6807-XL - Control plane interface showing down in logs and NMS
Getting the below logs on the switch and NMS station is also showing the CPP interface is down.
Jul 01 12:09:55: %LINEPROTO-5-UPDOWN: Line protocol on Interface Control Plane Interface, changed state to down
Any thoughts?
Getting the below logs on the switch and NMS station is also showing the CPP interface is down.
Jul 01 12:09:55: %LINEPROTO-5-UPDOWN: Line protocol on Interface Control Plane Interface, changed state to down
Any thoughts?
Similar Messages
-
Canon HF11 not showing up in log and transfer window
I am using FC Studio 6.0.6 and a Canon HD USB camera. The camera does not show up in the log and transfer window. It shows up on the desktop, works with iMovie '09 but not FCP. If I try to select files from the camera they are greyed out. Strange thing is is that it works fine on my iMac just not my MBP. I have trashed the FCP and Quicktime preferences but this did not help. HELP please.
I also am wondering what you mean by "file structure"? Do you mean the AVCHD files or something in FCP?
If you look for a particular file on a drive, there's a file structure or "path" to get to it. For instance;
Macintosh HD > Users > Nick > Documents > FCP > Projects > My latest project.
If I don't follow that path, I won't get to the file I am looking for.
Similarly, Final Cut Pro is expecting to see a certain path to the actual video files on your camera's Flash drive. If a folder name along the way is missing or had it's name changed, the path is no longer valid. -
Control-plane protection| soft ware hardware counters
Hi everybody
Today I noticed something stange at work. I was looking at how we implemented a policy to drop ICMPS hitting our processor after certains constraints are met.
cisco#show running-config | begin control-plane
control-plane
service-policy input copp-aggregated
+++++++++++++++++++++++
Policy defination:
policy-map copp-aggregated
class cpp-icmp
police cir 5000000 bc 93750 be 187500 conform-action transmit exceed-action drop violate-action drop
class-map match-all cpp-icmp
match access-group name cpp-icmp
cisco#show ip access cpp-icmp
Extended IP access list cpp-icmp
10 permit icmp any any (156222580 matches)
++++++++++++++++++++++++++++++
cisco#show policy-map control-plane
Control Plane Interface
Service-policy input: copp-aggregated
Hardware Counters:
class-map: cpp-icmp (match-all)
Match: access-group name cpp-icmp
police :
5000000 bps 93000 limit 93000 extended limit
Earl in slot 5 :
5295068971 bytes
5 minute offered rate 9528 bps
aggregate-forwarded 5259145173 bytes action: transmit
exceeded 35923798 bytes action: drop
aggregate-forward 9936 bps exceed 0 bps
Software Counters:
Class-map: cpp-icmp (match-all)
99672582 packets, 14936584392 bytes
5 minute offered rate 11000 bps, drop rate 0 bps
Match: access-group name cpp-icmp
police:
cir 5000000 bps, bc 93750 bytes, be 187500 bytes
conformed 99672950 packets, 14936253164 bytes; action: transmit
exceeded 289 packets, 422518 bytes; action: drop
violated 0 packets, 0 bytes; action: drop
conformed 13000 bps, exceed 0 bps, violate 0 bps
+++++++++++++++++++++++++++++++++++
I can see " software counters' just show the constraints defined under policy " copp-aggregated", how did we end up with hardware counters ?
Hardware counters shows " 5000000 bps 93000 limit 93000 extended limit" which we never defined that anywhere.
I appreciate your help
ThanksBTW, don't know why but the **** above should have read k - n - o - b. Probably the decorum police checking in...
-
Hi,
I did configuration for CCP on sw 4500 but it do the process cpu to grow up. On normal case the process is about 25% but when i configure the policy for control plane the cpu is about 40% and has peaks over 80%.
Please help me
thanks.Hi!
It interested for me too! -
Hi Everyone!
What will be if delete Control-plane from Cisco route?I doubt its got anything to do with the control plane of the router. As the control plane is not a link of any sort. It is like brain of the router and helps perform routing related functions.
Can you check show log on the router around the time the issue occurred? Control plane may manage some interface states like PPP, LACP etc. Check the router logs, it may point you what exactly is happening and you can address the issue accordingly.
-Terry -
i just received my i phone 4,inserted Amayim with 4G plan,but showing noservice and bar with emergency calls only screen.Also when i down loaded i tunes to my laptop (windows7) there is an error(9808) message saying i tunes store not supported completely.
first of all the iphone 4 is not a 4G phone
second it sounds like your iphone could be locked to another operator then the sim you have inserted -
Lacp port channel shows down on one 5k
I got one side of my lacp port channel down.
the topology is shown but the left side is showing down
20 Po20(SD) Eth LACP Eth1/5(s) Eth1/6(s)
# sh int port-channel 20
port-channel20 is down (No operational members)
Hardware: Port-Channel, address: 547f.eebb.644d (bia 547f.eebb.644d)
Description: **To-VA-7004**
MTU 1500 bytes, BW 100000 Kbit, DLY 10 usec
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA
Port mode is trunk
auto-duplex, 10 Gb/s
Input flow-control is off, output flow-control is off
Switchport monitor is off
EtherType is 0x8100
Members in this channel: Eth1/5, Eth1/6
Last clearing of "show interface" counters never
30 seconds input rate 80 bits/sec, 0 packets/sec
30 seconds output rate 176 bits/sec, 0 packets/sec
Load-Interval #2: 5 minute (300 seconds)
input rate 112 bps, 0 pps; output rate 288 bps, 0 pps
RX
4286 unicast packets 785765 multicast packets 1493093 broadcast packets
2283144 input packets 248607161 bytes
13 jumbo packets 0 storm suppression bytes
0 runts 0 giants 0 CRC 0 no buffer
0 input error 0 short frame 0 overrun 0 underrun 0 ignored
0 watchdog 0 bad etype drop 0 bad proto drop 0 if down drop
0 input with dribble 0 input discard
0 Rx pause
TX
0 unicast packets 3397636 multicast packets 0 broadcast packets
3397636 output packets 399463036 bytes
0 jumbo packets
0 output errors 0 collision 0 deferred 0 late collision
0 lost carrier 0 no carrier 0 babble 0 output discard
0 Tx pause
2 interface resets
sh run interface port-channel 20 membership
!Command: show running-config interface port-channel20 membership
!Time: Mon Feb 2 23:04:37 2015
version 5.1(3)N2(1b)
interface port-channel20
description **To-VA-7004**
switchport mode trunk
switchport trunk allowed vlan 1,200-202,251
interface Ethernet1/5
description **TO-VA-7004-ETH3/45**
switchport mode trunk
switchport trunk allowed vlan 1,200-202,251
channel-group 20 mode active
interface Ethernet1/6
description **To-VA-7004-ETH4/46**
switchport mode trunk
switchport trunk allowed vlan 1,200-202,251
channel-group 20 mode active
but on the right side everything is up,
20 Po20(SU) Eth LACP Eth1/5(P) Eth1/6(P)It seems have a problem on interfaces => 20 Po20(SD) Eth LACP Eth1/5(s) Eth1/6(s)
Can you share us the status about interfaces 1/5 - 6 & 3/45, 4/45 of 7k?
Do you have configured per Ethernet interfaces or on the Po ? -
I'd like to understand where the IP control & forwarding planes resides within the Cisco MDS 9000 Family 14/2-port Multiprotocol Services Module. Due to the low number of GE interfaces per card and for resilience, if FC to IP conversion takes place on one card but the egress GE is unavailable - can the architecture tolerate IP switching to another card and GE port in the same chassis and if so can an IP Routing protocol be used between MDS9506's to determine that as the best contingent path ?
Hi Meaton,
If I understand your topology correctly, you have one GE connection to the remote MDS and one to the local MDS.
1) No, fcip tunnel goes down, if the related GE port goes down.
For the fcip, first you need to configure an fcip profile such as :
fcip profile 1
ip address 100.100.100.7 >>ip add. of the GE int.
then the related fcip interface :
interface fcip1
no shutdown
use-profile 1
peer-info ipaddr 100.100.100.2
"peer-info" here is the ip address of the GE interface of the remote MDS.
In your case, if the DWDM goes down meaning the remote GE becomes down, FCIP tunnel which is established on this interface goes down.
As long as you have the ip connectivity between
the mds switches, your fcip tunnel will remains up.
2) It is the same, if you use two separate cards as well. -
How to map,e.g. conceptual control plane to physical element?
Route processor = control plane (customer, provider) in layer 3
Line card = data plane in layer 2& layer 3
where is management plane?
ThanksHi
When you configure MP you can see the logging for same . The log you will get
Aug 2 15:25:32.846: %CP-5-FEATURE: Management-Interface feature enabled on Control plane
host path
It shows that the MP work over Control plane. Means in Route processor the MP will take palce.
Regards
Chetan Kumar -
Fastethernet port showing down down
Hi guys,
I have a port on my switch that always shows down.
