Tacacs+ 2960S Stack
Hello All,
We have recently bought a batch of Cisco 2960x-48LPS-L switches. They where all shipped with c2960x-universalk9-mz.150-2.EX2. We have migrated our standard switch configuration which works fine on Cisco 2960, 3750 switches onto these x series switches but have an issue with TACACS+. When we connect using SSH we get a message regarding Authorisation Failure and are unable to logon. This is exactly the same config as used on other switches. I have seen discussions about old versions of code having issues with TACACS have these been fixed in this version? I have tried upgrading one stack to EX4 but with no difference in outcome.
Got another 20 of these switch planned for the next couple of weeks and TACACS+ is a must so any help would be very appreciated.
Thanks
Ian
Maybe try and zeroize the the ssh keys and recreate them. Also I have seen in the past where cutting and pasting a config the tacacs server keys do not get input correctly. Delete the tacacs server key line and "manually type the whole line with the key .
Similar Messages
-
2960 Stack Port Channel Question
I have a 2960 stack with 2 WS-C2960S-48FPD-L distribution switches running c2960s-universalk9-mz.150-2.SE2.bin.
I then have three stand alone 2960S-48 access switches running the same code.
I will have two ten Gig uplinks in a port-channel back to a 6500. I have this config. however
I would like to have port-channel between each of the distribution switches in the stack and each of the stand alone access switches.
So as an example:
distribution switches: port 1/0/48 and 2/0/48 in port channel 1
access switches: 1/0/51 and 1/0/52 in channel-group 1 active
Am I right in thinking that because these port channels come off of two different switches in a 2960 stack that they need to be LACP and the ports on the access switches need to be in "channel-group X active". And does it need to be in active mode on both sides?
Thank You in advanceYes, both sides must have identical channel mode.
-
Hey guys recently I tried to introduce a 2960x switch into a 2960s stack.
I prepped the bpth switches and made sure the prefer sdm was set to default as well as setting the stack port speed on the 2960s stack to 10 so its would be compatible.
Once i stacked the switches i got a version mismatch error and an auto upgrade message, after waiting roughly 40 minutes with no succcessful upgrade i removed the X switch from the stack
below are the IOS running on both switches
* 1 52 WS-C2960S-48FPS-L 15.0(2)SE5 C2960S-UNIVERSALK9-M
2 28 WS-C2960S-24TD-L 15.0(2)SE5 C2960S-UNIVERSALK9-M
3 52 WS-C2960X-48FPD-L 15.0(2)EX4 C2960X-UNIVERSALK9-M
Any thoughts on how to successfully stacked these?? Thanks in advanceHi,
some info about stacking different switch 2960S with 2960X.
More info is available at:
http://www.cisco.com/c/en/us/products/collateral/switches/catalyst-2960-x-series-switches/white_paper_c11-728327.html
Hope this can help you.
Mixed Stacks: FlexStack and FlexStack-Plus
The 2960-S and 2960-X support a mixed stack of 2960 models. All these 2960 models run the FlexStack protocol, allowing them to be stacked together into a single stack. The exception is the 2960-XR does not stack with either the 2960-X or the 2960-S. The 2960-XR has the IP-Lite feature set, and this is not compatible with the LAN Base feature set on the 2960-X and 2960-XR. Table 2 shows all the allowed mixed stack combinations. What is crucial is the Cisco IOS Software feature set. All 2960 models with the LAN Base Cisco IOS Software feature set can stack together.
Table 2. Allowed Mixed Stack Combinations
Mixed Stack Combination
2960-XR IP Lite
2960-X LAN Base
2960-S LAN Base
2960-XR IP Lite
Yes
No
No
2960-X LAN Base
No
Yes
Yes
2960-S LAN Base
No
Yes
Yes
Table 3 shows FlexStack-Plus backward compatibility and performance of 2960-X and 2960-XR with the 2960-S switches.
Table 3. Backward Compatibility
Scale of Mixed Stack Combination
Max Stack Bandwidth
Stack Limit
Cisco IOS Software Feature Set
2960-XR IP Lite
80Gbps
8
IP Lite
2960-X LAN Base
80Gbps
8
LAN Base
2960-X, 2960-S LAN Base
40Gbps
4
LAN Base
When the 2960-S and 2960-X members are stacked together, the entire stack (even the 2960-X members) fall back to FlexStack capabilities. Mixing 2960 members limits the max stack members to four, and 20Gbps stack bandwidth per member, and 40Gbps per stack. -
Ciscoview 2960S stack SFP interface representation incorrect
Hello,
i am experiencing the following problem.
In the Ciscoview, the uplink SFP interfaces of 2960S stack are represented incorrectly. The two uplink interface should be Ten1/0/1 and Ten4/0/1 but proved to be Ten1/0/1 and Gi4/0/25. There is no 1G SFP module, so that the interface gi4/0/25 doesn't exist.
Any assistance would be greatly appreciated
Information:
LMS 4.1
2960 device packet: version 14.0
2960 IOS: 12.2(55)SE4Thanks for your reply
The Gi4/0/25 interface appear in detailed device report, but this interface is not operational. We didnt insert any 1G SFP. -
I have a problem with 4 cisco 2960-s Switches in a stack.
2 of the switches are 2960-48fps-l
1 is a 2960-f48fps-l
and 1 is a 2960-24pd-l
The problem I ran into is the 2960-f48fps-L was running version 15 out of the box so I got a version mismatch when I did a show switch. So i upgraded all 4 switches to the newest ios 15.0.2 when they rebooted now 2 of them say provision and the f48fps does not even show. I have tried everything from moving the cables around to wiping the config on all 4 switch to setting provision setting to setting priority. If I go back to the original version 12.2 on the other 3 switch they all work fine but the oldest version on the f48fps is 15. I have tried everything all with no luck can anyone help?Hi,
Can you make sure that all of the switches use the same SDM template? You can check that with the show sdm prefer command.
Hope this helps. -
OK, I need some help understanding why I'm getting the following error scrolling continuously on two stacked 2960S 24 port PoE switches.
MAIN_LODGE_MDF_SWITCH#17:48:29.541 MST: platform assert failure: 0: ../src-hulc/src-common/hulc_mad_sd_mgr.c: 658: hmsm_l3_get_locked_mad (MAIN_LODGE_MDF_SWITCH-2)
026618: *Feb 28 17:48:29.541 MST: -Traceback= 11C0D78 11B1E4C 11B3328 10CF6E8 10D0824 10D282C 10D4450 10D5830 10D7510 116467C 1173F38 1168694 1164B78 115A724 115B014 18769A8 (MAIN_LODGE_MDF_SWITCH-2)
026619: *Feb 28 17:48:29.541 MST: platform assert failure: 0: ../src-hulc/src-common/hulc_mad_sd_mgr.c: 658: hmsm_l3_get_locked_mad (MAIN_LODGE_MDF_SWITCH-2)
026620:
MAIN_LODGE_MDF_SWITCH#*Feb 28 17:48:29.541 MST: -Traceback= 11C0D78 11B1E4C 11B3328 10CF6E8 10D0824 10D282C 10D4450 10D5830 10D7510 116467C 116754C 1174080 1168694 1164B78 115A724 115B014 (MAIN_LODGE_MDF_SWITCH-2)
026621: *Feb 28 17:48:29.546 MST: platform assert failure: 0: ../src-hulc/src-common/hulc_mad_sd_mgr.c: 658: hmsm_l3_get_locked_mad (MAIN_LODGE_MDF_SWITCH-2)
IOS matches on both switches:
MAIN_LODGE_MDF_SWITCH#show version
Cisco IOS Software, C2960S Software (C2960S-UNIVERSALK9-M), Version 12.2(55)SE7, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2013 by Cisco Systems, Inc.
Compiled Mon 28-Jan-13 10:28 by prod_rel_team
Image text-base: 0x00003000, data-base: 0x01B00000
ROM: Bootstrap program is Alpha board boot loader
BOOTLDR: C2960S Boot Loader (C2960S-HBOOT-M) Version 12.2(55r)SE, RELEASE SOFTWARE (fc1)
MAIN_LODGE_MDF_SWITCH uptime is 58 minutes
System returned to ROM by power-on
System image file is "flash:/c2960s-universalk9-mz.122-55.SE7/c2960s-universalk9-mz.122-55.SE7.bin"
This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html
If you require further assistance please contact us by sending email to
[email protected].
cisco WS-C2960S-24PS-L (PowerPC) processor (revision G0) with 131072K bytes of memory.
Processor board ID FOC1721X0L2
Last reset from power-on
4 Virtual Ethernet interfaces
1 FastEthernet interface
56 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.
512K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address : 0C:68:03:35:A4:80
Motherboard assembly number : 73-11908-09
Power supply part number : 341-0393-02
Motherboard serial number : FOC17204YXW
Power supply serial number : DCA1717U3Y3
Model revision number : G0
Motherboard revision number : A0
Model number : WS-C2960S-24PS-L
Daughterboard assembly number : 73-11933-04
Daughterboard serial number : FOC17206GK5
System serial number : FOC1721X0L2
Top Assembly Part Number : 800-30945-04
Top Assembly Revision Number : A0
Version ID : V04
CLEI Code Number : COMGE00ARD
Daughterboard revision number : A0
Hardware Board Revision Number : 0x01
Switch Ports Model SW Version SW Image
* 1 28 WS-C2960S-24PS-L 12.2(55)SE7 C2960S-UNIVERSALK9-M
2 28 WS-C2960S-24PS-L 12.2(55)SE7 C2960S-UNIVERSALK9-M
Switch 02
Switch Uptime : 22 minutes
Base ethernet MAC Address : C4:0A:CB:10:E1:80
Motherboard assembly number : 73-11908-06
Power supply part number : 341-0393-02
Motherboard serial number : FOC15496YA1
Power supply serial number : LIT15410X7U
Model revision number : D0
Motherboard revision number : A0
Model number : WS-C2960S-24PS-L
Daughterboard assembly number : 73-11933-04
Daughterboard serial number : FOC15486DNP
System serial number : FOC1550X52S
Top assembly part number : 800-30945-02
Top assembly revision number : B0
Version ID : V02
CLEI Code Number : COMGE00ARB
Daughterboard revision number : A0
Configuration register is 0xF
Switches are configured with numbers and priorities appropriately:
MAIN_LODGE_MDF_SWITCH#show switch
Switch/Stack Mac Address : 0c68.0335.a480
H/W Current
Switch# Role Mac Address Priority Version State
*1 Master 0c68.0335.a480 15 1 Ready
2 Member c40a.cb10.e180 14 1 Ready
And the stacking info is:
MAIN_LODGE_MDF_SWITCH#show platform stack manager all
Switch/Stack Mac Address : 0c68.0335.a480
H/W Current
Switch# Role Mac Address Priority Version State
*1 Master 0c68.0335.a480 15 1 Ready
2 Member c40a.cb10.e180 14 1 Ready
Stack Port Status Neighbors
Switch# Port 1 Port 2 Port 1 Port 2
1 Ok Ok 2 2
2 Ok Ok 1 1
Stack Discovery Protocol View
==============================================================
Switch Active Role Current Sequence Dirty
Number State Number Bit
1 TRUE Master Ready 131 FALSE
2 TRUE Member Ready 214 FALSE
Stack State Machine View
==============================================================
Switch Master/ Mac Address Version Current
Number Member (maj.min) State
1 Master 0c68.0335.a480 1.45 Ready
2 Member c40a.cb10.e180 1.45 Ready
Last Conflict Parameters
Switch Master/ Cfgd Default Image H/W # of Mac Address
Number Member Prio Config Type Prio Members
1 Member 15 No 4 5 0 0c68.0335.a480
2 Member 14 No 4 5 0 c40a.cb10.e180
Stack Discovery Protocol Counters
Messages Sent Messages Recvd
UP DOWN UP DOWN
*1: 0000005722 0000005726 0000005091 0000005082
2: 0000001878 0000001878 0000001926 0000001927
