Switch Management

Hey Folks,
There seems to be two schools of thought when it comes to switch management. From what I've read, two different approaches seem to be recommended. The first is to create a switch management VLAN, and trunk it to all the switches. The second is to create a loopback address, and distribute it via a IGP.
Any advantages or disadvantages? Which one do you use and why?
Thanks,
SM

Two approaches are two different kind of design. One is L2 VLAN separated the segment and one is L2 w/ individual NM segment.
What I suggest is to combine both designs that use separated VLAN w/ loopback address that dedicated for the NM traffic. The reason is at L2, it can separated the NM traffic from the production traffic, and for L3, you easily to observe the NM host by different subnet of the loopback address.
However, if there is WAN link that cannot carry VLAN traffic, then you have to use second approach in the WAN link.
And, if it is a L2 switch only, then you have to create a NM VLAN and assoicate the loopback address to this VLAN for NM.
Pease feel free to comment and discuss.
Hope this help.

Similar Messages

  • 3524-XL w/GBIC Visual Switch Manager

    I have a Cisco 3524-XL switch w/ 12.0(5)XU Enterprise Edition OS
    Been using the Java-based Visual Switch Manager to manage it, no problems.
    I added a 1000BaseT GBIC, and everything works mechanically and thru telnet, I can manage the switch. Everything works.
    But now when I try to use the Visual Switch Manager, I get the following Java Error:
    "Visual Switch Manager has detected a change in the devices hardware configuration and needs to redraw the device." I say ok, and it comes back again, and again, etc. The running config has been saved and rebooting does not help. Tried a coupla versions of Java(Sun's). Currently using 1.4.2_07
    Any suggestions?

    try upgrading the image of the switch, also run the latest Java plug in software. this should help.

  • Tacacs and visual switch management incompatibility

    We have upgraded the IOS on Cisco 2924 switch, configured it for Tacacs, however the visual switch management using Netscape for the above switch doesn't work. Any ideas?

    Hi Balaji,
    the management port is assigned to a VRF called "mgmt-vrf", so it does not participate in global ip forwarding because it is intended for out-of-band management. This link showes a configuration example for TACACS:
    http://blog.monkeyrouter.com/2014/04/tacacs-over-management-vrf.html
    HTH
    Rolf

  • Changing switch management from default Vlan1

    I'm in the process of changing some access layer switches and the distribution switch away from the default Vlan1 for switch management. I'm a little unclear on the native Vlan information. If I change the management vlan to lets say 299 do I need to change the trunk ports to reflect a native vlan of 299?

    Not neccessarily. Just make sure you allow the new VLAN on the trunk.

  • Windows 8.1 Starting Virtual Switch Manager from VMM crashes VMM service

    Started happening after tried to add external switch using WiFi.
    Now, VSM shows 'Load Failed' for the switch. Immediately after stating s/w manager VMM service crashes. I am unable to add a new virtual switch.
    Any help will be appreciated.
    Thanks
    Jas

    Hi Jas,
    >>Started happening after tried to add external switch using WiFi.
    If it is only happen to creating external virtual switch bounding it to Wireless NIC, I would suggest you to delete all virtual switch then uninstall hyper-v role and update the driver for wireless NIC then install hyper-v again to check the result .
    (By the way , in most of the cases external virtual switch bounding to  wireless NIC will not work well as bounding it to wired NIC )
     I would  suggest you  do not  create external virtual switch bounding to wireless NIC .
    If you want the VMs can access internet through host's wireless NIC please refer to following thread :
    https://social.technet.microsoft.com/Forums/en-US/d380e4c3-a9c0-483f-8fd9-11962b1f486c/enable-virtual-machine-to-access-internet-with-ics?forum=winserverhyperv
    Any further information please feel free to let us know .
    Best Regards
    Elton JI
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Switch Management Software

    is there a download for a management software for a switch hopefully that is GUI?

    Technochick-Rea wrote:
    is there a download for a management software for a switch hopefully that is GUI?
    Not for discontinued webOS devices... Support ended in January.
    WyreNut
    I am a Volunteer here, not employed by HP.
    You too can become an HP Expert! Details HERE!
    If my post has helped you, click the Kudos Thumbs up!
    If it solved your issue, Click the "Accept as Solution" button so others can benefit from the question you asked!

  • Cisco 3850 Switch Management Port - ACL on VTY

    Hi,
    I got these switches.
    Switch Ports Model              SW Version        SW Image              Mode   
    *    1 32    WS-C3850-24T       03.03.02SE        cat3k_caa-universalk9 INSTALL
         2 32    WS-C3850-24T       03.03.02SE        cat3k_caa-universalk9 INSTALL
    SSH access to Management port G0/0 with an ACL applied on line vty 0 4 is failing, even through the ACL is permiting traffic.
    interface GigabitEthernet0/0
     vrf forwarding Mgmt-vrf
     ip address 172.16.12.3 255.255.255.0
     negotiation auto
    ip access-list standard ACLVTY
     permit any log
    line vty 0 4
     access-class ACLVTY in
     exec-timeout 15 0
     length 0
     history size 64
     transport preferred ssh
     transport input ssh
     transport output telnet ssh
    037599: *Mar 28 2014 04:59:49.919 AEDT: %SEC-6-IPACCESSLOGS: list permit-any permitted 172.16.12.100 1 packet
    # show ip access-list permit-any
    Standard IP access list permit-any
        10 permit any log (3 matches)
    If I remove the ACL under VTY "no access-class ACLVTY in", then SSH to the management port works. If I don't use the management port and use a normal port say G1/0/1 configured on management VLAN and assigned the same IP address, then SSH works with the VTY ACL still existing. 
    Any ideas ?
    Thanks, 
    Rick.

    Hi,
    IOS will accept all VTY connections by default. However, if an access-class is used, the assumption is that connections should only arrive from the global VRF. If you need control the IP source while allowing VTY connections from VRF instances, you have a try configuration option "vrf-also"
    So, you should get something like this:
    line vty 0 4
    access-class ACLVTY in vrf-also  

  • Blade Switch Management

    I am deploying HP BladeSystem C Class with Cisco 3020 Ethernet blade switches connecting to Catalyst 6500 at the aggregation layer. What are my best options for managing layer 2, VLANs, etc, across the Cat6K and 3020 switches?

    Matt,
    Great catch, thank you!
    Switch#show link state group detail
    Link State Group: 1 Status: Disabled, Up
    Upstream Interfaces : Po1(Up)
    Downstream Interfaces : Gi0/1(Up) Gi0/2(Up) Gi0/3(Up) Gi0/4(Up) Gi0/5(Up)
    Gi0/6(Up) Gi0/7(Up) Gi0/8(Up) Gi0/9(Up) Gi0/10(Up)
    Gi0/11(Up) Gi0/12(Up) Gi0/13(Dwn)
    Link State Group: 2 Status: Disabled, Down
    Upstream Interfaces :
    Downstream Interfaces :
    (Up):Interface up (Dwn):Interface Down (Dis):Interface disabled
    Switch#conf t
    Enter configuration commands, one per line. End with CNTL/Z.
    Switch(config)#link state trac
    Switch(config)#link state track 1 ?
    Switch(config)#link state track 1
    Switch(config)#end
    Switch#show link state group detail
    Link State Group: 1 Status: Enabled, Up
    Upstream Interfaces : Po1(Up)
    Downstream Interfaces : Gi0/1(Up) Gi0/2(Up) Gi0/3(Up) Gi0/4(Up) Gi0/5(Up)
    Gi0/6(Up) Gi0/7(Up) Gi0/8(Up) Gi0/9(Up) Gi0/10(Up)
    Gi0/11(Up) Gi0/12(Up) Gi0/13(Dwn)
    Link State Group: 2 Status: Disabled, Down
    Upstream Interfaces :
    Downstream Interfaces :
    (Up):Interface up (Dwn):Interface Down (Dis):Interface disabled
    Switch#
    Scott
    www.xpresslearn.com

  • Switch management access

    Hello,
    Cisco 3560 configured with management VLan10 ip 10.10.10.10 can be accessed via ssh, add new management interface VLan60 ip 10.10.60.10, also can access via ssh.
    When I remove interface vlan 10, I can no longer access the switch, ip 10.10.60.10 is reachable, tried transport input to include telnet, same behavior.
    What am I missing here?
    Thanks
    Switch Ports Model              SW Version            SW Image
    *    1 52    WS-C3560-48PS      12.2(53)SE2           C3560-IPBASEK9-M

    Brendan
    Is this switch meant to be acting as a L2 switch or a L3 switch ?
    If it is L2 then disable ip routing and use the default gateway you have already configured
    if it is L3 then remove the default gateway and add a default route using the same next hop IP eg.
    ip route 0.0.0.0  0.0.0.0 10.10.60.1
    Jon

  • Ethernet Switch Manager

    Hello,
    I have a Ethernet Switch, I am trying to Manage this switch using LabVIEW. I want to perform some basic operations like port Enable/Disable.
    I am not getting how to start and how to access switch in LabVIEW.
    If someone have same kind of knowledge please share with me.
    Thanks and Regards
    Himanshu Goyal | LabVIEW Engineer- Power System Automation
    Values that steer us ahead: Passion | Innovation | Ambition | Diligence | Teamwork
    It Only gets BETTER!!!

    More likely than not the swicthes can be controlled using SNMP. Each manufacturer would have it's own MIB definition so a single general solution is very unlikely. You could define a switch object and use inheritance and dynamic dispatch to define a common API from your application's persepctive but will allow different implemenations specific to the switch. I have attached a basic SNMP library.
    Mark Yedinak
    "Does anyone know where the love of God goes when the waves turn the minutes to hours?"
    Wreck of the Edmund Fitzgerald - Gordon Lightfoot
    Attachments:
    snmp communication.llb ‏727 KB

  • 6509 issues - intervlan switch management

    Okay, so we did a recovery on our 6509 last night which appeared to go well. I currently have 10 vlans on the 6509 all with seperate dist switches on each subnet...Now traffic across all subnets work fine except I no longer seem to be able to access my switch IPs anymore. Unless I am local to that subnet.
    We did reboot the 6509 several times but none of the subnet switches were touched.
    I tested one switch by rebooting and it appeared to fix the problem. Possible Arp cache problem ? Any thoughts ? I can reboot them all tonight but would like to know the cause..From the active MSFC I can ping all switch IPs, but not from the 6509 switch console.

    Each floor is a Vlan which has a 3548 on it. The 3548 is trunked back to the 6509 via fiber and yes the uplink ports on the 6509 are trunked (isl).
    The management IP of each 3548 is in the local subnet of the floor vlan..Ex.10.1.3.0 /24 is vlan 3 and the switch IP is 10.1.3.2. The trunk links back to the 6509 are working fine as all users per floor have connectivity out of their vlan. So each 3548 appears to be switching fine.
    Thanks
    Dave

  • Remote route and switch management

    Good afternoon support community,
    Does Cisco have a replacement for the 2811 console servers, newer with more features? I have been looking at opengear, but I wanted to know if Cisco had something equivalent to it. I'm looking for a way to manage devices via console, on a out of band network. If you have any recommendation please feel free to post them.
    Thank you for your input.
    Delmiro

    There's not a direct replacement for the 2811 console server / router as far as I know.
    Most customers I see are choosing either Opengear products or the Emerson (former Avocent, former Cyclades) ACS console servers. Link

  • ESW Switch Management - KPIs

    I am looking for list of SNMP traps, Syslog messages (OIDs) recommended for Fault and performance monitoring of ESW switches.
    It will great if you can help me on this.

    Two approaches are two different kind of design. One is L2 VLAN separated the segment and one is L2 w/ individual NM segment.
    What I suggest is to combine both designs that use separated VLAN w/ loopback address that dedicated for the NM traffic. The reason is at L2, it can separated the NM traffic from the production traffic, and for L3, you easily to observe the NM host by different subnet of the loopback address.
    However, if there is WAN link that cannot carry VLAN traffic, then you have to use second approach in the WAN link.
    And, if it is a L2 switch only, then you have to create a NM VLAN and assoicate the loopback address to this VLAN for NM.
    Pease feel free to comment and discuss.
    Hope this help.

  • Switch Software management

    Hi,
          I am in the process of developing a System to monitor the components on the Printed circuit boards in oven,It s a basically a failure analysis of the components such as C's,Resistors and Capacitors. 
    The following is an overview of my test system 
    The test system should monitor the components on the PCB 1 year.
    I would like to measure the Resistances and Capacitances using an LCR meter to identify the failure. Failure of the Resistor is identified with a Open circuit and a failure of the Capacitor is identifed with a short circuit/open circuit.I have 420 capacitances to be measured and I would like to automate the measurement using NI Multiplexers.
    I have to monitor the first Capacitance (C1) for 3 mins ( which would be connected to the first input of the multiplexer) , followed by second for 3 mins and so on. Once all the 420 capacitances are monitored , the loop should start again from Capacitance C1.  I would like to know how to program the NI 's switches. Could someone please suggest me how to go ahead with this.? Is Labview good enough to automate the switches or should I go ahead with a switch management software ? Can you please explain in detail as am a newbie to Labview ?  Looking forward to your response. Thanks in advance 
    Solved!
    Go to Solution.

    Hello there, 2nF approaches the territory where we need to consider the parasitic capacitance in the cabling/modules/etc.  For example, the multi-conductor LFH-200 cable that plugs into the PXI-2575 specifies 25pF/ft nominal parasitic capacitance with a single-ended signal, versus 15pF/ft nominal with a 2-wire signal. There's also internal capacitance from the switch, your test harness (anything that plugs into the LFH-200 cabling), etc.  With a 1-wire system, all DUT capacitor minus terminals are connected together all the time, which means you have a bunch of additional coupling locations for additional stray capacitance... wherever you have a stray path from any of the minus leads back to the particular channel under test.  For example, you could have coupling back through each capacitor's power supply back through the DUT's power supply and then into your measurement, etc.  With a 2-wire system, both the plus and minus are switched, which greatly reduces the number of venues for stray parasitic capacitance.  You might be able to get away with a 1-wire system, but my concern is with 420 channels your parasitic capacitance could approach your DUT capacitance.  If the parasitics are constant, you could compensate out the error, but I still recommend a 2-wire solution. 
    NI HW definitely allows synchronization between DMM/Switch using external triggering, but in your case I recommend just using SW API calls: "switch: connect CHn" "dmm: take measurement y times" "switch: connect CHn+1" etc.  Synchronization is a method to measure as fast as possible, whereas you're taking measurements over a period of hours with a required period for each DUT... with HW synchronization, you can't implement a "wait t seconds" (unless you used additional external hardware, e.g. 555 timer to add delay, but this isn't practical when there's a perfectly good SW API). 
    Note that if you're not comfortable with LabVIEW programming, but do know text-based programming, NI-Switch has a full-featured C++ API.  NI-Switch includes numerous examples in both LabVIEW and C++, and of course the community here can offer tips/hints/advice if you run into coding trouble. 
    -John Sullivan
    Analog Engineer

  • Need help setting up a virtual switch setup for my lab.

    Hi,
    I used to be able to get this to work. But, I'm not able to anymore.
    I have two network cards in my PC.
    #1 Is what I use for everyday use and it's configured to use :
    IP: 192.168.0.2
    GW: 192.168.0.1
    DNS : 192.168.0.1 (Router address)
    #2 Is setup to use
    IP: 192.168.0.3
    GW: 192.168.0.1
    DNS : 192.168.0.1 (Router address)
    Then I create a Virtual Switch in Hyper V Virtual Switch Manager and bind it to Network Card #2.
    This creates the Hyper V Virtual Ethernet Adapter that I bind my VM's to.
    But for some reason none of my VM's can get a connection to the internet. There is an exclamation mark over the network icon.
    When I go back and look at the TCP/IP V4 properties of the Virtual Ethernet Adapter, I release that it has no DNS settings.
    But when I put any settings in there it gives me a warning about setting multiple default gateways, and do I want to continue, yes or no?
    What could I be doing wrong?
    Thanks

    Hi midi25,
    Then I create a Virtual Switch in Hyper V Virtual Switch Manager and bind it to Network Card #2.
    This creates the Hyper V Virtual Ethernet Adapter that I bind my VM's to.
    I think you checked the "Allow management operating system ..." , the new Vethernet adapter is a virtual adapter for HOST ( the name same with the Vswitch) .
    So , the "multiple default gateway" will arise when you configure GW for it .
    Best Regards
    Elton Ji
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

Maybe you are looking for

  • What is a manufacture warranty of the phone?

    Im currently having problems with my z2. The touchscreen is all crazy and non responsive. I tried the repair using sus but it didnt do anything to help. I contacted amazon to see if they could exchange it but since it has passed 30 days since i bough

  • Y470 driver Windows 8 Problems

    - I can't install audio driver for windows 8 64 bit - I can't use adjust fan function

  • RoboHelp 9 HTML crashing

    This may get a bit lengthy but I want to lay it all on the table in the hope of getting to the root thus helping to arrive at an answer. For the past several months I've been developing a help system for a food processing plant. This is a brand new p

  • Can't get Mail working properly

    I just got my new MacPro this week, and it's really great except for I can't get Mail working right. I've set up my accounts and a few emails come through, though not many, and because it's been a week since I've been online, there should be many mor

  • ABAP Buffer Problem - URGENT

    Hi All I have the following ABAP problem. I wrote a program that delimits(Just editing the end date) the Qualification and Person relationship in HRP1001. The problem is that I update the database directly, and all appears to be working fine but it a