Cisco

no service call-home no service config no service dhcp no service finger no service old-slip-prompts no service pad service password-encryption no service pt-vty-logging service sequence-numbers no service slave-log no service tcp-keepalives-in no service tcp-keepalives-out no service tcp-small-servers no service telnet-zeroidle service timestamps no service udp-small-servers

Continue reading IOS security

FreeRadius : https://freeradius.org/rfc/rfc2865.html RADIUS Attributes : https://www.cisco.com/c/en/us/td/docs/routers/asr9000/software/asr9k_r4-2/bng/configuration/guide/b_bng_cg42asr9k/b_bng_cg42asr9k_appendix_01000.pdf ASR9k VSA : https://supportforums.cisco.com/t5/service-providers-documents/asr9000-xr-bng-vsa-s-vendor-specific-attributes-and-services/ta-p/3141601

Continue reading Cisco Radius VSA

For anyone else in the future who may be experiencing a similar issue: Problem turned out to be QoS ACL matching conditions. Docs here state: http://www.cisco.com/c/en/us/td/docs/switches/metro/me3600x_3800x/software/release/15-5_1_S/configuration/guide/3800x3600xscg/swqos.html “Not all IP ACL options are supported in QoS ACLs. Only these protocols are supported for permit actions in an IP ACL: TCP, and UDP Although you can configure …

Continue reading Matching EXP bits in ME3600

NBAR2 Live Updates Protocol Pack 30 is now available on CCO! Please Note: minimal required release for protocol pack 28 and up is now: IOS XE 3.16.4bS Version 15.5(3)Sb4, IOS 15.5(3)M4a. So- what is new, you ask? Brand new protocols support: Splunk: platform for collecting and analyzing machine-generated big data, Google-Downloads: Google downloads and updates …

Continue reading Cisco, NBAR2 Live Updates

http://www.cisco.com/c/en/us/td/docs/switches/lan/smart_install/configuration/guide/smart_install/concepts.html#23355 https://tools.cisco.com/security/center/content/CiscoSecurityResponse/cisco-sr-20170214-smi

Continue reading Cisco ZTP | PNP

Compatability matrix specifically for ASR 920 http://www.cisco.com/c/en/us/td/docs/routers/asr920/hardware/installation/guide/ASR920_HIG/Supported_SFPs.html   Compatability matrix specifically for ASR 9000  (researching CWDM XFP:s for our 9001). https://supportforums.cisco.com/document/12940551/asr9000-optics-support-matrixAccording to this the DWDM SFP+ for 9001 should be coded asDWDM-SFP10G-xx.yy    

Continue reading ASR900\9000 optics support-matrix

Restrictions for Netflow Monitoring for ASR 920 Series Routers *         Netflow monitoring supports only the 7 keys-Source IP, Destination IP, Layer 3 protocol type, TOS, source port, destination port and input logical interface to identify or classify the flow for both IPv4 and IPv6 unicast traffic. All other keys are notsupported. *         MPLS and BGP-based …

Continue reading ASR-920 – Netflow