Cisco Switching/Routing :: 6850 Pvst Alternate Block Avoidance

Mar 14, 2013

I have an alcatel 6850 switch connected to a 3750. Two connections (cables) are used between the switches. The two connections from the alcatel are in different vlans 10 and 60 , but the cisco ones are in the same vlan ie 1 (I know not best practice but keep with it ). The cisco cables are connected into port 1 and 4. Port 1 is forwarding and 4 is blocking. The 3750 is configured with basic default pvst configuration.The alcatel is the root bridge. As can be realised traffic from alcatel on vlan 10 cannot pass traffic to the 3750, This was established by the spt seeing the same mac from the root bridge therefore blocking port 4.To stop this from blocking in this scenario I was going to use bpdufilter.

View 1 Replies


ADVERTISEMENT

Cisco Switching/Routing :: 6509 - Changing From PVST To Rapid-PVST

Dec 15, 2011

As a part of a major network cleanup/standardization project I have been working on for several weeks, I am now looking at spanning-tree and trying to get my company into line with Cisco Best Practice.  I currently have 3 switches in the data center that are spanning-tree root for different vlans.  Before I changing vlan priorities in spanning-tree, I feel that I should change from PVST that everything is on now to Rapid-PVST.  To minimize the momentary network disruptions from making the change, should I do the edge switches first and do the switches in the data center at the last ?
 
Related to this process is something that I want to do probably after the PVST to Rapid-PVST change.  I am going to manually set the vlan priorities for each vlan on the main core switch.  Assuming I set the vlan priority for each vlan on my main core switch (6509) to 4096, should I set the switch I want to be the backup to 8192 for each vlan and then set the edge switches to something like  12288 to keep them from getting up in the spanning-tree hierarchy  and for general principle to leave nothing to chance ?

View 9 Replies View Related

Cisco Switching/Routing :: 4096 - Influence Access Port Gi2/0/1 To Be Elected As Alternate?

Mar 2, 2013

Recently implemented a branch office LAN with dual core switches (core a and core b) all access switches connect to core a and core b.core a is root bridge with priority 0, b is as secondary root bridge with priority 4096  and rest of the switches with defaulf priority.
 
when a access switch is connected to core a and core b. RSTP converged but core b elected as Alternate role instead as designated on access switch side to core a as root port and core b as designated.How can I influence access switch port Gi2/0/1 to be elect as Alternate port and Core B port G1/1/1 as Designated port..?

View 6 Replies View Related

Cisco Switching/Routing :: Rapid-pvst Missing On 2950?

Nov 15, 2011

i'm trying to type the command (config)#spanning-tree mode rapid-pvst on my Cisco 2950, but (config)#spanning-tree mode ? only shows me one option - pvst. I've checked the Cisco support page which suggests my version of IOS should support rapid-pvst.

Switch_1#sh ver
Cisco Internetwork Operating System Software
IOS (tm) C2950 Software (C2950-I6Q4L2-M), Version 12.1(13)EA1, RELEASE SOFTWARE (fc1)

View 7 Replies View Related

Cisco Switching/Routing :: Configure MST On ASR And Have Rapid-pvst On 7600?

Jun 13, 2013

Is it possible to configure MST on ASR and have rapid-pvst on 7600? can they interoperate? ASR sees no BPDUs and both are root bridges.

View 2 Replies View Related

Cisco Switching/Routing :: Enabling Rapid-PVST In Catalyst 6513?

Mar 23, 2013

I can not  enable to rapid- protocol in catalyst 6513, does not support for it, only support pvst.
 
Someone how can i enable to rpvst? You know if is necessary to upgrade IOS, it has
s72033_rp-ENTSERVICESK9_WAN-M - 12.2(18)SXF9 IOS. The cisco software Advisor could not localized the features fot this IOS.

View 1 Replies View Related

Cisco Switching/Routing :: 3750 Adjusting Rapid PVST Timers

Jan 18, 2012

We have two L3 3750 switches running HSRP and routing for various Vlans on our corporate network. Rapid PVST is running across our entire WAN.   We are introducing a third party solution for remote communications over MPLS.  When interconnecting this equipment to our core network, we have experienced less than desirable failover times of 32 seconds and recovery times of 60 seconds.   The vendors engineers are telling is that the interoperability between IEEE spanning tree and Rapid PVST is the culprit. 

