How to increase SPAN sessions on 6509 switch?

Hi, I am using WS-C6509-E Switch having Supervisor Engine 720 10GE (VS-S720-10G)with IOS sup-bootdisk:s72033-advipservicesk9_wan-mz.122-33.SXH3.bin
Please let me know -
1- what is the limit of SPAN (Ingress/Egress) session using same scenario?
2- How Can i increase SPAN (Ingress/Egress) sessions?
Jeet!!!

Please see attached document
Here is the link retrieved from:
http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/span.html#Local_SPAN,_RSPAN,_and_ERSPAN_Destinations
Summary:(PFC3)
Total sessions: 80
Local & Source 2
Local span egress only: 14
destination sessions RSPAN:64 ERSPAN 23
Router(config)# monitor session 1 type local
Router(config-mon-local)# source interface gigabitethernet 1/1 rx
Router(config-mon-local)# destination interface gigabitethernet 1/2

Similar Messages

  • How to increase scan rate of NI Switch SCXI 1130

    Hi,
    I have NI PCI 4070 DMM used with NI SCXI 1130 sitch module. I have connected 10 thermocouples to 1130 module. I am scanning the channels and reading the values in the program using niSwitch and niDMM VIs. I am using software trigger in the program. I have configured Software Trigger in niDMM configur trigger and niDMM configure Multipoint. I get the correct values when i scan using chi->com0, where i goes from 0 to 9. But the problem is that the rate of scanning is very slow.
    There is niSwitch Configure scan Rate.vi, here i have given scan delay as 0 second.
    It takes one second for one channel when i run the program. why is this , is this because i used software trigger for each channel scan? how to improve the scan rate. ?

    Sorry for the confusion, I started writing a post and got interrupted and came back to it too late.  You can disregard the last post and here is my final answer:
    I would actually recommend that you use synchronous scanning if you want to maximize the speed of your scan, rather than using software triggers.  If you use synchronous scanning, the DMM will generate a digital pulse (Measurement Complete) each time it completes a measurement, allowing the switch to advance to the next entry in the scan list the instant the DMM has completed its measurement.  The DMM will then take the next meausurement after a specified harware-timed interval.  This will be much more efficient than sending software triggers back and forth to time the scanning.  To set up your application using synchronous scanning, follow these steps:
    Open the LabVIEW shipping example "niSwitch DMM Switch Synchronous Scanning.vi", found in the NI Example Finder in the folder Hardware Input and Output » Modular Instruments » NI-SWITCH (Switches).
    Physically connect the Measurement Complete output trigger from the DMM to the trigger input of the switch.  How you will do this depends on what type of chassis you are using (PXI/SCXI combo chassis or separate chassis) and what switch terminal block you're using.  If you need assistance with this please provide more details about your hardware setup and I'd be happy to help out.  The following resource may be helpful here: KnowledgeBase 3V07KP2W: Switch/DMM Hardware Configurations.
    Select valid values for all other front panel controls and run the VI.
    I hope this is helpful.  Please let me know if I have misunderstood your application, or if you would like me to go into more detail on any specific part of the solution provided above. 

  • How to increase the Weblogic Session Threads

    Hi Everyone,
    We have been using replicated-if-clustered property of session-descriptor element of weblogic.xml and things were smooth and fine until our application didnt grow. Now there is a heavy traffic on the application and we want to increase the session replication thread count to more then 2 servers. Does anyone have any idea how to go about it? I dont see a way of defining how many servers the session should be replicated. Right now it does on the 2 servers which forms the cluster. Is there really any difference between replicated and replicated-if-clustered property?
    Thanks a Lot in Advance for answering my queries.
    Yogendra N Joshi.

