Cisco Switching/Routing :: C6509-E / What Is Mean That Is Packet Capture?

Apr 1, 2013

I operate between c6509-E, what did you flooding? its just packet capture gi1/3 but  i dont know it and is it attack?also same seq no switch gots it?what is problem?

View 2 Replies


ADVERTISEMENT

Cisco Switching/Routing :: Port Monitoring On A 2901 For Purpose Of Packet Capture?

Jul 26, 2012

I have always done my port monitoring (SPAN) on Cisco layer 3 switches with no issues. This time I am trying to do this on a Cisco 2901 router:

Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version 15.1(4)M2, RELEASE SOFTWARE (fc1)
System image file is "flash0:c2900-universalk9-mz.SPA.151-4.M2.bin
 
I need to have the source port gig0/0 and destination port gig0/1. There is something about the gig port enumeration (slot/port#) that makes the command rejected. It is self explanatory:
 
#sh ip int brie
Interface                  IP-Address      OK? Method Status                Protocol
Embedded-Service-Engine0/0 unassigned      YES NVRAM  administratively down down   
GigabitEthernet0/0         xxx.xxx.xxx.xxx      YES NVRAM  up                    up     
GigabitEthernet0/1         unassigned      YES NVRAM  up                    up     
Serial0/0/0:0              unassigned      YES unset  up                    up     

[code]....
 
It doesn't matter what slot or port number I use, it is always rejected. The command is rejected for Both destination and source gig interfaces. I tried a wide variety of slot/port numbers. To my best understanding the complete port names are: GigabitEthernet0/0 and GigabitEthernet0/1, so why does it think there has to be another digit after 0/0 or 0/1? Does it have anything to do with the Embedded-Service-Engine0/0 being administratively down?

View 4 Replies View Related

Protocols / Routing :: How To Capture QOS (Quality Of Service) Filed From IP Packet

Aug 8, 2012

I want to make packet sniffer which capture the IP packet and then extracting QOS filed from it's header

View 1 Replies View Related

Packet Capture In FWSM?

Oct 1, 2012

when performing packet capture in a FWSM
[code]...

View 2 Replies View Related

Cisco WAN :: Embedded Packet Capture On ASR1000

Oct 30, 2012

I'm trying to use EPC on ASR1001 running IOS-XE 3.4, and it won't work. Configuration commands are accepted by the router, but there are no packets in the capture buffer.In release notes for IOS-XE, in the 2.5 section, there is a statement that EPC is not supported on ASR1k. Is it true also for newer versions of IOS-XR?

View 1 Replies View Related

Cisco WAN :: Embedded Packet Capture On ASR 1001

Feb 5, 2012

I have a need to capture traffic on an ASR 1001 subinterface, but what I have found is that the Embedded Packet Capture feature is not supported on this platform.  Are there any simple alternatives to capture egress traffic on a subinterface or am I SOL?  This is a walk in the park on normal IOS routers...

View 1 Replies View Related

Security / Firewalls :: Which Packet Capture Program To Use

Oct 24, 2011

I have a piece of software that I suspect is sending unwanted data over the internet to some IP address. I'm not an expert in anything related to computer networks, but I figure I could use such software after playing around a little with it.What application could I use that would so the following:

a) capture all the bytes the application is trying to send out so that it seems to the application it is doing it and see the place it was trying to send it

b) after inspecting the data, if it was ok, send the packages to wherever it was supposed to go so that it seems the original application sent.

View 6 Replies View Related

Cisco WAN :: 3945 MPLS L2VPN Packet Capture

Nov 27, 2012

I want to capture packet on gi0/0 of PE1 in  order to show customer that all his traffic is encapsulated and  transmitted by L2VPN (ldp signaling) in his lab.
 
CE1-----------(g0/1)PE1(g0/0)------------PE2-----------CE2
 
PE1 and PE2 are Cisco3945 and L2VPN is working well. I  tried cisco RITE(Router IP Traffic Export Packet Capture) feature, but  the output was not what I expected. I tried both export mode and capture  mode. Only LDP hello message I got, looks like RITE is only interested  in IP packet. Monitor session wasn't effective as well because it is not  a switch.
 
Is there any other way/workaround to capture customer's traffic encapsulated in L2VPN?

What I did on PE1 when I was trying RITE export mode:
ip traffic-export profile test
bidirectional

[Code].....

View 3 Replies View Related

Cisco VPN :: ASA-5520 / Packet Capture At VPN Entry (and Exit)

Oct 20, 2011

I would like to capture packets which are going through an IPSEC tunnel. The packets originate in the appliance (syslog) and are sent to the remote via a VPN. I can see the encapsulated packets going out to the peer and I can see the ISAKMP packets to and from the peer. Because the packets originate within the appliance, they do not appear on any interface to be captured.
 
Is there some way to capture these packets before they are encapsulated?I attempted to capture packets on the asa-dataplane, but they are in a format that I cannot decode, and I cannot put a filter on the capture.
 
Hardware is ASA-5520
Software is version 8.3(2)

View 2 Replies View Related

Cisco Application :: How To Capture Packet In Load Balancer CSS11501

Jan 15, 2012

how to capture the incoming and outgoing packets on the balancer?The load balancer is connected in between the customer DCN and cisco switches 2960.The reason of capturing both incoming and outgoing packets on the balancer is to prove to our customer that there is no packet loss issue on the balancer, and it could be some issue on their DCN network.Since it is a production server, I will need to ensure that there is no impact to the incoming and outgoing traffic on the balancer and other networking equipments as well.

View 1 Replies View Related

Cisco Firewall :: ASA 5505 Using Logging & Packet-capture To Locate Virus Infected PC

Aug 2, 2011

ATT notified my company we have a virus infected pc on one our networks which sits behind a Cisco ASA 5505 running 7.2(4). The set up is a basic inside/outside NAT configuration. They gave us the destination ip address and port which the our pc is contacting.  I have been tasked to track down the infected pc.  I created the following access-list and applied to the inside interface:
 
access-list VIRUS extended permit TCP ANY host x.x.x.x EQ YYYYY log debugging interval 600 access-group VIRUS in interface inside
 
I enable logging to the console whose output did not list the IP address of the infected pc, only the ip address of the DNS servers we were using. I then used the following capture commands to try locate the internal ip address of the infected pc:
 
capture in-cap interface inside access-list VIRUS-CAP buffer 1000000 packet 1522 capture in-cap access-list VIRUS-CAP interface inside
 
Neither step worked and the resulting console output overwhelmed the firewall in a very short period of time. Before attempting this task again, I would like to know if I am going about this the right way or if there is a better methodology?

View 24 Replies View Related

Cisco Switching/Routing :: How To Upgrade WS-C6509-E IOS

Oct 14, 2012

We would like to install a WS-SVC-WISM2-1-K9 in each of our 2 WS-C6509-E chassis.  Both of these have supervisor 720 engines installed.  One in each chassis.From what I have read we need to upgrade the IOS to 12.2.33 SXJ4.  Is this correct?If this is true then what are the memory requirements for the upgrade to this IOS version.  Below is the output from Show version?Is there sufficient memory instqalled to do this install?

View 3 Replies View Related

Cisco Switching/Routing :: C6509 To Have Feedbacks About Vss Availability

Mar 9, 2012

we plan to implement VSS on our datacenters (C6509/Sup720), in order to remove L2 loops (currently, access layer are C3750 stacks, which could evoluate for N5K/N2K). I would like to have some feedbacks about VSS stability. Some years ago, I have seen some bugs with this technology in another company, so I am still not totally comfortable  to use it in the datacenter.

View 0 Replies View Related

Cisco Switching/Routing :: Impact Of ACL On C6509 CPU Utilization?

Apr 4, 2012

We plan to implement a large number of ACL on our Distribution switch which is a HSRP pair of 6509C switches running on sup-bootflash:s72033-psv-mz.122-18.SXD3.bin WE need to divide the Network in three layers
 
unsecure layer
Proxy layer
Secure layer
 
We have approximately 250 vlans on the our distribution switches and plan to implement 15 ACL on different vlans Each ACL can contain upto 30 lines or less.
 
basic ACL example we will be applying on different vlan
vlan 200
ip access-group test123 in
 
My question is Can these ACL on a vlan can have a massive impact on the 6509 CPU ?

View 1 Replies View Related

Cisco Switching/Routing :: WS-C6509-E High CPU Utilization

Jan 13, 2013

I have a 2 cisco core (cisco WS-C6509-E (R7000) processor) and been working for quite sometime.they are conneted with HSRP with active standby config with a 10 g module for redundancy just today I see that the cpu utilization went to about 50% and its the same on both cores.

[Code] .......

View 5 Replies View Related

Cisco Switching/Routing :: C6509-E Do A Unexpected Reload

Feb 26, 2012

Last night, the C6509-E do a unexpected reload. In the crashinfo, I can see that the last error message before the reload, was as follows: %C6K_ PLATFORM-SP-2-PEER_RESET: SP is being reset by the RP
 
I consulted the cisco website about this error message and what I found was the following:C6K_PLATFORM-2.

View 1 Replies View Related

Cisco Switching/Routing :: What Should Be Minimum IOS Version On WS-C6509-E

Sep 26, 2012

what should it be the minimum IOS version that I require on my WS-C6509-E equipments to support "logging origin-id" command?

Cisco documentation says that this command was introduced in 12.2(15)T, and integrated into 12.2(33)SXH.
BUT my Cisco switches have 12.2(33)SXH5 IOS version......and they do not support "logging origin-id".
 
(config)#logging ?  Hostname or A.B.C.D  IP address of the logging host  buffered             Set buffered logging parameters  buginf               Enable buginf logging for debugging  cns-events           Set CNS Event logging level  console              Set console logging parameters  count                Count every log message and timestamp last occurance  esm                  Set ESM filter restrictions  event                Global interface events  exception            Limit(code)

View 2 Replies View Related

Cisco Switching/Routing :: WS-C6509-E Doesn't Remove IPs From ARP

Mar 25, 2012

we have a WS-C6509-E WITH SUP VS-S720-10G, and IOS s72033-advipservicesk9_wan-mz.122-33.SXI5.bin. [code]

From, what we can see, whenever we try to clear arp-cache, it doesn't remove the IPs from the ARP. We've checked a bug in the IOS 12.2(33)SXH4 with the same issue, in version SXI4 is solved, but I have version SXI5, it is supposed to be fixed, from this caveat CSCtf16300, since it says it was fixed on 12.2(33)SXI4, it should be fixed on SXI5, right ?

View 2 Replies View Related

Cisco Switching/Routing :: Monitor ICMP Traffic On C6509?

Dec 22, 2011

Both regular IP traffic and ICMP traffic are passing through the source port. C6509 provides the option of filtering vlan traffic during monitoring. But I don't have vlan traffic.
 
qa-c6509-c(config)#monitor session 1 filter ?  vlan  SPAN filter VLAN
 
So I applied an access-list which only allows icmp traffic to be sent out of the monitoring port. But it does not work.

View 4 Replies View Related

Cisco Switching/Routing :: C6509 Switch Port Over Subscription

Nov 25, 2012

I have a C6509 with WS-X6548-GE-TX port module. The first port group, 1-8, is showing oversubscription (packets dropping) in the shared buffer. What interface commands can I use to find the specific port causing the buffer overflow?None of the ports is continuously overutilized and none of them in a SPAN destination group.I don't want to move connections without knowing which one is causing the problem. Also I fear that moving the connections may shift the bleeding to another shared port group.

View 2 Replies View Related

Cisco Switching/Routing :: C6509-E And VS-S720-10G Visio Stencils?

Sep 9, 2009

I need those two stencils.I have checked here [URL] but:

- the one for the C6509-E is not there

- the one for the supervisor does not work properly (misaligned anchor points).

View 2 Replies View Related

Cisco Switching/Routing :: WS-C6509-E - Possible To Boot IOS From TFTP Server

Oct 21, 2012

I have been looking at grading the IOS version on our 6509-E however there is not enough space on disk:0 to upgrade to the version I need to install. The question I would like to ask is - is it possible to boot the IOS from a TFTP server? If this is possible what configuration do I need on the 6509 to enable this. How does the 6509 know about the TFTP server as an IOS is not installed and therefore it will not have a network configuration

View 2 Replies View Related

Cisco Switching/Routing :: WS-C6509 / VLAN Interface Limit

Jan 2, 2012

I have Cisco WS-C6509 with IOS version 12.2(18)I have several vlan interface on this device.Today I create new vlan intervace
 
interface Vlan165
description test5
ip address 10.10.10.1 255.255.255.252
end
 
and vlan:
 
VLAN Name                             Status    Ports
---- -------------------------------- --------- -------------------------------
165  test5                                 active    Gi7/14
 
But I can't ping this IP address and show ip route shows:
 
sh ip route 10.10.10.1
Routing entry for 10.10.10.0/24
  Known via "static", distance 254, metric 0 (connected)
 
I have static route for this subnet /24?I can not see any error in logs, but looks like I reached vlan interface limit on this device or something like this.How can I check it?

View 9 Replies View Related

Cisco Switching/Routing :: What Is Heat Dissipation Of C6509-E Configured

Sep 10, 2009

I am trying to figure out what is heat dissipation of a C6509-E configured as follows:
 
1 x WS-C6509-E-FAN
1 x VS-S720-10G-3C
1 x VS-F6K-PFC3C
8 x WS-X6748-GE-TX
8 x WS-F6700-DFC3C
2 x WS-CAC-6000W
 
I have tried two ways: 1) the power calculator and 2) manual calculation using the C6500 installation guide.
 
1) The power calculator says 13630 BTU/h
 2) Manual calculation says: [code]
 
The there should be also the two PS in the picture, and the new total should be: [code] Well, 62711 BTU/h looks quite a bit too much and I think that the heat dissipation of the power supply should't be considered in the calculation.Isn't it an item that takes power from the grid and that generates heat according to its efficiency as the other modules?

View 2 Replies View Related

Cisco Switching/Routing :: WS-C6509-E - Verification Of Services And Protocols

Sep 19, 2012

Network newbie need to verify all necessary services and protocols on a new WS-C6509-E are turned on.  This layer 3 switch will be used to connect to servers.
 
Cisco IOS Software, s72033_rp Software (s72033_rp-ADVIPSERVICESK9_WAN-M), Version 12.2(33)SXI9, RELEASE SOFTWARE (fc2)

[Code]....

View 6 Replies View Related

Cisco Switching/Routing :: C6K Randomly High CPU Usage C6509

Mar 20, 2012

We have two c6509 budled in VSS. I have noticed randomly high usage of CPU, sometimes up to 99% in peaks. I have found that it can be generated by SNMP engine. So I unconfigure all SNMP things. But situation is the same. I would like to know if this state is OK or not. CPU shows are enclosed in file.

View 1 Replies View Related

Cisco Switching/Routing :: 3560x VACL Capture Support

Aug 1, 2012

Is there a way to configure a VACL capture on 3560-x, we need more than 2 SPAN sessions. Feature navigator indicates that this feature is supported but it seems like it's not implemented in the IOS yet.

View 1 Replies View Related

Cisco Switching/Routing :: WS-C6509-E / VSS Switch Showing Very High CPU Continue?

Aug 8, 2012

We are facing issue of getting very high CPU utilization for the VSS Switch model WS-C6509-E some times approx 100%.Attaching here show tech-support taken later after CPU normal along with show logging, show cpu sorted.HCAINNOI01XXXCS0001#sh proces cpu | ex 0.0%CPU utilization for five seconds: 100%/13%; one minute: 90%; five minutes: 91%PID 5Sec 1Min 5Min Process16406 91.2% 75.2% 76.2% ios-base16426 1.7% 1.4% 1.4% udp.proc16429 0.3% 0.3% 0.3% raw_ip.proc16432 2.8% 3.1% 3.1% cdp2.iosproc

View 3 Replies View Related

Cisco Switching/Routing :: WS-C6509-V-E / Mac-address-table Synchronize Command

Nov 27, 2011

we have  cisco WS-C6509-V-E with IOS version 12.2(33)SXI4; s3223_rp_IPSERVICESK9_WAN_M) running on a switch. I am trying to configure the command "mac-address-table synchronize" under global config mode. But when I enter the command Cisco(config)#mac-address-table ?It doesn't show the synchronize option?

View 3 Replies View Related

Cisco Switching/Routing :: WS C6509 E - DHCP Snooping Command On CatOS

Nov 14, 2012

I am trying to find a command for dhcp snooping rate-limiting on a CatOS. The PFC card is PFC. PFC3B is said to support that command. But there seems no this command.
 
-6k> (enable) sh ver
   
WS-C6509-E Software, Version NmpSW: 8.4(5)
Copyright (c) 1995-2005 by Cisco Systems
NMP S/W compiled on Aug  3 2005, 13:26:46
 
[Code] ......
 
Up time is 1183 days, 1 hour, 41 minutes

View 3 Replies View Related

Cisco Switching/Routing :: Requirements For Line Card Upgrade On WS-C6509-E

Jan 14, 2013

We are planning to replace a few line cards in the existing 6509-E chassis. The sup installed is a VS-S720-10G-3C but the line cards are legacy. As a result we are not able to enable the VSS functionality. We are looking to replace the existing line cards with the following:

1. 1 x WS-X6716-10G-3C
2. 1 x WS-X6724-SFP
3. 4 x WS-X6724-GE-TX
 
What are the requirements in terms of IOS and Roman.
 
The current IOS is: Cisco IOS Software, s72033_rp Software (s72033_rp-IPSERVICESK9_WAN-M), Version 12.2(33)SXI2a, RELEASE SOFTWARE (fc2) 
And the ROM Version is: ROM: System Bootstrap, Version 12.2(17r)SX7, RELEASE SOFTWARE (fc1)
 
Do I need an upgrade?

View 3 Replies View Related

Cisco Switching/Routing :: C6509 Loss Of Packets ICMP Sent By Different Hosts In Different VLAN

Oct 17, 2012

I've a big problem with a loss of packets ICMP sent by different hosts in differents VLAN. Here my architecture:
 
Core Switch : 2 Switch's C6509 (Version 15.0 (1) SY1)- Mode VSS - One lien VSL , the other link is defective.Access Switch: C3750 , Connected to Core Switch through 2 fibre optique wires.Topology: redundant ring
 
When I send consecutive ping message I  found always a missing of packets . Furthermore When I insert the  "show ip traffic" command., the parameter "bad hop count" increase after a loss of packets. I've 2 hosts connected in my network and they send packets with TTL =127.
 
In the Core Switch I haven't configured the MEC because it gave me troubles with the packets multicast.

View 1 Replies View Related

Cisco Switching/Routing :: C6509 - Broadcast Not Working Between Primary And Secondary IP Address

May 11, 2012

I have recently configured secondary ip address on LAN Interface of Cisco C6509.. We have some application which needs to use broadcast traffic communication to communicate with client... Broadcast is working within subnet    & also working from broadcast server to primary subnet. But not working from secondary subnet.. I have checked broadcast within secondary IP range & it's working fine...  Secondary not working broadcast with primary and also with broadcast server... broadcast address is different for these subnet but both should be communicate since configured on same interface... When I went through Cisco website found that command "ip directed broadcast" which will pass broadcast to different subnet... But I'm not sure whether any other impact if I enable that command on particular Ethernet interface...

View 6 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved