DLSW ER+ at the central site

The network topology that I have is two MSFCs and two external routers at central site and two MSFCs and two external routers at the remote site.
DLSW is activated on the external routers. In regards to DLSW+ ER at the central site, only one translational or transparent bridge can be active at a time. Manual intervention is required to cause a router to take over for the other router. Is there any other way to have some means of dlsw redundancy (w/o manual intervention) at the central site (for ethernet environment only)?
Second, DLSW ER+ cannot be deployed easily at the central site, since you need a lot of dlsw mapping. On the other hand, you also need local SNA PUs to be able and reach the CIP (both located at the central site) but reside on a different broadcast domain. Any ideas?
Thanks

Hi,
on the central side, host end, there are a couple of things you can do.
The potential solutions mentioned below are in the order that cisco would prefer.
1.
The most clean thing to do is to upgrade and configure the mainframe for appn and allow hpr/ip between the host end router and the host.
You will need to run dlsw/vdlc/snasw in the host end routers to be able to do this.
It also requires that you have ip connectivity to the mainframe.
If you do this than the mac address, the remote devices connect to, is configured as a snasw vdlc port in the routers. Both of them are active all the time, the remotes will learn the remote mac address over both peers and as such you have automatic, non manual intervention, redundancy, loadbalancing. The mac addresses in this case only exist in the central router. Nowhere else. The remote device does not know anything about this change.
Each of the head end dlsw/vdlc/snasw routers will have at least one hpr/ip uplink to the host. This is routed ip traffic into the mainframe.
In that case you can also define the physical ethernets as snasw ports, do hsrp on it and configure a hsrp mac address, this mac address would then be used as dmac for local clients connecting to the host.
2.
If for some reason you can not do the appn/snasw configuration you still have some options.
If you are using cisco cip's with csna today than you most likely have on path into the mainframe today for each mac address.
You can configure multiple vlans between the dlsw router and the cip router, i.e. dot1q trunk, and on the cip router you can configure multiple virtual ring groups and more than one csna path statement into the host. At the end you attach each vlan to one of the channel path, configure srtlb for each vlan into a unique vring, and then configure a different adapter number on each of the internal tokenring lans with the same mac address.
On the dlsw router you can configure multiple bridge groups into dlsw and each of those bridge groups goes to a different vlan. If you do this with two dlsw routers going to the same cip router you then end up with two channel access's and one vlan on each of the dlsw routers. If you do it to two cip routers you need 4 vlans. Just make sure that you dont bridge the vlans together.
The remotes learn than the remote mac address over both peers and your redundancy is established.
For the local clients this solution has the draw back that you need to pick a vlan where to connect them. There is no automatic redundancy, like hsrp in the first example, for those.
3.
You can enable both dlsw routers towards a single bridge-group and apply a mac address filter inbound to the bridge group only allowing the mac address/es of the hosts as source mac address.
That way you kill the potential loop on the head end. You will also need to put on as much restrictive filtering as possible to only allow the traffic that is wanted.
thanks...
Matthias

Similar Messages

  • SCCM 2012 MP does not monitor anything but the central site

    Hi,
    We've tried implementing the SCCM 2012 MP (5.0.7804.1000) to monitor our SCCM 2012 SP1 setup running on Server 2012 from our SCOM 2012 SP1 setup.
    Everything imports fine and after ~30 minutes the servers are discovered and appears.
    After a while longer the central site and the SDK-service shows up as monitored but the resto of the 5 DPs and all other server roles remains unmonitored even after 3 days.. ..?
    All the agents are set to enable proxy.
    The SCOM servers runs with one service accounts and the agents with different action accounts.
    The SCOM action accounts on the SCCM-servers all run with the same domain service account with administrator-privileges on the SCCM-servers but no permissions within SCCM.
    Does the action account need any specific permissions in the SQL DB or in SCCM? To be part of any specific role?
    Any advise is greatly appreciated :)

