<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Cisco forum - dslreports.com community</title>
<link>http://www.dslreports.com/forum/equip,cis</link>
<description>Cisco forum current topics</description>
<language>en</language>
<copyright>Copyright 2007, dslreports.com</copyright>
<pubDate>Wed, 19 Jun 2013 18:18:56 EDT</pubDate>
<lastBuildDate>Wed, 19 Jun 2013 18:18:56 EDT</lastBuildDate>

<image>
<title>dslreports.com</title>
<url>http://i.dslr.net/bbrdisc1.gif</url>
<link>http://www.dslreports.com</link>
<width>19</width>
<height>18</height>
<description>bbr disc</description>
</image>

<item>
<title>Cisco Live 2013 Orlando</title>
<link>http://www.dslreports.com/forum/remark,28327873</link>
<description><![CDATA[Anyone else going to Orlando the end of June? I'll be there attending a number of the management and architect track sessions.
--
Scott, CCIE #14618 Routing & Switching
http://rolande.wordpress.com/]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28327873</guid>
<pubDate>2013-05-28 00:51:26</pubDate>
</item>

<item>
<title>Ether Channel Help</title>
<link>http://www.dslreports.com/forum/remark,28390992</link>
<description><![CDATA[Working with 2 3750 cross stack switches. Trying to setup an etherchannel. 
COnfig is below and error is at the end. Second port fails to join
Anyone have some advice? New to networking.

Port-channel48 is up, line protocol is up (connected)
  Hardware is EtherChannel, address is 0015.63ec.0304 (bia 0015.63ec.0304)
  MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Full-duplex, 1000Mb/s, link type is auto, media type is unknown
  input flow-control is off, output flow-control is unsupported
  Members in this channel: Gi1/0/4
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input never, output 00:00:00, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 484000 bits/sec, 449 packets/sec
  5 minute output rate 81000 bits/sec, 1648 packets/sec
     6359048 packets input, 855556348 bytes, 0 no buffer
     Received 1622946 broadcasts (0 multicast)
     0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 watchdog, 1588978 multicast, 0 pause input
     0 input packets with dribble condition detected
     21921076 packets output, 4163953334 bytes, 0 underruns
     0 output errors, 0 collisions, 1 interface resets
     0 babbles, 0 late collision, 0 deferred
     0 lost carrier, 0 no carrier, 0 PAUSE output
     0 output buffer failures, 0 output buffers swapped out

interface GigabitEthernet1/0/4
 description DB2 NIC1
 switchport trunk encapsulation dot1q
 switchport mode trunk
 duplex full
 speed 1000
 channel-group 48 mode active

interface GigabitEthernet2/0/1
 description db2 nic2
 switchport trunk encapsulation dot1q
 switchport mode trunk
 duplex full
 speed 1000

3750(config-if)#channel-group 48 mode active
%With LACP enabled, all ports in the Channel should belong to the same switch
Command rejected (Port-channel48, Gi2/0/1): Invalid etherchnl mode]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28390992</guid>
<pubDate>2013-06-18 11:16:14</pubDate>
</item>

<item>
<title>New Cisco rv220w - Can&#x27;t access web interface</title>
<link>http://www.dslreports.com/forum/remark,28388849</link>
<description><![CDATA[Brand New Cisco rv220w

Its generating a SSL issue trying to access the cisco rv220w interface. Tried two different pcs and 3 different browsers. 

Called and talked to cisco support they couldn't figure it out but since I have to wait until tomorrow to do anything else about it, thought I ask if anyone here has seen that issue?

Chrome Error: Error 113 (net::ERR_SSL_VERSION_OR_CIPHER_MISMATCH): unknown error

Firefox: Error Code: ssl_error_no_cypher_overlap

IE 10: Cannot Connect to Website

Out of the box it will connect to Comcast and wireless works  albeit unsecure. Only way to access the router config is via https web interface at 192.168.1.1.  Tried two different PC's and 3 different browsers with various switches set SSL 2 3 on/off TLS 1 1.1 1.2 on off etc.

I am now assuming the certificate is corrupt in the router but still wanted to run it up the flag pole here.
--
Yes, I Will Fix Your #@$!! Computer
http://www.memphispcguy.com]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28388849</guid>
<pubDate>2013-06-17 17:42:53</pubDate>
</item>

<item>
<title>SSID not visible on Mac, but is on phone</title>
<link>http://www.dslreports.com/forum/remark,28382776</link>
<description><![CDATA[Hi all. For once I am asking for help. :D

I have a 1242AG AP that has worked brilliantly in the past, but Im noticing some odd behaviour with it right now.

A little background: I moved in to a share house, and wi-fi is crazy around here. 2.4GHz is congested like crazy, but 5GHz is scantly used. Not to mention the house is huge and only has a single AP, so theres probably some hidden node stuff going on here...

So I set up my own AP and created two SSIDs, and broadcast one on 2.4GHz and the other on 5GHz giving me the ability to hook my Mac up on a frequency that isn't drowned.

The 5GHz one is giving me a little trouble. It seems to come and go - but only on my Mac. On my Android phone it is always visible. Right now, my Mac is connected to 2.4GHz and my phone to 5GHz. There was a time when the 5GHz SSID used to show up on my Mac, but for some reason it has disappeared now.

In the past I had always broadcast the same SSID on both 2.4 and 5GHz, so maybe I just didnt notice this before...

Can anyone take a look at my config and tell me if Im missing something obvious that might cause trouble?

Thanks. :-)

!&#012;version 12.4&#012;no service pad&#012;service timestamps debug datetime msec&#012;service timestamps log datetime msec&#012;service password-encryption&#012;!&#012;hostname eal-ap1&#012;!&#012;logging buffered 65535 debugging&#012;logging console informational&#012;enable secret 5 .....&#012;!&#012;no aaa new-model&#012;ip name-server 8.8.8.8&#012;ip name-server 8.8.4.4&#012;!&#012;!&#012;dot11 vlan-name snnap-fast vlan 21&#012;dot11 vlan-name snnap-lan vlan 11&#012;!&#012;dot11 ssid snnap-fast&#012;   vlan snnap-fast&#012;   authentication open &#012;   authentication key-management wpa&#012;   mbssid guest-mode&#012;   wpa-psk ascii 7 .....&#012;!&#012;dot11 ssid snnap-lan&#012;   vlan snnap-lan&#012;   authentication open &#012;   authentication key-management wpa&#012;   mbssid guest-mode&#012;   wpa-psk ascii 7 .....&#012;!&#012;power inline negotiation prestandard source&#012;!&#012;!&#012;!&#012;bridge irb&#012;!&#012;!&#012;interface Dot11Radio0&#012; description ** 802.11b/g Radio&#012; no ip address&#012; no ip route-cache&#012; load-interval 30&#012; !&#012; encryption vlan snnap-lan mode ciphers aes-ccm &#012; !&#012; ssid snnap-lan&#012; !&#012; mbssid&#012; channel 2412&#012; station-role root&#012; world-mode dot11d country GB indoor&#012; bridge-group 1&#012; bridge-group 1 block-unknown-source&#012; no bridge-group 1 source-learning&#012; no bridge-group 1 unicast-flooding&#012;!&#012;interface Dot11Radio0.11&#012; encapsulation dot1Q 11&#012; no ip route-cache&#012; bridge-group 11&#012; bridge-group 11 subscriber-loop-control&#012; bridge-group 11 block-unknown-source&#012; no bridge-group 11 source-learning&#012; no bridge-group 11 unicast-flooding&#012; bridge-group 11 spanning-disabled&#012;!&#012;interface Dot11Radio1&#012; description ** 802.11a Radio&#012; no ip address&#012; no ip route-cache&#012; load-interval 30&#012; !&#012; encryption vlan snnap-fast mode ciphers aes-ccm &#012; !&#012; ssid snnap-fast&#012; !&#012; no dfs band block&#012; mbssid&#012; channel dfs&#012; station-role root&#012; world-mode dot11d country GB indoor&#012; bridge-group 1&#012; bridge-group 1 block-unknown-source&#012; no bridge-group 1 source-learning&#012; no bridge-group 1 unicast-flooding&#012;!&#012;interface Dot11Radio1.21&#012; encapsulation dot1Q 21&#012; no ip route-cache&#012; bridge-group 11&#012; bridge-group 11 subscriber-loop-control&#012; bridge-group 11 block-unknown-source&#012; no bridge-group 11 source-learning&#012; no bridge-group 11 unicast-flooding&#012; bridge-group 11 spanning-disabled&#012;!&#012;interface FastEthernet0&#012; no ip address&#012; no ip route-cache&#012; load-interval 30&#012; duplex auto&#012; speed auto&#012; bridge-group 1&#012; no bridge-group 1 source-learning&#012; bridge-group 1 spanning-disabled&#012; hold-queue 160 in&#012;!&#012;interface FastEthernet0.11&#012; encapsulation dot1Q 11&#012; no ip route-cache&#012; bridge-group 11&#012; no bridge-group 11 source-learning&#012;!&#012;interface FastEthernet0.13&#012; encapsulation dot1Q 13&#012; no ip route-cache&#012; bridge-group 1&#012; no bridge-group 1 source-learning&#012; bridge-group 1 spanning-disabled&#012;!&#012;interface BVI1&#012; description ** Management Interface&#012; ip address 172.25.255.18 255.255.255.240&#012; no ip route-cache&#012;!&#012;ip default-gateway 172.25.255.17&#012;no ip http server&#012;no ip http secure-server&#012;ip http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag&#012;bridge 1 protocol ieee&#012;bridge 1 route ip&#012;!&#012;!&#012;!&#012;line con 0&#012; logging synchronous&#012;line vty 0 4&#012; exec-timeout 0 0&#012; password 7 .....&#012; logging synchronous&#012; login&#012;line vty 5 15&#012; exec-timeout 0 0&#012; password 7 .....&#012; logging synchronous&#012; login&#012;!&#012;sntp server 80.5.182.144&#012;sntp server 62.253.170.208&#012;end&#012;]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28382776</guid>
<pubDate>2013-06-15 04:43:08</pubDate>
</item>

<item>
<title>switch question question</title>
<link>http://www.dslreports.com/forum/remark,28390343</link>
<description><![CDATA[I'm hoping someone can help me out withquestion.

I have 1 distro switch 3560 and two 2960s  . Right now i have two trunking ether-channels groups going to the L3 switch.Should I create a loop by connecting the two L2 switches to each other enabling spanning tree, or should i leave what I have now? ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28390343</guid>
<pubDate>2013-06-18 06:57:59</pubDate>
</item>

<item>
<title>Router/Switch Recommendations</title>
<link>http://www.dslreports.com/forum/remark,28384691</link>
<description><![CDATA[We're just finishing up the construction of a new building and will me moving our operations over there in a few weeks.  At the last minute, we've been trying to figure the networking out.  We currently use a Cisco UC520, but haven't been too happy with it.  We're having tons of registration issues with Voip.ms and have had the unit fail twice requiring replacement.  I'm wondering if its worth moving to a new router and switch.

What we run (or will run shortly):
- 3 point of sale terminals
- 4-5 workstations
- POS server
- IP Camera NVR (possibly 15-20 IP cameras - some 2mp, some 5mp)
- Access control system
- Voip Phones (at least 9)

One thought was to switch VoIP over to a Switchvox server.  The other thought was to upgrade to a new router and switch.

If sticking with Cisco, I was thinking a 2921-VSEC-SRE would be my best bet for a router, and maybe a WS-C3750X-48PF-L switch.  I've found a few deals on eBay for a new (open box) 29xx series routers for a little over $2000 that would seem to suit our needs.

Your thoughts would be appreciated.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28384691</guid>
<pubDate>2013-06-16 01:21:29</pubDate>
</item>

<item>
<title>Configure Cisco 1811W to receive WI-FI</title>
<link>http://www.dslreports.com/forum/remark,28385863</link>
<description><![CDATA[Hello All,

I've just moved in an apartment where the landlord has wifi to all the tenants. I have a Cisco wireless router 1811W and want to configure it to receive wifi and act as an internet gateway for all my wired devices connected to its switch ports. How can I do it? If someone can give hints or a detail configuration I will appreciate that a lot.

Thanks in advance.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28385863</guid>
<pubDate>2013-06-16 16:57:41</pubDate>
</item>

<item>
<title>Licensing question</title>
<link>http://www.dslreports.com/forum/remark,28364110</link>
<description><![CDATA[Good afternoon.  I have a question for you good Cisco experts here.  Recently we found some Cisco ASA 5505's in a closet at work that we didn't know we had and have no use for, so they were "loaned" out to several of us to play with.  The first thing I did, after resetting the password and loading the default config, was to ascertain the software version (which is 7.2.4), and it appears to be about 5 years out of date.  

So my question is, can I purchase SmartNet from our Partner  for it to get the latest software and ASDM, even though I don't have any idea where this originally came from or if it ever had another SmartNet contract on it (I'm sure it doesn't have a valid one in force now)?  I would think the answer is yes but I know Cisco licensing can be an adventure.  
--
Ron Paul 2012 http://www.ronpaul2012.com
Beyond AM. Beyond FM. (((XM)))
]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28364110</guid>
<pubDate>2013-06-09 13:16:10</pubDate>
</item>

<item>
<title>Cisco ASA 5520 Error Code: -5</title>
<link>http://www.dslreports.com/forum/remark,28381201</link>
<description><![CDATA[Hello,

Today I rebooted my ASA 5520 and this is what I got

..************************************************************&#012;FATAL DEVICE ERROR DETECTED.  ERROR CODE: -5&#012; &#012;Please copy the following exactly as it appears,&#012;along with any visible version strings, and contact&#012;your support representative.&#012; &#012;Cisco Adaptive Security Appliance Software Version 8.4(2) &#012; &#012;Compiled on Wed 15-Jun-11 18:17 by builders&#012;Serial Number: JMX1248L1UA&#012;Running Permanent Activation Key: 0x8f31fc45 0xbc28ab92 0x9882c924 0x83f8c054 0x8a2814b3 &#012; &#012;************************************************************&#012;
Any idea? 
]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28381201</guid>
<pubDate>2013-06-14 15:02:43</pubDate>
</item>

<item>
<title>Forcing all traffic via VPN for remote clients</title>
<link>http://www.dslreports.com/forum/remark,28170058</link>
<description><![CDATA[So this is what I'm curious about doing....

I'd like to setup my 1841 so that whenever I make a VPN connection to it using Cisco VPN client, all my traffic is sent to the 1841 and then out to the Internet.

Right now I'm only able to get the "interesting" traffic through the tunnel, but when trying to access the Internet, it times out.

I tried having the ACL for the VPN pool point to the virtual interface 10.16.12.0/24 for all outbound traffic, and adding 10.16.12.0/24 to the NAT ACL but that doesn't seem to work. It doesn't even try to hit the interface, it simply keeps hitting the 10.17.12.0/24.

Is this possible?

TIA

Building configuration...&#012; &#012;Current configuration : 3396 bytes&#012;!&#012;version 12.4&#012;service timestamps debug datetime msec&#012;service timestamps log datetime msec&#012;service password-encryption&#012;!&#012;hostname router&#012;!&#012;boot-start-marker&#012;boot-end-marker&#012;!&#012;enable secret 5 xxx&#012;!&#012;aaa new-model&#012;!&#012;!&#012;aaa authentication login homenet_user_auth local&#012;aaa authorization network homenet_group_auth local&#012;!&#012;aaa session-id common&#012;ip cef&#012;!&#012;!&#012;!&#012;!&#012;ip domain name homenet.local&#012;!&#012;!&#012;!&#012;username xxx password 7 xxx&#012;!&#012;!&#012;!&#012;crypto isakmp policy 3&#012; encr 3des&#012; authentication pre-share&#012; group 2&#012;!&#012;crypto isakmp client configuration group vpnaccess&#012; key xxx&#012; dns 10.17.12.2&#012; domain homenet.local&#012; pool vpnpool&#012; acl 110&#012;!&#012;!&#012;crypto ipsec transform-set tset1 esp-3des esp-md5-hmac&#012;!&#012;crypto dynamic-map dynmap 10&#012; set transform-set tset1&#012; reverse-route&#012;!&#012;!&#012;crypto map vpnrasin client authentication list homenet_user_auth&#012;crypto map vpnrasin isakmp authorization list homenet_group_auth&#012;crypto map vpnrasin client configuration address respond&#012;crypto map vpnrasin 10 ipsec-isakmp dynamic dynmap&#012;!&#012;!&#012;!&#012;interface FastEthernet0/0&#012; no ip address&#012; ip virtual-reassembly&#012; duplex auto&#012; speed auto&#012;!&#012;interface FastEthernet0/0.1&#012; encapsulation dot1Q 1 native&#012; ip address 10.17.12.3 255.255.255.0&#012; ip nat inside&#012; ip virtual-reassembly&#012;!&#012;interface FastEthernet0/0.2&#012; encapsulation dot1Q 2&#012; ip address 10.16.12.3 255.255.255.0&#012; ip nat inside&#012; ip virtual-reassembly&#012;!&#012;interface FastEthernet0/1&#012; ip address dhcp&#012; ip nat outside&#012; ip virtual-reassembly&#012; duplex auto&#012; speed auto&#012; crypto map vpnrasin&#012;!&#012;interface Serial0/0/0&#012; no ip address&#012; shutdown&#012;!&#012;ip local pool vpnpool 10.18.12.25 10.18.12.30&#012;!&#012;!&#012;no ip http server&#012;no ip http secure-server&#012;ip nat inside source list 100 interface FastEthernet0/1 overload&#012;ip nat inside source static tcp 10.17.12.2 993 interface FastEthernet0/1 993&#012;ip nat inside source static tcp 10.17.12.2 60002 interface FastEthernet0/1 60002&#012;ip nat inside source static tcp 10.17.12.2 60001 interface FastEthernet0/1 60001&#012;ip nat inside source static tcp 10.17.12.2 60000 interface FastEthernet0/1 60000&#012;ip nat inside source static tcp 10.17.12.2 990 interface FastEthernet0/1 990&#012;ip nat inside source static tcp 10.17.12.2 443 interface FastEthernet0/1 443&#012;ip nat inside source static tcp 10.17.12.82 8062 interface FastEthernet0/1 8062&#012;ip nat inside source static tcp 10.17.12.2 80 interface FastEthernet0/1 80&#012;ip nat inside source static tcp 10.17.12.2 21 interface FastEthernet0/1 21&#012;ip nat inside source static tcp 10.17.12.2 20 interface FastEthernet0/1 20&#012;ip nat inside source static tcp 10.17.12.2 25 interface FastEthernet0/1 25&#012;ip nat inside source static tcp 10.17.12.3 22 interface FastEthernet0/1 22&#012;!&#012;access-list 100 permit ip 10.16.12.0 0.0.0.255 10.18.12.24 0.0.0.7&#012;access-list 100 deny   ip 10.17.12.0 0.0.0.255 10.18.12.24 0.0.0.7&#012;access-list 100 permit ip 10.17.12.0 0.0.0.255 any&#012;access-list 101 permit tcp host 143.104.xxx.xxx any eq 22&#012;access-list 101 permit tcp 10.17.12.0 0.0.0.255 any eq 22&#012;access-list 101 deny   ip any any&#012;access-list 110 permit ip 10.18.12.24 0.0.0.7 10.16.12.0 0.0.0.255&#012;access-list 110 permit ip any 10.18.12.24 0.0.0.7&#012;!&#012;!&#012;!&#012;!&#012;control-plane&#012;!&#012;!&#012;!&#012;line con 0&#012;line aux 0&#012;line vty 0 4&#012; access-class 101 in&#012; password 7 xxx&#012; transport input ssh&#012;line vty 5 15&#012; access-class 101 in&#012; password 7 xxx&#012; transport input ssh&#012;!&#012;scheduler allocate 20000 1000&#012;end&#012; &#012;router#&#012;]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28170058</guid>
<pubDate>2013-04-04 22:21:12</pubDate>
</item>

<item>
<title>A Work Smarter way to map MAC&#x3E;IP&#x3E;hostname on Catalyst/Nexus</title>
<link>http://www.dslreports.com/forum/remark,28336593</link>
<description><![CDATA[The Background : Catalyst / Nexus platform needs a SUP or linecard or hardware replacement, fact of life.
So how to figure out which endhosts (especially critical servers) will be affected?

The Need : a way to work smarter, not harder, everytime we have to schedule a SUP / Linecard replacement
that doesn't involve a manual inventory of a Catalyst / Nexus' CAM table (sh mac-add dynamic), then manually 
mapping that to an IP address (sh arp | i [mac address]), then manually mapping that to the server / endhost 
name (via nslookup).

