Cisco Security :: SNMP OID For VLAN And Port 2960 Series
Jan 19, 2011Cisco Catalyst 2960 series,i want do a SNMP request over OID. When the output should be like this: Portnumber and VlanID. Is there a OID for this output?
View 1 RepliesCisco Catalyst 2960 series,i want do a SNMP request over OID. When the output should be like this: Portnumber and VlanID. Is there a OID for this output?
View 1 Repliesi want use CACTI for monitor my bandwidth so i have a question how can i enable snmp for a switch port ? or i shoudl just enable snmp from configuratiopn terminal and then in CACTI i will choose which port will be monitor? can i do something that CACTI connect to my switch with a encryption key ? i have cisco 2960 48 port switch
View 2 Replies View RelatedI'm trying to configure Catalyst 2960 series 8 port switch in my office. I have just plugged in switch and started and then put Ethernet cable (which is coming from the wall port (LAN) into CONSOLE (switch). and connected my laptop's ethernet cable to switch's 1x por
View 16 Replies View RelatedAny snmpset commands to modify port vlan membership on SG300-28 switches? I checked [URL] however this information is apparently only valid for catalysts.
The latest firmware is installed and the provided MIB files are used.
I want to configure IEEE 802.1x port-based authentication on cisco switches, preferable 2960 series. Which models support this feature?. I have try with some older switches but it doesn't works properly on everyone. I have upgraded them whitout better results, there is namely an issue with TLS handshaking on some switches which produces authentication to fail.
View 1 Replies View RelatedI have a Cisco 2960 48-port switch. I enter "sh vlan" and it lists all the VLAN's. One of the VLAN's listed is "10" with the name "EPIC". What is the quickest way to find out what ports, if any, are assigned to this VLAN?
View 2 Replies View RelatedHow do I disable the USB port in the 881 router?
881router#show usb port
Port Number: 0
Status: Disabled
Connection State: Disconnected
Speed: Full
Power State: ON
we are using 2960 cisco switch asn we are trying to configure port security.we are able to configure MAC base port security, but unbale to configure IP base port security.can any one guide us can do IP base port security like MAC port security. if not which switch will support IP and Mac base port security.
View 6 Replies View RelatedWe're going to be switching some of our gear from Foundry to Cisco, and were looking at the WS-C2960S-48TS-L. We currently have 3 different VLAN's, and I wanted to have 1 uplink back to our firewall (ASA 5550) and then let the firewall do the routing between the subnets. I realize that 1 link will carry the traffic twice then, but is that possibly with those switches to have all three vlans assigned to one port and then just let the firewall do the routing between the vlans or would I need to have 3 uplink ports back to the 5550?
View 1 Replies View RelatedOne of my engineers issued a command to turn off port security on a number of ports using the range command. The command failed on the first attempt due to a tacacs auth failure which I suspect is due to a low tacacs timeout value. The engineer then reduced the number of ports in the range command and re-issued the config change after which the switch just crashed and rebooted.
The logging buffer on the switch displays the following:
000072: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: System previously crashed with the following message:
000073: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Cisco IOS Software, C2960 Software (C2960-LANBASEK9-M), Version 12.2(50)SE3, RELEASE SOFTWARE (fc1)
000074: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Technical Support: [URL]
000075: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Copyright (c) 1986-2009 by Cisco Systems, Inc.
000076: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Compiled Wed 22-Jul-09 07:03 by prod_rel_team
000077: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED:
[Code]........
I have done some searching and this could be related to bug CSCsq71492. I have tried using the output interpreter but it is still down.
I configured port security on my 2960 switches with the following commands: [code]
The problem is that when I should change someone's PC, first I disable port-secirity, then I clear all the mac addresses learned on the interface, then I plug the new PC and enable port-security. The new PC couldn't connect to the network and it's mac address has not be learned on the interface. Why?Which commands should I use to clear an old mac address and enable port-security with the new mac address.
I am looking to simply monitor Port-Security , Error-Disable and HSRP. I would like to receive an email when any of these are triggered.
Port Security - Port Is shut down
Err-Disable - Port goes into err-disable state (securedown)
HSRP - When HSRP standyby changes are detected
I need to receive emails with any of the able are triggered. What is the easiest way to do this? I know SNMP is the main option but I have never worked with SNMP and dont understand it too much.
Equipment:
2x Cisco 1921 series routers
3x Cisco 2960 POE switches stacked
For many years we've had the following vlan and port security config on our 3560s: [code] This has worked great on 12.2(37)SE1, 12.2(40)SE and 12.2(46)SE. However since 12.2(50)SE, and I've tried all the versions since then, we have a problem with 7900 phones and ATA186s taking upwards of 20 minutes before they can get a valid IP number.The problem on the newer IOSes seems to be related to the inactivity aging.On the older IOS versions the mac address of the voice device appears on the voice vlan straight away.
On the newer IOS versions the mac address of the voice device appears on the DATA vlan and seems to be stuck there until the inactivity aging removes it. It then gets re-learned, sometimes on the voice vlan, and sometimes on the data vlan. If you're unlucky and it gets re-learned on the data vlan you've got to wait until the inactivity time ages the address out again. Repeat until the mac address eventually gets learned on the voice vlan. I don't want to be stuck on 12.2(46)SE forever.
we are trying to do an automatic backup of our switches config trough snmp.my script can easily backup cisco 2950-2960-3550-3560 using snmp.but I dont know the mib to use to backup the cisco small business serie 300 switches.
View 6 Replies View RelatedAm I correct in thinking that 200 series swiches now support SNMP using v1.3?
View 1 Replies View RelatedI would like to be able to query the dot1dStpPortState obect on the Catalyst 2960-S on our LAN . Im running firmware c2960s-universalk9-mz.122-55.SE2.bin and according to the Cisco SNMP Object Navigator the object is supported (via the BRIDGE-MIB).However when i query using snmpwalk from my workstation :snmpwalk -v 2c -c bic-zua-ro 10.u.y.x 1.3.6.1.2.1.17.2.15.1.3 I receive and error .SNMPv2-SMI::mib-2.17.2.15.1.3 = No Such Instance currently exists at this OID For the sake of comparison, querying our 4700 :snmpwalk -v 2c -c bic-zua-ro 10.u.y.x 1.3.6.1.2.1.17.2.15.1.3 returns (as expected, cropped)
SNMPv2-SMI::mib-2.17.2.15.1.3.1 = INTEGER: 5
SNMPv2-SMI::mib-2.17.2.15.1.3.3 = INTEGER: 5
SNMPv2-SMI::mib-2.17.2.15.1.3.40 = INTEGER: 5
SNMPv2-SMI::mib-2.17.2.15.1.3.67 = INTEGER: 5
SNMPv2-SMI::mib-2.17.2.15.1.3.104 = INTEGER: 5
SNMPv2-SMI::mib-2.17.2.15.1.3.257 = INTEGER: 5
SNMPv2-SMI::mib-2.17.2.15.1.3.258 = INTEGER: 5
SNMPv2-SMI::mib-2.17.2.15.1.3.259 = INTEGER: 5
Is there some special configuration i need to do on our 2960's. The only snmp related settings i can see in the running config is snmp-server community. In this case :
snmp-server community bic-zua-ro RO
I have NM-AIR-WLC6-K9 in Cisco 2821. Is there opprotunity to retreive configuration via SNMP as from Cisco Catalyst 2960?
View 1 Replies View RelatedI would like to test the possibility to reload devices via SNMP for new switches like 2960, 3560 and so on.I know that the command "snmp-server system-shutdown" has to be configured, then I need to send the set query to the device via SNMP.
I have found on the net the OID 1.3.6.1.4.1.9.2.9.9.0 but it belongs to an old MIB and doesn't seem to work with new switch models.
I have a 2801 running c2801-spservicesk9-mz.124-3g.bin According to the Cisco IOS MIB locator the image supports OLD-CISCO-SYSTEM-MIB I have tried .1.3.6.1.4.1.9.2.1.55 etc to set server IP address and the filename string but without any luck.e.g.
Reason: (noSuchName) There is no such variable name in this MIB.
Failed object: iso.3.6.1.4.1.9.2.1.55.a.b.c.d (where a.b.c.d is the server IP)
I have also tried the method similar to that for Cat 3550 switches where you create a table of entries to define the transfer paramaters then activate the transfer (I think the CISCO-CONFIG-COPY-MIB)
e.g.
[URL]
C:>snmpset -v 1 -c private <device name> ccCopyProtocol.<random number> integer 1 ! 1 = tftpccCopySourceFileType.<Random number> integer 1 ! 1 = networkFileccCopyDestFileType.<Random number> integer 3 ! 3 = startup & 4 = runningccCopyServerAddress.<Random number> ipaddress "<server ip address>"ccCopyFileName. <Random number> octetstring "<file name>"ccCopyEntryRowStatus.<Random number> integer 4 ! 4 = createAndGo, or 1 = Active
To write net have the source as running (4) and the dest as network (1)
ccCopySourceFileType.<Random number> integer 4
ccCopyDestFileType.<Random number> integer 1
Clean up at the end - destroy .14 with the value of 6.
example output : -
-- earlier output omitted --
Error in packet.
Reason: (noSuchName) There is no such variable name in this MIB.
Failed object: iso.3.6.1.4.1.9.9.96.1.1.1.1.4.111
Error in packet.
[code]...
WS-C2960G-24TC-L 12.2(25)SEE3 C2960-LANBASE-M
I would like to get the temperature status from this 2960 switch (and several other models. Normally this OID should be:.1.3.6.1.4.1.9.9.13.1.3.1.6 But it does not return anything.
The termperature status can be found from the command line by running:"sh env temp" This reports back ok, so I assume there is a temperate gauge in the switch.
This oid is part of the "CISCO-ENVMON-MIB" mib and accouding to the Cisco MIB selector it is supported on my switch and IOS - 12.2(25).
(Another thing I woudl like to monitor and should be supported is the fan status oid (.1.3.6.1.4.1.9.9.13.1.4.1.3). That doesn't return anything either.
What do I need to do to get the temperature environment status from SNMP query?
I have Cisco 2960's, 3750's and 3750x's all running IOS on the access layer. I have Cisco 6504's running IOS on the Distribution and Core layers. I am looking to monitor redundant links through Spectrum by having specific ports send traps but I have run into trouble finding how to configure it. I would like to have:
1. Logging enabled for all links (Fiber and Copper) so that I see all links up/down messages in the syslog
2. SNMP traps sent for linkup/link down messages only for redundant links (ex. Dual Up links from Access Layer or Redundant Ether channel Links on Dist Layer)
3. SNMP traps should be ignored/not sent for all copper ports.
I have a problem I have Cisco 2960 series switches with ip address 10.10.10.2 255.255.255.0 works but can not connect to the Internet
View 1 Replies View RelatedI have this Cisco Switch: SRW2048-K9-NA. When I log into the Web GUI, I am provided the two options mentioned above for VLAN Management. I have fiddled with the two options and they seem identical to me. Is there really a difference, maybe better flexibility?
View 2 Replies View RelatedI have Linksys SPS224Trying to create VLAN through SNMP. Issueing the string to create VLAN ID=100 with name "VLAN100"
snmpset -c private -v2c 10.254.2.144 .1.3.6.1.2.1.17.7.1.4.3.1.1.100 s VLAN100 .1.3.6.1.2.1.17.7.1.4.3.1.5.100 i 4
It reports
Error in packet.
Reason: (genError) A general failure occured
Failed object: iso.3.6.1.2.1.17.7.1.4.3.1.1.100
In same time changing the name of existing vlan snmpset -c private -v2c 10.254.2.144 .1.3.6.1.2.1.17.7.1.4.3.1.1.23 s VLAN23 and even deleting the existing vlan snmpset -c private -v2c 10.254.2.144 .1.3.6.1.2.1.17.7.1.4.3.1.1.510 i 6 are successful.
How can I create new vlan through SNMP?
In an attempt to restore a Cisco IOS I deleted the file C2960-lanbasek9-mz.122-53.SE2.bin my swich
Before deleting the same was as follows:Directory of flash :/
3-rwx 12824 Mar 28 1993 21:00:37 -03:00 vlan.dat4-rwx 3096 Mar 7 2012 08:43:37 -02:00 multiple-fs5-rwx 2289 Mar 7 2012 08:43:37 -02:00 private-config.text6-rwx 7482 Mar 7 2012 08:43:37 -02:00 config.text9 drwx 192 Mar 23 2012 16:18:54 -03:00 C2960-lanbasek9-mz.122-53.SE2
32514048 bytes total (20204544 bytes free)Switch-01 #
Right now this switch as follows:
switch: dir flash:Directory of flash:/
2 drwx 64 <date> crashinfo_ext 3 -rwx 4120 <date> multiple-fs 5 -rwx 12824 <date> vlan.dat 6 -rwx 4018 <date>
[Code].....
When i connect two cisco 2960 series switchs via stright trough cable causes delay in transmission sw1 has vlans and having trunk port connected to router all vlans are able to access internet sw2 is connected to vlan5 on switch1 sw2 has factory default configuration computers on sw2 can access internet but I have low bandwith problem on sw2 there is transmission delay problem?
View 1 Replies View RelatedHow to change ip address in cisco 2960 series switch?
View 4 Replies View RelatedI have a design for my infrastructure and i'm thinking to choose 4 or 5, or more, 2960 series in a stack mode instead of one 4500 series?
View 6 Replies View RelatedSuddenly my 2960 D series switch went offline and i founf the switch was not powering. I can't figure out the issue.
View 3 Replies View RelatedWe are trying to config vlan 10 for data and vlan 20 for voice on the same port - port 1 of swtich SF300-24P to run both data and voice on different vlans.Do I have to add vlan 10 as an untagged vlan to port 1 and add vlan 20 as an tagged vlan to port 1?If I do not want to assign the native vlan 1 to port 1, how can I remove it ? The GUI page - assign VLAN to port does not allow to remove it.Aslo, what mode shall I set up on port 1? General, trunk or access ?
View 18 Replies View RelatedI have set up 2 DHCP pools and 2 VLANs (1 *the native* for data / 1 VLAN for voice). When I use the command "switchport voice vlan 20" the port disapear from the show vlan brief list. When I use the "switchport access vlan 20" it shows up in the show vlan brief in the correct VLAN and gives the phone an IP. I assume that using the access instead of the voice is wrong and the phones would not configure correctly. But when I use the access the phone goes to the next step and tells me the TFTP files are not found. Why does the port disapear from the VLAN list?
View 8 Replies View RelatedWhen using Cisco IOS c2960-lanbasek9-mz.122-50.SE3.bin we can delete line in SNMP group config with
no snmp-server group <group-name> v3 priv context vlan-<vlan-id>
without problems.
But, after upgrade on version c2960-lanbasek9-mz.122-58.SE2.bin there is output:
#####% Ambiguous command: "no snmp-server group <group-name> v3 priv context vlan-<vlan-id> "
It looks like some bug, but there is nothing in the bug toolkit.
How do you enable multicast traffic on 2900 series switches?
View 7 Replies View Related