<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:thr='http://purl.org/syndication/thread/1.0' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-7829349077338801903</atom:id><lastBuildDate>Sun, 05 Sep 2010 20:38:14 +0000</lastBuildDate><title>networker blog</title><description>выборочный лог поиска истины</description><link>http://blog.invalid.org.ua/</link><managingEditor>noreply@blogger.com (invalidCCIE)</managingEditor><generator>Blogger</generator><openSearch:totalResults>178</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-2721709680401517699</guid><pubDate>Sun, 05 Sep 2010 13:59:00 +0000</pubDate><atom:updated>2010-09-05T23:38:14.514+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>linux</category><category domain='http://www.blogger.com/atom/ns#'>ubuntu</category><title>[faq] как сделать что б в  убунту работало ...</title><description>&lt;ul&gt;&lt;li&gt;сохранялись и загружались правила файрвола&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;сразу предполагается что файрвол это iptables, а не ubuntu-f*ckingwall(ufw), сносим ufw:&lt;/div&gt;&lt;div&gt;apt-get purge ufw&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;создаем upstart job, vim /etc/init/iptables.conf:&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;description "Load and save iptables"&lt;br /&gt;&lt;br /&gt;start on runlevel [23]&lt;br /&gt;stop on runlevel [016]&lt;br /&gt;&lt;br /&gt;console output&lt;br /&gt;&lt;br /&gt;task&lt;br /&gt;&lt;br /&gt;post-stop script&lt;br /&gt;    iptables-save &amp;gt; /etc/iptables.conf&lt;br /&gt;    iptables -F&lt;br /&gt;    iptables -X&lt;br /&gt;    iptables -P INPUT ACCEPT&lt;br /&gt;    iptables -P FORWARD ACCEPT&lt;br /&gt;    iptables -P OUTPUT ACCEPT&lt;br /&gt;end script&lt;br /&gt;&lt;br /&gt;pre-start script&lt;br /&gt;    if test -f /etc/iptables.conf; then&lt;br /&gt;        iptables-restore &amp;lt; /etc/iptables.conf&lt;br /&gt;    else&lt;br /&gt;        iptables -F&lt;br /&gt;        iptables -X&lt;br /&gt;        iptables -P INPUT DROP&lt;br /&gt;        iptables -P FORWARD DROP&lt;br /&gt;        iptables -A INPUT -i lo -j ACCEPT&lt;br /&gt;        iptables -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT&lt;br /&gt;    fi  &lt;br /&gt;end script&lt;/pre&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;создаем базовую настройку в /etc/iptables/conf (или можно iptables-save &amp;gt;/etc/iptables.conf):&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;*nat&lt;br /&gt;:PREROUTING ACCEPT [0:0]&lt;br /&gt;:POSTROUTING ACCEPT [0:0]&lt;br /&gt;:OUTPUT ACCEPT [0:0]&lt;br /&gt;COMMIT&lt;br /&gt;*filter&lt;br /&gt;:INPUT DROP [0:0]&lt;br /&gt;:FORWARD DROP [0:0]&lt;br /&gt;:OUTPUT ACCEPT [0:0]&lt;br /&gt;:ACCEPT_NEW - [0:0]&lt;br /&gt;:SERVICES - [0:0]&lt;br /&gt;-A INPUT -i lo -j ACCEPT &lt;br /&gt;-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT &lt;br /&gt;-A INPUT -m conntrack --ctstate NEW -j SERVICES &lt;br /&gt;-A ACCEPT_NEW -m limit --limit 100/sec -j ACCEPT &lt;br /&gt;-A ACCEPT_NEW -j DROP &lt;br /&gt;-A SERVICES -p tcp -m tcp --dport 22 -j ACCEPT_NEW &lt;br /&gt;-A SERVICES -p tcp -m tcp --dport 21 -j ACCEPT_NEW &lt;br /&gt;-A SERVICES -p tcp -m tcp --dport 8010 -j ACCEPT_NEW &lt;br /&gt;COMMIT&lt;/pre&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;загружался мой любовно написаный(скопипащенный) конфиг screen'а, а не эта непонятная херь&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;echo &amp;gt; /etc/screenrc&lt;br /&gt;chattr +i /etc/screenrc&lt;/pre&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&amp;nbsp;(опустошаем дебильный убунтушный конфиг, и делаем что б при апгрейде никто его не тронул)&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;загружался мой любовно написаный(скопипащенный) конфиг zsh'а, а не эта непонятная херь, и что б нормально работала история и кнопки навигации/редактирования&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;rm -rf /etc/zsh&lt;br /&gt;touch /etc/zsh&lt;br /&gt;chattr +i /etc/zsh&lt;/pre&gt;&lt;/span&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&amp;nbsp;(опустошаем дебильный убунтушный конфиг, и делаем что б при апгрейде никто его не тронул)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman';"&gt;&lt;span class="Apple-style-span" style="font-size: medium; white-space: normal;"&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;возвращаем к жизни нетворк менеджер (ошибка 'network management is disabled (C)')&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px; white-space: normal;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;vim /var/lib/NetworkManager/NetworkManager.state&lt;/pre&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;меняем&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px; white-space: normal;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman'; font-size: medium; white-space: normal;"&gt;NetworkingEnabled=false&lt;/span&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;на&lt;br /&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px; white-space: normal;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman'; font-size: medium; white-space: normal;"&gt;NetworkingEnabled=true&lt;/span&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;ускоряем &amp;nbsp;работу с сетью/веб (тщетные попытки убунты резолвить dns через хрен знает что)&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;по-умолчанию убунта пробуем разрешать имена не через dns-сервер прописанный в /etc/resolv.conf, а через avahi-daemon. это приводит к значительным задержкам при открытии сайтов.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px; white-space: normal;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman';"&gt;&lt;span class="Apple-style-span" style="font-size: medium; white-space: normal;"&gt;update-rc.d -f avahi-daemon remove&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;избавляемся от подлых авто-апдейтов, пользующих без спросу наш драгоценный инет&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;удаляем любые намеки на автоапдейт из настроек apt:&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px; white-space: normal;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman';"&gt;&lt;span class="Apple-style-span" style="font-size: medium; white-space: normal;"&gt;vim&amp;nbsp;/etc/apt/apt.conf.d/10periodic&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;для надежности можно удалить сам запуск автоапдейтов из крона (внимание, при апгрейде может без спросу вернуться)&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: monospace; font-size: small;"&gt;&lt;span class="Apple-style-span" style="font-size: 12px; white-space: pre;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Lucida Grande', Verdana, Lucida, Helvetica, Arial, sans-serif; font-size: 13px; white-space: normal;"&gt;&lt;pre class="code" style="background-color: #f7f9fa; border-bottom-color: rgb(140, 172, 187); border-bottom-style: dashed; border-bottom-width: 1px; border-left-color: rgb(140, 172, 187); border-left-style: dashed; border-left-width: 1px; border-right-color: rgb(140, 172, 187); border-right-style: dashed; border-right-width: 1px; border-top-color: rgb(140, 172, 187); border-top-style: dashed; border-top-width: 1px; color: black; font-size: 12px; margin-bottom: 1em; margin-left: 0px; margin-right: 0px; margin-top: 0px; overflow-x: auto; overflow-y: auto; padding-bottom: 0.5em; padding-left: 0.5em; padding-right: 0.5em; padding-top: 0.5em;"&gt;&lt;span class="Apple-style-span" style="font-family: 'Times New Roman';"&gt;&lt;span class="Apple-style-span" style="font-size: medium; white-space: normal;"&gt;rm /etc/cron.daily/99apt&lt;/span&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-2721709680401517699?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/09/faq.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-31140559077778033</guid><pubDate>Sun, 04 Jul 2010 17:56:00 +0000</pubDate><atom:updated>2010-07-04T20:56:21.797+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>ipv6</category><title>Hurricane Electric IPv6 Certification</title><description>&lt;a href="http://ipv6.he.net/certification/scoresheet.php?pass_name=invalidccie" target="_blank"&gt;&lt;img src="http://ipv6.he.net/certification/create_badge.php?pass_name=invalidccie&amp;badge=1" width=128 height=128 border=0 alt="IPv6 Certification Badge for invalidccie"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;p.s. больше набрать не могу, ни для одного из моих доменов нельзя указать ipv6 dns hints :(&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-31140559077778033?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/07/hurricane-electric-ipv6-certification.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-4319655174451729225</guid><pubDate>Sun, 04 Jul 2010 17:54:00 +0000</pubDate><atom:updated>2010-07-04T20:54:26.291+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>Вопрос:&lt;br /&gt;&lt;br /&gt;какой MAC-адрес получателя используется для отправки кадров 802.1x?&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;по стандарту зарезервирован IEEE Std 802.1X PAE address 01-80-C2-00-00-03.&lt;/span&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: white;"&gt;данный адрес является&lt;i&gt; Link-Local адресом&lt;/i&gt;, то есть не передается дальше чем соседнему L2 устройству, что существенно усложняет использование 802.1x в виртуальных средах :(&lt;/span&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-4319655174451729225?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/07/question-of-day.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-2015741627204061033</guid><pubDate>Mon, 03 May 2010 04:22:00 +0000</pubDate><atom:updated>2010-05-03T07:24:05.900+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;что такое cef epoch?&lt;br /&gt;пример sh ip cef:&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;Router#sh ip cef detail&lt;br /&gt;IPv4 CEF is enabled and running&lt;br /&gt;VRF Default:&lt;br /&gt; 79 prefixes (79/0 fwd/non-fwd)&lt;br /&gt; Table id 0&lt;br /&gt; Database &lt;b&gt;epoch&lt;/b&gt;:        0 (79 entries at this &lt;b&gt;epoch&lt;/b&gt;)&lt;br /&gt;&lt;br /&gt;0.0.0.0/0, &lt;b&gt;epoch&lt;/b&gt; 0, flags default route handler&lt;br /&gt;  no route&lt;br /&gt;0.0.0.0/8, &lt;b&gt;epoch&lt;/b&gt; 0&lt;br /&gt;  Special source: drop&lt;br /&gt;  drop&lt;br /&gt;0.0.0.0/32, &lt;b&gt;epoch&lt;/b&gt; 0, flags receive&lt;br /&gt;  Special source: receive&lt;br /&gt;  receive&lt;br /&gt;10.0.1.0/24, &lt;b&gt;epoch&lt;/b&gt; 0&lt;br /&gt;  recursive via 192.168.1.2&lt;br /&gt;    attached to FastEthernet0/0.304&lt;br /&gt;10.0.2.0/24, epoch 0&lt;br /&gt;  recursive via 192.168.2.2&lt;br /&gt;    attached to FastEthernet0/0.305&lt;br /&gt;10.0.3.0/24, &lt;b&gt;epoch&lt;/b&gt; 0&lt;br /&gt;  recursive via 192.168.3.2&lt;br /&gt;    attached to FastEthernet0/0.306&lt;br /&gt;10.0.4.0/24, &lt;b&gt;epoch&lt;/b&gt; 0&lt;br /&gt;  recursive via 192.168.4.2&lt;br /&gt;    attached to FastEthernet0/0.307&lt;br /&gt;127.0.0.0/8, &lt;b&gt;epoch&lt;/b&gt; 0&lt;br /&gt;  Special source: drop&lt;br /&gt;  drop    &lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;div style="color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: white;"&gt;это глобальная версия таблицы FIB, т.е. у всех up-to-date записей версия должна быть равной. служит для синхронизации FIB.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-2015741627204061033?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/05/question-of-day.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-3798658143451165214</guid><pubDate>Sun, 02 May 2010 08:35:00 +0000</pubDate><atom:updated>2010-05-02T11:35:23.368+03:00</atom:updated><title>Какой ты сисадмин?</title><description>&lt;center&gt;&lt;div style="WIDTH: 350px; border: 2px groove; padding: 4px"&gt;&lt;P    align=right&gt;&lt;A href="http://www.mml.ru/" target=_blank&gt;&lt;img    align=top border="0" src="http://mml.ru/support.gif"&gt;&lt;/a&gt;&lt;P    align=center&gt;&lt;SPAN style="COLOR: #336699; FONT-FAMILY: Arial"&gt;&lt;FONT    size=4&gt;&lt;B&gt;Какой ты сисадмин?&lt;/B&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;P&gt;&lt;SPAN    style="FONT-SIZE: 11pt; FONT-FAMILY: Arial"&gt;Дорогой &lt;SPAN   style="COLOR: #336699"&gt;&lt;B&gt;Sergey&lt;/B&gt;&lt;/SPAN&gt;,&lt;P   &gt;&lt;SPAN style="FONT-SIZE: 11pt; FONT-FAMILY: Arial"&gt;Вы гуру! Мы сами не можем выбить столько правильных ответов в этом тесте. Пожалуйста, &lt;a href=http://mml.ru/job.htm&gt;пришлите нам Ваше резюме!&lt;/a&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P align=center&gt;&lt;span style="FONT-SIZE: 10pt; FONT-FAMILY: Arial"    &gt;Правильных ответов: 14 из 16&lt;/span&gt;&lt;/P&gt;&lt;P    align=center&gt;Пройти тест: &lt;A    href="http://www.mml.ru/satest.asp" target=_blank&gt;Какой ты сисадмин?&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/div&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-3798658143451165214?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/05/blog-post.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-7762410861645736263</guid><pubDate>Thu, 22 Apr 2010 04:07:00 +0000</pubDate><atom:updated>2010-04-22T07:07:53.623+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>fun</category><category domain='http://www.blogger.com/atom/ns#'>humor</category><title>Nerd Test</title><description>&lt;a href="http://www.nerdtests.com/ft_nq.php"&gt;&lt;br /&gt;&lt;img alt="I am nerdier than 100% of all people. Are you a nerd? Click here to take the Nerd Test, get geeky images and jokes, and talk on the nerd forum!" src="http://www.nerdtests.com/images/ft/nq/9df5e10593.gif" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-7762410861645736263?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/04/nerd-test.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-880192269285951710</guid><pubDate>Mon, 29 Mar 2010 14:45:00 +0000</pubDate><atom:updated>2010-03-29T17:45:48.694+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>performance</category><category domain='http://www.blogger.com/atom/ns#'>cisco</category><category domain='http://www.blogger.com/atom/ns#'>nbar</category><title>Нагрузка процессора NBAR'ом</title><description>на сайте циски появилась &lt;a href="http://www.cisco.com/en/US/technologies/tk543/tk759/technologies_white_paper0900aecd8031b712_ps6616_Products_White_Paper.html"&gt;статья, сравнивающая разницу производительности и нагрузки на процессор с использованием nbar и без него&lt;/a&gt;.&lt;br /&gt;для разных линеек програмных маршрутизоторов результаты немного разные, и есть небольшая разница при использовании protocol-discovery и match protocol, но результат приблизительно стабилен - &lt;b&gt;разница нагрузки на процессор без nbar и с nbar в полтора раза.&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-880192269285951710?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/03/nbar.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-6022245544522212789</guid><pubDate>Thu, 18 Mar 2010 08:03:00 +0000</pubDate><atom:updated>2010-03-18T11:03:04.037+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;что значит "interface is congested"?&lt;br /&gt;(формулировка, часто встречающаяся в объяснениях работы механизмов очередей)&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;div style="color: white;"&gt;несколько почти эквивалентных вариантов:&lt;/div&gt;&lt;div style="color: white;"&gt;1) wfq/llq/cbwfq/wrr/и.т.д. очередь на интерфейсе не пуста&lt;/div&gt;&lt;div style="color: white;"&gt;2) аппаратная фифо-очередь интерфейса (она же tx-ring) заполнена&lt;/div&gt;&lt;div style="color: white;"&gt;3) ваш вариант (оставляйте в комментариях)&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;вопрос2:&lt;br /&gt;как объяснять перегруженность в случаях когда пропускная предоставляемая через интерфейс существенно ниже скорости интерфейса (например 3Мбит на Fa-интерфейсе)?&lt;br /&gt;как объяснять перегруженность в случаях с вложенными политиками qos?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-6022245544522212789?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/03/question-of-day_18.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-6365805114076244255</guid><pubDate>Sat, 13 Mar 2010 01:04:00 +0000</pubDate><atom:updated>2010-03-13T04:04:00.862+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;что показывает команда show ip cef exact-route 10.1.1.1 10.2.2.2 ?&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;div style="color: white;"&gt;маршрут, который будет выбран сефом для конкретной пары src-ip 10.1.1.1, dst-ip 10.2.2.2.&lt;/div&gt;&lt;div style="color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: white;"&gt;вопрос2:&lt;/div&gt;&lt;div style="color: white;"&gt;а как же номера портов?&lt;/div&gt;&lt;div style="color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: white;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="color: white;"&gt;ответ2:&lt;/div&gt;&lt;div style="color: white;"&gt;а при 'ip cef load-sharing algorithm original' порты не фигурируют.&lt;/div&gt;&lt;span style="color: white;"&gt;а для прочих вариантов в новых ios есть 'show ip cef exact-route 10.1.1.1 src-port 32323 10.2.2.2 dst-port 23'&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-6365805114076244255?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/03/question-of-day_13.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-2306545844719503674</guid><pubDate>Fri, 12 Mar 2010 20:23:00 +0000</pubDate><atom:updated>2010-03-12T23:23:00.199+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>qos</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;что значат два числи выделенные в выводе команды show processes cpu?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;SW1#show processes cpu&lt;br /&gt;CPU utilization for five seconds:&lt;b&gt; &lt;u&gt;1%/0%&lt;/u&gt;&lt;/b&gt;; one minute: 1%; five minutes: 0%&lt;br /&gt;&amp;nbsp;PID Runtime(ms)&amp;nbsp;&amp;nbsp; Invoked&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; uSecs&amp;nbsp;&amp;nbsp; 5Sec&amp;nbsp;&amp;nbsp; 1Min&amp;nbsp;&amp;nbsp; 5Min TTY Process&lt;br /&gt;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; 0.00%&amp;nbsp; 0.00%&amp;nbsp; 0.00%&amp;nbsp;&amp;nbsp; 0 Chunk Manager&lt;br /&gt;&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp; 117516&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; 0.00%&amp;nbsp; 0.00%&amp;nbsp; 0.00%&amp;nbsp;&amp;nbsp; 0 Load Meter&lt;br /&gt;&amp;nbsp;&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4897&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp; 0.00%&amp;nbsp; 0.00%&amp;nbsp; 0.00%&amp;nbsp;&amp;nbsp; 0 DHCPD Timer&lt;br /&gt;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 482004&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 65064&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7408&amp;nbsp; 0.00%&amp;nbsp; 0.07%&amp;nbsp; 0.05%&amp;nbsp;&amp;nbsp; 0 Check heaps&lt;br /&gt;&amp;nbsp;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 72&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 257&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 280&amp;nbsp; 0.00%&amp;nbsp; 0.00%&amp;nbsp; 0.00%&amp;nbsp;&amp;nbsp; 0 Pool Manager&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;div style="color: white;"&gt;первое (1%) - загрузка проца суммарная&lt;/div&gt;&lt;span style="color: white;"&gt;второе (0%) - загрузка проца обработкой прерываний packet switching&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-2306545844719503674?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/03/question-of-day_3123.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-6396053674779300032</guid><pubDate>Fri, 12 Mar 2010 12:36:00 +0000</pubDate><atom:updated>2010-03-12T15:36:39.950+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;какой командой show можно получить следующий вывод:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;SW1#.............................................&lt;br /&gt;&lt;br /&gt;CAM Utilization for ASIC# 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Max&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Used&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Masks/Values&amp;nbsp;&amp;nbsp;&amp;nbsp; Masks/values&lt;br /&gt;&lt;br /&gt;&amp;nbsp;Unicast mac addresses:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 400/3200&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 42/263&lt;br /&gt;&amp;nbsp;IPv4 IGMP groups + multicast routes:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 144/1152&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9/41&lt;br /&gt;&amp;nbsp;IPv4 unicast directly-connected routes:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 400/3200&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 42/263&lt;br /&gt;&amp;nbsp;IPv4 unicast indirectly-connected routes:&amp;nbsp;&amp;nbsp;&amp;nbsp; 1040/8320&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20/127&lt;br /&gt;&amp;nbsp;IPv4 policy based routing aces:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 512/512&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2/2&lt;br /&gt;&amp;nbsp;IPv4 qos aces:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 512/512&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6/6&lt;br /&gt;&amp;nbsp;IPv4 security aces:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1024/1024&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 27/27&lt;br /&gt;&lt;br /&gt;Note: Allocation of TCAM entries per feature uses&lt;br /&gt;a complex algorithm. The above information is meant&lt;br /&gt;to provide an abstract view of the current TCAM utilization&lt;br /&gt;&lt;br /&gt;SW1#&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;свич - 3560&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: white; color: white;"&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;div style="background-color: white; color: white;"&gt;show platform tcam utilization&lt;/div&gt;&lt;div style="background-color: white; color: white;"&gt;&lt;/div&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div style="background-color: white; color: white;"&gt;на некоторых платформах близкий к указанному результат можно получить с show tcam&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-6396053674779300032?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/03/question-of-day_12.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-90932230922687440</guid><pubDate>Wed, 10 Mar 2010 14:11:00 +0000</pubDate><atom:updated>2010-03-10T17:11:05.243+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>Вопрос:&lt;br /&gt;&lt;br /&gt;какой коммандой show можно получить следующий вывод:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;SW1#show ........................&lt;br /&gt;Name : Fa0/1&lt;br /&gt;Administrative Speed: auto&lt;br /&gt;Administrative Duplex: auto&lt;br /&gt;Administrative Auto-MDIX: on&lt;br /&gt;Administrative Power Inline: N/A&lt;br /&gt;Operational Speed: 100&lt;br /&gt;Operational Duplex: full&lt;br /&gt;Operational Auto-MDIX: on&lt;br /&gt;&lt;br /&gt;SW1#&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;(это самый обычный свич, например 3560 или 2960) &lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;div style="color: white;"&gt;&lt;/div&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;div style="color: white;"&gt;SW1# show interface fa0/1 transceiver properties&lt;/div&gt;&lt;div style="color: white;"&gt;&lt;/div&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-90932230922687440?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2010/03/question-of-day.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-8077481355562351122</guid><pubDate>Sun, 06 Dec 2009 17:20:00 +0000</pubDate><atom:updated>2009-12-06T20:23:37.794+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>switching</category><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;может ли VTP передавать информацию о private-vlan map?&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;да, в версии VTP 3&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;кстати, &lt;/span&gt;&lt;a style="color: rgb(255, 255, 255);" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3560/software/release/12.2_52_se/configuration/guide/swvtp.html#wp1316856"&gt;эта версия таки реализована на IOS &lt;/a&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;(ранее она была только на CatOS):&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;кроме того третья версия поддерживает:&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;* распространение vlan-instance map для MST&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;* private-vlan&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;* extended vlan range&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;* множество других функций по контролю и управлению самим VTP&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-8077481355562351122?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/12/question-of-day_06.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-5416310667219028314</guid><pubDate>Thu, 03 Dec 2009 19:44:00 +0000</pubDate><atom:updated>2009-12-03T22:51:59.981+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;всегда ли bpdufilter работает одинаково?&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;нет. конечно, bpdufilter должен приводить к одному результату: прекращению отправки и обработки bpdu на порту. но. есть два варианта настройки:&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;* (config)# spanning-tree portfast bpdufilter default&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;* (config-if)# spanning-tree bpdufilter enable&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;первый включает bpdufilter по-умолчанию на всех portfast портах&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;второй - принудительно на интерфейсе.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;так вот, первый вариант работает следующим образом: сначала отправляются 11 (одинадцать, не больше и не меньше)  bpdu, и только затем, если не были обнаружены ответы, включается фильтр :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;SW1#sh span int fa0/1 de&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;  Port 3 (FastEthernet0/1) of VLAN0146 is designated forwarding&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Port path cost 19, Port priority 128, Port Identifier 128.3.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Designated root has priority 32914, address 000f.90fd.a280&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Designated bridge has priority 32914, address 001d.4614.cc80&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Designated port id is 128.3, designated path cost 19&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Timers: message age 0, forward delay 0, hold 0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Number of transitions to forwarding state: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;The port is in the portfast mode&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Link type is point-to-point by default&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;Bpdu filter is enabled by default&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;BPDU: sent 0&lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;, received 0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;SW1#&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;%LINK-3-UPDOWN: Interface FastEthernet0/1, changed state to up&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;%LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/1, changed state to up&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;SW1#sh span int fa0/1 de&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt; Port 3 (FastEthernet0/1) of VLAN0146 is designated forwarding&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Port path cost 19, Port priority 128, Port Identifier 128.3.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Designated root has priority 32914, address 000f.90fd.a280&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Designated bridge has priority 32914, address 001d.4614.cc80&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Designated port id is 128.3, designated path cost 19&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Timers: message age 0, forward delay 0, hold 0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Number of transitions to forwarding state: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   The port is in the portfast mode&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Link type is point-to-point by default&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Bpdu filter is enabled by default&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;BPDU: sent 3&lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;, received 0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;SW1#sh span int fa0/1 de&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt; Port 3 (FastEthernet0/1) of VLAN0146 is designated forwarding&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Port path cost 19, Port priority 128, Port Identifier 128.3.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Designated root has priority 32914, address 000f.90fd.a280&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Designated bridge has priority 32914, address 001d.4614.cc80&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Designated port id is 128.3, designated path cost 19&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Timers: message age 0, forward delay 0, hold 0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Number of transitions to forwarding state: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   The port is in the portfast mode&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Link type is point-to-point by default&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   Bpdu filter is enabled by default&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;   &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;BPDU: sent 11&lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;, received 0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;SW1#sh span int fa0/1 de&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;  Port 3 (FastEthernet0/1) of VLAN0146 is designated forwarding&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    Port path cost 19, Port priority 128, Port Identifier 128.3.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    Designated root has priority 32914, address 000f.90fd.a280&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    Designated bridge has priority 32914, address 001d.4614.cc80&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    Designated port id is 128.3, designated path cost 19&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    Timers: message age 0, forward delay 0, hold 0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    Number of transitions to forwarding state: 1&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    The port is in the portfast mode&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    Link type is point-to-point by default&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    Bpdu filter is enabled by default&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;    &lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;BPDU: sent 11&lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;, received 0&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;как мы видим, несмотря на то что "Bpdu filter is enabled by default" счетчик отправленных bpdu растет, и замирает на отметке 11.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-5416310667219028314?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/12/question-of-day.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-822920104072212192</guid><pubDate>Mon, 30 Nov 2009 19:58:00 +0000</pubDate><atom:updated>2009-11-30T23:03:29.987+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>switching</category><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;SW2#sh span int fa0/2 detail&lt;br /&gt;no spanning tree info available for FastEthernet0/2&lt;br /&gt;&lt;br /&gt;SW2#sh run int fa0/2&lt;br /&gt;Building configuration...&lt;br /&gt;&lt;br /&gt;Current configuration : 128 bytes&lt;br /&gt;!&lt;br /&gt;interface FastEthernet0/2&lt;br /&gt; description to R2&lt;br /&gt; switchport access vlan 100&lt;br /&gt; switchport mode access&lt;br /&gt; spanning-tree portfast&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;SW2#sh vlan brief | in N100&lt;br /&gt;1000 VLAN1000                         active&lt;br /&gt;&lt;br /&gt;SW2#sh run | in switchport backup&lt;br /&gt;SW2#&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;как удалось отключить spanning-tree?&lt;br /&gt;&lt;br /&gt;ответ: &lt;span style="color: rgb(255, 255, 255);"&gt;см. private-vlan&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;/span&gt;&lt;br /&gt; &lt;span style="color: rgb(255, 255, 255);"&gt;SW2#sh vla id 100&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;VLAN Name                             Status    Ports&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;---- -------------------------------- --------- -------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;100  VLAN0100                         active    Fa0/2, Fa0/19, Fa0/20, Fa0/21&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;                                                Fa0/24, Po1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;VLAN Type  SAID       MTU   Parent RingNo BridgeNo Stp  BrdgMode Trans1 Trans2&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;100  enet  100100     1500  -      -      -        -    -        0      0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;Remote SPAN VLAN&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;----------------&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;Disabled&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;Primary Secondary Type              Ports&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;------- --------- ----------------- ------------------------------------------&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;100     1000      community&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;100     2000      community         Fa0/4&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(255, 255, 255);"&gt;100     3000      isolated          Fa0/6&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;SW2#&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt; &lt;/pre&gt;&lt;/blockquote&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-822920104072212192?