FI's uplink ports Error Disabled on ENM loop
Hi,
I have two UCS6120XP FIs connected to a Cat2948G-GE-TX switch via port 1/3 on each FI. One port on the Cat2948G-GE-TX acts as the uplink port and is connected to the LAN. All ports of the Cat2948G-GE-TX are in VLAN 1 to allow all connected devices to reach the Gateway via the LAN uplink port.
Now after a while both ports 1/3 on the FIs get error disabled on ENM loop.
'show cdp neighbor' on the Cat2k shows FIs hanging off of 2/45 & 2/46. The management ports of both FIs are connected to ports 2/1 and 2/2 of the
Cat2948G-GE-TX as well, as are some other devices.
I'd like to keep both FI uplink ports enabled for failover scenarios - how can I achieve that w/o the ports getting error-disabled?
Thanks,
Matthias
Hi,
The reload was to test the loss of a FI prior to going into the production environment. A disassociate/reassociate of a SP made no difference.
I plan to upgrade to V2.2(1D) and re-test again tomorrow.
Similar Messages
-
EEM on port error-disable due to UDLD
I would like to ask from the EEM community for some assistance in regards to crafting an EEM script for an ME-3800X. We have one or two appliances whereby the only uplink (TenGigabitEthernet0/1 and/or TenGigabitEthernet0/2) goes into error-disable and caused by UDLD. What I am looking for is a script to do the following:
1. If the ports TenGigabitEthernet0/1 and/or TenGigabitEthernet0/2 goes into error-disable caused by UDLD or link-flap then disable the port, wait for 5 seconds, enable the port;
2. Wait for 15 seconds and send an email.
I only want this EEM to work on the TenGigabitEthernet interfaces and I do not want the EEM script to do this on the access ports.
Error-disable recovery is a global option and there's no option to limit on a per-interface level.
Thank you in advance.Thanks for responding, Joe.
We were not able to take down the error messages but I believe they error messages could be:
%UDLD-4-UDLD_PORT_DISABLED: UDLD disabled interface Te0/2, unidirectional link detected
%PM-4-ERR_DISABLE: udld error detected on Te0/2, putting Te0/2 in err-disable state
Could an EEM script be created when an error message or an event of "unidirectional link detected" occurs, do the following:
1. In privilege mode, issue the command "udld reset".
2. Wait for 30 seconds and then send an email.
Thanks for your assistance and support, Joe. -
Nexus 5500 - Fabricpath Core Port - Error disabled. Reason:DCX-No ACK in 100 PDUs
Has anyone seen Fabricpath Core Interfaces between two Nexus 5596UP switches error-disabled because of missing DCBX Acks after 50mins?
I do not see interface errors and the peer is another 5500.
Both switches are running 5.1(3)N2(1) with this port config:
int e1/3
switchport mode fabricpath
! Cisco 5m Twinax cables
Log messages
2012 May 25 17:40:59 nexus1 %L3VM-5-FP_TPG_INTF_DOWN: Interface Ethernet1/3 down in fabricpath topology 0 - Interface down
2012 May 25 17:40:59 nexus1 %ETHPORT-5-IF_DOWN_NONE: Interface Ethernet1/3 is down (None)
2012 May 25 17:40:59 nexus1 %ISIS_FABRICPATH-5-ADJCHANGE: isis_fabricpath-default [3365] P2P adj L1 nexus5 over Ethernet1/3 - DOWN (Delete All) on MT-0
2012 May 25 17:40:59 nexus1 %CDP-5-NEIGHBOR_REMOVED: CDP Neighbor nexus5(FOX1550GDH1) on port Ethernet1/3 has been removed
2012 May 25 17:40:59 nexus1 %LLDP-5-SERVER_REMOVED: Server with Chassis ID 547f.ee63.fa88 Port ID Eth1/1 on local port Eth1/3 has been removed
2012 May 25 17:40:59 nexus1 %ETHPORT-2-IF_DOWN_ERROR_DISABLED: Interface Ethernet1/3 is down (Error disabled. Reason:DCX-No ACK in 100 PDUs)
RobertCan you send the output of
show lldp interface ethernet 1/3
show lldp dcbx interface ethernet 1/3
a workaround may be to disable lldp on both sides on these physical interfaces -
New Trunking port Error Disabled on Nexus 5000
I configured my Nexus 5000 ports as so
Int Eth1000/1/48
switchport mode trunk
switchport trunk allowed vlan 8
speed 1000
channel-group 7 mode active
int Po7
switchport mode trunk
switchport trunk allowed vlan 8
vpc7
speed 1000
I configured my 3650 as so:
int Gig0/23
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 8
switchport mode trunk
speed 1000
channel-group 1 mode active
Port channel 1
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 8
switchport mode trunk
speed 1000
Both of these ports are connected Int Eth1000/1/48 and int Gig0/23. Int Eth1000/1/48 shut down and when I checked the logs on the N5K it said for the port ErrorDisabled REASON BPDUguard. I did not configure bpdufilter or bpduguard on either side. What is causing it?
I found 3 other ports the have bpdufilter on them would that be it?
Since the 3560 is an older switch how can I also ensure it get demoted to not be root bridge or secondary root bridge?Hi,
1- You tried to bundle GE and E interfaces with LACP on both switch but you did not mention the other bundle members, however, it looks the etherchannel did not comes up and interfaces work separately.
As a result, STP has prevented bridging loop and put one of them in errdisable state. I think you must check your etherchannel configuration.
2- you can use "spanning-tree vlan <> priority 61400" on 3560 switch to make sure it won't be a root bridge.
HTH
Houtan -
Anyone ever seen this before? Trying to understand why the port error disabled.
2011 Jan 18 11:53:09 MTWDAVDC1BLDB9001 %ETHPORT-2-IF_DOWN_ERROR_DISABLED: Interface Ethernet1/1 is down (Error disabled. Reason:requested by sap: MTS_SAP_DCX, req down_type: 2, req down_reason: 222 )
MTWDAVDC1BLDB9002# sh int eth1/1
Ethernet1/1 is down (DcxMultipleMSAPs)
Hardware: 1000/10000 Ethernet, address: 0027.0d23.4d8d (bia 0027.0d23.4d8d)
MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA
Port mode is trunk
full-duplex, 10 Gb/s, media type is 10g
Input flow-control is off, output flow-control is off
Rate mode is dedicated
Switchport monitor is off
Last link flapped 1d03h
Last clearing of "show interface" counters never
1 minute input rate 0 bits/sec, 0 packets/sec
1 minute output rate 0 bits/sec, 0 packets/sec
Rx
153349455 input packets 143221479 unicast packets 3730739 multicast packets
6397237 broadcast packets 0 jumbo packets 0 storm suppression packets
66448449173 bytes
Tx
328643307 output packets 90031378 multicast packets
113132871 broadcast packets 12877361 jumbo packets
62121338327 bytes
0 input error 0 short frame 0 watchdog
0 no buffer 0 runt 0 CRC 0 ecc
0 overrun 0 underrun 0 ignored 0 bad etype drop
0 bad proto drop 0 if down drop 0 input with dribble
1416 input discard
0 output error 0 collision 0 deferred
0 late collision 0 lost carrier 0 no carrier
0 babble
0 Rx pause 0 Tx pause
8 interface resetsI looked into the error and would suggest opening a TAC case so our engineering team can look into this error. You can open a case using the supportforum as well to turn the thread into a case.
Sorry to not be able to help more, but looks like our internal team needs to look into this further.
Chad -
I keep getting error 3004 when i try restoring and updateing my iphone 4 to iOS 7 i did everything 1. flushed dns 2. edited hosts 3. updated itunes and downloaded new one 4. switched usb ports 5. disabled antivirus 6. enabled ports 80 and 443 7. disabled firewall 8. even tryed putting mobile in DFU mode to restore it not of this worked so please help me
please replyyy i'm stuck on this like whole week
-
Campus Manager report - Ports in error Disabled state
Hi,
I have LMS 3.2 and I wonder how Campus Manager collects information from the switch to generate a report of discrepancies, namely a report of "Ports in Error Disabled state"??
I find that I have ports in errDisabled state but Campus Manger doesn´t show this information in "Ports in Error Dissabled state" report. What could be the problem?
Thanks.Hi,
Campus Manager do snmpwalk on the ciscoErrDisableMIB to get the status of the error disabled ports.
Thanks,
Gaganjeet Singh -
Vfc error disabled because of Ethernet port down?
We are building a new datacenter and is starting to set up the SAN.
This small DC consist of 2 Nexus 5596UP, a Compellent SAN and 2 Dell M1000e cassis with blade servers.
naive FC part in Nexus has been easy to set up but we have problems with the FCOE setup.
