Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

InferiorWang posted:

I'm looking at a 2960G as the "backbone" for an iScsi HA cluster. What sort of configuration considerations should I have as far as VLANs go?
I second this question. I'm also looking at 2960G to connect 3 SAN shelves (each with dual gigabit in a portchannel) to 12 servers. I'm worried about the backplane bandwidth.

Adbot
ADBOT LOVES YOU

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I setup a VPN on a PIX 515e and connect with the Cisco VPN client software. It works great, however I'm no longer able to route to the Internet, just the private internal network. Is there a way to have it route ALL my traffic through the PIX. I know a split tunnel is possible, but I don't want to do that. I heard somewhere that a PIX can't route traffic out the same interface it comes in on, so what I'm asking may not be possible without a VPN concentrator or whatnot.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

XakEp posted:

Out of curiosity, why dont you want to do a split tunnel?
So I don't have to deal with Time Warner packet shaping my cable connection.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

Tremblay posted:

This is applicable to 7 and 8. If your are running 6 let me know and I can dig up that too.
Perfect, that's exactly what I was looking for. I'm running 7.x, so I should be good to go.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I have a pair of stacked 3750's with a couple VLANs. One VLAN is used for Internet based traffic and the other is private SAN traffic. I'd like to use an mtu of 9000 for the second vlan, however from what I've read the mtu can only be set system wide and not per interface or vlan. How will having a sys mtu of 9000 affect internet traffic that upstreams to a pair of ASA's that have an mtu of 1500?

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

jwh posted:

If someone has a box running 12.4(15)T1, or can get a box running 12.4(15)T1, I'd like to see if they can reproduce a CEF problem with SSL VPN and VRF.
Is that problem related to the router crashing? We have some 3825's running 12.4(15)T1 that crash after a while when users connect using the AnyConnect VPN client, we're using vrf as well. It's a known issue that will be fixed on the next release.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I want to VPN in to a ASA 5510. I'm confused by the webvpn, ssl vpn, easyvpn options. Can someone post a simple ipsec config for use with the cisco client, or even pptp if its supported. I want to authenticate local users only.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

Girdle Wax posted:

Do you have ASDM installed on the device? If so, go to VPN in ASDM, click "VPN Wizard". It's probably the easiest and quickest way to configure VPN on an ASA/PIX.
I used the wizard to create an L2TP VPN. When I try to connect from my Windows XP client I get "Error 789: The L2TP connection attempt failed because the security layer encountered a process error during initial negotiations with the remote computer".

I don't believe its a firewall issue on my client side because I can connect to other L2TP VPNs just fine.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
Here is more info on error "789" when Windows XP tries to connect L2TP VPN to my ASA 5510. Says "Phase 2 Mismatch". I followed the sample on Cisco's site to the letter.

code:
Dec  9 10:23:36 Group = DefaultRAGroup, IP = 63.197.134.218, PHASE 1 COMPLETED
Dec  9 10:23:36 IP = 63.197.134.218, Keep-alives configured on but peer does not support keep-alives (type = None)
Dec  9 10:23:36 Group = DefaultRAGroup, IP = 63.197.134.218, QM FSM error (P2 struct &0xd6154930, mess id 0xfd5fc287)!
Dec  9 10:23:36 Group = DefaultRAGroup, IP = 63.197.134.218, Removing peer from correlator table failed, no match!
Dec  9 10:23:36 Group = DefaultRAGroup, Username = , IP = 63.197.134.218, Session disconnected. Session Type: IKE, Duration: 0h:00m:00s, Bytes xmt: 0, Bytes rcv: 0, Reason: Phase 2 Mismatch
Relevant config:

code:
crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac 
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac 
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac 
crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac 
crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac 
crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac 
crypto ipsec transform-set ESP-AES-256-SHA esp-aes-256 esp-sha-hmac 
crypto ipsec transform-set ESP-AES-128-SHA esp-aes esp-sha-hmac 
crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac 
crypto ipsec transform-set ESP-AES-128-MD5 esp-aes esp-md5-hmac 
crypto ipsec transform-set TRANS_ESP_3DES_MD5 esp-3des esp-md5-hmac 
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set pfs 
crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 set transform-set TRANS_ESP_3DES_MD5 ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA ESP-3DES-MD5 ESP-DES-SHA ESP-DES-MD5
crypto map outside_map 65535 ipsec-isakmp dynamic SYSTEM_DEFAULT_CRYPTO_MAP
crypto map outside_map interface outside
crypto isakmp enable outside
crypto isakmp policy 10
 authentication pre-share
 encryption 3des
 hash md5
 group 2
 lifetime 86400
crypto isakmp nat-traversal 30
crypto isakmp ipsec-over-tcp port 10000 
group-policy DefaultRAGroup internal
group-policy DefaultRAGroup attributes
 dns-server value 4.2.2.3 4.2.2.4
 vpn-tunnel-protocol IPSec l2tp-ipsec 
tunnel-group DefaultRAGroup general-attributes
 address-pool vpnpool
 authorization-server-group LOCAL
 default-group-policy DefaultRAGroup
tunnel-group DefaultRAGroup ipsec-attributes
 pre-shared-key *
tunnel-group DefaultRAGroup ppp-attributes
 authentication chap

brent78 fucked around with this message at 19:45 on Dec 9, 2007

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

Tremblay posted:

code:
Dec  9 10:23:36 Group = DefaultRAGroup, IP = 63.197.134.218, QM FSM error (P2 struct &0xd6154930, mess id 0xfd5fc287)!
Make sure your crypto ACL on the ASA and the traffic you specified on the Windows host match.
I don't have any ACL's setup for the VPN connection.. perhaps thats my problem, I'll go give it a look now.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I have a pair of ASA 5520's protecting a cluster of around 40 servers. I want to create a class-map that will rate limit SSH and FTP connections by source IP to 5 per minute to cut down on dictionary attacks and the like. Can someone help be find the configuration I'm looking for?

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
Is it possible to rate limit traffic by IP on a Catalyst 3750?

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

Girdle Wax posted:

If DirecTV already has some, they're probably not Nexus since I don't think it's shipping yet, the other Cisco full rack routers would be the CRS-1 single chassis, and I think there's also a GSR (XR) that takes up a full bay.
DirecTV uses 7609's.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I'm picking up a GigE IP circuit from Internap and going to push about 500 Mbit of traffic through it. I'm aggregating 12 cabinets which all use different subnets. What sort of router should I look at? I'm not doing BGP. Would a 3750 do this?

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

inignot posted:

internap is smoke and mirrors.
I have them in Chicago, and have been really happy with the service. Now I'm looking to add them in San Francisco.. Can you be less broad?

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

inignot posted:

I'm aware of that and acknowledged it in what you quoted. My point is that, at best, Internap is selling a voodoo black box that creates asymmetry as their competitive advantage without acknowledging it only works unidirectionally.
It's well known it's unidirectional, you can only control traffic leaving your network. As for "voodoo black box", just read their white papers about the FCP, flow control products. No secrets there. They measure latency, packet loss and broken routes and choose the best path. Have you ever been to their website or talked to an engineer there, doesn't sound like it.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I'm seeing poor speeds over an ipsec tunnel between two Cisco 3825's. I noticed that our DFS shares at each location are only replicating at about half the speed they should. I have outbound QOS on the routers set to 10 Mbit, however I never really see more than 5 Mbit. This got me thinking that maybe it's a MTU issue? netperf shows double the speed when using a udp_stream over tcp.


netperf -t TCP_STREAM -H rwc-vm-dev
Recv Send Send
Socket Socket Message Elapsed
Size Size Size Time Throughput
bytes bytes bytes secs. 10^6bits/sec

87380 16384 16384 10.10 500.21

netperf -t UDP_STREAM -H rwc-vm-dev
Socket Message Elapsed Messages
Size Size Time Okay Errors Throughput
bytes bytes secs # # 10^6bits/sec

126976 65507 10.00 18319 0 959.94
126976 10.00 0 0.00

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

jbusbysack posted:

nevermind, just read IPSEC tunnel, not metro ethernet like I thought.
The two connect over metro ethernet... if that matter or not.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
Can someone post or email a config for a Cisco AP1100 that's using WPA/TKIP, 802.1x / PEAP.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I have a pair of stacked 3750's (love em), with a few vlans. One vlan carries public traffic, another is dedicated to SAN (iSCSI). I'd like to set the system mtu to 9000 to use jumbo frames on the SAN for better performance. What's going to happen to traffic on my public vlan that uses an mtu of 1500? Will it work?

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
We're hiring a Network Engineer in Austin, TX. Must have CCNP or equivalent, will relocate.
http://trionworld.com/career.php?jid=102

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I'm trying to configure a 3825 that I bought refurb. I throw a console cable on it and boot, but after the following messages I don't get a prompt or anything (I hit return multiple times). Any ideas?

System restarted --
Cisco IOS Software, 3800 Software (C3825-ADVIPSERVICESK9-M), Version 12.4(24)T, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2009 by Cisco Systems, Inc.
Compiled Wed 25-Feb-09 22:21 by prod_rel_team
*Aug 22 00:03:56.967: %SNMP-5-COLDSTART: SNMP agent on host Router is undergoing a cold start
*Aug 22 00:03:57.515: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
*Aug 22 00:03:57.515: %CRYPTO-6-GDOI_ON_OFF: GDOI is OFF
*Aug 22 00:03:57.515: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
*Aug 22 00:03:57.515: %CRYPTO-6-GDOI_ON_OFF: GDOI is OFF
*Aug 22 00:03:57.731: %LINK-5-CHANGED: Interface GigabitEthernet0/1, changed state to administratively down


After these last lines I get no response from the console

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
Are there any small/free Windows apps that would allow me to access Cisco CDP information?

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I thought this would be appropriate for the thread. Configuring some switches for our new datacenter that will be all 10GbE. In this pic: 6509-V-E, Nexus 5010, ASR 1002, everything is redundant with VSS. Using the 5010's for top of rack aggregation back to the core. I have all this stuff running in the back of my office, no extra A/C. Get's about 82 degrees in there.

brent78 fucked around with this message at 23:55 on Jun 15, 2010

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

Powercrazy posted:

That looks extremely similar to what we might do for our data center. But we were planning on just keeping everything layer2 with cross chassis port channels between Nexus 5020s and the servers. What kind of topology are you going to use?
That's exactly what we're doing. Everything is layer2 between the blades using the nexus 2050 switches as an aggregation layer. 10 GbE down to each blade chassis (Flex10) and 20 Gbps up to the core using VSS. The only traffic going up to the 6509's is out to the Internet. The ASR 1002's are used for VPN traffic between data centers. I can't really go in to much more detail than that.

brent78 fucked around with this message at 16:58 on Jun 16, 2010

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

Powercrazy posted:

Must be nice have blade chassis with 10G uplinks, lots of ours have individual 1G links which makes it a pain especially since Dell and Cisco went separate ways.
We have 10G all the way down to the blade. I could team to get 20 Gbps, but that's just ridiculous. I wish Cisco made 10GbE switches for the blade chassis so I could run VSS, but now that HP purchased 3COM... well lets just say HP and Cisco won't be working on much together anymore.
http://h18000.www1.hp.com/products/blades/components/ethernet/10-10gb-f/index.html

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
I need to find a contractor in the Sacramento, CA area that can do some BGP/routing work on some 3800's. Can someone point me in the right direction?

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

Tremblay posted:

How are you paying them? I'll ask if anyone is interested in pulling a side gig.
Cold hard cash US American dollars, even if they aren't worth poo poo these days.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
Trying to configure an IPSEC tunnel on a 3925

(config)#crypto isakmp policy 10
^
% Invalid input detected at '^' marker.

Edit: Problem may be my image Version 15.0(1r)M6
c3900-universalk9-mz.SPA.150-1.M3.bin

brent78 fucked around with this message at 08:20 on Jan 5, 2012

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.

Powercrazy posted:

You are probably not using a "k9" IOS chain, so crypto doesn't exist. Alternatively it may be a licensing issue and you have to "activate" encryption, in addition to having a "k9" code.

code:
Technology Package License Information for Module:'c3900'

----------------------------------------------------------------
Technology    Technology-package          Technology-package
              Current       Type          Next reboot
-----------------------------------------------------------------
ipbase        ipbasek9      Permanent     ipbasek9
security      None          None          None
uc            None          None          None
data          None          None          None
What do I need to do?

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
How / where do I buy the securityk9 license for a 3925 router? Cisco's website makes my head hurt.

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
Cisco 2911/K9 (C2900-UNIVERSALK9-M), Version 15.1(4)M4, RELEASE SOFTWARE (fc1)

Shouldn't this be supported?

code:
(config)#ip urlfilter server vendor websense 172.16.4.12 timeout 8 retransmit 6
                        ^
% Invalid input detected at '^' marker.

Adbot
ADBOT LOVES YOU

brent78
Jun 23, 2004

I killed your cat, you druggie bitch.
Need a router that can do 500-800 Mbps of AES256 crypto. I'm looking at the ASR1001, but not familiar with the entire Cisco line these days.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply