Why the ACS is blocking my connection to the Console?

I have aaa to my SWs one routers, but wen my server goes down that I can't have access to the console port.

My config is attached and debug aaa authorization.

These are debugs it for each access: Telnet user, consoling Ganymede user Ganymede and testing of Pentecost the local user.

Telnet access

Oct 15 01:03:09: AAA: analyze name = tty2 BID type =-1 ATS = - 1

Oct 15 01:03:09: AAA: name = tty2 flags = 0 x 11 type = 5 shelf = 0 = 0 = 0 = channel 2 = 0 port adapter slot

Oct 15 01:03:09: AAA/MEMORY: create_user (0x2778E84) user = ruser 'NULL' = 'NULL' ds0 = 0 port = 'tty2' rem_addr'10.10.10.23 = 'authen_type = ASCII service = CONNECTION priv = 1 initial_task_id = ' 0', vrf = (id = 0)

Oct 15 01:03:10: CDP-4-NATIVE_VLAN_MISMATCH %: incompatibility of VLAN native on GigabitEthernet0/37 (102), was discovered with tst1-s2 GigabitEthernet0/1 (1).

Oct 15 01:03:11: AAA/MEMORY: free_user (0x28E1BFC) user = ruser 'ACS-USER' = 'NULL' port = 'tty2' rem_addr = '10.10.10.23' authen_type = ENABLE priv = 15 = ASCII service

Oct 15 01:03:13: AAA/MEMORY: free_user (0x2778E84) user = ruser 'ACS-USER' = 'NULL' port = 'tty2' rem_addr = '10.10.10.23' authen_type = ASCII = priv = 1 CONNECTION service

Access to consoles (work of Pentecost the ACS user)

Oct 15 01:08:57: AAA: analyze name = tty0 BID type =-1 ATS = - 1

Oct 15 01:08:57: AAA: name = tty0 flags = 0 x 11 type = 4 shelf = 0 = 0 = 0 = 0 = 0 channel port adapter slot

Oct 15 01:08:57: AAA/MEMORY: create_user (0x28AA8E4) user = ruser 'NULL' = 'NULL' ds0 = 0 port = "tty0" rem_addr = "async" authen_type = service ASCII = CONNECTION priv = 1 initial_task_id = '0', vrf = (id = 0)

Oct 15 01:09:11: AAA/MEMORY: free_user (0x27C0DC4) = user tweak "ACS-USER" = "NULL" port = "tty0" rem_addr = "async" authen_type = ASCII service = ENABLE priv = 15

Oct 15 01:09:18: AAA/MEMORY: free_user (0x28AA8E4) = user tweak "ACS-USER" = "NULL" port = "tty0" rem_addr = "async" authen_type = ASCII = priv = 1 CONNECTION service

Access console (not working whit the local user)

Oct 15 01:05:24: AAA: analyze name = tty0 BID type =-1 ATS = - 1

Oct 15 01:05:24: AAA: name = tty0 flags = 0 x 11 type = 4 shelf = 0 = 0 = 0 = 0 = 0 channel port adapter slot

Oct 15 01:05:24: AAA/MEMORY: create_user (0x27C1310) user = ruser 'NULL' = 'NULL' ds0 = 0 port = "tty0" rem_addr = "async" authen_type = service ASCII = CONNECTION priv = 1 initial_task_id = '0', vrf = (id = 0)

Oct 15 01:05:36: AAA/MEMORY: free_user_quiet (0x27C1310) = user tweak "LOCAL_USER" = "NULL" port = "tty0" rem_addr = "async" authen_type = 1 = 1 = 1 private service

Oct 15 01:05:36: AAA: analyze name = tty0 BID type =-1 ATS = - 1

Oct 15 01:05:36: AAA: name = tty0 flags = 0 x 11 type = 4 shelf = 0 = 0 = 0 = 0 = 0 channel port adapter slot

Oct 15 01:05:36: AAA/MEMORY: create_user (0x28D201C) user = ruser 'NULL' = 'NULL' ds0 = 0 port = "tty0" rem_addr = "async" authen_type = service ASCII = CONNECTION priv = 1 initial_task_id = '0', vrf = (id = 0)

Oct 15 01:06:09: AAA/MEMORY: free_user_quiet (0x28D201C) = user tweak "NULL" = "NULL" port = "tty0" rem_addr = "async" authen_type = 1 = 1 = 1 private service

Oct 15 01:06:09: AAA: analyze name = tty0 BID type =-1 ATS = - 1

Oct 15 01:06:09: AAA: name = tty0 flags = 0 x 11 type = 4 shelf = 0 = 0 = 0 = 0 = 0 channel port adapter slot

Oct 15 01:06:09: AAA/MEMORY: create_user (0 x 2773004) = user tweak 'NULL' = 'NULL' ds0 = 0 port = "tty0" rem_addr = "async" authen_type = service ASCII = CONNECTION priv = 1 initial_task_id = '0', vrf = (id = 0)

Oct 15 01:06:41: AAA/MEMORY: free_user (0 x 2773004) = user tweak "NULL" = "NULL" port = "tty0" rem_addr = "async" authen_type = ASCII = priv = 1 CONNECTION service

Thanks for your help.

Change your orders

AAA of default login authentication group Ganymede + activate

the AAA authentication enable default group Ganymede +.

TO

AAA authentication login default group Ganymede + local

the AAA authentication enable default group Ganymede + activate

Kind regards

Prem

Please if it helps!

Tags: Cisco Security

Similar Questions

  • Why keep internet exployer blocks all websites that I realize the dose?

    Why the dose to come internet exployer Dungeon say they have blocked this site?

