CSS11501 - Unable to Telnet to VRRP backup interface IP

Hi,
I have 2 units of Cisco CSS11501 which configured running on VRRP active/standby on 2 different VLAN (Circuit). When unit 1 is master unit, I am able to telnet to its circuit IP address, but unable to telnet to any circuit IP of backup unit.
Active unit configuration:
!************************** CIRCUIT **************************
circuit VLAN145
  ip address 172.19.145.182 255.255.255.0
    ip virtual-router 1 priority 101
    ip redundant-vip 1 172.19.145.184
    ip redundant-interface 1 172.19.145.183
circuit VLAN550
  ip address 192.168.50.18 255.255.255.0
    ip virtual-router 2 priority 101
    ip redundant-vip 2 192.168.50.20
    ip redundant-interface 2 192.168.50.19
!*************************** OWNER ***************************
owner ***
  content ***
    vip address 172.19.145.184
    port 80
    protocol tcp
    add service ***
    active
!*************************** GROUP ***************************
group ***
  vip address 192.168.50.20
  active
Backup unit configuration:
!************************** CIRCUIT **************************
circuit VLAN145
  ip address 172.19.145.183 255.255.255.0
    ip virtual-router 1 priority 90
    ip redundant-interface 1 172.19.145.182
    ip redundant-vip 1 172.19.145.184
circuit VLAN550
  ip address 192.168.50.19 255.255.255.0
    ip virtual-router 2 priority 90
    ip redundant-vip 2 192.168.50.20
    ip redundant-interface 2 192.168.50.18
!*************************** OWNER ***************************
owner ***
  content ***
    vip address 172.19.145.184
    port 80
    protocol tcp
    add service ***
    active
!*************************** GROUP ***************************
group ***
  vip address 192.168.50.20
  active
Please help!!
Regards,
Danny Lim

Hi Marko,
That means I could not to configure redundant-interface as I have redundant-vip configured already?
Actually the topology is:
VLAN550 is connecting to server farm
VLAN145 is where user sitting
my current config :
circuit VLAN145
  ip address 172.19.145.182 255.255.255.0
    ip virtual-router 1 priority 101
    ip redundant-vip 1 172.19.145.184
    ip redundant-interface 1 172.19.145.183
    ip critical-service 1 PING_DEFAULT_GATEWAY
circuit VLAN550
  ip address 192.168.50.18 255.255.255.0
    ip virtual-router 2 priority 101
    ip redundant-vip 2 192.168.50.20
    ip redundant-interface 2 192.168.50.19
    ip critical-service 2 PING_DEFAULT_GATEWAY
!*************************** OWNER ***************************
owner HLRLDAP
  content VIP_LDAP_16611
    vip address 172.19.145.184
    port 16611
    protocol tcp
    add service KPG-HV30-3
    add service KPG-HV30-6
    active
!*************************** GROUP ***************************
group Redundant_Server
  vip address 192.168.50.20
  active
So, I should have change my config like this:
CSS1
circuit VLAN145
  ip address 172.19.145.182 255.255.255.0
    ip virtual-router 1 priority 101
    ip redundant-vip 1 172.19.145.184
    ip redundant-interface 1 172.19.145.181
    ip critical-service 1 PING_DEFAULT_GATEWAY
circuit VLAN550
  ip address 192.168.50.18 255.255.255.0
    ip virtual-router 2 priority 101
    ip redundant-interface 2 192.168.50.20
    ip critical-service 2 PING_DEFAULT_GATEWAY
CSS2
!************************** CIRCUIT **************************
circuit VLAN145
  ip address 172.19.145.183 255.255.255.0
    ip virtual-router 1 priority 90
    ip redundant-interface 1 172.19.145.181
    ip redundant-vip 1 172.19.145.184
    ip critical-service 1 PING_DEFAULT_GATEWAY
circuit VLAN550
  ip address 192.168.50.19 255.255.255.0
    ip virtual-router 2 priority 90
    ip redundant-interface 2 192.168.50.20
    ip critical-service 2 PING_DEFAULT_GATEWAY

Similar Messages

  • Unable to Telnet / SSH to a particular cisco switch

    Hello,
    I have an unusual issue that I just can't seem to track down.  We have a Windows Server 2008 R2 box that is unable to telnet or ssh to one switch in our network.
    Server IP:  10.0.0.74
    Cisco Switch IP:  10.1.0.7
    I am able to access all other switches/routers on the 10.1.0.x network, but not this one.  I ping and tracert by ip address and name.
    We have a number other servers on our network and they all can access this switch
    Example:  
    a.  10.0.0.73 can telnet/ssh to 10.1.0.7
    b.  10.0.0.72  can telnet/ssh to 10.1.0.7
    c.  10.0.0.50  can telnet/ssh to 10.1.0.7
    d.  My workstation (10.0.250.213) can telnet/ssh to 10.1.0.7
    If anyone can help with troubleshooting further, I would greatly appreciate it.

    Thanks for the reply Philippe!  Here is the route print
    IPv4 Route Table
    ===========================================================================
    Active Routes:
    Network Destination        Netmask          Gateway       Interface  Metric
              0.0.0.0          0.0.0.0         10.0.0.2        10.0.0.74    266
             10.0.0.0      255.255.0.0         On-link         10.0.0.74    266
            10.0.0.74  255.255.255.255         On-link         10.0.0.74    266
         10.0.255.255  255.255.255.255         On-link         10.0.0.74    266
            10.10.0.0      255.255.0.0         On-link         10.0.0.74    266
           10.10.0.74  255.255.255.255         On-link         10.0.0.74    266
        10.10.255.255  255.255.255.255         On-link         10.0.0.74    266
            127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
            127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
      127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
            224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
            224.0.0.0        240.0.0.0         On-link         10.0.0.74    266
      255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      255.255.255.255  255.255.255.255         On-link         10.0.0.74    266
    ===========================================================================
    Persistent Routes:
      Network Address          Netmask  Gateway Address  Metric
              0.0.0.0          0.0.0.0         10.0.0.2  Default
    ===========================================================================
    IPv6 Route Table
    ===========================================================================
    Active Routes:
     If Metric Network Destination      Gateway
      1    306 ::1/128                  On-link
      1    306 ff00::/8                 On-link
    ===========================================================================
    Persistent Routes:
      None
    Firewall is disabled and there is no active antivirus.  Im pretty sure port blocking is not the issue.  I am able to ssh and telnet from this box to every other switch/router in our network.
    This server has Solarwinds on it and tracks the health of our network (servers, routers, switches, ups, ect.).  The only reason we noticed an issue is because it stopped backing up the config for this particular switch.  All other switchs/routers
    config is backed up to this server every morning at 2:00AM.  
    With solarwinds, this server is also able to communicate with this switch via snmp / icmp and ping.
    Thanks again for the help!

  • Unable to telnet and tftp to controller

    hello experts!!!
    5508 controller is at the headquarters which can be normally pinged, telnetted, http'd and tftp'ed....
    at the remote site,  controller can be pinged and http'ed but cannot be telnetted and tftp'ed.
    there is a complete tracert from the remote site pc all the way to the controller.
    from a switch at  a remote site, the controller can be telnetted.
    but from a pc on the remote site (which belongs to a remote site vlan), it is unable to telnet and tftp the controller.
    all active components can be telnetted  from the remote site, such as the core switches and routers at the headquearters, except the controller.
    upgraded the controller code to 7.2.xxx in headquarters but still unable to telnet and tftp the controller from remote site.
    is there any more settings on the controller for telnet and tftp?
    what could be the problem why the controller is not available for telnet and tftp from the remote site?
    thank you, experts, in advance for your replies!!!

    Hello, Leo!
    See output of the command:
    (Cisco Controller) >show network summary
    RF-Network Name............................. GID2012
    Web Mode.................................... Enable
    Secure Web Mode............................. Enable
    Secure Web Mode Cipher-Option High.......... Disable
    Secure Web Mode Cipher-Option SSLv2......... Enable
    OCSP........................................ Disabled
    OCSP responder URL..........................
    Secure Shell (ssh).......................... Enable
    Telnet...................................... Enable
    Ethernet Multicast Forwarding............... Disable
    Ethernet Broadcast Forwarding............... Disable
    AP Multicast/Broadcast Mode................. Unicast
    IGMP snooping............................... Disabled
    IGMP timeout................................ 60 seconds
    IGMP Query Interval......................... 20 seconds
    MLD snooping................................ Disabled
    MLD timeout................................. 60 seconds
    MLD query interval.......................... 20 seconds
    User Idle Timeout........................... 28800 seconds
    ARP Idle Timeout............................ 300 seconds
    Cisco AP Default Master..................... Enabled
    --More-- or (q)uit
    AP Join Priority............................ Disable
    Mgmt Via Wireless Interface................. Enable
    Mgmt Via Dynamic Interface.................. Enable
    Bridge MAC filter Config.................... Enable
    Bridge Security Mode........................ EAP
    Mesh Full Sector DFS........................ Enable
    AP Fallback ................................ Enable
    Web Auth Redirect Ports .................... 80
    Web Auth Proxy Redirect  ................... Disable
    Web Auth Captive-Bypass   .................. Disable
    Web Auth Secure Web  ....................... Enable
    Fast SSID Change ........................... Disabled
    AP Discovery - NAT IP Only ................. Enabled
    IP/MAC Addr Binding Check .................. Enabled
    CCX-lite status ............................ Disable
    oeap-600 dual-rlan-ports ................... Disable
    oeap-600 local-network ..................... Enable

  • HT4847 I am unable to delete the last backup from icloud, i checked my all device setting but it still say "cannot delete icloud this time because it is in use,"Please tell me what should i do.

    I am unable to delete the last backup from icloud, i checked my all device setting but it still say "cannot delete icloud this time because it is in use,"Please tell me what should i do                             

    It still didn't work...
    Within this commonfiles\apple folder, there is only one folder, labeled "Internet Services." Within this folder, there are 6 folders, labeled:
    APLZOD.resources
    BookmarkDAV_client.resources
    CoreDAV.resources
    iCloud.resources
    iCloudServices.resources
    ShellStreams.resources
    Within all but CoreDAV and BookmarkDAV_client, there are multiple different folders, all labeled starting with a two letter (acronym I believe, for different languages) then .lproj (for example, a folder is labeled "ar.lproj".
    In each of the folders of APLZOD.resources, there is a file labeled "APLZODlocalized.dll."
    In all of the folders containing the multiple .lproj folders, there are likewise "name"localized.dll files contained.
    In the BookmarkDAV_client and Core DAV folders, they each contain only one file, "Info.plist"
    I attempted to delete all of these files, and still, the FileAssassin could not delete them. I unlocked one of them for instance, and I tried to delete the file myself (thru windows explorer and just clicking delete), and I still had the same issue of coming eventually to the window requesting me to "try again" to have permission.
    What can I do?? I'd like to avoid Unlocker, but if it really is a reliable and SAFE program, and someone knows a SAFE place to download it from, I'd appreciate it very much so!!
    thanks!!

  • Unable to Telnet...............

    Posted by: vatsey.sharad - Engineer, HCL Comnet
    Jun 6, 2008, 2:09am PST
    Hi,
    I have two IP's Configured on my Cisco 2800. 1.1.1.1 - Loopback and 2.2.2.2 on Fast Ethernet. Both IP's are pingable across the WAN. And telnet to loopback IP is working fine. However I am unable to telnet to Fast Ethernet IP. The error message while trying to telnet to Fast Ethernet IP is: "Could not open connection to the host, on port 23: Connect failed". I tried to debug telnet on the router. The Debug output for unsuccessful telnet is as follows:
    Telnet194: recv SB NAWS 139 24
    However for a successful telnet session, the output is:
    Telnet195: 1 1 251 1
    TCP195: Telnet sent WILL ECHO (1)
    Telnet195: 2 2 251 3
    TCP195: Telnet sent WILL SUPPRESS-GA (3)
    Telnet195: 80000 80000 253 24
    TCP195: Telnet sent DO TTY-TYPE (24)
    Telnet195: 10000000 10000000 253 31
    TCP195: Telnet sent DO WINDOW-SIZE (31)
    TCP195: Telnet received DO ECHO (1)
    TCP195: Telnet received DO SUPPRESS-GA (3)
    TCP195: Telnet received WILL TTY-TYPE (24)
    Telnet195: Sent SB 24 1
    TCP195: Telnet received WILL WINDOW-SIZE (31)
    Telnet195: recv SB NAWS 110 52
    Telnet195: recv SB 24 0 ANSI
    There are no ACL's or firewalls involved in the picture.

    Sharad
    How many forums did you post this question in? I have already found it in 2 other forums.
    HTH
    Rick

  • Unable to telnet to LINUX desktop

    I've installed Linux 2.6.9-42.0.0.0.1 ( downloaded from oracle's website) and I'm unable to telnet to this machine from my laptop.
    I get this error
    C:\Documents and Settings\Administrator>telnet oragrid
    Connecting To oragrid...Could not open connection to the host, on port 23: Connect failed
    This is my first linux trial so I guess you need to tell me from scratch regarding starting the telnet.
    Thanks
    Mukul

    Mukul,
    Search this forum for "telnet". You'll see threads such as this one:
    Re: FTP & TELNET  in Enterprise Linux
    Bottom line, I recommend you use ssh rather than telnet. If you're connecting from Windows, download Putty, for example.
    Sergio

  • Unable to access time machine backup. The folder "Documents" can't be opened because you don't have permission to see its contents.

    My MacBook Pro with 750GB storage refuses to startup due to a problem with logic board (unfortunately I'm in Singapore and there is no Apple store here and zero customer support).  I'm trying to access some of the files from the time machine back-up using my MacBook Air with 120GB storage, but I'm unable to open the backup.  I receive an error message "you don't have permission to see its contents". Unable to access time machine backup. The folder “Documents” can’t be opened because you don’t have permission to see its contents.
    I don't really want to migrate the data from the time machine to the MacBook Air as I simply don't have sufficient storage space on the MacBook Air.  The iPhoto library which I'm trying to access is 200GB, which is more than the size of the MacBookAir.
    Is there any way I can view the photos and documents stored on the time machine backup.
    Thank you very much.

    When you setup the Mac, you created a Admin user account with say name X
    You ran Migration Assistant and it migrated user Y from the Windows machine.
    User Y has different permissions than User X.
    User X can't normally access User Y's account.
    So what you do is log out of User X via the Apple menu and into User Y, this way you have permission to access the files.
    If you want to transfer files from User Y to User X account
    Transfer files between user accounts on the same machine instructions
    Finder > Go menu > Computer
    A window appears with your boot drive, double click on it to open
    Inside is Users folder, double click to open it
    Inside is your User accounts, double click on the one you want to send files too
    Double click on the Public folder drop the files into the DropBox folder,
    The permissions will change and can be used in the other user account when you log into it and moved to the appropriate folders.
    Applications are typically installed and kept in the Applications folder which is a global access folder all users can access to run them from, but not all users can modify unless they are a Admin user.
    Windows programs won't run on a Mac, but they can be instaled into a virtual machine program that is running Windows.
    Windows in BootCamp or Virtual Machine?

  • Unable to telnet to localhost after CU5

    Hi
    We upgraded E2013 to CU5 on Sat 13 - On Thu 18 at 9:12 all 4 CAS servers stopped processing mail
    error from smarthost:
    421 4.3.2 The maximum number of concurrent connections has exceeded a limit, closing transmission channel
    unable to telnet locally: telnet localhost 25 
    421 4.3.2 Service not available
    netstat -an | find "25" shows port is listening
    Test-SmtpConnectivity shows success
    Any ideas appreciated
    shapi

    Hi ,
    Please check the below mentioned links 
    http://social.technet.microsoft.com/Forums/exchange/en-US/6cb89070-6c17-4f80-8ad1-b4bfff8c8ed6/432-the-maximum-number-of-concurrent-connections-has-exceeded-a-limit-closing-trasmission-channel
    http://social.technet.microsoft.com/Forums/exchange/en-US/62ccfbd1-9b1e-4e67-94be-692b725428a3/exchange-cas-array-exceeds-max-number-of-concurrent-connections?forum=exchange2010
    Please reply me if you have any queries.
    Thanks & Regards
    S.Nithyanandham
    Thanks S.Nithyanandham

  • When I try to backup to a disk I have used many times for backups I get the following error message: "unable to get status of backup disk"

    unable to get status of backup disk

    Greetings cf83,
    It seems you are unable to backup on an existing Time Machine backup drive. I have linked to an article that may help you troubleshooting the issue:
    OS X: If you can't back up or restore with Time Machine - Apple Support
    Thank you for contributing to Apple Support Communities.
    Best,
    Bobby_D

  • Loopback0 vs. "Backup interface GigabitEthernetx/x" for redundance

    Hi,
    I am a voice engineer. To configure MGCP gateways I have used the Cisco standard method of creating a loopback interface specially when there are redundant switch connections, e.g. GigabitEthernet0/0 and GigabitEthernet0/0.  Can anybody please explain if I use "backup interface" method, would it work same way.  The backup interface method also has a backup delay, not sure what is default, but secondary interface won't be active until the delay elapses.  If I configure "no backup delay" would there still be an event for MGCP?  Can somebody please share their experience?

    If your primary interface fails, is there an event for MGCP? What happens to active calls?
    Update: I just found that the default delay is 0 seconds (that means "no backup delay" is not required to be explicitly added, so I assume the MGCP gateway should not experience any impact at all. If you done this testing in your environment, please confirm.
    And thanks a lot for quick reply!

  • Time Machine could not complete the backup "Time Capsule". Unable to access disk image backup "/ Volumes / Time Capsule / iMac.sparsebundle" (error 112). How can I repair it?

    Time Machine could not complete the backup "Time Capsule". Unable to access disk image backup "/ Volumes / Time Capsule / iMac.sparsebundle" (error 112).
    How can I fix it?

    You might want to take a look at Pondini's excellent support document......Time Machine Troubleshooting
    http://pondini.org/TM/Troubleshooting.html
    See # C17

  • Unable to telnet or user disconnected

    Hi,
    It seems that every time a client/server application runs extensively on the Sun Solaris 7 server, users who are already connected to the server got disconnected or we're unable to telnet or ping the server (connection got timeout). I increased the pty's to 128 but still no luck. Traffic on the switch seems ok.
    Any idea someone.?
    Pls help
    Rales

    Are you able to console to the access point? Do you have an ACL preventing telnet or HTTP access to the AP? Is there a chance that HTTP and telnet are disabled on the AP?
    Mark

  • Unable to telnet SLM224G2

    hi.
    i am able to ping my SLM224G2 switch but unable to telnet the switch.
    pls. help me out. 
    Jitendra 

    I am not sure if the SLM224G2 if you can telnet the unit but if it does have that option usually you might have some enabled firewalls in the PC that is why you are unable telnet the unit. I tried to further look at either the user guide or datasheet for the SLM224G (anyway the SLM224G2 should belong to that family) and it doesn’t say that it has a telnet capability. I am honestly not familiar with this switch but I know the SRW series has telnet capabilities. I suggest try contacting CISCO tech support to report about this problem and seek their opinion about it.

  • Unable to telnet on command prompt for udp port 514, but able to on cmd for tcp port 514

    I am unable to telnet on command prompt for udp port 514. But when I use packet snifer or wireshark I am able to see traffic going to the targetted server from udp port 514. I thought it might be a firewall issue blocking the port from communicating. But
    I figured out that windows firewall is disabled. I am able to make similar connections on the cmd for tcp port 514.
    I did a netstat -an and see that udp:514 is enabled and listening on the server.
    What am I missing here?

    Telnet actually supports TCP only. You might want to try another tool as suggested here: http://serverfault.com/questions/263032/how-to-connect-to-a-udp-port-command-line
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • Unable to access time machine backup

    Due to a crashed disk I am unable to restore from my backup and have lost everything.  I can look at the data but I can't restore.  I believe it has to do with the user account. 
    in the account section I am logged in as Administrator with the name Daniel McCarter which appears to have a space between the first and last name.
    Underneath that is my  correct email address. 
    when I look at the Backup the name of it is Daniel's iMac
    Any help with straightening the out would be appreciated
    Dan

    The right thing to do would have been to use Setup Assistant to restore the data: Move your data to a new Mac - Apple Support
    If you have some reason not to want to do that, see below.
    While in Time Machine, press the key combination shift-command-C. The front window will show all mounted volumes. All snapshots should now be accessible. Select the one you want and navigate to the files you want to restore.
    If you need to restore from a backup of the hidden user Library folder, first select a snapshot, then press shift-command-G. A Go to Folder dialog will open. In it, you'll enter the path to the folder. The dialog will help you by automatically completing the parts of the path when you start to type them.
    The path begins with slash character ("/"). Enter that. The rest of the parts will be separated by slashes.
    The next part is the date and time of the current snapshot. Enter a "2", and the rest of the date should be filled in automatically. Press the right-arrow key to jump to the end of the path. Enter a slash to start the next part.
    Next is the name of the volume (usually "Macintosh HD" unless you gave it a different name.) Start to type that, then jump to the end and enter a slash.
    The next part is "Users", followed by a slash.
    Next is your (short) user name, which is also the name of your home folder.
    Finally, enter "Library", then press return. You should now be in the Library folder. From there you can get around as in the Finder.

Maybe you are looking for

  • Customer master creation and maintenance

    Hi All, I have a question regarding customer master. The client is implementing FSCM credit and collections management. Initially, all the existing customers in AR are mapped or loaded to SAP Business partner using the functions available (I dont rem

  • Can't find flex 3 component kit

    Downloaded the latest Flex 3 sdk but there's not flash-integration directory of and mxp file to install the latest component kit for Flash? Am I missing something? [flex_sdk_3.zip]\frameworks\flash-integration\

  • Visual SourceSafe Support?

    I've recently been running into an issue with the integrated sourcesafe support in Dreamweaver 8. I notice when you specify the project location you only get so many characters in the input field. The problem I'm running into is more often than not m

  • STO-SD delivery

    Dear all, I have tried to map sceniro STO-SD delivery,I have created PO and Delivery in Vl10b but i am getting an error message while doing PGI  "Address doesn't exist 22755" for the delivery created. I maintained address for supplying plant,shipping

  • Should I Run off AC or Battery for max battery life?

    I've read so many different theories on extending your battery life, I was wondering what is the most optimal setup to ensure a long battery life: 1) If I'm using my laptop at home on a desk, is it better to keep my laptop plugged into the AC battery