Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ior
Nov 21, 2003

What's a fuckass?

VR Cowboy posted:

Does anyone know how to find software serial number on NCS? We're trying to transfer our maintenance agreements to smartnet but I'll be damned if I can find any of those serials on NCS, or what they even look like.

Log on with SSH and do show udi.

Adbot
ADBOT LOVES YOU

Yeast Confection
Oct 7, 2005

ior posted:

Log on with SSH and do show udi.

Thanks! This was just what we needed :)

ior
Nov 21, 2003

What's a fuckass?

VR Cowboy posted:

Thanks! This was just what we needed :)

You really should get that upgraded to Prime Infrastructure though. (1.4 is almost out, wait for that before you do a migration)

less than three
Aug 9, 2007



Fallen Rib
Anyone run into a memory leak with 3560X running 15.0(2)SE2?

Particularly due to Auth Manager, *Init* or *Dead*

code:
#show proc mem sorted
Processor Pool Total:  175102024 Used:  158029008 Free:   17073016
      I/O Pool Total:   16777216 Used:    5604636 Free:   11172580
Driver te Pool Total:    4194304 Used:         40 Free:    4194264

 PID TTY  Allocated      Freed    Holding    Getbufs    Retbufs Process
 182   0 1144026320  855292808  128141468          0          0 Auth Manager    
   0   0   75986676   47526828   24875780          0          0 *Init*          
   0   0  448800868  591739404    3806020    7072519    1358594 *Dead*          
   0   0          0          0     394492          0          0 *MallocLite*    
  59   0     370272        600     379832          0          0 EEM ED Identity 
  84   0     643092     149228     324056          0          0 Stack Mgr Notifi
 317   0     265100          0     275260     100548          0 EEM ED Syslog   
 265   0   63304276    4734480     232028       2268          0 DHCPD Receive   
 329   0     196372          0     203532          0          0 EEM Server      
 185   0     312700      35840     164716          0          0 CDP Protocol    
 196   0     301532     169272     152092          0          0 IP ARP Adjacency
   1   0     190452      52944     146212          0          0 Chunk Manager   
 160   1     795988     692728     111260          0          0 SSH Process     
 358   0     319940      71008     104204          0          0 LLDP Protocol   
 103   0     101308          0      99792      58836          0 HRPC emac reques
  62   0     152064      22548      86356          0          0 USB Startup     
 216   0    1897952    1421856      80252          0          0 802.1x switch   

sudo rm -rf
Aug 2, 2011


$ mv fullcommunism.sh
/america
$ cd /america
$ ./fullcommunism.sh


I just received some of my hardware for my CCNA lab, and my two 2950s came without any IOS image. After much googling, it seemed like xmodem was the only way to get an image on the switches - so I set the BAUD rate to 115200 on both the switch and my com port (which is a usb-to-serial adapter), and started the transfer. Well, it's going pretty slow - only about 211 Bytes/s - it should be going faster than that, right? Any ideas why it wouldn't?

Yeast Confection
Oct 7, 2005

ior posted:

You really should get that upgraded to Prime Infrastructure though. (1.4 is almost out, wait for that before you do a migration)

That's one of our goals. Hopefully in the next year we'll have it in the door.

less than three
Aug 9, 2007



Fallen Rib

Erkenntnis posted:

I just received some of my hardware for my CCNA lab, and my two 2950s came without any IOS image. After much googling, it seemed like xmodem was the only way to get an image on the switches - so I set the BAUD rate to 115200 on both the switch and my com port (which is a usb-to-serial adapter), and started the transfer. Well, it's going pretty slow - only about 211 Bytes/s - it should be going faster than that, right? Any ideas why it wouldn't?

Are you transferring in xmodem 1k mode?

sudo rm -rf
Aug 2, 2011


$ mv fullcommunism.sh
/america
$ cd /america
$ ./fullcommunism.sh


less than three posted:

Are you transferring in xmodem 1k mode?

Not sure. I ended up canceling the transfer and switched term emulators (from terma to securecrt) and started the transfer again - worked fine.

Moving onto my router brought me more issues, though. I got a 2621xm from amazon (specifically, SAM networks). Hooked it all up, set the baud rate to 9600 - no console response. Changed the baud rate around to the various possible rates, still no response. Take a look at my front LEDs and sure enough:

quote:

Blink (500 ms ON, 500 ms OFF, 2 seconds between codes)—In
ROMMON, error detected.

is what I'm getting. Is my router probably shot?

nzspambot
Mar 26, 2010

Erkenntnis posted:

Not sure. I ended up canceling the transfer and switched term emulators (from terma to securecrt) and started the transfer again - worked fine.