    Hello

    1 is connected to the domain of the computer?

    2. what version of Internet Explorer?

    3. you get any error message?

    4 have had any changes made to the computer before the show?

    Please follow the methods.

    Method 1:

    Follow the steps from the link

    (a) open Internet Explorer.

    (b) click on 'tools '.

    (c) click on 'Internet Options '.

    (d) click on 'security '.

    (e) click 'Sensitive Sites' icon and then click the button 'Sites '.

    (f) click on the name of the site you want to not blocked over the list of sensitive sites. Click 'delete '. Click 'OK' to save your changes and crashes Internet Explorer is no longer this specific site.

    Method 2:

    Optimize Internet Explorer and check.

    NOTE: The Reset Internet Explorer Settings feature might reset security settings or privacy settings that you have added to the list of Trusted Sites. Reset the Internet Explorer settings can also reset parental control settings. We recommend that you note these sites before you use the reset Internet Explorer settings

    See the link.

    How to optimize Internet Explorer

    http://support.Microsoft.com/kb/936213/ro

  • Why the last OS update cost me gigabytes of data when you are connected directly to my computer and ISP via Itunes February 29, 2016

    Why the last OS update cost me gigabytes of data when you are connected directly to my computer and ISP via Itunes.  29 February 2016

    While it is connected to ITunes via my Dell system, I was informed of the latest OS update for my IPhone 6.  I decided that the direct connection to the internet would be the fastest way to download and install the software.  During the process I started to have some warning of our AT & T account that I approach the limit of our data plan, then in quick succession, only warnings, said I've reached the limit and then passed in the data, limit charges.  At the time it was done, I had accumulated more than 2 gigabytes of additional data charges.

    Until that point, I was very pleased with the device and confident in the ability to use Wifi and data.  Due to this incident, I became very suspicious of the camera and the huge potential for data overcharges. It is extremely disconcerting as it happened while it is directly connected to the internet using my computer at home.

    Please note that, in the episode my ISP and the computer is remained connected to the WEB with no sign of connectivity issues.

    Someone at - he had a similar experience and understand what went wrong?

    Thanks for your support,

    Jerry

    JerrolK wrote:

    Why the last OS update cost me gigabytes of data when you are connected directly to my computer and ISP via Itunes.  29 February 2016

    While it is connected to ITunes via my Dell system, I was informed of the latest OS update for my IPhone 6.  I decided that the direct connection to the internet would be the fastest way to download and install the software.

    You have chosen the option of direct download, you have received a message of warning from AT & T about it yet.

    He did what you asked it to do.

  • I have a PCI-6221 NIC connected to a block of connection TBX-68. How can I see the wiring for the analog channels with MAX?

    Hi all

    I have a PCI-6221 NIC connected to a block of connection TBX-68. Once I found a drawing that shows me all the connections on my block of connection for each analog input tasks. I don't see this option now. Can someone describe to me how I can find this new?


  • Why my PC will cut Internet connection whenever I try to open a PDF file and how do I corret the problem?

    Why my PC cuts her Internet connection whenever I try to open a PDF file and how can I fix the problem?  Even if I still have my cell phone internet access will not open a PDF document online.

    Hello

    ·        What operating system is installed on your computer?

    ·        What browser do you use to access the Internet?

    ·        It happens with PDF files or file as well?

    I suggest that you follow the instructions in the link and check if this can help:

    Cannot view PDF on the web

    http://kb2.Adobe.com/CPS/328/328233.html

    Respond with the required information so that we can help you further.

  • 120W:how RV to block of connected device to intern in the name of the device?

    Hi guys,.

    I use the router, rv 120w

    can I block device connected to the internet through device name?

    for example, the phone Android wil always has "android" in their name of the unit. How can I block the device which has "android" in their device name of connection to the internet?

    Thank you.

    Hello

    Please use our forum

    Hi Louis, my name is Johnnatan and I'm part of the community of support to small businesses. Can´t you block any device by name, but you can block devices using mac address. Go firewall > access control > Mac filtering in this section, you can specify the mac address of devices and block them.

    I hope you find this answer useful,

    "* Please mark the issue as response or write it down so others can benefit from.

    Greetings,

    Johnnatan Rodriguez Miranda.

    Support of Cisco network engineer.

  • Why the interconnections of fabric can be connected to the two MDS?

    Hi all

    1. why the white paper below says that if FI is connected to two MDS, then it will create a single point of failure?

    http://www.Cisco.com/c/en/us/products/collateral/storage-networking/MDS-9500-series-multilayer-directors/white_paper_c11_586100.html

    This image below is used to describe the scenario for question 2 to 4.

    2 and why the SAN design best practices to create SAN A and SAN B? Where when the switch 1 has failed, then it will use the b in SAN. And in this case, user can configure to connect to the storage using SAN B first, instead of using SAN first? And by default, the behavior of the SAN like that, what I mean is that she will check SAN failed, then it will use SAN B?

    3. and why there is no connection between the left more server and switch 2? They can not who design when switch 1 has failed, then it will use the other link first to switch 2, by linking the left more server for 2? Then when the core SAN switch one down, he uses the SAN B connection.

    4. can you the server to different SAN multipath? In this case, SAN A and B.

    Thank you

    Osbin

    Hi Osbin,

    Why the white paper below says that if FI is connected to two MDS, then it will create a single point of failure?

    Protocol FC build tissue, using the FSPF (such as OSPF) of the Protocol in order to MDS, FI (switch mode) Nexus 5 k, 7 k (storage VDC) form a single fabric using the links intercommutation.

    If a problem is occur in tissue alone device's problem (zoning, FSPF, EENT)

    If you connect fabric and fabric B (connect a FI for switch 1 and switch 2) in other words, this is no fabric A and B - it became a unique fabric (fabric single = single point of failure). That's why we use two FI, connected to two independent fabrics (isolation and redundancy)

    Technically, you can avoid this problem by using VSANS, but if some problem in a NX - OS or SAN - OS occure you may lose the two fabrics in a single failure (the worst of the world SAN)

    2 and why the SAN design best practices to create SAN A and SAN B? Where when the switch 1 has failed, then it will use the b in SAN. And in this case, user can configure to connect to the storage using SAN B first, instead of using SAN first? And by default, the behavior of the SAN like that, what I mean is that she will check SAN failed, then it will use SAN B?

    Point main initiator is in the answer above, can use both at the same time (multipath) fabrics with special drivers.

    It is configurable by the user to use any fabric (A and B - is just for engineers) first.

    It depends on the OS and drivers.

    3. and why there is no connection between the left more server and switch 2?

    I believe that this picture is schematic diagram and imagine if you have enough ports in the switch 1

    They can not who design when switch 1 has failed, then it will use the other link first to switch 2, by linking the left more server for 2?

    Remember the idea of FC fabric. If you spend 1 it will affect every single switch fabric, and it is much faster to use stable fabric B instead of A fabric converging.

    Then when the core SAN switch one down, he uses the SAN B connection.

    4. can you the server to different SAN multipath? In this case, SAN A and B.

    Yes

    Best regards

    Alex

  • Why LR CC continually trying to connect to the servers of amazon?

    The message continues to appear in the console and monopolizes the CPU usage. I have the connection of course blocked until further notice. Please advice!

    Thanks in advance.

    14/05/15 15:47:58, 928 adobe Lightroom [9091]: tcp_connection_destination_prepare_complete failed 114 connectx to 54.218.33.111:443@0: host is down

    14/05/15 15:47:58, 929 adobe Lightroom [9091]: tcp_connection_destination_prepare_complete failed 114 connectx to 54.218.70.38:443@0: host is down

    14/05/15 15:48:26, 599 adobe Lightroom [9091]: failure of tcp_connection_destination_prepare_complete 116 connectx to 54.191.168.197:443@0: host is down

    14/05/15 15:48:26, 600 adobe Lightroom [9091]: failure of tcp_connection_destination_prepare_complete 116 connectx to 54.213.115.21:443@0: host is down

    14/05/15 15:48:26, 600 adobe Lightroom [9091]: failure of tcp_connection_destination_prepare_complete 116 connectx to 54.213.151.218:443@0: host is down

    14/05/15 15:48:26, 600 adobe Lightroom [9091]: failure of tcp_connection_destination_prepare_complete 116 connectx to 54.187.27.31:443@0: host is down

    14/05/15 15:48:26, 600 adobe Lightroom [9091]: failure of tcp_connection_destination_prepare_complete 116 connectx to 54.201.87.107:443@0: host is down

    14/05/15 15:48:26, 600 adobe Lightroom [9091]: failure of tcp_connection_destination_prepare_complete 116 connectx to 54.200.173.188:443@0: host is down

    14/05/15 15:48:26, 600 adobe Lightroom [9091]: failure of tcp_connection_destination_prepare_complete 116 connectx to 54.218.33.111:443@0: host is down

    14/05/15 15:48:26, 601 adobe Lightroom [9091]: failure of tcp_connection_destination_prepare_complete 116 connectx to 54.218.70.38:443@0: host is down

    14/05/15 15:48:29, 215 adobe Lightroom [9091]: tcp_connection_destination_prepare_complete failed 118 connectx to 54.191.168.197:443@0: host is down

    14/05/15 15:48:29, adobe Lightroom 216 [9091]: tcp_connection_destination_prepare_complete failed 118 connectx to 54.213.115.21:443@0: host is down

    14/05/15 15:48:29, adobe Lightroom 216 [9091]: tcp_connection_destination_prepare_complete failed 118 connectx to 54.213.151.218:443@0: host is down

    14/05/15 15:48:29, adobe Lightroom 216 [9091]: tcp_connection_destination_prepare_complete failed 118 connectx to 54.187.27.31:443@0: host is down

    14/05/15 15:48:29, 217 adobe Lightroom [9091]: tcp_connection_destination_prepare_complete failed 118 connectx to 54.201.87.107:443@0: host is down

    14/05/15 15:48:29, 217 adobe Lightroom [9091]: tcp_connection_destination_prepare_complete failed 118 connectx to 54.200.173.188:443@0: host is down

    14/05/15 15:48:29, 217 adobe Lightroom [9091]: tcp_connection_destination_prepare_complete failed 118 connectx to 54.218.33.111:443@0: host is down

    14/05/15 15:48:29, 217 adobe Lightroom [9091]: tcp_connection_destination_prepare_complete failed 118 connectx to 54.218.70.38:443@0: host is down

    See if this document helps you:

    http://wwwimages.Adobe.com/content/dam/Adobe/en/DevNet/creativesuite/PDFs/Security_CCE_FAQ _20130424.pdf

  • Why the block size is multiple of 2?

    Hi all

    Sorry if I am at the base, I question why the Oracle block size is a multiple of 2?

    Rgds,
    Lherault

    Oracle is a software written to run on binary computers. Everything is built in the end between the lines, Word and double word boundries.

    Early block IO sizes have been built on the collections of sectors of 512 bytes then you end up with 1024, 2048, 4096, 8192 blocks IO sizes. Corresponding to the Oracle block size to the size of the OS IO seems logical.

    It has been possible to set Oracle block size to be 5K and 10K. I do not recommend it, but I've seen on older versions of Oracle. I don't know if technically you can always do.

    HTH - Mark D Powell.

  • Why the hell I see adds anywhere in the browser, even if I have my ad running block? and why the hell every time I put the default home page, this isn't?

    Hello

    Why the hell it adds every where now? It was not the case before? and why the hell every time I change the home page to be the default, the min that I restart Firefox, it came again on the same silly page I don't know where the hell it came from?

    It was a very pleasant experience to use Firefox, but no more, I still love him his heavy on the machine and stuck a lot lately!

    incident reports NEVER managed to send that I don't know why!

    Come on guys, you can do better than that!

    Hi ajag,.
    Sorry, you have problems, but probably some adware or malware.

    Thank you for including the information system. I'm not familiar with "Vonteera free ads" However, he is apparently adware. Pay attention to the advice, followed by research on the internet I would be, for example, do NOT try the YAC website or tool.

    Using the Firefox addons Manager and Panel configuration remove toolbars unwanted obvious or programs. Then fully analyze up to tools date and multiple.

    Please follow the tips in the link above immediately and then do full scans as shown below in this post.
    I notice that you have a user.js file require separately.
    Post back saying that you tried and what the results were.

    You can try these free programs to search for malicious software that work with your existing anti-virus software:

    Microsoft Security Essentials is a good permanent antivirus for Windows 7/Vista/XP, if you do not already have one. Windows 8 already has integrated antivirus.

    More information can be found in the article troubleshooting Firefox problems caused by malware .

  • Why the administrator is the only one who can connect to VMware server 2.0.1 GUI?

    I am facing this problem and have been unable to find a solution for this.

    I need to segment users who manages our servers VMware 2.0.1 in ProductionAdmins, DemoServerAdmins, DevAdmins etc etc. VMware server runs on Windows Server 2003 member of a domain (for example, the AD authentication).

    My main problem is that only users who are allowed to log on by using the graphical interface are those who are members of the local Administrators group - and by substituting so completely the VMware Server permission settings. I get a "you do not have the permissions to connect to the server" for all users, except the members of the group mentioned.

    In the VMware Server documentation, I can read that users and groups are managed by the host OS (AD), but is obviously not "the complete truth. I tried to add a user (domain or local user also) to the local 'users', '__vmware__', 'Power Users', etc., etc. no change

    What prevents the user to log on to the server. I even tried to add the user to "Remote desktop users" - which works very well (with the exception of the connection to the console that requires membership of the admin).

    I don't understand. What's wrong???

    Bjoern Dirchsen

    IT Manager

    Kapow Technologies

    Have you used the Administration-> manage roles (WebUI)?

    You set up the authorization for VMS (WebUI)?

    I work in the field and I can set up permission for domain members (not only Local Administrators or domain administrators).

    J.

    If you have found this device or any other answer useful please consider the use of buttons useful or Correct to award points.

  • Block outbound connections

    Hello, I want to know how to block outbound connections on my macbook 12 using MacOs Sierra.

    In the firewall, I have found that I can block incomming connections.

    I missed an option?

    How can I do Terminal form?

    You can edit the hosts file by using Terminal Server, although I wouldn't recommend it if you don't know what you're doing. But in doing so you can block outbound access to specified IP addresses or websites.

    If you just want to stop your mac login, why don't you just turn off your wifi if you are not connected to internet?

    Otherwise a GUI like Little Snitch firewall would be a better option that gives options very granular to block inbound and outbound traffic and is quite easy to use and implement.

  • Why the printer stop printing when you click Cancel?

    This may belong in the Technet forum, but this is a question that concerns me since the days of Windows 95.

    Sometimes striking impression make you you screwed up in a certain way and to cancel the print job. Enter the printer, right click on the document and hit Cancel usually takes some time, during which the printer keeps printing and waste of ink & paper.
    Why is this? Why doesn't it stop immediately? Why do several PAGES for it to stop? Come to think of it, I can't think of a time casual since I left high school (which uses Mac and Apple printers) when I have not tried to stop a print job to a printer that was not Hewlett-Packard (an HP printer from ""), so I'm not sure if it is exclusive to HP or not. Work used to stop printing almost immediately after order - Macintosh printing, or at least they did with printers ImageWriter and LaswerWriter Mac OS 6.0.8 - 9.1.
    This is not the case with Windows 95 - Windows 7.

    I used to assume it had something to do with the buffer memory of the printer, but a recent incident involving someone accidentally unplugging the computer when the printer was on changed this long assumption based on my experience when I bought a buffer for my printer ImageWriter II return to 1989 or 1990. Printing stopped almost immediately after the computer that it was connected to the lost power (he tried to disconnect a faulty device so that it could be shipped to the manufacturer and pulled the wrong plug).

    This phenomenon embarrassing occurs on several different computers, printers and configurations. School computer laboratories on the areas of small business workgroups to systems of the House with the directly connected printer.

    Hi, SlickRCBD,

    The memory has a lot to do with why this does not block when cancelled.  There may be an older doc who is was filed here.  Unplug the printer from the computer periodically.  Leave that he unplugged for several minutes (5 max), then reconnect.  Remove the cables that connect to the back of the printer for the same amount of time.  This clears the memory.

    Open elevated command prompt

    Enter Net Stop Spooler

    Wait message spooler stopped

    Go to your windows\system32\spool\PRINTERS\ folder

    Search for files ending with. SPL and. SHD created around the time that you were trying to print - delete these files.

    Return to the command prompt window

    Type Net Start Spooler

    You will see message spooler has begun

    Output

    Sometimes the files are hungup.  The above gets rid of them.

  • Why the SAN disks and drives NAS recognized differently by the computer?

    Hi all;

    I'm a newbie in the sharing of storage.
    Why the SAN disks and drives NAS recognized differently by the computer? Computer sees SAN disks as local drives, NAS drives as network drive, even if they are all connected to the computer by the same network topology.
    I knew that SAN uses the block level transfer to transfer data all in SIN use level file transfer. Is that what this has something to do with which SAN and NAS drives are recognized differently by the computer? If so, how?

    Thank you.

    Hello

    The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.
    http://social.technet.Microsoft.com/forums/en/w7itpronetworking/threads

  • Why the optimizer ignores Index Fast full Scan when much lower cost?

    Summary (tracking details below) - to improve the performance of a query on more than one table, I created an index on a table that included all the columns referenced in the query. With the new index in place the optimizer is still choosing a full Table Scan on an Index fast full scan. However, by removing the one query tables I reach the point where the optimizer suddenly use the Index Fast Full Scan on this table. And 'Yes', it's a lot cheaper than the full Table Scan it used before. By getting a test case, I was able to get the motion down to 4 tables with the optimizer still ignoring the index and table of 3, it will use the index.

    So why the optimizer not chooses the Index Fast Full Scan, if it is obvious that it is so much cheaper than a full Table Scan? And why the deletion of a table changes how the optimizer - I don't think that there is a problem with the number of join permutations (see below). The application is so simple that I can do, while remaining true to the original SQL application, and it still shows this reversal in the choice of access path. I can run the queries one after another, and he always uses a full Table Scan for the original query and Index fast full scan for the query that is modified with a table less.

    Watching trace 10053 output for the two motions, I can see that for the original query 4 table costs alone way of ACCESS of TABLE UNIQUE section a full Table Scan. But for the modified query with a table less, the table now has a cost for an Index fast full scan also. And the end of the join cost 10053 does not end with a message about exceeding the maximum number of permutations. So why the optimizer does not cost the IFFS for the first query, when it does for the second, nearly identical query?

    This is potentially a problem to do with OUTER joins, but why? The joins between the tables do not change when the single extra table is deleted.

    It's on 10.2.0.5 on Linux (Oracle Enterprise Linux). I did not define special settings I know. I see the same behavior on 10.2.0.4 32-bit on Windows (XP).

    Thank you
    John
    Blog of database Performance

    DETAILS
    I've reproduced the entire scenario via SQL scripts to create and populate the tables against which I can then run the queries. I've deliberately padded table so that the length of the average line of data generated is similar to that of the actual data. In this way the statistics should be similar on the number of blocks and so forth.

    System - uname - a
    Linux mysystem.localdomain 2.6.32-300.25.1.el5uek #1 SMP Tue May 15 19:55:52 EDT 2012 i686 i686 i386 GNU/Linux
    Database - v$ version
    Oracle Database 10g Enterprise Edition Release 10.2.0.5.0 - Prod
    PL/SQL Release 10.2.0.5.0 - Production
    CORE    10.2.0.5.0      Production
    TNS for Linux: Version 10.2.0.5.0 - Production
    NLSRTL Version 10.2.0.5.0 - Production
    Original query (complete table below details):
    SELECT 
        episode.episode_id , episode.cross_ref_id , episode.date_required , 
        product.number_required , 
        request.site_id 
    FROM episode 
    LEFT JOIN REQUEST on episode.cross_ref_id = request.cross_ref_id 
         JOIN product ON episode.episode_id = product.episode_id 
    LEFT JOIN product_sub_type ON product.prod_sub_type_id = product_sub_type.prod_sub_type_id 
    WHERE (
            episode.department_id = 2
        and product.status = 'I'
          ) 
    ORDER BY episode.date_required
    ;
    Execution of display_cursor after the execution plan:
    SQL_ID  5ckbvabcmqzw7, child number 0
    -------------------------------------
    SELECT     episode.episode_id , episode.cross_ref_id , episode.date_required ,
    product.number_required ,     request.site_id FROM episode LEFT JOIN REQUEST on
    episode.cross_ref_id = request.cross_ref_id      JOIN product ON episode.episode_id =
    product.episode_id LEFT JOIN product_sub_type ON product.prod_sub_type_id =
    product_sub_type.prod_sub_type_id WHERE (         episode.department_id = 2 and
    product.status = 'I'       ) ORDER BY episode.date_required
    
    Plan hash value: 3976293091
    
    -----------------------------------------------------------------------------------------------------
    | Id  | Operation             | Name                | Rows  | Bytes |TempSpc| Cost (%CPU)| Time     |
    -----------------------------------------------------------------------------------------------------
    |   0 | SELECT STATEMENT      |                     |       |       |       | 35357 (100)|          |
    |   1 |  SORT ORDER BY        |                     | 33333 |  1920K|  2232K| 35357   (1)| 00:07:05 |
    |   2 |   NESTED LOOPS OUTER  |                     | 33333 |  1920K|       | 34879   (1)| 00:06:59 |
    |*  3 |    HASH JOIN OUTER    |                     | 33333 |  1822K|  1728K| 34878   (1)| 00:06:59 |
    |*  4 |     HASH JOIN         |                     | 33333 |  1334K|       |   894   (1)| 00:00:11 |
    |*  5 |      TABLE ACCESS FULL| PRODUCT             | 33333 |   423K|       |   103   (1)| 00:00:02 |
    |*  6 |      TABLE ACCESS FULL| EPISODE             |   299K|  8198K|       |   788   (1)| 00:00:10 |
    |   7 |     TABLE ACCESS FULL | REQUEST             |  3989K|    57M|       | 28772   (1)| 00:05:46 |
    |*  8 |    INDEX UNIQUE SCAN  | PK_PRODUCT_SUB_TYPE |     1 |     3 |       |  0   (0)|          |
    -----------------------------------------------------------------------------------------------------
    
    Predicate Information (identified by operation id):
    ---------------------------------------------------
       3 - access("EPISODE"."CROSS_REF_ID"="REQUEST"."CROSS_REF_ID")
       4 - access("EPISODE"."EPISODE_ID"="PRODUCT"."EPISODE_ID")
       5 - filter("PRODUCT"."STATUS"='I')
       6 - filter("EPISODE"."DEPARTMENT_ID"=2)
       8 - access("PRODUCT"."PROD_SUB_TYPE_ID"="PRODUCT_SUB_TYPE"."PROD_SUB_TYPE_ID")
    Updated the Query:
    SELECT 
        episode.episode_id , episode.cross_ref_id , episode.date_required , 
        product.number_required , 
        request.site_id 
    FROM episode 
    LEFT JOIN REQUEST on episode.cross_ref_id = request.cross_ref_id 
         JOIN product ON episode.episode_id = product.episode_id 
    WHERE (
            episode.department_id = 2
        and product.status = 'I'
          ) 
    ORDER BY episode.date_required
    ;
    Execution of display_cursor after the execution plan:
    SQL_ID  gbs74rgupupxz, child number 0
    -------------------------------------
    SELECT     episode.episode_id , episode.cross_ref_id , episode.date_required ,
    product.number_required ,     request.site_id FROM episode LEFT JOIN REQUEST on
    episode.cross_ref_id = request.cross_ref_id      JOIN product ON episode.episode_id =
    product.episode_id WHERE (         episode.department_id = 2     and product.status =
    'I'       ) ORDER BY episode.date_required
    
    Plan hash value: 4250628916
    
    ----------------------------------------------------------------------------------------------
    | Id  | Operation              | Name        | Rows  | Bytes |TempSpc| Cost (%CPU)| Time     |
    ----------------------------------------------------------------------------------------------
    |   0 | SELECT STATEMENT       |             |       |       |       | 10515 (100)|          |
    |   1 |  SORT ORDER BY         |             | 33333 |  1725K|  2112K| 10515   (1)| 00:02:07 |
    |*  2 |   HASH JOIN OUTER      |             | 33333 |  1725K|  1632K| 10077   (1)| 00:02:01 |
    |*  3 |    HASH JOIN           |             | 33333 |  1236K|       |   894   (1)| 00:00:11 |
    |*  4 |     TABLE ACCESS FULL  | PRODUCT     | 33333 |   325K|       |   103   (1)| 00:00:02 |
    |*  5 |     TABLE ACCESS FULL  | EPISODE     |   299K|  8198K|       |   788   (1)| 00:00:10 |
    |   6 |    INDEX FAST FULL SCAN| IX4_REQUEST |  3989K|    57M|       |  3976   (1)| 00:00:48 |
    ----------------------------------------------------------------------------------------------
    
    Predicate Information (identified by operation id):
    ---------------------------------------------------
       2 - access("EPISODE"."CROSS_REF_ID"="REQUEST"."CROSS_REF_ID")
       3 - access("EPISODE"."EPISODE_ID"="PRODUCT"."EPISODE_ID")
       4 - filter("PRODUCT"."STATUS"='I')
       5 - filter("EPISODE"."DEPARTMENT_ID"=2)
    Creating the table and Population:
    1 create tables
    2. load data
    3 create indexes
    4. collection of statistics
    --
    -- Main table
    --
    create table episode (
    episode_id number (*,0),
    department_id number (*,0),
    date_required date,
    cross_ref_id varchar2 (11),
    padding varchar2 (80),
    constraint pk_episode primary key (episode_id)
    ) ;
    --
    -- Product tables
    --
    create table product_type (
    prod_type_id number (*,0),
    code varchar2 (10),
    binary_field number (*,0),
    padding varchar2 (80),
    constraint pk_product_type primary key (prod_type_id)
    ) ;
    --
    create table product_sub_type (
    prod_sub_type_id number (*,0),
    sub_type_name varchar2 (20),
    units varchar2 (20),
    padding varchar2 (80),
    constraint pk_product_sub_type primary key (prod_sub_type_id)
    ) ;
    --
    create table product (
    product_id number (*,0),
    prod_type_id number (*,0),
    prod_sub_type_id number (*,0),
    episode_id number (*,0),
    status varchar2 (1),
    number_required number (*,0),
    padding varchar2 (80),
    constraint pk_product primary key (product_id),
    constraint nn_product_episode check (episode_id is not null) 
    ) ;
    alter table product add constraint fk_product 
    foreign key (episode_id) references episode (episode_id) ;
    alter table product add constraint fk_product_type 
    foreign key (prod_type_id) references product_type (prod_type_id) ;
    alter table product add constraint fk_prod_sub_type
    foreign key (prod_sub_type_id) references product_sub_type (prod_sub_type_id) ;
    --
    -- Requests
    --
    create table request (
    request_id number (*,0),
    department_id number (*,0),
    site_id number (*,0),
    cross_ref_id varchar2 (11),
    padding varchar2 (80),
    padding2 varchar2 (80),
    constraint pk_request primary key (request_id),
    constraint nn_request_department check (department_id is not null),
    constraint nn_request_site_id check (site_id is not null)
    ) ;
    --
    -- Activity & Users
    --
    create table activity (
    activity_id number (*,0),
    user_id number (*,0),
    episode_id number (*,0),
    request_id number (*,0), -- always NULL!
    padding varchar2 (80),
    constraint pk_activity primary key (activity_id)
    ) ;
    alter table activity add constraint fk_activity_episode
    foreign key (episode_id) references episode (episode_id) ;
    alter table activity add constraint fk_activity_request
    foreign key (request_id) references request (request_id) ;
    --
    create table app_users (
    user_id number (*,0),
    user_name varchar2 (20),
    start_date date,
    padding varchar2 (80),
    constraint pk_users primary key (user_id)
    ) ;
    
    prompt Loading episode ...
    --
    insert into episode
    with generator as 
    (select rownum r
              from (select rownum r from dual connect by rownum <= 1000) a,
                   (select rownum r from dual connect by rownum <= 1000) b,
                   (select rownum r from dual connect by rownum <= 1000) c
             where rownum <= 1000000
           ) 
    select r, 2,
        sysdate + mod (r, 14),
        to_char (r, '0000000000'),
        'ABCDEFGHIJKLMNOPQRSTUVWXYZ' || to_char (r, '000000')
      from generator g
    where g.r <= 300000
    /
    commit ;
    --
    prompt Loading product_type ...
    --
    insert into product_type
    with generator as 
    (select rownum r
              from (select rownum r from dual connect by rownum <= 1000) a,
                   (select rownum r from dual connect by rownum <= 1000) b,
                   (select rownum r from dual connect by rownum <= 1000) c
             where rownum <= 1000000
           ) 
    select r, 
           to_char (r, '000000000'),
           mod (r, 2),
           'ABCDEFGHIJKLMNOPQRST' || to_char (r, '000000')
      from generator g
    where g.r <= 12
    /
    commit ;
    --
    prompt Loading product_sub_type ...
    --
    insert into product_sub_type
    with generator as 
    (select rownum r
              from (select rownum r from dual connect by rownum <= 1000) a,
                   (select rownum r from dual connect by rownum <= 1000) b,
                   (select rownum r from dual connect by rownum <= 1000) c
             where rownum <= 1000000
           ) 
    select r, 
           to_char (r, '000000'),
           to_char (mod (r, 3), '000000'),
           'ABCDE' || to_char (r, '000000')
      from generator g
    where g.r <= 15
    /
    commit ;
    --
    prompt Loading product ...
    --
    -- product_id prod_type_id prod_sub_type_id episode_id padding 
    insert into product
    with generator as 
    (select rownum r
              from (select rownum r from dual connect by rownum <= 1000) a,
                   (select rownum r from dual connect by rownum <= 1000) b,
                   (select rownum r from dual connect by rownum <= 1000) c
             where rownum <= 1000000
           ) 
    select r, mod (r, 12) + 1, mod (r, 15) + 1, mod (r, 300000) + 1,
           decode (mod (r, 3), 0, 'I', 1, 'C', 2, 'X', 'U'),
           dbms_random.value (1, 100), NULL
      from generator g
    where g.r <= 100000
    /
    commit ;
    --
    prompt Loading request ...
    --
    -- request_id department_id site_id cross_ref_id varchar2 (11) padding 
    insert into request
    with generator as 
    (select rownum r
              from (select rownum r from dual connect by rownum <= 1000) a,
                   (select rownum r from dual connect by rownum <= 1000) b,
                   (select rownum r from dual connect by rownum <= 1000) c
             where rownum <= 10000000
           ) 
    select r, mod (r, 4) + 1, 1, to_char (r, '0000000000'),
    'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz01234567890123456789' || to_char (r, '000000'),
    'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789012345678' || to_char (r, '000000')
      from generator g
    where g.r <= 4000000
    /
    commit ;
    --
    prompt Loading activity ...
    --
    -- activity activity_id user_id episode_id request_id (NULL) padding 
    insert into activity
    with generator as 
    (select rownum r
              from (select rownum r from dual connect by rownum <= 1000) a,
                   (select rownum r from dual connect by rownum <= 1000) b,
                   (select rownum r from dual connect by rownum <= 1000) c
             where rownum <= 10000000
           ) 
    select r, mod (r, 50) + 1, mod (r, 300000) + 1, NULL, NULL
      from generator g
    where g.r <= 100000
    /
    commit ;
    --
    prompt Loading app_users ...
    --
    -- app_users user_id user_name start_date padding 
    insert into app_users
    with generator as 
    (select rownum r
              from (select rownum r from dual connect by rownum <= 1000) a,
                   (select rownum r from dual connect by rownum <= 1000) b,
                   (select rownum r from dual connect by rownum <= 1000) c
             where rownum <= 10000000
           ) 
    select r, 
           'User_' || to_char (r, '000000'),
           sysdate - mod (r, 30),
           'ABCDEFGHIJKLMNOPQRSTUVWXYZ' || to_char (r, '000000')
      from generator g
    where g.r <= 1000
    /
    commit ;
    --
    
    prompt Episode (1)
    create index ix1_episode_cross_ref on episode (cross_ref_id) ;
    --
    prompt Product (2)
    create index ix1_product_episode on product (episode_id) ;
    create index ix2_product_type on product (prod_type_id) ;
    --
    prompt Request (4)
    create index ix1_request_site on request (site_id) ;
    create index ix2_request_dept on request (department_id) ;
    create index ix3_request_cross_ref on request (cross_ref_id) ;
    -- The extra index on the referenced columns!!
    create index ix4_request on request (cross_ref_id, site_id) ;
    --
    prompt Activity (2)
    create index ix1_activity_episode on activity (episode_id) ;
    create index ix2_activity_request on activity (request_id) ;
    --
    prompt Users (1)
    create unique index ix1_users_name on app_users (user_name) ;
    --
    prompt Gather statistics on schema ...
    --
    exec dbms_stats.gather_schema_stats ('JB')
    10053 sections - original query
    ***************************************
    SINGLE TABLE ACCESS PATH
      -----------------------------------------
      BEGIN Single Table Cardinality Estimation
      -----------------------------------------
      Table: REQUEST  Alias: REQUEST
        Card: Original: 3994236  Rounded: 3994236  Computed: 3994236.00  Non Adjusted: 3994236.00
      -----------------------------------------
      END   Single Table Cardinality Estimation
      -----------------------------------------
      Access Path: TableScan
        Cost:  28806.24  Resp: 28806.24  Degree: 0
          Cost_io: 28738.00  Cost_cpu: 1594402830
          Resp_io: 28738.00  Resp_cpu: 1594402830
    ******** Begin index join costing ********
      ****** trying bitmap/domain indexes ******
      Access Path: index (FullScan)
        Index: PK_REQUEST
        resc_io: 7865.00  resc_cpu: 855378926
        ix_sel: 1  ix_sel_with_filters: 1
        Cost: 7901.61  Resp: 7901.61  Degree: 0
      Access Path: index (FullScan)
        Index: PK_REQUEST
        resc_io: 7865.00  resc_cpu: 855378926
        ix_sel: 1  ix_sel_with_filters: 1
        Cost: 7901.61  Resp: 7901.61  Degree: 0
      ****** finished trying bitmap/domain indexes ******
    ******** End index join costing ********
      Best:: AccessPath: TableScan
             Cost: 28806.24  Degree: 1  Resp: 28806.24  Card: 3994236.00  Bytes: 0
    ***************************************
    10053 - updated the Query
    ***************************************
    SINGLE TABLE ACCESS PATH
      -----------------------------------------
      BEGIN Single Table Cardinality Estimation
      -----------------------------------------
      Table: REQUEST  Alias: REQUEST
        Card: Original: 3994236  Rounded: 3994236  Computed: 3994236.00  Non Adjusted: 3994236.00
      -----------------------------------------
      END   Single Table Cardinality Estimation
      -----------------------------------------
      Access Path: TableScan
        Cost:  28806.24  Resp: 28806.24  Degree: 0
          Cost_io: 28738.00  Cost_cpu: 1594402830
          Resp_io: 28738.00  Resp_cpu: 1594402830
      Access Path: index (index (FFS))
        Index: IX4_REQUEST
        resc_io: 3927.00  resc_cpu: 583211030
        ix_sel: 0.0000e+00  ix_sel_with_filters: 1
      Access Path: index (FFS)
        Cost:  3951.96  Resp: 3951.96  Degree: 1
          Cost_io: 3927.00  Cost_cpu: 583211030
          Resp_io: 3927.00  Resp_cpu: 583211030
      Access Path: index (FullScan)
        Index: IX4_REQUEST
        resc_io: 14495.00  resc_cpu: 903225273
        ix_sel: 1  ix_sel_with_filters: 1
        Cost: 14533.66  Resp: 14533.66  Degree: 1
    ******** Begin index join costing ********
      ****** trying bitmap/domain indexes ******
      Access Path: index (FullScan)
        Index: IX4_REQUEST
        resc_io: 14495.00  resc_cpu: 903225273
        ix_sel: 1  ix_sel_with_filters: 1
        Cost: 14533.66  Resp: 14533.66  Degree: 0
      Access Path: index (FullScan)
        Index: IX4_REQUEST
        resc_io: 14495.00  resc_cpu: 903225273
        ix_sel: 1  ix_sel_with_filters: 1
        Cost: 14533.66  Resp: 14533.66  Degree: 0
      ****** finished trying bitmap/domain indexes ******
    ******** End index join costing ********
      Best:: AccessPath: IndexFFS  Index: IX4_REQUEST
             Cost: 3951.96  Degree: 1  Resp: 3951.96  Card: 3994236.00  Bytes: 0
    ***************************************

    I mentioned that it is a bug related to the ANSI SQL standard and transformation probably.

    As suggested/asked in my first reply:
    1. If you use a no_query_transformation then you should find that you get the use of the index (although not in the plan you would expect)
    2. If you use the traditional Oracle syntax, then you should not have the same problem.

Maybe you are looking for

  • TE2100 - screen gone dark

    Can someone help me, I was working on my TE2100 the other night, when all of a sudden the screen went almost completely dark, and I was not able to recover any screen since. I tried re-booting etc, but no success.If I look closely I see a very small

  • Stats of different song in 'My Music' to ' for you, etc...?

    I noticed this info on the albums and songs when playing or looking for an album of music from the Apple does not match when the music is recorded in my music. For example, I recorded Album A in my music, favorite it and also give it a rating. Naviga

  • How to create column headings in the Windows 2000 Explorer?

    I need to create new managers of column in the Windows 2000 Explorer.   How can I do this? Steve

  • Server installation 2012 on PowerEdge T110 II in Raid Mode

    I am trying to install Windows Server 2012 on a server PowerEdge T110 II that I just bought.  No software utility disk and the driver provided with the computer!  When I try to install Windows directly from the OS installation disc it tells me that s

  • Printer stopped printing, but the other functions work

    I have a 1536mfp that has worked very well for many years... no problem.  I installed a second printer about two months (Officejet Pro 8620) for printing of color presentations... no there was no problem until last week when the 1536 stopped printing