5508 HA SSO ping timeout

Hi,
I recently implemented 5508 HA SSO pair running the latest FUS and 7.6.110.0 OS.
The HA Deployment Guide shows 0% ping loss for failover tests, but this pair of 5508s in production have shown up to two ping losses and are consistent for every failover test.
Since the guide makes clear the expectation that not even one ping should be dropped, any suggestions as to where to start looking for an issue. We followed the Deployment Guide instructions. Pings were to the Internet.
Thanks.

Well when testing, how are the pings on the local LAN or a continuous ping to the client?  If you have ping loss during internal LAN test, then there must be an issue.  I wouldn't test from the client to an internet IP. 
Please rate helpful post and Cisco Support Community will donate to Kiva
Scotty

Similar Messages

  • Sso session timeout per partner application

    Hello,
    I was just wondering if it is possible to configure SSO session timeouts per partner application? I'm looking to log out users of a particular application after 15 minutes, but don't want this change to affect any of my other SSO enabled applications. Is this possible?
    Thanks,

    Hi,
    I do not think so, you can not specify specail parameter for one application in SSO.
    Why because SSO is one component (within your Infra) through which you logon different apps.
    Another solution may be it will expensive is that you 'll need to use different infra for this specific application.
    Regards,
    Hamdy

  • Recurring ping timeout to certain IPs every minute

    Hi all,
    Had BT broadband for a month now and have been getting chronic lag when playing online games and surfing the web. The same issue seems to manifest when pinging certain IP addresses using "ping -t" in command prompt. I consistently get two consecutive timeouts every 55-60 seconds to IPs located USA, France and Sweden.
    Here's an image showing what I mean:
    I experience the same issue with two devices, my PC connected using the ethernet cable to a home hub 3.0 (plugged into master socket), and my phone connected wirelessly to the device. I have also tried a different router, a draytek vigor 2800v and have experienced the same issue.
    One thing to note is that not all IP addresses produce this problem. I've performed a tracert to eu.battle.net which is the first server that I noticed the problem with. If I  go down the list and ping each of these addresses in turn, I find that the issue begins at core2-pos1-0-0.telehouse.ukcore.bt.net [62.6.201.86]. However, I go through them in order of least ping, indicating the route that my network packets are following, the issue actually begins at ldn-bb1-link.telia.net [80.91.252.197]. 
    This result is backed up by someone elses findings in a similar thread.
    Here's the full tracert:
    >tracert eu.battle.net
    Tracing route to eu.battle.net [80.239.186.40]
    over a maximum of 30 hops:
    1 <1 ms <1 ms <1 ms BTHomeHub.home [192.168.1.254]
    2 18 ms 18 ms 18 ms 217.32.147.96
    3 18 ms 19 ms 18 ms 217.32.147.126
    4 27 ms 27 ms 27 ms 213.120.181.146
    5 27 ms 26 ms 26 ms 213.120.179.46
    6 26 ms 26 ms 27 ms 213.120.179.182
    7 30 ms 31 ms 30 ms acc2-10GigE-10-2-0.sf.21cn-ipp.bt.net [109.159.251.202]
    8 39 ms 39 ms 39 ms core2-te0-12-0-6.ealing.ukcore.bt.net [109.159.251.135]
    9 37 ms 37 ms 36 ms core2-pos1-0-0.telehouse.ukcore.bt.net [62.6.201.86]
    10 40 ms 40 ms 39 ms t2as2-tge4-3.uk-lon1.eu.bt.net [166.49.214.145]
    11 37 ms 37 ms 36 ms 166-49-211-34.eu.bt.net [166.49.211.34]
    12 36 ms 36 ms 36 ms ldn-bb1-link.telia.net [80.91.252.197]
    13 131 ms 52 ms 52 ms prs-bb1-link.telia.net [80.91.247.6]
    14 54 ms 53 ms 55 ms prs-b8-link.telia.net [213.155.131.7]
    15 * * * Request timed out.
    16 80-239-170-114.customer.teliacarrier.com [80.239.170.114] reports: Destination net unreachable.
    Trace complete.
    I'd appreciate it a lot of someone could look into this. It's ruining some of my games.

    Not sure the issue is with telia. In fact I don't know what's going on but here are my latest findings.
     I was pinging some more addresses and found that www.google.co.uk was also timing out every 60 seconds, so I got this trace route:
    Tracing route to www.l.google.com [209.85.229.105] over a maximum of 30 hops:
    1 <1 ms <1 ms <1 ms BTHomeHub.home [192.168.1.254]
    2 18 ms 18 ms 18 ms 217.32.147.96
    3 91 ms 18 ms 18 ms 217.32.147.142
    4 27 ms 27 ms 26 ms 213.120.181.146
    5 27 ms 27 ms 27 ms 213.120.179.46
    6 26 ms 27 ms 27 ms 213.120.179.182
    7 * 27 ms 27 ms 109.159.251.235
    8 44 ms 43 ms 39 ms core2-te0-13-0-2.ealing.ukcore.bt.net [109.159.251.139]
    9 35 ms 69 ms 34 ms acc1-10GigE-0-5-0-6.l-far.21cn-ipp.bt.net [109.159.254.108]
    10 38 ms 38 ms 38 ms 195.99.126.107
    11 36 ms 82 ms 50 ms 66.249.94.76
    12 35 ms 37 ms 35 ms 209.85.253.92
    13 45 ms 44 ms 44 ms 66.249.95.173
    14 45 ms 45 ms 45 ms 209.85.252.83
    15 47 ms 40 ms 58 ms 209.85.243.85
    16 * * 46 ms 209.85.229.105
    I pinged the IPs and found lines 10 and 11 were timing out every minute. All the IPs after that were non responsive.
    A minute later, I then redid the traceroute and got a different path, and now pinging google is fine and not producing any time outs at all.
    Tracing route to www.l.google.com [209.85.229.104] over a maximum of 30 hops:
    1 <1 ms <1 ms <1 ms BTHomeHub.home [192.168.1.254]
    2 18 ms 18 ms 18 ms 217.32.147.96
    3 18 ms 18 ms 19 ms 217.32.147.126
    4 24 ms 23 ms 23 ms 213.120.181.110
    5 23 ms 24 ms 23 ms 213.120.179.46
    6 23 ms 24 ms 24 ms 213.120.179.182
    7 24 ms 24 ms 24 ms acc2-10GigE-0-2-0.sf.21cn-ipp.bt.net [109.159.25
    1.194]
    8 36 ms 35 ms 35 ms core1-te0-12-0-6.ilford.ukcore.bt.net [109.159.2
    51.133]
    9 59 ms 31 ms 31 ms peer1-xe11-0-0.telehouse.ukcore.bt.net [109.159.
    254.124]
    10 31 ms 32 ms 31 ms 195.99.126.111
    11 29 ms 29 ms 29 ms 66.249.94.78
    12 31 ms 32 ms 32 ms 209.85.253.94
    13 35 ms 35 ms 35 ms 72.14.232.134
    14 40 ms 35 ms 37 ms 72.14.236.191
    15 40 ms 49 ms 53 ms 209.85.243.85
    16 36 ms 58 ms 35 ms ww-in-f104.1e100.net [209.85.229.104]
    Ok so when www.google.co.uk resolves to 209.85.229.104 it's fine, not ping timeouts at all. But when it resolves to 209.85.229.105 I get the 2 ping timeouts every minute or so as I have mentioned previously. 

  • Bridge update to Lollipop fails with "UE ping timeout"

    There was a problem downloading the latest software version for your Xperia device. 
    Description: UE ping timeout
    Sony Bridge 4.0(4003)
    Progress bar stops at 20% when this error happens. Retried 20 times.
    I don't think I'm alone with this problem.

    I suspect that there are some issues in the backend..... I was getting the same error. Would get no more than 20% through before the timeout. Sometimes less. I then tried a Windows machine and it came up with "unable to communicate with sony update engine (error 11)"  errors. Search for the thread "unable-to-communicate-with-sony-update-engine-error-11" (can't provide a direct link) where people are stuggling with it. Some have said various things like reinstalling the software has helped, but I suspect that has been more a coincidence rather than causal.
    Anyhow, I tried the windows software again, but fired up a VPN (using cyberghost, connecting to a US server) and I got past the error 11 issue. Makes me think that the problem may be with whatever physical server(s) is providing the updates in my region (Australia). Will see - can't confirm as the vpn is really slow - at the moment it's estimating 3 hours to download the software..... 
    Oooh - had hit 4 hours and getting worse, so I killed the vpn connection... and now it's dropped down to 20 mins and dropping.... fingers crossed!

  • Ping timeout

    Dear Java users,
    We have a ping timeout exception, could this be related to policies or firewall?
    11:01:31,556 WARN [Connection]: Connection failure:
    org.jboss.mq.SpyJMSException: Connection Failed; - nested throwable: (java.io.IOException: ping timeout.)
    at org.jboss.mq.Connection.asynchFailure(Connection.java:718)
    at org.jboss.mq.Connection$PingTask.run(Connection.java:1311)
    at EDU.oswego.cs.dl.util.concurrent.ClockDaemon$RunLoop.run(ClockDaemon.java:364)
    at java.lang.Thread.run(Thread.java:534)
    Caused by: java.io.IOException: ping timeout.
    at org.jboss.mq.Connection$PingTask.run(Connection.java:1303)
    ... 2 more

    there is no ping timeout in java. as there is no ping facility in java. this is a jboss configuration parameter. consult your jboss manual for such timeouts.

  • WLC 5508 HA-SSO 90-day timer

    Hello everybody
    We have 2 5508 in HA SSO (212licenses + 50permanentfor the secondary)
    it is not clear what is written in the documentations about the 90-day timer 
    – If the new WLC has a higher AP count than the previous, the 90-day counter is reset.
    – If the new WLC has a lower AP count than the previous, the 90-day counter is not reset.
    What about same ap count???
    let's assume the primary goes down and the secondary becomes active...
    the 90-day timer will start (as reported in the docs) and 212 licenses are inherited from primary unit
    now for example after 90 days the secondary controller starts nagging messages and the netadmin notices it, he forces a failover to revert back to the primary controller as the primary has no issues (it was just a failover caused by temporary gateway unreachability)
    so the primary becomes the new active with its original licenses
    The question is :
    what happens to the 90-day timer, does it get reset? 
    if a new failover occurrs will the ap join the backup controller?
    is there any way to show the remaining days for inherited license?
    Thank you

    Thank you Scott
    hope I did understand correctly...
    after 90d you were not able to access the secondary unit anymore... i assume cli was locked too.. so no manual switchover via cli command... (just unplug?)
    you did test a new switchover right?... was the wireless infrastructure still working with config synced with the primary unit?
    then you did a factory reset... rebuilt the secondary unit and had again the 90-day timer not zeroed? (looks like the primary controller is totally unaware of how much time the standby controller was online as primary)
    sorry for the many questions , cisco's documentation about this is really frustrating and I really can't understand why... if I did understand correctly I think this is a really bad behaviour (imho) at least the counter shoud be meant to stop when primary controller comes back online in standby hot state... reboots often happen cause of software failure and someone may never notice a switchover occurred until the timer is over... and we have no way to know how much time is left for the standby controller...

  • Network Load Balancing and IPv6 Ping Timeout

    I've noticed interesting behavior with NLB on Windows 2012 R2 and IPv6. I have two systems that use NLB on a Hyper-V cluster, each system is on a different node in the cluster. When I do an IPv6 ping within the same subnet, I notice that the reply time is
    normally 1-3ms, but every so often it goes to 100+ms. I also notice that both members of the NLB reply to a ping to the cluster IPv6 address. This is interesting.
    When I do a ping to the cluster IPv6 address from a different subnet, I notice that the reply is intermittent. The NLB nodes will either both reply to the ping or both won't. At first I thought that there was an issue with my network, but when I do a span
    on the ports that the cluster is attached to, I see that the IPv6 ping packets arrive, but the NLB nodes don't always send a reply.
    What is also interesting is that the NLB web farm I have setup seem to be working fine and is not intermittent, so this issue only has to do with ping. Has anyone else seen this type of issue, or is this a bug?
    Thanks!

    Hi Nathan,
    So are you running both IPV6 and IPV4? Do you have any clients that can't connect at all? Just on ping?
    The reason I ask is we had a server that was receiving IPV6 fine, but on receiving IPV4 would switch to IPV6 to connect SSL back to the client. Of course the clients never received it and just got a timeout. Funny thing is cell phones had no issue
    at all because they were straight IPV6. Only clients with both protocols got the timeout.
    So the ack was send back via the wrong protocol and nothing but the timeout is what the client sees. This may be an LLMNR issue. It came out from 2008R2 but think it may still apply
    Check this out:
    http://technet.microsoft.com/en-us/library/bb878128.aspx
    David Perkins
    IT Help Point, Inc.

  • WLC 5508 AP SSO FUS Upgrade with different Versions

    Hi everybody,
    I've got two 5508 configured as AP SSO and I want to upgrade the FUS to 1.9.0.0
    The Image running is 7.6.110.0
    On the active controller the FUS Version is 1.3
    On the HA-SKU controller the FUS Version is 1.7
    Now, can I upgrade the FUS to 1.9.0.0 using the GUI, even when both controllers don't use the same FUS Version? If yes, can I go directly from FUS 1.3 to 1.9.0.0?
    thanks a lot,
    marc

    Unfortunately its not possible to upgrade just the standby controller in a AP SSO setup. The Command "transfer" is not available on the controller with the standby role. :-/
    I don't get it, why it's not possible to upgrade either FUS oder Software in a AP SSO setup without downtime. The reason why people use AP SSO is because they have a sensitive wireless environment (24/7) and care about not having some downtime. Hopefully there will give some improvements in future releases in case of downtimes when upgrading.

  • WLC 5508 HA SSO configuration failure

    I've just replaced an older 5508 with two new 5508 controllers that we wanted to run in redundancy mode.  I've followed the directions here: to configure my units.  at this time i have my management, and redundancy management IP addresses configured in the same vlan on both units, also the service port addresses are in the same vlan, and the virtual interface is the same on both units.  I setup the mirrored reference in the redundancy global configuration for redundancy mgmt IP and Peer redundancy mgmt IP on both units.  I have designated the primary and the secondary units.  after doing all of this i connected (with a patch cable) the RP ports on both units.  On either unit i enable the SSO option and get the following message:
    "Please configure Redundancy Management VLAN before enabling redundancy"
    Clicking OK on this disables the option and returns me to the redundancy global configuration page.  I have searched all over and have been unable to find a working resolution for this problem.  I'm not finding much reference to this at all actually.
    Thanks in advance.
    Beer

    I read that but i'm confused as to what it actually means.  I have no redundancy VLAN unless it refers to the network created by the two service port IP addresses.  the devices are setup back to back, and only connect through the RP ports on each device.  here are the steps i took in setting this up.  before taking these steps the primary unit was configured and fully operational and the secondary only had a management ip address on it.  (I expected the secondary to sync it's configuration from the primary so did not set anything up further than needed for connectivity.)
    Log into both controllers using their web interfaces
    Navigate Controller > Interfaces
    Set the Management IP addressBoth units must have the management addresses within the same VLAN
    Set the redundancy-management IP addressBoth units must have the redundancy management address  in the same VLAN as the management interfaces
    Set the Service-port Ip addressBoth units should be setup so their service ports are in the same VLAN
    Set the virtual port IP addressThis should be the same on both units.
    Navigate to Controller > redundancy > Global configuration
    Verify the redundancy mgmt IP is prepopulated with the IP address from the redundancy-Management interface
    Set the Peer redundancy mgmt IPThis is the redundancy management IP Address form the opposing WLC
    On the primary unit set the redundant unit to Primary
    On the secondary unit set the redundant unit to secondary
    Click apply on both units
    Verify physical connection is in place between the RP ports on both WLC units
    Set the SSO option to Enable and click Apply on both units, starting with the primary unitThis will trigger a reboot on each unit after clicking apply.  The redundancy configuration setup will cause both units to reboot 2-3 times as the configuration is synced from the primary unit to the secondary unit
    Did I somehow miss a critical step in this process?

  • VPN conn. to Oracle Db: ping timeout!

    1. I have a VPN connection to a customer in the US.
    2. I am using a remote desktop to work on a first server.
    3. Now I am connecting to a secound database server with Toad.
    But I always get a timeout error.
    Even the ping <ip-address> in DOS-Window return timeouts.
    But this had worked from the US-office, but it doesn't work from Germany.
    Is it a db connection or a network problem?
    Who can help me?

    And what has this to do with Oracle?

