From: Xiangrong Wang (xiangrow@cisco.com)
Date: Fri May 28 2004 - 23:58:25 GMT-3
Hi Kenneth,
The "ip verify" command is not supported on Cat3550 as documented in the 
"Catalyst 3550 Multilayer Switch Software Configuration Guide" under 
"Unsupported CLI Commands".
The "ip verify unicast [reverse-path|source]" command is officially removed 
from 12.1(20)EA1 due to CSCec42543.
HTH,
Xiangrong
At 05:03 PM 05/28/04 -0400, Kenneth Wygand wrote:
>Are you sure you are running 12.1(20)EA2 ??  I don't have that option.
>See below.
>
>SWITCH#conf t
>Enter configuration commands, one per line.  End with CNTL/Z.
>SWITCH(config)#int vlan 10
>SWITCH(config-if)#ip ?
>Interface IP configuration subcommands:
>   access-group        Specify access control for packets
>   accounting          Enable IP accounting on this interface
>   address             Set the IP address of an interface
>   authentication      authentication subcommands
>   bandwidth-percent   Set EIGRP bandwidth limit
>   bgp                 BGP interface commands
>   broadcast-address   Set the broadcast address of an interface
>   cef                 Cisco Express Fowarding interface commands
>   cgmp                Enable/disable CGMP
>   dhcp                Configure DHCP parameters for this interface
>   directed-broadcast  Enable forwarding of directed broadcasts
>   dvmrp               DVMRP interface commands
>   hello-interval      Configures IP-EIGRP hello interval
>   helper-address      Specify a destination address for UDP broadcasts
>   hold-time           Configures IP-EIGRP hold time
>   igmp                IGMP interface commands
>   irdp                ICMP Router Discovery Protocol
>   load-sharing        Style of load sharing
>   local-proxy-arp     Enable local-proxy ARP
>   mask-reply          Enable sending ICMP Mask Reply messages
>   mrm                 Configure IP Multicast Routing Monitor tester
>   mroute-cache        Enable switching cache for incoming multicast
>packets
>   mtu                 Set IP Maximum Transmission Unit
>   multicast           IP multicast interface commands
>   ospf                OSPF interface commands
>   pim                 PIM interface commands
>   policy              Enable policy routing
>   probe               Enable HP Probe support
>   proxy-arp           Enable proxy ARP
>   rarp-server         Enable RARP server for static arp entries
>   redirects           Enable sending ICMP Redirect messages
>   rgmp                Enable/disable RGMP
>   rip                 Router Information Protocol
>   route-cache         Enable fast-switching cache for outgoing packets
>   sap                 Session Advertisement Protocol interface commands
>   sdr                 Session Directory Protocol interface commands
>   security            DDN IP Security Option
>   split-horizon       Perform split horizon
>   summary-address     Perform address summarization
>   unnumbered          Enable IP processing without an explicit address
>   unreachables        Enable sending ICMP Unreachable messages
>   urd                 Configure URL Rendezvousing
>   vrf                 VPN Routing/Forwarding parameters on the interface
>   wccp                WCCP interface commands
>
>SWITCH(config-if)#ip verify?
>% Unrecognized command
>SWITCH(config-if)#ip verify
>
>SWITCH#sh ver
>Cisco Internetwork Operating System Software
>IOS (tm) C3550 Software (C3550-I5Q3L2-M), Version 12.1(20)EA2, RELEASE
>SOFTWARE
>(fc1)
>Copyright (c) 1986-2004 by cisco Systems, Inc.
>Compiled Wed 19-May-04 05:06 by antonino
>Image text-base: 0x00003000, data-base: 0x0082D44C
>
>ROM: Bootstrap program is C3550 boot loader
>
>SWITCH uptime is 41 minutes
>System returned to ROM by power-on
>System restarted at 16:19:45 EDT Fri May 28 2004
>System image file is
>"flash:c3550-i5q3l2-mz.121-20.EA2/c3550-i5q3l2-mz.121-20.EA
>2.bin"
>
>cisco SWITCH (PowerPC) processor (revision G0) with 65526K/8192K bytes
>of
>memory.
>Processor board ID CAT0738X05G
>Last reset from warm-reset
>Bridging software.
>Running Layer2/3 Switching Image
>
>Ethernet-controller 1 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 2 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 3 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 4 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 5 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 6 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 7 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 8 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 9 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 10 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 11 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>Ethernet-controller 12 has 1 Gigabit Ethernet/IEEE 802.3 interface
>
>12 Gigabit Ethernet/IEEE 802.3 interface(s)
>
>The password-recovery mechanism is enabled.
>384K bytes of flash-simulated non-volatile configuration memory.
>Base ethernet MAC Address: 00:0D:BC:E7:A7:80
>Motherboard assembly number: 73-5526-08
>Power supply part number: 34-0967-01
>Motherboard serial number: CAT07380BTP
>Power supply serial number: DTH073416YL
>Model revision number: G0
>Motherboard revision number: A0
>Model number: WS-C3550-12G
>System serial number: CAT0738X05G
>Configuration register is 0x10F
>
>
>Kenneth E. Wygand
>Systems Engineer, Project Services
>CISSP #37102, CCNP, CCDP, ACSP, Cisco IPT Design Specialist, MCP, CNA,
>Network+, A+
>Custom Computer Specialists, Inc.
>"The only unattainable goal is the one not attempted."
>-Anonymous
>
>-----Original Message-----
>From: MMoniz [mailto:ccie2002@tampabay.rr.com]
>Sent: Friday, May 28, 2004 4:24 PM
>To: Kenneth Wygand; Group Study
>Subject: RE: ip verify unicast reverse-path... GONE?!?!
>
>It is functionally replaced with:
>
>Cat-3550(config-if)#ip verify uni ?
>reverse-path Reverse path validation of source address (old command
>format)<<<<<<<<<<
>source Validation of source address
>
>interface Vlan2
>ip address 133.5.23.8 255.255.255.0
>ip verify unicast source reachable-via rx
>
>mike
>
>-----Original Message-----
>From: nobody@groupstudy.com [mailto:nobody@groupstudy.com]On Behalf Of
>Kenneth Wygand
>Sent: Friday, May 28, 2004 4:08 PM
>To: Group Study
>Subject: ip verify unicast reverse-path... GONE?!?!
>
>
>Well...
>
>
>
>Due to CDP bug I just upgraded a test 3550 EMI switch from 12.1(19)EA1
>to 12.1(20)EA2.  To my surprise, all of my interface configuration lines
>"ip verify unicast reverse-path" are gone and the command is no longer
>recognized.
>
>
>
>I've searched each of the release notes incrementally from 12.1(19)EA1
>through 12.1(20)EA2 and there is no mention of this command being
>removed or the functionality replaced.
>
>
>
>I've just checked the command references and it's not listed in either
>version, but it was available in 12.1(19)EA1.
>
>
>
>Any run into this before or have any ideas?
>
>
>
>Kenneth E. Wygand
>Systems Engineer, Project Services
>
>CISSP #37102, CCNP, CCDP, ACSP, Cisco IPT Design Specialist, MCP, CNA,
>Network+, A+
>Custom Computer Specialists, Inc.
>
>"I am not really smart. I just stick with problems longer."
>-Albert Einstein
>
>
>
>Custom Computer Specialists, Inc.
>
>"Celebrating 25 Years of Excellence"
This archive was generated by hypermail 2.1.4 : Wed Jun 02 2004 - 11:12:19 GMT-3