Since the blades are not installed yet none of the Ethernet ports are up. As soon as we bind an ethernet port to a vfc the vfc goes to error disable with this message:
%PORT-2-IF_DOWN_ERROR_DISABLED: %$VSAN 1900%$ Interface vfc101 is down (Error disabled)
Config snippets:
vlan 1900
fcoe vsan 1900
name VSAN-A-FCOE
vlan 1901
name VSAN-B-FCOE
vsan database
vsan 1900 name "VSAN-A"
vsan 1901 name "VSAN-B"
interface vfc101
bind interface Ethernet1/1
no shutdown
vsan database
vsan 1900 interface vfc101
vsan 1900 interface fc2/13
vsan 1900 interface fc2/14
vsan 1900 interface fc2/15
vsan 1900 interface fc2/16
interface Ethernet1/1
switchport mode trunk
spanning-tree port type edge trunk
vlan 1900
fcoe vsan 1900
name VSAN-A-FCOE
vlan 1901
name VSAN-B-FCOE
vsan database
vsan 1900 name "VSAN-A"
vsan 1901 name "VSAN-B"
vsan database
vsan 1900 interface vfc101
vsan 1900 interface fc2/13
vsan 1900 interface fc2/14
vsan 1900 interface fc2/15
vsan 1900 interface fc2/16
interface vfc101
bind interface Ethernet1/1
no shutdown
interface Ethernet1/1
switchport mode trunk
spanning-tree port type edge trunk
Do the vfc go error disable because the ethernet interface being down? I was under the impression it should just go "down"What you are seeing is normal.. Here are outputs from my lab switch where I shut Eth1/20 which is tied to vFC 20
24.10.5020A.1(config)# int ethernet 1/20
24.10.5020A.1(config-if)# shut
2011 Oct 21 10:16:01 24 %ETHPORT-5-IF_DOWN_CFG_CHANGE: Interface Ethernet1/20 is down(Config change)
2011 Oct 21 10:16:01 24 %FLOGI-5-MSG_PORT_LOGGED_OUT: %$VSAN 100%$ [VSAN 100, Interface vfc20: mode[TF]] Nx Port 21:00:00:c0:dd:12:0e:35 logged OUT.
2011 Oct 21 10:16:01 24 %PORT-5-IF_PORT_QUIESCE_FAILED: Interface vfc20 port quiesce failed due to failure reason: Epp Not Supported by Peer (0x19d)
2011 Oct 21 10:16:01 24 %PORT-5-IF_DOWN_NONE: %$VSAN 100%$ Interface vfc20 is down (None)
2011 Oct 21 10:16:01 24 %PORT-2-IF_DOWN_ERROR_DISABLED: %$VSAN 100%$ Interface vfc20 is down (Error disabled)
2011 Oct 21 10:16:02 24 %ETHPORT-5-IF_DOWN_ADMIN_DOWN: Interface Ethernet1/20 is down (Administratively down)
24.10.5020A.1(config-if)# -
I have a 3550 switch that gets a error-disabled copper ports. There is no errors ont the port. What else would cause it to be disabled?
Although there is no error on the port , there should be an error message in the log that should tell you the reason why the port got error disabled like port security violation , loopback detection , etherchannel misconfig etc.
You can enable errordisable recovery for all different causes by setting a timer. What happens is once this timer expires , the port is brough out of error dsiabled state.
Here are some of the useful commands.
D-C3550-2A(config)#errdisable ?
detect Error disable detection
recovery Error disable recovery
D-C3550-2A(config)#errdisable recovery ?
cause Enable error disable recovery for application
interval Error disable recovery timer value
Hope this helps.
Salman Z. -
Failed:Error disabled - SFP vendor not supported on Fabric Interconnect 6248UP
We are connecting a FC-uplink on a Fabric Interconnect 6248UP to a MDS9124. On the Fabric Interconnect side we use a 8Gbps SFP (DSpSFP-FC8G-SW) on the MDS9124 side there is a 4 Gbps SFP.This should work when speed is at fixed speed 4 Gbps on both sides (I was told). When the SFP's and cabling is connected I get an error in the UCS manager on the FC-uplink port we are using:
Failed:Error disabled - SFP vendor not supported.
I cannot change the speed on the FC-Uplink ( I can only set user-label). The Fabric Interconnect is configured for FC on the last 8 ports and that is where the SFP for the storage is located (port 31).I have a similar problem. I'm using port 1/41 and gets this output
show system firmware expand | head lines 10
UCSM:
Running-Vers: 2.1(3a)
Package-Vers: 2.1(3a)A
Activate-Status: Ready
Catalog:
Running-Vers: 2.1(3a)T
Package-Vers: 2.1(3a)A
Activate-Status: Ready
sh interface fc 1/41
fc1/41 is down (Error disabled - SFP vendor not supported)
Hardware is Fibre Channel, SFP is Unknown(0)
Port WWN is 20:29:00:2a:6a:7e:7b:00
Admin port mode is F, trunk mode is off
snmp link state traps are enabled
Port vsan is 1
Receive data field Size is 2112
Beacon is turned off
1 minute input rate 0 bits/sec, 0 bytes/sec, 0 frames/sec
1 minute output rate 0 bits/sec, 0 bytes/sec, 0 frames/sec
0 frames input, 0 bytes
0 discards, 0 errors
0 CRC, 0 unknown class
0 too long, 0 too short
0 frames output, 0 bytes
0 discards, 0 errors
0 input OLS, 0 LRR, 0 NOS, 0 loop inits
0 output OLS, 0 LRR, 0 NOS, 0 loop inits
last clearing of "show interface" counters never
show int fc 1/41 transceiver details
fc1/41 sfp is present but not supported
name is CISCO-FINISAR
part number is FTLX8571D3BCL-C2
revision is A
serial number is FNS17401NYG
FC Transmitter type is Unknown(0)
FC Transmitter supports Unknown(0) link length
Transmission medium is Unknown(0)
Supported speeds are - Min speed: -1 Mb/s, Max speed: -1 Mb/s
Nominal bit rate is 10300 MBits/sec
Link length supported for 50/125mm fiber is 80 m(s)
Link length supported for 62.5/125mm fiber is 20 m(s)
No tx fault, no rx loss, no sync exists, diagnostic monitoring type is 0x68
SFP Diagnostics Information:
Alarms Warnings
Is this a firmware problem? -
UDLD Detection & Error Disable On Cat 6513
Hi
We have a problem with an etherchannel trunk between 2 Cat 6513's. The etherchannel is 8Gb split across 2 Copper 10/100/1000Mb 16 port cards in each chassis. The trunk uses ports 13 - 16 on slot 5 in one chassis to 13 - 16 on slot 5 in the other chassis and 13 - 16 on slot 6 in one chassis to 13 - 16 in slot 6 on the other chassis.
We appear to have had a UDLD Detection which error disabled all 4 of the links from slot 6 to slot 6 at the same time. IE ports 13 - 16 on slot 6 of both chassis went into error disabled state.
Could this be a ASIC hardware problem on one of the cards? If so, how do we establish which end of the trunk the problem exists? All other connections on these slot 6 cards are working fine.UDLD is a protocol that discovers if communication over a link is one-way only, and therefore partially broken. A damaged fiber cable or other cabling/port issue could cause this one-way only communication. Spanning tree loops can occur with this problem. UDLD allows the port to detect a unidirectional link, and can be configured to put a port in errDisable state when it detects this condition.
-
Cisco Prime Infrastructure 2.1 error-disable alert
We have a cisco PI 2.1 managing switches and a lot of switchports have BPDUGuard enabled. When occur error-disable , request send email notification to administrator .
By default, when a port of a switch goes down, the Prime generates alarm for that. (this is a problem, because every laptop disconnection will generate alarm for administrator)
Can i change the alert just for error-disable and how to ?
ThanksCauses of Errdisable
This feature was first implemented to handle special collision situations in which the switch detected excessive or late collisions on a port. Excessive collisions occur when a frame is dropped because the switch encounters 16 collisions in a row. Late collisions occur after every device on the wire should have recognized that the wire was in use. Possible causes of these types of errors include:
A cable that is out of specification (either too long, the wrong type, or defective)
A bad network interface card (NIC) card (with physical problems or driver problems)
A port duplex misconfiguration
A port duplex misconfiguration is a common cause of the errors because of failures to negotiate the speed and duplex properly between two directly connected devices (for example, a NIC that connects to a switch). Only half-duplex connections should ever have collisions in a LAN. Because of the carrier sense multiple access (CSMA) nature of Ethernet, collisions are normal for half duplex, as long as the collisions do not exceed a small percentage of traffic.
There are various reasons for the interface to go into errdisable. The reason can be:
Duplex mismatch
Port channel misconfiguration
BPDU guard violation
UniDirectional Link Detection (UDLD) condition
Late-collision detection
Link-flap detection
Security violation
Port Aggregation Protocol (PAgP) flap
Layer 2 Tunneling Protocol (L2TP) guard
DHCP snooping rate-limit
Incorrect GBIC / Small Form-Factor Pluggable (SFP) module or cable
Address Resolution Protocol (ARP) inspection
Inline power
Note: Error-disable detection is enabled for all of these reasons by default. In order to disable error-disable detection, use the no errdisable detect cause command. The show errdisable detect command displays the error-disable detection status. -
SR-IOV Uplink Port with NIC Teaming
Hello,
I'm trying to setup my uplink port profile and logical switch with NIC Teaming and SR-IOV support. In Hyper-V this was easy, just had to create the NIC Team (which I configured as Dynamic & LACP) then check the box on the virtual switch.
