cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
705
Views
0
Helpful
12
Replies

Accessing 4006 Swithc via Web

utawakevou
Level 4
Level 4

I have installed a 4006 Cisco Switch(supervisor engine 2) and want to access it via Web interface. I have setup the interface me1 and have already patch it up on a switch. I have already create localuser and can access it via SSH and telnet.

When I use a browser to access the switch it prompts me with a username and password. When I enter my localuser accounts and password it cant get me through. The switch got its own access and enable password which I tried but to no avail.

Is there something that I should enable from the switch or is it my browser. Im using IE 6.0

1 Accepted Solution

Accepted Solutions

Hi,

you are using a cryptographic sw image, aren't you?

(The file names in sh flash output are incomplete, but I think the warnig in the sh ver output is notifying that.)

If yes, the HTTP access to the switch is not allowed, I'm afraid.

I can't find the proper document confirming this at the moment.

But I remember testing cryptographing image two years ago with the conclusion web access was not allowed (and some document saying that).

Try to check your CatOS release notes, it might noticed this limit.

Regrads,

Milan

View solution in original post

12 Replies 12

Hello,

can you post your configuration ?

Regards,

Georg

I dont believe I can post it here. I tried posting a whole config before but it couldnt process it because it is too large to be posted. I can e-mail it to you provided you give me your e-mail address.

milan.kulik
Level 10
Level 10

Hi, I suppose you are running CatOS (I'm not sure if IOS supports http access on 4006s).

You need to

1) Download additional Ciscoview ADP Flash Code file to your switch flash. You can find it on Software Center (http://www.cisco.com/cgi-bin/tablebuild.pl/cat4000), the file has -cv- included in the name (cat4000-cv.8-3-1-GLX.bin if you are running CatOS 8-3-1-GLX).

2) Enable http server by set ip http server enable.

3) You can check by sh ip http

The output should look like:

HTTP Information

----------------------

HTTP server: enabled

HTTP port: 80

Web Interface: Supported

Web Interface version(s):

Engine: 5.3.4 ADP device: Cat4000 ADP Version: 4.1 ADK: 40

4) When prompted, try to use enable password without any user name.

This works with traditional CatOS setting (no local user).

BTW, Netscapr 4.79 work much faster than IE with my CatOS switches.

Regards,

Milan

Thank you for your message. Yes I think HTTP is enabled on this switch. When I do a SHOW IP HTTP it gives me that output.

Anyway, I got some of the ports enabled for gigabit etherchannel and when I log into the switch I got come of this warning console messages:

2004 Mar 03 08:30:10 %SYS-4-P2_WARN: 1/Host 00:08:02:de:37:17 is flapping betwe8

2004 Mar 03 08:30:21 %SYS-4-P2_WARN: 1/Host 00:02:a5:da:9b:58 is flapping betwe0

2004 Mar 03 08:30:33 %SYS-4-P2_WARN: 1/Host 00:08:02:de:96:72 is flapping betwe2

2004 Mar 03 08:30:41 %SYS-4-P2_WARN: 1/Host 00:08:02:de:37:17 is flapping betwe8

What is the meaning of this messages. Is there something wrong with my etherchannel config or is it the server end.

Hi,

are you receiving these messages all the time? If yes, there is something wrong in your STP.

The switch is receiving frames with the same MAC source address on two different ports.

If your Gigabit Etherchannel ports are mentioned in the messages I'd guess there is something wrong with the etherchannel configuration or with the fibers.

Regards,

Milan

Thank you very much for your message. Yes we found out that the server's NIC were not configured properly for Gigabit Etherchannel. This was later fixed and the error messages has gone

However Im still having problem trying to access the switch via Web

Thanks

Which CatOS and ADP file version are you running?

When does the web access freeze?

Do you receive the initial screen with the

"CiscoView for Catalyst Switch (version -4.1) - Manage the Catalyst Switch via CiscoView interface. " line?

When you click on it, do you receive a user/password prompt?

After responding, do you receive enable-access password prompt?

(It's very importatnt toreply withenable password without any user name, I think!!!)

After responding, do you receive the community string prompt?

Finally you should get the screen showing the switch with LEDs shining.

So WHEN exactly does the screen freeze?

Have you tried another browser (Netscape 4.79 work OK for me, e.g.)

Another problem might be caused by improper Java aplet (but it should give you a warning, I hope.)

Regards,

Milan

Below is the current version and show flash result:

ITC-Govnet-Switch> (enable) show version

WARNING: This product contains cryptographic features and is subject to United

States and local country laws governing import, export, transfer and use.

Delivery of Cisco cryptographic products does not imply third-party authority

to import, export, distribute or use encryption. Importers, exporters,

distributors and users are responsible for compliance with U.S. and local

country laws. By using this product you agree to comply with applicable

laws and regulations. If you are unable to comply with U.S. and local laws,

return this product immediately.

WS-C4006 Software, Version NmpSW: 8.1(1)

Copyright (c) 1995-2003 by Cisco Systems, Inc.

