SGE2000 stacking and routing

Greetings, people!

The question is:

Is it possible to overlay two or more SGE2000 sw in operation of layer 3 (so that they act as a single router...)?

I've never done with but yes. Put the two units in mode layer 3, then the battery.

Kind regards

Christopher

Tags: Cisco Support

Similar Questions

  • Conflict between Toshiba Bluetooth Stack and drawers of power on Tecra M5

    There seems to be a bug in TosBtShell.dll and hope this alert could get fixed in a future revision. Possibly it will save others the effort that it has cost me to track down the problem on my Tecra M5 new. I had to give up Toshiba Bluetooth Stack and now using XP SP2.

    When the Bluetooth Manager is running, TosBtShell.dll updates the element ' Bluetooth' beside ' send to ' in the context menu of files and folders. Unfortunately it is in conflict with the shell software improvement Power drawers http://www.dynamickarma.com/powerdrawers.htm that I defer to speed up access to my files on the computer. This software allows you to right click on a folder to view its contents in a list. Then you mouse to any folder in the list and give him also as a sublist - and so forth as deeply as you want until you reach the folder or file you want. Right click on an item in the waterfall and you get a list of useful options. However, if the Bluetooth Manager is running when you do the right click, power drawers breaks down and you must close and re-open explorer.exe to recover.

    The conflict stops if you remove "to Bluetooth" in the context menu of files and folders. I proved this by using ShellExView from Nirsoft http://www.nirsoft.net/utils/shexview.html to disable the registry key "Bluetooth File extension" [sic]. This key is associated with the C:\WINDOWS\system32\TosBtShell.dll and the CLSID {6BEF3D0B-53F0-4b0d-B91C-C19ED3D4C9D1}. Unfortunately the registry key back again every time that you restart the Bluetooth Manager.

    David Tong.

    Hello

    Thanks for the information.
    However, on the Toshiba Bluetooth page you can always notice whether or not the new version of the driver BT is available.
    http://APS.toshiba-tro.de/Bluetooth/

    I recommend you to visit this site regularly

  • Wireless connection unavailable on laptop, but shows all ok on pc and router

    I was at Midway through a conversation today on msn when my wireless connection (on my laptop) disappeared. I checked my pc and everything seems ok, here, my netgear router shows that everything is fine. When I click on 'Find a wireless network' his party! I can access the net very well by plugging it but as soon as I go wireless, I still lost.

    Tried to connect manually - says network with that name already there
    Tried to re start all
    All cables checked

    It's a laptop Toshiba L300
    Virgin cable broadband
    Router NETGEAR Wireless

    everything works fine as long as I'm using the cables.

    I only had my laptop and router wireless for a month.

    Please any other ideas what to do, I really need to be wireless for work as soon as possible

    Hello severina_falls,

    Thanks for posting on the Microsoft answers Community Forum.

    I have some suggestions for you to see if we can provide you with your wireless connection.

    (1) check that the WiFi switch is on on the front panel of your laptop. It is a quick check
    (2) Recycle the router wireless on and outside. Wait at least one minute, then turn it back on. Retest with your wireless network.
    (3) are getting you the error messages in the case where connects to deal with your wireless connection?
    To join the event logs: click on the Start button, right-click computer, click on manage.
    If you receive a notification of user account control , simply click on continue.
    Double-click Event Viewer. Study summary of the the event logs for errors dealing with wireless.
    (4) use System Restore to get your iIf wireless upward and running, you have a System Restore Point that was before starting the problem with your wireless network.
    Use the following KB to get the procedure on the system restore.
    936212 KB - how to repair the operating system and how to restore the configuration of the operating system to an earlier point in time in Windows Vista
    http://support.Microsoft.com/kb/936212

    If please post again and let us know if it helped to solve your problem or if you need further assistance.

    Sincerely, Marilyn
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Stacking and trunking

    Hello

    I have a question regarding trunking in combination with the stacked switches. In my example, I have two switches that are stacked and stacked switch. I placed all the sales employees in VLAN 10 (put first in the stack) and the management VLAN 20 (second switch in the stack) on switches employees stacked. The servers are on 30 VLAN on the switch stacked.

    I need to assign trunkports between two switches stacked in order to allow the stacked switches communicate?

    Thanks in advance!

    The ports that are used for the stacking shouldn't be junction ports.  They are only dedicated for stacking, and once the two (or more) switches are stacked together, they become a single logical switch.  Think about your carpet as a simple switch.  You only need ports of connectors for the connection between the battery and the only stacked switch.

    I hope this helps.

    B

  • SG500X - stacking and 10GbE Uplink together

    Hi guys,.

    I use a SG500x in native mode of stacking, using 10g ports S1/S2.

    My question is, in this mode am I could simultaneously use 10 GB uplinks/XG1 XG2 ports? The manual is not clear at all!

    If I can both stack and uplink at the same time can someone also let me know if I get the full 40 GB of bandwidth?

    Finally I need a SPF 10 GbE module so I can run cat6 from the ports of X 1 / X 2 for 10 GbE on my cluster but network cards can work on which we're compatible!

    Sorry lots of questions!

    Thank you guys

    Hi Sam, you can use the ports of the battery and the other 2 10 gig. S1/S2 are the default stack ports. The S3/S4 would be considered ports network at this time here, but can be toggled to use S3/S4 instead of S1/S2.

    The ability of the switch is 128 Gbps on the model of port 24 th, 176 Gbps on the 48-Port models. So, if you say a 48 switch ports.  1 = 48 x 48. 10 x 4 = 40. 40 plus 48 is 88.  88 x 2 = 176.

    You should get the result you want (if you can actually use the link 10 gig to capacity, many Internet tele-conferences are not yet used to full 10 gig).

    For the SFP capatibility, you can reference the Administrator's guide. It has all the modules support. Once you choose your module support you should talk to your provider of NETWORK card with one should work with your cluster.

    -Tom
    Please mark replied messages useful

  • Site to Site between ASA VPN connection and router 2800

    I'm trying to get a L2L VPN working between a ASA code 8.4 and a 2800 on 12.4.

    I first saw the following errors in the debug logs on the side of the ASA:

    Error message % PIX | ASA-6-713219: KEY-GAIN message queues to deal with when
    ITS P1 is complete.

    I see the following on the end of 2800:

    ISAKMP: (0): treatment charge useful vendor id
    ISAKMP: (0): provider ID seems the unit/DPD but major incompatibility of 157
    ISAKMP: (0): provider ID is NAT - T v3
    ISAKMP: (0): treatment charge useful vendor id
    ISAKMP: (0): provider ID seems the unit/DPD but major incompatibility of 69
    ISAKMP (0): provider ID is NAT - T RFC 3947
    ISAKMP: (0): treatment charge useful vendor id
    ISAKMP: (0): treatment of frag vendor id IKE payload
    ISAKMP: (0): IKE Fragmentation support not enabled
    ISAKMP: (0): entry = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
    ISAKMP: (0): former State = new State IKE_R_MM1 = IKE_R_MM1

    ISAKMP: (0): built NAT - T of the seller-rfc3947 ID
    ISAKMP: (0): send package to x.x.x.x my_port 500 peer_po0 (R) MM_SA_SETUP
    ISAKMP: (0): sending a packet IPv4 IKE.
    ISAKMP: (0): entry = IKE_MESG_INTERNAL, IKE_PROCESS_COMPLETE
    ISAKMP: (0): former State = new State IKE_R_MM1 = IKE_R_MM2

    ISAKMP (0): packet received from x.x.x.x dport 500 sports global (R)

    MM_SA_SETUP
    ISAKMP: (0): entry = IKE_MESG_FROM_PEER, IKE_MM_EXCH
    ISAKMP: (0): former State = new State IKE_R_MM2 = IKE_R_MM3

    ISAKMP: (0): processing KE payload. Message ID = 0
    ISAKMP: (0): processing NONCE payload. Message ID = 0
    ISAKMP: (0): found peer pre-shared key x.x.x.x corresponding
    ISAKMP: (2345): treatment charge useful vendor id
    ISAKMP: (2345): provider ID is the unit
    ISAKMP: (2345): treatment charge useful vendor id
    ISAKMP: (2345): provider ID seems the unit/DPD but major incompatibility of 54
    ISAKMP: (2345): provider ID is XAUTH
    ISAKMP: (2345): treatment charge useful vendor id
    ISAKMP: (2345): addressing another box of IOS!
    ISAKMP: (2345): treatment charge useful vendor id
    ISAKMP: (2345): vendor ID seems the unit/DPD but hash mismatch
    ISAKMP: receives the payload type 20
    ISAKMP (2345): sound not hash no match - this node outside NAT
    ISAKMP: receives the payload type 20
    ISAKMP (2345): no NAT found for oneself or peer
    ISAKMP: (2345): entry = IKE_MESG_INTERNAL, IKE_PROCESS_MAIN_MODE
    ISAKMP: (2345): former State = new State IKE_R_MM3 = IKE_R_MM3

    ISAKMP: (2345): sending package x.x.x.x my_port Exchange 500 500 (R)

    MM_KEY_EXCH

    ----------

    This is part of the configuration of the ASA:

    network of the ABCD object
    10.20.30.0 subnet 255.255.255.0
     
    network of the ABCD-Net object
    172.16.10.0 subnet 255.255.255.0
     
    cry-map-77-ip object-group XXXX object abc-site_Network allowed extended access list
     
    access list abc-site extended permitted ip object-group XXXX object abc-site_Network
     
    ip access list of abc-site allowed extended object abc-site_Network object-group XXXX-60
     
    NAT (any, any) static source 20 XXXX XXXX-20 destination static abc-site_Network abc-site_Network
     
    NAT (any, any) static source 20 XXXX XXXX-20 destination static abc-site_Network abc-site_Network
     
    XXXX-20
     
    object-group network XXXX-20
    ABCD-Net network object
    object-abcd-Int-Net Group
     
    XXXX_127
     
    object-group network XXXX-20
    ABCD-Net network object
    object-abcd-Int-Net Group
     
    ip access list of abc-site allowed extended object abc-site_Network object-group XXXX-60
     
     
    Crypto card off-map-44 11 match address cry-map-77
    card crypto out-map-44 11 counterpart set 62.73.52.xxx
    card crypto out-map-44 11 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA MD5-ESP-3DES ESP-DES-SHA ESP-DES-MD5

    cry-map-77-ip object-group XXXX object abc-site_Network allowed extended access list

    Crypto card off-map-44 11 match address cry-map-77
    card crypto out-map-44 11 counterpart set 62.73.52.xxx
    card crypto out-map-44 11 set ikev1 transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA MD5-ESP-3DES ESP-DES-SHA ESP-DES-MD5

    card crypto out-map-44 11 set transform-set ESP-3DES-SHA ikev1

    object-group network XXXX
    ABCD-Net network object
    object-abcd-Int-Net Group

    ------------------------

    Here is a part of the 2800:

    !
    crypto ISAKMP policy 1
    BA 3des
    preshared authentication
    Group 2
    ISAKMP crypto key r2374923 address 72.15.21.xxx
    !
    !
    Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac
    !
    card crypto cry-map-1 1 ipsec-isakmp
    the value of 72.15.21.xxx peer
    game of transformation-ESP-3DES-SHA
    match address VPN
    !
    type of class-card inspect match class-map-vpn
    game group-access 100
    type of class-card inspect cm-inspect-1 correspondence
    group-access name inside-out game
    type of class-card inspect correspondence cm-inspect-2
    match the name of group-access outside
    !
    !
    type of policy-card inspect policy-map-inspect
    class type inspect cm-inspect-1
    inspect
    class class by default
    drop
     
    type of policy-card inspect policy-map-inspect-2
    class type inspect class-map-vpn
    inspect
    class type inspect cm-inspect-2
    class class by default
    drop
    !

    !
    interface FastEthernet0
    IP address 74.25.89.xxx 255.255.255.252
    NAT outside IP
    IP virtual-reassembly
    security of the outside Member area
    automatic duplex
    automatic speed
    crypto cry-card-1 card
    !
    interface FastEthernet1
    no ip address
    Shutdown
    automatic duplex
    automatic speed
    !
    IP nat inside source overload map route route-map-1 interface FastEthernet0
    !
    IP access-list extended inside-out
    IP 172.16.10.0 allow 0.0.0.255 any
    IP nat - acl extended access list
    deny ip 192.168.0.0 0.0.255.255 172.16.10.0 0.0.0.255
    deny ip 10.200.0.0 0.0.255.255 172.16.10.0 0.0.0.255
    deny ip 192.168.0.0 0.0.255.255 172.16.10.0 0.0.0.255
    deny ip 0.0.255.255 28.20.14.xxx.0.0 172.16.10.0 0.0.0.255
    refuse the 10.10.10.0 ip 0.0.0.255 172.16.10.0 0.0.0.255
    refuse the 172.16.10.0 ip 0.0.0.255 192.168.0.0 0.0.255.255
    refuse the 172.16.10.0 ip 0.0.0.255 10.200.0.0 0.0.255.255
    refuse the 172.16.10.0 ip 0.0.0.255 192.168.0.0 0.0.255.255
    refuse the 172.16.10.0 ip 0.0.0.255 28.20.14.xxx.0.0 0.0.255.255
    refuse the 172.16.10.0 ip 0.0.0.255 10.10.10.0 0.0.0.255
    allow an ip
    outside extended IP access list
    allow an ip
    list of IP - VPN access scope
    IP 172.16.10.0 allow 0.0.0.255 192.168.0.0 0.0.255.255
    IP 172.16.10.0 allow 0.0.0.255 10.200.0.0 0.0.255.255
    IP 172.16.10.0 allow 0.0.0.255 192.168.0.0 0.0.255.255
    IP 172.16.10.0 allow 0.0.0.255 28.20.14.xxx.0.0 0.0.255.255
    IP 172.16.10.0 allow 0.0.0.255 10.10.10.0 0.0.0.255
    IP 192.168.0.0 allow 0.0.255.255 172.16.10.0 0.0.0.255
    IP 10.200.0.0 allow 0.0.255.255 172.16.10.0 0.0.0.255
    IP 192.168.0.0 allow 0.0.255.255 172.16.10.0 0.0.0.255
    28.20.14.xxx.0.0 0.0.255.255 ip permit 172.16.10.0 0.0.0.255
    ip licensing 10.10.10.0 0.0.0.255 172.16.10.0 0.0.0.255

