09-05-2024 03:06 AM
Hi Team,
I am encountering an issue with the storm-control configuration on our WS-C3560V2-24PS-S switches. The ports are repeatedly going into an err-disabled state due to storm-control on specific PCs.
Could anyone provide insights into the possible reasons for this behavior?
Thank you in advance for your assistance.
Solved! Go to Solution.
09-05-2024 06:26 AM - edited 09-05-2024 06:26 AM
If I remember correctly the % is % of the total link BW which if that's the case your 10% seems low. I don't believe there is a recommended level as every environment has different requirements. As I mentioned before you need to know your environment and what traffic is "supposed" to be traversing the link. I would adjust it, maybe put it at 50% and see if the issue persists. As you get a better feel what works in your network you can configure the rest of the ports.
-David
09-05-2024 07:58 AM
No problem! Glad to help. If it resolved your issue, please mark as solved to help other users find a solution.
09-05-2024 04:53 AM
Hello,
It sounds like storm control is doing what it needs to do on the port since its configured. The only 3 solutions is to remove it, increase the threshold at which it err-disables the port, or change the way it handles the storm by sending traps not not err-disabling the port with the storm control action. See Cisco doc below formore info.
-David
09-05-2024 05:35 AM
Hi David,
Thank you for the information, I really appreciate it.
Perhaps my question was not clear.
I did not mean to ask for the removal of the Err-Disabled Storm-Control.
Instead, I would like to understand the reason for this issue with the PC connected to the switch port.
Is it due to suspicious activity on PC such as a trojan, spam, adware, or something similar?
Thank you for your assistance.
09-05-2024 05:39 AM
Show interface <<- do this twice
Check boradcast and multicast counter
Show mac address table' see how many mac known in port
MHM
09-05-2024 05:58 AM
@MHM Cisco World
Thank you for your input.
Please find the output in the attachments.
Note: The issue occurs randomly, approximately twice per day.
09-05-2024 05:59 AM - edited 09-05-2024 06:10 AM
When storm control is configured, a threshold is set, which is a set packet/byte count. You can see this with the command
show storm-control or show interface counters storm-control
If your PC exceeds that threshold it will err-disable the port. So, either your threshold is too low, or your PC could be sending lots of traffic to the switchport. Either way you need to know your environment to set the appropriate threshold. If it keeps err-disabling you will need to raise the configured threshold while making sure the PC is sending an appropriate amount of traffic.
If this is configured on a trunk (I would not recommend) you will likely need to increase the threshold more as it's taking traffic from all VLANs/devices downstream.
Hope that clears it up.
-David
09-05-2024 06:16 AM
Thank you for the information.
I understand now.
does there a recommended value?
I have currently set it to 10.
interface FastEthernet0/2
switchport access vlan 217
switchport mode access
switchport voice vlan 172
storm-control broadcast level 10.00
storm-control action shutdown
spanning-tree portfast
spanning-tree bpduguard enable
Interface Filter State Upper Lower Current
--------- ------------- ----------- ----------- ----------
Fa0/1 Link Down 10.00% 10.00% 0.00%
Fa0/2 Forwarding 10.00% 10.00% 0.00%
Fa0/3 Forwarding 10.00% 10.00% 0.00%
Fa0/4 Forwarding 10.00% 10.00% 0.00%
Fa0/5 Link Down 10.00% 10.00% 0.00%
Fa0/6 Forwarding 10.00% 10.00% 0.00%
Fa0/7 Forwarding 10.00% 10.00% 0.00%
Fa0/8 Forwarding 10.00% 10.00% 0.00%
Fa0/9 Link Down 10.00% 10.00% 0.00%
Fa0/10 Forwarding 10.00% 10.00% 0.00%
Fa0/11 Forwarding 10.00% 10.00% 0.00%
Fa0/12 Link Down 10.00% 10.00% 0.00%
Fa0/13 Forwarding 10.00% 10.00% 0.00%
Fa0/14 Link Down 10.00% 10.00% 0.00%
Fa0/15 Forwarding 10.00% 10.00% 0.00%
Fa0/16 Forwarding 10.00% 10.00% 0.00%
Fa0/17 Forwarding 10.00% 10.00% 0.00%
Fa0/18 Forwarding 10.00% 10.00% 0.00%
Fa0/19 Link Down 10.00% 10.00% 0.00%
Fa0/20 Forwarding 10.00% 10.00% 0.00%
Fa0/21 Link Down 10.00% 10.00% 0.00%
Fa0/22 Forwarding 10.00% 10.00% 0.00%
Fa0/23 Forwarding 10.00% 10.00% 0.00%
Fa0/24 Forwarding 10.00% 10.00% 0.00%
09-05-2024 06:26 AM - edited 09-05-2024 06:26 AM
If I remember correctly the % is % of the total link BW which if that's the case your 10% seems low. I don't believe there is a recommended level as every environment has different requirements. As I mentioned before you need to know your environment and what traffic is "supposed" to be traversing the link. I would adjust it, maybe put it at 50% and see if the issue persists. As you get a better feel what works in your network you can configure the rest of the ports.
-David
09-05-2024 07:36 AM
@David Ruess
I initially thought this was only related to the broadcast level, not the total traffic. Are you sure it's related to the total bandwidth?
09-05-2024 07:44 AM
From the document I provided above:
The keywords have these meanings:
For level, specify the rising threshold level for broadcast, multicast, or unicast traffic as a percentage (up to two decimal places) of the bandwidth. The port blocks traffic when the rising threshold is reached. The range is 0.00 to 100.00.
-David
09-05-2024 07:54 AM
Thank you, David, for this information. I just noticed it now and really appreciate your support and the details you've provided. Thanks again!
09-05-2024 07:58 AM
No problem! Glad to help. If it resolved your issue, please mark as solved to help other users find a solution.
09-05-2024 08:05 AM
Do what David suggest increase level' if you still face issue update me
Please mention my name to make notice
MHM
09-05-2024 08:10 AM
@MHM Cisco World
Sure, I will. Thank you for your continued support, mate.
09-05-2024 06:28 AM
Port is voice are you sure PC is connect or phone ?
Also do you config stp bpdufilter in global ?
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide