We are running ISE 2.1. I’ve created a new Exception Rule for our Wired MAB Enforcement Policy Set called: “EFK_Misc”, and have my condition and permissions set. However, I’m seeing some anomalies during the initial rollout of these devices onto our network.
After manually adding their MAC address via Context Visibility; I can find the MAC on the main page of Context Visibility, but if I select it to go into the “Endpoints” screen, it shows the description I’ve given, that the Static Group Assignment is “True”, but shows nothing for Identity Group Assignment. If I edit it, it does show an Identity Group Assignment of “EFK_Misc”. This is not a java or browser issues as I’ve tried two different jump servers to access the Admin node…
When I try to do an import of additional MAC addresses, I get an error message that the Group Assignment is unknown.
I noticed that at least one device during the initial 5 devices had shown proper authentication on the switch via the “Show auth session int g 1/0/25 det”, but Context Visibility did not show the device authenticated.
Initial roll-out of these paging devices are mired in some “problems communicating” which I’m still trying to get better information regarding.
I’m not well versed in ISE, and am wondering if my new Exception for my MAB wired policy set may be missing something, or if this just a ghost in the machine.
Thanks for any input.
... View more
I believe another solution would be to disable IBM snooping on that particular VLAN on the N7000 where the L3 lives:
(config)# vlan configuration 2001 <E>
(config-vlan)# no ip igmp snooping <E>
Turns off IGMP snooping on VLAN 2001....
... View more
I have a C3560 Switch running IPServices. I never setup vrf's on a LAN switch so I know I'm missing basic config and concepts. All I want to do is set up a separate vrf from default (everything else is in default) and call it Labs; and have a couple of L3 VLANs (and default route) belong to it. It connects up to a firewall in a "Labs" security zone.
My current config- I can only PING a Labs VLAN if I precede the host IP with "vrf Labs" 10.34.48.62, so this works as expected. However, this VLAN is a point-to-point link to the FW with a 10.34.48.61 address. I can ONLY Ping it if I use default VRF...
(FW 10.34.48.61)----------------connects to -----------C3560 (VLAN598 10.34.48.62 vrf LABS)
Please see below for partial switch config and steps: (THANKS for any/all help!!!)
sho run int vlan 598 Building configuration...
Current configuration : 191 bytes ! interface Vlan598 description LAN-to-FW Labs Zone vrf forwarding Labs ip address 10.34.48.62 255.255.255.252 no ip redirects no ip unreachables no ip proxy-arp load-interval 30 end
NRDUOFFMDFSITSW02#ping 10.34.48.62 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10.34.48.62, timeout is 2 seconds: ..... Success rate is 0 percent (0/5) NRDUOFFMDFSITSW02#ping vrf Labs 10.34.48.62 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10.34.48.62, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
NRDUOFFMDFSITSW02#ping vrf Labs 10.34.48.61 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10.34.48.61, timeout is 2 seconds: ..... Success rate is 0 percent (0/5) NRDUOFFMDFSITSW02#ping 10.34.48.61 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 10.34.48.61, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/10 ms
sho run | be definition vrf definition Labs description HSS Lab rd 65000:1
NRDUOFFMDFSITSW02#sho vrf det VRF Labs (VRF Id = 3); default RD 65000:1; default VPNID <not set> Description: HSS Lab New CLI format, supports multiple address-families Flags: 0x180C Interfaces: Vl598 Vl3885 Address family ipv4 unicast (Table ID = 0x3): Flags: 0x0 No Export VPN route-target communities No Import VPN route-target communities No import route-map No global export route-map No export route-map VRF label distribution protocol: not configured VRF label allocation mode: per-prefix Address family ipv6 unicast not active
VRF Mgmt-vrf (VRF Id = 1); default RD <not set>; default VPNID <not set> New CLI format, supports multiple address-families Flags: 0x1808 Interfaces: Gi0/0 Address family ipv4 unicast (Table ID = 0x1): Flags: 0x0 No Export VPN route-target communities No Import VPN route-target communities No import route-map No global export route-map No export route-map VRF label distribution protocol: not configured VRF label allocation mode: per-prefix Address family ipv6 unicast (Table ID = 0x1E000001): Flags: 0x0 No Export VPN route-target communities No Import VPN route-target communities No import route-map No global export route-map No export route-map VRF label distribution protocol: not configured VRF label allocation mode: per-prefix
... View more
I have a 9508 interface running at 1 Gbps, but is showing TX/RX rates much higher than 1 Gbps...Is it a bug? I'm running NX-OS 7.0.3 I3. I also notice that "Clear counters" on the interface or the switch does not clear the counters. Please see below. (This is a FEX)...Any input would be appreciated.
Ethernet151/1/5 is up admin state is up, Hardware: 100/1000/10000 Ethernet, address: 94d4.6978.2966 (bia 94d4.6978.2966) Description: L82E15 - efkxtsmp031 MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec reliability 255/255, txload 255/255, rxload 255/255 Encapsulation ARPA, medium is broadcast Port mode is access full-duplex, 1000 Mb/s Beacon is turned off Auto-Negotiation is turned on, FEC mode is Auto Input flow-control is off, output flow-control is on Auto-mdix is turned off Switchport monitor is off EtherType is 0x8100 Last link flapped 4d14h Last clearing of "show interface" counters 01:21:03 0 interface resets 30 seconds input rate 4508360867360 bits/sec, 684904541 packets/sec 30 seconds output rate 8943593443944 bits/sec, 919411812 packets/sec Load-Interval #2: 5 minute (300 seconds) input rate 4506.79 Gbps, 684.53 Mpps; output rate 8937.92 Gbps, 918.88 Mpps RX 334630976479 unicast packets 0 multicast packets 185268 broadcast packets 334631161941 input packets 275449005498474 bytes 0 jumbo packets 0 storm suppression packets 0 runts 0 giants 0 CRC 0 no buffer 0 input error 0 short frame 0 overrun 0 underrun 0 ignored 0 watchdog 0 bad etype drop 0 bad proto drop 0 if down drop 0 input with dribble 0 input discard 0 Rx pause TX 446186948220 unicast packets 391886784 multicast packets 2591637942 broadcast packets 449170472934 output packets 546099820306165 bytes 0 jumbo packets 0 output error 0 collision 0 deferred 0 late collision 0 lost carrier 0 no carrier 0 babble 0 output discard 0 Tx pause
... View more
We have Nexus 5020s running 5.1(3) on our server Access Tier which show excessive Input Discards on several interfaces going up to the Distribution 7000s, but also on several of our interfaces connecting to the servers. This is in the magnitude of 120,000 discards in 80 minutes and 30,000 discards/80 minutes on two uplinks into the Dist Tier, but also 12,000/80 Min, 8,000/80 Min on several ports connecting to servers. I understand that this could be indicative of Head-of-Line-Blocking (switch egress congestion causing backup on the switch ingress), so when attempting to address the large number of input discards on the interfaces facing the Dist Tier, I'm looking for signs of egress congestion going to the servers, IE: high TX Interface Load, High output errors, etc. However, I do not see ANY signs of egress congestion.
The below was a great doc, but I think I need to look elsewhere.
Does anyone have any ideas, thoughts, insights or suggestions on where else to look?
... View more
Can I have a 40 Gbps link with a QSFP-40G-LR4 on one end and a QSFP-40G-LR4-S on another? It is my understanding that the -S is less tolerant of humidity/temperature extremes than the standard QSFP.
... View more
New installation (and I'm new on the N9500s).......Attempting to do some failover testing before going into production. When I commanded a "system switchover" from active SUP to backup SUP, switchover occurred, but what was the primary SUP now shows "powered-up" and never reloaded completely. Manual "reload mod 27" has no affect. Vers 7.0(3) I3. Redundancy status shows it is configured. Is there something I'm missing?
Please see below, and thanks!
NFC9975MDFFCSSW21A# show boot auto-copy Auto-copy feature is enabled NFC9975MDFFCSSW21A# show mod Mod Ports Module-Type Model Status --- ----- ------------------------------------- --------------------- --------- 1 52 48x1/10G-T 4x40G Ethernet Module N9K-X9464TX2 ok 2 52 48x1/10G SFP+ 4x40G Ethernet Module N9K-X9464PX ok 3 52 48x1/10G SFP+ 4x40G Ethernet Module N9K-X9464PX ok 22 0 Fabric Module N9K-C9508-FM ok 23 0 Fabric Module N9K-C9508-FM ok 24 0 Fabric Module N9K-C9508-FM ok 26 0 Fabric Module N9K-C9508-FM ok 27 0 Supervisor Module powered-up 28 0 Supervisor Module N9K-SUP-B active * 29 0 System Controller N9K-SC-A active 30 0 System Controller N9K-SC-A standby
Mod Sw Hw Slot --- ---------------- ------ ---- 1 7.0(3)I3(1) 1.1 LC1 2 7.0(3)I3(1) 1.3 LC2 3 7.0(3)I3(1) 1.3 LC3 22 7.0(3)I3(1) 2.4 FM2 23 7.0(3)I3(1) 2.5 FM3 24 7.0(3)I3(1) 2.4 FM4 26 7.0(3)I3(1) 2.4 FM6 28 7.0(3)I3(1) 1.0 SUP2 29 7.0(3)I3(1) 1.5 SC1 30 7.0(3)I3(1) 1.5 SC2
Mod MAC-Address(es) Serial-Num --- -------------------------------------- ---------- 1 00-a6-ca-5c-89-e4 to 00-a6-ca-5c-8a-27 SAL2033UJBB 2 84-3d-c6-b0-aa-94 to 84-3d-c6-b0-aa-d7 SAL2031TY6H 3 84-3d-c6-af-c3-54 to 84-3d-c6-af-c3-97 SAL2030TMBB 22 NA SAL2023RHP1 23 NA SAL2028T66Z 24 NA SAL2021QPXL 26 NA SAL2021QPWL 28 e0-0e-da-36-89-b0 to e0-0e-da-36-89-c1 SAL2029TEUE 29 NA SAL2031UA5Z 30 NA SAL2031U61L
Mod Online Diag Status --- ------------------ 1 Pass 2 Pass 3 Pass 22 Pass 23 Pass 24 Pass 26 Pass 28 Pass 29 Pass 30 Pass
* this terminal session NFC9975MDFFCSSW21A# show redundancy status Redundancy mode --------------- administrative: HA operational: None
This supervisor (sup-28) ----------------------- Redundancy state: Active Supervisor state: Active Internal state: Active with HA standby
Other supervisor (sup-27) ------------------------ Redundancy state: Standby
Supervisor state: Unknown Internal state: Other
System start time: Mon Jan 30 23:16:22 2017
System uptime: 19 days, 3 hours, 41 minutes, 22 seconds Kernel uptime: 19 days, 3 hours, 54 minutes, 59 seconds Active supervisor uptime: 2 days, 19 hours, 36 minutes, 17 seconds NFC9975MDFFCSSW21A#
... View more
I have a new data center deployment consisting of Nexus 7710s and I’m trying to solidify my power requirements to Facilities. We will deploy power supply redundancy (N+1) along with power grid redundancy. I am trying to derive solid current/amperage requirement for Facilities.
The Cisco Power Calculator tool, under the “Power Consumption/Heat Dissipation Summary” indicates a “Total Output Power” of 4830 Watts. The term “Output Power” honestly confuses me, and I’m assuming this is the power consumed. In order to cover 4830 Watts, I’ll need qty (2) 3000 Watt Power Supplies to cover the 4830 Watts, which will give me 6000 Watts, plus 1 P.S. for N+1, which brings me to 3 power supplies. For Grid Redundancy, I’ll add 3 more.
These will connect to 240v A.C. 3-phase circuits. To derive circuit draw: Power/Voltage=Current;
4830 watts/240 volts = 19.5 amps drawn per Nexus. I am ordering qty (2) 60 Amp circuits on diverse substations/circuits for every two Nexus. Each Nexus will have 3 power supplies connected to A.C. circuit A and 3 power supplies connected to A.C. circuit B.
Under normal operating conditions, I’d assume each Nexus will draw ½ of its current from Ckt A and ½ of its current from Ckt B- which is approximately 10 Amps drawn from each Nexus on each circuit. A 30 Amp ckt would suffice; however, if Ckt/Source A is lost, then both nodes will draw 19.5 Amps EACH from the 30 Amp circuit (or try to) and the break will blow. THAT is why I’m requesting the qty (2) 60 Amp circuits per 2 nodes. (Please see attached diagram)
Does this reasoning sound correct?
Is “Total Output Power” the power consumed by the node? Really, I consider output power coming from the line source.
Does the Power Calculator assume 3-phase or does it even matter, as long as I never convert 3-phase to single phase with RMS calculations?
What does the “Total Output Current” mean on the calculator?
What percentage should I be at for typical run-rate vs. Ckt breaker for network gear? For a 60 Amp circuit, should I plan on never exceeding 50%, 70%, 80% or what % of that circuit rating?
Thanks for any help you can provide in answering any of these questions. Heck, thanks for even reading this long-winded question.
... View more
Yes, we have recently invested in PAN5060s which run 6.1(3) but I've been unsuccessful getting LACP to run either in active or passive mode. Supposedly the PANs require Cisco to be Passive (what I've read out there from someone). I'm running a Nexus5672 with 7.0(5)N1.....
Anyone out there have any luck?
... View more
Kanwai, So when the request comes into the VIP, the ACE would send a DNS query to a rack cluster IP address and the response to that query would end up being the real server that ACE forwards the initial request to. Sounds bizarre, I know, and I questions the performance of such, but that is the architecture I'm being asked to create. Thanks, Mike.
... View more
I have a special requirement for a serverfarm where the ACE would need to load-balance a server farm based upon a response from a DNS query to a delegated DNS server. This delegated DNS server is a "smart connect" node that decides which sub-node should be the active node in the serverfarm, and responds to the DNS query with that sub-node address. There are many application/node architectural reasons why the ACE simply can't be used for making that decision, so I won't muddy the waters with that. Essentially, the ACE would only have one node in it's serverfarm at one time, based upon the reponse from the Smart-Connect to the DNS query. Thanks for any input. Mike.
... View more
We have a new Prime Collaboration Manager 10.0 deployment, and have Polycom Immersive end-points (ISX3xx) which I'd like to manage via CM. I've successfully added several of Polycom's infrastructure components and they are "Managed", however, the Immersive end-points (codec 700 series) come up "Unsupported". Documentation states 3rd-party devices are supported, so I'm thinking I just need to provide the MIB from the Seriess 700 codecs (which I can download right from the device) and install into CM so it knows the SysObjectID. I cannot find anywhere in CM doc, as to how/where to install new MIBs. Can someone point me in the right direction? Thanks! Mike.
... View more