I have been reading several posts in this forum to try to understand ACL behaviour on a standby HSRP 6500, I would be glad to get this cleared.I have two 6509 running HSRP for all Vlans...I created VLAN 100 with standby ip address 192.168.1.129 255.255.255.128
Active 6509 (SW01) ip is 192.168.1.130/25, priority 120 Standby 6509 (SW02) ip is 192.168.1.131/25
I have created a DHCP server on the standby 6509 only on the same VLAN 100 with a defaul router of 192.168.1.129 (i.e. the hsrp vip). I connected a pc directly to the ethernet port on the standby 6509 and put it under VLAN 100 and it obtained its ip 192.168.1.200 from the ios dhcp.Now I want to restrict this PC (and any other on its subnet) to access only a remote server 172.168.10.10 and nothing else. I have created the following access list, allowing traffic to the remote server, ospf and hsrp updates,ios dhcp...
Extended IP access list SWRES 10 permit ospf any any log (172 matches) 20 permit ip any host 172.168.10.10 30 permit ip any host 224.0.0.2 40 permit udp any host 255.255.255.255 eq bootpc 50 deny ip any any log (52 matches)
I have applied this ACL on both the 6509s under interface VLAN 100 ip access-group SWRES in
1. When I ping different subnets on the 6509s from the PC, I still receive icmp replies although I expected the acl to pass traffic destined for the remote server only. I do get deny log messages on the Active 6509, but not on the standby 6509 where the PC is connected.
2. Is permitting bootpc in the acl enough for IOS DHCP server and client operation? Do i need to explicitly permit access to the defaul-router configured in the DHCP, which happens to be the VLAN 100 gateway ip and hsrp vip as well (192.168.1.129)
3. I do get deny logs on both the 6509s from the PC trying to access the local VLAN 100 broadcast address on ports 137, 138.
%SEC-6-IPACCESSLOGP: list SWRES denied udp 192.168.1.200(137) -> 192.168.1.255(137)
I am seeing a strange situation on my 6500 switch?By having snmp walk on '1.3.6.1.4.1.9.9.109.1.1.1.1.3' (== cpmCPUTotal5sec), I came to know that there are two processor and the cpu util for switching processor is gone to 88 % and some time creeps to 99 %.
snmpwalk -v2c -c "removes" sw6500 '1.3.6.1.4.1.9.9.109.1.1.1.1.3' SNMPv2-SMI::enterprises.9.9.109.1.1.1.1.3.1 = Gauge32: 12 (--- this is for CPU of Router Processor ) SNMPv2-SMI::enterprises.9.9.109.1.1.1.1.3.3 = Gauge32: 99 (--- this is for CPU of Switching Processor )
but when I do sh process cpu on the console, all looks normal as it shows cpu utilization of RP. why the value is so high on the switching processor ?
we are using Cisco 6509-E VSS mode [12.2(33)SXI] ipbase image and facing high cpu utilization. In show process cpu output it is showing some "ios-base" process consuming cpu. I attached show cpu output
We bought Cisco sup engine WS-SUP32-GE-3B for 6500 switches 2 nos for redundancy. I have connected 6 systems on each sup engine ports. How to clarify whether both sup engine will forward the data while one is Master and other is standby?
We have a setup of FWSMs configured in single mode in 6509 chassis. Both 6509 are configured in VSS. Recently I have upgraded the firmwre from 4.0(3) to 4.1(3).....before upgradation config sync was not having any problem.
After upgradation...If any one of the FWSM reload..while coming up it gets stuck in config sync and no command we can run on any of the unit and get the error as.. Configuration update in progress by another process. Also on stannby fwsm no running-config displays.
If we used # failover suspend-config on primary and then reloads the standby fwsm...standby boots up with startup config and when # no failover suspend-config command runs on active fwsm..the sync started and completing succssfully within 15 sec..
Also failover works well..with #no failover active..
i do have two 6500 in VSS mode , and one FWSM module on each 6500, i want to configure these modules as Active/Standby, how do i start , should i follow this (not in VSS mode): url..
