Cisco 4506 Sup Engine IV

I have a cisco 4506 with supervisor Engine IV.Initially when i put the switch on the supervisor engine light turns orange.after some diagnosis i found out that one of the fans on the power supply wasnt functioning properly.when i remove this power supply and power the switch the sup engine turns green.However the ethernet interfaces and gigabit ethernet interfaces on the line card r down no traffic is being processed on the switch.what could be the problem.Is there a way u should configure the 4506 to process packets

Hi Kwak,
Oki now let us resolve it!!!
Yes by default all the ports are into vlan 1 so it depends if you want to assign the ports into any other vlan you have to create vlan first. But ports will remain in down down state till the the time you connect any network device to it. Can you please confirm if you have connected any device like workstation or any other device to any port.
All the ports remain in down down state if they are not active.
Try to connect some device it should work
Regards,
Ankur

Similar Messages

  • Cisco 4506 Sup V Utlization

    I have got 4506 Sup V with 10GE. On the Sup V engine there is something called Utlization and the bottom there is 1 2 3 4 5 6 7. Can any body tell me what is that about.
    And also how to check the backplane utlization on a switch.

    Hello,
    according to the data sheet (see the link below), the LED's you see are used for the following:
    Switch utilization load: 1- to 100-percent aggregate switching usage
    Cisco Catalyst Series Supervisor Engine V-10GE
    http://www.cisco.com/en/US/products/hw/modules/ps2797/products_data_sheet0900aecd801c5c66.html
    HTH,
    GNT

  • Cisco 4006 & 4506 sup engine

    Hi,
    My existing 4006 chassis is using Supervisor III (WS-X4014).
    I have another 4506 chassis using Supervisor IV (WS-X4515) and a Netflow Services Card (WS-F4531) build on top of it.
    I need Netflow Services Card in 4006, so can I just replace the Supervisor IV (WS-X4515) used in cisco 4006? Is it compatible with 4006?
    Any suggestion?
    Thanks,
    HowYee

    hi HowYee,
    http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps4324/product_data_sheet0900aecd8035cf2b.html
    according to that document, it is not possible if you want to put supIV to 4006 chassis
    Chassis and Line-Card Support
    You  can deploy the supervisor engine IV in single-chassis nonredundant mode  in the Cisco Catalyst 4503, 4503-E, 4506, and 4506-E chassis. You can  also deploy it in single-chassis redundant mode as an option in the  Cisco Catalyst 4507R chassis (slots 1 and 2 only) and Cisco Catalyst  4507R-E/4507R+E chassis (slots 3 and 4).
    The  supervisor engine IV is compatible with the classic Cisco Catalyst 4500  and the E-series Cisco Catalyst 4500 Line Cards. Table 1 gives  performance information for the Cisco Catalyst 4500 Series Supervisor  Engine IV.
    regards,

  • 4506 & SUP V Management IP address question.....

    Hello all, I have two questions. The new 4506 SUP V engines don't have the good old SCO interface that I'm used to. So, since it's running an IOS now instead of the old CATos, I figured I'l create a new vlan and then make it the management IP address by using the 'MANAGEMENT' command (like in the old 2900's). Well, that didn't work either, so my question is...on what int. do I configure the mgnt. IP address?
    -thank you....

    Russ,
    In the current version (up to 2.1) the Management IPs for blades are required to belong to the same subnet as the Management Interfaces of the Fabric Interconnects.  This is due to the way we proxy the KVM request from Management Interfaces to the Blades CIMC.  In a future release we're investigating breaking the blade IPs into their own subnet/VLAN but this is a ways out - no committed date at this time.
    We understand this puts quite a requirment on the size of the Management Subnet, but with proper design it shouldn't be much of an issue.
    Regards,
    Robert

  • Cisco 4506 getting restarted

    I have Cisco 4506 with Sup V. It is has been joined with one of the VTP domain, but the switch is in Client mode. There are around 10 switches which are connecteing to that switch with trunk ports.
    The switches which are connecting, some are in Transparent Mode and some in Client mode.
    This switch is a root switch. The problem what I am facing with this switch is it has got hanged twice and restarted once. There is no config changes which are been made since it has been installed.
    Can anybody please help me out.

    have you physically changed the switch from one place to another, because even an voltage problem could also lead in such situationz, apart from this, you also try upgrading the OS in the switch. becuase changing the VTP domain it is not at all possible in making a switch getting restarted or hang.
    rate this post if this information is helpful.