    user13017505 wrote:
    Hi Everyone,
    We have been using replicated-if-clustered property of session-descriptor element of weblogic.xml and things were smooth and fine until our application didnt grow. Now there is a heavy traffic on the application and we want to increase the session replication thread count to more then 2 servers. Does anyone have any idea how to go about it? I dont see a way of defining how many servers the session should be replicated. Right now it does on the 2 servers which forms the cluster. Is there really any difference between replicated and replicated-if-clustered property?
    Thanks a Lot in Advance for answering my queries.
    Yogendra N Joshi.To start with persistent store/session replication options:
    •memory—Disables persistent session storage.
    •replicated—Same as memory, but session data is replicated across the clustered servers.(No Persistent store)
    •replicated_if_clustered—If the Web application is deployed on a clustered server, the in-effect persistent-store-type will be replicated. Otherwise, memory is the default.
    http://download.oracle.com/docs/cd/E12840_01/wls/docs103/webapp/weblogic_xml.html
    Regarding increasing traffic on the servers:
    If there is heavy traffic on the servers and both servers in a cluster are utilized fully, you can add more managed servers to the cluster and load balance the requests amongst them equally.
    The sessions will be replicated across all the servers in a cluster as you have session replication enabled already.
    But for increasing load/traffic we will have to analyze the capacity of the present setup and then add more servers to the cluster as required.
    Regards,
    Swapna

  • How to increase EAS console session time?

    Hi,
    I would like to know how to increase EAS console session time.

    Hi,
    Right click to Essbase cluster node->Edit->Properties->Security Tab->Auto Log off node->Inactive limits.
    Refer following link for more information:-
    http://docs.oracle.com/cd/E38445_01/doc.11122/eas_help/frameset.htm?dbsprpsc.html
    Hope this help.
    Regards,
    -SM

  • Can't create span session with NAM

    Hi,
    I have a 6500 with a module WS-SVC-NAM-2 installed (slot3) and I have recently also installed an IDSM module (slot2).
    I am trying to configure a SPAN session via the web interface of the NAM:
    menu setup-> Data sources-> create
    but on the next screen, I choose SPAN type: switchport,  but doesn't appears the modules installed in 6500 (in menu Switch module) so I can't choose either the source port. Besides doesn't appears the destination ports: DATAPORT1 and DATAPORT2.
    I restarted the module but still not working, may be an incompatibility between NAM and IDSM?
    I also tried setting the CLI, but this configuration doesn't appear in the NAM web interface:
    switch (config) # monitor session 2 source interface both giga1/8/43
    switch (config) # monitor session 2 destination-switch 1 analysis module 3 data-port 1
    any idea?
    thanks.

    Thank you very much! this bug explains the problem I have.
    I will try to do the upgrade of the NAM.
    How can I tell if the NAM is running in the application image or not?
    thanks in advance!

  • TCP reset packet issue on Cisco 6509 switch

    Hi,
    We are connecting a malware prevention appliance to a SPAN port on cisco switch 6509 which uses IOS firmware.
    When the Malware appliance send TCP RST packet to the switch, it does not accept it.
    Please help with what additional config to be done on the switch or the span sport so that the packet is received by the switch.

    Hello, Wasim.
    No sure if 6500 supports the feature, but 3750 does:
    monitor session destination int f0/1 ingress vlan 100
    This last part allows SPAN port to send traffic into VLAN 100 (more details here -
    http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750/software/release/12-2_52_se/configuration/guide/3750scg/swspan.html#wp1260596)

  • How to increase the battery life of your N series ...

