顯示具有 cisco 標籤的文章。 顯示所有文章
顯示具有 cisco 標籤的文章。 顯示所有文章

2026/03/02

有台 CISCO UCS C240 M5S 的HD最近壞了

換新之後 smart 捉不到資料了

# smartctl -i /dev/bus/0 -d megaraid,2
smartctl 7.4 2024-10-15 r5620 [x86_64-linux-6.17.13-1-pve] (local build)
Copyright (C) 2002-23, Bruce Allen, Christian Franke, www.smartmontools.org
Smartctl open device: /dev/bus/0 [megaraid_disk_02] failed: INQUIRY failed

看了一下是firmware比較新





等待原廠回應如何解決

2019/10/03

最近才發現cisco 6504吐出來的netflow沒有包含 tcp flags的資料
昏到

https://www.cisco.com/c/en/us/support/docs/switches/catalyst-6500-series-switches/70974-netflow-catalyst6500.html

2018/08/23

今天早上 6:00收到cisco server發出的告警 OS 也當了

Server HostName:C240-
 Severity: major
 Fault Code: F0174

 Problem Cause: equipment-inoperable
 Entity DN: sys/rack-unit-1/board/cpu-2
 Description: P2_PROCHOT: Processor 2 is operating at a high temperature: Check cooling

 PLATFORM: UCS C240 M4S
 CIMC Ver: 3.0(3a) 
 BIOS Ver: C240M4.3.0.3a.0.0321172111

嚇了我一大跳 以為機房的冷氣又壞掉了

進環控去看 溫度是正常的
接下來進CIMC
看到









直覺是風扇壞了
先重開機看看還能不能開
還好可以開
先把guest全部搬走
因為前幾天storage壞了 把guest 全搬到肚子
連絡廠商後把上面的擷圖跟收log
等到下午
代理商連絡說有個東西要調





















預設的風扇策略是低功率 有可能會造成溫度過高
建議調整如下




















還問我是不是跑vm cpu有沒有吃很多

現在買server 99%都跑vm了吧
這個還要問
風扇策略竟然還會預設低轉速
欠罵

2018/08/01

最近借了一台 synology fs2017來測試
8顆 240G SSD

測試環境

cisco UCS C240 M4S

Intel(R) Xeon(R) CPU E5-2620 v4 @ 2.10GHz  *2
RAM 32G
HD 300G SAS  *5
NIC 10G

proxmox 5.2 環境
guest HD 32G

使用指令如下
time qm clone 123 456

===========================
fs2017 iscsi

real 1m41.039s
user 0m4.945s
sys 0m55.628s
===========================
fs2017 nfs

real 0m47.445s
user 0m3.224s
sys 0m36.446s
===========================
cisco local zfs

real 10m3.973s
user 0m4.739s
sys 0m5.394s
===========================

cisco local lvm

real 4m28.070s
user 0m5.645s
sys 0m54.285s
===========================

hp virtual store 4300

real 4m39.839s
user 0m4.612s
sys 0m49.002s

===========================

2018/06/11

graylog預設會捉取log的第一個欄位來當成source

最近碰到 Cisco的ASA 吐出來log的第一個欄位是月分的英文
導致每個月都會換一次source
如下

May 09 2018 15:00:40 context-admin : %ASA-4-106023: Deny tcp src inside:172.16.213.212/52854 dst outside:192.168.213.203/445 by access-group "inside_access_in" [0x0, 0x0]
May 09 2018 15:00:40 context-admin : %ASA-4-106023: Deny tcp src inside:172.16.213.212/52855 dst outside:192.168.213.203/445 by access-group "inside_access_in" [0x0, 0x0]

查到二個解決方法

一個是讓ASA吐出來的log不要帶timestamp 不過因為是別廠商維護的
他們也不太想改

再來就是加個extractor
直接更換source這個欄位


2017/05/31

今天突然在ipaudit上看到以下的log




























192.168.250.30是一台cisco的設備
怎麼會自己去ping別人
一度懷疑是被hack了
經詢問廠商得到的答案是看起來是外面有人在ping這個網段的機器
但因為本來就沒有這個ip
所以cisco就代為回應了
這個功能預設是打開的
可以下指令停掉
指令如下 (下在L3的routing port 上)

no ip unreachables

再觀察看看

2017/01/14

去年底進了三台server跟一台網路設備
接上arista 10G switch後都發現有大量的rx error







換了線 gbic 甚至再借了一台hp的10G設備來測都一樣
感覺上應該不是layer1的問題
詢問cisco 6504廠商後才知道10G已經不會去檢查封包內容 只要header正常就會直接forward
因此arista上並沒有看到任何的error
建議捉封包來看看
結果一捉發現以下的問題
















cisco 6504送出的DTP(Dynamic Trunking Protocol)封包出現checksum有問題 XD
因為目前也用不到DTP
所以建議先關了
在跟arista對接的cisco port上下指令

switchport nonegotiate

目前已經解決
第一次碰到cisco送出的封包有問題
無言

2015/07/30

昨天下午17點多發生一台cisco不明原因的網路不通
早上去查了一下
找不到原因
只好把昨天早上的config 備份倒回去
說也奇怪 就正常了

到了今天中午
宿舍的4台cisco一起出問題
查了一下log如下
Jul 30 11:10:27 GMT+8: %ACL_ERRMSG-4-UNLOADED: 1 fed:  Output IP Vlan ACL on interface Vlan206 for label 3 on asic255 could not be programmed in hardware and traffic will be dropped.
Jul 30 11:10:27 GMT+8: %ACL_ERRMSG-4-UNLOADED: 1 fed:  Output IP Vlan ACL on interface Vlan207 for label 3 on asic255 could not be programmed in hardware and traffic will be dropped.
Jul 30 11:10:27 GMT+8: %ACL_ERRMSG-4-UNLOADED: 1 fed:  Output IP Vlan ACL on interface Vlan208 for label 3 on asic255 could not be programmed in hardware and traffic will be dropped.
Jul 30 11:10:27 GMT+8: %ACL_ERRMSG-4-UNLOADED: 1 fed:  Output IP Vlan ACL on interface Vlan209 for label 3 on asic255 could not be programmed in hardware and traffic will be dropped.
Jul 30 11:10:27 GMT+8: %ACL_ERRMSG-4-UNLOADED: 1 fed:  Output IP Vlan ACL on interface Vlan210 for label 3 on asic255 could not be programmed in hardware and traffic will be dropped.

詢問廠商後得到這樣的回答

原廠對3850/3650 ACL限制的說明,

ACL TCAM (TAQ)有2塊,分別為in與out,但VACL只能使用其中1塊.限制如下:

1.VACL  => 1.5K 筆 (最多,不分in,out)

2.MAC VACL => 單向460筆(in,out分開算)

3.IPv4 VACL  => 單向690筆(in,out分開算)

4.IPv4 PACL,RACL => 單向1380筆(in,out分開算)

5.MAC PACL,RACL =>單向690筆(in,out分開算)

6.IPv6 PACL,RACL =>單向690筆(in,out分開算)



VLAN Access Control List (VACL) − A VACL is an ACL that is applied to a VLAN. It can only be applied to a VLAN and no other type of interface. The security boundary is to permit or deny traffic that moves between VLANs and permit or deny traffic within a VLAN. The VLAN ACL is supported in hardware, and has no effect on the performance.

Port Access Control List (PACL) − A PACL is an ACL applied to a Layer 2 switchport interface. The security boundary is to permit or deny traffic within a VLAN. The PACL is supported in hardware and has no effect on the performance.

Router ACL (RACL) − An RACL is an ACL that is applied to an interface that has a Layer 3 address assigned to it. It can be applied to any port that has an IP address such as routed interfaces, loopback interfaces, and VLAN interfaces. The security boundary is to permit or deny traffic that moves between subnets or n

意思就是說當acl下超過690條後 机器就會不正常了
XD
cisco吔

為什麼以前都沒發生過咧

不知是因為最近snort升到 2.9.7.5 所以 port scan變的比較敏感
還是port scan真的變多了

反正先改了一下程式
要block的ip直接下到fortiget而不先進LP了
看來也沒啥好方法可以處理了

2015/05/05

今天在設定二台cisco机器
因為二台之間走的是routing mode
設定完成後互相ping對方的對口ip都沒問題能互通
可是再ping到switch內設定的vlan ip時卻都ping不到
看了一下vlan也是正常啟動沒問題
試了半天才知道原來是如果該vlan下沒在串接任何設備或pc
該vlan ip是沒有啟動的
並不是設定的問題
也因此在cacti的設定也只能使用對口的routing ip不然如果所有的pc對關机
可能就會造成机器當机的誤判發生

2015/02/09

在cisco的設備設定完dhcp snooping及arp inspection後
如果要針對某些ip例外開放
必須使用arp access-list

arp access-list static-arp
permit ip host 1.1.1.1 mac host 0000.1234.5678

在把這個access-list 下到vlan上去

但在brocade fws624 上就不用這麼麻煩
只要在config裡下一行指令就解決了

arp 1.1.1.1 0000.1234.5678 inspect

接下來再port security這裡加上 maxmum
如果不加 預設每個port 只能出現一個mac
加上後才能允許多個mac出現(在下串小switch的情況下)
port security
  enable
  maximum 5
  violation restrict
  age 1

2015/02/04

如何記錄 telnet 至網路設備後的相關訊息

先建立一個指令檔 abc

#!/bin/bash
echo open 10.0.0.1
sleep 1
echo admin
sleep 1
echo admin123
sleep 1
echo terminal length 0  #此行設定不要出現 --more--  要按空白才能繼續 每種網路設備指令不同
sleep 1
echo sh ru
sleep 1
exit

再執行

./abc|/usr/bin/telnet > log

2014/11/10

最近這一兩週有個單位的一台printer一直有問題
換了outlet  跳線  switch的port都沒用
今天接到cisco上發現出現了很多error
99%是Layer 1的問題了
拿fluke dsp-4300去測
發現第二條線斷了
斷在1米的地方
可能是patch pannel接觸有問題
用工具重壓
目前是ok

問題是也沒人去動
久了也是會有問題
XD

以後查問題可能要從Layer 1 開始了

2014/10/07

目前比較新的switch都提供Time-Domain-Reflectometry(tdr)的功能
以方便管理人員可以初步由switch端回測到outlet
方便layer 1的查修
指令如下

cisco

#test cable tdr interface <interface of your choice>
Wait 5-7 seconds
#show cable tdr interface <interface of your choice>

brocade

#phy cable-diag tdr 1/1/1
Wait 5-7 seconds
#show cable-diag tdr 1/1/1

以下列出 brocade在有接client及未接client顯示出的結果

未接client
Port    Speed   Local pair      Pair Length     Remote pair     Pair status
----    -----   ----------      -----------     -----------     -----------
0/1/2   UNKWN   Pair A          0000081M                        Open
                Pair B          0000084M                        Open
                Pair C          0000084M                        Open
                Pair D          0000080M                        Open

有接client
Port    Speed   Local pair      Pair Length     Remote pair     Pair status
----    -----   ----------      -----------     -----------     -----------
0/1/1   100M    Pair A          N/A    M        Pair B          Terminated
                Pair B          N/A    M        Pair A          Terminated
                Pair C          0000076M                        Shorted
                Pair D          0000072M                        Shorted

2014/05/20

cisco 3750常會發生斷電後網路不通的情況
telnet 到該台机器後看到的vlan狀況如下

Vlan101 is up, line protocol is down

再看每個port的情況發現在該vlan中所有的port的情況都如下所示

GigabitEthernet1/0/1 is administratively down, line protocol is down (disabled)