Moving onto my router brought me more issues, though. I got a 2621xm from amazon (specifically, SAM networks). Hooked it all up, set the baud rate to 9600 - no console response. Changed the baud rate around to the various possible rates, still no response. Take a look at my front LEDs and sure enough:


is what I'm getting. Is my router probably shot?

If you can;t get to ROMMON I think you are boned; that being said I do believe (and I might be wrong) that the ROMMON for a 2600 is replaceable.

http://www.cisco.com/en/US/docs/routers/access/2600/hardware/installation/notes/2600mem.html#wp93177

try :

http://www.ebay.com/itm/NEW-BOOT-26...=item48465a6023

more here:

http://www.ebay.com/sch/i.html?_trksid=p2050601.m570.l1313.TR2.TRC1.A0.Xboot+rom+cisco&_nkw=boot+rom+cisco&_sacat=0&_from=R40

nzspambot fucked around with this message at 03:40 on Jul 22, 2013

Partycat
Oct 25, 2004

less than three posted:

Anyone run into a memory leak with 3560X running 15.0(2)SE2?

Yes, upgrade to 15.0(2)SE4 or go back to 12 where you came from. We chose the former and it seems to be working out.

sudo rm -rf
Aug 2, 2011


$ mv fullcommunism.sh
/america
$ cd /america
$ ./fullcommunism.sh



I just ended up getting a refund, fortunately.

Another question, though. Got my other router in, working fine - but I went to set-up SSH v2, and it's missing the 'version' part of the command.

code:
a0-f0-r0(config)#ip ssh ?      
  authentication-retries  Specify number of authentication retries
  break-string            break-string
  logging                 Configure logging for SSH
  port                    Starting (or only) Port number to listen on
  rsa                     Configure RSA keypair name for SSH
  source-interface        Specify interface for source address in SSH
                          connections
  time-out                Specify SSH time-out interval
Here's my ver output

code:
a0-f0-r0#sh ver
Cisco Internetwork Operating System Software 
IOS (tm) C2600 Software (C2600-IK9S-M), Version 12.3(22), RELEASE SOFTWARE (fc2)
Technical Support: [url]http://www.cisco.com/techsupport[/url]
Copyright (c) 1986-2007 by cisco Systems, Inc.
Compiled Wed 24-Jan-07 16:48 by ccai
Image text-base: 0x80008098, data-base: 0x81CBC398

ROM: System Bootstrap, Version 12.2(8r) [cmong 8r], RELEASE SOFTWARE (fc1)
ROM: C2600 Software (C2600-IK9S-M), Version 12.3(22), RELEASE SOFTWARE (fc2)

a0-f0-r0 uptime is 5 hours, 29 minutes
System returned to ROM by reload
System image file is "flash:c2600-ik9s-mz.123-22.bin"
Google isn't getting me anywhere - any ideas?

e:figured it out - apparently even though SSHv2 was first introduced in 12.2, it's not available for the version of IOS that I have.

sudo rm -rf fucked around with this message at 03:18 on Jul 23, 2013

Svarotslav
May 22, 2005
Can anyone give me some pointers or examples of manipulating vlanTrunkPortVlansEnabled via snmp? I can get the vlan list, convert it to binary, manipulate it, repackage to a hex string, but I cannot for the life of me work out how to set the values.

I understand there's the vlanTrunkPortSetSerialNo, but I have no idea how to use it. the documentation on cisco site does not make sense to me.

from:
http://tools.cisco.com/Support/SNMP/do/BrowseOID.do?local=en&translate=Translate&objectInput=1.3.6.1.4.1.9.9.46.1.6.1.1.4

"To avoid conflicts between overlapping partial updates by
multiple managers, i.e., updates which modify only a portion
of an instance of this object (e.g., enable/disable a single
VLAN on the trunk port), any SNMP Set operation accessing an
instance of this object should also write the value of
vlanTrunkPortSetSerialNo."

I have no idea how these spinnerlocks work, and the documentation I can find does not explain it terribly well.

thanks.

psydude
Apr 1, 2008

I'm setting up a pair of Stonesoft Stonegates and holy poo poo, this is a completely 100% different process than anything I've ever seen or worked with before.

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
ed

nvm

I'm a functional retard.

Zuhzuhzombie!! fucked around with this message at 21:42 on Jul 23, 2013

Partycat
Oct 25, 2004

Svarotslav posted:

I have no idea how these spinnerlocks work, and the documentation I can find does not explain it terribly well.

