3750 and Nexus 5548UP Support
I am working on a project that was handed down and several different engineers got their hands on. The project is (or should have been) a simple data storage/center. Fixing all the design problems has left me with very little time to research the security folks issues and I need help.
We are using Cisco Nexus 5548UP for our data center core and distribution/routing to encryptors connecting our remote sites which use Cisco 3750X series switches. The Nexus is running NOS 5.2(1)N1(4) and the 3750s use 12.2(55) IP base.
These are our particular issues:
1) For management and monitoring, what would be a good product to use to support this? If Cisco Prime Infrastructure, what ports would need to be allowed/opened through firewalls/ACLs (SNMP, syslog, etc)?
2) For switch login, the network security folks are reluctant to use TACACS and want to push for LDAP instead. Using Active Directory, is there any way to get the Cisco Nexus 5548UP and Cisco 3750Xs talking to Active Directory? I've found both 'yes' and 'no' answers online and am not sure. Do I need to use a different NOS and/or IOS? Are there specific directions somewhere? Or is it not possible?
3) Without TACACS, is there any way to implement command logging to a syslog server on the Nexus? On the 3750s, I make the following changes and all commands are relayed to our syslog server:
Enable
Configure terminal
Archive
Log config
Logging enable
Logging size 500
Hidekeys
Notify syslog
End
Is there anything similar for the Nexus?
4) In conjunction with #3, we need to be able to log each login attempt (success and failure) to a syslog server on the Nexus. On the 3750, using the "login on-[failure/success] log", it is can setup easy enough. On the Nexus, I haven't been able to find anything similar. I can't find any instructions on setting this up on the Nexus, though.
5) What IOS/NOS do we need to use to be able to lock out users after 3 failed logins (again, without using TACACS)?
If you need more information, please ask.
V/R,
Chris
The LRM is s special case transceiver which supports 10 Gbps over older FDDI grade multimode fiber when used with a mode conditioning patch cord. It is not supported on the Nexus 5548UP.
The SFP-10G-LR is used with single mode fiber for spans up to 10 km in length. It is supported on the 5548UP (and most every platform of Cisco's that takes SFPs).
Please see the product data sheet here.
Similar Messages
-
Cisco Nexus 5548UP support SFP-10G-LRM ?
Hi all, I have a question about Cisco Nexus 5548UP. Is Cisco Nexus 5548UP support SFP-10G-LRM ? Because in CCW, i can't configure the SFP-10G-LRM. There is only SFP-10G-LR, SR, and the others, but there's no LRM. Pelase help me to answer this question. Thanks a lot
The LRM is s special case transceiver which supports 10 Gbps over older FDDI grade multimode fiber when used with a mode conditioning patch cord. It is not supported on the Nexus 5548UP.
The SFP-10G-LR is used with single mode fiber for spans up to 10 km in length. It is supported on the 5548UP (and most every platform of Cisco's that takes SFPs).
Please see the product data sheet here. -
3750 and Netflow not supported (alternatives ??)
ISP
|
| 3750 | -------- | 3745 |
- - - - - - - - - - - - - - - - - span - - - - - - - - - - - - - - - -
|
Internal
I have an ISP facing 3750 switch running BGP. I want to collect Netflow statistics for this IP traffic.
I know that Netflow is not supported on the 3750 switch.
I know Lancope offer a Flow sensor for capturing data on a span port and turning this into netflow stats.
http://netflowninjas.typepad.com/blog/2009/12/stealthwatch-510-highlight-flowsensor-ae-features-and-benefits.html
I need a temporary solution and I have a spare 3745 router which supports netflow. I cant put this router
in series because it may be a bottleneck on a 20Mbps ISP connection.
Is there a way of feeding span traffic from the 3750 into a 3745 and seeing if it is able to generate the netflow stats.
I have tried this using only one interface and it does not work. Do I need to span both internal and external interfaces.
Does the IP traffic arriving at the 3745 have to cross two interfaces to generate neflow stats.
http://www.netflowanalysis.com/How%20does%20NetFlow%20Work.html
Any ideas ?Hello,
there are only 3 solutions.
1. Small router inline. I suppose that it will OK for 20Mbps line.
2. Use SPAN and some probe (software or hardware based).
3. Optical TAP and probe.
Our company is offering software or hardware based probes.
(see http://www.caligare.com/product/flowmon/ for more information)
You can also use the Lancope or nProbe (free) of course.
Kind regards,
Jan Nejman
Caligare, co.
http://www.caligare.com/ -
Is Cisco Nexus 5596UP support vlan base Policing and traffic shaping on code NX OS version: 5.1(3)N1(1)
where i couldn't see any police command under the policy mapI have tested this issue on another 5548UP with L3 running the same NX-OS version and get the same problem. Show CDP from the switch is not discovering devices, but the neightbors can see the 5K in question. Reboot sometimes will fix it, but not always. I suspect a problem with the software since that doesn't happen in NX-OS 5.2. The one I am using is
Software
BIOS: version 3.6.0
loader: version N/A
kickstart: version 5.1(3)N2(1)
system: version 5.1(3)N2(1) -
Cisco Nexus 5548UP and FI6248UP compatibility with FC SFP
Cisco Nexus 5548UP and FI 6248UP comes with Unified Ports. What are the SFP types this port can take? 1Gig, 10Gig and 2/4/8FC. Could you please clarify?
Thanks,
CheriyanHi Cheriyan,
Here is te URL to the 6200 series FI data sheet:
http://www.cisco.com/en/US/prod/collateral/ps10265/ps11544/data_sheet_c78-675245.pdf
Check for the table to supported SFPs.
Same for the 5500 switches
http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9670/data_sheet_c78-618603.html.
Hope this helps!
./Abhinav -
Nexus 5548UP and GLC-LH-SM showing sfpinvali
Hi gurus, have just received a 5548UP and when a 1GB GLC-LH-SM is inserted into the system it shows as being invalid.
Eth0/1 -- sfpInvali 1 auto 10G 1/10g
4 different SFPs have been tried in numerous interfaces on the system. I have also upgraded the software to 5.0(2).
And I have tried setting the speed to 1GB on the interface.
Any ideas on what simple configuration task I have missed?
LPHi,
I've the same issue with GLC-T 1Gbps SFP tranceiver and NX-5548UP with L3 Daughter Card.
sh int e1/32 status
Port Name Status Vlan Duplex Speed Type
Eth1/32 VLAN99 notconnec 99 full 1000 SFP-1000BAS
The cable is connected and in the other device (switch 2960x) the ethernet interface is UP
My configuration :
NX-OS : version 5.2(1)N1(4)
interface Ethernet1/32
description VLAN99
switchport access vlan 99
speed 1000
sh mod
Mod Ports Module-Type Model Status
1 32 O2 32X10GE/Modular Universal Plat N5K-C5548UP-SUP active *
3 0 O2 Daughter Card with L3 ASIC N55-D160L3-V2 ok
Tranceiver info :
Ethernet1/32
transceiver is present
type is SFP-1000BASE-T
name is CISCO-METHODE
part number is SP7041_Rev_E
revision is E
serial number is 00000MTC163405CF
nominal bitrate is 1300 MBit/sec
Link length supported for copper is 100 m
cisco id is --
cisco extended id number is 4
DOM is not supported
Interface capa :
Ethernet1/32
Model: N5K-C5548UP-SUP
Type (SFP capable): 10Gbase-(unknown)
Speed: 1000,10000
Duplex: full
Trunk encap. type: 802.1Q
Channel: yes
Broadcast suppression: no
Flowcontrol: rx-(off/on),tx-(off/on)
Rate mode: none
QOS scheduling: rx-(6q1t),tx-(1p6q0t)
CoS rewrite: no
ToS rewrite: no
SPAN: yes
UDLD: yes
Link Debounce: yes
Link Debounce Time: yes
MDIX: no
Pvlan Trunk capable: yes
TDR capable: no
FabricPath capable: yes
Port mode: Switched
FEX Fabric: yes
Any idea ?
Regards,
Julien. -
Nexus 5548UP - HSRP and vPC, tracking required?
Hi,
We've got two Nexus 5548UPs that are vPC and HSRP peers.
I've had some feedback that I should incorporate the tracking function to close the vPC down in the case of a layer 3 problem, the thing is I'm not sure it's required. I can see in this article it recommends implementing tracking when your L2 peer-link and L3 interfaces are on the same module (which it is in my case).. http://www.cisco.com/en/US/docs/switches/datacenter/sw/design/vpc_design/vpc_best_practices_design_guide.pdf
But in this article it says not to use tracking.. http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9670/design_guide_c07-625857.pdf
Any one got any real world experience and can offer some feedback.. I don't mind putting it in just want to understand why.
Thanks,
Nick.Hi Nick
there is two tracking can be use din nexus enviroment
HSRP tracking and vPC tracking
for using one line card for the vPC peer link vPC tracking is recomnded
HSRP tracking is used to track L3 uplinks to the core
Using vPC with HSRP/VRRP object tracking may leads to traffic blackholing in case object tracking is triggered
its better to use separate L3 inter switch link instead of using HSRP tracking
hope this help -
Hello,
I am trying to setup LACP on the Nexus 5548UP 10 Gig switch on Port-channel 3. However, when I setup LACP, eth ports 7 and 8 (on Port-channel 3) go into either inactive or down state (as below). The 10 gig ports (7 and 8) are connected to a server which has LACP capability.
ns5500(config-if)# do sh port-channel summary
Flags: D - Down P - Up in port-channel (members)
I - Individual H - Hot-standby (LACP only)
s - Suspended r - Module-removed
S - Switched R - Routed
U - Up (port-channel)
M - Not in use. Min-links not met
Group Port- Type Protocol Member Ports
Channel
1 Po1(SU) Eth NONE Eth1/15(P) Eth1/16(P)
3 Po3(SD) Eth LACP Eth1/7(D) Eth1/8(D)
LACP setup as follows:
feature lacp
interface port-channel3
switchport access vlan 10
speed 10000
interface Ethernet1/7
switchport access vlan 10
channel-group 3 mode active
interface Ethernet1/8
switchport access vlan 10
channel-group 3 mode active
It would be great if anyone can help me with getting LACP up and running on the 10 Gig Nexus 5548UP. Please let me know if you need more information.
Thanks!Thanks for your response. I do have vlan10 created and it is active. Thanks for correcting individual state instead of inactive.
I ran a few lacp commands below including "show lacp counters"
ns5500(config)# show lacp counters
LACPDUs Marker Marker Response LACPDUs
Port Sent Recv Sent Recv Sent Recv Pkts Err
port-channel3
Ethernet1/7 163655 13948 0 0 0 0 0
Ethernet1/8 161700 13976 0 0 0 0 0
By looking at LACP PDUs can we say that LACP is up and running?
ns5500(config)# show lacp port-channel
port-channel3
System Mac=54-7f-ee-8d-83-fc
Local System Identifier=0x8000,54-7f-ee-8d-83-fc
Admin key=0x2
Operational key=0x2
Partner System Identifier=0x0,0-0-0-0-0-0
Operational key=0x0
Max delay=0
VPC ID=0
Aggregate or individual=1
Member Port List=7-8
In the below command, it still says, interfaces 7 and 8 are down? What does that mean? An issue with the host? Is there anyway to test the nexus switch to check if it is doing its part and working correctly?
ns5500(config)# show port-channel summary
Flags: D - Down P - Up in port-channel (members)
I - Individual H - Hot-standby (LACP only)
s - Suspended r - Module-removed
S - Switched R - Routed
U - Up (port-channel)
M - Not in use. Min-links not met
Group Port- Type Protocol Member Ports
Channel
1 Po1(SD) Eth NONE --
3 Po3(SD) Eth LACP Eth1/7(D) Eth1/8(D)
Thanks. -
Adapter-fex Supported VICs and Nexus Switches
HI,
I am thinking of using C220M4 in standalone mode. I have been reading about adapter-fex and I am wondering which Cisco VIC supports adapter-fex and which Nexus Switch will support adapter-fex.
I am thinking of using a VIC1225 and Nexus 3000.
Thanks.I believe that adaptor fex is supported only with Nexus 5k and N2k:
Network Adapter Virtualization Design (Adapter-FEX) with Cisco Nexus 5500 Switches and Cisco Nexus 2232 Fabric Extenders
http://www.cisco.com/c/en/us/products/collateral/switches/nexus-5000-series-switches/guide_c07-690080.html
http://www.cisco.com/c/en/us/products/collateral/switches/nexus-5000-series-switches/data_sheet_c78-657397.html -
LMS User Tracking for NEXUS 5548UP
Dear,
A while ago I received a ticket from one of our customers because User Tracking was not working for NEXUS 5548UP on LMS 3.2. I opened a TAC case for this but this was normal since it is a Datacenter switch. Now the customer came back on this because they really want to see which server is connected to which switch port. I understood from the TAC engineer this is not on the roadmap to integrate in LMS 4.x. They want to know if there exists another product (they thought about DCNM) and wanted to know how this integrates or works together with LMS...
Kind regards,
Sven LaureyssensMy latest understanding of User Tracking and Nexus 5K series is that it is not supported due to a limitation of the MIB support in the NX-OS.
The current DCNM (release 5.2) is distinct from the LMS and Cisco Prime umbrella but that wil be changing a bit moving forwad as DCNM is enhanced and rolled into the Cisco Prime family. Last I heard there should be some information coming out of Cisco Live this week and a new release will have some additional functionality and better integration. Still, I doubt we'll see UT for the 5K due to the NX-OS limitation.
One way to do what you're asking apart from use of any of the Cisco products is to enable LLDP on your Nexus and servers. That will at least give you the ability to pull the information from the NX-OS command line ("show lldp neighbor") -
6500-VSS and NEXUS 56XX vPC interoperability
Hello, is it possible to establish a PORT CHANNEL between a couple of Cisco 6500 running VSS mode and a couple of NEXUS 5000 running vPC? . Design should be " Back-to-Back" : VSS-- Port-Channel--vPC.
I want also to support L2 and L3 flows between the two couples.
I read many forums but i am not sure it runs.
Is such design, if it runs; supported by Cisco?
Thanks a lot for your help.Hi Tlequertier,
We have VSS 6509Es with Sup 2Ts & 6908 modules. These have a 40gb/sec (4 x 10gb/sec) uplink to our NEXUS 5548UP vPC switches.
So we have a fully meshed ether-channel between the 4 physical switches (2 x N5548UP & 2x6509E)
Kind regards,
Tim -
I have a question regarding Nexus 5548UP which is supported from NXOS 5.0.3 on.
I assume thats the absolute indentical hardware as the Nexus5548P which was available a little bit
earlier and had also the HW ready for support Unified Ports on all Ports (but was just enabled on expansion-module).
Is it possible by SW upgrade to 5.0.3 to make a 5548UP from a 5548P ?
Thx
hubertThx Lucien,
then there is absolutely no reason to buy the 5548P, because 5548UP has same price, and no reason to buy another expansion-module than the UP(has the same price as well compared to the other expansion Module ?
So I assume 5548P and the pure Eth-uplink Modul, and the mixed FC and Eth-uplink Modul will have very limited lifetime ?!
One additional Question: I read that in case a 5596 has L3-Modul built in , it no longer supports the maximum numbers of FEXes it supports only 8 then.
Is this a limitation which will remain, or is there a chance new NX-OS Versions will break thhis limit
KR
Hubert -
Connecting many Brocade switches to Nexus 5548UP
Hello,
I have a SAN network composed of few separate PODs. Each POD is divided into SAN-A and SAN-B. Most of those PODs are Brocade switches (FOS 6.1). There are also few Nexus 5520s. Now, we have built new core infrastructure with Nexus 5548UPs and many MDS 9148s. We would like to move all servers and sotrage from old Brocades to the new SAN. As we cannot move all devices at the same time, all segments must be connected to the core for some time. Each POD has different zoning. Some zonings on Brocade switches are based on PWWN, some on Domain ID and Port ID. In my opinion, the only way of successfuly connecting all PODs together is to merge zones manualy (in excel, etc). and paste them on all switches. However, maybe there is some other way of merging all zones? What if I leave Nexus 5548UP in native mode (so zones from Brocade will not get merged), and only implement that manually merged zoneset on Nexus 5548UP? Will the ISL links get isolated due to zoning merge failure? Or they will maintain operational state even if zones are different on each POD? I do not have any lab boxes, so I cannot test it. Any advidse will be appreciated.
Best regards,
Krzyszofwell since you can not cluster the 45K as a virtual switch ( Cisco with new sup will start support VSS in the 4500 try to check which sup exactly and if you can upgrade as this will make a significant improvement to your design )
anyway the only method that you can use currently is the traditional way which is depending on STP ( use rapid-PVST)
from each N5K use one separate link to each 45K and STP will put on of the links in blocking mode
however you might do some STP and vlan design for load sharing where you can send vlan x over link1 and vlan y over link b to the 45K using STP cost
HTH -
Cisco Nexus 5548UP upgrade path
Hi,
I'm planning to upgrade Nexus 5548UP (no L3 services) from 5.2(1)N1(6) to 7.0(5)N1(1). Is this upgrade path vaild? or is there any intermediate version; also advise if ISSU is possible.
Regards,
Navin RKHi,
Yes you can upgrade directly from 5.2(1)N1(6) to 7.0(5)N1(1). ISSU is possible, provided you meet the requirements. You can copy the kickstart and system image to bootflash, then run the "show install all impact" command to see whether or not ISSU will be possible with your configuration.
Here is a document supporting the statements above: http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5500/sw/upgrade/705_N1_1/n5500_upgrade_downgrade_700.html#pgfId-640981 -
Cisco Nexus 5548UP to Brocade SAN Connectivity
Hi,
I have a Server-SAN-Storage setup as shown in the attachment/below. There are new Cisco UCS rack mount servers with VIC 1225 and Virtual servers on VMware Esxi hypevisor connected to a new Cisco Nexus 5548UP switch in IP+FCoE mode. The new 5548 switch then connects to an existing production SAN of Brocade 48000 Director SAN switch which connects to storage in production environment.
I need to know the best way to connect the 5548 switch to the Brocade SAN switch without disrupting the existing Production SAN environment i.e. Brocade SAN switch configurations & setup e.g. Fabric Principal switch. priority etc.
Would configuring the 5548 switch in NPV mode be best practice?See Figure 6-2 Converged Multi-hop FCoE Network Design Using FCoE NPV
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/operations/fcoe/513_n1_1/ops_fcoe/ops_fcoe_npv.html
You have to use NPV on N5k, there is no FC interop support on N5k, to connect to Brocade.
Maybe you are looking for
-
How to print the script before realasing?
how to print the script before realasing?
-
My ipod touch 4th gen dosen't work with my intempo speakers!
I got my speakers when that old square ipod nano came out. My speakers worked fine with that ipod. i just got a new ipod touch 4th gen and when i put it on my speakers it says "charging is not supported with this device" and when i play music it just
-
hi gurus please explain following queries? 1.what will be the position of a sap fresher while entering into SAP. 2.Where he will be placed in support or in implementation 3.can any one explain roles and responsibilities of SAP consultant as per the A
-
When is Apple going to fix the iTunes 11 syncing problem!!!!
After troubleshooting the iTune 11 upgrade seems to cause syncing problems for everyone. I've tried everything and my ipod will no longer sync. Help! When is Apple going to apply a fix for this?????
-
trying to purchase lion. get an error msg that says i must have a duel core processor to buy.I have a 2.16 GHz Intel Core Due