Cisco SG500 switch and 5 gbit links without stacking

Does the sfp ports link up to 5 gigabit when you don't use the stacking function?

Good question.  I can tell you that yesterday I was adding a switch to an existing stack via fiber and on the master switch I accidentally plugged into slot 3 or 4.  On the new switch I did the same and connected to port 3 or 4 and noticed that it came up as a trunk link and did not join the stack.  In my case I wanted it to join the stack and discovered that 1G Fiber stack is only supported in slots 1 and 2.  I have not idea if the trunk was 5G, but I think not because my fiber would only be 1G.  I think the 5G link uses copper SFP, no?

Similar Messages

  • Cisco SG500's and VLAN's

    OK so here's what I am trying to accomplish with 3 Cisco SG500-52 switches. I have created 4 VLAN's on one SG500 that I'm calling my core switch and it's set to routing mode. My VLAN's are as follows 400 (Infrastructure ESXI hosts, firewall, etc), 401 (VoIP), 402 (Users), and 403 (Wireless). I have interfaces configured and everything is routing without issue for me across my subnets and remote access communities across 3 offices.
    Where I am unsure is on the SG500 I have set as a L2 switch and my ESXi host are connected (I do have 10 ports on an isolated VLAN for iSCSI traffic) is do I need to create VLAN 400 and mark those as untagged ports? Then should I use 1-2 ports and set them as trunked ports and tag them to 400 to my core switch?
    If so on the core switch do I create trunk ports and tag them for the VLAN's on this switch that would access the L2 switch? Is that also the case for the other SG500 that I have that are all devices for VLAN 402?
    Am I overcomplicating this?
    Thanks in advance for any help.

    Hi Sdonnelly2,
    For vlan 402 and 400 on the uplink to your sg500(L2) would be 400U and 402T.
    Other interfaces for VoIP phones on vlan 401 would be configured to 401T. This is if your phones are expecting tagged traffic, if not they would be configured to 401U.
    For Vlan 402 on other interfaces would always be 402U. PC will only communicate with untagged traffic
    For Vlan 403 wireless the uplink access point would need to be configured (400U,401T,402T,403T)
    This might be more information than expected, but i hope i have answered any other questions you had.

  • Cisco CE500 Switch and SPAN Port Monitoring

    Does the Cisco CE500 switch support SPAN/Port Monitoring? If so, how is this configured via the browser?
    Thanks

    Please check this document on Cisco.
    http://www.cisco.com/en/US/products/hw/switches/ps708/products_tech_note09186a008015c612.shtml#Cat500