Well, it doesn't sound like there's any locking involved, it just increments that value, but it may behave like the copy operation and a few of the other ones do where you have to set the serial number and the requisite port index and vlan values in the same set command for it to accept it.

I'm in the same boat as you where I find pretty poor documentation on how to implement some of the SNMP MIBs, or, at least, I feel like there is some knowledge I don't have while reading the SNMP MIB file about how it operates.

Svarotslav
May 22, 2005

Partycat posted:

Well, it doesn't sound like there's any locking involved, it just increments that value, but it may behave like the copy operation and a few of the other ones do where you have to set the serial number and the requisite port index and vlan values in the same set command for it to accept it.

I'm in the same boat as you where I find pretty poor documentation on how to implement some of the SNMP MIBs, or, at least, I feel like there is some knowledge I don't have while reading the SNMP MIB file about how it operates.

Ok, I understand it now. Thanks.

The OID for the serial was not exactly as documented, so i did an snmpwalk and found the rest of the OID string I needed. Once I did that, I was able to pull the serial along with the data, and then push the updated vlan list back to the switch along with the serial. Makes sense to me now.

Cheers.

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
Been a while since I've added a stack to a production 3750. Best way to prep before hand? Basically just put the same IOS on it? I know that the master will push it's IOS on the slaves but I've had weird issues in the past.

I've changed the priority on my stack master to 10. Gonna set the priority of the slave to 1 and upgrade the IOS. That should be pretty much it?

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
Some people like to prep it in the config but I just bring the IOS code to the same as the others then shove it in raw

inignot
Sep 1, 2003

WWBCD?
Has anyone here ever successfully set up JunOS on a FreeBSD image in VMWare? I've found varying instructions for varying versions of JunOS. None of which have yet to work.

http://pauldotcom.com/2011/05/virtualizing-junos-on-vmware.html
http://dustinberube.com/2011/05/creating-a-junos-olive-in-vmware/
http://www.packetmischief.ca/2011/03/24/installing-olive-10-4r1-under-vmware/

Svarotslav
May 22, 2005

Zuhzuhzombie!! posted:

Been a while since I've added a stack to a production 3750. Best way to prep before hand? Basically just put the same IOS on it? I know that the master will push it's IOS on the slaves but I've had weird issues in the past.

I've changed the priority on my stack master to 10. Gonna set the priority of the slave to 1 and upgrade the IOS. That should be pretty much it?

My advice is
1) ensure the IOS is identical,
2) if it's not a brand new slave, delete the vlan.dat on the new slave switch,
3) if it's not a brand new slave perform a wr erase on the slave,
4) set the priority in the new device.
5) on the master, use the provision command to add the new switch of that type into the config and set the ports up so I can cable them straight away.
6) ensure the stack ring is complete, so when you break it, prod data is still able to flow.
7) make sure you have a long stack cable to complete the ring (3m is gooood).
8) perform the physical stack add.

ior
Nov 21, 2003

What's a fuckass?

Svarotslav posted:

My advice is
1) ensure the IOS is identical,
2) if it's not a brand new slave, delete the vlan.dat on the new slave switch,
3) if it's not a brand new slave perform a wr erase on the slave,
4) set the priority in the new device.
5) on the master, use the provision command to add the new switch of that type into the config and set the ports up so I can cable them straight away.
6) ensure the stack ring is complete, so when you break it, prod data is still able to flow.
7) make sure you have a long stack cable to complete the ring (3m is gooood).
8) perform the physical stack add.
9) Power on the new switch. (NOT before you cable it)

falz
Jan 29, 2005

01100110 01100001 01101100 01111010

inignot posted:

Has anyone here ever successfully set up JunOS on a FreeBSD image in VMWare? I've found varying instructions for varying versions of JunOS. None of which have yet to work.

http://pauldotcom.com/2011/05/virtualizing-junos-on-vmware.html
http://dustinberube.com/2011/05/creating-a-junos-olive-in-vmware/
http://www.packetmischief.ca/2011/03/24/installing-olive-10-4r1-under-vmware/
Juniper Olive in Virtualbox is pretty easy to set up, give that a shot instead? You have to un tar/gzip a file, put a new binary in it, repackage it and install.

DeNofa
Aug 25, 2009

WILL AMOUNT TO NOTHING IN LIFE.

How are you guys feeling about the GOD drat ISR-4451X?

Robb Boyd is pumped: http://www.cisco.com/en/US/products...otlight+isr4451

ruro
Apr 30, 2003

DeNofa posted:

How are you guys feeling about the GOD drat ISR-4451X?

Robb Boyd is pumped: http://www.cisco.com/en/US/products...otlight+isr4451

I feel ASR1002-X or go home.

inignot
Sep 1, 2003

WWBCD?

falz posted:

Juniper Olive in Virtualbox is pretty easy to set up, give that a shot instead? You have to un tar/gzip a file, put a new binary in it, repackage it and install.

I tried to follow the instructions on the pauldotcom site for freebsd on VmWare (shouldn't be radically different from Virtualbox). The un tar/gzip & re pack process was what they described there. However it was with an older Junos version 8 I believe. I have not found anything earlier then 10 available for download.

Several other sites have instructions for varying JunOS versions newer then 8, some involve also changing lines in the install scripts. I've had no luck with any of it. All result in failures upon trying to add the package to freebsd.

Pile Of Garbage
May 28, 2007



This question has probably been asked a million times in this thread so apologies in advance: what is the currently recommended router/switch combo for setting up a home CCNA lab? I've had a look around on Google however most of the guides/sites I found were a year or two old and I'm worried about investing in something that may be obsolete or not support a relevant IOS version.

ate shit on live tv
Feb 15, 2004

by Azathoth
CCNA requires pretty much nothing equipment-wise. Get 2 switches as long as they run IOS so that you can figure out trunking and port channels, and get a router.

Lab:
Create multiple VLANs on the switches
Change Spanning tree priority per vlan
Create multiple trunks and portchannels between the switches
Setup router on a stick so that a host on one vlan can get to a host in a different vlan.
If you have two routers create two router on a sticks and figure out how to advertise each network between the two routers using static routes, then do it again using a routing protocol, I'd suggest OSPF.

That's pretty much it.

Equipment:
Two of any of these:
2950/2960
3550/3560

and

one or two of either of these:
2600
1800/2800/3800

Everything else on the CCNA is basically Cisco sales speak/indoctrination. You'll need to know it to pass the test, but it's not super relevant in the real world.

ate shit on live tv fucked around with this message at 17:30 on Jul 25, 2013

GOOCHY
Sep 17, 2003

In an interstellar burst I'm back to save the universe!
Just use Packet Tracer unless you absolutely need physical access to gear.

Pile Of Garbage
May 28, 2007



Powercrazy posted:

CCNA requires pretty much nothing equipment-wise. Get 2 switches as long as they run IOS so that you can figure out trunking and port channels, and get a router.

Lab:
Create multiple VLANs on the switches
Change Spanning tree priority per vlan
Create multiple trunks and portchannels between the switches
Setup router on a stick so that a host on one vlan can get to a host in a different vlan.
If you have two routers create two router on a sticks and figure out how to advertise each network between the two routers using static routes, then do it again using a routing protocol, I'd suggest OSPF.

That's pretty much it.

Equipment:
Two of any of these:
2950/2960
3550/3560

and

one or two of either of these:
2600
1800/2800/3800

Everything else on the CCNA is basically Cisco sales speak/indoctrination. You'll need to know it to pass the test, but it's not super relevant in the real world.

Awesome thanks for the info. Regarding IOS versions would IP Base be fine across all the gear or would you recommend IP Advanced on the routers?


GOOCHY posted:

Just use Packet Tracer unless you absolutely need physical access to gear.

That's an excellent point I completely forgot about Packet Tracer. Can you get Packet Tracer outside of being a registered academy student? I'll probably see if I can grab a copy from one of my work mates.

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
I can't test this on anything in production at the moment, but I've been requested to provide a /28 subnet and have multiple IPs from it put on various interfaces as secondary IPs. Some interfaces are on the same device, some interfaces are on different devices. I'm telling him we can't do that, because you can't put multiple interfaces in the same subnet with a primary IP.

ragzilla
Sep 9, 2005
don't ask me, i only work here


Zuhzuhzombie!! posted:

I can't test this on anything in production at the moment, but I've been requested to provide a /28 subnet and have multiple IPs from it put on various interfaces as secondary IPs. Some interfaces are on the same device, some interfaces are on different devices. I'm telling him we can't do that, because you can't put multiple interfaces in the same subnet with a primary IP.

Do the interfaces have existing IP addresses? Could you use ip unnumbered?

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR

ragzilla posted:

Do the interfaces have existing IP addresses? Could you use ip unnumbered?

Yeah, they already have a /30 or a /29 on them. We need an additional range from some VOIP gateways.

This is the first I've ever heard of "ip unnumbered".


ed

From first look, not sure if that's what will work either. From what I understand, he wants half of a /28 to sit on various interfaces while he uses the other half of the /28 as his outbound interface's IP, and he'd use one individual IP from my half as a gateway for one individual IP from his half. I'd be putting

Zuhzuhzombie!! fucked around with this message at 22:43 on Jul 25, 2013

jwh
Jun 12, 2002

Yeah that's confusing.

Can you just modify the /28 to two /29s and then route him the second /29?

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR

jwh posted:

Yeah that's confusing.

Can you just modify the /28 to two /29s and then route him the second /29?

I don't think so. If it were that easy, we'd just use a secondary /30 like we have with previous customers.

Anyway. I'm sure I'll have to deal with this in the morning so I'll let ya know if it's as crazy as it seems.

World z0r Z
May 26, 2013

So I've got Nexus 7k OTV working across an MPLS core in a test env.

All interfaces are set for 9216 where applicable.

Why is my overlay interface 1400 mtu and cannot be adjusted?

This limits my datacenter to datacenter MTU to 1454 (42 bytes OTV + 4 bytes dot1q)

naturally the SAN guys are frothing like rabid animals (well more than usual anyway) about swinging a jumbo frame storage vlan over 1454.

Cisco was like "just set ur interfaces for 9216 bro"

Ummm, Cisco? I can't.

OTV module is M1 btw.

psydude
Apr 1, 2008

Okay, so my lack of doing layer 3 poo poo on a consistent basis (all layer 2 all the time, baby) has me kind of questioning my own design here.

I have a /28 block of public IP addresses (let's call 'em 12.100.0.0/28 just for ease) that I want to subnet into two /29 blocks. One of these /29 blocks (12.100.0.0/29) will actually be NATed on my firewall, whose interface in completely different broadcast domain (12.85.0.0/29). The other /29 block (12.100.0.8/29) will hang off another interface on the T3 router.

So the first /29 block on the NAT (12.100.0.0) won't need a network or broadcast address, freeing up the .0 and .7 addresses for me to use on the firewall. However, the thing that makes me nervous is that I need to advertise a /29 block to the T3 router from the firewall and a /28 block from the router to the ISP. So if I use that first address (12.100.0.0) as an address for translation on my NAT, everything will be fine, despite me advertising that 12.100.0.0/29 prefix from the firewall and then 12.100.0.0/28 from the router to the ISP, right?

psydude fucked around with this message at 02:20 on Jul 26, 2013

FatCow
Apr 22, 2002
I MAP THE FUCK OUT OF PEOPLE
You should be fine with that. That is basically how subnetting/supernetting works. The one thing you'll want to do is install a static null route for 12.100.0.0/28 on the T3 router. This way if your FW or other switch eats it and stops injecting the /29 you won't loop packets all over the place. (And if you're doing BGP with your upstream you'll need it anyhow)

Advertising a larger network to your ISP is super common on networks. I have 2 /20s that never actually exist as a /20. They immediately get broken up into /23s and /24s for each of my DCs. Then once they get into the DCs they are further broken down into /27s and /26s.

psydude
Apr 1, 2008

Okay, cool. For some reason I was worried that using a summary address with a prefix that doesn't have a network address would result in weirdness.

ruro
Apr 30, 2003

World z0r Z posted:

So I've got Nexus 7k OTV working across an MPLS core in a test env.

All interfaces are set for 9216 where applicable.

Why is my overlay interface 1400 mtu and cannot be adjusted?

This limits my datacenter to datacenter MTU to 1454 (42 bytes OTV + 4 bytes dot1q)

naturally the SAN guys are frothing like rabid animals (well more than usual anyway) about swinging a jumbo frame storage vlan over 1454.

Cisco was like "just set ur interfaces for 9216 bro"

Ummm, Cisco? I can't.

OTV module is M1 btw.

The 1400 MTU is for control traffic not for data traffic. Your data traffic is limited to the path MTU, so as long as all your intermediate interfaces etc. are set to jumbo you'll be fine.

Adbot
ADBOT LOVES YOU

ate shit on live tv
Feb 15, 2004

by Azathoth

World z0r Z posted:

So I've got Nexus 7k OTV working across an MPLS core in a test env.

All interfaces are set for 9216 where applicable.

Why is my overlay interface 1400 mtu and cannot be adjusted?

This limits my datacenter to datacenter MTU to 1454 (42 bytes OTV + 4 bytes dot1q)

naturally the SAN guys are frothing like rabid animals (well more than usual anyway) about swinging a jumbo frame storage vlan over 1454.

Cisco was like "just set ur interfaces for 9216 bro"

Ummm, Cisco? I can't.

OTV module is M1 btw.

I'll check our Nexus config tomorrow and let you know.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply