2013年12月31日星期二

How to connect Cisco 3750 to 2960s via fiber

We have a switch stack of 4 Catalyst 3750 switches and I will be running about 200 ft of fiber  SFP MM Duplex from one of those switches(switch A) to a brand new Cisco 2960 (switch B).   I have never done anything like this before so I am very excited and a little nervous. 

Switch B is a managable switch but I don't want to manage it, I need it to be a dummy switch to pass through data or should I manage it will that give me faster access

Switch A is an internal switch that is not hooked up to the internet.

Can someone help me with this or point me to a place I can find more information about doing this type of connection.....

The solution:
1 Connecting Fiber to another switch isn't much different then if you ran copper. They are just to different mediums. If you want to just want it to be  a dummy switch then just make sure the two ports you are connnecting are access ports on the same vlan (assuming you have multiple on the switch stack). By default all of the ports on the 2960 will be vlan 1, so change the the fiber and all of the other ports to the appropriate vlan that is on the 3750. And manage the switch. This way you can access it remotely and make any changes that come up later, instead of having to be locally at the switch.

2 You are on right track, please make sure followings;

if you are using MM fiber than USE MM module for Cisco switches
if you are using SM fiber than USE SFP module for Cisco switches

if you dont have VLAN in your network, you can ne need to do any configration on switch, but if you have you may need to assign IP on C2960G WS-C2960S-24PD-L . see below for VLAN or Etehr channel configration

For VLAN
http://www.cisco.com/en/US/tech/tk389/tk815/technologies_configuration_example09186a008015f17a.shtml

For Etherchannels
http://www.cisco.com/en/US/tech/tk389/tk213/technologies_configuration_example09186a0080094953.shtml

use the correct SFP modules. Make sure that the SFP module is MM and not SM. Also, yes, if you need to manage the switch create a VLAN interface and assign an ip address on the subnet that the 3750's vlan reside on.
So:
interface vlan x
ip address x.x.x.x 255.255.255.0 (Assuming)
no shut

2013年12月30日星期一

Why the Cisco 2960S Randomly Reboots

Having a strange problem, my catalyst Catalyst 2960 switches keep randomly restarting. They are stacked and are running IOS version 12.2(58) SE2. I also can't find a crash log file in the flash directory after they randomly reboot.
                 
Ive checked the show version with no avail, but it does indicate a possible power issue:
System returned to ROM by power-on
System restarted at 09:11:13 PAC Tue Nov 15 2011
System image file is "flash:/c2960s-universalk9-mz.122-58.SE2/c2960s-universalk9-mz.122-58.SE2.bin"

Im not too sure, but the switch WS-C2960-48TT-L is connected to a ups, that a few other switches are also connected to and they did not go offline during the time the switch did.
I am not sure whats going on, as I have nothing to base it on.

The solution:
Try changing the power lead or connecting it to a different source.

The line "System returned to ROM by power-on" usually means that the switch thinks it reset due to power loss.  So you may have a power issue, or possibly the power supply in the switch is bad.  Can you swap the stack master roles so the other switch is master?  It's unlikely that both switches have bad power supplies, so with the other switch running the stack, you should be able to look at the logs and see if the first switch looses power alone, or if both switches go down and come back up at the same time.

You may also try moving the switch to a different port of the UPS.


2013年12月25日星期三

Gateway to Gateway VPN Tunnel. 2 X Cisco RV082

Hoping someone can help me, been struggling for a few days.

Trying to establish a Gateway to Gateway VPN Tunnel with the below hardware

Linksys WAG300g Bridged to Cisco RV082 - HQ
Huawei HG655B Home Gateway Bridged to Cisco RV082 - Branch

HQ

Local Group Setup:
Local Security Gateway Type: IP Only
IP Address: xxx.xxx.xx.xx (WAN IP) - Can ping from remote pc.
Local Security Type: IP (For testing)
IP Address: xxx.xx.1.200

Remote Group setup:
Remote Security Gateway Type: IP Only
IP Address: xxx.xxx.xx.xx (WAN IP) - Can ping from remote pc.
Remote Security Type: IP (For testing)
IP Address: xxx.xx.2.101

IPSec Setup: All Default

Keying Mode: IKE With Pre Shared Key
Phase 1 DH Group: Group 1 - 768 bit
Phase 1 Encryption: DES
Phase 1 Authentication: MD5
Phase 1 SA Life Time: 28800 seconds
Perfect Forward secrecy: Checked

Phase 2 DH Group: Group 1 - 768 bit
Phase 2 Encryption: DES
Phase 2 Authentication: MD5
Phase 2 SA Life Time: 3600 seconds
Preshared Key: xxx
Min Preshared Key Complexity: Checked | Enabled

Aggressive Mode: Checked
NetBIOS Broadcast: Checked and Enabled on NIC
Dead Peer Detection: Checked

Branch is set exactly the same though obviously Local and Remote Groups info switched.

No Antivirus or firewalls enabled on either pc to test. Disabled Firewall on RV082's as well to eliminate any potential issues.

I can get a VPN connection, but cannot ping the LAN IP of the RV082 on either side.
Cannot access any local resources on either end either.

What am I missing here?  Both Pc's are Win 7 Pro 64bit if that makes any difference at all. Both RV02's have Public Ip's which I can ping.

The solution:
You would try changing from Local Security Type: IP to subnet and also uncheck aggressive mode.

Customers interested in purchasing Cisco switch or the price, please refer to below links, here are some popular switch for you:


2013年12月23日星期一

How to upgrade cisco 2960 from 12.x to 15.x

Question: I want to upgrade my production switches 2960 WS-C2960S-48FPS-L  from ver 12.2 to the latest firmware 15.0
Do I have to pay for the firmware upgrade or is it free? If there any processes related to payment can someone step through it for me.

Answer:
If you have a Smartnet Maintenance contract on your switches, it's free (or rather it's included in the contract). If you don't have a contract, you'll have to pay. Contact a Cisco cAuthorized Reseller for pricing.
"Smartnet Maintenance contract" is a contract with Cisco which allows you to obtain support from Cisco along with IOS upgrades.
It can be obtained directly through Cisco directly or through an Authorized Reseller.

Catalyst 2960 and 2960-S switches are the leading fixed-configuration Layer 2 edge access switches, 2960 is FE access switch while 2960-S most ports are GE. The Catalyst 2960-S Series Switches are stackable switches and support POE+ function. 3Anetwork.com keeps stock for most 2960 and 2960-S LAN base switches. Among all Cisco Catalyst 2960 switches, WS-C2960-24TT-L and WS-C2960-24TC-L are best selling models. Among all Cisco Catalyst 2960S switches, WS-C2960S-24TS-L and WS-C2960S-48TS-L are best selling models. 3Anetwork.com offers best Cisco 2960 Price, Cisco 2960S (2960-S) Price, ship to worldwide.
Telephone: +852-3069-7733


2013年12月19日星期四

How to enable flowcontrol on Cisco 2960

How to enable flowcontrol on Cisco 2960, the follwers are the two question about it, find the solution on your Cisco 2960 to enable the flowcontrol.
Question 1: I have 2 Cisco c2960 switches  that I'm setting up and I'm having some issues getting flow control to be active on all ports under 1 vlan.
My setup is to have 2 vlans on each switch and enable flow control  on each of my vlans.
what ever command  I typo it dose not like it.
Can someone give me the correct command line for this model ?

Answer 1: The Catalyst 2960 switch accepts received pause frames but cannot send them. The flowcontrol send command is not supported on the Catalyst 2960 switch.
The Catalyst 2960 switch rejects the command, and this message appears:
Switch(config-if)# flowcontrol send
desired
                              ^
%Invalid input detected at `^' marker
Command  Purpose 
Step 1 
 configure terminal
 Enter global configuration mode
Step 2 
 interface interface-id
 Specify the physical interface to be configured, and enter interface configuration mode.
Step 3 
 flowcontrol {receive} {on | off | desired}
 Configure the flow control mode for the port.
Step 4 
 end
 Return to privileged EXEC mode.
Step 5 
 show interfaces interface-id
 Verify the interface flow control settings.
Step 6 
 copy running-config startup-config
 (Optional) Save your entries in the configuration file.
To disable flow control, use the flowcontrol receive off interface configuration command.
Question 2: I met a strange problem after enabling flowcontrol in 2960s.
my enviroment,
- 2 cisco 2960s 24ts-l (WS-C2960S-48TS-L )have been created a stack
- IOS is 12.2(58)se2
- all ports have been enabled flowcontrol receive dersied
via show flowcontrol, I can see each Gigabyte Port have been enabled "flowcontrol receive desired" but, when I do the following tests
- connect equallogic ps4000xv to the port 21, I found the status of port is "input flow-control is off"
- connect one server with Broadcom Gigabyte Network adapter, which has been enable TX ON RX ON, or Auto, the status of the port is still  "input flow-control is off"   
I guess, the port status should be ""input flow-control is on". Test them with another port, I got the same result. why?
I attached the config file and the port status file.

Answer 2: The flowcontrol receive desired command enables the switch to utilise any pause frames it receives from your servers.
The 2960 cannot send pause frames, hence your servers report 'input flow-control is off'.

If your servers are enabled to send pause frames to the 2960, then flowcontrol should work in that direction only.

2013年12月16日星期一

Where does the Cisco IOS switch store VLAN information

I've got a 2960 switch WS-C2960S-48LPS-L  running IOS 12.2(25).  It has an access point connected to it but guests were unable to connect to one of the wireless networks the AP provides.

One of my techs looked into it and said that VLAN 12 was not configured on the Catalyst 2960 ; VLAN 12 is the VLAN the guest wireless network uses.  He just did "vlan 12" at a conf t prompt and it all woke up.  He didn't add any interfaces to VLAN 12.  So question 1 is this: VLAN 12 exists on the AP, and the switch port the AP is on is configured to trunk.  Why was it necessary to create VLAN 12 on the switch?  None of the resources accessed by users of the guest wifi are on that switch, they just need to use its backbone to our internet router, which is also configured to trunk.

Now I can see VLAN 12 in there when I do a "sho vlan", but I can't see the command that creates VLAN 12 in the running config.  So question 2 is, when the switch reboots or whatever, how does it know to re-create VLAN 12?  Is the info stored somewhere other than the running-config?
Asking because I can envision a time when the switch dies and we go to swap in a replacement by throwing a copy of the old config on it, then sit around scratching our heads because "everything should be identical" when really the VLAN is not being created.

The answer:
The actual vlan info is kept in a file called vlan.dat  .  Depending on the device this is normally in nvram.
What is kept in the startup-config file related to VLAN's are the layer 3 definitions for the svi if you have any.
 There can be two parts of a VLAN definition.  The VLAN itself, which is what is in the vlan.dat file I referenced early.  This allows the vlan to exist as a layer 2 resource. 
Then there is the svi, which is the virtual interface which is required if you want that vlan to exist at the layer 3 level.    A layer 3 interface for the vlan is not always required.
In a well-designed network you would push the Layer 3 outward and never have a lot of switches with the same vlans. So VTP is a tool to manage a badly-designed network. Even when I've had to push vlans to a number of switches, I prefer to manage it manually- because when VTP isn't used correctly (i.e. the default "server" mode is left in place on all switches), removing a vlan on one switch removes it everywhere!

And yes, you have to add the vlans to the switch, but that had to be done anyway. Setting VTP to transparent means that the vlan configuration is stored as part of the regular config where it can easily be recreated on a replacement switch.
More about the Cisco 2960 FAQ, please visit:
http://ciscoswichfaq.weebly.com/

2013年12月4日星期三

Etherchannel Configuration for Cisco 2960 WS-C2960S-48TS-L

I'm a software guy and new to setting up switches. I was told I can setup an Etherchannel on my 2 new Cisco WS-C2960S-48TS-L switches. I was told I can connect both switches together with just 1 cable, or setup Etherchannel and use 2 cables for double the bandwith. I'm not sure how to proceed. I've done quite a bit of research. Here is what I have come up with but not tried out yet. I'm not sure if what I have is even correct, and if I should use trunk or access or what mode to use. Just want to connect these 2 switches using 2 cables.

Switch1> enable
Switch1# configure terminal
Switch1(config)# interface range GigabitEthernet1/0/47-48
Switch1(config-if-range)# switchport mode trunk
Switch1(config-if-range)# channel-group 1 mode active
Switch1(config-if-range)# end

Switch2> enable
Switch2# configure terminal
Switch2(config)# interface range GigabitEthernet1/0/47-48
Switch2(config-if-range)# switchport mode trunk
Switch2(config-if-range)# channel-group 1 mode desirable
Switch2(config-if-range)# end

The solution:
The choice between trunk and access mode is simply whether or not you intend to pass multiple vlans between the switches. In most situations links between switches are configured as trunks, even if there is only a single vlan because it allows for a non-disruptive ability to add vlans in the future.

I would also recommend going with the port channel for both bandwidth and failover abilities assuming you have the ports to spare. Also, there is nothing wrong with using the "desirable" mode for the port channel, however, I would recommend going with "active" mode instead on both ends. The difference is that desirable uses a Cisco proprietary protocol and active uses a standards based protocol. There is no advantage in either protocol when dealing with Cisco switches, but without any advantage I would suggest going with the standards based protocol.

One thing to bear in mind when it comes to etherchannel bandwidth. A single session, such as a file transfer, will only use a single physical port in the etherchannel. This means that the bandwidth for a single session will never exceed the bandwidth of a single link within the etherchannel. You can have multiple sessions occurring simultaneously that utilize the full bandwidth of all links, but the individual session can only use one link.

Port-channel and etherchannel are interchangeable terms in the Cisco world. The configuration looks good. One thing you will have to check after running those commands is the actual port-channel configuration. Depending on the code version you will either need to configure the port-channel for trunk mode, or you might not need to do anything. So after running the commands, look at the running configuration and you'll see an interface port-channel 1 which should be configured as a trunk. If not,

config t
interface port-channel 1
switchport
switchport mode trunk
no shut

and you should be all set.
Other good commands are "show interface port-channel 1", and "show etherchannel summary". These will verify that the port-channel is up and both interfaces are members.

One more thing. Depending on the switch model and code version, you might also need to run the command "switchport trunk encapsulation dot1q" to each trunk interface including the port-channel.
Customers interested in purchasing Cisco 2960 or the price, please refer to below links:
http://www.3anetwork.com/cisco-catalyst-2960-switches-price_c39



2013年12月2日星期一

Do Cisco WS-C2960S-48LPD-L Support 1 Gigabit SFP modules

10 and 1 Gigabit Ethernet uplink flexibility with Small Form-Factor Pluggable Plus (SFP+), providing business continuity and fast transition to 10 Gigabit Ethernet

Comparison:
WS-C2960S-48LPD-L - support x2 1Gigabit Ethernet SFP+ ports or (x2 10Gigabit Ethernet)
WS-C2960S-48FPS-L - supports x2 1Gigabit Ethernet SFP ports

WS-C2960S-48LPD-L
48 Ethernet 10/100/1000 PoE+ ports
370W PoE capacity
2 10 Gigabit Ethernet or 2 1 Gigabit Ethernet SFP+ uplink ports
Optional Cisco FlexStack stacking support
LAN Base image

List price: US$6,995.00
Discount Price: US$3,045.00
You Save: US$3950.00 (56% off)

3Anetwork.com wholesales Cisco Catalyst 2960 switch WS-C2960S-48LPD-L, 2960S-48LPD-L, 2960S-48LPD, original new Cisco WS-C2960S-48LPD-L at competitive price. In most cases, we can deliver WS-C2960S-48LPD-L in 2 business days. Simply add Cisco WS-C2960S-48LPD-L to your shopping cart for the best price Catalyst WS-C2960S-48LPD-L. Good discount of Cisco 2960 switch, best Cisco Catalyst 2960 switch WS-C2960S-48LPD-L price, save your money.

Contact information:
Telephone: +852-3069-7733(Hong Kong)
Fax: +852-3069-7731
Email:   info@3Anetwork.com(Sales Inquiries)
Address: 23/F Lucky Plaza, 315-321 Lockhart Road, Wanchai, Hongkong