3com switch configuration file is not used: Tips and tricks for restoring your switch settings
- geobooystantio1981
- Aug 18, 2023
- 6 min read
As I understand it, if you do not know any usernames/passwords for the switch your only option is to perform a factory reset, losing ALL configuration from the switch. So hopefully you have an up-to-date backup of the config to re-apply, or it was a simply setup you can remember. You need to do this out of hours if it's in production!
1. Download application file to flash2. Select application file to boot3. Display all files in flash4. Delete file from flash5. Modify BootRom password6. Enter BootRom upgrade menu7. Skip current system configuration8. Set BootRom password recovery9. Set switch startup mode0. Reboot
3com Switch Configuration File Is Not Used
The current setting will run with current configuration file when reboot.Are you sure you want to skip current configuration file when reboot? Yes orNo (Y/N):YSetting...Done!
1. Download application file to flash2. Select application file to boot3. Display all files in flash4. Delete file from flash5. Modify BootRom password6. Enter BootRom upgrade menu7. Skip current system configuration8. Set BootRom password recovery9. Set switch startup mode0. Reboot
initialize The startup configuration file will be deleted and the system will be rebooted. Continue? [Y/N]:Y Please wait...#Apr 26 12:00:33:537 2000 3Com Baseline Switch DEV/1/REBOOT: Reboot device by command.
Press Ctrl-B to enter Extended Boot menu...0Starting to get the main application file--flash:/S2900-CMW520-R1101P09.bin!.............................................................................The main application file is self-decompressing........................................................................................................................................Done!System is starting...Startup configuration file does not exist.User interface aux0 is available.
I have a 3com 5500-EI switch which i have defaulted by using option 7 in the bootrom. However, now the switch will always skip the current config file so I can not upload any config to it, i have tried using the default file name and other file names and changing the startup config to use this file but it will still only ever load the default config.
Hi all -- has anyone encountered or resolved an issue with saving changes to 3com 5500 series switches? I am able to download the current configuration or script an update but am unable to save. Tried creating a template variable and executing from command script without success.
I have now managed to import the config from the HP 2530 into the 2930F units. Following some research and a few failed import attempts I discovered I needed to add the switch details/module into the header of the config file. So I added;
I had a go at importing the 3Com core switch config into the new 2930F Core switch but that didn't go well at all, there is a big difference in how the 3Com cfg file is written compared to how the HP 2530 pcc file wrtten. So now it's back to the drawing board and more research.
This is proving to be a very tedious exercise.... I have been trying to figure out what the individual lines mean in the 3Com switch's cfg file and then looking for the associated Aruba command, this is proving to be very difficult. The client is putting pressure on me to get the new switches in place despite me telling them in advance that this was not my area of expertise and that I would make a best effort attempt.
If the 3Com PC Card device is recognized, the pcelx driver is automatically loaded, ports and IRQs allocated, and specialfiles created (if they don't already exist). No manual configuration of thehardware is necessary or possible.
It's possible that the command parser is choking on the :/ or is not expecting an absolute path. Your command line is otherwise the same as the example given in the documentation I have on a random 3com managed switch, for what it's worth.
sysreset saved-configurationThis will erase all current settings in Flash memory. Note this does not affect any saved startup file(s). You should still at least set an ip address for the switch as a whole and save to a config file. This way you can ping the switch and access the web interface:
If your management authentication on your switch is default, applying theconfiguration above will have your authentication switch to a RADIUS based onewith PacketFence as the authentication server. It is almost certain that youdo not want that!
If your management authentication on your switch is default, applying the configuration abovewill have your authentication switch to a RADIUS based one with PacketFence as theauthentication server. It is almost certain that you do not want that!
Those switches are now supported using 802.1X for networks with or without VoIP.You can also use port-security with static MAC address but we can not securea MAC on the data VLAN specifically so enable it if there is no VoIP, uselinkUp/linkDown and MAC notification otherwise.So on setup that needs tohandle VoIP with this switch, go with a 802.1X configuration.
The 4500 Series and all the stacked switches work exactly the same way as if they were not stacked so the configuration is the same: they support port-security with static MAC address and allow us to secure a MAC on the data VLAN so we enable it whether there is VoIP or not.
PacketFence supports the 1800 series Router with linkUp / linkDown traps. It cannot doanything about the router interfaces (ie: fa0 and fa1 on a 1811). VLAN interfaces ifIndex shouldalso be marked as uplinks in the PacketFence switch configuration as they generate traps butare of no interest to PacketFence (layer 3).
Device sensor is a way to be able to receive some information about endpoints from the RADIUS accounting packet. (like DHCP, CDP, LLDP and HTTP information)In order to enable Device Sensor feature, you need to add the following parameters to your switch configuration:
Nothing is required to activate VoIP on the switch, you must simply configure the voice VLAN you want PacketFence to assign in the PacketFence switch configuration as well as enabling VoIP there. Note that your phones must not tag their packets on the network and should send their traffic untagged when connected into a PacketFence enabled port. This means you should not have the voice VLAN capabilities enabled on the switch itself as they might conflict with the authorization attributes returned by PacketFence.
In version 6 or later of the HiveOS, we do return VLAN ID matching the number that the User Profile has. Create your User Profile in the HiveManager as usual, assign the matching VLAN, and in PacketFence configuration add the wanted VLAN ID in the section Roles by VLAN.
Ruckus allows you to define roles. These roles link all users to the internal WLAN and permit access to all WLAN by default. You can still limit access to certain WLAN.Additionally, these roles can be used to apply per-user rate-limits and ACLs in newer versions of the Zone Director firmware, specifying also advanced options like Application Recognition Policies, URL filtering profiles, Etc.
For the Authentication & Accounting Service enable the "Use controller as proxy" checkbox for bothAuthentication and Accounting and select the previously created Authentication and Accounting profiles.(PacketFence-Auth and PacketFence-Acct respectively if you used the names suggested above)
Ruckus SmartZone allows you to define roles for RBAC purposes. They can be used to apply per-user rate-limitsand ACLs in newer versions of the SmartZone firmware, specifying also advanced options like Application RecognitionPolicies, URL filtering profiles, (Firwewall profiles)
A new window will open where we can create a "User Traffic Profile Mapping". Under Group Attribute Value enterthe string that will be sent from PacketFence (Configured under the Switch configuration in the"Role by Switch Role" section). This string must match between PacketFence and SmartZone and is the string sentin the RADIUS reply under the Ruckus-User-Group VSA. Then, under the "User Role", select the previously created User Role.
If you decide to define the AP by ip then you will need to define the controller as a switch and define the Controller IP and Webservices information (Transport/Username/Password) in his configuration.
Kiwi CatTools supports many 3Com superstack switches: 610 / 630 / 1100 / 3300 / 3300 FX / 3300XM / 3300TM / 3300SM / 3300MM. However, it has been found that 3Com switches can have issues when backing up the configuration of your switch.
Although telnet is not the most elegant, nor the most efficient, way to obtain the configuration of a 3Com switch, there aren't many other practical options. By capturing the output of various display commands, CatTools provides a readable list of configured settings in case of switch failure.
Since the chance of a switch crash, backup of the devices should only occur during times of low traffic use or after hours and you should reduce the frequency of your backups. Only make a backup when you believe the configuration has changed. Use the device Admin user account instead of the Security user account to login.
When setting up your switch device, ensure that you enter the username and passwords for the device into the appropriate fields. Leave the VTY and enable passwords blank as they are not used for 3Com superstack switches. The standard 3Com usernames are: 2ff7e9595c
Comments