  • Cisco 4506 network switch

    i need details of cisco 4506 network switch with supervisor module

    Hi,
    You can visit
    http://cisco.com/en/US/products/hw/switches/ps4324/prod_brochure_list.html
    a Good link on 4500 supervisor engines.
    Regards
    Dinesh
    http://Knowurtech.com
    (Good technical articles. Submit your articles and get featured on our website. Send email to [email protected] To know the benefits http://www.knowurtech.com/be_an_expert.html)
    Hi,
    You can visit
    http://cisco.com/en/US/products/hw/switches/ps4324/prod_brochure_list.html
    a Good link on 4500 supervisor engines.
    Regards
    Dinesh
    http://Knowurtech.com
    (Good technical articles. Submit your articles and get featured on our website. Send email to [email protected] To know the benefits http://www.knowurtech.com/be_an_expert.html)

  • WS-X6748-GE-TX sup engine?

    We have a 6509 with a 4000W power supply, a high speed fan and a s2-pfc2 running catos 8.4.2. The 6748 is being denied power because it is not recognized. We tried another sup engine with ios 12.1(27), it recognized the card but said it was incompatible and denied power. Software Advisor recomends 8.1 or 12.1(26) as the minimum required releases for the card. What else have we not tried? Information has been hard to find as to what sup engine it needs to run, but the Software Advisor accepted our config.

    I see that you are using a Sup 2. The 6748 is designed for use only with a Sup 720. See here: http://www.cisco.com/en/US/products/hw/switches/ps708/products_data_sheet0900aecd8017376e.html

  • Ask the Expert: Integrating Cisco Identity Service Engine (ISE) 1.2 for BYOD

    With Eric Yu and Todd Pula 
    Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions  about integrating Cisco ISE 1.2 for BYOD with experts Eric Yu and Todd Pula.
    Cisco Bring Your Own Device (BYOD) is an end-to-end architecture that orchestrates the integration of Cisco's mobile and security architectures to various third-party components. The session takes a deep dive into the available tools and methodologies for troubleshooting the Cisco BYOD solution to identify root causes for problems that stem from mobile device manager integration, Microsoft Active Directory and certificate authority services, and Cisco Enterprise Mobility integration to the Cisco Identity Services Engine (ISE). 
    Todd and Eric recently delivered a technical workshop that helps network designers and network engineers understand integration of the various Cisco BYOD components by taking a deep dive to analyze best practice configurations and time-saving troubleshooting methodologies. The content consisted of common troubleshooting scenarios in which TAC engineers help customers address operational challenges as seen in real Cisco BYOD deployments.
    Eric Yu is a technical leader at Cisco responsible for supporting our leading-edge borderless network solutions. He has 10 years of experience in the telecommunications industry designing data and voice networks. Previous to his current role, he worked as a network consulting engineer for Cisco Advance Services, responsible for designing and implementing Cisco Unified Communications for Fortune 500 enterprises. Before joining Cisco, he worked at Verizon Business as an integration engineer responsible for developing a managed services solution for Cisco Unified Communications. Eric holds CCIE certification in routing and switching no. 14590 and has two patents pending related to Cisco's medianet.   
    Todd Pula is a member of the TAC Security and NMS Technical Leadership team supporting the ISE and intrusion prevention system (IPS) product lines. Todd has 15 years of experience in the networking and information security industries, with 6 years of experience working in Cisco's TAC organization. Previous to his current role, Todd was a TAC team lead providing focused technical support on Cisco's wide array of VPN products. Before joining Cisco, he worked at Stanley Black & Decker as a network engineer responsible for the design, configuration, and support of an expansive global network infrastructure. Todd holds his CCIE in routing and switching no. 19383 and an MS degree in IT from Capella University.
    Remember to use the rating system to let Eric and Todd know if you have received an adequate response.
    Because of the volume expected during this event, Eric and Todd might not be able to answer every question. Remember that you can continue the conversation in the Security community, subcommunity AAA, Identity and NAC, shortly after the event. This event lasts through November 15, 2013. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.

    Hi Antonio,
    Many great questions to start this series.  For the situation that you are observing with your FlexConnect configuration, is the problem 100% reproducible or is it intermittent?  Does the problem happen for one WLAN but not another?  As it stands today, the CoA-Ack needs to be initiated by the management interface.  This limitation is documented in bug CSCuj42870.  I have provided a link for your reference below.  If the problem happens 100% of the time, the two configuration areas that I would check first include:
    On the WLC, navigate to Security > RADIUS > Authentication.  Click on the server index number for the associated ISE node.  On the edit screen, verify that the Support for RFC 3576 option is enabled.
    On the WLC, navigate to the WLANs tab and click on the WLAN ID for the WLAN in question.  On the edit screen, navigate to Security > AAA and make sure the Radius Server Overwrite interface is unchecked.  When this option is checked, the WLC will attemp to send client authentication requests and the CoA-Ack/Nak via the dynamic interface assigned to the WLAN vs. the management interface.  Because of the below referenced bug, all RADIUS packets except the CoA-Ack/Nak will actually be transmitted via the dynamic interface.  As a general rule of thumb, if using the Radius NAC option on a WLAN, you should not configure the Radius Server Overwrite interface feature.
    Bug Info:  https://tools.cisco.com/bugsearch/bug/CSCuj42870
    For your second question, you raise a very valid point which I am going to turn into a documentation enhancement request.  We don't currently have a document that lists the possible supplicant provisioning wizard errors that may be encountered.  Please feel free to post specific errors that you have questions about in this chat and we will try to get you answers.  For most Android devices, the wizard log file can be found at /sdcards/downloads/spw.log.
    As for product roadmap questions, we won't be able to discuss this here due to NDA.  Both are popular asks from the field so it will be interesting to see what the product marketing team comes up with for the next iterration of ISE.
    Related Info:
    Wireless BYOD for FlexConnect Deployment Guide

  • Cisco Identity Services Engine (ISE) Version 1.2: What's New in Features and Troubleshooting Options

    With Ali Mohammed
    Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about what’s new in Cisco Identity Services Engine (ISE) Version 1.2 and to understand the new features and enhanced troubleshooting options with Cisco expert Ali Mohammed.
    Cisco ISE can be deployed as an appliance or virtual machine to enforce security policy on all devices that attempt to gain access to network infrastructure. ISE 1.2 provides feature enrichment in terms of mobile device management, BYOD enhancements, and so on. It also performs noise suppression in log collection so customers have greater ability to store and analyze logs for a longer period.
    Ali Mohammed is an escalation engineer with the Security Access and Mobility Product Group (SAMPG), providing support to all Cisco NAC and Cisco ISE installed base. Ali works on complicated recreations of customer issues and helps customers in resolving configuration, deployment, setup, and integration issues involving Cisco NAC and Cisco ISE products. Ali works on enhancing tools available in ISE/NAC that are required to help troubleshoot the product setup in customer environments. Ali has six and a half years of experience at Cisco and is CCIE certified in security (number 24130).
    Remember to use the rating system to let Ali know if you have received an adequate response.
    Because of the volume expected during this event, Ali might not be able to answer each question. Remember that you can continue the conversation on the Security community, sub-community shortly after the event. This event lasts through September 6, 2013. Visit this forum often to view responses to your questions and the questions of other community members.

