Cisco :: Unknown Protocol Drops On Internal Interface Connecting To Switch?
Jul 31, 2012I have coome accross a few sites that I see some unknown protocol drops on the internal interface connecting to the switch
View 3 RepliesI have coome accross a few sites that I see some unknown protocol drops on the internal interface connecting to the switch
View 3 RepliesI have been having following situation on my WAN facing interface on Cisco2911 where the same number of broadcast, multicast and unknown protocol drops is happening. Not sure but some applications are struggling to run over on the WAN.
[code]....
I have a 1801 router connected to a 3550 switch with a regular 802.1q trunk, and I am curious as to what may be causing the unknown protocol drops on the connected router interface.
The switch is without any configuration at all except the following for the trunk configuration on the interface connecting to the router.
Switch:
-interface FastEthernet0/1
-switchport trunk encapsulation dot1q
-switchport mode trunk
Router:
-Interface FastEthernet8
-switchport mode trunk
There is nothing connected to the switch other than the router so the dropped traffic must be originating from the switch itself.The unknown protocol drop counter on the router increments by one every 30 seconds, and I tried using a packet sniffer but nothing noticeble showed up.
I read elsewhere on these forums that it might be udld, but that is not enabled by default, and just to be sure I tried disabling it on the interface and as expected it said it was not enabled, so I am ruling that one out.I also read that it could be because the router is recieving traffic from other protocols than IP, but I do not see how it applies in this case.
what does a 3550 send every 30 seconds that my 1801 does not understand?Could it have something to do with STP?
We are using 3825 Cisco router with IOS version 12.4(24)T2. The unknown protocol drops on our GigabitEthernet0/1 interface is increasing. This interface is connected to our modem. What could be causing this unknown protocol drops?
cnshaccent-gw-2#sh int GigabitEthernet0/1
GigabitEthernet0/1 is up, line protocol is up
Hardware is BCM1125 Internal MAC, address is ffff.ffff.ffff (bia ffff.ffff.ffff)
[Code]....
I have issues to connect Cisco 2911 to HP switch. I disable CDP on the LAN port, router at A end is ok, but the unknow protocal drops as same as before at B site. It happend around every 30sec. When I transfer a file from one end to the other end. It always disconnect every 25 second. HP Switch is not configure trunk as it work as a plain network
View 3 Replies View RelatedI have a Cisco router C1700 and it is presenting unknow errors on Serial 0/0 and fa0/0 interfaces. Why this counter is increasing?? Im not very sure if is by CDP neighbors or Vlans that are not configured on a switch attached.I undertand that the unknown protocol drops field displayed in the above example refers to the total number of packets dropped due to unknown or unsupported types of protocol. How to solve this unknown DROPS? [code]
View 4 Replies View RelatedI have a pair of 5505's in transparent mode and connected them to C2960S. The inside interface (which is VLAN5 on the switchport) keeps dropping, going in to error state. There is no log reference in the switch and the interface shows as UP. The standby ASA has no problem, both interfaces on the switch is up. As soon as I failover the units over, the active node inside interfaces drops.
View 2 Replies View RelatedAll of a sudden, the router's internal ethernet switch has started to get very slow at connecting to local machines. I can observe the connection fading in and out on each connected machine for up to half an hour until it gets stable. None of the settings have been changed lately.When I use WI-FI, the problem doesn't occur.
View 2 Replies View RelatedI'm trying to connect my router SR520 internal Ethernet port to my ESW520 24 port switch. When I physically connect the cable the port on the switch suddenly drops.
View 1 Replies View RelatedOne of my Catalyst 3750 switch have many out drops, I execute "sh mls qos int g2/0/3 statist" command, there are many output drops in queue3 threshold3. [code]
View 8 Replies View RelatedI have a pair of ASA5510s in a failover configuration where I see these 2 logs repeated every 15 seconds.
105008 1 Nov 27 2012 10:39:27 (Primary) Testing Interface management
105009 1 Nov 27 2012 10:39:28 (Primary) Testing on interface management Passed
I have read other threads where these are accompanied by "105005, Lost Failover communications with mate on interface". But I'm only getting these 2. The other thing that is confusing is that the "management" interface is not the failover interface. So why do I see 105008/9 logs about it?
Output of "sh fail":
5510a# sh fail
Failover On
Failover unit Primary
[Code].....
I've got a WRT54G v6 that is password protected via WPA2 Personal TKIP+AES, and SSID broadcast enabled. In the Status menu > Local Netork > DHCP Clients Table there is a MAC Address listed that none of my devices have.
View 6 Replies View RelatedI have encounterd a broplem on my Cisco 805 model.
When i use the command "show ip interface brief" the status shows "up" but the protocol is "down" on my serial interface.
The link between my to sites is down after this happend.
We have 3560 switch with following IOS. version 12.2(55)SE3 and image name is C3560-IPSERVICESK9-M. On one of the interface we need to know what are traffic is flowing.
Do we have "ip nbar or ip route-cache" support on this switch IOS? Is there any other way to find out which protocol traffic is flowing through that interface.
I configured dot1x on my swicth 4500 series, Here is the interface configration:
interface FastEthernet3/2
description Test dot1x
switchport mode access
load-interval 30
authentication event fail action authorize vlan 800
authentication host-mode multi-host
authentication port-control auto
[code]....
When I remove the port-control configuration on the interface, the status change to UP/UP.
when I want to recover my 2960 switch in rommon mode with xmodem command, It shows me these errors. when I reset the switch, still shoes these errors:
Unknown cmd: 1;2c1;2c[?1;21;2c[?1;21;2c[?1;2;21;2c[?1;2[
switch: ?1;2c[?1;21;2c[?1;21;2c
switch: ccknown cmd:
*** line too large *****tch: c1;2[?1
switch:
Unknown cmd: cc?1;2c[?1;21;2c[
[code]....
I have windows server 2008r2 running a FTP server, so I can back up my configs and upgrade IOS when needed. My problem is than I can backup to the server just fine but when i try and restore a config or pull a new IOS over it gives me this error
%Error opening ftp://13****** (Protocol error) this is happening on every switch I have and I can't figure it out.
I have a question about ACS RADIUS authentication with Alteon 3408 L4 Switch.
I configured a ACS 4.2.1(build 15 patch 4) software for windows on Windows Server 2008 Server STD.TACACS authentication with CISCO product was successfully passed.but RADIUS (IETF) authentication with NORTEL 3408 Switch was failed. ACS Authentication Failure Code was a " ACS password invalid "
I read the post that RADIUS VSA is needed in my environment.but i can not search any sample Nortel VSA dictionary configuration. Need Notel specific VSA configuration.
I'm trying to configure my BRI interface in "network protocol-emulate network" and "layer1-emulate network" but i don't have this second command.Is someone have allready to that with this type of interface ?I've to configure this because the ISDN line of my telco is in user mode only.
View 5 Replies View RelatedI am currently managing an ASA5510 using ASDM through the management port but I would like to manage the ASA through the internal port.
My concern is that I thought I remembered reading someplace that if you setup an internal port for management that it can't be used for anything else. Is this correct?
I only configured one internal port and it is the path to my LAN. I would hate to configure the port for management only to find that I disconnected my firewall from my internal network in the process. Can I use my one and only configured internal port for both ASA management and route from my LAN thru the ASA firewall?
I currently have the management port set to 192.168.1.1 and my internal interface is 10.1.1.1. If I open ASDM and connect thru the management port and select Configuration/Device Management/Management Access/ASDM/HTTPS/Telnet/SSH
select "ADD"
select access type "ASDM/HTTPS"
select interface "internal"
IP Address "10.1.1.0"
Mask "255.255.255.0"
Will that give me access to ASA management thru my internal network but cripple my network access to the ASA?
I've got a new CT2504 controller with software version 7.0.220.0 Regarding to [URL]I've tried to configure the internal DHCP on a dynamic-interface, but this is not possible:(Cisco Controller) >config interface dhcp dynamic-interface vlan401 primary 172.16.x.3 vlan401 Interface IP can not be used as internal DHCP server IP It works, if I use another IP (aka DHCP server) in the same subnet or in another subnet. It works also for the management interface.
(Cisco Controller) >show interface detailed management
Interface Name................................... management
MAC Address...................................... d0:c2:82:xx:xx:xx
IP Address....................................... 10.2.x.135
IP Netmask....................................... 255.255.255.240
IP Gateway....................................... 10.2.x.129
[code].....
We're seeing a strange issue with a Cisco 819 that we're testing out. We are able to ping out over the Cellular interface just fine, but as soon as we plug a device into one of the FastEthernet ports we immediately drop the cell connection. The Cell interface then continues to bounce until we unplug the device. We are intending to setup a VPN tunnel, but we've even stripped all that out for the sake of troubleshooting.
Current configuration : 2832 bytes
!
version 15.2
[Code].....
I have cisco 887M-K9 router and I can see output drops are increasing on ATM interface. [code]
View 9 Replies View RelatedWe recently changed locations and acquired a new circuit from our provider. They also connected our remote branch office to our main office through MPLS. Now, as I understand it, the branch office basically connects back to the main office through our providers network (MPLS). We have a new router at the branch office which has a gateway of 192.168.1.225. The clients in that office have IP's of 192.168.1.96 - 100, using the gateway of 192.168.1.225.
The main office network is 192.168.0.0 (Gateway of 192.168.0.1)
At this end (Main office), I also have a new Cisco 2900 provided by the ISP, with port 0/0 for the outside connection (connected to the 0 port on my ASA 5505). The ASA's port 1 obviously running into my network hub. The provider tells me that port 0/1 on the 2900 is or should be used to connect the branch office back to here and has an IP of 192.168.0.225, as that's how the provider provisioned it. So, I plug that into the ASA's Ethernet port 0/2. And I'm assuming they have a route setup either on the 2900 or the router in the branch office so that 192.168.1.225 can reach me here at 192.168.0.0.
There is already a static route setup on the ASA: (192.168.1.0 255.255.255.255 192.168.0.225 1). As soon as I plug in the cable, the IP phones at the branch office work, but they can't access the internet or any resources in the main office. My questions are:
1. Shouldn't I be able to just go straight from the 0/1 port on the Cisco 2900 to my hub. At first I was plugging right into the ASA, but I don't think I need to do that, why go from the branch office through my ASA to access resources and then back out the ASA for internet. If they're already coming from 192.168.1.225, through the MPLS network, then they should go right to my network and then back out the ASA.
2. They have to route through the ASA first, in which case, do I need to setup another VLAN for that branch network in conjunction with a static route? I can ping the router and hosts in the branch office through the ASA only!
Below is the running sanitized config:
Result of the command: "show running-config"
: Saved:ASA Version 8.2(2) !hostname ciscoasadomain-name audiology.orgenable password ulzaQiFnKVzDwUmW encryptedpasswd 2KFQnbNIdI.2KYOU encryptednames!interface Vlan1nameif insidesecurity-level 100ip address 192.168.0.1 255.255.255.0 ospf cost 10!interface Vlan2nameif outsidesecurity-level 0ip address 1.2.3.4 255.255.255.240 ospf cost 10!interface Ethernet0/0switchport access vlan 2!interface Ethernet0/1!interface Ethernet0/2!interface Ethernet0/3!interface Ethernet0/4!interface Ethernet0/5!interface Ethernet0/6!interface Ethernet0/7!boot system disk0:/asa822-k8.binftp mode passiveclock timezone EST -5clock summer-time EDT recurringdns server-group DefaultDNSdomain-name audiology.orgsame-security-traffic permit inter-interfacesame-security-traffic permit intra-interfaceaccess-list
[code]....
I have a cisco wlan controller (2100) running software 7.0.235.0. I have the internal private wlan running off of port 1 and that is working fine with an internal dhcp server.Is it possible to setup another ssid (guest) and have the interface directly linked to a static ip on the WAN and also use the built in cisco internal dhcp server?
View 4 Replies View RelatedI have been trying to create a Guest WLan on my 4402 WLC system and have found several confilcting documents explaining the procedure. During this process I have notices that although the current corp wireless works, there was never a virtual interface created for it. Instead it uses the same Wlan/Vlan as the ap manager and managemnt interfaces. Could this by why I cant seem to get the Guest access working? or is this not a problem after all since the wireless does work.
View 1 Replies View RelatedWe recently had a contractor deploy a 4500 catalyst switch with a WS-x45-SUP7-E. After installation and configurations, HP openview is detecting a "downed" interface on the 4500 chassis that is not in the configuration. I have attached an image with the interface circled. We assumed that it may be a configuration issue with openview, however after running diagnostics with a network analyzer, the same ip address for the down interface is still detected. Is this some sort of internal virtual interface on the SUP7?
View 4 Replies View RelatedI've got a 2621 configured as my main gateway to the internet - right now it's obtaining a DHCP ip from a the ISP's proprietary router set to bridged mode.
As of now, I'm unable to ping the internal interface of the router. I can ping external IP's only, even though I have DNS servers listed, i am unable to resolve host names. I'm running a few servers to which people are able to connect to my web server, among other services. I even have a crypto map setup to another 2621 across the country and can ping all internal ips on the other end... I JUST CANNOT PING THE INTERNAL INTERFACE of the router!!
I've noticed that when I ping the router during it's boot process (using linux un-interupted) I get a response in a very short window, then dies again. I'll post my config below:
[code]....
I have an ASA5510 running version 8.2(5) I am having an issue with routing/natting from an internal network to the outside interface IP on port 443 which has a nat back in to another internal address. i works externally in from a public address. i also see log messages to do with IP Spoofing
View 1 Replies View RelatedWe have a Cisco 1760 router . We are facing sevier packet drops in the serial interface.
When i swap the router with another router link is working working fine.
Troubleshooting steps taken
1. Swap the serial cable with another working cable : no change in state
2. Reconfigure the encapsulation commands (with PPP and HDLC) : no change in state
3. Try with a decreased MTU packet Ping : no change in state
4. Decreased the Input queue and increased the output queue size using hold-queue in command : Comparatively the packet drop is reducing but still a 10 percent drop is happening.
We have 3 internet links from different providers connected to configured WAN 1,2,3 in RV016. A remote client needs to connect to a internal VPN Server behind RV016, so we use one-to-one NAT to publish the internal server ip to a Valid IP from WAN3 and setup protocol binding in Multi wan to all trafic (TCP and UDP) from the internal VPN address exits with WAN3.
So, the remote client tries to connect to VPN using this ip Address from WAN3 and sometimes work and sometimes not. It's clear to us that the problem lies in the response from RV016 not coming always from WAN3, because if we disconnect the two other links (WAN1 and 2) Its works flawless.
I was just wondering if it's possible with an ASA 5510 to connect to the external IP address of an internal server from inside the network. I have already set up dns doctoring for dns lookups, and everything is working fine there. We have an application inside the network that tries to connect straight to the external Ip of another internal server. where to look in the ASDM 6.4?
View 2 Replies View RelatedWe have a 5508 with 7.4.100.0 vor Internal APs and OEAPs. till now every thing is ok. Now we have to connect an AP (local) in a remote office, connected to the WLC by a VPN Tunnel. The problem is that the AP in the remote office uses the NAT Address to connect to the WLC, so the traffic goes over the Internet, not trough the VPN Tunnel. On the controller I have the following setting:
AP Discovery - NAT IP Only ................. Disabled
On the AP:
AP Link Latency.................................. Disabled
How to force the AP to use the internal IP Address of the WLC?