  • Cisco 3850 Switch and Windows 7 IP Conflicts

    Team,
    Last evening (Christmas eve) we setup a pair of Cisco 3850 with IP Base version 3.3.35SE (recommended) and 3.7.0E (very latest).
    We got these to replace a very old switch that had died. Attached to this network are windows 7 PC's with all the standard patches, service packs, etc.
    with standard port configs - no PC would work - and in fact on each screen we got the windows 7 IP Conflict pop up box.
    This seemed very odd to us, as we know these IP's are all static (no dhcp on this segment at all)
    we went with a very vanilla config on each port
    interface g1/0/1
    switchport host
    that is it - nothing special at all.
    well, after hours of research we found the 3850 has a problem where its "ip device tracking" (even though disabled, by way of NOT being enabled on any interface) will effect the windows 7 PC's ip address in use detection port start up phase!
    This is a very big problem. I am frankly SHOCKED Cisco would release a major switch that is going to not work when connected to the average network with windows 7 PC's.
    we tried 3+ hours of prescribed work-arounds found when researching this issue -
    ip device tracking probe delay 10 (global config)
    ip device tracking max 0 (disabed, on interface)
    finally,
    nmsp attach suppress (interface, however this appears to be a default command in all IOS-XE versions we tried, as the command did NOT show in the show run) . this effected many different nic card vendors (laptops, desktops) and nic card drivers levels from old to very recent.
    Finally,
    we compared a 3850 in another location to this one - and we never got HIT by this problem before because that 3850 only as TRUNK ports and no windows 7 hosts directly attached.
    Doing more research, I found out this also can effect vmware guests running windows SERVER.
    this is now a huge issue as we have a scheduled deployment of 3850's throughout our network which is going to be put on hold.
    the work-around I came up with which is not great is -
    Make ALL the "access" ports connected to PC TRUNK ports and leave the NATIVE vlan (untagged) as the vlan you want the PC's to be in
    interface g1/0/1
    switchport mode trunk
    switchport trunk native vlan 1
    this is NOT an acceptable workaround as this presents security issues even with
    switchport trunk allowed vlan 1, etc. as the only allowed vlan.
    Note: this issue manifested itself and windows 7 PC's were UNABLE to use the network. if you do "ipconfig /all | more" you would see
    192.168.0.140(duplicate) and the interface would actually use 169.254.0.239(duplicate) so the duplicate message appeared twice in the output.
    1) With and without an SVI interface on each 3850 for the vlan where the windows 7 machines had a duplicate
    2) when we had an SVI and the command ip device tracking probe use-svi (or whatever the hidden command is I forget now, but it took it)
    3) when we had aaa new-model configured - and not configured - thinking this was some artifact of having aaa turn on something like 802.1x port state
    4) when could confirm NO DHCP SNOOPING
    5) when we DID not use static IP's - and had the switch assign DHCP addresses - the Windows 7 PC's STILL had duplicates and didnt work for their "Just leased" ip's.
    6) when we could confirm ios-xe ip device tracking = disabled with show ip device tracking status, etc.
    This is a major problem for this 3850 and unless we get a definitive answer on why this is happening and how we can rectify we are going to have to return our 3850's and get HP Procurve's something I would rather avoid doing. There is NO REASON I can imagine other than older switches who's ports default to ROUTED ports (i.e.. no ip switchport) where a switch should not at least function as a bare switch with essentially a default configuration out of the box.
    Any ideas? I'm working well now with the ports ALL in trunking mode with vlan 1 native, but this is not a scalable workaround we can live with as we have security risks of a port not blocking certain vlans from going out ports to pc's, etc. that attackers could send tags on at that point, etc.
    thanks,
    Joe Brunner
    #19366

    thanks for replying - i'm not onsite (its a standalone network) - but here is what it is -
    Answers in line -
    This all stems from a switch replacement correct?
    yes a 10 year old Allied Telesyn switch was replaced that had no config - like a hub, just used for connectivity.
    Are these 3850's in a stack?
    >yes, tested all aspects of the stack many times.
    Does it have a managment ip address -If so, is it using the old switch ip address
    >old switch had no ip - i made a "management interface" on vlan 1 - BUT no ip on the built-in management interface on the switch.
    What are they connecting to? (a router/L3 switch/anohter switch- cisco-HP etc..)
    >various other devices - only 1 link back to a single 3750x stack. that switch is "hardened" so to speak to reveal or propagate very little by design.
    How are they connected( L3 interface/L2 trunk/access port)
    >all ports are left in trunk mode with vlan 1 as the active and untagged port. this was the workaround done to ever get the switch going. in "out of the box" or default mode as we initially wanted (no config) links to windows 7 PC's didnt work. links to linux or other devices non-windows did work!
    Are thse switches performing inter-vlan routing or just acting as host switches?
    >dumb flat network, no routing.
    Is ip routing enabled?
    >not unless enabled on 3850 by default. I didnt type "ip routing"
    Do you have multiple vlans in your network and if so ar ethe being propergated to these new switches?
    Your 7 pcs = are they just client pcs not servers?
    client PC's - no servers OS per say.
    can you confirm something like ICS isnt enabled (Internet connection sharing)  on any of them?
    >yes not enabled.
    Are the just using one NIC each?
    > one machine is dual homed - but we know where its "second nic" goes - to another cisco network which is NOT connected back to this one. we traced all our ports a few times thinking even perhaps some small hub was "reflecting" traffic back to us - like a blackbox. Strangest thing -
    default config out of the box - with ALL ports SHUTDOWN EXCEPT the single windows 7 facing port - the windows 7 machine STILL registered an IP CONFLICT when connected to the 3850 - even when it had NO SVI's!!! (i know mind numbing). if you disconnected the pc and connected it to an old cisco switch - it worked fine!!! wow.
    sh switch
    2 identical 3850's in working stack. power and network stacked. both at same version, etc - upgraded each time with "software install file flash:<long ios name>.bin
    tested all power and general 3850 stacking. saw no issues.
    sh int trunk
    >all ports are now trunks (hence the workaround used to get it up).
    has 20 trunks to PC's and some single connected switches (far away on fiber) - all allow only vlan 1 - no other vlans were created - very very simple network. vlan 1 is native
    sh vlan brief
    >just vlan 1 - no vlans created, checked this many times - had vlan 100 at one point - made sure it was gone over a period of hours.
    sh vtp status
    not setup - left complete default; no vtp domain set - connected to all switches in transparent model if a switch connection exists.
    sh cdp neighbours
    cant post (for god and country LOL) but there is one link back to our "core" so to speak - that switch is hardened not to allow any settings to slip over to new switches so hence no vtp, cdp is one to help troubleshooting.
    sh ip route
    just the L and C routes for the vlan 1 ip address 192.168.17.1/24
    no static routes
    no vlan interfaces other than int vlan 1
    no ip address on g0/0/0 -> the default 3850 management interface hard assigned to the 3850 VRF you cant remove.
    int g0/0/0
    ip vrf forwarding Switch_Mgmt
    i can get over there if you think of anything else key to show the group.
    thanks,
    Joe