    Hi Ali,
    We currently have a two-node deployment running 1.1.3.124, as depicted in diagram:
    http://www.cisco.com/en/US/docs/security/ise/1.2/upgrade_guide/b_ise_upgrade_guide_chapter_010.html#ID89
    Question 1:
    After step 1 is done, node B becomes the new primary node.
    What's the license impact at that stage, when the license is mainly tied to node A, the previous primary PAN?
    Step 3 says to obtain a new license that's tied to both node A & node B, as if it's implying an issue would arise, if we leave node B as the primary PAN, instead of reverting back to node A.
    =========
    Question 2:
    When step 1 is completed, node B runs 1.2, while node A runs 1.1.3.124.
    Do both nodes still function as PSN nodes, and can service end users at that point? (before we proceed to step 2)
    Both nodes are behind our ACE load balancer, and I'm trying to confirm the behavior during the upgrade, to determine when to take each node out of the load balancing serverfarm, to keep the service up and avoid an outage.
    ===========
    Question 3:
    According to the upgrade guide, we're supposed to perform a config backup from PAN & MnT nodes.
    Is the config backup used only when we need to rollback from 1.2 to 1.1.3, or can it be used to restore config on 1.2?
    It also says to record customizations & alert settings because after  the upgrade to 1.2, these settings would change, and we would need to  re-configure them.
    Is this correct? That's a lot of screen shots we'll need to take; is there any way to avoid this?
    It says: "
    Disable services such as Guest, Profiler, Device Onboarding, and so on before upgrade and enable them after upgrade. Otherwise, you must add the guest users who are lost, and devices must be profiled and onboarded again."
    Exactly how do you disable services? Disable all the authorization policies?
    http://www.cisco.com/en/US/docs/security/ise/1.2/upgrade_guide/b_ise_upgrade_guide_chapter_01.html#reference_4EFE5E15B9854A648C9EF18D492B9105
    ==================
    Question 4:
    The 1.1 user guide says the maximum number of nodes in a node group was 4.
    The 1.2 guide now says the maximum is 10.
    Is there a hard limit on how many nodes can be in a node group?
    We currently don't use node group, due to the lack of multicast support on the ACE-20.
    Is it a big deal not to have one?
    http://www.cisco.com/en/US/customer/docs/security/ise/1.2/user_guide/ise_dis_deploy.html#wp1230118
    thanks,
    Kevin

  • Ask the Expert: Configuration and Troubleshooting the Cisco Application Control Engine (ACE) load balancer

    With Ajay Kumar and Telmo Pereira 
    Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about configuration and troubleshooting the Cisco Application Control Engine (ACE) load balancer with Cisco expert Ajay Kumar and Telmo Pereira. The Cisco ACE Application Control Engine Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers is a next-generation load-balancing and application-delivery solution. A member of the Cisco family of Data Center 3.0 solutions, the module: Helps ensure business continuity by increasing application availability Improves business productivity by accelerating application and server performance Reduces data center power, space, and cooling needs through a virtualized architecture Helps lower operational costs associated with application provisioning and scaling
    Ajay Kumar  is a customer support engineer in the Cisco Technical Assistance Center in Brussels, covering content delivery network technologies including Cisco Application Control Engine, Cisco Wide Area Application Services, Cisco Content Switching Module, Cisco Content Services Switches, and others. He has been with Cisco for more than four years, working with major customers to help resolve their issues related to content products. He holds DCASI and VCP certifications. 
    Telmo Pereira is a customer support engineer in the Cisco Technical Assistance Center in Brussels, where he covers all Cisco content delivery network technologies including Cisco Application Control Engine (ACE), Cisco Wide Area Application Services (WAAS), and Digital Media Suite. He has worked with multiple customers around the globe, helping them solve interesting and often highly complex issues. Pereira has worked in the networking field for more than 7 years. He holds a computer science degree as well as multiple certifications including CCNP, DCASI, DCUCI, and VCP
    Remember to use the rating system to let Ajay know if you have received an adequate response.
    Ajay and Telmo might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation on the Data Center sub-community discussion forum Application Networking shortly after the event.
    This event lasts through July 26, 2013. Visit this forum often to view responses to your questions and the questions of other community members.

    Hello Krzysztof,
    Another set of good/interesting questions posted. Thanks! 
    I will try to clarify your doubts.
    In the output below both resources (proxy-connections and ssl-connections rate) are configured with a min percentage of resources (column Min), while 'Max' is set to equal to the min.
    ACE/Context# show resource usage
                                                         Allocation
            Resource         Current       Peak        Min        Max       Denied
    -- outputs omitted for brevity --
      proxy-connections             0      16358      16358      16358      17872
      ssl-connections rate          0        626        626        626      23204
    Most columns are self explanatory, 'Current' is current usage, 'Peak' is the maximum value reached, and the most important counter to monitor 'Denied' represents the amount of packets denied/dropped due to exceeding the configured limits.
    On the resources themselves, Proxy-connections is simply the amount of proxied connections, in other words all connections handled at layer 7 (SSL connections are proxied, as are any connections with layer 7 load balance policies, or inspection).
    So in this particular case for the proxy-connections we see that Peak is equal to the Max allocated, and as we have denies we can conclude that you have surpassed the limits for this resource. We see there were 17872 connections dropped due to that.
    ssl-connections rate should be read in the same manner, however all values for this resource are in bytes/s, except for Denied counter, that is simply the amount of packets that were dropped due to exceeding this resource. 
    For your particular tests you have allocated a min percentage and set max equal to min, this way you make sure that this context will not use any other additional resources.
    If you had set the max to unlimited during resource allocation, ACE would be allowed to use additional resources on top of those guaranteed, if those resources were available.
    This might sound a great idea, but resource planning on ACE should be done carefully to avoid any sort of oversubscription, specially if you have business critical contexts.
    We have a good reference for ACE resource planning that contains also description of all resources (this will help to understand the output better):
    http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/virtualization/guide/config.html#wp1008224
    1) When a resource is utilized to its maximum limit, the ACE denies additional requests made by any context for that resource. In other words, the action is to Drop. ACE  should in theory silently drop (No RST is sent back to the client). So unless we changed something on the code, this is what you should see.
    To give more context, seeing resets with SSL connections is not necessarily synonym of drops. As it is usual to see them during normal transactions.
    For instance Microsoft servers are usually ungracefully terminating SSL connections with RESET. Also when there is renegotiation during an SSL transaction you may see RESETS, but this will pass unnoticed for end users. 
    2)  ACE will simply drop/ignore new connections when we reach the maximum amount of proxied connections for that context. Exisiting connections will continue there.
    As ACE doesn't respond back, client would simply retransmit, and if he is lucky maybe in the next attempt he will be able to establish the connection.
    To overcome the denies, you will definitely have to increase the resource allocation. This of course, assuming you are not reaching any physical limit of the box.
    As mentioned setting max as unlimited might work for you, assuming there are a lot of unused resources on the box.
    3)  If a new connection comes in with a sticky value, that matches the sticky entry of a real server, which is already in MAXCONNS state, then both the ACE module/appliance should reject the connection and that sticky entry would be removed.
    The client would at that point reestablish a new connection and ACE would associate a new sticky entry with the flow for a new RSERVER after the loadbalancing decision.
    I hope this makes things clearer! Uff...
    Regards,
    Telmo

  • Help, error connection Cisco Identity Services Engine with AD, global catalog port status error

    Dear all,
    I have Cisco Indentity Services Engine, that  connected to Active Directory. When I test connection detailed,
    the result is error, said:
    Test Connection Results
    This dialog shows the detailed logs for the operation for: idsv0018.
    Status: FAILED: Global Catalog port status error.
    Can anyone help?
    I believe,  because this error, I can't search group of AD, at Cisco ISE.
    FYI: the connection from Cisco ISE to AD, joined with successful result.
    Thanks,
    Jerri

    It's clears that when ISE tries to  find the GC using the _gc._tcp. DNS query. It doesn't find that  information on the Domain controller. The GC information is missing on  the DC.
    gc._tcp.DnsForestName
    Allows a client to locate a Global Catalog (gc) server for this domain.
    Jatin Katyal
    - Do rate helpful posts -

  • Cisco Identity Service Engine (ISE) (CSCup22534)--bug information

    I can see this bug information, can you please help?
    Cisco Identity Service Engine (ISE) (CSCup22534)

    Backup Data Type
    Cisco ISE allows you to back up data from the primary or standalone Administration node and from the Monitoring node. Backup can be done from the CLI or user interface.
    Cisco ISE allows you to back up the following type of data:
    Configuration data—Contains both application-specific and Cisco ADE operating system configuration data.
    Operational Data—Contains monitoring and troubleshooting data.
    Restore operation, can be performed with the backup files of previous versions of Cisco ISE and restored on a later version. For example, if you have a backup from an ISE node from Cisco ISE, Release 1.2, you can restore it on Cisco ISE, Release 1.3.
    http://www.cisco.com/c/en/us/td/docs/security/ise/1-3/admin_guide/b_ise_admin_guide_13/b_ise_admin_guide_sample_chapter_01100.html#reference_4F69987D3294499E95C1B652C4D1E73D

