Microsoft NLB and Cisco 4500 VSS

Hi,
I have a pair of Cisco 4507 switches in VSS mode. An server (10.4.1.166)  using Microsoft NLB MAC address (03bf.0a04.01a6) is connected to VSS Node 1 on port Gi1/6/43. The following is configured on the switch.
arp 10.4.1.166 03bf.0a04.01a6 ARPA
mac address-table static 03bf.0a04.01a6 vlan 31 interface Gi1/6/43
The second command appears differently in running-config but looks good in mac-address-table:
# show running-config | inc mac address
mac address-table static 03bf.0a04.01a6 vlan 31 interface Gi6/43
# show mac address static | inc 01a6
  31      03bf.0a04.01a6   static Gi1/6/43
Now, from a PC I can ping the VIP address 10.4.1.166 when connected to VSS Node 1 or any other switch connecting to VSS Node1. If the PC attachment is to VSS Node 2 directly or indirectly, then the ping times out. Doing the same for all the rest of servers not using Microsoft NLB  but connected to Node 1 only, is successful from anywhere.
Why is the traffic not traversing the the VSL link i.e. PC -> VSS Node 2 -> VSL -> VSS Node1 -> Server.
Thanks,
Rick.

Thanks Reza, Please find the output of the commands below. The VSS switch looks to be good and working for all other services.
#show switch virtualExecuting the command on VSS member switch role = VSS Active, id = 1Switch mode                  : Virtual SwitchVirtual switch domain number : 1Local switch number          : 1Local switch operational role: Virtual Switch ActivePeer switch number           : 2Peer switch operational role : Virtual Switch StandbyExecuting the command on VSS member switch role = VSS Standby, id = 2Switch mode                  : Virtual SwitchVirtual switch domain number : 1Local switch number          : 2Local switch operational role: Virtual Switch StandbyPeer switch number           : 1Peer switch operational role : Virtual Switch Active# show switch virtual redundancyExecuting the command on VSS member switch role = VSS Active, id = 1                  My Switch Id = 1                Peer Switch Id = 2        Last switchover reason = none    Configured Redundancy Mode = Stateful Switchover     Operating Redundancy Mode = Stateful SwitchoverSwitch 1 Slot 3 Processor Information :-----------------------------------------------        Current Software state = ACTIVE                 Image Version = Cisco IOS Software, Catalyst 4500 L3 Switch Software (cat4500e-UNIVERSALK9-M), Version 15.1(2)SG, RELEASE SOFTWARE (fc3)Technical Support: http://www.cisco.com/techsupportCopyright (c) 1986-2012 by Cisco Systems, Inc.Compiled Wed 05-Dec-12 04:38 by prod_rel_team                          BOOT = bootflash:cat4500e-universalk9.SPA.03.04.00.SG.151-2.SG.bin,1;        Configuration register = 0x102                  Fabric State = ACTIVE           Control Plane State = ACTIVESwitch 2 Slot 3 Processor Information :-----------------------------------------------        Current Software state = STANDBY HOT (switchover target)                 Image Version = Cisco IOS Software, Catalyst 4500 L3 Switch Software (cat4500e-UNIVERSALK9-M), Version 15.1(2)SG, RELEASE SOFTWARE (fc3)Technical Support: http://www.cisco.com/techsupportCopyright (c) 1986-2012 by Cisco Systems, Inc.Compiled Wed 05-Dec-12 04:38 by pro                          BOOT = bootflash:cat4500e-universalk9.SPA.03.04.00.SG.151-2.SG.bin,1;        Configuration register = 0x102                  Fabric State = ACTIVE           Control Plane State = STANDBYExecuting the command on VSS member switch role = VSS Standby, id = 2show virtual switch redundancy is not supported on the standbySKR_4507_01#show switch virtual link port-channelExecuting the command on VSS member switch role = VSS Active, id = 1Flags:  D - down        P - bundled in port-channel        I - stand-alone s - suspended        H - Hot-standby (LACP only)        R - Layer3      S - Layer2        U - in use      N - not in use, no aggregation        f - failed to allocate aggregator        M - not in use, no aggregation due to minimum links not met        m - not in use, port not aggregated due to minimum links not met        u - unsuitable for bundling        d - default port        w - waiting to be aggregatedGroup  Port-channel  Protocol    Ports------+-------------+-----------+-------------------15     Po15(SU)         -        Te1/3/1(P)  Te1/4/1(P)16     Po16(SU)         -        Te2/3/1(P)  Te2/4/1(P)Executing the command on VSS member switch role = VSS Standby, id = 2Flags:  D - down        P - bundled in port-channel        I - stand-alone s - suspended        H - Hot-standby (LACP only)        R - Layer3      S - Layer2        U - in use      N - not in use, no aggregation        f - failed to allocate aggregator        M - not in use, no aggregation due to minimum links not met        m - not in use, port not aggregated due to minimum links not met        u - unsuitable for bundling        d - default port        w - waiting to be aggregatedGroup  Port-channel  Protocol    Ports------+-------------+-----------+-------------------15     Po15(SU)         -        Te1/3/1(P)  Te1/4/1(P)16     Po16(SU)         -        Te2/3/1(P)  Te2/4/1(P)#show run int gi1/6/43interface GigabitEthernet1/6/43 switchport access vlan 31 switchport mode access spanning-tree portfast spanning-tree guard root
Regards,
Rick.