最快的方式
conf t
int ra gi 1/0/1 - 24
shutdown
no shutdown

把所有的port重開一次

恢復正常

2014/01/04

使用python的 telnetlib對網路設備進行一些自動化的操作
範例如下


import telnetlib

HOST = "1.1.1.1"

tn = telnetlib.Telnet(HOST)

tn.read_until("Password: ")
tn.write("12345\n")
tn.read_until("cc>")
tn.write("en\n")
tn.read_until("Password: ")
tn.write("12345\n")

tn.write("sh flash\n")
tn.write("exit\n")
print tn.read_all()

http://blog.johnsonlu.org/category/programe/pythin/
http://docs.python.org/2/library/telnetlib.html

2013/12/22

borcade

http://www.brocade.com/downloads/documents/product_manuals/MIB/IPMIB_Reference_Jun2013.pdf

OID前要加上 1.3.6.1.4.1.1991

1.3.6.1.4.1.1991.1.1.1.1.18  机器溫度

cisco 溫度相關oid

iso.3.6.1.4.1.9.9.13.1.3.1.2.1005 = STRING: "SW#1, Sensor#1, GREEN "
iso.3.6.1.4.1.9.9.13.1.3.1.2.2005 = STRING: "SW#2, Sensor#1, GREEN "
iso.3.6.1.4.1.9.9.13.1.3.1.3.1005 = Gauge32: 30
iso.3.6.1.4.1.9.9.13.1.3.1.3.2005 = Gauge32: 33
iso.3.6.1.4.1.9.9.13.1.3.1.4.1005 = INTEGER: 65
iso.3.6.1.4.1.9.9.13.1.3.1.4.2005 = INTEGER: 65
iso.3.6.1.4.1.9.9.13.1.3.1.5.1005 = INTEGER: 0
iso.3.6.1.4.1.9.9.13.1.3.1.5.2005 = INTEGER: 0
iso.3.6.1.4.1.9.9.13.1.3.1.6.1005 = INTEGER: 1
iso.3.6.1.4.1.9.9.13.1.3.1.6.2005 = INTEGER: 1

以下為目前實際值
.1.3.6.1.4.1.9.9.13.1.3.1.3.1005

舊型机器(2U)不支援此OID

2013/10/28

最近又開始出現私設dhcp server的問題了
看了一下dhcp協定的交握
先在L3 上把udp 68擋了
注意不要下到上層的link port了
再觀察看看要不要下到L2去

ip access-list extended dhcp_deny
deny udp any any eq bootpc
permit ip any any

int ra gi 1/0/1 - 24

ip access-group dhcp_deny in

P.S.
brocade 沒辦法使用ra下acl
Orz

2013/07/22

在config cisco port description的過程中發現只要打到某些中文字就會出現異常

進config mode後加入以下二行指令就正常了

default-value exec-character-bits 8
default-value special-character-bits

2013/05/28

FWS 624升級firmware後client拿不到ip 的問題終於有了解答

目前使用的 FGS04302c.bin這個版本在打開dhcp snooping的時候
並不會在dhcp的封包加上option 82的訊息
但之後的版本會
如下圖所示
而封包向上流會經過cisco 3750
問題就來了 cisco預設會丟棄含有option 82的封包
但有指令可以讓cisco不做check

ip dhcp relay information trust-all (全域)

ip dhcp relay information trusted (每埠或vlan)

但目前在cisco 3750上又開啟了dhcp snooping
導致以上二個指令在這種情況是無法作用的

接下來就只剩一個解法了

在brocade的每一個port加上

no dhcp snooping relay information

讓brocade不要在封包加上option 82

問題是這個指令無法使用 int e 0/1/1 to 0/1/24 來下
要一個port 一個port下
有一千多個port 喔
想到就累 @@