    What I am about to post here is valid for any 3G phone or device regardless of model but it is particularly focused towards the N series devices and their power hogging features.
    Your battery life is dependant on many many things. How often you take calls on the device, the condition of your battery, the features you use on the device and so on and on. Therefore it is impossible to say that by following the information in this post you will get x amount of days battery life, but it will get you more time out of the battery than you otherwise would have got.
    So with that out the way, if your looking to increase your battery life then follow these tips and your battery should start looking a lot healthier.
    First of all lets start with THE big one. The one that is going to save you the most juice. Switching 3G off.
    Yep, you heard me right. Just by switching the 3G capability of your phone off you will add hours and hours to your battery life. How is this so? Allow me to explain...
    Due to the rather poor delivery of 3G in the UK by the network operators, it is rare for any 3G phone to maintain a constant 3G signal. Instead you will find that the phone constantly flips between 3G and GSM mode (Keep an eye on your signal one day). Even those of you on Vodafone who probably have the best 3G network coverage will find this is the case.
    Unfortunately, this constant flipping between the two modes sucks power from the battery like a vampire as it alters its reception state for the different modes and the constant flipping is..well...causing it do this constantly! It can sometimes even make your phone unavailable for calls for very brief periods as it trips from GSM to 3G and vice versa.
    If you need to use 3G for video calls or whatever then I'm afraid your just going to have to live with this but if you don't (And lets face it few of us do) then you can switch 3G off and increase your battery life considerably.
    To do this, go into the "Settings" application (Found in the menu somewhere, by default Nokia normally stick it in "Tools"), and then to the "Phone" tab. In there you will see an option that says "Network mode" and you have a choice of "GSM" or "Dual Mode" (I.e. UMTS and GSM). Set it to GSM and your phone will restart. Once it restarts it will be working in GSM with GPRS speeds only but really for most purposes this is fine.
    You have now just extended your battery capability considerably. You can further extend it by going to the "Connection" tab, going into "Packet data" and changing it to "When needed" so it is not constantly checking for a data connection.
    The second big change you can make is to turn your phones wifi scanning capability off. The last time I looked not all Nokia's phones that have wifi capability can have their wifi cards switched off entirely but if you can, turn it off except for when you need to use it. Wifi is a power hog.
    The next big change you can make is to lower the screen brightness settings on your phone. The less bright your screen is the less power is being used to light it up. Nokia by default leave the screen brightness at something like 50%. Lowering this a bit more will conserve more juice. Before you do this though please consider the fact that lowering the brightness setting will have a big impact on your ability to see the screen clearly in sunny conditions although you will be fine in the dark as you can't lower the brightness that far.
    To lower the brightness, go to the settings tool in your phone and into the display option (Hidden in a subcategory called "Personalisation" on the N95). It won't hurt to set the power saving time out to 1 minute and the backlight time out to 10 seconds while your here (Although these are the Nokia default so they should already be set to this).
    Finally in regards to the screen, although they may look pretty, animated screensavers use more battery power than the standard blank screen with time and date so avoid them if you can.
    It also helps to keep Bluetooth switched off until you need it although the power savings are minimal in comparison to the other changes but every little milliamp counts!
    Using the above methods I generally get about 3 to 4 days with about 3 hours talktime on my N95 without using Bluetooth, GPS or anything like that (I might be able to get more but so far I have not paid attention to the battery state before I put it on charge). If I am on a long train journey I can get about 4 hours worth of full screen video and about 2 hours talktime over the period of about 24 hours before it needs a recharge. As I said at the start of the post your mileage will vary greatly depending on how you use your device.
    Hope this helps.
    Useful links: Phone firmware update | Nokia support site

    02-May-200701:14 PM
    bixby wrote:
    no keffa it is a cop out from nokia
    its not unfai as its a premium device with a premium price
    the n95 battery is atrocious
    dont change the post content as the title is 'How to increase the battery life of your N series device'
    your talking about nokia phones specifically
    the networks are not to blame
    they do not make the handsets : Nokia do !!!!!!!!!!
    I'm going to choose my words carefully here...
    I would never deny the battery on the N95 is not really up to the job of powering the N95 with its power hungry features. To put the same battery into a phone that has WiFi, GPS and a large 320x240 screen, the same one that goes into the E65 which has comparatively nothing compared to it is a bit pants.
    However at no point was I criticising them for the band hopping problem. I labelled the post as how to increase the battery life of your N series device because this is a board for the N series devices. It was a simple choice of wording and not intended to be cutting in any way and I did make a remark that the details would be true of any 3G device at the top of the post.
    What I was trying to point out in my second post is that the constant band hopping the phone is being forced to do that is draining its battery so much more quicker than it would if it had a constant signal of one kind or another isn't quite Nokia's fault.
    They build it to conform to a laid out specification for 3G. However if the network operators cannot be bothered to roll out their 3G infrastructure adequately enough that the phone can find and remain locked onto a 3G signal that is usable then what are Nokia to do other than offer you the capability to turn 3G off until you need it (Although note to Nokia: That **bleep** reboot the phone does when you do this is entirely unneeded and you know it).
    Blaming Nokia for this would be like blaming the manufacturer of your radio for failing to pick up radio because the radio station does not have any transmitters within range of your radio's receiver.
    Finally...this band hopping is exhibited by all 3G phones built by Samsung, Nokia, Sony Ericsson, etc, from their most budget 3G model to their priciest piece and is the reason that all phones with 3G capabilities have batteries that do not last for any respectable length of time because these phones are also having to band hop between 3G and GSM.
    Finally the proof is in the pudding. Turn 3G off for a few days. See your battery improve. Then (Although admittedly this will be harder to do...mcuh harder) find an area where you get a fairly decent 3G signal constantly. Again, see your battery improve. Try it with a different 3G phone...different manufacturer even. The same will be true.
    So I stand by my comment, the network operators and their woeful 3G rollout are the villains costing you a fair chunk of your battery and Nokia cannot be expected to mitigate this....but a better battery would be nice all the same...
    Useful links: Phone firmware update | Nokia support site

  • How to increase No. of Connections in Oracle DB?

    Hi,
    As my team using more no. of connections, I need to increase the number of connections.
    Kindly guide me to check the current number of connections and how to change / increase that?
    As I don't have knowledge on this, I am looking the detailed input on this.
    Kindly guide me, How to check the no. of connections in DB and how to increase that?
    Thanks in advance,
    Orahar.

    Orahar wrote:
    As my team using more no. of connections, I need to increase the number of connections.For what type of sessions? That determines whether dedicated or shared server sessions on the Oracle server can be used. Shared server scales a lot better than dedicated servers, but requires specific factors to be taken into consideration (e.g. the move of session UGA from the PGA to the SGA, dispatchers required, etc).
    For what server o/s? Windows deal differently with dedicated and shared servers (threads) as Unix/Linux (processes) do.
    And why the increase in connections required by your team? Are they using the Oracle server architecture correctly from the client side?
    Most 64bit Oracle severs can easily support 1000's of connections (shared server) - but the number of connections are secondary to how the clients are using their Oracle sessions.

  • How can I insert a code to switch between channels?

    I’ve got a HP4263A LCR meter which is being used with an ER-18 device to get multiple channel data acquisition, when I go to getting started to trigger the device, but this VI do not have an icon to change the channel how can I insert a code to switch between channels?

    I am just trying to use the drivers developed by NI for this device, but I don't know how to work on them to obtain data from three points, or three channels which I am using from an ER-16 device. So all what I have is the driver VI for the HP4263A.the only VI I can use is getting started, because whe I try to run any other one, this message appears:
    Error -1073807346 occurred at VISA Write in HP4263A Self-Test.vi.
    Possible reasons:
    VISA: (Hex 0xBFFF000E) The given session or object reference is invalid.
    your help would be very helpful
    thanks

  • How to increase the size of sort_area_size

    How to increase the size of sort_area_size and what size should be according to the PROD database
    Thanks

    user10869960 wrote:
    Hi,
    Many Thanks Charles
    Oracle does not recommend using the SORT_AREA_SIZE parameter unless the instance is configured with the shared server option. Oracle recommends that you enable automatic sizing of SQL working areas by setting PGA_AGGREGATE_TARGET instead. SORT_AREA_SIZE is retained for backward compatibility."
    --How can i know the instance is configured with the shared server option or not?This might be a tough question to answer. A shared server configuration may be enabled, but the clients may still connect using dedicated sessions, in which case PGA_AGGREGATE_TARGET would still apply.
    From
    http://download.oracle.com/docs/cd/B19306_01/server.102/b14237/dynviews_2088.htm
    V$SESSION includes a column named SERVER which will contain one of the following for each of the sessions: DEDICATED, SHARED, PSEUDO, or NONE. As a quick check, you could query V$SESSION to see if any sessions are connected using a shared server connection.
    From:
    http://download.oracle.com/docs/cd/B19306_01/server.102/b14231/manproc.htm
    There are several parameters which are used to configure shared server support, as well as several views to monitor shared server.
    As Robert mentioned, when the WORKAREA_SIZE_POLICY is set to AUTO, the SORT_AREA_SIZE setting is not used, unless a shared server configuration is in use.
    --What default value is WORKAREA_SIZE_POLICY and SORT_AREA_SIZE ?From:
    http://download.oracle.com/docs/cd/B19306_01/server.102/b14237/initparams157.htm
    "Setting PGA_AGGREGATE_TARGET to a nonzero value has the effect of automatically setting the WORKAREA_SIZE_POLICY parameter to AUTO. This means that SQL working areas used by memory-intensive SQL operators (such as sort, group-by, hash-join, bitmap merge, and bitmap create) will be automatically sized. A nonzero value for this parameter is the default since, unless you specify otherwise, Oracle sets it to 20% of the SGA or 10 MB, whichever is greater."
    Actually I am facing performence issue since long time till now i did not get the solution even i have raised SRs but i could not.When the issue occur system seems hang.what i monitored whenever hdisk0 and hdisk1 use 100% the issue occur.
    Regards,
    SajidWhen you say that you have had a performance issue for a long time, is it a performance problem faced by a single SQL statement, a single user, a single application, or everything on the server? If you are able to identify a single user, or SQL statement that is experiencing poor performance, I suggest starting with a 10046 trace at level 8 (wait events) or level 12 (wait events and bind variables) to determine why the execution appears to be slow. If you have not yet determined a specific user or SQL statement that is experiencing performance problems, you might start with either a Statspack Report or an AWR Report (AWR requires a separate license).
    If you believe that temp tablespace usage may be a contributing factor to the performance problem, you may want to periodically run this query, which will indicate currently in use temp tablespace usage:
    {code}
    SELECT /*+ ORDERED */
    TU.USERNAME,
    S.SID,
    S.SERIAL#,
    S.SQL_ID,
    S.SQL_ADDRESS,
    TU.SEGTYPE,
    TU.EXTENTS,
    TU.BLOCKS,
    SQL.SQL_TEXT
    FROM
    V$TEMPSEG_USAGE TU,
    V$SESSION S,
    V$SQL SQL
    WHERE
    TU.SESSION_ADDR=S.SADDR
    AND TU.SESSION_NUM=S.SERIAL#
    AND S.SQL_ID=SQL.SQL_ID
    AND S.SQL_ADDRESS=SQL.ADDRESS;
    {code}
    The SID and SERIAL# returned by the above could then be used to enable a 10046 trace for a session. The SQL_ID (and CHILD_NUMBER from V$SESSION in recent releases) could be used with DBMS_XPLAN.DISPLAY_CURSOR to return the execution plan for the SQL statement.
    You could also take a look in V$SQL_WORKAREA_ACTIVE to determine which, if any, SQL statement are resulting in single-pass, or multi-pass executions, which both access the temp tablespace.
    Charles Hooper
    IT Manager/Oracle DBA
    K&M Machine-Fabricating, Inc.

  • How to Increase the retreving size of instances using PAPI filters.

    Hi,
    How to Increase the retreving size of instances using PAPI filters.
    In my engine database instance size exceeds 2500 then we are getting following exception.
    If we login in to user workspace able to see the instances but while trying to retrieve from PAPI getting below exception and showing the user's inbox aize as 0.
    In Process Admin console we set all the required parameters.
    Still I m getting the same problem.
    Can you please lgive mev the solution.
    <Mar 23, 2010 8:58:24 PM SGT> <Warning> <RMI> <BEA-080003> <RuntimeException thrown by rmi server: fuego.ejbengine.EJBProcessControl_1zamnl_EOImpl.getInstancesByFilter(Lfuego.papi.impl.j2ee.EJBSecureEngineInfo;Ljava.lang.String;Lfuego.papi.Filter;)
    java.lang.ClassCastException: cannot assign instance of java.util.HashSet to field fuego.view.FilterImpl.attributes of type java.util.List in instance of fuego.view.FilterImpl.
    java.lang.ClassCastException: cannot assign instance of java.util.HashSet to field fuego.view.FilterImpl.attributes of type java.util.List in instance of fuego.view.FilterImpl
         at java.io.ObjectStreamClass$FieldReflector.setObjFieldValues(ObjectStreamClass.java:2032)
         at java.io.ObjectStreamClass.setObjFieldValues(ObjectStreamClass.java:1212)
         at java.io.ObjectInputStream.defaultReadFields(ObjectInputStream.java:1953)
         at java.io.ObjectInputStream.readSerialData(ObjectInputStream.java:1871)
         at java.io.ObjectInputStream.readOrdinaryObject(ObjectInputStream.java:1753)
    Regards,
    Bharath.
    Edited by: bg57295 on Mar 24, 2010 6:45 PM

    Hi Bharath,
    Believe me, you have an incompatibility between different build#.
    PAPI has an instance cache. When certain process has more instances than the maximum specified, the cache is switch to status OPEN. That means, that PAPI will not be able to resolve some instance queries using the information in the cache. When that occurs, PAPI forward all those queries to the engine.
    The incompatibility introduced is in the communication between PAPI and Engine. So, you only get the exception when you have more instances than the maximum cache size.
    Regards,
    Ariel

  • Catalyst 6509 switch

    I have a problem with one of our catalyst 6509 switches. We had power problem and when I tried to power the switch on after the power was restored it take me to the rommon.
    rommon>
    I urgently need answers to three questions and would therefore appreciate it if anyone can help me out.
    1. What is the cause of the switch not booting from flash but going to rommon?
    2.How do I get into the switch and
    3.How do I reset the switch to boot from flash and not going to the rommon
    Hope a savior comes to my aid

    Probably went into rommon due to incorrect or missing boot statement . You must already be in the switch if you know it is in rommon . If this is a native IOS box then just issue the "boot bootflash: " command and this should boot the box . Once booted up make sure the boot statement is correct . "boot system flash sup-bootflash: .

  • How to increase the size (Length and width)  of check box

    Hi All,
    I have to increase the size of ( width and length) of check box, I have revised to check box topic in dev guide but didnt find any clue, i have also tried to use CCStyle class but that is also not working, I would appreciate if some can help me out on this. Thanks in advance , let me know if any clarification required.
    Thanks
    Pratap

    Hi Pratap ,
    I honestly don't know how to increase the size
    But i am giving you an alternate solution : we can create two Images with check box type 1 ) with checked
    2 ) with unchecked . ( you can create image of any size ) and get them displayed on OAF screen dynamically using switcher case .
    Dynamically displaying image will give the illusion of check box being checked and unchecked .
    keep this image moved to following media directory
    eg : /oraapp/mfgtestcomn/java/oracle/apps/media .
    Implement the switcher case , add the fire action to this Image Column , create a transient attribute and attach to this
    column . Depending on the value returned by transient attribute display the image on the column .
    Let me know if its not clear .
    Keerthi

  • A Server Killing the CPU of a 6509 Switch

    HI all,
    Thanks for reading this in the first place.
    We are a hosting provider with over 600 dedicated servers.
    We have 2x6509 Switches in the Core Network, and every single server has statically routed subnets to Interfaces Vlan. (SVI's)
    - All ports on the switch have an ACL configured to allow traffic from ONLY certain subnets and to deny other types of packets.
    - All ports on the switch are configured with port-security, only allowing 100 MAC Addresses per port. This is because we have clients hosting VPS's.
    - The port-security mode is shutdown, and it reactivates after 60 seconds.
    THIS IS THE ACL CONFIGURED ON EVERY PORT ON THE SWITCH.
    Extended IP access list INTERNALDEFENSE
        10 deny tcp any any fragments
        11 deny gre any any
        20 deny udp any any fragments
        30 deny icmp any any fragments
        40 deny ip any any fragments
        50 deny icmp any any redirect log
        60 deny icmp any any mask-request log
        70 permit ip 46.19.136.64 0.0.0.63 any
        71 permit ip 179.43.0.0 0.0.255.255 any (209 matches)
        80 permit ip 46.19.136.128 0.0.0.127 any
        90 permit ip 46.19.137.0 0.0.0.255 any (48501 matches)
        100 permit ip 46.19.138.0 0.0.0.255 any (5654 matches)
        101 permit ip 185.12.44.0 0.0.3.255 any (39831 matches)
        102 permit ip 154.57.64.0 0.0.15.255 any (21040 matches)
        110 permit ip 46.19.139.0 0.0.0.255 any (278 matches)
        120 permit ip 46.19.140.0 0.0.0.255 any (11451 matches)
        130 permit ip 46.19.141.0 0.0.0.255 any (3123363 matches)
        140 permit ip 46.19.143.0 0.0.0.255 any
        150 permit ip 31.7.56.0 0.0.7.255 any (10365564 matches)
        160 permit ip 81.17.16.0 0.0.15.255 any (2395368 matches)
        170 permit ip 31.44.189.0 0.0.0.255 any
        180 permit ip 141.255.160.128 0.0.0.127 any
        190 permit ip 141.255.161.0 0.0.0.255 any (295833 matches)
        200 permit ip 141.255.162.0 0.0.0.255 any
        210 permit ip 141.255.163.0 0.0.0.255 any (1009 matches)
        220 permit ip 141.255.164.0 0.0.0.255 any (264641 matches)
        230 permit ip 141.255.165.0 0.0.0.255 any
        240 permit ip 141.255.166.0 0.0.0.255 any
        250 permit ip 141.255.167.0 0.0.0.255 any
        260 deny ip any any (296 matches)
    THIS IS THE CONFIGURATION OF THE PORT ITSELF.
    interface GigabitEthernet0/1
    switchport access vlan 101
    switchport mode access
    switchport nonegotiate
    switchport port-security maximum 100
    switchport port-security
    switchport port-security mac-address sticky
    ip access-group INTERNALDEFENSE in
    shutdown
    speed 1000
    duplex full
    no cdp enable
    end
    Today we had a MAJOR issue, where a single server was able to cause 100% of CPU utilization in one of the 6509 Switches.
    I have ran the SHOW PROC CPU command DURING the event, and AFTER the event.
    I realized this was the server issue, because of an event in the monitoring system, BUT i cant tell why, and HOW this server is able to do this.
    I have posted the details of the BEFORE AND AFTER command results so if someone out there has experience with this, can probably provide some insight on this.
    Thanks in advance.
    Ezequiel Pineda

    HI all,
    Thanks for reading this in the first place.
    We are a hosting provider with over 600 dedicated servers.
    We have 2x6509 Switches in the Core Network, and every single server has statically routed subnets to Interfaces Vlan. (SVI's)
    - All ports on the switch have an ACL configured to allow traffic from ONLY certain subnets and to deny other types of packets.
    - All ports on the switch are configured with port-security, only allowing 100 MAC Addresses per port. This is because we have clients hosting VPS's.
    - The port-security mode is shutdown, and it reactivates after 60 seconds.
    THIS IS THE ACL CONFIGURED ON EVERY PORT ON THE SWITCH.
    Extended IP access list INTERNALDEFENSE
        10 deny tcp any any fragments
        11 deny gre any any
        20 deny udp any any fragments
        30 deny icmp any any fragments
        40 deny ip any any fragments
        50 deny icmp any any redirect log
        60 deny icmp any any mask-request log
        70 permit ip 46.19.136.64 0.0.0.63 any
        71 permit ip 179.43.0.0 0.0.255.255 any (209 matches)
        80 permit ip 46.19.136.128 0.0.0.127 any
        90 permit ip 46.19.137.0 0.0.0.255 any (48501 matches)
        100 permit ip 46.19.138.0 0.0.0.255 any (5654 matches)
        101 permit ip 185.12.44.0 0.0.3.255 any (39831 matches)
        102 permit ip 154.57.64.0 0.0.15.255 any (21040 matches)
        110 permit ip 46.19.139.0 0.0.0.255 any (278 matches)
        120 permit ip 46.19.140.0 0.0.0.255 any (11451 matches)
        130 permit ip 46.19.141.0 0.0.0.255 any (3123363 matches)
        140 permit ip 46.19.143.0 0.0.0.255 any
        150 permit ip 31.7.56.0 0.0.7.255 any (10365564 matches)
        160 permit ip 81.17.16.0 0.0.15.255 any (2395368 matches)
        170 permit ip 31.44.189.0 0.0.0.255 any
        180 permit ip 141.255.160.128 0.0.0.127 any
        190 permit ip 141.255.161.0 0.0.0.255 any (295833 matches)
        200 permit ip 141.255.162.0 0.0.0.255 any
        210 permit ip 141.255.163.0 0.0.0.255 any (1009 matches)
        220 permit ip 141.255.164.0 0.0.0.255 any (264641 matches)
        230 permit ip 141.255.165.0 0.0.0.255 any
        240 permit ip 141.255.166.0 0.0.0.255 any
        250 permit ip 141.255.167.0 0.0.0.255 any
        260 deny ip any any (296 matches)
    THIS IS THE CONFIGURATION OF THE PORT ITSELF.
    interface GigabitEthernet0/1
    switchport access vlan 101
    switchport mode access
    switchport nonegotiate
    switchport port-security maximum 100
    switchport port-security
    switchport port-security mac-address sticky
    ip access-group INTERNALDEFENSE in
    shutdown
    speed 1000
    duplex full
    no cdp enable
    end
    Today we had a MAJOR issue, where a single server was able to cause 100% of CPU utilization in one of the 6509 Switches.
    I have ran the SHOW PROC CPU command DURING the event, and AFTER the event.
    I realized this was the server issue, because of an event in the monitoring system, BUT i cant tell why, and HOW this server is able to do this.
    I have posted the details of the BEFORE AND AFTER command results so if someone out there has experience with this, can probably provide some insight on this.
    Thanks in advance.
    Ezequiel Pineda

  • Does 6509 switch support CDP bypass feature when interface configured with IEEE 802.1X?

     hi, guys
            we are deploying CISCO video endpoints (SX 20) for out customers, as the access switch is 6509 which version is 12.2(33)SXJ5
    following is the configuration on the interface, but the endpoints can not pass through the authentication, and also it can not get  IP address
    from DHCP server , so just want to know whether if the 6509 switch support CDP BYPASS feature?
    interface GigabitEthernet x/xx
     switchport
     switchport access vlan 400
     switchport mode access
     switchport voice vlan 409
     authentication host-mode multi-domain
     authentication port-control auto
     authentication timer reauthenticate 65535
     authentication timer inactivity 120
     authentication violation restrict
     dot1x pae authenticator
     dot1x timeout tx-period 5
     dot1x timeout supp-timeout 10
     spanning-tree portfast edge

    What image are you running now ? I am facing the same problem in 8.4(1) workround : upgrade to 8.4(2)GLX.

Maybe you are looking for

  • I have a mac book osx 10.5.8 and would like to upgrade the hard drive any recommendations?

    can i upgrade hard drive on my mac book osx 10.5.8?

  • How to show TITLE of column?

    not sure on the numbers terminology but can anyone help me find where i turn on the ability to see the TITLE of the columns when i am not looking at an area that includes these? right now if i scroll way down i can see the ALPHABET but i need to see

  • Modify F4-search in CSPB - BOM browser - additional field material text

    Dear Experts, we want to modify the F4-search in CSPB - BOM browser. The displayed control on the right side of the screen shows an ALV (?) based on the table PRST. In order to make it easier to find the correct item  the material short text should d

  • Newly authorised users unable to view host info via console.

    I've recently added a number of users to the /var/opt/SUNWsymon/cfg/esusers file on the SunMC server and ensured that they have groups acess to esadm and esdomadm. Unfortunately, when they double click on a server icon in the SunMC console, the windo

  • VA01 User exit

    Hi I have requirement to load values from a certain custom table into Sales Order Header & item data additional screens when I create the order by reference to quotation... So for this reason I need to find a User Exit or BADI which will trigger befo