Applying a service policy on an ACE vlan
Hi All
Our ACE is held at a remote site and i just want to apply a Service policy on the client vlan which is also
our mgmt/access vlan.
As i am new to ACE s i thought i would run it past you guyst before i apply it - I am not going to lose
connectivity to my ACE am i -
Heres the Service policy -
policy-map multi-match CLIENT-VIPS
class VIP-150
loadbalance vip inservice
loadbalance policy lb-logic
class-map match-all VIP-150
2 match virtual-address xx.xx.xx.150 any
I was going to apply it on vlan 121
int vlan 121
service-policy input CLIENT-VIPS
Now the way i read it
- it should only affect access to the virtual address specified
Its not going to cut off my access to the ACE by only allowing
that address through is it ?
Could be a career damaging move if so for me
Thanks for your advice
Steve
Hello Steve,
If you are not modifying the MGMT class or policy, you do not need to worry about, like you mentioned, this LB policy is just intended to allow connections to that VIP, nothing else.
As always it is a good practice to not apply this during production time, as well you can create a test context, where you can test all this without using the production context, so you can play safe and learn at the same time.
Thanks, hope this help.
Similar Messages
-
Error while applying the Service Policy
Hi,
I am getting the below error while applying the service policy to the Interface.
I have set the mpls exp 4 as well as want to limit the bandwidth to 1Mbps
PE#sh policy-map setexp-GBoIP
Policy Map setexp-GBoIP
Class GBoIP-traffic
set mpls experimental imposition 4
police cir 1024000 bc 32000
conform-action transmit
exceed-action drop
PE(config-if)#int vlan 2007
PE(config-if)#service-policy input setexp-GBoIP
QoS-ERROR: Addition/Modification made to policymap setexp-GBoIP and class GBoIP-traffic is not valid, command is rejected
As well as I have created new clas--map with priority and Bandwidth and applied in output direction, I got the belwo error while applying the Service policy in
PE(config-if)#service-policy out TEST
bandwidth command is not supported in output direction for this interface
PE(config-if)#service-policy output TEST
priority command is not supported in output direction for this interface
Any idea why so ?
Thanks in Advance.
Regards,
NileshCheck the current value of IGW_AWARDS_S sequence and make sure the MINVALUE in the patch (i.e. 10000) is not greater than the current one.
OERR: ORA 4007 MINVALUE cannot be made to exceed the current value (Doc ID 19824.1)
You may also log a SR.
Thanks,
Hussein -
On our ASA 5510, I've got the global default-inspection policy enabled and pretty much unchanged since installing the firewall.
However, I created a new interface policy that rate-limtis (police) inboud traffic to our internal proxy server. Just slowing down the internet traffic our users are creating.
The new interface policy I created is applied to the inside interface.
I'm just nervous that applying that new interface policy has made our firewall less secure beings it says "Interface policies overwrite the global_policy". If I still have the global default-inspection policy enabled, and this new interface policy only applied to the inside interface, I'm still ok inspection wise with outside traffic coming in aren't I?The default inspection policy-map doesn't really add much to your security policy as its only concerned with opening dynamic ports through the firewall and handling embedded IP addresses which need to be translated (e.g. NetBIOS).
The only adverse effect could be certain protocols will no longer work between interfaces. Although generally inside traffic (security level 100) is permitted anyway so you should be fine.
Regarding your policing config, you might want to rate-limit in the input direction on the outside interface or the output direction on the interface facing either the proxy server or internal users. The idea is to limit the return traffic as this is what actually consumes the most bandwidth when people are browsing the web. -
My ISP has said they will set up their side to give 50% policed real time traffic and 30% for our application traffic burstable then 5% anything else burstable. The QOS below is my attempt to do this but I was advised that to apply it to the Dialer 1 interface I hade to create a second policy-map (ADSLOut) which had the class-default and the child policy (QOSADSL) within that.
When I did this I can't apply it to the Dialer 1 interface but if I use the child policy then it will allow me to apply that, will this work the same way.
class-map match-all RealTime
match ip dscp ef
class-map match-all General
match any
class-map match-any Application
match ip dscp cs3
match ip dscp af41
policy-map QOSADSL
class RealTime
bandwidth percent 50
class Application
priority percent 30
class General
priority percent 5
class class-default
shape peak percent 85
policy-map ADSLOut
class class-default
service-policy QOSADSL
interface Dialer1
<Snipped>
bandwidth 1240
ip nbar protocol-discovery
ip flow ingress
ip flow egress
load-interval 30
tx-ring-limit 3
tx-queue-limit 3
service-policy output QOSADSL
or
service-policy output ADSLOutHi @scotlandvisit,
My first opinion is a recomendation: in the policy-map, when you're configuring LLQ use the priority command for delay-sensitive traffic (Voice) and the bandwidth command for the rest. This is because the priority command is used to indentify a class as a "strict priority class" which in my opinion should be the voice traffic and the bandwidth command is used to allocate bandwidth to nonpriority classes.
The interface is not letting you apply the service-policy because you have to configure shaping inside the class-default of the parent policy-map. This shape is going to be the value in bps that you want to assing to the traffic classes that you've configured. For example, let's say that you want to allocate 1Mbps for all the classes.
policy-map QOSADSL
class RealTime
priority percent 50
class Application
bandwidth percent 30
class General
bandwidth percent 5
class class-default
shape peak percent 85
policy-map ADSLOut
class class-default
shape average 1000000
service-policy QOSADSL
interface Dialer1
service-policy output ADSLOut
Try this configuration and let me know.
HTH.
Rgrds,
Martin, IT Specialist -
Service-policy output voice-only
Hi, when i enter "service-policy output voice-only" in int BVI1 on a Cisco 878 (G.SHDSL), it throws an error saying, "Class Based Weighted Fair Queueing not supported"
Can i put this line in int ATM0 ?Hi,
It should be done as follows:
Remove BVI and "bridge irb". Configure an ATM subinterface point-to-point with the IP address, "atm route-bridging" and PVC. Under PVC apply the service policy.
please rate post if it helps! -
Service policy on subinterface or main interface
Folks,
We have a frame relay circuit and are applying MQC to the branch sites. We are not sure if we should apply the service policy to the subinterface or the main interface(serial). any pros and cons?
ThanksIf you want the same policy applied to each VC then applying at the physical interface would be best (depending on the scenario and how many sub-interfaces you have). In the long run applying the service-policy to the sub-interface will pay for itself.
-
Cannot configure service-policy on SIP-400
I have cisco 7606 with SIP-400 on slot1 , and I try to apply service-policy output on the interface pos1/1/0, after enter the command, the system
generate the error "queue-limit is invalid command w/o other queueing feature".
Why I cannot apply the service-policy?Thanks Marcio.
