VSS configurations

We have 2 core switches 4500 series. I'm going to set up VSS configurations at the first time. When I get first order for the creation of domain, but not recognition of switches.

"sw1 (config) #switch virtual area 9.
^
Invalid entry % detected at ' ^' marker.

Hello

It seems that you are using IOS XE 3.6 with characteristics of lanbase. However, for the VSS, you must at least the services IP Base and/or company:

http://www.Cisco.com/c/en/us/TD/docs/switches/LAN/catalyst4500/release/n...

http://www.Cisco.com/c/en/us/TD/docs/switches/LAN/catalyst4500/release/n...

Thank you

Tags: Cisco Support

Similar Questions

  • VSS configuration on cisco 4507 R + E

    Hi all

    This is the first time I'll configure VSS, I learned some stuff online, but most of them was 6500 Series also I need expert advice that's why I post here.

    Right now I have 2 brand new Cisco 4507 R + E and planning set up VSS on it. The hardware details are below.

    NAME: 'switch system', DESCR: "" Cisco Systems, Inc. WS-switch 7 slot C4507R + E ".
    PID: WS-C4507R + E, VID: V09, SN: FXS1937Q0ZE

    NAME: "line card (slot 1) ', DESCR:"1000BaseX (SFP) with 24 Ports SFP Jumbo Frame Support.
    -Other - PID: WS - X 4724-SFP-E, VID: V01, SN: CAT1946L468

    NAME: 'supervisor (slot 3)', DESCR: ' Sup 8 - E 10GE (SFP +), 1000BaseX (SFP) with 8 Ports SFP + ".
    PID: WS - X 45-SUP8-E, VID: V05, SN: CAT1947L0PP

    NAME: 'TenGigabitEthernet3/1', DESCR: 'SFP-10Gbase-SR.
    PID: SFP - 10 G - SR, VID: V03, SN: FNS19450B6N

    • Please let me know the correct way to set up this series as vss
    • do I need an ideal config on the two switch (during a power failure, if the other switch does not work then I think than its necessity even config as the first) sorry maybe I'm confused by VSS and HSRP work...: p.
    • How to connect to any other device L3 connected to vs. With L3 port channel?

    To make these clear confusion for me, thank you.

    Luck shines on you.

    Sup8E means that you can activate Easily VSS.

  • Cisco 6500's inside the VSS Configuration. Port ID's channel

    Hello

    I have a pair of 6500's Setup with VSS and there is currently only one link between then. However, one end of the link is Po10 and the other end is on Po25.  If I move the Po10 Po25, things will break? It seems to work fine now. I am about to add a second link and I am concerned about the current configuration.  It makes more sense for me to have the two ends of the same binding on the same port channel ID.  I have seen documentation that States otherwise however.

    Interface Port-channel10

    No switchport

    no ip address

    pass the virtual link 1

    MLS qos trust cos

    no consistency mls qos channel

    !

    Interface Port-channel25

    No switchport

    no ip address

    pass the virtual link 2

    MLS qos trust cos

    no consistency mls qos channel

    DTC_6509s_VSS #sh run int Te1/5/4

    Building configuration...

    Current configuration: 116 bytes

    !

    interface TenGigabitEthernet1/5/4

    No switchport

    no ip address

    MLS qos trust cos

    channel-group 10 mode on

    end

    DTC_6509s_VSS #sh run int Te2/5/4

    Building configuration...

    Current configuration: 116 bytes

    !

    interface TenGigabitEthernet2/5/4

    No switchport

    no ip address

    MLS qos trust cos

    channel-group 25 mode on

    end

    DTC_6509s_VSS #.

    DTC_6509s_VSS #sh vslp lmp sum

    Example #1:

    Summary of the LMP

    Information about the link: configured: operational 1: 1

    Peer Peer Peer Peer timers running

    Interface Interface state flag MAC indicator switch (time remaining)

    --------------------------------------------------------------------------------

    4/5/TE1 VSFP VSFP operational 0026.0a26.84c0 2 Te2/5/4 T4 (24ms)

    T5 (s 59.95)

    DTC_6509s_VSS #sh switch port-channel virtual link

    Flags: - Low P - D bundled in port-channel

    I have - autonomous s - suspended

    H Eve (LACP only)

    R - Layer 3 S - Layer2

    U - N running - is not in service, no aggregation

    f cannot allocate an aggregator

    M not in use, no aggregation due to minimum links has not met

    m don't use, port do not associate due to not meeting minimum links

    u - unfit to tied selling

    d default port

    w waiting to be aggregated

    Protocol for the Port-Channel port group

    ------+-------------+-----------+-------------------

    10 Po10 (RU) - Te1/5/4 (P)

    25 Po25 (RU) - Te2/5/4 (P)

    Hello

    It doesn't make a difference if you do both sides with the same channel id or not. The ID of the port channel is a logical interface that does not impact on the etherchannel between them at all. So, you can leave one side Po10 and other like Po25 without problem. Just make sure you have at least one member of the Portchannel Active physical interfaces for not losing your connection to VSS.

    Kind regards

    Mohamed

  • The profiles breaks iSCSI host configuration

    I determined that host profiles do not support configuring vSS correctly to for iSCSI jumbo frame support.

    How the host profiles work when applied is that they will seduce all of the existing switches and then re - set their place, problem with the way in which it does this is that it supports all the features required. I.e. Jumbo frames.

    I can get my understanding confirmed (host profiles are not fully cooked) and ask the next question.

    Is it possible to tell a host profile to ignore elements like a vSS configuration? My review, it appears that once the host profile was created from a host of sample you can not say NOT to implement parts of it.

    Fix - now host profiles are not fully cooked.

    -Matt

    VCP, VCDX #52, Unix Geek, Nerd of storage

  • VSS migration to virtual Distributed Switch configuration

    Hi all

    I am trying to wrap my brain around that and just run into a few problems actually make things work. Please bear with me, I will try and describe the environment that I have and what I'm trying to building with like jargin little I can.

    My current vmware environment consists of 3 hosts vsphere 4.x and about 6 different subnets. My primary host vSphere is home to the largest part of the virtual machine and manages 5 different subnets connected to each of 5 virtual switches separated with 1 assigned to each NETWORK adapter. Also, there is a switch of kernel VM with a connection to my NetApp iSCSI. The other vSphere hosts are simple enough, the two are connected to subnet 1 with a virtual switch for it and a switch of kernel VM with a connection to the NetApp iSCSI.

    Each subnet in my lab is managed/break through the VLANS on Cisco devices, so I saw that it had to assign any settings VLAN since the power of VMware.

    If you refer to the VMWare vNetwork Distributed Switch: Migration and vmware Configuration guide, I am trying to migrate a seup similar to this:

    vmware_multiple_vds.JPG

    However, I'm running issues when you try to get the int hosts a vDS configuration. I could create a vDS for my root subnet, add one of my hosts vSPhere and migrate the virtual machine to the new port group in this vDS. The Service console as well as the VMKernel remain virtual switches on the host and I can't understand how these migrate to a vDS host without lose the connection.

    I'm asssuming based on the number of subnets that I manage between hosts, I'll finish with about a 5-switch vritualDistributed for subnets, each with at least 1 card a vSphere host physical NETWORK link up to the appropriate subnet. In addition to this, I'm assumining I'll need to create a vDS for the Service console and VMKernel (iSCIS) traffic. The Service Console are on the same subnet, some VM most residence on that subnet, separate VSS was created on the hosts to manage separate traffic.

    Any help anyone can provide on how to create vDS for SC/vmk traffic and get the associated host migrated to which would be very useful. As I said I was able to create 1 vDS and add a host computer via 1 uplink NIC with the virtual machine, but nothing beyond that seems bad connection.

    Feel you please free to ask for additional details, I know it's a lot and maybe a bit confusing. Thank you.

    -Bryan

    Hello

    If I'm correct, when the host is added the vDS and the creation of the vDS Service Console, I have to select an unused NIC and migrate the SC existing to the new group of port... or should I add a second SC for the VSS by using a NETWORK card available and who migrate to the new vDS?

    Yes, select an unused physical nic so that you have a physical nic connected to the VSS and the other to connect to the uplink of vDS group and migrate the SC. existing if you have several hosts, vMotion all VM and test to see if the migration without distruption, also works to keep details of the ILO ready incase you need to connect to the console of the server.

    This is a very good book white http://www.vmware.com/files/pdf/vsphere-vnetwork-ds-migration-configuration-wp.pdf that provides detailed information about the migration.

    All the best.

    Kind regards
    Arun

    If you have found this or other useful information, please consider awarding points to 'Correct' or 'useful '. Regards, Arun VCP3/4, HPCP, HP UX CSA http://kb.vmware.com/

  • Configure the link point to point switches VSS backup

    I have two basic switches in each office linking the two by point to point one desktop.

    Now I have the second point to point which I wan to serve as a backup.

    See fix main diagram point to point is set up in Vlan not as routed port...

    What is the best way to do this?

    If the two links are routed links then your config will work as his floating static so 20 advertising will be more preferred as its bottom, I would use sla monitoring and intellectual property to apply, so it is removed from the table right away and replaced with the backup route

  • Error message from DPM 2010 and an unexpected error has occurred on the DPM server during a VSS operation.

    Hello

    I have a server running on a Windows 2008 R2 server DPM 2010

    Currently save a mix of virtual and physical machines, these are a mix of Windows Server 2003 SP2, 2008 & 2008 R2.

    The DPM was previously a bit crumbly, but it was supposed to be caused by lack of disk space. A QNAP server was introduced and configured as an iSCSI target. After the initial problems, it works now.

    EXCEPT

    Three volumes of backup not. They were part of the protection group but they had no point of recovery at all. I deleted their protection groups and have tried to add them to their original groups. These 3 volumes all fail with the following error message:

    An unexpected error occurred on the DPM server machine during a VSS operation.

    Error details: VssError:Shadow copy the specified volume only is not supported. (0x8004230C)

    3 volumes are on 3 different servers.

    All 3 servers are running Windows 2003 SP2

    3 servers have other volumes that are save successfully and consistantly

    There are an additional 3 servers Windows 2003 SP2 that all volumes save successfully and consistantly.

    I can run shadow copies on these three volumes on servers

    All servers run the latest DPM Agents

    3 volumes have unused production capacities, Gig instead of Mb

    The pool of storage on the DPM server has two disks in the storage pool, the local disk has 10 TB of capacity and 45% free, the iSCSI target has capacity to 55 and 78% free.

    There are no. VSS errors in system or application logs (or I've noticed in just about any other log file) on the DPM server or the customer Server

    I have tried to add in the protection group, 3 volumes at once, one at a time or a small directory, or create a new protection group and still get the same errors.

    I ran the Windows updates on these servers

    So far all I can say the disk permissions look OK and match those of the other volumes of work.

    I know that having two drives in the storage pool is not ideal, and it will be changed but not up to what I have fixed the problems on the three volumes.

    Hello

    I suggest you to report this issue in support for Windows Server 2008 R2: http://technet.microsoft.com/en-us/windowsserver/bb512923

    Thank you.

  • Error message having to do with VSS/open files when you perform backups remotely

    When you back up by using services of Mozy for the last 2 weeks that some files could not be backed up.    Mozy did a few checks and they said it had to do with some files remain open.  They said it had to do with the Vss/open files, is there anyone out there who might be able to help?

    Hello
    • What version of Windows XP you are using?
    • What is you receive the exact error message?
    You can view these methods:
    Method 1:
    I suggest you try Windows back up and check.
    Here is the link:
     
    Method 2:
    You can also see the question in the boot.
    You need to perform a clean boot to find the program that is causing and then disable or remove.
    How to configure Windows XP to start in a "clean boot" State
    http://support.Microsoft.com/kb/310353/en-us
    Note: When you are finished troubleshooting, follow the steps as explained in the article to reset the computer to start as usual.
  • VSS 8194 ID event after installation of 4.6 STRUCK

    I've seen this with some customers separated now.  The error ID 8194 event appears on the Hyper-V with the installed HIT 2012 hosts. Has anyone seen this?

    The volume shadow copy Service error: error unexpected mark of the IVssWriterCallback interface. HR = 0 x 80070005 access is denied.
    . This is often caused by incorrect security settings in the process of the writer or the applicant.

    Operation:
    Data collection of Writer

    Context:
    Writer class ID: {e8132975-6f93-4464-a53e-1050253ae220}
    Author name: System Writer
    Writer Instance ID: {c4cafe6b-9e92-49e6-b95e-35b7cd4c0cac}

     

    The forum below intimates that existed previously and the achievement points.

    http://social.technet.Microsoft.com/forums/en-us/c66d3ab4-44D7-4a24-bb4b-9b20b3ed56d1/backup-of-HyperV-2012-CSV-intermittent-fails-with-error-0x80042301?Forum=dpmhypervbackup

     

    It seems a solution is to configure removing access to the network service account, it does really is to stop the call to VSS, so no access not denied error is reported. The double \ is the result of the export of registry and is required.

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl]
    "NT Authority\\NetworkService" = DWORD: 00000000

  • VSS volume control Config Wizzar error

    Hello

    I get an error when I validate the configuration of the VSS feature on my server with the DELL auto 4.5 Snapshot Manager

    Do you have an idea of the problem?

    Thank you very much for your help

    Error:

    Started at 22:01:57

    Waiting for the ASM on the hyper-rd12 host Agent service.
    Preparation 1 host (s) to save the setting changes
    Apply the settings
    Saving settings of PS Group on the "hyper-rd12 host access.

    An error has occurred:

    Error saving access to the PS grpadmin group: 1. specified group WKAddress is not accessible.

    The well-known group address is the IP address of the iSCSI Group.

    Thus, your group has an iSCSI IP address and then each port on the controller has an IP address (eth0, eth1, eth2, eth3 (depending on the model, you can have 1, 2 or 4 iSCSI ports (older models may also have 3 iSCSI ports)).)

    Always use IP iSCSI of the group in the connectivity section in ASM and not the IP address of one of the eth ports.

    If you have used this, disable all but 1 of your iSCSI network cards and try to ping the IP of the Group and all the IPs port. If you can not achieve one or more of them, you need to check your network because it would be a separate iSCSI configuration, which will not work with an Equallogic implementation.

  • Snapshots created with the EqualLogic VSS provider are not displayed in SAN HQ

    Hello

    Poster for the first time. We have just implemented an EqualLogic SAN, PS6100X network, and we're having performance issues between our DPM backup server, one of our hosts Hyper-V and VM images stored on the San. I will try to provide as much information as I can

    Environment:

    Dedicated iSCSI using Dell Force10 switches network

    hyper-V (Windows Server 2008 R2) 3 hosts
    -2 hosts has a NETWORK 4 port GB dedicated adapter connected to the iSCSI network; 1 host has connected to the network iSCSI NETWORK 2 GB dedicated ports card
    -Each Hyper-V host computer has a dedicated on the EQ SAN, RAID-50 volume that stores the Hyper-V virtual machines
    -EQ VSS provider installed on all hosts Hyper - V 3 and works correctly

    Using DPM 2010 for backup

    Problem: on Hyper-V hosts 1 and 2, any/all backup activities are very slow. On the Hyper-V host 3rd, however, activities related to backup all are incredibly fast! We compared the NIC configurations, HIT / settings ME and ASM, but we cannot understand why it is so slow on hosts 1 & 2.

    In addition, whenever DPM 2010 tells the EQ VSS provider to create a snapshot, we see the snapshot being created in the EQ Team Manager, but he does not appear in the list of iSCSI connections. According to the documentation SAN HQ, instant and volumes should appear here.

    We also disabled TcpAckFrequency for all 3 hyper-v hosts. It helped a little, but there is still a HUGE difference with regard to backups of the DPM.

    We're pretty sure that there is something misconfigured on the hosts Hyper - V 1 & 2, given that the host Hyper-V 3 has no performance issues.

    How can I get snapshots to appear in the list of iSCSI SAN HQ connections?

    Version information:
    SAN AC = 2.2.0.5924
    Storage Array Firmware = 5.2.4

    There are two different issues in this post for the SANHQ doesn't show only not iSCSI connections.

    Now SANHQ displays the correct total connection number but doesn't provide details of connections individual iSCSI for snapshots, which it should. So in the meantime use Workgroup Manager that shows the details for each snapshot (I know that's not the best answer, it's a short term solution).

    The fact the SANHQ shows details of instant connection does not mean that they aren't here and I can't imagine anything to do with the question of the DPM.

    The real difficulty, look for upcoming beta SANHQ and subscription for this on the EQL support site. You can do it now.

  • Windows 7: error 5 (access denied) when you try to start the Volume Shadow Copy (VSS) service

    System: Win 7 Ultimate x 64 on a HP Pavilion DV6. My account is the user account only suitable on the laptop and an administrator account.

    When you try to do a system restore, it came with an error that the Volume Shadow Copy Service did not work, even if this error code is not relevant for the purposes of this question later, I managed to run the system restore in SafeMode to an old restore point...

    When you try to turn on VSS, I checked services.msc (which I ran as administrator) and VSS was off and on the manual. I tried clicking on start, the following error message came:

    "Windows didn't start the Volume shadow copy on the Local computer service."
    Error 5: access is denied. »

    I then switched to automatic and tried again, same error. I tried since everything I can possibly think (including the definition of back and forth between manual & auto then trying the solutions below) to get the service starts, nothing helps. The solutions tried so far:

    -net start vss high cmd - returns the same error (error 5 access is denied)
    -high vssvc.exe cmd - same
    -changed the full control permissions for me, the group admin and NETWORK SERVICE (that I had to add) to the System32 folder and vssvc.exe but no change
    -changed the permissions to full control for myself, admin and NETWORK SERVICE group (who even once, I must add) for VSS in regedit (open as administrator) still nothing
    -even tried to restart explorer.exe a high cmd and a task manager high and again made the permissions - still nothing.

    The only thing I haven't done is run a sfc scan, but tbh, I doubt that will fix anything. It also seems that VSS has been turned off for a while, as my last restore point was about 3 months ago and I installed things since.

    Any suggestions/ideas would be appreciated, because I'm going nuts with that now! Thank you!

    The Volume Shadow Copy Service must not be on auto-start.

    According to the site TechNet Microsoft VSS THAT was introduced with Windows XP SP1 and since that time it has always installed as manual start since he does not need to be started automatically and it works day and night to do nothing.  Some places say different times when VSS has been introduced, but be sure that it was a long time ago.

    A popular site to see how Windows Services should / could be put in place is here:

    http://www.blackviper.com/service-configurations/

    If you've read about VSS on Microsoft TechNet, it says:

    https://TechNet.Microsoft.com/en-us/library/hh125927 (v = ws.10) .aspx

    So do you think the MS TechNet site is fake and that each installation of Windows since XP has a badly installed VSS Service?  If that were the case all Windows systems in the world would be in trouble.

    On an unafflicted system if you open the services applet and observe the VSS Service, it should look like this:

    So if you start a backup operation or even create a Restore Point, go back to the Service applet and press F5 to refresh you'll see that the VSS Service changed its status to start:

    Once the operation is complete the VSS Service will stop itself (it may take a while).

    That's how it is supposed to work.

    We should certainly be able to affect the automatic VSS Service and you should be able to start, but you shouldn't need to.  People who say that "solved their problem" forgets to mention the days/weeks to try things that lead to get their system of work.  There is no way of knowing which of the dozens of things that they could have tried really solved the problem.

    You say that the system restore worked in Mode safe (but not a normal startup) and if it is true that means usually something to load in a normal trunk causing a problem and that something is usually an antivirus/antimalware application that is 'protect' your system against the changes.  When you start mode safe these things are usually not loaded this is why sometimes your system restore mode without failure.

    Contributors known for these programs are Norton, McAfee, Avast, Avira, Kaspersky and probably others.

    So what antivirus/antimalware programs you are running and have checked their support pages for known problems with backup/restore system restore?

    Norton has even a page about these issues:

    https://support.Norton.com/SP/en/us/home/current/solutions/v51118464_EndUserProfile_en_us

    Even McAfee told their product to uninstall completely before doing a system restore:

    "Intel Security recommends that you remove McAfee security products before to proceed with an upgrade of the operating system or the Microsoft System Restore and then re-install your McAfee product when the update/restore is complete. "

    So I assumed that whatever your AV program happens to be could be part of the issue here - but we don't know what it is.

    We know error 5 is a permissions/access denied error type, but you shouldn't make adjustments to get VSS to start if something is wrong.  If as you have tried adjustments have been necessary every Windows system in the world should also make these adjustments and coming is not past.

    Of course, now, your system might be more affected since you've been changing permissions on the things trying to VSS to start when there is probably not a problem with VSS in the first place, so who knows what condition are in now.

    You could start by uninstalling what your AV software (most manufacturers have a special program for that) and by eliminating third-party applications that are known to interfere.  You can always reinstall them again later, no?

  • Error of VSS volume controls with SUCCESS / ME

    I finally had time to MPIO configuration for data NTFS on a Windows 2008 R2 vm to my EQ group, but I get an error 'VSS volume control is not accessible from this host'. I have the EQ, access policy VSS to IP to accept the whole subnet.  Notifications of EQUALIZER error includes "CHAP grpadmin authentication failed", but I'm only using the IP access, chapter not CHAP is optional, no? This is a subnet on the internal switches.  In addition, access to the Group PS, "Use Chap credentials for iscsi discovery" don't are not ticked.

    In the view of host MPIO, connections iscsi displays "2 ok, 2 bad." I only have 2 network cards on this virtual machine.

    Edit: Also, in the Group Access window, access to VDS/MVS has a green check mark.

    Hello

    Probably that's because there's a CHAP ACL on the vss-control volume.  When the remote installation wizard to configure the table he asks you to create a name of user and password c.  He uses the ACL on the default vss control volume.

    If you delete this ACL CHAP error will probably disappear.

    Kind regards

  • Map of policy port 6880 - error AAGR re configured L4OPs

    Hello

    I work with a QoS configuration for the 6880-X-THE with 6800Ia aircraft. Configuring QoS, policymap, classes, ACL etc. have all been accepted very well.

    I can apply a policy to an interface, but when I do I get the following errors come upward:

    * Oct 13 03:13:55.832: % EARL_CM-SW1-5-NOL4OP: configured L4OPs exceeds the programmable limit for AAGR = 0
    * Oct 13 03:13:55.828: % EARL_CM-SW2_STBY-5-NOL4OP: configured L4OPs exceeds the programmable limit for AAGR = 0
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 2 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 2 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 2 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 2 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 03:13:58.360 13 Oct: % QM-SW1-4-TCAM_ENTRY: input material AAGR programming failed to switch 2 slot 5 Gi141, 1, 0, 1 dir IN intf: error Req AAGR: FAIL (4): low AAGR entries (1)

    I checked the quota police QoS and they look OK. Is there anything else I should look at?

    NewLevel4Switch #sh platform hardware capacity qos
    QoS resources police
    Aggregate controllers: Sw/Mod used total% used
    1/5                        16384           16        1%
    2/5                        16384           16        1%
    Configurations of policeman MicroFlow: Sw/Mod used total% used
    1/5            128            1        1%
    2/5            128            1        1%
    Configurations of policeman NetFlow: Sw/Mod used total% used
    1/5            384            0        0%
    2/5            384            0        0%
    Aggregate configurations to police: Sw/Mod used total% used
    1/5 1024 8 1%
    2/5 1024 8 1%
    Distributed controllers: Total % used used (s)
    4096 1 1%
    Entries of QoS AAGR: Sw/Mod Total used % used
    1/5 16384 1171 7%
    2/5 16384 1171 7%

    Thank you

    David.

    Hi David,

    I've confirmed the problem that you see on your 6880 s is due to the limit of L4Op 9. I put your config in the laboratory and see the same thing:

    6800 - VSS (config) #int Duration1/5/1
    6800 - VSS(config-if) #service - political TAG-INCOMING-MARKING-AND-POLICE entry
    6800 - VSS(config-if) #end
    6800 VSS #.
    * 05:34:20.419 Oct 14: % SYS-SW2-5-CONFIG_I: configured from console by console
    * 14 Oct 05:34:19.567: % EARL_CM-SW1_STBY-5-NOL4OP: configured L4OPs exceeds the programmable limit for AAGR = 0
    * 05:34:22.115 Oct 14: % QM-SW2-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 intf Te1/5/1 dir IN: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 05:34:22.115 Oct 14: % QM-SW2-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 intf Te1/5/1 dir IN: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 05:34:22.115 Oct 14: % QM-SW2-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 intf Te1/5/1 dir IN: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 05:34:22.115 Oct 14: % QM-SW2-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 intf Te1/5/1 dir IN: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 05:34:22.115 Oct 14: % QM-SW2-4-TCAM_ENTRY: input material AAGR programming failed to switch 1 slot 5 intf Te1/5/1 dir IN: error Req AAGR: FAIL (4): low AAGR entries (1)
    * 14 Oct 05:34:22.115: % FMCORE-SW2-6-RACL_ENABLED: TenGigabitEthernet1/5/1 Interface routed traffic is material in the direction of penetration

    For example, I advanced and used only a subset of your policy-map (match around the class 6 cards, each card class corresponding to a DSCP value).

    6800 - VSS #$e entry acl interface Duration1/5/1 qos IP switch 1 module 5

    mls_if_index:8100000 dir:0 function: 1 proto:0

    pass the #0 characteristics

    FNO:0

    TCAM:A, Bank: 0, prot:0    ACEs

    0x0000E010005D100B ip any any eq dscp 46
    0x000100100131100B ip any any eq dscp 24
    0x000120100245100B ip any any eq 34 dscp
    0x0000E0100349100B ip any any eq 36 dscp
    0x00014010044D100B ip any any eq dscp 38
    0x000160100529100B ip any any eq 20 dscp
    0x000000000080D00B ip all all (3 matches)

    I can see the entries correctly installed in the AAGR. If you look at the current capmap table (the table capmap is what makes reference to the index of the register where are stored the your L4Ops), you would see 6 entries here:

    6800 - VSS #show platform software acl capmap AAGR a label switch 2 1 module 5
    Entry of Table of Capmap of shadow for AAGR

    -----------------------------------------------------------------------
    Output in a format CNT/INV/RST: RST - result value; INV - reversed;
    CNT - aggregated reference account;

    CBF - number of bits to free cap (one per entry);
    Free items are not displayed
    -----------------------------------------------------------------------

    Index   CBF       [9]              [8]              [7]              [6]              [5]              [4]              [3]              [2]              [1]              [0]
    ----- ----- ---------------- ---------------- ---------------- ---------------- ---------------- ---------------- ---------------- ---------------- ---------------- ----------------
    2-3-212 / 0 / 1 free free free 7/1/1 6/1/1 5/1/1-4/1/1 3/1/1 2/1/1

    Ignore the 212/0/1 at the beginning - that is reserved and is used to specify the meaning of the installed feature.

    We see here the limit as well - after 3 other entries with no expandable L4Ops, you're out of space.

    Please change your policy map so that you don't go beyond 9 no expandable L4Ops.

    I will work on discovering why the sup720s and the 32s behaved differently. Please give me some time.

    Kind regards

    Farre

  • Replacement Module supervisor in Cisco Catalyst 6500 VSS 1440

    Hello forum Cisco team!

    I am trying to replace a defective supervisor (Sup720 VS 10 G) on a pair of Catalyst 6509 VSS. I received the RMA and the document Replace Module, supervisor of the Cisco Catalyst 6500 Virtual Switching System 1440 (the document is attached) with the procedure. After going through the steps, I have a few questions during the installation of the new supervisor:

    1. do all links (including the VSL) must be connected before feeding the new supervisor? It comes from before that image and the boot config is copied to the new supervisor.

    2. once the startup config and the image is copied from the active VSS switch in the new supervisor, the document said to check orders for priority switch in the copied startup config form the active VSS, but the priority of each switch is not stored in the startup configuration as far as I know. Can you please clarify this?

    My goal is to add the new supervisor engine without disrupting the current active VSS switch.

    Thank you in advanced for your support!

    Hey,.

    With regard to your questions:

    1. do all links (including the VSL) must be connected before feeding the new supervisor? It comes from before that image and the boot config is copied to the new supervisor. - Yes

    2. once the startup config and the image is copied from the active VSS switch in the new supervisor, the document said to check orders for priority switch in the copied startup config form the active VSS, but the priority of each switch is not stored in the startup configuration as far as I know. Can you please clarify this? - Once you convert the switch for VSS priorities will be stored in the startup configuration file. Please visit the following link:

    http://www.Cisco.com/c/en/us/TD/docs/switches/LAN/catalyst6500/IOS/12-2Sx/configuration/guide/book/VSS.html#wp1111770

    However, it is no longer recommended and therefore should be avoided. I suggest you not setting is not the priority.

    HTH.

    Kind regards

    RS.

Maybe you are looking for