cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
401
Views
0
Helpful
2
Replies

'classical mls' and CEF?

grueter
Level 1
Level 1

Hello,

our cus is running cat5005 (6.3.7) and C7206 (12.2.24a) with the MLS enabled. When doing show cmds on the switch and the router (show mls/show mls rp) all looks fine, so VTP domin ok, RP is recognized, flow mask ok , management ok.

The cus did a 'show mls stat rp' and recognized that no packet is 'switched'???

We don't know exactly was he has changed and if it was working before but what we notice is that the cus has configured on the C7206 the 'ip cef' which as far as I understand also is a L3 switching feature but handled on the router not on the switch.

Could this configuration lead to our problem that the packets are no longer be handled by the 'classical mls' but by the CEF? So the packets going back to the switch from the router don't have the xtag which is needed to become enable entry in the MLS-SE cache?

Thanks for your help, best regards Thomas

2 Replies 2

mchin345
Level 6
Level 6

MLS & CEF can work together. I think the OS running in Cat5005 is having some problem with interoperating with CEF. You can try upgrading to 6.3(10). You can refer to CSCdy75968 for more information.

Hello,

thanks a lot for your reply. I will check if cus agrees to update the switch. The thing is that the cus do have another 'pair' of router/switch with exactly the same CAT/IOS SW 'pair' and this is working fine, this of course does not mean it is not the CAT-OS problem but it makes it harder to argue.

Have a nice day, Thomas