08-02-2022 06:27 AM
Any reason why my 3750x would crash when I use the command cts role-based enforcement vlan-list? This is a lab environment for testing trustsec. This happens every time I use the command. I already tested another 3750x and I get the same results. Code version is 15.2(4)E8
Aug 2 08:12:22 EST: %SYS-2-INTSCHED: 'idle' at level 4 -Process= "CTS CORE", ipl= 4, pid= 51
-Traceback= 6D4DECz 324E628z 270E0F8z 20B9508z 20B9DD8z 2124C6Cz 2124E4Cz 216C670z 2132058z 3478F98z 34790B0z 2132778z 2132700z B24768z B240FCz B249A0z
Aug 2 08:12:22 EST: %SYS-2-INTSCHED: 'idle' at level 4 -Process= "CTS CORE", ipl= 4, pid= 51
08:15:18 EST Tue Aug 2 2022: Unexpected exception to CPUvector 200, PC = 2F2AEB0
-Traceback= 0x2F2AEB0z 0x30BE604z
Solved! Go to Solution.
08-02-2022 12:45 PM
The following guidelines and limitations apply to configuring Cisco TrustSec SGT and SGACL on the Catalyst 3750-X switch:
When port-to-SGT mapping is configured on a port, an SGT is assigned to all ingress traffic on that port. There is no SGACL enforcement for egress traffic on the port.
08-02-2022 07:15 AM
It looks like IOS bugs.
08-02-2022 07:34 AM
Agree with @ashish.kushwaha . You should upgrade to the current gold-star release IOS 15.2.4E10
08-02-2022 08:37 AM
I already tried the lasted IOS version as well as a few others. Same issue unfortunately.
08-02-2022 10:05 AM
Do you have more than 8 vlans on a trunk port?
Crashing when enabling enforcement has had a number of bugs that persisted in to ios-xe software trains as late as 16.6.4, 16.9.5, and even 16.12.3. Given that the 3750x is past tac support, it's unlikely you'll get a root cause. My suggestion would be to start experimenting with removing config, see if it works with a factory reset + base ip config, go from there.
08-02-2022 12:45 PM
The following guidelines and limitations apply to configuring Cisco TrustSec SGT and SGACL on the Catalyst 3750-X switch:
When port-to-SGT mapping is configured on a port, an SGT is assigned to all ingress traffic on that port. There is no SGACL enforcement for egress traffic on the port.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide