Avaya ERS 2500 Troubleshooting Manual Download Page 1

Troubleshooting

Avaya Ethernet Routing Switch 2500

Series

4.1

        

NN47215-700, 01.02

November 2010

Summary of Contents for ERS 2500

Page 1: ...Troubleshooting Avaya Ethernet Routing Switch 2500 Series 4 1 NN47215 700 01 02 November 2010...

Page 2: ...THERS TO DO SO YOU ON BEHALF OF YOURSELF AND THE ENTITY FOR WHOM YOU ARE INSTALLING DOWNLOADING OR USING THE SOFTWARE HEREINAFTER REFERRED TO INTERCHANGEABLY AS YOU AND END USER AGREE TO THESE TERMS A...

Page 3: ...r 5 General diagnostic tools 17 ACLI command modes 17 Chapter 6 Initial troubleshooting 19 Gather information 19 Chapter 7 Emergency recovery trees 21 Emergency recovery trees 21 Corruption of flash 2...

Page 4: ...P users 65 Set EAPOL request packet 67 EAP RADIUS VLAN is not being applied 68 Configure VLAN at RADIUS 69 Configure switch 71 Configured MAC is not authenticating 74 Configure the switch 75 Non EAP R...

Page 5: ...cking License Kits that are available for standalone switches Each kit contains a license certificate and LAC The license file management and generation is through the Avaya Licensing Portal The licen...

Page 6: ...nal purchase Also available for purchase are additional cables of 1 5 m 5 ft and 3 m 10 ft and are similar to stack return cables You are permitted to use your own cables and longer lengths up to 100m...

Page 7: ...e on an ERS 2500 PWR is set to 802 3af and legacy while a PoE port on the switch is connected to a non PoE device Be aware that this is a hardware limitation that is caused by the capacitive detection...

Page 8: ...New in this release 8 Troubleshooting November 2010...

Page 9: ...ethernet bridging and IP routing Are familiar with networking concepts and terminology Have experience with Graphical User Interface GUI Have basic knowledge of network topologies Troubleshooting Too...

Page 10: ...Introduction 10 Troubleshooting November 2010...

Page 11: ...d paper copies of your device configuration information Ensure that all online data is stored with your site s regular data backup for your site If your site has no backup system copy the information...

Page 12: ...h as which devices are typically accessed or when peak usage times occur Use a baseline analysis as an important indicator of overall network health A baseline view of network traffic as it typically...

Page 13: ...s that are used to analyze packet traffic the packet traffic is uninterrupted and packets flow normally through the mirrored port Port mirroring limitations The Ethernet Routing Switch 2500 Series sup...

Page 14: ...er software component called syslogd that resides on your management workstation The daemon syslogd is a software component that receives and locally logs displays prints or forwards messages that ori...

Page 15: ...enabled or disabled from ACLI and DM By default AUR is enabled For more information about AUR see Avaya Ethernet Routing Switch 2500 Series Configuration System NN47215 500 Avaya knowledge and solutio...

Page 16: ...Troubleshooting fundamentals 16 Troubleshooting November 2010...

Page 17: ...ivileges User EXEC Privileged EXEC Global configuration Interface configuration Each mode provides a specific set of commands The command set of a higher privilege mode is a superset of a lower privil...

Page 18: ...nfiguration mode In the Interface Configuration mode also referred to as config if mode you can configure parameters for each port or VLAN such as speed duplex mode and rate limiting It is possible to...

Page 19: ...echnical information about system status and information about the hardware software and switch operation For more detail use the show tech command Information about past events To obtain this informa...

Page 20: ...show tech show running config show port statistics port Initial troubleshooting 20 Troubleshooting November 2010...

Page 21: ...n Each ERT describes steps to correct a specific issue the ERTs are not dependant upon each other Figure 4 Emergency recovery trees Navigation Corruption of flash on page 21 Incorrect PVID on page 22...

Page 22: ...e Figure 5 Corruption of flash Incorrect PVID An issue can occur where clients cannot communicate to critical servers when their ports are put in wrong VLAN If the server is plugged in VLAN 3 and the...

Page 23: ...o an ERS 8600 series switch and devices in a VLAN on the ERS 8600 series switch are not able to communicate with devices at the ERS 2500 series switch in the same VLAN then it is likely that the uplin...

