Cisco Switching/Routing :: 2950 Port Security Is Not Working

Feb 23, 2013

I have network consists of more then 20 cisco 2950/2960/3700 switches.  I have configured port security in my switches. initially when i configured on my switches it worked fine....even for copule of months it worked fine. but suddenly it start creating issues and now i am not able to implement port security on switches. the configuration is same but there is no effect now. Same switches were fine but now even having same configuration it is not working. please see the configuration: [code]

View 5 Replies


ADVERTISEMENT

Cisco Switching/Routing :: 2950 - Security Precautions

Jul 15, 2012

What are the security issues in connecting a notebook to a console of the 2950 switch? Can  virus or Trojan enter into a switch during configuration session? If the answer is yes, what precautions must I take to prevent such case?

View 2 Replies View Related

Cisco Switching/Routing :: Gigabit Ports Not Working On 2950?

Apr 18, 2012

I am trying to test the gigabit ports on a Cisco 2950 switch. 1000Base-SX.  I have the internet or dhcp server connected to port 24 on the first switch and my pc hooked up to the (any) port on the second switch. Both switchs are connected with a fiberoptic cable with MTRJ connectors on either side.
 
Now when I use gi0/2 on both switchs all works fine. I get a dhcp address from the router on the other end of the first switch. but when ever I include gi0/1 on either end of the fiber optic cable neither of the ports will initialize (neither of the leds above the ports light up). I have deleted all the config files before booting up the switchs so they should have a default blank configuration.
 
When looking at the Http web page for the switch I dont see any issues with the port. what can I do to make sure these ports are working or can be configured?
 
 I will not be able to post back any more information about the switch until next tuesday. Im off till then.

View 5 Replies View Related

Cisco Switching/Routing :: Dot1x Authentication Not Working On 2950

Mar 14, 2011

I have issue with 2950 switch dot1x config is not working , but on 2960 its working fine .Below are the configs from both switches and a debug dot1x all snap, what may be the issue with 2950 switch ...
 
on 2950======>
aaa new-modelaaa authentication dot1x default group radiusaaa authorization network default group radius

[Code].....

View 1 Replies View Related

Cisco Switching/Routing :: 2950 DTMF Not Working On Voice Vlan

Nov 9, 2011

i am facing a strange issue on cisco 2950 .IOS (tm) C2950 Software (C2950-I6K2L2Q4-M), Version 12.1(22)EA9, RELEASE SOFTWARE (fc1) suddenly my phone stopped working for DTMF tone, i mean when i  dial a conference bridge lets say 6565 and then it ask for conference  bridge code lets say 12345, it doesnt recognize the code and says code  is invalid, SIP Proxy is Asterisk in this case.Currently my cisco switch port is configured for dual data + voice vlan, where DTMF dont work, sample config below [code]

View 2 Replies View Related

Cisco Switching/Routing :: Configuring Port Forwarding For 2950?

Jul 11, 2012

Is it posible to config port forwarding on cisco 2950 or other switchs.if such a option is there ple let me know ho to config port forwarding on cisco 2950 switch..

View 1 Replies View Related

Cisco Switching/Routing :: 2950 Laptop Doesn't Have Serial Port

Feb 15, 2013

I have two 2950 Switches and am trying to connect via my laptop.  My laptop doesn't have a serial port so I am trying to connect through the ethernet port, with a straight through cable and on the end as it goes into the console port I have bought a cisco console rollover adapter.When I turn on terra term I get nothing...just a black screen and it disconnects.

View 6 Replies View Related

Cisco Switching/Routing :: Enabling Port Security On C4507R Shuts Down Port

Aug 13, 2012

I'm trying to enable port security on several 4507R's. When I try to configure a range of ports the switch will randomly put 1 or 2 in err-disable.  It's different every time I apply the config to the same group of ports.  However if I do them one at a time it seems to work.  But I really don't want to configure 6 fully populated switches one port at a time.   We also have a lot of 3750's and they gave me no problem using a port range. [code]

View 4 Replies View Related

Cisco Switching/Routing :: How To Set Port Security On 881

Oct 25, 2011

Was wondering how to set port security on the 881. I have all the FE ports shutdown except one and want to limit that port to one specific MAC address. 

View 7 Replies View Related

Cisco Switching/Routing :: Port Security In CE500 Switch?

Sep 8, 2010

configure  port security Cisco 500 Swich ? There is no CLI mode in this switch?

View 2 Replies View Related

Cisco Switching/Routing :: 2960 - Turn Off Port Security

Dec 15, 2009

One of my engineers issued a command to turn off port security on a number of ports using the range command. The command failed on the first attempt due to a tacacs auth failure which I suspect is due to a low tacacs timeout value. The engineer then reduced the number of ports in the range command and re-issued the config change after which the switch just crashed and rebooted.
 
The logging buffer on the switch displays the following:
 
000072: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: System previously crashed with the following message:
000073: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Cisco IOS Software, C2960 Software (C2960-LANBASEK9-M), Version 12.2(50)SE3, RELEASE SOFTWARE (fc1)
000074: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Technical Support: [URL]
000075: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Copyright (c) 1986-2009 by Cisco Systems, Inc.
000076: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Compiled Wed 22-Jul-09 07:03 by prod_rel_team
000077: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED:
[Code]........
 
I have done some searching and this could be related to bug CSCsq71492. I have tried using the output interpreter but it is still down. 

View 22 Replies View Related

Cisco Switching/Routing :: SF300 - Port Security / Possible To Disable?

Aug 2, 2012

I have several SF300 switches deployed (SF300-08, SF300-24P). They are connected to IP Telephones (NEC) which communicate with the switch for auto voice VLAN on LLDP. The problem I am experiencing is that periodically the IP telephones are rebooted by the telephone vendor and when they do the switch puts that port into "Locked" port security mode and discards all traffic to the port. The IP telephones of course do not work. In other switch models, I have seen the ability to enable / disable port security switch wide or on a port by port basis. This model does not appear to have this feature. How to disable or why the phones would cause the switch ports to "lock"? There is usually one PC attached to each phone.

View 1 Replies View Related

Cisco Switching/Routing :: 3750 Port-security Will Not Clear

Jun 5, 2012

We have several 3750 stacks across our campus that we are unable to completely clear port security on. We have mac address stick set up on all access ports. When we clear the sticky address on the port, the mac address is removed from the running config like normal, but we keep getting port-security voilations. If port security is taken off the port completely, i.e. no switchport port-security, traffic still doesn't pass the port. Even clear port security across the stack doesn't work. If we try to reload the stack, only the master reboots, and the other switches in the stack lose switch capabilities.

View 1 Replies View Related

Cisco Switching/Routing :: Port Security On Nortel 5520

Jun 6, 2012

I've just completed a port security project at a site on numerous Cisco switches and all works well, however they have 2 Nortel 5520 switches (which I left until the end) which they would like to lock down.  I have logged a message on the Nortel forums and I have heard nothing for days.  I just need to lock 2 ports down to the Mac address of 2 computers stopping any other computer being plugged in. 

View 2 Replies View Related

Cisco Switching/Routing :: 3550 - Port Security Verification

Apr 1, 2013

I'm trying to test port-security in my c3550 but when I show port-security int f0/23 shows it only "Disabled" as below:
 
run
interface FastEthernet0/23switchport access vlan 200switchport mode dynamic desirableswitchport port-security mac-address stickyspanning-tree portfast 

View 2 Replies View Related

Cisco Switching/Routing :: CE500 Switchport Port-security

Apr 19, 2012

I try change the configuration the port in the switch catalyst express 500, i need disable switch port port-security, a try with http://10.1.1.1/exec and save configuration with wr command, if a check the configuration de port is correct but i reboot the switch and check the configuration the port appear the switch port port-security configuration again.

