Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
sudo rm -rf
Aug 2, 2011


$ mv fullcommunism.sh
/america
$ cd /america
$ ./fullcommunism.sh


So I started working at my first "real" job out of college, and I'm basically going to be taking over a few server rooms that each have four/five racks as well as a couple classrooms with some lab computers. The equipment is a mix of Cisco video products (think QAM modulators), server products (UCS, DNCS, etc), and networking products (various routers and switches). I also get a /23 to play with, but at the moment everything seems to be thrown into a single network - no logical or physical subnets at the moment.

The server rooms are kind of cluttered. No real cable management - coaxial and ethernet everywhere. No real documentation either. About 25% of the equipment is no longer being used, and there aren't any real-time monitoring systems in place.

I feel like I can do this, I just haven't done it yet, so I'm not sure where to start. I started building an inventory using an excel sheet to get an idea of where things are physically - I figure the next step is to document how everything is connected.

I want to get into a position where this equipment can be centrally managed and monitored. I figure you guys could point me in the right direction.

Adbot
ADBOT LOVES YOU

jwh
Jun 12, 2002

Eh, just drink a beer and take a nap. That's really the best advice I have.

H.R. Paperstacks
May 1, 2006

This is America
My president is black
and my Lambo is blue

Erkenntnis posted:

So I started working at my first "real" job out of college, and I'm basically going to be taking over a few server rooms that each have four/five racks as well as a couple classrooms with some lab computers. The equipment is a mix of Cisco video products (think QAM modulators), server products (UCS, DNCS, etc), and networking products (various routers and switches). I also get a /23 to play with, but at the moment everything seems to be thrown into a single network - no logical or physical subnets at the moment.

The server rooms are kind of cluttered. No real cable management - coaxial and ethernet everywhere. No real documentation either. About 25% of the equipment is no longer being used, and there aren't any real-time monitoring systems in place.

I feel like I can do this, I just haven't done it yet, so I'm not sure where to start. I started building an inventory using an excel sheet to get an idea of where things are physically - I figure the next step is to document how everything is connected.

I want to get into a position where this equipment can be centrally managed and monitored. I figure you guys could point me in the right direction.

Step one will always be to make zero changes until you have documented everything. There might be a method to the madness, you just haven't seen/found it yet. The last thing you want to do is come in and start making sweeping changes and potentially break things.

Take a few weeks and build a big initial set of documentation, then start to build projects around what you want to see implemented / changed, like a management network, centralized logging, authentication, etc

bort
Mar 13, 2003

I was drinking a beer and looking at this http://www.opendcim.org before my nap. And yeah, proceed with caution. "I was trying to clean stuff up" doesn't generally satisfy people when your network is down.

ruro
Apr 30, 2003

bort posted:

I was drinking a beer and looking at this http://www.opendcim.org before my nap. And yeah, proceed with caution. "I was trying to clean stuff up" doesn't generally satisfy people when your network is down.

My DC manager acquired iTRACS at the start of the financial year. Many months later he's still working on getting all the cable runs and auditing complete to make it useful :(.

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
Just changed the console password on a 3750 stack and the master switch crashed hard. Hmmmmmmmmmmmmm.

jwh
Jun 12, 2002

Zuhzuhzombie!! posted:

Just changed the console password on a 3750 stack and the master switch crashed hard. Hmmmmmmmmmmmmm.

Yikes.

nzspambot
Mar 26, 2010

Zuhzuhzombie!! posted:

Just changed the console password on a 3750 stack and the master switch crashed hard. Hmmmmmmmmmmmmm.

I did that once by adding a SNMP community :wtc:

ruro
Apr 30, 2003

At least you didn't hold down the mode button to demonstrate express setup wasn't enabled on the service desk switch stack only to find out it was enabled... (who decided that feature was a good idea).

Partycat
Oct 25, 2004

I've had that feature used by an errant janitor cart that was the right height to somehow press the mode button. I've had the lovely bezel on the 3750 bust off and press the mode button. And, I've had it used by a guy who said "it wasn't blinking right so I pressed the reset button". The day I realized it just renamed the config files and VLAN database was the day I stopped being concerned about it, though I still can't convince engineering it needs to be turned off.

jwh
Jun 12, 2002

Question: I'm being asked to look at long-term packet retention appliances- probably no more than 1-2gbps. No IDS functionality is required, just straight pcaps.

We had originally tried rolling our own, but it seems as though our security-onion box was dying under only 100-200mbps. I'm not on our sysadmin team, so I don't know the details.

Anyway, I know Riverbed makes their Cascade / Shark stuff, and I've heard of nPulse, but have no experience directly.

Anyone have any recommendations?