They are suggesting two scenarios - either converting our corporate network to MST (which I prefer not to do but provides us the fastest fail/recovery times) or adjust the timers on our Rapid PVST forwarding timer to 4 seconds.  What would the implications be to change these timers on our network, and if I choose to do this, do I only do it at the core (on the two devices that would become root bridge)?  I have been doing some reading that says to not mess with the timers, but nowhere do I see reasons why. 

View 2 Replies View Related

Cisco Switching/Routing :: STP Stops Loops But R-PVST Goes Flapping 2960

Feb 22, 2012

Stange problem which I encountered today, I have a Cisco 2960 which is connected to a netgear. The switch started showing itself in CDP and was running STP. I checked the cables physically today and noted 3 uplinks to the netgear, all port on the Cisco active and forwarding and green lights.
 
The Cisco was running STP, I changed it to R-PVST and the lights on the Cisco went crazy and I got the message port flapping on the switch but the switch did not block any ports (all ports on same vlan).
 
There after I changed it back to stp and the switch blocked the other up links apart from one.
 
Sure R-PVST is far superior than STP?

View 5 Replies View Related

Cisco Switching/Routing :: 28672 Two Root Bridges VLAN1 Rapid-pvst

Apr 1, 2013

I have two locations DC and Corp connected to each other via Point to Point Circuit.  I have forced the two core switches setup as GLBP pair to be primary and secondary for certain VLAN's including VLAN1.I have a switch in our Corporate office 3750 which is where the point to point circuit terminates.  VLAN1 SVI is manually shut on that switch.  Also the priority on VLAN1 is increased manually like this, "spanning-tree vlan 1 priority 28672". 
 
Now the issue is that the Primarey Root Bridge in the DC is the root bridge for VLAN 1.  But this other switch 3750 in our corporate office also is a root bridge for VLAN1.  [code]

View 17 Replies View Related

Cisco Switching/Routing :: 3750 / Configure Rapid-pvst On Both Blade Switches Or Keep Default Configuration

Nov 14, 2011

3750 switch connects to Blade-switch_1 and Blade-switch_2 Spanning-tree mode is configured as rapid-pvst on 3750 switch, do I need to configure rapid-pvst on both blade-switches or keep the default pvst config.3750 is running VTP domain HQ and transparent mode Both Blade_switches are running VTP domain CLI and transparent mode To configure Etherchannel between 3750 and blade-switch_1 do I need to have all devices in same vtp domain?

View 16 Replies View Related

Cisco Switches :: SG300-52 Continuous Reboot After TCP Congestion Avoidance Engaged

Mar 12, 2012

I have an SG300-52 gigabit switch that has been constantly rebooting and is effectively unusable.This started after Enabling TCP Congestion Avoidance, specifically:
 
-Turned on TCP CA
-Saved Running Config -> Startup Config
-Rebooted Switch
 
Since then the switch has been rebooting roughly every half a minute, and the management (HTTP) interface is inaccessible. In addition the factory reset (i.e. reset button for greater than 10 seconds) does not make a difference. I suspect that there is some bug with TCP CA that causes the switch to fail to start up, and that factory reset has failed to clear the startup config.

View 2 Replies View Related

Cisco Switching/Routing :: 2960 What Can Block ARP

Feb 23, 2012

We recently updated a site2site link to metro ethernet, ISP call it 100mbps LAN Extension, but to me it is just QinQ over fibre connection. Most went well, one thing (annoying to me) is we can not ping our switches on both ends anymore.
 
We have a 3750 in headend and another 2960 on the other end. I used to be able to ping/telnet to the management IP from one to the other. Now we can not. I think the ISP is applying some configuration on ports of their customer-premises equipments (both are Cisco switches) but agent in ISP told me no. I thought there is some configuration on Cisco switch to block "MAC discovery" but i just can not remmenber what was that and google also failed me this time.

View 3 Replies View Related

Cisco Switching/Routing :: 6509 ACL Block TCP Traffic One Way

Jul 14, 2010

Got servers in vlan 10 ip range 10.0.0.0 and servers in vlan 20 ip range 20.0.0.0 at the same layer 3 switch. (c6509 sup720)I would like to block TCP traffic initiated from Vlan 20 to Vlan 10. But the servers in Vlan 10 needs to be able to open an TCP connections to Vlan 20 did test with the ACL thats blocking (ack/established/syn) but unable to get it to work.Or it works both directions or is works non directions.

View 4 Replies View Related

Cisco Switching/Routing :: 3560 - How To Block A Vlan

Jul 22, 2012

I have 4 vlan and all has conectivity/access with all (VLAN10,VLAN20,VLAN30 and VLAN40, I use a 3560 Switch for this propose, I need to modificate one vlan (VLAN40) that has access to the rest of the VLAN's BUT the rest of the VLAN's dont have access to VLAN40. I know that it is a problem of access-list BUT I can't undertand how to obtain the result that I like

View 1 Replies View Related

Cisco Switching/Routing :: Best Way To Block Website On 2800

Nov 26, 2012

I have a 2800 router and tried so many ways to block the unwanted sites on my office network.Like access list ip based, null0 routing and policy map. Faced issues with below config

1. Creating Access-list. very difficulty to block the sites with https those sites will be opend, and we cant block all the IPs
 
2. Creating null0 routing. it also a bit deficult the block maximum sites because we can't fiend all IPs for those sites
 
3. Policy map.. with policy map we can only 1site we can block, but not more than one..
 
I heard that port based routing or port based access-list are the best ways to stop the websites in my local network..for this one i need to map the site to unsued ports then i need to null rouging or need to create the access-list.

View 3 Replies View Related

Cisco Switching/Routing :: How To Block Sites In 2800

Nov 23, 2012

I have a cisco 2800 router.. (flash:/c2800nm-advsecurityk9-mz.151-4.M4.bin, Version 12.4(13r)T11) configured DHCP, DNS, NATING and Bandwidth restriction...And to stop some social network [URL] i configured ip route 66.220.144.0 255.255.240.0 Null0 (rang of facebook address) But still i am able to open facebook.com in my network...
 
ADMIN-II_2811#sh run
Building configuration... 
Current configuration : 1812 bytes
!
! Last configuration change at 17:26:33 UTC Sat Nov 24 2012
version 15.1
service timestamps debug datetime msec
service timestamps log datetime msec

[code]....

View 1 Replies View Related

Cisco Switching/Routing :: Block LAN To LAN Traffic On 2960

Apr 16, 2013

Is there a way to block lan to lan traffic (except lan to gateway/gateway to lan traffic of course) on a Cisco 2960?

View 9 Replies View Related

Cisco :: Device For Alternate Internet Connections?

Nov 29, 2012

I have 2 internet connections, one as primary and one as backup Internet connectionIs there any device which I can use to auto switch to backup in case of any problem in the primary internet connection ?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Patch And AD Alternate UPN Suffix

May 31, 2012

i'm using ACS 5.3.0.40.2 and its setup with an AD External Identity store for wireless PEAP MSCHAPv2. AD is configured with Alternate UPN suffixes so that for example: 22056 Subject not found in the applicable identity store(s). ##
 
I've checked the release notes for 5.3.0.40.5 and there are some changes/fixes for AD but nothing I can see to explain the behaviour above. I'm looking to upgrade to 5.3.0.40.5 soon but I really need the Alternate UPN suffixes to work.mydomain.com is the AD domain namean Alternate UPN suffix of another.com has been added to AD 
 
A valid AD user can add either the @mydomain.com or the @another.com suffixes to their username and login successfully. This works fine with 5.3.0.40.2 but changes when I upgrade to 5.3.0.40.5 - users who use the @mydomain.com login ok but users using the Alternate UPN @another.com fail with the error: [code]

View 2 Replies View Related

Cisco Switching/Routing :: Block Appletalk On 3560 Switches

Sep 9, 2012

In cisco documentation for the 3560 it is mentioned that blocking appletalk will not work .It shows up in command line but it is not working due to hardware limitation.Is there any other way to block appletalk on 3560 swiitches.

View 3 Replies View Related

Cisco Switching/Routing :: 4500 - Allow Only Specific Vendor Mac And Block Others

May 20, 2013

I have arequirement where in I need to allow only specific vendor made desktops/laptops to be connected to the switch and block the rest. Say I want only the HP made Laptops to be connected on the Network. and block all other vendors. such as dell, ibm etc.
 
 I am having Catalyst 4500 switches in My network. i tried using the mac access list using the permit and deny statement and then mapping the access list to the vlan access map and then filter using the vlan id. But this doesnt work on cat 4500....the same I tested for 2950 switch and it works perfectly. are there any restrictions on 4500 or any extra configuration has to be done.

View 2 Replies View Related

Cisco Switching/Routing :: Catalyst 4948E 10G Block Or Non-blocks

Jan 14, 2012

I want to understand - if 10G ports of 4948E (4 x 10Gb) they are block or non-blocks? I want to connect this switches with 20 GB (lag) to my BB switches and i need to prepare my infrastructure to 17.5GB troughput of video traffic.

View 9 Replies View Related

Cisco Switching/Routing :: 2800 Block Some URL That Users Have Access Through LAN

Jan 30, 2012

I wish to block some url that users have access through my LAN .That's i wish to block icmp,access towards such sites, i wish to block icmp because dns will resolve the domain and they can access through ip address.what i have in place is a cisco 2800 series routers,

View 7 Replies View Related

Cisco Switching/Routing :: Nexus 7010 - How To Block SSH Access On SVI Interfaces

Jun 4, 2012

I use Nexus 7010 as our layer 3 router.I have ssh feature turned on so I can manage it from the management interface. I just found out that users can use putty to ssh to the local SVI interface of the NEXUS. Although they still need username and password to login but we dont want them even able to bring up the welcome screen.Example, user's IP is : 172.16.25.100 , they can ssh to 172.16.25.1 which is the NX SVI interface.

View 1 Replies View Related

Cisco Switching/Routing :: How To Block Single Mac Address In 3550 Switch

Nov 16, 2011

I need to block this mac address in  my 3550 switch.i enable port security but this mac address comes and do the violation and port is shut down.

View 3 Replies View Related

Cisco Switching/Routing :: 3560x / Block DHCP Requests Over VLANs

Jan 10, 2012

I have two 3560x Catalyst switches setup between two different locations. They link via a PTP line (Layer 2). I have setup Intervlan routing between the switches and that works fine.Each location has a separate subnet and a Windows DHCP server for each subnet.I want to block any DHCP requests to be sent from hosts on one subnet to the DHCP server on the other side (i.e across the PTP link) What is the best method to do this?

View 5 Replies View Related

Cisco Switching/Routing :: 2911 / Block All Traffic But Allow One Way Data Transfer?

Feb 5, 2013

I am trying to connect a Control network that can not have access to the Internet, or any other network for that matter, to my Admin network so that I can retrieve trend data about the plant that goes into a database. Right now the process is print information, hand jam into excel spreadsheet, print again, and hand jam into another excel spreadsheet on the other network. Reports are printed automatically once a day, but would like a simplified way of getting data from one network to the other without having to re-enter data several times. Current policies stipulate no USB drives connected to Control systems. Even if we could loosen that, personnel needed to transfer data is not available and going to each individual machine would take more time than current system.Now that background is laid, I have two 2911 ISR routers with EIGRP configured, each with a 4 port EHWIC card. The 3 L3 ports on the router are setup as follows: interface G0/1 to the internet, interface G0/2 to a wireless  back haul, and interface G0/0 for IT network. I then have 3 VLANs setup on the EHWICs for our Admin network. We will move the IT network to a VLAN on the remaining EHWIC port and connect the two 2911's through the G0/0 interface. I am going to have one computer on my Administration network dedicated to receiving the information and have a program that will take that data and import it to a database. I need to allow only that computer to receive traffic from the Control network and I need no traffic to flow back into the Control network. In other words I will transmit data from the control network to the admin computer using one protocol (TFTP more than likely) and block any other traffic coming out of and going into the Control network.

View 1 Replies View Related

Cisco Switching/Routing :: 3550 / Access List - Block One Ip Or Port

Jan 9, 2012

I have a layer 3 switch, 3550.I have several vlans on there just for playing around with. One of the vlans, has a vonage linksys box attached to it with a UK number attached. From time to time telemarketers call at 03:00 in the morning, this as I'm sure you can imagine is not much fun. The linksys box gets 192.168.3.3 as it's ip.The switch is connected to a non cisco router at 192.168.0.1
 
interface FastEthernet0/24
no switchport
ip address 192.168.0.2 255.255.255.0
 
I was thinking a time based access list would work best I have tried several variations but the phone still rings. I have tried access-list 1 deny host 192.168.3.3 permit ..... and more extensive lists but the phone still rings. I have not applied the time-range yet, so that's not the problem.I have applied the list to the vlan interface and to fa0/24 but it's not working.

View 3 Replies View Related

Cisco Switching/Routing :: ASA 5510 Connectivity - Rule To Block Protocols

Nov 29, 2012

I've configured an ASA 5510 FW with asa901-k8 ios. on it's "inside" port there is 10.90.0.0 network. there is another network (10.190.0.0) in my system that can be reached via another router which has 10.90.0.253 ip address. when a client in the 10.90 network wants to reach the 10.190 network the fw redirects the request to the router (10.90.0.253) because the fw is my gateway. there is no problem so far... but... while i can ping and traceroute a 10.190... user from 10.90... network, i can't use any non-icmp appliactions. for example i can't use rdp programs, http web interfaces of some devices on remote network (10.190.0.0). what can cause that? is there any rule in asa that blocks these protocols?

View 4 Replies View Related

Cisco Switching/Routing :: Implement ASA 5510 / 5505 For Existing IP Block

Jun 5, 2012

some recommendations for product selection and overall infrastructure setup for our datacenter:  We have an old, legacy setup, and are looking to replace equipment, improve performance, enhance security, and implement hardware redundancy (if cost effective).
 
1)  We now have (2) IP blocks from our provider, and need to support both (because we have mailers on older IPs with a good reputation rating).
2)  We have (2) aged Sonicwalls, one for each IP block, each connects to multiple internal subnets (some internal subnets need connectivity to eachother, some don't).
3)  We have (mostly) public facing web servers (Linux/Apache), as well as database servers (with no external access).
 
Questions-

1)  Should we implement a Cisco ASA 5520 w/ or w/o SSM modules for the new IP block (for webservers)?
1a)  Should we implement a Cisco ASA 5510 or 5505 for the existing IP block (for mailers)?
1b)  Or, can we have multiple public IP blocks connected to a single ASA 5520 (or 2 ASA's w/ failover)?
2)  Can we connect both firewalls (5520 and 5510/5505) to a single Catalyst 3550 (or similar) using VLANs, and have 6 - 10 VLANs for webserver subnets, with ACLs controlling which subnets/servers can connect to eachother?
2a)  Should we implement a second Catalyst 3550 (or similar) for redundancy (webservers have multiple network cards).
3)  From our provider, we only have (1) dmark which both IP blocks connect through.  Currently we have a switch connected to the dmark in order to 'splice' the connection, and have both existing firewalls connected.  Is there a better approach to this?
4)  We would like to implement SSL-VPN, and possibly site to site IPSec VPN, but only if there will not be significant performance degredation.
5)  Other thoughts/recommendations for new features, enhanced security, or redundancy?

View 1 Replies View Related

Cisco Switching/Routing :: Block All DHCP Packets Through 2960S LAN Base IOS?

Mar 23, 2013

I am trying to block all dhcp packets through 2960S lan base IOS. But when i set no trust interface for dhcp snooping, the dhcp packet source port will be err-disabled.  Is there any other solution to block any DHCP packet through switch without interface or other service outage?Is possible to block DHCP packet through specific VLAN?

View 6 Replies View Related

Cisco Switching/Routing :: 2821 Best Way To Block A Vlan From Accessing Other Vlans

May 22, 2012

I have a LAN with 6 vlans and a 2821 router. By default, intervlan routing is enabled for all vlans, however, I want specific vlans to be denied access to others, though all should still be able to use the Internet being served from GE/0.

View 6 Replies View Related

Cisco Switching/Routing :: 3750 - How To Block Unauthorized DHCP SOHO Router

Jan 20, 2012

If it's possible, how do you protect/block a unauthorized DHCP SOHO router with NAT form a Cisco 3750?

View 16 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved