Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I'm having a very strange issue with a 3850 right now. We use 3850's as building routers on campus. Each building gets its own 3850 and then there is a variety of 4500, 2960X and 9300 switches deployed for layer 2. On each 3850 we have the traffic se...
We do most device builds by template here. We recently have been rolling out tacacs and when following our template build, we get an error in the accounting lines in the vty config. Please see below: aaa config from template:aaa new-modelaaa authenti...
Hi, I have remote access setup for faculty, staff and students using FMC/FTD,FXOS and I am curious if there is a better way to accomplish an objective. For example, we have a server support team (SAS) that want to tunnel traffic to certain subnets wh...
Hey all, have a couple of design questions. I have one group on campus asking for "jumbo frame support" for their servers. In our campus network, each building has a router and multiple switches. That building router uplinks to distribution.
I ask...
Title pretty much says it all. If I set up a mon cap on a 4500-x or 3850, and specify both on the interface, I only see dns queries, I never see any dns responses. It's not clear to me why I don't see the dns responses. In this example, we have a bui...
I seem to have fixed this issue. I added an additional rp-address command for the target vrf using the ip of the rp for the source vrf and appended the acl to it:i.e.ip pim vrf Dist rp-address x.x.x.x MCAST-GRPI can now run vrf based pim show command...
Thanks for the input. The challenge was not so much to separate students from faculty, but to have a different split tunnel acl based on source ip address.
Thank you for the reply. We do not have ISE, unfortunately. We do have FreeRADIUS. But the hope was to avoid two connection profiles for each of these situations. It sounds like we would still have needed that anyway.
Did some testing with a dev 3850 L3 connected to our distribution. I tried setting the ip mtu on the point to point vlans to 1500, saved config, then did a system mtu 9198 command. The mtu for the point to points is overwritten at this point and ospf...