網頁

顯示具有 Cisco 標籤的文章。 顯示所有文章
顯示具有 Cisco 標籤的文章。 顯示所有文章

2015年3月8日 星期日

TCP/IP Packet Size

Ethernet II frame , IEEE802.3 frame

icmp packet size

udp packet size


tcp packet size





2013年2月21日 星期四

2013.2.21 EtherChannel

LACP IEEE 802.3ad
PAgP Cisco property

PAgP
     主動式 desirable
     被動式 auto

LACP
     主動式 active
     被動式 passive

而on用法不是很確定, Cisco官方網站是這樣解釋:
Forces the interface into an EtherChannel without PAgP or LACP. With the on mode, a usable EtherChannel exists only when an interface group in the on mode is connected to another interface group in the on mode.
看起來是兩方都是on時就能建立起來, 但是用何種protocol ? 不詳!

由於每一connection的packet(其實應該用frame的字眼才對)並非平均分散在EtherChannel線路上, 因此要懂得依架構去設定:by source mac, by destination mac, by source/destination mac, by source ip, by destination ip, by source/destination ip, by source port, by destination port, by source/destination port
例如:
1.許多的host往同一Server連線, 此時host端 switch因使用by source mac or by source ip, 而server端 switch因使用by destination mac or by destination ip
2.Server與NAS連線, NAS需有多個MAC or 多個IP,然後再來調整設定(如仿照上式)

show etherchannel summary
show etherchannel 1 port-channel
show int port-channel 1
show int (從這裡看不動實體介面歸屬於哪一個etherchannel, 必須靠description彌補)

當堆疊的cisco switch, 自己要跨switch去與對方switch建etherchannel時, 只能用LACP

2015.3
       F5 trunk與Cisco LACP (不管是35xx, 4500x (VSS), Nexus)都可以建立起來.

2012年7月14日 星期六

2012.7.14 學了一套IOS模擬器

這天下午(其實約略只有半個小時),學了一套IOS模擬器, 模擬器的名稱先保密!
這套效率比以往的模擬器都來得更好!
電腦負擔也輕.
往後要建環境模擬時,可以事半功倍了!

2012年6月8日 星期五

Cisco IOS exec-timeout vs. session-timeout


exec-timeout vs. session-timeout

此文章出處來自於
http://ieoc.com/forums/p/2592/8562.aspx

imagine the following topology

PC---R2---R3

Let's say you open telnet connection from PC to R2 and log into exec shell (usually this is the default). If you leave your shell inactive for the period of "exec-timeout" configured on R2 VTYs, then R2 will close you exec session and terminate telnet connection.

Now imagine you telnet from PC to R2 and then to R3. At this moment, if you leave your shell idle on R3, one of the following will happen. Either "exec-timeout" configured on R3 expires, and R3 teminates your shell OR "session-timeout" configured on R2 VTY lines expires and R2 closes your outgoing connection. This depends on which timeout has smaller  value.

Keep in mind, "session-timeout" is for sessions originated out from this VTY, while "exec-timeout" is for EXEC sessions started when someone logs into this VTY.

2011年11月28日 星期一

2011.11.28 To delete all RSA keys from your router

To delete all RSA keys from your router, use the crypto key zeroize rsa command in global configuration mode.
crypto key zeroize rsa [key-pair-label]
Ex:crypto key zeroize rsa  TP-self-signed-3216526592

2011年8月5日 星期五

2011.8.5 某客戶內部網路不穩

某一A客戶, 接連三個禮拜, 內部網路, 不定時的都會忽然來一下約一分鐘的不穩.
這一分鐘內服務都停擺......

2011年7月29日 星期五

2011.7.29 Cisco 3750 output drop

陸續有兩三個案子, 發生3750 uplink (使用802.1q & speed 100)介面有大量output drop情況發生.
在此介面上當傳輸量在30Mb以上後, 就會發生7位數的output drop.

2011年6月24日 星期五

2011.6.24 Transit Access Control Lists: Filtering at Your Edge

Transit Access Control Lists: Filtering at Your Edge
關於Invalid Traffic這裡有講到
RFC1918
RFC3330
RFC2827--Apply anti-spoof filters, in accordance with RFC 2827; your address space should never be the source of packets from outside your autonomous system (AS).

2011年6月21日 星期二

2011.6.21 pre-shared key如果忘掉了怎麼辦?

在IOS設備上,所設定的pre-shared key如果沒記錄下來,也忘記了, 那怎麼辦?
去看設備上的設定, 一定是顯示星號(如下所示)所以會查不出來.

2011年6月15日 星期三

2011.6.15 IPSec VPN Client for Android

由於iPhone, Android盛行, 企業VPN需求味口也跟著膨脹, 所以呢, 今年接連著測試了:
1.IPSec VPN Client for iPhone on Cisco ASA
2.SSL VPN for iPhone on F5 Firepass (同一個月內兩次)
再來登場的是:
IPSec VPN Client for native Android on Cisco ASA, 也就是最近在處理的case之一.

ASA說要到8.4.1, 偏偏呢ASA的NAT功能到了8.3後,有重大變革, 於是讓事情更複雜
上禮拜某一天已測到Android可以連到內部伺服器, 但是呢split tunnel沒發揮作用
今天下午重新來過, VPN設定還沒開始就卡在NAT設定上.....

2010年11月22日 星期一

2010.11.22 Cisco 6500 boot system 策略

Operational Best Practices for the Cisco Catalyst 6500 Series

2.6 Backup Cisco IOS Software and Configuration
Normal operation of the switch requires an image to boot the system. Bootable images are typically stored on the supervisor bootflash located on the supervisor module. The switch can load an OS image from local flash memory (for example, compact flash), or from a device reachable through the network such as a TFTP/FTP server. It is a good practice to have a backup copy of the current OS image located either on the supervisor flash or on a separate compact flash. Both Cisco Catalyst 6500 Series Supervisor Engine 720 and Cisco Catalyst 6500 Supervisor Engine 32 support a compact flash slot on the front panel. Should the image on bootflash be deleted accidentally or become inaccessible, locating a backup image on the flash card will save time in getting the switch back up and running.

2010年11月9日 星期二

2010.11.9 kron

kron occurrence ClearTcpTcbSchedule at 4:00 recurring
policy-list ClearTcp
!
kron policy-list ClearTcp
cli terminal monitor
cli debug kron all
cli clear tcp tcb *
cli u all
!

2010年10月26日 星期二

2010.10.26 ASA/PIX/FWSM: Handling ICMP Pings and Traceroute

ASA/PIX/FWSM: Handling ICMP Pings and Traceroute


Introduction

Internet Control Message Protocol (ICMP) pings and traceroute on the PIX Firewall are handled differently based on the version of PIX and ASA code.

Inbound ICMP through the PIX/ASA is denied by default. Outbound ICMP is permitted, but the incoming reply is denied by default.

Note: ASA/PIX supports ICMP redirects from version 8.2(1) and later. ICMP redirects is not supported in ASA versions prior to 8.2(1) because these versions do not support asymmetric routing.

Note: The information in the Make the Firewall Show Up in a Traceroute in ASA/PIX section of this document applies to ASA versions 8.0(3) and later. Versions prior to 8.0(3) do not support the configuration explained in this section due to the bug CSCsk76401 (registered customers only) .

2010年10月23日 星期六

2010.10.23 Supported VPN Platforms, Cisco ASA 5500 Series

Supported VPN Platforms, Cisco ASA 5500 Series

ASA各版本所支援的ASDM, CSD, AnyConnect各版本列表
Clientless所支援的OS及Browser列表
AnyConnect版本與各OS相容性列表

追蹤者