Firewall service module vs ASA

Hi
Someone told me that the cisco firewall service module of 6500 has poor performances compared to ASA
What do you recommend as a core firewall (to protect internal servers): ASA or firewall service module ?
thanks

Hi,
We are using 5 FWSMs at the moment but are moving away from them to ASA5585-X models.
I wouldnt suggest going to FWSMs anymore at this point if you have any plan on having support for new features.
End Of Life and End of Sale Notice
http://www.cisco.com/en/US/prod/collateral/modules/ps2706/eol_c51-699134.html
The follower for the FWSM is the ASA Service Module which supports the newer softwares (while the FWSM doesnt). Heres a link to a document about the ASASM
http://www.cisco.com/en/US/prod/collateral/modules/ps2706/ps11621/data_sheet_c78-672507.html
Also you could always consider a separate ASA models. Here are links to both the orignal ASA 5500 series and new ASA 5500-X series
ASA 5500 Series
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/prod_brochure0900aecd80285492.pdf
ASA 5500-X Series
http://www.cisco.com/en/US/prod/collateral/vpndevc/ps6032/ps6094/ps6120/at_a_glance_c45-701635.pdf
I guess the question for you is what are the requirements for the device regarding performance. All of the above documentation should give you a clue about which model might be the best for you.
- Jouni

Similar Messages

  • Question on how does load balancing work on Firewall Services Module (FWSM)

    Hi everyone,
    I have a question about the algorithm of load balancing on Firewall Services Module (FWSM).
    I understand that the FWSM supports up to three equal cost routes on the same interface for load balancing.
    Please see a lower simple figure.
    outside inside
    --- L3 SW --+
    |
    MHSRP +--- FWSM ----
    |
    --- L3 SW --+
    I am going to configure the following default routes on FWSM point to each MHSRP VIP (192.168.13.29 and 192.168.13.30) for load balancing.
    route outside_1 0.0.0.0 0.0.0.0 192.168.13.29 1
    route outside_1 0.0.0.0 0.0.0.0 192.168.13.30 1      
    However I don't know how load balancing work on FWSM.
    On FWSM, load balancing work based on
    Per-Destination ?
    Per-Source ?
    Per-Packet ?
    or
    Other criteria ?
    Your information would be greatly appreciated.
    Best Regards,

    Configuring "tunnel default gateway' on the concentrator allowed traffic to flow as desired through the FWSM.
    FWSM is not capable of performing policy based routing, the additional static routes for the VPN load balancing caused half of the packets to be lost. As a result, it appears that the VPN concentrators will not be able to load balance.

  • Assigning VLANs to the Firewall Services Module

    I need add a new vlan group to our fwsm module. I have some doubts:
    What command do i need for it?
         firewall vlan-group 5 100,101,102,103,104,105
         firewall switch 2 module 4 vlan-group 5
         firewall switch 1 module 4 vlan-group 5
         or
         firewall vlan-group 5 100,101,102,103,104,105
         firewall switch 2 module 4 vlan-group 1,2,3,4,5
         firewall switch 1 module 4 vlan-group 1,2,3,4,5
    Will it be disruptive?
    Thanks!

    So, just to confirm, in this case to add/append a new vlan-goup to the firewall module I should use:
    Switch# firewall switch <1-2> module 02 vlan-group 2
    My main concern is if with the command It will replace the curent vlan-goup (4,5,6) or if it just append the new vlan-group.
    Thanks in advance!

  • Firewall services module authentication issues

    Have internal web apps and Nfuse available to remote users after they authenticate to our firewall using a ACS account. All was cool until we recently upgraded our FWSM and IOS image. Now some users are complaining that they do not get an authentication prompt from the firewall and cannot login. Most users can authenticate as usual.
    Weird thing is that if the end user takes their home router or firewall out of the mix, the firewall authentication works. In some cases, an upgrade of the remote router or firewall firmware resolves the issue as well.
    Any reason why the FWSM would start acting this way and not allow connections from devices that could connect previously? NAT issue? I don't want to have to upgrade firmware on users personal routers and firewalls to make this work...

    The only workaround is to reboot the FWSM after creating new interfaces.
    Try this Bug - CSCsg65455

  • Partition cf in Firewall Services Module

    Hi,
    Reference CISCO: Flash Card in FWSM equals 128MB partition but on 6 cf, totaling about 20MB per cf.
    I am upgrading my FWSM and ASDM software, but I can not because I have little space in flash.
    Settings file 2MB
    Old version:
    FWSM 3.1 (5) - 5.59Mb
    ASDM 5.0 (2) F - 3.09Mb
    Configuration File: 2MB
    Total Space in flash: 10.7Mb
    New Version:
    FWSM 4.1 (12) - 6.10Mb
    ASDM 6.2 (3) F - 13.11Mb
    Configuration File: 2MB
    Total Space in flash: 21.20Mb (Insufficient space in memory)
    How to solve this problem, I can not put software and ASDM configuration file in the same cf. Hi,
    Reference CISCO: Flash Card in FWSM equals 128MB partition but on 6 cf, totaling about 20MB per cf.
    I am upgrading my FWSM and ASDM software, but I can not because I have little space in flash.
    Settings file 2MB
    Old version:
    FWSM 3.1 (5) - 5.59Mb
    ASDM 5.0 (2) F - 3.09Mb
    Configuration File: 2MB
    Total Space in flash: 10.7Mb
    New Version:
    FWSM 4.1 (12) - 6.10Mb
    ASDM 6.2 (3) F - 13.11Mb
    Configuration File: 2MB
    Total Space in flash: 21.20Mb (Insufficient space in memory)
    How to solve this problem, I can not put software and ASDM configuration file in the same cf.

    Hi Bro
    Why don't you remove your old IOS version permanently and put in this new IOS version instead. Can I have a look at your show run output in your system context.
    Regards,
    Ram

  • Migrating from FWSM to ASA Service Module (ASASM)

    I'm migrating from a failover pair of FWSM modules across to a failover pair of ASA Service Modules. In order to avoid a "big bang" switchover I intend to migrate subnets from one to the other over a protracted period.
    With that in mind, can anyone confirm whether there is any restriction on having FWSM and ASASM modules in the same chassis? A trawl of the relevant documentation hasn't revealed anything.
    In this specific case it is Catalyst 6509E VSS chassis pairs with Sup-2T.
    Thanks in advance.

    So long as the chassis has enough power to power these modules you are good.
    Upto 4 FWSMs can be installed in a chassis.
    Upto 4 ASA-SM modules can be installed in a chassis.
    FWSM:
    http://www.cisco.com/en/US/prod/collateral/modules/ps2706/ps4452/product_data_sheet0900aecd803e69c3.html
    • Up to 4 FWSMs (20 Gbps) per Catalyst 6500 chassis
    ASA-SM
    http://www.cisco.com/en/US/prod/collateral/modules/ps2706/ps11621/qa_c67-662207.html
    Q. How many ASA Services Modules can I place in a Cisco Catalyst 6500 Series chassis?
    A. Up to four independent ASA Services Modules can simultaneously run in a Cisco Catalyst 6500-E Series chassis.
    -Kureli
    Checkout my breakout session at Cisco Live 2013, Orlando, Florida.
    BRKSEC-2024 Deploying Next-Generation Firewall Services on the ASA 
    Room 314A Tuesday, June 25 3:00 PM - 4:30 PM

  • ASA Service module shut down and on automatically

    hello,
    i have a asa service module which is inserted on 6509 chassis.
    This morning when i came to the office i have noticed my asa service module was restarted at last night but 6509 was up.
    one more thing we dont have failover.only have single asa service module.
    ASA SM version is 8.5
    below is the failover history and details
    ciscoasa up 17 hours 11 mins
    ------------------ show crashinfo ------------------
    No crash file found.
    ------------------ show failover history ------------------
    ==========================================================================
    <--- More --->
    From State                 To State                   Reason
    ==========================================================================
    14:28:40 UTC Apr 7 2013
    Not Detected               Disabled                   No Error
    can any one tell me why this happend.
    thanks in advanced
    Khem

    Hi,
    Would seem to me that it would be best to check this through Cisco TAC to determine the cause.
    It would seem though that no Crashinfo file was generated so thats kinda strange.
    You should be able to confirm if the ASASM is set to save a crashinfo file with the command "show crashinfo save"
    - Jouni

  • ASA Service Module on 6500 montoring console session

    We have 6500 with ASA Service Module
    On 6500 how can we configure so that if someone logs in to the ASA Service Module and reboots the firewall we can have logs of it in syslog of switch .
    Thanks for help

    I hate to answer my own posts, but here it is.  TAC tells us that there are 2 choices to make this work.  Apparently the way that worked on an ISR and ISRG2 does not work on the 4000 series routers.  I guess that's progress.
    Option 1. Use a physical cable to connect one of the router's interfaces to one of the etherswitches interfaces and treat it just like the etherswitch is a seperate physical switch.  I'm sure there is a use case for that but I'll not cover that here.
    Option 2. Use the "service instance" feature on the router's internal interface to bind it to a new "BDI" virtual interface on the router.  This is what we'll do.
    On our router ethernet-internal 1/0/0 maps to Gi0/18 on the etherswitch, all internal to the box.  The router will be10.0.0.1 and the switch will be 10.0.0.2.
    Router:
    interface Ethernet-Internal 1/0/0
    service instance 1 ethernet
    encapsulation dot1q 50
    rewrite ingress tag pop 1
    interface BDI 1
    mtu 9216
    ip address 10.0.0.1 255.255.255.0
    Switch:
    interface Gi0/18
    switchport trunk vlan allowed 50
    switchport mode trunk
    vlan 50
    name Egress vlan
    interface vlan 50
    ip address 10.0.0.2 255.255.255.0
    ip route 0.0.0.0 0.0.0.0 10.0.0.1
    Then there are a million ways to design and configure the switch as a normal 3560X switch but that's beyond the scope of my question.

  • Does ASA Service Module on 6509-E support Remote Access VPN ?

    I'm having a problem configuring Remote Access VPN (SSL, Anyconnect ect.) on ASA Service Module on 6509-E. Is this even supported  or am i wasting my time trying to make something work which will not work in a first place :) ? Site-to-Site works without any problems.
    Tech Info:
    6509-E running SUP 2T 15.1(2)SY
    ASA Module - WS-SVC-ASA-SM1 running image - asa912-smp-k8 & asdm-712
    Licenses on ASA:
    Encryption-DES - Enabled
    Encryption-3DES-AES  -Enabled
    Thanks in Advance for support.

    Are you running multiple context mode?
    If you are, remote access VPN is not supported in that case:
    "Note Multiple context mode only applies to IKEv2 and IKEv1 site to site and does not apply to AnyConnect, clientless SSL VPN, the legacy Cisco VPN client, the Apple native VPN client, the Microsoft native VPN client, or cTCP for IKEv1 IPsec."
    Reference.

  • Service module placement and the L2 adjacency problem

    I'd be very interested to hear others opinions on this. You have a datacenter environment with L2 boundaries at end of row aggregators, then L3 back to the core and edge. You have 6500 service module switches hanging off the core housing ACE and FWSM modules. You want to offer firewalling and load-balancing services to servers around the datacenter.
    What is the current best practice ways of resolving the L2 adjacency requirement that the firewalling and load-balancing services impose? L2TPv3? EoMPLS? Any relevant advice, deployment examples, whitepapers etc would be much appreciated!
    Thanks for any replies,
    George

    George
    You could i suppose look to use L2TPv3 if your switches support it or EoMPLS but to my mind this is actually using a band aid to fix a problem that shouldn't be there.
    We too struggled in our data centres with this setup but remember you only need L2 adjacency if you are running the FWSM in transparent mode or the ACE in bridged mode.
    If you are then the cleanest solutions are either
    1) redesign core connections to L2
    2) deploy 6500 switches in the distribution layer. I say distribution layer because it's not clear from your description what your topology actually is but i'm assuming L2 access to distro and then L3 distro to core and the core switches are the 6500 switches.
    Personally i always use the routed L3 approach where possible for fast failover and no STP and in the campus environment it works really well.
    However L3 from the access-layer to the distro in the data centre is very limiting and you often come across problems such as the one you are facing.
    Now again it does depend on your topology but assuming the issue is your core is L3 connected and you need L2 adjacency with your distro to offer servers i would look to deploy 6500 switches in the distro layer with the service modules in them.
    If i have misunderstood please come back with more details.
    Jon

  • Trying to enable/configure an IPS software module on ASA 5545

    I've been trying to get our IPS module working on a pair of ASA 5545-X with nothing but grief.  First we lost our license paks, then I found then and genned the license files  FALCONXXXX.LIC. Cisco told me that I have to config the CX module and use Prime Security Manager to load the *.lic files. 
    Finally get that done but the IPS module is still inactive. Okay missing IPS image on disk0: copy that on to ASA and try loading it using the 
    sw-module cmds and return error is can't load image another service is running
    So do I have to stop the CX after all this Prime Security manager stuff?  I can't use ASDM since it only wants an activation key (hex) which I don't have..
    Ideas? suggestions? 
    od  Card Type                                    Model              Serial No. 
       0 ASA 5545-X with SW, 8 GE Data, 1 GE Mgmt     ASA5545            FCH1831JCXB
     ips Unknown                                      N/A                FCH1831JCXB
    cxsc ASA CX5545 Security Appliance                ASA CX5545         FCH1831JCXB
     sfr Unknown                                      N/A                FCH1831JCXB
    Mod  MAC Address Range                 Hw Version   Fw Version   Sw Version     
       0 7c0e.ceee.d8eb to 7c0e.ceee.d8f4  1.0          2.1(9)8      9.2(2)8
     ips 7c0e.ceee.d8e9 to 7c0e.ceee.d8e9  N/A          N/A          
    cxsc 7c0e.ceee.d8e9 to 7c0e.ceee.d8e9  N/A          N/A          9.2.1.1
     sfr 7c0e.ceee.d8e9 to 7c0e.ceee.d8e9  N/A          N/A          
    Mod  SSM Application Name           Status           SSM Application Version
     ips Unknown                        No Image Present Not Applicable
    cxsc ASA CX                         Up               9.2.1.1
     sfr Unknown                        No Image Present Not Applicable
    Mod  Status             Data Plane Status     Compatibility
       0 Up Sys             Not Applicable        
     ips Unresponsive       Not Applicable        
    cxsc Up                 Up                    
     sfr Unresponsive       Not Applicable        
    Mod  License Name   License Status  Time Remaining
     ips IPS Module     Disabled        perpetual     

    The thing to keep in mind is what IPS you have purchased. There are three distinct types.
    The classic IPS uses the IPS software module. That uses a subscription that is bound to your ASA via your Smartnet support and does not require an license file once the software module is activated using an activation key.
    The CX module also has an IPS license option. That is configured from within the PRSM interface and will only be visible in PRSM - not in the "show module" output. Your output indicates the CX module is installed so if you have that IPS license type for CX (i.e. the FALCONXXXX.LIC) you need to follow the CX quick start guide and apply the license file via the PRSM GUI.
    There's also an IPS license type for the sfr (FirePOWER service module) which is installed via the separate FireSIGHT Management Center and applied to the module remotely.

  • Service Modules in 6500s, IPS/IDS and Stand-alone options.

    Hi,
    My first post here and it's a question regarding knowledge that I can't seem to find via CCW and through people I know.
    Does the Service Module in the 6500 i.e. WS-SVC-ASASM1B-K9 come with or support an IPS/IDS option?
    Does a stand-alone ASA5500 come with an installed IPS/IDS option.
    Thanks.

    > Does the Service Module in the 6500 i.e. WS-SVC-ASASM1B-K9 come with or support an IPS/IDS option?
    On the Cat6k5 is the IDSM2. Thats a completely outdated module with 500 MBit/s of throuput. For the Datacenter designs Cisco recommends the standalone IPS 4500 instead a module if you need good IPS throughput.
    > Does a stand-alone ASA5500 come with an installed IPS/IDS option.
    The ASA has build-in IPS with a fixed signature-set that is not such rerlevant. The better way of doing IPS on the ASa is to have an optional IPS-module. These modules are didicated hardware on the legacy ASAs (the ones without -X) and pure software-modules on the new ASAs. The 5585 is an exception where IPS is also a dedicated hardware-module.
    Sent from Cisco Technical Support iPad App

  • Windows Firewall Service Crashes on Windows Server 2012

    Hello Team,
    I am facing issues with Windows Firewall Service in new Windows 2012 R2 deployments. when i try to start the Firewall service it wont start and it throws an error message to check the system event logs for information
    The Windows Firewall service terminated with the following service-specific error: 
    The data is invalid.
    I deployed this OS on a VM running with latest VM tools and HW version which is running on ESXi 5.1 U1
    2 GB RAM, 1 vCPU
    OS deployed through ISO downloaded from MS portal and License activated through KMS system, performed a couple of reboots as well.
    any advise on this issue? i am sure some of you might have also faced the same issue

    1. VMware support forum and knowledge base may give you more specific advice.
    2. Windows services may be dependent on another service(s). Analyze these dependences. Do it after you understand implications of VMware firewall function.
    3. More detailed info from Event log is needed for analysis (Event ID, etc)
    4. Hope you have connectivity configured correctly.
    5. For firewall in VMware read the following article(s):
    http://pubs.vmware.com/vsphere-51/index.jsp?topic=%2Fcom.vmware.vsphere.security.doc%2FGUID-52188148-C579-4F6A-8335-CFBCE0DD2167.html&__utma=207178772.2027713003.1393320147.1393320147.1393320147.1&__utmb=207178772.0.10.1393320147&__utmc=207178772&__utmx=-&__utmz=207178772.1393320147.1.1.utmcsr=google|utmccn=(organic)|utmcmd=organic|utmctr=(not%20provided)&__utmv=-&__utmk=174193441
    Regards
    Milos

  • XML Publisher with Service Module - Service Request Reports -- URGENT

    Hi all ... any pointers/help/guidance with the problem listed below would be much appreciated.
    I'm working in the context of the Oracle Service Module & Service Request Reports.
    I'm required to configure the XML Publisher Responsibility seeded functionality with the service module reports.
    Listed below are the two reporting requirements that I'm considering , corresponding to the following seeded XMLP Responsibility seeded components:
    (I'm quoting an extract from the Oracle TeleService Implementation & User Guide here).
    Detailed Report
    Data Definition: Service Request Detail Definition (CS_SR_DETAIL_DEF)
    Corresponding Template: Service Request Detail Report Template (CS_SR_DETAIL_TMP.en)
    Template Description: Includes all of the available service request attributes including charges, the two descriptive flexfields, and extensible attributes.
    Summary Report
    Data Definition: Service Request Summary Definition (CS_SR_SUMMARY_DEF)
    Corresponding Template: Service Request Summary Report Template (CS_SR_SUMMARY_TMP_en)
    Template Description: Includes a subset of the detailed report attributes including the same charges information as the detailed report.
    When I log into the EBS >> XML Publisher Administrator Responsibility >> Service Application ... I find these seeded XMLP components, together with the preview data, downloadable templates & sample output.
    The question is:
    Where (responsibility/application/navigation/etc.) do I find the seeded EBS Service Reports to provide the expected XML input to the seeded XMLP Service Request Data Definitions & Templates????
    Notes ...
    I have found the following two reports, under the Service Application in EBS, set their output type to XML and viewed the output of the submitted request:
    - Service Request Detail Report
    - Service Request Summary Report
    ... but each of these two reports produce XML output of a different data model/structure to that expected by each of the corresponding seeded XMLP data-definitions/templates.
    Additionally, I cannot find any corresponding concurrent program definitions on the system with the same SHORT-NAME/CODE as the seeded XMLP data definitions themselves i.e. CS_SR_DETAIL_DEF and CS_SR_SUMMARY_DEF.
    Are the necessary reports not actually seeded within EBS? Do the seeded XMLP data definitions & templates require development of new Concurrent Programs from scratch to access the database tables and provide the necessary data/input, or am I missing something here??

    I am sure you found a solution to your problem. If not, to give a pointer to this issue, I guess these reports are gererated right from the service request screen and this definition is used there.This report can be generated from several places based on where you are within SR scree.
    Thanks
    Nagamohan

  • How to configure link between 2921 and SM-D-ES3G-48-P EtherSwitch Service Module

    hi,
    I can't do that like the procedure given by Cisco.
    http://www.cisco.com/en/US/partner/docs/routers/access/interfaces/software/feature/guide/eesm_sw.html#wp1942894
    Cisco Procedure :
    interface gi10/0
    ip address x.x.x.x x.x.x.x
    service-module gigabitethernet 1/0 session
    My result :
    R2921-8CPITR-1(config)#int gi 1/1
    R2921-8CPITR-1(config-if)#ip address 2.2.2.2 255.255.255.192
    % IP addresses may not be configured on L2 links.
    R2921-8CPITR-1(config-if)
    R2921-8CPITR-1(config)#interface gigabitEthernet 1/1.1 ?
    % Unrecognized command
    R2921-8CPITR-1(config)#interface gigabitEthernet 1/1 ?
      <cr>
    R2921-8CPITR-1(config)#
    the session is not possible also ?
    R2921-8CPITR-1#service-module gigabitEthernet 1/1 sess
                                                      ^
    % Invalid input detected at '^' marker.
    R2921-8CPITR-1#
    The routeur said that it's not a L3 port, so how to configure it to allow communication between the 2921 and the card ?
    Is there a bug with that version I'm in 15.1(4)M4 ????
    R2921-8CPITR-1#sh ver
    Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version 15.1(4)M4, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2012 by Cisco Systems, Inc.
    Compiled Tue 20-Mar-12 18:57 by prod_rel_team
    ROM: System Bootstrap, Version 15.0(1r)M15, RELEASE SOFTWARE (fc1)
    R2921-8CPITR-1 uptime is 19 hours, 21 minutes
    System returned to ROM by power-on
    System restarted at 16:00:45 GAB Fri Sep 14 2012
    System image file is "flash0:c2900-universalk9-mz.SPA.151-4.M4.bin"
    Last reload type: Normal Reload
    This product contains cryptographic features and is subject to United
    States and local country laws governing import, export, transfer and
    use. Delivery of Cisco cryptographic products does not imply
    third-party authority to import, export, distribute or use encryption.
    Importers, exporters, distributors and users are responsible for
    compliance with U.S. and local country laws. By using this product you
    agree to comply with applicable laws and regulations. If you are unable
    to comply with U.S. and local laws, return this product immediately.
    A summary of U.S. laws governing Cisco cryptographic products may be found at:
    http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
    If you require further assistance please contact us by sending email to
    [email protected].
    Cisco CISCO2921/K9 (revision 1.0) with 479232K/45056K bytes of memory.
    Processor board ID FGL1618119E
    6 Gigabit Ethernet interfaces
    2 terminal lines
    DRAM configuration is 64 bits wide with parity enabled.
    255K bytes of non-volatile configuration memory.
    250880K bytes of ATA System CompactFlash 0 (Read/Write)
    License Info:
    License UDI:
    Device#   PID                   SN
    *0        CISCO2921/K9          FGL1618119E
    Technology Package License Information for Module:'c2900'
    Technology    Technology-package           Technology-package
                  Current       Type           Next reboot
    ipbase        ipbasek9      Permanent      ipbasek9
    security      None          None           None
    uc            None          None           None
    data          None          None           None
    Configuration register is 0x2102
    R2921-8CPITR-1#

    Same issue here.
    I just waited a few minutes and the interface went down and back up, this time it was a L3 interface.
    My guess is that it was booting the switch module IOS, and it detected it until it was fully booted:
    Apr 11 05:26:52.091: %LINK-3-UPDOWN: Interface GigabitEthernet0/0, changed state to down
    Apr 11 05:26:52.091: %LINK-3-UPDOWN: Interface GigabitEthernet0/1, changed state to down
    Apr 11 05:26:52.091: %LINK-3-UPDOWN: Interface GigabitEthernet0/2, changed state to down
    Apr 11 05:26:52.091: %LINK-3-UPDOWN: Interface GigabitEthernet1/0, changed state to up
    Apr 11 05:26:52.795: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to down
    Apr 11 05:26:53.091: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to down
    Apr 11 05:26:53.091: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/1, changed state to down
    Apr 11 05:26:53.091: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/2, changed state to down
    Apr 11 05:26:53.091: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0, changed state to up
    Apr 11 05:27:46.895: %LINK-5-CHANGED: Interface Embedded-Service-Engine0/0, changed state to administratively down
    Apr 11 05:27:46.895: %LINK-5-CHANGED: Interface GigabitEthernet0/0, changed state to administratively down
    Apr 11 05:27:46.947: %LINK-5-CHANGED: Interface GigabitEthernet0/1, changed state to administratively down
    Apr 11 05:27:47.031: %LINK-5-CHANGED: Interface GigabitEthernet0/2, changed state to administratively down
    Apr 11 05:27:47.083: %LINK-5-CHANGED: Interface GigabitEthernet1/0, changed state to administratively down
    Apr 11 05:27:47.895: %LINEPROTO-5-UPDOWN: Line protocol on Interface Embedded-Service-Engine0/0, changed state to down
    Apr 11 05:27:48.083: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0, changed state to down
    Apr 11 05:27:49.283: %IP-5-WEBINST_KILL: Terminating DNS process
    Apr 11 05:27:52.499: %LINK-3-UPDOWN: Interface GigabitEthernet1/1, changed state to up
    Apr 11 05:27:53.087: %SYS-5-RESTART: System restarted --
    Cisco IOS Software, C2951 Software (C2951-UNIVERSALK9-M), Version 15.1(4)M5, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2012 by Cisco Systems, Inc.
    Compiled Tue 04-Sep-12 16:50 by prod_rel_team
    Apr 11 05:27:53.255: %SNMP-5-COLDSTART: SNMP agent on host Router is undergoing a cold start
    Apr 11 05:27:53.499: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/1, changed state to up
    Apr 11 05:28:21.435: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to up
    Apr 11 05:29:22.091: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/1, changed state to down
    Apr 11 05:29:22.095: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to down
    Router>en
    Router#sh ip int brief
    Interface                  IP-Address      OK? Method Status                Protocol
    Embedded-Service-Engine0/0 unassigned      YES unset  administratively down down
    GigabitEthernet0/0         unassigned      YES unset  administratively down down
    GigabitEthernet0/1         unassigned      YES unset  administratively down down
    GigabitEthernet0/2         unassigned      YES unset  administratively down down
    GigabitEthernet1/0         unassigned      YES unset  administratively down down
    GigabitEthernet1/1         unassigned      YES unset  up                    down
    Vlan1                      unassigned      YES unset  down                  down
    Router#
    Apr 11 05:29:46.106: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/1, changed state to upconf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    Router(config)#int g1/0
    Router(config-if)#ip add 1.1.1.1 255.255.255.0
    Router(config-if)#no shut
    Router(config-if)#
    Apr 11 05:30:09.046: %LINK-3-UPDOWN: Interface GigabitEthernet1/0, changed state to up
    Apr 11 05:30:10.046: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0, changed state to up
    Router(config-if)#end

Maybe you are looking for

  • After upgrading to lion vevo, youtube, and hbo no longer plays videos. I'm assuming this is some kind of plug-in issue. How can I resolve it?

    After upgrading to lion, vevo, youtube, and hbo no longer plays videos. I'm assuming this is some kind of plug-in issue. How can I resolve it?

  • MS Usb Mouse Scroll Wheel Problems

    Im having this problem on my laptop running arch.  I have the USB module loaded.  My XF86Config file looks as follows. Section "ServerLayout" Identifier "XFree86 Configured" Screen 0 "Screen0" 0 0 InputDevice "Mouse0" "CorePointer" InputDevice "Mouse

  • B1DE For VS 2008

    Hi, Am Currently working with VS 2008 to Create Add-ons.. sofar i worked on VS 2005 and created ARD through B1DESetup_2005_1.3_VS2005 without any problem.. now what version i have to use to create ARD.. B1DE only available for Frameworks upto 2.0 onl

  • How to group in a single code

    Dear all, I have this query <SELECT DISTINCT VC_EMP_CODE,VC_SAL_COMP_CODE AS EMP_SAL_VALUE FROM (SELECT A.*,B.VC_SAL_COMP_CODE FROM PERSDET A,DT_SAL_SLIP B WHERE A.VC_COMP_CODE=01 AND A.VC_EMP_CODE=774 AND A.VC_EMP_CODE=B.VC_EMP_CODE AND SAL_MONTH=06

  • HT1926 itunes installation rolls back in windows 7

    I had iTunes on my PC and I was using it until it failed to read my iphone, so I tried to reinstall it.  The installation of itunes 10.6 for 64 bit starts, but rolls back and aborts after the step labeled "copying files".  This happens again and agai