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
We use Fluke's Network Time Machine at 10gbps and it doesn't choke.

bort
Mar 13, 2003

Not completely relevant, since I am perennially trying to justify budget for Shark, but we use Cascade for Net-/Sflow. Recent versions have been challenging. We had the most recent (10.0.7) Profiler upgrade hang up and require us to set it to defaults and restore from backup (support: 'it happens'). It later crashed hard when a device had time that was off -- and sure, I'll take partial blame for that. But most unlike a Riverbed product, and never had an issue with a Cascade before. Getting burned by expensive equipment makes an especially sour taste.

e: forgot a word

bort fucked around with this message at 20:19 on Oct 16, 2013

jwh
Jun 12, 2002

I had used RiOS boxes before, supposedly for wan opt, but our users were pretty ambivalent about apparent improvement.

This most recent need for long term pcap retention came about as part of a 'security incident', so they're asking for long term forensic capabilities.

I'm sure we'll figure something out. I'm still of the mind that they don't actually need full frames written to disk for, say, 90 days, but then again, I just work here.

abigserve
Sep 13, 2009

this is a better avatar than what I had before
You should be able to roll your own just using Gulp or some equivilent (tcpdump might even work natively) and a properly tuned linux host. I have not tried it myself but honestly if you have spare hardware it doesn't sound difficult (http://staff.washington.edu/corey/gulp/ ; http://blog.crox.net/archives/72-gulp-tcpdump-alternative-for-lossless-capture-on-Linux.html)

Make sure you have fast disk, a cron job to rotate the files, and some sort of process checking so if it crashes for whatever reason it starts again and doesn't overwrite the older files.

Let me know if you get the chance to do it because I'd like to look at doing it myself.

H.R. Paperstacks
May 1, 2006

This is America
My president is black
and my Lambo is blue
This sounds like a perfect opportunity to use pf_Ring from the Ntop crew: http://www.ntop.org/products/pf_ring/

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
Could some one help me understand how to navigate the Cisco Feature Navigator? Tried to install a 48 port gigabit blade in our 6509 (running adventerprisek9_wan-mz.122-33.SXJ.bin). This was released in 2011. Upon installing the blade I received an error that, according to Google sources, means that my OS is out of date and doesn't support the blade. Fine. Found the latest release in this train that was released in July this year (adventerprisek9_wan-mz.122-33.SXJ6.bin) but I can't for the life of me figure out how to verify that it will support the 48 port blade.

n0tqu1tesane
May 7, 2003

She was rubbing her ass all over my hands. They don't just do that for everyone.
Grimey Drawer

Zuhzuhzombie!! posted:

Could some one help me understand how to navigate the Cisco Feature Navigator? Tried to install a 48 port gigabit blade in our 6509 (running adventerprisek9_wan-mz.122-33.SXJ.bin). This was released in 2011. Upon installing the blade I received an error that, according to Google sources, means that my OS is out of date and doesn't support the blade. Fine. Found the latest release in this train that was released in July this year (adventerprisek9_wan-mz.122-33.SXJ6.bin) but I can't for the life of me figure out how to verify that it will support the 48 port blade.

Go to the product page for the linecard. It should have the earliest supported version listed.

ragzilla
Sep 9, 2005
don't ask me, i only work here


Zuhzuhzombie!! posted:

Could some one help me understand how to navigate the Cisco Feature Navigator? Tried to install a 48 port gigabit blade in our 6509 (running adventerprisek9_wan-mz.122-33.SXJ.bin). This was released in 2011. Upon installing the blade I received an error that, according to Google sources, means that my OS is out of date and doesn't support the blade. Fine. Found the latest release in this train that was released in July this year (adventerprisek9_wan-mz.122-33.SXJ6.bin) but I can't for the life of me figure out how to verify that it will support the 48 port blade.

What line card and error message?

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
%C6KPWR-SP-4-UNSUPPORTED: unsupported module in slot 1, power not allowed: Unknown Card Type.

I'll grab the model number and see what's up. Thanks.

Zuhzuhzombie!! fucked around with this message at 16:31 on Oct 17, 2013

jwh
Jun 12, 2002

what model 48 port blade is it?

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
ws-x6848-GE-TX V01


ed

Data sheet says:
• Supervisor engine: Compatible with Supervisor Engine 2T and Supervisor Engine 2TXL


Though we're using Supervisor 720. Maybe that's my problem?

Zuhzuhzombie!! fucked around with this message at 17:12 on Oct 17, 2013

H.R. Paperstacks
May 1, 2006

This is America
My president is black
and my Lambo is blue
You will need to know your chassis as well, 6509 vs 6509-E, because if they are similar to how the 4500 vs 4500-E series is, there are specific slots that E series line cards can go into.

EDIT:

You can check with "sh module", it will be similar to:

code:
#sh module 
Chassis Type : WS-C4510R-E

tortilla_chip
Jun 13, 2007

k-partite
You're trying to run a linecard with a DFC4 with a MSFC3 supervisor. Not supported.

e: You might be able to install a DFC3 on the linecard, effectively making it a WS-X6748-GE-TX

tortilla_chip fucked around with this message at 17:18 on Oct 17, 2013

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
WS-C6509-E



ed


quote:

PFC4 linecard with a MSFC3 supervisor

Just curious as to what this means, specifically. But thank you for clearing that up. I doubt we'd want to change SUP engines, but curious, would doing so fix that issue or is it something larger?

Zuhzuhzombie!! fucked around with this message at 17:17 on Oct 17, 2013

tortilla_chip
Jun 13, 2007

k-partite
https://supportforums.cisco.com/docs/DOC-21377
http://www.cisco.com/en/US/prod/collateral/modules/ps2797/ps11878/qa_c67-648478.html

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
Thanks!

Which brings up another question... what kinda CPUs are in these things?

tortilla_chip
Jun 13, 2007

k-partite
Some bitchin Motorola PowerPCs!

bort
Mar 13, 2003

jwh posted:

I had used RiOS boxes before, supposedly for wan opt, but our users were pretty ambivalent about apparent improvement.
I think they crush CIFS out of the park and are marginal on everything else.

tortilla_chip
Jun 13, 2007

k-partite
Direct link to the Cisco Live presentation for 6500 architecture:
http://d2zmdbbm9feqrf.cloudfront.net/2013/usa/pdf/BRKARC-3465.pdf

If that doesn't work, create an account on https://www.ciscolive365.com

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
"• Supervisor engine: Compatible with Supervisor Engine 2T and Supervisor Engine 2TXL"

On this page

http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/data_sheet_c78-451794.html


is

"Supervisor 2"

On this page

https://supportforums.cisco.com/docs/DOC-21377#Policy_Feature_Card_PFC




Yes? Sorry if this just seems blatantly obvious.




Ah. DMCA policing, the time I get to search through my eMails for "Horny White Moms 2" at the office with legitimate purpose.

tortilla_chip
Jun 13, 2007

k-partite
Sup2 != Sup2T

Sup2 = MSFC2
Sup2T = MSFC5

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
Thank you again. One more question if you'll spare some more patience.

Where can I go to find what kind of card it is? For example:

http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/data_sheet_c78-451794.html

This is the spec sheet for the card I have but a ctrl F doesn't find anything PFC or MSFC. Or am I supposed to figure that out from the Supervisor Engine requirement listing?

tortilla_chip
Jun 13, 2007

k-partite
The PFC/MSFC are both on the Supervisor. Linecards have a CFC/DFC. Both the PFC/MSFC and CFC/DFC have to be compatible for the card to boot. Furthermore, the whole chassis can only boot to the lowest common denominator of features.

e: Slide 45 in the Cisco Live presentation explains this with a nice table.

Zuhzuhzombie!!
Apr 17, 2008
FACTS ARE A CONSPIRACY BY THE CAPITALIST OPRESSOR
Thanks. Completely glossed over the post with that link.

CrazyLittle
Sep 11, 2001





Clapping Larry
What do you guys think about a catalyst 4900m as a cheap 10gig aggregation switch? I won't be using much if any routing logic on it.

adorai
Nov 2, 2002

10/27/04 Never forget
Grimey Drawer

CrazyLittle posted:

What do you guys think about a catalyst 4900m as a cheap 10gig aggregation switch? I won't be using much if any routing logic on it.
I don't have production experience, but we looked at them and got scared by the backplane speeds.

sudo rm -rf
Aug 2, 2011


$ mv fullcommunism.sh
/america
$ cd /america
$ ./fullcommunism.sh


What kind of switches should I be looking at for top-of-rack 10g uplinks to a core 6509-e? Something like the 3650-X?

Badgerpoo
Oct 12, 2010

Erkenntnis posted:

What kind of switches should I be looking at for top-of-rack 10g uplinks to a core 6509-e? Something like the 3650-X?

Are you looking for 1Gb or 10Gb edge ports? Do you want to stack?

Adbot
ADBOT LOVES YOU

ToG
Feb 17, 2007
Rory Gallagher Wannabe
This isn't a strictly Cisco question but can you make ntp more tolerant of time difference for a switch. We enabled ntp on a few switches and now they're spewing snmp messages about the time changing a few times an hour. Our monitoring software throws an alarm for this but it's literally changes of sub second values.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply