Cisco :: L3 Core Switch VLAN Monitoring With IPS?
Jun 10, 2012We have a L3 core switch with multiple VLANs setup. Is there a way to place an IPS so as to monitor the traffic passing between, lets say, VLANS 1-3 and VLANs 4-10?
View 3 RepliesWe have a L3 core switch with multiple VLANs setup. Is there a way to place an IPS so as to monitor the traffic passing between, lets say, VLANS 1-3 and VLANs 4-10?
View 3 RepliesI have a L3 core switch with multiple VLANs setup. Is there a way to place an IPS so as to monitor the traffic passing between, lets say, VLANS 1-3 and VLANs 4-10?
View 19 Replies View RelatedI need to create a DMZ Vlan. Core switch is a 6509. FW is an ASA5520. Need to create a VLAN for DMZ purposes for outside facing servers. NAT is used on ASA.
View 7 Replies View Relatedi'm already has one internet connection is connecting directly to the Core Switch 6509,Vlan 500 (1921.168.1.0) and the Switch is route any internet request with default route:
SW6509-conf)# ip route 0.0.0.0 0.0.0.0 10.170.10.10
10.170.10.10 is --> Next hop for the DSL router internal IP, and it's working fine.
The Problem: We have a new internet connection with new Vlan 600 (172.16.1.0) another ISP/ with another DSL router, so i need your kindly support and suggest how to connect both of them to exit from the Core Switch 6509. is it ok if i make another default route to the Next hop to the new DSL router as:
SW6509-conf)# ip route 0.0.0.0 0.0.0.0 10.80.10.10
10.80.10.10 is --> Next hop for the new DSL router internal IP.
is there any way like default route , route-map or any other features to :
route Vlan 500 (192.168.1.0) to exit from DSL 1 --> 10.170.10.10
route Vlan 600 (172.16.1.0) to exit from DSL 2 --> 10.80.10.10
I have a requirement to monitor all traffic going from the internal LAN to the cloud. The LAN is a layer 2 VLAN which spans multiple Cisco 4507 switched and other smaller switches.
The VLAN has an IP address which the hosts use as the default gateway.
The exit port is on a Cisco 3600X switch connecrted to 4507 #1 via a 10G fiber link. 4507 #1 connects the rest of the LAN. Those switches interconnect via 10G fiber and 1G copper links.
Currently the monitor host is connected to a 1G copper port, configured as a monitor port, on one of the backside 4507s The switch manager says he has the switches configured so that I can see all traffic on the VLAN.
In my Company there is a core Switch 4500 series , to which in the 1st module servers are connected and in the second module 2960 , 3750 series Switches are connected, problem is that the Utilization of Core switch is very high and the core gets hanged. the configuration of the senerio is VTP domain i.e core is Server and the rest are Clients....
View 12 Replies View Relatedthere are more than 15 servers which include xen,esx,vmware,also san etc..which are connected to L3 core switch directly. And vlans are created for each.....xen,iscsi,vmware,xen,server. wanted to know is there any other technology other than directly connecting servers to core switch and assigning vlans that can be used in place?
View 4 Replies View RelatedI am facing issue with LMS 4.0. The Core Switch is showing in RED color,and device type as UNKNOWN. It was working fine but some how it is showing this problem.
View 14 Replies View RelatedHow to configure SLA monitoring in 3560 switch. I have 2 DSL links terminating in switch and want to do WAN failover. I know how to do in ASA and router. I found IP SLA and track commands on switch but don't know exactly how to use them.
View 2 Replies View RelatedI want my core switch auto failover to other route if the primary route is link down it will go to the secondary route
example
ip route 0.0.0.0 0.0.0.0 1.1.1.1
ip route 0.0.0.0 0.0.0.0 2.2.2.2 100
if my core switch detect next-hop 1.1.1.1 it will re-route and go to the 2.2.2.2 for the next-hop my core switch using static route and cant support ip sla
I am getting following error in Cisco 6509 switch.BUt there is no impact in the switch.
: %MAC_MOVE-SP-4-NOTIF: Host 0000.0c07.ac01 in vlan 694 is flapping between port Te8/1 and port Te7/1
29:33.959: %MAC_MOVE-SP-4-NOTIF: Host 0000.0c07.ac01 in vlan 269 is flapping between port Te7/1 and port Te8/1
[Code].....
I tried to implement WLC5508 in my network but when I came to connect it to the switch core which is a Catalyst 4000 the link didn't get up. This switch module is a fastethernet, I wonder if that might be the problem since I also tried connecting my laptop to the WLC and the link got up.
If that might be the cause, is it possible to get WLC to 100 Mbps?
What is the VPC configuration template with two core 6509 switch.Pls find the attachment for Network topology.
View 3 Replies View RelatedMy CORE Switch 4507R Suddenly restarted (Powe is good) , and gets the business down for 30 Mts,my boss came to me and asks why it has restarted , what is the root cause of this restart, i dont have any syslog or NMS enabled in my network to be informed
View 6 Replies View RelatedDHCP configuration on CISCO core switch 4507R switch.With one vlan and multipul vlan both configuration using any ip address range.
View 3 Replies View RelatedI got new task moving WS-3560X24 port layer 3 core switch from one branch to be moved to my branch and connect WS3560 layer 3 core switch my site network. Both core switch has got 3-4 cisco 2960 switch underneath and lots of vlan offcourse. I am thinking about creating etherchannel between these two switch.
View 2 Replies View Relatedwe need to relocate our core switch 6500 with sup 720 to another bldg
what is the command to gracefully shut it down I mean power off
I was told one can just switch off the power
what is location of flash file in 6500 Series switch and how can we take back of IOS image for 6500 series.
View 4 Replies View Relatedi have configure new ACE 30 module on top of 6500 core switch , the issues am facing whenver i want to access to https://ACE_IP and after i enter the user name and the password , it's forwared me to the follwoing page: is there anything should i configure to avoid this page ?
View 1 Replies View Relatedi configure the uplinks as etherchannel, i configure two svi interface on core switch int vlan 51(192.168.51.1) and int vlan 50(192.168.50.0) for this two svi int i configured two dhcp pool , when any of the pc is requesting for dhcp add i am getting dhcp request failed/
View 7 Replies View RelatedI'm trying to decide what switch to use as a core for 500 users. I'm currently looking at either 2 x 3750X stacks or 2 x 4500s with dual SUPs and PSUs, both options will provide the number of switchports required without the need for additonal access layer swiches. Which switch option is best to go for here? All of our services will be located in our data centre which will be connected using 2 1000Mbps MPLS circuits. I wont need any advanced L3 features and we are not likley to scale over 450 users. Also is it ok to use the dual switch stacks or chassis to provide the collapsed core/access layer or is it best to have a dedicated core (using one of the above options with less switchports) and having a dedicated accesss layer using 2960Gs for example. Our structured cabling terminates in a single comms room so we wont need to distribute switches throughout the office.
View 3 Replies View Relatedwe have Core-Siwtch 4503 in the main building which is connected to another Core 4503-E in another building ,, now our PCs connected to the 4503-E ,,, any XP M/C can pick an Dhcp-ip but and M/C run Win.7 Cannot !!
action taken :
1st we try to connect our win 7 pc in the node which was connected to xp M/C ,, and it didnot take ip from the DHCP . ,, 2
2nd we ensure from the core-switch configuration and its normal with no mistake
3rd trying to use tool from Microsoft Fix-it Center whih name is ( Microsoftfixit 50475 ) which is just .msi file but the problem face us is that this tool donnot accept to run on win 7 cause its made for vista .
4th after some researchs we notic that there is some modifications have to be performed on registery by disabling the dhcp broadcast flag we did it but nothing change yet
5th now we are waiting to perform another action which is Disable the IP Helper service in win 7
I am doing an evaluation of LMS 4.0. I have loaded the system on Windows and manually added my core 3750 switch into the system. Device availability is showing the device as available. However, the other pollers like link utilization, error count, etc. all show that there is no data. When I go into the poller config, the pollers for link utilization and errors show 0 devices associated and a status of "instance not found". The CPU and availability pollers show active with my one device added. I have verified the credentials and if I go into Inventory -> Port and module and select my 3750 I do get a list of all the interfaces and the descriptions so LMS is connecting to the switch and pulling data.
So how do I get the pollers for link utilization and errors to start populating data?
Second question, during install I did configure the software update section and it said there was an LMS 4.0.1 available which I told it to download. Now I have a psu_download directory and some more directories like cm, cmf, etc. but I don't see any file on what to do with them. What do I need to do to install the new package files that were downlaoded to psu_download?
At our site we have a 4510 core switch and 3750x switches in our IDFs. The 3750 switches are connected to the core via DOT1Q trunks in a server client setup. We are putting in an Informacast/Berbee server witch will send pages and text to the cisco phones. We also have 1 3750 switch connecting to the core via a layer 3 port channel. If we put the Informacast server on the phones vlan would I just need to enable ip pim sparse-dense mode on that vlan only and enable multicast routing, ip multicast routing?
View 5 Replies View RelatedI have 2 units core swicth C4510R+E SUP7-E need to connect together for redundant purpose , i bought also 4X 10GE uplinks for each core switches .May i know how i shall connect both core switches together using my spec Catalyst 4500 E-Series 12-Port 10GbE (SFP+) ?
View 6 Replies View RelatedNowadays i have a project @ my work , the project consists of replacing our Cisco 6500 Core Switch with two other Core switches 6513E .
Is there is any tool to filter which port is connected to which server with its mac address and IP?
Is this a good idea to connect access layer directly to core layer with fiber and omit the distribution layer?
View 2 Replies View RelatedI have two networks at two sites with a dot1q trunk between the two L3 switches at both sites (no routers involved)
SITE A - Cisco 3750 L3 - VLAN ID 50
10.10.50.0/24
SITE B - Cisco 3750 L3 - VLAN ID 50
10.20.50.0/24
I would like to extend the SITE A VLAN to SITE B so that I can move hosts from SITE A to SITE B without needing to change their IP address but the vlan ID is already in use. Obviously the easy solution is to change the VLAN ID for one or other of the sites but both sites contain hosts that run 24/7. Is there a way to join two VLANs with different IDs together.So for example I create a new VLAN 60 at SITE B and associate it with VLAN 50 at SITE A.
I have been working on redesign of our network which was very challenging but almost there.We have a limited budget of around £20k(32k Dollor) Max. The cabling has been done before my time and it is very messy and cheap so you can not do a proper cisco hierarchical model at all.I can not have multiple links from each access layer switch to the core/distribution and as a result i had to connect some access switches together to introduces redundancy in a nutshell,we have two buildings, main building which has the server room in it and the other building which is just bunch of office. i have introduced a partial mesh on the normal building and have tried to introduce full mesh on the main building .
View 9 Replies View RelatedI am experiencing high cpu utilization in my 4000 series core switch.
I checked the loggs. i saw some strange loggs.
Please see the below logs:
Code...
What is the "invalidsourceaddresspacket" ?
Is this is due to some virus attack or something?? Also one more thing this switch is the Active router in HSRP.
I have a problem with extending the LAN on a client site . They are looking to extend the LAN with a 2960S-series switch. Already in place is a 4510 switch which the 2960 is connected to via fibre. The 2 switches are both set up but there is no connectivity as I cant ping between them or anything. The management VLAN on the 2960 shows line up, protocol down, which I believe means the VLAN is enabled but there is a form of physical mismtach on the ports. I have attached the configs of both switches. I feel it might be a problem with GBIC module compatibility. The SFP installed on both ends of the switch are GLC-SX-MMD. On the 4510, the SFP sits in a twingig converter (CVR-X2-SFP) but there is no light on it at all when the cables are plugged in.
View 40 Replies View RelatedWe have two 6500 core switches and one(primary) of them is running in VTP transparesnt mode and the other (secondary) one is running in VTP client mode. I would like to change the VTP mode of the second switch to transparent mode. Would it cause any issue. I guess i have to create VLANs onto the switch.
View 7 Replies View RelatedI have a 3750X four-switch stack acting as the core of a fairly simple LAN. All I need to achieve (and this seems inordinately hard, but it is entirely likely that I'm just being dense) is to get access to the internet through my core switch, through the firewall and out through my VSAT. I've spoken at some length with the firewall providers (Cyberoam) and they tell me all I need to do when I migrate onto my new system (Cyberoam is currently in place at the entrance to our existing LAN) is change the local IP address of the Firewall, plug in the new switch to the LAN port, and away I go. Tried that, didn't work, so obviously I'm missing something.
View 22 Replies View Related