Page 24: ...Uplink ports not tagged to VLAN recovery tree Figure 7 Uplink ports not tagged to VLAN Emergency recovery trees 24 Troubleshooting November 2010...

Page 25: ...ion of the management station or its setup If you can reach a device but no traps are received verify the trap configurations the trap destination address and the traps configured to be sent SNMP reco...

Page 26: ...be the result of a communication error between the individual units due to configuration or cabling Failures can also arise when there are multiple bases configured Emergency recovery trees 26 Troubl...

Page 27: ...Stack Recovery Tree Figure 9 Stack Stack Troubleshooting November 2010 27...

Page 28: ...Emergency recovery trees 28 Troubleshooting November 2010...

Page 29: ...ion for hardware troubleshooting specific to the Ethernet Routing Switch 2500 Series Work flow Troubleshooting hardware The following work flow assists you to determine the solution for some common ha...

Page 30: ...oubleshooting hardware Navigation Check power on page 31 Check cables on page 33 Check port on page 34 Check fiber port on page 36 Replace unit on page 38 Troubleshooting hardware 30 Troubleshooting N...

Page 31: ...Ethernet Routing Switch 2500 Series device is powered correctly Figure 11 Check power Navigation Correcting voltage source on page 32 Ensuring power cord is installed on page 32 Observing error report...

Page 32: ...lure Power LED blinking corrupt flash Reloading agent code Reload the agent code on the Ethernet Routing Switch 2500 Series device to eliminate corrupted or damaged code that causes a partial boot of...

Page 33: ...orrectly connected Task flow Check cables The following task flow assists you to confirm the stacking cables on the Ethernet Routing Switch 2500 Series device are installed correctly Figure 12 Check c...

Page 34: ...ing procedures in Avaya Ethernet Routing Switch 2500 Series Configuration System NN47215 500 Figure 13 Stack configuration 1 Base unit 2 Cascade cable 3 Cascade cable used for return Check port Confir...

Page 35: ...g the cables are working on page 36 Confirming the cables are working on page 36 Viewing port information Review the port information to ensure that the port is enabled 1 Use the show interfaces port...

Page 36: ...g correctly 1 Go to interface specific mode using the interface fastethernet port command 2 Use the no shutdown command to change the port configuration 3 Use the show interfaces port command to displ...

Page 37: ...onfirming cables are working on page 38 Returning unit for repair on page 38 Viewing fiber port information Review the port information to ensure the port is enabled 1 Use the show interfaces port com...

Page 38: ...the show interfaces port command to display the port 3 Note the port operational and link status Returning unit for repair Return unit to Avaya for repair Contact Avaya for return instructions and RM...

Page 39: ...is not designed for the situation of removing and reinserting the same switch with the same MAC address For detailed information about AUR see Avaya Ethernet Routing Switch 2500 Series Configuration S...

Page 40: ...e on page 41 Obtaining the correct software version on page 41 Placing a new unit on page 41 Connecting stacking cables on page 41 Powering on the unit on page 42 Returning unit for repair on page 42...

Page 41: ...Obtain and install the correct software version Caution Ensure you have adequate backup of your configuration prior to reloading software Know the Release number of your software before loading it Lo...

Page 42: ...stack The single device being replaced is the only device that you must power on after integration to the stack 1 Connect the power to the unit 2 Allow time for the new unit to join the stack and for...

Page 43: ...the command adac voice vlan x ADAC automatically creates the voice VLAN when needed You only have to reserve or set the VLAN number used by ADAC with the adac voice vlan x command After the VLAN numb...

Page 44: ...llowing work flow assists you to resolve detection issues Figure 18 IP phone not detected Navigation Correct filtering on page 44 Reload ADAC MAC in range table on page 46 Reduce LLDP devices on page...

Page 45: ...ng of unregistered frames on page 45 Confirming port belongs to at least one VLAN View information to ensure that the port belongs to a VLAN 1 Use the show vlan interface info port command to view the...

Page 46: ...oad ADAC MAC in range table The following task flow assists you to place the ADAC MAC address in the range table Figure 20 Reload ADAC MAC in range table Navigation Disconnecting and reconnecting phon...

Page 47: ...he MAC addresses already learned on the respective port are aged out 1 Use the no adac enable port command to disable ADAC 2 Use the adac enable port command to enable ADAC Reduce LLDP devices Reduce...

Page 48: ...ormation Display the LLDP devices that are connected to a port 1 Use the show lldp port 1 neighbor command to identify the LLDP devices 2 Note if there are more than 16 LLDP enabled devices on the por...

Page 49: ...ion is not applied Correct some common issues that may interfere with auto configuration of devices Task flow Auto configuration is not applied The following task flow assists you to solve auto config...

Page 50: ...In tagged frames mode everything is configured correctly but auto configuration is not applied on a telephony port Task flow Correct auto configuration The following task flow assists you to correct a...

Page 51: ...er call server and uplink port on page 52 Replacing Unit on page 52 Viewing ADAC global status Display the global status of ADAC 1 Use the show adac command to display the ADAC information 2 Note if t...

Page 52: ...tion if AUR is enabled 1 Follow the replacement guidelines in Avaya Ethernet Routing Switch 2500 Series System Configuration NN47215 500 2 Refer to the unit replacement section in the Troubleshooting...

Page 53: ...n Viewing ADAC port status on page 53 Reducing the number of devices on page 54 Disabling and enabling the port on page 54 Viewing ADAC port status Display the status of ADAC on the port Auto configur...

Page 54: ...edures and SOPs to reduce the number of devices connected 2 Use the show adac in port command to display the ADAC information for the port to ensure there are less than 32 devices connected Disabling...

Page 55: ...ng work flow shows typical authentication problems These work flows are not dependant upon each other Figure 25 Troubleshooting authentication Navigation EAP client authentication on page 56 EAP multi...

Page 56: ...troubleshooting guidelines for the EAP and non EAP features on the Ethernet Routing Switch 2500 Series devices Work flow EAP client is not authenticating The following work flow assists you to determ...

Page 57: ...is not authenticating Navigation Restore RADIUS connection on page 58 Enable EAP on the PC on page 60 Apply the method on page 61 Enable EAP globally on page 62 EAP client authentication Troubleshoot...

Page 58: ...s you to restore the connection to the RADIUS server Figure 27 Restore RADIUS connection Navigation Getting correct RADIUS server settings for the switch on page 59 Viewing RADIUS information on page...

Page 59: ...other older servers do not support UDP at all 1 Use the show radius server command to view the RADIUS server settings 2 Refer to the vendor documentation for server configuration Configuring the RADI...

Page 60: ...y configured Task flow Enable EAP on the PC The following task flow assists you to ensure the PC network card has EAP enabled Figure 28 Enable EAP on the PC Navigation Enabling EAP on PC network card...

Page 61: ...Ensure you apply the correct EAP method Task flow Apply the method The following task flow assists you to apply the correct EAP method Figure 29 Apply the method Navigation Configuring the RADIUS serv...

Page 62: ...ave the information for later reference Enable EAP globally Enable EAP globally on the 2500 Series device Task flow Enable EAP globally The following task flow assists you to enable EAP globally on th...

Page 63: ...dministrative status to auto on page 64 Enabling EAP globally Enable EAP globally on the Ethernet Routing Switch 2500 Series device 1 Use the eapol enable command to enable EAP globally on the 2500 Se...

Page 64: ...1 Use the eapol status auto command to change the port status to auto 2 Ensure that there are no errors after the command execution EAP multihost repeated re authentication issue Eliminate the multipl...

Page 65: ...er of authenticated users reaches the allowed maximum lower the eap mac max to the exact number of EAP users that may soon enter to halt soliciting EAP users with multicast requests Task flow Match EA...

Page 66: ...of users at allowed max Obtain the exact number of EAP users that may soon enter when the number of authenticated users reaches the allowed max Use the show eapol multihost status command to display...

Page 67: ...st packet The following task flow assists you to set the EAPOL request packet to unicast Figure 33 Set EAPOL request packet Navigation Setting EAPOL request packet globally on page 67 Setting EAPOL re...

Page 68: ...r the Interface Configuration mode 2 Use the eapol multihost eap packet mode unicast command to set the EAPOL request packet to unicast for the interface EAP RADIUS VLAN is not being applied Ensure th...

Page 69: ...switch on page 71 Configure VLAN at RADIUS Correct any discrepancies in VLAN information at the RADIUS server Task flow Configure VLAN at RADIUS The following task flow assists you to ensure the VLAN...

Page 70: ...troubleshooting guidelines to obtain the correct RADIUS server settings 1 Obtain network information from Planning and Engineering documentation to locate server information 2 Obtain network informat...

Page 71: ...assigned VLANs These attributes are the same for all RADIUS vendors Tunnel Medium Type 802 Tunnel Pvt Group ID VLAN ID Tunnel Type Virtual LANs VLAN Configure switch The VLAN must be configured corre...

Page 72: ...multihost interface on page 73 Showing VLAN config control on page 73 Changing VLAN config from strict to flexible on page 73 Showing spanning tree on page 74 Adding RADIUS assigned VLAN to desired ST...

Page 73: ...ing EAPOL multihost interface Display the EAPOL interface information 1 Use the show eapol multihost interface port command to display the interface information 2 Note the status of ALLOW RADIUS VLANs...

Page 74: ...Identify if the RADIUS assigned VLAN and the original VLAN are in the same STG Adding RADIUS assigned VLAN to desired STG Configure the VLAN that was assigned by RADIUS to correct Spanning Tree Group...

Page 75: ...witch Configure the switch to ensure the correct settings are applied to ensure the MAC is authenticating Task flow Configure the switch The following task flow assists you to ensure the MAC is authen...

Page 76: ...Enabling allow non EAPOL clients on page 77 Showing EAPOL multihost interface on page 77 Enabling multihost status and allow non EAPOL clients on page 78 Showing EAPOL multihost non eap mac interface...

Page 77: ...to command to change port status to auto Showing EAPOL multihost Display the EAPOL multihost information 1 Enter the show eapol multihost command to display the information 2 Ensure that Allow Non EAP...

Page 78: ...command to enable multihost status Showing EAPOL multihost non eap mac interface Display the EAPOL multihost interface information 1 Enter the show eapol multihost non eap mac interface port command...

Page 79: ...ou to determine the cause of and solution for a RADIUS MAC that does not authenticate Figure 39 Non EAP RADIUS MAC not authenticating Navigation Configure switch on page 79 RADIUS server configuration...

Page 80: ...eap enabled and port at eap auto on page 81 Displaying EAPOL multihost on page 81 Enabling RADIUS to authenticate non EAPOL clients on page 81 Formatting non EAPOL RADIUS password attribute on page 81...

Page 81: ...show eapol port multihost command to display the information 2 Note the following Use RADIUS To Authenticate NonEAPOL Clients is enabled Non EAPOL RADIUS Password Attribute Format IpAddr MACAddr Port...

Page 82: ...equired changes on the RADIUS server to authenticate non EAP clients Apply changes to RADIUS server using vendor documentation RADIUS server configuration error The RADIUS server requires that the cor...

Page 83: ...e correct If it is incorrect the 2500 Series device may not authenticate See the vendor documentation for the RADIUS server for details Non EAP MHSA MAC is not authenticating Ensure that the switch is...

Page 84: ...ation Configure switch on page 84 Configure switch Configure the switch to enable MHSA Task flow Configure switch The following task flow assists you to enable MHSA on the 2500 Series device Troublesh...

Page 85: ...page 86 Showing EAPOL multihost on page 86 Formatting non EAPOL RADIUS password attribute on page 86 Showing EAPOL multihost interface on page 87 Enabling RADIUS to auth non EAP MACs on page 87 Showin...

Page 86: ...multihost information 1 Enter the show eapol port multihost command to display the information 2 Note the following Use RADIUS To Authenticate NonEAPOL Clients is enabled Formatting non EAPOL RADIUS p...

Page 87: ...on the RADIUS server to authenticate non EAP clients Apply changes to RADIUS server using vendor documentation EAP non EAP unexpected port shutdown Identify the reason for the port shutdown and make...

Page 88: ...h on page 88 Configure switch Configure ports to allow more unauthorized clients Task flow Configure switch The following task flow assists you to allow an increased number of unauthorized clients on...

Page 89: ...Showing EAPOL port information on page 90 Making changes on page 90 Showing Logs Display log information to provide additional information 1 Use the show logging command to display the log 2 Observe...

Page 90: ...w eapol port port command to display the port information 2 Observe the log output and note any anomalies Making changes This section provides troubleshooting guidelines for changing the EAP settings...

Reviews: