0 0 0 0 >>>>>>>>> 0 >>>>>>>>> cpu heartbeat 14116 0 0 0 >>>>>>>>> 0 >>>>>>>>> >>>>>>>>> ODD i have disabled IGMP SNOOPING... >>>>>>>>> >>>>>>>>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow >>>>>>>>> > wrote: >>>>>>>>> >>>>>>>>> You can use show controller cpu to help see >>>>>>>>> whats >>>>>>>>> going to the cpu >>>>>>>>> Make sure you have no ip redirects and no proxy >>>>>>>>> arp >>>>>>>>> on >>>>>>>>> all the interfaces. >>>>>>>>> How many routed interfaces do you have ? >>>>>>>>> The output below for "max" is for 8 routed >>>>>>>>> interfaces if >>>>>>>>> you have more you >>>>>>>>> should change to the desktop switching template. >>>>>>>>> With your roughly your values for indirectly >>>>>>>>> connected >>>>>>>>> routes and 13 ip >>>>>>>>> interfaces on a box I needed to switch the >>>>>>>>> template >>>>>>>>> "sdm >>>>>>>>> prefer routing" >>>>>>>>> requies reload. >>>>>>>>> >>>>>>>>> Regards >>>>>>>>> >>>>>>>>> Brian >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> -----Original Message----- >>>>>>>>> From: cisco-nsp-bounces at puck.nether.net >>>>>>>>> >>>>>>>>> [mailto: >>>>>>>>> cisco-nsp-bounces at puck.nether.net >>>>>>>>> ] On >>>>>>>>> Behalf Of >>>>>>>>> Chris Lane >>>>>>>>> Sent: venerd? 24 aprile 2009 1.09 >>>>>>>>> To: Peter Rathlev >>>>>>>>> Cc: cisco-nsp at puck.nether.net >>>>>>>>> >>>>>>>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input >>>>>>>>> >>>>>>>>> sh platform tcam utilization >>>>>>>>> >>>>>>>>> CAM Utilization for ASIC# 0 >>>>>>>>> Max >>>>>>>>> Used >>>>>>>>> Masks/ >>>>>>>>> Values >>>>>>>>> Masks/values >>>>>>>>> >>>>>>>>> Unicast mac addresses: >>>>>>>>> 784/6272 >>>>>>>>> 37/235 >>>>>>>>> IPv4 IGMP groups + multicast routes: >>>>>>>>> 144/1152 >>>>>>>>> 6/26 >>>>>>>>> IPv4 unicast directly-connected routes: >>>>>>>>> 784/6272 >>>>>>>>> 37/235 >>>>>>>>> IPv4 unicast indirectly-connected routes: >>>>>>>>> 272/2176 >>>>>>>>> 52/326 >>>>>>>>> IPv4 policy based routing aces: >>>>>>>>> 0/0 >>>>>>>>> 0/0 >>>>>>>>> IPv4 qos aces: >>>>>>>>> 528/528 >>>>>>>>> 18/18 >>>>>>>>> IPv4 security aces: >>>>>>>>> 1024/1024 >>>>>>>>> 57/57 >>>>>>>>> >>>>>>>>> Note: Allocation of TCAM entries per feature uses >>>>>>>>> a complex algorithm. The above information is >>>>>>>>> meant >>>>>>>>> to provide an abstract view of the current TCAM >>>>>>>>> utilization >>>>>>>>> >>>>>>>>> Hope this helps. >>>>>>>>> >>>>>>>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev >>>>>>>>> > >>>>>>>>> wrote: >>>>>>>>> >>>>>>>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane >>>>>>>>> wrote: >>>>>>>>> >>>>>>>>> This box has been in production for >>>>>>>>> over a >>>>>>>>> year >>>>>>>>> and doesn't really do >>>>>>>>> to much as you can see from my orig >>>>>>>>> thread it >>>>>>>>> moves about 11MB. >>>>>>>>> >>>>>>>>> This just started late last night yet we >>>>>>>>> didn't >>>>>>>>> add any new customer >>>>>>>>> nor did anybody even touch switch as the >>>>>>>>> device >>>>>>>>> is remote. >>>>>>>>> >>>>>>>>> I read in an older thread regarding same >>>>>>>>> thing >>>>>>>>> that the person >>>>>>>>> rebooted and of course it resolved >>>>>>>>> issue. I >>>>>>>>> am >>>>>>>>> planning to do that >>>>>>>>> Early tomorrow am, but >>>>>>>>> i really want to know what the heck is >>>>>>>>> causing >>>>>>>>> this. >>>>>>>>> >>>>>>>>> Yes CEF is running. >>>>>>>>> >>>>>>>>> What about TCAM utilisation ("show platform >>>>>>>>> tcam >>>>>>>>> utilization")? >>>>>>>>> >>>>>>>>> Regards, >>>>>>>>> Peter >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> -- >>>>>>>>> //CL >>>>>>>>> _______________________________________________ >>>>>>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>>>>>> >>>>>>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>>>>>> archive at http://puck.nether.net/pipermail/cisco- >>>>>>>>> nsp/ >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> -- >>>>>>>>> //CL >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> -- >>>>>>>>> //CL >>>>>>>>> >>>>>>>> >>>>>>>> >>>>>>> >>>>>>> >>>>>>> -- >>>>>>> //CL >>>>>>> >>>>>> >>>>>> >>>>>> >>>>>> -- >>>>>> //CL >>>>>> _______________________________________________ >>>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>>> >>>>> _______________________________________________ >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>>> >>>> >>> >>> >>> >>> -- >>> //CL >>> > > From rgallagh at cisco.com Fri Apr 24 12:15:41 2009 From: rgallagh at cisco.com (Richard Gallagher) Date: Fri, 24 Apr 2009 17:15:41 +0100 Subject: [c-nsp] 3750 High Cpu IP Input In-Reply-To: References: <2e1cd850904231051l527cc07fo26c2ab0403a28f21@mail.gmail.com> <2e1cd850904240435x2b2994f1g4e0d28a2d507462d@mail.gmail.com> <49F1A655.5020505@ya.ru> <2e1cd850904240444h7a98a82l750084ee44eb39ad@mail.gmail.com> <49F1AAF7.2000807@ya.ru> <2e1cd850904240522v2879233r16f5729d3bbce7bc@mail.gmail.com> <2e1cd850904240626k397aae22k31cb8e97606fd1f3@mail.gmail.com> <2e1cd850904240707l6a4b317cub337002cccbe64b2@mail.gmail.com> Message-ID: It does block these packets, but this does not effect the CPU, they are still punted, nothing can be done about this. There is no rate-limiter either on this platform, on the 6k we have: - mls rate-limit all ttl-failure Best case is going to be stop the sources sending, not many other options. Rich On 24 Apr 2009, at 16:06, Lee wrote: > Too bad the multicast ttl-thresold doesn't work. Does your > access-list 178 block traffic to 224.0.0.252? > > Lee > > > On 4/24/09, Chris Lane wrote: >> nterface Vlan217 >> description CUSTOMER A >> ip address x.x.x.x.x >> ip access-group 178 in >> no ip redirects >> no ip unreachables >> no ip proxy-arp >> ip multicast ttl-threshold 3 >> >> shcpu >> CPU utilization for five seconds: 92%/51%; one minute: 92%; five >> minutes: >> 92% >> PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process >> 9 14412 39169 367 0.95% 0.19% 0.08% 0 ARP >> Input >> >> 51 155152 901076 172 2.55% 0.92% 0.93% 0 Fifo >> Error >> Detec >> 67 12541 522329 24 0.15% 0.07% 0.05% 0 HLFM >> address >> ret >> 115 622003 413812 1503 7.34% 7.52% 7.49% 0 Hulc >> LED >> Process >> 136 166229 17815 9330 0.63% 0.60% 0.60% 0 PI MATM >> Aging >> Pr >> 168 5892258 12519191 470 25.23% 23.54% 24.45% 0 IP >> Input >> >> 171 32572 45322 718 0.15% 0.13% 0.12% 0 >> Spanning >> Tree >> >> thanks for input >> 2009/4/24 Lee >> >>>> These TTL=1 are causing the high CPU. >>> >>> Just out of curiousity, would adding "ip multicast ttl-threshold 3" >>> and/or "no ip unreachable" on the interface reduce cpu usage? >>> >>> Lee >>> >>> >>> On 4/24/09, Richard Gallagher wrote: >>>> Input queue was full of packets like this: >>>> >>>> Buffer information for RxQ3 buffer at 0x2E792F0 >>>> data_area 0x7BB2AB0, refcount 1, next 0x2E7E210, flags 0x200 >>>> linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 >>>> if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) >>>> inputtime 00:00:00.000 (elapsed never) >>>> outputtime 00:00:00.000 (elapsed never), oqnumber 65535 >>>> datagramstart 0x7BB2AF6, datagramsize 82, maximum size 2196 >>>> mac_start 0x7BB2AF6, addr_start 0x7BB2AF6, info_start 0x0 >>>> network_start 0x7BB2B04, transport_start 0x7BB2B18, caller_pc >>>> 0x6D1024 >>>> >>>> source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, >>>> ttl: >>>> 1, >>>> TOS: 0 prot: 17, source port 58064, destination port 5355 >>>> >>>> Buffer information for RxQFB buffer at 0x2672BB0 >>>> data_area 0x758C35C, refcount 1, next 0x263960C, flags 0x200 >>>> linktype 7 (IP), enctype 1 (ARPA), encsize 14, rxtype 1 >>>> if_input 0x3ABBAE0 (Vlan217), if_output 0x0 (None) >>>> inputtime 00:00:00.000 (elapsed never) >>>> outputtime 00:00:00.000 (elapsed never), oqnumber 65535 >>>> datagramstart 0x758C3A2, datagramsize 64, maximum size 2196 >>>> mac_start 0x758C3A2, addr_start 0x758C3A2, info_start 0x0 >>>> network_start 0x758C3B0, transport_start 0x0, caller_pc 0x6D1024 >>>> >>>> source: 74.212.165.187, destination: 224.0.0.252, id: 0x3CDA, >>>> ttl: >>>> 1, >>>> TOS: 0 prot: 17, source port 58064, destination port 5355 >>>> >>>> These TTL=1 are causing the high CPU. >>>> >>>> >>>> On 24 Apr 2009, at 14:26, Chris Lane wrote: >>>> >>>>> Richard Gallagher found that it was one of my customers sending >>>>> mcast >>>>> packets with a TTL 1. Tried adding ACL's to lower CPU but this >>>>> didn't fix. >>>>> We shutdown Vlan to verify and CPU came down 40% to adequate >>>>> levels. >>>>> >>>>> I have a call into out customer notifying them to fix. >>>>> >>>>> Thanks to all for your input >>>>> >>>>> Regards >>>>> Chris >>>>> >>>>> 2009/4/24 Chris Lane >>>>> >>>>>> Yes with a high preference. >>>>>> >>>>>> 2009/4/24 junior >>>>>> >>>>>> Hello. >>>>>>> >>>>>>> Does this switch have default route? >>>>>>> >>>>>>> Chris Lane wrote: >>>>>>> >>>>>>>> sh ip traffic IP statistics: >>>>>>>> Rcvd: 37788273 total, 24253 local destination >>>>>>>> 0 format errors, 0 checksum errors, 9771492 bad hop count >>>>>>>> 0 unknown protocol, 27979860 not a gateway >>>>>>>> 0 security failures, 0 bad options, 7762670 with options >>>>>>>> Opts: 0 end, 0 nop, 0 basic security, 0 loose source route >>>>>>>> 0 timestamp, 0 extended security, 0 record route >>>>>>>> 0 stream ID, 0 strict source route, 7762670 alert, 0 >>>>>>>> cipso, 0 ump >>>>>>>> 0 other >>>>>>>> Frags: 0 reassembled, 0 timeouts, 0 couldn't reassemble >>>>>>>> 0 fragmented, 0 couldn't fragment >>>>>>>> Bcast: 2884 received, 87 sent >>>>>>>> Mcast: 2334 received, 2209 sent >>>>>>>> Sent: 24621 generated, 8328118 forwarded >>>>>>>> Drop: 4258 encapsulation failed, 0 unresolved, 83 no adjacency >>>>>>>> 69 no route, 0 unicast RPF, 0 forced drop >>>>>>>> 0 options denied, 0 source IP address zero >>>>>>>> >>>>>>>> ICMP statistics: >>>>>>>> Rcvd: 0 format errors, 0 checksum errors, 0 redirects, 0 >>>>>>>> unreachable >>>>>>>> 9560 echo, 0 echo reply, 0 mask requests, 0 mask >>>>>>>> replies, 0 >>>>>>>> quench >>>>>>>> 0 parameter, 0 timestamp, 0 info request, 0 other >>>>>>>> 0 irdp solicitations, 0 irdp advertisements >>>>>>>> Sent: 0 redirects, 3129 unreachable, 0 echo, 9560 echo reply >>>>>>>> 0 mask requests, 0 mask replies, 0 quench, 0 timestamp >>>>>>>> 0 info reply, 47 time exceeded, 0 parameter problem >>>>>>>> 0 irdp solicitations, 0 irdp advertisements >>>>>>>> >>>>>>>> TCP statistics: >>>>>>>> Rcvd: 7710 total, 8 checksum errors, 1 no port >>>>>>>> Sent: 6762 total >>>>>>>> >>>>>>>> UDP statistics: >>>>>>>> Rcvd: 4615 total, 0 checksum errors, 1430 no port >>>>>>>> Sent: 2909 total, 0 forwarded broadcasts >>>>>>>> >>>>>>>> IP-EIGRP statistics: >>>>>>>> Rcvd: 0 total >>>>>>>> Sent: 0 total >>>>>>>> >>>>>>>> BGP statistics: >>>>>>>> Rcvd: 162 total, 1 opens, 0 notifications, 1 updates >>>>>>>> 160 keepalives, 0 route-refresh, 0 unrecognized >>>>>>>> Sent: 159 total, 1 opens, 0 notifications, 0 updates >>>>>>>> 158 keepalives, 0 route-refresh >>>>>>>> >>>>>>>> PIMv2 statistics: Sent/Received >>>>>>>> Total: 0/0, 0 checksum errors, 0 format errors >>>>>>>> Registers: 0/0 (0 non-rp, 0 non-sm-group), Register Stops: 0/0, >>>>>>>> Hellos: >>>>>>>> 0/0 >>>>>>>> Join/Prunes: 0/0, Asserts: 0/0, grafts: 0/0 >>>>>>>> Bootstraps: 0/0, Candidate_RP_Advertisements: 0/0 >>>>>>>> State-Refresh: 0/0 >>>>>>>> >>>>>>>> IGMP statistics: Sent/Received >>>>>>>> Total: 0/0, Format errors: 0/0, Checksum errors: 0/0 >>>>>>>> Host Queries: 0/0, Host Reports: 0/0, Host Leaves: 0/0 DVMRP: >>>>>>>> 0/0, PIM: >>>>>>>> 0/0 >>>>>>>> >>>>>>>> OSPF statistics: >>>>>>>> Rcvd: 2363 total, 0 checksum errors >>>>>>>> 1900 hello, 12 database desc, 2 link state req >>>>>>>> 345 link state updates, 104 link state acks >>>>>>>> >>>>>>>> Sent: 2231 total >>>>>>>> 1904 hello, 11 database desc, 4 link state req >>>>>>>> 223 link state updates, 89 link state acks >>>>>>>> >>>>>>>> ARP statistics: >>>>>>>> Rcvd: 2254 requests, 82 replies, 0 reverse, 0 other >>>>>>>> Sent: 4178 requests, 2447 replies (2 proxy), 0 reverse >>>>>>>> Drop due to input queue full: 0 >>>>>>>> >>>>>>>> Thanks for looking. >>>>>>>> >>>>>>>> On Fri, Apr 24, 2009 at 7:45 AM, junior >>>>>>> drrtuy at ya.ru>> wrote: >>>>>>>> >>>>>>>> Hi, >>>>>>>> >>>>>>>> Did You check TAC cases? >>>>>>>> Can You post this switch current configuration with sh ip >>>>>>>> traffic >>>>>>>> command output? >>>>>>>> >>>>>>>> WBR >>>>>>>> Roman A. Nozdrin >>>>>>>> >>>>>>>> Chris Lane wrote: >>>>>>>> >>>>>>>> 1 routed interface.sh platform ip unicast failed route >>>>>>>> Total of 0 covering fib entries >>>>>>>> >>>>>>>> Thanks for reply.. I checked earlier regarding sdm. >>>>>>>> Its the same on all of my 3750's i have about 20 of them >>>>>>>> throughout the >>>>>>>> states, this is probably the quietest one in regards to >>>>>>>> bandwidth and >>>>>>>> services. >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> On Fri, Apr 24, 2009 at 7:21 AM, Brian Turnbow < >>> b.turnbow at twt.it >>>>>>>> > wrote: >>>>>>>> >>>>>>>> how many routed interfaces do you have ( sh ip int >>>>>>>> brief >>>>>>>> with ip >>>>>>>> addresses ) ? >>>>>>>> if more than 8 change the sdm template to routing >>>>>>>> >>>>>>>> you can use sh platform ip unicast failed route to >>>>>>>> see >>>>>>>> if >>>>>>>> routes are >>>>>>>> failing to be programmed into tcam >>>>>>>> >>>>>>>> Brian >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> ------------------------------ >>>>>>>> *From:* Chris Lane [mailto:clane1875 at gmail.com >>>>>>>> ] >>>>>>>> *Sent:* venerd? 24 aprile 2009 11.17 >>>>>>>> >>>>>>>> *To:* Brian Turnbow >>>>>>>> *Cc:* Peter Rathlev; cisco-nsp at puck.nether.net >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> *Subject:* Re: [c-nsp] 3750 High Cpu IP Input >>>>>>>> >>>>>>>> sh controllers cpu-interface >>>>>>>> ASIC Rxbiterr Rxunder Fwdctfix Txbuflos >>>>>>>> Rxbufloc >>>>>>>> Rxbufdrain >>>>>>>> >>>>>>>> >>> ------------------------------------------------------------------------- >>>>>>>> ASIC0 0 0 0 >>>>>>>> 0 0 >>>>>>>> 0 >>>>>>>> ASIC1 0 0 0 >>>>>>>> 0 0 >>>>>>>> 0 >>>>>>>> >>>>>>>> >>>>>>>> cpu-queue-frames retrieved dropped invalid >>>>>>>> hol- >>>>>>>> block >>>>>>>> stray >>>>>>>> ----------------- ---------- ---------- ---------- >>>>>>>> ---------- ---------- >>>>>>>> rpc 0 0 0 0 >>>>>>>> 0 >>>>>>>> stp 1807 0 0 0 >>>>>>>> 0 >>>>>>>> ipc 0 0 0 0 >>>>>>>> 0 >>>>>>>> routing protocol 1516326 0 0 0 >>>>>>>> 0 >>>>>>>> L2 protocol 27 0 0 0 >>>>>>>> 0 >>>>>>>> remote console 0 0 0 0 >>>>>>>> 0 >>>>>>>> sw forwarding 915 0 0 0 >>>>>>>> 0 >>>>>>>> host 2014 0 0 0 >>>>>>>> 0 >>>>>>>> broadcast 1766 0 0 0 >>>>>>>> 0 >>>>>>>> cbt-to-spt 0 0 0 0 >>>>>>>> 0 >>>>>>>> igmp snooping 1518651 0 0 0 >>>>>>>> 0 >>>>>>>> icmp 45 0 0 0 >>>>>>>> 0 >>>>>>>> logging 0 0 0 0 >>>>>>>> 0 >>>>>>>> rpf-fail 0 0 0 0 >>>>>>>> 0 >>>>>>>> queue14 0 0 0 0 >>>>>>>> 0 >>>>>>>> cpu heartbeat 14116 0 0 0 >>>>>>>> 0 >>>>>>>> >>>>>>>> ODD i have disabled IGMP SNOOPING... >>>>>>>> >>>>>>>> On Fri, Apr 24, 2009 at 4:19 AM, Brian Turnbow >>>>>>>> > wrote: >>>>>>>> >>>>>>>> You can use show controller cpu to help see >>>>>>>> whats >>>>>>>> going to the cpu >>>>>>>> Make sure you have no ip redirects and no proxy >>>>>>>> arp >>>>>>>> on >>>>>>>> all the interfaces. >>>>>>>> How many routed interfaces do you have ? >>>>>>>> The output below for "max" is for 8 routed >>>>>>>> interfaces if >>>>>>>> you have more you >>>>>>>> should change to the desktop switching template. >>>>>>>> With your roughly your values for indirectly >>>>>>>> connected >>>>>>>> routes and 13 ip >>>>>>>> interfaces on a box I needed to switch the >>>>>>>> template >>>>>>>> "sdm >>>>>>>> prefer routing" >>>>>>>> requies reload. >>>>>>>> >>>>>>>> Regards >>>>>>>> >>>>>>>> Brian >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> -----Original Message----- >>>>>>>> From: cisco-nsp-bounces at puck.nether.net >>>>>>>> >>>>>>>> [mailto: >>>>>>>> cisco-nsp-bounces at puck.nether.net >>>>>>>> ] On >>>>>>>> Behalf Of >>>>>>>> Chris Lane >>>>>>>> Sent: venerd? 24 aprile 2009 1.09 >>>>>>>> To: Peter Rathlev >>>>>>>> Cc: cisco-nsp at puck.nether.net >>>>>>>> >>>>>>>> Subject: Re: [c-nsp] 3750 High Cpu IP Input >>>>>>>> >>>>>>>> sh platform tcam utilization >>>>>>>> >>>>>>>> CAM Utilization for ASIC# 0 >>>>>>>> Max >>>>>>>> Used >>>>>>>> Masks/ >>>>>>>> Values >>>>>>>> Masks/values >>>>>>>> >>>>>>>> Unicast mac addresses: >>>>>>>> 784/6272 >>>>>>>> 37/235 >>>>>>>> IPv4 IGMP groups + multicast routes: >>>>>>>> 144/1152 >>>>>>>> 6/26 >>>>>>>> IPv4 unicast directly-connected routes: >>>>>>>> 784/6272 >>>>>>>> 37/235 >>>>>>>> IPv4 unicast indirectly-connected routes: >>>>>>>> 272/2176 >>>>>>>> 52/326 >>>>>>>> IPv4 policy based routing aces: >>>>>>>> 0/0 >>>>>>>> 0/0 >>>>>>>> IPv4 qos aces: >>>>>>>> 528/528 >>>>>>>> 18/18 >>>>>>>> IPv4 security aces: >>>>>>>> 1024/1024 >>>>>>>> 57/57 >>>>>>>> >>>>>>>> Note: Allocation of TCAM entries per feature uses >>>>>>>> a complex algorithm. The above information is >>>>>>>> meant >>>>>>>> to provide an abstract view of the current TCAM >>>>>>>> utilization >>>>>>>> >>>>>>>> Hope this helps. >>>>>>>> >>>>>>>> On Thu, Apr 23, 2009 at 4:41 PM, Peter Rathlev >>>>>>>> > >>>>>>>> wrote: >>>>>>>> >>>>>>>> On Thu, 2009-04-23 at 16:15 -0400, Chris Lane >>>>>>>> wrote: >>>>>>>> >>>>>>>> This box has been in production for >>>>>>>> over a >>>>>>>> year >>>>>>>> and doesn't really do >>>>>>>> to much as you can see from my orig >>>>>>>> thread it >>>>>>>> moves about 11MB. >>>>>>>> >>>>>>>> This just started late last night yet we >>>>>>>> didn't >>>>>>>> add any new customer >>>>>>>> nor did anybody even touch switch as the >>>>>>>> device >>>>>>>> is remote. >>>>>>>> >>>>>>>> I read in an older thread regarding same >>>>>>>> thing >>>>>>>> that the person >>>>>>>> rebooted and of course it resolved >>>>>>>> issue. I >>>>>>>> am >>>>>>>> planning to do that >>>>>>>> Early tomorrow am, but >>>>>>>> i really want to know what the heck is >>>>>>>> causing >>>>>>>> this. >>>>>>>> >>>>>>>> Yes CEF is running. >>>>>>>> >>>>>>>> What about TCAM utilisation ("show platform >>>>>>>> tcam >>>>>>>> utilization")? >>>>>>>> >>>>>>>> Regards, >>>>>>>> Peter >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> -- >>>>>>>> //CL >>>>>>>> _______________________________________________ >>>>>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>>>>> >>>>>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>>>>> archive at http://puck.nether.net/pipermail/cisco- >>>>>>>> nsp/ >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> -- >>>>>>>> //CL >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>> -- >>>>>>>> //CL >>>>>>>> >>>>>>> >>>>>>> >>>>>> >>>>>> >>>>>> -- >>>>>> //CL >>>>>> >>>>> >>>>> >>>>> >>>>> -- >>>>> //CL >>>>> _______________________________________________ >>>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>> >>>> _______________________________________________ >>>> cisco-nsp mailing list cisco-nsp at puck.nether.net >>>> https://puck.nether.net/mailman/listinfo/cisco-nsp >>>> archive at http://puck.nether.net/pipermail/cisco-nsp/ >>>> >>> >> >> >> >> -- >> //CL >> From frnkblk at iname.com Fri Apr 24 12:47:34 2009 From: frnkblk at iname.com (Frank Bulk) Date: Fri, 24 Apr 2009 11:47:34 -0500 Subject: [c-nsp] The dreaded microburst - definition and troubleshooting In-Reply-To: <3329cbb40904232138i3c45ac87va2138a787685cc02@mail.gmail.com> References: <3329cbb40904232138i3c45ac87va2138a787685cc02@mail.gmail.com> Message-ID: I know what you're feeling. I had a case open with TAC to diagnose why were getting input drops, and they wanted me to packet capture all the traffic going to the interface to see if I could identify what traffic was generating the microburst....except the volume is 40 to 60 Mbps and the drops may not show up for an hour at a time. How does one correlate it? Run "sh controllers $interface | inc rx_no_descriptors|rx_resource_error" and "sh int $interface | inc ignored" every second? The TAC engineer made it sound trivial to match things up, but it's not. So instead the TAC engineer did a little more research and in the end attributed it to microbursts. I don't really understand how Cisco can build a product (I'm using the NPE-G2) that can't take deal with microbursts, especially if the other interface is a Cisco product! The RX ring on an NPE-G2 is a 128 -- why wasn't it designed with 1024? Rodney mentions working with the BU, but it appears in the end it doesn't matter that input drops due to microbursts are a fact with this product. The Cisco TAC engineer was apologetic, but he wasn't going to lobby the PM. Frank -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Dale Shaw Sent: Thursday, April 23, 2009 11:38 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] The dreaded microburst - definition and troubleshooting Hi all, Is there a universally agreed upon definition for a 'microburst'? Is there a defined time measurement - i.e. 5ms, 10ms, 50ms, 100ms, 1000ms - during which a certain bps or pps threshold must be met/exceeded? Does anyone have any tips for troubleshooting microbursts, particularly in relation to the c7200 platform exhibiting "no buff" drops? We're going to capture some data (w/SPAN on an adjacent switch) but it would be nice to be able to look at the data and somehow marry it up with incrementing drop counters on the affected c7200 interface. It would be nice to be able to explain such drops like "within the measurement window, we saw traffic at bps/pps rate x, and we know that anything beyond bps/pps rate y will result in drops". I suppose it's platform-specific, but how does one come up with an accurate benchmark? Is such precision just wishful thinking in the murky world of microbursts? :-) cheers, Dale _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From lists.james.edwards at gmail.com Fri Apr 24 12:52:04 2009 From: lists.james.edwards at gmail.com (james edwards) Date: Fri, 24 Apr 2009 10:52:04 -0600 Subject: [c-nsp] Problems with DHCP static bindings Message-ID: We are using DHCP off the router, assigning static and dynamic addresses. The static configs work fine for Dell printers but not Xerox. Here is one that does not work, we have tried both "hardware-address" and "client-identifier"; with and without the host name: ip dhcp excluded-address 10.14.138.1 10.14.138.9 ip dhcp pool pr03 host 10.14.138.12 255.255.255.0 hardware-address 0000.aa67.415d ieee802 default-router 10.14.138.1 ip dhcp pool pr03 host 10.14.138.12 255.255.255.0 client-identifier 0100.00aa.6741.5d default-router 10.14.138.1 No luck after multiple reboots of the printers. This is on a 2620XM running c2600-is-mz.122-8.T5.bin. Any clues on this one ? Thanks, -- James H. Edwards Senior Network Systems Administrator Judicial Information Division jedwards at nmcourts.gov From icox at cisco.com Fri Apr 24 12:56:21 2009 From: icox at cisco.com (Ian Cox) Date: Fri, 24 Apr 2009 09:56:21 -0700 Subject: [c-nsp] The dreaded microburst - definition and troubleshooting In-Reply-To: <3329cbb40904232138i3c45ac87va2138a787685cc02@mail.gmail.com> References: <3329cbb40904232138i3c45ac87va2138a787685cc02@mail.gmail.com> Message-ID: <49F1EF35.6050402@cisco.com> The definition I generally use is this: [snip] A microburst is when packet drops occur when there is not sustained or noticeable congestion upon a link or device. Example: The 1 minute utilization of a link is 20% and packet drops are occurring. Microbursts happen in every packet based network where flow control is not extended end to end in all types of switches both blocking and non-blocking. [end snip] I principally work on high end switching and the 4 main ways we see it occur: - Speed Mismatch (10G into 1G, 10G into 10M) More extreme the speed mismatch the more dramatic the issue. - Network Oversubscription, Example 20 1G hosts using 1x10G uplink - L2 Unicast Flood - Synchronization of flood from multiple hosts - L2 Multicast - Synchronization of multicast from multiple hosts in large any to any multicast environments. Microbursts are how packet networks work that do not have end to end flow control. (End to end flow control is no panacea, you then have to create ways to prevent deadlock situations) You can use larger buffers to mask the issue, but that increases the latency and causes jitter. You can end up with the situation of packets arriving in extreme cases tens of seconds latter. Dropping packets is not the end of the world, it puts a limit on how large the latency and jitter can grow. Ian Dale Shaw wrote: > Hi all, > > Is there a universally agreed upon definition for a 'microburst'? > > Is there a defined time measurement - i.e. 5ms, 10ms, 50ms, 100ms, > 1000ms - during which a certain bps or pps threshold must be > met/exceeded? > > Does anyone have any tips for troubleshooting microbursts, > particularly in relation to the c7200 platform exhibiting "no buff" > drops? We're going to capture some data (w/SPAN on an adjacent switch) > but it would be nice to be able to look at the data and somehow marry > it up with incrementing drop counters on the affected c7200 interface. > > It would be nice to be able to explain such drops like "within the > measurement window, we saw traffic at bps/pps rate x, and we know that > anything beyond bps/pps rate y will result in drops". > > I suppose it's platform-specific, but how does one come up with an > accurate benchmark? Is such precision just wishful thinking in the > murky world of microbursts? :-) > > cheers, > Dale > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From Jeff.Wojciechowski at midlandpaper.com Fri Apr 24 12:30:41 2009 From: Jeff.Wojciechowski at midlandpaper.com (Jeff Wojciechowski) Date: Fri, 24 Apr 2009 11:30:41 -0500 Subject: [c-nsp] Adding member to Multilink PPP during production Message-ID: <6B8401A83219DF499C34DEAEE9A599920FF7C795B1@XBOX.midlandpaper.com> Hi all, We took down one of our 3 T1's in a PPP multilink group last night so that the LEC could replace a cable pair. Is it safe to add it back to the bundle during production hours? We've got mostly VoIP and Citrix traffic traversing that WAN link. Naturally it's the VoIP that I am mostly concerned about. Thanks, Jeff ------------------------------------------------------------------------------------------------------------------------------------------------------------ This electronic mail (including any attachments) may contain information that is privileged, confidential, or otherwise protected from disclosure to anyone other than its intended recipient(s). Any dissemination or use of this electronic mail or its contents (including any attachments) by persons other than the intended recipient(s) is strictly prohibited. If you have received this message in error, please delete the original message in its entirety (including any attachments) and notify us immediately by reply email so that we may correct our internal records. Midland Paper Company accepts no responsibility for any loss or damage from use of this electronic mail, including any damage resulting from a computer virus. From BBlackford at nwresd.k12.or.us Fri Apr 24 13:09:56 2009 From: BBlackford at nwresd.k12.or.us (Bill Blackford) Date: Fri, 24 Apr 2009 10:09:56 -0700 Subject: [c-nsp] C7301 dropping OSPF Message-ID: <6069A203FD01884885C037F81DD75080032AAA9DC4@wsc-mail-01.intra.nwresd.k12.or.us> PROBLEM: 7301 dropping OSPF adjacencies. The log is showing the following messages: Apr 23 12:20:01 c7301 392: 000398: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/0 from LOADING to FULL, Loading Done Apr 23 12:20:01 c7301 393: 000399: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/1 from LOADING to FULL, Loading Done During this, all traffic moves over to my other router. BGP peers stay up, but IGP routes get dumped. The router sees about 200M and 30k PPS on each interface at peak times. CPU gets to about 55% at peak. This issue is occurring near, but not always at peak. Code is older, disk0:c7301-js-mz.123-14.T3.bin. But this issue just started showing up. It has me a bit concerned as we just had a series of power events with a misbehaved UPS. I can ping the multicast address fine: wsc-rtr-7301#ping 224.0.0.5 Type escape sequence to abort. Sending 1, 100-byte ICMP Echos to 224.0.0.5, timeout is 2 seconds: Reply to request 0 from lo.bdr1.fqdn (x.x.x.x), 1 ms Reply to request 0 from ge-1-0-6.agr1.fqdn (x.x.x.x), 4 ms Reply to request 0 from ge-0-2-v100.bdr1.fqdn (x.x.x.x), 1 ms wsc-rtr-7301#sh ip os n Neighbor ID Pri State Dead Time Address Interface x.x.x.x 255 FULL/DR 00:00:06 x.x.x.x GigabitEthernet0/0 y.y.y.y 25 FULL/BDR 00:00:07 x.x.x.x GigabitEthernet0/1 The interfaces includes the following: int gi0/0 ip ospf hello-interval 2 ip ospf priority 25 ip ospf retransmit-interval 1 int gi0/1 ip ospf hello-interval 2 ip ospf priority 30 ip ospf retransmit-interval 1 Thank you in advance for any help. -b -- Bill Blackford Senior Network Engineer NWRESD my /home away from home From biged7600 at gmail.com Fri Apr 24 13:20:04 2009 From: biged7600 at gmail.com (James Edmondson) Date: Fri, 24 Apr 2009 12:20:04 -0500 Subject: [c-nsp] Cisco 7606S PPP Multilink issues Message-ID: I have a Cisco 7606S router with 8 port spa T1 card, running ios version: c7600rsp72043-adventerprisek9-mz.122-33.SRC1.bin Right now i have 2 T1's coming in on the same chassis and we are trying to use PPP Multilink. The far end equipment is a Cisco 7206 router with IOS version: c7200-p-mz.123-19.bin When we enable multilink and place the T1s in the ppp multilink group, the T1's are up/up, the multilink interface is up/up, however no traffic passes over the multilink, you cant ping the local or remote end multilink ip address (/30 subnet). I have tried just putting 1 t1 in the ppp multi group and leaving the other alone. When this happens, i get same results; T1 in multilink cant ping and no traffic, the other t1 not in ppp multilink is up and working fine, pinging, passing traffic just as expected. I have a Cisco case open, however so far its not much help, just want to ensure proper multilink configuration, which isnt that difficult. doing a sh ppp multilink - tells me the interfaces are active debug ppp multilink negeotation tells me: Apr 24 06:18:02.288: Se2/1/1:1 PPP: Sending cstate UP notification Apr 24 06:18:02.288: Se2/1/1:1 PPP: Processing CstateUp message Apr 24 06:18:02.288: PPP: Alloc Context [19321D28] Apr 24 06:18:02.288: ppp630 PPP: Phase is ESTABLISHING Apr 24 06:18:02.288: Se2/1/1:1 PPP: Using default call direction Apr 24 06:18:02.288: Se2/1/1:1 PPP: Treating connection as a dedicated line Apr 24 06:18:02.288: Se2/1/1:1 PPP: Session handle[FE0000E0] Session id[630] Apr 24 06:18:02.288: Se2/1/1:1 LCP: Event[OPEN] State[Initial to Starting] Apr 24 06:18:02.288: Se2/1/1:1 LCP: O CONFREQ [Starting] id 1 len 24 Apr 24 06:18:02.288: Se2/1/1:1 LCP: MagicNumber 0x68F1815B (0x050668F1815B) Apr 24 06:18:02.288: Se2/1/1:1 LCP: MRRU 1500 (0x110405DC) Apr 24 06:18:02.288: Se2/1/1:1 LCP: EndpointDisc 1 RTLOCAL (0x130A0152543031524D44) Apr 24 06:18:02.288: Se2/1/1:1 LCP: Event[UP] State[Starting to REQsent] Apr 24 06:18:02.492: Se2/1/1:1 LCP: I CONFREQ [REQsent] id 89 len 25 Apr 24 06:18:02.492: Se2/1/1:1 LCP: MagicNumber 0x38221371 (0x050638221371) Apr 24 06:18:02.492: Se2/1/1:1 LCP: MRRU 1524 (0x110405F4) Apr 24 06:18:02.492: Se2/1/1:1 LCP: EndpointDisc 1 RTREMOTE (0x130B0152543131304D4E41) Apr 24 06:18:02.492: Se2/1/1:1 LCP: O CONFACK [REQsent] id 89 len 25 Apr 24 06:18:02.492: Se2/1/1:1 LCP: MagicNumber 0x38221371 (0x050638221371) Apr 24 06:18:02.492: Se2/1/1:1 LCP: MRRU 1524 (0x110405F4) Apr 24 06:18:02.492: Se2/1/1:1 LCP: EndpointDisc 1 RTREMOTE (0x130B0152543131304D4E41) Apr 24 06:18:02.492: Se2/1/1:1 LCP: Event[Receive ConfReq+] State[REQsent to ACKsent] Apr 24 06:18:02.492: Se2/1/1:1 LCP: I CONFACK [ACKsent] id 1 len 24 Apr 24 06:18:02.492: Se2/1/1:1 LCP: MagicNumber 0x68F1815B (0x050668F1815B) Apr 24 06:18:02.492: Se2/1/1:1 LCP: MRRU 1500 (0x110405DC) Apr 24 06:18:02.492: Se2/1/1:1 LCP: EndpointDisc 1 RTLOCAL (0x130A0152543031524D44) Apr 24 06:18:02.492: Se2/1/1:1 LCP: Event[Receive ConfAck] State[ACKsent to Open] Apr 24 06:18:02.492: Se2/1/1:1 PPP: Phase is FORWARDING, Attempting Forward Apr 24 06:18:02.492: Se2/1/1:1 LCP: State is Open Apr 24 06:18:02.492: Se2/1/1:1 PPP: Phase is ESTABLISHING, Finish LCP Apr 24 06:18:02.492: Se2/1/1:1 MLP: Request add link to bundle Apr 24 06:18:02.492: Se2/1/1:1 PPP: Phase is VIRTUALIZED Apr 24 06:18:02.492: Se2/1/1:1 MLP: Adding link to bundle Apr 24 06:18:02.492: Se2/1/1:1 MLP: Requested bundle Mu1 switching setup Apr 24 06:18:02.492: Se2/1/1:1 MLP: Determine clone source for SSS Apr 24 06:18:02.492: Se2/1/1:1 MLP: No cloning source provided, bundle interface statically configured Apr 24 06:18:02.492: Se2/1/1:1 MLP: SSS connect, bundle interface Mu1 Apr 24 06:18:02.492: PPP: Alloc Context [193223E8] Apr 24 06:18:02.492: ppp631 PPP: Phase is ESTABLISHING Apr 24 06:18:02.492: Mu1 MLP: Changing bundle bandwidth from 1544 to 1544 Apr 24 06:18:02.492: Se2/1/1:1 MLP: Computed frag size 5782 exceeds MTU, changed to 1496 Apr 24 06:18:02.492: Mu1 MLP: Updated interface delay to 20000 usec Apr 24 06:18:02.492: Mu1 MLP: Update bundle bandwidth 1544 set 1544 Apr 24 06:18:02.492: Se2/1/1:1 MLP: Change transmit status from Init to Enabled, transmit links 1 Apr 24 06:18:02.492: DML(sip_mlp_vlan_init,Multilink1): sending vlan update Apr 24 06:18:02.492: Sending command 25 to slot 2 hwidb Multilink1 hw_if_index 79 vc = 1048577 slotunit 64, bundle = Multilink1 hw_if_index 79 vc = 1048577 slotunit = 64, direction = 0, interleave = 0 frag = 0 hw_support = 0 new_primary_link 0 acfc 0 pfc 0, mrru 1500 Apr 24 06:18:02.492: Sending command 27 to slot 2 hwidb Serial2/1/1:1 hw_if_index 75 vc = 1 slotunit 65, bundle = Multilink1 hw_if_index 79 vc = 1048577 slotunit = 64, direction = 3, interleave = 0 frag = 1496 hw_support = 1 new_primary_link 0 acfc 0 pfc 0, mrru 1500 Apr 24 06:18:02.496: Mu1 MLP: Added first link Se2/1/1:1 to bundle RTREMOTE Apr 24 06:18:02.496: Mu1 MLP: Received segment updated message for bundle Apr 24 06:18:02.696: Se2/1/1:1 PPP: Queue IPCP code[1] id[1] Apr 24 06:18:02.696: Se2/1/1:1 PPP: Discarded CDPCP code[1] id[1] Apr 24 06:18:02.696: Mu1 PPP: Force LCP OPEN on MLP Bundle Apr 24 06:18:02.696: Mu1 PPP: Outbound cdp packet dropped, line protocol not up Apr 24 06:18:02.696: Mu1 PPP: Outbound ip packet dropped, line protocol not up Apr 24 06:18:02.696: Mu1 PPP: Outbound ip packet dropped, line protocol not up Apr 24 06:18:02.696: Mu1 PPP: Phase is UP Apr 24 06:18:02.696: Mu1 IPCP: Protocol configured, start CP. state[Initial] Apr 24 06:18:02.696: Mu1 IPCP: Event[OPEN] State[Initial to Starting] Apr 24 06:18:02.696: Mu1 IPCP: O CONFREQ [Starting] id 1 len 10 Apr 24 06:18:02.696: Mu1 IPCP: Address 10.X.X.X (0x03060AFB276A) Apr 24 06:18:02.696: Se2/1/1:1 MLP: O data FF03 8021 0101 000A 0306 0AFB 276A Apr 24 06:18:02.696: Mu1 IPCP: Event[UP] State[Starting to REQsent] Apr 24 06:18:02.696: Mu1 CDPCP: Protocol configured, start CP. state[Initial] Apr 24 06:18:02.696: Mu1 CDPCP: Event[OPEN] State[Initial to Starting] Apr 24 06:18:02.696: Mu1 CDPCP: O CONFREQ [Starting] id 1 len 4 Apr 24 06:18:02.696: Se2/1/1:1 MLP: O data FF03 8207 0101 0004 Apr 24 06:18:02.696: Mu1 CDPCP: Event[UP] State[Starting to REQsent] Apr 24 06:18:02.696: Se2/1/1:1 PPP: Process pending ncp packets Apr 24 06:18:02.696: Se2/1/1:1 IPCP: Redirect packet to Mu1 Apr 24 06:18:02.696: Mu1 IPCP: I CONFREQ [REQsent] id 1 len 10 Apr 24 06:18:02.696: Mu1 IPCP: Address 10.X.X.X (0x03060AFB2769) Apr 24 06:18:02.696: Mu1 IPCP: O CONFACK [REQsent] id 1 len 10 Apr 24 06:18:02.696: Mu1 IPCP: Address 10.X.X.X (0x03060AFB2769) Apr 24 06:18:02.696: Se2/1/1:1 MLP: O data FF03 8021 0201 000A 0306 0AFB 2769 Apr 24 06:18:02.696: Mu1 IPCP: Event[Receive ConfReq+] State[REQsent to ACKsent] Apr 24 06:18:02.860: Se2/1/1:1 MLP: I data FF03 8021 0201 000A 0306 0AFB 276A Apr 24 06:18:02.860: Se2/1/1:1 MLP: I data FF03 8207 0201 0004 Apr 24 06:18:02.900: Mu1 IPCP: I CONFACK [ACKsent] id 1 len 10 Apr 24 06:18:02.900: Mu1 IPCP: Address 10.X.X.X (0x03060AFB276A) Apr 24 06:18:02.900: Mu1 IPCP: Event[Receive ConfAck] State[ACKsent to Open] Apr 24 06:18:02.900: Mu1 CDPCP: I CONFACK [REQsent] id 1 len 4 Apr 24 06:18:02.900: Mu1 CDPCP: Event[Receive ConfAck] State[REQsent to ACKrcvd] Apr 24 06:18:02.908: Mu1 IPCP: State is Open Apr 24 06:18:02.908: Mu1 IPCP: Add link info for cef entry 10.X.X.X Apr 24 06:18:02.908: Mu1 IPCP: Install route to 10.X.X.X Apr 24 06:18:03.696: Mu1 PPP: Outbound cdp packet dropped, NCP not negotiated Apr 24 06:18:04.508: Mu1 CDPCP: O CONFREQ [ACKrcvd] id 2 len 4 Apr 24 06:18:04.508: Mu1 CDPCP: Event[Timeout+] State[ACKrcvd to REQsent] Apr 24 06:18:04.652: Se2/1/1:1 MLP: I data FF03 8207 0102 0004 Apr 24 06:18:04.652: Mu1 CDPCP: I CONFREQ [REQsent] id 2 len 4 Apr 24 06:18:04.652: Mu1 CDPCP: O CONFACK [REQsent] id 2 len 4 Apr 24 06:18:04.652: Mu1 CDPCP: Event[Receive ConfReq+] State[REQsent to ACKsent] Apr 24 06:18:04.668: Se2/1/1:1 MLP: I data FF03 8207 0202 0004 Apr 24 06:18:04.668: Mu1 CDPCP: I CONFACK [ACKsent] id 2 len 4 Apr 24 06:18:04.668: Mu1 CDPCP: Event[Receive ConfAck] State[ACKsent to Open] Apr 24 06:18:04.700: Mu1 CDPCP: State is Open Apr 24 06:18:06.880: Se2/1/1:1 MLP: I data FF03 0207 02B4 7717 0001 000C 5254 3131 Apr 24 06:18:07.880: Se2/1/1:1 MLP: I data FF03 0207 02B4 7717 0001 000C 5254 3131 Any help is greatly appreciated! -- James From MLouis at nwnit.com Fri Apr 24 13:22:44 2009 From: MLouis at nwnit.com (Mike Louis) Date: Fri, 24 Apr 2009 13:22:44 -0400 Subject: [c-nsp] C7301 dropping OSPF Message-ID: Bill Do you have multicast routing enabled on your network? If so what multicast addresses are you using? Can you do a show interface on the routed interfaces and post? Show ip ospf interface as well if you would. -----Original Message----- From: Bill Blackford Sent: Friday, April 24, 2009 1:17 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] C7301 dropping OSPF PROBLEM: 7301 dropping OSPF adjacencies. The log is showing the following messages: Apr 23 12:20:01 c7301 392: 000398: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/0 from LOADING to FULL, Loading Done Apr 23 12:20:01 c7301 393: 000399: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/1 from LOADING to FULL, Loading Done During this, all traffic moves over to my other router. BGP peers stay up, but IGP routes get dumped. The router sees about 200M and 30k PPS on each interface at peak times. CPU gets to about 55% at peak. This issue is occurring near, but not always at peak. Code is older, disk0:c7301-js-mz.123-14.T3.bin. But this issue just started showing up. It has me a bit concerned as we just had a series of power events with a misbehaved UPS. I can ping the multicast address fine: wsc-rtr-7301#ping 224.0.0.5 Type escape sequence to abort. Sending 1, 100-byte ICMP Echos to 224.0.0.5, timeout is 2 seconds: Reply to request 0 from lo.bdr1.fqdn (x.x.x.x), 1 ms Reply to request 0 from ge-1-0-6.agr1.fqdn (x.x.x.x), 4 ms Reply to request 0 from ge-0-2-v100.bdr1.fqdn (x.x.x.x), 1 ms wsc-rtr-7301#sh ip os n Neighbor ID Pri State Dead Time Address Interface x.x.x.x 255 FULL/DR 00:00:06 x.x.x.x GigabitEthernet0/0 y.y.y.y 25 FULL/BDR 00:00:07 x.x.x.x GigabitEthernet0/1 The interfaces includes the following: int gi0/0 ip ospf hello-interval 2 ip ospf priority 25 ip ospf retransmit-interval 1 int gi0/1 ip ospf hello-interval 2 ip ospf priority 30 ip ospf retransmit-interval 1 Thank you in advance for any help. -b -- Bill Blackford Senior Network Engineer NWRESD my /home away from home _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ Note: This message and any attachments is intended solely for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, legally privileged, confidential, and/or exempt from disclosure. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the original sender immediately by telephone or return email and destroy or delete this message along with any attachments immediately. From rodunn at cisco.com Fri Apr 24 13:23:43 2009 From: rodunn at cisco.com (Rodney Dunn) Date: Fri, 24 Apr 2009 13:23:43 -0400 Subject: [c-nsp] The dreaded microburst - definition and troubleshooting In-Reply-To: References: <3329cbb40904232138i3c45ac87va2138a787685cc02@mail.gmail.com> Message-ID: <20090424172343.GD2926@rtp-cse-489.cisco.com> On Fri, Apr 24, 2009 at 11:47:34AM -0500, Frank Bulk wrote: > I know what you're feeling. I had a case open with TAC to diagnose why were > getting input drops, and they wanted me to packet capture all the traffic > going to the interface to see if I could identify what traffic was > generating the microburst....except the volume is 40 to 60 Mbps and the > drops may not show up for an hour at a time. How does one correlate it? Just to be accurate..input drops are a bit different beast. On the new code that has EPC you can do a process level capture to see the punted traffic. And if you didn't have the fix for: CSCse05447 7200 ethernet interfaces should not throttle on input queue full drops the input drops could cuase us to throttle the ingress interface hence result in overruns. > Run "sh controllers $interface | inc rx_no_descriptors|rx_resource_error" > and "sh int $interface | inc ignored" every second? The TAC engineer made > it sound trivial to match things up, but it's not. So instead the TAC > engineer did a little more research and in the end attributed it to > microbursts. It's not easy. > > I don't really understand how Cisco can build a product (I'm using the > NPE-G2) that can't take deal with microbursts, especially if the other > interface is a Cisco product! It's like the GEIP days where it was just meant as a transition plan from the agg to the core. The speeds of the CPU's went up but not to the speed of the core. Eventually you have to upgrade the agg to support the rate. Just took a little longer for ASR1000 to come out. The RX ring on an NPE-G2 is a 128 -- why > wasn't it designed with 1024? Rodney mentions working with the BU, but it > appears in the end it doesn't matter that input drops due to microbursts are > a fact with this product. I want to be 100% accurate...it's not input drops that people correlate to the "input drop" on the 'sh int' output. That is totally different and not a result of a throttle/overrun. We tried to bump up the rx ring depth to be more tolerate of those burst but after a detailed analysis it simply wasn't worth the risk to change it. Real answer is move to something that can do gig linerate...ASR1000, etc.. Rodney The Cisco TAC engineer was apologetic, but he > wasn't going to lobby the PM. > > Frank > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Dale Shaw > Sent: Thursday, April 23, 2009 11:38 PM > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] The dreaded microburst - definition and troubleshooting > > Hi all, > > Is there a universally agreed upon definition for a 'microburst'? > > Is there a defined time measurement - i.e. 5ms, 10ms, 50ms, 100ms, > 1000ms - during which a certain bps or pps threshold must be > met/exceeded? > > Does anyone have any tips for troubleshooting microbursts, > particularly in relation to the c7200 platform exhibiting "no buff" > drops? We're going to capture some data (w/SPAN on an adjacent switch) > but it would be nice to be able to look at the data and somehow marry > it up with incrementing drop counters on the affected c7200 interface. > > It would be nice to be able to explain such drops like "within the > measurement window, we saw traffic at bps/pps rate x, and we know that > anything beyond bps/pps rate y will result in drops". > > I suppose it's platform-specific, but how does one come up with an > accurate benchmark? Is such precision just wishful thinking in the > murky world of microbursts? :-) > > cheers, > Dale > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From rodunn at cisco.com Fri Apr 24 13:26:33 2009 From: rodunn at cisco.com (Rodney Dunn) Date: Fri, 24 Apr 2009 13:26:33 -0400 Subject: [c-nsp] C7301 dropping OSPF In-Reply-To: <6069A203FD01884885C037F81DD75080032AAA9DC4@wsc-mail-01.intra.nwresd.k12.or.us> References: <6069A203FD01884885C037F81DD75080032AAA9DC4@wsc-mail-01.intra.nwresd.k12.or.us> Message-ID: <20090424172633.GE2926@rtp-cse-489.cisco.com> Turn on log adjacency detail under OSPF and correlate it. Almost always a result of packet loss with the peers. Rodney On Fri, Apr 24, 2009 at 10:09:56AM -0700, Bill Blackford wrote: > PROBLEM: > 7301 dropping OSPF adjacencies. The log is showing the following messages: > > Apr 23 12:20:01 c7301 392: 000398: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/0 from LOADING to FULL, Loading Done > Apr 23 12:20:01 c7301 393: 000399: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/1 from LOADING to FULL, Loading Done > > > During this, all traffic moves over to my other router. BGP peers stay up, but IGP routes get dumped. > The router sees about 200M and 30k PPS on each interface at peak times. > CPU gets to about 55% at peak. This issue is occurring near, but not always at peak. > Code is older, disk0:c7301-js-mz.123-14.T3.bin. But this issue just started showing up. It has me a bit concerned as we just had a series of power events with a misbehaved UPS. > > > I can ping the multicast address fine: > wsc-rtr-7301#ping 224.0.0.5 > > Type escape sequence to abort. > Sending 1, 100-byte ICMP Echos to 224.0.0.5, timeout is 2 seconds: > > Reply to request 0 from lo.bdr1.fqdn (x.x.x.x), 1 ms Reply to request 0 from ge-1-0-6.agr1.fqdn (x.x.x.x), 4 ms Reply to request 0 from ge-0-2-v100.bdr1.fqdn (x.x.x.x), 1 ms > > wsc-rtr-7301#sh ip os n > > Neighbor ID Pri State Dead Time Address Interface > x.x.x.x 255 FULL/DR 00:00:06 x.x.x.x GigabitEthernet0/0 > y.y.y.y 25 FULL/BDR 00:00:07 x.x.x.x GigabitEthernet0/1 > > The interfaces includes the following: > > int gi0/0 > ip ospf hello-interval 2 > ip ospf priority 25 > ip ospf retransmit-interval 1 > > > > int gi0/1 > ip ospf hello-interval 2 > ip ospf priority 30 > ip ospf retransmit-interval 1 > > > Thank you in advance for any help. > > -b > > -- > Bill Blackford > Senior Network Engineer > NWRESD > > my /home away from home > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From charles at thewybles.com Fri Apr 24 13:47:52 2009 From: charles at thewybles.com (Charles Wyble) Date: Fri, 24 Apr 2009 10:47:52 -0700 Subject: [c-nsp] Problems with DHCP static bindings In-Reply-To: References: Message-ID: <49F1FB48.203@thewybles.com> I recall having this problem with Xerox printers. I believe I ended up having to set the address via the control panel on the device. This was with ISC DHCPD server. It's something weird with Xerox kit, not the server side. james edwards wrote: > We are using DHCP off the router, assigning static and dynamic addresses. > The static configs work fine for Dell printers > but not Xerox. Here is one that does not work, we have tried both > "hardware-address" and "client-identifier"; with and > without the host name: > > > ip dhcp excluded-address 10.14.138.1 10.14.138.9 > > ip dhcp pool pr03 > host 10.14.138.12 255.255.255.0 > hardware-address 0000.aa67.415d ieee802 > default-router 10.14.138.1 > > ip dhcp pool pr03 > host 10.14.138.12 255.255.255.0 > client-identifier 0100.00aa.6741.5d > default-router 10.14.138.1 > > No luck after multiple reboots of the printers. This is on a 2620XM running > c2600-is-mz.122-8.T5.bin. > Any clues on this one ? > > Thanks, > From ptimmins at clearrate.com Fri Apr 24 14:04:17 2009 From: ptimmins at clearrate.com (Paul G. Timmins) Date: Fri, 24 Apr 2009 14:04:17 -0400 Subject: [c-nsp] Adding member to Multilink PPP during production In-Reply-To: <6B8401A83219DF499C34DEAEE9A599920FF7C795B1@XBOX.midlandpaper.com> References: <6B8401A83219DF499C34DEAEE9A599920FF7C795B1@XBOX.midlandpaper.com> Message-ID: We do this all the time in carrier scenarios, carrying voip. I've never seen a problem with taking out members of ppp multilink groups at random, and re-adding them at random. It might cause a packet or two to drop when the link goes away unexpectedly. > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- > bounces at puck.nether.net] On Behalf Of Jeff Wojciechowski > Sent: Friday, April 24, 2009 12:31 PM > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] Adding member to Multilink PPP during production > > Hi all, > > We took down one of our 3 T1's in a PPP multilink group last night so > that the LEC could replace a cable pair. > > Is it safe to add it back to the bundle during production hours? We've > got mostly VoIP and Citrix traffic traversing that WAN link. Naturally > it's the VoIP that I am mostly concerned about. > > Thanks, > > Jeff > > ----------------------------------------------------------------------- > ----------------------------------------------------------------------- > -------------- > This electronic mail (including any attachments) may contain > information that is privileged, confidential, or otherwise protected > from disclosure to anyone > other than its intended recipient(s). Any dissemination or use of this > electronic mail or its contents (including any attachments) by persons > other than > the intended recipient(s) is strictly prohibited. If you have received > this message in error, please delete the original message in its > entirety (including > any attachments) and notify us immediately by reply email so that we > may correct our internal records. Midland Paper Company accepts no > responsibility > for any loss or damage from use of this electronic mail, including any > damage resulting from a computer virus. > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From dsinn at dsinn.com Fri Apr 24 14:09:24 2009 From: dsinn at dsinn.com (David Sinn) Date: Fri, 24 Apr 2009 11:09:24 -0700 Subject: [c-nsp] number of VRFs on Cisco Cat/7600 In-Reply-To: <49F0A35C.2090601@memetic.org> References: <49F0A35C.2090601@memetic.org> Message-ID: <70A241CE-55C2-43CA-B0DD-0D009A0CD971@dsinn.com> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Sup720's support a Max of 1024 VRF's. See the datasheet: http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/product_data_sheet09186a0080159856.html David On Apr 23, 2009, at 10:20 AM, Adam Armstrong wrote: > Marlon Duksa wrote: >> I found this in Cisco documentation under the title "OSPF Support for >> Unlimited Software VRFs per >> Provider Edge Router" : >> >> "The OSPF Support for Unlimited Software VRFs per Provider Edge >> Router >> feature allows for an >> approximate range of 300 to 10,000 VRFs, depending on the particular >> platform and on the applications, >> processes, and protocols that are currently running on the platform." >> >> 10,000 VRF? >> >> 7600/Cat have a limitation of 4K internal VLANs and each L3 VPN >> (MPLS) takes >> one of those, up to 512 L3 VPNs. After 512 L3 VPNs it takes 2 >> internal >> VLANs. >> >> This would max out L3 VPNs on 7600/Cat to less than 3K. I assume >> that L3 VPN >> = VRF. >> >> Does anyone know how they arrived to this 10K VRFs number? It just >> does not >> make sense. > Unlimited *software* VRFs? > > adam. > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (Darwin) iEYEARECAAYFAknyAFQACgkQLa9jIE3ZamMy5QCgpuZXfABnboYazixOEouRJtNI LvkAoNNpiVLE9+9/5qU8Hmif11V76dM9 =pmME -----END PGP SIGNATURE----- From MLouis at nwnit.com Fri Apr 24 14:11:27 2009 From: MLouis at nwnit.com (Mike Louis) Date: Fri, 24 Apr 2009 14:11:27 -0400 Subject: [c-nsp] C7301 dropping OSPF Message-ID: Have you ever seen it with overlapping multicast addressing? -----Original Message----- From: Rodney Dunn Sent: Friday, April 24, 2009 1:36 PM To: Bill Blackford Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] C7301 dropping OSPF Turn on log adjacency detail under OSPF and correlate it. Almost always a result of packet loss with the peers. Rodney On Fri, Apr 24, 2009 at 10:09:56AM -0700, Bill Blackford wrote: > PROBLEM: > 7301 dropping OSPF adjacencies. The log is showing the following messages: > > Apr 23 12:20:01 c7301 392: 000398: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/0 from LOADING to FULL, Loading Done > Apr 23 12:20:01 c7301 393: 000399: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/1 from LOADING to FULL, Loading Done > > > During this, all traffic moves over to my other router. BGP peers stay up, but IGP routes get dumped. > The router sees about 200M and 30k PPS on each interface at peak times. > CPU gets to about 55% at peak. This issue is occurring near, but not always at peak. > Code is older, disk0:c7301-js-mz.123-14.T3.bin. But this issue just started showing up. It has me a bit concerned as we just had a series of power events with a misbehaved UPS. > > > I can ping the multicast address fine: > wsc-rtr-7301#ping 224.0.0.5 > > Type escape sequence to abort. > Sending 1, 100-byte ICMP Echos to 224.0.0.5, timeout is 2 seconds: > > Reply to request 0 from lo.bdr1.fqdn (x.x.x.x), 1 ms Reply to request 0 from ge-1-0-6.agr1.fqdn (x.x.x.x), 4 ms Reply to request 0 from ge-0-2-v100.bdr1.fqdn (x.x.x.x), 1 ms > > wsc-rtr-7301#sh ip os n > > Neighbor ID Pri State Dead Time Address Interface > x.x.x.x 255 FULL/DR 00:00:06 x.x.x.x GigabitEthernet0/0 > y.y.y.y 25 FULL/BDR 00:00:07 x.x.x.x GigabitEthernet0/1 > > The interfaces includes the following: > > int gi0/0 > ip ospf hello-interval 2 > ip ospf priority 25 > ip ospf retransmit-interval 1 > > > > int gi0/1 > ip ospf hello-interval 2 > ip ospf priority 30 > ip ospf retransmit-interval 1 > > > Thank you in advance for any help. > > -b > > -- > Bill Blackford > Senior Network Engineer > NWRESD > > my /home away from home > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ Note: This message and any attachments is intended solely for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, legally privileged, confidential, and/or exempt from disclosure. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the original sender immediately by telephone or return email and destroy or delete this message along with any attachments immediately. From BBlackford at nwresd.k12.or.us Fri Apr 24 14:17:11 2009 From: BBlackford at nwresd.k12.or.us (Bill Blackford) Date: Fri, 24 Apr 2009 11:17:11 -0700 Subject: [c-nsp] C7301 dropping OSPF In-Reply-To: References: Message-ID: <6069A203FD01884885C037F81DD75080032AAA9DF3@wsc-mail-01.intra.nwresd.k12.or.us> wsc-rtr-7301#sh int gi0/0 GigabitEthernet0/0 is up, line protocol is up Hardware is BCM1250 Internal MAC, address is ####.####.#### (bia ####.####.####) Description: Internet Internet address is x.x.x.x/30 MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 4/255, rxload 30/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex, 1000Mb/s, media type is RJ45 output flow-control is unsupported, input flow-control is unsupported ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:00, output hang never Last clearing of "show interface" counters never Input queue: 0/75/116200/85873 (size/max/drops/flushes); Total output drops: 1 Queueing strategy: fifo Output queue: 0/40 (size/max) 5 minute input rate 120394000 bits/sec, 13851 packets/sec 5 minute output rate 17119000 bits/sec, 9050 packets/sec 926342756 packets input, 1996679340 bytes, 0 no buffer Received 1 broadcasts, 0 runts, 0 giants, 33 throttles 0 input errors, 0 CRC, 0 frame, 241700 overrun, 0 ignored 0 watchdog, 812170 multicast, 0 pause input 0 input packets with dribble condition detected 3157683501 packets output, 4172533168 bytes, 0 underruns 4 output errors, 0 collisions, 3 interface resets 0 babbles, 0 late collision, 0 deferred 4 lost carrier, 0 no carrier, 0 pause output 0 output buffer failures, 0 output buffers swapped out wsc-rtr-7301#sh int gi0/1 GigabitEthernet0/1 is up, line protocol is up Hardware is BCM1250 Internal MAC, address is ####.####.#### (bia ####.####.####) Description: NWRESD WAN & all SDs Internet address is x.x.x.x/24 MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 27/255, rxload 3/255 Encapsulation ARPA, loopback not set Keepalive set (10 sec) Full-duplex, 1000Mb/s, media type is RJ45 output flow-control is unsupported, input flow-control is unsupported ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:00, output hang never Last clearing of "show interface" counters never Input queue: 1/75/168340/202 (size/max/drops/flushes); Total output drops: 5 Queueing strategy: fifo Output queue: 0/40 (size/max) 5 minute input rate 14421000 bits/sec, 8824 packets/sec 5 minute output rate 109796000 bits/sec, 13114 packets/sec 3350123857 packets input, 3632867472 bytes, 137 no buffer Received 285023 broadcasts, 0 runts, 0 giants, 2375 throttles 0 input errors, 0 CRC, 0 frame, 164839 overrun, 0 ignored 0 watchdog, 697983 multicast, 0 pause input 0 input packets with dribble condition detected 1133783666 packets output, 2917422301 bytes, 0 underruns 4 output errors, 0 collisions, 3 interface resets 0 babbles, 0 late collision, 0 deferred 4 lost carrier, 0 no carrier, 0 pause output 0 output buffer failures, 0 output buffers swapped out wsc-rtr-7301#sh ip ospf interface Loopback10 is up, line protocol is up Internet Address x.x.x.x/32, Area 0 Process ID 5794, Router ID x.x.x.x, Network Type LOOPBACK, Cost: 1 Loopback interface is treated as a stub Host GigabitEthernet0/2 is up, line protocol is up n/a GigabitEthernet0/0 is up, line protocol is up Internet Address x.x.x.x/30, Area 0 Process ID 5794, Router ID x.x.x.x, Network Type BROADCAST, Cost: 1 Transmit Delay is 1 sec, State BDR, Priority 25 Designated Router (ID) x.x.x.x, Interface address x.x.x.x Backup Designated router (ID) x.x.x.x, Interface address x.x.x.x Timer intervals configured, Hello 2, Dead 8, Wait 8, Retransmit 1 oob-resync timeout 40 Hello due in 00:00:01 Supports Link-local Signaling (LLS) Index 2/2, flood queue length 0 Next 0x0(0)/0x0(0) Last flood scan length is 1, maximum is 32 Last flood scan time is 0 msec, maximum is 52 msec Neighbor Count is 1, Adjacent neighbor count is 1 Adjacent with neighbor x.x.x.x (Designated Router) Suppress hello for 0 neighbor(s) Message digest authentication enabled Youngest key id is 5 GigabitEthernet0/1 is up, line protocol is up Internet Address x.x.x.x/24, Area 0 Process ID 5794, Router ID x.x.x.x, Network Type BROADCAST, Cost: 1 Transmit Delay is 1 sec, State DR, Priority 30 Designated Router (ID) x.x.x.x, Interface address x.x.x.x Backup Designated router (ID) x.x.x.x, Interface address x.x.x.x Timer intervals configured, Hello 2, Dead 8, Wait 8, Retransmit 1 oob-resync timeout 40 Hello due in 00:00:00 Supports Link-local Signaling (LLS) Index 1/1, flood queue length 0 Next 0x0(0)/0x0(0) Last flood scan length is 3, maximum is 4 Last flood scan time is 0 msec, maximum is 4 msec Neighbor Count is 1, Adjacent neighbor count is 1 Adjacent with neighbor x.x.x.x (Backup Designated Router) Suppress hello for 0 neighbor(s) Message digest authentication enabled Youngest key id is 5 -----Original Message----- From: Mike Louis [mailto:MLouis at nwnit.com] Sent: Friday, April 24, 2009 10:23 AM To: Bill Blackford; cisco-nsp at puck.nether.net Subject: RE: [c-nsp] C7301 dropping OSPF Bill Do you have multicast routing enabled on your network? If so what multicast addresses are you using? Can you do a show interface on the routed interfaces and post? Show ip ospf interface as well if you would. -----Original Message----- From: Bill Blackford Sent: Friday, April 24, 2009 1:17 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] C7301 dropping OSPF PROBLEM: 7301 dropping OSPF adjacencies. The log is showing the following messages: Apr 23 12:20:01 c7301 392: 000398: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/0 from LOADING to FULL, Loading Done Apr 23 12:20:01 c7301 393: 000399: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: Process 5794, Nbr x.x.x.x on GigabitEthernet0/1 from LOADING to FULL, Loading Done During this, all traffic moves over to my other router. BGP peers stay up, but IGP routes get dumped. The router sees about 200M and 30k PPS on each interface at peak times. CPU gets to about 55% at peak. This issue is occurring near, but not always at peak. Code is older, disk0:c7301-js-mz.123-14.T3.bin. But this issue just started showing up. It has me a bit concerned as we just had a series of power events with a misbehaved UPS. I can ping the multicast address fine: wsc-rtr-7301#ping 224.0.0.5 Type escape sequence to abort. Sending 1, 100-byte ICMP Echos to 224.0.0.5, timeout is 2 seconds: Reply to request 0 from lo.bdr1.fqdn (x.x.x.x), 1 ms Reply to request 0 from ge-1-0-6.agr1.fqdn (x.x.x.x), 4 ms Reply to request 0 from ge-0-2-v100.bdr1.fqdn (x.x.x.x), 1 ms wsc-rtr-7301#sh ip os n Neighbor ID Pri State Dead Time Address Interface x.x.x.x 255 FULL/DR 00:00:06 x.x.x.x GigabitEthernet0/0 y.y.y.y 25 FULL/BDR 00:00:07 x.x.x.x GigabitEthernet0/1 The interfaces includes the following: int gi0/0 ip ospf hello-interval 2 ip ospf priority 25 ip ospf retransmit-interval 1 int gi0/1 ip ospf hello-interval 2 ip ospf priority 30 ip ospf retransmit-interval 1 Thank you in advance for any help. -b -- Bill Blackford Senior Network Engineer NWRESD my /home away from home _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ Note: This message and any attachments is intended solely for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, legally privileged, confidential, and/or exempt from disclosure. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, please notify the original sender immediately by telephone or return email and destroy or delete this message along with any attachments immediately. From puhis at puhis.net Fri Apr 24 13:47:07 2009 From: puhis at puhis.net (Sergey T) Date: Fri, 24 Apr 2009 20:47:07 +0300 Subject: [c-nsp] Using SUP V-10GE in WS-C4006 Message-ID: <80DE14915A9B449AB1724B6BB57C8905@puhis> Hi! Did anybody know, can i use SUP V-10GE in WS-C4006 chassis? that link http://www.cisco.com/web/partners/downloads/765/tools/quickreference/catalyst4000supervisors.pdf say`s "Any chassis except 4003", but if i try to boot i see "WS-X4516-10GE supervisor not supported in WS-C4006 chassis". i try boot using the various IOS images, less than 12.2(37)SG because http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/release/note/OL_5184.html#wp757986 say`s - "The Catalyst 4006 chassis is no longer supported in Cisco IOS Release 12.2(37)SG." Serj From cphillips at wbsconnect.com Fri Apr 24 14:41:45 2009 From: cphillips at wbsconnect.com (Chris Phillips) Date: Fri, 24 Apr 2009 11:41:45 -0700 Subject: [c-nsp] Using SNMP to determine BGP neighbor received route count Message-ID: <49F207E9.4040401@wbsconnect.com> Is there an SNMP MIB that can be used to determine a BGP neighbor's received route count? Thanks in advance. -- Chris Phillips From braaen at zcorum.com Fri Apr 24 15:42:02 2009 From: braaen at zcorum.com (Brian Raaen) Date: Fri, 24 Apr 2009 15:42:02 -0400 Subject: [c-nsp] Using SNMP to determine BGP neighbor received route count In-Reply-To: <49F207E9.4040401@wbsconnect.com> References: <49F207E9.4040401@wbsconnect.com> Message-ID: <49F2160A.5070402@zcorum.com> yes there is, You can find the information in the BGP4-MIB.my file which you can download using anonymous ftp to ftp.cisco.com. Chris Phillips wrote: > Is there an SNMP MIB that can be used to determine a BGP neighbor's > received route count? > > Thanks in advance. > -- ----------------- Brian Raaen Network Engineer email: /braaen at zcorum.com/ From kloch at kl.net Fri Apr 24 16:37:12 2009 From: kloch at kl.net (Kevin Loch) Date: Fri, 24 Apr 2009 16:37:12 -0400 Subject: [c-nsp] 6500 SXD7b VRRP issue In-Reply-To: References: Message-ID: <49F222F8.9080107@kl.net> Jon Lewis wrote: > I just searched bug toolkit and didn't see anything similar, but has > anyone else had issues with VRRP "freaking out" with 6500s running > s72033-pk9sv-mz.122-18.SXD7b.bin? > > Last night, we lost connectivity to one of our BGP providers. 10 > seconds after the > > %BGP-5-ADJCHANGE: neighbor x.x.x.x Down BGP Notification sent > %BGP-3-NOTIFICATION: sent to neighbor x.x.x.x 4/0 (hold time expired) 0 > bytes > > all the interfaces on this router running VRRP started having their > states change from backup to master to backup every few seconds. After > about 40 seconds of this, it settled down and all the VRRP states went > back to their original state. While this was going on, the other 6500 > participating in the VRRPs (which was the master) logged nothing and > thought it was the master the whole time. This is likely a side effect of the cpu being maxed out, or encountering control plane rate limiting. Was there something that spiked the cpu or exeeded your control plane limits that caused both the BGP session to drop and the vrrp flaps? Loops on the switch that include cpu affecting packets (like vrrp for example) can easily do this. It is also possible that just importing a full table (which maxes out the cpu for a minute) caused the vrrp flaps as a side effect. Do you have the control-plane policer configured with a low rate limit and are there exceptions for BGP and vrrp? - Kevin From andrew at routeip.net Fri Apr 24 17:19:13 2009 From: andrew at routeip.net (Andrew Yerofyeyev) Date: Fri, 24 Apr 2009 17:19:13 -0400 Subject: [c-nsp] Using internal ports on Cisco 2106 Wireless controller for AP Message-ID: Is there a way to assign address from DHCP (internal on controller or external) to AP connected to ports on 2106 ? Would somebody share working configuration for that ? If AP connected to external switch (which is connected to 2106 via 802.1q trunk) all seems to be nice and easy, AP registered and works like charm. -- Best Regards, From lists at memetic.org Fri Apr 24 17:39:51 2009 From: lists at memetic.org (Adam Armstrong) Date: Fri, 24 Apr 2009 22:39:51 +0100 Subject: [c-nsp] number of VRFs on Cisco Cat/7600 In-Reply-To: <70A241CE-55C2-43CA-B0DD-0D009A0CD971@dsinn.com> References: <49F0A35C.2090601@memetic.org> <70A241CE-55C2-43CA-B0DD-0D009A0CD971@dsinn.com> Message-ID: <49F231A7.40405@memetic.org> I have heard it said that more than 512 VRFs is crazy. more than 1024 *INSANE*. adam. > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Sup720's support a Max of 1024 VRF's. See the datasheet: > > http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/product_data_sheet09186a0080159856.html > > > David > > On Apr 23, 2009, at 10:20 AM, Adam Armstrong wrote: > >> Marlon Duksa wrote: >>> I found this in Cisco documentation under the title "OSPF Support for >>> Unlimited Software VRFs per >>> Provider Edge Router" : >>> >>> "The OSPF Support for Unlimited Software VRFs per Provider Edge Router >>> feature allows for an >>> approximate range of 300 to 10,000 VRFs, depending on the particular >>> platform and on the applications, >>> processes, and protocols that are currently running on the platform." >>> >>> 10,000 VRF? >>> >>> 7600/Cat have a limitation of 4K internal VLANs and each L3 VPN >>> (MPLS) takes >>> one of those, up to 512 L3 VPNs. After 512 L3 VPNs it takes 2 internal >>> VLANs. >>> >>> This would max out L3 VPNs on 7600/Cat to less than 3K. I assume >>> that L3 VPN >>> = VRF. >>> >>> Does anyone know how they arrived to this 10K VRFs number? It just >>> does not >>> make sense. >> Unlimited *software* VRFs? >> >> adam. >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.9 (Darwin) > > iEYEARECAAYFAknyAFQACgkQLa9jIE3ZamMy5QCgpuZXfABnboYazixOEouRJtNI > LvkAoNNpiVLE9+9/5qU8Hmif11V76dM9 > =pmME > -----END PGP SIGNATURE----- From jlewis at lewis.org Fri Apr 24 18:25:46 2009 From: jlewis at lewis.org (Jon Lewis) Date: Fri, 24 Apr 2009 18:25:46 -0400 (EDT) Subject: [c-nsp] 6500 SXD7b VRRP issue In-Reply-To: <49F222F8.9080107@kl.net> References: <49F222F8.9080107@kl.net> Message-ID: On Fri, 24 Apr 2009, Kevin Loch wrote: >> all the interfaces on this router running VRRP started having their states >> change from backup to master to backup every few seconds. After about 40 >> seconds of this, it settled down and all the VRRP states went back to their >> original state. While this was going on, the other 6500 participating in >> the VRRPs (which was the master) logged nothing and thought it was the >> master the whole time. > > This is likely a side effect of the cpu being maxed out, or encountering > control plane rate limiting. Was there something that spiked the cpu > or exeeded your control plane limits that caused both the BGP session to > drop and the vrrp flaps? Loops on the switch that include cpu affecting > packets (like vrrp for example) can easily do this. It's not control plane rate limiting. Because the BGP peer that went down was a transit peer (~280k routes), the CPU would likely have been quite busy dealing with the routing changes. Do I need to tune process-max-time to keep VRRP from failing during periods of high CPU usage? I don't think I've messed with that since AS5200s. ---------------------------------------------------------------------- Jon Lewis | I route Senior Network Engineer | therefore you are Atlantic Net | _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________ From jf at probe-networks.de Fri Apr 24 19:02:43 2009 From: jf at probe-networks.de (Jonas Frey) Date: Sat, 25 Apr 2009 01:02:43 +0200 Subject: [c-nsp] Cisco 7304/NSE-100 L2TP session problem Message-ID: <1240614163.20989.19.camel@wks02.probe-networks.de> Hello, i am using a 7304 w/NSE-100 for DSL aggregation. Am running 12.2.33SB5 now (also tried 12.2.31 and 12.2.28). However i cant get things to work, L2TP tunnels are getting established but as soon as sessions are coming in they are getting closed. My config as follows: virtual-profile if-needed vpdn enable vpdn multihop vpdn logging vpdn logging local vpdn logging remote vpdn logging user vpdn logging tunnel-drop vpdn-group 2 accept-dialin protocol l2tp virtual-template 2 session-limit 1000 terminate-from hostname xxxxxxxxx source-ip x.x.x.x local name xxxx lcp renegotiation always l2tp tunnel password 7 xxx l2tp tunnel receive-window 100 l2tp tunnel retransmit timeout min 2 interface Virtual-Template2 mtu 1492 ip unnumbered Loopback0 no ip redirects no ip proxy-arp ip mtu 1492 no logging event link-status peer default ip address pool test1 keepalive 60 ppp mtu adaptive ppp authentication pap ADSL ppp authorization ADSL ppp accounting ADSL no clns route-cache As for errors i do get these: 00:18:35: %VPDN-4-MIDERROR: L2TP LNS xxxx unable to terminate user shdsl-0/001; Result 1, Error 1, Dataplane down note: 12.2.31 and 12.2.28 give a different message: 00:49:37: %VPDN-6-CLOSED: L2TP LNS xxxx closed user shdsl-0/001; Result 1, Error 0, nas-error/VPDN Carrier Loss Also the system prints the following error from time to time: 00:18:39: %SW_MGR-3-CM_ERROR: Connection Manager Error - provision segment failed [ADJ:L2TP:5041] - hardware platform error. -Traceback= 40812F84 408134C8 41177478 4117754C 42123DC8 41174DD0 42A0FEF4 42A0FFB4 411757F8 41175988 41166FB8 42A0FEF4 42A0FFB4 41167BC0 411627C4 41166250 And debug vodn l2x-events gives: 00:21:21: L2TP _____:032E1:0000C9C5: Open sock x.x.x.x:1701->y.y.y.y:1701 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn ev Sock-Ready 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn in Wt-Rx-ICCN 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn do Ignore-Sock-Up 00:21:21: L2TP _____:032E1:0000C9C5: 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn ev DP-Setup 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn in Wt-Rx-ICCN 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn do Ignore-DP-Setup 00:21:21: L2TP tnl 162F2:0000ABED: Congestion Control event received is positive acknowledgement 00:21:21: L2TP tnl 162F2:0000ABED: Congestion Window size, Cwnd 2 00:21:21: L2TP tnl 162F2:0000ABED: Slow Start threshold, Ssthresh 8 00:21:21: L2TP tnl 162F2:0000ABED: Remote Window size, 8 00:21:21: L2TP tnl 162F2:0000ABED: Congestion Ctrl Mode is Slow Start 00:21:21: L2TP tnl 162F2:0000ABED: FSM-CC ev Rx-SCCCN 00:21:21: L2TP tnl 162F2:0000ABED: FSM-CC Wt-SCCCN->Proc-SCCCN 00:21:21: L2TP tnl 162F2:0000ABED: FSM-CC do Rx-SCCCN 00:21:21: L2TP tnl 162F2:0000ABED: Got a response in SCCCN from xxxx 00:21:21: L2TP tnl 162F2:0000ABED: Tunnel Authentication success 00:21:21: L2TP tnl 162F2:0000ABED: Control connection authentication skipped/passed. 00:21:21: L2TP tnl 162F2:0000ABED: FSM-CC ev SCCCN-OK 00:21:21: L2TP tnl 162F2:0000ABED: FSM-CC Proc-SCCCN->established 00:21:21: L2TP tnl 162F2:0000ABED: FSM-CC do Established 00:21:21: L2TP tnl 162F2:0000ABED: Control channel up 00:21:21: L2TP tnl 162F2:0000ABED: x.x.x.x<->y.y.y.y 00:21:21: L2TP tnl 162F2:0000ABED: Control connection authentication skipped/passed. 00:21:21: L2X _____:_____:________: Create logical session 00:21:21: L2TP _____:_____:________: Create session 00:21:21: L2TP _____:_____:________: Using ICRQ FSM 00:21:21: L2TP _____:_____:________: FSM-Sn ev created 00:21:21: L2TP _____:_____:________: FSM-Sn Init->Idle 00:21:21: L2TP _____:_____:________: FSM-Sn do none 00:21:21: L2TP _____:_____:________: remote ip set to y.y.y.y 00:21:21: L2TP _____:_____:________: local ip set to x.x.x.x 00:21:21: L2TP tnl 162F2:0000ABED: FSM-CC ev Session-Conn 00:21:21: L2TP tnl 162F2:0000ABED: FSM-CC in established 00:21:21: L2TP tnl 162F2:0000ABED: FSM-CC do Session-Conn-Est 00:21:21: L2TP tnl 162F2:0000ABED: Session count now 1 00:21:21: L2TP _____:162F2:00004873: FSM-Sn ev CC-Up 00:21:21: L2TP _____:162F2:00004873: FSM-Sn in Idle 00:21:21: L2TP _____:162F2:00004873: FSM-Sn do CC-Up-Ignore0-1 00:21:21: L2TP _____:162F2:00004873: Session attached 00:21:21: L2TP _____:162F2:00004873: no cookies enabled 00:21:21: L2TP _____:162F2:00004873: FSM-Sn ev Rx-ICRQ 00:21:21: L2TP _____:162F2:00004873: FSM-Sn Idle->Proc-ICRQ 00:21:21: L2TP _____:162F2:00004873: FSM-Sn do Rx-ICRQ 00:21:21: L2TP _____:162F2:00004873: Chose application VPDN 00:21:21: L2TP _____:162F2:00004873: App type set to VPDN 00:21:21: L2TP tnl 162F2:0000ABED: VPDN Session count now 1 00:21:21: L2TP _____:162F2:00004873: VPDN: process AVPs 00:21:21: L2TP _____:162F2:00004873: Local AC is now UP 00:21:21: L2TP _____:162F2:00004873: Remote AC is now UP 00:21:21: L2TP _____:162F2:00004873: 00:21:21: L2TP tnl 032E1:00006170: Control connection authentication skipped/passed. 00:21:21: L2TP tnl 032E1:00006170: Congestion Control event received is positive acknowledgement 00:21:21: L2TP tnl 032E1:00006170: Congestion Window size, Cwnd 7 00:21:21: L2TP tnl 032E1:00006170: Slow Start threshold, Ssthresh 64 00:21:21: L2TP tnl 032E1:00006170: Remote Window size, 64 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn ev Rx-ICCN 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn Wt-Rx-ICCN->Proc-ICCN 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn do Rx-ICCN 00:21:21: L2TP _____:032E1:0000C9C5: MTU is 65535 00:21:21: L2TP _____:032E1:0000C9C5: Session data plane UP 00:21:21: L2TP _____:032E1:0000C9C5: VPDN: process AVPs 00:21:21: L2TP _____:032E1:0000C9C5: 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn ev ICCN-OK 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn Proc-ICCN->established 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn do Established 00:21:21: L2TP _____:032E1:0000C9C5: Session up 00:21:21: L2TP _____:032E1:0000C9C5: x.x.x.x<->y.y.y.y 00:21:21: L2X:Session DB (Tnl/Sn: 24944/51653): Stored the switching session in the session DB 00:21:21: L2TP:(Tnl24944:Sn51653)L2X s/w switching session provisioned 00:21:21: L2TP _____:032E1:0000C9C5: Received a SSM L2TP segment down event 00:21:21: L2TP _____:032E1:0000C9C5: 00:21:21: L2TUN APP: uid:119handle/5217Destroying app session 00:21:21: L2TUN APP: uid:119handle/5217Stopping service selection 00:21:21: L2TP _____:162F2:00004873: App type set to VPDN 00:21:21: L2TP _____:162F2:00004873: Conditional debugging is enabled 00:21:21: L2TP _____:162F2:00004873: UDP checksum ignore is enabled 00:21:21: L2TP _____:162F2:00004873: Framing set to sync 00:21:21: L2TP _____:162F2:00004873: Bearer set to none 00:21:21: L2TP _____:162F2:00004873: FSM-Sn ev ICRQ-OK 00:21:21: L2TP _____:162F2:00004873: FSM-Sn Proc-ICRQ->Wt-Tx-ICRP 00:21:21: L2TP _____:162F2:00004873: FSM-Sn do Tx-ICRP-Local-Check 00:21:21: L2TP _____:162F2:00004873: FSM-Sn ev Local-Cont 00:21:21: L2TP _____:162F2:00004873: FSM-Sn Wt-Tx-ICRP->Wt-Rx-ICCN 00:21:21: L2TP _____:162F2:00004873: FSM-Sn do Tx-ICRP 00:21:21: L2TP _____:162F2:00004873: Open sock x.x.x.x:1701->y.y.y.y:1701 00:21:21: L2TP _____:162F2:00004873: FSM-Sn ev Sock-Ready 00:21:21: L2TP _____:162F2:00004873: FSM-Sn in Wt-Rx-ICCN 00:21:21: L2TP _____:162F2:00004873: FSM-Sn do Ignore-Sock-Up 00:21:21: L2TP _____:162F2:00004873: 00:21:21: L2TP _____:162F2:00004873: FSM-Sn ev DP-Setup 00:21:21: L2TP _____:162F2:00004873: FSM-Sn in Wt-Rx-ICCN 00:21:21: L2TP _____:162F2:00004873: FSM-Sn do Ignore-DP-Setup 00:21:21: L2TP _____:032E1:0000C9C5: 00:21:21: L2TP _____:032E1:0000C9C5: App type set to VPDN 00:21:21: L2TP _____:032E1:0000C9C5: Framing set to sync 00:21:21: L2TP _____:032E1:0000C9C5: Bearer set to none 00:21:21: L2TP _____:032E1:0000C9C5: 00:21:21: L2TP _____:032E1:0000C9C5: Shutting down session 00:21:21: L2TP _____:032E1:0000C9C5: Result Code 00:21:21: L2TP _____:032E1:0000C9C5: Loss of carrier (1) 00:21:21: L2TP _____:032E1:0000C9C5: Error Code 00:21:21: L2TP _____:032E1:0000C9C5: No error (0) 00:21:21: L2TP _____:032E1:0000C9C5: Vendor Error 00:21:21: L2TP _____:032E1:0000C9C5: None (0) 00:21:21: L2TP _____:032E1:0000C9C5: Optional Message 00:21:21: L2TP _____:032E1:0000C9C5: "Dataplane down" 00:21:21: L2TP _____:032E1:0000C9C5: 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn ev App-Disc 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn in established 00:21:21: L2TP _____:032E1:0000C9C5: FSM-Sn do App-Disc-Active 00:21:21: L2TP _____:032E1:0000C9C5: Session down 00:21:21: L2TP _____:032E1:0000C9C5: x.x.x.x<->y.y.y.y 00:21:21: L2TP _____:032E1:0000C9C5: Destroying session 00:21:21: L2TP _____:032E1:0000C9C5: Request teardown data plane 00:21:21: L2TP tnl 032E1:00006170: FSM-CC ev Session-Disc 00:21:21: L2TP tnl 032E1:00006170: FSM-CC in established 00:21:21: L2TP tnl 032E1:00006170: FSM-CC do Session-Disc-Est 00:21:21: L2TP tnl 032E1:00006170: Session count now 0 00:21:21: L2TP tnl 032E1:00006170: VPDN Session count now 0 00:21:21: L2TP tnl 032E1:00006170: FSM-CC ev No-Users 00:21:21: L2TP tnl 032E1:00006170: FSM-CC established->Est-No-User 00:21:21: L2TP tnl 032E1:00006170: FSM-CC do No-Users 00:21:21: L2TP tnl 032E1:00006170: No more cc users, shutdown (likely) in 15 secs 00:21:21: L2TP _____:_____:________: Session detached 00:21:21: L2X _____:_____:________: Destroying logical session 00:21:21: L2TP:(Tnl24944:Sn51653)L2X s/w switching session unprovisioned 00:21:21: L2X:Session DB (Tnl/Sn: 24944/51653): Removed the switching session from the session DB Does anyone have any idea howto solve this? Unfortunatly i do not have access to the LAC as to where these tunnels are coming from. Regards, Jonas From gert at greenie.muc.de Sat Apr 25 03:28:34 2009 From: gert at greenie.muc.de (Gert Doering) Date: Sat, 25 Apr 2009 09:28:34 +0200 Subject: [c-nsp] 6500 SXD7b VRRP issue In-Reply-To: References: <49F222F8.9080107@kl.net> Message-ID: <20090425072834.GF290@greenie.muc.de> Hi, On Fri, Apr 24, 2009 at 06:25:46PM -0400, Jon Lewis wrote: > Do I need to tune process-max-time to keep VRRP from failing during > periods of high CPU usage? I don't think I've messed with that since > AS5200s. I've never seen CPU-induced VRRP or HSRP problems on our 6500 and 7600s - but then, I've never used SXD or SXE. So: SXI sounds like a good plan. Beware of the BGP mem leak bug if you have neighbors set to "shutdown" (not yet integrated). If not SXI, SXH3a is also working *very* well for us. Have not tested SXH4 or SXH5. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From mcdonald.richards at gmail.com Sat Apr 25 05:13:49 2009 From: mcdonald.richards at gmail.com (McDonald Richards) Date: Sat, 25 Apr 2009 19:13:49 +1000 Subject: [c-nsp] C7301 dropping OSPF In-Reply-To: <6069A203FD01884885C037F81DD75080032AAA9DF3@wsc-mail-01.intra.nwresd.k12.or.us> References: <6069A203FD01884885C037F81DD75080032AAA9DF3@wsc-mail-01.intra.nwresd.k12.or.us> Message-ID: <8bde567b0904250213m645e6165ua0d972c8e7bacd0a@mail.gmail.com> At the risk of over simplifying the issue - I'd suggest you increase your input queue on both devices to at least 1000. Looks like the 75 packet queue is not enough for the pps load on the device and other process switched packets may be causing your OSPF messages to be tail dropped during periods of high load causing your adjacencies to reset. Increase the input queue on both devices, clear counters and monitor for input queue drops. The overruns on the interface may also indicate the hardware was under serious load at one point. Again - reset the counters and monitor so you have a reference point so you can try and determine the root cause. On Sat, Apr 25, 2009 at 4:17 AM, Bill Blackford wrote: > wsc-rtr-7301#sh int gi0/0 > GigabitEthernet0/0 is up, line protocol is up > Hardware is BCM1250 Internal MAC, address is ####.####.#### (bia > ####.####.####) > Description: Internet > Internet address is x.x.x.x/30 > MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, > reliability 255/255, txload 4/255, rxload 30/255 > Encapsulation ARPA, loopback not set > Keepalive set (10 sec) > Full-duplex, 1000Mb/s, media type is RJ45 > output flow-control is unsupported, input flow-control is unsupported > ARP type: ARPA, ARP Timeout 04:00:00 > Last input 00:00:00, output 00:00:00, output hang never > Last clearing of "show interface" counters never > Input queue: 0/75/116200/85873 (size/max/drops/flushes); Total output > drops: 1 > Queueing strategy: fifo > Output queue: 0/40 (size/max) > 5 minute input rate 120394000 bits/sec, 13851 packets/sec > 5 minute output rate 17119000 bits/sec, 9050 packets/sec > 926342756 packets input, 1996679340 bytes, 0 no buffer > Received 1 broadcasts, 0 runts, 0 giants, 33 throttles > 0 input errors, 0 CRC, 0 frame, 241700 overrun, 0 ignored > 0 watchdog, 812170 multicast, 0 pause input > 0 input packets with dribble condition detected > 3157683501 packets output, 4172533168 bytes, 0 underruns > 4 output errors, 0 collisions, 3 interface resets > 0 babbles, 0 late collision, 0 deferred > 4 lost carrier, 0 no carrier, 0 pause output > 0 output buffer failures, 0 output buffers swapped out > > wsc-rtr-7301#sh int gi0/1 > GigabitEthernet0/1 is up, line protocol is up > Hardware is BCM1250 Internal MAC, address is ####.