Cisco Switching/Routing :: 3750 - ICMP Redirect Aging Timer

Apr 29, 2013

Amazed I cannot find this in any documentation but I want to know the default aging timer for ICMP redirects on a 3750 switch running at layer 2.

View 10 Replies


ADVERTISEMENT

Cisco Switching/Routing :: HTTP Redirect Using 3750 Switch

Sep 16, 2012

I have tried search but found found anything for the 3750 switch about how to redirect HTTP, HTTPS & SMTP traffic to altenative gateway, than our standard gateway on our network, so here goes:
 
The network that need the HTTP, HTTPS and SMTP traffic redirect is 192.168.5.0/24 and should be redirect to 192.168.5.205 where as all other traffic need to be direct to 192.168.5.199.
 
Can the 3750 switch do this typo of refirect and if how?? I cannot find anything on the Cisco site stating how or even if it is possible! 

View 2 Replies View Related

Cisco Switching/Routing :: Can't Execute (ip Wccp Redirect Out) On 3750 Switch

Mar 13, 2012

Today, my customer have 1 project that have to deploy Cisco 3750 to redirect wccpv2 to  Websense Security Gateway.However, i can't excute "ip wccp redirect out" on Cisco Catalyst 3750.

View 5 Replies View Related

Cisco Switching/Routing :: 3750 Switch - ICMP Delay To Default Gateway

Aug 25, 2012

I had setup a lan infrastructure with 5 3750 stack swithes. In these 3 of them are in one stack which is acting as access switch, 2 of them in another stack which is as core switch where all the SVI is configured. Now, when i tried to ping from our edge pc which is connected in access switch to default gaeway, which is configured in core switch, the ICMP is getting delayed . But when try to ping from the same edge pc to another user PC, it is getting less tahn 1 millisecond icmp replies.
  
why icmp is delaying to default gateway , but working with another edge to edge pcs without any delays?

View 1 Replies View Related

Cisco Switching/Routing :: Catalyst 3750-x Icmp Delay To Default Gateway?

Sep 10, 2012

i am facing a problem when the client vlan is commmunicating with the default gateway on the core 3750-x.
 
ios in 3750-x core is  3750e-universalk9-mz.150-2.SE.bin.  But, client to client communication is happening without any dealy and icmp is less than 1 ms always.
 
When try to ping default gateway of client vlan, it is getting delayed (variable icmp delays). Is this an ios bug?

View 2 Replies View Related

Cisco Switching/Routing :: 2811 / BGP / Default Originate Timer At Max Delay Of 64 Sec

Jul 22, 2009

I have a working BGP session established. With "debug ip bgp events" I see many (2/3 every second) messages like this:
 
*Jul 23 11:23:48.773: BGP: default originate timer at max delay of 64 sec
*Jul 23 11:23:48.997: BGP: default originate timer at max delay of 64 sec
 
I can find nothing about this message. IOS version is  12.4(24)T and platform is Cisco 2811

View 8 Replies View Related

Cisco Switching/Routing :: Stack Mac Persistent Timer Lacp Port Channels C3750

Sep 27, 2012

I am having an issue on a Cisco 3750 stack where when the stack master is rebooted, all my lacp port-channels drop and then come back up again. After doing some investigation It seems that it is happening because of lacp using the stack master mac-address as part of the system-id, so when the stack master reboots, the stack mac changes. I see that there is the command: stack-mac persistent timer 0

There is this warning about using this command:
 
When you configure this feature, a warning message displays the consequences of your configuration. You should use this feature cautiously. Using the old master MAC address elsewhere in the domain could result in lost traffic.
 
My question are:
 
Are there any other consequences to using this command (apart from moving the switch/mac to another location in the network)It mentions 'If the entire switch stack reloads, it acquires the MAC address of the master as the stack MAC address' Is this still the case if you have the stack-mac persistent timer to 0? Does using channel-group mode on for the port-channels still use the same mechanism of having a system-id? (Will the channels flap using 'mode on' when rebooting the stack master.