  • Ping timeouts at server and broken pipes at client

    I am experiencing unexpected broken pipe exceptions at the client side of a coherence server. These exceptions prevent our code to establish a connection to the cache server.
    Due to network restrictions, we are connecting client and server through Coherence*Extend.
    At the server side, the logs show the following message:
    DEBUG Coherence:3 - 2013-02-01 11:12:20.584/85.322 Oracle Coherence GE 3.7.1.5 <D6> (thread=Proxy:TcpProxyServicePof:TcpAcceptor, member=1): Closed: TcpConnection(Id=0x0000013C953D8F150AA202D9F632E5EAFD6BDDE1A713F026C65BC1E7CC1E5952, Open=false, Member(Id=0, Timestamp=2013-02-01 11:11:44.404, Address=127.0.0.1:0, MachineId=0, Location=site:,process:1612, Role=WeblogicServer), LocalAddress=10.162.2.217:28088, RemoteAddress=10.162.2.231:45202) due to:
    com.tangosol.net.messaging.ConnectionException: TcpConnection(Id=0x0000013C953D8F150AA202D9F632E5EAFD6BDDE1A713F026C65BC1E7CC1E5952, Open=true, Member(Id=0, Timestamp=2013-02-01 11:11:44.404, Address=127.0.0.1:0, MachineId=0, Location=site:,process:1612, Role=WeblogicServer), LocalAddress=10.162.2.217:28088, RemoteAddress=10.162.2.231:45202): did not receive a response to a ping within 500 millis
    at com.tangosol.coherence.component.util.daemon.queueProcessor.service.Peer.checkPingTimeout(Peer.CDB:12)
    at com.tangosol.coherence.component.util.daemon.queueProcessor.service.peer.Acceptor.checkPingTimeouts(Acceptor.CDB:7)
    at com.tangosol.coherence.component.util.daemon.queueProcessor.service.Peer.onNotify(Peer.CDB:115)
    at com.tangosol.coherence.component.util.Daemon.run(Daemon.CDB:42)
    at java.lang.Thread.run(Thread.java:662)
    And at the client side:
    ERROR (01/02/2013) 11:12:20 [threadsafe]Thread-15/AbstractComponentHandler Unable to create new instance 45067 ms
    com.tangosol.net.messaging.ConnectionException: TcpConnection(Id=0x0000013C953D8F150AA202D9F632E5EAFD6BDDE1A713F026C65BC1E7CC1E5952, Open=true, Member(Id=0, Timestamp=2013-02-01 11:11:44.404, Address=127.0.0.1:0, MachineId=0, Location=site:,process:1612, Role=WeblogicServer), LocalAddress=10.162.2.231:45202, RemoteAddress=10.162.2.217:28088)
    at com.tangosol.coherence.component.util.daemon.queueProcessor.service.peer.initiator.TcpInitiator$TcpConnection.send(TcpInitiator.CDB:35)
    at com.tangosol.coherence.component.util.daemon.queueProcessor.service.Peer.send(Peer.CDB:29)
    at com.tangosol.coherence.component.util.daemon.queueProcessor.service.Peer.post(Peer.CDB:23)
    at com.tangosol.coherence.component.net.extend.Channel.post(Channel.CDB:25)
    at com.tangosol.coherence.component.net.extend.Channel.request(Channel.CDB:18)
    at com.tangosol.coherence.component.net.extend.Channel.request(Channel.CDB:1)
    at com.tangosol.coherence.component.net.extend.RemoteNamedCache$BinaryCache.putAll(RemoteNamedCache.CDB:10)
    at com.tangosol.util.ConverterCollections$ConverterMap.putAll(ConverterCollections.java:1708)
    at com.tangosol.coherence.component.net.extend.RemoteNamedCache.putAll(RemoteNamedCache.CDB:1)
    at com.tangosol.coherence.component.util.SafeNamedCache.putAll(SafeNamedCache.CDB:1)
    at com.tangosol.net.cache.CachingMap.putAll(CachingMap.java:1023)
    Caused by: java.net.SocketException: Write failed: Broken pipe
    at jrockit.net.SocketNativeIO.writeBytesPinned(Native Method)
    at jrockit.net.SocketNativeIO.socketWrite(SocketNativeIO.java:46)
    at java.net.SocketOutputStream.socketWrite0(SocketOutputStream.java)
    at java.net.SocketOutputStream.socketWrite(SocketOutputStream.java:92)
    at java.net.SocketOutputStream.write(SocketOutputStream.java:136)
    at java.io.BufferedOutputStream.flushBuffer(BufferedOutputStream.java:65)
    at java.io.BufferedOutputStream.write(BufferedOutputStream.java:104)
    at java.io.DataOutputStream.write(DataOutputStream.java:90)
    at com.tangosol.coherence.component.util.daemon.queueProcessor.service.peer.initiator.TcpInitiator$TcpConnection.send(TcpInitiator.CDB:27)
    at com.tangosol.coherence.component.util.daemon.queueProcessor.service.Peer.send(Peer.CDB:29)
    at com.tangosol.coherence.component.util.daemon.queueProcessor.service.Peer.post(Peer.CDB:23)
    at com.tangosol.coherence.component.net.extend.Channel.post(Channel.CDB:25)
    at com.tangosol.coherence.component.net.extend.Channel.request(Channel.CDB:18)
    at com.tangosol.coherence.component.net.extend.Channel.request(Channel.CDB:1)
    at com.tangosol.coherence.component.net.extend.RemoteNamedCache$BinaryCache.putAll(RemoteNamedCache.CDB:10)
    at com.tangosol.util.ConverterCollections$ConverterMap.putAll(ConverterCollections.java:1703)
    at com.tangosol.coherence.component.net.extend.RemoteNamedCache.putAll(RemoteNamedCache.CDB:1)
    at com.tangosol.coherence.component.util.SafeNamedCache.putAll(SafeNamedCache.CDB:1)
    at com.tangosol.net.cache.CachingMap.putAll(CachingMap.java:1023)
    I can ping the client machine from the server without a problem.
    Has anybody seen this before?
    Edited by: 982740 on Feb 1, 2013 2:29 AM

    Hi user,
    It seems from the log that when the proxy node accepts your client connection the client fails to respond to a ping request down the same pipe. Does this happen consistently? If so, no putAll would ever succeed.
    I have to admit I've never seen this behaviour before. I can't see how this would be a firewall port issue, as the connection has been established... the only things I can think of would be a) your weblogic client node is running way to hot and doesn't respond to the grids ping request in time, b) Some very aggressive network infrastructure is killing the connection just after its created, or c) aliens are interfering with your system.
    sorry I can't be of more help,
    Andy

  • First ping probe timeout

    Hello,
    May be silly question but...
    When I check connectivity between two neighbour Cisco devices (routers and switches) using standart ping command with default parameters, I frequently see, what first ping probe is timeout and next four are successfull
    I suppose what on Ethernet links this is due ARP mechanism. But default ping timeout 2s, ARP Requst/Reply roundtrip on 100 Mbit/s Ethernet is ~ 100 us (I have observed with analyzer).
    The same situation on serial point-to-point links, where no ARP exists.
    Any Idea, why first ping probe is timeout?
    Also I have found this question in Cisco BCMSN Course LAB Guide
    On some pings, there was one lost packet (.) and then four good packets. You should know why that occurred.
    Best Regards,
    Tomas

    Tomas
    To understand this behavior I suggest that you start with show arp and look for the destination that you will ping. Then run debug arp and debug ip icmp. Then try the ping. This should help to clarify what the router does if the destination is not in the arp table and how that impacts the first ping.
    HTH
    Rick

  • 5508 MC with 3650 MA L2 roaming problem

    Hello,
    I am testing L2 roaming on an open SSID between 3650 (MA) and 2 x 5508 in SSO (MC).
    The output of the show wireless mobility summary on the 3650 is :
    3650-ERM-LT1#show wireless mobility summary
    Mobility Agent Summary:
    Mobility Role                                   : Mobility Agent
    Mobility Protocol Port                          : 16666
    Mobility Switch Peer Group Name                 : 3650-ERM-LT1
    Multicast IP Address                            : 0.0.0.0
    DTLS Mode                                       : Enabled
    Mobility Domain ID for 802.11r                  : 0x6549
    Mobility Keepalive Interval                     : 10
    Mobility Keepalive Count                        : 3
    Mobility Control Message DSCP Value             : 0
    Switch Peer Group Members Configured            : 1
    Central Management                              : Disabled
    Link Status is Control Link Status : Data Link Status
    The status of Mobility Controller:
    IP              Public IP            Link Status
    172.17.1.1      172.17.1.1           UP   : UP
    Switch Peer Group members:
    IP              Public IP            Data Link Status
    172.17.27.1     172.17.27.1          N/A
    The output of show mobility summary on 5508 is :
    (WLC5508-MAR-1) >show mobility summary
    New Mobility (Converged Access).................. Enabled
    Mobility Protocol Port........................... 16666
    Default Mobility Domain.......................... mobility
    Multicast Mode .................................. Disabled
    DTLS Mode ....................................... Enabled
    Mobility Domain ID for 802.11r................... 0x6549
    Mobility Keepalive Interval...................... 10
    Mobility Keepalive Count......................... 3
    Mobility Group Members Configured................ 1
    Mobility Control Message DSCP Value.............. 0
    Mobility Oracle.................................. Disabled
    Mobility MC public IP ........................... 172.17.1.1
    Mobility Oracle IP address ...................... 0.0.0.0
    Controllers configured in the Mobility Group
     IP Address       Public IP Address       Group Name         Multicast IP  MAC Address               Status
     172.17.1.1       172.17.1.1              mobility           0.0.0.0       f4:cf:e2:94:c0:00          Up
    Switch Peer Group Configuration:
      Switches configured in Switch Peer Group: 3650-ERM-LT1
     IP Address           Public IP Address    Status
        172.17.27.1           172.17.27.1          Up
    So the mobility domain ID is the same.
    The show wlan id :
    On 3650 :
    3650-ERM-LT1#sh run wlan testNXO
    wlan test 6 TEST
     no broadcast-ssid
     no mobility anchor sticky
     no security wpa
     no security wpa akm dot1x
     no security wpa wpa2
     no security wpa wpa2 ciphers aes
     session-timeout 1800
     no shutdown
    On 5508 :
    WLAN Identifier.................................. 6
    Profile Name..................................... test
    Network Name (SSID).............................. TEST
    Status........................................... Enabled
    Broadcast SSID................................... Disabled
    AAA Policy Override.............................. Disabled
    Exclusionlist Timeout............................ 60 seconds
    Session Timeout.................................. 1800 seconds
    User Idle Timeout................................ Disabled
    Sleep Client..................................... disable
    Sleep Client Timeout............................. 720 minutes
    User Idle Threshold.............................. 0 Bytes
    NAS-identifier................................... WLC5508-MAR-1
    CHD per WLAN..................................... Enabled
    I enabled fast-ssid-change on both side.
    So, on both side :
    - mobility domain and bridge domain ID are the same
    - WLAN settings are the same
    The coverage area for my test is OK.
    The wireless management interface on both 3650 and 5508 is on the same VLAN (172.17.0.0 /16).
    I test with android smartphone and windows laptop.
    The WLC version : 8.0.115.0
    The 3650 version : 03.07.00E
    Others elements to check ?
    From the config guide I don't see what I miss :
    http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3650/software/release/3se/mobility/configuration_guide/b_mobility_3se_3650_cg/b_mobility_3se_3650_cg_chapter_01001.html

    Going forward this setup not going to be supported. ie you cannot make 5508 (or AireOS) controller as MC for 3850/3650 MA. In AireOS 8.1 code this support is not there, so better to get a 5760 if you want a dedicated MC in converged access.
    Still you should be able to have roam between 5760 & 5508 set up in same mobility group.
    If you have to go ahead with this testing, first try to do it with single 5508 (without SSO) & see. I would suggest 3.6.2aE for 3650 ( 3.7 is latest, but there may be unknows issues)
    HTH
    Rasika
    *** Pls rate all useful responses ***

  • VPN connection works, but can't ping or access any other device on remote network

    I have an OS X Lion server at work (uses a static IP of 192.168.2.10). VPN is setup and works.
    The work network's router has an IP of 192.168.2.1 and hands out IPs of 192.168.2.100-149. The VPN service is configured to hand out IPs of 192.168.2.150-170.
    My home network uses a router with an IP of 192.168.1.1 and hands out IPs from 192.168.1.2-49
    Both routers are using subnet mask of 255.255.255.0
    The problem is, I can connect to the VPN just fine and access all services running on that same OS X server like iChat and AFP file sharing. But, I cannot directly access any other device on the office network like client machines or even trying to log into the router's GUI interface. Pings timeout, etc.
    Example:
    At my home, I have a local IP of 192.168.1.12 and I connect to the work VPN. It assigns me an IP address of 192.168.2.151 and I'm able to connect to iChat on the OS X server that has a static IP of 192.168.2.10
    In terminal, I try to ping the router on the work network (192.168.2.1) and I get no response (even though ICMP response is turn ON). I try to ping another OS X workstation on the work office, and get no response.
    I'm not sure how to fix this, or whether I need to change settings on either router or the server.
    Would greatly appreciate any insight or help on this. Thanks.

    danimalapple wrote:
    I have an OS X Lion server at work (uses a static IP of 192.168.2.10). VPN is setup and works.
    The work network's router has an IP of 192.168.2.1 and hands out IPs of 192.168.2.100-149. The VPN service is configured to hand out IPs of 192.168.2.150-170.
    My home network uses a router with an IP of 192.168.1.1 and hands out IPs from 192.168.1.2-49
    Both routers are using subnet mask of 255.255.255.0
    The problem is, I can connect to the VPN just fine and access all services running on that same OS X server like iChat and AFP file sharing. But, I cannot directly access any other device on the office network like client machines or even trying to log into the router's GUI interface. Pings timeout, etc.
    Example:
    At my home, I have a local IP of 192.168.1.12 and I connect to the work VPN. It assigns me an IP address of 192.168.2.151 and I'm able to connect to iChat on the OS X server that has a static IP of 192.168.2.10
    In terminal, I try to ping the router on the work network (192.168.2.1) and I get no response (even though ICMP response is turn ON). I try to ping another OS X workstation on the work office, and get no response.
    I'm not sure how to fix this, or whether I need to change settings on either router or the server.
    Would greatly appreciate any insight or help on this. Thanks.
    Check the DNS settings on the server (see my earlier post in this thread).

  • STMS distribution error - timeout during allocate / CPIC-CALL: 'ThSAPCMRCV'

    Hello All
    i am trying to confugreu STMS but i am facing this error when i am tryin to distribute the same,
    System   EC2              Command  TMS_PM_DISTRIBUTE_PROFILE
    Client   000              Service  tp Profile Service
    User     TMSADM           Start    Online
    Date     20.10.2009       Function TMS_PS_WRITE_PROFILE_TO_DISK
    Time     17:36:23         Message  SET_CODEPAGE_FAILED
    description : Could not start transport control program tp
    detail error is as below if i press on more information
    Could not start transport control program tp
    Message no. TP608 Diagnosis
    There was an attempt to start the transport control program tp using the local RFC interface. An error occurred here.
      Error code: 4
      RFC error text: timeout during allocate / CPIC-CALL: 'ThSAPCMRCV'
    Meaning of the error codes:
      03  RFC system failure
      04  RFC communication failure
    System Response
    The function terminates. Details about the error can be found in the trace file of the Gateway Monitor (SMGW).
    some of the posts on forum suggested i should try from same domain i tried but in vain, then i updated the SAP kernel from 7.01 sp 14 to sp 55. but i am still facing the problem.
    i created this system recently using system copy based upon export image of a system (ABAP stack ) but using ABAP+Java during export process (by mistake). then we tried to build system using import (ABAP stack only i know its weird but its up and running). I assume we should have builf export imgae using ABAP method but some how due to lack of time we proceeded this way.
    The main problem i see is TP RFC . The output from prgram RSTPTEST is as below
    everythign is fine except below entries
    under RFC destination
    EFC ping - timeout during allocate / CPIC-CALL: 'ThSAPCMRCV' : cmRc=20 thRc=456#Time out during connection setup (check  that partner exists
    under TP call
    RFC link and Offline Call shws me the same error as RFC ping. and there is no output from tp version and DB connect.
    Can anybody please help me on the same.
    Mani

    Hello All,
      thanks a lot for you reply, i want to clear some point here
    - I have no other physical attached to the system, i created other system as virtual system.
    - to Sunny - i allready went through that thread and upgraded my Kernel also accordign to thread but problem still persist.
    - to Anil .. i did as u said but nothing changed after that.
    here is the log from trans log file
    4 ETW000 r3trans.exe version 6.14 (release 701 - 12.06.09 - 15:20:00).
    4 ETW000 unicode enabled version
    4 ETW000 ===============================================
    4 ETW000
    4 ETW000 date&time   : 20.10.2009 - 17:37:33
    4 ETW000 control file: <no ctrlfile>
    4 ETW000 R3trans was called as follows: r3trans.exe -d
    4 ETW000  trace at level 2 opened for a given file pointer
    4 ETW000  [dev trc     ,00000]  Tue Oct 20 17:37:37 2009                                               12584  0.012584
    4 ETW000  [dev trc     ,00000]  db_con_init called                                                        65  0.012649
    4 ETW000  [dev trc     ,00000]  create_con (con_name=R/3)                                                401  0.013050
    4 ETW000  [dbcon.c     ,00000]  *** ERROR => Invalid profile parameter dbms/type (or environment variable dbms_type) = <undef>, cannot load DB library
    4 ETW000                                                                                160  0.013210
    2EETW169 no connect possible: "connect failed with DBLI_RC_LOAD_LIB_FAILED."
    i have dbms/type = mss in profile parameters
    I am still getting the same error.
    Mani

Maybe you are looking for

  • How to release function module...

    Hi All,    I have created one function module and activated that. How to release that function module?   But Release option is in deactive state...how can i release the FM....please let me know the resons for that. thank you.

  • Problem in date functions

    Using: Jdev 11.1.1.5.0-adfbc problem description: problem in function not properly working Resource: this is my vo query which is based on one eo SELECT LegalDocDetailsEO.LDD_BE,        LegalDocDetailsEO.LDD_UNIT,        LegalDocDetailsEO.LDD_SUPLR_I

  • IPod touch library to new MacBook Pro

    Previous computer was stolen so I do not have access to it. My iPod touch has over 1,000 songs, only some of which were purchased on iTunes. Does anyone know how I can get my ENTIRE iPod touch library into my new MacBook Pro iTunes library? Thanks fo

  • IMovie Quality Playback

    I have made several iMovies and the quality is terrible. My pictures are 5 Megapixel or 2580 x 1950 when I drag them to the time line and play back full screen on my 20 inch Mac Cinema Display; all the curved or diagonal edges of people and objects a

  • Batch No range assignemnt to Claaisfication

    Dear SAP experts, I have three probems related to batch management : 1. Multi class selection in material master for class type 23 (batch) 2.Batch no should be generated class wise.     If I select class "size"   batch no should be 00000100001     If