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/11/question-of-day_30.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-7107084316328598912</guid><pubDate>Fri, 27 Nov 2009 07:17:00 +0000</pubDate><atom:updated>2009-11-27T10:21:08.412+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>asa</category><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;что из нижеперечисленного пропускается в прозрачном режиме файрвола (при настройках по-умолчанию, из inside на outside):&lt;br /&gt;dhcp, eigrp, ospf, rip, icmp, multicast, arp, stp, cdp, is-is?&lt;br /&gt;&lt;br /&gt;ответ: &lt;span style="color: rgb(255, 255, 255);"&gt;icmp.&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;l2-протоколы такие как stp, cdp, is-is необходимо явно разрешать с помощью ethertype acl;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;l3-протоколы маршрутизации и dhcp тоже по-умолчанию запрещены.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-7107084316328598912?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/11/question-of-day_27.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-2035563290642708744</guid><pubDate>Sun, 22 Nov 2009 11:32:00 +0000</pubDate><atom:updated>2009-11-22T14:37:36.470+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>switching</category><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;сколько есть вариантов реагирование на превышение лимита mac-адресов port-security?&lt;br /&gt;&lt;br /&gt;ответ: &lt;span style="color: rgb(255, 255, 255);"&gt;приблизительно 4-5:&lt;br /&gt;  * shutdown (при нарушении - err-disable port)&lt;br /&gt;  * protect(игнорирует все кадры с mac-адресов отличных от зафиксированных)&lt;br /&gt;  * restrict(&lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;игнорирует все кадры с mac-адресов отличных от зафиксированных, и кроме того отправляет &lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;trap/syslog и увеличивает violation counter)&lt;br /&gt;  * shutdown vlan(err-disable только того vlan в котором появился mac нарушителя, например только voice vlan :))&lt;br /&gt;  * и конечно же no switchport port-security :))&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-2035563290642708744?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/11/question-of-day_22.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-8893291624513260395</guid><pubDate>Fri, 20 Nov 2009 22:31:00 +0000</pubDate><atom:updated>2009-11-21T01:42:43.162+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>switching</category><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Questions of the day</title><description>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;вопрос 1:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;топология sw1==sw2, оба свича - клиенты vtp домена cisco, в базе - 15 вланов, ревизия 21.&lt;br /&gt;a) переводим sw1 в домен linksys. как изменится на нем номер ревизии vtp?&lt;br /&gt;b) переводим sw1 обратно в домен cisco. как изменится на нем номер ревизии vtp?&lt;br /&gt;c) почему?&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;a) станет равной нулю&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;b) станет равной 21&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;c) потому что клиенты vtp ОТПРАВЛЯЮТ АПДЕЙТЫ VTP НИЧУТЬ НЕ ХУЖЕ СЕРВЕРОВ :)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;вопрос 2:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;топология sw1==sw2, оба свича - клиенты vtp домена cisco. свичпорт sw1 административно является dynamic desirable, порт sw2 - dynamic auto.&lt;br /&gt;a) какое будет операционное состояние свичпортов линка между sw1 и sw2?&lt;br /&gt;b) теперь переводим sw1 в домен vtp linksys. изменится ли состояние свичпортов?&lt;br /&gt;с) почему?&lt;br /&gt;d) а что было бы если б административный режим свичпорта был trunk?&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;a) trunk&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;b) trunk (до перезапуска переговоров dtp)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;c) переговоры dtp рестартуют  к примеру при смене down/up свичпорта&lt;/span&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;, и до этих пор порт останется trunk&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;d) в любом случае был бы trunk&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-8893291624513260395?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/11/questions-of-day.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-9204363928009301885</guid><pubDate>Fri, 20 Nov 2009 20:40:00 +0000</pubDate><atom:updated>2009-11-21T00:40:37.231+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>cisco</category><category domain='http://www.blogger.com/atom/ns#'>eem</category><category domain='http://www.blogger.com/atom/ns#'>humor</category><title>Зачем нужен сислог, если есть твиттер?</title><description>на цискокоме в коллекции скриптов для Embeded Event Manager'а появился &lt;a href="http://forums.cisco.com/eforum/servlet/EEM;jsessionid=BD2A8A214889C82525FB64064F4AC790.SJ4A?page=eem&amp;amp;fn=script&amp;amp;scriptId=2121"&gt;скрипт для twitter'а&lt;/a&gt;&lt;br /&gt;(&lt;a href="http://twitter.com/EASyDMI"&gt;пример использования указан там же&lt;/a&gt;).&lt;br /&gt;рассмотрим как им пользоваться :)&lt;br /&gt;&lt;br /&gt;1) качаем и загружаем на роутер&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;# copy tftp://10.1.1.1/tweet-policy.tcl flash:/tweet-policy.tcl&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;2) регистрируем политику EEM&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;(config)# event manager directory user policy "flash:/"&lt;br /&gt;(config)# event manager policy tweet-policy.tcl type user&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;3) заполняем переменные окружения&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;$ dig +short twitter.com&lt;br /&gt;168.143.162.52&lt;br /&gt;$ echo login:password | base64 -&lt;br /&gt;bG9naW46cGFzc3dvcmQK&lt;br /&gt;&lt;br /&gt;(config)# event manager environment _tweet_ip 168.143.162.52&lt;br /&gt;(config)# event manager environment _tweet_b64 bG9naW46cGFzc3dvcmQK&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;3a) выполняем политику вручную&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;# event manager run tweet-policy.tcl&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;3b) выполняем политику периодически каждые 5 минут&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;(config)#event manager applet tweetme&lt;br /&gt;(config-applet)# event timer watchdog time 300                   &lt;br /&gt;(config-applet)# action 1 policy tweet-policy.tcl&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;домашнее задание: разобраться с формированием статуса, научится постить в твиттер сислог...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-9204363928009301885?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/11/blog-post.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-7008281937331155521</guid><pubDate>Sun, 08 Nov 2009 07:49:00 +0000</pubDate><atom:updated>2009-11-08T11:12:06.383+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>humor</category><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;какими способами можно запретить привилегированому пользователю перезагружать роутер? :)&lt;br /&gt;&lt;br /&gt;ответы:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;1) сделав alias команды reload:&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;alias exec relo sh ver&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;alias exec reloa sh ver&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;alias exec reload sh ver&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;^Z&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;wr mem&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;2) Role-Based CLI, поместив пользователя в вид в котором команда reload запрещена:&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;aaa new&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;ena pass cisco123&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;^Z&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;enable view&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;cisco123&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;parser view reload&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;secret cisco123-super-secret&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;commands exec include-exclusive all reload&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;parser view normal&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;secret cisco123&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;username test nopassword priv 15 view normal&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;aaa authentication login default local&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;aaa authorization exec default local&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;aaa authorization console&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;^Z&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;wr mem&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;logout&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;3) Embedded Event Manager - при вводе команды reload писать в сислог сообщение, а команду - игнорировать :)&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;conf t&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;event manager applet noReload&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;event cli pattern "relo.*" sync no skip yes&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;action 10 syslog msg "Reload not permitted"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;буду рад услышать ваши остроумные способы :)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-7008281937331155521?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/11/question-of-day_08.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-8639618161009091761</guid><pubDate>Fri, 06 Nov 2009 16:41:00 +0000</pubDate><atom:updated>2009-11-06T23:33:45.852+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>bgp</category><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>Вопрос:&lt;br /&gt;&lt;br /&gt;можно ли использовать time-based acl совместно с политиками бгп?&lt;br /&gt;например в светлое время суток для префиксов 10.1.0.0/16 ставить локал преференс выше?&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;&lt;pre&gt;time-range DAY&lt;br /&gt;periodic daily 9:00 to 18:00&lt;br /&gt;&lt;br /&gt;access-list 101 permit 10.1.0.0 0.0.255.255 any time-range DAY&lt;br /&gt;&lt;br /&gt;route-map SET_LPREF 10&lt;br /&gt;match ip address 101&lt;br /&gt;set local-preference 150&lt;br /&gt;!&lt;br /&gt;route-map SET_LPREF 20&lt;br /&gt;set local-preference 50&lt;br /&gt;&lt;/pre&gt;router bgp 65001&lt;br /&gt; neighbor 192.168.1.2 remote-as 65002&lt;br /&gt; neighbor 192.168.1.2 route-map SET_LPREF in&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;да. то есть нет. на новых иосах bgp не обратит внимание на смену времени по time-based acl без другого внешнего события (падения/изменения маршрута на 10.1.0.0/16).  &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;так же смотрите обратный пример (модификация анонсируемого по bgp префикса) - http://blog.internetworkexpert.com/2008/01/25/bgp-time-based-policy-routing/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-8639618161009091761?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/11/question-of-day_06.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-6745149853875784022</guid><pubDate>Wed, 04 Nov 2009 14:10:00 +0000</pubDate><atom:updated>2009-11-04T17:13:18.998+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>qotd</category><title>Question of the day</title><description>вопрос:&lt;br /&gt;&lt;br /&gt;какие значения соответствуют "стандартным" коммюнити no-export, no-advertise, local-as, internet?&lt;br /&gt;&lt;br /&gt;ответ:&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;no-export=0xFFFFFF01&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;no-advertise=0xFFFFFF02&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;local-as=0xFFFFFF03&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 255, 255);"&gt;internet=&lt;span style="font-family: monospace;"&gt;0&lt;/span&gt;&lt;/span&gt;&lt;code style="color: rgb(255, 255, 255);"&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-6745149853875784022?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/11/question-of-day.