I have been having an annoying issue for the past few weeks with my ASA setup. We are using the ASA as our Remote Access Gateway and originally had it setup in a Active/Standby failover configuration using 2 x 5520 ASA's.The original setup of the devices was that the 2 x ASA were setup in a failover configuration, with both of them connecting back to the internal network via a 6500 device. Because of using failover I created a VLAN on the 6500 and put the two ports that connect the ASA's into that VLAN. I then configured the VLAN interface to be the EIGRP interface for the neighbour relationship to the ASA's.
The problem I am seeing is that the EIGRP neighbour relationship between the Active ASA and the 6500 keeps flapping. It occurs abour 4-5 times every day at randmon intervals. Sometimes the neighbour relationship will stay up for 6-7 hours, other times it flaps every 1-2 hours. I initially thought it was due to the failover configuration so I removed one of the ASA's and removed all of the failover configuration, but the EIGRP neighbour flapping problem still exisits. [code] Since removing the failvoer configuration I am thinking it could be a physical cable problem?
I have just received a new Cisco 3750G Switch from my parent company. When attempting to install the switch, I discovered that it will not boot to CLI, only to the bootloader. After using the command boot, the switch attempts to boot the most current IOS version, but fails, stating "error loading XXXXXXXXXX.bin".
Obviously, I just need to get a functional version of the IOS onto the switch to boot, but the problem is exactly how can I do that? All (or most) the commands with which I am familiar are unavailable in the bootloader, so all methods known to me fail. Is there a simple way (maybe using the copy command?) to put the .tar or .bin file onto the flash?
I have 6509 E. Actually what happen it last 3-4 times it reload its self and got stuck in rommon mode, i tried to boot it with boot by connecting a console cable on supervisor 720 2b. What and where is problem and why is stuck in rommon after reload.
I have a Catalyst 3560-X PoE that suddenly stopped working. I plugged in via console and below is the output I received. It scrolls constantly and I am unable to enter ROMMON mode or stop it from scrolling. I've read of a possible problem with the IOS version but I'm unable to verify due to not being able to stop the scrolling.
Switch uptime is 4 minutes, 4 seconds cisco WS-C3560X-24P (PowerPC405) processor (revision A0) with 262144K bytes of memory. Processor board ID FDO1522R2AY
We did an upgrade from NX-OS 5.1.5 to 5.2.4 and found all M1 line card interfaces were stuck in initializing state for long time.'show module' status says ok. And we cannot execute shut/no shut command under the interface. N7K-M108X2-12L & N7K-M148GT-11 are the two M series cards. Only option was to downgrade back for the time being.
N7K01# sh int e1/1 | in down Ethernet1/1 is down (initializing)
I have configured my new 3850 using the command line and all works well. I logged into the web interface expecting to see device manager with a pretty image of the switch etc.
However I am presented with the Express Setup page and even if i fill in all of the details again and click submit then nothing happens and this is all I can get.
I have a 7600 with ws-sup750 and when it boots it displays these errors:
Cisco IOS Software, s72033_sp Software (s72033_sp-ADVIPSERVICESK9_WAN-M), Version 12.2(33)SXH2a, RELEASE SOFTWARE (fc2)Technical Support: [URL] Firmware compiled 07-Apr-08 22:12 by integ Build [100] 00:00:05: %C6K_PLATFORM-0-UNKNOWN_CHASSIS: The chassis type is not known.(0x6003)
[Code]....
Then it got stuck in rommon, i tried using a 7200 pcmcia card (I downloaded the 7600 IOS there) but if i do from rommon boot disk0:
it complaints with :open: file "c7200-atafslib-m" not found so, it doesn't boot.
Anything I can do to be able to boot this device ?
We have a couple of 7911 that get stuck in Registering, each monday. During the week, no user reports the problem. But after the weekend, we get ready to hear complaints from our collegues. The same phones often experience this issue, although the other phones report no problems. The problem is temporarily solved when we issue "shut/no shut" on switch ports.
