Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-27 Thread Mark Tinka
On Thursday, June 26, 2014 04:54:33 PM thiyagarajan b wrote:

 Hello,
 Request to suggest whether 12.2(58)SE or 12.2(55)SE , a
 stable IOS for Cisco 3560-24TS switch since the switch
 got a software crash installed with 12.2(52)SE.

We've been on the 15 train for our PoE 3560G's.

A previous version was causing switch crashes in one office 
due to memory exhaustion. An upgrade fixed that, so we're 
now on 15.0(2)SE6 and that has been solid.

Mark.


signature.asc
Description: This is a digitally signed message part.
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-27 Thread Mark Tinka
On Thursday, June 26, 2014 11:38:55 PM Nick Hilliard wrote:

 Also the OP should note that when you boot from from
 12.2(52)SE to a later versions, the boot loader will
 almost do a microcode upgrade on the C3560X platform.
 Depending on the version involved, this can take up to
 35 minutes downtime per box.  The release notes still
 don't mention this as a risk, which is not good.  It
 would be very helpful if cisco provided some information
 on this in the release notes.

Yes, we noted this on all upgrades from shipped 12.2 to 
operational 15.

Ours were 3560G's and the microcode update took about 15x 
minutes (causing lots of fan noise).

Mark.


signature.asc
Description: This is a digitally signed message part.
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-27 Thread Mark Tinka
On Thursday, June 26, 2014 11:38:55 PM Nick Hilliard wrote:

 Am currently installing 15.2 on new boxes as it provides
 much better support for ipv6 neighbor security.  Haven't
 run into any major problems yet.

3560 and 3560G only have 15.0. No 15.2 :-(.

Mark.


signature.asc
Description: This is a digitally signed message part.
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-27 Thread Alan Buxey
It's the fact that all the fan control stuff is STOPPED when doing the update.  
That's how noisy the things would always be if there was no fan control (its 
actually how noisy they can get if in a really bad environment ;) ). A bit like 
servers before you enable all the sensible stuff 8)

alan
-- 
Sent from my Android device with K-9 Mail. Please excuse my brevity.
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


[c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-26 Thread thiyagarajan b
Hello,
Request to suggest whether 12.2(58)SE or 12.2(55)SE , a stable IOS for
Cisco 3560-24TS switch since the switch got a software crash installed
with 12.2(52)SE.

Warm Regards,
Thiyagarajan B.
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-26 Thread Darren O'Connor
I've stuck with (55) and it's never given me trouble

Thanks
Darren
http://www.mellowd.co.uk/ccie



 Date: Thu, 26 Jun 2014 20:24:33 +0530
 From: bn.thiyagara...@gmail.com
 To: cisco-nsp@puck.nether.net
 Subject: [c-nsp] Need suggestion on cisco 3560 sw IOS
 
 Hello,
 Request to suggest whether 12.2(58)SE or 12.2(55)SE , a stable IOS for
 Cisco 3560-24TS switch since the switch got a software crash installed
 with 12.2(52)SE.
 
 Warm Regards,
 Thiyagarajan B.
 ___
 cisco-nsp mailing list  cisco-nsp@puck.nether.net
 https://puck.nether.net/mailman/listinfo/cisco-nsp
 archive at http://puck.nether.net/pipermail/cisco-nsp/
  
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-26 Thread Peter Rathlev
On Thu, 2014-06-26 at 20:24 +0530, thiyagarajan b wrote:
 Request to suggest whether 12.2(58)SE or 12.2(55)SE , a stable IOS for
 Cisco 3560-24TS switch since the switch got a software crash installed
 with 12.2(52)SE.

Both of 12.2(55)SE (and SE1) and 12.2(58)SE1 have been good for us.
We've seen no crashes and noticed no bugs. 

We have seen a few crashes on 12.2(53)SE2 and 15.0(1)SE3, both of which
are releases we have been using widespread. The crashes have been so few
it might just be statistical noise though.

This is from looking at ~2000 through 18 months, all of them L2 only and
running IP Base feature set.

I'd probably suggest 12.2(58)SE1 between the two you mention.

-- 
Peter


___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-26 Thread Nick Hilliard
On 26/06/2014 21:31, Peter Rathlev wrote:
 We have seen a few crashes on 12.2(53)SE2 and 15.0(1)SE3,

I've seen several boxes running 15.0(2)SE and rebuilds suddenly die with
memory problems.  The box would be fine for many months, then one day the
monitoring system would show that it had suddenly started losing ~1% memory
per hour and then would crash a couple of days later with OOM.  I caught
one in the act last week, and show memory suggested that the dot1x
process was chewing up fragments all over the place.  dot1x was disabled on
that switch.

Am currently installing 15.2 on new boxes as it provides much better
support for ipv6 neighbor security.  Haven't run into any major problems yet.

Also the OP should note that when you boot from from 12.2(52)SE to a later
versions, the boot loader will almost do a microcode upgrade on the C3560X
platform. Depending on the version involved, this can take up to 35 minutes
downtime per box.  The release notes still don't mention this as a risk,
which is not good.  It would be very helpful if cisco provided some
information on this in the release notes.

Nick

___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-26 Thread A . L . M . Buxey
Hi,

 Request to suggest whether 12.2(58)SE or 12.2(55)SE , a stable IOS for
 Cisco 3560-24TS switch since the switch got a software crash installed
 with 12.2(52)SE.

can you even GET 12.2(58)SE for that 3560-24TS switch?  why not use/check
the cisco IOS software download page?  they suggest 12.2.55-SE9(ED) 

we're running a slightly older version than that with no issues (damn..
cursed myself now) - but I guess it depends which of the features 
on the switch you are currently using - I mean, WHAT caused your
software crash? had it analysed?

alan
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-26 Thread A . L . M . Buxey
Hi,

 Also the OP should note that when you boot from from 12.2(52)SE to a later
 versions, the boot loader will almost do a microcode upgrade on the C3560X
 platform. Depending on the version involved, this can take up to 35 minutes
 downtime per box.  The release notes still don't mention this as a risk,
 which is not good.  It would be very helpful if cisco provided some
 information on this in the release notes.

on recent versions you can do the microcode update BEFORE the reload
(check the update-sw flag list!) which saves loads of down time(!)

alan
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-26 Thread David Farrell

On 26/06/2014 22:38, Nick Hilliard wrote:

I've seen several boxes running 15.0(2)SE and rebuilds suddenly die with
memory problems.  The box would be fine for many months, then one day the
monitoring system would show that it had suddenly started losing ~1% memory
per hour and then would crash a couple of days later with OOM.  I caught
one in the act last week, and show memory suggested that the dot1x
process was chewing up fragments all over the place.  dot1x was disabled on
that switch.
I've seen similar with 15.0(2)SE on the 2960G but I suspected the SSH 
process according to sh mem, possibly exacerbated by monitoring the 
SSH port for availability. When ours died only a power cycle brought the 
thing back, as opposed to IOS crashing/rebooting... Unpleasant.


I'm planning a downgrade to 12.2(55)SE9 on two units this weekend. I've 
had the code running on a test switch to my satisfaction, I'll attempt 
to remember to note any oddities here.


Cheers,

David.
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-26 Thread Jeff Kell
On 6/26/2014 6:09 PM, a.l.m.bu...@lboro.ac.uk wrote:

 on recent versions you can do the microcode update BEFORE the reload
 (check the update-sw flag list!) which saves loads of down time(!)

First I've heard of that one (!).

The microcode update is pervasive across the 3560s/3750s.  First time I
ran across it, I was doing a remote IOS update on a number of switches
at a preset maintenance window (reload at xx:yy)... most came right
back, but the ones doing the microcode update I thought were a
meltdown and I was packing up for a repair field trip before trying them
one last time before hitting the door...

Very annoying, and very unexpected the first time around...

Jeff
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


Re: [c-nsp] Need suggestion on cisco 3560 sw IOS

2014-06-26 Thread Jeremy Bresley

On 6/26/2014 5:31 PM, David Farrell wrote:

On 26/06/2014 22:38, Nick Hilliard wrote:

I've seen several boxes running 15.0(2)SE and rebuilds suddenly die with
memory problems.  The box would be fine for many months, then one day 
the
monitoring system would show that it had suddenly started losing ~1% 
memory

per hour and then would crash a couple of days later with OOM. I caught
one in the act last week, and show memory suggested that the dot1x
process was chewing up fragments all over the place.  dot1x was 
disabled on

that switch.
I've seen similar with 15.0(2)SE on the 2960G but I suspected the SSH 
process according to sh mem, possibly exacerbated by monitoring the 
SSH port for availability. When ours died only a power cycle brought 
the thing back, as opposed to IOS crashing/rebooting... Unpleasant.


I'm planning a downgrade to 12.2(55)SE9 on two units this weekend. 
I've had the code running on a test switch to my satisfaction, I'll 
attempt to remember to note any oddities here.


If you're running into out of memory issues on 15.0(2)SE or 15.2(1)SE 
trains, and aren't doing AutoSmartPorts, try doing a no macro auto 
monitor in your config.  This was the cause of memory leaks that we 
experienced on several hundred 3560G/3560X's across multiple sites.  
Sites with large numbers of port up/down events seemed to hit it even 
quicker.  With this disabled we've been pretty happy with 15.0(2)SE4's 
stability for the last 6-9 months or more. We were testing 15.2(1)SE but 
ran into major issues with ip device tracking causing all kinds of 
duplicate IP issues/alert messages. Anybody else encounter this and have 
a fix for it in a predominantly MS environment (Win2K8/2K12 servers for 
DHCP, Win7/8 clients).  The ip device tracking delay 10 didn't make any 
difference when we tried it.  We'd really like to find a fix for it so 
we can get RSVP snooping enabled for mediatrace (dependent on ip device 
tracking)


Jeremy TheBrez Bresley
b...@brezworks.com
___
cisco-nsp mailing list  cisco-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/