Thanks for the feedback but I am still confused. In multiple examples I found for class-maps they show the dscp bit being set as my previous example. If I do set the dscp bit on the ingress traffic to AF41 how will the AF42 queue ever get hit? I did some testing in the lab and if have do a set dscp Af41 and I do the command show platform hardware fed switch 1 qos dscp-cos counters interface gig 1/9/0/38 The egress AF41 only counter increments Egress DSCP34 224794 0 Egress DSCP35 0 0 Egress DSCP36 251788 0 Egress DSCP37 0 0 Egress DSCP38 114839 0 Egress DSCP34 231530 0 Egress DSCP35 0 0 Egress DSCP36 251788 0 Egress DSCP37 0 0 Egress DSCP38 114839 0 If I take out the set dscp af41 marking then the rest of the dscp 34,36 and 38 counters all increment Egress DSCP34 348909 0 Egress DSCP35 0 0 Egress DSCP36 253336 0 Egress DSCP37 0 0 Egress DSCP38 115397 0 Egress DSCP34 349469 0 Egress DSCP35 0 0 Egress DSCP36 254784 0 Egress DSCP37 0 0 Egress DSCP38 115857 0 Lets take for example I have a video camera on a port I trust (by default 3850 trusts all markings). The camera is sending dscp AF42. In my post above this would get set to dscp 41. If I want to be able to match dscp 41 and 41 (Multimedia Traffic) I would assume I would need to do the following class-map MULTIMEDIA-CONFERENCING-AF41 set dscp af41 class-map MULTIMEDIA-CONFERENCING-AF42 match dscp af42 Then my policy-map class MULTIMEDIA-CONFERENCING-MARK-AF41 set dscp af41 class MULTIMEDIA-CONFERENCING-MARK-AF42 set dscp af42 Thanks for helping
... View more
I am following the cisco validated design for the 3850 switch and have a question on the Classification and Queuing. They have the following example for queueing in their example Policy-map Marker class MULTIMEDIA-CONFERENCING set dscp af41 They don't show the class-maps but I found on another website the following class-map class-map MULTIMEDIA-CONFERENCING match dscp af41 match dscp af42 match dscp af43 My question if I attach this policy to an interface it will take all AF41, AF42 and AF43 and set it to AF41. I did this in the lab and did a capture and I confirmed that any af42 or af43 would be remarked to af41. How will AF42 ever hit the output queueing policy if any traffic coming in is automatically set to AF41 before going out the interface with the queueing policy applied? class-map match-all MULTIMEDIA-CONFERENCING-QUEUE MATCH DSCP AF41 AF42 AF43 class MULTIMEDIA-CONFERENCING-QUEUE queue-limit dscp af43 percent 80 queue-limit dscp af42 percent 90 queue-limit dscp af41 percent 100
... View more
I am looking at configuring QOS on a Catalyst 9500 which will be our core switch. I am following the Cisco Catalst 9000 Series QoS Design which I have also attached. In the document it seems to say that if you are trusting the DSCP markings you need to just employ Queuing. In the design guide they have a policy-map NBAR-MARKING that classifies the traffic coming into the switch int gig 0/0 service-policy input NBAR-MARKING They then have another policy-map 2P6Q3T-WRED that does the queuing. int gig 0/0 service-policy output 2P6Q3T-WRED My question is if I am trusting all DSCP Markings coming into the switch do I still need to have a service-policy input NBAR-MARKING on my interfaces which classifies the incoming traffic? int ten 0/1 service-policy input NBAR-MARKING service-policy output 2P6Q3T-WRED or just configure queueing only int ten0/1 service-policy output 2P6Q3T-WRED
... View more
We have a 5548UP and am having problems with some new FET 10G we just got.
I get the error message N5548-A %ETHPORT-3-IF_UNSUPPORTED_TRANSCEIVER: Transc eiver on interface Ethernet1/7 is not supported
when I do a show int transceiver it looks ok
Ethernet1/7 transceiver is present type is Fabric Extender Transceiver name is CISCO-LUMENTUM part number is PLRXPL-VC-S43-CG revision is C serial number is JUR2049B1VW nominal bitrate is 10300 MBit/sec Link length supported for 50/125um OM3 fiber is 100 m Link length supported for 62.5/125um fiber is 10 m cisco id is -- cisco extended id number is 4
We have other FET 10Gs that work but they seem to be a different model
Ethernet1/5 transceiver is present type is Fabric Extender Transceiver name is CISCO-FINISAR part number is FTLX8570D3BCL-C1 revision is A serial number is FNS15401XH4 nominal bitrate is 10300 MBit/sec Link length supported for 50/125um OM3 fiber is 100 m Link length supported for 62.5/125um fiber is 10 m cisco id is -- cisco extended id number is 4
Any idea why the newer FET 10Gs are not working
interface Ethernet1/7 description Uplink to Nexus2248-2/1 switchport mode fex-fabric switchport trunk allowed vlan 10,20,30,60,1402-1404,1420 fex associate 102 duplex full channel-group 102
interface port-channel102 description Uplink to Nexus2248-102 switchport mode fex-fabric switchport trunk allowed vlan 10,20,30,60,1402-1404,1420 fex associate 102 duplex full vpc 102
... View more
I am testing out mac bypass and I am running into a problem with Cisco IP phones not authenticating during boot up. If I plug my pc into the port on the phone my PC shows up in my authentication server and passes authentication just fine. If I unplug the phone and just plug my laptop into the port it also triggers the mac bypass authentication so the radius server is working fine, it is something on the config on the switch.
For what ever reason the phone never triggers an MAB event.
This is the way the port is configured. This is on a 3850 switch and I have tried updating the firmware to see if it was a problem with the firmware.
interface GigabitEthernet1/0/35 description CISCO-PHONE switchport access vlan 458 switchport mode access switchport voice vlan 456 switchport port-security maximum 2 switchport port-security violation restrict switchport port-security aging time 2 switchport port-security aging type inactivity switchport port-security authentication host-mode multi-host authentication port-control auto mab spanning-tree portfast
Anybody know what is going on and causing the phone not to trigger an MAB event?
... View more