Cisco AAA/Identity/Nac :: ISE & 3750 Switch MAB Configuration
Jan 16, 2013
I am writting in response to MAB issue which I noticed a few days ago and I am still not able to undestand what exactly happend. First of all I would like to say that I configured MAB authentication and according to the MAC the ISE configure a VLAN. All worked well: the test computer can change VLAN based on its MAC. The problem appear when I cut the connection to ISE server. Accourding to configuration the switch authorize the new device to VLAN 11 (critical VLAN) That is fine ! When the ISE server is up again I had a configuration which should reauthorize all ports assign in critical VLAN. But why that is not happend ??? It looks as the switch didn't notice that the RADIUS (ISE) was up and working again. [code]
View 1 Replies
ADVERTISEMENT
Jan 10, 2012
I replaced an access switch 3750 with a switch 2960. Basically I just copy the whole config of the 3750 to 2960.
The 3750 use AAA, Crypto pki trustpoint TP-self-signed and radius-server host etc.
Now I can only telnet to 2960 but not SSH to it.
View 3 Replies
View Related
May 20, 2013
im trying to move the config from an 3750 to 3750 PoE but without using the PoE options.I have allready download the config with tftp and upload it to the 3750 PoE. Now the new config is stored on the PoE switch but some of the old setting are still there. Not sure why, i think the config only overwrite the settings which are in the conf file and the setting which are not in the conf file but enabled on it will stay on the switch.After the upload of the config file I deleted all the config I do not need by hand.They are some settings i can't delete and I don't know why, this are the sittings:
1. each fastethernet port has this option: "no cdp enabled" this entry was no availble on the old switch, is the any possiblity to remove this entry?
2. the same for "no mls qos rewrite ip dscp"
3 and for this one "vlan internal allocation policy ascending"
View 1 Replies
View Related
May 6, 2013
The access swtich is a Cisco 3750 and the Core switch is a Nexus 5000 series. I am configuring the switchport were the AP (3502) and WLC (5508) is connected below:
For AP: interface GigabitEthernetX/XX
switchport access vlan 244
switchport mode access
[Code]....
The WLC is connected to the Nexus switch and it is not accepting the 'mls qos trust cos' command.
View 3 Replies
View Related
Jul 27, 2011
We are using 3750 switches as WAN router facing the WAN cloud. To configure QoS for its WAN port, should I use 'auto qos voip trust" or treat it like a router port and configure class-maps, policy-maps, and attact service-policy input or output?
Because switches have different queuing and dropping methods than routers, auto qos can generate QoS configs that are considered most appropriate for 3750 switches. However the switch functions as WAN router. Maybe it should be configured using router type of QoS with policy-maps and service-policy?
View 9 Replies
View Related
Mar 29, 2011
I would like to make a centralized management of loggin account on my cisco switch (with a radius server). But, on Cisco 3750 E, i use 12.2(44) SE1 IOS and no command aaa authentication login exist.
Cisco 3750 can support other IOS than 12.2 who have this ability ?
View 2 Replies
View Related
Jul 4, 2012
I have a 3750 stack of 4 switches that was installed about 2 years ago. Recently I was doing some work on the switch and realized that I am unable to save the config. I amobviously concerned that if the power fails or the switch reboots I will be reconfiguring it and that is not something I am interested in doing!
Here is the error that I am receiving:
switch#copy run startup-config
Destination filename [startup-config]?
Building configuration.
View 11 Replies
View Related
Sep 28, 2011
I am trying to configure a trunk between the above two devices. I like to have vlan11 on ASA. Then I like to connect a host to my switch, and have it communicate with other devices in VLAN 11 or other vlans that reside on the ASA. Below is the config that I currently have.
ASA:
ciscoasa# show run interface Ethernet0/1
!
interface Ethernet0/1
[Code].....
View 5 Replies
View Related
Apr 17, 2012
I am uploading new configurations to my Cisco 3750 stacked switch and noticed that after the load I cannot log back into the switch because my password somehow was changed. After performing password recovery and getting back into the swtch, I noticed the configuration register was 0xF. I have never seen this before. The config-register command does not seem to be supported to change it back to factory default. The switch is on a ship which has several power hits when they switch power from shore to ship power.Can this cause the configuration register to change? What is the best way to change the configuration register?
View 1 Replies
View Related
Dec 20, 2012
I have stack of 2 switches 3750?I config etherchannel between them.
here is result
2 Po2(SD) LACP Fa1/0/15(I) Fa2/0/15(I)
Both ports are up up but standalone Int port channel 2 is down down.Need to know if this is default behaviour when we config etherchannel between stack switches?
View 2 Replies
View Related
Mar 6, 2013
I have a 2911 router connected to a 3750 switch. I have configured vlan interfaces on the 2911 router:I am using the vlan 89 (89.2) as the management ip address for me to remotely get to the switch. Is this a proper configuration or could this cause issues in the future.
View 4 Replies
View Related
Dec 13, 2011
boot system switch all flash:c3750-ipservicesk9-mz.122-55.SE1/c3750-ipservicesk9-mz.122-55.SE1.bin;flash:c3750-ipservices-mz.122-25.SEE2/c3750-ipservices-mz.122-25.SEE2.bin We have two stack of 3750 switches. When I enter above command getting below mentioned error, two images are showing switch 1, but one image only showing in switch 2, i.e 1st image in show boot command.
%Command to set boot system switch all flash:c3750-ipservicesk9-mz.122-55.SE1/c3750-ipservicesk9-mz.122-55.SE1.bin;flash:c3750-ipservices-mz.122-25.SEE2/c3750-ipservices-mz.122-25.SEE2.bin on switch=2 failed
View 5 Replies
View Related
May 29, 2013
Since Avaya phones do not run CDP, how does the phone know which DHCP pool to pull from to get its IP address if the PC is connected to the phone.
Let's say I have a interface config like this
interface gigabitethernet1/0/1
cisco3750(config-if)#switchport mode trunk
cisco3750(config-if)#switchport access vlan 126
[code]....
And two DHCP scopes configured on the switch. What keeps the phone from pulling from the wrong scope?
View 2 Replies
View Related
Dec 10, 2012
I am having the Cisco NAC enviroment (Software Version is 4.9.1) and OOB VG.
We are getting the below and attached Error while deploying on some machines.
"Invalid switch configuration-OOB Error:OOB client "mac/ip" not found."
Some users on same switches are working fine but some are not....
What would be the possibilities and any work around? other than keeping the port shudown for long time means that atleast 10 - 20 secs or more or a PC restart. Customer is not feeling comfortable with the current situation.
View 4 Replies
View Related
Nov 2, 2011
i have an issue to connect a trunk between cisco switch and extreme switch i have many vlans that i want to cross via a link between cisco 3750 switch and a Extreme Alpine 3800 switch
View 12 Replies
View Related
Nov 18, 2012
I have two 3750-X configured to be a stack and I am planning to re-rack these somewhere else. What I would like to know is what are the effects of having the master switch itself lose power? Does it immediately just make the member take over master (there should be no election since there are only 2 switches??) and there would be no loss of connectivity?
View 1 Replies
View Related
Nov 20, 2009
I have a Catalyst 4006 switch in production and a spare switch of same model. I have to quickly copy the configuration from production switch to spare switch (both L2 and L3 configurations) How do I do that?
View 6 Replies
View Related
Jan 4, 2012
I am struggling with configuring NPS AA for our 3750 array ... authentication and authorization. I tried almost every config i could find online but the most i got out of it is a simple authentication. What i need is quite simple: we have several AD groups.
1- Admin
2- Read only with few privileges for ping, show, trace route and telnet
I need my switches to be able to recognize the groups and assign them the correct priv. But it doesn't seem to be happening. Any clean config for the switch and for NPS ?
View 8 Replies
View Related
May 28, 2012
We have PC's that connect through the Siemens IP phones and back to the cisco 3750 which is connected to our core 6500 via L3. The phones use a voice VLAN and the PC's use another VLAN. The whole setup seems to work ok but I was just wondering if the QOS was configured correctly. Our current config on our 3750 switches are mls qos trust dscp on the port that connects to the phone and PC and mls qos trust dscp on the L3 links. The phones are configured for "QOS L2/L3"From the reading I've done so far it seems that any ports connected to a L2 device should be set to cos and not dscp?
View 16 Replies
View Related
Jun 16, 2011
I could do configuration of a VPLS in 3750, I have doubt about whether the configuration is similar to that of 7600, but is so I could recommend some document to observe the configuration.
View 1 Replies
View Related
May 17, 2011
I have an issue with connecting my OPTEMAN 100mb handoff to the 3750 ME ES ports. Because the ES ports will only accept gig connections, I am unable to use the ES ports.
Is there a work-around? It's too costly to have the OPTEMAN changed over to a GIG hand off and I really don't want to put in another piece of equipment to use the ES ports.
Is there a way to have the traffic flow into a 100mb port ont the 3750 and then over to the ES port?
View 2 Replies
View Related
Feb 27, 2012
When I upgraded my cisco 3750 ME from c3750me-i5k91-mz.122-46.SE to c3750me-i5k91-mz.122-58.SE2.bin all commands for radius disappeared? However, there are a lot of commands to ldap which was missing in the previous version. Seems as if the radius has disappeared and been replaced by ldap?
View 1 Replies
View Related
Mar 19, 2012
i have linksys modem which already running for differents vlans i cerated another different vlans 10 amd 20 for 10 and 20 i need internet how should i configure internet on another core switch3750
View 0 Replies
View Related
Aug 16, 2011
I have a WCS that I use to manage 8 controllers (2 WiSM's totaling 4 controllers, and 4 more controllers at remote locations). All controllers connect to 3750 switches. The layer three interfaces for all V LAN's that are related to the wireless network are created on these switches. Each layer three interface has a helper address that points the devices in the sub net to the correct DHCP server.
When a wireless device requests a DHCP request I believe it gets to that server based on the relay from the layer three interface on the 3750. However, I know that the virtual interface on the controller is also requesting an address because my firewall is flooded with deny statements. The virtual interface is configured for 1.1.1.1 and so it gets blocked. I am starting to question the use of this interface considering the fact that it is getting blocked and the clients are still getting address.
Are both interfaces trying to act as DHCP relays? Could I setup the controllers to be the only relay (without using the virtual interface)?
View 3 Replies
View Related
Oct 13, 2011
I've inherited a server running Ciscoworks LMS 4.0 to manage our plethora of switches. Running 'Configuration > Configuration Archive > Synchronization' against a Catalyst 3750 switch called switch1 successfully retrieved the Running, Startup, and VLAN configs.Running the same command the following day on switch1 failed and returned this in the job execution result:Unable to get results of job execution for device. Retry the job after increasing the job result wait time using the option:Admin > Collection Settings > Config > Config Job Timeout Settings I modified the job result wait time setting to be 600 seconds, tried again and received the same timeout failure. I have also seen this same Failed message on other devices, but have never actually received the configs for them, so I feel switch1 is a better place to start.What are the first things I should check in CiscoWorks for a problem like this? Is there a particular software revision I should be on with LMS 4.0? What timeout value should be used for Archive Synchronization?
View 1 Replies
View Related
Dec 29, 2011
I have a customer who used to own a 3750 with a older version of IOS. The switch he had used a three year old version of IOS which allowed him to browse to the switch IP and manage it via HTTP without entering a password at all. Now that he has a replacement switch with a new ver of IOS (since the previous switch died). We slapped the config on from the old switch but no matter what we do (understanding that new http aaa authentication commands were added) we cant get this thing to let him in without prompting him for a password. I understand this was an insecure config to begin with so I shouldn't be advocating using it in the first place, but this is what the customer wants.Basically what I'm trying to figure out is are we banging our heads into the wall for nothing as the "ip http server" will not allow an authentication method of "none" anyway? None of the offical documentation I have read for the http aaa authentication cmds shows this as an example nor have I found any blog posts on how to do it ether. Perhaps Cisco removed this by design.
Here is the config:
aaa new model
aaa authentication login default local
aaa authentication enable default none
aaa authentication login none none
ip http server
ip http authentication aaa login-authentication none
[code]....
View 1 Replies
View Related
Feb 24, 2013
There are two Win7 SP1 PCs (A & B), plugged in to a 3750-x (v12.2-58-SE2), on ports 33 and 41.
The ports are configured for 802.1x, auth order of MAB then Dot1x. Priority is Dot1x, MAB. The config is the same on both ports (verified at show run all).
When either PC is plugged in to port 33, everything works as I expect. Client sends an EAPoL message, gets a response, and is authenticated. When PC A is plugged in to port 41, same correct result. When PC B is plugged into port 41, the client sends an EAPoL start, and the switch never replies.
If port 41 has the authentication order changed to dot1x then MAB, PC B works fine.
View 3 Replies
View Related
Jan 28, 2012
We have a few stacked 3750 switches with vtp transparent configured...some plugged in a fiber from another network into our stacked switches...that network/switch has vtp server configured...once that switch connected to our stack of switches, it turned that stack switch into vtp server...causing the previous vlans configured to erase thus causing management issues with the stacked switches..
View 4 Replies
View Related
Aug 10, 2009
I'm experiencing some problems with AAA authentication banners and banner logins.I'm trying to use spaces and empty lines, but when login, all the lines are after each other, no empty lines, no spaces.The problem appears on a 3750 with IOS version 12.2(5)SE2.
View 5 Replies
View Related
Jan 20, 2013
We have Cisco 3750G switches and have them setup to use Cisco ACS 5.2.0.26.5. Some switches after they are restarted and we know that the config is saved the server address for the AAA authentication is dropped. We are running IOS c3750-ipbasek9-mz.122-40.SE. I have started to upgrade switches to c3750-ipbasek9-mz.122-50.SE5 to fix an issue with reporting high drops in Solarwinds.
View 6 Replies
View Related
Feb 17, 2013
seeking for configuration assitance on etherchannel between catalyst 3750 and 6506
View 3 Replies
View Related
Dec 31, 2011
I have CISCO catalyst with VLANs (VLAN ID 33, 36, 40-53) configured. I need to configure port mirroring in Switch 3750 for NAC (Network Access Control). I need to Monitor all the VLANs. Here is the SPAN configuration of switch: [code] Monitor session 1 source vlan 33 , 36 , 40 – 53.Monitor Session 1 destination interface fa 1/0/8 (here I am not able to set encapsulation dot1q ) because the error occurred saying %one or more dest port do not support the encapsulation%.
View 5 Replies
View Related
Jul 3, 2012
I have configured SPAN in cisco 3750 switch as below mentioned. but the destination port protocol is down.
Network Diagram:
switch(config)#monitor session 1 source interface gigabitethernet1/0/1switch(config)#monitor session 1 destination interface gigabitethernet1/0/11 ingress vlan 1
[Code]....
View 8 Replies
View Related