I am having an issue with this device after setting the ip address and rebooting. I have tried renaming the config.text file without success. I have also tried the steps mentioned here: [URL]
we're facing a weird issue lately with a Cisco 2821.An interface stops responding after a few hours.The only way to bring it 'up' again is:
Hardcode: duplex or speed or shutdown -> no shutdown
there are no errors in the "sho interface" and no errors or entries in the log.
FastEthernet0/0/0 is up, line protocol is up Hardware is Fast Ethernet, - Description: Infopoint MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec, reliability 255/255, txload 1/255, rxload 1/255
sh fex FEX FEX FEX FEX Number Description State Model Serial ------------------------------------------------------------------------ 105 FEX0105 Image Download N2K-C2232TM-E-10GE sh fex FEX FEX FEX FEX Number Description State Model Serial ------------------------------------------------------------------------ 105 FEX0105 Offline N2K-C2232TM-E-10GE
I have a Cisco 4500 as my core switch and there are two sup eng in this core. However, I noticed that the redundant sup is in diable mode rather than Hot Standby.
I have tired to enable the module but I am not able to do that.
I have issue with my 4510 switch which has got two supervisor engine in single switch.
I am trying find the root cause but not able to ....
Standy supervisor engine is not detecting ....
In show module and bootvar output also , there is error saying " Standby is not up "
show module ouput :
Switch-4510#show moduleChassis Type : WS-C4510RPower consumed by backplane : 40 WattsMod Ports Card Type Model Serial No.---+-----+--------------------------------------+------------------+-----------1 6 Sup V-10GE 10GE (X2),
I have a couple of 3560 switches running c3560-advipservicesk9-mz.122-44 and they are randomly experiencing the following:
- The switch locks up with no preceding error message in the log (I am forwarding syslog to Splunk).
- Upon reboot, the switch goes through the normal startup sequence with no error messages, then for some reason reloads the flash and starts all over again. (refer to doc)
This could happen after days or weeks. Sometimes they will go through two of these reloads on boot and be fine for awhile, and other times they will be stuck in the loop infinitely. I am using this same image with all of our 3560s, but am only having this issue with two of them.
sup: WS-X4516-V ios version: cat4500-entservices-mz.122-54.SG.bin ! show process cpu CPU utilization for five seconds: 97%/1%; one minute: 97%; five minutes: 97%
I'd like to know what is "masks" in the output of show platform tcam utilization. What does 784 mean? What effect has the number of mask in the amount of supported unicast direct routes?
I'm having trouble comparing the capacity of theese two switches, regarding unicast directly-connected routes. I know the second switch has cpu utilization issues and ip unicast failed routes over 4096 arp entries. What would be the case for the first one?
Switch 1:
CAM Utilization for ASIC# 0 Max Used Masks/Values Masks/values
Unicast mac addresses: 784/6272 12/26 IPv4 IGMP groups + multicast routes: 144/1152 6/26 [Code]...
I am running HSRP on three 4506 switches..S1(active) S2( standby) and S3(listen)..S1 is active for all the vlansRight now, I wanted to make S3 active for two vlans: vlan 10 and 19What would be the impact to the end hosts?Also, can you tell me why the arp is not syncing for all the three devices? [code]
I have multiple 6509 vss switch. and i notice when the standby chassis reboot I didn't get any snmp trap, but I got when the active one reboot. my question is is there any mib out there for detecting and got a trap when standby reboot?
I have my hsp setup where switch A and switch B share active/standby roles among several vlans. In the last few weeks, i have seen trouble tickets where connectivity is lost and upon investigation i discover that i can ping physical interface IP addresses for both standby and active devices but not the standby IP. I have also validated configurations and layer 2 paths and they haven't been broken.
What I end up doing is failover to the standby device and back and the problem clears, reachability is restored. My question is whether I am solving this the right way. If so, what is it that would cause the standby IP to not be reachable and how does my solution fix that? N/B the switches are catalyst 6509's.