Cisco Switching/Routing :: Configure Snmp Traps For RPS 2300 Failure On 3750S?
Dec 7, 2011I want to capture RPS related alarm on SNMP server for RPS2300 and cisco 3750d switch
View 1 RepliesI want to capture RPS related alarm on SNMP server for RPS2300 and cisco 3750d switch
View 1 Replieshow to configure an IPaddress for a PWR-RPS 2300?.I tried finding info on the website but no luck as yet. RPS 2300 will be used on stack of 3750E series switches.
View 3 Replies View RelatedTrying to migrate the config run on IOS 12.1 to 12.2 ?It seems there's no snmop traps isdn command support on 12.2.
where i can enable trap on ISDN over IOS 12.2 (33) sxj1 running on C6500 chassis?
Is there a way to send an SNMP trap form the ASA when port 80 is trying to be accessed??
We use the ASA5510 and also use ScanSafe Web Security. Web Security is great but we find ourselves worrying if user has edited their Browser connection settings to remove the proxy settings that we push down using Group Policy. We also cut off the users ability to make changes to those settings but it interferes when I need to troubleshoot a special program that cant use a proxy server. It just makes it harder for me. The other thing is that Group Policy only works for IE. Google Chrome will inherit the system settings in IE. So we have Safari and Firefox as well as a lot of others to worry about not getting the configuration. There is also debate about limitting the use of anything but IE and FireFox.
Without laying down the law and getting all sorts of hate mail and death threats I would like to run ScanSafe in such a way as to make sure each user receives the Group Policy settings and that is all.
I would now like to just set up an SNMP trap on the ASA for ANY traffic that is trying to get to port 80. Either get in in my syslog server or have the asa email me directly. Scansafe sends the Internet traffic out on 8080 to the Proxy towers.
I could block port 80 outbound but again, I limit my ability to troubleshoot on the fly. I would have to break this every time I need to troubleshoot.
Cisco LMS 4.0: Is able to forward SNMP traps (ver. 2c) received from device registered with it to a configurable IP address? • Traps contain the original Device Agent IP to identify the source (Not the IP of LMS)?• Is possible to configure one logical IP address or Domain Name for redundant LMS:Cisco Security Manager 4.1:Is able to forward SNMP traps (ver. 2c) received from device registered with it to a configurable IP address?• Traps contain the original Device Agent IP to identify the source (Not the IP of Security Manager)? • Is possible to configure one logical IP address or Domain Name for redundant Security Manager?
View 0 Replies View RelatedWe have a catalyst 2950 switch running:
IOS (tm) C2950 Software (C2950-I6K2L2Q4-M), Version 12.1(22)EA6, RELEASE SOFTWARE (fc1)
This release doesnt have the snmp-server enable traps errdisable command.
Where to look on the cisco site for the next available release for me that would have this command in place?
I am getting these unwanted entries on my syslog server.03/10/2012 12:57:48 172.21.113.20 Error 23898: Interface FastEthernet0/1, changed state to downI tried to stop them with no snmp trap link-status but it hasn;t worked.[CODE]
View 4 Replies View RelatedI have a 3750 cluster and I want to know what are the recommended snmp traps to be sent. We definitely want to know when one of the switches in the cluster fails.
I've read about snmp-server enable traps stackwise and snmp-server enable traps cluster. What do these traps actually do?
I have been experiencing wireless connectivity issues with one of our Cisco 1231G AP. Every now and then users would not be able to connect to the AP. To dive deeper into this issue, I would like to configure SNMP traps on this AP. We are using PRTG and there is an option to configure SNMP trap. However, I would need to now the OID of the AP. Also i need to check for interface up/down status for both fastethernet and the radio. PRTG should be able to notify me when there is any interface resets.
View 6 Replies View RelatedI want to configure snmp-traps regarding stpx (root-inconsistency, loop-inconsistency) on a Cisco Nexus 1000V. The command "show snmp traps" lists stpx as a trap that could be configured and which is not at the moment.
MKBE1NX1# sh snmp trap
--------------------------------------------------------------------------------
Trap type Enabled
--------------------------------------------------------------------------------
entity : entity_mib_change Yes
entity : entity_module_status_change Yes
entity : entity_power_status_change Yes
[code].....