  • AAA and Cisco MDS switches.........

    have configured Cisco ACS 4.0 (TACACS) with Windows AD for all Cisco MDS switches and it is working fine. But local "admin" access to the Cisco MDS switches via telnet is not working. At the same time , if I create a user with "network-admin" role locally, that works but not the default admin user.
    Could anyone help me in this regard.

    local. Below is the script I used to configure TACACS (Cisco ACS 4.0) on Cisco MDS switches.
    config t
    # Enable TACACS+
    tacacs+ enable
    tacacs-server host nnn.nnn.nnn.nnn key 0 xxxxxx
    tacacs-server host mmm.mmm.mmm.mmm key 0 xxxxx
    # Specify TACACS+ Server groups
    aaa group server tacacs+ tacgrp
    server nnn.nnn.nnn.nnn
    server mmm.mmm.mmm.mmm
    aaa authentication login default group tacgrp
    aaa authentication login console local
    # Enable TACACS+ Accounting
    aaa accounting default group tacgrp local
    end
    copy running-config startup-config
    Thanks
    MOhan

  • Converting Eth port to FC port in a cisco 6001 switch

    Hi,
    Back to forum after a long time. I have one issue to discuss regarding cisco 6001 switch. We purchased a new 6001 switch. Want to convert some of the Ethernet ports out of total 48 to FC to join the switch into a existing fabric.
    cisco Nexus 6001 Chassis ("Norcal 64 Supervisor")  - This is what H/W version look like from show version command.
    In the past, we have quite a few Cisco 5548UP switch and the way convert the Ethernet port into FC port is, by going to correct slot/module and then
    (config)# slot 1
    (config-slot)# port 41-48 type fc
    Then "reload" willl complete the conversion. But in the new 6001 switch, it throws the following error when above command is typed. We have full license for the switch including  FC_FEATURES_PKG
    "ERROR: Module type doesn't support this CLI"
    We are running firmware : 6.0(2)N2(2)
    Any help in this regard will be helpful.
    Thanks.

    I have this exact same error;
     show ver
    Cisco Nexus Operating System (NX-OS) Software
    TAC support: http://www.cisco.com/tac
    Documents: http://www.cisco.com/en/US/products/ps9372/tsd_products_support_series_home.html
    Copyright (c) 2002-2014, Cisco Systems, Inc. All rights reserved.
    The copyrights to certain works contained herein are owned by
    other third parties and are used and distributed under license.
    Some parts of this software are covered under the GNU Public
    License. A copy of the license is available at
    http://www.gnu.org/licenses/gpl.html.
    Software
      BIOS:      version 1.5.0
      loader:    version N/A
      kickstart: version 7.0(5)N1(1)
      system:    version 7.0(5)N1(1)
      Power Sequencer Firmware:
                 Module 1: version v4.0
                 Module 2: version v4.0
      Fabric Power Sequencer Firmware: Module 1: version v4.0
      Microcontroller Firmware:        version v1.2.0.5
      QSFP Microcontroller Firmware:
                 Module 2: v1.3.0.0
      SFP Microcontroller Firmware:
                 Module 1: v1.1.0.0
      BIOS compile time:       12/29/2012
      kickstart image file is: bootflash:///n6000-uk9-kickstart.7.0.5.N1.1.bin
      kickstart compile time:  10/29/2014 22:00:00 [10/30/2014 11:46:56]
      system image file is:    bootflash:///n6000-uk9.7.0.5.N1.1.bin
      system compile time:     10/29/2014 22:00:00 [10/30/2014 11:47:58]
    Hardware
      cisco Nexus 6001 Chassis ("Nexus 64 Supervisor")
      Intel(R) Xeon(R) CPU  @ 2.00 with 8238120 kB of memory.
      Processor Board ID FOC181506P3
      Device name: xxxxxxxxxxxxxx
      bootflash:    7823360 kB
    Kernel uptime is 3 day(s), 17 hour(s), 25 minute(s), 49 second(s)
    Last reset at 642096 usecs after  Fri Feb 27 15:24:40 2015
      Reason: Disruptive upgrade
      System version: 6.0(2)N2(3)
      Service:
    plugin
      Core Plugin, Ethernet Plugin, Fc Plugin
    xxxxxx# conf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    xxxxxx(config)# slot 1
    xxxxxx# port 47-48 type fc
    ERROR: Module type doesn't support this CLI

  • Remote Command Tool for Cisco Routers/Switches

    Is anyone aware of any tools or scripts out there which allow preconfigured commands to be remotely run again Cisco Router/Switches and display the output result?
    I'm looking for a tool which I can give our Service Desk personnel that will allow them to select from a list of commands enter a target IP Address of a router/switch and then the tool will display the vlan table or the running config of a particular switch-port so they can see if its configured on the correct data vlan or its missing its voice vlan etc.
    For example a Service Desk Operator needs to check what vlan a switch-port is on. So they open the tool, enter the switches IP address and the port number and select an option like "display a switch-ports vlan" and the tool will login into the switch in the background run a show command on the switch and then output the result.
    Thanks.

    Check out rConfig. You will be able to run multiple instances of it i.e. one instance for your standard configuration backups and another for more specific configuration downloads info like show vlan bri commands etc for service desk staff to view.
    You could also use the IOS menu function and create menus or role based access on each of your devices for your users.
    Regards
    Stephen
    ==========================
    http://www.rConfig.com 
    A free, open source network device configuration management tool, customizable to your needs!
    - Always vote on an answer if you found it helpful

  • Cisco 4506 switch in Err-disable mode

        I have a Cisco 4506 switch and its 10 gig interface is in error disable mode.I tried Shut and no shut the port couple of times but it transits from up to down number of times and then to error-disable. Did anyone else encountered this issue before. kindly advise the solution for the same. thanks         

    Hi Shariq,
    Can you post the output of the show interface status err-disable ? That output contains the reason for putting your port into err-disabled state.
    Best regards,
    Peter

  • Unable to Remove Metal Casing for Cisco 1924 Switch

    Hi Guys,
    I just bought a Cisco 1924 switch and would like to check out its insides but I can't seem to work out how to remove the metal cover.
    I have removed all the visable screws and have also checked out the Cisco Support site and Internet but considering that the 1924 switch is an end of line product, I'm finding it extremely to find any support resources for the 1924 switch.
    I don't really want to force it open as I don't want to crack or snap anything.
    Thanks all
    two5om

    Hi,
    Here you are the Catalyst 1900 Series Installation and Configuration Guide, but unfortunately it doesn't contain how to remove the metal cover, please try to softly remove it, try to move it to the back before lifting it:
    http://www.cisco.com/en/US/docs/switches/lan/catalyst2900xl_3500xl/catalyst1900_2820/version9.00.00/icgf/19icinst.html
    HTH,
    Mohammed Mahmoud.

  • AAA for Cisco MDS Switches

    I have configured Cisco ACS 4.0 (TACACS) with Windows AD for all Cisco MDS switches and it is working fine. But local "admin" access to the Cisco MDS switches via telnet is not working. At the same time , if I create a user with "network-admin" role locally, that works but not the default admin user.
    Could anyone help me in this regard.

    You have two options.
    1. Configure an "admin" user in AD. (note that you don't have to use the account named admin, you can just as easily assign a local user with the network-admin role).One thing to note, is that you normally use this local account in case the tacacs+ or radius authentication server goes down.
    You can have users configured locally and AD at the same time. If you are running AAA the default config is to check your AAA servers first, if they are not available, then to default to a local account
    2. Configure your local network-admin role user and then specify that say console access is authenticated locally, while ssh and telnet is authenticated through tacacs. This will allow you to always get in with a local account through the console, while it will force SSH and Telnet connections to authenticate through the AAA servers.
    You can find this option in Device Manager > Security > AAA > Applications
    If you found this helpful, please give it a rating.

  • How to Recover Password on Cisco 2960 Switch?

    How to Recover Password on Cisco 2960 Switch? Who knows, please tell me the detail steps, thank you very much!

    You can find the detail steps on this article, hope can solve your problem.
    http://www.briefingwire.com/pr/how-to-recover-password-on-cisco-2960-switch
    and as I research, the WS-C2960X-48TS-L on sale on 3anetwork.com now, get a quote for the big discount.
    WS-C2960X-48TS-L
    http://www.3anetwork.com/cisco-ws-c2960x-48ts-l-price_p1542.html

  • How can I mirror all ports on CISCO 3750 switches to one Gigabyte port?

    Hi,
    I have a requirement to mirror all the ports on my 7 CISCO 3750 switches, which are in 3 separate stacks, to one single Gigabyte Ethernet port.
    Does anyone know how I can do that?
    Thanks in advance.

    Vlad, thanks a heap for your response.
    I want to apply to my sitation. Please let me know if I get them right in the following:
    Catalyst A
    vlan 901
    remote-span
    monitor session 1 source interface fastethernet 1-48 (I want to monitor all ports on the CISCO 3725)
    monitor session 1 destination remote vlan 901
    Catalyst B
    vlan 901
    remote-span (If I don't need to monitor this switch, do I still need to put anything into this switch at all?)
    Catalyst C
    vlan 901
    remote-span
    monitor session 1 source interface fastethernet 1-48 (I want to monitor all ports on this switch as well)
    monitor session 1 source remote vlan 901
    monitor session 1 destination interface gigabitethernet 3 (There are 4 Gigabit Ethernet Uplink in CISCO 3750, I want all the traffic to go to port 3, is this the right way to do?)
    Thanks in advance.

  • Trouble with Windows7 and Gigabit link on Cisco 3560X switch

    Hello,
    In my company, we are using Cisco IP Phones 7945G (with 2 gigabit network ports) and Cisco 3560X-48P (1GB ports) switches for our users.
    Our client computers are running on Windows 7 SP1 (64bit - Enterprise edition) and are connected behind the IP Phone. We use a "Boradcom
    Xtreme Gigabit" onboard network card on the computers. All ports (on the switch site and IP Phone side) and on the network card of the computer are configured in "auto negotiation". Duplex and speed are set to "auto".
    We tried now to deploy a new engineering software and we are facing a very strange problem. This means that the engineer software fails to download some files from the server. We are using a flat network, all the servers and computers are on the same network segment with no firewall inbetween.
    The firewall and Anti-virus on the computers are configured to allow all incoming/outing connections.
    To troubleshoot, I tried to change all the network cables but I still get same result --> download fails.
    I connected the client computer directly to the Cisco 3560X switch, without the IP Phone and I get the same result.
    I installed a separate network card from INTEL (Intel PRO1000 PT) but I get the same result.
    As last test, I have connected to same client computer directly to a Cisco 2960-8TC switch (100Mbit; auto negotiate) and here is working fine. The software successfully downloads all the files from the server.
    If I connect the computer behind the Cisco 7945 IP Phone, set the speed and duplex of the PC-Port on the Cisco IP Phone 7945G to "100MBit/full duplex" is also working fine.
    Is there any know issue with Windows7 and Gigabit network connections?
    Do I need to set any Registry key on my Windows 7?
    The firmware version of my Cisco 3560X-48P switch is 12.2(53)SE2; do I need to update it?
    The firmware version of the IP Phone 7945G is 9.2.1.
    Thanks in advanced for your help.
    Marc Hoffmann

