Cisco WAN :: Remove IPSec VPN SPA Module From 6509 Chassis?
Feb 29, 2012Need to remove the IPSec VPN SPA module from the 6509 chassis. Does the module is hot swappable or does the 6509 need to be turned off prior to removal.
View 2 RepliesNeed to remove the IPSec VPN SPA module from the 6509 chassis. Does the module is hot swappable or does the 6509 need to be turned off prior to removal.
View 2 RepliesI currently have a couple of 6509 chassis (router/switches) with the following hardware blades:
x3 48 ports
x1 NAM
x2 Sup720
Running 12.2(18)SXF3
I am keeping the four Sup720 modules and have purchased new versions of the others blades including two new 6509-E chassis?Can I take my stand-by Sup720 out of the production machine and insert it into the new chassis?
I currently have a couple of 6509 chassis (router/switches) with the following hardware blades:
x3 48 ports
x1 NAM
x2 Sup720
Running 12.2(18)SXF3.I am keeping the four Sup720 modules and have purchased new versions of the others blades including two new 6509-E chassis. Can I take my stand-by Sup720 out of the production machine and insert it into the new chassis?
why is not possible to put a WS-X4712-SFP+E - module into an R-E chassis?The module has the same connection to backplane as the WS-X4748-UPOE+E and this one works in a R-E chassis.I know the restriction of Cisco that the 4712 is only supported in 4503-E, 4506-E,4507+E and 4510+E, but why?Are there hardware-restrictions, is the backplane different?
View 2 Replies View RelatedI am experiencing 1 4548 module fail issue with one of my customer place. unfortunately they are having only 1 4507R+E chassis and 1 4548 module. however i have replaced the module 4548 and getting the same error even after replacing ...!! but they are having redudant X45-SUP6L-E tried by removing each at one time with no luck. [code]
View 3 Replies View RelatedCurrently have a pair of 6509 chassis setup with VSS. Only have the Sup and two line cards in each chassis. Would like to replace with a new pair of 6504E chassis. Is it possible to fail one chassis at a time and migrate to the new 6504E?
View 3 Replies View RelatedI know to add a user in the service engine is (config)#user Aileen create but how would you remove it. I tried no before user to negate the command but i do #sh users and the username is still listed.
View 1 Replies View RelatedWe have a backup sup 720 which has a 2 gigabit ethernet though port channel, to another chassis. Suddenly UDLD detected an error and got into err disable, then this err disable didn't let the interface set to DOWN, and created a switch loop, then our Supervisor reloaded. I'd like to know what could have caused this reload. In my opinion could have a been the switch loop, but also I've been checking from the output interpreter the show tech and might have been a bug, the only one that could match in IOS version 12.2(33)SXH, is this one: url...
We're going to disable err-disable next time I guess and recover the link manually, apart from that what could have made the sup for crash and reload?
I have inherited a 6509 VSS switch system as the network core and have the task of ensuring proper redundancy and redesign of the directly connected data center devices. One of the connected devices (WLC 4402) physically appears to be connected to both switches - the WLC is in the same rack as VSS-Chassis1 so I can trace the fiber from WLC port 1 to gi1/1/22, the other fiber from the WLC port 2 goes into the floor and presumably over to VSS-Chassis2 gi2/1/22 (there is fiber connected there, I have link lights on both sides, and the port channel, Po200, on the VSS switch which is configured on gi1/1/22 is also configured on gi2/1/22). My question pertains to the CDP neighbor output I get on the VSS switch: (truncated to include just the WLC) [code]
So my question, arising at least partly from the apparently misleading CDP information, is this: How can I confirm that the WLC is correctly dual homed to both core switches? (short of tracing the cable) I ask because there are several other devices (not WLCs) that need to have the dual homed connections confirmed.I tried a layer 2 trace route but for all macs associated with the WLC, the trace abborts with the error "Device has Multiple CDP neighbours on destination port."
swapping out a failed supervisor card on a 6509 chassis?
View 6 Replies View Relatedwe have some pairs of 6509-VSS, which partially have old (no more officially supported) 6509-Chassis.All linecards in the VSS are the same (Sup 720-10GE-3C, 67XX).
We now bought some new 6509-E-Chassis and want to change the old chassis by the new ones in a ISSU manner, that means:
1. putting the partner, which chassis changes, in redundancy mode, switch it off, exchange chassis (old "Catalyst 6509", new "Catalyst 6509-E")
2. inserting the line-cards exactly in the same slots and connecting all cables
3. switch on the new chassis, witing to come up in VSS
I'm not sure of having to set the switch number for VSS (is that in the Sup?; configuration? or part of the chassis-memory?)
I've looked up cisco for some hints, but don't found anything.
Are there any physical characteristic differences between the 6509 and 6509-E chassis?
View 4 Replies View RelatedI have multiple 6509 vss switch. and i notice when the standby chassis reboot I didn't get any snmp trap, but I got when the active one reboot. my question is is there any mib out there for detecting and got a trap when standby reboot?
View 2 Replies View RelatedI have a heck of a time finding this kind of information on the cisco site...Is the WS-SUP720-BASE line card a fully supported module in the 6509-E chassis?
View 4 Replies View RelatedAny have experience on triggered failover on VSS deployment with 1 VS-720-10G-3C in each chassis? I tried using "redundancy force-switchover" but after that the 20G VSL is flapping up & down and cannot be up normally, we got 1 FWSM in each chassis, any configuration need to fit in this kind deployment? BTW, if I shutdown the power source of VSS active chassis, both FWSM & VSS can failover normally.
View 3 Replies View RelatedCurrently we have two inter-chassis FWSM redundancy. I would like to configure them for intra-chassis.
Both FWSM's are in slot 7 of 6509 switches and i want to take secondary out from one of the 6509 switch and insert in the slot 3 of primary switch.
I addedd the following commands in my primary switch.
There were commands already present for FWSM in primary switch
firewall multiple-vlan-interfaces
firewall module 7 vlan-group 1
firewall vlan-group 1 2,3,777
to create intra-chassis redundancy i addedd the following command also there.
firewall module 3 vlan-group 1
after adding that, my firewalls worked fine but there was a issue with site loading. People from outside were able to access inside but from inside, we were not able to go outside.
do we need to clear arp from both FWSM's ? is there any other precautionary step, which we need to follow while working on it.
We've just invested in a pair of Sup2Ts to upgrade a Sup720 6509 chassis but I'm unsure exactly how the management port(s), aka the Connectivity Management Processor (CMP), should be configured (and patched) in a dual supervisor system?Is each CMP an independent entity or is the management interface configuration (IP address, gateway, etc) replicated between supervisors?If it's the latter then do both management ports need to be physically connected at the same time?
View 1 Replies View Relatedsetting up VRF-lite on redundant 6509-E chassis to account for chassis failure? Let's say I have 2x 6509-Es configured with HSRP for 2 vlans, ServerA and ServerB. So
6509-A#
!
interface Vlan10
description ServerA VLAN
ip address 10.10.10.2 255.255.255.0
ip flow ingress
standby 1 ip 10.10.10.1
standby 1 priority 105
[code].....
I now need to create an environment where the Server VLANs can be provided for two customers and they need to be wholly separate. On 6509-A, I make VRF CustomerA and VRF CustomerB and I assign Vlan10 to VRF CustomerA and Vlan20 to CustomerB. Do I create the SAME VRFs on 6509-B with the same logic?
We have a pair of 6509's with duplicate ACL lists & entries.
1 = Version 12.2(33)SXI4a
2 = Version 12.2(18)SXF15a
I wanted to remove some logging that was on an entry on one of our extended ACL's. On 1 this worked fine with the no 400
400 <acl rule without log>
However on 2 it lets me carry out the no 400 command but when i go to add the 400 <acl rule without log> i get the error % Duplicate sequence number.sure enough when i perform the 'Show access-lists <Name>' it is still there!
I have tried the following:
Adding a duplicate ACL entry before it (399) without log and i still get hits on line 400Adding and removing the duplicate created line 399 (without logging) with no issues.Adding and removing a dupliacte ACL (without Logging) after (line 401) with no issues
It looks like it is just this line it seems to think it has removed but hasn't?!
I understand an option is to duplicate the ACL in a text editor remove line, delete the ACL and put the edit back in .....however i wondered if this is something known (bug).
I have a 6509 running s72033_rp-ADVIPSERVICESK9_WAN-M version 12.2(33)SXH5. Four incorrect bgp aggregate-address statements were entered in which overlap. Attempted to remove the statements but they won't come out.
aggregate address 16.37.31.0 255.255.224.0 summary-only
aggregate address 16.37.30.0 255.255.224.0 summary-only
aggregate address 16.37.29.0 255.255.224.0 summary-only
aggregate address 16.37.26.0 255.255.224.0 summary only
I have entered in the correct statements and have no problem getting those in, removing them, and reentering them.
The 6509 Series Switches support the scenario VSS Active-Active Chassis, I would like to setup both switch's as one virtual switch but working at the same time, not with Active - Stand By Chassis.
My plans it to create PortChannel accross both Switches 6509 in order to have 2 links one connected to one slot/switch and the other connected to slot/switch in the second 6509 for servers redundancy.
we need to install a line cards (WS-X4548-GB-RJ45, chassis WS-C4510R-E), on a chassis Ws-6504-E.where I can find information about compatibility?
View 2 Replies View RelatedWe have a 6509-e (WS-C6509-E V04) with (4) (WS-X6148-GE-TX) 48 port modules and a supervisor 32 (WS-SUP32-GE-3B).We purchased a supervisor 720 (WS-SUP720-3B) and (2) (WS-6708-10G-3C) 8 port fiber modules and (1) WS-X6748-GE-TX)48 port module to add to the switch. My question is what is the best way to swap out the supervisor module? Can the SUP720 be added as a standby module so that the config can be transferred? Probably a long shot. Is there anything in this swap that I should be concerned with? The other three modules should be pretty straight forward.
View 4 Replies View Relatedwe have two 6509 catalyst. we bought two new SFM-capable 16 port 1000mb GBIC/WS-X6516A-GBIC module. but our catalysts doesnt support them. we don't know the reason. we tried on another 6500 series catalyst they worked.
here are the outputs from our 6509:
Core-SW-1#sh module
Mod Ports Card Type Model Serial No.
--- ----- -------------------------------------- ------------------ -----------
1 0 1-subslot SPA Interface Processor-600 7600-SIP-600 JAE14090958
2 48 CEF720 48 port 10/100/1000mb Ethernet WS-X6748-GE-TX SAL1413DX2B
3 16 CEF720 16 port 10GE WS-X6716-10GE SAL1414EL2Q
4 1 Application Control Engine Module ACE20-MOD-K9 SAD1408036Z
5 5 Supervisor Engine 720 10GE (Active) VS-S720-10G SAL1414ERDT
6 5 Supervisor Engine 720 10GE (RPR-Warm) VS-S720-10G SAL1414ERE3
7 16 CEF720 16 port 10GE WS-X6716-10GE SAL1414ER93
8 16 SFM-capable 16 port 1000mb GBIC WS-X6516A-GBIC SAL1326SVBS(code)
i just configured GRE over IPSEC on my Cisco 3745 router with VPN module installed. As soon i hit 25Mbps traffic, my CPU is touching 80%.
What maximum Traffic 3745 with GRE over IPSEC it can support?
Also show process CPU sorted dont show any evidence of which process eating it up.
sh processes cpu sorted
CPU utilization for five seconds: 75%/75%; one minute: 77%; five minutes: 78%
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
[Code].....
I try to access to WS-SVC-NAM-2 module in the Switch 6509. But is not work although the HTTP port is enabled (I tested with the command telnet @ip 80).
I try telnet access to the module to check the config , but I always the message that the lo gin / password is wrong even though they are valid.
I have a pair of 6509-E Switches running VS-720 Supervisors. We are planning to add Ace Module onto the 6509-E. Will IP Base Image suffice the requirement? Will Ace Module work with only IP Base Image?
View 1 Replies View RelatedWe have a 6509 with an ACE module. For reasons I don't fully understand the ACE is running using a BVI in bridge mode. It has loads of secondary interfaces.
[Code]...
I can ping all of the IPs on the BVI, but only servers in Subnet 10.7.42/42 can ping out of the the layer 3 on the 6509. I have all the routes configured properly on the 6509 pointing to the ACE for these subnets. The question is though the config has been excepted, is there a limit to the number of secondary on a BVI.
I have a switch Cisco WS-C6509-E WS-X6716-10G-3C module ( module for 10 GB) , i have the IOS s72033-ipservicesk9-mz.122-18.SXF9.bin. I want to know if this IOS can support this module or not ? or , if i must do a upgrade , is that the IOS : "s72033-ipservicesk9_wan-mz.122-33.SXH8" work fine ?
View 7 Replies View RelatedWe have 7606 router without any ipsec module on it,so i check the ios and it has all commands in interface tunnel for configuring the dmvpn multipoint tunnel and also protection profile for ipsec! so i have this question: do we can run dmvpn between this router and our wan routers wich are 3845.
View 2 Replies View RelatedTo configure the GRE tunnel over IPSEC with OSFT via Encryption module from Cisco Router 3845, I have few queries:
1. Does the router 3845 support hot swap for encryption module?
2. Does the router require to be rebooted after plug in encryption module?
3. Any samples configuration for GRE tunnel over IPSEC?
Suffered a big outage on the network, the fix was to reload the module 3 on the 6509 switch, we had these errors on the log %CONST_DIAG-SW1_SP-3-HM_PORT_TEST_FAIL: Switch 1 Module 3 TestUnusedPortLoopback Port(s)[24,46] failed. System operation continues.in the end, we reloaded the card and it was all ok. is there anything I can do to check the card / or any deeper logs? would that error cause the card to crash?
View 1 Replies View RelatedI have a cisco 6509 configured with a cisco NAM module. I have reset the config of the NAM module by the config clear command. Since this moment I can't no more ping the NAM module via the management port: OK via the 127.0.0.91 address and log in ok via the ios cli session command. [code] I have already tried to reboot the module via the ios cli hw module command and nothing better.
View 12 Replies View Related