<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: ERS 8600 Access Policy</title>
	<atom:link href="http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/</link>
	<description>technology, networking and IP telephony</description>
	<lastBuildDate>Tue, 07 Feb 2012 12:06:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Michael McNamara</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-2396</link>
		<dc:creator>Michael McNamara</dc:creator>
		<pubDate>Wed, 28 Jul 2010 21:23:16 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-2396</guid>
		<description>Hi Marc,

Well something needs to be wrong somewhere. Have you tried restarting the switch? You might have a corrupt file, so you might need to delete the file p80c3717.img and then re-upload it to the switch. 

You should see the 3DES file loaded from a &#039;config info&#039; like so (this was run from a 5.1.2.0 software);

&lt;pre&gt;ERS-8610:6# config info

Sub-Context: clear config dump monitor mplsping mplstrace peer show switchover test trace wsm asfm sam
Current Context:

        load-encryption-module : 3DES File p80c5120.img
                       setdate : N/A
           mac-flap-time-limit : 500
            auto-recover-delay : 30
&lt;/pre&gt;

Good Luck!</description>
		<content:encoded><![CDATA[<p>Hi Marc,</p>
<p>Well something needs to be wrong somewhere. Have you tried restarting the switch? You might have a corrupt file, so you might need to delete the file p80c3717.img and then re-upload it to the switch. </p>
<p>You should see the 3DES file loaded from a &#8216;config info&#8217; like so (this was run from a 5.1.2.0 software);</p>
<pre>ERS-8610:6# config info

Sub-Context: clear config dump monitor mplsping mplstrace peer show switchover test trace wsm asfm sam
Current Context:

        load-encryption-module : 3DES File p80c5120.img
                       setdate : N/A
           mac-flap-time-limit : 500
            auto-recover-delay : 30
</pre>
<p>Good Luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: marc</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-2386</link>
		<dc:creator>marc</dc:creator>
		<pubDate>Wed, 28 Jul 2010 10:07:00 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-2386</guid>
		<description>Hello

Will you help me?
I&#039;ve got a problem with the module on a passport 3DES 8010.
My image p80c37170.img, unable to load the software.

I can not load module 3DES.
In my logs I get the message:
SW ERROR Dynamic loading of 3DES encryption module failed, Module IS Already loaded.

I do not see the module to load when I type the command &quot;config info&quot; and when I run the SSH command he replied &quot;no matching cipher found&quot;.

All this worked well on other passport with the same software.

Do you have an answer to this problem?

Regards.</description>
		<content:encoded><![CDATA[<p>Hello</p>
<p>Will you help me?<br />
I&#8217;ve got a problem with the module on a passport 3DES 8010.<br />
My image p80c37170.img, unable to load the software.</p>
<p>I can not load module 3DES.<br />
In my logs I get the message:<br />
SW ERROR Dynamic loading of 3DES encryption module failed, Module IS Already loaded.</p>
<p>I do not see the module to load when I type the command &#8220;config info&#8221; and when I run the SSH command he replied &#8220;no matching cipher found&#8221;.</p>
<p>All this worked well on other passport with the same software.</p>
<p>Do you have an answer to this problem?</p>
<p>Regards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dophilin</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-1432</link>
		<dc:creator>dophilin</dc:creator>
		<pubDate>Tue, 10 Nov 2009 06:39:47 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-1432</guid>
		<description>Hi Michael

This is the first policy

sys access-policy policy 1 disable
sys access-policy policy 1 service ftp enable

I finally got the root cause of this issue. Someone changed the security name of community and that&#039;s why the original community strings couldn&#039;t match default groups for SNMPv1/v2. 

Thanks for your kind help and advices.</description>
		<content:encoded><![CDATA[<p>Hi Michael</p>
<p>This is the first policy</p>
<p>sys access-policy policy 1 disable<br />
sys access-policy policy 1 service ftp enable</p>
<p>I finally got the root cause of this issue. Someone changed the security name of community and that&#8217;s why the original community strings couldn&#8217;t match default groups for SNMPv1/v2. </p>
<p>Thanks for your kind help and advices.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael McNamara</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-1431</link>
		<dc:creator>Michael McNamara</dc:creator>
		<pubDate>Tue, 10 Nov 2009 01:39:52 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-1431</guid>
		<description>In your example you were configuring the second rule. What was the first access policy rule?

That rule might be blocking you. I believe you can show the statistics of how many time each rule is fired or triggered although I can&#039;t remember the command right now.

Cheers!</description>
		<content:encoded><![CDATA[<p>In your example you were configuring the second rule. What was the first access policy rule?</p>
<p>That rule might be blocking you. I believe you can show the statistics of how many time each rule is fired or triggered although I can&#8217;t remember the command right now.</p>
<p>Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dophilin</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-1429</link>
		<dc:creator>dophilin</dc:creator>
		<pubDate>Tue, 10 Nov 2009 01:32:07 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-1429</guid>
		<description>Hi Maicael

Thanks for your advices. I could access ERS8600 when I disabled the access policy and the global SNMP access is enabled from bootconfig flags. So, I am wondering what else I should setup for SNMP access with access policy.

Regards</description>
		<content:encoded><![CDATA[<p>Hi Maicael</p>
<p>Thanks for your advices. I could access ERS8600 when I disabled the access policy and the global SNMP access is enabled from bootconfig flags. So, I am wondering what else I should setup for SNMP access with access policy.</p>
<p>Regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael McNamara</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-1428</link>
		<dc:creator>Michael McNamara</dc:creator>
		<pubDate>Tue, 10 Nov 2009 01:20:20 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-1428</guid>
		<description>Hi dophilin,

If you disable the access policy can you access the switch via SNMP? This will help you determine if the problem is with the access policy or if the problem lies in your SNMP configuration.

You might want to make sure that someone hasn&#039;t disabled SNMP globally from the bootconfig flags. You can check that by issuing a &quot;show config bootconfig flags&quot; command.

You might want to post the specific details of your problem over on the forums;  &lt;a href=&quot;http://forums.networkinfrastructure.info/nortel-ethernet-switching/&quot; rel=&quot;nofollow&quot;&gt;http://forums.networkinfrastructure.info/nortel-ethernet-switching/&lt;/a&gt;

Good Luck!</description>
		<content:encoded><![CDATA[<p>Hi dophilin,</p>
<p>If you disable the access policy can you access the switch via SNMP? This will help you determine if the problem is with the access policy or if the problem lies in your SNMP configuration.</p>
<p>You might want to make sure that someone hasn&#8217;t disabled SNMP globally from the bootconfig flags. You can check that by issuing a &#8220;show config bootconfig flags&#8221; command.</p>
<p>You might want to post the specific details of your problem over on the forums;  <a href="http://forums.networkinfrastructure.info/nortel-ethernet-switching/" rel="nofollow">http://forums.networkinfrastructure.info/nortel-ethernet-switching/</a></p>
<p>Good Luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dophilin</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-1427</link>
		<dc:creator>dophilin</dc:creator>
		<pubDate>Tue, 10 Nov 2009 00:30:53 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-1427</guid>
		<description>Hi Michael

I have a question about access policy for SNMP. The configuration below is the access policy on an ERS8600 and I also changed the default community to new one. But, I still can&#039;t use SNMPv1/v2 to get data from ERS8600. Could you please let me know what I might miss ?

Thanks

sys access-policy policy 2 create
sys access-policy policy 2 accesslevel rwa 
sys access-policy policy 2 name &quot;mgmt access&quot; 
sys access-policy policy 2 precedence 1 
sys access-policy policy 2 network 172.16.0.0/16
sys access-policy policy 2 service snmpv3 enable
sys access-policy policy 2 service telnet enable
sys access-policy policy 2 service tftp enable
sys access-policy policy 2 snmp-group-add readgrp snmpv1
sys access-policy policy 2 snmp-group-add readgrp snmpv2c
sys access-policy policy 2 snmp-group-add v1v2grp snmpv1
sys access-policy policy 2 snmp-group-add v1v2grp snmpv2c</description>
		<content:encoded><![CDATA[<p>Hi Michael</p>
<p>I have a question about access policy for SNMP. The configuration below is the access policy on an ERS8600 and I also changed the default community to new one. But, I still can&#8217;t use SNMPv1/v2 to get data from ERS8600. Could you please let me know what I might miss ?</p>
<p>Thanks</p>
<p>sys access-policy policy 2 create<br />
sys access-policy policy 2 accesslevel rwa<br />
sys access-policy policy 2 name &#8220;mgmt access&#8221;<br />
sys access-policy policy 2 precedence 1<br />
sys access-policy policy 2 network 172.16.0.0/16<br />
sys access-policy policy 2 service snmpv3 enable<br />
sys access-policy policy 2 service telnet enable<br />
sys access-policy policy 2 service tftp enable<br />
sys access-policy policy 2 snmp-group-add readgrp snmpv1<br />
sys access-policy policy 2 snmp-group-add readgrp snmpv2c<br />
sys access-policy policy 2 snmp-group-add v1v2grp snmpv1<br />
sys access-policy policy 2 snmp-group-add v1v2grp snmpv2c</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael McNamara</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-1285</link>
		<dc:creator>Michael McNamara</dc:creator>
		<pubDate>Tue, 22 Sep 2009 16:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-1285</guid>
		<description>Hi Justin,

Glad to hear you figured it out!

Cheers!</description>
		<content:encoded><![CDATA[<p>Hi Justin,</p>
<p>Glad to hear you figured it out!</p>
<p>Cheers!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Di Tomaso</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-1284</link>
		<dc:creator>Justin Di Tomaso</dc:creator>
		<pubDate>Tue, 22 Sep 2009 14:00:09 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-1284</guid>
		<description>Ignore my last, I cracked it by some additional policy statements on my trusted ip&#039;s plus restricting the default policy, thanks</description>
		<content:encoded><![CDATA[<p>Ignore my last, I cracked it by some additional policy statements on my trusted ip&#8217;s plus restricting the default policy, thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Di Tomaso</title>
		<link>http://blog.michaelfmcnamara.com/2008/01/ers-8600-access-policy/#comment-1282</link>
		<dc:creator>Justin Di Tomaso</dc:creator>
		<pubDate>Tue, 22 Sep 2009 09:37:11 +0000</pubDate>
		<guid isPermaLink="false">http://maddog.mlhs.org/blog/2008/01/ers-8600-access-policy/#comment-1282</guid>
		<description>Thanks for the info Michael which pretty much mirrors what I&#039;m trying to set up, in allowing only access via 2 hosts. The problem I&#039;m having is loss of Device Manager, how does these settings sit with the default policy? I mean I want to only allow any connectivity from 2 ip addresses and deny everything else - will invoking the 2 policies for the two addresses automatically deny all other ips? I can provide a config if you like</description>
		<content:encoded><![CDATA[<p>Thanks for the info Michael which pretty much mirrors what I&#8217;m trying to set up, in allowing only access via 2 hosts. The problem I&#8217;m having is loss of Device Manager, how does these settings sit with the default policy? I mean I want to only allow any connectivity from 2 ip addresses and deny everything else &#8211; will invoking the 2 policies for the two addresses automatically deny all other ips? I can provide a config if you like</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Served from: blog.michaelfmcnamara.com @ 2012-02-08 16:38:33 by W3 Total Cache -->
