Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
ate shit on live tv
Feb 15, 2004

by Azathoth

tortilla_chip posted:

This is what you get for running CGNAT :)

haha.

Adbot
ADBOT LOVES YOU

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
We would run it native on the ASR5500 but Cisco wants 1.5 million for the license :/

Bigass Moth
Mar 6, 2004

I joined the #RXT REVOLUTION.
:boom:
he knows...
Why did Cisco make some ASA models show an Amber link light on 1000Mbps links? Could they not afford a third led?

mythicknight
Jan 28, 2009

my thick night

Is it possible to integrate Cisco Jabber with AD, but not CUCM itself?

CrazyLittle
Sep 11, 2001





Clapping Larry

Bigass Moth posted:

Why did Cisco make some ASA models show an Amber link light on 1000Mbps links? Could they not afford a third led?

Why did Cisco violate IEEE gigabit spec for auto-negotiation?

... The world may never know....

ate shit on live tv
Feb 15, 2004

by Azathoth

Bigass Moth posted:

Why did Cisco make some ASA models show an Amber link light on 1000Mbps links? Could they not afford a third led?

I think it's because of the NIC's they used when they built the PIX and even the early ASAS's . They weren't Cisco ASIC's for a long time, and still might not be.

No idea about the ASA-X lines.

Computer Serf
May 14, 2005
Buglord

CrazyLittle posted:

Why did Cisco violate IEEE gigabit spec for auto-negotiation?

... The world may never know....

eh.. yeah I thought something was fishy after a vendor came to install some embedded system thing and mentioned it needed auto-negotiation... I ended up throwing a simple netgear switch inbetween the 2960 as a workaround. :ssh:

Slickdrac
Oct 5, 2007

Not allowed to have nice things

Powercrazy posted:

I think it's because of the NIC's they used when they built the PIX and even the early ASAS's . They weren't Cisco ASIC's for a long time, and still might not be.

No idea about the ASA-X lines.

Irrelevant anyway since they're already putting out the X line replacement later this year and using the purchased Sourcefire as the base.

Contingency
Jun 2, 2007

MURDERER

Slickdrac posted:

Irrelevant anyway since they're already putting out the X line replacement later this year and using the purchased Sourcefire as the base.

Is this like the 5515>5516 move, or something new?

Partycat
Oct 25, 2004

mythicknight posted:

Is it possible to integrate Cisco Jabber with AD, but not CUCM itself?

It authenticates via the UCM , which you can sync and use ldap auth for.

And in later versions of the UCM, 9+, you can sync or not so you can mix users.

I believe you can also have it autoprovision based on templates which would make it more or less transparent.

Partycat fucked around with this message at 01:18 on Mar 10, 2016

Slickdrac
Oct 5, 2007

Not allowed to have nice things

Contingency posted:

Is this like the 5515>5516 move, or something new?

Something new entirely, they apparently have the new devices on their website, but I'm not entire sure what's NDA of what I know and what's not, but it's more like PIX>ASA

http://www.cisco.com/c/en/us/products/security/firewalls/index.html

X series should still be covered for a while, but I guess it depends how hard they want to push the new hotness. It's clearly superior to existing ASA in several ways Yes, that's a low bar to clear, but still

Slickdrac fucked around with this message at 02:51 on Mar 10, 2016

Contingency
Jun 2, 2007

MURDERER

Slickdrac posted:

Something new entirely, they apparently have the new devices on their website, but I'm not entire sure what's NDA of what I know and what's not, but it's more like PIX>ASA

http://www.cisco.com/c/en/us/products/security/firewalls/index.html

X series should still be covered for a while, but I guess it depends how hard they want to push the new hotness. It's clearly superior to existing ASA in several ways Yes, that's a low bar to clear, but still

Thanks--I saw reference to a Firepower 9300 in the ASA release notes, but didn't pay it any mind. This would explain it. I have a 5520 I'm replacing this spring, but with the lowest end Firepower (4110) retailing at $64K, it may take a few years to displace ASAs at my company's pricepoint.

abigserve
Sep 13, 2009

this is a better avatar than what I had before

Heads up to everyone: I didn't hit this specific issues but I have found another issue where the HTTPS on the box will randomly stop working, i.e you can't get to either ASDM or any other functions of the web interface. VPN still works.

Edit: And the only fix is to reload the box. This is running 9.1(7).

Morganus_Starr
Jan 28, 2001
Anyone use local DNS servers on Cisco 2900 series routers? Just as DNS forwarders. I'm thinking of having my local clients use my routers as primary/secondary DNS instead of Google public DNS. I've had a few clients recently get hit with either malware, of malfunctioning software that ends up spamming the gently caress out of Google DNS and throttling us back (they use aTC-reject flag in the response and Windows client OSes do NOT seem to play nice with this).