The Issue : where I work, the various support teams are siloed off from one another -- ie. network team, 
server team, app team, cabling team, etc. etc. etc.  so no one group has a birds eye view of what servers 
may be connected to which switchports, which may be connected to said Catalyst / Nexus we have to do the 
SUP / linecard replacement.  So whenever we (the network team) need to do such a replacement, we're 
usually called to inventory the connected servers via the above method.  Just imagine that if you have to do 
that for a 6509 with 7(!) fully populated 48x linecards -- I just had to do that today.  What makes it worse is 
if you toss in virtualization, so you're staring at a whole bunch of 0050.56xx.xxxx MAC addresses and 
wanting to just kill yourself.

Personally I think the smarter way would be the server teams / admins keeping their own documentation
up to date so we could just tell them "subnet w.x.y.z will be affected by this, make a note that your boxes
will be down x hours while we work," but then of course, documentation's always the first housekeeping
item not to be done by anyone.

Just want to know if anyone has another "work smarter" way to do this, or know of any tool(sets) what would help
automate what we're currently doing above manually -- TCL, *nix / windows scripting, etc.  Pretty sure I'm not the only 
person to have done this before in their professional career.

Any ideas or pointers?

Regards]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28336593</guid>
<pubDate>2013-05-30 21:47:29</pubDate>
</item>

<item>
<title>HSRP question</title>
<link>http://www.dslreports.com/forum/remark,28355157</link>
<description><![CDATA[is one of the HSRP or VSRP (or such) able to do load balancing or are they only able to do failover?

also can it be done on a NME-16ES-1G-P running the EMI IOS?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28355157</guid>
<pubDate>2013-06-06 11:11:15</pubDate>
</item>

<item>
<title>Pfsense &#x26;amp; Cisco Router</title>
<link>http://www.dslreports.com/forum/remark,28365323</link>
<description><![CDATA[Before I begin, this is my suggested setup:

Cable Modem  Pfsense Machine  Cisco 881W  Internal Network

I'm trying to find out if I used PFsense device as a Firewall/IPS, would that work? Having the router do all the NAT'ing, etc.?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28365323</guid>
<pubDate>2013-06-09 22:57:13</pubDate>
</item>

<item>
<title>[H/W] Catalyst WS-C3550-48-SMI  Will it do EMI?</title>
<link>http://www.dslreports.com/forum/remark,28354286</link>
<description><![CDATA[I have a WS-C3550-48-SMI with IOS ver 12.2(25)SEB4 installed. 
The application I want to use it in calls for an EMI switch. While what I read on the Cisco site seems to indicate that upgrading the IOS will allow EMI. I'm not really sure what it said. 

I've downloaded the Release 12.2.44-SE6  ED IPServices version of IOS, (IP SERVICES W/O CRYPTO WITH WEB BASED DEV MGR 
c3550-ipservices-tar.122-44.SE6.tar to be specific) which seems like it would give EMI operation. 

Is that really the case? There is also mention of ordering upgrade, but that seems to be just the IOS.

I have not tried to install anything yet, since when it comes to this stuff I'm somewhat confused.

The application is for  AOIP which uses a large amount of multicast packets, and is quite chatty.. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28354286</guid>
<pubDate>2013-06-06 01:36:12</pubDate>
</item>

<item>
<title>cctv multicast</title>
<link>http://www.dslreports.com/forum/remark,28370159</link>
<description><![CDATA[Hi All, 

We need to implment new CCTVs over a network. Im trying to choose the right core switch for that network. This is my first time working with multicast. How would I judge which switch to use? Say I have 100 or 200 or 300 CCTV, do I look at switch throughput just as I would when I look at users throughput to the core? Or is there a different criteria. I know I need IGMP. Is 4500 overkill or would i need 6500 ect.. ?

THanks]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28370159</guid>
<pubDate>2013-06-11 11:17:22</pubDate>
</item>

<item>
<title>[HELP] Re: Cisco 837 Help</title>
<link>http://www.dslreports.com/forum/remark,28373203</link>
<description><![CDATA[Hello Everyone

I am trying to configure my Cisco 837 Router on ADSL
Actually from the hyperterminal i can ping www.yahoo.com and other hosts ( from my pc connected to LAN1 also )

But i cannot open any web site due to unresolved dns :(

My config is below can you help

Rgds

Bryan

Current configuration : 2103 bytes
!
version 12.3
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime localtime
service timestamps log datetime localtime
service password-encryption
!
hostname xxxxxxxxxxxxx
!
logging buffered 12288 debugging
logging console critical
enable secret xxxxxxxxxxxxxxxx
!
no aaa new-model
ip subnet-zero
no ip source-route
no ip gratuitous-arps
ip name-server 8.8.8.8
ip name-server 8.8.4.4
ip dhcp excluded-address 192.168.1.254
!
ip dhcp pool LAN
   network 192.168.1.0 255.255.255.0
   default-router 192.168.168.254
   domain-name Local
   dns-server 8.8.8.8 8.8.4.4
   lease 0 12
!
!
no ip bootp server
ip cef
ip audit notify log
ip audit po max-events 100
no ftp-server write-enable
!
!
!
!
!
!
!
interface Ethernet0
 description INSIDE:192.168.1.254-255.255.255.0
 ip address 192.168.1.254 255.255.255.0
 ip nat inside
 no ip mroute-cache
 no cdp enable
 hold-queue 100 out
!
interface ATM0
 no ip address
 no ip mroute-cache
 no atm ilmi-keepalive
 pvc 8/35
  encapsulation aal5mux ppp dialer
  dialer pool-member 1
 !
 dsl operating-mode auto
!
interface FastEthernet1
 description LAN Port 1
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet2
 description LAN Port 2
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet3
 description LAN Port 3
 no ip address
 duplex auto
 speed auto
!
interface FastEthernet4
 description LAN Port 4
 no ip address
 shutdown
 duplex auto
 speed auto
!
interface Dialer1
 ip address negotiated
 no ip redirects
 no ip unreachables
 no ip proxy-arp
 ip mtu 1492
 ip nat outside
 encapsulation ppp
 dialer pool 1
 no cdp enable
 ppp authentication chap callin
 ppp chap hostname xxxxxx3@xxxxxx
 ppp chap password xxxxxxxxxx
!
ip classless
ip route 0.0.0.0 0.0.0.0 Dialer1
no ip http server
no ip http secure-server
!
access-list 121 permit ip 192.168.1.0 0.0.0.255 any
no cdp run
!
line con 0
 exec-timeout 120 0
 no modem enable
 stopbits 1
line aux 0
line vty 0 4
 access-class 23 in
 exec-timeout 120 0
 login local
 length 0
!
scheduler max-task-time 5000
!
end]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28373203</guid>
<pubDate>2013-06-12 08:08:32</pubDate>
</item>

<item>
<title>[Config] Cisco Switch to Switch Fiber Connectivity Issue</title>
<link>http://www.dslreports.com/forum/remark,28331124</link>
<description><![CDATA[I am facing an issue while connecting two Cisco LAN Switches Via Fiber module.
These Two were already connected by a provider (my Location A-> provider--> My Location B) via FE port, and working ok.

I did a Fiber link between Two end, link got up, but if i unplugged or shut the FE port which is via Provider to check my own Fiber connectivity, both swith don't ping each other, no data

Confs are as under

End-A
-----------------
interface GigabitEthernet0/1
 switchport trunk encapsulation dot1q
 switchport mode trunk
 speed nonegotiate
!

End-B
----------------
interface GigabitEthernet0/2
 switchport trunk encapsulation dot1q
 switchport mode trunk
 speed nonegotiate
!
Both Switches are Cisco 3550.

Any possible help please....

Best regards

Masriffa]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28331124</guid>
<pubDate>2013-05-29 06:13:08</pubDate>
</item>

<item>
<title>[Info] Cisco ACS question of functionality</title>
<link>http://www.dslreports.com/forum/remark,28360775</link>
<description><![CDATA[In short I was just wondering if the Cisco ACS that we use can provide a audit trail of commands enter based on a particular date.

Reason our Senior Engineer was implementing a Change and had to roll it back. 

Were i come in is the Noc Engineer (ie the junior b$%#$) i just want to know if he missed a simple command as I did a little research in some items with some OLD as hell IOS. 

Trying to get rid of our native vlan mis-match snmp trap messages that hogg the log all day ;)

Getting them between or Core 6509 1 and 2 (VSS group) --> old cisco catalyst 3524 XL. 

Basically the change resulted in complete loss of connectivity between core and this other network segment that serves particular purposes for external clients. Good news is its a seldom used segment, so client noticing or impact is low.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28360775</guid>
<pubDate>2013-06-07 23:20:47</pubDate>
</item>

<item>
<title>[Config] Cisco 1841 DHCP config problem</title>
<link>http://www.dslreports.com/forum/remark,28358959</link>
<description><![CDATA[i have been at this for about a month lol

What i'm trying to do here should be simple

FE0/0 WAN side Cable DHCP connect
FE0/1 LAN side 192.168.1.X /24 with a 1.1 gateway

i cannot for the life of me.. get anything to pass from the WAN to the LAN or LAN to WAN..

here's a Copy of the Config File..

any help would be awesome, thank you!

=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2013.06.05 10:44:48 =~=~=~=~=~=~=~=~=~=~=~=

RabbitBox>enable
Password:
RabbitBox#show running-config
Building configuration...

Current configuration : 9784 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname RabbitBox
!
boot-start-marker
boot-end-marker
!
logging buffered 52000
enable secret 5 xxxxxxxxx
enable password xxxxxxxxxx
!
no aaa new-model
no ip routing
no ip cef
!
!
no ip dhcp use vrf connected
 --More--         !
 --More--         ip dhcp pool RABBIT_POOL
   network 192.168.1.0 255.255.255.0
   default-router 192.168.1.1
   dns-server 8.8.8.8
   domain-name rabbitlab.local
!
!
ip name-server 8.8.8.8
ip name-server 8.8.4.4
!
multilink bundle-name authenticated
parameter-map type protocol-info msn-servers
 server name messenger.hotmail.com
 server name gateway.messenger.hotmail.com
 server name webmessenger.msn.com

parameter-map type protocol-info aol-servers
 server name login.oscar.aol.com
 server name toc.oscar.aol.com
 server name oam-d09a.blue.aol.com

parameter-map type protocol-info yahoo-servers
 server name scs.msg.yahoo.com
 --More--         server name scsa.msg.yahoo.com
 server name scsb.msg.yahoo.com
 server name scsc.msg.yahoo.com
 server name scsd.msg.yahoo.com
 server name cs16.msg.dcn.yahoo.com
 server name cs19.msg.dcn.yahoo.com
 server name cs42.msg.dcn.yahoo.com
 server name cs53.msg.dcn.yahoo.com
 server name cs54.msg.dcn.yahoo.com
 server name ads1.vip.scd.yahoo.com
 server name radio1.launch.vip.dal.yahoo.com
 server name in1.msg.vip.re2.yahoo.com
 server name data1.my.vip.sc5.yahoo.com
 server name address1.pim.vip.mud.yahoo.com
 server name edit.messenger.yahoo.com
 server name messenger.yahoo.com
 server name http.pager.yahoo.com
 server name privacy.yahoo.com
 server name csa.yahoo.com
 server name csb.yahoo.com
 server name csc.yahoo.com

parameter-map type regex sdm-regex-nonascii
 --More--         pattern [^\x00-\x80]

!
crypto pki trustpoint TP-self-signed-576898705
 enrollment selfsigned
 subject-name cn=IOS-Self-Signed-Certificate-576898705
 revocation-check none
 rsakeypair TP-self-signed-576898705
!
!
crypto pki certificate chain TP-self-signed-576898705
 certificate self-signed 01
  3082023F 308201A8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
  30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
  69666963 6174652D 35373638 39383730 35301E17 0D313330 36303530 32333733
  305A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
  532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3537 36383938
  37303530 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100
  A6023ACB 378F3F9C 57E08C64 B3E2EF94 60242D75 E1C0C257 920EE708 7C6C1741
  1AE0E4B2 B6B6767D 5A31C9A3 BBE95A4C D5B9EF06 5F8E4159 88D7CFAB 49FADE4C
  72613480 7A97D662 81A447CB AE8EFF43 7297E618 B7F0BD2B 98A3D7E6 C5C04B5D
  5F1B0B16 1EA74352 F8FC3857 C127F43F C52151C5 7052039E B23B3D63 D668B593
  02030100 01A36930 67300F06 03551D13 0101FF04 05300301 01FF3014 0603551D
 --More--           11040D30 0B820952 61626269 74426F78 301F0603 551D2304 18301680 14A8C93B
  0AC5A863 ABBFE98F AEA1790B F3960776 D7301D06 03551D0E 04160414 A8C93B0A
  C5A863AB BFE98FAE A1790BF3 960776D7 300D0609 2A864886 F70D0101 04050003
  81810053 1FB89FDD F6B43CAC 35D010DE 6B8D03BE C7F17966 99ADACCA 288D844E
  5859C71D 664E8643 D147D146 F64C2A7F 209942E2 8AD9BEE3 F4B3F1F1 153FDA43
  8F23D274 4D83A581 7901F056 5C6F985D AAA46FB4 060E7A58 1FE89E04 347AE8C3
  066934E3 8B27DDB2 14E9CA71 E749BF85 FEC9953B 2C1A8738 5CDE70BC 8446F2A9 10172F
  quit
!
!
username xntech privilege 15 password 0 xxxxxxxx
!
!
class-map type inspect smtp match-any sdm-app-smtp
 match  data-length gt 5000000
class-map type inspect http match-any sdm-app-nonascii
 match  req-resp header regex sdm-regex-nonascii
class-map type inspect imap match-any sdm-app-imap
 match  invalid-command
class-map type inspect match-any sdm-cls-protocol-p2p
 match protocol edonkey signature
 match protocol gnutella signature
 match protocol kazaa2 signature
 --More--         match protocol fasttrack signature
 match protocol bittorrent signature
class-map type inspect match-any sdm-cls-insp-traffic
 match protocol dns
 match protocol https
 match protocol icmp
 match protocol imap
 match protocol pop3
 match protocol tcp
 match protocol udp
class-map type inspect match-all sdm-insp-traffic
 match class-map sdm-cls-insp-traffic
class-map type inspect match-any SDM-Voice-permit
 match protocol h323
 match protocol skinny
 match protocol sip
class-map type inspect match-all sdm-protocol-pop3
 match protocol pop3
class-map type inspect match-any sdm-cls-icmp-access
 match protocol icmp
 match protocol tcp
 match protocol udp
class-map type inspect match-any sdm-cls-protocol-im
 --More--         match protocol ymsgr yahoo-servers
 match protocol msnmsgr msn-servers
 match protocol aol aol-servers
class-map type inspect pop3 match-any sdm-app-pop3
 match  invalid-command
class-map type inspect match-all sdm-protocol-p2p
 match class-map sdm-cls-protocol-p2p
class-map type inspect http match-any sdm-http-blockparam
 match  request port-misuse im
 match  request port-misuse p2p
 match  request port-misuse tunneling
 match  req-resp protocol-violation
class-map type inspect match-all sdm-protocol-im
 match class-map sdm-cls-protocol-im
class-map type inspect match-all sdm-icmp-access
 match class-map sdm-cls-icmp-access
class-map type inspect match-all sdm-invalid-src
 match access-group 100
class-map type inspect edonkey match-any sdm-app-edonkey
 match  file-transfer
 match  text-chat
 match  search-file-name
class-map type inspect http match-any sdm-app-httpmethods
 --More--         match  request method bcopy
 match  request method bdelete
 match  request method bmove
 match  request method bpropfind
 match  request method bproppatch
 match  request method connect
 match  request method copy
 match  request method delete
 match  request method edit
 match  request method getattribute
 match  request method getattributenames
 match  request method getproperties
 match  request method index
 match  request method lock
 match  request method mkcol
 match  request method mkdir
 match  request method move
 match  request method notify
 match  request method options
 match  request method poll
 match  request method post
 match  request method propfind
 match  request method proppatch
 --More--         match  request method put
 match  request method revadd
 match  request method revlabel
 match  request method revlog
 match  request method revnum
 match  request method save
 match  request method search
 match  request method setattribute
 match  request method startrev
 match  request method stoprev
 match  request method subscribe
 match  request method trace
 match  request method unedit
 match  request method unlock
 match  request method unsubscribe
class-map type inspect match-all sdm-protocol-http
 match protocol http
class-map type inspect match-all sdm-protocol-smtp
 match protocol smtp
class-map type inspect match-all sdm-protocol-imap
 match protocol imap
!
!
 --More--         policy-map type inspect sdm-permit-icmpreply
 class type inspect sdm-icmp-access
  inspect
 class class-default
  pass
policy-map type inspect http sdm-action-app-http
 class type inspect http sdm-http-blockparam
  log
  reset
 class type inspect http sdm-app-httpmethods
  log
  reset
 class type inspect http sdm-app-nonascii
  log
  reset
 class class-default
policy-map type inspect smtp sdm-action-smtp
 class type inspect smtp sdm-app-smtp
  reset
 class class-default
policy-map type inspect imap sdm-action-imap
 class type inspect imap sdm-app-imap
  log
 --More--           reset
 class class-default
policy-map type inspect pop3 sdm-action-pop3
 class type inspect pop3 sdm-app-pop3
  log
  reset
 class class-default
policy-map type inspect sdm-inspect
 class type inspect sdm-invalid-src
  drop log
 class type inspect sdm-protocol-http
  inspect
  service-policy http sdm-action-app-http
 class type inspect sdm-protocol-smtp
  inspect
  service-policy smtp sdm-action-smtp
 class type inspect sdm-protocol-imap
  inspect
  service-policy imap sdm-action-imap
 class type inspect sdm-protocol-pop3
  inspect
  service-policy pop3 sdm-action-pop3
 class type inspect sdm-protocol-p2p
 --More--           drop log
 class type inspect sdm-protocol-im
  drop log
 class type inspect sdm-insp-traffic
  inspect
 class type inspect SDM-Voice-permit
  inspect
 class class-default
  pass
policy-map type inspect sdm-permit
 class class-default
!
zone security out-zone
zone security in-zone
zone-pair security sdm-zp-self-out source self destination out-zone
 service-policy type inspect sdm-permit-icmpreply
zone-pair security sdm-zp-out-self source out-zone destination self
 service-policy type inspect sdm-permit
zone-pair security sdm-zp-in-out source in-zone destination out-zone
 service-policy type inspect sdm-inspect
!
!
!
 --More--         !
!
interface FastEthernet0/0
 description $FW_OUTSIDE$
 ip address dhcp
 ip nat outside
 ip virtual-reassembly
 zone-member security out-zone
 no ip route-cache
 speed auto
 half-duplex
 no mop enabled
!
interface FastEthernet0/1
 description $ETH-LAN$$FW_INSIDE$
 ip address 192.168.1.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly
 zone-member security in-zone
 no ip route-cache
 duplex auto
 speed auto
!
 --More--         interface Serial0/0/0
 no ip address
 no ip route-cache
 shutdown
!
interface Serial0/1/0
 no ip address
 no ip route-cache
 shutdown
!
!
!
ip http server
ip http authentication local
ip http secure-server
ip nat inside source list 1 interface FastEthernet0/0 overload
!
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 192.168.1.0 0.0.0.255
access-list 100 remark SDM_ACL Category=128
access-list 100 permit ip host 255.255.255.255 any
access-list 100 permit ip 127.0.0.0 0.255.255.255 any
!
 --More--         !
!
!
!
!
control-plane
!
!
!
line con 0
line aux 0
line vty 0 4
 privilege level 15
 password xxxxxxxx
 login local
 transport input telnet ssh
!
scheduler allocate 20000 1000
end

RabbitBox#

Any help would be greatly Appreciated as my Juniper Netscreen took a bolt of lighting.. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28358959</guid>
<pubDate>2013-06-07 13:37:49</pubDate>
</item>

<item>
<title>buying my first cisco switch</title>
<link>http://www.dslreports.com/forum/remark,28343733</link>
<description><![CDATA[I am currently studying for the ccent the new version not the old one.  I am thinking about buying a cisco 2960 switch from eBay but I am not sure what to look out for.  At this point I don't think I need a router yet but if I do I would like to get 1 router and 1 switch.  I am more of a hands of type of person so I think it would make it easier to study for the exam.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,28343733</guid>
<pubDate>2013-06-02 19:38:26</pubDate>
</item>

</channel>
</rss>