  •  Cisco Identity Services Engine VM (eDelivery) - Part # L-ISE-VM-K9=

    Hello,
    I would like to know, if the following will run on Microsoft Hyper V. (Windows 2008 R2)
    Cisco Identity Services Engine VM (eDelivery) - Part # L-ISE-VM-K9=
    Thank you and best regards

    Hello,
    I would like to know, if the following will run on Microsoft Hyper V. (Windows 2008 R2)
    Cisco Identity Services Engine VM (eDelivery) - Part # L-ISE-VM-K9=
    Thank you and best regards

  • Help, error connection Cisco Identity Services Engine with AD.

    Dear all,
    I have Cisco Indentity Services Engine, that  connected to Active Directory. When I test connection detailed,
    the result is error, said:
    Test Connection Results
    This dialog shows the detailed logs for the operation for: idsv0018.
    Status: FAILED: Global Catalog port status error.
    Can anyone help?
    I believe,  because this error, I can't search group of AD, at Cisco ISE.
    FYI: the connection from Cisco ISE to AD, joined with successful result.
    Thanks,
    Jerri

    Hello Jerri,
    Please follow these steps:
    1.    Make sure that ISE can connect to the Global Catalog (by Default  it is Domain Controller) on the following ports (see table below)
    2.    Check Windows Event Viewer > System Events on your Domain  Controller and locate any errors / warning. Note down Event ID
    3.    If there are any errors, other client computers in your AD domain  are likely to experience problems locating User groups, Printers etc.
    4.    If the above steps are confirmed, then you need to fix  .msdcs.ad-domain.xyz and the records, on your primary DNS (Master Domain  Controller by default)
    5.    To fix those records, you may refer to the following link for more  guidance on how to do it. Or your Windows AD Administrator should  fix it
    How DNS Support for Active Directory Works
    http://technet.microsoft.com/en-us/library/cc759550
    Otherwise let me know about the detail on Event IDs you notice in your Windows Event Viewer
    Service Name
    UDP
    TCP
    LDAP
    3268 (global catalog)
    LDAP
    3269 (global catalog Secure Sockets Layer [SSL])
    LDAP
    389
    389
    LDAP
    636 (SSL)
    RPC/REPL
    135 (endpoint mapper)
    Kerberos
    88
    88
    DNS
    53
    53
    SMB over IP
    445
    445

  • Cisco 4506 switch in Err-disable mode

        I have a Cisco 4506 switch and its 10 gig interface is in error disable mode.I tried Shut and no shut the port couple of times but it transits from up to down number of times and then to error-disable. Did anyone else encountered this issue before. kindly advise the solution for the same. thanks         

    Hi Shariq,
    Can you post the output of the show interface status err-disable ? That output contains the reason for putting your port into err-disabled state.
    Best regards,
    Peter

Maybe you are looking for

  • Zen Visio

    I have recently bought a Vision M, I love the player but I have some issues with it. Primarily, when navigating whenever i try to access the Artist page, it takes a good 0 seconds to load; is this normal? iPods seem to manage it a lot faster. Also, w

  • What is the "Stationary Pad" in the Get Info window?

    What is it's function? Thanks

  • DBS_ORA_SCHEMA environment variable?

    Hi Gurus, I am doing a refresh from Production (P01) to Development (D01). I am having problem to start SAP in D01. I have run the OPS$ script but still unsuccessful. Based on note 534765, it advice to change environment dbs_ora_schema to SAP<SID>. B

  • Custom Filter-Depend

    Hi all,    i am very confusing. i have couple of questions for you. 1. what is filter-depend in se18? 2. there is a filter attach with BBP_DOC_CHECK_BADI and BBP_DOC_CHECK_BADI, how does it work? because filter is a data element then what the logic b

  • NoClassDefFoundError  JDK5.0

    I have installed J2EE1.4 SDK where JDK5.0 included. When I tried "helloWorldApp.java", javac can work for compiling, but java can not execute the class due to a error. The error is: ======================================= Exception in thread "main" j