I'm VMM it does not seem to like to enable NIC Teams with SR-IOV:
Can anyone advise? I'm not using any virtual ports. I just want all my VMs to connect to the physical switch though the LACP NIC Team, something which I thought would be simple.
I have a plan B - don't use Microsoft's NIC Teaming and instead use the Intel technology to present all the adapters as one to the host. I'd rather no do this.
Thanks
MrGoodBytesHi Sir,
"SR-IOV does have certain limitations. If you configure port access control lists (ACLs), extensions or policies in the virtual switch, SR-IOV is disabled because its traffic totally bypasses the switch.
You can’t team two SR-IOV network cards in the host. You can, however, take two physical SR-IOV NICs in the host, create separate virtual switches and team two virtual network cards within a VM. "
There is really a limitation when using NIC teaming :
http://technet.microsoft.com/en-us/magazine/dn235778.aspx
Best Regards,
Elton Ji
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected] . -
Dears
After configuring DOT1x on access ports , some ports show error disabled without enabling the port-security , is their any way to increase the number of MAC addresses allowed on the port ? , is it possible to disable this feature
Sent from Cisco Technical Support iPhone AppHi Eng.malak,
The port config provided by you the interface GigabitEthernet1/0/2 is configured for MDA that means an IP phone and a single host behind the IP phone are authenticated independently, even though both the IP phone and host machine are connected to a single switch port on the switch. If more than once device is detected in either domain, a security violation will be triggered. This can be a problem when a phone fails to authenticate properly. If a phone fails authentication, then the switch does not receive the "device-traffic-class=voice" VSA from the radius server and the switch will assume that the failed device was in the data domain. However if there is already a data device behind the phone, there will be now 2 devices in the data domain, and a security violation is triggered. On this port only 2 MAC addresses are allowed. The switch place the client machine in a data vlan and the IP phone in a voice vlan.
Configure the violation mode. The keywords have these meanings:
authentication violation shutdown | restrict | protect | replace}
•shutdown-Error disable the port.
•restrict-Generate a syslog error.
•protect-Drop packets from any new device that sends traffic to the port.
•replace-Removes the current session and authenticates with the new host.
Configuring 802.1x Violation Modes
http://www.cisco.com/en/US/docs/switches/lan/catalyst3560/software/release/12.2_55_se/configuration/guide/sw8021x.html#wp1324086
~BR
Jatin Katyal
**Do rate helpful posts** -
Hi,
We have a campus network. A student's hostel room port that is connected to a 2960 switch get error-disabled time and again and it shows the reason being "loopback".
From switch patch panel to user's LAN port in room , we have tested the connectivity through cable tester and it is found to be proper.
He has changed his LAN cable also, what can be the exact reasons causing this problemThanks for the output to the command "sh version".
Look at the uptime of the switch. Because of this the output to the "loopback_error_2960" is totally useless. Why? If there was any line errors which can determine if there was a cabling issue, a NIC card issue or something more sinister, then there's only 4-days worth of data. Not much to run with.
The IOS is very, very old.
Currently, the only thing I can think of is remove the configuration of setting the speed to the port to 10 Mbps. (I don't see the benefit of punishing students by slowing down their network speed.) Once the port is running auto speed/auto duplex, wait for approximately 30 minutes and run a TDR on the port. Even better if you can move the cable to the GigabitEthernet port and run the TDR there so you'll get a better picture of all the pairs.
Another thing, post the output to the command "sh post".
Maybe you are looking for
-
How do I transfer photos from MacPro to iPad 2,without using iPhoto
How do I transfer photos from MacPro to iPad 2,without using iPhoto on the ipad.
-
Why is the preview generated by "export to html" appear without formatting or background?
I use Muse to design my site, but upload via Filezilla. After making a change to one page, I exported to html, and the preview that appears has the entire website stripped of formatting, and everything appears as a bulleted list. I haven't uploaded i
-
We need help installing our new printer
We bought a new HP Photosmart 7520e printer because our old one wasn't working with our computer. We were assured by the salespeople that it would be compatible with Windows 8. That doesn't appear to be the case! We've used the CD that came with i
-
SunDisk ImageMate SDDR-05 dose not show in Finder not even as hidden
I tried that method that says you open Terminal and did ls -a /Volumes but the output was: . .. Macintosh HD Raport from System Profiler. USB CFII: Product ID: 0x0005 Vendor ID: 0x0781 (SanDisk Corporation) Version: 0.05 Speed: Up to 12 Mb/sec Manufa
-
I have money on my iPod but he always ask for my account I cancel my bank account , so I want to puchase with my money.