    We have resolved this issue, I'm not exactly sure how we resolved it but what I think fixed the problem for us was creating overrides for the object discovery rules contained in the MP. 
    See my blog on our implementation: http://damonjohns.com/2014/07/01/monitoring-configuration-manager-2012-r2-with-the-scom-2012-r2-management-pack/
    My blog contains a screen shot and all the values I changed.
    You may ask why we increased the rate at which the hierarchy discovery rule executed with an override? Well
    in part it was due to:
    A. Us having the issue and
    B. I was sick of trying to trouble shoot the event log error that by default only registered every 6 hours.
    After I created the overrides, the MP started discovering data. It wasn't immediate though, it took another 6 hours or so for it to start working correctly. I think what might be happening is that one of the discovery rules is not completing correctly which
    causes the others to fail - hence no data. I have no idea why shortening the time on the discovery objects made any difference. But...it worked for me.
    Cheers
    Damon

  • SCCM central site and primary site use the same SQL SERVER with two Instance.

    Hi  Guys,
    I want deploy SCCM 2012 central site and primary site in my domain. But Only one Sql server for me. Any one can tell me how to install the central site server and primary site server with the same SQL SERVER with two instance.
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
    Sean Xiao
    TechNet Community Support

    Although you can install like the configuration you said above, we do not recommend you do it this way. If your SQL box has  problems, all the data will go away and you will not have data redundancy.
    You need to configure the different SQL Port and SQL Broke service port e.g.
    SQL port 4023  SQL Broke Service port 4022 for CAS instance
    SQL port 4024  SQL Broke Service port 4021 for PRI instance
    Juke Chou
    TechNet Community Support
    I agree with Johan and this configuration should not be used. But I want to clarify that the default ports for "SQL port" (actually, SQL over TCP) is 1433 and the SQL Broker Service uses 4022. The configuration above should work but the "correct" would be
    to use 1433 and 4022 for the CAS and 10434 and 4023 for the Primary :)
    You can read more about Network Ports used by Configuration Manager here
    http://technet.microsoft.com/en-us/library/hh427328.aspx#BKMK_CommunicationPorts
    /Tim
    Tim Nilimaa | Blog: http://infoworks.tv | Twitter: @timnilimaa

  • Deploying multiple central sites sharing the same edge, persistent chat and monitoring services

    Hi,
    We've already one central site and multible branches that have SBS installed ,we're planning to replace these SBSs with standard edition servers to reduce the dependencies on the FE and BW that are located in the central site but that all will share the
    same Edge ,Persistent chat and Monitoring roles located in the Main site.
    What points we should take care of while making these changes regarding the following:
    1- Reverse Proxy
    2- DNS records
    3- Edge configuration and communication with the branch sites
    4- Persistent Chat communication with the branch sites
    5- Monitoring services which is coallocated on the main FE
    6- Users sign in internally and externally and how they will be directed to use their server for meet and dialin

     1- Reverse Proxy
    publish the webservices for all additional standard Server (Change certificate with additional SAN!)
    2- DNS records
    The registrar on the branch side should point to the Standard server
    3- Edge configuration and communication with the branch sites
    can still be used with the standard server
    4- Persistent Chat communication with the branch sites
    can still be used with the standard server
    5- Monitoring services which is coallocated on the main FE
    the same for the standrad Server, only configuration
    6- Users sign in internally and externally and how they will be directed to use their server for meet and dialin
    therefore you have to publish the webservices through your reverse Proxy and to Change the DNS entries for your local sites.
    regards Holger Technical Specialist UC

  • The master site control file does not contain a component item for SMS_STATUS_MANAGER.