####.#### (bia > ####.####.####) > Description: NWRESD WAN & all SDs > Internet address is x.x.x.x/24 > MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, > reliability 255/255, txload 27/255, rxload 3/255 > Encapsulation ARPA, loopback not set > Keepalive set (10 sec) > Full-duplex, 1000Mb/s, media type is RJ45 > output flow-control is unsupported, input flow-control is unsupported > ARP type: ARPA, ARP Timeout 04:00:00 > Last input 00:00:00, output 00:00:00, output hang never > Last clearing of "show interface" counters never > Input queue: 1/75/168340/202 (size/max/drops/flushes); Total output drops: > 5 > Queueing strategy: fifo > Output queue: 0/40 (size/max) > 5 minute input rate 14421000 bits/sec, 8824 packets/sec > 5 minute output rate 109796000 bits/sec, 13114 packets/sec > 3350123857 packets input, 3632867472 bytes, 137 no buffer > Received 285023 broadcasts, 0 runts, 0 giants, 2375 throttles > 0 input errors, 0 CRC, 0 frame, 164839 overrun, 0 ignored > 0 watchdog, 697983 multicast, 0 pause input > 0 input packets with dribble condition detected > 1133783666 packets output, 2917422301 bytes, 0 underruns > 4 output errors, 0 collisions, 3 interface resets > 0 babbles, 0 late collision, 0 deferred > 4 lost carrier, 0 no carrier, 0 pause output > 0 output buffer failures, 0 output buffers swapped out > > > > wsc-rtr-7301#sh ip ospf interface > Loopback10 is up, line protocol is up > Internet Address x.x.x.x/32, Area 0 > Process ID 5794, Router ID x.x.x.x, Network Type LOOPBACK, Cost: 1 > Loopback interface is treated as a stub Host > GigabitEthernet0/2 is up, line protocol is up > n/a > GigabitEthernet0/0 is up, line protocol is up > Internet Address x.x.x.x/30, Area 0 > Process ID 5794, Router ID x.x.x.x, Network Type BROADCAST, Cost: 1 > Transmit Delay is 1 sec, State BDR, Priority 25 > Designated Router (ID) x.x.x.x, Interface address x.x.x.x > Backup Designated router (ID) x.x.x.x, Interface address x.x.x.x > Timer intervals configured, Hello 2, Dead 8, Wait 8, Retransmit 1 > oob-resync timeout 40 > Hello due in 00:00:01 > Supports Link-local Signaling (LLS) > Index 2/2, flood queue length 0 > Next 0x0(0)/0x0(0) > Last flood scan length is 1, maximum is 32 > Last flood scan time is 0 msec, maximum is 52 msec > Neighbor Count is 1, Adjacent neighbor count is 1 > Adjacent with neighbor x.x.x.x (Designated Router) > Suppress hello for 0 neighbor(s) > Message digest authentication enabled > Youngest key id is 5 > GigabitEthernet0/1 is up, line protocol is up > Internet Address x.x.x.x/24, Area 0 > Process ID 5794, Router ID x.x.x.x, Network Type BROADCAST, Cost: 1 > Transmit Delay is 1 sec, State DR, Priority 30 > Designated Router (ID) x.x.x.x, Interface address x.x.x.x > Backup Designated router (ID) x.x.x.x, Interface address x.x.x.x > Timer intervals configured, Hello 2, Dead 8, Wait 8, Retransmit 1 > oob-resync timeout 40 > Hello due in 00:00:00 > Supports Link-local Signaling (LLS) > Index 1/1, flood queue length 0 > Next 0x0(0)/0x0(0) > Last flood scan length is 3, maximum is 4 > Last flood scan time is 0 msec, maximum is 4 msec > Neighbor Count is 1, Adjacent neighbor count is 1 > Adjacent with neighbor x.x.x.x (Backup Designated Router) > Suppress hello for 0 neighbor(s) > Message digest authentication enabled > Youngest key id is 5 > > > > > -----Original Message----- > From: Mike Louis [mailto:MLouis at nwnit.com] > Sent: Friday, April 24, 2009 10:23 AM > To: Bill Blackford; cisco-nsp at puck.nether.net > Subject: RE: [c-nsp] C7301 dropping OSPF > > Bill > > Do you have multicast routing enabled on your network? If so what multicast > addresses are you using? > > Can you do a show interface on the routed interfaces and post? Show ip ospf > interface as well if you would. > > -----Original Message----- > From: Bill Blackford > Sent: Friday, April 24, 2009 1:17 PM > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] C7301 dropping OSPF > > > PROBLEM: > 7301 dropping OSPF adjacencies. The log is showing the following messages: > > Apr 23 12:20:01 c7301 392: 000398: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: > Process 5794, Nbr x.x.x.x on GigabitEthernet0/0 from LOADING to FULL, > Loading Done > Apr 23 12:20:01 c7301 393: 000399: Apr 23 12:20:00.016 PDT: %OSPF-5-ADJCHG: > Process 5794, Nbr x.x.x.x on GigabitEthernet0/1 from LOADING to FULL, > Loading Done > > > During this, all traffic moves over to my other router. BGP peers stay up, > but IGP routes get dumped. > The router sees about 200M and 30k PPS on each interface at peak times. > CPU gets to about 55% at peak. This issue is occurring near, but not always > at peak. > Code is older, disk0:c7301-js-mz.123-14.T3.bin. But this issue just started > showing up. It has me a bit concerned as we just had a series of power > events with a misbehaved UPS. > > > I can ping the multicast address fine: > wsc-rtr-7301#ping 224.0.0.5 > > Type escape sequence to abort. > Sending 1, 100-byte ICMP Echos to 224.0.0.5, timeout is 2 seconds: > > Reply to request 0 from lo.bdr1.fqdn (x.x.x.x), 1 ms Reply to request 0 > from ge-1-0-6.agr1.fqdn (x.x.x.x), 4 ms Reply to request 0 from > ge-0-2-v100.bdr1.fqdn (x.x.x.x), 1 ms > > wsc-rtr-7301#sh ip os n > > Neighbor ID Pri State Dead Time Address Interface > x.x.x.x 255 FULL/DR 00:00:06 x.x.x.x GigabitEthernet0/0 > y.y.y.y 25 FULL/BDR 00:00:07 x.x.x.x > GigabitEthernet0/1 > > The interfaces includes the following: > > int gi0/0 > ip ospf hello-interval 2 > ip ospf priority 25 > ip ospf retransmit-interval 1 > > > > int gi0/1 > ip ospf hello-interval 2 > ip ospf priority 30 > ip ospf retransmit-interval 1 > > > Thank you in advance for any help. > > -b > > -- > Bill Blackford > Senior Network Engineer > NWRESD > > my /home away from home > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > > Note: This message and any attachments is intended solely for the use of > the individual or entity to which it is addressed and may contain > information that is non-public, proprietary, legally privileged, > confidential, and/or exempt from disclosure. If you are not the intended > recipient, you are hereby notified that any use, dissemination, > distribution, or copying of this communication is strictly prohibited. If > you have received this communication in error, please notify the original > sender immediately by telephone or return email and destroy or delete this > message along with any attachments immediately. > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From lists at memetic.org Sat Apr 25 05:23:30 2009 From: lists at memetic.org (Adam Armstrong) Date: Sat, 25 Apr 2009 10:23:30 +0100 Subject: [c-nsp] number of VRFs on Cisco Cat/7600 In-Reply-To: References: <49F0A35C.2090601@memetic.org> <70A241CE-55C2-43CA-B0DD-0D009A0CD971@dsinn.com> <49F231A7.40405@memetic.org> Message-ID: <49F2D692.3050204@memetic.org> Benny Amorsen wrote: > Adam Armstrong writes: > > >> I have heard it said that more than 512 VRFs is crazy. more than 1024 >> *INSANE*. >> > > Why? You want as many customers one one box as possible, to keep costs > and maintenance down. Having an array of PE's at 1/100th of capacity > just because they're limited to 512 VRFs is crazy. > Hardware limitations? Stealing from inetpro.org's Wiki (which i'm assuming to be accurate) : "The VPN CAM maps VPNs to VLANs within the 6500. As all interfaces (included routed) are ultimately assigned a vlan (see above), we know that a match here will result in a pop operation and the destination network will be plain old IP. The current size of the VPN CAM is 512 entries. Therefore, *512 is the maximum number of VPNs suggested on a 6500*. While 4096 is the hard absolute limit, more than 1024 is insane and more than 512 crazy. In a normal operation, a packet due to exit to an IP network will do a query in the VPN CAM based on its VPN ID and be given a hit. At this point, the 6500 knows to strip the MPLS label and disregard it. It will copy the TOS value in to the internal DSCP and then process the packet through the TCAM as normal. If there is a miss, but we still want to pop out to a regular IP network, we make a TCAM lookup based on the ingress VLAN number. We then get a match in the FIB to recirculate. Becuase we still have a full MPLS label and no adjacency information, the packet must do just that and go back around. The match from earlier, gives us an ingress VLAN to look up (based this time on our egress destination) and we get our correct L2 rewrite info etc, as well as any ACLs and policing on the packet. Due to this, a full VPN CAM will halve performance for those packets getting misses! The absolute limit of 4096 is due to the maximum number of supported vlans in a 6500. Of course, in the real world, vlans will be used elsewhere, so be sure to provision an internal vlan for each VRF." adam. From benny+usenet at amorsen.dk Sat Apr 25 04:30:11 2009 From: benny+usenet at amorsen.dk (Benny Amorsen) Date: Sat, 25 Apr 2009 10:30:11 +0200 Subject: [c-nsp] number of VRFs on Cisco Cat/7600 In-Reply-To: <49F231A7.40405@memetic.org> (Adam Armstrong's message of "Fri\, 24 Apr 2009 22\:39\:51 +0100") References: <49F0A35C.2090601@memetic.org> <70A241CE-55C2-43CA-B0DD-0D009A0CD971@dsinn.com> <49F231A7.40405@memetic.org> Message-ID: Adam Armstrong writes: > I have heard it said that more than 512 VRFs is crazy. more than 1024 > *INSANE*. Why? You want as many customers one one box as possible, to keep costs and maintenance down. Having an array of PE's at 1/100th of capacity just because they're limited to 512 VRFs is crazy. /Benny From chris at chrisserafin.com Sat Apr 25 18:01:51 2009 From: chris at chrisserafin.com (ChrisSerafin) Date: Sat, 25 Apr 2009 17:01:51 -0500 Subject: [c-nsp] Worst case: Compromised Internet router? Message-ID: <49F3884F.9010208@chrisserafin.com> So I'm trying ot lock down and Internet router and I had a few thoughts pop in my head...of what is the worst thing that could happen, other than someone bricking the device and locking ligit users out of the router? Here are some questions I thought of.....let me know what you think.... * If the device doesn't have any private IP's on it....I can't create a remote VPN client connection to it and then login to the network. How could I capture/sniff traffic to a .pcap in this scenario? I would like to do this besides redirecting traffic over GRE tunnels to a different router I have, just to sniff.....this scenario sounds good, but I assume would interrupt traffic to the point I would notice it and take action in a 24/7 NOC Thanks..... From jared at puck.nether.net Sat Apr 25 18:31:52 2009 From: jared at puck.nether.net (Jared Mauch) Date: Sat, 25 Apr 2009 18:31:52 -0400 Subject: [c-nsp] Worst case: Compromised Internet router? In-Reply-To: <49F3884F.9010208@chrisserafin.com> References: <49F3884F.9010208@chrisserafin.com> Message-ID: <18569BD4-13A2-4E02-94C5-581870CF2BDA@puck.nether.net> What if they set up lawful intercept on the device? That could relay all your packets without visible configuration, or just the "interesting" ones. As with any device, you want to insure it's integrity of both configuration and image running is important. I suggest rancid or something else to help audit these items. Jared Mauch On Apr 25, 2009, at 6:01 PM, ChrisSerafin wrote: > So I'm trying ot lock down and Internet router and I had a few > thoughts pop in my head...of what is the worst thing that could > happen, other than someone bricking the device and locking ligit > users out of the router? Here are some questions I thought > of.....let me know what you think.... > > * If the device doesn't have any private IP's on it....I can't > create a remote VPN client connection to it and then login to the > network. How could I capture/sniff traffic to a .pcap in this > scenario? I would like to do this besides redirecting traffic over > GRE tunnels to a different router I have, just to sniff.....this > scenario sounds good, but I assume would interrupt traffic to the > point I would notice it and take action in a 24/7 NOC > > Thanks..... > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From scott at labyrinth.org Sat Apr 25 19:26:25 2009 From: scott at labyrinth.org (Scott Keoseyan) Date: Sat, 25 Apr 2009 19:26:25 -0400 Subject: [c-nsp] Worst case: Compromised Internet router? In-Reply-To: <18569BD4-13A2-4E02-94C5-581870CF2BDA@puck.nether.net> References: <49F3884F.9010208@chrisserafin.com> <18569BD4-13A2-4E02-94C5-581870CF2BDA@puck.nether.net> Message-ID: <7412D61D-D185-4CB3-8E6A-95D41286E4D7@labyrinth.org> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Worst-case is a lot worse than simply crashing the router. Have a look at: http://www.phenoelit-us.org/stuff/FX_Phenoelit_25c3_Cisco_IOS.pdf http://hsdailywire.com/single.php?id=6728 Scott On Apr 25, 2009, at 6:31 PM, Jared Mauch wrote: > What if they set up lawful intercept on the device? That could relay > all your packets without visible configuration, or just the > "interesting" ones. > > As with any device, you want to insure it's integrity of both > configuration and image running is important. I suggest rancid or > something else to help audit these items. > > Jared Mauch > > On Apr 25, 2009, at 6:01 PM, ChrisSerafin > wrote: > >> So I'm trying ot lock down and Internet router and I had a few >> thoughts pop in my head...of what is the worst thing that could >> happen, other than someone bricking the device and locking ligit >> users out of the router? Here are some questions I thought >> of.....let me know what you think.... >> >> * If the device doesn't have any private IP's on it....I can't >> create a remote VPN client connection to it and then login to the >> network. How could I capture/sniff traffic to a .pcap in this >> scenario? I would like to do this besides redirecting traffic over >> GRE tunnels to a different router I have, just to sniff.....this >> scenario sounds good, but I assume would interrupt traffic to the >> point I would notice it and take action in a 24/7 NOC >> >> Thanks..... >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ - -- Scott A. Keoseyan +17047711656 Homepage - http://www.labyrinth.org/homepages/scott Blog - http://www.labyrinth.org/wp1 PGP Key - http://www.labyrinth.org/homepages/scott/pgp.html -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.8 (Darwin) iEYEARECAAYFAknznCEACgkQA7TpMPAlvEctQQCfWq4GyqsAfJHyigHmJLzytDVN jzQAnA4u5bPKtO81CyaYIP3T6nK5i+MO =Y4YB -----END PGP SIGNATURE----- From john at vocus.com.au Sat Apr 25 21:24:04 2009 From: john at vocus.com.au (John Edwards) Date: Sun, 26 Apr 2009 11:24:04 +1000 Subject: [c-nsp] Worst case: Compromised Internet router? In-Reply-To: <18569BD4-13A2-4E02-94C5-581870CF2BDA@puck.nether.net> References: <49F3884F.9010208@chrisserafin.com> <18569BD4-13A2-4E02-94C5-581870CF2BDA@puck.nether.net> Message-ID: On 26/04/2009, at 8:31 AM, Jared Mauch wrote: > What if they set up lawful intercept on the device? That could relay > all your packets without visible configuration, or just the > "interesting" ones. With routers now shipping that have 80Gb hard disks, one wonders whether relaying is now even necessary for an intruder. They can potentially capture data locally, and analyze on the router itself rather than risk detection by relaying large volumes of data to a server. John Edwards From william.mccall at gmail.com Sat Apr 25 23:57:15 2009 From: william.mccall at gmail.com (William McCall) Date: Sat, 25 Apr 2009 22:57:15 -0500 Subject: [c-nsp] Worst case: Compromised Internet router? In-Reply-To: References: <49F3884F.9010208@chrisserafin.com> <18569BD4-13A2-4E02-94C5-581870CF2BDA@puck.nether.net> Message-ID: On Sat, Apr 25, 2009 at 8:24 PM, John Edwards wrote: > On 26/04/2009, at 8:31 AM, Jared Mauch wrote: > > What if they set up lawful intercept on the device? That could relay all >> your packets without visible configuration, or just the "interesting" ones. >> > > What about this one: Spammer has a fat pipe, but IRL, their IPs get blacklisted pretty quickly. What about a compromised box being used with a tunnel (GRE or L2TP) to utilize your compromised box and related IP space for the funness? I recently had a discussion with a spammer who has wondered why the spam industry hasn't turned to this as a solution. He said that after running a scan of about /16 worth of machines, he found over 1000 Cisco routers with cisco/cisco for u/p. Now, he is a legitimate person (relative to the spam world), but the nefarious type could certainly exploit it for whatever benefit they saw fit. The possibilities are endless for a compromised router. With the TCL interpreter, you could even turn compromised routers into small botnets. When you ask yourself "what can a compromised router do?" ask yourself "What can a compromised host do with small disk space and limited processing power?" Some routers are beefier than others, but the majority... eh, not so much. From cooleyr at gmail.com Sun Apr 26 00:27:18 2009 From: cooleyr at gmail.com (RC) Date: Sat, 25 Apr 2009 21:27:18 -0700 Subject: [c-nsp] Worst case: Compromised Internet router? In-Reply-To: References: <49F3884F.9010208@chrisserafin.com> <18569BD4-13A2-4E02-94C5-581870CF2BDA@puck.nether.net> Message-ID: <20090425212718.14e0f790.cooleyr@gmail.com> On Sat, 25 Apr 2009 22:57:15 -0500 William McCall wrote: > He said that after running a scan of about /16 worth of machines, he > found over 1000 Cisco routers with cisco/cisco for u/p. The problem with these figures is that you are assuming there are no honeypots in the world... From william.mccall at gmail.com Sun Apr 26 00:38:14 2009 From: william.mccall at gmail.com (William McCall) Date: Sat, 25 Apr 2009 23:38:14 -0500 Subject: [c-nsp] Worst case: Compromised Internet router? In-Reply-To: <20090425212718.14e0f790.cooleyr@gmail.com> References: <49F3884F.9010208@chrisserafin.com> <18569BD4-13A2-4E02-94C5-581870CF2BDA@puck.nether.net> <20090425212718.14e0f790.cooleyr@gmail.com> Message-ID: On Sat, Apr 25, 2009 at 11:27 PM, RC wrote: > > > The problem with these figures is that you are assuming there are no > honeypots in the world... > > Sure there are. But how many of these are just because someone is too lazy/incompetent to lock down a router? Especially in our favorite Asia Pacific / Eastern European countries? Most people don't even know what the term 'honeypot' means. Out of that 1000 or so, maybe 15 would be honeypots. In real life, people are just kind of simple. You know.. like your neighbor with the "linksys" SSID on his AP and no crypto turned on... because it just works! From avayner at cisco.com Sun Apr 26 03:49:10 2009 From: avayner at cisco.com (Arie Vayner (avayner)) Date: Sun, 26 Apr 2009 09:49:10 +0200 Subject: [c-nsp] Forcing all HSRP interfaces to failover In-Reply-To: <49F1A2D3.9060209@imperial.ac.uk> References: <20090424110443.GA26907@kallisti.us> <49F1A2D3.9060209@imperial.ac.uk> Message-ID: <78C984F8939D424697B15E4B1C1BB3D78D47CC@xmb-ams-331.emea.cisco.com> Another nice thing for large scale HSRP is to have a master HSRP group, and have the others track the master's state (removing the need to process all those keepalives). If you look here: http://www.cisco.com/en/US/docs/ios/ipapp/command/reference/iap_s3.html# wp1062861 You would notice the "standby track group-number" option, which tracks another group's status, and mimics it's operational status. This is very useful when you have a very symmetric topology for many groups. Arie -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Phil Mayers Sent: Friday, April 24, 2009 14:30 To: Ross Vandegrift Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] Forcing all HSRP interfaces to failover Ross Vandegrift wrote: > Hi everyone, > > Is there any good way to have IOS abdicate the active status on all of > its HSRP interfaces? Of course I could change each of a few thousand > SVIs, but I'd like a better way. > > The only thing I can come up with is to create an unnumbered loopback > just to use as a tracking target. Admin down that interface when you > want to take down one of the routers for maintenance. What platform/IOS? Under later IOS e.g. SXH/SXI on 6500 you can track the tracking "objects". We do this: track 10 interface Vlan4000 ip routing track 11 interface Vlan4001 ip routing track 100 stub-object default-state up track 101 list boolean or object 10 object 11 int VlanXX standby 0 track 100 decrement 4 standby 0 track 101 decrement 4 standby 0 preempt delay reload 180 ...and then do: conf t track 100 default-state down ...or use an EEM script to put the tracking object "down". Obviously the EEM script opens up a load more possibilities. Note you can also do this: int VlanXX standby 0 track 100 shutdown ...which will shutdown the HSRP group, but you'll then have to wait for the timers to expire - I prefer the priority decrement with appropriate pre-empt statements on the standby/master. Some versions of IOS have HSRP "follow groups": http://www.cisco.com/en/US/docs/ios/ipapp/configuration/guide/ipapp_hsrp .html#wp1055821 ...but on the switch platforms e.g. 6500 this seems to work with sub-ints only, not SVIs. Sigh. _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From ross at kallisti.us Sun Apr 26 10:37:33 2009 From: ross at kallisti.us (Ross Vandegrift) Date: Sun, 26 Apr 2009 10:37:33 -0400 Subject: [c-nsp] Forcing all HSRP interfaces to failover In-Reply-To: <78C984F8939D424697B15E4B1C1BB3D78D47CC@xmb-ams-331.emea.cisco.com> References: <20090424110443.GA26907@kallisti.us> <49F1A2D3.9060209@imperial.ac.uk> <78C984F8939D424697B15E4B1C1BB3D78D47CC@xmb-ams-331.emea.cisco.com> Message-ID: <20090426143733.GA8237@kallisti.us> On Sun, Apr 26, 2009 at 09:49:10AM +0200, Arie Vayner (avayner) wrote: > Another nice thing for large scale HSRP is to have a master HSRP group, > and have the others track the master's state (removing the need to > process all those keepalives). > > If you look here: > http://www.cisco.com/en/US/docs/ios/ipapp/command/reference/iap_s3.html# > wp1062861 > > You would notice the "standby track group-number" option, which tracks > another group's status, and mimics it's operational status. > This is very useful when you have a very symmetric topology for many > groups. Does that really prevent the tracking group from processing keepalives? Phil's link to HSRP follow groups clearly documents that it does, while the above link kinda just says it makes a tracked object to monitor the status of another group. Either way, it's probably a moot point for now since I'm stuck on SXF and neither feature appears in my "standby track ..." options. Ross -- Ross Vandegrift ross at kallisti.us "If the fight gets hot, the songs get hotter. If the going gets tough, the songs get tougher." --Woody Guthrie From paul at paulstewart.org Sun Apr 26 11:17:22 2009 From: paul at paulstewart.org (Paul Stewart) Date: Sun, 26 Apr 2009 11:17:22 -0400 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade Message-ID: <001e01c9c682$19fe15a0$4dfa40e0$@org> Hi there. We have several WS-C2950G-24-EI switches (AC and DC versions) running.. Most of them are running 12.1(13)EA1 code and we'd like to upgrade into 12.1(22)EA13 with crypto. These switches have 8 meg flash and 8 meg DRAM today - upgrade in software requires 8 meg flash and 16 meg DRAM. Has anyone done a memory upgrade on these? Is it just a matter of cracking the case and putting a DIMM module in? I'm just trying to understand if anyone has done this and any surprises they might have encountered - these switches are in remote locations that involve many hours of driving to reach.. rather only do the drive once ;) Searched Google and Cisco.com and come up pretty empty - do most people just replace these switches? I hate to go that route if some additional memory can just be popped in... Thanks in advance, Paul From paul at paulstewart.org Sun Apr 26 12:09:44 2009 From: paul at paulstewart.org (Paul Stewart) Date: Sun, 26 Apr 2009 12:09:44 -0400 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade In-Reply-To: References: <001e01c9c682$19fe15a0$4dfa40e0$@org> Message-ID: <002301c9c689$6b2f7020$418e5060$@org> Thanks Jason... That's a shame that Cisco put a product out that isn't upgradable but their newest software releases require additional memory (referring to the 2950's that we have). Can anyone else confirm this is true and/or make suggestions? Best regards, Paul -----Original Message----- From: Jason Link [mailto:Jason.Link at whgroup.com] Sent: April 26, 2009 11:50 AM To: Paul Stewart; Cisco-nsp Subject: RE: [c-nsp] WS-C2950G-24-EI memory upgrade I don't believe the 2950's are memory-upgradable. At least the 2950T-24 and 2950-24 I've got sitting here aren't... -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Paul Stewart Sent: Sunday, April 26, 2009 10:17 AM To: 'Cisco-nsp' Subject: [c-nsp] WS-C2950G-24-EI memory upgrade Hi there. We have several WS-C2950G-24-EI switches (AC and DC versions) running.. Most of them are running 12.1(13)EA1 code and we'd like to upgrade into 12.1(22)EA13 with crypto. These switches have 8 meg flash and 8 meg DRAM today - upgrade in software requires 8 meg flash and 16 meg DRAM. Has anyone done a memory upgrade on these? Is it just a matter of cracking the case and putting a DIMM module in? I'm just trying to understand if anyone has done this and any surprises they might have encountered - these switches are in remote locations that involve many hours of driving to reach.. rather only do the drive once ;) Searched Google and Cisco.com and come up pretty empty - do most people just replace these switches? I hate to go that route if some additional memory can just be popped in... Thanks in advance, Paul _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From lukasz at bromirski.net Sun Apr 26 12:15:05 2009 From: lukasz at bromirski.net (=?ISO-8859-2?Q?=A3ukasz_Bromirski?=) Date: Sun, 26 Apr 2009 18:15:05 +0200 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade In-Reply-To: <001e01c9c682$19fe15a0$4dfa40e0$@org> References: <001e01c9c682$19fe15a0$4dfa40e0$@org> Message-ID: <49F48889.1050401@bromirski.net> On 2009-04-26 17:17, Paul Stewart wrote: > We have several WS-C2950G-24-EI switches (AC and DC versions) > running.. Most of them are running 12.1(13)EA1 code and we'd like to > upgrade into 12.1(22)EA13 with crypto. > These switches have 8 meg flash and 8 meg DRAM today - upgrade in > software requires 8 meg flash and 16 meg DRAM. Has anyone done a > memory upgrade on these? Is it just a matter of cracking the case > and putting a DIMM module in? The fixed line of Catalyst switches doesn't support upgrading memory - both RAM and flash. When you look at the motherboard - everything is fixed to it, no slots to change/upgrade anything. The IOS you're trying to download to the 2950G should boot just fine, as all 2950 were shipped with maxed out memory config, and there was no IOS needing any kind of upgrade (as it was not field doable). -- "Don't expect me to cry for all the | ?ukasz Bromirski reasons you had to die" -- Kurt Cobain | http://lukasz.bromirski.net From paul at paulstewart.org Sun Apr 26 12:25:59 2009 From: paul at paulstewart.org (Paul Stewart) Date: Sun, 26 Apr 2009 12:25:59 -0400 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade In-Reply-To: <49F48889.1050401@bromirski.net> References: <001e01c9c682$19fe15a0$4dfa40e0$@org> <49F48889.1050401@bromirski.net> Message-ID: <002401c9c68b$b16bde00$14439a00$@org> Thank you - so I have to ask what might seem like a dumb question ;) Why would Cisco put out an image and claim it requires 16 meg of SDRAM if all/some of the 2950's don't have it? Is this just a blunder from Cisco possibly? I checked a number of our other 2950's and none of them have more than 8 meg SDRAM but they are all 2950T's - we don't have any other 2950G series to verify.... Take care, Paul -----Original Message----- From: ?ukasz Bromirski [mailto:lukasz at bromirski.net] Sent: April 26, 2009 12:15 PM To: Paul Stewart Cc: 'Cisco-nsp' Subject: Re: [c-nsp] WS-C2950G-24-EI memory upgrade On 2009-04-26 17:17, Paul Stewart wrote: > We have several WS-C2950G-24-EI switches (AC and DC versions) > running.. Most of them are running 12.1(13)EA1 code and we'd like to > upgrade into 12.1(22)EA13 with crypto. > These switches have 8 meg flash and 8 meg DRAM today - upgrade in > software requires 8 meg flash and 16 meg DRAM. Has anyone done a > memory upgrade on these? Is it just a matter of cracking the case > and putting a DIMM module in? The fixed line of Catalyst switches doesn't support upgrading memory - both RAM and flash. When you look at the motherboard - everything is fixed to it, no slots to change/upgrade anything. The IOS you're trying to download to the 2950G should boot just fine, as all 2950 were shipped with maxed out memory config, and there was no IOS needing any kind of upgrade (as it was not field doable). -- "Don't expect me to cry for all the | ?ukasz Bromirski reasons you had to die" -- Kurt Cobain | http://lukasz.bromirski.net From Jason.Link at whgroup.com Sun Apr 26 12:17:15 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Sun, 26 Apr 2009 11:17:15 -0500 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade In-Reply-To: <002301c9c689$6b2f7020$418e5060$@org> References: <001e01c9c682$19fe15a0$4dfa40e0$@org> <002301c9c689$6b2f7020$418e5060$@org> Message-ID: This might be a silly question, but are you certain you only have 8MB ram? Everything I see online shows that switch to have 16MB. I do know that Cisco used to have switches that came with 8 initially and were later released with 16 - but that was back in the days of the 2924s. -----Original Message----- From: Paul Stewart [mailto:paul at paulstewart.org] Sent: Sunday, April 26, 2009 11:10 AM To: Jason Link; 'Cisco-nsp' Subject: RE: [c-nsp] WS-C2950G-24-EI memory upgrade Thanks Jason... That's a shame that Cisco put a product out that isn't upgradable but their newest software releases require additional memory (referring to the 2950's that we have). Can anyone else confirm this is true and/or make suggestions? Best regards, Paul -----Original Message----- From: Jason Link [mailto:Jason.Link at whgroup.com] Sent: April 26, 2009 11:50 AM To: Paul Stewart; Cisco-nsp Subject: RE: [c-nsp] WS-C2950G-24-EI memory upgrade I don't believe the 2950's are memory-upgradable. At least the 2950T-24 and 2950-24 I've got sitting here aren't... -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Paul Stewart Sent: Sunday, April 26, 2009 10:17 AM To: 'Cisco-nsp' Subject: [c-nsp] WS-C2950G-24-EI memory upgrade Hi there. We have several WS-C2950G-24-EI switches (AC and DC versions) running.. Most of them are running 12.1(13)EA1 code and we'd like to upgrade into 12.1(22)EA13 with crypto. These switches have 8 meg flash and 8 meg DRAM today - upgrade in software requires 8 meg flash and 16 meg DRAM. Has anyone done a memory upgrade on these? Is it just a matter of cracking the case and putting a DIMM module in? I'm just trying to understand if anyone has done this and any surprises they might have encountered - these switches are in remote locations that involve many hours of driving to reach.. rather only do the drive once ;) Searched Google and Cisco.com and come up pretty empty - do most people just replace these switches? I hate to go that route if some additional memory can just be popped in... Thanks in advance, Paul _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From Jason.Link at whgroup.com Sun Apr 26 11:49:38 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Sun, 26 Apr 2009 10:49:38 -0500 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade In-Reply-To: <001e01c9c682$19fe15a0$4dfa40e0$@org> References: <001e01c9c682$19fe15a0$4dfa40e0$@org> Message-ID: I don't believe the 2950's are memory-upgradable. At least the 2950T-24 and 2950-24 I've got sitting here aren't... -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Paul Stewart Sent: Sunday, April 26, 2009 10:17 AM To: 'Cisco-nsp' Subject: [c-nsp] WS-C2950G-24-EI memory upgrade Hi there. We have several WS-C2950G-24-EI switches (AC and DC versions) running.. Most of them are running 12.1(13)EA1 code and we'd like to upgrade into 12.1(22)EA13 with crypto. These switches have 8 meg flash and 8 meg DRAM today - upgrade in software requires 8 meg flash and 16 meg DRAM. Has anyone done a memory upgrade on these? Is it just a matter of cracking the case and putting a DIMM module in? I'm just trying to understand if anyone has done this and any surprises they might have encountered - these switches are in remote locations that involve many hours of driving to reach.. rather only do the drive once ;) Searched Google and Cisco.com and come up pretty empty - do most people just replace these switches? I hate to go that route if some additional memory can just be popped in... Thanks in advance, Paul _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From paul at paulstewart.org Sun Apr 26 12:36:06 2009 From: paul at paulstewart.org (Paul Stewart) Date: Sun, 26 Apr 2009 12:36:06 -0400 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade In-Reply-To: References: <001e01c9c682$19fe15a0$4dfa40e0$@org> <002301c9c689$6b2f7020$418e5060$@org> Message-ID: <002501c9c68d$197fbce0$4c7f36a0$@org> Wow.. do I feel like an $ss....;) I was looking at "sh proc mem" and didn't account for the other memory.....duh! My apologies - these switches all have 20 meg of RAM it appears: Cisco Internetwork Operating System Software IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(13)EA1, RELEASE SOFTWARE (fc1) Copyright (c) 1986-2003 by cisco Systems, Inc. Compiled Tue 04-Mar-03 02:14 by yenanh Image text-base: 0x80010000, data-base: 0x805A8000 ROM: Bootstrap program is CALHOUN boot loader dis1-swt-kn uptime is 34 weeks, 3 days, 20 hours, 17 minutes System returned to ROM by power-on System restarted at 16:11:12 EDT Wed Aug 27 2008 System image file is "flash:/c2950-i6q4l2-mz.121-13.EA1.bin" cisco WS-C2950G-24-EI (RC32300) processor (revision G0) with 20839K bytes of memory. Sorry again.... appreciate the response... Paul -----Original Message----- From: Jason Link [mailto:Jason.Link at whgroup.com] Sent: April 26, 2009 12:17 PM To: Paul Stewart; Cisco-nsp Subject: RE: [c-nsp] WS-C2950G-24-EI memory upgrade This might be a silly question, but are you certain you only have 8MB ram? Everything I see online shows that switch to have 16MB. I do know that Cisco used to have switches that came with 8 initially and were later released with 16 - but that was back in the days of the 2924s. -----Original Message----- From: Paul Stewart [mailto:paul at paulstewart.org] Sent: Sunday, April 26, 2009 11:10 AM To: Jason Link; 'Cisco-nsp' Subject: RE: [c-nsp] WS-C2950G-24-EI memory upgrade Thanks Jason... That's a shame that Cisco put a product out that isn't upgradable but their newest software releases require additional memory (referring to the 2950's that we have). Can anyone else confirm this is true and/or make suggestions? Best regards, Paul -----Original Message----- From: Jason Link [mailto:Jason.Link at whgroup.com] Sent: April 26, 2009 11:50 AM To: Paul Stewart; Cisco-nsp Subject: RE: [c-nsp] WS-C2950G-24-EI memory upgrade I don't believe the 2950's are memory-upgradable. At least the 2950T-24 and 2950-24 I've got sitting here aren't... -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Paul Stewart Sent: Sunday, April 26, 2009 10:17 AM To: 'Cisco-nsp' Subject: [c-nsp] WS-C2950G-24-EI memory upgrade Hi there. We have several WS-C2950G-24-EI switches (AC and DC versions) running.. Most of them are running 12.1(13)EA1 code and we'd like to upgrade into 12.1(22)EA13 with crypto. These switches have 8 meg flash and 8 meg DRAM today - upgrade in software requires 8 meg flash and 16 meg DRAM. Has anyone done a memory upgrade on these? Is it just a matter of cracking the case and putting a DIMM module in? I'm just trying to understand if anyone has done this and any surprises they might have encountered - these switches are in remote locations that involve many hours of driving to reach.. rather only do the drive once ;) Searched Google and Cisco.com and come up pretty empty - do most people just replace these switches? I hate to go that route if some additional memory can just be popped in... Thanks in advance, Paul _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From merlyn at Geeks.ORG Sun Apr 26 14:42:39 2009 From: merlyn at Geeks.ORG (Doug McIntyre) Date: Sun, 26 Apr 2009 13:42:39 -0500 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade In-Reply-To: References: <001e01c9c682$19fe15a0$4dfa40e0$@org> <002301c9c689$6b2f7020$418e5060$@org> Message-ID: <20090426184239.GA39447@geeks.org> On Sun, Apr 26, 2009 at 11:17:15AM -0500, Jason Link wrote: > This might be a silly question, but are you certain you only have 8MB > ram? Everything I see online shows that switch to have 16MB. I do know > that Cisco used to have switches that came with 8 initially and were > later released with 16 - but that was back in the days of the 2924s. That was 4M (for ws-c2924-xx) and 8M (for ws-c2924xl-xx). At least the physical size of the box changed from a 2924 to a 2924xl and the color was different, with different part #s. Cisco has been known to silently upgrade products for memory as well, and only the new hardware rev will run the newest code. Ie. I have an 837 that doesn't have any RAM on the motherboard, and a max DIMM size of 32M. Later on, they updated the data sheet, silently put out 837's with some RAM soldered on, and the latest (as of 12.3T somewhere) images for it require something like 48M of DRAM now, something my 837 hardware can't do, even if I put a 64M stick of RAM in it. But thankfully, that doesn't happen often, and certainly not on the fixed catalyst which is all soldered on RAM, no HW upgrades at all on them. From Jason.Link at whgroup.com Sun Apr 26 16:07:14 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Sun, 26 Apr 2009 15:07:14 -0500 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade Message-ID: <006501c9c6aa$91933941$0600a8c0@whgroup.com> Ah yes...it was 4m and 8m...I believe that if you had the 8m could do dot1Q or something similar... -----Original Message----- From: Doug McIntyre Sent: Sunday, April 26, 2009 1:42 PM To: Jason Link Cc: Paul Stewart ; Cisco-nsp Subject: Re: [c-nsp] WS-C2950G-24-EI memory upgrade On Sun, Apr 26, 2009 at 11:17:15AM -0500, Jason Link wrote: > This might be a silly question, but are you certain you only have 8MB > ram? Everything I see online shows that switch to have 16MB. I do know > that Cisco used to have switches that came with 8 initially and were > later released with 16 - but that was back in the days of the 2924s. That was 4M (for ws-c2924-xx) and 8M (for ws-c2924xl-xx). At least the physical size of the box changed from a 2924 to a 2924xl and the color was different, with different part #s. Cisco has been known to silently upgrade products for memory as well, and only the new hardware rev will run the newest code. Ie. I have an 837 that doesn't have any RAM on the motherboard, and a max DIMM size of 32M. Later on, they updated the data sheet, silently put out 837's with some RAM soldered on, and the latest (as of 12.3T somewhere) images for it require something like 48M of DRAM now, something my 837 hardware can't do, even if I put a 64M stick of RAM in it. But thankfully, that doesn't happen often, and certainly not on the fixed catalyst which is all soldered on RAM, no HW upgrades at all on them. From pshem.k at gmail.com Sun Apr 26 16:07:20 2009 From: pshem.k at gmail.com (Pshem Kowalczyk) Date: Mon, 27 Apr 2009 08:07:20 +1200 Subject: [c-nsp] Problems with multiple VPDN hops In-Reply-To: <1C15FB264A06794F8BDE2120972B51C1050E2821@netexch04.ad.netservicesplc.com> References: <1C15FB264A06794F8BDE2120972B51C1050E280A@netexch04.ad.netservicesplc.com> <20fe625b0904231640x33624e1bx7862e69088a8bc2d@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2821@netexch04.ad.netservicesplc.com> Message-ID: <20fe625b0904261307m776ac158u7f54408868afbd07@mail.gmail.com> Hi, {cut} > Based on this information, do you have any further suggestions and are > you able to supply example configs of your own setup? Please see here - both LTS in our example have exactly the same vpdn config: vpdn-group L2TP-wholesale ! Default L2TP VPDN group accept-dialin protocol l2tp vpn vrf InternalL2TP local name akl-mdr-lts1 lcp renegotiation always l2tp tunnel hello 300 l2tp tunnel password 0 xxxxxxxxxxxxxxxx l2tp tunnel timeout no-session 1800 l2tp tunnel retransmit retries 7 l2tp tunnel retransmit timeout min 2 l2tp tunnel retransmit timeout max 5 and corresponding radius config: DEFAULT Service-Type == Outbound-User, User-Name =~ "^host:", NAS-Identifier =~ "^akl-mdr-lts1", Auth-Type := Accept Cisco-AVPair += "vpdn:ip-addresses=10.119.255.93/10.119.255.92", Cisco-AVPair += "vpdn:tunnel-type=l2tp", Cisco-AVPair += "vpdn:vpn-vrf=InternalL2TP", Cisco-AVPair += "vpdn:l2tp-tunnel-password=xxxxxxxxxxxxxxxx" (the second layer of LTSes only differ in names and ip addresses) kind regards Pshem From lukasz at bromirski.net Sun Apr 26 16:41:20 2009 From: lukasz at bromirski.net (Lukasz Bromirski) Date: Sun, 26 Apr 2009 22:41:20 +0200 Subject: [c-nsp] WS-C2950G-24-EI memory upgrade In-Reply-To: <20090426184239.GA39447@geeks.org> References: <001e01c9c682$19fe15a0$4dfa40e0$@org> <002301c9c689$6b2f7020$418e5060$@org> <20090426184239.GA39447@geeks.org> Message-ID: <49F4C6F0.9090205@bromirski.net> On 2009-04-26 20:42, Doug McIntyre wrote: > That was 4M (for ws-c2924-xx) and 8M (for ws-c2924xl-xx). At least the > physical size of the box changed from a 2924 to a 2924xl and the color > was different, with different part #s. > > Cisco has been known to silently upgrade products for memory as well, Upgrading, yes. Silently - no. If you read the bulletins, of course. The one you're mentioning is here: http://www.cisco.com/en/US/prod/collateral/routers/ps380/prod_bulletin0900aecd80263d26.html -- "Don't expect me to cry for all the | ?ukasz Bromirski reasons you had to die" -- Kurt Cobain | http://lukasz.bromirski.net From john at vanoppen.com Sun Apr 26 16:13:05 2009 From: john at vanoppen.com (John van Oppen) Date: Sun, 26 Apr 2009 13:13:05 -0700 Subject: [c-nsp] 6500 sup720-3bxl crash Message-ID: Has anyone seen this reload cause before? Sounds like bad memory but the memory addresses are pretty non machine sounding some I am wondering if it is a software bug. Cache error detected! CPO_ECC (reg 26/0): 0x000000F3 CPO_CACHERI (reg 27/0): 0x84000000 CP0_CAUSE (reg 13/0): 0x00004400 Real cache error detected. System will be halted. Error: Primary data cache, fields: , 1st dword Actual physical addr 0x00000000, virtual address is imprecise. Imprecise Data Parity Error Software version is: s72033_sp-ADVIPSERVICESK9_WAN-M), Version 12.2(33)SXI, RELEASE SOFTWARE (fc2) Thanks, John From oles at ovh.net Sun Apr 26 17:23:44 2009 From: oles at ovh.net (oles at ovh.net) Date: Sun, 26 Apr 2009 23:23:44 +0200 Subject: [c-nsp] 6500 sup720-3bxl crash In-Reply-To: References: Message-ID: <20090426212344.GD23362@ovh.net> Hmmm ... same today morning !? Cache error detected! CPO_ECC (reg 26/0): 0x0000009F CPO_CACHERI (reg 27/0): 0xA0000000 CP0_CAUSE (reg 13/0): 0x00000800 Real cache error detected. System will be halted. Error: Primary data cache, fields: data, Actual physical addr 0x00000000, virtual address is imprecise. Imprecise Data Parity Error Imprecise Data Parity Error Interrupt exception, CPU signal 20, PC = 0x40E7BE6C ========= Start of Crashinfo Collection (07:05:17 GMT Sun Apr 26 2009) ========= IOS (tm) s72033_sp Software (s72033_sp-IPSERVICESK9-M), Version 12.2(18)SXF14, RELEASE SOFTWARE (fc1) On Sun, Apr 26, 2009 at 01:13:05PM -0700, John van Oppen wrote: > Has anyone seen this reload cause before? Sounds like bad memory but > the memory addresses are pretty non machine sounding some I am wondering > if it is a software bug. > > > Cache error detected! > CPO_ECC (reg 26/0): 0x000000F3 > CPO_CACHERI (reg 27/0): 0x84000000 > CP0_CAUSE (reg 13/0): 0x00004400 > > Real cache error detected. System will be halted. > > Error: Primary data cache, fields: , 1st dword > Actual physical addr 0x00000000, > virtual address is imprecise. > > Imprecise Data Parity Error > > > Software version is: s72033_sp-ADVIPSERVICESK9_WAN-M), Version > 12.2(33)SXI, RELEASE SOFTWARE (fc2) > > > Thanks, > John > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From Jason.Link at whgroup.com Sun Apr 26 19:15:24 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Sun, 26 Apr 2009 18:15:24 -0500 Subject: [c-nsp] DHCP Route Tracking in the 870 Series In-Reply-To: References: <001e01c9c682$19fe15a0$4dfa40e0$@org> Message-ID: Hello all, I've got a situation that requires tracking (and removing) the DHCP-added default-gateway route in an 877. In the documentation (http://www.cisco.com/en/US/tech/tk648/tk361/technologies_configuration_ example09186a00808d2b72.shtml) this is done via "ip route 0.0.0.0 0.0.0.0 dhcp track 123". When I try to enter the command as above, the "track" option is not available. I'm using the same version of IOS as the above example, with the exception that the hardware is an 877 and not an 1811. This leads me to believe the issue is related to the hardware, as in its not available on the 877. Am I missing something? Thanks! From eninja at gmail.com Sun Apr 26 19:25:14 2009 From: eninja at gmail.com (Eninja) Date: Mon, 27 Apr 2009 00:25:14 +0100 Subject: [c-nsp] 6500 sup720-3bxl crash In-Reply-To: <20090426212344.GD23362@ovh.net> References: <20090426212344.GD23362@ovh.net> Message-ID: <44B6BE5C-4D00-4B6B-B36E-7DA5DACA130E@gmail.com> Sig 20 = cache parity exception aka parity errors. Take no action for now and only replace mem/board should this recur within a 12-month window. In the meantime, ensure you follow proper ESD procedures when handling devices/modules/memory etc. Eninja On Apr 26, 2009, at 10:23 PM, oles at ovh.net wrote: > Hmmm ... same today morning !? > > Cache error detected! > CPO_ECC (reg 26/0): 0x0000009F > CPO_CACHERI (reg 27/0): 0xA0000000 > CP0_CAUSE (reg 13/0): 0x00000800 > > Real cache error detected. System will be halted. > > Error: Primary data cache, fields: data, > Actual physical addr 0x00000000, > virtual address is imprecise. > > Imprecise Data Parity Error > > Imprecise Data Parity Error > > Interrupt exception, CPU signal 20, PC = 0x40E7BE6C > > > ========= Start of Crashinfo Collection (07:05:17 GMT Sun Apr 26 > 2009) ========= > IOS (tm) s72033_sp Software (s72033_sp-IPSERVICESK9-M), Version > 12.2(18)SXF14, RELEASE SOFTWARE (fc1) > > > On Sun, Apr 26, 2009 at 01:13:05PM -0700, John van Oppen wrote: >> Has anyone seen this reload cause before? Sounds like bad memory >> but >> the memory addresses are pretty non machine sounding some I am >> wondering >> if it is a software bug. >> >> >> Cache error detected! >> CPO_ECC (reg 26/0): 0x000000F3 >> CPO_CACHERI (reg 27/0): 0x84000000 >> CP0_CAUSE (reg 13/0): 0x00004400 >> >> Real cache error detected. System will be halted. >> >> Error: Primary data cache, fields: , 1st dword >> Actual physical addr 0x00000000, >> virtual address is imprecise. >> >> Imprecise Data Parity Error >> >> >> Software version is: s72033_sp-ADVIPSERVICESK9_WAN-M), Version >> 12.2(33)SXI, RELEASE SOFTWARE (fc2) >> >> >> Thanks, >> John >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From David at Hughes.com.au Sun Apr 26 20:55:11 2009 From: David at Hughes.com.au (David Hughes) Date: Mon, 27 Apr 2009 10:55:11 +1000 Subject: [c-nsp] Question about Multiple Spanning Tee (MST) In-Reply-To: <56F211C5E3F24F47B103EA1B253822BE03654D39@vic-cr-ex1.staff.netspace.net.au> References: <56F211C5E3F24F47B103EA1B253822BE03654D39@vic-cr-ex1.staff.netspace.net.au> Message-ID: <64509F43-3B45-42B9-B809-EEBF6EE0A918@Hughes.com.au> Hi Andy, How is your PVST+ configured? Usually your STP configuration is based on your L2 topology. If you have a "normal" dual-uplinked access layer then you are probably "load balancing" your vlans over your uplinks on a per-vlan basis using root bridge priorities. If that's the sort of setup you are looking for then In MST mode there's really no reason to have more than 2 instances. Having more instances than you have paths to your root bridges will just result in multiple instances blocking on the same ports. If you have dual paths and run 2 instancess then you can "load balance" your vlans by mapping them into the 2 different instances. The granularity of your "load balancing" will depend on your traffic patterns. Something like the below can work well. Just swap the priorities on the second root switch. ---- spanning-tree mode mst ! spanning-tree mst configuration instance 1 vlan 1-49, 100-149, 200-249, 300-349, 400-449, 500-549, 600-649 instance 1 vlan 700-749, 800-849, 900-949, 1000-1049, 1100-1149, 1200-1249 instance 1 vlan 1300-1349, 1400-1449, 1500-1549, 1600-1649, 1700-1749 instance 1 vlan 1800-1849, 1900-1949 instance 2 vlan 50-99, 150-199, 250-299, 350-399, 450-499, 550-599, 650-699 instance 2 vlan 750-799, 850-899, 950-999, 1050-1099, 1150-1199, 1250-1299 instance 2 vlan 1350-1399, 1450-1499, 1550-1599, 1650-1699, 1750-1799 instance 2 vlan 1850-1899, 1950-1999 ! spanning-tree mst 0-1 priority 8192 spanning-tree mst 2 priority 16384 ---- David ... On 24/04/2009, at 12:58 PM, Andy Saykao wrote: > Hi All, > > Our switch network needs to be migrated from PVST+ to MST in order for > our Cisco switches to be able to speak RSTP to some non-cisco > switches. > Given that we have a few hundred vlans configured, is there some best > practice to determine how many instances we need or can we basically > do > whatever we want? > > For example: > > Option 1/ If we have 500 vlans, do we split them into two instances > (instance 1 vlan 1-250 and instance 2 vlan 251-500). > > Options2/ Or would you split the vlans up based on their business > requirements. > Eg: vlan 1,10,100 Marketing-related vlans, vlan 2,20,200 Sales-related > vlans - therefore create instance 1 vlan 1,10,100 and instance 2 vlan > 2,20,200??? > > Secondly, what if you went with option 2, and added a new vlan into > Marketing (eg: vlan 1000). Would you have to manually update the > spanning-tree mst config on all MST switches to include the new vlan > in > the instance??? > > Thanks. > > Andy > > > > This email and any files transmitted with it are confidential and > intended > solely for the use of the individual or entity to whom they are > addressed. > Please notify the sender immediately by email if you have received > this > email by mistake and delete this email from your system. Please note > that > any views or opinions presented in this email are solely those of the > author and do not necessarily represent those of the organisation. > Finally, the recipient should check this email and any attachments for > the presence of viruses. The organisation accepts no liability for any > damage caused by any virus transmitted by this email. > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From john at vanoppen.com Sun Apr 26 21:07:22 2009 From: john at vanoppen.com (John van Oppen) Date: Sun, 26 Apr 2009 18:07:22 -0700 Subject: [c-nsp] 6500 sup720-3bxl crash References: <20090426212344.GD23362@ovh.net> <44B6BE5C-4D00-4B6B-B36E-7DA5DACA130E@gmail.com> Message-ID: Ok, that is what I figured. I guess I could swap-in my spare sup, think it is worth bothering? John van Oppen Spectrum Networks LLC Direct: 206.973.8302 Main: 206.973.8300 Website: http://spectrumnetworks.us -----Original Message----- From: Eninja [mailto:eninja at gmail.com] Sent: Sunday, April 26, 2009 4:25 PM To: oles at ovh.net Cc: John van Oppen; cisco-nsp at puck.nether.net Subject: Re: [c-nsp] 6500 sup720-3bxl crash Sig 20 = cache parity exception aka parity errors. Take no action for now and only replace mem/board should this recur within a 12-month window. In the meantime, ensure you follow proper ESD procedures when handling devices/modules/memory etc. Eninja On Apr 26, 2009, at 10:23 PM, oles at ovh.net wrote: > Hmmm ... same today morning !? > > Cache error detected! > CPO_ECC (reg 26/0): 0x0000009F > CPO_CACHERI (reg 27/0): 0xA0000000 > CP0_CAUSE (reg 13/0): 0x00000800 > > Real cache error detected. System will be halted. > > Error: Primary data cache, fields: data, > Actual physical addr 0x00000000, > virtual address is imprecise. > > Imprecise Data Parity Error > > Imprecise Data Parity Error > > Interrupt exception, CPU signal 20, PC = 0x40E7BE6C > > > ========= Start of Crashinfo Collection (07:05:17 GMT Sun Apr 26 > 2009) ========= > IOS (tm) s72033_sp Software (s72033_sp-IPSERVICESK9-M), Version > 12.2(18)SXF14, RELEASE SOFTWARE (fc1) > > > On Sun, Apr 26, 2009 at 01:13:05PM -0700, John van Oppen wrote: >> Has anyone seen this reload cause before? Sounds like bad memory >> but >> the memory addresses are pretty non machine sounding some I am >> wondering >> if it is a software bug. >> >> >> Cache error detected! >> CPO_ECC (reg 26/0): 0x000000F3 >> CPO_CACHERI (reg 27/0): 0x84000000 >> CP0_CAUSE (reg 13/0): 0x00004400 >> >> Real cache error detected. System will be halted. >> >> Error: Primary data cache, fields: , 1st dword >> Actual physical addr 0x00000000, >> virtual address is imprecise. >> >> Imprecise Data Parity Error >> >> >> Software version is: s72033_sp-ADVIPSERVICESK9_WAN-M), Version >> 12.2(33)SXI, RELEASE SOFTWARE (fc2) >> >> >> Thanks, >> John >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From eng_mssk at hotmail.com Mon Apr 27 02:08:11 2009 From: eng_mssk at hotmail.com (Mohammad Khalil) Date: Mon, 27 Apr 2009 09:08:11 +0300 Subject: [c-nsp] DNS Stuff Message-ID: Hey all is there any way to know the number of DNS requests or hits on a specific DNS server (Via SNMP for example) can we darw this ? _________________________________________________________________ Show them the way! Add maps and directions to your party invites. http://www.microsoft.com/windows/windowslive/products/events.aspx From dale.shaw+cisco-nsp at gmail.com Mon Apr 27 02:19:46 2009 From: dale.shaw+cisco-nsp at gmail.com (Dale Shaw) Date: Mon, 27 Apr 2009 16:19:46 +1000 Subject: [c-nsp] DNS Stuff In-Reply-To: References: Message-ID: <3329cbb40904262319x1117ba6x833fbdfe72125e38@mail.gmail.com> Hi, On Mon, Apr 27, 2009 at 4:08 PM, Mohammad Khalil wrote: > > Hey all > is there any way to know the number of DNS requests or hits on a specific DNS server (Via SNMP for example) > can we darw this ? Are you asking if there's a way to track such requests by interrogating a router the requests are passing _through_? Or are you referring to a DNS server instance configured in IOS? Please elaborate on your scenario/requirement. cheers, Dale From jay at west.net Mon Apr 27 02:23:02 2009 From: jay at west.net (Jay Hennigan) Date: Sun, 26 Apr 2009 23:23:02 -0700 Subject: [c-nsp] DNS Stuff In-Reply-To: References: Message-ID: <49F54F46.8030303@west.net> Mohammad Khalil wrote: > Hey all > is there any way to know the number of DNS requests or hits on a specific DNS server (Via SNMP for example) > can we darw this ? From the server logs would be the obvious way. In the context of the c-nsp list, netflow is one possibility or count the hits on an extended access-list facing the server "permit udp any host w.x.y.z eq 53 log" (danger, potential cpu pig). -- Jay Hennigan - CCIE #7880 - Network Engineering - jay at impulse.net Impulse Internet Service - http://www.impulse.net/ Your local telephone and internet company - 805 884-6323 - WB6RDV From gaborivanszky at gmail.com Mon Apr 27 03:16:22 2009 From: gaborivanszky at gmail.com (Gabor Ivanszky) Date: Mon, 27 Apr 2009 09:16:22 +0200 Subject: [c-nsp] L2TPv3 "LNS mode" In-Reply-To: <10f693fd0903181158x763e38c6o9b85fc5afbf4f7f@mail.gmail.com> References: <10f693fd0903181057u631316cdgb3a58746183c1033@mail.gmail.com> <10f693fd0903181158x763e38c6o9b85fc5afbf4f7f@mail.gmail.com> Message-ID: <10f693fd0904270016t770c3e17w3d5c93f28f1beb1b@mail.gmail.com> Hi, I received some kind orientation from Cisco on this matter. This function is called "Routed Pseudowire Support", and is documented at http://www.cisco.com/en/US/docs/ios/12_2sr/release/notes/122SRrn.html regards, Gabor On Wed, Mar 18, 2009 at 8:58 PM, Gabor Ivanszky wrote: > Hello, > > is there any possibility to route(L3 process) Ethernet encapsulated IP > packets arriving at a Cisco router in a L2TPv3 tunnel? > > In other words, is it possible to configure a Cisco box in LNS role in > an Ethernet L2TPv3 setup? > > " L2TP Network Server (LNS) > > ? ? ?If a given L2TP session is terminated at the L2TP node and the > ? ? ?encapsulated network layer (L3) packet processed on a virtual > ? ? ?interface, we refer to this L2TP node as an L2TP Network Server" (RFC3931) > > Actually i'd like to implement ?"(a) LAC-LNS Reference Model: > > On one side, the LAC receives traffic > ? from an L2 circuit, which it forwards via L2TP across an IP or other > ? packet-based network. ?On the other side, an LNS logically terminates > ? the L2 circuit locally and routes network traffic to the home > ? network. ?The action of session establishment is driven by the LAC > ? (as an incoming call) or the LNS (as an outgoing call). > > ? ?+-----+ ?L2 ?+-----+ ? ? ? ? ? ? ? ? ? ? ? ?+-----+ > ? ?| ? ? |------| LAC |.........[ IP ].........| LNS |...[home network] > ? ?+-----+ ? ? ?+-----+ ? ? ? ? ? ? ? ? ? ? ? ?+-----+ > ? ?remote > ? ?system > ? ? ? ? ? ? ? ? ? ? ? |<-- emulated service -->| > ? ? ? ? ?|<----------- L2 service ------------>| "(RFC3931) > > Practically an Ethernet interface with an xconnect setting on "LAC" > side, and something like an IP tunnel interface on the "LNS" side. > > The obvious > > interface Tunnel1 > ?tunnel mode l2tpv3 > > doesn't exist. > > > cheers, > Gabor > From p.mayers at imperial.ac.uk Mon Apr 27 05:29:02 2009 From: p.mayers at imperial.ac.uk (Phil Mayers) Date: Mon, 27 Apr 2009 10:29:02 +0100 Subject: [c-nsp] 6500 sup720-3bxl crash In-Reply-To: References: <20090426212344.GD23362@ovh.net> <44B6BE5C-4D00-4B6B-B36E-7DA5DACA130E@gmail.com> Message-ID: <49F57ADE.2080909@imperial.ac.uk> John van Oppen wrote: > Ok, that is what I figured. I guess I could swap-in my spare sup, > think it is worth bothering? No - then you won't know if it's faulty. Leave it running, if it does it a second time get it RMAed. From avayner at cisco.com Mon Apr 27 06:53:31 2009 From: avayner at cisco.com (Arie Vayner (avayner)) Date: Mon, 27 Apr 2009 12:53:31 +0200 Subject: [c-nsp] L2TPv3 "LNS mode" In-Reply-To: <10f693fd0904270016t770c3e17w3d5c93f28f1beb1b@mail.gmail.com> References: <10f693fd0903181057u631316cdgb3a58746183c1033@mail.gmail.com><10f693fd0903181158x763e38c6o9b85fc5afbf4f7f@mail.gmail.com> <10f693fd0904270016t770c3e17w3d5c93f28f1beb1b@mail.gmail.com> Message-ID: <78C984F8939D424697B15E4B1C1BB3D78D4A4A@xmb-ams-331.emea.cisco.com> Gabor, Yes, this is the right way to make it work. You need to take into consideration that you are actually running a L2VPN pseudowire over L2TPv3, but the service is actually based on terminating the attachment circuit locally on the router using a L3 interface. This can also be done using regular L2VPN over MPLS, and L2TPv3 is just a substitute for the MPLS infrastructure, allowing to run MPLS-like services directly over an IP core. Arie -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Gabor Ivanszky Sent: Monday, April 27, 2009 10:16 To: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] L2TPv3 "LNS mode" Hi, I received some kind orientation from Cisco on this matter. This function is called "Routed Pseudowire Support", and is documented at http://www.cisco.com/en/US/docs/ios/12_2sr/release/notes/122SRrn.html regards, Gabor On Wed, Mar 18, 2009 at 8:58 PM, Gabor Ivanszky wrote: > Hello, > > is there any possibility to route(L3 process) Ethernet encapsulated IP > packets arriving at a Cisco router in a L2TPv3 tunnel? > > In other words, is it possible to configure a Cisco box in LNS role in > an Ethernet L2TPv3 setup? > > " L2TP Network Server (LNS) > > ? ? ?If a given L2TP session is terminated at the L2TP node and the > ? ? ?encapsulated network layer (L3) packet processed on a virtual > ? ? ?interface, we refer to this L2TP node as an L2TP Network Server" (RFC3931) > > Actually i'd like to implement ?"(a) LAC-LNS Reference Model: > > On one side, the LAC receives traffic > ? from an L2 circuit, which it forwards via L2TP across an IP or other > ? packet-based network. ?On the other side, an LNS logically terminates > ? the L2 circuit locally and routes network traffic to the home > ? network. ?The action of session establishment is driven by the LAC > ? (as an incoming call) or the LNS (as an outgoing call). > > ? ?+-----+ ?L2 ?+-----+ ? ? ? ? ? ? ? ? ? ? ? ?+-----+ > ? ?| ? ? |------| LAC |.........[ IP ].........| LNS |...[home network] > ? ?+-----+ ? ? ?+-----+ ? ? ? ? ? ? ? ? ? ? ? ?+-----+ > ? ?remote > ? ?system > ? ? ? ? ? ? ? ? ? ? ? |<-- emulated service -->| > ? ? ? ? ?|<----------- L2 service ------------>| "(RFC3931) > > Practically an Ethernet interface with an xconnect setting on "LAC" > side, and something like an IP tunnel interface on the "LNS" side. > > The obvious > > interface Tunnel1 > ?tunnel mode l2tpv3 > > doesn't exist. > > > cheers, > Gabor > _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From Anton.Schweitzer at o2.com Mon Apr 27 07:06:36 2009 From: Anton.Schweitzer at o2.com (Anton.Schweitzer at o2.com) Date: Mon, 27 Apr 2009 13:06:36 +0200 Subject: [c-nsp] IP Sla + Track does not trigger EEM applet Message-ID: Hi, i set up a configuration to reset an IPSEC Tunnel : track 1 ip sla 1 reachability delay down 60 up 30 ip sla 1 icmp-echo 1.1.1.1 source-interface Loopback13 ip sla schedule 1 life forever start-time now event manager applet Reset_IPsec_Tunnel event none action 1.0 cli command "ena" action 2.0 comment "clear crypto ipsec client ezvpn" event manager applet IPSec_Tunnel_Down event track 1 state down action 1.0 comment "en" action 2.0 comment "event manager run Reset_IPsec_Tunnel" action 3.0 comment "conf term" action 4.0 comment "event manager applet Reset_IPsec_Tunnel" action 5.0 comment "event timer watchdog time 360" action 6.0 comment "end" event manager applet IPSec_Tunnel_UP event track 1 state up action 1.0 comment "en" action 2.0 comment "conf term" action 3.0 comment "event manager applet Reset_IPsec_Tunnel" action 4.0 comment "event none" action 5.0 comment "end" The problem is that when there is an Track 1 state -> down event no action happens ??? IOS 12.4.24T Cheers Anton Anton Schweitzer Senior Specialist BS Projekt & Service Customer Design o2 (Germany) GmbH & Co.OHG Georg Brauchle-Ring 23-25, D-80992 M?nchen Tel +49(0)89-2442-5794 Mobil +49(0)176-23407715 Fax +49(0)89-2442-4281 anton.schweitzer at o2.com Ein Beitrag zum Umweltschutz. Nicht jede E-Mail muss ausgedruckt werden. http://www.o2engagiert-fuer-morgen.de Telef?nica o2 Germany GmbH & Co. OHG ? Georg-Brauchle-Ring 23-25 ? 80992 M?nchen ? Deutschland ? www.o2.com/de Ust.-Id.-Nr. DE 811 889 638. Amtsgericht M?nchen HRA 70343. Gesellschafter: Telef?nica o2 Germany Management GmbH. Amtsgericht M?nchen HRB 109061 und Telef?nica o2 Germany Verwaltungs GmbH. Amtsgericht M?nchen HRB 121389, beide ebenda. Gesch?ftsf?hrer beider Gesellschafter: Jaime Smith Basterra, Vorsitzender. Antonio Botas Banuelos. Andrea Folgueiras. Andr? Krause. Lutz Sch?ler. Carsten Wreth. From david.freedman at uk.clara.net Mon Apr 27 08:24:11 2009 From: david.freedman at uk.clara.net (David Freedman) Date: Mon, 27 Apr 2009 13:24:11 +0100 Subject: [c-nsp] IP Sla + Track does not trigger EEM applet In-Reply-To: References: Message-ID: try "debug event manager all" Dave. Anton.Schweitzer at o2.com wrote: > Hi, > > i set up a configuration to reset an IPSEC Tunnel : > > track 1 ip sla 1 reachability > delay down 60 up 30 > > ip sla 1 > icmp-echo 1.1.1.1 source-interface Loopback13 > ip sla schedule 1 life forever start-time now > > > event manager applet Reset_IPsec_Tunnel > event none > action 1.0 cli command "ena" > action 2.0 comment "clear crypto ipsec client ezvpn" > event manager applet IPSec_Tunnel_Down > event track 1 state down > action 1.0 comment "en" > action 2.0 comment "event manager run Reset_IPsec_Tunnel" > action 3.0 comment "conf term" > action 4.0 comment "event manager applet Reset_IPsec_Tunnel" > action 5.0 comment "event timer watchdog time 360" > action 6.0 comment "end" > event manager applet IPSec_Tunnel_UP > event track 1 state up > action 1.0 comment "en" > action 2.0 comment "conf term" > action 3.0 comment "event manager applet Reset_IPsec_Tunnel" > action 4.0 comment "event none" > action 5.0 comment "end" > > > The problem is that when there is an Track 1 state -> down event no > action happens ??? > > IOS 12.4.24T > > > > Cheers > > Anton > > > Anton Schweitzer > Senior Specialist BS Projekt & Service > Customer Design > > o2 (Germany) GmbH & Co.OHG > Georg Brauchle-Ring 23-25, D-80992 M?nchen > Tel +49(0)89-2442-5794 > Mobil +49(0)176-23407715 > Fax +49(0)89-2442-4281 > anton.schweitzer at o2.com > > Ein Beitrag zum Umweltschutz. Nicht jede E-Mail muss ausgedruckt werden. > http://www.o2engagiert-fuer-morgen.de > > Telef?nica o2 Germany GmbH & Co. OHG ? Georg-Brauchle-Ring 23-25 ? 80992 > M?nchen ? Deutschland ? www.o2.com/de > > Ust.-Id.-Nr. DE 811 889 638. Amtsgericht M?nchen HRA 70343. > Gesellschafter: Telef?nica o2 Germany Management GmbH. Amtsgericht M?nchen > HRB 109061 und > Telef?nica o2 Germany Verwaltungs GmbH. Amtsgericht M?nchen HRB 121389, > beide ebenda. > Gesch?ftsf?hrer beider Gesellschafter: Jaime Smith Basterra, Vorsitzender. > Antonio Botas Banuelos. Andrea Folgueiras. Andr? Krause. Lutz Sch?ler. > Carsten Wreth. > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From Jason.Link at whgroup.com Mon Apr 27 09:50:29 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Mon, 27 Apr 2009 08:50:29 -0500 Subject: [c-nsp] DHCP Route Tracking in the 870 Series In-Reply-To: <78C984F8939D424697B15E4B1C1BB3D78D48B7@xmb-ams-331.emea.cisco.com> References: <001e01c9c682$19fe15a0$4dfa40e0$@org> <78C984F8939D424697B15E4B1C1BB3D78D48B7@xmb-ams-331.emea.cisco.com> Message-ID: Actually - I think I figured it out. Anyway, I was trying to install the tracked dhcp route like this: Ip route 0.0.0.0 0.0.0.0 dhcp track 123 Since the 877 switch ports are standard L2 ports, you need to set everything up with vlans. Vlan3 is my outside / dhcp vlan. Since dhcp isn't an actual interface, you can't track it as such. But, you can create a BVI, put vlan3 into that BVI, and track that BVI. So, this spears to work: Ip route 0.0.0.0 0.0.0.0 bvi2 track 123 I haven't tested it yet though, so I'm not certain it will work. I will give it a shot later. -----Original Message----- From: Arie Vayner (avayner) [mailto:avayner at cisco.com] Sent: Monday, April 27, 2009 1:19 AM To: Jason Link Subject: RE: [c-nsp] DHCP Route Tracking in the 870 Series Jason, Can you share the show ver please? I have a feeling it might be a license/feature set thing... Arie -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jason Link Sent: Monday, April 27, 2009 02:15 To: Cisco-nsp Subject: [c-nsp] DHCP Route Tracking in the 870 Series Hello all, I've got a situation that requires tracking (and removing) the DHCP-added default-gateway route in an 877. In the documentation (http://www.cisco.com/en/US/tech/tk648/tk361/technologies_configuration_ example09186a00808d2b72.shtml) this is done via "ip route 0.0.0.0 0.0.0.0 dhcp track 123". When I try to enter the command as above, the "track" option is not available. I'm using the same version of IOS as the above example, with the exception that the hardware is an 877 and not an 1811. This leads me to believe the issue is related to the hardware, as in its not available on the 877. Am I missing something? Thanks! _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From pao_rivi at hotmail.com Mon Apr 27 11:09:17 2009 From: pao_rivi at hotmail.com (P@0l0) Date: Mon, 27 Apr 2009 17:09:17 +0200 Subject: [c-nsp] DNS Stuff In-Reply-To: References: Message-ID: Hi why don't you use the DNS logs or a FW logs in case you have one of this opportunity or make a acl and log it hope this help cheers Paolo Riviello Mob. +39.328.1749468 Home: http://www.paoloriviello.com Msn: pao_rivi at hotmail.com Skype: pao_rivi If men could get pregnant, abortion would be a sacrament. -H- > From: eng_mssk at hotmail.com > To: cisco-nsp at puck.nether.net > Date: Mon, 27 Apr 2009 09:08:11 +0300 > Subject: [c-nsp] DNS Stuff > > > Hey all > is there any way to know the number of DNS requests or hits on a specific DNS server (Via SNMP for example) > can we darw this ? > > _________________________________________________________________ > Show them the way! Add maps and directions to your party invites. > http://www.microsoft.com/windows/windowslive/products/events.aspx > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ _________________________________________________________________ Quante ne sai? Scoprilo con CrossWire! http://clk.atdmt.com/GBL/go/140630367/direct/01/ From peter at rathlev.dk Mon Apr 27 11:13:48 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Mon, 27 Apr 2009 17:13:48 +0200 Subject: [c-nsp] BGP Dynamic Neighbors and VPNv4 Message-ID: <1240845228.7881.64.camel@localhost.localdomain> Hello, Reading about BGP Dynamic Neighbors I can see that the 12.2SX Configuration Guide[1] states that only IPv4 peering is supported. Would anybody know if this actually means "no IPv6" or if it also means "no VPNv4"? I don't currently have a SXH/SXI box to test this from I'm afraid. Thank you. Regards, Peter [1]: http://www.cisco.com/en/US/docs/ios/iproute/configuration/guide /irp_bgp_neighor_ps6017_TSD_Products_Configuration_Guide_Chapter.htm l#wp1055389 (http://tinyurl.com/cuzggf) From p.mayers at imperial.ac.uk Mon Apr 27 12:36:10 2009 From: p.mayers at imperial.ac.uk (Phil Mayers) Date: Mon, 27 Apr 2009 17:36:10 +0100 Subject: [c-nsp] BGP Dynamic Neighbors and VPNv4 In-Reply-To: <1240845228.7881.64.camel@localhost.localdomain> References: <1240845228.7881.64.camel@localhost.localdomain> Message-ID: <49F5DEFA.3000200@imperial.ac.uk> Peter Rathlev wrote: > Hello, > > Reading about BGP Dynamic Neighbors I can see that the 12.2SX > Configuration Guide[1] states that only IPv4 peering is supported. Would > anybody know if this actually means "no IPv6" or if it also means "no > VPNv4"? I don't currently have a SXH/SXI box to test this from I'm > afraid. SXI will accept and nvgen the following config: router bgp 64580 bgp listen range 192.168.1.0/24 peer-group foo neighbor foo peer-group neighbor foo remote-as 64580 ! address-family ipv4 neighbor foo activate exit-address-family ! address-family vpnv4 neighbor foo activate neighbor foo send-community extended exit-address-family ! ...whether it works as expected is another matter - I can't test that without outage to our test router (which is being used for other testing at the moment). Related: It's tedious (to my mind) that the dynamic neighbour stuff can't use templates: core-spare(config-router)#neighbor foo inherit peer-session iBGP-world % Peer-group cannot inherit a template ...given that templates are superior to peer groups. From billbuhlman at yahoo.com Mon Apr 27 13:22:56 2009 From: billbuhlman at yahoo.com (Bill Buhlman) Date: Mon, 27 Apr 2009 10:22:56 -0700 (PDT) Subject: [c-nsp] SSH login hangs still third session Message-ID: <159892.35700.qm@web43134.mail.sp1.yahoo.com> Hi, I'm running 12.2(33)SRA6 on a 7609-Sup720-3b. Its been up for about a year aand a half. When I first deployed it, I was able to login with ssh first try with Putty. About 4 months later after I put in username and password, the session hangs until I get "protocol error: expected type 50 got -1" (with putty. no error code with Teraterm) At that time if I opened another session and put in username and password while the other session was hung I was able to login fine. Now, on the first TWO sessions it hangs and the third session I am able to login. I've tried different versions of putty and teraterm but doesn't seem to be client related. I've regenerated the RSA key twice and I've got an open case with Cisco but no resolution so far. Anyone seen this? Thanks, Bill From maillist at webjogger.net Mon Apr 27 14:05:17 2009 From: maillist at webjogger.net (Adam Greene) Date: Mon, 27 Apr 2009 14:05:17 -0400 Subject: [c-nsp] eBGP --> OSPF --> eBGP vs eBGP --> iBGP --> eBGP Message-ID: <9396D49753F24294A8D788749A309A26@GINKGO> Hi, We run BGP to our upstream providers and OSPF on our local backbone. We have a customer who will be multihomed and needs us to advertise his IP blocks to us via BGP. My question is how best to propagate his AS-PATH prepending to my upstream providers. Is it possible to inject this information into OSPF and then into the eBGP to my upstreams? Or should I plan on establishing iBGP sessions between the backbone router that will be servicing the customer and the routers facing my upstream providers? I assume the latter .... Thanks, Adam From gert at greenie.muc.de Mon Apr 27 14:14:36 2009 From: gert at greenie.muc.de (Gert Doering) Date: Mon, 27 Apr 2009 20:14:36 +0200 Subject: [c-nsp] DHCP Route Tracking in the 870 Series In-Reply-To: References: <78C984F8939D424697B15E4B1C1BB3D78D48B7@xmb-ams-331.emea.cisco.com> Message-ID: <20090427181436.GN290@greenie.muc.de> Hi, On Mon, Apr 27, 2009 at 08:50:29AM -0500, Jason Link wrote: > So, this spears to work: > > Ip route 0.0.0.0 0.0.0.0 bvi2 track 123 If this does what it seems to do, this is a baaaaad idea. Normally, if you point a default route to an interface that does ARP, it will send out (proxy-) ARP request for every single IP address that you want to talk to - and it will only work if the router on the other end will nicely do proxy ARP for you, answering ARP requests for non-local IP addresses. Which is something that was also a bad idea to implement as a default. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From pshem.k at gmail.com Mon Apr 27 16:17:06 2009 From: pshem.k at gmail.com (Pshem Kowalczyk) Date: Tue, 28 Apr 2009 08:17:06 +1200 Subject: [c-nsp] eBGP --> OSPF --> eBGP vs eBGP --> iBGP --> eBGP In-Reply-To: <9396D49753F24294A8D788749A309A26@GINKGO> References: <9396D49753F24294A8D788749A309A26@GINKGO> Message-ID: <20fe625b0904271317j8fe5c59yac79425b624d5eb@mail.gmail.com> Hi, 2009/4/28 Adam Greene : > Hi, > > We run BGP to our upstream providers and OSPF on our local backbone. > > We have a customer who will be multihomed and needs us to advertise his IP blocks to us via BGP. > > My question is how best to propagate his AS-PATH prepending to my upstream providers. Is it possible to inject this information into OSPF and then into the eBGP to my upstreams? Or should I plan on establishing iBGP sessions between the backbone router that will be servicing the customer and the routers facing my upstream providers? I assume the latter .... Definitely the latter, it works 'out of the box' and what's more important gives you ability to control the way customers' information is propagated further up. If you only have one customer like that (and one customer-facing device) it's easier to just fully mesh it with the 'upstream' routers, if you have more then a few - have a look at setup with route servers. kind regards Pshem From devon at noved.org Mon Apr 27 15:57:07 2009 From: devon at noved.org (Devon True) Date: Mon, 27 Apr 2009 15:57:07 -0400 Subject: [c-nsp] 6500 - SVI Showing ifInDiscards - Meaning? Message-ID: <49F60E13.7050009@noved.org> All: What does an ifInDiscard mean on a SVI on a 6500? I did some searching and http://www.cisco.com/en/US/tech/tk648/tk362/technologies_q_and_a_item09186a00800b69ac.shtml said that "ifInDiscards - These are counted as no buffers as reflected in the show interfaces command.". The example shows them looking at the "ignored" counter of the interface. This issue was brought about when the snmp counter showed a high amount, but the corresponding interface did not. IF-MIB::ifDescr.64 = STRING: Vlan11 IF-MIB::ifInDiscards.64 = Counter32: 2589982 Vlan11 is up, line protocol is up Hardware is EtherSVI, address is 0009.7bb8.9400 (bia 0009.7bb8.9400) Description: xxxxxxxxxxxxxxxxx Internet address is x.x.x.x/yy MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, reliability 255/255, txload 32/255, rxload 38/255 Encapsulation ARPA, loopback not set Keepalive not supported ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:00, output hang never Last clearing of "show interface" counters never Input queue: 0/75/2589982/2425805 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 30 second input rate 150667000 bits/sec, 63644 packets/sec 30 second output rate 128132000 bits/sec, 21616 packets/sec L2 Switched: ucast: 339694471 pkt, 39597395897 bytes - mcast: 1845732 pkt, 339663263 bytes L3 in Switched: ucast: 355669693266 pkt, 104243041264475 bytes - mcast: 0 pkt, 0 bytes mcast L3 out Switched: ucast: 168426931431 pkt, 133867540821374 bytes mcast: 0 pkt, 0 bytes 356191072919 packets input, 104297673767698 bytes, 0 no buffer Received 1845550 broadcasts (0 IP multicasts) 0 runts, 0 giants, 14689 throttles 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored 168607360398 packets output, 133882917573234 bytes, 0 underruns 0 output errors, 0 interface resets 0 output buffer failures, 0 output buffers swapped out Running s72033-adventerprisek9_wan-mz.122-18.SXF8.bin. -- Devon From pavel.skovajsa at gmail.com Mon Apr 27 16:38:52 2009 From: pavel.skovajsa at gmail.com (Pavel Skovajsa) Date: Mon, 27 Apr 2009 22:38:52 +0200 Subject: [c-nsp] DHCP server suited for option 82 Message-ID: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> Hello all, I am trying to setup linux dhcpd ISC server to act according to certain circuit-id values in the Option 82, and I find the whole configuration very poorly documented, and quite complex. This is quite surprising to me that for such a market pushy technology as IPoE there are no 'easily' configurable DHCP servers. Maybe I am looking wrong direction, can somebody tell me what DHCP server are you using if you need to hand out specific IPs for specific switch ports? Thanks, Pavel Skovajsa From charles at thewybles.com Mon Apr 27 17:06:38 2009 From: charles at thewybles.com (Charles Wyble) Date: Mon, 27 Apr 2009 14:06:38 -0700 Subject: [c-nsp] DHCP server suited for option 82 In-Reply-To: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> References: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> Message-ID: <49F61E5E.9050900@thewybles.com> http://www.cisco.com/en/US/docs/ios/12_2t/12_2t2/feature/guide/ftrbeo82.html Pavel Skovajsa wrote: > Hello all, > > I am trying to setup linux dhcpd ISC server to act according to > certain circuit-id values in the Option 82, and I find the whole > configuration very poorly documented, and quite complex. This is quite > surprising to me that for such a market pushy technology as IPoE there > are no 'easily' configurable DHCP servers. > > Maybe I am looking wrong direction, can somebody tell me what DHCP > server are you using if you need to hand out specific IPs for specific > switch ports? > > Thanks, > Pavel Skovajsa > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From charles at thewybles.com Mon Apr 27 17:07:05 2009 From: charles at thewybles.com (Charles Wyble) Date: Mon, 27 Apr 2009 14:07:05 -0700 Subject: [c-nsp] DHCP server suited for option 82 In-Reply-To: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> References: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> Message-ID: <49F61E79.3000606@thewybles.com> Also http://www.cisco.com/en/US/docs/ios/12_3t/12_3t4/feature/guide/gdhcpopt.html which I think is what you want. Pavel Skovajsa wrote: > Hello all, > > I am trying to setup linux dhcpd ISC server to act according to > certain circuit-id values in the Option 82, and I find the whole > configuration very poorly documented, and quite complex. This is quite > surprising to me that for such a market pushy technology as IPoE there > are no 'easily' configurable DHCP servers. > > Maybe I am looking wrong direction, can somebody tell me what DHCP > server are you using if you need to hand out specific IPs for specific > switch ports? > > Thanks, > Pavel Skovajsa > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From charles at thewybles.com Mon Apr 27 17:08:59 2009 From: charles at thewybles.com (Charles Wyble) Date: Mon, 27 Apr 2009 14:08:59 -0700 Subject: [c-nsp] DHCP server suited for option 82 In-Reply-To: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> References: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> Message-ID: <49F61EEB.7090902@thewybles.com> http://www.thtech.net/article/10 for ISC example Pavel Skovajsa wrote: > Hello all, > > I am trying to setup linux dhcpd ISC server to act according to > certain circuit-id values in the Option 82, and I find the whole > configuration very poorly documented, and quite complex. This is quite > surprising to me that for such a market pushy technology as IPoE there > are no 'easily' configurable DHCP servers. > > Maybe I am looking wrong direction, can somebody tell me what DHCP > server are you using if you need to hand out specific IPs for specific > switch ports? > > Thanks, > Pavel Skovajsa > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From william.mccall at gmail.com Mon Apr 27 17:26:21 2009 From: william.mccall at gmail.com (William McCall) Date: Mon, 27 Apr 2009 16:26:21 -0500 Subject: [c-nsp] 6500 - SVI Showing ifInDiscards - Meaning? In-Reply-To: <49F60E13.7050009@noved.org> References: <49F60E13.7050009@noved.org> Message-ID: Input queue: 0/75/2589982/2425805 (size/max/drops/flushes); Total output drops: 0 ->> Corresponds with your input drops you see in SNMP. you might want to try "sh buffers