Alternatively I've got some ASA 5550's on the edge - not sure if anyone has any advice/experience doing outbound throttling on DNS traffic, and any baseline/scaling info to implement this?

Computer Serf
May 14, 2005
Buglord
oops? https://currentlydown.com/cisco.com

Thanks Ants
May 21, 2004

#essereFerrari


Seems to be affecting the Meraki dashboard login as well

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
Could I ask a few of you to test something for me? We're building some virtual labs to test some guys networking knowledge and want to make sure that people outside of our dev group can actually use the site - obviously from my perspective it looks great but I'd like some outside thoughts.

Just go here: http://104.145.231.83/start_test/ and enter the"email" and "activation key" - I'm guessing a few people will try to test it out so I'll post a few email/keys to use.

There's a visio, some scenarios to complete, and the ip/port to telnet to in order to reach each device in the topology. You'll have 60 minutes to complete the scenarios if you want to try and beat the clock

Edit: Testing over thanks guys!

Sepist fucked around with this message at 21:23 on Mar 21, 2016

Thanks Ants
May 21, 2004

#essereFerrari


I can't even reach that IP. For what it's worth I'm coming from:

code:
% Information related to '86.148.0.0 - 86.159.255.255'

% Abuse contact for '86.148.0.0 - 86.159.255.255' is 'abuse@bt.com'

inetnum:        86.148.0.0 - 86.159.255.255
remarks:        *******************************************************************
remarks:        * Report abuse via: [url]http://bt.custhelp.com/app/contact/c/346,3024[/url] *
remarks:        *******************************************************************
netname:        BT-CENTRAL-PLUS
descr:          IP pools
country:        GB
admin-c:        BTCP1-RIPE
tech-c:         BTCP1-RIPE
status:         ASSIGNED PA
remarks:        Report abuse via: [url]http://bt.custhelp.com/app/contact/c/346,3024[/url]
mnt-by:         BTNET-MNT
mnt-lower:      BTNET-MNT
mnt-routes:     BTNET-MNT
created:        2006-11-01T01:49:30Z
last-modified:  2011-02-24T14:19:29Z
source:         RIPE

role:           BT CENTRAL PLUS - OPERATIONAL SUPPORT
remarks:        *******************************************************************
remarks:        * Report abuse via: [url]http://bt.custhelp.com/app/contact/c/346,3024[/url] *
remarks:        *******************************************************************
address:        BT
address:        Wholesale
address:        UK
abuse-mailbox:  [email]abuse@bt.com[/email]
admin-c:        PC487-RIPE
tech-c:         SR401-RIPE
nic-hdl:        BTCP1-RIPE
mnt-by:         BTNET-MNT
created:        2004-06-08T09:02:16Z
last-modified:  2011-02-21T13:40:11Z
source:         RIPE # Filtered

% Information related to '86.128.0.0/11AS2856'

route:          86.128.0.0/11
descr:          BT Public Internet Service
origin:         AS2856
mnt-by:         BTNET-INFRA-MNT
created:        2010-10-19T07:40:47Z
last-modified:  2014-07-31T08:07:04Z
source:         RIPE # Filtered

% This query was served by the RIPE Database Query Service version 1.86 (DB-2)

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
Should be good now

Edit: Ok now its good, lab server was also blocking.

Sepist fucked around with this message at 15:59 on Mar 21, 2016

Ahdinko
Oct 27, 2007

WHAT A LOVELY DAY

Sepist posted:

Could I ask a few of you to test something for me? We're building some virtual labs to test some guys networking knowledge and want to make sure that people outside of our dev group can actually use the site - obviously from my perspective it looks great but I'd like some outside thoughts.

Just go here: http://104.145.231.83/start_test/ and enter the"email" and "activation key" - I'm guessing a few people will try to test it out so I'll post a few email/keys to use.

There's a visio, some scenarios to complete, and the ip/port to telnet to in order to reach each device in the topology. You'll have 60 minutes to complete the scenarios if you want to try and beat the clock


I used goon1, I reset the router1 instance and think I ruined the lab as the config is really blank and e0/0 on each router does not connect together afaik. Also sticking some IP's on the diagram would be nice.
It worked though, I could telnet into the devices. Whats running this?

Ahdinko fucked around with this message at 17:24 on Mar 21, 2016

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
Hmm interesting, I'll have to check it out once your session expires since you're locked to the console.

For IP Addressing, it's intended that whoever configures it would set up their own schema, we're trying to keep it very hands off to see how far they get.

It's running IOU on a beefy backend device to handle quite a few sessions, using a mix of bash, python, php and mysql to handle individual sessions.

SamDabbers
May 26, 2003



I tried the goon4 credentials and it spun for a whole minute before saying "Lab Down, please contact administrator" :(

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k
Sorry I stole it for a moment, its free now

jwh
Jun 12, 2002

Wow, I've been gone for a long long time. Hi everybody.

Working for a firewall vendor now.

Moey
Oct 22, 2010

I LIKE TO MOVE IT

jwh posted:

Wow, I've been gone for a long long time. Hi everybody.

Working for a firewall vendor now.

How is your firewall better than the rest?

Ahdinko
Oct 27, 2007

WHAT A LOVELY DAY

Sepist posted:

Hmm interesting, I'll have to check it out once your session expires since you're locked to the console.

For IP Addressing, it's intended that whoever configures it would set up their own schema, we're trying to keep it very hands off to see how far they get.

It's running IOU on a beefy backend device to handle quite a few sessions, using a mix of bash, python, php and mysql to handle individual sessions.

I closed my teraterm sessions to hopefully its free now, i only had a 10 minute play with it though and didn't try to diagnose the e0/0 thing on the routers further as i had a meeting to run to. Its pretty cool though, I like it.

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k

Ahdinko posted:

I closed my teraterm sessions to hopefully its free now, i only had a 10 minute play with it though and didn't try to diagnose the e0/0 thing on the routers further as i had a meeting to run to. Its pretty cool though, I like it.

Thanks, I just fixed the reset issue. The script was launching from the wrong directory so it couldn't find it's NVRAM on boot.

jwh
Jun 12, 2002

Moey posted:

How is your firewall better than the rest?

It has a pleasing blue color.

Richard Noggin
Jun 6, 2005
Redneck By Default

jwh posted:

It has a pleasing blue color.

chestnut santabag
Jul 3, 2006

Sepist posted:

Could I ask a few of you to test something for me? We're building some virtual labs to test some guys networking knowledge and want to make sure that people outside of our dev group can actually use the site - obviously from my perspective it looks great but I'd like some outside thoughts.

Just go here: http://104.145.231.83/start_test/ and enter the"email" and "activation key" - I'm guessing a few people will try to test it out so I'll post a few email/keys to use.

There's a visio, some scenarios to complete, and the ip/port to telnet to in order to reach each device in the topology. You'll have 60 minutes to complete the scenarios if you want to try and beat the clock


Activation Key: 1458571274
Email: goon2

Activation Key: 1458571296
Email: goon3

"Hmm why won't an adjacency form on over VLAN 10? It's trunking correctly between the switches by default so whatever could the pr" Operational Trunking Encapsulation: isl
:doom:

And for whatever reason I couldn't get the routers to properly form an HSRP group - I suspect the hello packets weren't making it across the trunked link between the two switches.

chestnut santabag fucked around with this message at 19:48 on Mar 21, 2016

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k

chestnut santabag posted:

"Hmm why won't an adjacency form on over VLAN 10? It's trunking correctly between the switches by default so whatever could the pr" Operational Trunking Encapsulation: isl
:doom:

And for whatever reason I couldn't get the routers to properly form an HSRP group - I suspect the hello packets weren't making it across the trunked link between the two switches.

Weird, I don't know which lab is yours but I was able to get HSRP up and speaking between the two, so not sure what it was.

SamDabbers
May 26, 2003



I just worked the goon3 slot, and couldn't get an HSRP adjacency up either. Both show as active. Cool setup though!

Sepist
Dec 26, 2005

FUCK BITCHES, ROUTE PACKETS

Gravy Boat 2k

SamDabbers posted:

I just worked the goon3 slot, and couldn't get an HSRP adjacency up either. Both show as active. Cool setup though!

Thanks, looks like IGMP snooping needs to be disabled on the switches otherwise it doesn't forward the multicast packets for HSRP, weird IOU bug.

ate shit on live tv
Feb 15, 2004

by Azathoth

jwh posted:

It has a pleasing blue color.

Congrats!

madsushi
Apr 19, 2009

Baller.
#essereFerrari

That's giving jwh's employer's web UI too much credit.

Congrats jwh!

BaseballPCHiker
Jan 16, 2006

Anyone here have much experience with the new SourceFire web interface? When I login now and go to the summary dashboards I just see every metric as "loading..." and nothing ever displays.

Thanks Ants
May 21, 2004

#essereFerrari


Is there anything inherently wrong with Brocade FCX-S switches that a 48 port PoE model isn't worth £300? Vendor is having a bit of a fire sale.

MrMoo
Sep 14, 2000

Software licenses? Usually that's fibre switches though.

Jedi425
Dec 6, 2002

THOU ART THEE ART THOU STICK YOUR HAND IN THE TV DO IT DO IT DO IT

I know in my limited experience with them the Brocade switches are generally solid products.

Now, if the guy offers you an ADX, you make him pay you.

Adbot
ADBOT LOVES YOU

Wicaeed
Feb 8, 2005
What's everyones recommendation for a free (or otherwise inexpensive) Netflow collector?

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply