Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Spurious Access

Reply
Thread Tools

Spurious Access

 
 
Mark St Laurent
Guest
Posts: n/a
 
      09-30-2004
Just installed shelved router (sat for three years brand new in box) no
problems with standard ip feature set. To create firewall for organization
installed features as per below and getting spurious access errrors it only
records within a few minutes of console reload but always records the same
addresses. Router does not yet have maintenence so I can't use bug tool. I
have disabled SNMP and IPS no effect any ideas greatly appreciated.

Thanks

Mark St Laurent





Alignment data for:

3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)

Technical Support: http://www.cisco.com/techsupport

Compiled Sat 18-Sep-04 14:32 by eaarmas

No alignment data has been recorded.

Total Spurious Accesses 67, Recorded 1

Address Count Traceback

36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0

0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8


 
Reply With Quote
 
 
 
 
Ivan Ostreš
Guest
Posts: n/a
 
      09-30-2004
In article <xMY6d.22492$(E-Mail Removed) >,
stormrunner'_removethis'@comcast.net says...
> Just installed shelved router (sat for three years brand new in box) no
> problems with standard ip feature set. To create firewall for organization
> installed features as per below and getting spurious access errrors it only
> records within a few minutes of console reload but always records the same
> addresses. Router does not yet have maintenence so I can't use bug tool. I
> have disabled SNMP and IPS no effect any ideas greatly appreciated.
>
> Alignment data for:
>
> 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
>
> Technical Support: http://www.cisco.com/techsupport
>
> Compiled Sat 18-Sep-04 14:32 by eaarmas
>
> No alignment data has been recorded.
>
> Total Spurious Accesses 67, Recorded 1
>
> Address Count Traceback
>
> 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
>
> 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
>
>
>


A spurious access means that the router is trying to read from an
invalid low address, and the router corrects that by itself. This is
done under interrupt and if you have numerous spurious accesses, it can
raise the cpu utilization (67 does not look too much).

I noticed one interesting thing: you said that router does not have
maintenace (I assume you meant support contract) but you're still
running the latest IOS which could not be initially found on 3 years old
router. When you downloaded image, were there any reason to get the
newest, from the T-train specially??? If I were you, I would downgrade
to the latest mainline 12.3 version or even better to 12.2 GD mainline
version since it's much less possibility that GD image would have such
error (but these days, you never know).

HTH,

--
-Ivan.

*** Use Rot13 to see my eMail address ***
 
Reply With Quote
 
 
 
 
PES
Guest
Posts: n/a
 
      09-30-2004
Sperious access always points to a bug. You might try a slightly older
version or just using fairly standard items in your config (if you aren't
already).

Per http://www.cisco.com/warp/public/63/spuraccess.html
Spurious access is an attempt by Cisco IOS software to access memory in a
restricted location. An example of system log output for a spurious access
is shown below:

%ALIGN-3-SPURIOUS: Spurious memory access made at 0x60968C44 reading 0x0
%ALIGN-3-TRACE: -Traceback= 60968C44 60269808 602389D8 00000000 00000000
00000000
00000000 00000000
Cause
A spurious access occurs when a process attempts to read from the lowest 16
KB region of memory. This portion of memory is reserved and should never be
accessed. A read operation to this region of memory is usually caused when a
nonexisting value is returned to a function in the software, or in other
words, when a null pointer is passed to a function.

Cisco IOS Software Handling
Depending on the platform, Cisco IOS software handles spurious accesses
differently. On platforms where this is possible, the Cisco IOS software
code handles these invalid accesses by returning a value of zero and
recording the event. If this is not supported on the platform, then the
router will crash with a SegV error. Since any spurious access is
inappropriate, spurious accesses always point to a bug.

"Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
newsMY6d.22492$(E-Mail Removed) om...

> Just installed shelved router (sat for three years brand new in box) no
> problems with standard ip feature set. To create firewall for organization
> installed features as per below and getting spurious access errrors it
> only records within a few minutes of console reload but always records the
> same addresses. Router does not yet have maintenence so I can't use bug
> tool. I have disabled SNMP and IPS no effect any ideas greatly
> appreciated.
>
> Thanks
>
> Mark St Laurent
>
>
>
>
>
> Alignment data for:
>
> 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
>
> Technical Support: http://www.cisco.com/techsupport
>
> Compiled Sat 18-Sep-04 14:32 by eaarmas
>
> No alignment data has been recorded.
>
> Total Spurious Accesses 67, Recorded 1
>
> Address Count Traceback
>
> 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
>
> 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
>
>



