WS-C2960-24TC-L - %PLATFORM_PM-3-HOSTACCESSFAIL - error

Hello,
I have issue with 3 ports on the switch.
Once I put he following commands under the port I got error message : 
authentication control-direction in
authentication host-mode multi-auth
authentication port-control auto
authentication periodic
authentication timer restart 240
authentication timer reauthenticate server
authentication timer inactivity server
mab
*Jun  7 06:45:18: %PLATFORM_PM-3-HOSTACCESSFAIL: Unable to configure hardware to restrict host access on Fa0/17.  Port may not behave as expected.
*Jun  7 06:45:18: %PM-4-ERR_DISABLE: port-mode-failure error detected on Fa0/17, putting Fa0/17 in err-disable state
I have the same configuration under other ports and I don't have any issue.
When I remove these commands , these 3 ports are working fine.
What's going on ?  Can you help me to find the root cause ? 
The device is WS-C2960-24TC-L, Version 12.2(58)SE2
The current configuration of port is here : 
interface FastEthernet0/17
 switchport access vlan 274
 switchport mode access
 switchport nonegotiate
 switchport voice vlan 1293
 speed 100
 duplex full
 mls qos trust dscp
 spanning-tree portfast
Thank you,
Jan

Hi Kartnik,
I found some bugs related to these error message and one is describing our issue : 
CSCui14520
Symptom:
Several ports which are 802.1X-enabled port go into err-disable intermittently.
Jan 21 13:56:09: PLATFORM_PM-3-HOSTACCESSFAIL Unable to configure hardware to restrict host access on Fa0/9. Port may not behave as expected.
Jan 21 13:56:09: PM-4-ERR_DISABLE port-mode-failure error detected on Fa0/9, putting Fa0/9 in err-disable state
Workaround:
"shut" / "no shut" the port
Last Modified:
Apr 7,2014
Status:
Terminated
Severity:
3 Moderate
Product:
Cisco Catalyst 2960 Series Switches
Known Affected Releases: (1)
12.2(53)SE2
Known Fixed Releases: (0)
No release planned to fix this bug

Similar Messages

  • Can not config full duplex on Gi0/1 of WS-C2960-24TC-L

    Hi,
    I have a problem when connect two modules GLC-FX-100FE to two switch WS-C2960-24TC-L as below:
    When I plug each SFP module like above to each switch WS-C2960-24TC-L to SFP slot (gigabit 0/1: dual purpose port), then the duplex become to Haft.
    So, I can not configure them to full duplex as other copper ports.
    But when I use two switch WS-C3560G-24TS-S, I can do this.
    OS version of WS-C2960-24TC-L I am using is: c2960-lanbasek9-mz.122-55.SE7.bin, I think it is new.
    Please help me solve this problem.
    I have to explain to our customer in the next morning. You know, I am Vietnamese and in Vietnam, the time is 22:40 pm,
    Thank you so much.

    Hi,
    in interface configuration mode you have to configure
    media-type sfp
    Afterwards you can configure media-specific parameters like the duplex mode.
    Note: Changing the media-type will cause an outage for a couple of seconds.
    Hope that helps
    Rolf
    http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_55_se/command/reference/cli1.html#wp13646909

  • Switch WS-C2960+24TC-L not recognized by CNA

    Switch WS-C2960+24TC-L not recognized by Cisco network assistant. Switch is running on IOS 15.0(2)SE5, CNA 5.8(8.9). CNA show switch as wireless klient.
    I tried upgrade but not help.

    Yes 6.1 supports it , 5.8 does not
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_network_assistant/version6/relnotes/ol32368.html
    With Cisco Network Assistant 6.0, you can manage these devices:
    Catalyst 2960-Plus switches
    – WS-C2960+24PC-L
    – WS-C2960+24LC-L
    – WS-C2960+48TC-L
    – WS-C2960+24TC-L
    – WS-C2960+48PST-S

  • Why choose Cisco Catalyst WS-C2960-24TC-L Switch ?

    As the new family of fixed-configuration standalone devices, Cisco 2960s series intelligent Ethernet Switches provide desktop 10/100 Fast Ethernet and 10/100/1000 Gigabit Ethernet connectivity for entry-level enterprise, mid-market, and branch office networks
    to enable enhanced LAN services.
    Why choose cisco WS-C2960-24TC-L ?
    The Cisco Catalyst WS-C2960-24TC-L has hardware enhancements for network managers, including configurations featuring dual-purpose (alternatively wired) uplinks for Gigabit Ethernet, allowing the network manager to use their Cisco switches as either a copper
    or a fiber uplink.

    Agreed! WS-C2960-24TC-L has hardware enhancements for network managers, and if you want to buy it, here 3anetwork.com  64%
    off, USD 460 ! 

  • Cisco WS-C2960-24TC-S switch connectivity problam

    I configured my cisco WS-C3750X-12S-S with ip routing and it is working properly. i configured  a cisco  WS-C2960-24TC-S  switch and connect both switches via Fiber. each switches can communicate with other end. i can connect to C3750X from my local WAN, all interfaces are working properly but i cant connect to L2 switch from WAN. please help me.
    (test result pages attached)

    Dear
    the fast Ethernet interface on the switch is meant only for OOB (out of band management) so this way you will not be able to route traffic. It will not communicate to any other subnets apart from the connected subnet. Its better you create a SVI in the switch and use that SVI for management purposes.
    regards
    Najeeb

  • Ws-c2960-24TC-S IOS update

    Hi
    Iam trying to update my WS-C2960-24TC-S IOS from version c2960-lanlitek9-mz.122-55.SE5.bin to higher version but new IOS is not able to boot .any body have a solution for that.
    Thank you

    Hello nasser1965
    Can you please tell me which one image are you updating in theWS-C2960-24TC-S?
    Regards,
    Mukesh Kumar
    Network Engineer
    Spooster IT Services

  • WS-C2960-24TC-L vs WS-C2960-48TC-L

    I want to buy cisco c2960 series switch which support voice, video, data, and highly secure access. My friend suggest me try to use
    WS-C2960-24TC-L or WS-C2960-48TC-L which are equipped with Ethernet 10/100 ports and 2 dual-purpose uplinks. But i don't know what's the difference between them ?

    24TC means it's a 24 port, non-PoE.
    48TC means it's a 48-port, non-PoE.

  • Can i upgrade this switch WS-C2960-24TC-L with lastest IOS 15.0(2)SE6.

    Can i upgrade this switch WS-C2960-24TC-L with lastest IOS 15.0(2)SE6. 

    Yes I see that this is supported on this switch. Upgrade to this switch should not face any problem.
    Suggested
    12.2.55-SE9(MD) 
    Latest
    15.0.2-SE6(MD)
    12.2.58-SE2(ED)
    http://software.cisco.com/download/release.html?mdfid=279963375&flowid=2547&softwareid=280805680&release=12.2.55-SE9&relind=AVAILABLE&rellifecycle=MD&reltype=latest
    HTH
    Regards
    Inayath

  • Cisco Catalyst 2960 - Model WS-C2960-24TC-S

    Hello,
    I'm not an everyday networking guy - but have been taksed with getting these ready for an install. Our firm has some "templates" we use to help me along bu thtey are fo rthe model without the "S" at the end. Firmware needs to be at 12.2 (58) SE2 for special reasons.
    I have 4, two are to be Level 2, two are to be Level 3. Each has 24 ports, plus 2 RJ45 GIG ports and 2 Fiber Ports.
    Questions are:
    The Level 2's need to use the fiber to connect long distance to one unit.
    - What shoult the trunking ports on these be? 23 & 24? Forget the 2 GIG prots for trunking as one is used for something else?
    - What would be the time zone for California / Cisco wise?
    There's a lot more questions on this - but this is my starting point. I apologize that I'm not up on this, hope you'll provide some slack / time :-)
    Thank you ...

    Dear
    the fast Ethernet interface on the switch is meant only for OOB (out of band management) so this way you will not be able to route traffic. It will not communicate to any other subnets apart from the connected subnet. Its better you create a SVI in the switch and use that SVI for management purposes.
    regards
    Najeeb

  • Cisco WS-C2960-24PC-S no LANBASE image?

    Hi
    I have two swichtes
    1 x WS-C2960-24PC-S with SW version 12.2(58)SE2 and SW Image C2960-LANLITEK9-M
    1 x WS-C2960-24TC-L with SW version 12.2(58)SE2 and SW Image C2960-LANBASEK9-M
    At the WS-C2960-24TC-L with LANBASE Image it`s possible to activate sdm prefer lanbase-Routing.
    At the WS-C2960-24PC-S I also need this Feature but I can`t activate it because of the LANLITE Image.
    Is there any LANBASE Image for WS-C2960-24PC-S to activate sdm prefer lanbase-Routing also on this Switch?
    BR
    Michael

    Hi,
    You can't upgrade from lanlite to lanbase.
    Q. Can I upgrade or downgrade a Cisco Catalyst 2960 Switch between the LAN Base and LAN Lite IOS images?
    A. No. Cisco Catalyst 2960 Series Switches cannot be upgraded from LAN Lite to LAN Base and cannot be downgraded from LAN Base to LAN Lite.
    http://www.cisco.com/c/en/us/products/collateral/switches/catalyst-2960-series-switches/qa_c67-577519.html
    HTH

  • Can't get device information: Operation already in progress

    Hello,
    I am trying to connect my Microsoft Notebook Mouse 5000 and having a bit of trouble.  I am following the instructions I found here: https://wiki.archlinux.org/index.php/Bluetooth_Mouse
    I have all the packages installed and am able to search for and find my mouse.  The problem is when I try to connect to it.  I have tried using both these commands
    hidd --connect <bdaddr>
    hidd --show
    Both of them give me the same error message.  "Can't get device information: Operation already in progress"
    All the information I have found on this error just says to use the first command, which did not work.
    Any ideas on where to go from here?
    Thanks in advance.

    Hi,
    If you have the shadow directory function running (http:///help/lms_admin/index.html?config_EnblDsblShadowDir.html) then you will have a group of flat config files that are not linked with LMS in any other way.  That is to say that the files generated are simply text files residing within the shadow directory that should mirror what you have in the database.
    This function is one way.  LMS generates the file upon config change to 'shadow' what is in it's database.
    In regards to the C2960 24TC-L,  you need to obtain the sysObjectID for the device.  For example: 
    WS-C2970G-24TS has a sysObject ID of 1.3.6.1.4.1.9.1.527.
    If you navigate to the Device Status Page: http://:1741/cwportal/group/lms/lms-deviceadmin
    There you will find 'Supported Device Finder' where you can enter the device [IP,Display Name, etc].
    You can also navigate to Device Center, look for the star icon on the same line as 'Device Status' and click on it. Then choose 'SNMP Walk'.  This will return the OID in numerical format.
    Thanks

  • Switch configuration urgent help (edge and core)

    hi
    i have new project in with the bellow product :
    20 X WS-C2960-24TC-S
    2 X WS-C3750X-48T-S
    2 X WS-C2960S-24TS-S
    i need to configure this switch in order to work without having vlan, first the 2 core switch for redundancy, then each catalyst switch 2960(edge Switch) connected to the two core with 2 uplink each uplink will be connected to single core switch(i have 2 core switch and i want to configure it in stack mode redundancy) 
    i need help to configure this switch to work perfectly with each other in best redundancy mode any configuration for this switch will be very helpfull for me
    thank you

    Hey,
    This is a very open question but i believe the document below is a good point to start:
    http://www.cisco.com/c/dam/en/us/td/docs/solutions/Enterprise/Small_Enterprise_Design_Profile/chap2sba.pdf
    HTH.
    Regards,
    RS.

  • ME 3400 PACKET LOSS

    e3400 packet loss
    I have a me3400 connected as follows:
    in port G1 / 0 fiber optic switch connects 7 WS-C2960-24TC-s.
    The switches are running vlans 2960 and serves to intervlan ME3400 routing.
    All of the GTW vlans are defined in the ME3400, in addition this does dhcp for network VLANs.
    In the port f0 / 1 is defined as non-me3400 swichport and create an interconnection network with a firewall that outputs the internet
    in ports f0 / 5 f0 / 6 is set up a vlan me3400 additional servers
    problem:
    When a machine that is in the vlans, located in any switch in 2960, seeking access to the servers connected to the f0 / 5 f0 / 6 has lost and slowly, the same is true if you want to access the internet.
    Tests done from a PC on the vlans.
    If it pings with size 100 to the servers or the firewall is not a problem.
    but if you increase the size of the datagram to 500 or 1000 are lost. \
    If ping with size of 1000 from a PC to me3400 no problem.
    From me3400 If you ping the router or 100 servers with no loss size, but if it increases to 500 or more lost packets again has all of the above results that both the internet as accceso to this rather slow servers . It is worth mentioning that the vlan voip telephony and servcio not a problem.
    Assistant to the configuration of me3400
    sh ver
    Switch Ports Model SW Version SW Image
    * 1 26 ME-3400-24TS-A 12.2(55)SE ME340x-METROIPACCESSK9-M
    CPU utilization for five seconds: 9%/3%; one minute: 10%; five minutes: 9%
    SWICHT-MAIN#sh run
    Building configuration...
    Current configuration : 5733 bytes
    version 12.2
    no service pad
    service timestamps debug uptime
    service timestamps log uptime
    no service password-encryption
    hostname SWICHT-MAIN
    boot-start-marker
    boot-end-marker
    enable secret 5 $1$EBwk$LIAacdQj3VxvaNUUiBuzk1
    no aaa new-model
    system mtu routing 1500
    ip routing
    ip dhcp excluded-address 192.168.150.2 192.168.150.33
    ip dhcp pool wifi-alumnos
    network 192.168.152.0 255.255.255.0
    default-router 192.168.152.1
    dns-server 190.4.6.194
    ip dhcp pool telefonos
    network 192.168.151.0 255.255.255.128
    default-router 192.168.151.1
    ip dhcp pool wifi-administrativa
    network 192.168.153.0 255.255.255.128
    default-router 192.168.153.1
    dns-server 190.4.6.194
    ip dhcp pool AP+SIN-IP
    network 192.168.150.0 255.255.255.0
    default-router 192.168.150.1
    crypto pki trustpoint TP-self-signed-2032354048
    enrollment selfsigned
    subject-name cn=IOS-Self-Signed-Certificate-2032354048
    revocation-check none
    rsakeypair TP-self-signed-2032354048
    crypto pki certificate chain TP-self-signed-2032354048
    certificate self-signed 01
    30820244 308201AD A0030201 02020101 300D0609 2A864886 F70D0101 04050030
    31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
    69666963 6174652D 32303332 33353430 3438301E 170D3933 30333031 30303031
    30335A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
    4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 30333233
    35343034 3830819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
    8100EC3D 75F8B980 C2788415 51766BB5 17CA2AFC 6FA69FE7 E1CCF252 A82EFFE6
    1B2A4B25 F4B93A0F BA1DE932 FEFDA3E6 B2B8A20C 6322D58F 1164F87A 0AC837B3
    E602E824 9E692394 F616E907 6779C8C8 12111E3B C8F3BF57 1ED89E10 76767BB0
    7658715F B95F2D47 B7986E5B DE1A8C7C 71358900 1A9B7F00 0845E024 170B6031
    73650203 010001A3 6C306A30 0F060355 1D130101 FF040530 030101FF 30170603
    551D1104 10300E82 0C535749 4348542D 4D41494E 2E301F06 03551D23 04183016
    8014D21E 00624A3E A7974522 3D33F971 714928BC 412A301D 0603551D 0E041604
    14D21E00 624A3EA7 9745223D 33F97171 4928BC41 2A300D06 092A8648 86F70D01
    01040500 03818100 BC45CDE9 CD7B23D8 44B1E597 70D088D6 19935AB0 D8D52735
    5BFEC71B C8D688BA 76425E3F C220BAC7 D076C4C1 3EA78927 D35A8CF6 228F69AD
    EDB74205 897C32E4 645B788C F20F8247 26DB7755 B280E433 B8BA112D 68510F82
    BA44600E DF4A316E C3928098 440870B1 028677FF AF6CBA07 1B66200A EC57221E
    1C934403 9900B785
    quit
    spanning-tree mode rapid-pvst
    spanning-tree extend system-id
    vlan internal allocation policy ascending
    vlan 2-6
    ip tcp mss 1430
    class-map match-any ping-class
    match access-group 101
    policy-map ping-policy
    class ping-class
    police cir 1000000
    interface FastEthernet0/1
    description HACIA FORTINET
    port-type nni
    no switchport
    ip address 192.168.149.2 255.255.255.252
    ip accounting output-packets
    ip tcp adjust-mss 1430
    service-policy input ping-policy
    interface FastEthernet0/2
    switchport trunk allowed vlan 1-4
    switchport mode trunk
    service-policy input ping-policy
    interface FastEthernet0/3
    switchport access vlan 4
    switchport trunk allowed vlan 1-4
    service-policy input ping-policy
    interface FastEthernet0/4
    switchport access vlan 5
    switchport trunk allowed vlan 1-5
    service-policy input ping-policy
    interface FastEthernet0/5
    switchport access vlan 6
    service-policy input ping-policy
    interface FastEthernet0/6
    switchport access vlan 6
    service-policy input ping-policy
    interface FastEthernet0/7
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/8
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/9
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/10
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/11
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/12
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/13
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/14
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/15
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/16
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/17
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/18
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/19
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/20
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/21
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/22
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/23
    shutdown
    service-policy input ping-policy
    interface FastEthernet0/24
    shutdown
    service-policy input ping-policy
    interface GigabitEthernet0/1
    port-type nni
    switchport mode trunk
    interface GigabitEthernet0/2
    port-type nni
    switchport mode trunk
    interface Vlan1
    description LAN EQUIPOS SWITCH Y APS
    ip address 192.168.150.1 255.255.255.192
    interface Vlan2
    description RED TELEFONOS IP
    ip address 192.168.151.1 255.255.255.0
    interface Vlan3
    description RED WIFI ALUMNOS
    ip address 192.168.152.1 255.255.255.0
    interface Vlan4
    description RED WIFI ADMINISTRATIVA
    ip address 192.168.153.1 255.255.255.0
    interface Vlan5
    description RED LAN CABLEADA
    ip address 192.168.154.1 255.255.255.0
    interface Vlan6
    description LAN HOTELES Y PAGINA WWW
    ip address 192.168.155.1 255.255.255.248
    ip http server
    ip http secure-server
    ip classless
    ip route 0.0.0.0 0.0.0.0 192.168.149.1
    ip sla enable reaction-alerts
    access-list 101 permit ip any any
    line con 0
    line vty 0 4
    password
    login
    line vty 5 15
    login
    end

    Have you try to remove the service-policy from the interfaces or increase the CIR?

  • 2960 Plus VLAN Interface

    Hi, i have a 2960 which i need to replace as it is now end of life, the replacement Cisco recommendes is the WS-C2960+24TC-L which is one of the new 260 Plus models, can you tell me if you can create a VLAN interface on this switch as it states that this is a layer 2 switch only??
    Thanks

    Yes, you can create VLAN interfaces.

  • Change default username on Cisco 2960

    Hi! It is possible to change de default username "admin" from Cisco 2960?
    Ports  Model              SW Version              SW Image
    WS-C2960-24TC-L    12.2(35)SE5             C2960-LANBASEK9-M

    Hello,
    If you have console access, please try the following:
    configure terminal
    ##### Create a new username/password pair ############
    username priv 15 password
    ##### Configure HTTP access using local username ######
    ip http authentication local
    ##### Configure telnet access using local username #####
    line vty 0 4
    login local
    exit
    If you want to delete a username, please use the following command:
    no username
    Hope this helps.
    Regards,
    NT

Maybe you are looking for

  • How can I get an ImageIcon back from a JToggleButton...

    When I create a JToggleButton I have to create an ImageIcon and pass it to the constructor. e.g. JToggleButton toggleButtonA = new JToggleButton( new ImageIcon( "images/A.gif" ) ); But when I want to get that ImageIcon back, all I can find in the doc

  • How to get "clear passwords" on WGM

    When adding a user or editing an existing one, there is the problem that password fields (accounts section, tab "general") just show points (*) instead of the real password. I find this annoying, since there is definitively nobody that looks over my

  • MS TS RemoteApp Programs Command-line Parameters (%temp% or %appdata%)

    Hello, We are trying to get an in house Application published to the TS RemoteApp Programs. We are using a logon script that places the a cmd file in the users %temp% or %adddata%.  We are using this so that there is no file locks that occur. Then we

  • Standard text translation

    Hi, i have created Form in that i used Standard text /:  INCLUDE ZTEST1 OBJECT TEXT ID ST LANGUAGE EN. but this form will be Used in 4 languages as Germoney italy.. Now i need to translate the standard text accordingly please let me know how about do

  • Write dynamic box using sapscript

    I would like to write two box layout. but each box layout are variants, so i can wirte a fixed height. how can i when the first box is finished, then close the bottom line, and the start to write second box and the close. Thanks!