3: 0000000000 0000000000 0000000000 0000000000
4: 0000000000 0000000000 0000000000 0000000000
Misc Counters
Counter Up Down
Wrong Ver Number: Send: 0000000000 0000000000
Wrong Ver Number: Recv: 0000000000 0000000000
Missed Messages: 0000000000 0000000000
Orphaned Messages 0000000000 0000000000
Suppressed Messages 0000000000 0000000000
No Available Messages 0000000000 0000000000
Link Present 0000000000 0000000000
Link Not Present 0000000000 0000000000
Link RxReset 0000000000 0000000000
Link Sync Stuck Resets 0000000000 0000000000
Duplicates 0000000001 0000000000
RAC Not OK Resets 0000000000
Switch# of last duplicate 0000000002
Sequence Number Failures 0000000000
RAC Not OK Resets 0000000000
Sync Not OK Resets 0000000000 0000000000
Switch# of last Failure: 256 Last Difference 0
Switch Number Conflicts 0
Stack Changes 16
Int Stack Link changes 0
Int Stack Link state 0x0
Reciprocal Efficiency Changes: Upgrade 0, Downgrade 0
Resource Counters
Chunk Alloc's 0000000016
Chunk Free's 0000000015
Enqueue Failures: 0000000000
Null Queue Failures: 0000000000
Chunk Alloc Errors: 0000000000
Stack State Machine Counters
Messages Sent Messages Recvd
*1: 0000000001 0000000001
2: 0000000005 0000000005
3: 0000000000 0000000000
4: 0000000000 0000000000
Any clue why this error keeps repeating itself? As far as I can tell both switches in the stack are forwarding frames appropriately.
Thanks in advance for any help,
Kevin
P.S. The only match to the error message that I could find was in cyrillic, and unfortunately I don't read Russian . . . . ;-)Firstly, it's not going to help because the switch doesn't have a valid time set. So I have no idea how far back were the "Traceback" errors generated.
Next, I've been using the same IOS you are using for months and I've never seen a Traceback like that.
I'm not saying that you are lying. I'm suggeting that it could be something wrong with the configuration of your switch or a potential harware failure.
Hmmmm ... Can you post the output to the following commands:
1. dir flash:
2. dir flash2: -
IP SLA responder on Catalyst 2960S stacked
Hi
I have a pair of switches stacked:
Switch Ports Model SW Version SW Image
1 52 WS-C2960S-48FPS-L 15.0(1)SE C2960S-UNIVERSALK9-M
* 2 52 WS-C2960S-48FPS-L 15.0(1)SE C2960S-UNIVERSALK9-M
When I try to enable ip sla responder on the stack I get:
%SYS-3-HARIKARI: Process IP SLAs Responder top-level routine exited
I have been able to find a bug in the toolkit. Should ip sla responder be supported on the
stack as above?
Thanks
Lee FlightI can confirm 15.0(1)SE3 still has the bug.
I just tested 15.0(2)SE3 released yesterday in a lab environment and....... (drum roll)..... no more HARIKARI . Hardware were two WS-C2960S-48FPS-L unstacked (one of them with installed stacking module though)
Haven't tried the earlier 15.0(2) (i.e. SE, SE1 and SE2) releases - maybe they work too. -
Gents We have three WS-C2960S-48TS-L swicthes which are working as standalone i want to stack them for proper redudency and efficient network design. I have checked it from cisco website and it says that it can be done. I need to know what i have to do to make them stack....ofcourse cables are required (do they have stacking cables just like 3750 at the back) secondly is there any IOS requirment (minimum)
Theer are 52 ports in total 48 RJ45 and 4XSFP
My core swicth is 4500 which has RJ45 module so can i get RJ45 ethernet SFP for my stack and just plug them in in 4500 ( i need to make the uplink as 4G) will that be achievable ? i am think to run on cable (from esch SFP in stack for each switch once i stack the swicth and make them trunk port-chanel with 4500 core so that i can have 4Gbps uplink???