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-1628042518022690403</guid><pubDate>Mon, 26 Oct 2009 11:19:00 +0000</pubDate><atom:updated>2009-10-26T14:21:51.681+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>cisco</category><title>EIGRP hidden commands</title><description>случайно нашел еще одну "скрытую" команду связанную с eigrp:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;BBR1#sh ip ei eve&lt;br /&gt;Event information for AS 1:&lt;br /&gt;1    11:22:36.267 Poison squashed: 10.97.97.0/24 reverse&lt;br /&gt;2    11:22:34.259 Poison squashed: 172.31.1.0/24 reverse&lt;br /&gt;3    11:22:34.243 Change queue emptied, entries: 1&lt;br /&gt;4    11:22:34.243 Metric set: 10.97.97.0/24 281600&lt;br /&gt;5    11:22:34.243 Update reason, delay: new if 4294967295&lt;br /&gt;6    11:22:34.243 Update sent, RD: 10.97.97.0/24 4294967295&lt;br /&gt;7    11:22:34.243 Update reason, delay: metric chg 4294967295&lt;br /&gt;8    11:22:34.243 Update sent, RD: 10.97.97.0/24 4294967295&lt;br /&gt;9    11:22:34.243 Route install: 10.97.97.0/24 10.254.0.3&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-1628042518022690403?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/10/eigrp-hidden-commands.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-7972399395312172537</guid><pubDate>Thu, 22 Oct 2009 06:33:00 +0000</pubDate><atom:updated>2009-10-22T09:36:24.024+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>cisco</category><category domain='http://www.blogger.com/atom/ns#'>asa</category><title>ASA: change https/ASDM certificate</title><description>по-умолчанию, аса использует самоподписанный сертификат при подключении по https/asdm. краткая инструкция как это исправить.&lt;br /&gt;&lt;br /&gt;1) получаем законный сертификат&lt;br /&gt;а) добавляем центр сертификации:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;(config)# crypto ca trustpoint CorpCA&lt;br /&gt;(config-ca-trustpoint)# enrollment url http://172.26.26.50/certsrv/mscep/mscep.dll&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;b) подтверждаем сертификат CorpCA&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;crypto ca authenticate CorpCA&lt;br /&gt;Do you accept this certificate? [yes/no]: yes   &lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;c) указываем атрибуты для своего будущего сертификата&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;(config)# crypto ca trustpoint CorpCA&lt;br /&gt;(config-ca-trustpoint)# subject-name cn=CORP-ASA&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;d) запрашиваем сертификат&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;(config)# crypto ca enroll CorpCA&lt;br /&gt;%                                                                          &lt;br /&gt;% Start certificate enrollment ..                                          &lt;br /&gt;% Create a challenge password. You will need to verbally provide this      &lt;br /&gt;password to the CA Administrator in order to revoke your certificate.   &lt;br /&gt;For security reasons your password will not be saved in the configuration.&lt;br /&gt;Please make a note of it.                                               &lt;br /&gt;Password:                                                                  &lt;br /&gt;Re-enter password:                                                         &lt;br /&gt;&lt;br /&gt;% The subject name in the certificate will be: cn=CORP-ASA&lt;br /&gt;&lt;br /&gt;% The fully-qualified domain name in the certificate will be: CORP-ASA&lt;br /&gt;&lt;br /&gt;% Include the device serial number in the subject name? [yes/no]: no&lt;br /&gt;&lt;br /&gt;Request certificate from CA? [yes/no]: yes&lt;br /&gt;% Certificate request sent to Certificate Authority&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;2) привязываем свой сертификат к интерфейсу&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;(config)# ssl trust-point ASA inside&lt;br /&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-7972399395312172537?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/10/asa-change-httpsasdm-certificate.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-7829349077338801903.post-4036046008144213470</guid><pubDate>Tue, 20 Oct 2009 05:27:00 +0000</pubDate><atom:updated>2009-10-20T08:32:23.656+03:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>cisco</category><category domain='http://www.blogger.com/atom/ns#'>asa</category><category domain='http://www.blogger.com/atom/ns#'>qos</category><title>ASA QoS</title><description>проводя курс на асе с прошивкой 8.2, заметил некоторые изменения в списке доступных действий MPF layer3/4 policy-map:&lt;br /&gt;&lt;blockquote&gt;&lt;pre&gt;&lt;br /&gt;ASA-CO2(config)# policy-map test&lt;br /&gt;ASA-CO2(config-pmap)# class class-default&lt;br /&gt;ASA-CO2(config-pmap-c)# ?            &lt;br /&gt;&lt;br /&gt;MPF policy-map class configuration commands:&lt;br /&gt; csc             Content Security and Control service module&lt;br /&gt; exit            Exit from MPF class action configuration mode&lt;br /&gt; flow-export     Configure filters for NetFlow events     &lt;br /&gt; help            Help for MPF policy-map class/match submode commands&lt;br /&gt; inspect         Protocol inspection services&lt;br /&gt; ips             Intrusion prevention services&lt;br /&gt; no              Negate or set default values of a command&lt;br /&gt; police          Rate limit traffic for this class&lt;br /&gt; priority        Strict scheduling priority for this class&lt;br /&gt; quit            Exit from MPF class action configuration mode&lt;br /&gt; service-policy  Configure QoS Service Policy&lt;br /&gt; set             Set connection values&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;  shape           Traffic Shaping&lt;/span&gt;&lt;br /&gt;ASA-CO2(config-pmap-c)# shape ?&lt;br /&gt;&lt;br /&gt;mpf-policy-map-class mode commands/options:&lt;br /&gt; average  configure token bucket: CIR (bps) [Bc (bits)], send out Bc only per&lt;br /&gt;          interval&lt;br /&gt;ASA-CO2(config-pmap-c)# shape average ?&lt;br /&gt;&lt;br /&gt;mpf-policy-map-class mode commands/options:&lt;br /&gt; &lt;64000-154400000&gt;  Target Bit Rate (bits per second), the value needs to be&lt;br /&gt;                  multiple of 8000&lt;br /&gt;ASA-CO2(config-pmap-c)# shape average 200000 ?&lt;br /&gt;&lt;br /&gt;mpf-policy-map-class mode commands/options:&lt;br /&gt; &lt;2048-154400000&gt;  bits per interval, sustained. Needs to be multiple of 128.&lt;br /&gt;                   Recommend not to configure it, the algorithm will find out&lt;br /&gt;                   the best value&lt;br /&gt;&lt;cr&gt;&lt;br /&gt;ASA-CO2(config-pmap-c)# shape average 200000&lt;br /&gt;ASA-CO2(config-pmap-c)#&lt;/cr&gt;&lt;/pre&gt;&lt;/blockquote&gt;&lt;br /&gt;на асах наконец-то появился шейпинг! :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7829349077338801903-4036046008144213470?l=blog.invalid.org.ua' alt='' /&gt;&lt;/div&gt;</description><link>http://blog.invalid.org.ua/2009/10/asa-mpf.html</link><author>noreply@blogger.com (invalidCCIE)</author><thr:total>2</thr:total></item></channel></rss>