Nothing about stpx... Is there some other way to configure more traps?
I have Cisco 2960's, 3750's and 3750x's all running IOS on the access layer. I have Cisco 6504's running IOS on the Distribution and Core layers. I am looking to monitor redundant links through Spectrum by having specific ports send traps but I have run into trouble finding how to configure it. I would like to have:
1. Logging enabled for all links (Fiber and Copper) so that I see all links up/down messages in the syslog
2. SNMP traps sent for linkup/link down messages only for redundant links (ex. Dual Up links from Access Layer or Redundant Ether channel Links on Dist Layer)
3. SNMP traps should be ignored/not sent for all copper ports.
Had setup my ACE ,to send traps to SNMP server .but dont see any logs on the SNMP server from ACE.
SNMP configuration on ACE
logging enable
logging buffered 6
logging host 10.12.40.12 udp/514
[code].....
I am seeing SNMP coldstart traps that either are delayed by many hours or are false (e.g. right after receiving the coldstart trap a query to sysUptime shows the nodes been up for days).I seen this twice this week in a new network environment for me for two different C2900s running C2900-UNIVERSALK9-M Version 15.0(1)M3 Assuming the coldstart traps are coming from the actual source nodes, I am curious what could be going on here.
1) One guess I have is possibly the system clock changed could cause the SNMP agent to send a false cold start trap. Then my guess is in the device log I should see a system time change syslog message.
2) I recall hearing once that syslog and possible traps messages are held in configurable buffer who default value is 1 and if not sent are held and then suffer a delayed sent. Is it true for both traps and syslog ? In the past I assumed this was simply the logging history buffer and applicable to syslog traps only. My assumption in the past was that last trap or last syslog message is sometimes held on reload and sent immediately after restart regardless of device connectivity to the management target.
I always assumed coldstart traps are never delayed for any reason and that they were pretty accurate substitutes for system reload syslog messages. Does anyknow know any reason for false or delayed coldstart traps on a C2900 with IOS 15.0(1) ?
If we have 3 stacked 3750s# running Layer 3. Do we need license for every switch? or is it one license for the 3 switches? Also is the license associated with the MAC address of a specific switch? What i# am trying to know also, is if we have to install one license and it is associated# with one MAC and this switch failed.. will the Layer 3 be broken?
View 1 Replies View RelatedI've got LACP-enabled port-channels between a Cisco 3750 stack and a few different switches (some Cisco 3750s and some Juniper EX2200s). The Ciscos are all sending slow LACP updates, the Junipers are sending fast LACP updates (but the Cisco they connect with is responding with slow LACP updates).
I have a couple of questions:
1) what are the pros and cons of slow vs fast updates? my research has led me to the conclusion that fast updates are better for network resiliency as long as you have plenty of bandwidth overhead (which I do at the moment). is there anything to add to this conclusion?
2) is there any way to configure the Cisco 3750s for fast updates?
We've recently inherited a platform with little handover and also minimal networking experience.We're going 100 miles an hour in learning, but I'm a bit confused with the idea of a L2 switch with no IP assignments to ports, so using VLANs, and a L3 switch with IP assignments. And the combination of both.We have 2 Cisco 3750 switches, along with a whole host of other hardware, so we're starting at this "gateway" to start breaking things down.
View 7 Replies View RelatedI've read the document (Document ID: 91672) on setting up WoL, but I had a few questions as this doesn't completely fit our situation.We have 4 3560 switches, 3 have only access to vlan 1, SW4 has access to vlan 1 and vlan 2, every switch is connected by fiber to a 3750.We want to enable every server/PC on vlan 2 to allow WoL packets to all PC's on the internal network (so WoL through all 5 switches). In the above document, it allows WoL to be executed only from a single IP/Server, is it possible to allow an entire vlan to execute WoL? or allow multiple IP's to execute WoL? Also, in the switch configuration it says to type
-"switchport mode access"
-"switchport access vlan4"
-"spanning-tree portfast"
We do not use STP and is disabled, is portfast required for WoL use? if Port Fast is disabled by default, could this also be blocking a WoL packet from vlan2 to vlan1 on the same switch?
I've to enable it on 3750 and nexus 7K switches. what are the steps involved? can we enable jumbo frame per port instead of enabling globally? i.e. we will only have few ports that will be using jumbo frames, rest of the ports will be using default 1500 MTU size.
View 6 Replies View RelatedHere's what I'm trying to do. We are having new storage servers installed that will be using NFS. I'm being told that they need to have their connections port channeled. Right now, the servers have connections to 2 different 3750s for HA. Is it possible to configure a port channel between these 2 connections?
View 4 Replies View Relatedcan you stack a 3750 switch over fiber.....the answer is no, but the virtual switching supervisor 720-10G for the 6500 can create one virtual switch using two 6500s...
how can we get cisco to come up with a way for access switches to be stacked over fiber similar to above supervisor? i know of few of my site that would benefit from this...maybe they can come up with a vss appliance, similar to a media converter, to convert stackwise over fiber...then of course, you would need the same appliance on the other end....
I have a network with static routes witch I need to convert to OSPF.Never used OSPF, and do not have much experience in routing in general.The netvork is connected via some fiber links, but moastly wireless bridges.I have attached a drawing of how the network is.Routers are 3550, 3560 and 3750s.Each router is on a different physical site.
View 2 Replies View RelatedMy group has recently started configuring traps on our switches to alert us of issues as they arise vs. waiting for the Helpdesk to receive user complaints and then responding.We have successfully configured the 2950 and 2960 switches to alert us when a port-security violation happens. However, the 3750 switches refuse to fire the port-security violation traps. The 3750's will fire an errdisable trap when the port goes down though.
Here is one of the port configurations:
interface FastEthernet1/0/45
switchport access vlan 5
switchport mode access
switchport port-security
switchport port-security mac-address sticky
[code].....
And here is the output of the port-security debug:
2522070: Oct 21 16:37:04: %LINK-3-UPDOWN: Interface FastEthernet1/0/45, changed state to down
2522089: Oct 21 16:37:05: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa1/0/45, putting Fa1/0/45 in err-disable state
2522100: Oct 21 16:37:05: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 0012.3f07.95d3 on port FastEthernet1/0/45.
All of the 3750's are running C3750-IPBASEK9-M, Version 12.2(53) SE2. Wireshark also shows the errdisable traps, but no other traps so I've ruled out the traps being missed. All of the switches have been reloaded and power cycled.
I want to make my switch send trap when failed SSH login is detected. I found the "login Enhancement" feature and enabled the trap and logging for the failed attempt.
3750# sh run | in login
aaa authentication login default local
login delay 1
[Code].....
I am trying to update a switch I bought to the latest IOS using the Cisco Network Assistant but the it is failing becasue it's saying I dont have the space.
In the CLI I get,
Switch#dir all-filesystemsDirectory of flash:/
2 -rwx 109 Mar 01 1993 00:01:47 +00:00 info 3 -rwx 270 Jan 01 1970 00:01:37 +00:00 env_vars 7 -rwx 3081999 Mar 01 1993 00:03:23 +00:00 c2950-
[Code]....
After trying to downgrade a Nexus 7K from 5.2.1 to 5.1.5 by updating the boot & kickstart boot statements and reloading, I'm now stuck in an endless cycle of reloading. See below:
Is there a break sequence which will allow me to modify the boot statement back to the original via ROMMON or something similar?
[code]....
I have a cable from an SFP module in a WS-C3750-48P with 12.2(55)SE1 running to a Gigabit port on a Cisco WLC. After the switch recovers from a power failure, the gigabit autonegotiation fails. The cure is a long drive to unplug and reseat the SFP. Note this happens at too many similar sites for this to be a loose connection. Interface shutdown then 'no shutdown' is not sufficient. The state is 'line protocol is down (not connected)'. Interface is configured for switchport mode trunk (auto speed, auto duplex). Command 'switchport nonegotiate' makes no difference. Is there a more powerful command than 'shutdown' which might toggle the interface signals? Is there some way of resetting the SFP? sh int gi 1/0/1 displays 'media type is 10/100/1000BaseTX SFP' and zero packets received.
View 4 Replies View RelatedI have a C2960-24TT-L Switch with the following problem:When the Power Cord is plugged in the Switch, all switch indicator LEDs go on very briefly. Then SYST LED blinks very briefly, goes on steady and remains at this state without any indication at the console.Tried the reset by holding the MODE button while plugging in power but I still get no indication at the console. All is fine with console, meaning that if I take out the cable and plug it in another switch, then I see all that there is there to be seen.My question: Is the switch beyond repair or is there something that can be done to get the switch to run POST and boot at rommon so that I can reload SW and configs?
View 3 Replies View RelatedI'm currently getting a Nexus hardware failure at present.
switch %MODULE-2-MOD_DIAG_FAIL: Module 8 reported failure due to DEVICE POST/DIAG FAILURE in device 48
IOS upgrade tried on the stack of 2XWS-C3750X-24T-S , Upgrade was tried to support WCCP on the platform. Current version is Cisco IOS Software, C3750E Software (C3750E-UNIVERSALK9-M), Version 12.2(58)SE1, Not able find any IP Plus ios in the site ? Only available are IP base and Universal K9 , Tried upgrading to c3750e-universalk9-tar.122-58.SE2.tar by using stack upgrade method as per document [URL]
Upgrade fails with error :
%Error opening flash:update/info (No such file or directory)
ERROR: Image is not a valid IOS image archive.
Why current ios is not supporting WCCP , I hope it is there in the featureset. ( tried "sdm prefer routing" but no success) Does c3750e-universalk9-tar.122-58.SE2.tar will give me wccp support ? What is the issue with my upgrade and how do I do a successfull upgrade ?
When installing the license for a 3750-E I get an error that the license doesn't reside on the flash though dir reveals the image in flash. Seen this, know of a resolution?
View 5 Replies View RelatedI have implemented in my company network recommended by cisco scheme with MEC etherchannel from some segment distribution layer (VSS) to core switches (legacy 650x) exactly as on picture: Core switches have rather old IOS (Version 12.2(33)SRB4 and i have reasons not to upgrade it now) which dont support many functions - like BFD over Etherchannels and Enhanced PAgP. And we run a OSPF/MP-BGP/MPLS bunch over those links with OSPF reference bandwidth configured to such values that failure of one link in etherchannel will not lead to link cost changes (we dont have a lot of traffic for now on those links and 1 link can handle it easily) and consequently will not trigger changes to RIB and BGP topology table.
Problem is that i am afraid that in case of one of link of portchannel will fail (but without port down event - unidirectional link or smth else) it will take rather long time to converge - and im talking about L2, not L3 protocols. Cos i cant implement BFD and ePaGP over this link - best i can do that improve 30 seconds PAgP hello timer to 1 second. But at least 3 seconds of possible traffic blackholed - is rather big problem.First time i considered 2 possible solutions:
1) BFD - but even i can use it, it will not improve much recovery time cos 750 ms for BFD over etherchannel not much better that 1 second PaGP fast timer.
2) ePAgP - as i understand this protocol have enhancements to discover failed link faster and improve recovery time, but all information i can find about it - is how to use it for dual active detection and none about timers improvements. So i cant be sure that i should upgrade IOS on Core switches and it will improve my failure detection time. ( if it possible adduce some links to description of this protocol enhancements in comparison with PAGP)
For now im already thinking about using four L3 links (instead of 2 portchannels) and BFD over those links with 50 ms hello timer. But in case of link failure reconvergence of OSPF will take some time, and BGP will react to this no immediately, so i am afraid that even using aggressive timers for routing processes and hellos i will not win much time.
We had power failure catalyst 6509 and after the device boot up ssh does not work any more below is error messages
line con 0
access-class 90 out
logging synchronous
[Code]....
We have FEX (2232TM) connected with 2 x NEXUS N5K-C5596UP.
One port Ethernet 101/1/7 which was connected to Dell Server went down...
It was working for a couple of weeks at least. Then the link went down and now I'm unable to get anything connected to this port As I said, this already happened before, but unfortunately I can't remember if it was on the same port/fex ... from the fex uptime it seems that this was on another fex I was able to get the link back up by doing a power cycle of the fex
At the moment Dell server is connected to different port Ethernet101/1/4.. See config bellow:
. config, how ports are configured
interface Ethernet101/1/7
description VM008 Network 1
switchport mode trunk
[Code].....