Cisco AAA/Identity/Nac :: Not Able To Ping From ACS Engine 4.2
Jan 14, 2011
I am able to ping the ACS ENGINE 4.2 from any PC or device. But I am not able to ping any device from the box while logged in via SSH. while I can do so while logged in via console. Is this some kind of bug or is there any patch which after installing will allow me to ping devices from ACS SSH sessions.
how profiling works exactly ?How intelligent is the profiling engine, meaning: Will it discover that one device has more than one different MACs and will merge the entries in the database ??
Example:This is in fact the same device, there is only one WLC-2500 in the network ....If it can discover that, what needs to be configured on the ISE to do that ?
Our ACS appliance (Cisco 1113) has died and it is not cost effective to get it replaced as it will only be used until the end of this year.Is it possible to get the tacacs software to install on a Windows server? How do I go about sourcing the software as the original documentation is no longer available? Will the fact that I have a defunct appliance be sufficient proof to get a copy of the software? We are currently running v4.1
I Have a requirement to migrate from ipv4 to ipv6, I have checked the scalability of all the devices for this migration except ACS 1113 Solution Engine, Version 4.2. I couldnt reach the proper documentation to check its support for ipv6.
In my existing production router 7609 of my company, sup-engine already fixed in slot 5 with SRC2 12.2(33) IOS and I need to insert another sup engine in slot 6 with SRE7 IOS code image and after this, again sup engine in slot 5 must be with SRE7 IOS image...(also I have extra sup engines with SRE 7 code image ready with me) Query:i am going to offload router before proceed for this activity?i will insert new sup engine in slot 6 with SRE 7 ios image and now i need to re-install spare sup engine with SRE 7 code readily available with me by removing existing sup engine from slot 5 (Active) so what will be the proceedure to insert new sup engine with SRE 7 code in slot 5 and slot 6 with minimum downtime of router?
existing setup sup engine in slot 5 with SRC2 12.3 (old hardware) slot 6 is EMPTY
final result should be like this: sup engine in slot 6 with SRE 7 (new hardware)
I have supervisor engine ws-x4516 with two line card WS-X4424 - GB - RJ45 - 1No ,WS-X4548 - GB - RJ45 - 1No. Now i want switch and hardware redundancy.
In my test lab , I have a CISCO 1841 with a AIM-VPN/BPII-PLUS board , everything was working fine , until I would like to see the difference with and without the accelerator.Sins the moment that the IOS told me that he will change to SW accelerator instead of HW accelerator , I can not make it work anymore.I have a copy of the full working configuration before I did this , I have put it back on my router but still NO VPN. [code]
can I install and Cisco WAAS and Cisco Prime Network Analysis Module (NAM) together on a single Cisco Service-Ready Engine (SRE) 910 module? Or it can only run 1 of the software?
I have a cisco 7609 with sup engine 720, I want to implement VPLS for that I purchased a 7600-ES+20G3C with the adv license 76-ES+ADVIP-LIC in a separate pak?how to activate the license on the 7609.
I have an inventory added to Ciscoworks and am getting alerts on interfaces that I want to exclude but for the life of me I can't figure out how to exclude interfaces. Any tips on how to exclude interfaces from the fault engine in 4.1.
My existing 4006 chassis is using Supervisor III (WS-X4014). I have another 4506 chassis using Supervisor IV (WS-X4515) and a Net flow Services Card (WS-F4531) build on top of it.
I need Net flow Services Card in 4006, so can I just replace the Supervisor IV (WS-X4515) used in Cisco 4006? Is it compatible with 4006?
I am currently running a 4506 with a sup V engine. I have purchased a sup 7 engine. Is there a guide on how to perform this task. I am sure I need to do an IOS update as well.
i have a standalone SUP720, no traffic is passing through it. only one port connected for remote telnet, its kind of backup device.today i checked its log, and there are some wiered message.is it a software bug or my SUP has gone bad? [code]
Removing and Installing a Supervisor Engine on a cisco router 7690 and more important IOS upgrade of this module.
I need some kind of manual, but I would prefer a short procedure to do this change. A brief of the steps to do that. Also i don't if i have to upgrade the new module after install it.
PD. IP7VAL02#sh modMod Ports Card Type Model Serial No.--- ----- -------------------------------------- ------------------ ----------- 1 48 CEF720 48 port 10/100/1000mb Ethernet WS-X6748-GE-TX SAL1034Z32J 2 48 CEF720 48 port 10/100
I have a strange issue with 4500 E chassis loaded with SUP 7L-E which always remains in ORANGE LED status, also the uplink ports interface is down and the line protocol is down but when i execute the command sh int gig1/5 it show me the media type sfp but there is no red laser light seen in the sfp transiever,The below command is configured for the uplink gig port on the SUP engine.hw-module uplink select gigabitethernet?
to the above question. I see the specs for the WS-SUP720-3B and 3BXL but not the WS-SUP720-BASE with the MSFC3 and PFC3A daughter cards.The 3B can handle 256,000 routes using IPv4 and the 3BXL can do 1,000,000.
I have recetly upgraded our core switches (6509E) to SUP 2T from 32. Each core has 2 SUP's (hot/standby). out of 4 SUP engines, one is defective. i had received the new SUP from cisco. Currently my core swicth 2 is running with single SUP. Can i directly insert the new SUP engine in slot 6 (free)? will it automatically load the existing IOS from active SUP? what will happen if the new SUP has a different IOS other than the active SUP? Also is there a way to find out the IOS version without inserting in the chasy?
we have installed the MSE 3350 with the lates Context Aware Sup Service from AeroscoutBut the Service still terminated because of unexpected null node message (see below)
I've connected my c3560G which I use as Core-switch in my company to Prime Infrastructure 1.3.And sometimes I see a CPU overload over 50% only by SNMP ENGINE process. Total CPU load at this time - up to 100% Possibly, It's happened after IOS update from 12.2(25r)SEE4 to 15.0(2)SE2 C3560-IPSERVICESK9-M.
I've exclude some OIDs from snmp view, but problem is still exists:
PRIMEview internet - excluded nonvolatile active PRIMEview mib-2 - excluded nonvolatile active PRIMEview system - included nonvolatile active PRIMEview interfaces - included nonvolatile active PRIMEview at - excluded nonvolatile active
We have a scenario with 2 chassis, both with 2 supervisor Engine 2T, we try to make a configuration of VSS with the chassis and would link to know if is possible have 2 supervisor on chassis one and 2 supervisors on chassis 2 with VSS?
Router#sho switch virtual redundancy My Switch Id = 1 Peer Switch Id = 2 Last switchover reason = active unit removed Configured Redundancy Mode = sso Operating Redundancy Mode = sso
[code]....
would like to use the second supervisors for obteind the local redundancy en chassis 1 and 2, this is possible?
the actually version on four supervisors is: s2t54-ipservicesk9-mz.SPA.150-1.SY3.bin
I have a 510a Cache engine and the IDE hard drive failed. I installed a new blank hard drive, but I can't get it to boot off of the new hard drive. Currently, I moved the original to Disk 1. I switched the boot up disk to disk 1. I was then able to setup the new hard drive (in disk 0). Everything is functioning, but I don't want to keep the dead hard drive in there. How do I setup a boot sector on the new hard drive?
We recently perchaced 4503 switch with Sub Engine 7L. It has universal IOS. We are unable to run EIGRP and HSRP protocol and the switch came with temporal license.how to proceed further to get EIGRP and HSRP enabled on the 4503 switch.
I was looking to 6500 series switches. I saw DFC4 module (WS-F6K-DFC4-A, WS-F6K-DFC4-AXL) and (WS-F6K-DFC4-E, WS-F6K-DFC4-EXL). Data sheet for supervisor engine 2T wrote that for maximum performance you should DFC4. I'm a bit confused. I didn't any useful information about it:
1. DFC4 is a separate module(consumes 1 slot)? Does it have any ports on it?
2. Is it a daughter card? If yes, should it be installed on supervisor or it should be installed on line cards?
I have configured the VSS in two cisco 6509-E series with only one supervisor engine, but if i configured with two supervisor engine. it is going to common mode. One supervisor engine is 3c and 3cxl.
I have an older 4006 with a Supervisor II+. We now need OSPF support, which the Sup II+ does not provide. I have access to a Supervisor III (WS-X4014), which will provide OSPF support. Question is, are there any gotchas to shutting down the switch, replacing Supervisor Engines and then powering up? What about the flash card? On my current system, it appears that I am only using bootflash: , which is where the IOS resides (see below). Since my startup config is in nvram and my IOS is in bootflash, what's the purpose of the flash card in slot0: ? and where does NVRAM and bootflash actually live on a 4006 ( on the Supervisor Engine?)
sh bootvar BOOT variable = bootflash:cat4500-ipbase-mz.122-31.SGA11.bin,1;,1; CONFIG_FILE variable does not exist BOOTLDR variable does not exist
I am trying to add 89,462+ access list rules to an ASA 5510 running 8.2(5). I have added all the rules to an object group and when I try to apply the access list to an interface it gives me the following error:
ERROR: Cannot add policy to rule engine ERROR: Unable to assign access-list wan-out to interface wan
I have not tried not using an object group and just putting the rules in the access list. I want to be able to add to these rules if needed easily.
I think it's clear that i have exceeded the rule limit for the ASA. So my question is, what is the rule limit for an ASA 5510 and which ASA could I purchase that would handle this amount of rules?
Sure this is a simple one. New to the 1900 series routers, have a 1921 with IOS 15.1. Noticed that there is a standard interface labeled Embedded-Service-Engine0/0. What the purpose of this is? Cannot seem to find any detail on it. See extract from default config below.