Cisco switch 2960
whether 2960 is a l2 layer or l3 layer
Cisco introduced Layer 3 switching on the 2960S, 2960G, 2960, and 2975 series switches when running the LAN BASE IOS with version 12.2(55)SE.
But there’s a small catch…it does NOT support RIP, OSPF, EIGRP, BGP, or routed interfaces. It ONLY supports 16 static routes with SVIs.
http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_55_se/configuration/guide/swipstatrout.html
Hope this helps
Sent from Cisco Technical Support iPhone App
Similar Messages
-
NAC is not managing new Cisco Switch 2960S
Hello,
we want to add a Cisco Switch 2960S to the devices, but CAM says he is unable to control that switch.
The switch type Cisco WS-C2960-8TC-L is already running on the CAM.
Is there a OID Update for the 2960S?
Our CAM version is 4.5.1.Solution:
Use the update on CAM:
-> Device Management -> Clean Access -> Updates -> Update
to get new OIDs for the switches.
This solved the problem. The device was added afterwards successfully. -
Cisco Switches (2960 Series) Management
We are managing these devices using HP OpenView Network Node Manager (Ver. 7.5) on HP-UX platform.
What are the known problems, limitations on its initial discovery and on later stages of managing the same ?The Cisco Catalyst 2960 Series supports the Cisco IOS LAN BASE software image. This software image is a rich suite of intelligent services that is also available in a crypto image at no additional charge.
Cisco Network Assistant also offers centralized management and configuration of Cisco switches and other Cisco devices such as routers and wireless access points. With Cisco Network Assistant, in addition to configuring multiple switches at a time, you can configure Cisco wireless access points, and invoke the Device Manager on Cisco routers and access points. Cisco Network Assistant can be downloaded (available at no cost).
This URL should help you:
http://www.cisco.com/en/US/products/ps5931/index.html -
SFP (Cisco GLC-SX-MM) unknown in cisco switch 2960s
I have cisco switch WS-C2960S-24TS-S with IOS 12.2(55)SE8 C2960S-UNIVERSALK9-M when I connect the SFP Cisco GLC-SX-MM to the interface the switch does not know it .
Switch#sh interfaces gig0/25 status
Port Name Status Vlan Duplex Speed Type
Gi0/25 err-disabled 1 auto auto unknownSwitch(config)#int gigabitEthernet 0/25
Switch(config-if)#sho
Switch(config-if)#shu
Switch(config-if)#shutdown
Switch(config-if)#do sh
*Mar 1 00:08:10.481: %LINK-5-CHANGED: Interface GigabitEthernet0/25, changed state to administratively down ip int br
Interface IP-Address OK? Method Status Protocol
Vlan1 unassigned YES unset up up
FastEthernet0 unassigned YES unset down down
GigabitEthernet0/1 unassigned YES unset down down
GigabitEthernet0/2 unassigned YES unset down down
GigabitEthernet0/3 unassigned YES unset down down
GigabitEthernet0/4 unassigned YES unset down down
GigabitEthernet0/5 unassigned YES unset down down
GigabitEthernet0/6 unassigned YES unset down down
GigabitEthernet0/7 unassigned YES unset down down
GigabitEthernet0/8 unassigned YES unset down down
GigabitEthernet0/9 unassigned YES unset down down
GigabitEthernet0/10 unassigned YES unset down down
GigabitEthernet0/11 unassigned YES unset down down
GigabitEthernet0/12 unassigned YES unset down down
GigabitEthernet0/13 unassigned YES unset down down
GigabitEthernet0/14 unassigned YES unset down down
GigabitEthernet0/15 unassigned YES unset down down
GigabitEthernet0/16 unassigned YES unset down down
GigabitEthernet0/17 unassigned YES unset down down
GigabitEthernet0/18 unassigned YES unset down down
GigabitEthernet0/19 unassigned YES unset down down
GigabitEthernet0/20 unassigned YES unset down down
GigabitEthernet0/21 unassigned YES unset down down
GigabitEthernet0/22 unassigned YES unset down down
GigabitEthernet0/23 unassigned YES unset down down
GigabitEthernet0/24 unassigned YES unset up up
GigabitEthernet0/25 unassigned YES unset administratively down down
GigabitEthernet0/26 unassigned YES unset down down
Switch(config-if)#no shut
Switch(config-if)#
*Mar 1 00:08:30.326: %LINK-3-UPDOWN: Interface GigabitEthernet0/25, changed state to down
Switch(config-if)#
Switch#show ip int brief
Interface IP-Address OK? Method Status Protocol
Vlan1 unassigned YES unset up down
