Cisco Switching/Routing :: ME3600X Is Switchport Port-security Mac-address Sticky Available

May 5, 2012

Our customer has a Cisco ME3600X with the IOS me 360x-universalK9-mz.122-52.EY3.They are saying that is not possible to configure the "switchport port-security mac-address sticky" in the interfaces and want to know whether any additional license is needed.As far as I know there isn't any extra license to activate this feature and also I believe the ME3600 switch should have this feature with the universal IOS, isn't that right?

View 1 Replies


ADVERTISEMENT

Cisco Switching/Routing :: CE500 Switchport Port-security

Apr 19, 2012

I try change the configuration the port in the switch catalyst express 500, i need disable switch port port-security, a try with http://10.1.1.1/exec and save configuration with wr command, if a check the configuration de port is correct but i reboot the switch and check the configuration the port appear the switch port port-security configuration again.

View 3 Replies View Related

Cisco Switching/Routing :: Catalyst 3546 XL / Switchport Port-security Command Not Available

Oct 26, 2011

Im trying to follow along documentation i see via train single videos and some online resources. I am trying to enable port security.I have a Catalyst 3546 XL when i type in "rtr1# switchport ?""port-security" is not only of the options to choose from.   I have already set this as an access port.

View 4 Replies View Related

Cisco Switching/Routing :: ME3600X Storm Control On Admin Down Port

Oct 30, 2012

I have 2 ME3600Xs and utilize Broadcast and Multicast storm control on client facing interfaces.  One of my ME3600s is reporting a Multicast storm and that a packet filter action has been applied.  The strange thing is that it is showing up on an Admin Down interface that has nothing connected to it. [code]

View 2 Replies View Related

Cisco Switching/Routing :: 3560 Port Security Triggers With Valid Mac Address During Power On

Feb 28, 2013

I have 2 3560 switches that are running 12.2(25)SEE2. Port security is enabled on some of the ports. Whenever there is a power failure, when power is restored, 1 port on each switch goes to err-disabled. The mac address that causes this is a valid address for that port. Below is the configuration on one of the ports.

View 1 Replies View Related

Cisco Switching/Routing :: ME3600X Ip Accounting / Net-flow

Jul 26, 2012

Struggling to find any documentation that states both "ip accounting & netflow" are supported on the new ME3600 switches. I have tried both a 12 and 15 release of software. Netflow produces no data what so ever, ip accounting only produces data (of the global network) when configured on my uplink (running MP-BGP network) unable to get specific data for user networks in seperate VRFs. Is this a case of the commands being there but not being supported?

View 0 Replies View Related

Cisco Switching/Routing :: Using SD Card Slot On ME3600X

Mar 13, 2013

we are trying to use the SD Card Slot on an Cisco ME3600X (ME-3600X-24FS-M) IOS Version 15.2(4)S2. If i try to copy a file from the sd card slot to the flash there is no Option like "slot0:" or something alse and no syslog message appers while adding the SD Card.

View 5 Replies View Related

Cisco Switching/Routing :: 3750 - ME3600X Vs WS-C3750X-24S-S

Apr 16, 2012

I'm looking for a 24-port SFP switch. Each of the two switches in the subject meets that requirement.  If I went with the ME switch over the 3750 (at about half the cost), what features/functionality if any, would I be giving up?

View 5 Replies View Related

Cisco Switching/Routing :: Enabling Port Security On C4507R Shuts Down Port

Aug 13, 2012

I'm trying to enable port security on several 4507R's. When I try to configure a range of ports the switch will randomly put 1 or 2 in err-disable.  It's different every time I apply the config to the same group of ports.  However if I do them one at a time it seems to work.  But I really don't want to configure 6 fully populated switches one port at a time.   We also have a lot of 3750's and they gave me no problem using a port range. [code]

View 4 Replies View Related

Cisco Switching/Routing :: Cat 3560 No Switchport Command Test Out Routing With Switch

Dec 8, 2011

The last few days I've been exploring options in getting rid of some old routers accross a wan connections.  I have a cat 3560 to play with and I thought I would try and use the no switchport command test out routing with switch.  I've got some type of route issue and I tried a few things which I thought would fix the issue but had no effect.  I'll post the config and a few commands so you can see what the basic setup is. 

Here we can see in the arp that it knows about both 10.7.1.2 (PC unable to ping 10.3.3.254) as well as 10.3.3.254 (ASA).I tried adding in a ip route of 10.7.0.0 255.255.0.0 10.3.3.110 as well as 10.3.3.254.  Neither produced the results I wanted allowing 10.7.1.2 (PC) to ping the ASA (10.3.3.254). [code]

View 4 Replies View Related

Cisco Switching/Routing :: Nexus 7K No Switchport Command Available?

Mar 22, 2013

I created new VDCs.  Since I have done so, there is not switchport command under the interface configuration.
 
The interesting this is that it is available on the admin VDC, but not the new VDC I created.  I cannot create a peer VPC Peer link between my 2 Nexus switches.  I did allocate ports to the new VDC and I did verify the enabled feature are the same.
 
why the switchport command is not available?

View 3 Replies View Related

Cisco Switching/Routing :: 3750 - Two Different MAC Addresses On Same Switchport

Feb 16, 2012

I have Catalyst 3750 running IOS version c3750-ipservicesk9-mz.122-55.SE.bin.  I have an access port that connects to a Redhat Linux version 5.4 64 bits machine.  When I perform a "show mac address-table interface g1/0/3" where the redhat machine is connected to, I see two mac addresses on this access port.  One of the mac addresses, 0025.9006.4898,  belongs the the redhat machine.  the other mac address, I have no idea where it comes from.  I tried to perform clear mac address-table dynamic g1/0/3 several times but it does not work either.

View 8 Replies View Related

Cisco Switching/Routing :: Unable To Policy Switchport Interface Of 861

Jul 24, 2012

I'm unable to apply a policing limit in a switchport of the CISCO861 router. This is my configuration:interface FastEthernet0, service-policy input wired-input,service-policy output wired-output end.

View 3 Replies View Related

Cisco Switching/Routing :: 3524xL - Switchport Voice VLan

Nov 10, 2012

I have encountered a different issue. When I configure " switchport voice vlan 2" under f0/2 connected to ip phone, it does not have any effect.
 
Below is my set up:
Sw  is cisco cat 3524 XL.
 
ip phone-------f0/2( vlan1)-----SW----f0/1---trunk------f0/0-CME-router+dhcp
                                                          |
                                                       f0/3( vlan2)
                                                       tftp server ( 201.201.201.3)
 
switch has two vlans:
 
vlan1 (data)   200.200.200.0/24
vlan 2 (voice)  201.201.201.0/24
 
Switch management int vlan 1 : 200.200.200.3
 
router
f0/0.1  200.200.200.1
f0/0.2  201.201.201.1
 
The trunk is working correctly. (code)

View 7 Replies View Related

Cisco Switching/Routing :: 2960 - Multiple VLANS On 1 Switchport

Apr 30, 2012

I have a a hardware server running a VM hosting virtual servers which are all on different VLANs. My challenge now is to configure the switchport that the server is connected to, to see all the VLANs needed by this VM. The VM has an IP that is used for managing the server VMs which is on a different VLAN also.
 
My switch is a 2960 switch and it is presently trunked from the core switch.

View 3 Replies View Related

Cisco Switching/Routing :: 2901 - Multiple Subnets On Same Vlan Switchport?

Jun 29, 2012

I have a Cisco 2901 with the 4port gigabit ethernet switch module that I'm trying to get configured to have a seperate subnet for each port.  So far I have it set up so each subnet is a vlan, then on each port I use the switchport access vlan command to tell it which subnet I want that port to be on.  However, there is one port that I need to have 2 subnets on.  The way I found to do that was to use switchport trunking on that port, but it doesn't seem to be working properly. how they would configure this?  Right now I have vlan 101 as x.x.x.17/28 and vlan 103 as x.x.x.53/30.  I think where I'm getting hung up is the proper association between the physical port and the vlan subnets.

View 5 Replies View Related

Cisco Switching/Routing :: 3750 - Make Switchport 10.1.1.13 And Then Create IP VLan?

Feb 7, 2013

Currently have two routers inside our network.

One is the default GW 10.1.1.13
One is Jump Router for ATT 10.1.1.12
Both connected to HP Procurve L2 switch

The ATT Router is 10.1.1.2Want to replace GW and Jump with one 3750 L3 switch.icomplish this with only one port g0/1 connected to HP Procurve?Can I make the switchport 10.1.1.13 and then create a ip vlan999 10.1.1.12?route all to 10.1.1.2Or do I just connect two ports, and hardcode them with an ip?

View 1 Replies View Related

Cisco Switching/Routing :: 2950 Error Would Be That Sticky Command Doesn't Exist

Jun 5, 2013

I'm having an issue with port-security on a cisco 2950 switch. The port-security is setup to user sticky mac-addresses and was working just fine. Recently when a computer was changed out and I needed to clear the security on the port it wouldn't let me.I would type clear port-security sticky int fa0/## and it would give me an error. The error would be that the sticky command doesn't exist.So I went back and type clear port-security ? and the only option was dynamic. Even if I try to take the port security off the switch it wont let me, it never shows the option for sticky.If I change the maximum number of mac-addresses allow the computer will work, but I can never clear the old addresses out.

View 3 Replies View Related

Cisco Switching/Routing :: Switchport Trunk Encapsulation Dot1q Fails On A 4900m?

Jan 9, 2012

I'm setting up a new 4900m running  cat4500e-ipbase-mz.122-53.SG5.bin. I'm attempting to create Port-Channels as a Trunk for uplink to a 4503 running cat4500-ipbase-mz.122-37.SG1.bin.When I attempt the command "switchport trunk encapsulation dot1q" it errors out.

View 3 Replies View Related

Cisco WAN :: Unique Mac Address On All L2 Switchport Interfaces

Jun 2, 2013

I was wondering why do L2 swicthes have a unique mac address on all switchports ? These addresses are not used for mac rewrite during L2 forwarding since these switches themselves are layer to transit switches. What are these mac addreses used for then ?

View 1 Replies View Related

Cisco Switching/Routing :: How To Set Port Security On 881

Oct 25, 2011

Was wondering how to set port security on the 881. I have all the FE ports shutdown except one and want to limit that port to one specific MAC address. 

View 7 Replies View Related

Cisco Switching/Routing :: Port Security In CE500 Switch?

Sep 8, 2010

configure  port security Cisco 500 Swich ? There is no CLI mode in this switch?

View 2 Replies View Related

Cisco Switching/Routing :: 2960 - Turn Off Port Security

Dec 15, 2009

One of my engineers issued a command to turn off port security on a number of ports using the range command. The command failed on the first attempt due to a tacacs auth failure which I suspect is due to a low tacacs timeout value. The engineer then reduced the number of ports in the range command and re-issued the config change after which the switch just crashed and rebooted.
 
The logging buffer on the switch displays the following:
 
000072: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: System previously crashed with the following message:
000073: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Cisco IOS Software, C2960 Software (C2960-LANBASEK9-M), Version 12.2(50)SE3, RELEASE SOFTWARE (fc1)
000074: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Technical Support: [URL]
000075: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Copyright (c) 1986-2009 by Cisco Systems, Inc.
000076: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Compiled Wed 22-Jul-09 07:03 by prod_rel_team
000077: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED:
[Code]........
 
I have done some searching and this could be related to bug CSCsq71492. I have tried using the output interpreter but it is still down. 

View 22 Replies View Related

Cisco Switching/Routing :: SF300 - Port Security / Possible To Disable?

Aug 2, 2012

I have several SF300 switches deployed (SF300-08, SF300-24P). They are connected to IP Telephones (NEC) which communicate with the switch for auto voice VLAN on LLDP. The problem I am experiencing is that periodically the IP telephones are rebooted by the telephone vendor and when they do the switch puts that port into "Locked" port security mode and discards all traffic to the port. The IP telephones of course do not work. In other switch models, I have seen the ability to enable / disable port security switch wide or on a port by port basis. This model does not appear to have this feature. How to disable or why the phones would cause the switch ports to "lock"? There is usually one PC attached to each phone.

View 1 Replies View Related

Cisco Switching/Routing :: 2950 Port Security Is Not Working

Feb 23, 2013

I have network consists of more then 20 cisco 2950/2960/3700 switches.  I have configured port security in my switches. initially when i configured on my switches it worked fine....even for copule of months it worked fine. but suddenly it start creating issues and now i am not able to implement port security on switches. the configuration is same but there is no effect now. Same switches were fine but now even having same configuration it is not working. please see the configuration: [code]

View 5 Replies View Related

Cisco Switching/Routing :: 3750 Port-security Will Not Clear

Jun 5, 2012

We have several 3750 stacks across our campus that we are unable to completely clear port security on. We have mac address stick set up on all access ports. When we clear the sticky address on the port, the mac address is removed from the running config like normal, but we keep getting port-security voilations. If port security is taken off the port completely, i.e. no switchport port-security, traffic still doesn't pass the port. Even clear port security across the stack doesn't work. If we try to reload the stack, only the master reboots, and the other switches in the stack lose switch capabilities.

View 1 Replies View Related

Cisco Switching/Routing :: Port Security On Nortel 5520

Jun 6, 2012

I've just completed a port security project at a site on numerous Cisco switches and all works well, however they have 2 Nortel 5520 switches (which I left until the end) which they would like to lock down.  I have logged a message on the Nortel forums and I have heard nothing for days.  I just need to lock 2 ports down to the Mac address of 2 computers stopping any other computer being plugged in. 

View 2 Replies View Related

Cisco Switching/Routing :: 3550 - Port Security Verification

Apr 1, 2013

I'm trying to test port-security in my c3550 but when I show port-security int f0/23 shows it only "Disabled" as below:
 
run
interface FastEthernet0/23switchport access vlan 200switchport mode dynamic desirableswitchport port-security mac-address stickyspanning-tree portfast 

View 2 Replies View Related

Cisco Switching/Routing :: Configured Port Security On 2960 Switches

Feb 18, 2013

I configured port security on my 2960 switches with the following commands: [code]
 
The problem is that when I should change someone's PC, first I disable port-secirity, then I clear all the mac addresses learned on the interface, then I plug the new PC and enable port-security. The new PC couldn't connect to the network and it's mac address has not be learned on the interface. Why?Which commands should I use to clear an old mac address and enable port-security with the new mac address.

View 4 Replies View Related

Cisco Switching/Routing :: 3560 Port Security And Voice Vlan On Newer IOS

May 20, 2010

For many years we've had the following vlan and port security config on our 3560s: [code] This has worked great on 12.2(37)SE1, 12.2(40)SE and 12.2(46)SE. However since 12.2(50)SE, and I've tried all the versions since then, we have a problem with 7900 phones and ATA186s taking upwards of 20 minutes before they can get a valid IP number.The problem on the newer IOSes seems to be related to the inactivity aging.On the older IOS versions the mac address of the voice device appears on the voice vlan straight away.
 
On the newer IOS versions the mac address of the voice device appears on the DATA vlan and seems to be stuck there until the inactivity aging removes it. It then gets re-learned, sometimes on the voice vlan, and sometimes on the data vlan. If you're unlucky and it gets re-learned on the data vlan you've got to wait until the inactivity time ages the address out again. Repeat until the mac address eventually gets learned on the voice vlan. I don't want to be stuck on 12.2(46)SE forever.

View 11 Replies View Related

Cisco Switching/Routing :: Port Security Dynamic Configuration On Catalyst 3560xPOE

Oct 2, 2012

I have connected a 10BaseT device to a CISCO Catalyst 3560xPOE switch with dynamic port security.  All seems to work fine when the distance between the two devices is closer then 200ft.  When I connect to 10BaseT devices farther out near 300ft the response from the attached device is lost. It works ok on unmanaged switches at the longer distance. Is there a minimum response time from attached devices for dynamic port security to work properly?  Is there any other explanation why it would work on cheaper switches, but not on the Port Secured Switch?

View 2 Replies View Related

Cisco Switching/Routing :: 1941 Port-Security With Router Switch Module

Feb 29, 2012

I have a 1941 that I am going to deploy with a HWIC-D-9ESW switch module (I only need 3 switch ports but need the PoE).  I am going to hang a 1262 autonomous AP off one of the ports but I need to configure MAC address port-security so that only that AP can pass traffic. I know the switch modules are 'almost' exactly like a switch for commands but I can't seem to enable or configure any port-security settings.  Is port-security no available on the switch modules?

View 3 Replies View Related

Cisco Switching/Routing :: Cat 3750 Drops First Frame / Packet With Port Security

Mar 5, 2013

our C3750 like the one described here [URL]
 
We have the port on the switch set like this:
switchport port-security maximum 25
switchport port-security
switchport port-security aging time 2
switchport port-security violation restrict
switchport port-security aging type inactivity
 
In case a device connected to the port is inactive for more than 2 minues ( aging time ) the first frame/packet the device generates arrives to the port on the switch, but the switch does not forward it to the appropriate port ( discards it or whatever ).
 
So far I tested on
1 30    WS-C3750E-24PD     15.0(2)SE2            C3750E-IPBASEK9-M       
2 30    WS-C3750E-24PD     15.0(2)SE2            C3750E-IPBASEK9-M       
3 52    WS-C3750G-48PS     15.0(2)SE2            C3750-IPBASEK9-M

[Code].....
 
When we remove port security from the port, it works perfectly fine, as expected.
 
It seems this is not HW or IOS version related. It seems it is not a stack synchronization issue, it does not matter if a device is connected to the first or other stack member. I tested on C3560 too, here there are no problems, so seems it is 3750 related.

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved