McAfee M4050 Troubleshooting Guide - Page 28

Cisco PIX® Firewall, Cisco CSS 11000, Cisco Catalyst® 2900XL, 3500XL Series (Hybrid)

Page 28 highlights

McAfee® Network Security Platform 6.0 Troubleshooting Network Security Platform Sometimes there are duplex inconsistencies between Network Security Platform and the switch port. Symptoms include poor port performance and frame check sequence (FCS) errors that increment on the switch port. To troubleshoot this issue, manually configure the switchport to 100 Mbps, half-duplex. If this action resolves the connectivity problems, you may be running into this issue. Contact Cisco's TAC for assistance. Use the following commands to verify fixed interface settings on some Cisco devices that connect to Sensors: Cisco PIX® Firewall  interface ethernet0 100full Cisco CSS 11000  interface ethernet-3  phy 100Mbits-FD Cisco Catalyst® 2900XL, 3500XL Series (Hybrid)  interface FastEthernet0/2  duplex full  speed 100 Cisco Catalyst 4000, 5000, 6000 Series (Native)  set port speed 1/1 100  set port duplex 1/1 full Connectivity issues with Cisco 3750-12S switch Use the following ports when connecting a Cisco 3750-12s switch to your Sensor: 3, 4, 7, 8, 11, or 12. Connections using ports 1, 2, 5, 6, 9, or 10 may cause network jitter, which is an inconsistent delay of packets. Cisco IOS® for Catalyst 4000, 6000 Series  Router(config)# interface fastethernet slot/port  Router(config-if)# speed 100  Router(config-if)# duplex full When troubleshooting Network Security Platform performance issues with Cisco switches, view the output of the show port mod/port command, and note the counter information. 19

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95

McAfee® Network Security Platform 6.0
Troubleshooting Network Security Platform
19
Sometimes there are duplex inconsistencies between Network Security Platform and the
switch port. Symptoms include poor port performance and frame check sequence (FCS)
errors that increment on the switch port. To troubleshoot this issue, manually configure the
switchport to 100 Mbps, half-duplex. If this action resolves the connectivity problems, you
may be running into this issue. Contact Cisco's TAC for assistance.
Use the following commands to verify fixed interface settings on some Cisco devices that
connect to Sensors:
Cisco PIX® Firewall
interface ethernet0 100full
Cisco CSS 11000
interface ethernet-3
phy 100Mbits-FD
Cisco Catalyst® 2900XL, 3500XL Series (Hybrid)
interface FastEthernet0/2
duplex full
speed 100
Cisco Catalyst 4000, 5000, 6000 Series (Native)
set port speed 1/1 100
set port duplex 1/1 full
Connectivity issues with Cisco 3750-12S switch
Use the following ports when connecting a Cisco 3750-12s switch to your Sensor: 3, 4, 7,
8, 11, or 12. Connections using ports 1, 2, 5, 6, 9, or 10 may cause network jitter, which is
an inconsistent delay of packets.
Cisco IOS® for Catalyst 4000, 6000 Series
Router(config)# interface fastethernet slot/port
Router(config-if)# speed 100
Router(config-if)# duplex full
When troubleshooting Network Security Platform performance issues with Cisco switches,
view the output of the
show port mod/port
command, and note the counter
information.