Is there a command to run diagnostics on a single switch port on a line card in a 6807-XL Switch? We have a C6800-32P10G and the LED for port 32 on that card we have all ports disabled and the other ports are solid amber/orange. There are no SFP's in any of the ports at this time. In an identical switch with the same model line card in the same slot (5), the LED goes green and then solid amber/orange. That switch doesn't have any SFPs in it either and ports are administratively down like the other switch. Is there a command I can run on that specific port to see if we have a bad port?
... View more
Not Sure if this has been answered, but you have to configure the interface with the history command and any options you want.
ROUTER1(config)#int s1/0/0 ROUTER1(config-if)#history bps/pps ? all Include all counters crcs Include CRCs - CRCs dribbles Include dribbles - Dribl flushes Include flushes - Flush frame-errors Include frame errors - FrErr giants Include giants - Giant ignored Include ignored - Ignor input-broadcasts Include input broadcasts - iBcst input-drops Include input drops - iDrop input-errors Include input errors - iErr interface-resets Include interface resets - IRset output-broadcasts Include output broadcasts - oBcst output-buffer-failures Include output buffer failures - oBufF output-buffers-swapped-out Include output buffers swapped out - oBSwO output-drops Include output drops - oDrop output-errors Include output errors - oErr output-no-buffer Include output no buffer - oNoBf overruns Include overruns - OvrRn runts Include runts - Runts throttles Include throttles - Thrtl underruns Include underruns - UndRn unknown-protocol-drops Include unknown protocol drops - Unkno <cr>
... View more
We have 3 systems monitoring our 6807 switches that have this message in their log. How can we tell which system is causing this "error" to generate?
The systems are
PI 3.3
Whats Up Gold
Statseeker
... View more
I'm having yet another issue with PI. I recently upgraded to 3.3 at Cisco's suggestion to "fix" a bug on 3.2. I have port groups created for the 3850 switch stacks at each of our sites. I have dynamic filters set to include the following ports:
name starts with GigabitEthernet
description does not contain trunk
description does not contain TR
description does not contain router
description does not contain vg224
The goal is to only put End User ports from those switch stacks in a port group so that I can then create an alarm policy to suppress alarms for the end user ports so that I'm not getting an email alert every time a user shuts down their pc or whatever. PI is not adding all of the end user ports from the switch stacks to that port group and there's not rhyme or reason as to why it selected some ports and why it didn't select other ports with identical configurations. Not trying to make this into a Cisco bashing session, but I'm frustrated with PI 3.x because it lacks basic functionality that other NMS have. You can't modify the alert subject or body to help you distinguish an alert especially when you're looking at it on your phone. All Alerts are like "Alarm Category - Switches and Routers; Severity - " I'm most familiar with Solar Winds so I'm going to use them as an example. With SW, I can create a subject based on pretty much whatever I want. I can create a subject for router interfaces that says "Alert - Chicago WAN Router Interface Down". When I get that email to my phone, I know it's important by just looking at the subject and it gives me a sense of urgency to take action. I've brought this up to Cisco TAC before but I don't think Cisco is putting any serious thought into making this product more administrator friendly.
... View more
What I want to say: "Get Solar Winds and use prime for wireless heat maps." I'm having similar issues too. Haven't been happy with PI for a while. Every 3.x update breaks something else. I hope you find the fix and hope the solution is not upgrading to 3.4
... View more
We just got a full 1GB internet link. It's going to be for internet only. Is it recommended to police it or shape it or can I just let it ride???
... View more
Thanks for your reply. So for the 1G link I'm moving to, the numbers are as follows?
1,000,000,000 * 1 byte/8bits *1.5 ==> 187,500,000 and 375,000,000?
Any reason to put less than full rate of link in policing statement?
We currently have a 300Mb CIR on our existing link, but the policy was configured for 275,000,000
Our new circuit is a 1Gb link and I was going to put 910,000,000 instead of 1,000,000,000 on the policing statement, but is there a reason not to use 1,000,000,000?
... View more
We're upgrading our 300Mb circuit with a full 1Gb circuit and I'm wondering what the recommended inbound policing percentages are for burst-normal and burst-max.
on the 300Mbps link we have:
police 275000000 55000000 110000000 conform-action transmit exceed-action transmit violate-action drop
Is the recommended percentage 18% and 36% respectively or is there a formula for this?
... View more
I figured it out. I upgraded my remote site 4451's IOS-XE 3.17.4S and that allowed me to change the macsec ether-type to B860 on all routers. The routers were then able to establish macsec sessions. My ISP (Level 3) says they're not blocking EAPoL but that has to be happening somewhere. My DR site and my HQ site have 2 different last mile providers and I'm wondering if one of their networks is blocking or dropping it.
DR - AT&T (Macsec worked using eapol destination-address broadcast-address but without changing eth-type to B860)
HQ - AboveNet (Macsec worked after changing eth-type to B860 and using eapol destination-address broadcast-address)
... View more
I'm having a problem where my ISR 4K router at my HQ will cannot form a macsec session to 3 of our Remote Sites over 3 different VLANs. They're all ISR 4451 routers with the same NIM-2GE-CU-SFP module. However the 3 remote sites can form macsec sessions between each other.
HQ <-> RS1 over VLAN 101 doesn't work but L2 connectivity is there
HQ <-> RS2 over VLAN 102 doesn't work but L2 connectivity is there
HQ <-> RS3 over VLAN 103 doesn't work but L2 connectivity is there
R1 <->R2<->R3 over VLAN 105 works fine.
My ISP confirmed they are not blocking EAPoL traffic and I set the eapol destination-address broadcast setting on ALL routers.
Any suggestions on what to look for? I have a TAC case open but we're still trying to get this on figured out.
... View more
I don't think we have the same situation. I have 4 x 6807 chassis' and each has a SUP6T. From what I understand, you can only put 2 6807 Chassis' in a VSS pair. In my case, I'd have to create 2 VSS Pair with Trunks between them.
... View more
We have 4 6807's that we're going to use to replace 2 6509's. Each 6807 has a SUP6T engine. Can we put all 4 switches in VSS mode in a single domain? If so, does anyone know of any design documentation that covers this scenario?
... View more