Solved

Cisco 3560+ Configuration suggestions

Posted on 2008-10-29
12
2,063 Views
Last Modified: 2013-11-05
I would like comments and suggestions on the following switch configuration:

!
! No configuration change since last restart
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname <myswitch>
!
enable secret 5 <secret>
!
no aaa new-model
clock timezone cst -6
clock summer-time cst recurring
system mtu routing 1500
ip subnet-zero
ip routing
!
!
cluster commander-address <mac> member 3 name <cluster name> vlan 1
!
!
!
!
no errdisable detect cause link-flap
errdisable recovery cause udld
errdisable recovery cause bpduguard
errdisable recovery cause security-violation
errdisable recovery cause channel-misconfig
errdisable recovery cause pagp-flap
errdisable recovery cause dtp-flap
errdisable recovery cause link-flap
errdisable recovery cause gbic-invalid
errdisable recovery cause l2ptguard
errdisable recovery cause psecure-violation
errdisable recovery cause dhcp-rate-limit
errdisable recovery cause vmps
errdisable recovery cause storm-control
errdisable recovery cause arp-inspection
errdisable recovery cause loopback
errdisable recovery interval 60
no file verify auto
spanning-tree mode pvst
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
interface FastEthernet0/1
 switchport mode access
 spanning-tree portfast
!
interface FastEthernet0/2
 spanning-tree portfast
!
interface FastEthernet0/3
 spanning-tree portfast
!
interface FastEthernet0/4
 spanning-tree portfast
!
interface FastEthernet0/5
 spanning-tree portfast
!
interface FastEthernet0/6
 spanning-tree portfast
!
interface FastEthernet0/7
 spanning-tree portfast
!
interface FastEthernet0/8
 spanning-tree portfast
!
interface FastEthernet0/9
 spanning-tree portfast
!
interface FastEthernet0/10
 spanning-tree portfast
!
interface FastEthernet0/11
 spanning-tree portfast
!
interface FastEthernet0/12
 spanning-tree portfast
!
interface FastEthernet0/13
 spanning-tree portfast
!
interface FastEthernet0/14
 spanning-tree portfast
!
interface FastEthernet0/15
 spanning-tree portfast
!
interface FastEthernet0/16
 spanning-tree portfast
!
interface FastEthernet0/17
 spanning-tree portfast
!
interface FastEthernet0/18
 spanning-tree portfast
!
interface FastEthernet0/19
 spanning-tree portfast
!
interface FastEthernet0/20
 spanning-tree portfast
!
interface FastEthernet0/21
 spanning-tree portfast
!
interface FastEthernet0/22
 spanning-tree portfast
!
interface FastEthernet0/23
 spanning-tree portfast
!
interface FastEthernet0/24
 spanning-tree portfast
!
interface FastEthernet0/25
 spanning-tree portfast
!
interface FastEthernet0/26
 spanning-tree portfast
!
interface FastEthernet0/27
 spanning-tree portfast
!
interface FastEthernet0/28
 spanning-tree portfast
!
interface FastEthernet0/29
 spanning-tree portfast
!
interface FastEthernet0/30
 spanning-tree portfast
!
interface FastEthernet0/31
 spanning-tree portfast
!
interface FastEthernet0/32
 spanning-tree portfast
!
interface FastEthernet0/33
 spanning-tree portfast
!
interface FastEthernet0/34
 spanning-tree portfast
!
interface FastEthernet0/35
 spanning-tree portfast
!
interface FastEthernet0/36
 spanning-tree portfast
!
interface FastEthernet0/37
 spanning-tree portfast
!
interface FastEthernet0/38
 spanning-tree portfast
!
interface FastEthernet0/39
 spanning-tree portfast
!
interface FastEthernet0/40
 spanning-tree portfast
!
interface FastEthernet0/41
 spanning-tree portfast
!
interface FastEthernet0/42
 spanning-tree portfast
!
interface FastEthernet0/43
 spanning-tree portfast
!
interface FastEthernet0/44
 spanning-tree portfast
!
interface FastEthernet0/45
 spanning-tree portfast
!
interface FastEthernet0/46
 spanning-tree portfast
!
interface FastEthernet0/47
 spanning-tree portfast
!
interface FastEthernet0/48
 spanning-tree portfast
!
interface GigabitEthernet0/1
 switchport trunk encapsulation isl
 switchport mode trunk
!
interface GigabitEthernet0/2
 switchport trunk encapsulation isl
 switchport mode trunk
!
interface GigabitEthernet0/3
 switchport trunk encapsulation isl
 switchport mode trunk
!
interface GigabitEthernet0/4
 switchport trunk encapsulation isl
 switchport mode trunk
!
interface Vlan1
 ip address <ip> 255.255.0.0
!
ip classless
ip route 0.0.0.0 0.0.0.0 <ip>
ip http server
ip http secure-server
!
!
!
control-plane
!
!
line con 0
 password <password>
 login
line vty 0 4
 password <password>
 login
line vty 5 15
 password <password>
 no login
!
ntp clock-period 36029200
ntp server <ip>
end

Please let me know if there are changes that would be recommended etc.  Thanks in advance!

-D-
0
Comment
Question by:John Gates
  • 7
  • 5
12 Comments
 
LVL 15

Accepted Solution

by:
bkepford earned 500 total points
ID: 22831841
The configuration will work but I would look at two things.
1) Your running standard Per Vlan Spanning tree. Which doesn't converge very fast. I would change to  rapid-pvst. Seeing as you are running portfast on everything it seems speed is important to you.
spanning-tree mode rapid-pvst
2) You have portfast enabled on all of your ports which is actually not a bad thing as long as you know no one is going to plug a switch in to one of the ports and possibly create a loop.  
0
 
LVL 17

Author Comment

by:John Gates
ID: 22833562
Thank you for your response.  Let's see what the other experts suggest.

-D-
0
 
LVL 15

Expert Comment

by:bkepford
ID: 22834411
Just out of curiosity other then straight layer 2 connectivity on a single vlan, do you have any other requirements for your network?
0
Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

 
LVL 17

Author Comment

by:John Gates
ID: 22834452
Not really just looking for the most solid configuration.
0
 
LVL 17

Author Comment

by:John Gates
ID: 22834514
Like should input flow control be enabled on the gigabit fiber eth ports etc...


-D-
0
 
LVL 15

Expert Comment

by:bkepford
ID: 22834696
In my opinion flow control should only be used if you are experiencing congestion. If you check your links during peak usage and they have plenty of capacity yet it is better to leave it at the default.  
For your trunk links I would add them to an ether channel if they are going to the same switch and that other switch can support etherchannel.  I would also turn on udld (unidirectional link detection) again is the other switch supports the feature this will create the most redundancy and the most "solid" config
example
interface GigabitEthernet0/1
 switchport trunk encapsulation isl
 switchport mode trunk
 udld port
 channel-group 1 mode on
!
interface GigabitEthernet0/2
 switchport trunk encapsulation isl
 switchport mode trunk
 udld port
 channel-group 1 mode on

0
 
LVL 17

Author Comment

by:John Gates
ID: 22834838
I am seeing a lot of input errors:

GigabitEthernet1/0/5 is up, line protocol is up (connected)
  Hardware is Gigabit Ethernet, address is <mac>
  MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive not set
  Full-duplex, 1000Mb/s, link type is auto, media type is 1000BaseSX SFP
  input flow-control is off, output flow-control is unsupported
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input 00:00:51, output 00:00:00, output hang never
  Last clearing of "show interface" counters 00:55:01
  Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 36000 bits/sec, 7 packets/sec
  5 minute output rate 155000 bits/sec, 34 packets/sec
     530836 packets input, 208730707 bytes, 0 no buffer
     Received 7173 broadcasts (0 multicast)
     0 runts, 0 giants, 0 throttles
     21 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 watchdog, 2696 multicast, 0 pause input
     0 input packets with dribble condition detected
     659411 packets output, 515940865 bytes, 0 underruns
     0 output errors, 0 collisions, 0 interface resets


Does this look unreasonable?
-D-
0
 
LVL 15

Expert Comment

by:bkepford
ID: 22835092
Well you have 530836 packets input and 21 input errors and it looks like a time frame of 55 minutes since your last clear counters.
This is a low percentage and from the amount of traffic I don't think it is congestion related. Obviously this isn't causing tons of drops and To answer your question it looks reasonable even with the input errors.
Of course you want the errors to stop so I would start with these questions. What is on the other side of the line and are you seeing any errors on that side?  How long is the run? Have you tried moving to another SFP port on the switch? Have you tested the cable?
 
0
 
LVL 17

Author Comment

by:John Gates
ID: 22837477
The other side of the fiber link goes to a switch that is not reporting errors at all as far as input.


-D-
0
 
LVL 17

Author Comment

by:John Gates
ID: 22840608
I have also seen interface resets.  Like 1 in a day.  Is this normal too?
0
 
LVL 15

Expert Comment

by:bkepford
ID: 22840739
Nope, This is a duplex (a pair of fibers) mmf so have you tried switching the pairs on both sides as long as the connector isn't a duplex connector. It would be a good test. The reason I say this is from what your telling me the most likely problem is a slight cable quality issue.
Input errors tend to be a physical problem whether from interference or cable quality issue to bad SFP ports or modules.
0
 
LVL 17

Author Closing Comment

by:John Gates
ID: 31511161
Thank you very much for your input.  It is appreciated.


-D-
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco 2960 port led all amber 5 124
Network Infrastructure for Branch Office 16 100
traffic flow without STP 9 54
Switch ports not working 8 54
The worst thing when starting a new job is when the previous Network Administrator left behind no documentation. How do you get into the devices? If you've been in this situation or just accidently mistyped your password, this article will hopefully…
I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question