Cisco Switching/Routing :: ASR 1001 - Configure CoPP / Unwanted Traffic?

Oct 30, 2012

I'm configuring CoPP for an ASR 1001 router with consolidated IOS XE Version: 03.07.01.S.  And I'm trying to use 'DROP' command under policy map to drop.un wanted traffic. But the drop command is not listed.


View 6 Replies


Cisco Switching/Routing :: Apply A QOS For Traffic LAN In ASR 1001?

Jan 31, 2013

i want to apply a QOS for my trafic LAN, in my ASR 1001 , the LAN is connected with ge0/0/0 interface and it configured with the service instance to bridge vlan 1 ( i do that for OTV ) i put  service policy in "service instance 1" to marking data with ef31  but i noticed that the class "plateform_datacenter" match the trafic and  the ACL associate to this class not mach any trafic trafic !
tha policy-map march trafic for Datacenter  :
 sh policy-map interface gigabitEthernet 0/0/0 service instance 1
GigabitEthernet0/0/0: EFP 1
Service-policy input: MARKING-OTV
Class-map: Platforme_DC (match-any) 


View 9 Replies View Related

Cisco Switching/Routing :: Is CoPP Only Available With 5500s

Mar 22, 2012

According to release notes, this is available in v5.1.3-n1.1. I am running 5.1.3-n1.1a According to the security guide, all you should have to do is config t, then control-plane, but I do not have that option:
nx5k-2(config)# c?
  callhome   Enter the callhome configuration mode
  cdp        Configure CDP parameters
  cfs        CFS configuration commands
  class-map  Configure a class map
  cli        Configure CLI commands
  clock      Manage the system clock
so my question is, is CoPP only available with the 5500s?

View 1 Replies View Related

Cisco Switching/Routing :: CoPP Logging On A 6500

Mar 19, 2013

I am looking for a way to see packets that are matched on certain ACLs in a CoPP policy map.  I have read that it is not a good thing to add the log keyword at the end of an ACL when using that ACL for CoPP.  I initially tried to use a logging policy map but the 6500 12.2sx doesn't support this.
how I can see source/destination IP for a certain class in a CoPP policy map?           

View 1 Replies View Related

Cisco Switching/Routing :: N7000 Details Of Packets Dropped By COPP Policy

Mar 13, 2012

On one of our N7K, we have some packets dropped by the COPP policy in the class-default class-map. Partial results of "show policy-map interface control-plane" not so long after clearing the counters : [code]
what traffic is dropped by the policy ? Is there any logging possible ?

View 2 Replies View Related

Cisco Switching/Routing :: How To Configure 6506 Or 2960G To Process Multicast Traffic

Aug 8, 2012

Multicasting.  The configuration is I have a 6506 as my core switch receiving multicasts from an interface assigned to VLAN10.  I have a monitor port setup with a PC running Observer which says multicasts are being received on the core switch.  On a different interface on the core switch I have a 2960G switch connected to it and this interface is on VLAN 10.  The 2960G switch has a workstation connected to it that needs to receive the multicasts.  How do I configure the 6506 and/or the 2960G to process the multicast traffic?         

View 0 Replies View Related

Cisco Switching/Routing :: ASR 1001 - Trace Route / HSRP / VRF

Mar 24, 2013

when i make a trace route on an ASR 1001 router to I get the following output:
VRF info: (vrf in name/id, vrf out name/id)
  1 0 msec 1 msec 0 msec
  2 1 msec 1 msec 1 msec
  3 1 msec 1 msec 1 msec
Is there a loop between and .192 (this are two routers with hsrp .190) or is this normal behavior when using trace route on an asr 1001?

View 2 Replies View Related

Cisco Switching/Routing :: ASR 1001 - IKE Phase 2 SA Expires Immediately

Dec 11, 2012

I am migration an IPsec site to site VPN config to a new ASR1001 router «facing» a Linux box (ipsec-tools + racoon). As the Debian Linux does not offer VTI, I am using a crypto map.
The working config is given below with the corresponding logs on the Linux side.
When I try to apply this previously working config to the ASR1001, I get the following error :
000855: *Dec 12 18:28:21.859 UTC: %ACE-3-TRANSERR: IOSXE-ESP(14): IKEA trans 0x1350; opcode 0x60; param 0x2EE; error 0x5; retry cnt 0
Dec 12 18:50:19 FAKE-AUCH-GW racoon: INFO: initiate new phase 1 negotiation:[500]<=>[500]
Dec 12 18:50:19 FAKE-AUCH-GW racoon: INFO: begin Identity Protection mode.
Dec 12 18:50:19 FAKE-AUCH-GW racoon: INFO: received Vendor ID: CISCO-UNITY
Dec 12 18:50:19 FAKE-AUCH-GW racoon: INFO: received Vendor ID: DPD
Dec 12 18:50:19 FAKE-AUCH-GW racoon: INFO: received Vendor ID: draft-ietf-ipsra-isakmp-xauth-06.txt(code)

View 8 Replies View Related

Cisco Switching/Routing :: Deploy OTV Using ASR 1001 Between 2 Data-centers?

Apr 9, 2013

deploy OTV using ASR 1001 between 2 data-centers? We want to acquire HSRP localization there, but at this moment I can only see lots docs are saying how to do this on N7K, not ASR. I saw it has a FHRP filtering enabled by default when the OTV configuration is done, and also see there is a access-list created by default call otv_filter_fhrp, Im just wondering besides this IP ACL there should be MAC ACL applied?

View 3 Replies View Related

Cisco Switching/Routing :: ASR 1001 False Environmental Alert

Dec 18, 2011

I have a few new ASR 1001s throwing false environmental alerts.According to the logs, the inlet temp is in excess of 100 degrees C.When I telnet to the routers, they're well within tolerance (30-32C),Running 15.1(1)S and bug toolkit shows no related issues or caveats.

View 1 Replies View Related

Cisco Switching/Routing :: ASR 1001 - Adding Redundant Power Supply?

Dec 23, 2012

I was wondering if I am able to add a redundant power supply to an asr 1001 router that is in production without losing connectivity or causing any diruption to the Users  - is it hotswappable?

View 1 Replies View Related

Cisco Switching/Routing :: 5520 Configure Traffic Flow Between Computers Inside VLANs And Routed Port

Jul 7, 2012

How to configure traffic flow between  computers inside VLANs and a routed port? Here is the setup details:
1. Switch 3750-X
2. VLAN 100 - ( SVI IP address /24)
3. VLAN 200 - ( SVI IP address /24)
4. routed port gi1/0/48 (IP address /24). Note: this port is directly connected to a firewall ASA 5520 port IP /24
Ip routing is enabled on the switch and inter vlan traffic is flowing ok. I can ping the routed port gi1/0/48 from  any computer connected in the VLAN 100 or 200. For example computer with IP can ping the routed port Switch can ping firewall port and the 'sh ip route' command shows the network /24 as directly connected network.
any computer in the two VLANs CANNOT ping firewall ASA port   Is it because inter VLAN routing does not work with a routed port on L3 switch? I looked up fallback bridging, but it is meant for non IP traffic.The goal is I am trying to set the ASA port as an internet gateway for VLANs. 

View 4 Replies View Related

Cisco Switching/Routing :: ASR 1001 - License Required To Create IPSec Tunnel?

Oct 26, 2011

what license do I need to create a IPSEC tunnel? I have an ASR 1001, running? [code]

View 2 Replies View Related

Cisco Firewall :: Configure ASA 5510 For Individual Server Traffic Routing

Jan 27, 2013

I am wondering if this is possible. We have multiple internet connections with fixed IP's coming into the office. We'd like to use one for FTP backup and another to service our websites. From what i have read a 5510 doesn't do policy based routing, but we'd like to configure our ftp server to use one of the internet pipes and our webserver to use another internet pipe. Is that possible?
We'd have two outside fixed IP interfaces and two internal interfaces. I could then use one of the internal interfaces for the web server and the other for the FTP server. consequently if the internal web server and FTP server use the fixed IP"s corresponding DNS server wouldn't that effectively route all FTP traffic out one interface and all web traffic out the other?
Then the FTP traffic would be NAT'ed to an internal interface and the HTTP & HTTPS traffic would be NAT'ed to a separate internal interface.
Then if each of the internal servers used the corresponding internal NIC on the ASA as it's gateway and the fixed IP's that correspond to the external DNS server, then it would affectively only use that gatway out for traffic? Would that work? Does it should route traffic out those pipes correct? Will the asa support two different next hop routers for the two different interfaces?

View 2 Replies View Related

Cisco WAN :: CoPP On 2811 ISR?

Aug 23, 2012

Looking to implement CoPP in our 2811 ISR. We currently have the base 256mb of DRAM in there. Will this bring our router to its knees? I've priced a RAM upgrade.

View 0 Replies View Related

Cisco WAN :: C2811 - Implement CoPP On Routers?

Apr 9, 2012

Required by regulations to implement CoPP on our routers, I installed  the following configuration on a C2811 router  pair with integrated DSU/CSU cards connecting a point T1.  STAC compression(software) is configured on the serial interfaces  and the link is often congested.


This configuration severely degraded the IP traffic flow and I had to remove it. Not having any practical experince with CoPP.

View 1 Replies View Related

Cisco Switching/Routing :: ASA 5510 Routing Specific Traffic To Inside Router

Nov 7, 2012

I have an ASA 5510, with Ethernet0 connected to Internet via a T1 line, Ethernet1 connected to LAN1, and Ethernet2 connected to LAN2.  LAN1 & LAN2 are independant, but share the Internet connection, via the T1 line.  On LAN2, I have another router that connects to the Internet, via a Comcast line.  I wish to route some of the traffic on LAN2 ( to the other Router, on LAN2 ( (connected to the Comcast line).  I have entered the following lines:

route inside2 1
route inside2 1
route inside2 1
I can trace the routes from the ASA 5510 (1st hop is to, but not from anything else on LAN2.

View 7 Replies View Related

Cisco Switching/Routing :: Routing Traffic In ASA5520 Failover Scenario

Apr 2, 2012

We're in the process of swapping in a new pair of ASA5520s and Catalyst 3750s to support two separate business units. We want Firewall A and Switch A to handle traffic for Org A (VLAN 100). Similarly, firewall B and Switch B should handle traffic for Org B (VLAN200). But we want to be able to fail traffic over in case of firewall or switch failure. Traffic between the two Orgs is being routed at the switch level. [code]

The uplink interface on each switch is currently a routed port with a static address on the uplink subnet.  This works fine in a normal state.  However, when we fail over one of the firewall contexts to the other chassis, this results in the inability to route internal traffic because the internal interface is now physically connected to a different switch with a different IP port address (obvious in hindsight).  The question is, rather than a routed port, what would be the proper way to handle traffic between the switches and firewalls in a failover scenario? If I make the uplink ports into trunks, won't this cause all packets destined for either firewall to hit both both?  Seems like that's not the way to go either? [code]

View 0 Replies View Related

Cisco Switching/Routing :: 2821 Periodically Stops Routing All Traffic

Oct 3, 2010

We've got a cisco 2821 router which periodically stops routing all traffic. It seems to happen about once every 2 weeks, and I can't find anything that could be causing it. There are no entries in the log and the router stays up and running but requires a restart to begin processing traffic again. We're running 12.4(13r)T11.Any thoughts, or troubleshooting steps to track this down?

View 7 Replies View Related

Cisco Switching/Routing :: 6509 Use Policy Based Routing To Redirect Http Traffic

May 29, 2012

We have a Catalyst 6509 switch, and we hope to use policy based routing to redirect http traffic to my proxy server, where I can find the configuration example?

View 11 Replies View Related

Cisco Switching/Routing :: Internet Traffic Not Routing Through VPN 891w?

Feb 21, 2013

I have an 891w as my edge device for my home office. I have a VLAN for family use (wired and wireless) that routes out to the internet just fine. I have a second VLAN assigned to a VPN tunnel that backhauls traffic to my corporate network (wired and wireless) and all of the traffic gets to the corporate network fine when I am on that VLAN.
However, while I am on the VPN VLAN, no traffic gets to the internet. I believe it is because I have the gateway of last resort ( set to the WAN IP address provided by my ISP, so DNS is resolving against corporate, but because there is no specific route, it is trying to dump the traffic back out the WAN without traversing the VPN tunnel.

View 4 Replies View Related

Cisco Switching/Routing :: 800 / Use ASA To Configure All The Vlans And Intervlan Routing And Access Lists?

Jul 4, 2012

upgrading our small office network. We currently have about 75 employees with probably 125 devices on the network. I'd like to create about 10 vlans for the different departments and then configure intervlan routing as needed. Currently we have all unmanaged switches and it's just a huge broadcast storm on the network. We are upgrading our Cisco 800 router to an ASA5505 sec. Plus license. I need some recommendations on switches. Of course, this needs to be done as cheap as possible.... Is there a way to use the ASA to configure all the vlans and intervlan routing and access lists and use a cheaper switch to provide the access layer to hosts?

View 4 Replies View Related

Cisco Switching/Routing :: How To Configure Policy Based Routing On 3750

Jan 28, 2013

In our datacenter we have a 3750 stack with IP base image.  I have enabled PBR and reloaded the switch.  Show sdm prefer says i am using default template.  The reason i want to use PBR is that we have 2 firewalls on the same work and want to be able to have granular control over which gateway out of the network they use but still be able to access all internal resouces accross wan and locally.

Created access list to identify traffic:
access-list 10 permit (test workstation on vlan 3)
Created policy:
route-map TestASA permit 10
match ip address 10
set ip next-hop
Assigned policy to the user vlan3:
ip policy route-map TestASA
Results:It changed the default gateway to the above gateway but i could not access any resources on any other vlan, could not access resouces accross wan. 

View 16 Replies View Related

Cisco Switching/Routing :: Configure Routing Between 2800 And 3550

Sep 18, 2012

The layer 2 switches are connected to layer 3 Switch via trunks, and routing between layer 2 switch ports with configured SVI's on 3550. All working fine. Now I'm trying to configure routing between 2800 and 3550, I tried connecting both Straight Throught and Crossover cables to the 2800 Fa0/0 and Fa0/1 ports as well as the switchports on 3550
No switchport commands are configured however, the lights do not go on for both straight through or crossover cables. I tried connecting 1750 routers but same result. My goal is to have all the VLANS routed to the internet with configuring NAT translation the router.

View 2 Replies View Related

Cisco WAN :: 6500 - Copp Configuration / Error Failed To Install Policy

Dec 12, 2012

I was trying to configure copp on one of 6500 sup-2T. Is it ok to add customized policies to the default copp "policy-default-autocopp".When I created my own customized policy using policy-map, I get following error
control-plane service-policy input policy-custom
error: failed to install policy map policy-custom

View 7 Replies View Related

Cisco Switching/Routing :: How To Configure Routing On ASA 5505

Dec 5, 2011

how do i configure the new asa 5505 to be as a router as shown in the diagram note: the isps' routers placed in head office. but i cannot change the configurations of the isp's routers.

View 9 Replies View Related

Cisco Switching/Routing :: Inbound Traffic On 7606?

Jan 17, 2013

I have two Cisco 7606 routers using BGP to connect our customers to the internet.  Recently we added a new 1G circuit in addition to an existing 1G circuit and all traffic inbound is now on this new 1G circuit.  We would like to shift some of the inbound traffic over to the other 7606.  Our Tier provider has the same AS number for both paths.  One path goes directly to New York and the other goes to Boston then New York. 

View 1 Replies View Related

Cisco Switching/Routing :: 3560X Multicast Traffic Should Not Appear

Feb 18, 2013

I have a 3560X switch with interfaces 36-48 on the same LAN. All interfaces are switchports. Hosts on 38, 39 and 40 are multicast senders: all sending to the same single multicast address. Hosts on 36 and 37 are receivers, having joined that multicast group. I created an SVI for the LAN and put it in ip pim passive. (That is the only PIM mode allowed for an SVI with my IOS.) Show ip igmp snooping groups shows that 36 and 37 are the only interfaces in this group. I attach a laptop to interface 42 and Wireshark, and the laptop is receiving the multicast traffic. The laptop does not join the group. I expect it would not see the traffic.

View 4 Replies View Related

Cisco Switching/Routing :: 6509 ACL Block TCP Traffic One Way

Jul 14, 2010

Got servers in vlan 10 ip range and servers in vlan 20 ip range at the same layer 3 switch. (c6509 sup720)I would like to block TCP traffic initiated from Vlan 20 to Vlan 10. But the servers in Vlan 10 needs to be able to open an TCP connections to Vlan 20 did test with the ACL thats blocking (ack/established/syn) but unable to get it to work.Or it works both directions or is works non directions.

View 4 Replies View Related

Cisco Switching/Routing :: 2911 - Allow Traffic Between Two LAN Interfaces?

Nov 15, 2011

I have a 2911 router. One interface is configured external (WAN) and two interfaces are configured on separate internal private subnets. What is the configuration to allow all traffic in both directions between the two internal subnets?

View 21 Replies View Related

Cisco Switching/Routing :: 2960S Cannot See VLAN100 Traffic On SW1

Jan 29, 2013

I have two switches (2960S's) both with IP Phones on VLAN100..We need to monitor voice traffic via a monitor port on SW1 of all VLAN100 traffic on both switches.The following is what we have configured, but we cannot see VLAN100 traffic on SW1
According to Cisco doco you cannot have a SPAN and RSPAN on the same session, however since these are two sessions on SW1, I would have thought it to be OK.

View 4 Replies View Related

Cisco Switching/Routing :: Block LAN To LAN Traffic On 2960

Apr 16, 2013

Is there a way to block lan to lan traffic (except lan to gateway/gateway to lan traffic of course) on a Cisco 2960?

View 9 Replies View Related

Cisco Switching/Routing :: 4500 - STM-4 (622) / How To Limit FTP Traffic

Mar 10, 2012

I have the attached setup. now i would like to limit my ftp transfer to 10 mb  from a specific vlan to ftp server on the STM-4 (622) link.  what would be the best way to limit ftp traffic to 10 mb .
following is  my switch deatils
Video_Main#sh verCisco IOS Software, IOS-XE Software, Catalyst 4500 L3 Switch Software (cat4500e-UNIVERSAL-M), Version 03.02.00.SG RELEASE SOFTWARE (fc4)Technical Support:

Cisco IOS-XE software, Copyright (c) 2005-2010 by cisco Systems, Inc.All rights reserved.  Certain components of Cisco IOS-XE software arelicensed under the GNU General Public License ("GPL") Version 2.0.  Thesoftware code licensed under GPL Version 2.0 is free software that comeswith ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify suchGPL code under the terms of GPL Version 2.0.  For more details, see thedocumentation or "License Notice" file accompanying the IOS-XE software,or the applicable URL provided on the flyer accompanying the IOS-XEsoftware.


View 2 Replies View Related

Copyrights 2005-15, All rights reserved