    access-list 23 allow 192.168.0.0 0.0.255.255
    access-list 23 allow 10.200.0.0 0.0.255.255
    access-list 23 allow 172.16.10.0 0.0.0.255
    access-list 123 note category class-map-LCA-4 = 0
    access-list 123 allow ip 192.168.0.0 0.0.255.255 172.16.10.0 0.0.0.255
    access-list 123 allow ip 10.200.0.0 0.0.255.255 172.16.10.0 0.0.0.255
    access-list 123 allow ip 192.168.0.0 0.0.255.255 172.16.10.0 0.0.0.255
    access-list 123 allow ip 0.0.255.255 28.20.14.xxx.0.0 172.16.10.0 0.0.0.255
    access-list 123 allow ip 10.10.10.0 0.0.0.255 172.16.10.0 0.0.0.255
    access-list 123 allow ip 172.16.10.0 0.0.0.255 192.168.0.0 0.0.255.255
    access-list 123 allow ip 172.16.10.0 0.0.0.255 10.200.0.0 0.0.255.255
    access-list 123 allow ip 172.16.10.0 0.0.0.255 192.168.0.0 0.0.255.255
    access-list 123 allow ip 172.16.10.0 0.0.0.255 28.20.14.xxx.0.0 0.0.255.255
    access-list 123 allow ip 172.16.10.0 0.0.0.255 10.10.10.0 0.0.0.255
    !
    !
    !

    !
    route-map-1 allowed route map 1
    match the IP nat - acl
    !

    Hello

    I quickly browsed your config and I could notice is

    your game of transformation (iskamp) on SAA and router are not the same, try to configure the same on both sides.

    in the statement of the ASA NAT you gave (any, any) try to give the name of the interface instead of a whole.

  • LAN to lan vpn between ASA and router 7200

    Hi friends,

    I need to configure the lan to lan between ASA vpn (remote location) and router 7200 (on our network).

    <7200 router="" (ip="" add:="" 10.10.5.2)="">-(Internet) -<(IP add:="" 192.168.12.2)="" asa(5510)="">---192.135.5.0/24 network

    I will have the following configuration:

    7200 router:

    crypto ISAKMP policy 80

    the enc

    AUTH pre-shared

    Group 1

    life 3600

    ISAKMP crypto key cisco123 address 192.168.12.2

    Cryto ipsec transform-set esp - esp-md5-hmac VPNtrans

    map VPNTunnel 80 ipsec-isakmp crypto

    defined by peer 192.168.12.2

    game of transformation-VPNtrans

    match address 110

    int fa0/0

    IP add 10.10.5.2 255.255.255.192

    IP virtual-reassembly

    no ip route cache

    Speed 100

    full duplex

    card crypto VPNTunnel

    access-list 110 permit ip any 192.135.5.0 0.0.0.255

    ASA:

    int e0/0

    nameif inside

    security-level 100

    192.135.5.254 Add IP 255.255.255.0

    int e0/1

    nameif outside

    security-level 0

    IP add 192.168.12.2 255.255.255.240

    access-list ACL extended ip 192.135.5.0 allow 255.255.255.0 any

    Route outside 0.0.0.0 0.0.0.0.0 192.168.12.3 1

    "pre-shared key auth" ISAKMP policy 10

    ISAKMP policy 10-enc

    ISAKMP policy 10 md5 hash

    10 1 ISAKMP policy group

    ISAKMP duration strategy of life 10-3600

    Crypto ipsec transform-set esp - esp-md5-hmac VPNtran

    card crypto VPN 10 matches the ACL address

    card crypto VPN 10 set peer 10.10.5.2

    card crypto VPN 10 the transform-set VPNtran value

    tunnel-group 10.10.5.2 type ipsec-l2l

    IPSec-attributes of type tunnel-group 10.10.5.2

    cisco123 pre-shared key

    card crypto VPN outside interface

    ISAKMP allows outside

    dhcpd address 192.135.5.1 - 192.135.5.250 inside

    dhcpd dns 172.15.4.5 172.15.4.6

    dhcpd wins 172.15.76.5 172.15.74.5

    dhcpd lease 14400

    dhcpd ping_timeout 500

    dhcpd allow inside

    Please check the configuration, please correct me if I missed something. I'm in a critical situation at the moment...

    Please advise...

    Thank you very much...

    Where it fails at the present time?

    Can you share out of after trying to establish the VPN tunnel:

    See the isa scream his

    See the ipsec scream his

    Please also run the following debug to see where it is a failure:

    debugging cry isa

    debugging ipsec cry

  • Private of IPSec VPN-private network between ASA and router

    Hello community,

    This is first time for me to configure IPSec VPN between ASA and router. I have an ASA 5540 at Headquarters and 877 router to EH Branch

    Headquarters ASA summary.

    Peer IP: 111.111.111.111

    Local network: 10.0.0.0

    Branch

    Peer IP: 123.123.123.123

    LAN: 192.168.1.0/24

    Please can someone help me set up the vpn.

    Hello

    This guide covers exactly what you need:

    Establishment of ASDM and SDM - http://www.netcraftsmen.net/resources/archived-articles/273.html

    Tunnel VPN - ASA to the router configuration:

    http://www.Cisco.com/en/us/products/ps5855/products_configuration_example09186a0080a9a7a3.shtml#ASDM

    Kind regards

    Jimmy

  • Issue of ASA NAT and routing

    Hello

    I have a question about NAT and routing on the SAA. I'm relatively new to ASA and don't know if it works or not. I have a pool of public IP (209.x.x.x/28) that routes my ISP to the external interface of my ASA. IP was assigned address for the outside of the ASA is an address of 206.x.x.2/24 with a default GW of 206.x.x.1. I intend using NAT to allow my web/mail servers on the DMZ (192.168.x.x) use 209.x.x.x addresses. However, I do know how to make it work since I'm not arping on any interface for 209.x.x.x addresses as they will be sent to the 206.x.x.2 address by the ISP. Can I just set up a translation NAT (on the external interface?) of the 209.x.x.x on 192.168.x.x address and the ASA will figure it out?

    Thanks for the help.

    Todd

    The ASa will figure it out, he will answer ARP queries for all that he has set up in a "static" command As long as th PSIA routes 209.x.x.x directly to the ASA addresses then it should all work fine.

    You just need to add lines like the following:

    static (dmz, external) 209.x.x.x netmask 255.255.255.255 192.168.x.x

    for each of your internal servers in the DMZ. Then an access-list to allow only HTTP/SMTP/etc through these addresses 209.x.x.x.

    list of allowed inbound tcp access any host 209.x.x.x eq smtp

    list of allowed inbound tcp access any host 209.y.y.y eq http

    Access-group interface incoming outside

  • Client certificate and router WebVPN

    Hello!

    In my test harness I can not to run my webvpn configuration =.

    I have several components: AD MS, MS CS (but without NDE), 2911 router and client computer. Client and router have a certificate of MS CS. In my setup I use certificate or aaa (LDAP) authentication and authentication work aaa good. But the client certificate authentication does not work. And my internal https services do not work too--"no certificate or invalid", but this strange because I imported the CA certificate for that.

    Can you help me it work?

    My version of 2911:

    Cisco IOS software, software C2900 (C2900-UNIVERSALK9-M), Version 15.1 (3) T, RELEASE SOFTWARE (fc1)

    My Config:

    AAA authentication login webvpn group local ldap

    IP local pool webvpn 192.168.200.1 192.168.200.254

    bind authenticates root-dn cn = webvpn, OU = team, dc = domain, dc = com password [email protected]/ * /.

    WebVPN vpn gateway

    IP address port 4443

    SSL root-ca trustpoint

    development

    !

    WebVPN install svc flash0:/webvpn/anyconnect-dart-win-2.5.3055-k9.pkg sequence 1

    !

    employee framework WebVPN

    SSL authentication check all

    !

    connection message 'Portal VPN'

    !

    the policy group peche1

    List of URLS "on the inside".

    functions compatible svc

    filter VPN SPLIT tunnel

    SVC-pool of addresses "webvpn" netmask 255.255.255.0

    SVC by default-domain "domain.com".

    SVC Dungeon-client-installed

    SVC split dns "domain.com".

    SVC split include 192.168.0.0 255.255.0.0

    SVC-Server primary dns 192.168.1.1

    SVC-Server secondary dns 192.168.1.2

    Citrix enabled

    virtual-model 1

    strategy-group-by default peche1

    AAA authentication list webvpn

    vpn gateway

    authentication certificate

    user name - sign up

    root CA trustpoint-AC

    User location flash0 profile: / userprof

    development

    !

    Crypto pki trustpoint root-ca

    Terminal registration

    revocation checking no

    rsakeypair root-ca

    !

    I imported with CA pkcs12 certificate.

    My debug (it happened so I am trying to access my webvpn portal and I choose my certificate of MS CS for access)

    5 Jun 11:22:39: WV: validated_tp: cert_username: matched_ctx:

    5 Jun 11:22:39: WV: could not get opssl appinfo sslvpn

    5 Jun 11:22:39: WV: could not get opssl appinfo sslvpn

    5 Jun 11:22:39: WV: error: no certificate validated for the customer

    Can someone explain to me why it does not work?

    Resolved by the update IOS - version 15.2 (4) M2.

    Concerning

  • The fields 'Name' and 'Domain' to 'DNS and routing configuration/host Identification' are always in gray

    In VI3, I used to change the settings of the host DNS (host and domain name) to the tab 'DNS and routing' - & gt; "Identification of home." Even more, if the DNS and DHCP are configured correctly in the environment, there is no need to set these values manually - they were discovered automatically. The story is defferent in vSphere 4. I still have the set of fields 'Name' by 'localhost' and 'Domain' field is empty. And I can't change them - they are grey.

    Seems that the host is still able to discover its hostname automatically. I see the proper name in the (left pane of vSphere Client) console tree. But these values are not met the 'DNS and routing' tab and I can't put them manually.

    This is normal and how do I use these fields now?

    Yes, you're right. It's a little strange, but it works this way in vSphere now.

    ---

    VMware vExpert 2009

    http://blog.vadmin.ru

  • 3750 X stack and question wccp ACNS Content Engine (CE)

    Hello

    I work with 3 3750Xs in a 'carrot' and we have a directly connected content engine (CE) on a WAE-612 CNSE ce612 - filtering 5.5.23.2 running web services. We use the wccp with forwarding L2 and L2 return with assignment of MASK.

    The this is located in the vlan 1013 and is directly connected to the 3750Xs of base via po5.  Users are in vlan 72 a stack of 3750Xs in a closet of access that is connected to the base through PO4.  64 VLANS plugs on the perimeter (to the Internet) firewall.

    When only one member of PO4 is physically connected web filtering works, however the web filtering does not work when several members are connected in PO4 and end-users are not filtered.  It seems the 3750Xs kernel redirect not the traffic to THIS more at this time.

    Anyone have any ideas why adding members to the port channel seems to break the wccp functionality.  Would it be due to the "Battery cross" of the channel port?

    Here are some details of the 3750 basic configuration s

    *************************************************************************************************************************************

    #show CORE-3750Xs version

    ...

    c3750e-universalk9 - mz.122 - 58.SE1.bin

    *************************************************************************************************************************************

    CORE-3750Xs #show license

    1 function of the index: ipservices

    ...

    *************************************************************************************************************************************

    CORE-3750Xs #show run int vlan 1013
    interface Vlan1013
    WAE-Smartfilter description
    IP 10.144.1.193 255.255.255.192
    no ip proxy-arp
    *************************************************************************************************************************************

    CORE-3750Xs #show run int vlan 72
    interface Vlan72
    Description STDNT_wired_a114
    IP 10.144.72.1 255.255.255.0
    IP helper 10.144.6.2
    no ip proxy-arp
    property intellectual cache wccp web redirection in
    IP pim sparse - dense mode
    *************************************************************************************************************************************

    #show run int vlan 64 CORE-3750Xs
    interface Vlan64
    IP 10.144.64.1 255.255.255.0
    IP helper 10.144.6.2
    no ip proxy-arp
    IP pim sparse - dense mode
    *************************************************************************************************************************************

    CORE-3750Xs #show run int po4
    Interface Port-Channel 4
    Description * Port channel of closet 114a *.
    switchport trunk encapsulation dot1q
    switchport trunk allowed vlan 2,3,9-12,20,40,41,72,100,608,614,1423,1620
    switchport trunk allowed vlan add 3001-3003
    switchport mode trunk
    switchport nonegotiate
    disable the protocols spanning-tree bpdufilter
    disable the protocols spanning-tree bpduguard

    *************************************************************************************************************************************

    CORE-3750Xs #show etherchannel 4 sum
    Flags: - Low P - D bundled in port-channel
    I have - autonomous s - suspended
    H Eve (LACP only)
    R - Layer 3 S - Layer2
    U - running f - cannot allocate an aggregator

    M - don't use, minimum contacts not satisfied
    u - unfit to tied selling
    w waiting to be aggregated
    d default port

    Number of channels in use: 5
    Number of aggregators: 5

    Protocol for the Port-Channel port group
    ------+-------------+-----------+-----------------------------------------------
    4 (SU) Po4 - Gi1/0/20 (P) Gi1/0/21 (P) Gi1/0/22 (P)
    Gi2/0/20 (P) Gi2/0/21 (P) Gi2/0/22 (P)
    Gi3/0/21 (P) Gi3/0/22 (P)

    *************************************************************************************************************************************

    #show run int po5 CORE-3750Xs
    Interface Port-channel5
    Description * Port engine content channel *.
    switchport access vlan 1013
    switchport mode access
    *************************************************************************************************************************************

    CORE-3750Xs #show etherchannel 5 sum
    Flags: - Low P - D bundled in port-channel
    I have - autonomous s - suspended
    H Eve (LACP only)
    R - Layer 3 S - Layer2
    U - running f - cannot allocate an aggregator

    M - don't use, minimum contacts not satisfied
    u - unfit to tied selling
    w waiting to be aggregated
    d default port

    Number of channels in use: 5
    Number of aggregators: 5

    Protocol for the Port-Channel port group
    ------+-------------+-----------+-----------------------------------------------
    Po5 (SU) 5 - Gi1/0/5 (P) Gi2/0/5 (P)

    *************************************************************************************************************************************

    CORE-3750Xs #show ip web cache wccp
    The WCCP customer information:
    WCCP Client ID: 10.144.1.194
    Protocol Version: 2.0
    Status: usable
    Redirect: L2
    Package return: L2
    Directed packets: 0
    Connection time: 10:15:38
    Assignment: MASK

    Mask port DstAddr SrcPort DstPort
    ----  -------    -------    ------- -------
    0000: 0x00000000 0 x 00001741 0x0000 0x0000

    Value port DstAddr SrcPort DstPort CE - IP
    ----- -------    -------    ------- ------- -----
    0000: 0x00000000 0x00000000 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0001: 0x00000000 0x00000001 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0002: 0x00000000 0 x 00000040 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0003: 0 x 00000000 00000041 0 x 0 x 0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0004: 0x00000000 0x00000100 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0005: 0x00000000 0 x 00000101 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0006: 0x00000000 0 x 00000140 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0007: 0x00000000 0 x 00000141 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0008: 0x00000000 0 x 00000200 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0009: 0x00000000 0 x 00000201 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0010: 0x00000000 0 x 00000240 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0011: 0x00000000 0 x 00000241 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0012: 0x00000000 0 x 00000300 0000 0 x 0 x 0000 0x0A9001C2 (10.144.1.194)
    0013: 0x00000000 0 x 00000301 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0014: 0 x 00000000 00000340 x 0 0 x 0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0015: 0x00000000 0 x 00000341 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0016: 0x00000000 0 x 00000400 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0017: 0x00000000 0 x 00000401 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0018: 0x00000000 0 x 00000440 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0019: 0x00000000 0 x 00000441 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0020: 0x00000000 0 x 00000500 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0021: 0x00000000 0 x 00000501 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0022: 0x00000000 0 x 00000540 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0023: 0x00000000 0 x 00000541 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0024: 0x00000000 0 x 00000600 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0025: 0x00000000 0 x 00000601 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0026: 0x00000000 0 x 00000640 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0027: 0x00000000 0 x 00000641 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0028: 0x00000000 0 x 00000700 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0029: 0x00000000 0 x 00000701 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0030: 0x00000000 0 x 00000740 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0031: 0x00000000 0 x 00000741 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0032: 0x00000000 0 x 00001000 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0033: 0x00000000 0 00001001 x 0 x 0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0034: 0x00000000 0 x 00001040 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0035: 0x00000000 0 x 00001041 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0036: 0x00000000 0x00001100 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0037: 0x00000000 0 x 00001101 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0038: 0x00000000 0 x 00001140 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0039: 0x00000000 0 x 00001141 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0040: 0x00000000 0 x 00001200 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0041: 0x00000000 0 x 00001201 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0042: 0x00000000 0 x 00001240 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0043: 0x00000000 0 x 00001241 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0044: 0x00000000 0 x 00001300 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0045: 0x00000000 0 x 00001301 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0046: 0x00000000 0 x 00001340 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0047: 0x00000000 0 x 00001341 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0048: 0x00000000 0 x 00001400 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0049: 0x00000000 0 x 00001401 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0050: 0x00000000 0 x 00001440 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0051: 0x00000000 0 x 00001441 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0052: 0x00000000 0 x 00001500 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0053: 0x00000000 0 x 00001501 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0054: 0x00000000 0 x 00001540 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0055: 0x00000000 0 x 00001541 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0056: 0x00000000 0 x 00001600 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0057: 0x00000000 0 x 00001601 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0058: 0x00000000 0 x 00001640 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0059: 0x00000000 0 x 00001641 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0060: 0x00000000 0 x 00001700 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0061: 0x00000000 0 x 00001701 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0062: 0x00000000 0 x 00001740 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)
    0063: 0x00000000 0 x 00001741 0x0000 0 x 0000 0x0A9001C2 (10.144.1.194)

    *************************************************************************************************************************************

    CORE-3750Xs #show ip wccp web cache
    Global information WCCP:
    Router information:
    Router identifier: 10.144.75.1
    Protocol Version: 2.0

    Identify service: web cache
    Number of Clients of Service Group: 1
    Number of routers in Service Group: 1
    S/w redirected packets total: 0
    Process:                                     0
    CEF:                                          0
    Redirect the access-list: - none -.
    Redirect denied packets total: 0
    Packages not assigned total: 0
    Group access list: - none -.
    Total Messages refused for the Group: 0
    Total authentication failures: 0
    Total GRE bypassed packets received: 0

    Check the license on stack x 3750.  Master suspect IP services, other members have only basic IP.

  • How to uninstall TOSHIBA Bluetooth Stack and all the drivers?

    Hello! I installed TOSHIBA Bluetooth Stack of [here | http://aps2.toshiba-tro.de/bluetooth/?page=download] or, more precisely of the [here | http://aps2.toshiba-tro.de/bluetooth/?page=download-toshiba] (8.00.12 |) Windows 2000 / XP / Vista / Windows 7 x 32 | Multilanguage) (_I have windows xp_). I tried to connect my phone with it, but it didn't work the way I expected.

    As I did not, I tried to uninstall, but I had problems there too. :( I was able to uninstall it from the Control Panel / Add-Remove programs and I also uninstalled in Device Manager, but it does not work too.

    It is more drivers, and they are all on my system: in my departure much I option 'connect too', in the Panel, I "Bluetooth Local COM" and Bluetooth devices Manager also lights up while windows starts... I had to remove all those things, but I don't know how? Help, please!

    Also, if someone could explain to me how to transfer data through your Toshibas Bluetooth, that would be nice too - in this case I would not uninstall it. Only in this case when it seems useless to me, these drivers are only bothers me. They spread throughout the system as someone wanted to hurt me! xD

    Thank you once again, people! :)

    * EDIT *: I now have to stop bluetooth manager executed departure while windows starts, so now it's less a problem. I don't particularly want some unnecessary processes slow down my computer. On the other hand, there is a problem that I have not mentioned - the computer restarts it self without reason in some cases. However, it seems that these reboots are associated with uninstalling programs - especially during attempts to uninstall toshiba bluetooth stack. Anyway I'll examine this reboot problem a bit more tomorrow perhaps it relates only to install/uninstall these drivers toshibas.

    Post edited by: samir89ns
    the reason for the change: I forgot to say certain things

    I use laptops Toshiba and Toshiba BT for years and I've never had no problem to connect my mobile phone using the BT software. I use it mainly to transfer data (photo made by mobile phone).
    It is so easy to make the connection between the computer laptop and phone so I n t understand why you have all these problems.

    If you n t need it disable Autostart BT software.

    You have for Toshiba laptop?

  • ORBI replace DSL Modem and router Nighthawk?

    I have a Nighthawk AC1900 R7000 router and a Netgear DM111PSPv2 Modem and I was wondering if the system ORBI would replace both of them and give me greater coverage. Anyone?

    Thanks for the reply. Think I'll stick to what I have.

  • WNR3500L model after a power cut my modem and router stopped working.

    I tried to unplug and leave for 30 minutes and plugged back but nothing has worked. Does anyone know what I need to do?

    What are the symptoms that you get from the router? In the case the modem and the router something might have gotten fried. I would try different adapters on both hoping that power adapters are those who got fried. If you still have the same results its probably time to get the router and the new modem. Let us know what happens.

Maybe you are looking for