View 3 Replies View Related

Cisco Switching/Routing :: Configured Port Security On 2960 Switches

Feb 18, 2013

I configured port security on my 2960 switches with the following commands: [code]
 
The problem is that when I should change someone's PC, first I disable port-secirity, then I clear all the mac addresses learned on the interface, then I plug the new PC and enable port-security. The new PC couldn't connect to the network and it's mac address has not be learned on the interface. Why?Which commands should I use to clear an old mac address and enable port-security with the new mac address.

View 4 Replies View Related

Cisco Switching/Routing :: Supervisor 7L-E USB Port Is Not Working?

May 1, 2012

Nothing happens when we plug a USB Flash Drive into an SUP7L-E USB port.

View 4 Replies View Related

Cisco Switching/Routing :: 3560 Port Security And Voice Vlan On Newer IOS

May 20, 2010

For many years we've had the following vlan and port security config on our 3560s: [code] This has worked great on 12.2(37)SE1, 12.2(40)SE and 12.2(46)SE. However since 12.2(50)SE, and I've tried all the versions since then, we have a problem with 7900 phones and ATA186s taking upwards of 20 minutes before they can get a valid IP number.The problem on the newer IOSes seems to be related to the inactivity aging.On the older IOS versions the mac address of the voice device appears on the voice vlan straight away.
 
On the newer IOS versions the mac address of the voice device appears on the DATA vlan and seems to be stuck there until the inactivity aging removes it. It then gets re-learned, sometimes on the voice vlan, and sometimes on the data vlan. If you're unlucky and it gets re-learned on the data vlan you've got to wait until the inactivity time ages the address out again. Repeat until the mac address eventually gets learned on the voice vlan. I don't want to be stuck on 12.2(46)SE forever.

View 11 Replies View Related

Cisco Switching/Routing :: Catalyst 3546 XL / Switchport Port-security Command Not Available

Oct 26, 2011

Im trying to follow along documentation i see via train single videos and some online resources. I am trying to enable port security.I have a Catalyst 3546 XL when i type in "rtr1# switchport ?""port-security" is not only of the options to choose from.   I have already set this as an access port.

View 4 Replies View Related

Cisco Switching/Routing :: ME3600X Is Switchport Port-security Mac-address Sticky Available

May 5, 2012

Our customer has a Cisco ME3600X with the IOS me 360x-universalK9-mz.122-52.EY3.They are saying that is not possible to configure the "switchport port-security mac-address sticky" in the interfaces and want to know whether any additional license is needed.As far as I know there isn't any extra license to activate this feature and also I believe the ME3600 switch should have this feature with the universal IOS, isn't that right?

View 1 Replies View Related

Cisco Switching/Routing :: Port Security Dynamic Configuration On Catalyst 3560xPOE

Oct 2, 2012

I have connected a 10BaseT device to a CISCO Catalyst 3560xPOE switch with dynamic port security.  All seems to work fine when the distance between the two devices is closer then 200ft.  When I connect to 10BaseT devices farther out near 300ft the response from the attached device is lost. It works ok on unmanaged switches at the longer distance. Is there a minimum response time from attached devices for dynamic port security to work properly?  Is there any other explanation why it would work on cheaper switches, but not on the Port Secured Switch?

View 2 Replies View Related

Cisco Switching/Routing :: 1941 Port-Security With Router Switch Module

Feb 29, 2012

I have a 1941 that I am going to deploy with a HWIC-D-9ESW switch module (I only need 3 switch ports but need the PoE).  I am going to hang a 1262 autonomous AP off one of the ports but I need to configure MAC address port-security so that only that AP can pass traffic. I know the switch modules are 'almost' exactly like a switch for commands but I can't seem to enable or configure any port-security settings.  Is port-security no available on the switch modules?

View 3 Replies View Related

Cisco Switching/Routing :: Cat 3750 Drops First Frame / Packet With Port Security

Mar 5, 2013

our C3750 like the one described here [URL]
 
We have the port on the switch set like this:
switchport port-security maximum 25
switchport port-security
switchport port-security aging time 2
switchport port-security violation restrict
switchport port-security aging type inactivity
 
In case a device connected to the port is inactive for more than 2 minues ( aging time ) the first frame/packet the device generates arrives to the port on the switch, but the switch does not forward it to the appropriate port ( discards it or whatever ).
 
So far I tested on
1 30    WS-C3750E-24PD     15.0(2)SE2            C3750E-IPBASEK9-M       
2 30    WS-C3750E-24PD     15.0(2)SE2            C3750E-IPBASEK9-M       
3 52    WS-C3750G-48PS     15.0(2)SE2            C3750-IPBASEK9-M

[Code].....
 
When we remove port security from the port, it works perfectly fine, as expected.
 
It seems this is not HW or IOS version related. It seems it is not a stack synchronization issue, it does not matter if a device is connected to the first or other stack member. I tested on C3560 too, here there are no problems, so seems it is 3750 related.

View 1 Replies View Related

Cisco Switching/Routing :: 7060 - POE Not Working On Specific Port

Mar 18, 2013

when plugging a Cisco 7060 to the specific switch port it does not power on.  The inline power consumption is abnormally high compared to the other phones that are plugged in, maybe double the amount. 

non Poe devices work on the same port.
 
I used multiple cables and phones.

View 6 Replies View Related

Cisco Switching/Routing :: Cat2960 Gigabit Port Not Working?

Mar 12, 2012

Brand new 2960. When I plug a cable into the port, nothing happens. The port light doesn't begin negotiation or anything, it just stays dark. The cable works fine--I have it on another switchport with a crossover connector connecting to a little Cisco SOHO switch without problems.
 
I've done the following:
switchport
switchport mode trunk
switchport trunk allowed vlan 1
no shutdown
 
In other words, I've fiddled with it. But I don't know why it doesn't light up..

View 1 Replies View Related

Cisco Switching/Routing :: 3560 Port Security Triggers With Valid Mac Address During Power On

Feb 28, 2013

I have 2 3560 switches that are running 12.2(25)SEE2. Port security is enabled on some of the ports. Whenever there is a power failure, when power is restored, 1 port on each switch goes to err-disabled. The mac address that causes this is a valid address for that port. Below is the configuration on one of the ports.

View 1 Replies View Related

Cisco Switching/Routing :: 3750 Switches Refuse To Fire The Port-security Violation Traps

Oct 20, 2010

My group has recently started configuring traps on our switches to alert us of issues as they arise vs. waiting for the Helpdesk to receive user complaints and then responding.We have successfully configured the 2950 and 2960 switches to alert us when a port-security violation happens. However, the 3750 switches refuse to fire the port-security violation traps. The 3750's will fire an errdisable trap when the port goes down though.

Here is one of the port configurations:

interface FastEthernet1/0/45
switchport access vlan 5
switchport mode access
switchport port-security
switchport port-security mac-address sticky

[code].....

And here is the output of the port-security debug:

2522070: Oct 21 16:37:04: %LINK-3-UPDOWN: Interface FastEthernet1/0/45, changed state to down
2522089: Oct 21 16:37:05: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa1/0/45, putting Fa1/0/45 in err-disable state
2522100: Oct 21 16:37:05: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 0012.3f07.95d3 on port FastEthernet1/0/45.

All of the 3750's are running C3750-IPBASEK9-M, Version 12.2(53) SE2. Wireshark also shows the errdisable traps, but no other traps so I've ruled out the traps being missed. All of the switches have been reloaded and power cycled.

View 3 Replies View Related

Cisco Switching/Routing :: Monitoring Port-Security Error-Disable And HSRP With 1921 And 2960

Aug 1, 2012

I am looking to simply monitor Port-Security , Error-Disable and HSRP. I would like to receive an email when any of these are triggered.
 
Port Security - Port Is shut down
Err-Disable - Port goes into err-disable state (securedown)
HSRP - When HSRP standyby changes are detected
 
I need to receive emails with any of the able are triggered. What is the easiest way to do this? I know SNMP is the main option but I have never worked with SNMP and dont understand it too much.