 
Reply With Quote
 
Mark St Laurent
Guest
Posts: n/a
 
      09-30-2004
I am to replace a 1605 series router that has no firewall. The 3640 had been
unopened and sat at a sister store unused. My intent was to use this router
with firewall feature pack. I saw ciscos flash demo of the new 12.3T train
and its support for SDM which includes IPS which looked perfect for my
network. Documentation says the router as equipped (C3640 w NM-2FE2W 64\16)
supports this config. So we coughed up $1100 for IOS software from local
reseller. I flashed, set basic config, then finished config with SDM (one
step lockdown),
piece of cake if it didn't have this problem. Reluctant to smartnet router
till functioning properly maybe
future release or 12.4 M will solve. Really would like to use the
IPS(Intrusion Prevention System), not available before 12.3(T which I also
installed and had similar problems. What is the consensus on this new
technology. The intrusion inspection it does I found similar to Symantec
gateway device. Also router never averages more than 3% cpu load and 60%
free memory available
"Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
newsMY6d.22492$(E-Mail Removed) om...
> Just installed shelved router (sat for three years brand new in box) no
> problems with standard ip feature set. To create firewall for organization
> installed features as per below and getting spurious access errrors it
> only records within a few minutes of console reload but always records the
> same addresses. Router does not yet have maintenence so I can't use bug
> tool. I have disabled SNMP and IPS no effect any ideas greatly
> appreciated.
>
> Thanks
>
> Mark St Laurent
>
>
>
>
>
> Alignment data for:
>
> 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
>
> Technical Support: http://www.cisco.com/techsupport
>
> Compiled Sat 18-Sep-04 14:32 by eaarmas
>
> No alignment data has been recorded.
>
> Total Spurious Accesses 67, Recorded 1
>
> Address Count Traceback
>
> 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
>
> 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
>
>



 
Reply With Quote
 
PES
Guest
Posts: n/a
 
      09-30-2004

"Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
news:F8%6d.4759$(E-Mail Removed) ...
>I am to replace a 1605 series router that has no firewall. The 3640 had
>been unopened and sat at a sister store unused. My intent was to use this
>router with firewall feature pack. I saw ciscos flash demo of the new 12.3T
>train and its support for SDM which includes IPS which looked perfect for
>my network. Documentation says the router as equipped (C3640 w NM-2FE2W
>64\16) supports this config. So we coughed up $1100 for IOS software from
>local reseller.


This could be a case of hindsight is 20/20. I know the intent of your
message was to solicit input on users of the new IPS. I cannot comment on
that. However, I would like to mention that you could have met your
requiremtents with a 1711 with one year smartnet for under $1100 dollars.
Additionally the annual smartnet which I encourage security products would
be less than $100 anually vs a little more than $1100 dollars a year with
your 3640. We have found this to be the case often when trying to use
something just because we all ready have it. Now if you are in need of
equipmint that can terminate 5 or 6 t1's you have the right equipment. This
would be where the ids/fw and IPS capability would come into play with the
3640 (building extranet links) or links to untrusted branches. Or it would
also work well for terminating 6 or so internet connections. However, the
recurring cost is going to kill you if you don't need the density.

> I flashed, set basic config, then finished config with SDM (one step
> lockdown),
> piece of cake if it didn't have this problem. Reluctant to smartnet router
> till functioning properly maybe
> future release or 12.4 M will solve. Really would like to use the
> IPS(Intrusion Prevention System), not available before 12.3(T which I
> also installed and had similar problems. What is the consensus on this new
> technology. The intrusion inspection it does I found similar to Symantec
> gateway device. Also router never averages more than 3% cpu load and 60%
> free memory available
> "Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
> newsMY6d.22492$(E-Mail Removed) om...
>> Just installed shelved router (sat for three years brand new in box) no
>> problems with standard ip feature set. To create firewall for
>> organization installed features as per below and getting spurious access
>> errrors it only records within a few minutes of console reload but always
>> records the same addresses. Router does not yet have maintenence so I
>> can't use bug tool. I have disabled SNMP and IPS no effect any ideas
>> greatly appreciated.
>>
>> Thanks
>>
>> Mark St Laurent
>>
>>
>>
>>
>>
>> Alignment data for:
>>
>> 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
>>
>> Technical Support: http://www.cisco.com/techsupport
>>
>> Compiled Sat 18-Sep-04 14:32 by eaarmas
>>
>> No alignment data has been recorded.
>>
>> Total Spurious Accesses 67, Recorded 1
>>
>> Address Count Traceback
>>
>> 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
>>
>> 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
>>
>>

>
>



 
Reply With Quote
 
Mark St Laurent
Guest
Posts: n/a
 
      10-01-2004
Sometime within the next 8 months we will be opening a satellite showroom
about one mile from here all server systems will be provided to it from this
location. I have a 1720 that was originally configured for 56k DDS that
hopefully can be configured for channelized T1 to 3640 (channelized required
by network connection for phone system a 4 yr old ComDial)
"PES" <NO*SPAMpestewartREMOVE*(E-Mail Removed)*SUCK S> wrote in message
news:415c8e82$(E-Mail Removed)...
>
> "Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
> news:F8%6d.4759$(E-Mail Removed) ...
>>I am to replace a 1605 series router that has no firewall. The 3640 had
>>been unopened and sat at a sister store unused. My intent was to use this
>>router with firewall feature pack. I saw ciscos flash demo of the new
>>12.3T train and its support for SDM which includes IPS which looked
>>perfect for my network. Documentation says the router as equipped (C3640 w
>>NM-2FE2W 64\16) supports this config. So we coughed up $1100 for IOS
>>software from local reseller.

>
> This could be a case of hindsight is 20/20. I know the intent of your
> message was to solicit input on users of the new IPS. I cannot comment on
> that. However, I would like to mention that you could have met your
> requiremtents with a 1711 with one year smartnet for under $1100 dollars.
> Additionally the annual smartnet which I encourage security products would
> be less than $100 anually vs a little more than $1100 dollars a year with
> your 3640. We have found this to be the case often when trying to use
> something just because we all ready have it. Now if you are in need of
> equipmint that can terminate 5 or 6 t1's you have the right equipment.
> This would be where the ids/fw and IPS capability would come into play
> with the 3640 (building extranet links) or links to untrusted branches.
> Or it would also work well for terminating 6 or so internet connections.
> However, the recurring cost is going to kill you if you don't need the
> density.
>
>> I flashed, set basic config, then finished config with SDM (one step
>> lockdown),
>> piece of cake if it didn't have this problem. Reluctant to smartnet
>> router till functioning properly maybe
>> future release or 12.4 M will solve. Really would like to use the
>> IPS(Intrusion Prevention System), not available before 12.3(T which I
>> also installed and had similar problems. What is the consensus on this
>> new technology. The intrusion inspection it does I found similar to
>> Symantec gateway device. Also router never averages more than 3% cpu load
>> and 60% free memory available
>> "Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
>> newsMY6d.22492$(E-Mail Removed) om...
>>> Just installed shelved router (sat for three years brand new in box) no
>>> problems with standard ip feature set. To create firewall for
>>> organization installed features as per below and getting spurious access
>>> errrors it only records within a few minutes of console reload but
>>> always records the same addresses. Router does not yet have maintenence
>>> so I can't use bug tool. I have disabled SNMP and IPS no effect any
>>> ideas greatly appreciated.
>>>
>>> Thanks
>>>
>>> Mark St Laurent
>>>
>>>
>>>
>>>
>>>
>>> Alignment data for:
>>>
>>> 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
>>>
>>> Technical Support: http://www.cisco.com/techsupport
>>>
>>> Compiled Sat 18-Sep-04 14:32 by eaarmas
>>>
>>> No alignment data has been recorded.
>>>
>>> Total Spurious Accesses 67, Recorded 1
>>>
>>> Address Count Traceback
>>>
>>> 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
>>>
>>> 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
>>>
>>>

>>
>>

>
>



 
Reply With Quote
 
MC
Guest
Posts: n/a
 
      10-01-2004
Cisco has been shipping many version 2 cards for several devices forcing us
to a 12.3 release to support the newer hardware versions. We order many of
the same configurations, Now I have to support newer IOS than wanted to with
the new routers, have different hardware versions in production and have to
support multiple versions IOS since many of the routers already installed
100+ would require upgrades to run 12.3 @#$%


"Ivan Ostres" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed) t...
> In article <xMY6d.22492$(E-Mail Removed) >,
> stormrunner'_removethis'@comcast.net says...
> > Just installed shelved router (sat for three years brand new in box) no
> > problems with standard ip feature set. To create firewall for

organization
> > installed features as per below and getting spurious access errrors it

only
> > records within a few minutes of console reload but always records the

same
> > addresses. Router does not yet have maintenence so I can't use bug tool.

I
> > have disabled SNMP and IPS no effect any ideas greatly appreciated.
> >
> > Alignment data for:
> >
> > 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
> >
> > Technical Support: http://www.cisco.com/techsupport
> >
> > Compiled Sat 18-Sep-04 14:32 by eaarmas
> >
> > No alignment data has been recorded.
> >
> > Total Spurious Accesses 67, Recorded 1
> >
> > Address Count Traceback
> >
> > 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
> >
> > 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
> >
> >
> >

>
> A spurious access means that the router is trying to read from an
> invalid low address, and the router corrects that by itself. This is
> done under interrupt and if you have numerous spurious accesses, it can
> raise the cpu utilization (67 does not look too much).
>
> I noticed one interesting thing: you said that router does not have
> maintenace (I assume you meant support contract) but you're still
> running the latest IOS which could not be initially found on 3 years old
> router. When you downloaded image, were there any reason to get the
> newest, from the T-train specially??? If I were you, I would downgrade
> to the latest mainline 12.3 version or even better to 12.2 GD mainline
> version since it's much less possibility that GD image would have such
> error (but these days, you never know).
>
> HTH,
>
> --
> -Ivan.
>
> *** Use Rot13 to see my eMail address ***



 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Spurious Internet Connection ch742718 Hardware 5 07-19-2006 06:12 AM
spurious DMZ Barrett Bonden Cisco 1 02-01-2006 05:50 AM
Status query: Java 1.5 Linux spurious mouse clicked events. Ian A. Mason Java 0 02-24-2005 04:15 AM
Re: spurious wakeup Markus Elfring C++ 10 11-30-2004 10:07 PM
Re: spurious wakeup Markus Elfring C++ 0 11-25-2004 11:34 AM



Advertisments