Cisco WAN :: 2960 To Configure Switch Port Security
Apr 7, 2012
we are using 2960 cisco switch asn we are trying to configure port security.we are able to configure MAC base port security, but unbale to configure IP base port security.can any one guide us can do IP base port security like MAC port security. if not which switch will support IP and Mac base port security.
I need to configure a Cisco 2960 switch as a DHCP server. The current IP address will be on a different seed than the DHCP addresses. i.e.
Switch IP = 10.1.2.3, GW = 10.1.2.1, Subnet = 255.255.255.0 DHCP addresses would be 192.168.1.1 - 200, GW=???? (10.1.2.3?) and subnet would be 255.255.255.0
I have a problem, i would like todo MACSEC betwwen two switches cisco catalyst 3560-x but I know that for this operation i needed ACS server 5.1 is it possible to encryp dataflow without ACS server and if you have the configuration
I am trying to configure a new 2960 POE switch, but seem to me the int fa0 is layer 3 interface. Is any way we can convert it to a switchport, so we can connect it to other switch in trunk mode?
One of my engineers issued a command to turn off port security on a number of ports using the range command. The command failed on the first attempt due to a tacacs auth failure which I suspect is due to a low tacacs timeout value. The engineer then reduced the number of ports in the range command and re-issued the config change after which the switch just crashed and rebooted.
The logging buffer on the switch displays the following:
000072: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: System previously crashed with the following message: 000073: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Cisco IOS Software, C2960 Software (C2960-LANBASEK9-M), Version 12.2(50)SE3, RELEASE SOFTWARE (fc1) 000074: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Technical Support: [URL] 000075: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Copyright (c) 1986-2009 by Cisco Systems, Inc. 000076: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: Compiled Wed 22-Jul-09 07:03 by prod_rel_team 000077: *Mar 1 00:03:00 GMT: %PLATFORM-1-CRASHED: [Code]........
I have done some searching and this could be related to bug CSCsq71492. I have tried using the output interpreter but it is still down.
Cisco Catalyst 2960 series,i want do a SNMP request over OID. When the output should be like this: Portnumber and VlanID. Is there a OID for this output?
Today in my rush to get home I plugged in a new 2960 stack and did a little bit of very basic configuration, but no passwords were set. I tried to telnet in and the message says that a password is required, but none is set. I tried the SDM as I hadn't turned it off yet and it is prompting me for a user/pass but I have no idea what to put in there. No console is available, it's a new office so no employees around either.
I configured port security on my 2960 switches with the following commands: [code]
The problem is that when I should change someone's PC, first I disable port-secirity, then I clear all the mac addresses learned on the interface, then I plug the new PC and enable port-security. The new PC couldn't connect to the network and it's mac address has not be learned on the interface. Why?Which commands should I use to clear an old mac address and enable port-security with the new mac address.
I Have a problem I'm trying to configure automatically my switch over ther DHCP when I start the switch it request an IP from the DHCP from here everythings is fine but it does nothing more,indeed I put on my dhcp the option 66 and 67 which is an adress of my TFTP server and a file to download and the switch seems not to understand theses options , I tried my dhcp with a cisco airport and everythings works fine the File from the TFTP is automatically downloaded into the airport...There is an option to add or am I missing something in order to make it work with my switch ?
I'm trying to configure Catalyst 2960 series 8 port switch in my office. I have just plugged in switch and started and then put Ethernet cable (which is coming from the wall port (LAN) into CONSOLE (switch). and connected my laptop's ethernet cable to switch's 1x por
I am looking to simply monitor Port-Security , Error-Disable and HSRP. I would like to receive an email when any of these are triggered.
Port Security - Port Is shut down Err-Disable - Port goes into err-disable state (securedown) HSRP - When HSRP standyby changes are detected
I need to receive emails with any of the able are triggered. What is the easiest way to do this? I know SNMP is the main option but I have never worked with SNMP and dont understand it too much.
As per my attached diagram, I have three switches (Cat 3560-E and couple of Cat 2960-G)
Each PC is on different vlan PC -1 on vlan 100 PC-2 on vlan 200
I need to connect PC-1 and PC-2 to the server. Server has no fixed vlan and can be changed.
Restrictions:
1) can’t change PCs vlan assignment. 2) can’t add 2nd NIC in the server.
I’ve tried private vlan but it requires separate physical ports for host and/or community vlan and somehow it did not work. I could be wrong Trunking using dot1q enabled on port 2 on all switches and connection works fine (server to PC-1 or server to PC-2) by enabling switchport access vlan 100 or switchport access vlan 200. However I need port 5 on switch-1 to respond to vlan 100 and 200.
I want to configure IEEE 802.1x port-based authentication on cisco switches, preferable 2960 series. Which models support this feature?. I have try with some older switches but it doesn't works properly on everyone. I have upgraded them whitout better results, there is namely an issue with TLS handshaking on some switches which produces authentication to fail.
i want use CACTI for monitor my bandwidth so i have a question how can i enable snmp for a switch port ? or i shoudl just enable snmp from configuratiopn terminal and then in CACTI i will choose which port will be monitor? can i do something that CACTI connect to my switch with a encryption key ? i have cisco 2960 48 port switch
In my network we use all cisco 2960 switches, problem is when someone copying 4gb data or high from one switch to another switch, by that time rto (Request time out) is coming.
router | | |
[Code]....
1. when user 1 copy data from server ,at that time who is in switch2 behind like user2 ,he is getting problem like when ping to default-gateway,or rto is coming and network is very slow .
2. when i open sw2,sw1,sw3,trunk ports utilization is very high except sw4 to sw1 trunk ports,who behind sw4 like user4 ,he is not getting problem.
3.all switches trunkport in my network is faster ethernet and i have no option to connect trunkport to gigaehternet and ethernet channel.
Is there a way to identify if a switch port is burned via CLI? I have a 2960-48PST switch and some ports don't provide power to a PoE device connected. When I change the port, the device turns on.
I want to configure switch port bandwidth limit for my Catalyst 2960-48, is there any hardware / ios limitation? can I configure it at all 48 switch ports?
Is it possible to obtain a replacement rackmount kit for a 2960 48 port switch? I've had a read of the manuals but can't see a part number specified. The part number suggested to me (by BT) is for the 8 port version, which is not much use.
2960 switch stack (flex) Spanning tree re-calculate from stack port one?I need to identify with port in the stack is causing the re-calc I have four 48 port switches and show spanning detail only indicates stack port 1.
I am using 3560 switch senerio is that we have dhcp server on and I want that switch filter mac on whole switch ports not on a some port. Switch only give IP to the mac whcih is in mac table of switch/particular which we enter manually.I have read chapter 62 of port security but it doesnot fulfill my requirements.I am also using 3com 5500Ei switch in which we dont have to bind a mac on every port, we just enter a mac in the switch and it filter itself by using simple commands.DHCP server is not in our hands, we cant do any things there.
I want to configure my SRW248G4 switch thru console port. Unfortunately in this switch there is no RJ45 console port input, I can only see cosole port that is look like RS232 input. I bought two standard cisco console cables that have one end with db9 and one with RJ45.
Now I have and idea to put one end of one cable (db9) to switch, and one end (db9) of second cable in my computer (COM input/output)
I need to connect two RJ45 together - this is not a problem, I know how to do this. Here is the question :I know how pinout in my computer look like but i can't find pinout of console port in my SRW248G4. There is many pictures in Internet, for many Cisco devices but this isn't working. Maybe in LINKSYS pinout look different ?
How to configure SF300 48port switch as DHCP Server or not.
My Configuration as below
I have 8 vlan configure in SF300 (SVI with ip address)isit possible to configure dhcp server and how i can apply access-list to restrict with other vlans.
Trying to configure the Cisco 4948e switch gigabit ethernet port with "switch port trunk encapsulation dot1q", but didn't get the option. Please find below the options got after "swith port trunk"............
SW(config-if)#switch port trunk ? allowed Set allowed V LAN characteristics when interface is in trunking mode native Set trunking native characteristics when interface is in trunking mode pruning Set pruning V LAN characteristics when interface is in trunking mode
SW(config-if)#switch port trunk. Please find below the version of the SW............
SW#sh ver Cisco IOS Software, Catalyst 4500 L3 Switch Software (cat4500e-LANBASE-M), Versi on 12.2(54)SG1, RELEASE SOFTWARE (fc1) Technical Support: {URL} ROM: 12.2(44r)SG11 Hobgoblin Revision 21, Fortooine Revision 1.22 [code]...
So, whether the command is not supporting on this Cisco switch ? But we have Cisco 4948 Cisco sw where that command is working fine.
I am tryıng to confıgure port base Vlan on 3com S7900E switch. There are already 9 of them confıgured but one is missing and I need to add 1 more. I have done this on cisco routers but cant get my head around 3com commands.
I have a 1941 that I am going to deploy with a HWIC-D-9ESW switch module (I only need 3 switch ports but need the PoE). I am going to hang a 1262 autonomous AP off one of the ports but I need to configure MAC address port-security so that only that AP can pass traffic. I know the switch modules are 'almost' exactly like a switch for commands but I can't seem to enable or configure any port-security settings. Is port-security no available on the switch modules?