FastEthernet0 unassigned YES unset down down
GigabitEthernet0/1 unassigned YES unset down down
GigabitEthernet0/2 unassigned YES unset down down
GigabitEthernet0/3 unassigned YES unset down down
GigabitEthernet0/4 unassigned YES unset down down
GigabitEthernet0/5 unassigned YES unset down down
GigabitEthernet0/6 unassigned YES unset down down
GigabitEthernet0/7 unassigned YES unset down down
GigabitEthernet0/8 unassigned YES unset down down
GigabitEthernet0/9 unassigned YES unset down down
GigabitEthernet0/10 unassigned YES unset down down
GigabitEthernet0/11 unassigned YES unset down down
GigabitEthernet0/12 unassigned YES unset down down
GigabitEthernet0/13 unassigned YES unset down down
GigabitEthernet0/14 unassigned YES unset down down
GigabitEthernet0/15 unassigned YES unset down down
GigabitEthernet0/16 unassigned YES unset down down
GigabitEthernet0/17 unassigned YES unset down down
GigabitEthernet0/18 unassigned YES unset down down
GigabitEthernet0/19 unassigned YES unset down down
GigabitEthernet0/20 unassigned YES unset down down
GigabitEthernet0/21 unassigned YES unset down down
GigabitEthernet0/22 unassigned YES unset down down
GigabitEthernet0/23 unassigned YES unset down down
GigabitEthernet0/24 unassigned YES unset down down
GigabitEthernet0/25 unassigned YES unset down down
GigabitEthernet0/26 unassigned YES unset down down
Switch#
Mar 1 00:07:55.508: %GBIC_SECURITY_CRYPT-4-VN_DATA_CRC_ERROR: GBIC in port Gi0/25 has bad crc
*Mar 1 00:07:55.508: %PM-4-ERR_DISABLE: gbic-invalid error detected on Gi0/25, putting Gi0/25 in err-disable state
*Mar 1 00:08:24.003: %GBIC_SECURITY_CRYPT-4-VN_DATA_CRC_ERROR: GBIC in port Gi0/25 has bad crc
*Mar 1 00:08:39.144: %GBIC_SECURITY_CRYPT-4-VN_DATA_CRC_ERROR: GBIC in port Gi0/25 has bad crc
Mar 1 00:24:18.611: %GBIC_SECURITY_CRYPT-4-VN_DATA_CRC_ERROR: GBIC in port Gi0/25 has bad crc
*Mar 1 00:24:18.611: %PHY-4-UNSUPPORTED_TRANSCEIVER: Unsupported transceiver found in Gi0/25 -
Hello,
I have a switch which is powers up but does not work. I saw the below logs the I connected to to an interface.
Kindly assist.
POST: Inline Power Controller Tests : Begin
POST: inline power post failed for port 0
POST: inline power post failed for port 1
POST: inline power post failed for port 2
POST: inline power post failed for port 3
POST: inline power post failed for port 4
POST: inline power post failed for port 5
POST: inline power post failed for port 6
POST: inline power post failed for port 7
POST: inline power post failed for port 8
POST: inline power post failed for port 9
POST: inline power post failed for port 10
POST: inline power post failed for port 11
POST: inline power post failed for port 12
POST: inline power post failed for port 13
POST: inline power post failed for port 14
POST: inline power post failed for port 15
POST: inline power post failed for port 16
POST: inline power post failed for port 17
POST: inline power post failed for port 18
POST: inline power post failed for port 19
POST: inline power post failed for port 20
POST: inline power post failed for port 21
POST: inline power post failed for port 22
POST: inline power post failed for port 23
POST: Inline Power Controller Tests : End, Status Failed
POST: Thermal, Fan Tests : Begin
POST: Thermal, Fan Tests : End, Status Passed
POST: PortASIC Stack Port Loopback Tests : Begin
POST: PortASIC Stack Port Loopback Tests : End, Status Passed
POST: PortASIC Port Loopback Tests : Begin
POST: PortASIC Port Loopback Tests : End, Status Passed
POST: EMAC Loopback Tests : Begin
POST: EMAC Loopback Tests : End, Status Passed
Election Complete
Switch 1 booting as Master
Waiting for Port download...Complete
*Mar 1 00:00:1e Vlan1, changed state to down
*Mar 1 00:01:37.077: %SPANTREE-5-EXTENDED_SYSID: Extended SysId enabled for type vlan
*Mar 1 00:02:14.506: %SYS-5-CONFIG_I: Configured from memory by console
*Mar 1 00:02:14.736: %STACKMGR-5-SWITCH_READY: Switch 1 is READY
*Mar 1 00:02:14.736: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 1 Switch 1 has changed to state DOWN
*Mar 1 00:02:14.736: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 2 Switch 1 has changed to state DOWN
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/1 can't be brought up because it failed POST in Inline Power test.
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/2 can't be brought up because it failed POST in Inline Power test.
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/3 can't be brought up because it failed POST in Inline Power test.
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/4 can't be brought up because it failed POST in Inline Power test.
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/5 can't be brought up because it failed POST in Inline Power test.
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/6 can't be brought up because it failed POST in Inline Power test.
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/7 can't be brought up because it failed POST in Inline Power test.
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/8 can't be brought up because it failed POST in Inline Power test.
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/9 can't be brought up because it failed POST in Inline Power test.
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/10 can't be broug
*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/11 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/12 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/13 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/14 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/15 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/16 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/17 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/18 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/19 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/20 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/21 can't be broug
*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/22 can't be broug
*Mar 1 00:02:15.025: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/23 can't be broug
*Mar 1 00:02:15.025: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/24 can't be broug
*Mar 1 00:02:15.040: %STACKMGR-5-MASTER_READY: Master Switch 1 is READY
AnimHi Frederick,
POST: Inline Power Controller Tests : BeginPOST: inline power post failed for port 0POST: inline power post failed for port 1POST: inline power post failed for port 2POST: inline power post failed for port 3POST: inline power post failed for port 4POST: inline power post failed for port 5POST: inline power post failed for port 6POST: inline power post failed for port 7POST: inline power post failed for port 8POST: inline power post failed for port 9POST: inline power post failed for port 10POST: inline power post failed for port 11POST: inline power post failed for port 12POST: inline power post failed for port 13POST: inline power post failed for port 14POST: inline power post failed for port 15POST: inline power post failed for port 16POST: inline power post failed for port 17POST: inline power post failed for port 18POST: inline power post failed for port 19POST: inline power post failed for port 20POST: inline power post failed for port 21POST: inline power post failed for port 22POST: inline power post failed for port 23POST: Inline Power Controller Tests : End, Status FailedPOST: Thermal, Fan Tests : BeginPOST: Thermal, Fan Tests : End, Status PassedPOST: PortASIC Stack Port Loopback Tests : BeginPOST: PortASIC Stack Port Loopback Tests : End, Status PassedPOST: PortASIC Port Loopback Tests : BeginPOST: PortASIC Port Loopback Tests : End, Status PassedPOST: EMAC Loopback Tests : BeginPOST: EMAC Loopback Tests : End, Status PassedElection CompleteSwitch 1 booting as MasterWaiting for Port download...Complete*Mar 1 00:00:1e Vlan1, changed state to down*Mar 1 00:01:37.077: %SPANTREE-5-EXTENDED_SYSID: Extended SysId enabled for type vlan*Mar 1 00:02:14.506: %SYS-5-CONFIG_I: Configured from memory by console*Mar 1 00:02:14.736: %STACKMGR-5-SWITCH_READY: Switch 1 is READY*Mar 1 00:02:14.736: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 1 Switch 1 has changed to state DOWN*Mar 1 00:02:14.736: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 2 Switch 1 has changed to state DOWN*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/1 can't be brought up because it failed POST in Inline Power test.*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/2 can't be brought up because it failed POST in Inline Power test.*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/3 can't be brought up because it failed POST in Inline Power test.*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/4 can't be brought up because it failed POST in Inline Power test.*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/5 can't be brought up because it failed POST in Inline Power test.*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/6 can't be brought up because it failed POST in Inline Power test.*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/7 can't be brought up because it failed POST in Inline Power test.*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/8 can't be brought up because it failed POST in Inline Power test.*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/9 can't be brought up because it failed POST in Inline Power test.*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/10 can't be broug*Mar 1 00:02:15.014: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/11 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/12 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/13 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/14 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/15 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/16 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/17 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/18 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/19 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/20 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/21 can't be broug*Mar 1 00:02:15.019: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/22 can't be broug*Mar 1 00:02:15.025: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/23 can't be broug*Mar 1 00:02:15.025: %PLATFORM_ENV-3-ILP_PORT_POST_ERR: Gi1/0/24 can't be broug*Mar 1 00:02:15.040: %STACKMGR-5-MASTER_READY: Master Switch 1 is READY
try no shut on each interface and check it.
If still fails then, Please contact Cisco and try to get the appliance replaced. This swicth is dead, also raise a TAC case.
Reagrds
Dont forget to rate helpful posts. -
Collecting information from Cisco switchs using SNMP
Dear All,
I have a wide network with more than 250 sites connected using the DSL. the WAN devices are under the provider responsability and the LAN devices are directly in my responsability. In each site, I have :
1 or 2 Cisco switchs (2960 or 3560), connecting via fibr.
or
Linksys switch connected via ethernet cable
and
cisco 877 router connected to switch
cisco 881G router conected to switch
pc and printers
In order to improve the availibilty of our network, we lauch every day a script from local pc to test connectivity of LAN equipements :
ping to switchs (Vlan 1), ping to ip fa0/0 cisco router1, ip cisco router2, ping to HSRP address (of two router). the resulting ini file will be inserted in a database and exported to excel for analysing.
I'm asking if someone can help in order to implement SNMP and let me know the name of cisco MIB to implement to :
- to have from SNMP information, the result of show cdp nei, show interface status, show ip int brief,...
- to have if wan router LAN interface are up,connected
- others usefuls informations.
Thanks and regards,
AAHi,
the basic SNMP config for 2960 and 3560 is:
snmp-server community <> RO
The configuration for SNMP traps to get alerts from the device if there is for example a failure with a fan is:
snmp-server enable traps
snmp-server host <> <>
This enables all traps available with your IOS version. You can the disable not wanted traps by using the "no"-command like this.
Example for dot1x traps:
no snmp-server enable traps dot1x
With a snmp client you can then do a snmpwalk (or snmp get) without a specific OID to get all the SNMP information from the device:
On a Linux server the following command should work:
snmpwalk -v 2c -c <> -T <>
-v = use SNMP version 2c
-c = use the community string you configured on the device
-T = output in the dotted decimal format
But be careful, this will be a lot of data output.
Here you will find a docu for configuring SNMP on a Cisco device:
http://www.cisco.com/en/US/docs/ios/12_2/configfun/configuration/guide/fcf014.html
Sven -
Hi all,
I have some problems involved Cisco Catalyst 2960 Switch.
I am using a device which includes Marvell PHY chip 88E1111. The device can send and receive PTP packet to and from my PC.
Now, I want to connect the device and the PC to Cisco Catalyst 2960 Switch, which will help me trace all of packets in the network . The test scenario is below:
- Switch: Cisco Catalyst 2960
- Tracer: Wireshark software
- PC: Windows 7-64 bit, plugging in Switch port 1 (interface 1)
- Device: FPGA board, plugging in Switch port 2 (interface 2),
operating mode: 1000Mbps, Fullduplex, no auto-negotiation, no auto power efficient-ethernet.
- Interface 2 of the Switch is static set by the device’s MAC
address , which ensures the Switch known the device’s MAC.
I suffered a problem. Although the RJ45 TX status led are on, there is not any packet sent to the Switch. I have no idea in this case.
Could you give me an advise please.It means the IOS used is corrupt.
Go to the Cisco website and download again the IOS. Once download is complete, compare the MD5 hash value of the file downloaded against the MD5 hash value found in the Cisco website. -
Error in switch ports POE model, "Cisco Catalyst 2960S-24PS-L Switch"
I have problem with the poe switch Cisco Catalyst 2960S-24PS-L posts does not respond, and me the following error resporta was t
%PLATFORM_ENV-3-ILP_PORT_POST_ERR: %s can’t be brought up because it failed POST
in Inline Power test.
he source of that error and what are the possible causesHey Dustin,
Device needs to be RMA'ed. The inline power supply has failed.
HTH.
Regards,
RS. -
Last version Cisco Catalyst 2960-24PC-L Switch (bugs study)
Hi team,
I need know, what´s the last IOS version to Cisco Catalyst 2960-24PC-L Switch and understand the bug study about these versions?
How make a bug study?
If you have any information, please let me know.
Regards,
Yerko.Latest release as of January 14th is 15.0.2-SE5 (Release Nov 6, 2013)
There aren't any public utilities in the Cisco website that provides you with a bug study.
We have a bug tracker https://tools.cisco.com/bugsearch/?referring_site=popular but it will be extremely time consuming to identify each bugs and if you are affected.
If you are a Cisco Advanced customer with optimization services in your contract, this deliverable can be done for you at no cost. -
Cisco WS-2960S-48TS-L does not work after firmware update
Hello.
After purchasing the Cisco WS-2960S-48TS-L decided to do a firmware upgrade using the CISCO NETWORK ASSISTANT. Unfortunately update failed. Currently the switch when you run can not load the system image.
Since up to now I had to deal with the other switches do not really know how to upload the correct image now. The more that you connect the switch through the console acts as to a limited extent.
Please helpThank you Leo Laohoo.
Your suggestion to usbflash0 helpful.
It is true that I was struggling because of usbflash latest iso system also did not want to go, but I recorded version of one lower and went.
By the way, I learned that the USB must be formatted to FAT file system.
Again, thank you for your help.
Darek Rynkowski -
NPS Discarding RADIUS request from Cisco switch (802.1x)
Last few weeks I've been busy to get the following to work:
- Cisco 2960 switch as the suppliant
- Another Cisco 2960 as the authenticator switch
- The supplicant is only able to send MS-EAP MS-ChapV2 requests
- The NPS server is Windows 2008 R2 (and also tested on 2012 R2)
This is called "NEAT" by Cisco; which does seem to work with Cisco ISE (http://www.cisco.com/c/en/us/support/docs/lan-switching/8021x/116681-config-neat-cise-00.html)
but I'd like to get it to work with Windows NPS.
Within NPS I've setup the following Connection Request policy:
- NAS Port Type: Ethernet
I'm using the following Network Policy:
- User Group: DOMAIN\Switches (the useraccount used by the switch is part of this group)
- NAS Port Type: Ethernet
- Autehntcation Type: EAP
Now the request sent by the switch is discarded. The actual error is the following (excluded irrelevant information):
User:
Account Name: Rotterdam-Switch-8-1
Account Domain: DOMAIN
Authentication Details:
Connection Request Policy Name: Secure Wired Connections
Network Policy Name: Switches Allowed
Authentication Provider: Windows
Authentication Server: SERVER.DOMAIN.local
Authentication Type: EAP
EAP Type: -
Account Session Identifier: -
Reason Code: 1
Reason: An internal error occurred. Check the system event log for additional information.
Wireshark on the NPS server shows:
1. The RADIUS Access-Request (1) being received by the NPS Server
2. The NPS Server sending out a RADIUS Access-Challenge (11) to the authenticator switch
3. Another RADIUS Access-Request (1) is beging received by the NPS Server
Packet 2 has an t=EAP-Message(79) with type MS-EAP-Authentication [Palekar](26) and MS-CHAPv2-ID set to 2 and OpCode 1 (Challange)
Packet 3 has an t=EAP-Message(79) with type MS-EAP-Authentication [Palekar](26) and MS-CHAPv2-ID set to 2 and OpCode 2 (Response)
I've also tried the following:
- I've also tested with an invalid username/password. The request is correctly denied
- I've also tested by added ALL EAP Types as condition to the Network Policy. The request isn't pickup by this policy anymore.
Any help would be greatly appriciated ofcourse.
Kind regards,
PeterIt only took like.. uhm.. forever.. but there's an answer which is "OK ish..".
Cisco 2960 switches support EAP-MSCHAP; but it seems that NPS only supports EAP-MSCHAP for VPN Connections and not for Wired/Wirelss authentication. Something to do with inner and outer methods and NPS requireing PEAP as an outer method for Wired/Wirelss
authentication.
End result is that both the Cisco switches and NPS do support EAP-MD5. Though it's definitly not as secure (at all), it's definitly a step in the right direction and it's something that we'll be implementing.
Now it seems that NPS doesn't support EAP-MD5 (which is supposidly depricated), it's possible to re-enable it. Using the following articles.
http://support.microsoft.com/kb/922574/en-us
Microsft mentioned me that "Though this article says it applies to Windows Vista only, it does apply to Server 2008R2 as well. Also I would suggest you the following link:
http://support.microsoft.com/kb/981190"
Please note that you'll have to enable 'Store password using reversible encryption’ on the accounts that will be used for NEAT authentication.
All though I would have hoped EAP-MSCHAPv2 would work, I feel I do need to clarify that I understand Microsoft's point of view on this as well. They feel EAP methods without PEAP are simply not safe; which is understandable, espcially for EAP-MD5 which
could be sniffer using a hub/repeater/etc.
Kind regards,
Peter -
802.1x on Cisco Catalyst 2960
I am trying to enable 802.1x on one of
the switchports of the Cisco Catalyst
2960:
C2960#sh run | i radius
aaa authentication login test group radius local
aaa authentication dot1x default group radius
radius-server host 10.250.97.26 auth-port 1812 acct-port 1813
radius-server source-ports 1645-1646
radius-server key 123456
C2960#sh run | i dot
aaa authentication dot1x default group radius
dot1x system-auth-control
dot1x guest-vlan supplicant
dot1x critical eapol
C2960#conf t
Enter configuration commands, one per line. End with CNTL/Z.
C2960(config)#int g0/14
C2960(config-if)#dot1x ?
% Unrecognized command
C2960(config-if)#dot1x
As you can see, I can not enable 802.1x
at the interface level. The code is am running is 12.2.25SEE4:
Switch Ports Model SW Version SW Image
* 1 24 WS-C2960G-24TC-L 12.2(25)SEE4 C2960-LANBASEK9-M
System image file is "flash:c2960-lanbasek9-mz.122-25.SEE4.bin"
According to Cisco, this image supports
802.1x. Why can't enable it at the
interface level?
Can someone help me out? Thanks.some additional info:
C2960#sh dot1x all
Sysauthcontrol Enabled
Dot1x Protocol Version 2
Critical Recovery Delay 100
Critical EAPOL Enabled
C2960# -
Cisco catalyst 2960 booting garbage, help on restore IOS
Dear All,
This is my first time on terminal access of Cisco Catalyst 2960 (2960TC-L), normally would use the web configuration for most task.
Now the switch has an issue with the web interface and when I try to access through terminal, I was greeted with garbage upon the booting of the switch, I searched for the terminal boot process and it wasn't what I was expected for my switch. I was a bit dumbfound now of how can I recover the firmware to its default stage, now that I cannot even boot through its terminal console.
Any help is highly appreciated. Thank you for your time.Hi,
I just verified with my colleague of whom have done quite a few bits before I took over his task.
His reply was he actually did an IOS flash before, though I'm not sure how he did it, but according to him, it was actually a success and the web interface still works for few times before it become like this.
As I tried another time to goes into root mode (or Admin mode??) for the switch, the steps as I performed below:
1. Refer to cisco-2960-putting-setting.jpg for the settings. I press Open and it does display the console Window, no issue there.
2. I hold the "mode" button on the switch and turn on the switch power, and after few seconds the screen display as such (refer to cisco-2960-putty-output2.jpg), the SYST L.E.D. did flash with following pattern: Green (blink ~15 times) then Orange-Green (repeat blink twice) then Green (stable light), for this I was expecting it to goes off after few seconds but it didn't, I wait about a minute before I let go the "mode" button.
3. After I let go the "mode" button, it goes to the screen (refer cisco-2960-putty-output3.jpg), and the SYST still blinking, possibly infinitely... with the console output screen stays like that... and whatever I entered display weird/garbage characters instead, I can't do anything on it.
Each tries display different weird characters, as the SYST still blinking infinitely.
I'm unsure if I'm giving enough details for online troubleshooting, I'll try my best to give as per instructed.
Thank you for your time. -
Cisco Catalyst 2960-X and Cisco Prime compatibility
Hello All,
I had review all the compatibility matrix of versions of Cisco Prime 1.2, 1.4 and 2.0, and just can't find the Cisco Catalyst 2960-X series as a listed device, which really surprises me.
Can you clear that out??
Thanks,The 2960X (and XR) support was added with Device Pack 2 for PI 2.0. It was released on 22 January 2014 and is available here.
(PI 2.1 won't be out until later this year, release date not yet announced.)
Following are the 2960X/XR types added:
Cisco Catalyst 2960-X Series Switches
Device Type
SYSOIDS
S/W Version
Software
Cisco Catalyst 2960X-24TS-L Switch
OID:1.3.6.1.4.1.9.1.1699
>=12.1
IOS
Cisco Catalyst 2960X-48FPD-L Switch
OID:1.3.6.1.4.1.9.1.1690
>=12.1
IOS
Cisco Catalyst 2960X-48LPD-L Switch
OID:1.3.6.1.4.1.9.1.1691
>=12.1
IOS
Cisco Catalyst 2960X-48TD-L Switch
OID:1.3.6.1.4.1.9.1.1692
>=12.1
IOS
Cisco Catalyst 2960X-24PD-L Switch
OID:1.3.6.1.4.1.9.1.1693
>=12.1
IOS
Cisco Catalyst 2960X-24TD-L Switch
OID:1.3.6.1.4.1.9.1.1694
>=12.1
IOS
Cisco Catalyst 2960X-48FPS-L Switch
OID:1.3.6.1.4.1.9.1.1695
>=12.1
IOS
Cisco Catalyst 2960X-48LPS-L Switch
OID:1.3.6.1.4.1.9.1.1696
>=12.1
IOS
Cisco Catalyst 2960X-24PS-L Switch
OID:1.3.6.1.4.1.9.1.1697
>=12.1
IOS
Cisco Catalyst 2960X-48TS-L Switch
OID:1.3.6.1.4.1.9.1.1698
>=12.1
IOS
Cisco Catalyst 2960X-24PSK-L Switch
OID:1.3.6.1.4.1.9.1.1700
>=12.1
IOS
Cisco Catalyst 2960X-48LPS-S Switch
OID:1.3.6.1.4.1.9.1.1701
>=12.1
IOS
Cisco Catalyst 2960X-24PS-S Switch
OID:1.3.6.1.4.1.9.1.1702
>=12.1
IOS
Cisco Catalyst 2960X-48TS-LL Switch
OID:1.3.6.1.4.1.9.1.1703
>=12.1
IOS
Cisco Catalyst 2960X-24TS-LL Switch
OID:1.3.6.1.4.1.9.1.1704
>=12.1
IOS
Cisco Catalyst 2960-XR Series Switches
Device Type
SYSOIDS
S/W Version
Software
Cisco Catalyst 2960XR-48FPD-I Switch
OID:1.3.6.1.4.1.9.1.1797
>=12.1
IOS
Cisco Catalyst 2960XR-48LPD-I Switch
OID:1.3.6.1.4.1.9.1.1798
>=12.1
IOS
Cisco Catalyst 2960XR-48TD-I Switch
OID:1.3.6.1.4.1.9.1.1799
>=12.1
IOS
Cisco Catalyst 2960XR-24PD-I Switch
OID:1.3.6.1.4.1.9.1.1800
>=12.1
IOS
Cisco Catalyst 2960XR-24TD-I Switch
OID:1.3.6.1.4.1.9.1.1801
>=12.1
IOS
Cisco Catalyst 2960XR-48FPS-I Switch
OID:1.3.6.1.4.1.9.1.1802
>=12.1
IOS
Cisco Catalyst 2960XR-48LPS-I Switch
OID:1.3.6.1.4.1.9.1.1803
>=12.1
IOS
Cisco Catalyst 2960XR-48TS-I Switch
OID:1.3.6.1.4.1.9.1.1804
>=12.1
IOS
Cisco Catalyst 2960XR-24PS-I Switch
OID:1.3.6.1.4.1.9.1.1805
>=12.1
IOS
Cisco Catalyst 2960XR-24TS-I Switch
OID:1.3.6.1.4.1.9.1.1806
>=12.1
IOS
Cisco Catalyst 2960XR-48FPD-L Switch
OID:1.3.6.1.4.1.9.1.1807
>=12.1
IOS
Cisco Catalyst 2960XR-48LPD-L Switch
OID:1.3.6.1.4.1.9.1.1808
>=12.1
IOS
Cisco Catalyst 2960XR-48TD-L Switch
OID:1.3.6.1.4.1.9.1.1809
>=12.1
IOS
Cisco Catalyst 2960XR-24PD-L Switch
OID:1.3.6.1.4.1.9.1.1810
>=12.1
IOS
Cisco Catalyst 2960XR-24TD-L Switch
OID:1.3.6.1.4.1.9.1.1811
>=12.1
IOS
Cisco Catalyst 2960XR-48FPS-L Switch
OID:1.3.6.1.4.1.9.1.1812
>=12.1
IOS
Cisco Catalyst 2960XR-48LPS-L Switch
OID:1.3.6.1.4.1.9.1.1813
>=12.1
IOS
Cisco Catalyst 2960XR-48TS-L Switch
OID:1.3.6.1.4.1.9.1.1814
>=12.1
IOS
Cisco Catalyst 2960XR-24PS-L Switch
OID:1.3.6.1.4.1.9.1.1815
>=12.1
IOS
Cisco Catalyst 2960XR-24TS-L Switch
OID:1.3.6.1.4.1.9.1.1816
>=12.1
IOS -
Connecting 300 IP Cameras using Cisco Switches
Require help on a Case study. (Can only use Cisco switch)
Description:
This is a setup required for 300 security cameras.
So availability and redundancy is important.
I have calculate the bandwidth using [URL="http://www.jvsg.com/download/IPDesignToolSetup.zip"]this software[/URL].
If each camera is set to 5MP and H.264-10, Bandwidth is 12.08Mbit
So 300 cameras will require at least 3624.96Mbits in total.
(correct me if i am wrong)
Each NVR has 32 port.
It will be just connecting within a LAN.
Here is the brief 2 possible design I have draft out, but I am not sure which model and series of cisco switch to be use??
Design 1:
Design 2:
Please advise which model and series can be used for this 2 two of design.Hello Chun,
you need to accomodate 300 cameras and 32 ports for each network video recorder.
data flows are from cameras to network video recorder ports.
The amount of traffic per port at port connected to cameras is not huge and total traffic from cameras exceed GE links
48 * 12,08 = ?? in any case less then < 1 Gbps
You can deploy a hierarchical network design with an access layer made of switches with fixed configuration 48 ports and GE uplinks like a C3750 with 48 ports or a 2960 with 48 ports (if it exists)
Each access layer switch needs to have two uplinks to distribution switches
And you need 300/48 switches => 7 switches => 7 GE uplinks on each distribution switches
Distribution switches should be two and should be able to connect to access layer switches and to NVR that requires 32 ports each.
Different solutions are possible:
instead od deploying 7 standalone switches with 48 ports each you could use two modular C4507 equipped with WS-4548 48 10/100/1000 linecards
the distribution switches can be two C3750 E, eventually configured and connected as a stack, to allow to use both uplinks of each access layer switch
Hope to help
Giuseppe
Maybe you are looking for
-
View Duplicate Entries in Address Book
Does anyone know how you can view your duplicate entries in Address Book before you merge them? Thank you!
-
Hi, I'm using forms6i. I have an item in my form , say, Invoicebase, whose default value to be fetched from another table and to be shown in the form while loading. The query to fetch the default value involves a where condition, like where company =
-
my dell pc is in the wireless mode but my fax is connected to house phone. How to I connect to 2 so I can send and receive fax
-
Batch conversion to replace the anamorphic flag in DV Stream
I have a bunch of .dv files form my video camera but, unfortunately, when migrating them from iMovie '06 to iMovie '08 (and switching to a brand new iMac in between) some of them have lost the anamorphic flag. This means that when I try and import th
-
Hello everyone Im made a form for an application and i wanted to send a autoresponder. But everytime a recive an autoresponder its not the email adress witch i added but its the email adress of FC... how can i change that? thank for the answer