Wednesday, April 15, 2009

IOS: %BGP_MPLS-3-GEN_ERROR


Mar 18 20:41:38.892 EDT: %BGP_MPLS-3-GEN_ERROR: BGP: MPLS outlabel changed, MPLS forw not updated, prefix not in routing table -Traceback= 10D36950 10D3709C 10B10388 10B10718 10AEEFD0 10AEF030 10B53A50 10B53DC0 10AF588C 10AFD610 10AFE8E0 10A44524 10A3B6D4
Mar 18 20:41:38.892 EDT: %BGP_MPLS-3-GEN_ERROR: BGP: MPLS outlabel changed, MPLS forw not updated, prefix not in routing table -Traceback= 10D36950 10D3709C 10B10388 10B10718 10AEEFD0 10AEF030 10B53A50 10B53DC0 10AF588C 10AFD610 10AFE8E0 10A44524 10A3B6D4
Mar 18 20:41:38.892 EDT: %BGP_MPLS-3-GEN_ERROR: BGP: MPLS outlabel changed, MPLS forw not updated, prefix not in routing table -Traceback= 10D36950 10D3709C 10B10388 10B10718 10AEEFD0 10AEF030 10B53A50 10B53DC0 10AF588C 10AFD610 10AFE8E0 10A44524 10A3B6D4


Cisco IOS Software, Catalyst 4500 L3 Switch Software (cat4500e-ENTSERVICES-M), Version
12.2(50)SG1, RELEASE SOFTWARE (fc2)
Technical Support:
http://www.cisco.com/techsupport
Copyright (c) 1986-2009 by Cisco Systems, Inc.
Compiled Tue 10-Feb-09 00:17 by prod_rel_team
Image text-base: 0x10000000, data-base: 0x124FED8C

ROM: 12.2(44r)SG
Darkside Revision 0, Jawa Revision 11, Tatooine Revision 140, Forerunner Revision 1.74

MyRouter uptime is 5 days, 3 hours, 12 minutes
System returned to ROM by power-on
System restarted at 19:50:40 EDT Fri Mar 13 2009
System image file is "bootflash:/cat4500e-entservices-mz.122-50.SG1.bin"

cisco WS-C4900M (MPC8548) processor (revision 2) with 524288K bytes of memory.
Processor board ID JAE130628BD
MPC8548 CPU at 1.33GHz, Cisco Catalyst 4900M
Last reset from PowerUp
1 Virtual Ethernet interface
36 Gigabit Ethernet interfaces
16 Ten Gigabit Ethernet interfaces
511K bytes of non-volatile configuration memory.

Configuration register is 0x2102



CSCse15707: Trace back seen at bgp_ipv4_mpls_label_change.

http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCse15707


First Found-In:

  • 12.2(32.8.7)SRB




  • 12.2(32.8.8)SRA




  • 12.4(12.15)PI7e




  • 12.2(31)SB9




  • 12.2(31.4.5)SB11




  • 12.2(31.4.11)SB12




  • 12.2(28.5.24)SB13




  • Fixed-In:

  • 12.2(32.8.63)SR




  • 12.2(33)SRC




  • 12.4(13.8)PI7c




  • 12.2(33)SRB3




  • 12.2(33.2.18)SRB




  • 12.2(33)SB




  • 12.2(32.8.99a)SR133




  • 12.2(31)SB13




  • 12.2(32.8.1)YCA172.24




  • 12.4(21.14.9)PIC1





  • Symptoms: A router may generate the following error message and a traceback:

    %BGP_MPLS-3-GEN_ERROR: BGP: MPLS outlabel changed, MPLS forw not updated, prefix not in routing table

    Conditions: This symptom is observed on a Cisco router that functions in a VPN carrier supporting carrier topology and that is configured for BGP and IPv4.

    Workaround: This is a cosmetic issue, the traceback is harmless and the functionality of the router is not affected.

    CATOS: %SYS-3-PKTBUFFERFAIL_ERRDIS: Packet buffer failure detected.

    %%SYS-3-PKTBUFFERFAIL_ERRDIS: Packet buffer failure detected. Err-disabling port [dec]/[dec]

    Description:

    This message indicates that the default error-detection packet buffer setting is error disabling the port. Whenever a parity failure is detected on the port, ASIC ports are error disabled. [dec]/[dec] is the module number/port number of the error-disabled port.

    Recommended Action:

    Power cycle the switching module with the error-disabled port. Note The next message appears as four lines.

    Example:
    2009 Mar 19 22:19:18 GMT +00:00 %SYS-3-PKTBUFFERFAIL_ERRDIS:Packet buffer failure detected. Err-disabling port 12/11.
    2009 Mar 19 22:19:19 GMT +00:00 %SYS-3-PKTBUFFERFAIL_ERRDIS:Packet buffer failure detected. Err-disabling port 12/12.