    Hello, Thanks for your answers. First of all, I have updated the firmware of my Cisco Catalyst 3560X-48P switch to the version 12.2(55)SE5. Unfortunately, this did not solve my problem. As second step, I ran an TDR test on my 3560X switch but I do not get any result. The "Pair status" always says "not completed". Even if I wait for 5 minutes, the status remains at "Not completed". Am I doing something wrong ? To do the TDR test, I use the commande "test cable-diagnostics tdr interface gigabitEthernet 0/XY". For your information, the port gigabitEthernet 0/XY is in a "Connected" status when I run the "show int status" command. Jeff, I think there is no issue on the server side, because if I connect my workstation on a 100MB switch (example Cisco Catalyst 2960-8TC-L) the application works absolutely fine. Also, if I run the application locally on the server, it works fine. As next step, I will connect the workstation directly on our backbone switch and try the same test. Is there perhaps any Registry key in our Windows7 which could cause this trouble? If you have any other ideas or options, please let me know. Thanks a lot, Marc Hoffmann

  • How to view the login log in window NPS after login cisco switch and without SQL server database

    how to view the login log in window NPS after login cisco switch and without SQL server database
    in summary 
    there is only log with event id 4400
    A LDAP connection with domain controller XCPAWS20.cyberport.noc for domain NOC2 is established.

    Hi adil,
    For your issue, you can create a custom security token service (STS) and then set up a trust relationship between a SharePoint 2010 farm and the custom STS.
    For more information, you can refer to the articles:
    http://forums.asp.net/t/1335229.aspx?Sharing+Authentication+Ticket+Between+ASP+NET+and+Sharepoint
    https://msdn.microsoft.com/en-us/library/office/ff955607(v=office.14).aspx
    http://www.paraesthesia.com/archive/2011/02/01/working-with-windows-identity-foundation-in-asp-net-mvc.aspx/
    Best Regards,
    Eric
    Eric Tao
    TechNet Community Support

  • Cisco SG300 - IGMP and multiple switches

    Hi all,
    I have read through various Cisco documents and tried various configurations and i have been unsuccessful
    Here is the network layout
    Cisco SG300-10 in Layer 3 mode, managing all VLANS created and inter-vlan traffic is working fine
    Ports 1-4 are in LAG 1 with LACP enabled, Ports 5-8 are in LAG 2 again with LACP enabled, port 9 is connected to the ASA 5505 (Trunk port, all VLANS) and port 10, again a trunk port I use for management
    LAG 1 and 2 are connected to Cisco SG300-52 switches
    again traffic between the switches is working ok, what we would like to do is the following
    on VLAN 7, we have multiple devices streaming using UDP multicast, what we would like to do is allow PC's on VLAN 5 to be able to pick up these streams as and when they need to, the devices broadcast on their own unique UDP ranges
    Could someone please explain to me what I need to configure on the Layer 3 switch and the other two Layer 2 switches in order for this to work?
    If i put a port into VLAN 7 and can view the stream without a problem, also if there is any fine tuning to be done once this is working
    Thanks
    Andy

    Jason,
    The only advantage you would get from using SFPs (fiber tranceivers) in the GBIC slots would be if you needed to make a run of over 100m between the switches.  Unless you have a very large property with switches at either end you are just as well to use the copper ports in the setup you described.  There is also nothing wrong with chaining the SG100s together if necessary to free up a port on the RV320.  The only other thing to consider is if you are using VLANs.  Each unmanaged SG100 will only pass a single VLAN so if you need segregated distribution coming from the RV320 you would need to put each SG100 on its own port.  Or, you could run a trunk from a port on the RV320 to your SG200 and then split off your untagged VLANs from there.  Hope this answers your question and have a nice day.
    Regards,
    Mike.V

Maybe you are looking for