Equipment:
2x Cisco 1921 series routers
3x Cisco 2960 POE switches stacked

View 1 Replies View Related

Cisco Switching/Routing :: 25565 Port Forwarding Not Working On Some Ports

May 15, 2013

I've created some port forwards from my public IP (Dialer0) to our private LAN but only the 25565 port forward works. I've even added an any statement to the Nat source list Homenet_NAT. Full config attached. My Cisco router is an 877W. [Code]

View 6 Replies View Related

Cisco Switching/Routing :: 2801 Router Console Port Not Working?

Feb 13, 2013

I  have issue with Cisco Router 2801's Console Port. My student was doing a  lab and he said during configuration, Console Port stopped responding.  He was in middle of configuration, so now at present, only telnet is  able to login on "R2>" user mode, enable password is not set, so  getting "R2>en % No password set R2>" I have tried  different terminal software but no output from Console Port, changed the  Console Cables, replace with working console cables, change speed  (baud) settings. Also tried to connect same console with "AUX" port and  got same error mentioned above. AUX Port responds but I am not able to  change mode (R2#) because of incomplete running-config. it seems "Console Port" is physically  damaged.

View 4 Replies View Related

Cisco Switching/Routing :: P3750-E - Port Based DHCP IOS 15 Not Working

Apr 9, 2013

I am upgrading from 3750-E IOS 12.2 to 3750-X IOS 15.0
 
I have a dhcp pool set up to give out an ip address based on the Physical port of the switch.  I also have it configured to give out "reserved only" addresses.
 
The configuration works when i plug a dhcp device in the 3750E. (IOS12.2) The configuration does not work when i use the same config on 3750X (IOS15)                  
 
When i debug dhcp, i see the DHCP discover message come in, but no offers or anykind of response from the 3750X.
 
If i remove the "reserved only" line the switch gives out IPs, but of ocurse not the ones i want.  I did that to prove both the client and the switch can give out an IP.
 
So i have a feeling the subscriber-id client-id interface name  mapping is not right, or not created.
 
Here is a snippet of config.
 
!
no ip dhcp use vrf connected
ip dhcp use subscriber-id client-id
ip dhcp subscriber-id interface-name

[Code]......

View 1 Replies View Related

Cisco Switching/Routing :: Stacking 24 And 48 Port 3750X Switches Not Working?

Dec 11, 2012

We purchased a number of 3750X 48 and 24 port switches for the College Campus. Am finally getting around to getting them inserted on the network. Working with a WS-3750X-48PF-S and a WS-3750X-24P-L. Have them stacked with the 10Gb uplink on the 48 port switch. Have not been having fun.In the boot sequence, the switches recognize they are stacked, but as soon as they finish boot, I get the message on the 48 port switch: “Stack Port 1 Switch 1 has changed to state down.” Then “Stack Port 2 Switch1 has changed to state down.” Am noticing that I have a message preceding that: “Major version mismatch with stack neighbor.”The 48 port is running c3750e-universalk9-mz.150-1.SE3, HBOOT 12.2(53r)SE2.The 24 port is running c3750e-unversalk9-mz.122-55.SE3, HBOOT 12.2(53r)SE2Most of our 3750X and older switches are running 122-55 or 122.58 code. IP base or Universal. There is speculation that the problem is the 24 Port is Lan base, as the part number might indicate. (WS-C3750X-24-P-L.... I think that is the part number) and the 48 is IP base. Both switches are Universal, and my understanding is that they don't care about LAN or IP Base until you enable a function that falls in the IP Base domain. Then I have to call Cisco Licensing.For these switches, LAN Base is fine, based on the boot message, I feel the real problem is 122-55 versus 150-1 in the stack. So.. the question is: Do I downgrade the 48 port to match what we have in our environment, and what is on the 24 port switch. Or... Upgrade the 24 port switch to match the 48 port switch and have an installation that is not consistent with our environment? I do have two more edge closets to install with this purchase of 3750X 48 port switches.

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved