Cisco Switching/Routing :: Configure RADIUS In IOS15 On 3750X?
Mar 21, 2013
I went to configure RADIUS on my 3750X with IOS 15, and lo and behold it is not where it used to be. Did it get moved somewhere else that I can't seem to find very easily?
We have many 3750E's and need to use Finisar X2 modules FTLX8541E2. After 15.0(1) IOS upgrade the 3750's now recognize the Cisco part X2-10GB-LRM's, but will not recognize our Finisar modules.
I'm about to configure radius on a 2960 and 2955 switch as I have been testing this on a 1841 router and to my dismay I can't see the options to configure radius, do these L2 switches not supoprt radius?
edit - apoligies I forgot the "aaa new-model" all ok now
I have a one 3750x switch and 10 nos of 2950 switch, i want to configuration etherchanel between 3750 to 2950, for that i need 10 nos of etherchanel interface(virtual), but the 2950 switch support maximum of 6 nos of etherchanel port?
Possible to configure multichassis port-channel between a VSS and 3750X (Port-channel not in the same switch on the 3750X stack). I got it using LACP but I need Pagp to get VSL redundancy “dual-active detection pagp trust channel-group 1”. I am using the last VSS IOS version 15.0(1)SY. I can’t get the option “switch 1 preempt”, has it changed with other option?
I have two stacks 3750X on two different sites with two links L_2_L, and I want to configure the port channel to aggregate the two links.
Site A Site B 3750X -A1 --------------------------------------( )--------------------------------------- 3750X -B1 ( L-2-L ) 3750X -A2 --------------------------------------( )--------------------------------------- 3750X -B2
Below the configuration that I have put the two stacks.
site A interface Port-channel5 description Etherchannel group entre le stack 3750X-A et Switch Lan_2_Lan switchport trunk encapsulation dot1q switchport trunk allowed vlan 11,12,999 switchport mode trunk switchport nonegotiate speed 100
But the problem is only one link is Bundeled in channel group, see below
Group Port-channel Protocol Ports ------+-------------+-----------+----------------------------------------------- 5 Po5(SU) LACP Gi1/0/15(I) Gi2/0/15(P)
My management has tasked me to give them a high level overview of the different switching we can choose for our new building.
This is what I know so far.4 Closets, each closet has 450 ports,One MDF room that is will contain one UCS Chassis and a Nimble iSCSI SAN.
I am working on the spreadsheet and it looks like this (Not totally filled):
2960s3560x3750x45064510Approx cost (Each, 48PORT, POE+, 10G uplink, Dual PS, IP BASE) 6K7K8K45K75KMax Capacity192432432192384Backplane speed206464520520ProLeast ExpensiveStackable to 9Stackable to 9ProDual PSDual PSDual PSDual PSDual PSProLayer 3 opt Layer 3 optDual SupsDual SupsConExpensiveExpensiveConNo Dual PSConLayer 2 OnlyCannot stack more than 4 For the MDF I would like to use 2 Nexus 5548's with FEX's, and the layer 3 daughter board. For the IDF's I was thinking of two 4010's.
i cant find any difference in these two devices when i am trying to compare throughput.I need upgrade our new POP and there will be around 4900 MAC adresses in VLAN 150 and 130 MAC adresses in vlan 200.Uplink is 1 gig routed internet connection and there is 14 downlinks to separate villages.i found a few differences for eg stack interface on 3750x but i dont need it.
I have a stack of 2 x 3750X switches these are running 12.2(55)SE5. I needed to add some static IP routes and found that the ‘ip routing’ command is not supported. I came across a document that stated “On switches running the LAN base feature, static routing on VLANs is supported only with Cisco IOS Release 12.2(58)SE and later.” So I have upgraded to 12.2(58)SE2, but ‘ip routing’ is still not a valid command.
The release notes state:“On the Cisco Catalyst 3560-X and 3750-X Series, it adds support for 16 static IPv4 routes in the LAN Base image.”
I have read other posts that talk about running the ‘sdm prefer routing’ command which I have done, but I am still unable to add any routes or run the ‘ip routing’ command.
I have an 1811 with several subnets connected to it.I recently installed a 3750x plant and want to bring my interior routing back to it.
All the routing is handled by the 1811 via secondary interfaces on vlan1?
I have 192 ports, and subnets show up on almost all of them. None of the ports are assigned to any specific vlans. Most ports have several subnets on them.
What is the best approach to getting the 3750x to handle the routing?
my company pay a switch 3750 X. WS-C3750X-24T-E. It uses IP services basically but I failed to configure InterVLAN routing. why interVLAN routing doesn't work on my switch?
I am setting up a vm environment for a customer in my lab off site. I have two stacked 3750-x switches, a san, and threes UCS c220 M3S servers for hosts. I am trying to separate the lan traffic, san iscsi traffic, and san management traffic using vlans. The problem is i'm unable to communicate cross vlan with my current config, which I have attached to this post. The only noteworthy things in my conifg is that the ip route 0.0.0.0 0.0.0.0 192.168.83.6 is referring to a switch stack they have on site, that I will connect this stack to using the first two trunk ports on each switch, that I do not have here in the lab. I don't want to cause any confusion in why I have things set a certain way.
Why does my 3750x-12s switch say it's not supported in CNA??? I upgraded to CNA 5.7.1 and still says unsupported. This device is supported or I'm just missing something.I use CNA heavily to manage our MANY vlans.
I want to confirm this is a licensing issue. On a 3750X with ipbase, I cannot create a vrf. So I would need the universal image, and that is a seperate license, correct?Is there a link that describes the difference bewteen ipbase and univeral images?
PC---2960---3750(One Routed Port and All Switched Port)------------------------ 3750(One Routed Port and All Switched Port)-----2960------Internet
I have many Vlans on left side of image , Right Side of Image is having internet connection via Modem, and local connectivity between VLAN works fine but Other Vlans Except Vlan1 is able to Access Internet.Note that 3750X did not have NAT Feature ,How should I able to get Internet on Other Vlans (10,20)
There seems to be a lot of conflicting information on what can and can't stack together in the 3750X range.
I know that LAN Base can only stack with other LAN Base switches.
Can IP Base stack with IP services in 3750X? I have also heard that the 15.x.x IOS restricts mixed feature set stacks?
I know that Cisco recommends that all switches in a stack have the same IOS and feature set but having all IP Services in a stack can get too expensive.
I'm trying to review a QoS setup, and I'd like to make sure I fully understand the current setup before I change anything. I'm seeing output drops on two different queue-thresholds, but not sure how packets are making it to one of the queues.
Switch Version CORE#show ver Cisco IOS Software, C3750E Software (C3750E-UNIVERSALK9-M), Version 15.0(2)SE, RELEASE SOFTWARE (fc1) System image file is "flash:/c3750e-universalk9-mz.150-2.SE/c3750e-universalk9-mz.150-2.SE.bin" cisco WS-C3750X-24 (PowerPC405) processor (revision A0) with 262144K bytes of memory. Switch Ports Model SW Version(code)
I can find queue4-threshold3 in the mappings, but how are packets getting mapped to queue2-threshold1? The priority queue is disabled for this interface, so I'm not sure how this queue is dropping packets, according to the maps nothing is mapped to 02-01.
I am building a switch stack using 4 48 port 3750X switches that will also have the power stacked. If I install a single 715W power supply in each switch will the stack support 802.3af accross all 48 ports on each switch? My calculations are 48 ports x 15.4W which gives me almost 740W needed which is over hte 715W power supply. I was reading somewhere were it mentioned that in a powerstack additional power can be drawn from the stack. I know this will not work if you are trying to support power on all switches accross all ports but would it if say 2 of the 4 switches are needing to provide PoE accross all 48 ports? If I say we can only use 24 ports per switch for PoE that drops the power need down to 370W which I believe should work. Just trying to get a better understanding of PoE consumption. Would the best solution be to just add a second power supply to each switch?
We are using mac authentication, it is working fine on all of the other 3560's except this new one.
Mac address shows up completely different (very long hex, doesnt even look like a mac address) on ACS compared to what its showing on the switch in the mac address table.
Im stumped, config matches every other 3560 in the building, has something changed in the v2 software compared to the older 3560's ?
A Cisco 3560V2 was bought to complete a project at my company. I noticed the IPBase IOS Image was installed. I was unable to configure RADIUS. I upgraded the IOS to the Latest Release of the IPServices IOS Image. I still dont have the capabilities of configuring RADIUS.
I have a switch which is rebooting it self, we bought it a year back,its a new switch, i did not find any error on sh ver after rebooting. I am using OP manager, i did not receive any alerts. I have done all diagnostic test, all are passed, i did not find any problem..
I am having an odd issue on a couple of new 3750X switches.I am trying to configure VRF-lite and it is not recoginizing the command.Does that make any sense? I have goggled the syntax ans it should be right.
we are replacing network equipment at one of our sites. The network will have 12, 3750X switches(6 stacks) - one stack will be the core. A 1002 will be the WAN router to the Main campus. The 1002 will connect to the core via 2 ethernet cables. I'm debating whether to use L3 or L2 between the router and Core. I've heard that routing is more efficient if L3 is used and also I will be able to create an L3 etherchannel between the 1002 and Core switch. See the attached doc.
This 3750X stack (3 members) has some 100% cpu spikes. Is this bad enough to start tracking down the cause(s) or is this somewhat typical and not a reason for concern? I just took this reading. How can you detemine when the 100% and 80% spikes occurred?
This is my scenario. I have my IP as 172.16.1.1 (aaaa.bbbb.cccc.dddd) which has full internet access. Now when i am not available in the office, i noticed some one assigning my IP in to his workstation and gaining full internet access. How do i restrict such things? i.e. even if some one assigning my IP on the network, they shouldnt access LAN or WAN.I tried 'arp 172.16.1.1 aaaa.bbbb.cccc.dddd arpa' configuring on my L3 Cisco 3750X switch assuming i can acheive, but that did not work.
If the 3560 or 3750 "X" series support GRE.I am pretty certain the older 3750-E does not support GRE (both in hardware and software)Was hoping the new super duper X series do. If not, it could get expensive
I have been looking to find out the list of features that the IP Base IOS has for the 3750X series switch. What would be ideal is a comparable list but essentially I need to know which of the LAN Base/IP Base/IP Services has SSH functionality.
I recently created a stack using (2) 3750x switches. I have three vlans on the stack (1,105,241) Vlan 105 is configured on 6509 core switches with multicasting and are connected to the stack via gigabit fiber. It is working well with clients on the Master or SW1, however clients on SW2 do not participate in multicasting Any client pc that is connected to SW2 vlan 105 does not show up in the "sh ip igmp snooping group" command. I can statically assign a client on SW2 to the mcast groups but but they fail to register on their own. I can take the cable connection from SW2 and plug it into an SW1 Vlan 105 port and it immediately becomes a member of the groups. I can then connect it back to the SW2 port and it disappears from the group membership. IGMP and PIM are configured with the defaults.