#show interfaces fastEthernet 1/0/19
FastEthernet1/0/19 is down, line protocol is down (notconnect)
Hardware is Fast Ethernet, address is 001e.f686.dd15 (bia 001e.f686.dd15)
Description: IP Phone & PC Port
MTU 1500 bytes, BW 10000 Kbit, DLY 1000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Auto-duplex, Auto-speed, media type is 10/100BaseTX
input flow-control is off, output flow-control is unsupported
ARP type: ARPA, ARP Timeout 04:00:00
Last input 6w3d, output 00:10:24, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 15
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
11189035 packets input, 8414542539 bytes, 0 no buffer
Received 103348 broadcasts (27165 multicasts)
0 runts, 0 giants, 0 throttles
1 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog, 27165 multicast, 0 pause input
0 input packets with dribble condition detected
Regards,
Norman D.Hello Norman
This is saying it even nothing is attached to that port or something physical is wrong -Please check your connections - cabling/sfp's/ ports.
res
Paul
Please don't forget to rate this post if it has been helpful. -
Hello,
I'm attempting to limit what IP addreses can connect to an ASA using the SSL VPN. I would have thought control-plane policing would have worked, however it did not.
Here is what I configured:
access-list vpn_control extended permit tcp object-group allowed_clients interface outside
access-group vpn_control in interface outside control-plane
any suggestions would be appreciated.
Thanks!I'm having a problem which I think is described here. I would essentially like to whitelist networks for ssl anyconnect vpn access. I understand that the anyconnect client would attempt a connection to my outside interface on 443 and that it would be considered "to the box traffic" which would bypass the interface ACL's. I set up an acl to deny traffic from a specific test network to test the control plane option. At first I tried 443 traffic and later expanded it to a deny any from the external network, but in either case I was still able to VPN to the asa from this test network using the anyconnect client. I assume this has something to do with management traffic having priority and not distiguishing between managment traffic destined for /admin and ssl vpn connections. However, I do not have the outside interface enabled as a management interface, so even that is a little puzzling.
access-list outside_access_in_1 extended deny ip object test_network any
access-list outside_access_in_1 extended permit ip any any
access-group outside_access_in_1 in interface outside control-plane
If I do a packet trace for 443 traffic from that network to my outside interface IP it does show the traffic passing and the ACL section specifically shows it passing via implicit rule... -
Data Control does not show POJO returned from method
Hi,
I am running JDev 11.1.1.7. In my AppModule.impl I created a method that returns a simple POJO (which implements serializable) that has two String fields. I have exposed the method in the appmodule client interface. In the data control the method shows up with a return element instead of an object or any way to access the two String fields. I want to display the two String fields in separate output text components on my jspx page. I'm not finding documentation on how to do this. Can somebody point me to documentation or tell me how to make this change to the data control method return?
Thanks in advance,
SteveAM method can return custom type, but AFAIK there is no support for object introspection in design time.
(so you can invoke this programmatically and cast to appropriate type, but you can't do DnD from Data Control pane).
So, option 1 is to bind value property of your outputText fields to managed bean, programmatically call AM method, fill these properties manually and refresh your UI components(note that managed bean must be registered in viewScope or higher to preserve values)
Option 2 is to create Bean DataControl (with this you will have DnD support)
Dario -
Hi there,
I'm trying to figure out how to determine and how to differentiate between control plane and data plane especially in troubleshooting MPLS VPN. Any keyword that distinguish between them? It seems to be confusing for a newbie here :)
Thanks in advance.
maherHi Maher,
The control plane is simply the set of processes that are responsible for disseminating information on routes, labels etc within a network. This includes routing protocols whose job is to communicate information on routes between different routers. The information provided by these protocols is then used to building routing/forwarding tables.
The data plane is simply an abstraction used to describe the actual flow of data packets using paths determined by the control plane. The control plane traffic carries control traffic (which is not end-user data) whereas the data plane traffic is actual end-user data.
There is no single command that you can use to distinguish between the two. The commands you have on a router that can be used to view control plane operation are as such:
sh ip route
sh ip cef
sh ip bgp ...
sh ip ospf ...
sh mpls forwarding-table...
etc... and many, many more
Typically, there isn't a clear demarcation between commands that display control plane info and those that display data plane information... You could use commands such as the following to get some idea of data traffic flowing through a router:
sh interfaces
sh policy-map interface
etc.
Hope that helps - pls rate the post if it does.
Paresh -
IOS XR Interface up/down trap
For interface up/down trap
In IOS it used to be:
Generic: 2; Specific: 0; Enterprise: .1.3.6.1.6.3.1.1.5;
Variables:
[1] mgmt.mib-2.interfaces.ifTable.ifEntry.ifIndex.34 (Integer): 34
[2] mgmt.mib-2.interfaces.ifTable.ifEntry.ifDescr.34 (OctetString): POS2/1/0
[3] mgmt.mib-2.interfaces.ifTable.ifEntry.ifType.34 (Integer): 171[4] private.enterprises.cisco.local.linterfaces.lifTable.lifEntry.locIfReason.34 (OctetString): Keepalive failed
Annotations:
In IOS XR we are missing ifDescrThanks Joe.
This solves the problem.
One more question. we do not see LDP traps coming from the XR router.
here is the config; when i enable LDP traps it just does not show up in the config:
snmp-server host 10.10.141.253 traps ovadmin
snmp-server view N ip included
snmp-server view N system included
snmp-server view N cpwVcMIB included
snmp-server view N entityMIB included
snmp-server view N interfaces included
snmp-server view N cpwVcMplsMIB included
snmp-server view N mplsTeStdMIB included
snmp-server view N ciscoCBQosMIB included
snmp-server view N ciscoPingEntry included
snmp-server view N ciscoProcessMIB included
snmp-server view N ciscoMemoryPoolEntry included
snmp-server view N ciscoEnhancedMemPoolMIB included
snmp-server community admin RO
snmp-server community admirw RW
snmp-server traps snmp
snmp-server traps config
snmp-server traps entity
snmp-server location Y
snmp-server trap-source MgmtEth0/8/CPU0/0
Tried to enable it:
RP/0/8/CPU0:P1(config)#snmp-server traps mpls ?
frr Enable MPLS FRR traps
l3vpn Enable MPLS L3VPN traps
ldp Enable MPLS LDP traps
traffic-eng Enable MPLS TE traps
RP/0/8/CPU0:P1(config)#snmp-server traps mpls ldp ?
down Enable MPLS LDP session down traps
threshold Enable MPLS LDP threshold traps
up Enable MPLS LDP session up traps
RP/0/8/CPU0:P1(config)#snmp-server traps mpls ldp ?
down Enable MPLS LDP session down traps
threshold Enable MPLS LDP threshold traps
up Enable MPLS LDP session up traps
RP/0/8/CPU0:P1(config)#snmp-server traps mpls ldp down ?
RP/0/8/CPU0:P1(config)#snmp-server traps mpls ldp down
RP/0/8/CPU0:P1(config)#snmp-server traps mpls ldp up
RP/0/8/CPU0:P1(config)#commit
RP/0/8/CPU0:P1(config)#end
does not show up in the config. -
Control-plane policing on ML Card
Hi All,
We are experiencing high CPU utilization on one of our ML Card in the ONS 15454. The "IP Input" has relatively higher CPU utilization consumed irrespective of the proper fast/CEF switching enabled on the interfaces. We are trying to figure out,whether there is an attack to the control-plane or even any IP Packets destined local to the ML Card,which is causing those packet to process switched.
In order to figure that,we thought we may try to use Control plance policing on the control-plane but it seems not taking the service-policy associated with that. Is this feature supported in the ML card or any other suggestion would be really appreciated.
Thanks
Regards
Anantha Subramanian NatarajanTry the "clear ip mroute" command on the ML card with high cpu usage and check for the issue. Ml card having a large number of mac address traffic can also cause high cpu usage.In very large bridged networks, which may connect directly to 1000s of layer-3 devices, it may also be wise to increase the MAC table limit above the default of 1000 MAC addresses. This is done with the configuration command:
bridge X limit dynamic entries 10000
Maybe you are looking for
-
What videos can i put onto my 30gb ipod? AVI's do not appear when i ...
What type of videos can i put onto my ipod? I tried putting .avi's by dragging them into the itunes movies area but it doesnt work , i also tried adding it through file... Please help .
-
Hi everyone, Please see below for customer requirement and please advise on which of the products will be appropriate. Specification: · Estimated 300 concurrent application users · 2 application servers seating behind the load balance
-
PC Suite detecting in 'non-compatible' mode
I updated the PC Suite today. Now the PC Suite fails to connect to E71 in PC Suite mode. It keeps saying the phone has been connected in 'non-compatible mode'.
-
Paid for my creative cloud photoshop and it won't download
paid for my creative cloud photoshop and it won't download
-
I am overseeing several small Win 8.1 Tablets. They used Wimboot to optimize their disks. When they came out of the box, they had 5.24 GB (of 8.77GB) free. Updating Windows Defender dropped this down to 4.84GB. The Primary partition says that it is a