Spurious Access

Discussion in 'Cisco' started by Mark St Laurent, Sep 30, 2004.

  1. Just installed shelved router (sat for three years brand new in box) no
    problems with standard ip feature set. To create firewall for organization
    installed features as per below and getting spurious access errrors it only
    records within a few minutes of console reload but always records the same
    addresses. Router does not yet have maintenence so I can't use bug tool. I
    have disabled SNMP and IPS no effect any ideas greatly appreciated.

    Thanks

    Mark St Laurent





    Alignment data for:

    3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)

    Technical Support: http://www.cisco.com/techsupport

    Compiled Sat 18-Sep-04 14:32 by eaarmas

    No alignment data has been recorded.

    Total Spurious Accesses 67, Recorded 1

    Address Count Traceback

    36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0

    0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
     
    Mark St Laurent, Sep 30, 2004
    #1
    1. Advertising

  2. Mark St Laurent

    Ivan Ostreš Guest

    In article <xMY6d.22492$>,
    stormrunner'_removethis'@comcast.net says...
    > Just installed shelved router (sat for three years brand new in box) no
    > problems with standard ip feature set. To create firewall for organization
    > installed features as per below and getting spurious access errrors it only
    > records within a few minutes of console reload but always records the same
    > addresses. Router does not yet have maintenence so I can't use bug tool. I
    > have disabled SNMP and IPS no effect any ideas greatly appreciated.
    >
    > Alignment data for:
    >
    > 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
    >
    > Technical Support: http://www.cisco.com/techsupport
    >
    > Compiled Sat 18-Sep-04 14:32 by eaarmas
    >
    > No alignment data has been recorded.
    >
    > Total Spurious Accesses 67, Recorded 1
    >
    > Address Count Traceback
    >
    > 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
    >
    > 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
    >
    >
    >


    A spurious access means that the router is trying to read from an
    invalid low address, and the router corrects that by itself. This is
    done under interrupt and if you have numerous spurious accesses, it can
    raise the cpu utilization (67 does not look too much).

    I noticed one interesting thing: you said that router does not have
    maintenace (I assume you meant support contract) but you're still
    running the latest IOS which could not be initially found on 3 years old
    router. When you downloaded image, were there any reason to get the
    newest, from the T-train specially??? If I were you, I would downgrade
    to the latest mainline 12.3 version or even better to 12.2 GD mainline
    version since it's much less possibility that GD image would have such
    error (but these days, you never know).

    HTH,

    --
    -Ivan.

    *** Use Rot13 to see my eMail address ***
     
    Ivan Ostreš, Sep 30, 2004
    #2
    1. Advertising

  3. Mark St Laurent

    PES Guest

    Sperious access always points to a bug. You might try a slightly older
    version or just using fairly standard items in your config (if you aren't
    already).

    Per http://www.cisco.com/warp/public/63/spuraccess.html
    Spurious access is an attempt by Cisco IOS software to access memory in a
    restricted location. An example of system log output for a spurious access
    is shown below:

    %ALIGN-3-SPURIOUS: Spurious memory access made at 0x60968C44 reading 0x0
    %ALIGN-3-TRACE: -Traceback= 60968C44 60269808 602389D8 00000000 00000000
    00000000
    00000000 00000000
    Cause
    A spurious access occurs when a process attempts to read from the lowest 16
    KB region of memory. This portion of memory is reserved and should never be
    accessed. A read operation to this region of memory is usually caused when a
    nonexisting value is returned to a function in the software, or in other
    words, when a null pointer is passed to a function.

    Cisco IOS Software Handling
    Depending on the platform, Cisco IOS software handles spurious accesses
    differently. On platforms where this is possible, the Cisco IOS software
    code handles these invalid accesses by returning a value of zero and
    recording the event. If this is not supported on the platform, then the
    router will crash with a SegV error. Since any spurious access is
    inappropriate, spurious accesses always point to a bug.

    "Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
    news:xMY6d.22492$...

    > Just installed shelved router (sat for three years brand new in box) no
    > problems with standard ip feature set. To create firewall for organization
    > installed features as per below and getting spurious access errrors it
    > only records within a few minutes of console reload but always records the
    > same addresses. Router does not yet have maintenence so I can't use bug
    > tool. I have disabled SNMP and IPS no effect any ideas greatly
    > appreciated.
    >
    > Thanks
    >
    > Mark St Laurent
    >
    >
    >
    >
    >
    > Alignment data for:
    >
    > 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
    >
    > Technical Support: http://www.cisco.com/techsupport
    >
    > Compiled Sat 18-Sep-04 14:32 by eaarmas
    >
    > No alignment data has been recorded.
    >
    > Total Spurious Accesses 67, Recorded 1
    >
    > Address Count Traceback
    >
    > 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
    >
    > 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
    >
    >
     
    PES, Sep 30, 2004
    #3
  4. I am to replace a 1605 series router that has no firewall. The 3640 had been
    unopened and sat at a sister store unused. My intent was to use this router
    with firewall feature pack. I saw ciscos flash demo of the new 12.3T train
    and its support for SDM which includes IPS which looked perfect for my
    network. Documentation says the router as equipped (C3640 w NM-2FE2W 64\16)
    supports this config. So we coughed up $1100 for IOS software from local
    reseller. I flashed, set basic config, then finished config with SDM (one
    step lockdown),
    piece of cake if it didn't have this problem. Reluctant to smartnet router
    till functioning properly maybe
    future release or 12.4 M will solve. Really would like to use the
    IPS(Intrusion Prevention System), not available before 12.3(8)T which I also
    installed and had similar problems. What is the consensus on this new
    technology. The intrusion inspection it does I found similar to Symantec
    gateway device. Also router never averages more than 3% cpu load and 60%
    free memory available
    "Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
    news:xMY6d.22492$...
    > Just installed shelved router (sat for three years brand new in box) no
    > problems with standard ip feature set. To create firewall for organization
    > installed features as per below and getting spurious access errrors it
    > only records within a few minutes of console reload but always records the
    > same addresses. Router does not yet have maintenence so I can't use bug
    > tool. I have disabled SNMP and IPS no effect any ideas greatly
    > appreciated.
    >
    > Thanks
    >
    > Mark St Laurent
    >
    >
    >
    >
    >
    > Alignment data for:
    >
    > 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
    >
    > Technical Support: http://www.cisco.com/techsupport
    >
    > Compiled Sat 18-Sep-04 14:32 by eaarmas
    >
    > No alignment data has been recorded.
    >
    > Total Spurious Accesses 67, Recorded 1
    >
    > Address Count Traceback
    >
    > 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
    >
    > 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
    >
    >
     
    Mark St Laurent, Sep 30, 2004
    #4
  5. Mark St Laurent

    PES Guest

    "Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
    news:F8%6d.4759$...
    >I am to replace a 1605 series router that has no firewall. The 3640 had
    >been unopened and sat at a sister store unused. My intent was to use this
    >router with firewall feature pack. I saw ciscos flash demo of the new 12.3T
    >train and its support for SDM which includes IPS which looked perfect for
    >my network. Documentation says the router as equipped (C3640 w NM-2FE2W
    >64\16) supports this config. So we coughed up $1100 for IOS software from
    >local reseller.


    This could be a case of hindsight is 20/20. I know the intent of your
    message was to solicit input on users of the new IPS. I cannot comment on
    that. However, I would like to mention that you could have met your
    requiremtents with a 1711 with one year smartnet for under $1100 dollars.
    Additionally the annual smartnet which I encourage security products would
    be less than $100 anually vs a little more than $1100 dollars a year with
    your 3640. We have found this to be the case often when trying to use
    something just because we all ready have it. Now if you are in need of
    equipmint that can terminate 5 or 6 t1's you have the right equipment. This
    would be where the ids/fw and IPS capability would come into play with the
    3640 (building extranet links) or links to untrusted branches. Or it would
    also work well for terminating 6 or so internet connections. However, the
    recurring cost is going to kill you if you don't need the density.

    > I flashed, set basic config, then finished config with SDM (one step
    > lockdown),
    > piece of cake if it didn't have this problem. Reluctant to smartnet router
    > till functioning properly maybe
    > future release or 12.4 M will solve. Really would like to use the
    > IPS(Intrusion Prevention System), not available before 12.3(8)T which I
    > also installed and had similar problems. What is the consensus on this new
    > technology. The intrusion inspection it does I found similar to Symantec
    > gateway device. Also router never averages more than 3% cpu load and 60%
    > free memory available
    > "Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
    > news:xMY6d.22492$...
    >> Just installed shelved router (sat for three years brand new in box) no
    >> problems with standard ip feature set. To create firewall for
    >> organization installed features as per below and getting spurious access
    >> errrors it only records within a few minutes of console reload but always
    >> records the same addresses. Router does not yet have maintenence so I
    >> can't use bug tool. I have disabled SNMP and IPS no effect any ideas
    >> greatly appreciated.
    >>
    >> Thanks
    >>
    >> Mark St Laurent
    >>
    >>
    >>
    >>
    >>
    >> Alignment data for:
    >>
    >> 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
    >>
    >> Technical Support: http://www.cisco.com/techsupport
    >>
    >> Compiled Sat 18-Sep-04 14:32 by eaarmas
    >>
    >> No alignment data has been recorded.
    >>
    >> Total Spurious Accesses 67, Recorded 1
    >>
    >> Address Count Traceback
    >>
    >> 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
    >>
    >> 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
    >>
    >>

    >
    >
     
    PES, Sep 30, 2004
    #5
  6. Sometime within the next 8 months we will be opening a satellite showroom
    about one mile from here all server systems will be provided to it from this
    location. I have a 1720 that was originally configured for 56k DDS that
    hopefully can be configured for channelized T1 to 3640 (channelized required
    by network connection for phone system a 4 yr old ComDial)
    "PES" <NO*SPAMpestewartREMOVE**SUCKS> wrote in message
    news:415c8e82$...
    >
    > "Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
    > news:F8%6d.4759$...
    >>I am to replace a 1605 series router that has no firewall. The 3640 had
    >>been unopened and sat at a sister store unused. My intent was to use this
    >>router with firewall feature pack. I saw ciscos flash demo of the new
    >>12.3T train and its support for SDM which includes IPS which looked
    >>perfect for my network. Documentation says the router as equipped (C3640 w
    >>NM-2FE2W 64\16) supports this config. So we coughed up $1100 for IOS
    >>software from local reseller.

    >
    > This could be a case of hindsight is 20/20. I know the intent of your
    > message was to solicit input on users of the new IPS. I cannot comment on
    > that. However, I would like to mention that you could have met your
    > requiremtents with a 1711 with one year smartnet for under $1100 dollars.
    > Additionally the annual smartnet which I encourage security products would
    > be less than $100 anually vs a little more than $1100 dollars a year with
    > your 3640. We have found this to be the case often when trying to use
    > something just because we all ready have it. Now if you are in need of
    > equipmint that can terminate 5 or 6 t1's you have the right equipment.
    > This would be where the ids/fw and IPS capability would come into play
    > with the 3640 (building extranet links) or links to untrusted branches.
    > Or it would also work well for terminating 6 or so internet connections.
    > However, the recurring cost is going to kill you if you don't need the
    > density.
    >
    >> I flashed, set basic config, then finished config with SDM (one step
    >> lockdown),
    >> piece of cake if it didn't have this problem. Reluctant to smartnet
    >> router till functioning properly maybe
    >> future release or 12.4 M will solve. Really would like to use the
    >> IPS(Intrusion Prevention System), not available before 12.3(8)T which I
    >> also installed and had similar problems. What is the consensus on this
    >> new technology. The intrusion inspection it does I found similar to
    >> Symantec gateway device. Also router never averages more than 3% cpu load
    >> and 60% free memory available
    >> "Mark St Laurent" <stormrunner'_removethis'@comcast.net> wrote in message
    >> news:xMY6d.22492$...
    >>> Just installed shelved router (sat for three years brand new in box) no
    >>> problems with standard ip feature set. To create firewall for
    >>> organization installed features as per below and getting spurious access
    >>> errrors it only records within a few minutes of console reload but
    >>> always records the same addresses. Router does not yet have maintenence
    >>> so I can't use bug tool. I have disabled SNMP and IPS no effect any
    >>> ideas greatly appreciated.
    >>>
    >>> Thanks
    >>>
    >>> Mark St Laurent
    >>>
    >>>
    >>>
    >>>
    >>>
    >>> Alignment data for:
    >>>
    >>> 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
    >>>
    >>> Technical Support: http://www.cisco.com/techsupport
    >>>
    >>> Compiled Sat 18-Sep-04 14:32 by eaarmas
    >>>
    >>> No alignment data has been recorded.
    >>>
    >>> Total Spurious Accesses 67, Recorded 1
    >>>
    >>> Address Count Traceback
    >>>
    >>> 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
    >>>
    >>> 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
    >>>
    >>>

    >>
    >>

    >
    >
     
    Mark St Laurent, Oct 1, 2004
    #6
  7. Mark St Laurent

    MC Guest

    Cisco has been shipping many version 2 cards for several devices forcing us
    to a 12.3 release to support the newer hardware versions. We order many of
    the same configurations, Now I have to support newer IOS than wanted to with
    the new routers, have different hardware versions in production and have to
    support multiple versions IOS since many of the routers already installed
    100+ would require upgrades to run 12.3 @#$%


    "Ivan Ostres" <> wrote in message
    news:...
    > In article <xMY6d.22492$>,
    > stormrunner'_removethis'@comcast.net says...
    > > Just installed shelved router (sat for three years brand new in box) no
    > > problems with standard ip feature set. To create firewall for

    organization
    > > installed features as per below and getting spurious access errrors it

    only
    > > records within a few minutes of console reload but always records the

    same
    > > addresses. Router does not yet have maintenence so I can't use bug tool.

    I
    > > have disabled SNMP and IPS no effect any ideas greatly appreciated.
    > >
    > > Alignment data for:
    > >
    > > 3600 Software (C3640-IO3-M), Version 12.3(11)T, RELEASE SOFTWARE (fc2)
    > >
    > > Technical Support: http://www.cisco.com/techsupport
    > >
    > > Compiled Sat 18-Sep-04 14:32 by eaarmas
    > >
    > > No alignment data has been recorded.
    > >
    > > Total Spurious Accesses 67, Recorded 1
    > >
    > > Address Count Traceback
    > >
    > > 36 67 0x60DBE1C8 0x60DC1D4C 0x60DC3994 0x60DC51A0
    > >
    > > 0x606A9FD0 0x606AA3C8 0x606AA484 0x606AA5F8
    > >
    > >
    > >

    >
    > A spurious access means that the router is trying to read from an
    > invalid low address, and the router corrects that by itself. This is
    > done under interrupt and if you have numerous spurious accesses, it can
    > raise the cpu utilization (67 does not look too much).
    >
    > I noticed one interesting thing: you said that router does not have
    > maintenace (I assume you meant support contract) but you're still
    > running the latest IOS which could not be initially found on 3 years old
    > router. When you downloaded image, were there any reason to get the
    > newest, from the T-train specially??? If I were you, I would downgrade
    > to the latest mainline 12.3 version or even better to 12.2 GD mainline
    > version since it's much less possibility that GD image would have such
    > error (but these days, you never know).
    >
    > HTH,
    >
    > --
    > -Ivan.
    >
    > *** Use Rot13 to see my eMail address ***
     
    MC, Oct 1, 2004
    #7
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. Barrett Bonden

    spurious DMZ

    Barrett Bonden, Jan 31, 2006, in forum: Cisco
    Replies:
    1
    Views:
    748
    Walter Roberson
    Feb 1, 2006
  2. ch742718

    Spurious Internet Connection

    ch742718, Jul 15, 2006, in forum: Hardware
    Replies:
    5
    Views:
    1,766
    unholy
    Jul 19, 2006
  3. Roel
    Replies:
    6
    Views:
    3,943
    A.Vidic
    Apr 25, 2010
  4. ChrisM
    Replies:
    2
    Views:
    526
    ChrisM
    Sep 4, 2006
  5. Woudman van der Kinderlokker

    Re: spurious or spam/virus e/mails

    Woudman van der Kinderlokker, Mar 12, 2007, in forum: Computer Support
    Replies:
    2
    Views:
    503
    James Morrow
    Mar 13, 2007
Loading...

Share This Page