Thanks guys your opinion has alweays helped meYou need three stack modules for this. The order code is "C2960S-STACK".
Do you need all 144 RJ-45 ports for your user-devices? If not, you can connect the non-SFP ports to the core. That will safe you some money on SFPs.
And remember that a 4-Port Etherchannel will give you 4*1Gig and not 4Gig. -
Catalyst 2960s Stacking with different IOS versions
Hello Forum Team;
When adding a new switch with older ios version to an existing stack (flexstack) does the new switch will be able to join the stack?
Thanks in advanced!Hi,
In a stack/flexstack all the switches should have exact same IOS version, otherwise there will be a version mismatch on the stack and the new switch will not be able to join the stack.
The following Document contains more info:
http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps6406/white_paper_c11-578928.html
Thanks
Ankur
"Please rate the post if found useful" -
Mixed 2960 S/X Stack speed
i have a 2960s 3 switch stack.
i purchased a 2960x switch to add to the above stack.
i plan to upgrade the 2960s stack IOS version to the version on the 2960x switch and then add the new switch to the stack.
i have read that i also need to change the default stack speed with this command "switch stack port-speed 10"
however i didnt understand when to execute the command in my situation.
if i run this on the new 2960X switch before adding it to the stack will the command have affect after joining the stack and having all its config replaced by the stack config?
thanksread
http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960x/software/15-0_2_EX/stack_manager/command_reference/b_stck_152ex_2960-x_cr/b_stck_152ex_2960-x_cr_chapter_01.html#wp3514062886
i my case the existing stack is made up of 3 2960S and i want to add a 2960X.
do i need to execute the above command ? and on which switch/stack -
C2960S-STACK module in a 2960-X switch
Do the 2960S stacking modules work in a 2960-X? The stacking cables are the same part #, even though the description for the 2960-X says Flexstack-Plus.
C2960S-STACK - FlexStack hot-swappable stacking module
C2960X-STACK - FlexStack-Plus hot-swappable stacking module
CAB-STK-E-0.5M - FlexStack stacking cable with a 0.5 m length
CAB-STK-E-0.5M - FlexStack-Plus stacking cable with a 0.5 m lengthNo!
1) 2960-stack moudles fit only 2960s
2) 2960-x fit modules fit only 2960x
3) cables are the same
4) IOS must be the same version. (UPGRADE OR DOWNGADE AS APPROPRIAT
5) for a stack with both 2960s and 2960x there are two command that need to be entered on the 2960-x...1) change the port speed to 10. 2) change the smd to routing. -
hi all,
we have a bunch of 2960-S switches on a site that we want to stack.
my question is, is it ok just to connect the stackwise cable accordingly, boot up the master switch first, backup next, and member last?
or would it be 'best' practice to put the switch x priority y command?
also, all switches have IP addresses for remote management already configured.
do we remove the IP address (for member) and retain only for the master/backup switch?Disclaimer
The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
Liability Disclaimer
In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
Posting
I haven't worked with 2960 stacks, but on the 3750 stacks, preprovisioning allows you to configure ports for switch members not actually active. When the switch is added to the stack, it will immediately use the preprovisioned configuration.
The stack member to be added, can be completely "clean" or it might be "clean" but configured with a stack member number. (The former, I recall, will take the first available set of preprovisioned information, the latter will take only the preprovisioned information for the member number set.) -
2960S PoE switch into a non-PoE stack
I have two 2960 Stacks
Stack # 1 is a PoE stack with two WS-C2960S-48FPD-L with TenGig uplinks running c2960s-universalk9-mz.152-1.E.bin.
Stack #2 is Non PoE stack with three WS-C2960S-48TS-L running c2960s-universalk9-mz.150-2.SE2.bin.
I need to add an WS-C2960S-24PS-L for additional PoE port capacity. If I add it to Stack #1 I will have three switches in both stacks, and all PoE switches will be part of the same stack. I am just wondering If I can have disparate switch models in the same stack running the same IOS? If I add the new WS-C2960S-24PS-L to Stack #2 I will end up making this stack a 4 switch stack with three non-PoE switches and one PoE switch. If I add the PoE switch to this stack will I have access to the PoE capabilities of that one switch. Again with the question can I have disparate switch models in the same stack running the same IOS?I am just wondering If I can have disparate switch models in the same stack running the same IOS
Yes. You can have a different models of 2960S in a single stack. The main important thing is all members of the stack should have the same IOS version. -
Uplinking Stacked 2960S with Etherchannel
I'm in the process of configuring the uplink of two stacked 2960S to a 3560X that is not stacked.
My plan is to configure 2 ports in each of the stacked 2960S' for a total of 4 Etherchannel members. On the other side, I'd configure the 3560X with a 4 member channel.
Would the configurations below work for what I intend to do?
#Configurations in 2960S Stack members
2960SMaster(config)int range g1/0/1 - 2
channel-group 1 mode active
2960SMember(config)int range g2/0/1 - 2
channel-group 1 mode active
#Configurations in 3560X core switch
3560X(config)int range g0/23 - 26
These configurations are based on article that deals with a similar scenario (except for two sets of stacked 3750's)
http://www.cisco.com/c/en/us/support/docs/switches/catalyst-3750-series-switches/69979-cross-stack-etherchannel.html
Additional questions:
- These configurations assume LACP. Is there a reason not to use LACP here?
- Both sides are set to active, but I've seen it configured also in active-passive. Would I derive any benefit from one approach or the other?
- And finally, the n00b question. Do I use regular Ethernet cable or do I have to use cross-over?- These configurations assume LACP. Is there a reason not to use LACP here?
No reason at all. LACP is the standard and PAGp is Cisco
- Both sides are set to active, but I've seen it configured also in active-passive. Would I derive any benefit from one approach or the other?
Active actively tries to negotiate whereas passive listens for lacp frames. You can use active/active or active/passive, but you won't be able to use 2 passive.
- And finally, the n00b question. Do I use regular Ethernet cable or do I have to use cross-over?
Regular cables should be fine.
The other things you need to keep in mind is that the ports in the channel group need to be configured the same way - speed, duplex, same vlans, etc. in order for them to for an etherchannel.
HTH,
John -
Catalyst 2960S switch stack support?
I have a customer with a new stack of four Catalyst 2960S switches.
Is this configuration supported by Onplus?
I can't seem to figure out the login access and enable access credentials
so that Onplus can backup the configuration of the stack.
Jeff Bright
Bright Systems
Broken Arrow, OKI also have a 2960S stack in my office. I checked my handy OnPlus iPhone App and it shows backup, restore, and firmware all equal 1 which I recall correctly means backup is supported. I'll double check when I get into the office to ensure backups are actually working.
Sent from Cisco Technical Support iPhone App
Maybe you are looking for
-
Cannot get ITS SSO to work with EP6 Sp15
I am having problems with SSO from EP6 to ITS (my EP5 to the same ITS works great). This is what I have done..... It is a R3 4.6C system so I wondered if any patches were needed....however I have got SSO working with the SAP Win GUI - so this tells m
-
Dear All How to enable free item check in Purchase Order .The field Free item is Gray in Purchase Order Regards sandeep
-
What usb auto switch is compatible with OSX and Windows for sharing the same printer
I just bought a new iMac for myself to replace my old Dell PC. My husband still has his PC with Windows Vista and our work stations are set up to share the same MFC with a Belkin auto switch. Unfortunately that software is not compatible with my O
-
Indexing email addresses in Apple mail
I have newly installed the system and imported again my older previous email folders with thousands emails. Is there any way to "index" email addresses that when writing new emails, the email address will be automatically filled in when starting writ
-
Is there a phone number I can call from Australia where I can get over the phone assistance.
I have spent the past hour on my PC going around in circles. I have a deactivation problem that I need sorted ASAP. Old computer unusable.