    New to the System Center world. We are using a fresh install of Server 2012 R2 and System Center R2 with everything working until Server 2012 R2 Update 1 was installed. Now we are getting the following:
    Site type: Primary Site or CAS SMS_STATUS_MANAGER
    6/4/2014 1:35:21 PM 10996 (0x2AF4)
    Resolved the "Status Manager" inbox to "C:\Program Files\Microsoft Configuration Manager\inboxes\statmgr.box\statmsgs".
    SMS_STATUS_MANAGER 6/4/2014 1:35:21 PM
    10996 (0x2AF4)
    Opened a change notification handle for directory "C:\Program Files\Microsoft Configuration Manager\inboxes\statmgr.box\statmsgs".
    SMS_STATUS_MANAGER 6/4/2014 1:35:21 PM
    10996 (0x2AF4)
    Resolved the "Site Control Manager (Master Site Control File)" inbox to "C:\Program Files\Microsoft Configuration Manager\inboxes\sitectrl.box".
    SMS_STATUS_MANAGER 6/4/2014 1:35:21 PM
    10996 (0x2AF4)
    Opened a change notification handle for directory "C:\Program Files\Microsoft Configuration Manager\inboxes\sitectrl.box".
    SMS_STATUS_MANAGER 6/4/2014 1:35:21 PM
    10996 (0x2AF4)
    Parsed the master site control file, serial number 1551209029.
    SMS_STATUS_MANAGER 6/4/2014 1:35:21 PM
    10996 (0x2AF4)
    This site is the central site. SMS_STATUS_MANAGER
    6/4/2014 1:35:21 PM 10996 (0x2AF4)
    ERROR: The master site control file does not contain a component item for SMS_STATUS_MANAGER.
    SMS_STATUS_MANAGER 6/4/2014 1:35:21 PM
    10996 (0x2AF4)
    Sleeping for 60 seconds... SMS_STATUS_MANAGER
    6/4/2014 1:35:21 PM 10996 (0x2AF4)
    Any thoughts on how to fix this? Seen a few references to a "site reset" for SCCM 2007 but wanted to make sure there wasn't anything else to try before heading down that road with 2012R2.

    A site reset can also be done in CM12 so it's worth a try.
    Torsten Meringer | http://www.mssccmfaq.de

  • Central Site Internet Connectivity for MPLS VPN User

    What are the solutions of Central site Internet connectivity for a MPLS VPN user, and what is the best practice?

    Hello,
    Since you mentioned that Internet Access should be through a central site, it is clear that all customer sites (except the central) will somehow have a default (static/dynamic) to reach the central site via the normal VPN path for unknown destinations. Any firewall that might be needed, would be placed at the central site (at least). So, the issue is how the central site accesses the Internet.
    Various methods exist to provide Internet Access to an MPLS VPN. I am not sure if any one of them is considered the best. Each method has its pros and cons, and since you have to balance various factors, those factors might conflict at some point. It is hard to get simplicity, optimal routing, maximum degree of security (no matter how you define "security"), reduced memory demands and cover any other special requirements (such as possibility for overlapping between customer addresses) from a single solution. Probably the most secure VPN is the one which is not open to the Internet. If you open it to the Internet, some holes also open inevitably.
    One method is to create a separate Internet_Access VPN and have other VPNs create an extranet with that Internet_Access VPN. This method is said to be very secure (at least in terms of backbone exposure). However, if full routing is a requirement, the increased memory demands of this solution might lead you to prefer to keep the internet routing table in the Global Routing Table (GRT). You might have full routing in the GRT of PEs and Ps or in PEs only (second is probably better).
    Some names for solutions that exist are: static default routing, dynamic default routing, separate BGP session between PE and CE (via separate interface, subinterface or tunnel), extranet with internet VRF (mentioned earlier), extranet with internet VRF + VRF-aware NAT.
    The choice will depend on the requirements of your environment. I cannot possibly describe all methods here and I do not know of a public document that does. If you need an analysis of MPLS VPN security, you may want to take a look at Michael Behringer's great book with M.Morrow "MPLS VPN Security". Another book that describes solutions is "MPLS and VPN Architectures" by Ivan Pepelnjak. There is a Networkers session on MPLS VPNs that lists solutions. There is also a relevant document in CCO:
    http://www.cisco.com/en/US/tech/tk436/tk428/technologies_configuration_example09186a00801445fb.shtml (covering static default routing option).
    Kind Regards,
    M.

  • SCCM 2007 - All clients from primary site have vanished from central site collections

    Hi all,
    we have a SCCM 2007 R2 setup with one central site, one Primary Site (A) with a secondary site hanging off it and another Primary Site (B). Suddenly all the clients from the Primary Site A (and also it's Secondary Site) have vanished from the central
    site. All the clients are still present when we check Collections from the admin console on Primary Site A site server - they have simply disappeared when we check Collections from the Central Site admin console.
    Can anyone provide any info on a good starting point for troubleshooting this issue? As a sidenote, we can still push packages out to the Primary Site A distribution point and both the Primary and Central site can communicate/ping each other.
    Any help/info would be much appreciated!
    Thanks

    Check the
    site replication on central site, is that SQL is working fine, and also see the
    inbox folder in central site, might be there is backlog and those DDR files are
    not processing, and after maintenance they got deleted.<o:p></o:p>
    please run
    the heartbeat discovery by hour or day, and once the clients will sent all the
    DDR files then they will appears again.<o:p></o:p>
    Sharad Singh | My blogs: SharadTech | Twitter:
    @SinghSharaad | | Please remember to click “Mark as Answer” on the post that helps you.This can be beneficial to other community members reading the thread.

  • Script to get all the Server Names on Central Site in the SCCM 2007 Hierarchy

    I want a script which will run on Central Site, and give all the SCCM server names in the hierarchy.
    Thanks and Regards, Mohd Zaid www.techforcast.com

    Duplicated post of
    http://social.technet.microsoft.com/Forums/systemcenter/en-US/97910cd5-8f8b-46a7-86fa-c00932571d0d/script-to-get-all-the-server-names-on-central-site-in-the-sccm-2007-heirarchy?forum=configmgrgeneral
    Garth Jones | My blogs: Enhansoft and
    Old Blog site | Twitter:
    @GarthMJ

  • Is more than one Central Site in the same AD site supported?

    Working with a customer here, and they will be hosting 250,000 accounts for Lync 2013, and I know that a Central Site can only host 240,000 accounts. Knowing this limitation, can more than one Central Site be located within the same data center? I would
    think that separate subnets (AD Sites) are all that is required.
    Is it this simple?
    Thanks,
    Christian
    Christian Frank

    I haven't looked at the limits of a site, because I've never had to go that high.  Can you reference where you found that information?  Is that an actual limitation or just a limit of the capacity planner? 
    http://technet.microsoft.com/en-us/library/jj205120.aspx
    I couldn't find reference to it in the user models which is why I ask if you have more information:
    http://technet.microsoft.com/en-us/library/gg615015.aspx
    I'm not challenging it, I'm just unaware of it.  What modalities and roles would you be supporting? 
    And you could split the pools into different sites if needed, that should get you around the limit if it exists. 
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question please click "Mark As Answer".
    SWC Unified Communications

  • Value does not fall within the expected range in my itemupdated eventreceiver while accessing a splist column on the root site collection

    hi,
     I am performing the below operations:
    1) Itemupdated event handler when a document is uploaded into the document library
    2) Now amreading another list which is in the root  site level so, i used spsite, spweb again and accessed that splist and trying to read single line of text column and user or group column.
    Now when i am reading this, i am getting the error "Value does not fall within the expected range".
    I went to resource throttling under central admin -->my current web appln and changed that value to 20  from 8
    even after performing the above, i am getting the same error.
    pls help anyone has faced this issue before.
    Accessing a splist which is under root site collection within the itemupdated eventreceiver is allowed in SP ?

    hello sir,
     as per my requirement i have to access a  splist which is residing in the ROOT SITE COLLECTION OF THIS WEB APPLICATION. the event receiver i have written is residing in one of the few document libraries within the sub site. there are hundreds
    of sub sites exist in this site collection. I need to access the root site collection within the itemevent receiver and access thatperson column from that splist. why i ahve kept this list at the root site collection level [
    http://server1:2020/ ] , because this  splist is the UI for customer's sp admin for performing  weekly tasks. like adding few items in the splist and my event receiver fires and check this column- person /group
    column ]  and apply permissions on the  document.
    so my doubt is it possible to access the root site collection from my event receiver code.
    spweb from properties web is just the subsite url and not the site collection. i want to get the root sitec ollection url's splist.
    also am already running this code under runwithelevatedprivileges.

  • Project Server 2013 - New - Project, creates groups at the root site level, Server is in Project Server Permission mode

    I created an Enterprise Project in PWA and moving up to the root site settings I see there was the four basic groups created there just for this project. This is not acceptable when there will be 500 projects on the server. Is there a setting to turn this
    off. I guess we will rarely create projects with PWA, so I will see if creating a Project in Desktop has the same effect.  Still would like to understand why this is happening.  Thank you.
    Site Provisioning settings are located under Central Administration -> Manage Service Applications -> Project Application Service -> Manage ->
    Project Site Provisioning Settings
    Turning that off allows the group creation to cease.
    Then PWA Settings -> Operational Policies -> Connected Sharepoint Sites
    allows selective creation of a Project Site (Workspace)
    This set up is perfect for what I require.

    I assume that you're talking about the SharePoint security groups for each Project site? If so, then this is as designed. Each site can have different users, so this is absolutely necessary when you use SharePoint. If you do not want to create project sites
    for your projects automatically, you have already discovered how to turn off automatic site creation.
    If you turn off the Project application service, you disable Project Server. I don't think that is what you want to do. I don't understand your objection to the groups because if you are running in Project Server classic permissions mode, Project Server
    manages the group membership for you.
    Gary Chefetz, MCITP, MCP, MVP msProjectExperts
    Project and Project ServerFAQs
    Project Server Help BLOG

  • Insufficiant for performing this operationwhen try to connect to the sharepoint site

    Dears,
    I have an issue when i try to open the SharePoint site from the report builder to save the report or get the data source 
    it gives :unable to open or save the file
    the permissions granted to the 'Nt Authority\Anonymous logon' are insufficient for performing this operation
    any help please its so urgent , thanks in advance
    as the image below
    khatib7

    Hi khatib7,
    According to your description, my understanding is that you got an error when you opened a SharePoint site from the report builder to save the report.
    SSRS does not support anonymous access. You can disable anonymous access or extend the Web Application into another zone that does not have anonymous access enabled.
    For disabling anonymous access, please go to SharePoint Central Administration->Manage web applications, select the web application that you used, and click Authentication Providers->Default, unselect ‘Enable anonymous access’, click Save.
    Here is a similar post for you to take a look at:
    http://social.msdn.microsoft.com/Forums/en-US/c79f12a9-23f0-446b-9af1-49f1c7a1692b/the-permissions-granted-to-user-nt-authorityanonymous-logon-are-insufficient-for-performing-this?forum=sqlreportingservices
    I hope this helps.
    Thanks,
    Wendy
    Forum Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Wendy Li
    TechNet Community Support

  • Upgrade weblogic10.3.2 to 10.3.5., error in discover using central site

    Hi,
    I have installed weblogic 10.3.2 in my host, created domain, and discovered them in central site.then I used upgrade installer to upgrade weblogic server to 10.3.5, in Adminserver Console, I can see the version changed to 10.3.5, but in EM central site, the weblogic version is still 10.3.2 even after I refresh the domain. I wonder whether it should rediscover the target again, so I remove the domain, and discover again, but when I finding target, it prompt "No targets discovered.",Hide:"For more troubleshooting tips refer support note: 1458357.1 ".
    I have three questions:
    1、when we update targets,do we need to rediscover in central site?if not,why the version of weblogic is still 10.3.2
    2、why I rediscover the target, it prompt "No targets discovered.". I have domain on that host.
    3、I cannot find support note: 1458357.1 in mos.
    Thanks & Regards,
    Dan
    Edited by: 955975 on 2012-8-30 下午11:43
    Edited by: 955975 on 2012-8-30 下午11:54

    Hi Dan,
    The discovery perl scripts are located in /agent/plugins/oracle.sysman.emas.discovery.plugin_12.1.0.2.0/scripts/*
    Troubleshooting steps:
    1. Agent side
    Set Agent PERL Traces to DEBUG level by Login to Cloud control ->Targets->All Targets->click on the Agent link->expend drop-down menu "Agent"->Properties ->Choose" DEBUG" for property: EMAGENT_PERL_TRACE_LEVEL
    The log file associated to emagent perl is [..]/agent/agent_inst/sysman/log/emagent_perl.trc. If agent successfully discovers the targets, the targets properties are listed in emagent_perl.trc.
    2. OMS side
    Once the targets had been discovered by the agent, the target discovery information is sent back to OMS in order to be added as monitored targets in Cloud Control.
    There should be no BEA-XXX error in /agent/agent_inst/sysman/log/emagent_perl.trc file before targets definition discovered. If there is BEA-XXX error, it will be sent back to OMS and adding targets to Cloud Control will fail.
    Set OMS to DEBUG level
    cd <OMS_HOME>/bin
    emctl set property -name log4j.rootCategory -value 'DEBUG, emlogAppender, emtrcAppender' -module logging
    The OMS log file to investigate: [..]/Middleware/gc_inst/em/EMGC_OMS1/sysman/log/emoms.trc
    Regards,
    Kal

  • Why is the div sitting at the bottom of the page?

    Can anyone tell me why the div <div id="maindiv" class="maindiv_scroll">  is sitting at the bottom of the page?
    http://www.milesfunerals.com/nafd.php

    I have not tested this BUT most probably the scrollbar on the central <div> is making the width of the <div> wider than the space it has to fit itself into so the <div> is being thrown to the next available space, at the bottom of the construction. Below I have commented out the overflow: scroll; - see what effect it has, if any.
    .maindiv_scroll {
        width:100%;
        max-width:812px;
        background-image: url(images/scrollbgnew.jpg);
        /* overflow:scroll; */
        background-repeat: no-repeat;
        margin-left: 138px;
        height:1176px;
        border-top: 1px solid #F4ECC5;
    I don't want to be the bringer of bad news (again) but you really are getting into a bit of a mess. This is largely down to excessive css. When it gets to that amount of css you should try breaking it down, ie you could put the mainnav css into its own linked css file and that gets that out of the way, making troubleshooting a bit less of a nightmare.
    Also you are mixing fixed width with percenatge width. I don't have a lot of experience with that but it's not as easy as using all percentages or all fixed width. Obviously in this case you need the percentages as it's a responsive construction so why are you fixiing the left navigation and the right sidebar.
    It would be better to set those as percentages and float all the <divs> left in my opinion.

  • How I to restore the Project Site Deleted on Project Server 2010 ?

    Hi
    I have a questions, I deleted  a Project Site from project server 2010, but I need restore this site Do you have any way for restore the project site.
    Thanks a lot for the help

    Ademir,
    With 2010, you don't have to attach content database to another PWA. We can restore the site using unattached content database from Central admin
    1. Restore backup of content database in SQL server
    2. Launch Central Admin and Navigate to >> Backup and Restore >> Recover data from unattached content database.
    3. Enter restored database name and select option export site or list
    4. Export your desired site
    5. Restore exported site using stsadm command with import switch
    stsadm -o import -url "<a href="http:///<pwainstancename>/<workspacename">http://<servername>/<pwainstancename>/<workspacename>" -filename "c:\<backupdir>\<workspacename>" -nofilecompression
    -includeusersecurity
    Hrishi Deshpande – Senior Consultant DeltaBahn
    Blog | < |
    LinkedIn
    Please click Mark As Answer; if a post solves your problem or Vote As Helpful if a post has been useful to you.This can be beneficial to other community members reading the thread.

Maybe you are looking for