    MySwitch (enable) show port errdisable-timeout 12/12
    Module 12 is not a Komodo+ Firewall
    Module 12 is not a Venus SLB

    Port Status ErrDisable Reason Port ErrDisableTimeout Action on Timeout
    ---- ---------- ------------------- ---------------------- -----------------
    12/12 errdisable packet-buffer-error Enable No Change
    MySwitch (enable)




    MySwitch (enable) show port errdisable-timeout 12/11
    Module 12 is not a Komodo+ Firewall
    Module 12 is not a Venus SLB

    Port Status ErrDisable Reason Port ErrDisableTimeout Action on Timeout
    ---- ---------- ------------------- ---------------------- -----------------
    12/11 errdisable packet-buffer-error Enable No Change
    MySwitch (enable)




    MySwitch (enable) sh port status 12
    Port Name Status Vlan Duplex Speed Type
    ----- -------------------- ---------- ---------- ------ ----- ------------
    12/1 FOLPT1412 connected 562 full 100 10/100BaseTX
    12/2 FOLPT1413 connected 562 full 100 10/100BaseTX
    12/3 3/6 splpw232131 errdisable 562 full 100 10/100BaseTX
    12/4 ldnpsmeg025 errdisable 565 full 100 10/100BaseTX
    12/5 LDNPSM14006 errdisable 565 full 100 10/100BaseTX
    12/6 LDNPSM14007 errdisable 565 full 100 10/100BaseTX
    12/7 LDNPSM14008 errdisable 565 full 100 10/100BaseTX
    12/8 LDNPSM02989 errdisable 565 full 100 10/100BaseTX
    12/9 LDNPSM14015 errdisable 565 full 100 10/100BaseTX
    12/10 LDNPSM14014 errdisable 565 full 100 10/100BaseTX
    12/11 LDNPSM14012 errdisable 565 full 100 10/100BaseTX
    12/12 lsc42n02-app2 errdisable 562 full 100 10/100BaseTX


    MySwitch (enable) show port errdisable-timeout 12/3
    Module 12 is not a Komodo+ Firewall
    Module 12 is not a Venus SLB

    Port Status ErrDisable Reason Port ErrDisableTimeout Action on Timeout
    ---- ---------- ------------------- ---------------------- -----------------
    12/3 errdisable packet-buffer-error Enable No Change
    MySwitch (enable)





    Example:Resolution:

    set module power down 12
    set module power up 12



    Related document:

    Best Practices for Catalyst 4500/4000, 5500/5000, and 6500/6000 Series Switches Running CatOS Configuration and Management

    Thursday, March 19, 2009

    PIX 6.X - Configuring Logical / VLAN interfaces

    Scenario:
    The inside/ethernet1 interface of the PIX will be mapped to two VLANs, VLAN1 with IP address 192.168.1.2/24 and VLAN2 with IP address 192.168.2.2. The outside interface has IP address 10.199.248.225/24

    Topology:



    [Thanks to former colleague Dan for the image.]


    PIX 6 Configuration:

    interface ethernet1 auto
    nameif ethernet1 inside security100
    address inside 192.168.1.2 255.255.255.0

    interface ethernet1 vlan2 logical
    nameif vlan2 inside2 security50
    address vlan2 192.168.2.2 255.255.255.0

    Notes:
    Your Physical Interface is (by default), your VLAN1.


    PIX 7 Configuration:

    interface Ethernet1
    nameif inside
    security-level 100
    ip address 192.168.1.2 255.255.255.0
    no shut

    interface Ethernet1.2
    vlan 2
    nameif inside2
    security-level 50
    ip address 192.168.2.2 255.255.255.0
    no shut

    Tuesday, July 29, 2008

    BIG-IP v4 - Common bigstart commands

    The bigstart is the command used for controlling the F5 BIGIP daemons/services. For Windows users, this is synonymous to Control Panel -> Admin Tools -> Services. Here is BIG-IP v4.x bigstart command syntax dissected:


    SYNTAX

    bigstart [-d] action [id]

    • -d
      Lists the execution order of the services for the specified action command.

    • action
      Performs whatever action is specified. Values are startup, shutdown, active, standby, status, reinit and restart.

    • id
      The specific service on which the specified action would be acted upon. That is, for example, bigstart shutdown named will shutdown the service named.


    ACTIONS
    • startup
      The target program commences. Bigstart startup is called from /etc/rc before rc.local is executed.

    • shutdown
      The target program should shut down gracefully.

    • active
      The target program takes any action necessary whenits host BIG-IP becomes the active unit. Bigstart active is called when the BIG-IP becomes the active
      BIG-IP.

    • standby
      The target program takes any action necessary when its host BIG-IP becomes the standby unit.

    • reinit
      The target program initializes itself from its configuration data.

    • restart
      The target program is to be restarted. Typically this means the program will be stopped then started.

    • status
      The target program responds by providing some status information.




    SCRIPT AND ACTION DIRECTORIES

    The scripts for each of the services are in the /etc/bigstart/scripts directory.

    Each of the actions have their own individual action directories in /etc/bigstart/action. Files in the action directories are actually symbolic links pointing to the actual scripts in the /etc/bigstart/scripts directory.


    SYMBOLIC LINK FORMAT

    Each symbolic link in the action directories follow this naming convention:

    SNNString

    NN - two digit number that determines the execution order of the services.

    String - name of the service

    The contents of, say, /etc/bigstart/startup will correspond to the output of the command bigstart -d startup.


    CASE STUDY: PREVENT A SERVICE FROM RUNNING ON STARTUP

    Scenario: In our setup, the name service named of the BIG-IP is not being used. Hence, it was decided to be not started during device startup.

    Procedure:
    1. Verify the status of the named service:

      bigip:# bigstart status named
      bigstart: status named
      status named: (pid=1130) is running
      bigip:#


    2. Shutdown the service:

      bigip:# bigstart shutdown named
      bigip:#


    3. Remove the named symbolic link in the startup action directory:

      bigip:# cd /etc/bigstart/startup
      bigip:/etc/bigstart/startup# ls *named*
      S10named
      bigip:/etc/bigstart/startup# rm S10named
      remove S10named? y
      bigip:/etc/bigstart/startup#


    Verification
    • Verify that the service is not in the execution order for the startup action.

      bigip:# bigstart -d startup
      ...
      <output omitted>
      ...


    • Verify status of the current running status of the service:

      bigip:# bigstart status named
      bigstart: status named
      status named: is not running
      bigip:#