Similar Messages

  • Cisco 4500 VSS link issue

    Hi,
    We are having Cisco 4500 switches running in VSS mode. Currently VSS links are connected on ports with capacity of 1 GB & we wanted to replace those ports with new 10 GB DAC cable.
    We manage this switch remotely via SSH. If we disable VSS link or broke the VSS between 2 switches , is it still possible to access  switches over SSH ?
    or we need someone near to device for Console session ?
    Thanks in advance.

    It depends on how the setup is.
    If you have the devices access through the  console server then you should be able to access the box.
    Reason: When you bring down the VSL link the dua active condition triggered. 
    Switch 1 detects that switch 2 is now also active triggering dual active 
    condition thus switch 1 brings down all the local interfaces to avoid network 
    instability. Until VSL link restoration occurs, switch 1 is isolated from the 
    network; 
     Once the VSL link comes up, the role negotiation determines that switch 1 
    needs to come up in STAND_BY mode hence it reboots itself; finally, all 
    interface on switch 1 are brought on line and switch 1 assumes STAND_BY role.
    HTH

  • I am an engineer, Microsoft Certified and Cisco Certified Professional

    Hi, I have recently updated my Xperia Z to Lolipop, the user interface is stunning, but unfortunately, the battery drains too fast, the XLoud is removed, the sound of the internal speaker has gone too low, the most annoying thing is that the Quality of the Music App, (Walkman) has degraded to an unacceptable degree, I have Always used Sony products, be it TV or a mobile or Headphones or Camera's.. The Quality of the sound was amazing with the Walkman app and the early versions of kitkat (the time when I bought the phone), I wonder why Sony Upgraded the app to Music, it just degraded the sound Quality. With the Kitkat version of Android, even after the Upgrade to Music app, sound quality was yet acceptable, but now the sound Quality went from bad to worse. Now the Sound Quality of HTC and Samsung Devices are way better and the Old Sony Mp3 player which i have NWZ-B142F has way better sound Quality than what I currently have on my Xperia Z.. Didn't expect this from Sony. I will literally stop Sony Devices if this is not fixed and Post this everywhere (all Social Networking Sites) so that people who have high expectations from Sony do not have any more expectations. I was about to buy Xperia Z3+ but looking at the Quality going down with each upgrade, I don't think I will continue with Sony anymore.
    Used to be a proud Sony User, now I am not Owner of 4 Different Sony Ericsson model phones, then Owner of Tipo Dual, Xperia J, Xperia Z, and many more models my family uses, and many more Models of Sony Xperia Devices given as gift to family and friends. Will this issue ever be fixed? Or is that Sony Will Continue to do as Sony wishes? Need and honest answer!! I am ready to be patient but if my expectations not met, I will have to say Bye Bye Sony!

    True, none should threaten anyone, neither am I doing so, if you feel that way, I am sorry, but that still does not solve or answer none of my questions or Queries or concerns.. I can use my right! So True! So Sony does not even say thanks for being a good loyal customer since so many years nor does Sony representatives here appreciate or solve anything.. Amazed! I see you love Quoting; here's some of my favouites: “Service, in short, is not what you do, but who you are. It is a way of living that you need to bring to everything you do, if you are to bring it to your customer interactions.” ~ Betsy Sanders “Every contact we have with a customer influences whether or not they’ll come back. We have to be great every time or we’ll lose them.” ~ Kevin Stirtz  “Good customer service begins at the top. If your senior people don’t get it, even the strongest links further down the line can become compromised.” “The customer’s perception is your reality.” ~ Kate Zabriskie  “The longer you wait, the harder it is to produce outstanding customer service.”  “Being on par in terms of price and quality only gets you into the game. Service wins the game.” ~ Tony Alessandra  “The more you engage with customers the clearer things become and the easier it is to determine what you should be doing.”  ~ John Russell   

  • So what is ActiveSync and Cisco VPN

    Sorry if I sound like an idiot here, but I'm not really up on all the technology. What I am wondering is what is this Microsoft ActiveSync and Cisco IPsec VPN that was talked about in today's press conferance?
    Also, I am kind of fuzzy about what the difference between this "push email" and what us iPhone owners have?
    Finially, I am more than likely younger than most of the posters here, and I was hoping for an MMS and AIM app. How are those looking?
    Thank you for your help, and I apologize for my ignorance

    ActiveSync is the Microsoft protocal which allows Over the Air (OTA) syncing with an exchange server. Its a vital program for getting businesses on board with the iPhone
    Cisco VPN is a very popular Virtual Private Network protocol. Again, vital for getting the iPhone in the hands of business professionals.
    Push email is an email system that sends the email to the device the moment it is received, rather than waiting for the device to poll the server to check for new messages.
    Aim is looking very good, since they demoed it at the Roadmap event. MMS is still on the fence since we won't know if the developers will have the ability to tap into that part of the OS until they get the change to really play around with the SDK.

  • Cisco 4500-X Stacking or VSS

    Dear All, 
    We are planning to purchase 2 Cisco 4500-X Series switches for "Enterprise Campus Collapsed Distribution and Core Architecture" design. Could you please answer me below questions:
    1. Which is good stacking or VSS? 
    2. What are the points I should remember before implementing stacking?
    3. Do we have to purchase stacking cables? 
    4. Do we need twinax cables to Interconnect each switch or stacking is enough?
    5. The plan is to implement High availability in a way if one switch fails another should take over automatically. So which solution will be good here VSS or stacking? 

    Disclaimer
    The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
    Liability Disclaimer
    In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
    Posting
    Yes and no. When you configure a VSS pair, the pair appears as one device.  Whatever configuration changes are made, they're saved to both physical switches.
    With VSS there's primary and secondary, but that deals with which switch actively manages the pair.  Both switches actively forward traffic.
    I'm not 100% sure about what happens if the primary switch fails, then you make configuration changes, and then the primary switch comes back on-line.  However, I would expect the switch coming back on-line would get the latest configuration changes.  (Normally, when a VSS unit fails, your first concern is getting it back on-line, not making new configuration changes.  Ideally, everything will work with just either VSS unit being active.)

  • SG switches and Microsoft NLB

    Hi,
    does anyone know if the SG300 switches can be used with Microsoft NLB in Multicast mode?
    I know on traditional Catalyst switches you can statically "map" IP's to mac's and then to multiple ports but this doesn't seem to work correctly on the SG switches - it gives an error about the mac not being not Unicast?
    So, any help or links to Cisco SG examples would be appreciated.
    thanks
    John

    I have not tested it yet. But I want to know this as well.
    Keep in mind that you need to use the multicast MAC Address, not your normal MAC Address. It is bound to a multicast IP Address.

  • The Advantages of Official Microsoft and Cisco Certification Training Courses

    Lots of professionals in design and networking management channels are desirous to obtain various recognized Microsoft certifications like MCSE (Microsoft Certified System Engineer) and MCSA (Microsoft Certified System Administrator). These Testking
    642-446 certifications can shift you from average low rewarding jobs as a programmer towards prosperous and lucrative career. People are crazy today to do anything to obtain such certifications. They invest their time, money, and energy toward achieving
    their goal certifications.
    But beware of internet scammers who commonly lure people into buying various second-hand tutorials and self-study oriented training programs, promising great results with Testking SY0-201 minimal efforts. However at the same time lots of reliable and solid
    web sites are available also, providing comprehensive, well structured, and elaborate study material. It definitely facilitates your process of learning and guaranteeing success.
    It is very important to distinguish a difference between an average and a reliable website. Take time out of your busy schedule and focus on your study course. It is better if you attend a short classroom Testking 640-863 training course instead of using
    self-study oriented programs. If you search online you will come across various websites providing advanced MCSE and MCSA accelerated training courses, seminaries, laboratories, taught by experienced, well educated experts. That is why these classes are better
    than self study programs because they involve better comprehension and learning, more participation, stimulating students' thinking and enhancing their overall skills and knowledge. If a person attends 14 days training course of MCSE or MCSA then he is capable
    enough to formulate a solution in design and Testking VCP-410 network management issue with the help of well-trained professionals. In fact these training classes make the candidate capable of all practical abilities that help him in future career. Training
    program of MCSE or MCSA guarantee graduates acceptance in the best multinational companies of the world!
    Apart from MCSE and MCSA, Cisco certified Network Associate CCNA and Cisco Certified Internetwork Expert certification CCIE are highly demanded in present era. There are various training institutions providing a comprehensive and elaborate training to
    the candidates. These training centers quickly familiarize the students with latest Cisco technologies and hardware. During CCNA and CCIE training sessions , attending students receive constant support and feed-back from well-trained, experienced and certified
    professionals. The instructors here focus not only on theory but at forming and enhancing Testking 642-481 students' practical skills on various aspects of Cisco technologies and hardware. Thousands of graduates recommend professional CCNA and CCIE
    training courses to people who wish to build a solid, strong, successful career in the IT field.
    At the end I would like to recommend Testking MCSE training,Testking CCNA practice test, Testking CCIE training for gaining best guidance for the exams.

    MCSE (Certified Systems Engineer
    for Microsoft) and MCSA
    (Microsoft Certified System
    Administrator). These globally recognized
    certifications are highly desirable because they can
    easily make the difference between a thriving career
    in the lucrative design and average
    low rewarding job as a programmer. (Cisco
    Certified Network Associate) and CCIE
    (Cisco Certified Internetwork Expert)
    certifications are also in demand today.
    There are several training centers that offer people
    the opportunity to participate in the development of
    training programs for CCNA and CCIE
    in exchange for a reasonable sum of money.
    When attending a CCNA five or
    six days and the CCIE training course, students can
    quickly become familiar with the latest technologies and
    Cisco hardware.For more info about this exam Latest Dumps PDF Exam Question visit Examcollectionvce.com

  • Connect MICROSOFT UC to android and CISCO

    does someone know how to connect  plateforme UC based on MICROSOFT  to CISCO ANDROID? any article?
    thank you

    How do you want to connect Microsoft UC to Android?
    Did you mean Android mobile phone?
    If you want to integrate Lync Server and Cisco Unified Communications Manager, you can check
    http://www.microsoft.com/en-us/download/details.aspx?id=26800
    Lisa Zheng
    TechNet Community Support

  • Microsoft Lync 2010 and Cisco APs

    My company has extensively deployed Microsoft Lync Enterprise voice and this was an upgrade from OCS R2. Staff in my company have complained often of poor calls over wireless. I have resisted applying QoS for now until I understand fully how Cisco APs and WLCs implement QoS. I recently watched a video from Aruba networks comparing performance of Lync calls over its access points and Cisco access points. The Cisco setup was a 3500 AP and 5508 WLC with 7.0.116 code. There were also other bandwidth consuming applications running at the background. I must say that I was impressed at how Aruba's access point performed over Cisco access points. This is because Aruba does application specific QoS and not the traditional client or SSID QoS.
    I am considering making recommendation to management to go Aruba for the upgrade of a larger subsidiary. However, before I make such a recommendation,I have 2 quetstions
    1.  I would like to know if Cisco has revamped its WLC code to better deal with Lync and if so, I would be grateful if I could be shown any documentation or video on how to implement QoS to improve Lync experience.
    2. Also if HREAP is implemented, does the WLC still implement QoS or has this to be handled by the switch since packets are locally switched.
    I currently have a mix of 5508 and 4404 WLCs with over 300 1041n APs.

    Osita,
    As far as I know, Cisco has not done any optimization specifically for Lync, but as long as Lync is using standards-based tagging for the latency-sensitive parts of the application (voice and video), then you can elevate your WLAN QoS setting to the appropriate metal to allow for elevated QoS-tagged traffic on that WLAN.
    Keep in mind that the controller does not actively tag upstream client traffic, so even if you have clients doing other applications on their workstations over that WLAN, that traffic will not be re-marked from best effort to a multimedia QoS level. I.e., you can have a WLAN that shares both data and voice/video in a Lync environment.
    If you want to learn WLC QoS from the best (IMO), here is is Jerome Henry doing a 5-part video series explaining and implementing QoS on the WLC. It starts with Part 1, and the goes to Part 2-a, 2-b, 3-a and 3-b:
    http://www.youtube.com/watch?v=44t-0JYEwkA&list=UUm3YBBhcJRokmAD1LaJg3hQ&index=15&feature=plcp
    Locally switched HREAP traffic will come out into the switchport marked with the DSCP tag given to it by the application. It is up to you to configure proper end-to-end QoS on your network from there.
    Justin

  • How to replace bad sup in 4500 VSS cluster

    I have a Supervisor 7-E on its way to replace a bad one in a 4500 VSS cluster that handles my executive row and I've just realized I only have the foggiest idea what config is required to make it join the VSS cluster.
    I've looked and not found anything on point. Does anyone have a quick cheat sheet on how to do this?

    I actually was able to read between the lines of some different docs and came to the exact same conclusion. There is one BIG caveat that is not mentioned in your document and that is licensing.
    First, Cisco TAC is totally ill-equipped to understand how VSS affects commands output on the 4500 and was little to no help in the process. I figured out the other issues below on my own and basically told them what I needed
    The RMA'd unit will not have the correct license on it, it will only have LAN base which does not support VSS
    4500's are licensed per chassis, not per supervisor HOWEVER the supervisor(s) are where the license resides (on 4500 sup7/8)
    The "show license udi" and "license install <location>" command only run on the active supervisor. There is NO WAY that I could find to update the license on the inactive supervisor. If you replace a chassis or supervisor and add it to the VSS cluster before doing licensing, you will have to reboot the current active chassis before putting the correct license on it
    You are FAR better off getting the licensing straight before adding an RMA replacement supervisor/chassis added to the VSS cluster then after.

  • Cisco 4500 Quad Supervisor Deployment

    Hi Experts,
    I'm installing 2nd supervisor in Cisco 4500 redundant chassis.
    1st supervisor is working fine with Enterprise Services License but now i need to install 2nd (newly purchased supervisor) in the chassis.
    Could someone please help me on how to deploy only one license on the chassis level and link the 2nd supervisor with the existing one's enterprise services license. 
    Cisco delivered paper base license PAK with the 2nd supervisor, so do i need to use that PAK for this new supervisor OR without doing it i can sync the new supervisor with the license of existing one. 
    Your usual support is required.
    With Regards,
    Umer

    Disclaimer
    The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
    Liability Disclaimer
    In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
    Posting
    I recall, all you need to do is install the 2nd sup with an Enterprise license, and insure SSO is configured.  (I also recall, unless Enterprise license is already installed, 2nd sup installation "acts funny'; at least with sup7.)  I.e. don't believe you need to muck about with license again.
    Your subject title, though, has "Quad", so is this for VSS?

  • Microsoft NLB on Nexus 5596T

      Hi guys,
    We recently installed two 5596T in a cluster at a customer. They are currently migrating their servers to a VMWARE solution and have asked if the nexus supports microsoft NLB on multicast mode.
    I reached to Cisco TAC on this however I havent gotten any confirmation on the commands that are required. Can you advise what commands are required for this to allow servers to see the NLB server. So far the customer are able to migrate and the solution is working however is it recommended to set static maps on the nexus for the nlb server?
    Thanks much.

    Hi,
    Look this document, I applied this configuration once and worked fine.
    There are 3 modes to Microsoft Network Load Balancing (NLB)
    1.      1.Unicast
    2.      2.Multicast
    3.      3.IGMP multicast  (check the IGMP checkbox in the GUI while in multicast mode)
    In general,every mode uses a different sending and receiving mac address while keeping the unicast virtual IP address (VIP) constantacross all 3 modes. This concept makes switches flood traffic at layer 2 since the switch either never sees the destination mac address come in on any of its ports(and hence can’t learn it) or the multicast mac address floods. Either multicast mode, IGMP or normal multicast, also requires static ARP entries on the gateway router since Cisco routers will not learn an ARP reply with a multicast mac address tied to a unicast ip address.
    Mac addresses in the 3 modes breakdown into the following components:
    The     first number in the mac address is the type of NLB configuration: 01=IGMP,     02=Unicast, 03=Multicast (Note: bit 2 is the administered locally     multicast space)
    The second number, (bf) is the same for unicast and multicast mode (not IGMP multicast mode     which uses the standard 01-00-5e mac address)
    The last two (IGMP multicast mode) or four (unicast or     multicast mode) numbers are the virtual IP address, i.e. c0=192, a8=168,     04=4, 0a=10 and thus the IP of 192.168.4.10 has a multicast mac address 03-BF-C0-a8-04-0a     while an IGMP multicast mac address would be 01-00-5e-7f-04-0a
    Summary of configuration
    NLB mode
    Switch  configuration
    Router  configuration
    Unicast
    Mac  address-table static 02bf.xxxx.xxxx vlan y interface  
    Not  required – unicast mac address with unicast ip address
    Multicast
    Mac-address-table static 03bf.xxxx.xxxx  vlan y interface   
    n7k[5.2(1)]: mac address-table  multicast 03bf.xxxx.xxxx vlan y interface
    Arp  03-bh-xx-xx-xx-xx arpa
    IGMP multicast
    Mac address-table static 01005exx.xxxx  vlan y interface   
    Arp  01-00-5e-7f-xx-xx arpa
    Basicly you have to add the mac address static to all ports that you learned the mac address of your cluster microsoft (including the vpc peer-link if exist).
    In the router (could be the N5K, if it doing the L3 boundary) you have to add the arp entry in the vlan sub-interface configuraton mode.
    The cluster comes up instantly.
    Richard

  • Can not access FWSM via session command in cisco 6513 (VSS enabled)

    Dear All,
                  Today i received FWSM from cisco (RMA), I need to configure it as standby unit for existing FWSM active/standby setup.
    IOS on RMAed FWSM is 2.3.4 and  cisco VSS supports FWSM IOS 4.0.4 and later.
    My issue is, I cannot access FWSM (IOS 2.3.4) via session command from cisco 6513 but could successfully consoled it without any problem. I have reloaded it twice and also tried to disable and enable power on it.
    VSS#sh module switch 2
    Switch Number:     2   Role:  Virtual Switch Standby
    Mod Ports Card Type                              Model              Serial No.
       2    6  Firewall Module                        WS-SVC-FWM-1  -----------
    Mod MAC addresses                       Hw    Fw           Sw           Status
      2  0034.2fd7.3b04 to 0019.2fa7.3b0b   4.2   7.2(1)       2.3(4)       Ok
    Mod  Online Diag Status
      2  Pass
    VSS#session switch 2 slot 2 pro 1
    The default escape character is Ctrl-^, then x.
    You can also type 'exit' at the remote prompt to end the session
    Trying 127.0.1.21 ...
    % Connection timed out; remote host not responding
    Can someone please let me know why I cannot access FWSM through session command ?
    Whether this is because of older IOS ? If yes then how to upgrade its IOS ?
    Is it possible to upgrade IOS via FWSM console ? if yes, please let me know.
    Do i need to test on different slot ?
    Look forward to hearing from someone.
    Thanks & Regards
    Ahmed...

    There is a limitation that FWSM running version older than 4.0.4 will not accept session from the switch if the FWSM is not seated into switch 1 AND if switch 1 is not active.
    So to upgrade the FWSM you either need to use the console or put the FWSM physically in switch 1.
    Thanks,
    Jeroen

  • Cisco 4500 series switch

    Dear support taem, in cisco 4500 series switch i am getting error interface TenGigabitethernet 1/14 utlization threshold violated.current in traffic 705.228 (70.52 %) and out traffic 707.462 ( 70.75 %) whereas configured threshold is 30 %.
    i have checked on switch but qos is there in configuration.
    where i need to check if any restriction is there for incoming and outgoing traffic.
    and what necassery troubleshooting i need to be done.

    This looks like a policy shaping.

  • Anybody had used Microsoft NLB to LoadBalance LDAP traffic?

    Hi all.
    I got some lines from a Microsoft spoker and he says that the NLB (Microsoft Network Load Balancing Manager) could balance LDAP traffic.
    I'm trying to find a way to do this without a hardware load balancer.
    Anybody has any experience on this field?
    Thanks.

    Paolo,
    I really thought you were using the IGMP option because of your statement:
    "2) Other hosts in the same VLAN do not receive any broadcast related to this cluster (multicast is working)"
    Without the IGMP option, NLB uses a locally administered Multicast MAC address with the format 03:BF:<IP-Address-of-the-Cluster>. Thus this is not an IANA-assingend multicast MAC address (01-00-5E), IGMP snopping cannot avoid the flooding of those frames throughout the entire VLAN, which is the only way a switch can handle such frames. The recommendation for avoiding/containing this flooding is the configuration of static MAC entries for the multicast Cluster MAC (binding it exclusively to the required ports). Those static entries then also will be listed in the "show mac address-table" output.
    With the IGMP option, you can make use of IGMP snooping in order to avoid the flooding, so static MAC entries are not required in this case and the multicast cluster MAC can be learned dynamically by IGMP snooping. It should then be listed in the "show mac address-table multicast" output.
    HTH
    Rolf

Maybe you are looking for

  • Handling unit status at table level

    Dear Experts, I want to know the logic to find only those HUs which exist in the inventory i.e. which are present physically. I do not want those which have been delivered/deleted/scrapped etc. How can I get this at table level and what filters shoul

  • My Serial Number is registered on my old "crashed" computer.

    I am trying to use my Adobe Photoshop Elements 10 and Adobe Premier Elements 10 on my new computer.  I just bought this software and then my computer crashed, so I got a new computer.  I have downloaded the Adobe software on my new computer and it ke

  • Lumia 620 cyan update

    Web link showing cyan update for Lumia 620 is available in India, but my mobile showing its up to date. I am still in black update,not getting cyan update.

  • Problem Viewing/Opening PDF from Outlook attachment

    Some PDF files will open just fine.  Other PDF files will give me this error: "Can't create file.  Right-click the folder you want to create the file in, and then click Properties on the shortcut menu to check your permissions for the folder." Can so

  • Fade effect after inactivity in ADF 11.1.1.6 application

    Hello everyone, after a period of inactivity (about 10-15 minutes) in my ADF application (v. 11.1.1.6) the page is shown in semi-transparency mode with a little icon of warning on the bottom of the page. This fade effect disappears after a mouse move