cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
565
Views
8
Helpful
15
Replies

Assistance Required: Err-Disabled Storm-Control on WS-C3560

ALI12
Level 1
Level 1

Hi Team,

I am encountering an issue with the storm-control configuration on our WS-C3560V2-24PS-S switches. The ports are repeatedly going into an err-disabled state due to storm-control on specific PCs.

Could anyone provide insights into the possible reasons for this behavior?

Thank you in advance for your assistance.

2 Accepted Solutions

Accepted Solutions

If I remember correctly the % is % of the total link BW which if that's the case your 10% seems low. I don't believe there is a recommended level as every environment has different requirements. As I mentioned before you need to know your environment and what traffic is "supposed" to be traversing the link. I would adjust it, maybe put it at 50% and see if the issue persists. As you get a better feel what works in your network you can configure the rest of the ports.

 

-David

View solution in original post

No problem! Glad to help.  If it resolved your issue, please mark as solved to help other users find a solution.

View solution in original post

15 Replies 15

Hello,

 

It sounds like storm control is doing what it needs to do on the port since its configured. The only 3 solutions is to remove it, increase the threshold at which it err-disables the port, or change the way it handles the storm by sending traps not not err-disabling the port with the storm control action. See Cisco doc below formore info.

Catalyst 3560 Software Configuration Guide, Release 12.2(52)SE - Configuring Port-Based Traffic Control [Cisco Catalyst 3560 Series Switches] - Cisco

 

-David

 

 

 

@David Ruess 

Hi David,

Thank you for the information, I really appreciate it.

Perhaps my question was not clear.
I did not mean to ask for the removal of the Err-Disabled Storm-Control.
Instead, I would like to understand the reason for this issue with the PC connected to the switch port.
Is it due to suspicious activity on PC such as a trojan, spam, adware, or something similar?

Thank you for your assistance.

 

Show interface <<- do this twice 

Check boradcast and multicast counter

Show mac address table' see how many mac known in port 

MHM

@MHM Cisco World 

Thank you for your input.

Please find the output in the attachments.

Note: The issue occurs randomly, approximately twice per day.

 

When storm control is configured, a threshold is set, which is a set packet/byte count. You can see this with the command 

show storm-control or show interface counters storm-control

If your PC exceeds that threshold it will err-disable the port. So, either your threshold is too low, or your PC could be sending lots of traffic to the switchport. Either way you need to know your environment to set the appropriate threshold. If it keeps err-disabling you will need to raise the configured threshold while making sure the PC is sending an appropriate amount of traffic.

If this is configured on a trunk (I would not recommend) you will likely need to increase the threshold more as it's taking traffic from all VLANs/devices downstream.

Hope that clears it up.

 

-David

@David Ruess 

Thank you for the information.

I understand now.
does there a recommended value?
I have currently set it to 10.


interface FastEthernet0/2
switchport access vlan 217
switchport mode access
switchport voice vlan 172
storm-control broadcast level 10.00
storm-control action shutdown
spanning-tree portfast
spanning-tree bpduguard enable

Interface Filter State Upper Lower Current
--------- ------------- ----------- ----------- ----------
Fa0/1 Link Down 10.00% 10.00% 0.00%
Fa0/2 Forwarding 10.00% 10.00% 0.00%
Fa0/3 Forwarding 10.00% 10.00% 0.00%
Fa0/4 Forwarding 10.00% 10.00% 0.00%
Fa0/5 Link Down 10.00% 10.00% 0.00%
Fa0/6 Forwarding 10.00% 10.00% 0.00%
Fa0/7 Forwarding 10.00% 10.00% 0.00%
Fa0/8 Forwarding 10.00% 10.00% 0.00%
Fa0/9 Link Down 10.00% 10.00% 0.00%
Fa0/10 Forwarding 10.00% 10.00% 0.00%
Fa0/11 Forwarding 10.00% 10.00% 0.00%
Fa0/12 Link Down 10.00% 10.00% 0.00%
Fa0/13 Forwarding 10.00% 10.00% 0.00%
Fa0/14 Link Down 10.00% 10.00% 0.00%
Fa0/15 Forwarding 10.00% 10.00% 0.00%
Fa0/16 Forwarding 10.00% 10.00% 0.00%
Fa0/17 Forwarding 10.00% 10.00% 0.00%
Fa0/18 Forwarding 10.00% 10.00% 0.00%
Fa0/19 Link Down 10.00% 10.00% 0.00%
Fa0/20 Forwarding 10.00% 10.00% 0.00%
Fa0/21 Link Down 10.00% 10.00% 0.00%
Fa0/22 Forwarding 10.00% 10.00% 0.00%
Fa0/23 Forwarding 10.00% 10.00% 0.00%
Fa0/24 Forwarding 10.00% 10.00% 0.00%

If I remember correctly the % is % of the total link BW which if that's the case your 10% seems low. I don't believe there is a recommended level as every environment has different requirements. As I mentioned before you need to know your environment and what traffic is "supposed" to be traversing the link. I would adjust it, maybe put it at 50% and see if the issue persists. As you get a better feel what works in your network you can configure the rest of the ports.

 

-David

@David Ruess 

I initially thought this was only related to the broadcast level, not the total traffic. Are you sure it's related to the total bandwidth?

From the document I provided above:

The keywords have these meanings:

For level, specify the rising threshold level for broadcast, multicast, or unicast traffic as a percentage (up to two decimal places) of the bandwidth. The port blocks traffic when the rising threshold is reached. The range is 0.00 to 100.00.

 

-David

@David Ruess 

Thank you, David, for this information. I just noticed it now and really appreciate your support and the details you've provided. Thanks again!

 

No problem! Glad to help.  If it resolved your issue, please mark as solved to help other users find a solution.

Do what David suggest increase level' if you still face issue update me

Please mention my name to make notice

MHM

@MHM Cisco World 
Sure, I will. Thank you for your continued support, mate.

Port is voice are you sure PC is connect or phone ?

Also do you config stp bpdufilter in global ?

MHM

Review Cisco Networking for a $25 gift card