Skip to main content

Cisco IOU and VMware vSwitch

I have been looking around the interweb seeing Cisco IOU kicking around,I began to wonder how you could integrate this into an environment where you can build a lab with connections to external devices. e.g Firewalls, ACS server, other vendor routers etc. Particularly how would I build a test environment assuming that I could legitimately use IOU.  Anyway after looking a the article I could how this could be done with a physical machine, but how would this relate to an IOU machine in ESX Vmware. I would have multiple NICs tied to different VLANS, then use IOU2Net to connect interfaces in IOU to these different network; easy!!!

So as I sit back and dream of what could be if Cisco would release a version that I could be use in such a way, I realized a problem. "promiscuous mode" - this is require for traffic to traverse from the real work back into the IOU instance, however if you add new NICs to a vSwitch in ESX then the default is to have "promiscuous mode" rejected.

So in essence here is a tip based on theory. If you are building a IOU environment in ESX then enable "promiscuous mode".

If any one can validate this theory then please post in the comments.



Popular posts from this blog

ASR1006 Dual Route Processors Password Recovery - Tip

I recently ran into an issue when trying to perform dual route processors password recovery on a Cisco  ASR1006
After breaking into rommon mode and using confreg to ignore the startup configuration, during the rest the ASR1006 loaded the startup configuration!!!!!!!!
So quick and simple, I pulled one of the RP and preformed password recovery running on a single RP. All went according to the Cisco documentation

After the system running on a single RP was recovered and fully booted I waiting for 5 minutes just to be sure; then I inserted the second RP and allowed everything to sync up.

All was well again :) phew

Note: The system was previously fully functioning with dual RPs; a configuration error was made during Tacacs+ configuration which resulted in lockout.

I hit an issue recovering and ASR with dual RPs, so rather that spending hour researching, I decided very quickly to go …

Where are all the AAA and PKI solutions gone for Dot1x

More Question than answers
(This series will be based on an enterprise with >20,000 dot1x devices)

I have been looking into dot1x authentication for Wired and Wireless devices based on device identity using x.509 Certificates. While I understand PKI, AAA, PEAP and sorts I had never really had the opertunity to bring these technologies together. I quickly found out that despite this stuff being around for years,  it was difficult to answer the following questions:

Which PKI solution should I use?
Which AAA solution should I use?
How to setup the PKI solution?
Does the PKI server need to be part of AD?
What if the clients are not in AD e.g. Wireless Tablets?
How do I issue certificates for devices?
How to configure the devices (wired and wireless)?
What AAA server do I use?
How do configure the rules and policies and identify clients?

What are the answers?
I am going to kick off a series here at that tries to address the question above; I have limited time but hopefully I can …

Dell Latitude D830 SSD Upgrade

Slow Laptop Syndrome
I have a LATITUDE D830 : INTEL CORE 2 DUO T7500 4GB Ram from 2008, I did get a fairly high specification at the time, so it has always had pretty decent performance. However I haven't been using it for a while and when I did it seemed slow compared to my Core 5i desktop computer. (I use Windows 7 ultimate with the latest updates)

Laptop for Work
Now I might be doing a fair bit of travelling to customer sites in the near future and the last thing I want is a poorly performing Laptop, so I decide to ditch all the crap I had on it like iTunes, movies, miscellaneous software and cut back to a basic "work" PC. After all I do have iPhone, iPad and new kindle (soon) for all my multi media needs.

I purchased a "Corsair 120GB Force 3 SSD 2.5" SATA-III 6Gb/s Read = 550MB/s, Write = 510MB/s" from Now I am guessing that SATA-II rather that SATA-III on the system board, but the price difference between SATA-II and SATA-III was nothing …