View 4 Replies View Related

Cisco Switching/Routing :: 6509 Use Policy Based Routing To Redirect Http Traffic

May 29, 2012

We have a Catalyst 6509 switch, and we hope to use policy based routing to redirect http traffic to my proxy server, where I can find the configuration example?

View 11 Replies View Related

Cisco WAN :: IP SLA ICMP-Echo On 3750?

Jan 22, 2012

Have a very peculiar issue with IP SLA. Firstly, the architecture.
 
1) There are two sites - A & B. Both have their own internet connection.

2) Sites A & B are connected via MPLS.

3) Both sites have the below topology.
 
3750 CORE --> FIREWALL -->ROUTER ---> INTERNET
 
4) 3750 has a Default route pointing to firewall .

5) MPLS router is connected to 3750. A default information is originated via BGP to MPLS at each location. So that default route is learnt as a backup path from any location if it has to lose its local internet.

6) IP SLA has been configured at each location to track the default route using icmp-echo to hit a public IP (i.e 4.2.2.2 as an example).
 
Issue?ICMP probes from Site-A via its local internet fails abruptly. I can reach the public IP mentioned above from my firewall pretty fine, but not from my 3750. Whenever i remove the tracking from the static default route & push in the plain default route without tracking, it works fine. Again, if i add the tracking back, it will work fine for an hour or so & then fails back again. To my bad, Site-B had recently gone offline due to some natural calamity. So, there is no other path for internet.
 
My config looks pretty simple
 
track 10 ip sla 1 reachability
!
ip sla 1
icmp-echo 4.2.2.2 source-ip 10.1.254.1
frequency 180
ip sla schedule 1 life forever start-time now
ip sla enable reaction-alerts
!
ip route 0.0.0.0 0.0.0.0 10.1.254.1 track 10
 
I am running IOS version 12.2(53)SE2 (IPservices images).

View 3 Replies View Related

Cisco WAN :: 3750 - Flooding Of ICMP-Q

Feb 5, 2012

The below output has taken from Cisco 3750 switch which the CPU utilization is more than 80%. What is the meaning of this below information.
 
switch#debug platform CPU-queues icmp-q
debug platform CPU-queue icmp-q debugging is on
 
 
Feb  6 18:44:09.860: ICMP-Q:Dropped redirect disabled on L3 IF: Local Port Fwding L3If:Vlan41 L2If:GigabitEthernet1/0/8 DI:0xB4, LT:7, Vlan:41   SrcGPN:8, SrcGID:8, ACLLogIdx:0x0, MacDA:0019.aade.0d58, MacSA: b8ac.6f2a.2734   IP_SA:10.43.41.87 IP_DA:172.20.31.25 IP_Proto:6
TPFFD:ED580008_00290029_00B0009F-000000B4_90BD001F_6C6E1FC0

View 3 Replies View Related

Cisco Switching/Routing :: ME3800 - ACL To Match ICMP

Nov 24, 2011

We have some ME3800MX router/switches running ME380x-UNIVERSALK9-M), Version 12.2(52)EY2.  The Cisco website says:
 
The switch does not support these Cisco IOS router ACL-related features: # •Non-IP protocol ACLs (see Table 26-1) or bridge-group ACLs
 
how we would match ICMP traffic then?

View 4 Replies View Related

Cisco Switching/Routing :: Monitor ICMP Traffic On C6509?

Dec 22, 2011

Both regular IP traffic and ICMP traffic are passing through the source port. C6509 provides the option of filtering vlan traffic during monitoring. But I don't have vlan traffic.
 
qa-c6509-c(config)#monitor session 1 filter ?  vlan  SPAN filter VLAN
 
So I applied an access-list which only allows icmp traffic to be sent out of the monitoring port. But it does not work.

View 4 Replies View Related

Cisco Switching/Routing :: 1800 - Configure IP SLA With ICMP Tracker?

Jan 16, 2012

I would like to configure IP SLA with ICMP tracker. What  is the minimum IOS & Feature required in cisco 1800 Router?

View 2 Replies View Related

Cisco Switching/Routing :: Can 7600 Redirect Layer 4 Traffic

Dec 6, 2012

i want to to ask about redirecting in MLS 7600 .assume the user a has an ip x.x.x.xand that user requested url...i want to to redirect his request to url...the users that have to pay the monthly bills , i want to give thim an ips  and redirect all the http requests from this to a special local webpage .is is applicable to to it on router cisco 7600 ??or is it applicable on router 7206 npeg2 ? also i have siwtch 2960g.i dont want to do it by proxy server.

View 4 Replies View Related

Cisco Switching/Routing :: 3560 Redirect Internet Traffic

Nov 24, 2011

At one of my field offices I want to redirect internet traffic down a separate DSL connection instead of having it ride the T1 back to the main office then going out.  At this office I have a 2600 router, 3560 switch, with a Fortigate firewall in between DSL connection and LAN, Fa0/0 on router and firewall are both plugged in to switch.  I have seen posts that mention PBR or static routes which is the reccomended method for dealing with this? 

View 6 Replies View Related

Cisco :: Redirect Show Tech To Tftp On 3750

Mar 7, 2012

On my 2960, 3550, and 2801 equipment which all have IOS 12.2 or 12.3 I am able to obtain things like "show tech" and save it on a tftp server in this manner: ch3550#show tech | redirect tftp://192.168.18.18/techsupport.txt,This is because the | pipe has a bunch of options it refers to as output modifiers.HOWEVER, on my 3750, I am not able to do this. The list of output modifiers has changed, and "redirect" is not available. Consider the following: The 3750 unit I am working with is WS-C3750G-12S with IOS version 12.2(25)SEB2,Now, I know I can capture the show tech output via other means such as in the buffer of Putty.exe.

View 3 Replies View Related

Cisco Switching/Routing :: 1841 Enable ICMP After Auto-secure

Dec 31, 2011

I ran autosecure on my 1841 routere and now I cant do ping or traceroutes. What should I do to enable the pings and traceroutes after auto secure is done.

View 1 Replies View Related

Cisco Switching/Routing :: WCCP V2 - Unable To Redirect The HTTPS Traffic?

Jun 3, 2013

I am unable to redirect the HTTPS traffic on my cisco router with WCCP V2

View 2 Replies View Related

Cisco Switching/Routing :: 6509 Unable To Redirect Http Traffic

Mar 26, 2012

On a Catalyst 6509 switch I have configured wccp protocol in order to redirect the Http traffic to a Bluecoat SG8100. It was working fine until a new L3 interface implementation.Thereafter I was unable to redirect the http traffic due to an error reported from the Cat6509: [code] After some checks I supposed that the problem should be the UDP 2048 port connection between the Switch and the Bluecoat while the switch L3 port and the bluecoat are on the same Lan. A deep analysis found that the WCCP protocol seems to be as follow:

-Proxy address 10.64.28.240 to Switch Port 10.64.28.250 Here I Am
-Switch Port 10.64.28.250 to Proxy address 10.64.28.240 I See You
-Switch Port 10.66.0.251 to Proxy address 10.64.28.240 UDP 2048 packet (dropped by firewall)
 
It's strange to me that the first dialog is correctly handled by the correct Cat6509 interface while the UDP packets are flowing from another Vlan interface not configured with the WCCP and apparently not involved on the protocol.Last of all the WCCP is now disabled and unusable?

View 4 Replies View Related

Cisco Switching/Routing :: Policy Map Redirect Port 80 Switch 3750X

May 15, 2012

I would like to know if it possible to create a policy map in order to redirect the traffic ( 80 , http, 8080) to a proxy.
 
My current equipment its a 3750X using a IP Service License ,I was reviewing some options but i want to be sure before implement in production.

View 8 Replies View Related

Cisco Switching/Routing :: Nexus 5500 Duplicate ICMP Echo-replay

Nov 24, 2012

I am experiencing inconsistent echo-replay from devices connected via VPC to Nexus 5500s while pinging from the Nexus exec prompt.

In some cases I receive normal response when pinging from one Nexus,  but no response when pinging from the other switch. In other instance I receive normal response to one Nexus, and duplicate replays to the other. It looks like a VPC related bug. NXOS is 5.1.3.N2.1
 
5501# ping 10.12.12.232
PING 10.12.12.232 (10.12.12.232): 56 data bytes
64 bytes from 10.12.12.232: icmp_seq=0 ttl=253 time=8.585 ms
64 bytes from 10.12.12.232: icmp_seq=0 ttl=254 time=9.227 ms (DUP!)
64 bytes from 10.12.12.232: icmp_seq=1 ttl=253 time=1.011 ms
64 bytes from 10.12.12.232: icmp_seq=2 ttl=253 time=8.097 ms
64 bytes from 10.12.12.232: icmp_seq=2 ttl=254 time=9.429 ms (DUP!)
64 bytes from 10.12.12.232: icmp_seq=3 ttl=253 time=18.195 ms
64 bytes from 10.12.12.232: icmp_seq=4 ttl=253 time=8.807 ms(code)

View 5 Replies View Related

Cisco Switching/Routing :: ICMP High Response Time To SVI Interface 3750X

Mar 13, 2011

I am in the process of installing a 3750x (IOS 12.2 (53r) SE2 IP Base) Cisco Catalyst switch in a new network of just 2 PC's (2 hosts, OS windows7 64Bits). I have enabled SVI interfaces with the both hosts installed in 2 different network segments.  We then start connectivity test.  The response time for the PING command between both hosts remain below 1 millisecond, whereas the response time between the hosts and their correspondent SVI interface is variable, and at all time is higher than 1 millisecond, sometimes it reaches 17 milliseconds. (Note that the switch CPU usage is only 8% at the time of testing)  We have performed this same connectivity test changing the 3750x switches  and in two different locations obtaining the same results. 

View 2 Replies View Related

Cisco Switching/Routing :: C6509 Loss Of Packets ICMP Sent By Different Hosts In Different VLAN

Oct 17, 2012

I've a big problem with a loss of packets ICMP sent by different hosts in differents VLAN. Here my architecture:
 
Core Switch : 2 Switch's C6509 (Version 15.0 (1) SY1)- Mode VSS - One lien VSL , the other link is defective.Access Switch: C3750 , Connected to Core Switch through 2 fibre optique wires.Topology: redundant ring
 
When I send consecutive ping message I  found always a missing of packets . Furthermore When I insert the  "show ip traffic" command., the parameter "bad hop count" increase after a loss of packets. I've 2 hosts connected in my network and they send packets with TTL =127.
 
In the Core Switch I haven't configured the MEC because it gave me troubles with the packets multicast.

View 1 Replies View Related

Cisco Switching/Routing :: IP SLA ICMP Echo Support Catalyst 3560X / 3750X?

Feb 13, 2012

Need to clarify if ip sla icmp echo operation is supported in catalyst 3kx switches (ip services)? on the configuration guide, commands are available, but on the feature navigator, i can't find the feature, only ip sla video operation. i don't have a device to test on here.

View 2 Replies View Related

Cisco Switching/Routing :: WS-C2950S 23 Hours Of Icmp Ping Unreachable On Switch?

Mar 7, 2012

Today one of our 9 Cisco switches a "WS-C2950S" (we also got 2 other WS-C2950S on same network) stop responding icmp ping packages. When i tried to telnet the switch its network was unreachable but i was able to see its existance from other switches by "sh cdp neig". So i decided to fix the situation on a suitable night time work, checking by console cable or even rebooting the device.
 
Then i started to wonder... what this could possibly be about?We have like 40 clients behind that switch and there was no communication problem during the problem.

View 2 Replies View Related

Cisco Infrastructure :: Blocking ICMP On Catalyst 3750 Switch Vlan?

Apr 7, 2011

I have set up an ACL on my 3750 switch to deny icmp from PC A  on our inside network to PC B on a different VLAN on our inside network using the following ACLs:
 
deny icmp host 10.1.17.15 host 10.3.10.4
deny icmp host 10.3.10.4 host 10.1.17.15
 
-- or --
 
deny icmp host 10.1.17.15 host 10.3.10.4 echo-replydeny icmp host 10.3.10.4 host 10.1.17.15 echo-reply

These ACLs belong to an access-list that also limits ip traffic to a few specific machines.When I try pinging from PC A I receive a reply message back from PC B. Shouldn't this configuration block any ICMP from PC A to PC B and from PC B to PC A? I would have expected the first ACL statement to block any packets associated with ICMP and when that didn't work I tried the second configuration.

View 6 Replies View Related

Cisco Switching/Routing :: 5520 To Redirect An External Address To An Inside Server

Mar 21, 2012

I am desperate to make some kind of translation which convert an outside IP Address of our web server to its inside ip address so that requests can be routed internally to the server.
 
This is what we have:  A wireless network with an SSID to serve visitors.  We also have an in-house web server which can be accessed internally and externally.  We have a ASA 5520 that protects the internal network, including the Web server, and also routes all traffic from the all visitors connected to the public SSID to the outside.  The DHCP server for the wireless network for visitors is configured to give the 8.8.8.8 as dns server.  The problem with that is that the www.ourwebserver.com is resolved by Google's dns server to the public IP Address of our web server!  The traffic then is sent to the outside interface of the ASA 5520.  The visitor who wants to access our web server cannot connect!
 
How can I configure the ASA to route that traffic to our web server with the public ip address to the inside ip address of the web server?

View 2 Replies View Related

Cisco Switching/Routing :: 6500 - Acl Object Group With Wccp Redirect List

Dec 31, 2012

Can i use acl object group with wccp redirect list?My platforms are 6500 and isr 2921

View 1 Replies View Related

Cisco Switching/Routing :: 2811 Disable Audit-trail For Icmp Packets In CBAC Logging

Mar 23, 2013

I have a cisco 2811 router set up as a nat/firewall gateway for my network. I've configured it for CBAC on using ip inspect and an access list.What I want is to use audit-trail to record network traffic (which means sending syslog messages to a server) concerning established sessions from my own network to locations in the outside. If i configure this using ip inspect audit-trail and no ip inspect alert-off, the configuration looks like this: [code] which works just fine, but there is the matter of icmp packets.
 
Since i use polling software that needs to check some machines in the outside part of the network, it is only natural that several icmp sessions are established through the Inspection Rule per minute. The problem is that since these sessions are recorded along with everything else, my syslogs are flooded with these (since i am using logging trap informational) to the point that more messages are generated about icmp than all other traffic combined, especially in non-working hours.What I am asking is a way for the audit-trail to be selecively disabled for icmp, so that the outgoing (echo) &incoming (echo reply) sessions can be established without generating syslog messages.

View 1 Replies View Related

Cisco Switching/Routing :: Perform STFTP On 3750 Or 3750-X?

Jun 30, 2012

Do I need the Universal image to perform stftp on a 3750 or 3750-X?

View 8 Replies View Related

Cisco Switching/Routing :: 7200 - QoS Input Policy Doesn't Classify ICMP Packet Based On DSCP

Dec 20, 2011

I have made some test and i noticed that qos input policy does not classify the icmp packet based on their dscp.The "match dscp ef" or "match precedence 5" is not working only the "match protocol icmp" shows hits.
 
We need to classify the different icmp packets based on dscp ( TOS ) for measurement purpose.CISCO 7200, 12.4.25d and 12.4.20T have a same behavior.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 Password Aging Feature Enablement

Sep 1, 2011

I am using an ACS 4.2 trial version, and am trying to enable the password aging feature.  I am using the ACS internal database for users.  I have looked at the user guide, which has clear instructions, but I don't seem to have the ability to set password aging rules.  When I go into the Jump To pull down, I am only presented with four options; Access Restrictions, Enable Options, IP Address Assignment and TACACS+.  The Password Aging options are not shown. 

View 1 Replies View Related

Cisco Switching/Routing :: Stacking 3750-X With Universal Image With 3750-G Running BIN Image?

Oct 10, 2011

I'm looking at adding a Cisco 3750-X switch running c3750e-universalk9-mz.122-55.SE1 (IP base license) into a stack of 3750-G switches running c3750-ipbasek9-mz.122-55.SE1.bin Given that the version and feature sets are the same I don't forsee any compatibility issues. Would there be any reason why a universal image wouldn't stack correctly with other switches running the single .bin file?

View 9 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved