2013年7月17日星期三

WAN router bandwidth usage

Question:

Need some help to figure out Cisco 3560 Switch the bandwidth usage for the WAN router f2/0 interface, sending you what we have from this interface

30 second input rate 881000 bits/sec, 296 packets/sec
30 second output rate 395000 bits/sec, 292 packets/sec
1297322378 packets input, 1616261346 bytes
Received 59127 broadcasts, 0 runts, 0 giants, 0 throttles

Answer:

If you want to validate the speed of the link transmit and receive at the time you take the sample, you should only check the following lines:

30 second input rate 2952000 bits / sec, 555 packets / sec
30 second output rate 479000 bits / sec, 470 packets / sec


Here you should not add or subtract anything. As I mentioned earlier in a FastEthernet link in full duplex mode, the transmission is independent (30 seconds output rate) incoming (30 seconds input rate).

These statistics are based on bits per second as this is handled in terms of transmission in data networks.

For the snapshot you send you:

30 second input rate 2952000 bits / sec, 555 packets / sec
30 second output rate 479000 bits / sec, 470 packets / sec

That is for you reception: 2952000 bits / sec,

so if you want to refer this value in kilobits divide by 1000 and you have:
2952000/1000 = 2952 kbps

if you want to refer this value in megabits divide between 1000000 and have:
2952000/1000000 = 2.952 Mbps

Importantly, as the point referring transmission rates in data networks (x Gbps Mbps x, x Kbps, x bps) that are expressed in terms of bits, as opposed to storage that is expressed in terms of Bytes (Gbytes, Mbytes, Kbytes, bytes). It is also important to note that the second character of the velocity:

xbps = second character is "b" in lower case that which be interpreted as bits. "x" or first character can be G, g, M,m,K,k, or not exist if the rate is expressed in bits.
There are statistical tools that add these two values:
Input Ouput rate + rate to generate a total, but personally I'm not decuerdo with this and usually do not use this type of graph. Prefer separate or overlapping graphs.

Important

There are statistical tools that add these two values:

Input Ouput rate + rate to generate a total, but personally I'm not decuerdo with this and usually do not use this Cisco 3560 type of graph. Prefer separate or overlapping graphs.

Stumped - 871W home network config. pages not loading?

Question:

Hi i have a really simple WS-C3560X-48P-L  home network setup using the Cisco 871W 4-Port 10/100 Wireless G Router (CISCO871W-G-A-K9). I can't figure out for the life of me what is going on. Web pages seem to "half load" sometimes (netflix, facebook, bank of america doesn't load at all, etc). It doesn't always happen. Sometimes the pages will load fine. I have tested with multiple computers so I know that it is the router itself. Below is my configuration. Please ignore anything regarding the wifi. I know that isn't set up correctly. I'll deal with that later. I wanted to see if i was missing anything. Config is really basic. Attached is what one of the "half loading" web pages looks like

!
version 12.4
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname MyRouter
!
boot-start-marker
boot-end-marker
!
logging buffered 51200 warnings
enable secret 5 blahblahblahblah
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization exec default local
!
!
aaa session-id common
!
crypto pki trustpoint TP-self-signed-1608398951
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1608398951
revocation-check none
rsakeypair TP-self-signed-1608398951
!
!
crypto pki certificate chain TP-self-signed-1608398951
certificate self-signed 01
  ZX82X252 ZX82X1BB AXXZX2X1 X2X2X1X1 ZXXDX6X9 2A864886 F7XDX1X1 X4X5XXZX
  Z1Z12FZX 2DX6XZ55 X4XZ1Z26 494F5Z2D 5Z656C66 2D5Z6967 6E65642D 4Z657274
  6966696Z 6174652D Z1Z6ZXZ8 ZZZ9Z8Z9 Z5Z1ZX1E 17XDZXZ2 ZXZZZXZ1 ZXZ1Z4Z2
  ZXZZ5A17 XDZ2ZXZX Z1ZXZ1ZX ZXZXZXZX ZX5AZXZ1 Z12FZX2D X6XZ55X4 XZ1Z2649
  4F5Z2D5Z 656C662D 5Z69676E 65642D4Z 65727469 66696Z61 74652DZ1 Z6ZXZ8ZZ
  Z9Z8Z9Z5 Z1ZX819F ZXXDX6X9 2A864886 F7XDX1X1 X1X5XXXZ 818DXXZX 8189X281
  81XXB9FX ZCEB6492 27Z78Z9F BZ5C8ZEF 9EB81B52 FB4F1Z51 A5AC8B5E 5ZAXFXB8
  5911CCB9 EC5A22C1 5X98C2E8 ZCE17DED 121B224X 57B95C2C A4Z827Z7 4967FZ49
  8681456F 175668F9 AC12BA6B 19A55718 FBFZ2DA2 914C1CFF 88766ZA5 XA1AXEDF
  81DC49DC 4D2Z29F4 ZBZ69555 ZDZZ22X9 41DC6A57 X28ZD8B6 15ADB5F9 6F617FXE
  569FX2XZ X1XXX1AZ 7AZX78ZX XFX6XZ55 1D1ZX1X1 FFX4X5ZX XZX1X1FF ZX25X6XZ
  551D11X4 1EZX1C82 1A4B4Z69 7A7A6C65 4Z697Z6Z 6F2E6B6Z 697A7A6C 652E6C6F
  6Z616CZX 1FX6XZ55 1D2ZX418 ZX168X14 18FZ6CBZ 1DZ7F684 661ZE559 FF7CE7BX
  24DB22B4 ZX1DX6XZ 551DXEX4 16X41418 FZ6CBZ1D Z7F68466 1ZE559FF 7CE7BX24
  DB22B4ZX XDX6X92A 864886F7 XDX1X1X4 X5XXXZ81 81XX28Z5 8CC9Z7AB 4D49DB5Z
  AZBDXCBX E2E6A8CE 27CCZ9AB 52C469EA 45C5B2Z6 68X82572 72AX1C58 F6C4D76B
  2A21E4X6 1E5BC585 72ZEX9B6 2917D89F 95DZXFE5 FCDXF428 ACC7ZZ44 Z4E2CDZE
  8EXFB92A 6E26F29A B6778B4Z 5ACB1946 D826AEF6 8EZ96X7A X6B6AEA2 X7CXACZ7
  X6E2C98X D76DZ588 CF55D966 94X2745C XAXCAF65 ED71
            quit
dot11 syslog
!
dot11 ssid MyWiFi
   authentication open
   authentication key-management wpa
   guest-mode
   wpa-psk ascii 7 blahblahblahblhabhab
!
ip cef
!
!
no ip dhcp use vrf connected
ip dhcp excluded-address 1.1.2.1 1.1.2.99
!
ip dhcp pool 1.1.2.0/24
   network 1.1.2.0 255.255.255.0
   default-router 1.1.2.1
   dns-server 1.1.2.5
   lease 7
!
!
ip domain name mydomain.local
ip host desktop 1.1.2.14
ip name-server 1.1.2.5
!
multilink bundle-name authenticated
!
!
username admin privilege 15 secret 5 blahblahblahblah
!
!
archive
log config
  hidekeys
!
!
!
!
!
interface FastEthernet0
!
interface FastEthernet1
!
interface FastEthernet2
!
interface FastEthernet3
!
interface FastEthernet4
description INTERNET WAN PORT
mac-address 0000.1111.2222
ip address dhcp
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface Dot11Radio0
description Built-in Atheros miniPCI
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip flow ingress
no dot11 extension aironet
!
encryption mode ciphers aes-ccm
!
broadcast-key change 3600
!
speed basic-1.0 basic-2.0 basic-5.5 basic-6.0 basic-9.0 basic-11.0 basic-12.0 basic-18.0 basic-24.0 basic-36.0 basic-48.0 basic-54.0
channel 2412
station-role root
no cdp enable
!
interface Vlan1
description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$
ip address 1.1.2.1 255.255.255.0
ip nat inside
ip virtual-reassembly
ip tcp adjust-mss 1452
!
ip forward-protocol nd
!
!
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list ACL-NAT interface FastEthernet4 overload
!
ip access-list extended ACL-NAT
permit ip 1.1.2.0 0.0.0.255 any
!
no cdp run
!
!
!
!
control-plane
!
banner motd
#################################################################
# My Router
# GET THE F OUT.
# Unauthorized Access Is Prohibited!!!
#
# Love,
# Me
#
#################################################################

!
line con 0
exec-timeout 30 0
logging synchronous
no modem enable
line aux 0
line vty 0 4
exec-timeout 20 0
privilege level 15
password blahblah
logging synchronous
transport input telnet ssh
!
scheduler max-task-time 5000
end

Answer:


Wrong forum, post in "infrastructure - WAN and routing". You can move your post using the actions panel WS-C3560X-48P-S Price on the right.

2013年7月16日星期二

OSPF Multicast address

Question:

I was doing a small OSPF Lab Cisco 3560X Price in GNS3 with three routers in a single broadcast domain R1 (Router id 1.1.1.1 )is Drother, R2(2.2.2.2) is BDR and R3(3.3.3.3) is DR.

Now what i know is DR will lisen to Multicast IP 224.0.0.6 and will send the updates to others on Multicast IP 224.0.0.5

But my output is wierd when iam lloking in to ospf debug packets in R1 (DROTHER)

It is sending hello on 224.0.0.5 I am unable to get it. Somebody out there can u help me better understand this

R1#debug ip ospf events
R1#
*Mar  1 00:28:46.891: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:28:48.579: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:28:48.583: OSPF: End of hello processing
R1#
*Mar  1 00:28:53.467: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:28:53.471: OSPF: End of hello processing
R1#
*Mar  1 00:28:56.103: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:28:58.071: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:28:58.075: OSPF: End of hello processing
R1#
*Mar  1 00:29:02.615: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:29:02.619: OSPF: End of hello processing
R1#
*Mar  1 00:29:05.867: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:29:07.435: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:29:07.439: OSPF: End of hello processing
R1#
*Mar  1 00:29:12.267: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:29:12.267: OSPF: End of hello processing
R1#
*Mar  1 00:29:15.039: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:29:17.371: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:29:17.375: OSPF: End of hello processing
R1#
*Mar  1 00:29:21.711: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:29:21.715: OSPF: End of hello processing
R1#
*Mar  1 00:29:24.227: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:29:26.767: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:29:26.771: OSPF: End of hello processing
R1#
*Mar  1 00:29:31.291: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:29:31.295: OSPF: End of hello processing
R1#
*Mar  1 00:29:33.563: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:29:35.911: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:29:35.911: OSPF: End of hello processing
R1#
*Mar  1 00:29:40.799: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:29:40.803: OSPF: End of hello processing
R1#
*Mar  1 00:29:42.587: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:29:45.007: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:29:45.011: OSPF: End of hello processing
R1#
*Mar  1 00:29:50.411: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:29:50.415: OSPF: End of hello processing
R1#
*Mar  1 00:29:52.191: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:29:54.067: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:29:54.071: OSPF: End of hello processing
R1#
*Mar  1 00:29:59.847: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:29:59.851: OSPF: End of hello processing
R1#
*Mar  1 00:30:01.271: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:30:03.279: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:30:03.283: OSPF: End of hello processing
R1#
*Mar  1 00:30:09.591: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:30:09.595: OSPF: End of hello processing
R1#
*Mar  1 00:30:11.003: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:30:13.079: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:30:13.083: OSPF: End of hello processing
R1#
*Mar  1 00:30:19.259: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:30:19.263: OSPF: End of hello processing
*Mar  1 00:30:20.107: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:30:22.539: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:30:22.543: OSPF: End of hello processing
R1#
*Mar  1 00:30:29.103: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:30:29.107: OSPF: End of hello processing
*Mar  1 00:30:29.471: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#
*Mar  1 00:30:32.323: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:30:32.327: OSPF: End of hello processing
R1#
*Mar  1 00:30:38.679: OSPF: Rcv hello from 3.3.3.3 area 0 from FastEthernet0/0 132.1.1.3
*Mar  1 00:30:38.683: OSPF: End of hello processing
*Mar  1 00:30:38.703: OSPF: Send hello to 224.0.0.5 area 0 on FastEthernet0/0 from 132.1.1.1
R1#u
*Mar  1 00:30:42.199: OSPF: Rcv hello from 2.2.2.2 area 0 from FastEthernet0/0 132.1.1.2
*Mar  1 00:30:42.203: OSPF: End of hello processing
R1#u all
All possible debugging has been turned off
R1#sh ip ospf ne
R1#sh ip ospf neighbor
Neighbor ID     Pri   State           Dead Time   Address         Interface
2.2.2.2           1   FULL/BDR        00:00:38    132.1.1.2       FastEthernet0/0
3.3.3.3           1   FULL/DR         00:00:35    132.1.1.3       FastEthernet0/0

Regards
Thanveer
"Everybody is genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is a stupid."     

Answer:

I'm not sure if there's any  OSPF debug command that shows the AllDRouter address in it's output.
But since it's gns3 and not a production network we can use debug ip packets:

R1(config)#access-list 100 permit ip any host 224.0.0.6
R1#debug ip packet 100
R1#debug ip ospf adj

Now we could wait for reliable flooding or just create a new OSPF link to trigger an update.

*Mar  1 00:40:34.211: OSPF: Interface Loopback0 going Up
*Mar  1 00:40:34.711: IP: s=132.1.1.1 (local), d=224.0.0.6 (FastEthernet0/0), len 96, sending broad/multicast
*Mar  1 00:40:34.715: OSPF: Build router LSA for area 0, router ID 1.1.1.1, seq 0x80000004
*Mar  1 00:40:34.779: OSPF: Rcv LS UPD from 3.3.3.3 on FastEthernet0/0 length 76 LSA count 1
*Mar  1 00:40:42.371: OSPF: Rcv LS UPD from 3.3.3.3 on FastEthernet0/0 length 64 LSA count 1
*Mar  1 00:40:44.875: IP: s=132.1.1.1 (local), d=224.0.0.6 (FastEthernet0/0), len 64, sending broad/multicast


Another way with gns3 is Cisco 3560X  to use Wireshark.

2013年7月15日星期一

Internet access for users in remote location

Question:

i configured MPLS vpn for remote Catalyst Switches Price locations using cisco 881 at remote side and cisco 2811 on our head-office side with a ip vpn service provider.

the remote user is able to access head office network.

now the problem is he needs internet access, which i only know the way  is we have allow him to use head office internet connection or another MPLS vpn tunnel with service provider for internet connection which will be a huge cost.

whcih our office reluctent to give.

now i am looking for a way to get the internet traffic out from the modem connected to his router cisco 881 and the head- office traffic to go on MPLS vpn

now the traffice flow is like

remote user-------->cisco 881------>internet modem------------------>serivce provide netowrk----------------->head office(cisco 2811)----------->Servers



Any help will be highly appriciated

Answer:

sorry that i didn't say it clearly, you should ping 192.168.1.1 from remote user's computer only after you configure default route to internet (ip route 0.0.0.0 0.0.0.0 192.168.1.1) but not when tunnel is up.

for nat, TRY this out:

access-list 2000 deny ip any HO_net1
access-list 2000 deny ip any YOUR_HEAD_OFFICE_SUBNET2
access-list 2000 permit ip any any

interface FastEthernet4
ip nat outside
interface Vlan1
ip nat inside

ip nat inside source list 2000 interface FastEthernet4 overload

verify nat:

sh access-list

2013年7月14日星期日

Help configurating an 851 with PPPoE and DHCP


Question:

I write this because i'm Cisco 3560X  puzzling myself for a few days now trying to find a way to configure my 851 for home use.
My internet provider use PPPoE with PAP and althrough I found many configuration options they all are incomplete...or i cant find the logic behind those commands.
First of all I need to say what I need:
1. Configurate my int Fa4 (WAN) with pppoe so when i insert my ISP cable in it it will negotiate and take IP.
2. Configurate DHCP on LAN (Fa0-3) so that when I insert my PC it will take a fake IP.

Here is the place where i found some conf examples: http://www.cisco.com/en/US/docs/routers/access/800/850/software/configuration/guide/pppoenat.html and I have some questions:
1. MTU - Should I use the 1492 value or the "pppoe-client ppp-max-payload 1500"?
2. ip route 10.10.25.2 255.255.255.255 dialer 0 - How can i set an IP route when my connexion informations only come after i connect? (Because is PPPoE)???
3. I cant configurate the DHCP because I dont know the default route, I dont know the DNS, and i dont know the default gateway because I dont know them due to PPPoE !!!

Please help me because I dont know what to do whit it.

Answer:

The document you have referenced seems to have it wrong... You do not need any of the VPDN configured there, just a plain PPPoE client will do.

Your configuration should look as follows:

ip dhcp excluded-address 192.168.0.1 192.168.0.10
ip dhcp pool LAN
 import all
 network 192.168.0.0 255.255.255.0
 default-router 192.168.0.1
 lease 0 0 30
!
interface Vlan1
 ip address 192.168.0.1 255.255.255.0
 ip nat inside
 ip tcp adjust-mss 1452
!
interface FastEthernet 4
 pppoe-client dial-pool-number 1
!
interface Dialer 0
 encapsulation ppp
 dialer pool 1
 ppp pap sent-username YOURLOGIN password YOURPASSWORD
 ip mtu 1492
 ip address negotiated
 ip nat outside
!
ip route 0.0.0.0 0.0.0.0 Dialer0
!
access-list 1 permit 192.168.0.0 0.0.0.255
ip nat inside source list 1 interface Dialer0 overload

To your questions:

1. MTU - Should I use the 1492 value or the "pppoe-client ppp-max-payload 1500"?

Use the ip tcp adjust-mss on your Vlan1 interface, and the ip mtu 1492 on your Dialer0 interface as I already indicated in my configuration example.

2. ip route 10.10.25.2 255.255.255.255 dialer 0 - How can i set an IP  route when my connexion informations only come after i connect? (Because  is PPPoE)???

You do not need to set up this kind of routing. Your own interface address will be assigned to you automatically after the PPP link comes up (thanks to the ip address negotiated command on Dialer0). You only set up the default route statically - ip route 0.0.0.0 0.0.0.0 Dialer0 which does not use any particular address information, just tells the router to send anything through the Dialer0 interface.

3. I cant configurate the DHCP because I dont know the default route, I  dont know the DNS, and i dont know the default gateway because I dont  know them due to PPPoE !!!

Not entirely. The gateway for your stations is the router itself, and in my example, I have assigned it the IP address 192.168.0.1, so this is the gateway. You are correct with the DNS, however, your provider will assign you these addresses during PPP link negotiation and you will automatically import them into the DHCP configuration thanks to the import all command. If this does not work then certainly, your ISP uses a stable set of DNS servers. He should be able to tell you their exact addresses and then we can configure them statically in your DHCP configuration.

Test this configuration please and let Catalyst 3560 Price me know if it worked. Thanks!

2013年7月3日星期三

c3825 BGP ASN 32bit


Question:

I have a router cisco c3825 WS-C3750X-48PF-S Price with 256mb of ram and 64mb of flash memory.

I need to setup a bgp instance but our asn it's in the new format (32bit).

Can someone help me to understand what ios version support this ASN ?

Now, the router running c3825-adventerprisek9-mz.124-25g.bin

Answer:

Support on the 3800 platform was WS-C3750X-48PF-L introduced with Release 12.4(24)T. See the link below for details:

Active/Active, multi homed BGP, dual router , HSRP config


Question:

I have
Active/Active, multi homed BGP, WS-C3560X-24T-S Price dual router , HSRP config on LAN,  Now I want to  change the HSRP priority to avoid one extra hop in case one ISP fails, I want to use the EEM feature instead of IP SLA  which I am currently using But It’s the first time I am trying to use this,
Can you guys help me to find whether my EEM config is good enough to achieve what I am trying to achieve or I need to make some changes to this config

ISP1

event manager applet track-bgp-down

event syslog pattern "%BGP-5-ADJCHANGE: neighbor 10.10.10.17 Down BGP Notification sent"
action 1.0 syslog priority critical msg "EBGP Session to peer is down"
action 2.0 cli command "enable"
action 3.0 cli command "conifg t"
action 4.0 cli command "FastEthernet0/1.90"
action 5.0 cli command " standby 12 priority 85 "
action 6.0 cli command "end"

event manager applet track-bgp-up

event syslog pattern "%BGP-5-ADJCHANGE: neighbor 10.10.10.17 Up"
action 1.0 syslog priority critical msg "EBGP Session to peer is up"
action 2.0 cli command "enable"
action 3.0 cli command "conifg t"
action 4.0 cli command "FastEthernet0/1.90"
action 5.0 cli command " standby 12 priority 110 "
action 6.0 cli command "end"

ISP2

event manager applet track-bgp-down

event syslog pattern "%BGP-5-ADJCHANGE: neighbor 20.20.20.41 Down BGP Notification sent"
action 1.0 syslog priority critical msg "EBGP Session to peer is down"
action 2.0 cli command "enable"
action 3.0 cli command "conifg t"
action 4.0 cli command "FastEthernet0/1.90"
action 5.0 cli command " standby 11 priority 85 "
action 6.0 cli command "end"

event manager applet track-bgp-up

event syslog pattern "%BGP-5-ADJCHANGE: neighbor 20.20.20.41 Up"
action 1.0 syslog priority critical msg "EBGP Session to peer is up"
action 2.0 cli command "enable"
action 3.0 cli command "conifg t"
action 4.0 cli command "interface FastEthernet0/1.90"
action 5.0 cli command " standby 11 priority 110 "
action 6.0 cli command "end"

Answer:

You would probably get WS-C3560X-24T-S a better response to this one in the EEM scripting forum.