interface vlan11" and try "sh interfaces vlan11 switching" to take a look at whats going on. --WJM IV On Mon, Apr 27, 2009 at 2:57 PM, Devon True wrote: > All: > > What does an ifInDiscard mean on a SVI on a 6500? I did some searching > and > > http://www.cisco.com/en/US/tech/tk648/tk362/technologies_q_and_a_item09186a00800b69ac.shtml > said that "ifInDiscards - These are counted as no buffers as reflected > in the show interfaces command.". The example shows them looking at the > "ignored" counter of the interface. > > This issue was brought about when the snmp counter showed a high amount, > but the corresponding interface did not. > > IF-MIB::ifDescr.64 = STRING: Vlan11 > IF-MIB::ifInDiscards.64 = Counter32: 2589982 > > Vlan11 is up, line protocol is up > Hardware is EtherSVI, address is 0009.7bb8.9400 (bia 0009.7bb8.9400) > Description: xxxxxxxxxxxxxxxxx > Internet address is x.x.x.x/yy > MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec, > reliability 255/255, txload 32/255, rxload 38/255 > Encapsulation ARPA, loopback not set > Keepalive not supported > ARP type: ARPA, ARP Timeout 04:00:00 > Last input 00:00:00, output 00:00:00, output hang never > Last clearing of "show interface" counters never > Input queue: 0/75/2589982/2425805 (size/max/drops/flushes); Total > output drops: 0 > Queueing strategy: fifo > Output queue: 0/40 (size/max) > 30 second input rate 150667000 bits/sec, 63644 packets/sec > 30 second output rate 128132000 bits/sec, 21616 packets/sec > L2 Switched: ucast: 339694471 pkt, 39597395897 bytes - mcast: 1845732 > pkt, 339663263 bytes > L3 in Switched: ucast: 355669693266 pkt, 104243041264475 bytes - > mcast: 0 pkt, 0 bytes mcast > L3 out Switched: ucast: 168426931431 pkt, 133867540821374 bytes mcast: > 0 pkt, 0 bytes > 356191072919 packets input, 104297673767698 bytes, 0 no buffer > Received 1845550 broadcasts (0 IP multicasts) > 0 runts, 0 giants, 14689 throttles > 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored > 168607360398 packets output, 133882917573234 bytes, 0 underruns > 0 output errors, 0 interface resets > 0 output buffer failures, 0 output buffers swapped out > > Running s72033-adventerprisek9_wan-mz.122-18.SXF8.bin. > > -- > Devon > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From walter.keen at RainierConnect.net Mon Apr 27 17:32:06 2009 From: walter.keen at RainierConnect.net (Walter Keen) Date: Mon, 27 Apr 2009 14:32:06 -0700 Subject: [c-nsp] DHCP server support for mysql configuration Message-ID: <49F62456.90107@rainierconnect.net> Greetings, I've searched the archive, but I couldn't quite find what I was looking for. Does anyone know if it's possible to use SQL for the DHCP config? (defining address ranges, all the way to configuring dhcp reservations). Where I work, we use dhcp reservations for cablemodem provisioning, and occasionally we have a problem with the dhcp server (not) reloading after a provisioning change. ideally we'd like it to read from some type of sql db, and not have to reload on every modem add. We're using an older version (3.01?) of ISC DHCP now, but I wanted to know if anyone else had suggestions around this. From drrtuy at ya.ru Mon Apr 27 17:58:27 2009 From: drrtuy at ya.ru (junior) Date: Tue, 28 Apr 2009 00:58:27 +0300 Subject: [c-nsp] DHCP server suited for option 82 In-Reply-To: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> References: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> Message-ID: <49F62A83.2040601@ya.ru> Hello. Pavel Skovajsa wrote: > Hello all, > > I am trying to setup linux dhcpd ISC server to act according to > certain circuit-id values in the Option 82, and I find the whole > configuration very poorly documented, and quite complex. This is quite > surprising to me that for such a market pushy technology as IPoE there > are no 'easily' configurable DHCP servers. I have recently configured dhcp relay with option 82 using 5 catalyst switches with ISC DHCP server. It was hard to find useful information. Here is well documented example of ISC DHCP server with Option 82 configuration file... in Russian. But You can find sample configuration inside the text. > Maybe I am looking wrong direction, can somebody tell me what DHCP > server are you using if you need to hand out specific IPs for specific > switch ports? ISC DHCP server is the correct choice to manage with this. > Thanks, > Pavel Skovajsa > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From simon at slimey.org Mon Apr 27 18:04:27 2009 From: simon at slimey.org (Simon Lockhart) Date: Mon, 27 Apr 2009 23:04:27 +0100 Subject: [c-nsp] DHCP server suited for option 82 In-Reply-To: <49F61EEB.7090902@thewybles.com> References: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> <49F61EEB.7090902@thewybles.com> Message-ID: <20090427220427.GC27435@virtual.bogons.net> On Mon Apr 27, 2009 at 02:08:59PM -0700, Charles Wyble wrote: > http://www.thtech.net/article/10 for ISC example That appears to be the canonical example that's trotted out everytime Option 82 is mentioned. Fine if all you want to do is log the Option 82 information, but less than useful if you want to do anything intelligent based on it. I've ended up developing my own simple DHCP server - I don't need the complexities that ISC offers, but I do need to do clever stuff with Option 82, and I also need to trigger external actions whenever IPs are leased, renewed, released, etc. I didn't really want to rely on watching a logfile to achieve this. SImon From miquels at cistron.nl Mon Apr 27 19:13:44 2009 From: miquels at cistron.nl (Miquel van Smoorenburg) Date: Tue, 28 Apr 2009 01:13:44 +0200 Subject: [c-nsp] DHCP server suited for option 82 In-Reply-To: <20090427220427.GC27435@virtual.bogons.net> References: <323aca890904271338s132851fbkcf843b33718dbad6@mail.gmail.com> <49F61EEB.7090902@thewybles.com> <20090427220427.GC27435@virtual.bogons.net> Message-ID: <1240874024.6169.82.camel@laptop> On Mon, 2009-04-27 at 23:04 +0100, Simon Lockhart wrote: > On Mon Apr 27, 2009 at 02:08:59PM -0700, Charles Wyble wrote: > > http://www.thtech.net/article/10 for ISC example > > That appears to be the canonical example that's trotted out everytime > Option 82 is mentioned. Fine if all you want to do is log the Option 82 > information, but less than useful if you want to do anything intelligent > based on it. Yup, it's hard to find a working config sample. This is the way to do it- # dhcpd.conf # stash-agent-options true; subnet 192.168.1.0 netmask 255.255.255.0 { option broadcast-address 192.168.1.255; option routers 192.168.1.1; option subnet-mask 255.255.255.0; # Match on circuit-id. class "id-192.168.1.10" { match if option agent.circuit-id = "ATM 2/1/0.3"; } pool { allow members of "id-192.168.1.10"; range 192.168.1.10; } # ... more here ... } This scales up to about 5000 entries, then it gets slow. I patched ISC DHCPD to scale beyond that, perhaps I should publish that patch somewhere. Mike. From miquels at cistron.nl Mon Apr 27 19:16:20 2009 From: miquels at cistron.nl (Miquel van Smoorenburg) Date: Tue, 28 Apr 2009 01:16:20 +0200 Subject: [c-nsp] DHCP server support for mysql configuration In-Reply-To: <49F62456.90107@rainierconnect.net> References: <49F62456.90107@rainierconnect.net> Message-ID: <1240874180.6169.84.camel@laptop> On Mon, 2009-04-27 at 14:32 -0700, Walter Keen wrote: > Greetings, I've searched the archive, but I couldn't quite find what I > was looking for. > > Does anyone know if it's possible to use SQL for the DHCP config? Something like this ? http://users.accesscomm.ca/docsis_server/ Never used it, but stumbled upon it a while ago. Hope it's useful. Mike. From walter.keen at RainierConnect.net Mon Apr 27 19:59:17 2009 From: walter.keen at RainierConnect.net (Walter Keen) Date: Mon, 27 Apr 2009 16:59:17 -0700 Subject: [c-nsp] DHCP server support for mysql configuration In-Reply-To: <1240874180.6169.84.camel@laptop> References: <49F62456.90107@rainierconnect.net> <1240874180.6169.84.camel@laptop> Message-ID: <49F646D5.3050603@rainierconnect.net> Looks ideal, except for part of the fine print that will hinder my use of it: /TODO:/ add support for VoIP devices. ie. packet cable. (unless I want to try to implement it myself that is) Is anyone using this? Granted, I'm not talking about a large user-base for this (roughly 2k modems) but it would be nice to know if another service provider is using it. Miquel van Smoorenburg wrote: > On Mon, 2009-04-27 at 14:32 -0700, Walter Keen wrote: > >> Greetings, I've searched the archive, but I couldn't quite find what I >> was looking for. >> >> Does anyone know if it's possible to use SQL for the DHCP config? >> > > Something like this ? > > http://users.accesscomm.ca/docsis_server/ > > Never used it, but stumbled upon it a while ago. Hope it's useful. > > Mike. > > From jay at west.net Mon Apr 27 20:50:40 2009 From: jay at west.net (Jay Hennigan) Date: Mon, 27 Apr 2009 17:50:40 -0700 Subject: [c-nsp] eBGP --> OSPF --> eBGP vs eBGP --> iBGP --> eBGP In-Reply-To: <9396D49753F24294A8D788749A309A26@GINKGO> References: <9396D49753F24294A8D788749A309A26@GINKGO> Message-ID: <49F652E0.8020203@west.net> Adam Greene wrote: > Hi, > > We run BGP to our upstream providers and OSPF on our local backbone. > > We have a customer who will be multihomed and needs us to advertise his IP blocks to us via BGP. > > My question is how best to propagate his AS-PATH prepending to my upstream providers. Is it possible to inject this information into OSPF and then into the eBGP to my upstreams? Or should I plan on establishing iBGP sessions between the backbone router that will be servicing the customer and the routers facing my upstream providers? I assume the latter .... It's possible to inject to OSPF and then back to BGP. It's also possible to commute 20 miles on a unicycle. But there are more appropriate vehicles in both cases. Seriously, go with iBGP. In fact consider moving all of your customer routes to iBGP, you'll find it more scalable. Use OSPF for infrastructure only. Here's a good guide on how to do it: www.ripe.net/meetings/regional/manama-2006/presentations/BGP-BCP.pdf -- Jay Hennigan - CCIE #7880 - Network Engineering - jay at impulse.net Impulse Internet Service - http://www.impulse.net/ Your local telephone and internet company - 805 884-6323 - WB6RDV From jzp-cnsp at rsuc.gweep.net Mon Apr 27 21:05:54 2009 From: jzp-cnsp at rsuc.gweep.net (Joe Provo) Date: Mon, 27 Apr 2009 21:05:54 -0400 Subject: [c-nsp] eBGP --> OSPF --> eBGP vs eBGP --> iBGP --> eBGP In-Reply-To: <9396D49753F24294A8D788749A309A26@GINKGO> References: <9396D49753F24294A8D788749A309A26@GINKGO> Message-ID: <20090428010554.GA18367@gweep.net> On Mon, Apr 27, 2009 at 02:05:17PM -0400, Adam Greene wrote: > Hi, > > We run BGP to our upstream providers and OSPF on our local backbone. > > We have a customer who will be multihomed and needs us to advertise his IP blocks to us via BGP. > > My question is how best to propagate his AS-PATH prepending to > my upstream providers. Is it possible to inject this information > into OSPF and then into the eBGP to my upstreams? Possible yes, but full of fail. > Or should I plan on establishing iBGP sessions between the backbone > router that will be servicing the customer and the routers facing > my upstream providers? I assume the latter .... Yes. For maximal win along the axes (scalable,flexible,maintainable), your OSPF should only carry only loopbacks and network edges (just enough to enable next-hop processing of BGP) and your iBGP should carry all the prefixes. Cheers! Joe -- RSUC / GweepNet / Spunk / FnB / Usenix / SAGE From risnaini at indo.net.id Mon Apr 27 22:46:45 2009 From: risnaini at indo.net.id (a. rahman isnaini r.sutan) Date: Tue, 28 Apr 2009 09:46:45 +0700 Subject: [c-nsp] eBGP --> OSPF --> eBGP vs eBGP --> iBGP --> eBGP In-Reply-To: <9396D49753F24294A8D788749A309A26@GINKGO> References: <9396D49753F24294A8D788749A309A26@GINKGO> Message-ID: <49F66E15.5040702@indo.net.id> iBGP, also depends on how many your OSPF hops. if it just one hop, just a simple bgp. if 2 hops, use RR. if more than 2 hops -> tunnel not recomended. [sometimes I used to bypass layer 2 between hops]... a. rahman isnaini rangkayo sutan Adam Greene wrote: > Hi, > > We run BGP to our upstream providers and OSPF on our local backbone. > > We have a customer who will be multihomed and needs us to advertise his IP blocks to us via BGP. > > My question is how best to propagate his AS-PATH prepending to my upstream providers. Is it possible to inject this information into OSPF and then into the eBGP to my upstreams? Or should I plan on establishing iBGP sessions between the backbone router that will be servicing the customer and the routers facing my upstream providers? I assume the latter .... > > Thanks, > Adam > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > From jarruda-cnsp at jarruda.com Tue Apr 28 08:38:13 2009 From: jarruda-cnsp at jarruda.com (Julio Arruda) Date: Tue, 28 Apr 2009 08:38:13 -0400 Subject: [c-nsp] GRE on GSR Message-ID: <49F6F8B5.5030304@jarruda.com> Just to confirm, from what I understand, IOS on the 12K only allows you to configure GRE if you have a TSC (tunnel server card). http://www.cisco.com/en/US/docs/ios/12_0s/feature/guide/gre.html But, still not clear to me: 0- This still the case ? (I would assume so).. 1- Can we use newer gen cards (> Engine 2) for TSC purposes ? 2- Can we have the GRE tunnel being part of a VRF ? From mhuff at ox.com Tue Apr 28 10:00:08 2009 From: mhuff at ox.com (Matthew Huff) Date: Tue, 28 Apr 2009 10:00:08 -0400 Subject: [c-nsp] sup 720 3c 10GE blades for 7600 In-Reply-To: <49F6F8B5.5030304@jarruda.com> References: <49F6F8B5.5030304@jarruda.com> Message-ID: <483E6B0272B0284BA86D7596C40D29F9C38082C1E7@PUR-EXCH07.ox.com> Our cisco rep and var are pushing back on our plans to upgrade our 7600 from sup32 to the RSP 720 with 10GE saying they are in limited production. Of course, they are pushing us toward the ASR product line. Anyone know of any issues with the RSP 720 w 10GE interfaces? ---- Matthew Huff?????? | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff? | Fax:?? 914-460-4139 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 4229 bytes Desc: not available URL: From michel.renfer at finecom.ch Tue Apr 28 10:57:30 2009 From: michel.renfer at finecom.ch (Michel Renfer) Date: Tue, 28 Apr 2009 16:57:30 +0200 Subject: [c-nsp] sup 720 3c 10GE blades for 7600 In-Reply-To: <483E6B0272B0284BA86D7596C40D29F9C38082C1E7@PUR-EXCH07.ox.com> References: <49F6F8B5.5030304@jarruda.com> <483E6B0272B0284BA86D7596C40D29F9C38082C1E7@PUR-EXCH07.ox.com> Message-ID: <7ABEE57B986BDA429B535673CBE0C623038E5CB3@xanthe.lan.intra> AFAIK there are some issues when using the the RSP720-10G in redundant configurations. Thats the statement we know, why the RSP is not yet general orderable. cheers, michel -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Matthew Huff Sent: Tuesday, April 28, 2009 4:00 PM To: 'Cisco Nsp' Subject: [c-nsp] sup 720 3c 10GE blades for 7600 Our cisco rep and var are pushing back on our plans to upgrade our 7600 from sup32 to the RSP 720 with 10GE saying they are in limited production. Of course, they are pushing us toward the ASR product line. Anyone know of any issues with the RSP 720 w 10GE interfaces? ---- Matthew Huff?????? | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff? | Fax:?? 914-460-4139 From mhuff at ox.com Tue Apr 28 11:15:18 2009 From: mhuff at ox.com (Matthew Huff) Date: Tue, 28 Apr 2009 11:15:18 -0400 Subject: [c-nsp] sup 720 3c 10GE blades for 7600 In-Reply-To: <7ABEE57B986BDA429B535673CBE0C623038E5CB3@xanthe.lan.intra> References: <49F6F8B5.5030304@jarruda.com> <483E6B0272B0284BA86D7596C40D29F9C38082C1E7@PUR-EXCH07.ox.com> <7ABEE57B986BDA429B535673CBE0C623038E5CB3@xanthe.lan.intra> Message-ID: <483E6B0272B0284BA86D7596C40D29F9C38082C1F7@PUR-EXCH07.ox.com> That's good news. That's what we heard as well. Since we are doing box-to-box redudancy (eigrp load balancing) and not using SSO, RPR/RPR+ then there shouldn't be an issue. ---- Matthew Huff?????? | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com | Phone: 914-460-4039 aim: matthewbhuff? | Fax:?? 914-460-4139 > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- > bounces at puck.nether.net] On Behalf Of Michel Renfer > Sent: Tuesday, April 28, 2009 10:58 AM > To: cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] sup 720 3c 10GE blades for 7600 > > AFAIK there are some issues when using the the RSP720-10G in redundant > configurations. Thats the statement we know, why the RSP is not yet > general orderable. > > cheers, > michel > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- > bounces at puck.nether.net] On Behalf Of Matthew Huff > Sent: Tuesday, April 28, 2009 4:00 PM > To: 'Cisco Nsp' > Subject: [c-nsp] sup 720 3c 10GE blades for 7600 > > Our cisco rep and var are pushing back on our plans to upgrade our 7600 > from > sup32 to the RSP 720 with 10GE saying they are in limited production. > Of > course, they are pushing us toward the ASR product line. Anyone know of > any > issues with the RSP 720 w 10GE interfaces? > > ---- > Matthew Huff?????? | One Manhattanville Rd > OTA Management LLC | Purchase, NY 10577 > http://www.ox.com | Phone: 914-460-4039 > aim: matthewbhuff? | Fax:?? 914-460-4139 > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 4229 bytes Desc: not available URL: From peter at rathlev.dk Tue Apr 28 12:59:47 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Tue, 28 Apr 2009 18:59:47 +0200 Subject: [c-nsp] BGP Dynamic Neighbors and VPNv4 In-Reply-To: <49F5DEFA.3000200@imperial.ac.uk> References: <1240845228.7881.64.camel@localhost.localdomain> <49F5DEFA.3000200@imperial.ac.uk> Message-ID: <1240937987.4502.3.camel@localhost.localdomain> On Mon, 2009-04-27 at 17:36 +0100, Phil Mayers wrote: > SXI will accept and nvgen the following config: > > router bgp 64580 > bgp listen range 192.168.1.0/24 peer-group foo > neighbor foo peer-group > neighbor foo remote-as 64580 > ! > address-family ipv4 > neighbor foo activate > exit-address-family > ! > address-family vpnv4 > neighbor foo activate > neighbor foo send-community extended > exit-address-family > ! > > ...whether it works as expected is another matter - I can't test that > without outage to our test router (which is being used for other testing > at the moment). Thanks for testing it. I hope to be able to test it for real on SXI in a matter of weeks. If it at least accepts the configuration we have reasonable reason to start testing it. :-) Regards, Peter From SteveMc at netservicesplc.com Tue Apr 28 13:44:16 2009 From: SteveMc at netservicesplc.com (Steve McCrory) Date: Tue, 28 Apr 2009 18:44:16 +0100 Subject: [c-nsp] Problems with multiple VPDN hops In-Reply-To: <20fe625b0904261307m776ac158u7f54408868afbd07@mail.gmail.com> References: <1C15FB264A06794F8BDE2120972B51C1050E280A@netexch04.ad.netservicesplc.com> <20fe625b0904231640x33624e1bx7862e69088a8bc2d@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2821@netexch04.ad.netservicesplc.com> <20fe625b0904261307m776ac158u7f54408868afbd07@mail.gmail.com> Message-ID: <1C15FB264A06794F8BDE2120972B51C1050E2B54@netexch04.ad.netservicesplc.com> Hi Pshem, Thanks for you reply. It seems that our radius and vpdn-group configurations were correct but we were missing the 'vpdn authen-before-forward' command on the middle LNS which was causing the problem. Thanks again for your input. Regards Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -----Original Message----- From: Pshem Kowalczyk [mailto:pshem.k at gmail.com] Sent: 26 April 2009 21:07 To: Steve McCrory Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] Problems with multiple VPDN hops Hi, {cut} > Based on this information, do you have any further suggestions and are > you able to supply example configs of your own setup? Please see here - both LTS in our example have exactly the same vpdn config: vpdn-group L2TP-wholesale ! Default L2TP VPDN group accept-dialin protocol l2tp vpn vrf InternalL2TP local name akl-mdr-lts1 lcp renegotiation always l2tp tunnel hello 300 l2tp tunnel password 0 xxxxxxxxxxxxxxxx l2tp tunnel timeout no-session 1800 l2tp tunnel retransmit retries 7 l2tp tunnel retransmit timeout min 2 l2tp tunnel retransmit timeout max 5 and corresponding radius config: DEFAULT Service-Type == Outbound-User, User-Name =~ "^host:", NAS-Identifier =~ "^akl-mdr-lts1", Auth-Type := Accept Cisco-AVPair += "vpdn:ip-addresses=10.119.255.93/10.119.255.92", Cisco-AVPair += "vpdn:tunnel-type=l2tp", Cisco-AVPair += "vpdn:vpn-vrf=InternalL2TP", Cisco-AVPair += "vpdn:l2tp-tunnel-password=xxxxxxxxxxxxxxxx" (the second layer of LTSes only differ in names and ip addresses) kind regards Pshem -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- From booloo at ucsc.edu Tue Apr 28 14:03:54 2009 From: booloo at ucsc.edu (Mark Boolootian) Date: Tue, 28 Apr 2009 11:03:54 -0700 Subject: [c-nsp] sup 720 3c 10GE blades for 7600 In-Reply-To: <7ABEE57B986BDA429B535673CBE0C623038E5CB3@xanthe.lan.intra> References: <49F6F8B5.5030304@jarruda.com> <483E6B0272B0284BA86D7596C40D29F9C38082C1E7@PUR-EXCH07.ox.com> <7ABEE57B986BDA429B535673CBE0C623038E5CB3@xanthe.lan.intra> Message-ID: <20090428180354.GC30325@root.ucsc.edu> > AFAIK there are some issues when using the the RSP720-10G in redundant > configurations. Thats the statement we know, why the RSP is not yet > general orderable. Do you have any details on the types of issues? From neilding2000 at gmail.com Tue Apr 28 14:51:19 2009 From: neilding2000 at gmail.com (Neil d) Date: Tue, 28 Apr 2009 14:51:19 -0400 Subject: [c-nsp] question about SSO Message-ID: <68f87c470904281151m59c0a378v6aaa02d38ab20aaf@mail.gmail.com> Hi everyone, I have a 7609s with 2 sup720, working in sso mode, now when the sup switchover, according to cisco documentation, layer 2 traffic shouldnt be interupted, but I noticed there's a rougly 0.6s gap in packet loss. ( traffic is in/out the same router, no other router involved). Is this normal? I was thinking forwarding plan is not affected by the redundancy switchover command. maybe I'm wrong? From cchurc05 at harris.com Tue Apr 28 15:13:55 2009 From: cchurc05 at harris.com (Church, Charles) Date: Tue, 28 Apr 2009 14:13:55 -0500 Subject: [c-nsp] question about SSO In-Reply-To: <68f87c470904281151m59c0a378v6aaa02d38ab20aaf@mail.gmail.com> References: <68f87c470904281151m59c0a378v6aaa02d38ab20aaf@mail.gmail.com> Message-ID: Unless there are DFCs involved, I would expect a tiny delay when the linecards switch over to the other PFC. I thought Cisco promised failover times or a second or two with SSO on a 6500. I think you're seeing what you should. Chuck -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Neil d Sent: Tuesday, April 28, 2009 2:51 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] question about SSO Hi everyone, I have a 7609s with 2 sup720, working in sso mode, now when the sup switchover, according to cisco documentation, layer 2 traffic shouldnt be interupted, but I noticed there's a rougly 0.6s gap in packet loss. ( traffic is in/out the same router, no other router involved). Is this normal? I was thinking forwarding plan is not affected by the redundancy switchover command. maybe I'm wrong? _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From clinton at scripty.com Tue Apr 28 15:28:59 2009 From: clinton at scripty.com (Clinton Work) Date: Tue, 28 Apr 2009 13:28:59 -0600 Subject: [c-nsp] 3750 and show mls qos interface stat output Message-ID: <49F758FB.5050408@scripty.com> Anybody have a more detailed description of the field headers for the "show mls qos interface stat" output on a 3750? Table 2-30 describes 6 field headers, but the command output only has 5 fields of output. Are they the same as the 3550: incoming, no_change, classified, policed, and dropped? http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/command/reference/cli2.html#wp1947019 Clinton. From sethfiermonti at me.com Tue Apr 28 15:49:29 2009 From: sethfiermonti at me.com (Seth Fiermonti) Date: Tue, 28 Apr 2009 15:49:29 -0400 Subject: [c-nsp] 7600 with Sup720-3CXL and 6704/8 line cards Message-ID: <4335BDBC-19AD-4121-97CA-5284F43DF5BA@me.com> Hello, I am new to this and got very confused looking at cisco.com. Can I do MPLS and large route tables with 67xx line cards in the 7600? I have DFCs in all cards. What are my limitations? Do I need ES/ES+ modules instead? Any help is appreciated! From anthony.gueneau at gmail.com Tue Apr 28 15:56:45 2009 From: anthony.gueneau at gmail.com (Anthony GUENEAU) Date: Tue, 28 Apr 2009 21:56:45 +0200 Subject: [c-nsp] ICMP unreachable packets handling on IOS firewall (Zone-based not CBAC) Message-ID: <49f75f7c.0702d00a.4da2.ffff87cd@mx.google.com> Hello, I recently configured a Cisco 3825 router with the IOS firewall, running Zone-based Policy Firewall feature. I'm experiencing the following issue: ICMP unreachable packets, with code 4 (Fragmentation required, and DF flag set), passing through the fw-router are properly processed at the router layer (watched with debug ip packet) BUT seem to be completely ignored at the firewall/inspection layer! No match, no logging. Is it a regular behavior on IOS firewall ? If yes, I would like to know how to work around this issue. Indeed, because of that, ICMP unreachable packets do not reach the initial sender (asking him to fragment) and some TCP flows passing through the fw-router hang. Any help would be very welcome J Many thanks! Anthony From achatz at forthnet.gr Tue Apr 28 15:57:05 2009 From: achatz at forthnet.gr (Tassos Chatzithomaoglou) Date: Tue, 28 Apr 2009 22:57:05 +0300 Subject: [c-nsp] question about SSO In-Reply-To: References: <68f87c470904281151m59c0a378v6aaa02d38ab20aaf@mail.gmail.com> Message-ID: <49F75F91.7040905@forthnet.gr> Enhanced chassis (6500-E), DFC cards and SXI should do around 500ms. Cisco has said in later versions it will move down to 50ms. On my own L2 tests, the above setup did < 1s, regardless of which card was used for passing traffic. -- Tassos Church, Charles wrote on 28/04/2009 22:13: > Unless there are DFCs involved, I would expect a tiny delay when the > linecards switch over to the other PFC. I thought Cisco promised > failover times or a second or two with SSO on a 6500. I think you're > seeing what you should. > > Chuck > > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Neil d > Sent: Tuesday, April 28, 2009 2:51 PM > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] question about SSO > > > Hi everyone, > > I have a 7609s with 2 sup720, working in sso mode, now when the sup > switchover, according to cisco documentation, layer 2 traffic shouldnt > be > interupted, but I noticed there's a rougly 0.6s gap in packet loss. ( > traffic is in/out the same router, no other router involved). Is this > normal? I was thinking forwarding plan is not affected by the redundancy > switchover command. maybe I'm wrong? > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From gert at greenie.muc.de Tue Apr 28 16:03:40 2009 From: gert at greenie.muc.de (Gert Doering) Date: Tue, 28 Apr 2009 22:03:40 +0200 Subject: [c-nsp] 7600 with Sup720-3CXL and 6704/8 line cards In-Reply-To: <4335BDBC-19AD-4121-97CA-5284F43DF5BA@me.com> References: <4335BDBC-19AD-4121-97CA-5284F43DF5BA@me.com> Message-ID: <20090428200340.GT290@greenie.muc.de> Hi, On Tue, Apr 28, 2009 at 03:49:29PM -0400, Seth Fiermonti wrote: > I am new to this and got very confused looking at cisco.com. Can I do > MPLS and large route tables with 67xx line cards in the 7600? I have > DFCs in all cards. What are my limitations? Do I need ES/ES+ modules > instead? Your Google-Fu needs training. This is a VERY common topic on this mailing list. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 304 bytes Desc: not available URL: From rni at umn.edu Tue Apr 28 16:17:04 2009 From: rni at umn.edu (Richard N. Ingram) Date: Tue, 28 Apr 2009 15:17:04 -0500 Subject: [c-nsp] 3750 and show mls qos interface stat output In-Reply-To: <49F758FB.5050408@scripty.com> References: <49F758FB.5050408@scripty.com> Message-ID: <49F76440.1060109@umn.edu> The policer stats (Inprofile and OutofProfile) are right next to each other, instead of on top of each other, so there are indeed 6 fields in the command output as well. In addition, you get enqueued and drop statistics for each queue and threshold. You used to only get that from the "show platform port-asic stats" command, which was difficult to use. Rich Clinton Work wrote: > > Anybody have a more detailed description of the field headers for the > "show mls qos interface stat" output on a 3750? Table 2-30 > describes 6 field headers, but the command output only has 5 fields of > output. Are they the same as the 3550: incoming, no_change, > classified, policed, and dropped? > http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/command/reference/cli2.html#wp1947019 > > > Clinton. _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From gert at greenie.muc.de Tue Apr 28 16:24:02 2009 From: gert at greenie.muc.de (Gert Doering) Date: Tue, 28 Apr 2009 22:24:02 +0200 Subject: [c-nsp] 7600 with Sup720-3CXL and 6704/8 line cards In-Reply-To: References: <4335BDBC-19AD-4121-97CA-5284F43DF5BA@me.com> <20090428200340.GT290@greenie.muc.de> Message-ID: <20090428202402.GV290@greenie.muc.de> Hi, (I'm copying my reply back to the mailing list, as other readers will find the answers in the archives) On Tue, Apr 28, 2009 at 04:10:46PM -0400, Seth Fiermonti wrote: > If it is so common, please answer. We have this specific line of questions about once per months. It's really not so hard to find the answers in the archives. I assume you get paid to do research these questions. The people answering on the list are not paid to do this. > I am coming from a Foundry > background where things were just easier with regards to this. Why > does Cisco have to make everything so confusing? There is a reason > why no one gets fired for buying Cisco! Well, with foundry it's easy - "as soon as you want something complicated, the box will crash and burn". Indeed :-) > From my research, I cannot do VPLS on the 67xx line cards. Correct. > I also cannot do any MPLS VPNs if I am not mistaken. Wrong. With Sup720-3B and later, you can do all MPLS (L2 VPN, L3 VPN). Whether or not the box can do MPLS with "LAN cards" does not depend on the type of LAN card, but on the supervisor. No go with Sup1, Sup2, Sup720-3A, full MPLS support with Sup720-3B, -3C or RSP720. If you have DFCs, the box will run with the lowest common denominator - read: if you have a single "-3A", no MPLS. If all is -3B or better: MPLS. Some caveats apply, like "limited number of distinctive L3 VPNs" (1024 or so). Discussed two days ago. > My question is, can I > still populate up to 1 million IPv4 routes in the FIB on the 67xx. Yes. 1 million TCAM entries, to be carved into partitions for IPv4, IPv6, multicast and MPLS. > Also, if I enable ay MPLS VPN services, will my performance drop by 50%. This depends. If MPLS TCAM gets full (more than 512 VPNs), yes. Answered yesterday. gert -- USENET is *not* the non-clickable part of WWW! //www.muc.de/~gert/ Gert Doering - Munich, Germany gert at greenie.muc.de fax: +49-89-35655025 gert at net.informatik.tu-muenchen.de From peter at rathlev.dk Tue Apr 28 16:30:38 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Tue, 28 Apr 2009 22:30:38 +0200 Subject: [c-nsp] 3750 and show mls qos interface stat output In-Reply-To: <49F758FB.5050408@scripty.com> References: <49F758FB.5050408@scripty.com> Message-ID: <1240950638.7992.6.camel@localhost.localdomain> On Tue, 2009-04-28 at 13:28 -0600, Clinton Work wrote: > Anybody have a more detailed description of the field headers for the > "show mls qos interface stat" output on a 3750? Table 2-30 > describes 6 field headers, but the command output only has 5 fields of > output. Are they the same as the 3550: incoming, no_change, > classified, policed, and dropped? The command output has all 6 fields mentioned in Table 2-30 (DSCP incoming, DSCP outgoing, CoS incoming, CoS outgoing, Policer inprofile, Policer outofprofile) when I run it: AAR-R2-1-ASW-01#sh mls qos interface g1/0/1 stat Load for five secs: 6%/0%; one minute: 5%; five minutes: 5% Time source is NTP, 22:23:09.677 CEST Tue Apr 28 2009 GigabitEthernet1/0/1 dscp: incoming ------------------------------- 0 - 4 : 4214116912 0 0 0 0 ... 60 - 64 : 0 0 0 0 dscp: outgoing ------------------------------- 0 - 4 : 737640602 3 9 0 4 ... 60 - 64 : 0 0 0 0 cos: incoming ------------------------------- 0 - 4 : 52897690 0 0 4161830576 0 5 - 7 : 0 0 0 cos: outgoing ------------------------------- 0 - 4 : 738646401 0 0 350381249 0 5 - 7 : 0 6512607 0 Policer: Inprofile: 0 OutofProfile: 0 AAR-R2-1-ASW-01# Beware that the two policer statistics are in one line. Regards, Peter From clinton at scripty.com Tue Apr 28 18:02:39 2009 From: clinton at scripty.com (Clinton Work) Date: Tue, 28 Apr 2009 16:02:39 -0600 Subject: [c-nsp] 3750 and show mls qos interface stat output In-Reply-To: <49F76440.1060109@umn.edu> References: <49F758FB.5050408@scripty.com> <49F76440.1060109@umn.edu> Message-ID: <49F77CFF.6090700@scripty.com> All the fields are there, I was asking about the column headers. 3750# show mls qos int f1/0/15 stat FastEthernet1/0/15 cos: outgoing ------------------------------- incoming no_change classified policed dropped 0 - 4 : 96372939 4929270 0 8681542 16688309 5 - 7 : 1106025 10513898 3412 Take cos 0-4 as the example, do the column headers match the 3550 "show mls qos interface stat" output? Richard N. Ingram wrote: > The policer stats (Inprofile and OutofProfile) are right next to each > other, instead of on top of each other, so there are indeed 6 fields > in the command output as well. In addition, you get enqueued and drop > statistics for each queue and threshold. You used to only get that > from the "show platform port-asic stats" command, which was difficult > to use. From peter at rathlev.dk Tue Apr 28 18:29:10 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Wed, 29 Apr 2009 00:29:10 +0200 Subject: [c-nsp] 3750 and show mls qos interface stat output In-Reply-To: <49F77CFF.6090700@scripty.com> References: <49F758FB.5050408@scripty.com> <49F76440.1060109@umn.edu> <49F77CFF.6090700@scripty.com> Message-ID: <1240957750.9642.8.camel@localhost.localdomain> On Tue, 2009-04-28 at 16:02 -0600, Clinton Work wrote: > All the fields are there, I was asking about the column headers. > > 3750# show mls qos int f1/0/15 stat > FastEthernet1/0/15 > > cos: outgoing > ------------------------------- > incoming no_change classified policed > dropped > 0 - 4 : 96372939 4929270 0 8681542 16688309 > 5 - 7 : 1106025 10513898 3412 > > Take cos 0-4 as the example, do the column headers match the 3550 "show > mls qos interface stat" output? Is that from a 3750? The ones I have at hand right now haven't got that extra line. I tried 12.2(35)SE5 and 12.2(50)SE. And the documentation you referred to in the original post (12.2(46)SE) also doesn't display that extra line. Could it be a FastEthernet-specific thing? I don't have any 3750s with FE interfaces I'm afraid. And I have no idea how to interpret those headers. They're not column headers; the five columns are the five different CoS values mentioned at the beginning of the line. Regards, Peter From mduksa at gmail.com Tue Apr 28 21:10:17 2009 From: mduksa at gmail.com (Marlon Duksa) Date: Tue, 28 Apr 2009 18:10:17 -0700 Subject: [c-nsp] video processing modules Message-ID: Hi - does anyone know of a Cisco product that does a server function for Rapid Chanel Change and Retransmission. Is it a stand alone appliance or is it a service module in a 7600?Thanks, Marlon From llc at dansketelecom.com Wed Apr 29 02:28:00 2009 From: llc at dansketelecom.com (Lars Lystrup Christensen) Date: Wed, 29 Apr 2009 08:28:00 +0200 Subject: [c-nsp] video processing modules In-Reply-To: References: Message-ID: <44417CD2F19FEA4F885088340A71D33201E09653@mail.office.dansketelecom.com> Hi Marlon Yes, Cisco has an appliance for RCC, which is based on a technology called VQE (Visual Quality of Experience). The VQE consist of a server and a client, which is installed at the enduser equipment (e.g. STB or PC). The client is free and has been implemented on several STB from other vendors. The VQE can also do some retransmission (a few frames), so this is what you are looking for. You can read more about VQE on http://www.cisco.com/en/US/solutions/collateral/ns341/ns524/ns610/net_implementation_white_paper0900aecd8057f290.html ______________________________________ Med venlig hilsen / Kind regards Lars Lystrup Christensen Director of Engineering, CCIE(tm) #20292 Danske Telecom A/S Sundkrogsgade 13, 4 2100 K?benhavn ? -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Marlon Duksa Sent: 29. april 2009 03:10 To: cisco-nsp at puck.nether.net Subject: [c-nsp] video processing modules Hi - does anyone know of a Cisco product that does a server function for Rapid Chanel Change and Retransmission. Is it a stand alone appliance or is it a service module in a 7600?Thanks, Marlon _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From clinton at scripty.com Wed Apr 29 10:01:27 2009 From: clinton at scripty.com (Clinton Work) Date: Wed, 29 Apr 2009 08:01:27 -0600 Subject: [c-nsp] 3750 and show mls qos interface stat output In-Reply-To: <1240957750.9642.8.camel@localhost.localdomain> References: <49F758FB.5050408@scripty.com> <49F76440.1060109@umn.edu> <49F77CFF.6090700@scripty.com> <1240957750.9642.8.camel@localhost.localdomain> Message-ID: <49F85DB7.8000908@scripty.com> I added the column headers based upon what I thought they were. :-) What I missed is that they are simply the packet counters for each DScP or COS value. The 3550 was limited to reporting on 8 DSCP markings at a time and it didn't occur to me that the 3750 could report on all DSCP and COS values at the same time. Thanks. Peter Rathlev wrote: > Is that from a 3750? The ones I have at hand right now haven't got that > extra line. I tried 12.2(35)SE5 and 12.2(50)SE. And the documentation > you referred to in the original post (12.2(46)SE) also doesn't display > that extra line. > > Could it be a FastEthernet-specific thing? I don't have any 3750s with > FE interfaces I'm afraid. > > And I have no idea how to interpret those headers. They're not column > headers; the five columns are the five different CoS values mentioned at > the beginning of the line. > > From peter at rathlev.dk Wed Apr 29 10:30:18 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Wed, 29 Apr 2009 16:30:18 +0200 Subject: [c-nsp] 7600 with Sup720-3CXL and 6704/8 line cards In-Reply-To: <20090428202402.GV290@greenie.muc.de> References: <4335BDBC-19AD-4121-97CA-5284F43DF5BA@me.com> <20090428200340.GT290@greenie.muc.de> <20090428202402.GV290@greenie.muc.de> Message-ID: <1241015418.26239.11.camel@localhost.localdomain> On Tue, 2009-04-28 at 22:24 +0200, Gert Doering wrote: > On Tue, Apr 28, 2009 at 04:10:46PM -0400, Seth Fiermonti wrote: > > If it is so common, please answer. Ehh... that seems like very questionable logic. To me this says: If the answer is so common that I'd have to be quite careful NOT to find it, I still want the answer served. I sincerely hope OP was thinking in another direction. If I do a search on "7600 mpls" from the front page of cisco.com the third link describes configurations and restrictions regarding MPLS and PFC3B, probably the most common setup. Maybe a FAQ is really overdue. :-) Regards, Peter From panocisco77 at gmail.com Wed Apr 29 11:03:37 2009 From: panocisco77 at gmail.com (Renelson Panosky) Date: Wed, 29 Apr 2009 11:03:37 -0400 Subject: [c-nsp] Anybody here is running IPv6 Message-ID: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> Hello fellow Engineers We are getting ready to start testing IPv6 at my job, if you are running IPv6 right now please let me how is it working fo you? I would like to know the good, the bad and the ugly Renelson From zeusdadog at gmail.com Wed Apr 29 11:35:47 2009 From: zeusdadog at gmail.com (Jay Nakamura) Date: Wed, 29 Apr 2009 11:35:47 -0400 Subject: [c-nsp] QoS and VLAN Message-ID: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> We have several customers coming in on Ethernet. They are connected to L2 switch and trunked into a 7500 router via VLAN. This has worked fine so far with the use of rate-limit on the sub-interface. Most customers have 5~10mbps. However, we are increasingly needing QoS so VoIP traffic does not drop when data traffic bursts. Only work around I know how to do is to give separate rate-limit based on IP address since most of the time VoIP has separate gateway on the customer side than the data firewall. Classification of the traffic is not a problem. The issue is, how do you give VoIP traffic priority over data traffic on a Ethernet sub-interface? Is there a good way to implement this on a 7500? If not, what Cisco hardware will work? We are on a tight budget and the number of clients are small. (dozen or so) Would going with L3 switch be better? If so, what model? Thanks! From mark.kelsay at confused.com Wed Apr 29 11:42:45 2009 From: mark.kelsay at confused.com (Kelsay, Mark) Date: Wed, 29 Apr 2009 16:42:45 +0100 Subject: [c-nsp] CSS 11501 Question Message-ID: <62D8ECFDF835A648AD4FB4328B15F364047ECC14@mud.admiral.uk> I need to erase an old config and tried the erase config command but it did not work. Any idea what the command is? I am consoled into the console port. TIA, Mark ****** This email is sent for and on behalf of Inspop.com Limited ****** Authorised and regulated by the Financial Services Authority. Registration no. 310635. Inspop.com Limited [also trading as "Confused.com"] is registered in England and Wales at 2nd Floor, Friary House, Greyfriars Road, Cardiff, CF10 3AE [Reg. No. 03857130]. Any opinions expressed in this email are those of the individual and not necessarily the company. This email and any files transmitted with it, including replies and forwarded copies [which may contain alterations] subsequently transmitted from the Company, are confidential and solely for the use of the intended recipient. It may contain material protected by attorney-client privilege. If you are not the intended recipient or the person responsible for delivering to the intended recipient, be advised that you have received this email in error and that any use is strictly prohibited. If you have received this email in error please notify the Information Security Officer by telephone on +44 [0] 29 2043 4372. Please then delete this email and destroy any copies of it. This email has been swept for viruses before leaving our system. Security Warning: Please note that this email has been created in the knowledge that Internet email is not a 100% secure communications medium. We advise that you understand and accept this lack of security when emailing us. Viruses: Although we have taken steps to ensure that this email and any attachments are free from any virus, we advise that in keeping with good computing practice the recipient should ensure they are actually virus free. We may monitor the content of E-mails sent and received via our network for viruses or unauthorised use and for other lawful business purposes. ________________________________________________________________________ This e-mail has been scanned for all viruses by Messagelabs. The service is powered by MessageLabs. ________________________________________________________________________ From steve at ibctech.ca Wed Apr 29 12:19:12 2009 From: steve at ibctech.ca (Steve Bertrand) Date: Wed, 29 Apr 2009 12:19:12 -0400 Subject: [c-nsp] Anybody here is running IPv6 In-Reply-To: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> References: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> Message-ID: <49F87E00.6030605@ibctech.ca> Renelson Panosky wrote: > Hello fellow Engineers > > We are getting ready to start testing IPv6 at my job, if you are running > IPv6 right now please let me how is it working fo you? It works just as well as IPv4 does :) > I would like to know > the good, - it's just emerging so learning/implementing now will allow me to relax when the real crunch hits - deployment/experience as early as possible allows you to really find out which of your hardware, services, software etc are not compatible, and provide you the opportunity to rectify things that are lacking - the sheer size of the address space > the bad and the ugly I wouldn't say anything bad or ugly. Personally, I really enjoyed delving into it, and very glad we're moving forward. Of course it adds management time as it pretty much doubles everything (ACL's, BGP peerings, IP allocation/assignment documentation, troubleshooting (is it v4 that's broken, or v6)). Other than certain pieces of the software we run on all of our mail servers (Matt Simerson's Mail Toaster) that required some custom patches to make it v6 capable, no other major services had any trouble at all (web servers, DNS servers (mix of TinyDNS & BIND), SSH etc) after some slight reconfiguration. We don't use the router advertisement functions at all, but the combination of eui-64 addresses on PtP links running OSPFv3 for loopbacks is wonderful, and eui-64 addresses in general are handy for copy/paste config deployments. We've currently got v6 deployed to all of our edge routers, and a couple of our 100Mb fibre clients are testing it internally with us on a small scale. All new client deployments we handle (that are not wholesaled ie: SDSL, fibre, wireless etc) are going out v6 enabled if the CE is managed. We're working on gaining native v6 connectivity at this point, which has been the biggest hurdle. I've finally learnt who provides it, but in my current setup, I need to learn more about the inner workings of the IX before I can decide how to proceed. Currently, we announce our prefix via two providers through IPv6IP tunnels, which has worked very well. Once we go native and use our own bandwidth, I will allow clients to use v6 in production. Feel free to ask any further information on, or off-list. Steve -IPv6 enabled since March 2008 From lsawyer at gci.com Wed Apr 29 12:33:51 2009 From: lsawyer at gci.com (Leif Sawyer) Date: Wed, 29 Apr 2009 08:33:51 -0800 Subject: [c-nsp] Anybody here is running IPv6 In-Reply-To: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> Message-ID: <38D04BF3A4B7B2499D19EB1DB54285EA0A63F5DA@FNB1EX01.gci.com> > Renelson Panosky writes: > We are getting ready to start testing IPv6 at my job, if you > are running IPv6 right now please let me how is it working fo you? > I would like to know the good, the bad and the ugly. The good: I have a heirarchical addressing model that puts all of my loopbacks into a single /64; as well, all my internal core links are also consolidated into a single /64. This makes for very simple management ACLs*. * there is no trade-off in security here, as if you allow router-to-router vty connections, once an attacker has brute-forced into one router, they have access to all of them hop-by-hop. my 12xxx, 7600, 6500, 7200 series router all support it with BGP and ISIS, and no issues. I've got /127's on some point-to-point links with no issues (cisco-to-cisco) and /125's on other non-cisco-to-cisco point-to-point links. I haven't rolled out to smaller-model devices, but my original lab was 2621XM's, so I know it's supported there, too. The bad: There is no cisco firewall archetecture that allows mixed-mode IPv4 and IPv6. Oh, they -claim- that it works, but it is so full of caveats and bugs that it is effectively broken. 1) you can't have IPv6 on and IPv4 context using shared-interfaces -even if- you have static IPv6 addresses with a prefix-len < 64 and have disabled auto-discovery. 2) you can't mix an IPv6 and a separate IPv4 context using cross-connected switchports, -even with STP disabled-, because of what appear to be multiple issues. TAC case opened. 3) if you -want- to use the GUI, you can't use it for IPv6. at all. and The Ugly: 1) there are no Cisco training classes for IPv6-based services. Oh, sure, there's an -intro- to IPv6. But nothing in terms of migration planning, scaling, firewalling, application support, nothing. 2) if you mention IPv6 to the TAC, your time for support resolution increases exponentially; the image given is that nobody there understands it or is willing to support it. There's probably more, if I sit and think about it. From leonardo.souza at nec.com.br Wed Apr 29 12:36:46 2009 From: leonardo.souza at nec.com.br (Leonardo Gama Souza) Date: Wed, 29 Apr 2009 13:36:46 -0300 Subject: [c-nsp] RES: CSS 11501 Question In-Reply-To: <62D8ECFDF835A648AD4FB4328B15F364047ECC14@mud.admiral.uk> References: <62D8ECFDF835A648AD4FB4328B15F364047ECC14@mud.admiral.uk> Message-ID: <9E07F8717FE8BC4FBAE6860F61EA6C1D023E6890@spsrvmail03.nec.br> Are you in debug mode? if not, execute: #llama -----Mensagem original----- De: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] Em nome de Kelsay, Mark Enviada em: quarta-feira, 29 de abril de 2009 12:43 Para: cisco-nsp at puck.nether.net Assunto: [c-nsp] CSS 11501 Question I need to erase an old config and tried the erase config command but it did not work. Any idea what the command is? I am consoled into the console port. TIA, Mark ****** This email is sent for and on behalf of Inspop.com Limited ****** Authorised and regulated by the Financial Services Authority. Registration no. 310635. Inspop.com Limited [also trading as "Confused.com"] is registered in England and Wales at 2nd Floor, Friary House, Greyfriars Road, Cardiff, CF10 3AE [Reg. No. 03857130]. Any opinions expressed in this email are those of the individual and not necessarily the company. This email and any files transmitted with it, including replies and forwarded copies [which may contain alterations] subsequently transmitted from the Company, are confidential and solely for the use of the intended recipient. It may contain material protected by attorney-client privilege. If you are not the intended recipient or the person responsible for delivering to the intended recipient, be advised that you have received this email in error and that any use is strictly prohibited. If you have received this email in error please notify the Information Security Officer by telephone on +44 [0] 29 2043 4372. Please then delete this email and destroy any copies of it. This email has been swept for viruses before leaving our system. Security Warning: Please note that this email has been created in the knowledge that Internet email is not a 100% secure communications medium. We advise that you understand and accept this lack of security when emailing us. Viruses: Although we have taken steps to ensure that this email and any attachments are free from any virus, we advise that in keeping with good computing practice the recipient should ensure they are actually virus free. We may monitor the content of E-mails sent and received via our network for viruses or unauthorised use and for other lawful business purposes. ________________________________________________________________________ This e-mail has been scanned for all viruses by Messagelabs. The service is powered by MessageLabs. ________________________________________________________________________ _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From SteveMc at netservicesplc.com Wed Apr 29 12:39:57 2009 From: SteveMc at netservicesplc.com (Steve McCrory) Date: Wed, 29 Apr 2009 17:39:57 +0100 Subject: [c-nsp] QoS and VLAN In-Reply-To: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> Message-ID: <1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com> Have you tried implementing Modular QoS CLI (MQC) using service policies? I haven't worked on the 7500 platform but we have successfully applied QoS for VoIP on subinterfaces on the 7200 series routers. It should be noted that on sub-interfaces, you need a parent service policy to shape traffic to a particular level and then a child service policy which will carry out the actual QoS markings/prioritizations within the shaped allowance. Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jay Nakamura Sent: 29 April 2009 16:36 To: cisco-nsp at puck.nether.net Subject: [c-nsp] QoS and VLAN We have several customers coming in on Ethernet. They are connected to L2 switch and trunked into a 7500 router via VLAN. This has worked fine so far with the use of rate-limit on the sub-interface. Most customers have 5~10mbps. However, we are increasingly needing QoS so VoIP traffic does not drop when data traffic bursts. Only work around I know how to do is to give separate rate-limit based on IP address since most of the time VoIP has separate gateway on the customer side than the data firewall. Classification of the traffic is not a problem. The issue is, how do you give VoIP traffic priority over data traffic on a Ethernet sub-interface? Is there a good way to implement this on a 7500? If not, what Cisco hardware will work? We are on a tight budget and the number of clients are small. (dozen or so) Would going with L3 switch be better? If so, what model? Thanks! _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- From mduksa at gmail.com Wed Apr 29 12:44:41 2009 From: mduksa at gmail.com (Marlon Duksa) Date: Wed, 29 Apr 2009 09:44:41 -0700 Subject: [c-nsp] video processing modules In-Reply-To: <44417CD2F19FEA4F885088340A71D33201E09653@mail.office.dansketelecom.com> References: <44417CD2F19FEA4F885088340A71D33201E09653@mail.office.dansketelecom.com> Message-ID: Thanks Lars. Do you know by any chance what is this appliance called? Probably the video module on ASR9K will have it as well. Thanks, Marlon On Tue, Apr 28, 2009 at 11:28 PM, Lars Lystrup Christensen < llc at dansketelecom.com> wrote: > Hi Marlon > > Yes, Cisco has an appliance for RCC, which is based on a technology called > VQE (Visual Quality of Experience). The VQE consist of a server and a > client, which is installed at the enduser equipment (e.g. STB or PC). The > client is free and has been implemented on several STB from other vendors. > > The VQE can also do some retransmission (a few frames), so this is what you > are looking for. > > You can read more about VQE on > http://www.cisco.com/en/US/solutions/collateral/ns341/ns524/ns610/net_implementation_white_paper0900aecd8057f290.html > > > > ______________________________________ > > Med venlig hilsen / Kind regards > > Lars Lystrup Christensen > Director of Engineering, CCIE(tm) #20292 > > Danske Telecom A/S > Sundkrogsgade 13, 4 > 2100 K?benhavn ? > > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto: > cisco-nsp-bounces at puck.nether.net] On Behalf Of Marlon Duksa > Sent: 29. april 2009 03:10 > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] video processing modules > > Hi - does anyone know of a Cisco product that does a server function for > Rapid Chanel Change and Retransmission. Is it a stand alone appliance or is > it a service module in a 7600?Thanks, > Marlon > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From david.freedman at uk.clara.net Wed Apr 29 13:08:41 2009 From: david.freedman at uk.clara.net (David Freedman) Date: Wed, 29 Apr 2009 18:08:41 +0100 Subject: [c-nsp] Anybody here is running IPv6 In-Reply-To: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> References: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> Message-ID: No IPv6 uRPF in hardware on 6500/7600 No IPv6 uRPF at all in many other cisco platforms. Dave. Renelson Panosky wrote: > Hello fellow Engineers > > We are getting ready to start testing IPv6 at my job, if you are running > IPv6 right now please let me how is it working fo you? I would like to know > the good, the bad and the ugly > > Renelson > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From cchurc05 at harris.com Wed Apr 29 13:14:33 2009 From: cchurc05 at harris.com (Church, Charles) Date: Wed, 29 Apr 2009 12:14:33 -0500 Subject: [c-nsp] QoS and VLAN In-Reply-To: <1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com> Message-ID: Steve, You have an example of this? I've found on the platforms I work on most that you can't use any LLQ (priority keyword) on a subint. So I've put a policy handling the priority stuff on the main int, and then the other shaping/policing stuff on the subint, but have always questioned its effectiveness, or the order of operation for traffic, whether it hits the subint policy first, or the main int one. Thanks, Chuck -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Steve McCrory Sent: Wednesday, April 29, 2009 12:40 PM To: Jay Nakamura; cisco-nsp at puck.nether.net Subject: Re: [c-nsp] QoS and VLAN Have you tried implementing Modular QoS CLI (MQC) using service policies? I haven't worked on the 7500 platform but we have successfully applied QoS for VoIP on subinterfaces on the 7200 series routers. It should be noted that on sub-interfaces, you need a parent service policy to shape traffic to a particular level and then a child service policy which will carry out the actual QoS markings/prioritizations within the shaped allowance. Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jay Nakamura Sent: 29 April 2009 16:36 To: cisco-nsp at puck.nether.net Subject: [c-nsp] QoS and VLAN We have several customers coming in on Ethernet. They are connected to L2 switch and trunked into a 7500 router via VLAN. This has worked fine so far with the use of rate-limit on the sub-interface. Most customers have 5~10mbps. However, we are increasingly needing QoS so VoIP traffic does not drop when data traffic bursts. Only work around I know how to do is to give separate rate-limit based on IP address since most of the time VoIP has separate gateway on the customer side than the data firewall. Classification of the traffic is not a problem. The issue is, how do you give VoIP traffic priority over data traffic on a Ethernet sub-interface? Is there a good way to implement this on a 7500? If not, what Cisco hardware will work? We are on a tight budget and the number of clients are small. (dozen or so) Would going with L3 switch be better? If so, what model? Thanks! _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From dnightin at wellesley.edu Wed Apr 29 13:00:31 2009 From: dnightin at wellesley.edu (Don Nightingale) Date: Wed, 29 Apr 2009 13:00:31 -0400 Subject: [c-nsp] CSS 11501 Question In-Reply-To: <62D8ECFDF835A648AD4FB4328B15F364047ECC14@mud.admiral.uk> References: <62D8ECFDF835A648AD4FB4328B15F364047ECC14@mud.admiral.uk> Message-ID: <49F887AF.3010801@wellesley.edu> "clear running-config" Kelsay, Mark wrote: > I need to erase an old config and tried the erase config command but it > did not work. Any idea what the command is? I am consoled into the > console port. > > > > TIA, > > > > Mark > > > > > ****** This email is sent for and on behalf of Inspop.com Limited ****** > Authorised and regulated by the Financial Services Authority. Registration no. 310635. > Inspop.com Limited [also trading as "Confused.com"] is registered in England and Wales at 2nd Floor, Friary House, Greyfriars Road, Cardiff, CF10 3AE [Reg. No. 03857130]. Any opinions expressed in this email are those of the individual and not necessarily the company. This email and any files transmitted with it, including replies and forwarded copies [which may contain alterations] subsequently transmitted from the Company, are confidential and solely for the use of the intended recipient. It may contain material protected by attorney-client privilege. If you are not the intended recipient or the person responsible for delivering to the intended recipient, be advised that you have received this email in error and that any use is strictly prohibited. > If you have received this email in error please notify the Information Security Officer by telephone on +44 [0] 29 2043 4372. Please then delete this email and destroy any copies of it. This email has been swept for viruses before leaving our system. > Security Warning: Please note that this email has been created in the knowledge that Internet email is not a 100% secure communications medium. We advise that you understand and accept this lack of security when emailing us. > Viruses: Although we have taken steps to ensure that this email and any attachments are free from any virus, we advise that in keeping with good computing practice the recipient should ensure they are actually virus free. > We may monitor the content of E-mails sent and received via our network for viruses or unauthorised use and for other lawful business purposes. > > > ________________________________________________________________________ > This e-mail has been scanned for all viruses by Messagelabs. The > service is powered by MessageLabs. ________________________________________________________________________ > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > -- Don Nightingale Systems and Networks Manager Wellesley College 781-283-3271 From dcp at dcptech.com Wed Apr 29 13:36:08 2009 From: dcp at dcptech.com (David Prall) Date: Wed, 29 Apr 2009 13:36:08 -0400 Subject: [c-nsp] Anybody here is running IPv6 In-Reply-To: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> References: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> Message-ID: <000601c9c8f1$0c877fd0$25967f70$@com> Probably better to stumble over to the ipv6-ops at lists.cluenet.de archives http://lists.cluenet.de/pipermail/ipv6-ops David -- http://dcp.dcptech.com > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- > bounces at puck.nether.net] On Behalf Of Renelson Panosky > Sent: Wednesday, April 29, 2009 11:04 AM > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] Anybody here is running IPv6 > > Hello fellow Engineers > > We are getting ready to start testing IPv6 at my job, if you are > running > IPv6 right now please let me how is it working fo you? I would like to > know > the good, the bad and the ugly > > Renelson > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From thomas.braun at flashstudy.de Wed Apr 29 12:46:18 2009 From: thomas.braun at flashstudy.de (Thomas Braun) Date: Wed, 29 Apr 2009 18:46:18 +0200 Subject: [c-nsp] QoS and VLAN In-Reply-To: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> Message-ID: <49F8845A.5080201@flashstudy.de> Hi, you should try Class Based Weighted Fair Queuing (CBWFQ), This ist what you are looking for. Regards thomas > We have several customers coming in on Ethernet. They are connected > to L2 switch and trunked into a 7500 router via VLAN. This has worked > fine so far with the use of rate-limit on the sub-interface. Most > customers have 5~10mbps. > > However, we are increasingly needing QoS so VoIP traffic does not drop > when data traffic bursts. Only work around I know how to do is to > give separate rate-limit based on IP address since most of the time > VoIP has separate gateway on the customer side than the data firewall. > > Classification of the traffic is not a problem. The issue is, how do > you give VoIP traffic priority over data traffic on a Ethernet > sub-interface? > > Is there a good way to implement this on a 7500? If not, what Cisco > hardware will work? We are on a tight budget and the number of > clients are small. (dozen or so) Would going with L3 switch be > better? If so, what model? > > Thanks! > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From SteveMc at netservicesplc.com Wed Apr 29 13:43:56 2009 From: SteveMc at netservicesplc.com (Steve McCrory) Date: Wed, 29 Apr 2009 18:43:56 +0100 Subject: [c-nsp] QoS and VLAN In-Reply-To: References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com> Message-ID: <1C15FB264A06794F8BDE2120972B51C1050E2BF5@netexch04.ad.netservicesplc.com> Hi Chuck, Here's an example of a nested policy that we have deployed on 7206VXR (NPE400): policy-map cust_4Mbvoip_parent class class-default shape average 4000000 service-policy cust-4Mvoip-out ! policy-map cust-4Mvoip-out class cust-rtp priority percent 28 class cust-skinny bandwidth percent 17 class cust-citrix-new bandwidth percent 45 class cust-network bandwidth percent 2 class class-default fair-queue ! interface GigabitEthernet1/0.230 description Southampton 10Mb encapsulation dot1Q 230 ip vrf forwarding TU-MZRS-01 ip address 192.168.1.89 255.255.255.248 ip verify unicast source reachable-via any no ip redirects no ip proxy-arp no snmp trap link-status service-policy output cust_4Mbvoip_parent end This seems to work quite well and helped to alleviate congestion problems that our customer was having after they rolled out VoIP across their network. Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -----Original Message----- From: Church, Charles [mailto:cchurc05 at harris.com] Sent: 29 April 2009 18:15 To: Steve McCrory; cisco-nsp at puck.nether.net Subject: RE: [c-nsp] QoS and VLAN Steve, You have an example of this? I've found on the platforms I work on most that you can't use any LLQ (priority keyword) on a subint. So I've put a policy handling the priority stuff on the main int, and then the other shaping/policing stuff on the subint, but have always questioned its effectiveness, or the order of operation for traffic, whether it hits the subint policy first, or the main int one. Thanks, Chuck -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Steve McCrory Sent: Wednesday, April 29, 2009 12:40 PM To: Jay Nakamura; cisco-nsp at puck.nether.net Subject: Re: [c-nsp] QoS and VLAN Have you tried implementing Modular QoS CLI (MQC) using service policies? I haven't worked on the 7500 platform but we have successfully applied QoS for VoIP on subinterfaces on the 7200 series routers. It should be noted that on sub-interfaces, you need a parent service policy to shape traffic to a particular level and then a child service policy which will carry out the actual QoS markings/prioritizations within the shaped allowance. Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jay Nakamura Sent: 29 April 2009 16:36 To: cisco-nsp at puck.nether.net Subject: [c-nsp] QoS and VLAN We have several customers coming in on Ethernet. They are connected to L2 switch and trunked into a 7500 router via VLAN. This has worked fine so far with the use of rate-limit on the sub-interface. Most customers have 5~10mbps. However, we are increasingly needing QoS so VoIP traffic does not drop when data traffic bursts. Only work around I know how to do is to give separate rate-limit based on IP address since most of the time VoIP has separate gateway on the customer side than the data firewall. Classification of the traffic is not a problem. The issue is, how do you give VoIP traffic priority over data traffic on a Ethernet sub-interface? Is there a good way to implement this on a 7500? If not, what Cisco hardware will work? We are on a tight budget and the number of clients are small. (dozen or so) Would going with L3 switch be better? If so, what model? Thanks! _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- From panocisco77 at gmail.com Wed Apr 29 13:52:32 2009 From: panocisco77 at gmail.com (Renelson Panosky) Date: Wed, 29 Apr 2009 13:52:32 -0400 Subject: [c-nsp] Anybody here is running IPv6 In-Reply-To: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> References: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> Message-ID: <16e2ac180904291052h130ad66eq2cc456365625375b@mail.gmail.com> Thank you all for the responses on IPv6 i've learned a lot from you guys and i feel a lot more comfortable Renelson On Wed, Apr 29, 2009 at 11:03 AM, Renelson Panosky wrote: > Hello fellow Engineers > > We are getting ready to start testing IPv6 at my job, if you are running > IPv6 right now please let me how is it working fo you? I would like to know > the good, the bad and the ugly > > Renelson > From trejrco at gmail.com Wed Apr 29 14:11:03 2009 From: trejrco at gmail.com (TJ) Date: Wed, 29 Apr 2009 14:11:03 -0400 Subject: [c-nsp] Anybody here is running IPv6 In-Reply-To: <38D04BF3A4B7B2499D19EB1DB54285EA0A63F5DA@FNB1EX01.gci.com> References: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> <38D04BF3A4B7B2499D19EB1DB54285EA0A63F5DA@FNB1EX01.gci.com> Message-ID: <007901c9c8f5$e601a520$b204ef60$@com> While this is a great conversation, and I hope people continue to jump in, I have something to say in response to the following excerpt: ... and The Ugly: 1) there are no Cisco training classes for IPv6-based services. Oh, sure, there's an -intro- to IPv6. But nothing in terms of migration planning, scaling, firewalling, application support, nothing. Cisco is making forward progress on this ... one step is migrating IPv6 (slowly!) into the certificatino process. Additionally, there are a couple of courses; an ~intro level course (IP6FDv2) and a more advanced course (DDINv2; which also has a "specialized" day for either Enterprise or Service Provider). ((Admittedly, still a bit light on the firewalling and application side. Not sure what you would like to see from Cisco on the Application side ... ?)) Additionally (^2), for the IOS-XR side of the world, an IPv6 course is being developed - IIRC, focussing on the configuration details and design goals. I have no ETA on that, but feel free to have your SEs push that up the chain :). And finally, there are some books out there from Cisco Press ... on the technical side, Chip's "Deploying IPv6 Networks" and Hogg's/Vyncke's "IPv6 Security" are top notch. I guess what I am trying to say is I wouldn't call it "ugly" - certainly not ideal yet, but better than it could be! As for Ugly#2, TAC not being sufficiently IPv6 clueful ... I have to agree with that! /TJ PS - In the interest of full disclosure, I suppose I should add a disclaimer - I was part of the development team for IP6FD and DDIN, and have taught both of them a couple of times. PPS - IPv6 enabled at work and at home(home is via 6to4, for now) ... dual-stack FTW. >-----Original Message----- >From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp- >bounces at puck.nether.net] On Behalf Of Leif Sawyer >Sent: Wednesday, April 29, 2009 12:34 PM >To: cisco-nsp at puck.nether.net >Subject: Re: [c-nsp] Anybody here is running IPv6 > >> Renelson Panosky writes: >> We are getting ready to start testing IPv6 at my job, if you are >> running IPv6 right now please let me how is it working fo you? >> I would like to know the good, the bad and the ugly. > > >The good: > > I have a heirarchical addressing model that puts all of my loopbacks into >a single /64; as well, all my internal core links are also consolidated into a >single /64. This makes for very simple management ACLs*. > >* there is no trade-off in security here, as if you allow router-to-router vty >connections, once an attacker has brute-forced into one router, they have >access to all of them hop-by-hop. > > my 12xxx, 7600, 6500, 7200 series router all support it with BGP and >ISIS, and no issues. I've got /127's on some point-to-point links with no >issues (cisco-to-cisco) and /125's on other non-cisco-to-cisco point-to-point >links. I haven't rolled out to smaller-model devices, but my original lab was >2621XM's, so I know it's supported there, too. > > >The bad: > There is no cisco firewall archetecture that allows mixed-mode >IPv4 and IPv6. Oh, they -claim- that it works, but it is so full of caveats >and bugs that it is effectively broken. > > 1) you can't have IPv6 on and IPv4 context using shared-interfaces > -even if- you have static IPv6 addresses with a prefix-len < 64 > and have disabled auto-discovery. > > 2) you can't mix an IPv6 and a separate IPv4 context using cross- >connected > switchports, -even with STP disabled-, because of what appear to > be multiple issues. TAC case opened. > > 3) if you -want- to use the GUI, you can't use it for IPv6. at all. > > >and The Ugly: > > 1) there are no Cisco training classes for IPv6-based services. >Oh, > sure, there's an -intro- to IPv6. But nothing in terms of > migration planning, scaling, firewalling, application support, > nothing. > > 2) if you mention IPv6 to the TAC, your time for support resolution > increases exponentially; the image given is that nobody there > understands it or is willing to support it. > > >There's probably more, if I sit and think about it. >_______________________________________________ >cisco-nsp mailing list cisco-nsp at puck.nether.net >https://puck.nether.net/mailman/listinfo/cisco-nsp >archive at http://puck.nether.net/pipermail/cisco-nsp/ From sethm at rollernet.us Wed Apr 29 14:28:21 2009 From: sethm at rollernet.us (Seth Mattinen) Date: Wed, 29 Apr 2009 11:28:21 -0700 Subject: [c-nsp] Anybody here is running IPv6 In-Reply-To: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> References: <16e2ac180904290803k750b46bu9760c23a330f3003@mail.gmail.com> Message-ID: <49F89C45.803@rollernet.us> Renelson Panosky wrote: > Hello fellow Engineers > > We are getting ready to start testing IPv6 at my job, if you are running > IPv6 right now please let me how is it working fo you? I would like to know > the good, the bad and the ugly > I'm not an ISP but I have deployed IPv6. I currently only offer POP3/IMAP, DNS, and webmail over IPv6. I can't say it gets much use outside of myself and a handful of users who are in to playing with IPv6, but I haven't received a single trouble ticket on it. Good: * Works great. My core, border, and edge is all dual stack. It's just like IPv4 with funny looking addresses. I announce a PI /48. It was completely painless to set up. Bad: * Access lists on the 3750 only let me use EUI-64 host entries. Maybe I'm just paranoid, but I don't like having MAC addresses exposed. * TCAM space suddenly looks very small with IPv6. Ugly: * I wish at least one of my upstreams offered dual-stack. * Systems out there in the world that think they have IPv6 connectivity but don't. This is a problem for deploying concurrent A and AAAA records. ~Seth From justin at justinshore.com Wed Apr 29 14:29:53 2009 From: justin at justinshore.com (Justin Shore) Date: Wed, 29 Apr 2009 13:29:53 -0500 Subject: [c-nsp] PIX/ASA full tunnel for clients Message-ID: <49F89CA1.5030009@justinshore.com> I've got what's probably a simple question that I just can't figure out. Is there a trick for setting up a "full" tunnel client VPN profiles (ie, no split tunneling?) on a PIX or ASA running v7 or better? I used to do this on VPN 3000 Concentrators with ease but my searches on "cisco ASA ipsec client VPN full tunnel" isn't giving me anything useful. Is it called something else now? I know that I have to run v7.x or better to hairpin encrypted and unencrypted traffic in and out of the outside interface. I could experiment with the routes I hand out in a test profile but I'd rather get the official word on how to do this. Thanks Justin From justin at justinshore.com Wed Apr 29 14:35:35 2009 From: justin at justinshore.com (Justin Shore) Date: Wed, 29 Apr 2009 13:35:35 -0500 Subject: [c-nsp] Anybody here is running IPv6 In-Reply-To: <38D04BF3A4B7B2499D19EB1DB54285EA0A63F5DA@FNB1EX01.gci.com> References: <38D04BF3A4B7B2499D19EB1DB54285EA0A63F5DA@FNB1EX01.gci.com> Message-ID: <49F89DF7.1080405@justinshore.com> Leif Sawyer wrote: > The bad: > There is no cisco firewall archetecture that allows mixed-mode > IPv4 and IPv6. Oh, they -claim- that it works, but it is so full of > caveats > and bugs that it is effectively broken. Does this include the FWSMs or just the ASAs and PIXs? > 2) if you mention IPv6 to the TAC, your time for support > resolution > increases exponentially; the image given is that nobody > there > understands it or is willing to support it. This tends to be what happens when I ask an IS-IS question, though I have had some engineers who had a very good grasp of it. It's just hit and miss. This makes me wish there was still a group within TAC that was dedicated to serving SPs so they could really bone up on things typically seen in SP environments like IS-IS. Justin From llc at dansketelecom.com Wed Apr 29 14:47:13 2009 From: llc at dansketelecom.com (Lars Lystrup Christensen) Date: Wed, 29 Apr 2009 20:47:13 +0200 Subject: [c-nsp] video processing modules In-Reply-To: References: <44417CD2F19FEA4F885088340A71D33201E09653@mail.office.dansketelecom.com> Message-ID: <44417CD2F19FEA4F885088340A71D33201E0977A@mail.office.dansketelecom.com> Hi Marlon Unfortunately I'm not that familiar with all the IPTV equipment. I just saw a few slides about the system last week at a local Cisco conference. I suggest you contact your local Cisco contact for further details. ______________________________________ Med venlig hilsen / Kind regards Lars Lystrup Christensen Director of Engineering, CCIE(tm) #20292 Danske Telecom A/S Sundkrogsgade 13, 4 2100 K?benhavn ? ________________________________ From: Marlon Duksa [mailto:mduksa at gmail.com] Sent: 29. april 2009 18:45 To: Lars Lystrup Christensen Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] video processing modules Thanks Lars. Do you know by any chance what is this appliance called? Probably the video module on ASR9K will have it as well. Thanks, Marlon On Tue, Apr 28, 2009 at 11:28 PM, Lars Lystrup Christensen wrote: Hi Marlon Yes, Cisco has an appliance for RCC, which is based on a technology called VQE (Visual Quality of Experience). The VQE consist of a server and a client, which is installed at the enduser equipment (e.g. STB or PC). The client is free and has been implemented on several STB from other vendors. The VQE can also do some retransmission (a few frames), so this is what you are looking for. You can read more about VQE on http://www.cisco.com/en/US/solutions/collateral/ns341/ns524/ns610/net_implementation_white_paper0900aecd8057f290.html ______________________________________ Med venlig hilsen / Kind regards Lars Lystrup Christensen Director of Engineering, CCIE(tm) #20292 Danske Telecom A/S Sundkrogsgade 13, 4 2100 K?benhavn ? -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Marlon Duksa Sent: 29. april 2009 03:10 To: cisco-nsp at puck.nether.net Subject: [c-nsp] video processing modules Hi - does anyone know of a Cisco product that does a server function for Rapid Chanel Change and Retransmission. Is it a stand alone appliance or is it a service module in a 7600?Thanks, Marlon _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From Jason.Link at whgroup.com Wed Apr 29 14:51:09 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Wed, 29 Apr 2009 13:51:09 -0500 Subject: [c-nsp] PIX/ASA full tunnel for clients In-Reply-To: <49F89CA1.5030009@justinshore.com> References: <49F89CA1.5030009@justinshore.com> Message-ID: In the group policy for the specific VPN instance, use "split-tunnel-policy tunnelall" -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Justin Shore Sent: Wednesday, April 29, 2009 1:30 PM To: 'Cisco-nsp' Subject: [c-nsp] PIX/ASA full tunnel for clients I've got what's probably a simple question that I just can't figure out. Is there a trick for setting up a "full" tunnel client VPN profiles (ie, no split tunneling?) on a PIX or ASA running v7 or better? I used to do this on VPN 3000 Concentrators with ease but my searches on "cisco ASA ipsec client VPN full tunnel" isn't giving me anything useful. Is it called something else now? I know that I have to run v7.x or better to hairpin encrypted and unencrypted traffic in and out of the outside interface. I could experiment with the routes I hand out in a test profile but I'd rather get the official word on how to do this. Thanks Justin _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From mksmith at adhost.com Wed Apr 29 14:58:37 2009 From: mksmith at adhost.com (Michael K. Smith - Adhost) Date: Wed, 29 Apr 2009 11:58:37 -0700 Subject: [c-nsp] PIX/ASA full tunnel for clients In-Reply-To: <49F89CA1.5030009@justinshore.com> References: <49F89CA1.5030009@justinshore.com> Message-ID: <17838240D9A5544AAA5FF95F8D52031605EC138F@ad-exh01.adhost.lan> Hi Justin: -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Justin Shore Sent: Wednesday, April 29, 2009 11:30 AM To: 'Cisco-nsp' Subject: [c-nsp] PIX/ASA full tunnel for clients I've got what's probably a simple question that I just can't figure out. Is there a trick for setting up a "full" tunnel client VPN profiles (ie, no split tunneling?) on a PIX or ASA running v7 or better? I used to do this on VPN 3000 Concentrators with ease but my searches on "cisco ASA ipsec client VPN full tunnel" isn't giving me anything useful. Is it called something else now? I know that I have to run v7.x or better to hairpin encrypted and unencrypted traffic in and out of the outside interface. I could experiment with the routes I hand out in a test profile but I'd rather get the official word on how to do this. Thanks Justin [Michael K. Smith - Adhost] On the ASA you have to do the change in the group-policy settings: group-policy attributes split-tunnel-policy tunnelall Regards, Mike From rshughes at gmail.com Wed Apr 29 15:01:01 2009 From: rshughes at gmail.com (Ryan Hughes) Date: Wed, 29 Apr 2009 15:01:01 -0400 Subject: [c-nsp] PIX/ASA full tunnel for clients In-Reply-To: <49F89CA1.5030009@justinshore.com> References: <49F89CA1.5030009@justinshore.com> Message-ID: Not really - simply don't specify a split tunnel policy under the group-policy for the Remote Access group on the ASA. group-policy RAS attributes dns-server value X.X.X.X vpn-tunnel-protocol IPSec split-tunnel-policy excludespecified ! don't need split-tunnel-network-list value TEST-ACL ! don't need address-pools value VPN-POOL2 webvpn url-list value XXX-XXX Ryan On Wed, Apr 29, 2009 at 2:29 PM, Justin Shore wrote: > I've got what's probably a simple question that I just can't figure out. > > Is there a trick for setting up a "full" tunnel client VPN profiles (ie, no > split tunneling?) on a PIX or ASA running v7 or better? I used to do this > on VPN 3000 Concentrators with ease but my searches on "cisco ASA ipsec > client VPN full tunnel" isn't giving me anything useful. Is it called > something else now? I know that I have to run v7.x or better to hairpin > encrypted and unencrypted traffic in and out of the outside interface. > > I could experiment with the routes I hand out in a test profile but I'd > rather get the official word on how to do this. > > Thanks > Justin > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From justin at justinshore.com Wed Apr 29 15:02:43 2009 From: justin at justinshore.com (Justin Shore) Date: Wed, 29 Apr 2009 14:02:43 -0500 Subject: [c-nsp] PIX/ASA full tunnel for clients In-Reply-To: References: <49F89CA1.5030009@justinshore.com> Message-ID: <49F8A453.3020804@justinshore.com> Jason, Michael, and Luan, Thanks for the replies. That's exactly what I was looking for. I never looked for a sub-option under the split-tunnel config. I figured there was an alternate command to the split-tunnel command that I just couldn't find. Thanks again Justin Jason Link wrote: > In the group policy for the specific VPN instance, use > "split-tunnel-policy tunnelall" From zeusdadog at gmail.com Wed Apr 29 15:09:41 2009 From: zeusdadog at gmail.com (Jay Nakamura) Date: Wed, 29 Apr 2009 15:09:41 -0400 Subject: [c-nsp] QoS and VLAN In-Reply-To: <1C15FB264A06794F8BDE2120972B51C1050E2BF5@netexch04.ad.netservicesplc.com> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF5@netexch04.ad.netservicesplc.com> Message-ID: <9418aca70904291209x6852365emf83323d998554972@mail.gmail.com> Thanks Steve, after seeing your example, I found this http://www.cisco.com/en/US/partner/tech/tk543/tk545/technologies_tech_note09186a0080114326.shtml Would it work on inbound traffic? On Wed, Apr 29, 2009 at 1:43 PM, Steve McCrory wrote: > Hi Chuck, > > Here's an example of a nested policy that we have deployed on 7206VXR > (NPE400): > > policy-map cust_4Mbvoip_parent > ?class class-default > ? ?shape average 4000000 > ? service-policy cust-4Mvoip-out > ! > policy-map cust-4Mvoip-out > ?class cust-rtp > ? ?priority percent 28 > ?class cust-skinny > ? ?bandwidth percent 17 > ?class cust-citrix-new > ? ?bandwidth percent 45 > ?class cust-network > ? ?bandwidth percent 2 > ?class class-default > ? ?fair-queue > ! > interface GigabitEthernet1/0.230 > ?description Southampton 10Mb > ?encapsulation dot1Q 230 > ?ip vrf forwarding TU-MZRS-01 > ?ip address 192.168.1.89 255.255.255.248 > ?ip verify unicast source reachable-via any > ?no ip redirects > ?no ip proxy-arp > ?no snmp trap link-status > ?service-policy output cust_4Mbvoip_parent > end > > This seems to work quite well and helped to alleviate congestion > problems that our customer was having after they rolled out VoIP across > their network. > > Steven > > Steven McCrory > > Senior Network Engineer > > Netservices PLC > Waters Edge Business Park > Modwen Road > Manchester, M5 3EZ > > www.netservicesplc.com > -----Original Message----- > From: Church, Charles [mailto:cchurc05 at harris.com] > Sent: 29 April 2009 18:15 > To: Steve McCrory; cisco-nsp at puck.nether.net > Subject: RE: [c-nsp] QoS and VLAN > > Steve, > > ? ? ? ?You have an example of this? ?I've found on the platforms I work > on most that you can't use any LLQ (priority keyword) on a subint. ?So > I've put a policy handling the priority stuff on the main int, and then > the other shaping/policing stuff on the subint, but have always > questioned its effectiveness, or the order of operation for traffic, > whether it hits the subint policy first, or the main int one. > > Thanks, > > Chuck > > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Steve McCrory > Sent: Wednesday, April 29, 2009 12:40 PM > To: Jay Nakamura; cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] QoS and VLAN > > > Have you tried implementing Modular QoS CLI (MQC) using service > policies? > > I haven't worked on the 7500 platform but we have successfully applied > QoS for VoIP on subinterfaces on the 7200 series routers. > > It should be noted that on sub-interfaces, you need a parent service > policy to shape traffic to a particular level and then a child service > policy which will carry out the actual QoS markings/prioritizations > within the shaped allowance. > > Steven > > Steven McCrory > > Senior Network Engineer > > Netservices PLC > Waters Edge Business Park > Modwen Road > Manchester, M5 3EZ > > www.netservicesplc.com > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jay Nakamura > Sent: 29 April 2009 16:36 > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] QoS and VLAN > > We have several customers coming in on Ethernet. ?They are connected > to L2 switch and trunked into a 7500 router via VLAN. ?This has worked > fine so far with the use of rate-limit on the sub-interface. ?Most > customers have 5~10mbps. > > However, we are increasingly needing QoS so VoIP traffic does not drop > when data traffic bursts. ?Only work around I know how to do is to > give separate rate-limit based on IP address since most of the time > VoIP has separate gateway on the customer side than the data firewall. > > Classification of the traffic is not a problem. ?The issue is, how do > you give VoIP traffic priority over data traffic on a Ethernet > sub-interface? > > Is there a good way to implement this on a 7500? ?If not, what Cisco > hardware will work? ?We are on a tight budget and the number of > clients are small. ?(dozen or so) ?Would going with L3 switch be > better? ?If so, what model? > > Thanks! > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > -------- > NetServices plc, Company No. 4178393, > Registered Office: NetServices House, 31 Modwen Road, > Waters Edge Business Park, SALFORD, M5 3EZ > -------- > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > -------- > NetServices plc, Company No. 4178393, > Registered Office: NetServices House, 31 Modwen Road, > Waters Edge Business Park, SALFORD, M5 3EZ > -------- > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From anthony.gueneau at gmail.com Wed Apr 29 15:24:43 2009 From: anthony.gueneau at gmail.com (Anthony GUENEAU) Date: Wed, 29 Apr 2009 21:24:43 +0200 Subject: [c-nsp] ICMP unreachable packets handling on IOS firewall (Zone-based not CBAC) In-Reply-To: <49F81946.3030109@ya.ru> References: <49f75f7c.0702d00a.4da2.ffff87cd@mx.google.com> <49F81946.3030109@ya.ru> Message-ID: <49f8a979.1701d00a.7bad.6cc2@mx.google.com> Hello, Forget about it. I solved the issue by clamping the TCP MSS (maximum segment size) to 1200 bytes on packets flowing through the corresponding router interfaces. I used the following command in config-int: ip tcp adjust-mss 1200. This trick prevent IP fragmentation along the path by forcing senders to reduce their TCP MSS and so the MTU. Now the MTU=1240 Anyway, for your information, I got the confirmation the IOS firewalls do ignore ICMP unreachable packets! Thanks anyway! Regards, Anthony GUENEAU -----Original Message----- From: junior [mailto:drrtuy at ya.ru] Sent: mercredi 29 avril 2009 11:09 To: Anthony GUENEAU Subject: Re: [c-nsp] ICMP unreachable packets handling on IOS firewall (Zone-based not CBAC) Hello. > I recently configured a Cisco 3825 router with the IOS firewall, running > Zone-based Policy Firewall feature. > > I'm experiencing the following issue: > > ICMP unreachable packets, with code 4 (Fragmentation required, and DF flag > set), passing through the fw-router are properly processed at the router > layer (watched with debug ip packet) BUT seem to be completely ignored at > the firewall/inspection layer! No match, no logging. Can You share the IOS acl? > Is it a regular behavior on IOS firewall ? If yes, I would like to know how > to work around this issue. > > Indeed, because of that, ICMP unreachable packets do not reach the initial > sender (asking him to fragment) and some TCP flows passing through the > fw-router hang. What are You trying to achieve actually? > Any help would be very welcome J WBR Roman A. Nozdrin > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From Jason.Link at whgroup.com Wed Apr 29 15:57:54 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Wed, 29 Apr 2009 14:57:54 -0500 Subject: [c-nsp] ASA / EIGRP / Redundant Interfaces Message-ID: Hello all, With an ASA running a redundant physical interface pair for the Inside interface, each link connected to a separate switch which is connected to a separate router, and everything running EIGRP, I get multiple routes (2) to the same destination subnet, one for each of the connected routers. This is obviously causing problems, and I can't seem to find a way to resolve it. Setting delay on the physical interfaces doesn't seem to take effect, and there is no variance sub-command so I can't just force one route. This needs to function in a redundant situation, as in if I lose a router or switch everything will continue to function (hence the redundant interface). I tried google and cisco and found nothing of any significance...anyone got any ideas? Thanks! Jason Link Network Engineer Wisconsin Hospitality Group / RSC Office 414-259-8484 Cell 414-403-3110 From jeff-kell at utc.edu Wed Apr 29 16:23:48 2009 From: jeff-kell at utc.edu (Jeff Kell) Date: Wed, 29 Apr 2009 16:23:48 -0400 Subject: [c-nsp] 2975 stack... interoperability? Message-ID: <49F8B754.9030109@utc.edu> Quick question... the new[ish] Catalyst 2975 switch looks like a 2960+stacking. Do these things stack with 3750s / 3750Es ? They show up as another "blade" on the stack? Jeff From bdikici at gmail.com Wed Apr 29 16:53:00 2009 From: bdikici at gmail.com (Burak Dikici) Date: Wed, 29 Apr 2009 23:53:00 +0300 Subject: [c-nsp] rate limit per user traffic with WLC and billing system Message-ID: Hello , We want to rent the internet access service to the houses which are provided to employees. That's why we need bandwidth limit per user and billing system solution. There will be also a guest users in the network. Could you give me an idea , is it possible to do that with Cisco wireless LAN controller devices , if it is possible how can it be done ? In this address ; http://www.cisco.com/en/US/docs/wireless/controller/5.2/configuration/guide/c52ccfg.html#wpxref21838 "Using the CLI to Configure QoS Profiles " "To define the average data rate in Kbps for TCP traffic per user, enter this command: " "config qos average-data-rate {bronze | silver | gold | platinum} rate " I see this command option. What is this for , is this option helps me ? Another option is , "Per-User Bandwidth Contracts" option under QoS Profiles menu in the Controller. Is that option helps me also ? Kind Regards... From tvarriale at comcast.net Wed Apr 29 18:43:43 2009 From: tvarriale at comcast.net (Tony Varriale) Date: Wed, 29 Apr 2009 17:43:43 -0500 Subject: [c-nsp] ASA / EIGRP / Redundant Interfaces References: Message-ID: It's really hard to say without knowing some details about your network but if you want 1 path active at once you can always use the max-paths command set to 1. tv ----- Original Message ----- From: "Jason Link" To: "Cisco-nsp" Sent: Wednesday, April 29, 2009 2:57 PM Subject: [c-nsp] ASA / EIGRP / Redundant Interfaces > Hello all, > > > > With an ASA running a redundant physical interface pair for the Inside > interface, each link connected to a separate switch which is connected > to a separate router, and everything running EIGRP, I get multiple > routes (2) to the same destination subnet, one for each of the connected > routers. This is obviously causing problems, and I can't seem to find a > way to resolve it. Setting delay on the physical interfaces doesn't > seem to take effect, and there is no variance sub-command so I can't > just force one route. This needs to function in a redundant situation, > as in if I lose a router or switch everything will continue to function > (hence the redundant interface). I tried google and cisco and found > nothing of any significance...anyone got any ideas? > > > > Thanks! > > > > > > > > Jason Link > > Network Engineer > > Wisconsin Hospitality Group / RSC > > Office 414-259-8484 > > Cell 414-403-3110 > > > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From gsgranados at comcast.net Wed Apr 29 19:13:59 2009 From: gsgranados at comcast.net (Scott Granados) Date: Wed, 29 Apr 2009 16:13:59 -0700 Subject: [c-nsp] rate limit per user traffic with WLC and billing system In-Reply-To: References: Message-ID: Ok Burak officially gets to negotiate my future contracts. I've never had a house thrown in on an offer letter. ;) ----- Original Message ----- From: "Burak Dikici" To: Sent: Wednesday, April 29, 2009 1:53 PM Subject: [c-nsp] rate limit per user traffic with WLC and billing system > Hello , > > We want to rent the internet access service to the houses which are > provided to employees. That's why we need bandwidth limit per user and > billing system solution. There will be also a guest users in the network. > Could you give me an idea , is it possible to do that with Cisco wireless > LAN controller devices , if it is possible how can it be done ? > > In this address ; > http://www.cisco.com/en/US/docs/wireless/controller/5.2/configuration/guide/c52ccfg.html#wpxref21838 > "Using the CLI to Configure QoS Profiles " > > "To define the average data rate in Kbps for TCP traffic per user, enter > this command: " > "config qos average-data-rate {bronze | silver | gold | platinum} rate " > > I see this command option. What is this for , is this option helps me ? > > Another option is , "Per-User Bandwidth Contracts" option under QoS > Profiles > menu in the Controller. Is that option helps me also ? > > Kind Regards... > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > __________ Information from ESET NOD32 Antivirus, version of virus > signature database 4043 (20090429) __________ > > The message was checked by ESET NOD32 Antivirus. > > http://www.eset.com > > > From risnaini at indo.net.id Wed Apr 29 20:54:22 2009 From: risnaini at indo.net.id (a. rahman isnaini r.sutan) Date: Thu, 30 Apr 2009 07:54:22 +0700 Subject: [c-nsp] rate limit per user traffic with WLC and billing system In-Reply-To: References: Message-ID: <49F8F6BE.3020002@indo.net.id> Burack, Use Cisco Wireless as bridge & Mikrotik will do the rest [hotspot, bw management, qos] except billing for a cheaper solution. a. r. isnaini rangkayo sutan Scott Granados wrote: > Ok Burak officially gets to negotiate my future contracts. I've never > had a house thrown in on an offer letter. > > ;) > > > > ----- Original Message ----- From: "Burak Dikici" > To: > Sent: Wednesday, April 29, 2009 1:53 PM > Subject: [c-nsp] rate limit per user traffic with WLC and billing system > > >> Hello , >> >> We want to rent the internet access service to the houses which are >> provided to employees. That's why we need bandwidth limit per user and >> billing system solution. There will be also a guest users in the network. >> Could you give me an idea , is it possible to do that with Cisco wireless >> LAN controller devices , if it is possible how can it be done ? >> >> In this address ; >> http://www.cisco.com/en/US/docs/wireless/controller/5.2/configuration/guide/c52ccfg.html#wpxref21838 >> >> "Using the CLI to Configure QoS Profiles " >> >> "To define the average data rate in Kbps for TCP traffic per user, enter >> this command: " >> "config qos average-data-rate {bronze | silver | gold | platinum} rate " >> >> I see this command option. What is this for , is this option helps me ? >> >> Another option is , "Per-User Bandwidth Contracts" option under QoS >> Profiles >> menu in the Controller. Is that option helps me also ? >> >> Kind Regards... >> _______________________________________________ >> cisco-nsp mailing list cisco-nsp at puck.nether.net >> https://puck.nether.net/mailman/listinfo/cisco-nsp >> archive at http://puck.nether.net/pipermail/cisco-nsp/ >> >> __________ Information from ESET NOD32 Antivirus, version of virus >> signature database 4043 (20090429) __________ >> >> The message was checked by ESET NOD32 Antivirus. >> >> http://www.eset.com >> >> >> > > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > From cluestore at gmail.com Wed Apr 29 21:04:24 2009 From: cluestore at gmail.com (Clue Store) Date: Wed, 29 Apr 2009 20:04:24 -0500 Subject: [c-nsp] Pix 515 to 837 DSL IPsec Tunnel Message-ID: <580af3b90904291804m40a3fb0ds1b40cae0f4594183@mail.gmail.com> Hi All, This seems like a simple solution, but I cannot seem to get this working. What I have is a the following setup... 837-------[Internet]--------Pix515--------7200------[T1]----Customer 2691 I have a lan to lan tunnel going from the 837 to the pix. The 7200 behind the pix is addressed with the same subnet as the inside interface as the pix. I can currently ping from the 837 (lan interface) to the 7200 (lan interface in the pix subnet) with no issues. I cannot ping the T1 interface on the 7200 from the 837 nor can I ping from the 837 when sourcing pings from the T1 interface. I have a nonat statement on each side of the tunnel for the subnets that are involved, but still no luck. I can post cfg's if they are needed, but simply, will this setup work if translation (or non-translations in this case) and routing is setup correctly?? Or should I just do GREoIPSEC from the Customer 2691 to the 837?? tia Max From lobo at allstream.net Wed Apr 29 23:27:22 2009 From: lobo at allstream.net (Jose) Date: Wed, 29 Apr 2009 23:27:22 -0400 Subject: [c-nsp] Loose uRPF behaving like strict mode on 7600 Message-ID: <49F91A9A.9060403@allstream.net> I was wondering if someone might have an explanation as to why we encountered an issue with uRPF (loose mode) when we tried enabling it on our upstream facing links. We have 2 x 7603s w/ SUP32 acting as our Gwy routers and our transit providers connect into them (one on each gwy + private peers). We are fed from each of them the entire internet table along with a default route. Now I know that we are multi-homed and obviously have asymmetrical routing occurring so I decided to implement loose uRPF on the interfaces: ip verify unicast source reachable-via any However shortly after enabling it we got calls that our customers could not reach parts of the internet. Specifically destinations where the packets would travel over the links that had RPF enabled on them and were our transits. Traffic to and from our private peers appeared fine though with RPF. Pings to our internal CIDRs from external route-servers would fail as well so long as the path was over the transits. Disabling RPF on the interfaces resolved the problem immediately. From my understanding of this feature, it would seem as if the RPF check was working in strict mode vs loose mode. Could there have been something that we missed? Should the "allow-default" be used in this case? I've never had to use it before when I've implemented loose mode in other environments. The 7603s are running 12.2(18)SXF11 Advanced IP Services. Thanks for any feedback. Jose From brett at looney.id.au Wed Apr 29 23:25:01 2009 From: brett at looney.id.au (Brett Looney) Date: Thu, 30 Apr 2009 11:25:01 +0800 Subject: [c-nsp] 2975 stack... interoperability? In-Reply-To: <49F8B754.9030109@utc.edu> References: <49F8B754.9030109@utc.edu> Message-ID: <01b001c9c943$4236cfd0$c6a46f70$@id.au> > the new[ish] Catalyst 2975 switch looks like a 2960+stacking. > Do these things stack with 3750s / 3750Es ? They show > up as another "blade" on the stack? Word I have is that they do not stack. Haven't physically plugged one in to see what happens, however. B. From jlewis at lewis.org Thu Apr 30 00:18:54 2009 From: jlewis at lewis.org (Jon Lewis) Date: Thu, 30 Apr 2009 00:18:54 -0400 (EDT) Subject: [c-nsp] Loose uRPF behaving like strict mode on 7600 In-Reply-To: <49F91A9A.9060403@allstream.net> References: <49F91A9A.9060403@allstream.net> Message-ID: On Wed, 29 Apr 2009, Jose wrote: > I was wondering if someone might have an explanation as to why we encountered > an issue with uRPF (loose mode) when we tried enabling it on our upstream > facing links. We have 2 x 7603s w/ SUP32 acting as our Gwy routers and our > transit providers connect into them (one on each gwy + private peers). We > are fed from each of them the entire internet table along with a default > route. > > Now I know that we are multi-homed and obviously have asymmetrical routing > occurring so I decided to implement loose uRPF on the interfaces: ip verify > unicast source reachable-via any > > However shortly after enabling it we got calls that our customers could not > reach parts of the internet. Specifically destinations where the packets > would travel over the links that had RPF enabled on them and were our > transits. Traffic to and from our private peers appeared fine though with > RPF. Pings to our internal CIDRs from external route-servers would fail as > well so long as the path was over the transits. Disabling RPF on the > interfaces resolved the problem immediately. > > From my understanding of this feature, it would seem as if the RPF check was > working in strict mode vs loose mode. Could there have been something that > we missed? Should the "allow-default" be used in this case? I've never had > to use it before when I've implemented loose mode in other environments. > > The 7603s are running 12.2(18)SXF11 Advanced IP Services. http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/hybrid/release/notes/ol_4563.html#wp210802 ---------------------------------------------------------------------- Jon Lewis | I route Senior Network Engineer | therefore you are Atlantic Net | _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________ From rubensk at gmail.com Thu Apr 30 00:35:40 2009 From: rubensk at gmail.com (Rubens Kuhl) Date: Thu, 30 Apr 2009 01:35:40 -0300 Subject: [c-nsp] Cisco MPLS interoperability with Mikrotik (or Linux) MPLS Message-ID: <6bb5f5b10904292135h23af6144udea2645aee3a9af1@mail.gmail.com> Have anynone done any testing interoperating Cisco MPLS (Cat 6k or 7600 families) with Mikrotik (which is just packaging of MPLS Linux) ? I'm specially curious about EoMPLS and H-VPLS interoperating, but basic LDP/RSVP/MPLS-TE/MPLS-FRR also needs to be addressed, of course. Rubens From charles at thewybles.com Thu Apr 30 00:58:27 2009 From: charles at thewybles.com (Charles Wyble) Date: Wed, 29 Apr 2009 21:58:27 -0700 Subject: [c-nsp] Cisco MPLS interoperability with Mikrotik (or Linux) MPLS In-Reply-To: <6bb5f5b10904292135h23af6144udea2645aee3a9af1@mail.gmail.com> References: <6bb5f5b10904292135h23af6144udea2645aee3a9af1@mail.gmail.com> Message-ID: <49F92FF3.2010703@thewybles.com> Last time I looked into this (mid last year) the Linux bits weren't very mature. Not sure how Mikrotik or Vyatta have changed it. Hopefully they have made things better. Rubens Kuhl wrote: > Have anynone done any testing interoperating Cisco MPLS (Cat 6k or > 7600 families) with Mikrotik (which is just packaging of MPLS Linux) ? > I'm specially curious about EoMPLS and H-VPLS interoperating, but > basic LDP/RSVP/MPLS-TE/MPLS-FRR also needs to be addressed, of course. > > > Rubens > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > From tojo.raonisoa at yahoo.fr Thu Apr 30 02:25:39 2009 From: tojo.raonisoa at yahoo.fr (Tojo RAONISOA) Date: Thu, 30 Apr 2009 06:25:39 +0000 (GMT) Subject: [c-nsp] Defining new radius attribute on a Cisco NAS Message-ID: <821592.77481.qm@web23607.mail.ird.yahoo.com> Hello, I would like to ask you how to define a new radius attribute on a Cisco NAS (Cisco 3825). We have already define the attribute on our AAA server, but we don't know how to configure the Cisco NAS for this new attribute. Please could you help us to solve this ? Thanks. Best regards Tj From peter at rathlev.dk Thu Apr 30 03:22:32 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 30 Apr 2009 09:22:32 +0200 Subject: [c-nsp] ASA / EIGRP / Redundant Interfaces In-Reply-To: References: Message-ID: <1241076152.3465.1.camel@localhost.localdomain> On Wed, 2009-04-29 at 14:57 -0500, Jason Link wrote: > With an ASA running a redundant physical interface pair for the Inside > interface, each link connected to a separate switch which is connected > to a separate router, and everything running EIGRP, I get multiple > routes (2) to the same destination subnet, one for each of the connected > routers. This is obviously causing problems, and I can't seem to find a > way to resolve it. Setting delay on the physical interfaces doesn't > seem to take effect, and there is no variance sub-command so I can't > just force one route. This needs to function in a redundant situation, > as in if I lose a router or switch everything will continue to function > (hence the redundant interface). I tried google and cisco and found > nothing of any significance...anyone got any ideas? AFAIK the "standard" way of doing this would be a shared VLAN on the inside and then HSRP or similar on the routers. Any reason for not doing that? Regards, Peter From zhqasmi at cyber.net.pk Thu Apr 30 03:27:52 2009 From: zhqasmi at cyber.net.pk (Amjad Ul Hasnain Qasmi) Date: Thu, 30 Apr 2009 13:27:52 +0600 Subject: [c-nsp] TE-DB issue Message-ID: <007101c9c965$2ceeb0d0$86cc1270$@net.pk> Hello, I have enabled traffic engineering support in my domain. My setup is like. (Cisco)------Gig-------(Juniper1)-------FE-------(Juniper2). When I see the entries at Cisco in the TE-DB that were built from LSAs sent by Juniper2, it shows me igp metric as "IGP metric:invalid". I am unable to find any reference material on this issue any help will be highly appreciated. ---------------------------------------------------------------------------- -------------------------------- IGP Id: 192.168.96.251, MPLS TE Id:192.168.96.251 Router Node (ospf 10 area 0) id 53 link[0]: Broadcast, DR: 192.168.85.249, nbr_node_id:124, gen:22637 frag_id 4, Intf Address:192.168.85.250, Nbr Intf Address:0.0.0.0 TE metric:10, IGP metric:invalid, attribute flags:0x0 SRLGs: None physical_bw: 1000000 (kbps), max_reservable_bw_global: 1000000 (kbps) max_reservable_bw_sub: 0 (kbps) Global Pool Sub Pool Total Allocated Reservable Reservable BW (kbps) BW (kbps) BW (kbps) --------------- ----------- ---------- bw[0]: 0 1000000 0 bw[1]: 0 1000000 0 bw[2]: 0 1000000 0 bw[3]: 0 1000000 0 bw[4]: 0 1000000 0 bw[5]: 0 1000000 0 bw[6]: 0 1000000 0 bw[7]: 0 1000000 0 ---------------------------------------------------------------------------- -------------------------------- Regards, AHQ From eng_mssk at hotmail.com Thu Apr 30 04:07:59 2009 From: eng_mssk at hotmail.com (Mohammad Khalil) Date: Thu, 30 Apr 2009 11:07:59 +0300 Subject: [c-nsp] Security Management tool Message-ID: hey all, I am looking for a free software for security management any suggestions ? _________________________________________________________________ Drag n? drop?Get easy photo sharing with Windows Live? Photos. http://www.microsoft.com/windows/windowslive/products/photos.aspx From benny+usenet at amorsen.dk Thu Apr 30 05:38:12 2009 From: benny+usenet at amorsen.dk (Benny Amorsen) Date: Thu, 30 Apr 2009 11:38:12 +0200 Subject: [c-nsp] Cisco MPLS interoperability with Mikrotik (or Linux) MPLS In-Reply-To: <49F92FF3.2010703@thewybles.com> (Charles Wyble's message of "Wed\, 29 Apr 2009 21\:58\:27 -0700") References: <6bb5f5b10904292135h23af6144udea2645aee3a9af1@mail.gmail.com> <49F92FF3.2010703@thewybles.com> Message-ID: Charles Wyble writes: > Last time I looked into this (mid last year) the Linux bits weren't > very mature. Not sure how Mikrotik or Vyatta have changed it. > Hopefully they have made things better. Mikrotik has done their own MPLS/VPLS implementation. You can't really use experiences with the (indeed immature) attempts that others made as a guide. In the last 6 months Mikrotik's MPLS implementation has taken great leaps forward. /Benny From risnaini at indo.net.id Thu Apr 30 05:43:30 2009 From: risnaini at indo.net.id (a. rahman isnaini r.sutan) Date: Thu, 30 Apr 2009 16:43:30 +0700 Subject: [c-nsp] Security Management tool In-Reply-To: References: Message-ID: <49F972C2.3040805@indo.net.id> Mohammad, You mean open source ? PFsense, IPCop, Untangle, ect Unfortunately this list is not on what you need. rgs a. r. isnaini rangkayo sutan Mohammad Khalil wrote: > hey all, > I am looking for a free software for security management > any suggestions ? > > _________________________________________________________________ > Drag n? drop?Get easy photo sharing with Windows Live? Photos. > > http://www.microsoft.com/windows/windowslive/products/photos.aspx > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ From allan.eising+usenet at gmail.com Thu Apr 30 05:37:29 2009 From: allan.eising+usenet at gmail.com (Allan Eising) Date: Thu, 30 Apr 2009 09:37:29 +0000 (UTC) Subject: [c-nsp] Cisco MPLS interoperability with Mikrotik (or Linux) MPLS References: <6bb5f5b10904292135h23af6144udea2645aee3a9af1@mail.gmail.com> Message-ID: On Thu, 30 Apr 2009 01:35:40 -0300, Rubens Kuhl wrote: > Have anynone done any testing interoperating Cisco MPLS (Cat 6k or 7600 > families) with Mikrotik (which is just packaging of MPLS Linux) ? I'm > specially curious about EoMPLS and H-VPLS interoperating, but basic > LDP/RSVP/MPLS-TE/MPLS-FRR also needs to be addressed, of course. > > > Rubens > _______________________________________________ cisco-nsp mailing list > cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp archive at > http://puck.nether.net/pipermail/cisco-nsp/ Hi, MikroTik works fine against Cisco with their mpls-test and routing-test packages. LDP works fine, and they even got a cisco-style VPLS implementation that seem to work fine. Their L3VPN works fine too with OSPF. I haven't tested MPLS-TE, but as far as I remember, they don't support RSVP yet. Also, IPv6 over MPLS doesn't work on MT yet. As a cheap PE router, the MikroTik works very good, but I advice you to test everything thoroughly before implementing anything. Their support staff is very forthcoming and in my experience they fix any bug you report at an amazing speed! Allan From SteveMc at netservicesplc.com Thu Apr 30 07:35:34 2009 From: SteveMc at netservicesplc.com (Steve McCrory) Date: Thu, 30 Apr 2009 12:35:34 +0100 Subject: [c-nsp] QoS and VLAN In-Reply-To: <9418aca70904291209x6852365emf83323d998554972@mail.gmail.com> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com><1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com><1C15FB264A06794F8BDE2120972B51C1050E2BF5@netexch04.ad.netservicesplc.com> <9418aca70904291209x6852365emf83323d998554972@mail.gmail.com> Message-ID: <1C15FB264A06794F8BDE2120972B51C1050E2C79@netexch04.ad.netservicesplc.com> Hi Jay, Unfortunately, shaping is an outbound feature only. We work round this by implementing outbound QoS on the CE device on the other end of the link. As far as I know, there are few, if any, software-based queuing mechanisms to deal with inbound traffic. Once traffic has arrived on an interface, it is considered difficult to then implement queuing. Policing is available for inbound traffic but obviously this can result in issues when considering TCP traffic. Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jay Nakamura Sent: 29 April 2009 20:10 To: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] QoS and VLAN Thanks Steve, after seeing your example, I found this http://www.cisco.com/en/US/partner/tech/tk543/tk545/technologies_tech_note09186a0080114326.shtml Would it work on inbound traffic? On Wed, Apr 29, 2009 at 1:43 PM, Steve McCrory wrote: > Hi Chuck, > > Here's an example of a nested policy that we have deployed on 7206VXR > (NPE400): > > policy-map cust_4Mbvoip_parent > ?class class-default > ? ?shape average 4000000 > ? service-policy cust-4Mvoip-out > ! > policy-map cust-4Mvoip-out > ?class cust-rtp > ? ?priority percent 28 > ?class cust-skinny > ? ?bandwidth percent 17 > ?class cust-citrix-new > ? ?bandwidth percent 45 > ?class cust-network > ? ?bandwidth percent 2 > ?class class-default > ? ?fair-queue > ! > interface GigabitEthernet1/0.230 > ?description Southampton 10Mb > ?encapsulation dot1Q 230 > ?ip vrf forwarding TU-MZRS-01 > ?ip address 192.168.1.89 255.255.255.248 > ?ip verify unicast source reachable-via any > ?no ip redirects > ?no ip proxy-arp > ?no snmp trap link-status > ?service-policy output cust_4Mbvoip_parent > end > > This seems to work quite well and helped to alleviate congestion > problems that our customer was having after they rolled out VoIP across > their network. > > Steven > > Steven McCrory > > Senior Network Engineer > > Netservices PLC > Waters Edge Business Park > Modwen Road > Manchester, M5 3EZ > > www.netservicesplc.com > -----Original Message----- > From: Church, Charles [mailto:cchurc05 at harris.com] > Sent: 29 April 2009 18:15 > To: Steve McCrory; cisco-nsp at puck.nether.net > Subject: RE: [c-nsp] QoS and VLAN > > Steve, > > ? ? ? ?You have an example of this? ?I've found on the platforms I work > on most that you can't use any LLQ (priority keyword) on a subint. ?So > I've put a policy handling the priority stuff on the main int, and then > the other shaping/policing stuff on the subint, but have always > questioned its effectiveness, or the order of operation for traffic, > whether it hits the subint policy first, or the main int one. > > Thanks, > > Chuck > > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Steve McCrory > Sent: Wednesday, April 29, 2009 12:40 PM > To: Jay Nakamura; cisco-nsp at puck.nether.net > Subject: Re: [c-nsp] QoS and VLAN > > > Have you tried implementing Modular QoS CLI (MQC) using service > policies? > > I haven't worked on the 7500 platform but we have successfully applied > QoS for VoIP on subinterfaces on the 7200 series routers. > > It should be noted that on sub-interfaces, you need a parent service > policy to shape traffic to a particular level and then a child service > policy which will carry out the actual QoS markings/prioritizations > within the shaped allowance. > > Steven > > Steven McCrory > > Senior Network Engineer > > Netservices PLC > Waters Edge Business Park > Modwen Road > Manchester, M5 3EZ > > www.netservicesplc.com > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jay Nakamura > Sent: 29 April 2009 16:36 > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] QoS and VLAN > > We have several customers coming in on Ethernet. ?They are connected > to L2 switch and trunked into a 7500 router via VLAN. ?This has worked > fine so far with the use of rate-limit on the sub-interface. ?Most > customers have 5~10mbps. > > However, we are increasingly needing QoS so VoIP traffic does not drop > when data traffic bursts. ?Only work around I know how to do is to > give separate rate-limit based on IP address since most of the time > VoIP has separate gateway on the customer side than the data firewall. > > Classification of the traffic is not a problem. ?The issue is, how do > you give VoIP traffic priority over data traffic on a Ethernet > sub-interface? > > Is there a good way to implement this on a 7500? ?If not, what Cisco > hardware will work? ?We are on a tight budget and the number of > clients are small. ?(dozen or so) ?Would going with L3 switch be > better? ?If so, what model? > > Thanks! > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > -------- > NetServices plc, Company No. 4178393, > Registered Office: NetServices House, 31 Modwen Road, > Waters Edge Business Park, SALFORD, M5 3EZ > -------- > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > -------- > NetServices plc, Company No. 4178393, > Registered Office: NetServices House, 31 Modwen Road, > Waters Edge Business Park, SALFORD, M5 3EZ > -------- > _______________________________________________ > cisco-nsp mailing list ?cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- From mhuff at ox.com Thu Apr 30 09:31:21 2009 From: mhuff at ox.com (Matthew Huff) Date: Thu, 30 Apr 2009 09:31:21 -0400 Subject: [c-nsp] BGP Med and outbound metric In-Reply-To: <1C15FB264A06794F8BDE2120972B51C1050E2C79@netexch04.ad.netservicesplc.com> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com><1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com><1C15FB264A06794F8BDE2120972B51C1050E2BF5@netexch04.ad.netservicesplc.com> <9418aca70904291209x6852365emf83323d998554972@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2C79@netexch04.ad.netservicesplc.com> Message-ID: <483E6B0272B0284BA86D7596C40D29F9C38082C28C@PUR-EXCH07.ox.com> Since we use BGP as peering to our ISPs, and don't use BGP internally in our core, I haven't used MED or local_pref much. However, we have two routers connected to another ASN (not via the internet) and I'm trying to influence their return path since we are getting asynchronous routing. I'm trying to use MED to advertise a lower preference out our second router but it doesn't seem to be working. Any suggestions? Here is the config... router bgp 14607 ... neighbor 10.151.0.82 remote-as 26585 neighbor 10.151.0.82 distribute-list bgp_distribute_cap in neighbor 10.151.0.82 distribute-list bgp_distribute_core_plus_ecn out neighbor 10.151.0.82 route-map setMED-LOW out neighbor 10.151.0.82 filter-list 10 out route-map setMED-LOW permit 10 match ip address routemap_ecn set metric 200 ip access-list standard routemap_ecn permit 129.77.44.0 I've done the "clear ip bgp * soft" and have verified that the other side has seen the change (previously I had a block all access list on the distribute out so I know that the change has taken effect). rtr-feed2#show ip bgp 129.77.44.0 BGP routing table entry for 129.77.44.0/24, version 22 Paths: (1 available, best #1, table default) Advertised to update-groups: 3 Local 0.0.0.0 from 0.0.0.0 (129.77.40.42) Origin incomplete, metric 0, localpref 100, weight 32768, valid, sourced, best rtr-feed2#show ip bgp neighbors 10.151.0.82 advertised-routes BGP table version is 198, local router ID is 129.77.40.42 Status codes: s suppressed, d damped, h history, * valid, > best, i - internal, r RIB-failure, S Stale Origin codes: i - IGP, e - EGP, ? - incomplete Network Next Hop Metric LocPrf Weight Path *> 129.77.44.0/24 0.0.0.0 0 32768 ? Total number of prefixes 1 Both outputs show a metric of 0. Any ideas? ---- Matthew Huff?????? | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com? | Phone: 914-460-4039 aim: matthewbhuff? | Fax:?? 914-460-4139 From dr at cluenet.de Thu Apr 30 08:41:02 2009 From: dr at cluenet.de (Daniel Roesen) Date: Thu, 30 Apr 2009 14:41:02 +0200 Subject: [c-nsp] 2975 stack... interoperability? In-Reply-To: <49F8B754.9030109@utc.edu> References: <49F8B754.9030109@utc.edu> Message-ID: <20090430124102.GA7034@srv03.cluenet.de> On Wed, Apr 29, 2009 at 04:23:48PM -0400, Jeff Kell wrote: > Quick question... the new[ish] Catalyst 2975 switch looks like a > 2960+stacking. Do these things stack with 3750s / 3750Es ? They show > up as another "blade" on the stack? We've been told that it's the usual "StackWise, but without the advanced features" (I guess this was referring to StackWise+). CSCO was unable to explain the pricing and thus positioning though. :) Best regards, Daniel -- CLUE-RIPE -- Jabber: dr at cluenet.de -- dr at IRCnet -- PGP: 0xA85C8AA0 From mark.kelsay at confused.com Thu Apr 30 09:38:07 2009 From: mark.kelsay at confused.com (Kelsay, Mark) Date: Thu, 30 Apr 2009 14:38:07 +0100 Subject: [c-nsp] CSS 11501 Question In-Reply-To: <49F887AF.3010801@wellesley.edu> References: <62D8ECFDF835A648AD4FB4328B15F364047ECC14@mud.admiral.uk> <49F887AF.3010801@wellesley.edu> Message-ID: <62D8ECFDF835A648AD4FB4328B15F364047ECC18@mud.admiral.uk> Thanks for that. I ran "clear running-config" Then "write memory" Then "reboot" Default username is "admin" and password is "system" in case anyone needs this info. Cheers, Mark -----Original Message----- From: Don Nightingale [mailto:dnightin at wellesley.edu] Sent: 29 April 2009 18:01 To: Kelsay, Mark Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] CSS 11501 Question "clear running-config" Kelsay, Mark wrote: > I need to erase an old config and tried the erase config command but it > did not work. Any idea what the command is? I am consoled into the > console port. > > > > TIA, > > > > Mark > > > > > ****** This email is sent for and on behalf of Inspop.com Limited ****** > Authorised and regulated by the Financial Services Authority. Registration no. 310635. > Inspop.com Limited [also trading as "Confused.com"] is registered in England and Wales at 2nd Floor, Friary House, Greyfriars Road, Cardiff, CF10 3AE [Reg. No. 03857130]. Any opinions expressed in this email are those of the individual and not necessarily the company. This email and any files transmitted with it, including replies and forwarded copies [which may contain alterations] subsequently transmitted from the Company, are confidential and solely for the use of the intended recipient. It may contain material protected by attorney-client privilege. If you are not the intended recipient or the person responsible for delivering to the intended recipient, be advised that you have received this email in error and that any use is strictly prohibited. > If you have received this email in error please notify the Information Security Officer by telephone on +44 [0] 29 2043 4372. Please then delete this email and destroy any copies of it. This email has been swept for viruses before leaving our system. > Security Warning: Please note that this email has been created in the knowledge that Internet email is not a 100% secure communications medium. We advise that you understand and accept this lack of security when emailing us. > Viruses: Although we have taken steps to ensure that this email and any attachments are free from any virus, we advise that in keeping with good computing practice the recipient should ensure they are actually virus free. > We may monitor the content of E-mails sent and received via our network for viruses or unauthorised use and for other lawful business purposes. > > > ________________________________________________________________________ > This e-mail has been scanned for all viruses by Messagelabs. The > service is powered by MessageLabs. ________________________________________________________________________ > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > -- Don Nightingale Systems and Networks Manager Wellesley College 781-283-3271 ______________________________________________________________________ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email ______________________________________________________________________ ________________________________________________________________________ This e-mail has been scanned for all viruses by Messagelabs. The service is powered by MessageLabs. ________________________________________________________________________ From Michael.Robson at manchester.ac.uk Thu Apr 30 10:37:44 2009 From: Michael.Robson at manchester.ac.uk (Michael Robson) Date: Thu, 30 Apr 2009 15:37:44 +0100 Subject: [c-nsp] Optical module transmit power Message-ID: <5C4E7532-71EB-4056-A491-9AE1FB5919D5@manchester.ac.uk> We have a selection of ZR modules (XENPAK-10GB-ZR) in 6500s that we are using to drive some links at 10Gbps and I have recently noticed that all receive values (as reported via the sh int te x/y trans command) are lower than what Cisco specify as the minimum allowed values for those modules (i.e. the minimum quoted is -24dBm whereas we are seeing value reported as low as -28.8 dBm), and also a link that is receiving at -28.9dB and flapping. For these modules, none of them are transmitting at anything like their maximum of +4.0dBm (Cisco's figures for the maximum transmit power), they are in fact transmitting between +1.9dBm and +2.3dBm. What determines what they will transmit at i.e. is it simply that better manufactured ones achieve a transmit value closer to the +4.0dBm power level, or is there some sort for decision/negotiation that determines the transmit value at connection; if the the latter, how can these modules be convinced to transmit at a higher power value? Ta, Michael -- From ras at e-gerbil.net Thu Apr 30 11:20:33 2009 From: ras at e-gerbil.net (Richard A Steenbergen) Date: Thu, 30 Apr 2009 10:20:33 -0500 Subject: [c-nsp] Optical module transmit power In-Reply-To: <5C4E7532-71EB-4056-A491-9AE1FB5919D5@manchester.ac.uk> References: <5C4E7532-71EB-4056-A491-9AE1FB5919D5@manchester.ac.uk> Message-ID: <20090430152033.GU51443@gerbil.cluepon.net> On Thu, Apr 30, 2009 at 03:37:44PM +0100, Michael Robson wrote: > We have a selection of ZR modules (XENPAK-10GB-ZR) in 6500s that we > are using to drive some links at 10Gbps and I have recently noticed > that all receive values (as reported via the sh int te x/y trans > command) are lower than what Cisco specify as the minimum allowed > values for those modules (i.e. the minimum quoted is -24dBm whereas we > are seeing value reported as low as -28.8 dBm), and also a link that > is receiving at -28.9dB and flapping. This is normal, it is very common for optics to "work" a bit below their min rx spec. Like how elevator cables don't snap and let you plummet to your death as soon as you hit +1 lbs over the maximum weight specified, there is a built in safety margin in the specs to make sure the min spec is achieved under all circumstances. Of course you're taking your life into your own hands if you run it like this, as someone walking past and bumping or bending the SMF cable could easily add enough loss to kill the circuit completely. When you do cross that magic line where the signal is no longer strong enough to work, flapping constantly is a common behavior on Cisco 6500s with XENPAKs (particularly on WAN PHY optics, which flap on any kind of error). On most other platforms you'll just start to see CRC errors and then eventually lose the link. Of course DOM on these things has been known to be wrong too (both due to hardware and software issues), but the behavior you're describing is normal so this probably isn't the case. > For these modules, none of them are transmitting at anything like > their maximum of +4.0dBm (Cisco's figures for the maximum transmit > power), they are in fact transmitting between +1.9dBm and +2.3dBm. > What determines what they will transmit at i.e. is it simply that > better manufactured ones achieve a transmit value closer to the > +4.0dBm power level, or is there some sort for decision/negotiation > that determines the transmit value at connection; if the the latter, > how can these modules be convinced to transmit at a higher power > value? You can't "adjust" the transmit power (well not on these things, on some of the latest newfangled optics you can but thats a completely different discussion), what it does it what it does. The transmit power spec is basically telling you to expect your optic to put out a signal level somewhere in the range between specified min and max, so you can plan an optical budget that is both strong enough to work properly, but not so strong that it blows up your amps or rx optics on the other side. -- Richard A Steenbergen http://www.e-gerbil.net/ras GPG Key ID: 0xF8B12CBC (7535 7F59 8204 ED1F CC1C 53AF 4C41 5ECA F8B1 2CBC) From petelists at templin.org Thu Apr 30 11:40:55 2009 From: petelists at templin.org (Pete Templin) Date: Thu, 30 Apr 2009 10:40:55 -0500 Subject: [c-nsp] Loose uRPF behaving like strict mode on 7600 In-Reply-To: References: <49F91A9A.9060403@allstream.net> Message-ID: <49F9C687.9040306@templin.org> Jon Lewis wrote: > On Wed, 29 Apr 2009, Jose wrote: > >> From my understanding of this feature, it would seem as if the RPF >> check was working in strict mode vs loose mode. > > http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SXF/hybrid/release/notes/ol_4563.html#wp210802 I've known about these limitations for a while. What I can't seem to glean from the docs is how it handles exception ACLs. Does it apply a per-interface exception ACL as expected, or do those also behave in some sort of global manner? Pete From dwcarder at wisc.edu Thu Apr 30 11:08:22 2009 From: dwcarder at wisc.edu (Dale W. Carder) Date: Thu, 30 Apr 2009 10:08:22 -0500 Subject: [c-nsp] Optical module transmit power In-Reply-To: <5C4E7532-71EB-4056-A491-9AE1FB5919D5@manchester.ac.uk> References: <5C4E7532-71EB-4056-A491-9AE1FB5919D5@manchester.ac.uk> Message-ID: On Apr 30, 2009, at 9:37 AM, Michael Robson wrote: > We have a selection of ZR modules (XENPAK-10GB-ZR) > For these modules, none of them are transmitting at anything like > their maximum of +4.0dBm (Cisco's figures for the maximum transmit > power), they are in fact transmitting between +1.9dBm and +2.3dBm. This is to be expected. Vendors just publish a tolerable range somewhere in which the optics will operate. > What determines what they will transmit at i.e. is it simply that > better manufactured ones achieve a transmit value closer to the > +4.0dBm power level Maybe it's luck. Anyway, how long are your fiber spans? If they are really long, and you're living on the edge now, you may end up in a sticky situation as these optics degrade over time. If they are not extremely long, you may have some horrible jumpers or splices that are eating some dB. Do you have an OTDR? Dale p.s. My fiance did her postgraduate work at Manchester. Quite a nice place! From p.mayers at imperial.ac.uk Thu Apr 30 12:32:01 2009 From: p.mayers at imperial.ac.uk (Phil Mayers) Date: Thu, 30 Apr 2009 17:32:01 +0100 Subject: [c-nsp] %IPC-SPSTBY-5-WATERMARK errors on dual-sup 6500 & SXI Message-ID: <49F9D281.9010008@imperial.ac.uk> All, We have a chassi with 2x sup720-3B and running SXI that, for the second time, appears to have "lost" the standby SUP to the above error messages. The first time, the pattern was: Mar 17 17:24:37.378 GMT: %XDR-6-XDRIPCNOTIFY: Message not sent to slot 6/0 (6) because of IPC error timeout. Disabling linecard. (Expected during linecard OIR or system reloads) Mar 17 17:24:42.826 GMT: %XDR-SPSTBY-3-XDRNOMEM: XDR failed to allocate memory during ipcQ chunks creation. -Traceback= 40252F70 4025350C 40932AB8 40DD8E9C 40426BA8 40427068 40427534 40427E38 40428608 40F465F4 40F3699C 40F36BB8 416E175C ...we did not notice these, but then a few days later the router began logging: Mar 21 07:17:51.798 GMT: %IPC-SPSTBY-5-WATERMARK: 1600 messages pending in rcv for the port Card6/0:Request(2060000.7) seat 2060000 Mar 21 07:18:21.967 GMT: %IPC-SPSTBY-5-WATERMARK: 1600 messages pending in rcv for the port Card6/0:Request(2060000.7) seat 2060000 Mar 21 07:18:52.126 GMT: %IPC-SPSTBY-5-WATERMARK: 1600 messages pending in rcv for the port Card6/0:Request(2060000.7) seat 2060000 ...with the number of IPC messages rising, basically forever. TAC advised a bunch of stuff that basically amounted to re-seating the card, failing over to the sup to see if the sup or software was faulty (yikes...), swapping the sups around in the slots, and so forth. I re-seated the sup and it seemed stable, until a few days ago: Apr 21 01:26:18.815 BST: %RPC-SPSTBY-2-FAILED_USERHANDLE: Failed to send RPC request online_diag_sp_request:get_rp_cpu_info -Traceback= 40252F70 4025350C 40B43D3C 410D8528 410FCEF8 4109B750 4109C550 4109D140 4109AAD0 4109A8E4 4088E6C0 4088E6AC ...then... Apr 24 08:18:46.367 BST: %IPC-SPSTBY-5-WATERMARK: 1600 messages pending in rcv for the port Card6/0:Request(2060000.7) seat 2060000 ...again, rising forever. I'm going to re-open the TAC case and see what they say, but I was wondering if anyone had come across this. There are some similar-sounding messages in the SXI release notes, but we've got other identically-configured boxes that don't display these symptoms, so I'm fearing a hardware fault (which would be ironic - this sup came from Cisco in response to an RMA...) From SteveMc at netservicesplc.com Thu Apr 30 12:35:25 2009 From: SteveMc at netservicesplc.com (Steve McCrory) Date: Thu, 30 Apr 2009 17:35:25 +0100 Subject: [c-nsp] Per session shaping Message-ID: <1C15FB264A06794F8BDE2120972B51C1050E2D09@netexch04.ad.netservicesplc.com> Afternoon all, I've been asked to look into the capabilities of the Cisco IOS feature 'Per-Session Shaping and Queuing' and I am looking for some expertise from anyone who has utilized this feature. I would like to know if it is possible to shape an SSS session that is forwarded on to another LNS or is this feature specifically for shaping subscriber sessions that terminate locally? I tried configuring a service policy on the virtual-template that is associated with the VPDN group for the incoming L2TP tunnel but this appear to break everything and debugging radius identifies a 'nas-error' as the cause: *Apr 30 15:26:50.187: RADIUS: Acct-Terminate-Cause[49] 6 nas-error [9] Cheers Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- From Jason.Link at whgroup.com Thu Apr 30 12:39:10 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Thu, 30 Apr 2009 11:39:10 -0500 Subject: [c-nsp] ASA / EIGRP / Redundant Interfaces In-Reply-To: <1241076152.3465.1.camel@localhost.localdomain> References: <1241076152.3465.1.camel@localhost.localdomain> Message-ID: Unfortunately, EIGRP on the ASA doesn't appear to support the max-paths command. Both physical interfaces are in the same VLAN, connected to different switches that are trunked together...and I understand that only one switchport "should" be active, and it is shown as such when doing a "sh int redun1 detail", but it appears to be learning (and using) routes from both routers that are on the VLAN. Additionally, I'm not sure HSRP would help me in a situation like this, since the way I understand it the ASA will still learn both routers "real" IP address and will form a neighbor to each one. I would like to avoid calling out the neighbor specifically, if I can help it. Maybe I could play around with the RSTP priority on the particular switch uplink ports to make it so that one of the ports is blocking - that way if a switch dies, that port will stop blocking and then converge. It may take a little longer, but I believe the end result would be the same...but I'm not sure this is any better than calling out the neighbor specifically (the HSRP address). -----Original Message----- From: Peter Rathlev [mailto:peter at rathlev.dk] Sent: Thursday, April 30, 2009 2:23 AM To: Jason Link Cc: Cisco-nsp Subject: Re: [c-nsp] ASA / EIGRP / Redundant Interfaces On Wed, 2009-04-29 at 14:57 -0500, Jason Link wrote: > With an ASA running a redundant physical interface pair for the Inside > interface, each link connected to a separate switch which is connected > to a separate router, and everything running EIGRP, I get multiple > routes (2) to the same destination subnet, one for each of the connected > routers. This is obviously causing problems, and I can't seem to find a > way to resolve it. Setting delay on the physical interfaces doesn't > seem to take effect, and there is no variance sub-command so I can't > just force one route. This needs to function in a redundant situation, > as in if I lose a router or switch everything will continue to function > (hence the redundant interface). I tried google and cisco and found > nothing of any significance...anyone got any ideas? AFAIK the "standard" way of doing this would be a shared VLAN on the inside and then HSRP or similar on the routers. Any reason for not doing that? Regards, Peter From p.mayers at imperial.ac.uk Thu Apr 30 12:41:58 2009 From: p.mayers at imperial.ac.uk (Phil Mayers) Date: Thu, 30 Apr 2009 17:41:58 +0100 Subject: [c-nsp] %IPC-SPSTBY-5-WATERMARK errors on dual-sup 6500 & SXI In-Reply-To: <49F9D281.9010008@imperial.ac.uk> References: <49F9D281.9010008@imperial.ac.uk> Message-ID: <49F9D4D6.6010100@imperial.ac.uk> > > I'm going to re-open the TAC case and see what they say, but I was > wondering if anyone had come across this. There are some SR 611339993 opened From danletkeman at gmail.com Thu Apr 30 12:48:22 2009 From: danletkeman at gmail.com (Dan Letkeman) Date: Thu, 30 Apr 2009 11:48:22 -0500 Subject: [c-nsp] cef load sharing timeouts Message-ID: Hello, I have five 827 adsl routers in front of a 2821 for internet access. The 2821 is doing cef load sharing: ip cef load-sharing algorithm include-ports source destination Browsing the internet works great, but it seems like large downloads timeout often, but not all of the time. When i direct traffic to only one of the 827's instead of the cef load-sharing randomly picking one, then the large downloads work and do not timeout. The 2821 is running: c2800nm-adventerprisek9-mz.124-20.T.bin Is load-sharing the problem? Dan. From peter at rathlev.dk Thu Apr 30 12:49:07 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 30 Apr 2009 18:49:07 +0200 Subject: [c-nsp] BGP Med and outbound metric In-Reply-To: <483E6B0272B0284BA86D7596C40D29F9C38082C28C@PUR-EXCH07.ox.com> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF5@netexch04.ad.netservicesplc.com> <9418aca70904291209x6852365emf83323d998554972@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2C79@netexch04.ad.netservicesplc.com> <483E6B0272B0284BA86D7596C40D29F9C38082C28C@PUR-EXCH07.ox.com> Message-ID: <1241110147.3465.15.camel@localhost.localdomain> On Thu, 2009-04-30 at 09:31 -0400, Matthew Huff wrote: ... > neighbor 10.151.0.82 route-map setMED-LOW out > neighbor 10.151.0.82 filter-list 10 out > > route-map setMED-LOW permit 10 > match ip address routemap_ecn > set metric 200 > > ip access-list standard routemap_ecn > permit 129.77.44.0 > > I've done the "clear ip bgp * soft" and have verified that the other > side has seen the change (previously I had a block all access list on > the distribute out so I know that the change has taken effect). > > rtr-feed2#show ip bgp 129.77.44.0 Is the "rtr-feed2" your side or their side? ... > Both outputs show a metric of 0. Any ideas? You can only see the results of an outbound route-map on the other side. The metric you see on your side is the one you box knows about. Are you sure they would accept the MED setting? It's quite normal to clear this inbound to enforce some standard policy. Regards, Peter From Jonathan.Soler at eu.didata.com Thu Apr 30 12:41:55 2009 From: Jonathan.Soler at eu.didata.com (Jonathan Soler (Europe)) Date: Thu, 30 Apr 2009 18:41:55 +0200 Subject: [c-nsp] Cisco ASA 5505 limitations Message-ID: <67FB78EB09CB274DBEF2FE672B6404028C7196@EUBEBRUSVEX1.eu.didata.local> Hello, ?Does Cisco ASA5505 support 4 network segments, one inside, one outside and two DMZs? ?Does Cisco ASA5505 support all ASA5510, 5520... functionalities, like for example OSPF? Thanks Jonathan From mhuff at ox.com Thu Apr 30 12:51:08 2009 From: mhuff at ox.com (Matthew Huff) Date: Thu, 30 Apr 2009 12:51:08 -0400 Subject: [c-nsp] BGP Med and outbound metric In-Reply-To: <1241110147.3465.15.camel@localhost.localdomain> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF5@netexch04.ad.netservicesplc.com> <9418aca70904291209x6852365emf83323d998554972@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2C79@netexch04.ad.netservicesplc.com> <483E6B0272B0284BA86D7596C40D29F9C38082C28C@PUR-EXCH07.ox.com> <1241110147.3465.15.camel@localhost.localdomain> Message-ID: <483E6B0272B0284BA86D7596C40D29F9C38082C2B4@PUR-EXCH07.ox.com> rtr-feed2 is on our side. What I'm attempting to do is to pref rtr-feed1 over rtr-feed2 (hence the 200 metric). I'm also seeing the metric of 0 on the "show ip bgp neighbor 10.151.0.82 advertised-routes". ---- Matthew Huff?????? | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com? | Phone: 914-460-4039 aim: matthewbhuff? | Fax:?? 914-460-4139 -----Original Message----- From: Peter Rathlev [mailto:peter at rathlev.dk] Sent: Thursday, April 30, 2009 12:49 PM To: Matthew Huff Cc: cisco-nsp at puck.nether.net Subject: Re: [c-nsp] BGP Med and outbound metric On Thu, 2009-04-30 at 09:31 -0400, Matthew Huff wrote: ... > neighbor 10.151.0.82 route-map setMED-LOW out > neighbor 10.151.0.82 filter-list 10 out > > route-map setMED-LOW permit 10 > match ip address routemap_ecn > set metric 200 > > ip access-list standard routemap_ecn > permit 129.77.44.0 > > I've done the "clear ip bgp * soft" and have verified that the other > side has seen the change (previously I had a block all access list on > the distribute out so I know that the change has taken effect). > > rtr-feed2#show ip bgp 129.77.44.0 Is the "rtr-feed2" your side or their side? ... > Both outputs show a metric of 0. Any ideas? You can only see the results of an outbound route-map on the other side. The metric you see on your side is the one you box knows about. Are you sure they would accept the MED setting? It's quite normal to clear this inbound to enforce some standard policy. Regards, Peter From peter at rathlev.dk Thu Apr 30 12:52:24 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 30 Apr 2009 18:52:24 +0200 Subject: [c-nsp] ASA / EIGRP / Redundant Interfaces In-Reply-To: References: <1241076152.3465.1.camel@localhost.localdomain> Message-ID: <1241110344.3465.19.camel@localhost.localdomain> On Thu, 2009-04-30 at 11:39 -0500, Jason Link wrote: > Additionally, I'm not sure HSRP would help me in a situation like this, > since the way I understand it the ASA will still learn both routers > "real" IP address and will form a neighbor to each one. I would like to > avoid calling out the neighbor specifically, if I can help it. Yes of course, if the ASA has to do EIGRP my suggestion is irrelevant. I overlooked that somewhat since I'm not used to thinking about having firewalls do dynamic routing. :-) The HSRP thing would of course be with the ASA not participating in the EIGRP. On the ASA side you would use static routes pointing at the HSRP IP. On the router side you would use static routes pointing at the ASA primary IP. Regards, Peter From peter at rathlev.dk Thu Apr 30 12:56:55 2009 From: peter at rathlev.dk (Peter Rathlev) Date: Thu, 30 Apr 2009 18:56:55 +0200 Subject: [c-nsp] BGP Med and outbound metric In-Reply-To: <483E6B0272B0284BA86D7596C40D29F9C38082C2B4@PUR-EXCH07.ox.com> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF5@netexch04.ad.netservicesplc.com> <9418aca70904291209x6852365emf83323d998554972@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2C79@netexch04.ad.netservicesplc.com> <483E6B0272B0284BA86D7596C40D29F9C38082C28C@PUR-EXCH07.ox.com> <1241110147.3465.15.camel@localhost.localdomain> <483E6B0272B0284BA86D7596C40D29F9C38082C2B4@PUR-EXCH07.ox.com> Message-ID: <1241110615.3465.24.camel@localhost.localdomain> On Thu, 2009-04-30 at 12:51 -0400, Matthew Huff wrote: > rtr-feed2 is on our side. What I'm attempting to do is to pref > rtr-feed1 over rtr-feed2 (hence the 200 metric). > > I'm also seeing the metric of 0 on the "show ip bgp neighbor > 10.151.0.82 advertised-routes". Well, as I tried writing: On Thu, 2009-04-30 at 18:49 +0200, Peter Rathlev wrote: > You can only see the results of an outbound route-map on the other side. > The metric you see on your side is the one you box knows about. This is also true when showing "advertised-routes", which just shows you the routes from your own local table that being sent to the neighbor, but before the route-map has had a chance to change anything. AFAIK the only way of seeing what they receive is on their side. > Are you sure they would accept the MED setting? It's quite normal to > clear this inbound to enforce some standard policy. This is also still relevant. Do you have an agreement with them on this? Regards, Peter From Jason.Link at whgroup.com Thu Apr 30 13:00:26 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Thu, 30 Apr 2009 12:00:26 -0500 Subject: [c-nsp] ASA / EIGRP / Redundant Interfaces Message-ID: <007a01c9c9b5$22c119a1$0600a8c0@whgroup.com> Maybe that's the best option here. I can't seem to find any other way to do it cleanly. Thanks! -----Original Message----- From: Peter Rathlev Sent: Thursday, April 30, 2009 11:52 AM To: Jason Link Cc: Cisco-nsp Subject: RE: [c-nsp] ASA / EIGRP / Redundant Interfaces On Thu, 2009-04-30 at 11:39 -0500, Jason Link wrote: > Additionally, I'm not sure HSRP would help me in a situation like this, > since the way I understand it the ASA will still learn both routers > "real" IP address and will form a neighbor to each one. I would like to > avoid calling out the neighbor specifically, if I can help it. Yes of course, if the ASA has to do EIGRP my suggestion is irrelevant. I overlooked that somewhat since I'm not used to thinking about having firewalls do dynamic routing. :-) The HSRP thing would of course be with the ASA not participating in the EIGRP. On the ASA side you would use static routes pointing at the HSRP IP. On the router side you would use static routes pointing at the ASA primary IP. Regards, Peter From Jason.Link at whgroup.com Thu Apr 30 13:08:44 2009 From: Jason.Link at whgroup.com (Jason Link) Date: Thu, 30 Apr 2009 12:08:44 -0500 Subject: [c-nsp] Cisco ASA 5505 limitations Message-ID: <007b01c9c9b6$4bce2c1c$0600a8c0@whgroup.com> The 5505 will support as many VLANs as you are licensed for. The base license won't do what you are asking, but the plus license will. You can configure the VLANs with ACLs to make them function as you wish (DMZ1 / DMZ2 / etc). As for the routing, it should do OSPF and EIGRP - but it can't do everything the 5510 and up can do. -----Original Message----- From: Jonathan Soler (Europe) Sent: Thursday, April 30, 2009 12:03 PM To: cisco-nsp at puck.nether.net Subject: [c-nsp] Cisco ASA 5505 limitations Hello, ?Does Cisco ASA5505 support 4 network segments, one inside, one outside and two DMZs? ?Does Cisco ASA5505 support all ASA5510, 5520... functionalities, like for example OSPF? Thanks Jonathan _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From avayner at cisco.com Thu Apr 30 13:11:17 2009 From: avayner at cisco.com (Arie Vayner (avayner)) Date: Thu, 30 Apr 2009 19:11:17 +0200 Subject: [c-nsp] Per session shaping In-Reply-To: <1C15FB264A06794F8BDE2120972B51C1050E2D09@netexch04.ad.netservicesplc.com> References: <1C15FB264A06794F8BDE2120972B51C1050E2D09@netexch04.ad.netservicesplc.com> Message-ID: <78C984F8939D424697B15E4B1C1BB3D7932632@xmb-ams-331.emea.cisco.com> Steve, >From what I know this is meant to be used on the terminating LNS... Arie -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Steve McCrory Sent: Thursday, April 30, 2009 19:35 To: cisco-nsp at puck.nether.net Subject: [c-nsp] Per session shaping Afternoon all, I've been asked to look into the capabilities of the Cisco IOS feature 'Per-Session Shaping and Queuing' and I am looking for some expertise from anyone who has utilized this feature. I would like to know if it is possible to shape an SSS session that is forwarded on to another LNS or is this feature specifically for shaping subscriber sessions that terminate locally? I tried configuring a service policy on the virtual-template that is associated with the VPDN group for the incoming L2TP tunnel but this appear to break everything and debugging radius identifies a 'nas-error' as the cause: *Apr 30 15:26:50.187: RADIUS: Acct-Terminate-Cause[49] 6 nas-error [9] Cheers Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ From mhuff at ox.com Thu Apr 30 13:24:40 2009 From: mhuff at ox.com (Matthew Huff) Date: Thu, 30 Apr 2009 13:24:40 -0400 Subject: [c-nsp] BGP Med and outbound metric In-Reply-To: <1241110615.3465.24.camel@localhost.localdomain> References: <9418aca70904290835s453823e3p9c9ace6ca6eebceb@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF4@netexch04.ad.netservicesplc.com> <1C15FB264A06794F8BDE2120972B51C1050E2BF5@netexch04.ad.netservicesplc.com> <9418aca70904291209x6852365emf83323d998554972@mail.gmail.com> <1C15FB264A06794F8BDE2120972B51C1050E2C79@netexch04.ad.netservicesplc.com> <483E6B0272B0284BA86D7596C40D29F9C38082C28C@PUR-EXCH07.ox.com> <1241110147.3465.15.camel@localhost.localdomain> <483E6B0272B0284BA86D7596C40D29F9C38082C2B4@PUR-EXCH07.ox.com> <1241110615.3465.24.camel@localhost.localdomain> Message-ID: <483E6B0272B0284BA86D7596C40D29F9C38082C2B8@PUR-EXCH07.ox.com> Ah. I didn't realize the "show" was before the route-map was applied. I was trying to make sure everything was setup correctly on our side before contacting the other ASN. They may very well have something that zero's the metric. ---- Matthew Huff?????? | One Manhattanville Rd OTA Management LLC | Purchase, NY 10577 http://www.ox.com? | Phone: 914-460-4039 aim: matthewbhuff? | Fax:?? 914-460-4139 -----Original Message----- From: Peter Rathlev [mailto:peter at rathlev.dk] Sent: Thursday, April 30, 2009 12:57 PM To: Matthew Huff Cc: cisco-nsp at puck.nether.net Subject: RE: [c-nsp] BGP Med and outbound metric On Thu, 2009-04-30 at 12:51 -0400, Matthew Huff wrote: > rtr-feed2 is on our side. What I'm attempting to do is to pref > rtr-feed1 over rtr-feed2 (hence the 200 metric). > > I'm also seeing the metric of 0 on the "show ip bgp neighbor > 10.151.0.82 advertised-routes". Well, as I tried writing: On Thu, 2009-04-30 at 18:49 +0200, Peter Rathlev wrote: > You can only see the results of an outbound route-map on the other side. > The metric you see on your side is the one you box knows about. This is also true when showing "advertised-routes", which just shows you the routes from your own local table that being sent to the neighbor, but before the route-map has had a chance to change anything. AFAIK the only way of seeing what they receive is on their side. > Are you sure they would accept the MED setting? It's quite normal to > clear this inbound to enforce some standard policy. This is also still relevant. Do you have an agreement with them on this? Regards, Peter From SteveMc at netservicesplc.com Thu Apr 30 14:11:31 2009 From: SteveMc at netservicesplc.com (Steve McCrory) Date: Thu, 30 Apr 2009 19:11:31 +0100 Subject: [c-nsp] [SPAM?] Re: ASA / EIGRP / Redundant Interfaces In-Reply-To: <007a01c9c9b5$22c119a1$0600a8c0@whgroup.com> References: <007a01c9c9b5$22c119a1$0600a8c0@whgroup.com> Message-ID: <1C15FB264A06794F8BDE2120972B51C1050E2D0B@netexch04.ad.netservicesplc.com> Hi Jason, Have you considered tweaking the metrics on the routers to force the ASA to prefer the routes from only one router at a time? A few of the options to influence path selection are detailed at the following link: http://www.cisco.com/en/US/tech/tk365/technologies_tech_note09186a00800c 2d96.shtml Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Jason Link Sent: 30 April 2009 18:00 To: Peter Rathlev; Jason Link Cc: Cisco-nsp Subject: [SPAM?] Re: [c-nsp] ASA / EIGRP / Redundant Interfaces Maybe that's the best option here. I can't seem to find any other way to do it cleanly. Thanks! -----Original Message----- From: Peter Rathlev Sent: Thursday, April 30, 2009 11:52 AM To: Jason Link Cc: Cisco-nsp Subject: RE: [c-nsp] ASA / EIGRP / Redundant Interfaces On Thu, 2009-04-30 at 11:39 -0500, Jason Link wrote: > Additionally, I'm not sure HSRP would help me in a situation like this, > since the way I understand it the ASA will still learn both routers > "real" IP address and will form a neighbor to each one. I would like to > avoid calling out the neighbor specifically, if I can help it. Yes of course, if the ASA has to do EIGRP my suggestion is irrelevant. I overlooked that somewhat since I'm not used to thinking about having firewalls do dynamic routing. :-) The HSRP thing would of course be with the ASA not participating in the EIGRP. On the ASA side you would use static routes pointing at the HSRP IP. On the router side you would use static routes pointing at the ASA primary IP. Regards, Peter _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- From SteveMc at netservicesplc.com Thu Apr 30 14:22:06 2009 From: SteveMc at netservicesplc.com (Steve McCrory) Date: Thu, 30 Apr 2009 19:22:06 +0100 Subject: [c-nsp] Per session shaping In-Reply-To: <78C984F8939D424697B15E4B1C1BB3D7932632@xmb-ams-331.emea.cisco.com> References: <1C15FB264A06794F8BDE2120972B51C1050E2D09@netexch04.ad.netservicesplc.com> <78C984F8939D424697B15E4B1C1BB3D7932632@xmb-ams-331.emea.cisco.com> Message-ID: <1C15FB264A06794F8BDE2120972B51C1050E2D0C@netexch04.ad.netservicesplc.com> Are you aware of any techniques (expect DPI) that would allow us to inspect a users traffic as their VPDN session passes through our network via a series of tunnels? Is it possible to terminate a user temporarily to apply some sort of QoS before forwarding them onto to their final destination LNS? Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -----Original Message----- From: Arie Vayner (avayner) [mailto:avayner at cisco.com] Sent: 30 April 2009 18:11 To: Steve McCrory; cisco-nsp at puck.nether.net Subject: RE: [c-nsp] Per session shaping Steve, >From what I know this is meant to be used on the terminating LNS... Arie -----Original Message----- From: cisco-nsp-bounces at puck.nether.net [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Steve McCrory Sent: Thursday, April 30, 2009 19:35 To: cisco-nsp at puck.nether.net Subject: [c-nsp] Per session shaping Afternoon all, I've been asked to look into the capabilities of the Cisco IOS feature 'Per-Session Shaping and Queuing' and I am looking for some expertise from anyone who has utilized this feature. I would like to know if it is possible to shape an SSS session that is forwarded on to another LNS or is this feature specifically for shaping subscriber sessions that terminate locally? I tried configuring a service policy on the virtual-template that is associated with the VPDN group for the incoming L2TP tunnel but this appear to break everything and debugging radius identifies a 'nas-error' as the cause: *Apr 30 15:26:50.187: RADIUS: Acct-Terminate-Cause[49] 6 nas-error [9] Cheers Steven Steven McCrory Senior Network Engineer Netservices PLC Waters Edge Business Park Modwen Road Manchester, M5 3EZ www.netservicesplc.com -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- _______________________________________________ cisco-nsp mailing list cisco-nsp at puck.nether.net https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/ -------- NetServices plc, Company No. 4178393, Registered Office: NetServices House, 31 Modwen Road, Waters Edge Business Park, SALFORD, M5 3EZ -------- From giesen at snickers.org Thu Apr 30 16:16:53 2009 From: giesen at snickers.org (Gary T. Giesen) Date: Thu, 30 Apr 2009 16:16:53 -0400 Subject: [c-nsp] QoS Strategy for Cisco 877 Message-ID: <9a9d0c6a0904301316u4d9835a1o920a12a2445cdbfe@mail.gmail.com> Guys, I've been trying a bunch of different methods, but nothing seems to achieve what I want. Ideally I'd like to use Priority Queueing (or something that operates the same) on the ATM0 interface of a Cisco 877. I have 3 classes of traffic: Telnet/SSH/ICMP/Management - High Priority General Data - Default Priority IP Video Camers - Low Priority Normally I would just use a priority-list/priority-group, but I can't seem to apply it to either the ATM0 interface or the ATM0.33 interface (and I have also tried applying it on the PVC under the subinterface). I would like all packets in the high priority queue to be serviced first, then all packets in the default priority, and if there's any bandwidth leftover, service the low priority queue. I would prefer not to have to define minimum and maximum bandwidth for each queue (I don't want any hard queues/bandwidth limits, I would like all available bandwidth to be used by any particular queue as long as the queues above it are serviced). Can anyone recommend a QoS strategy/configuration for this that will work on the ATM0/DSL interface (no PPPoE) on a Cisco 877? Thanks, GG From cordmacleod at gmail.com Thu Apr 30 19:24:53 2009 From: cordmacleod at gmail.com (Cord MacLeod) Date: Thu, 30 Apr 2009 16:24:53 -0700 Subject: [c-nsp] 1 port 2 vlans Message-ID: I found a CatOS way of doing this, set port auxiliaryvlan 3/1 30. However, I was unable to find an IOS way, does one exist? I'm attempting move machines from one subnet to another, and rather than do this one at a time, 2 vlans would be ideal. From ler762 at gmail.com Thu Apr 30 20:17:40 2009 From: ler762 at gmail.com (Lee) Date: Thu, 30 Apr 2009 20:17:40 -0400 Subject: [c-nsp] 1 port 2 vlans In-Reply-To: References: Message-ID: On 4/30/09, Cord MacLeod wrote: > I found a CatOS way of doing this, set port auxiliaryvlan 3/1 30. I think that requires incoming traffic to have an 802.1q tag of vlan 30 to work.. > However, I was unable to find an IOS way, does one exist? switchport voice vlan 30 But that still requires incoming traffic to have a vlan 30 tag. > I'm attempting move machines from one subnet to another, and rather > than do this one at a time, 2 vlans would be ideal. Why not one vlan & two subnets? If you're starting out with, say interface vlan 20 ip address 192.168.20.1 255.255.255.0 ip helper-address 192.168.100.10 change it to interface vlan 20 ip address 192.168.30.1 255.255.255.0 ip address 192.168.20.1 255.255.255.0 secondary ip helper-address 192.168.100.10 Fix the DHCP server to give out 192.168.30.xxx addresses, reconfigure the machines with static addresses to use the new subnet & when they're all moved over + all the old leases have expired, remove the secondary address. Regards, Lee From cordmacleod at gmail.com Thu Apr 30 21:01:01 2009 From: cordmacleod at gmail.com (Cord MacLeod) Date: Thu, 30 Apr 2009 18:01:01 -0700 Subject: [c-nsp] 1 port 2 vlans In-Reply-To: References: Message-ID: A good idea, unsure why I didn't think of that. Thanks! On Apr 30, 2009, at 5:17 PM, Lee wrote: > On 4/30/09, Cord MacLeod wrote: > >> I found a CatOS way of doing this, set port auxiliaryvlan 3/1 30. > > I think that requires incoming traffic to have an 802.1q tag of vlan > 30 to work.. > >> However, I was unable to find an IOS way, does one exist? > > switchport voice vlan 30 > But that still requires incoming traffic to have a vlan 30 tag. > >> I'm attempting move machines from one subnet to another, and rather >> than do this one at a time, 2 vlans would be ideal. > > Why not one vlan & two subnets? > > If you're starting out with, say > > interface vlan 20 > ip address 192.168.20.1 255.255.255.0 > ip helper-address 192.168.100.10 > > change it to > > interface vlan 20 > ip address 192.168.30.1 255.255.255.0 > ip address 192.168.20.1 255.255.255.0 secondary > ip helper-address 192.168.100.10 > > Fix the DHCP server to give out 192.168.30.xxx addresses, reconfigure > the machines with static addresses to use the new subnet & when > they're all moved over + all the old leases have expired, remove the > secondary address. > > Regards, > Lee From adi.siswanto at indosatm2.com Thu Apr 30 21:09:48 2009 From: adi.siswanto at indosatm2.com (adi.siswanto) Date: Fri, 01 May 2009 08:09:48 +0700 Subject: [c-nsp] Per session shaping In-Reply-To: <1C15FB264A06794F8BDE2120972B51C1050E2D0C@netexch04.ad.netservicesplc.com> References: <1C15FB264A06794F8BDE2120972B51C1050E2D09@netexch04.ad.netservicesplc.com> <78C984F8939D424697B15E4B1C1BB3D7932632@xmb-ams-331.emea.cisco.com> <1C15FB264A06794F8BDE2120972B51C1050E2D0C@netexch04.ad.netservicesplc.com> Message-ID: <1241140188.9815.3.camel@adisis> Hi Steve, if you put DPI between LAC - LNS, I think it will difficult for DPI to recognize per user traffic, because it inside tunnel (cmiiw). The common implementation is to put DPI after LNS. For per user traffic shaping you can use radius attribut on the LNS, you can see below http://www.cisco.com/en/US/docs/ios/12_2sb/feature/guide/sbsbpssq.html regards On Thu, 2009-04-30 at 19:22 +0100, Steve McCrory wrote: > Are you aware of any techniques (expect DPI) that would allow us to > inspect a users traffic as their VPDN session passes through our network > via a series of tunnels? > recognise > Is it possible to terminate a user temporarily to apply some sort of QoS > before forwarding them onto to their final destination LNS? > > Steven > > Steven McCrory > > Senior Network Engineer > > Netservices PLC > Waters Edge Business Park > Modwen Road > Manchester, M5 3EZ > > www.netservicesplc.com > > -----Original Message----- > From: Arie Vayner (avayner) [mailto:avayner at cisco.com] > Sent: 30 April 2009 18:11 > To: Steve McCrory; cisco-nsp at puck.nether.net > Subject: RE: [c-nsp] Per session shaping > > Steve, > > >From what I know this is meant to be used on the terminating LNS... > > Arie > > -----Original Message----- > From: cisco-nsp-bounces at puck.nether.net > [mailto:cisco-nsp-bounces at puck.nether.net] On Behalf Of Steve McCrory > Sent: Thursday, April 30, 2009 19:35 > To: cisco-nsp at puck.nether.net > Subject: [c-nsp] Per session shaping > > Afternoon all, > > > > I've been asked to look into the capabilities of the Cisco IOS feature > 'Per-Session Shaping and Queuing' and I am looking for some expertise > from anyone who has utilized this feature. > > > > I would like to know if it is possible to shape an SSS session that is > forwarded on to another LNS or is this feature specifically for shaping > subscriber sessions that terminate locally? > > > > I tried configuring a service policy on the virtual-template that is > associated with the VPDN group for the incoming L2TP tunnel but this > appear to break everything and debugging radius identifies a 'nas-error' > as the cause: > > > > *Apr 30 15:26:50.187: RADIUS: Acct-Terminate-Cause[49] 6 nas-error > [9] > > > > Cheers > > > > Steven > > > > Steven McCrory > > > > Senior Network Engineer > > > > Netservices PLC > > Waters Edge Business Park > > Modwen Road > > Manchester, M5 3EZ > > > > www.netservicesplc.com > > > > > > -------- > NetServices plc, Company No. 4178393, > Registered Office: NetServices House, 31 Modwen Road, > Waters Edge Business Park, SALFORD, M5 3EZ > -------- > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ > > -------- > NetServices plc, Company No. 4178393, > Registered Office: NetServices House, 31 Modwen Road, > Waters Edge Business Park, SALFORD, M5 3EZ > -------- > _______________________________________________ > cisco-nsp mailing list cisco-nsp at puck.nether.net > https://puck.nether.net/mailman/listinfo/cisco-nsp > archive at http://puck.nether.net/pipermail/cisco-nsp/ K-Music: online music shop - Download ribuan lagu favorit di http://music.kongkoow.com/ Disclaimer This is an e-mail from PT Indosat Mega Media intended solely for the named addressee(s). It is confidential and may contain legally privileged information. Therefore, any unauthorized use, disclosure or copying of this information is strictly prohibited. PT Indosat Mega Media does not accept liability for any email loss or files damage.