I have added failover details to the client's tnsnames file (see below), but still i get the '500 - The Network Adapter could not establish the connection' error:
TESTDB =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCP)(HOST = lontestdb01-vip)(PORT = 1526))
(ADDRESS = (PROTOCOL = TCP)(HOST = lontestdb02-vip)(PORT = 1526))
(LOAD_BALANCE = TRUE)
(FAILOVER = TRUE)
(CONNECT_DATA =
(SERVER = DEDICATED)
(SERVICE_NAME = ESTDB)
(FAILOVER_MODE =
(BACKUP=lontestdb02-vip)
(TYPE=select)
(METHOD=preconnect)
(RETRIES=180)
(DELAY=5)
Bal - the output of crs_stat -t is as follows (please note the listener on node 1 is intentionally down)
-bash-3.00$ crs_stat -t
Name Type Target State Host
ora....B1.inst application ONLINE ONLINE lonestdb01
ora....B2.inst application ONLINE ONLINE lonestdb02
ora....DB1.srv application ONLINE ONLINE lonestdb01
ora....DB2.srv application ONLINE ONLINE lonestdb02
ora....BOTH.cs application ONLINE ONLINE lonestdb01
ora....DB1.srv application ONLINE ONLINE lonestdb02
ora....LIVE.cs application ONLINE ONLINE lonestdb01
ora....DB2.srv application ONLINE ONLINE lonestdb02
ora....NDBY.cs application ONLINE ONLINE lonestdb02
ora.ESTDB.db application ONLINE ONLINE lonestdb02
ora....01.lsnr application OFFLINE OFFLINE
ora....b01.gsd application ONLINE ONLINE lonestdb01
ora....b01.ons application ONLINE ONLINE lonestdb01
ora....b01.vip application ONLINE ONLINE lonestdb01
ora....02.lsnr application ONLINE ONLINE lonestdb02
ora....b02.gsd application ONLINE ONLINE lonestdb02
ora....b02.ons application ONLINE ONLINE lonestdb02
ora....b02.vip application ONLINE ONLINE lonestdb02
Many thanks to everyone that's helped so far
Rup -
Can't apply service-policy to atm int?
Attempted to apply service-policy output MPLS-EGRESS to ATM Int:
class-map match-any GOLD
match mpls experimental topmost 5
match ip precedence 5
class-map match-any BRONZE
match mpls experimental topmost 3
match ip precedence 3
class-map match-any SILVER
match mpls experimental topmost 4
match ip precedence 4
policy-map MPLS-EGRESS
class GOLD
priority percent 5
set mpls experimental topmost 5
class SILVER
bandwidth percent 10
random-detect
set mpls experimental topmost 4
class BRONZE
bandwidth percent 20
random-detect
set mpls experimental topmost 3
class class-default
set mpls experimental topmost 0
fair-queue
random-detect
interface ATM4/0.102 point-to-point
description TRUNK LINK TO PE_B
bandwidth 16000
ip address xxx.xxx.xxx.xxx 255.255.255.252
no ip redirects
no ip proxy-arp
ip ospf message-digest-key xxx
no snmp trap link-status
mpls ip
pvc PE_B 10/102
tx-ring-limit 3
oam-pvc manage
encapsulation aal5snap
service-policy output MPLS-EGRESS
And it *appears* to apply without error, but logs show:
Jul 28 09:34:32.550 aest: %SCHED-3-SEMLOCKED: Virtual Exec attempted to lock a semaphore, already locked by itself -Traceback= 0x61317864 0x62658A88 0x620F0A4C 0x60DD3668 0x60DD5648 0x6135ABD8 0x61379744 0x62644508 0x626444EC
Jul 28 09:34:33.870 aest: I/f ATM4/0.102 VC 10/102 class GOLD requested bandwidth 0 (kbps), available only 0 (kbps)
And ATM4/0.102 does not include the service-policy output MPLS-EGRESS when I do a show run nor when I do a sho policy-map interface?Resolved my own issue - I needed:
vbr-nrt 32000 16000
under the atm sub int... -
Service-policy on Vlan interface failed
Hi, All!
This is my configuration:
class-map match-any voip_control_trust-CMAP
match ip dscp cs3
match ip dscp af31
class-map match-any voip_rtp_trust-CMAP
match ip dscp ef
class-map match-any internetwork-cntrl-CMAP
match ip dscp cs6
policy-map output_qos-PMAP
class voip_rtp_trust-CMAP
priority 56
class voip_control_trust-CMAP
bandwidth percent 2
class internetwork-cntrl-CMAP
bandwidth percent 5
class class-default
fair-queue
random-detect
cisco(config)#int Vlan 2
cisco(config-if)#service-policy output output_qos-PMAP
Configuration failed!
It was tested on 877, 871, 871W, 877W with ios c870-advipservicesk9-mz.124-15.T5.bin, c870-advipservicesk9-mz.124-15.T8.bin, c870-advipservicesk9-mz.124-15.T10.bin, c870-advipservicesk9-mz.124-15.T11.bin, c870-advipservicesk9-mz.124-24.T2.bin
Strange error. Does anybody know what's the problem?Ok, i tried to make workaround solution:
policy-map OUTPUT_QOS_PMAP
class VOIP_RTP_TRUST_CMAP
priority 56
class VOIP_CTRL_TRUST_CMAP
bandwidth percent 2
class INETWORK-CTRL-CMAP
bandwidth percent 5
class class-default
fair-queue
random-detect
service-policy OUTPUT_QOS_PMAP
service-policy output OUTPUT_QOS_PMAP
interface Vlan2
description *** WAN SVI ***
bandwidth 256
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
ip virtual-reassembly
bridge-group 1
end
interface BVI1
description *** WAN BVI ***
bandwidth 256
ip address 10.96.0.57 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip virtual-reassembly
service-policy output OUTPUT_QOS_PMAP
end
sh policy-map interface
BVI1
Service-policy output: OUTPUT_QOS_PMAP
queue stats for all priority classes:
queue limit 64 packets
(queue depth/total drops/no-buffer drops) 0/0/0
(pkts output/bytes output) 0/0
Class-map: VOIP_RTP_TRUST_CMAP (match-any)
0 packets, 0 bytes
5 minute offered rate 0 bps, drop rate 0 bps
Match: ip dscp ef (46)
0 packets, 0 bytes
5 minute rate 0 bps
Priority: 56 kbps, burst bytes 1500, b/w exceed drops: 0
Class-map: VOIP_CTRL_TRUST_CMAP (match-any)
0 packets, 0 bytes
5 minute offered rate 0 bps, drop rate 0 bps
Match: ip dscp cs3 (24)
0 packets, 0 bytes
5 minute rate 0 bps
Match: ip dscp af31 (26)
0 packets, 0 bytes
5 minute rate 0 bps
Queueing
queue limit 64 packets
(queue depth/total drops/no-buffer drops) 0/0/0
(pkts output/bytes output) 0/0
bandwidth 2% (5 kbps)
Class-map: INETWORK-CTRL-CMAP (match-any)
6 packets, 896 bytes
5 minute offered rate 0 bps, drop rate 0 bps
Match: ip dscp cs6 (48)
6 packets, 896 bytes
5 minute rate 0 bps
Match: access-group name IKE
0 packets, 0 bytes
5 minute rate 0 bps
Queueing
queue limit 64 packets
(queue depth/total drops/no-buffer drops) 5/0/0
(pkts output/bytes output) 6/1120
bandwidth 5% (12 kbps)
Class-map: class-default (match-any)
11 packets, 660 bytes
5 minute offered rate 0 bps, drop rate 0 bps
Match: any
Queueing
queue limit 64 packets
(queue depth/total drops/no-buffer drops/flowdrops) 10/0/0/0
(pkts output/bytes output) 11/660
Fair-queue: per-flow queue limit 16
Exp-weight-constant: 9 (1/512)
Mean queue depth: 0 packets
class Transmitted Random drop Tail/Flow drop Minimum Maximum Mark
pkts/bytes pkts/bytes pkts/bytes thresh thresh prob
0 11/660 0/0 0/0 20 40 1/10
1 0/0 0/0 0/0 22 40 1/10
2 0/0 0/0 0/0 24 40 1/10
3 0/0 0/0 0/0 26 40 1/10
4 0/0 0/0 0/0 28 40 1/10
5 0/0 0/0 0/0 30 40 1/10
6 0/0 0/0 0/0 32 40 1/10
7 0/0 0/0 0/0 34 40 1/10
BUT! Until service-policy is on interface works nothing.
sh int bvi1
BVI1 is up, line protocol is up
Hardware is BVI, address is 0025.454a.940d (bia 0024.c495.6780)
Description: *** WAN BVI ***
Internet address is 10.96.0.57/24
MTU 1500 bytes, BW 256 Kbit/sec, DLY 5000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
ARP type: ARPA, ARP Timeout 04:00:00
Last input never, output never, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 74
Queueing strategy: Class-based queueing
Output queue: 33/1000/0 (size/max total/drops)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
114 packets output, 11034 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped out
ping 10.96.0.1 source bvi1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.96.0.1, timeout is 2 seconds:
Packet sent with a source address of 10.96.0.57
Success rate is 0 percent (0/5) -
ACE - incomplete 'sh service-policy NAME detail' listing
Hi guys,
our customer reported to me problem with incomplete 'sh service-policy CLIENT_VIP detail' listing. this listing is not complete and ends with 'Unexpected header: 0'.
he reported, that (for example) 25 policy maps in policy-map multi-match working correctly and listing is complete, but more policy maps in the policy-map multi-match cause incomplete listing and this extra policy maps are not working properly.
I tried copy his config file to my ACE, and service policy listing is complete.
any ideas? maybe no more resources for this context (I got no 'sh resource usage' from the customer till now).
ACE SW: 3.0(0)A1(5a)
config has 39 class maps in the class-map multi-match CLIENT_VIP definition
thanks,
martinI forgot... customer reported behavior, that is very important:
Primary problem is, that removed class from policy-class multi-match is still working (!) and new added class is not working. configuration is ok, because without too many classes in policy-map multi-match are this config parts operational.
is this known defect?
resources usage is without problem.
martin -
Hi,
I am not able to ping the VLAN interfaces defined on the ACE devices unless directly connected to the subnet.
I tried options - defining Access-list,service-policy.I can ping the servers behind the ACE but i cannt ping the ACE vlan interface.
I captured the traffic on the ACE.I cannt see any traffic on the interfaces if i ping the VLAN ip address.I can see the traffic if i am pinging the host behind the ACE.
Is there any option available to enable icmp on the interfaces.In order to ping the Vlan Interface you just need management policy applied to the vlan interface.
Class-maps used in the management-policy
defines the source addresses from where these management accesses are allowed.
If you can ping the interfaces from locally connected subnets but not from the remote subnets then there could be 2 reasons.
1. Some routing issues
2. Source IPs in Management class maps are not defined.
Following is an example of typical management policy
#Allow telnet & SSH from these ip addresses
#Allow ICMP from any source
class-map type management match-any MGMT-CLASS
10 match protocol telnet
20 match protocol ssh
30 match protocol icmp any
policy-map type management first-match MGMT-POLICY
class MGMT-CLASS
permit
interface vlan 10
ip address x.x.x.x 255.255.255.0
service-policy input MGMT-POLICY
no shutdown
interface vlan 20
ip address y.y.y.y 255.255.255.0
service-policy input MGMT-POLICY
no shutdown
Syed Iftekhar Ahmed -
Why doesn't "show service-policy url-summary" work?
Does any one know -- At Cisco Live this year -- this command was shown as an Option to see the number of
hits on L7 class maps urls.
It's not an option for me: Running A3 (2.5)
Thanks,
From A2 documentation (maybe this command was dropped from A3 -- but that would be unfortunate)
To display the statistics for all policy maps or a specific policy map that is currently in service, use the show service-policy command. This command also allows you to display statistics for a specific class map in a policy or the hit counts for match HTTP URL statements in a Layer 7 HTTP policy map. If you do not enter an option with this command, the ACE displays all enabled policy statistics.
show service-policy [policy_name [class-map class_name]] [detail | summary | url-summary] [|] [>]
Syntax Description
policy_name
(Optional) Identifier of an existing policy map that is currently in service (applied to an interface) as an unquoted text string with a maximum of 64 alphanumeric characters. If you do not enter the name of an existing policy map, the ACE displays information and statistics for all policy maps.
class-map class_name
(Optional) Displays the statistics for the specified class map associated with the policy.
detail
(Optional) Displays a more detailed listing of policy map or class map statistics and status information.
summary
(Optional) Displays a summary of policy map or class map statistics and status information.
url-summary
(Optional) Displays the number of times that a connection is established based on a match HTTP URL statement for a class map in a Layer 7 HTTP policy map.
The URL hit counter is per match statement per load-balancing Layer 7 policy. If you are using the same combination of Layer 7 policy and class maps with URL match statements in different VIPs, the count is combined. If the ACE configuration exceeds 64K URL and load-balancing policy combinations, this counter displays NA.Hi Dan,
The url-summary has only been added to the ACE module code at this time. The A2 code train is only for the module, while the A3 train is only for the appliance. The good news is that later this year, we will have a new software coming out (A4) that will be the exact same image that can be loaded on either the module or the appliance, hence all functionality will be the same for both (except the acceleration and optimization that only the appliance will support.
Hope this helps,
Sean -
Fundamental ACL & Service Policy related questions
Hi All,
apologies in advance for seemingly stupid questions but I was forced to ask them as I have ALWAYS had great difficulty in using debug on Cisco platforms. Nothing ever shows up when I set up debug despite configuring "logging console" and setting the level to 7 etc. I have no clue why that is and if it's because all debugging messages go to the debug log instead of being prnted on the console, or what it is...I just don't get it. When I'm saying logging console...please print it on the console! Anyway, that rant aside...
I have a VERY simple topology like so
A few servers in this VLAN
ISP <---> 3560G (Physical Routed Port) <--> SVI (VLAN)
ASA5520 <--> Internal VLAN
With regards to ACLs and their direction, when an ACL is applied to a physical port (or in cases where QoS is enabled and a service-policy) is applied to either a routed physical port on the 3560, saying that the policy is applied in the "in" direction (or 'input' in case of service-policy) does that mean 'inbound' in either direction? As in IF that routed port is my direct connection to the ISP, and I set up "ip access-group myacl in" (or service-policy input myPolicymap) ...will that be applicable if the traffic enters that port from the ISP side OR from the internal network side, or "IN" for it is always JUST the ISP side because it's assuming that all traffic generated from inside the network going out to the Internet is implcitly allowed UNLESS an ACL somewhere in the network restricts that?
then, in case of an SVI...I believe just like the physical routed port, I can ONLY implement an "Inbound" ACL on this as well. So when I implement either a Heirarchical policy-map or just an access-group "in", then what is "IN" ...traffic entering this VLAN from the internal network and those public servers going out to the Internet AND Traffic entering this VLAN from the ISP/Internet via the physical routed Port OR is it JUST the latter, or is it just the former?
Now Lastly, when I have the physical ports to which the ASA and each of those physical servers are connected to sitting on the public VLAN, if I apply port-based ACLs or service-policies to them, then again, what direction is the "IN" ACL applied? Both? i.e. traffic coming into it from the public servers and the Internal network through the ASA, and the Internet OR just the traffic coming into it from the Internet, but the traffic going out from the servers to the Internet is not subjected to this ACL or service-policy
Again, very sorry for a dumb question but I'm seeing bizzare things in my network so was just wondering before I decide on what kind of security I want to plan/design
Thanks in advanceThe mystical difference between debug output going to the console versus showing up in syslog is "logging debug-trace". On goes to syslog, "no logging debug-trace" goes to console. I've been bit by this one myself.
ACLs on physical ports have directionality like the cable plug: "in" is from the cable entering into the switch or firewall, "out" is leaving the device to run along the cable to somewhere else. On Catalyst switches port ACLs are inbound (receiving packets) only. Obviously, on directly connected devices, one devices out is the other devices in.
ACLs on SVI's depend on whether your are running a base image or services image; services images can do IPv4 and IPv6 in both directions. However, port ACL's trump routed ACL's; if both exist, the port ACL is the only one applied. I think if a directly connected port has no port ACL, no ACL is applied at all; routed ACL's on SVI's only apply to transitions between VLANs inside the switch, not to traffic entering physical ports.
-- Jim Leinweber, WI State Lab of Hygiene -
C3750-48ts Service-Policy Output Like Command
Hello,
I'm having an issue trying to find a way to make a QOS or limiting of network traffic on a cisco 3750 that we have at a client site.
What the end goal is to make the network traffic 10x5mbs on some ports and 5x1mbs on others.
From how I normally do traffic shaping on routers is Class-map, policy-map and service-policy. However as I found out with with this project I can't run the Service-policy Output command on the 3750 model. The other way that I know how to limit bandwidth on these switches is to use the srr-queue bandwidth limit % command. However, this isn't going to work for the clients that have 30x5mbs connection though us.
Here is what I have programmed:
mls qos
vlan 100
class-map match-any IN
match access-group 100
class-map match-any OUT
match ip dscp default
policy-map 5M_IN
class IN
police 5000000 256000 exceed-action drop
policy-map 1M_IN
class IN
police 1000000 256000 exceed-action drop
policy-map 30M_OUT
class OUT
police 30000000 512000 exceed-action drop
policy-map 5M_OUT
class OUT
police 5000000 256000 exceed-action drop
interface FastEthernet1/0/36
description TEST
switchport access vlan 100
servic-policy input 1M_IN
(This is where I would like to run the service-policy output 5M_OUT)
If you have any idea on how to limit traffic per port please let me know so that this may help others.
Thank you,
MichaelThe 3560 & 3750 (& 2960) don't support egress policy-maps. They do however support queueing so it is possible to achieve similar results by applying an ingress policer to your user ports to classify (& police?) the traffic, at the egress port you can then queue the traffic based on it's DSCP or CoS value that it was classified with (same as 3550).
It is also possible to restrict the bandwidth in use at an egress port with the interface command 'srr-queue bandwidth limit <10-90>' where 10-90 represents a percentage of the links bandwidth. For example if you want to restrict a 100Mbps port to 10Mbps you would use the command 'srr-queue bandwidth limit 10'
HTH
Andy -
Applying Software Installation Policy Is Taking Long Time During Boot Process
1 of my servers is having slow boot up issue. I have enabled user environment debugging and the gpsvc.log file has been generated. I have also used the Windows Performance Analyzer to capture logs and results came back that the GP Client is taking a long
time in the boot process. So, I reckoned the slow boot is due to GPO but I am not sure where to look from this log file.
I have only paste part of the gpsvc.log file here due to limitation in the number of characters allowed to be posted. Would appreciate some good advise on this issue that I am facing.
GPSVC(34c.408) 04:03:30:109 ReadExtStatus: Reading Previous Status for extension {FB2CA36D-0B40-4307-821B-A13B252DE56C}
GPSVC(34c.408) 04:03:30:109 ReadExtStatus: Reading Previous Status for extension {fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f}
GPSVC(34c.408) 04:03:30:109 GetMachineToken: Looping for authentication again.
GPSVC(34c.408) 04:03:30:109 ProcessGPOs: Logging Data for Target <SW01E772>.
GPSVC(34c.408) 04:03:30:109 GPLockPolicySection: Sid = (null), dwTimeout= 30000, dwFlags= 0
GPSVC(34c.408) 04:03:30:109 LockPolicySectioncalled for user <Machine>
GPSVC(34c.408) 04:03:30:109 Sync Lock Called
GPSVC(34c.408) 04:03:30:109 Writer Lock got immediately.
GPSVC(34c.408) 04:03:30:109 Lock taken successfully
GPSVC(34c.408) 04:03:30:109 UnLockPolicySectioncalled for user <Machine>
GPSVC(34c.408) 04:03:30:109 UnLockedsuccessfully
GPSVC(34c.408) 04:03:30:109 ProcessGPOs: OpenThreadTokenfailed with error 1008, assuming thread is not impersonating
GPSVC(34c.408) 04:03:30:109 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:30:109 ProcessGPOs: Processing extension Registry
GPSVC(34c.408) 04:03:30:125 ReadStatus: Read Extension's Previous status successfully.
GPSVC(34c.408) 04:03:30:125 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:30:125 CheckGPOs: No GPO changes and nosecurity group membership change and extension Registry has NoGPOChangesset.
GPSVC(34c.408) 04:03:30:125 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:30:125 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Processing extension Wireless Group Policy
GPSVC(34c.408) 04:03:30:125CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:30:125 CheckGPOs: No GPO changes but couldn't read extension Wireless Group Policy's status or policy time.
GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Extension Wireless Group Policy skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:30:125 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Processing extension Group Policy Environment
GPSVC(34c.408) 04:03:30:125 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:30:125 CheckGPOs: No GPO changes but couldn't read extension Group Policy Environment's status or policy time.
GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Extension Group Policy Environment skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:30:125 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:30:125 ProcessGPOs: Processing extension Group Policy Local Users and Groups
GPSVC(34c.408) 04:03:30:125 ReadStatus: Read Extension's Previous status successfully.
GPSVC(34c.408) 04:03:30:125 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:30:156 GPLockPolicySection: Sid = (null), dwTimeout= 30000, dwFlags= 0
GPSVC(34c.408) 04:03:30:156 LockPolicySectioncalled for user <Machine>
GPSVC(34c.408) 04:03:30:156 Sync Lock Called
GPSVC(34c.408)04:03:30:156 Writer Lock got immediately.
GPSVC(34c.408) 04:03:30:156 Lock taken successfully
GPSVC(34c.408) 04:03:30:156 ProcessGPOList: Entering for extension Group Policy Local Users and Groups
GPSVC(34c.408) 04:03:30:156 MachinePolicyCallback: Settingstatus UI to Applying Group Policy Local Users and Groups policy...
GPSVC(34c.408) 04:03:30:156 ProcessGPOList: No changes. CSEwill not be passed in the IwbemServicesintfptr
GPSVC(34c.364)04:03:30:156 Message Status = <Applying Group Policy Local Users and Groups policy...>
GPSVC(34c.364) 04:03:30:156 Setting GPsessionstate = 1
GPSVC(34c.408) 04:03:31:796 ProcessGroupPolicyCompletedExInternal: Entering. Extension = {17D89FEC-5C44-4972-B12D-241CAEF74509}, dwStatus= 0x0
GPSVC(34c.408) 04:03:31:953 GetWbemServices: CoCreateInstancesucceeded
GPSVC(34c.408) 04:03:36:031 ConnectToNameSpace: ConnectServerreturned 0x0
GPSVC(34c.408) 04:03:36:140 ProcessGroupPolicyCompletedExInternal: Extension {17D89FEC-5C44-4972-B12D-241CAEF74509} was able to log data. Error = 0x0, dwRet= 0. Clearing the dirty bit
GPSVC(34c.408) 04:03:36:500 ProcessGroupPolicyCompletedExInternal: Finished processing extension <Group Policy Local Users and Groups> at 44203 ticks (ms)
GPSVC(34c.408) 04:03:36:500 ProcessGroupPolicyCompletedExInternal: Leaving. Extension = {17D89FEC-5C44-4972-B12D-241CAEF74509}, Return status dwRet= 0x0
GPSVC(34c.408) 04:03:36:500 ProcessGPOList: Extension Group Policy Local Users and Groups returned 0x0.
GPSVC(34c.408) 04:03:36:500 ProcessGPOList: Extension Group Policy Local Users and Groups status was not updated because there was no changes and no transition or rsopwasn't enabled
GPSVC(34c.408) 04:03:36:500 UnLockPolicySectioncalled for user <Machine>
GPSVC(34c.408) 04:03:36:500 UnLockedsuccessfully
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Processing extension Group Policy Device Settings
GPSVC(34c.408) 04:03:36:531 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:531 CheckGPOs: No GPO changes but couldn't read extension Group Policy Device Settings'sstatus or policy time.
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Extension Group Policy Device Settings skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Processing extension Folder Redirection
GPSVC(34c.408) 04:03:36:531 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:531 CheckGPOs: No GPO changes but couldn't read extension Folder Redirection's status or policy time.
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Extension Folder Redirection skipped with flags 0x7.
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Processing extension Microsoft Disk Quota
GPSVC(34c.408) 04:03:36:531 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:531 CheckGPOs: No GPO changes but couldn't read extension Microsoft Disk Quota's status or policy time.
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Extension Microsoft Disk Quota skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:531 ProcessGPOs: Processing extension Group Policy Network Options
GPSVC(34c.408) 04:03:36:531CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:546 CheckGPOs: No GPO changes but couldn't read extension Group Policy Network Options'sstatus or policy time.
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Extension Group Policy Network Options skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Processing extension QoSPacket Scheduler
GPSVC(34c.408) 04:03:36:546 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:546 CheckGPOs: No GPO changes but couldn't read extension QoSPacket Scheduler's status or policy time.
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Extension QoSPacket Scheduler skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Processing extension Scripts
GPSVC(34c.408) 04:03:36:546 ReadStatus: Read Extension's Previous status successfully.
GPSVC(34c.408) 04:03:36:546 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:546 CheckGPOs: No GPO changes and no security group membership change and extension Scripts has NoGPOChangesset.
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Processing extension Remote Desktop USB Redirection
GPSVC(34c.408) 04:03:36:546 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:546 CheckGPOs: No GPO changes but couldn't read extension Remote Desktop USB Redirection's status or policy time.
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Extension Remote Desktop USB Redirection skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:546 ProcessGPOs: Processing extension Internet Explorer Zonemapping
GPSVC(34c.408) 04:03:36:562 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Zonemapping'sstatus or policy time.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Internet Explorer Zonemappingskipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processing extension Group Policy Drive Maps
GPSVC(34c.408) 04:03:36:562 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't read extension Group Policy Drive Maps'sstatus or policy time.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Group Policy Drive Maps skipped withflags 0x7.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processingextension Group Policy Folders
GPSVC(34c.408) 04:03:36:562 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't read extension Group Policy Folders'sstatus or policy time.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Group Policy Folders skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processing extension Group Policy Network Shares
GPSVC(34c.408) 04:03:36:562 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't read extension Group Policy Network Shares's status or policy time.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Group Policy Network Shares skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processing extension Group Policy Files
GPSVC(34c.408) 04:03:36:562 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:562 CheckGPOs: No GPO changes but couldn't readextension Group Policy Files's status or policy time.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Extension Group Policy Files skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:562 ProcessGPOs: Processing extension Group Policy Data Sources
GPSVC(34c.408) 04:03:36:562 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:578 CheckGPOs:No GPO changes but couldn't read extension Group Policy Data Sources's status or policy time.
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Extension Group Policy Data Sources skipped because bothdeleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Processing extension Group Policy Ini Files
GPSVC(34c.408) 04:03:36:578 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:578 CheckGPOs: No GPO changes but couldn't read extension Group Policy Ini Files's status or policy time.
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Extension GroupPolicy Ini Files skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Processing extension Internet Explorer User Accelerators
GPSVC(34c.408) 04:03:36:578 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:578 CheckGPOs: No GPO changes but couldn't readextension Internet Explorer User Accelerators's status or policy time.
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Extension Internet Explorer User Accelerators skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Processing extension Security
GPSVC(34c.408) 04:03:36:578ReadStatus: Read Extension's Previous status successfully.
GPSVC(34c.408) 04:03:36:578 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:578 CheckGPOs: No GPO changes and no security group membership change and extension Security has NoGPOChanges set.
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Processing extension Deployed Printer Connections
GPSVC(34c.408) 04:03:36:578 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:578 CheckGPOs: No GPO changes but couldn't read extension Deployed Printer Connections's status or policy time.
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: Extension Deployed Printer Connections skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:578 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Group Policy Services
GPSVC(34c.408) 04:03:36:593 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:593 CheckGPOs: No GPO changes but couldn't read extension Group Policy Services's status or policy time.
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Extension Group Policy Services skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Internet Explorer Branding
GPSVC(34c.408) 04:03:36:593 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:593 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Branding's status or policy time.
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Extension Internet Explorer Branding skipped with flags 0x7.
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Group PolicyFolder Options
GPSVC(34c.408) 04:03:36:593 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:593 CheckGPOs: No GPO changes but couldn't read extension Group Policy Folder Options's status or policy time.
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Extension Group Policy Folder Options skipped because bothdeleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Group Policy Scheduled Tasks
GPSVC(34c.408) 04:03:36:593 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:593 CheckGPOs: No GPO changes but couldn't read extension Group Policy Scheduled Tasks's status or policy time.
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Extension Group Policy Scheduled Tasks skipped because both deletedand changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:593 ProcessGPOs: Processing extension Group Policy Registry
GPSVC(34c.408) 04:03:36:593 ReadStatus: Read Extension's Previous status successfully.
GPSVC(34c.408) 04:03:36:593 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:625 GPLockPolicySection: Sid = (null), dwTimeout = 30000, dwFlags = 0
GPSVC(34c.408)04:03:36:625 LockPolicySection called for user <Machine>
GPSVC(34c.408) 04:03:36:625 Sync Lock Called
GPSVC(34c.408) 04:03:36:625 Writer Lock got immediately.
GPSVC(34c.408) 04:03:36:625 Locktaken successfully
GPSVC(34c.408) 04:03:36:625 ProcessGPOList: Entering for extension Group Policy Registry
GPSVC(34c.408) 04:03:36:625 MachinePolicyCallback: Setting status UI to Applying Group Policy Registry policy...
GPSVC(34c.408) 04:03:36:625 ProcessGPOList: No changes. CSE will not be passed in the IwbemServices intf ptr
GPSVC(34c.364) 04:03:36:625 Setting GPsession state =1
GPSVC(34c.408) 04:03:36:765 ProcessGroupPolicyCompletedExInternal: Entering. Extension = {B087BE9D-ED37-454F-AF9C-04291E351182}, dwStatus = 0x0
GPSVC(34c.408) 04:03:36:796 GetWbemServices: CoCreateInstance succeeded
GPSVC(34c.408) 04:03:36:812 ConnectToNameSpace: ConnectServer returned 0x0
GPSVC(34c.408) 04:03:36:812 ProcessGroupPolicyCompletedExInternal: Extension {B087BE9D-ED37-454F-AF9C-04291E351182} was able to log data. Error = 0x0, dwRet = 0. Clearing the dirty bit
GPSVC(34c.408) 04:03:36:843 ProcessGroupPolicyCompletedExInternal: Finished processing extension <Group Policy Registry> at 44546 ticks (ms)
GPSVC(34c.408) 04:03:36:843 ProcessGroupPolicyCompletedExInternal: Leaving. Extension = {B087BE9D-ED37-454F-AF9C-04291E351182}, Return status dwRet = 0x0
GPSVC(34c.408) 04:03:36:843 ProcessGPOList: Extension Group Policy Registry returned 0x0.
GPSVC(34c.408) 04:03:36:843 ProcessGPOList: Extension Group Policy Registry status was not updated because there was no changes and no transition or rsop wasn'tenabled
GPSVC(34c.408) 04:03:36:843 UnLockPolicySection called for user <Machine>
GPSVC(34c.408) 04:03:36:843 UnLocked successfully
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Processing extension 802.3 Group Policy
GPSVC(34c.408) 04:03:36:875 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:875 CheckGPOs: No GPO changes but couldn't read extension 802.3 Group Policy's status or policy time.
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Extension 802.3 Group Policy skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Processing extension Group Policy Printers
GPSVC(34c.408) 04:03:36:875 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:875 CheckGPOs: No GPO changes but couldn't read extension Group Policy Printers's status or policy time.
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Extension Group Policy Printers skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Processing extension Group Policy Shortcuts
GPSVC(34c.408) 04:03:36:875 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:875 CheckGPOs: No GPO changes but couldn't read extension Group Policy Shortcuts's status or policy time.
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: Extension Group Policy Shortcuts skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:36:875 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:36:890 ProcessGPOs: Processing extension Software Installation
GPSVC(34c.408) 04:03:36:890 ReadStatus: Read Extension's Previous status successfully.
GPSVC(34c.408) 04:03:36:890 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:36:890 GPLockPolicySection: Sid = (null), dwTimeout = 30000, dwFlags = 0
GPSVC(34c.408) 04:03:36:890 LockPolicySection called for user <Machine>
GPSVC(34c.408) 04:03:36:890 Sync Lock Called
GPSVC(34c.408) 04:03:36:890 Writer Lock got immediately.
GPSVC(34c.408) 04:03:36:890 Lock taken successfully
GPSVC(34c.408) 04:03:36:890 ProcessGPOList: Entering for extension Software Installation
GPSVC(34c.408) 04:03:36:890 MachinePolicyCallback: Setting status UI to Applying Software Installation policy...
GPSVC(34c.408) 04:03:36:890ProcessGPOList: No changes. CSE will not be passed in the IwbemServices intf ptr
GPSVC(34c.364) 04:03:36:890 Message Status = <Applying Software Installation policy...>
GPSVC(34c.364) 04:03:36:890 Setting GPsession state = 1
GPSVC(34c.408) 04:03:37:312 ProcessGPOList: Extension Software Installation returned 0x0.
GPSVC(34c.408) 04:03:37:312 ProcessGPOList: Extension Software Installation status was not updated because there was no changes and no transition or rsop wasn't enabled
GPSVC(34c.408) 04:03:37:312UnLockPolicySection called for user <Machine>
GPSVC(34c.408) 04:03:37:312 UnLocked successfully
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Processing extension TCPIP
GPSVC(34c.408) 04:03:37:328 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:328 CheckGPOs: No GPO changes but couldn't read extension TCPIP's status or policy time.
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Extension TCPIP skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Processing extension Internet Explorer Machine Accelerators
GPSVC(34c.408) 04:03:37:328 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:328 CheckGPOs: No GPO changes but couldn't read extension Internet Explorer Machine Accelerators's status or policy time.
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Extension Internet Explorer Machine Accelerators skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Processing extension IP Security
GPSVC(34c.408) 04:03:37:328 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:328 CheckGPOs: No GPO changes but couldn't read extension IP Security's status or policy time.
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Extension IP Security skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:328 ProcessGPOs: Processing extension Group Policy Internet Settings
GPSVC(34c.408) 04:03:37:343 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extension Group Policy Internet Settings's status or policy time.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Group Policy Internet Settings skipped with flags 0x7.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processing extension Group Policy Start Menu Settings
GPSVC(34c.408) 04:03:37:343 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extension Group Policy Start Menu Settings's status or policy time.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Group Policy Start Menu Settings skipped because both deleted and changed GPO listsare empty.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processingextension Group Policy Regional Options
GPSVC(34c.408) 04:03:37:343 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extensionGroup Policy Regional Options's status or policy time.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Group Policy RegionalOptions skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processing extension Group Policy Power Options
GPSVC(34c.408) 04:03:37:343 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extension Group Policy Power Options's status or policy time.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Group Policy Power Options skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processing extension Audit Policy Configuration
GPSVC(34c.408) 04:03:37:343 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:343 CheckGPOs: No GPO changes but couldn't read extension Audit Policy Configuration's status or policy time.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Extension Audit Policy Configuration skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:343 ProcessGPOs: Processing extension Group Policy Applications
GPSVC(34c.408) 04:03:37:359 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:359 CheckGPOs: No GPO changes but couldn't read extension Group Policy Applications's status or policy time.
GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Extension Group Policy Applications skipped with flags 0x7.
GPSVC(34c.408) 04:03:37:359 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Processing extension Enterprise QoS
GPSVC(34c.408) 04:03:37:359 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:359 CheckGPOs: No GPO changes but couldn't read extension Enterprise QoS's status or policy time.
GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Extension Enterprise QoS skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:37:359 ProcessGPOs: -----------------------
GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Processing extensionCP
GPSVC(34c.408) 04:03:37:359 CompareGPOLists: The lists are the same.
GPSVC(34c.408) 04:03:37:359 CheckGPOs: No GPO changes but couldn't read extension CP's status or policy time.
GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Extension CP skipped because both deleted and changed GPO lists are empty.
GPSVC(34c.408) 04:03:37:359 gpGetFgPolicyRefreshInfo: Mode: 1, Reason: 7
GPSVC(34c.408) 04:03:37:359 SetFgRefreshInfo: Previous Machine Fg policy Synchronous, Reason: SKU.
GPSVC(34c.408) 04:03:37:359 SetFgRefreshInfo: Next Machine Fg policy Synchronous, Reason: SKU.
GPSVC(34c.408) 04:03:37:359 ProcessGPOs: No WMI logging done in this policy cycle.
GPSVC(34c.408) 04:03:37:359 ProcessGPOs: Boot/Logon Policy processing - checking if UBPM trigger events need to be fired
GPSVC(34c.408) 04:03:37:375 CheckAndFireGPTriggerEvent: FiredPolicy present UBPM trigger event for Machine.
GPSVC(34c.408) 04:03:37:375 Application complete with bConnectivityFailure = 0.
GPSVC(34c.79c) 04:03:40:546 CGPNotify::RegisterForNotification: Entering with target Machine and event 0xc8c
GPSVC(34c.79c) 04:03:40:546 Client_InitialRegisterForNotification: User = machine, changenumber = 0
GPSVC(34c.3a0) 04:03:40:546 Target = Machine
GPSVC(34c.79c) 04:03:40:546 Client_RegisterForNotification: User =machine, changenumber = 0
GPSVC(34c.79c) 04:03:40:546 CGPNotify::RegisterForNotification: Exiting with status = 0
GPSVC(3bc.ac8) 04:03:59:296 CGPNotify::RegisterForNotification: Entering withtarget Machine and event 0x1ac
GPSVC(3bc.ac8) 04:03:59:296 Client_InitialRegisterForNotification: User = machine, changenumber = 0
GPSVC(34c.748) 04:03:59:296 Target = Machine
GPSVC(3bc.ac8) 04:03:59:296 Client_RegisterForNotification: User = machine, changenumber = 0
GPSVC(3bc.ac8) 04:03:59:296 CGPNotify::RegisterForNotification: Exiting with status = 0
GPSVC(34c.748) 04:03:59:343 Target = Machine
GPSVC(34c.748) 04:03:59:343 Target = Machine,ChangeNumber 0
GPSVC(34c.3ac) 04:03:59:515 Target = Machine
GPSVC(34c.3ac) 04:03:59:531 Target = Machine, ChangeNumber 0
GPSVC(34c.3ac) 04:03:59:531 Sid = (null), dwTimeout = 600000, dwFlags = 268435456
GPSVC(34c.3ac) 04:03:59:531 LockPolicySection calledfor user <Machine>
GPSVC(34c.3ac) 04:03:59:546 Async Lock called
GPSVC(34c.3ac) 04:03:59:546 Reader Lock got immediately. m_cReadersInLock : 1
GPSVC(34c.3ac) 04:03:59:546 Sid = (null)
GPSVC(34c.3ac) 04:03:59:546 UnLockPolicySection called for user <Machine>
GPSVC(34c.3ac) 04:03:59:546 Found the caller in the ReaderHavingLock List. Removing it...
GPSVC(34c.3ac) 04:03:59:546 Settinglock state as notLocked
GPSVC(34c.3ac) 04:03:59:546 UnLocked successfully
GPSVC(34c.bdc) 04:04:00:000 CGPNotify::RegisterForNotification: Entering with target Machine and event 0xd04
GPSVC(34c.bdc) 04:04:00:000 Client_InitialRegisterForNotification: User = machine, changenumber = 0
GPSVC(34c.3ac) 04:04:00:000 Target =Machine
GPSVC(34c.bdc) 04:04:00:000 Client_RegisterForNotification: User = machine, changenumber = 0
GPSVC(34c.bdc) 04:04:00:000 CGPNotify::RegisterForNotification: Exiting with status = 0
GPSVC(34c.3ac) 04:04:00:000 Target = Machine, ChangeNumber 0
GPSVC(34c.748) 04:04:01:140 Target = Machine
GPSVC(34c.748) 04:04:01:140 Target = Machine, ChangeNumber 0
GPSVC(154.41c) 04:05:25:509CGPNotify::RegisterForNotification: Entering with target Machine and event 0x458
GPSVC(154.41c) 04:05:25:509 Client_InitialRegisterForNotification: User = machine, changenumber = 0
GPSVC(34c.3ac) 04:05:25:509 Target = Machine
GPSVC(154.41c) 04:05:25:525 Client_RegisterForNotification: User = machine, changenumber = 0
GPSVC(34c.3ac) 04:05:25:525 Target = Machine, ChangeNumber 0
GPSVC(154.41c) 04:05:25:525 CGPNotify::RegisterForNotification: Exiting with status = 0
GPSVC(154.41c) 04:05:25:759 CGPNotify::RegisterForNotification: Entering with target Machine and event 0x4e8
GPSVC(154.41c) 04:05:25:759 Client_InitialRegisterForNotification: User = machine, changenumber = 0
GPSVC(34c.3ac) 04:05:25:759 Target = Machine
GPSVC(154.41c) 04:05:25:775 Client_RegisterForNotification: User = machine, changenumber = 0
GPSVC(154.41c) 04:05:25:775 CGPNotify::RegisterForNotification: Exiting with status = 0
GPSVC(34c.3ac) 04:05:25:775 Target = Machine, ChangeNumber 0
GPSVC(34c.3ac) 04:05:59:217 Target = Machine
GPSVC(34c.3ac)04:05:59:233 Target = Machine, ChangeNumber 0
GPSVC(3bc.3cc) 04:05:59:389 CGPNotify::UnregisterNotification: Entering with event 0x1ac
GPSVC(3bc.3cc) 04:05:59:389 CGPNotify::AbortAsyncRegistration: No asyn registration is pending
GPSVC(3bc.3cc) 04:05:59:405 CGPNotify::UnregisterNotification: Canceling pending calls
GPSVC(3bc.3cc) 04:05:59:420 Client_CompleteNotificationCall: failed with 0x4c7
GPSVC(3bc.3cc) 04:05:59:420 CGPNotify::UnregisterNotification: Cancelled pending calls
GPSVC(3bc.3cc) 04:05:59:420 CGPNotify::UnregisterNotification: Exiting with dwStatus = 0x0
GPSVC(34c.360) 04:06:00:827 Target = Machine
GPSVC(34c.360) 04:06:00:827 Target = Machine, ChangeNumber 0
GPSVC(34c.360) 04:06:01:155 Target = Machine
GPSVC(34c.360) 04:06:01:171 Target = Machine, ChangeNumber 0
GPSVC(34c.fe8) 04:06:02:124 CGPNotify::RegisterForNotification: Entering with target Machine and event 0x218
GPSVC(34c.fe8) 04:06:02:140 Client_InitialRegisterForNotification: User = machine, changenumber = 0
GPSVC(34c.360) 04:06:02:155 Target = Machine
GPSVC(34c.fe8) 04:06:02:155 Client_RegisterForNotification: User = machine, changenumber = 0
GPSVC(34c.fe8) 04:06:02:171 CGPNotify::RegisterForNotification: Exiting with status = 0
GPSVC(34c.da4) 05:06:16:856 Target = Machine
GPSVC(34c.da4) 05:06:16:856 Target = Machine, ChangeNumber 0
GPSVC(34c.da4) 05:06:16:856 Target = S-1-5-20
GPSVC(34c.da4) 05:06:16:856 Could not find user by sid, finding user by session id
GPSVC(34c.da4) 05:06:16:856 Caller requesting for user notification/lock is from session 0
GPSVC(34c.da4) 05:06:16:856 Target = S-1-5-20, ChangeNumber 0
GPSVC(34c.da4) 05:06:16:856 Could not find user by sid, finding user by session id
GPSVC(34c.de8) 05:06:16:856 Target = S-1-5-20
GPSVC(34c.de8) 05:06:16:856 Could not find user by sid, finding user by session id
GPSVC(34c.de8) 05:06:16:872 Callerrequesting for user notification/lock is from session 0
GPSVC(34c.de8) 05:06:16:872 Target = S-1-5-20, ChangeNumber 0
GPSVC(34c.de8) 05:06:16:872 Could not find user by sid, finding user by session id
GPSVC(34c.de8) 05:06:16:872 Caller requesting for usernotification/lock is from session 0
GPSVC(34c.da4) 05:06:16:872Target = S-1-5-20
GPSVC(34c.da4) 05:06:16:872 Could not find user by sid, finding user by session id
GPSVC(34c.da4) 05:06:16:872 Caller requesting for user notification/lock is from session 0
GPSVC(34c.da4) 05:06:16:872 Target = S-1-5-20, ChangeNumber 0
GPSVC(34c.da4) 05:06:16:872 Could not find user by sid, finding user by session id
GPSVC(34c.da4) 05:06:16:872 Caller requesting for user notification/lock is from session 0
GPSVC(34c.de8) 05:06:16:887 Target = S-1-5-20
GPSVC(34c.de8) 05:06:16:887 Could notfind user by sid, finding user by session id
GPSVC(34c.de8) 05:06:16:887 Caller requesting for user notification/lock is from session 0
GPSVC(34c.de8) 05:06:16:887 Target = S-1-5-20, ChangeNumber 0
GPSVC(34c.de8) 05:06:16:887 Could not find user by sid, finding user by session id
GPSVC(34c.de8) 05:06:16:887 Caller requesting for user notification/lock is from session 0
GPSVC(34c.da4) 05:06:26:981 Setting GPsession state = 1
GPSVC(34c.de8) 05:06:32:341 SID = S-1-5-21-206128196-3657029889-627342018-7757
GPSVC(34c.de8) 05:06:32:356 bMachine = 0
GPSVC(34c.de8) 05:06:32:356 Setting GPsession state = 1
GPSVC(34c.de8) 05:06:32:356 Message Status = <Applying user settings...>
GPSVC(34c.778) 05:06:32:356 StartTime For network wait: 32140ms
GPSVC(34c.778) 05:06:32:356 Current Time: 3819953ms
GPSVC(34c.de8) 05:06:32:356 Setting GPsession state = 1
GPSVC(34c.778) 05:06:32:356 MaxTimeToWaitForNetwork: 5212ms
GPSVC(34c.778) 05:06:32:356 TimeRemainingToWaitForNetwork: 0ms
GPSVC(34c.778) 05:06:32:356 UserPolicy: Waiting for machine policy wait for network event with timeout 0 ms
GPSVC(34c.778) 05:06:32:388 GPLockPolicySection: Sid = (null), dwTimeout = 30000, dwFlags = 65538
GPSVC(34c.778) 05:06:32:388 LockPolicySection called for user <Machine>Hi,
Any update?
Just checking in to see if the suggestions were helpful. Please let us know if you would like further assistance.
Best Regards,
Andy Qi
TechNet Subscriber Support
If you are
TechNet Subscription user and have any feedback on our support quality, please send your feedback
here.
Andy Qi
TechNet Community Support
Maybe you are looking for
-
Error when compiling jasper report on Linux
Hey guys/gals :) I'm having trouble creating a jasper report on Linux. I'm getting the ff. error after i click the link to generate my report: Http status 500: exception: javax.servlet.ServletException: Servlet execution threw an exception root cause
-
Hi Friends, While posting customer down payment using F-29 , i have entered wrong bank entries & wrong customer name. so how i can change the bank name & customer name . Regards, Sanjeev
-
How to Setup Fiscal Calendars in Oracle BI Applications through DAC
Hi, I m new to OBI thing. I need to Setup Finscal calendar for "enterprise calendar using an Oracle EBS source system" and i got some martial but it is not helping out. Kindly help me out on this issue. ASAP. thanks in-advance Edited by: 862383 on Ma
-
When I go to the Photoshop help menu, I get a message that the Help center is not loading. Checking my applications menu, I see that the Adobe Help Viewer has a question mark by it. A message said I may have to reinstall the Help Center. Do I have to
-
Can't sync bluetooth with my macbook pro?
I get to the screen and make the iphone discoverable the macbook sees it then it fails to get the phone to open up to being able to enter the code.. I have tried a bunch of times. what am I doind wrong?