NMP S/W compiled on Jul 10 2003, 16:05:34

GSP S/W compiled on Jul 10 2003, 13:59:37

System Bootstrap Version: 5.4(1)

Hardware Version: 3.2 Model: WS-C4006 Serial #: FOX053701SN

Mod Port Model Serial # Versions

--- ---- ------------------ -------------------- -------------------------------

1 2 WS-X4013 JAB054109J2 Hw : 3.2

Gsp: 8.1(1.0)

Nmp: 8.1(1)

2 48 WS-X4448-GB-RJ45 JAB064607SQ Hw : 1.0

6 48 WS-X4148-RJ45V JAB054704F2 Hw : 1.5

DRAM FLASH NVRAM

Module Total Used Free Total Used Free Total Used Free

------ ------- ------- ------- ------- ------- ------- ----- ----- -----

1 65536K 39320K 26216K 16384K 10748K 5636K 480K 343K 137K

Uptime is 102 days, 12 hours, 59 minutes

ITC-Govnet-Switch> (enable) show flash

-#- ED --type-- --crc--- -seek-- nlen -length- -----date/time------ name

1 .. ffffffff 7292926 4cef68 20 4779752 Jun 11 2003 10:08:29 cat4000-k8.n

2 .. ffffffff d8c9458c 991fec 20 4993028 Sep 04 2003 09:39:23 cat4000-k9.n

3 .. ffffffff 7a27bf3f 99c300 7 41618 Sep 10 2003 11:11:39 module2

4 .. ffffffff f646f3e7 99ed40 3 10685 Sep 30 2003 08:47:34 run

5771968 bytes available (9825600 bytes used)

When I put in the IP address of the switch to my browser, it prompts me with a username and password. When I enter the enable password without the username this comes up:

Accessing Cisco Catalyst Switch

--------------------------------------------------------------------------------

Help resources

CCO at www.cisco.com - Cisco Connection Online, including the Technical Assistance Center (TAC).

tac@cisco.com - e-mail the TAC.

1-800-553-2447 or +1-408-526-7209 - phone the TAC.

cs-html@cisco.com - e-mail the HTML interface development group.

This happens when I put in the sc0 or the me1 IP address to the address bar of my browser eg. http://10.1.85.8. I havent tried out that Netscape version. I even try out Netscape version 6. I think it could be the Java aplet settings of my IE 6. Is there a special setting that we should enable on the browser.

Please do let me know

Hi,

you are using a cryptographic sw image, aren't you?

(The file names in sh flash output are incomplete, but I think the warnig in the sh ver output is notifying that.)

If yes, the HTTP access to the switch is not allowed, I'm afraid.

I can't find the proper document confirming this at the moment.

But I remember testing cryptographing image two years ago with the conclusion web access was not allowed (and some document saying that).

Try to check your CatOS release notes, it might noticed this limit.

Regrads,

Milan

Thank you very much for the informative message. Yes that is what I figure out. Since I have enable SSH.

Do you have any information or link about the following 4006 Switch modules:

Model WS-X4013

Model WS-X4448-GB-RJ45

Model WS-X4148-RJ45V

Thank you

I have a similar issue with a 4006. I'm quite sure this unit has not been updated so this may just be an older version issue. In my case I get the "CiscoView for Catalyst Switch (version -1.6)". Normally I would click on this and get the second user/password prompt. Now the normal window opens ("http://{my4006IPaddr}/v-1.6Cat4000.html") that is empty - which is not normal. A "view source" show an complete empty page. I've tried this on WinXP/IE6 and an old Win98/IE5.5.

A 'sh ver' from a telnet session returns the following:

TWC RNEWS 4006-1> sh ver

WS-C4006 Software, Version NmpSW: 6.3(5)

Copyright (c) 1995-2002 by Cisco Systems, Inc.

NMP S/W compiled on Feb 7 2002, 21:00:39

GSP S/W compiled on Feb 07 2002, 18:11:42

System Bootstrap Version: 5.4(1)

Hardware Version: 3.2 Model: WS-C4006 Serial #: FOX061100A0

Mod Port Model Serial # Versions

--- ---- ---------- -------------------- ---------------------------------

1 2 WS-X4013 JAE061601K3 Hw : 3.2

Gsp: 6.3(5.0)

Nmp: 6.3(5)

2 48 WS-X4148-RJ JAE061200P7 Hw : 3.0

3 48 WS-X4148-RJ JAE0614060P Hw : 3.0

4 48 WS-X4148-RJ JAE061406BY Hw : 3.0

DRAM FLASH NVRAM

Module Total Used Free Total Used Free Total Used Free

------ ------- ------- ------- ------- ------- ------- ----- ----- -----

1 65536K 33802K 31734K 16384K 7000K 9384K 480K 238K 242K

Uptime is 690 days, 4 hours, 1 minute

TWC RNEWS 4006-1>

Hopefully you'll be able to help me as you did the other gentleman. Any guidance would be greatly appreciated.

Thank you,

Jake Roztocil

Hi,

what is your "sh ip http" output?

Regards,

Milan