3750 and Nexus 5548UP Support

I am working on a project that was handed down and several different engineers got their hands on.  The project is (or should have been) a simple data storage/center.  Fixing all the design problems has left me with very little time to research the security folks issues and I need help.
We are using Cisco Nexus 5548UP for our data center core and distribution/routing to encryptors connecting our remote sites which use Cisco 3750X series switches.  The Nexus is running NOS 5.2(1)N1(4) and the 3750s use 12.2(55) IP base.
These are our particular issues:
1)  For management and monitoring, what would be a good product to use to support this?  If Cisco Prime Infrastructure, what ports would need to be allowed/opened through firewalls/ACLs (SNMP, syslog, etc)?
2)  For switch login, the network security folks are reluctant to use TACACS and want to push for LDAP instead.  Using Active Directory, is there any way to get the Cisco Nexus 5548UP and Cisco 3750Xs talking to Active Directory?  I've found both 'yes' and 'no' answers online and am not sure.  Do I need to use a different NOS and/or IOS?  Are there specific directions somewhere?  Or is it not possible?
3)  Without TACACS, is there any way to implement command logging to a syslog server on the Nexus?  On the 3750s, I make the following changes and all commands are relayed to our syslog server:
Enable
Configure terminal
Archive
Log config
Logging enable
Logging size 500
Hidekeys
Notify syslog
End
Is there anything similar for the Nexus?
4)  In conjunction with #3, we need to be able to log each login attempt (success and failure) to a syslog server on the Nexus.  On the 3750, using the "login on-[failure/success] log", it is can setup easy enough.  On the Nexus, I haven't been able to find anything similar.  I can't find any instructions on setting this up on the Nexus, though.
5)  What IOS/NOS do we need to use to be able to lock out users after 3 failed logins (again, without using TACACS)?
If you need more information, please ask.
V/R,
Chris

The LRM is s special case transceiver which supports 10 Gbps over older FDDI grade multimode fiber when used with a mode conditioning patch cord. It is not supported on the Nexus 5548UP.
The SFP-10G-LR is used with single mode fiber for spans up to 10 km in length. It is supported on the 5548UP (and most every platform of Cisco's that takes SFPs).
Please see the product data sheet here.

Similar Messages

  • Cisco Nexus 5548UP support SFP-10G-LRM ?

    Hi all, I have a question about Cisco Nexus 5548UP. Is Cisco Nexus 5548UP support SFP-10G-LRM ? Because in CCW, i can't configure the SFP-10G-LRM. There is only SFP-10G-LR, SR, and the others, but there's no LRM. Pelase help me to answer this question. Thanks a lot

    The LRM is s special case transceiver which supports 10 Gbps over older FDDI grade multimode fiber when used with a mode conditioning patch cord. It is not supported on the Nexus 5548UP.
    The SFP-10G-LR is used with single mode fiber for spans up to 10 km in length. It is supported on the 5548UP (and most every platform of Cisco's that takes SFPs).
    Please see the product data sheet here.

  • 3750 and Netflow not supported (alternatives ??)

                  ISP
                   |
    |             3750            |  --------  |           3745              |
    - - - - - - - - - - - - - - - - -    span   - - - - - - - - - - - - - - - -
                   |
              Internal
    I have an ISP facing 3750 switch running BGP. I want to collect Netflow statistics for this IP traffic.
    I know that Netflow is not supported on the 3750 switch.
    I know Lancope offer a Flow sensor for capturing data on a span port and turning this into netflow stats.
    http://netflowninjas.typepad.com/blog/2009/12/stealthwatch-510-highlight-flowsensor-ae-features-and-benefits.html
    I need a temporary solution and I have a spare 3745 router which supports netflow. I cant put this router
    in series because it may be a bottleneck on a 20Mbps ISP connection.
    Is there a way of feeding span traffic from the 3750 into a 3745 and seeing if it is able to generate the netflow stats.
    I have tried this using only one interface and it does not work. Do I need to span both internal and external interfaces.
    Does the IP traffic arriving at the 3745 have to cross two interfaces to generate neflow stats.
    http://www.netflowanalysis.com/How%20does%20NetFlow%20Work.html
    Any ideas ?

    Hello,
    there are only 3 solutions.
    1. Small router inline. I suppose that it will OK for 20Mbps line.
    2. Use SPAN and some probe (software or hardware based).
    3. Optical TAP and probe.
    Our company is offering software or hardware based probes.
    (see http://www.caligare.com/product/flowmon/ for more information)
    You can also use the Lancope or nProbe (free) of course.
    Kind regards,
    Jan Nejman
    Caligare, co.
    http://www.caligare.com/

  • Is Cisco Nexus 5596UP support vlan base Policing and traffic shaping on code NX OS version: 5.1(3)N1(1)

    Is Cisco Nexus 5596UP support vlan base Policing and traffic shaping on code NX OS version: 5.1(3)N1(1)
    where i couldn't see any police command under the policy map 

    I have tested this issue on another 5548UP with L3 running the same NX-OS version and get the same problem. Show CDP from the switch is not discovering devices, but the neightbors can see the 5K in question. Reboot sometimes will fix it, but not always. I suspect a problem with the software since that doesn't happen in NX-OS 5.2. The one I am using is
    Software
      BIOS:      version 3.6.0
      loader:    version N/A
      kickstart: version 5.1(3)N2(1)
      system:    version 5.1(3)N2(1)

  • Cisco Nexus 5548UP and FI6248UP compatibility with FC SFP

    Cisco Nexus 5548UP and FI 6248UP comes with Unified Ports. What are the SFP types this port can take? 1Gig, 10Gig and 2/4/8FC. Could you please clarify?  
    Thanks,
    Cheriyan

    Hi Cheriyan,
    Here is te URL to the 6200 series FI data sheet:
    http://www.cisco.com/en/US/prod/collateral/ps10265/ps11544/data_sheet_c78-675245.pdf
    Check for the table to supported SFPs.
    Same for the 5500 switches
    http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9670/data_sheet_c78-618603.html.
    Hope this helps!
    ./Abhinav

  • Nexus 5548UP and GLC-LH-SM showing sfpinvali

    Hi gurus, have just received a 5548UP and when a 1GB GLC-LH-SM is inserted into the system it shows as being invalid.
    Eth0/1       --                 sfpInvali 1         auto  10G     1/10g
    4 different SFPs have been tried in numerous interfaces on the system.  I have also upgraded the software to 5.0(2). 
    And I have tried setting the speed to 1GB on the interface.
    Any ideas on what simple configuration task I have missed?
    LP

    Hi,
    I've the same issue with GLC-T 1Gbps SFP tranceiver and NX-5548UP with L3 Daughter Card.
    sh int e1/32 status
    Port          Name               Status    Vlan      Duplex  Speed   Type
    Eth1/32       VLAN99             notconnec 99        full    1000    SFP-1000BAS
    The cable is connected and in the other device (switch 2960x) the ethernet interface is UP
    My configuration :
    NX-OS : version 5.2(1)N1(4)
    interface Ethernet1/32
      description VLAN99
      switchport access vlan 99
      speed 1000
     sh mod
    Mod Ports Module-Type                       Model                  Status
    1   32    O2 32X10GE/Modular Universal Plat N5K-C5548UP-SUP        active *
    3   0     O2 Daughter Card with L3 ASIC     N55-D160L3-V2          ok
    Tranceiver info :
    Ethernet1/32
        transceiver is present
        type is SFP-1000BASE-T
        name is CISCO-METHODE   
        part number is SP7041_Rev_E    
        revision is E   
        serial number is 00000MTC163405CF
        nominal bitrate is 1300 MBit/sec
        Link length supported for copper is 100 m
        cisco id is --
        cisco extended id number is 4
    DOM is not supported
    Interface capa :
    Ethernet1/32
      Model:                 N5K-C5548UP-SUP
      Type (SFP capable):    10Gbase-(unknown)
      Speed:                 1000,10000
      Duplex:                full
      Trunk encap. type:     802.1Q
      Channel:               yes
      Broadcast suppression: no
      Flowcontrol:           rx-(off/on),tx-(off/on)
      Rate mode:             none
      QOS scheduling:        rx-(6q1t),tx-(1p6q0t)
      CoS rewrite:           no
      ToS rewrite:           no
      SPAN:                  yes
      UDLD:                  yes
      Link Debounce:         yes
      Link Debounce Time:    yes
      MDIX:                  no
      Pvlan Trunk capable:   yes
      TDR capable:           no
      FabricPath capable:    yes
      Port mode:             Switched
      FEX Fabric:            yes
    Any idea ?
    Regards,
    Julien.

  • Nexus 5548UP - HSRP and vPC, tracking required?

    Hi,
    We've got two Nexus 5548UPs that are vPC and HSRP peers.
    I've had some feedback that I should incorporate the tracking function to close the vPC down in the case of a layer 3 problem, the thing is I'm not sure it's required. I can see in this article it recommends implementing tracking when your L2 peer-link and L3 interfaces are on the same module (which it is in my case).. http://www.cisco.com/en/US/docs/switches/datacenter/sw/design/vpc_design/vpc_best_practices_design_guide.pdf
    But in this article it says not to use tracking.. http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9670/design_guide_c07-625857.pdf
    Any one got any real world experience and can offer some feedback.. I don't mind putting it in just want to understand why.
    Thanks,
    Nick.

    Hi Nick
    there is two tracking can be use din nexus enviroment
    HSRP tracking and vPC tracking
    for using one line card for the vPC peer link vPC tracking is recomnded
    HSRP tracking is used to track L3 uplinks to the core
    Using vPC with HSRP/VRRP object tracking may leads to traffic blackholing in case object tracking is triggered
    its better to use separate L3 inter switch link instead of using HSRP tracking
    hope this help

  • Nexus 5548UP and LACP

    Hello,
    I am trying to setup LACP on the Nexus 5548UP 10 Gig switch on Port-channel 3. However, when I setup LACP, eth ports 7 and 8 (on Port-channel 3) go into either inactive or down state (as below). The 10 gig ports (7 and 8) are connected to a server which has LACP capability.
    ns5500(config-if)# do sh port-channel summary
    Flags:  D - Down        P - Up in port-channel (members)
            I - Individual  H - Hot-standby (LACP only)
            s - Suspended   r - Module-removed
            S - Switched    R - Routed
            U - Up (port-channel)
            M - Not in use. Min-links not met
    Group Port-       Type     Protocol  Member Ports
          Channel
    1     Po1(SU)     Eth      NONE      Eth1/15(P)   Eth1/16(P)
    3     Po3(SD)     Eth      LACP      Eth1/7(D)    Eth1/8(D)
    LACP setup as follows:
    feature lacp
    interface port-channel3
      switchport access vlan 10
      speed 10000
    interface Ethernet1/7
      switchport access vlan 10
      channel-group 3 mode active
    interface Ethernet1/8
      switchport access vlan 10
      channel-group 3 mode active
    It would be great if anyone can help me with getting LACP up and running on the 10 Gig Nexus 5548UP. Please let me know if you need more information.
    Thanks!

    Thanks for your response. I do have vlan10 created and it is active. Thanks for correcting individual state instead of inactive.
    I ran a few lacp commands below including "show lacp counters"
    ns5500(config)# show lacp counters
                        LACPDUs         Marker      Marker Response    LACPDUs
    Port              Sent   Recv     Sent   Recv     Sent   Recv      Pkts Err
    port-channel3
    Ethernet1/7        163655 13948    0      0        0      0        0
    Ethernet1/8        161700 13976    0      0        0      0        0
    By looking at LACP PDUs can we say that LACP is up and running?
    ns5500(config)# show lacp port-channel
    port-channel3
      System Mac=54-7f-ee-8d-83-fc
      Local System Identifier=0x8000,54-7f-ee-8d-83-fc
      Admin key=0x2
      Operational key=0x2
      Partner System Identifier=0x0,0-0-0-0-0-0
      Operational key=0x0
      Max delay=0
      VPC ID=0
      Aggregate or individual=1
      Member Port List=7-8
    In the below command, it still says, interfaces 7 and 8 are down? What does that mean? An issue with the host? Is there anyway to test the nexus switch to check if it is doing its part and working correctly?
    ns5500(config)# show port-channel summary
    Flags:  D - Down        P - Up in port-channel (members)
            I - Individual  H - Hot-standby (LACP only)
            s - Suspended   r - Module-removed
            S - Switched    R - Routed
            U - Up (port-channel)
            M - Not in use. Min-links not met
    Group Port-       Type     Protocol  Member Ports
          Channel
    1     Po1(SD)     Eth      NONE      --
    3     Po3(SD)     Eth      LACP      Eth1/7(D)    Eth1/8(D)
    Thanks.

  • Adapter-fex Supported VICs and Nexus Switches

    HI,
    I am thinking of using C220M4 in standalone mode. I have been reading about adapter-fex and I am wondering which Cisco VIC supports adapter-fex and which Nexus Switch will support adapter-fex.
    I am thinking of using a VIC1225 and Nexus 3000.
    Thanks.

    I believe that adaptor fex is supported only with Nexus 5k and N2k:
    Network Adapter Virtualization Design (Adapter-FEX) with Cisco Nexus 5500 Switches and Cisco Nexus 2232 Fabric Extenders
    http://www.cisco.com/c/en/us/products/collateral/switches/nexus-5000-series-switches/guide_c07-690080.html
    http://www.cisco.com/c/en/us/products/collateral/switches/nexus-5000-series-switches/data_sheet_c78-657397.html

  • LMS User Tracking for NEXUS 5548UP

    Dear,
    A while ago I received a ticket from one of our customers because User Tracking was not working for NEXUS 5548UP on LMS 3.2. I opened a TAC case for this but this was normal since it is a Datacenter switch. Now the customer came back on this because they really want to see which server is connected to which switch port. I understood from the TAC engineer this is not on the roadmap to integrate in LMS 4.x. They want to know if there exists another product (they thought about DCNM) and wanted to know how this integrates or works together with LMS...
    Kind regards,
    Sven Laureyssens                    

    My latest understanding of User Tracking and Nexus 5K series is that it is not supported due to a limitation of the MIB support in the NX-OS.
    The current DCNM (release 5.2) is distinct from the LMS and Cisco Prime umbrella but that wil be changing a bit moving forwad as DCNM is enhanced and rolled into the Cisco Prime family. Last I heard there should be some information coming out of Cisco Live this week and a new release will have some additional functionality and better integration. Still, I doubt we'll see UT for the 5K due to the NX-OS limitation.
    One way to do what you're asking apart from use of any of the Cisco products is to enable LLDP on your Nexus and servers. That will at least give you the ability to pull the information from the NX-OS command line ("show lldp neighbor")

  • 6500-VSS and NEXUS 56XX vPC interoperability

    Hello, is it possible to establish a PORT CHANNEL between a couple of Cisco 6500 running VSS mode and a couple of NEXUS 5000 running vPC? . Design should be " Back-to-Back" :  VSS-- Port-Channel--vPC.
    I want also to support L2 and L3 flows between the two couples.
    I read many forums but i am not sure it runs.
    Is such design, if it runs; supported by Cisco?
    Thanks a lot for your help.

    Hi Tlequertier,
    We have VSS 6509Es with Sup 2Ts & 6908 modules. These have a 40gb/sec (4 x 10gb/sec) uplink to our NEXUS 5548UP vPC switches.
    So we have a fully meshed ether-channel between the 4 physical switches (2 x N5548UP & 2x6509E)
    Kind regards,
    Tim

  • Nexus 5548P vs Nexus 5548UP

    I have a question regarding Nexus 5548UP which is supported from NXOS 5.0.3 on.
    I assume thats the absolute indentical hardware as the Nexus5548P which was available a little bit
    earlier and had also the HW ready for support Unified Ports on all Ports (but was just enabled on expansion-module).
    Is it possible by SW upgrade to 5.0.3 to make a 5548UP from a 5548P ?
    Thx
    hubert

    Thx Lucien,
    then there is absolutely no reason to buy the 5548P, because 5548UP has same price, and no reason to buy another expansion-module than the UP(has the same price as well compared to the other expansion Module ?
    So I assume 5548P and the pure Eth-uplink Modul, and the mixed FC and Eth-uplink Modul will have very limited lifetime ?!
    One additional Question: I read that in case a 5596 has L3-Modul built in , it no longer supports the maximum numbers of FEXes  it supports only 8 then.
    Is this a limitation which will remain, or is there a chance new NX-OS Versions will break thhis limit
    KR
    Hubert

  • Connecting many Brocade switches to Nexus 5548UP

    Hello,
    I have a SAN network composed of few separate PODs. Each POD is divided into SAN-A and SAN-B. Most of those PODs are Brocade switches (FOS 6.1). There are also few Nexus 5520s. Now, we have built new core infrastructure with Nexus 5548UPs and many MDS 9148s. We would like to move all servers and sotrage from old Brocades to the new SAN. As we cannot move all devices at the same time, all segments must be connected to the core for some time. Each POD has different zoning. Some zonings on Brocade switches are based on PWWN, some on Domain ID and Port ID. In my opinion, the only way of successfuly connecting all PODs together is to merge zones manualy (in excel, etc). and paste them on all switches. However, maybe there is some other way of merging all zones? What if I leave Nexus 5548UP in native mode (so zones from Brocade will not get merged), and only implement that manually merged zoneset on Nexus 5548UP? Will the ISL links get isolated due to zoning merge failure? Or they will maintain operational state even if zones are different on each POD? I do not have any lab boxes, so I cannot test it. Any advidse will be appreciated.
    Best regards,
    Krzyszof

    well since you can not cluster the 45K as a virtual switch ( Cisco with new sup will start support VSS in the 4500 try to check which sup exactly and if you can upgrade as this will make a significant improvement to your design )
    anyway the only method that you can use currently is the traditional way which is depending on STP ( use rapid-PVST)
    from each N5K use one separate link to each 45K and STP will put on of the links in blocking mode
    however you might do some STP and vlan design for load sharing where you can send vlan x over link1 and vlan y over link b to the 45K using STP cost
    HTH

  • Cisco Nexus 5548UP upgrade path

    Hi,
       I'm planning to upgrade Nexus 5548UP (no L3 services) from 5.2(1)N1(6)  to 7.0(5)N1(1). Is this upgrade path vaild? or is there any intermediate version; also advise if ISSU is possible.
    Regards,
    Navin RK

    Hi,
    Yes you can upgrade directly from 5.2(1)N1(6) to 7.0(5)N1(1).  ISSU is possible, provided you meet the requirements.  You can copy the kickstart and system image to bootflash, then run the "show install all impact" command to see whether or not ISSU will be possible with your configuration.
    Here is a document supporting the statements above: http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5500/sw/upgrade/705_N1_1/n5500_upgrade_downgrade_700.html#pgfId-640981

  • Cisco Nexus 5548UP to Brocade SAN Connectivity

    Hi,
    I have a Server-SAN-Storage setup as shown in the attachment/below. There are new Cisco UCS rack mount servers with VIC 1225 and Virtual servers on VMware Esxi hypevisor connected to a new Cisco Nexus 5548UP switch in IP+FCoE mode. The new 5548 switch then connects to an existing production SAN of Brocade 48000 Director SAN switch which connects to storage in production environment.
    I need to know the best way to connect the 5548 switch to the Brocade SAN switch without disrupting the existing Production SAN environment i.e. Brocade SAN switch configurations & setup e.g. Fabric Principal switch. priority etc.
    Would configuring the 5548 switch in NPV mode be best practice?

    See Figure 6-2 Converged Multi-hop FCoE Network Design Using FCoE NPV
    http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/operations/fcoe/513_n1_1/ops_fcoe/ops_fcoe_npv.html
    You have to use NPV on N5k, there is no FC interop support on N5k, to connect to Brocade.

Maybe you are looking for