I have a 4507R-E with dual Sup 7L-E that will not upgrade IOS. These two Sup's came with IOS XE 3.4 on them. I have copied the image for 3.9.1 to both supervisors and modified the config to 'boot system flash bootflash:<imagename>' then wrote the mem and copied running to startup.
After the config sync to both sups, I do a 'redun reload shelf' and when the unit comes back up its still on 3.4.
I've never had this issue before. The only thing that is different that my other Sup 7's is that these were Cisco refurbished and the others were new.
Any help would be appreciated
Thanks,
Kevin
... View more
I have a large number of new AP's that we are preparing to install. Is there a way to import a listing of AP's to a WLC5508 that has their mac address and its appropriate name, potentially even other parameters such as AP Group, so we don't have to do this manually?
Thanks,
Kevin
... View more
I have a 4507R-E Switch with dual Sup 7L consoles that was recently updated to IOS XE 3.9.2E. After the upgrade and reloading the switch, the unit is misclassifying devices and the wrong macro runs. For example, we have a Cisco Phone plugged in on port 5/10. It detects it as a Lightweight AP and runs the LAP macro.
If I configure that port directly as a phone port and exclude it from macro processing, QoS will tell me that a phone is detected/not detected when we unplug and re-plug the device in.
Any ideas on why it would mis-classify the devices and any thoughts on resolution? I can roll-back to previous IOS version no problem, just thought I would ask about this before I made that decision.
Thanks,
Kevin
... View more
I have 2901 ISR routers with FXO units installed in them and connected to POTS lines. We route 911 through these units instead of through the PRI so we ensure 911 is receiving accurate address and number information. The other day we had an issue in which service to one of the POTS lines was not working so 911 failed. Is there a way to configure the router to test for dial-tone on the FXO port(s) and if it doesn't hear a tone syslog that out to my syslog server? Our basic alarms and fire alarm panels do this except they display on their panel. It would be nice if the router could do this too. Thanks, Kevin
... View more
I had this same problem. It was related to bug CSCuu49765. In order to fix it, TAC had to send me the latest engineering special firmware. At first they sent me ES5 however that did not fix the problem. They then sent me ES13 and this resolved the issue. The modules no longer reboot.
... View more
Went home Friday thinking there was something else I had to do. Lost it all on the drive home and definitely lost it on the weekend. As soon as you said it, I had the big facepalm moment. That worked.
... View more
I have CP-7811 that I cannot get to register with our CallManager, CUCM 9.1.2.13900-10. I have loaded the device pack and the phone load to the publisher and subscriber and then restarted the TFTP service on both units. In the configuration. I have double-checked the MAC address and made sure it was input correctly. I also defined the phone load name after it wouldn't register and no change. It is picking up an ip address as well as picking up the tftp address information. The phone display is stuck on 'Registering'. Any help would be appreciated.
... View more
In looking through the Tomcat Security Logs, it kept erroring out due to a FQDN/hostname mismatch in the certificate. I verified it as correct in the certificate. For the time being, after talking to TAC, we issued a 'utils ldap config ipaddr' to match on IP instead of FQDN. We'll revisit the security certificate issue at a later date when users won't be impacted by testing. Thanks for the nudge in the right direction.
... View more
We recently updated from 9.1.2.12901 to 9.1.2.13900. Once we finished updating, users are no longer to sign in to the CCMUser portal. Users who use the CM Attendant Console are also unable to sign in. We were able to sign-in appropriately prior to the upgrade. On the CCMUser portal, I am getting the following error: 'An LDAP Error has occurred. Retry the username and password. Contact your system administrator if the problem persists.' I have made sure that the users who need it are assigned the Standard CCM User Role. I have also removed that role from my account, saved, then added it back and saved. No change. Oddly enough, I can go into System-->LDAP-->LDAP Directory, perform a sync and it will pull in new users or remove users accordingly. We use secure LDAP for Microsoft AD. All certificates are loaded to the system. Any help would be much appreciated. Kevin
... View more
Maybe I haven't looked long enough or deep enough through the documents and guides, but I am wondering if there is a best practice for purging endpoints in general. For my guest endpoints, I have it set to purge those endpoints every 3 days. When i look at how many endpoints I have profiled at the current time, its a very large number of devices. I'm sure there is a large number of these that are no longer connecting to our network and probably won't in the future. If there isn't a current best practice, would it sound logical to purge every 180 to 190 days? We are a public school district and we have 180 instructional days. Employees and students alike are able to bring their own devices. I figure with 190 day purge, it would cover the time that employees and students are in session. Thoughts, opinions? Thank you for your time. Kevin
... View more
Thanks for the response but TAC provided me with the following document: http://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/115734-ise-policies-ssid-00.html It fit the bill. We had already verified everything else you mention as our Jr. Admins are responsible for creating student users we wanted to make sure they hadn't done something wrong but they hadn't. Everything else was spot on correct. The rule is much simpler by using a simple condition matching the WLAN ID and then Employee Group. Conversely, I applied the same principal to the student WLAN to keep employees from hitting the student network.
... View more
ISE 1.3 MS AD 2008R2 Two Groups: All Employees , All Students Problem: Students connecting to the employee network I have two wireless networks STUDENTS and EMPLOYEES. In ISE I have two authorization policies for these networks. In a prior effort to keep students from connecting to the employee network, I set the authorization policy to: Employee: If ( Wireless_802.1X AND AD1:ExternalGroups EQUALS mydomain/User Accounts/All Employees AND AD1:ExternalGroups NOT_EQUALS mydomain/Students/All Students ) then: Employee_Profile Unfortunately this did not work. Students have their own username and password in AD and so does each faculty/staff member. I have verified that the students are using their credentials and connecting to the employee network. Conversely, I can connect to the student network using an employee's credentials. The main issue is that with the students connecting to the employee network, they are using up all of the addresses in the applicable DHCP scope. I need to disallow connection to the employee network by students and the student network by employees. Any help would be appreciated! Kevin
... View more