ACE Switchover and Config Sync

Hi
I'm new to the ACE modul and trying to set up some szenarios and i run already into some troubles.
Question 1)
I configured redundancy to another module - virtulised mode. Config sync between the context worked fine. If i change s'thing in the activ context it was copied to the standby context. But if i changed something in the active Admin context it was not copied to the standby Admin context.
Question 2)
FT Switchover in the Admin context is not possible returns the following fault:
ACE_Switch08/Admin# ft switchover
This command will cause card to switchover (yes/no)? [no] yes
Invalid FT group. FT switchover command will be ignored.
ACE_Switch08/Admin#
If I switch a single FT group it works. But how is it possible to switch all FT groups a the same time? Do i have to switch each context by itself?
Question 3)
After i have switched the active context to the standby context, the ft group x command shows both peers as active. After i take the standby ft group no inservice and back inservice it shows correctly Active and standby_HOT.
The configuration:
hostname ACE_Switch08
boot system image:c6ace-t1k9-mz.3.0.0_A1_4a.bin
resource-class RC1
limit-resource all minimum 10.00 maximum equal-to-min
class-map type management match-any REMOTE_ACCESS
description -- Remote Access traffic match --
2 match protocol telnet any
3 match protocol ssh any
4 match protocol icmp any
policy-map type management first-match REMOTE_MGMT_ALLOW_POLICY
class REMOTE_ACCESS
permit
interface vlan 2100
ip address 172.29.190.16 255.255.255.0
service-policy input REMOTE_MGMT_ALLOW_POLICY
no shutdown
ft interface vlan 2020
ip address 192.168.100.1 255.255.255.0
peer ip address 192.168.100.2 255.255.255.0
no shutdown
ft peer 1
heartbeat interval 200
heartbeat count 20
ft-interface vlan 2020
ip route 0.0.0.0 0.0.0.0 172.29.190.1
context sf0-2200
allocate-interface vlan 2201
allocate-interface vlan 2207
member RC1
context sf0-2220
allocate-interface vlan 2221
allocate-interface vlan 2227
member RC1
ft group 1
peer 1
no preempt
priority 200
peer priority 150
associate-context sf0-2200
inservice
ft group 2
peer 1
no preempt
priority 200
peer priority 150
associate-context sf0-2220
inservice
username admin password xxx role Admin domain
default-domain
username www password xxx role Admin domain de
fault-domain
Any help is appreciated
pat

Hi Pat,
1)
for my config i just put the "user" or "backend" contexts into ft groups. I don't sync the admin contexts on both aces. I am not even sure if that makes sense or is "best practicse".
So if you don't put the admin context into an extra ft group it won't be synced. you have to configure the admin contexts on each physical ace separately.
Putting the contexts sf0-2200 & sf0-2220 into an ft group and not having an ft group for admin is the way to go IMHO.
2)
If you do a switchover you always have to specify which context you want to switchover. I don't think that you can actually switchover a whole bunch of contexts with this command. If you want to do that a reload is the only way AFAIK.
Try:
ft switchover 1
ft switchover 2
3)
This could be because you have not configured the other ACE's admin context to participate in the ft properly.
My configs looke like this.
ACE01:
ft interface vlan 777
ip address 172.16.99.1 255.255.255.252
peer ip address 172.16.99.2 255.255.255.252
no shutdown
ft peer 1
heartbeat interval 200
heartbeat count 20
ft-interface vlan 777
query-interface vlan 444
ft group 3
peer 1
priority 150
peer priority 110
associate-context FOO
inservice
ft group 4
peer 1
priority 150
peer priority 110
associate-context BAR
inservice
ft group 2
peer 1
priority 150
peer priority 110
associate-context FOO-BAR
inservice
ACE02:
ft interface vlan 777
ip address 172.16.99.2 255.255.255.252
peer ip address 172.16.99.1 255.255.255.252
no shutdown
ft peer 1
heartbeat interval 200
heartbeat count 20
ft-interface vlan 777
query-interface vlan 444
ft group 2
peer 1
no preempt
priority 110
peer priority 150
associate-context FOO
inservice
ft group 3
peer 1
no preempt
priority 110
peer priority 150
associate-context BAR
inservice
ft group 4
peer 1
no preempt
priority 110
peer priority 150
associate-context FOO-BAR
inservice
Hope that helps
Roble

Similar Messages

  • ANM device importing and config sync - user name authenticatiing via ACS

    Good day,
    We have the following issue:
    Switches and ACE modules imported into ANM 3.2. Additional modules added and tried to import. Failed. Tried to sync and recieved the following message for Admin context:
    - Failed to import ACE configuration: Device discovery failed: cannot find the serial number.
    All other contexts also fail to sync.
    Thought this may be due fact that the user Id used for import is and AD account and this authenticates via ACS to AD and this has expired and changed since original import. Deleted chassis and re-impoted with same user Id and new password and all works fine.
    Have checked the links below, however, I don't beleive these will resolve the issue:
    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:"Table Normal";
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-priority:99;
    mso-style-qformat:yes;
    mso-style-parent:"";
    mso-padding-alt:0in 5.4pt 0in 5.4pt;
    mso-para-margin:0in;
    mso-para-margin-bottom:.0001pt;
    mso-pagination:widow-orphan;
    font-size:11.0pt;
    font-family:"Calibri","sans-serif";
    mso-ascii-font-family:Calibri;
    mso-ascii-theme-font:minor-latin;
    mso-fareast-font-family:"Times New Roman";
    mso-fareast-theme-font:minor-fareast;
    mso-hansi-font-family:Calibri;
    mso-hansi-theme-font:minor-latin;
    mso-bidi-font-family:"Times New Roman";
    mso-bidi-theme-font:minor-bidi;}
    http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/application_networking_manager/3.1/user/guide/UG_manage_devices.html#wp1094120
    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:"Table Normal";
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-priority:99;
    mso-style-qformat:yes;
    mso-style-parent:"";
    mso-padding-alt:0in 5.4pt 0in 5.4pt;
    mso-para-margin:0in;
    mso-para-margin-bottom:.0001pt;
    mso-pagination:widow-orphan;
    font-size:11.0pt;
    font-family:"Calibri","sans-serif";
    mso-ascii-font-family:Calibri;
    mso-ascii-theme-font:minor-latin;
    mso-fareast-font-family:"Times New Roman";
    mso-fareast-theme-font:minor-fareast;
    mso-hansi-font-family:Calibri;
    mso-hansi-theme-font:minor-latin;
    mso-bidi-font-family:"Times New Roman";
    mso-bidi-theme-font:minor-bidi;}
    http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/application_networking_manager/3.1/user/guide/UG_manage_devices.html#wp1393377
    I beleive this is occuring due the fact that we are authenticating via ACS to AD for all devices (switches and ACE modules) as well as ANM.
    So is the only solution here to create a static user account in ACS and add to relevent NDG's for switches and ACE modules?
    Also would we have to have the password never expire as I don't see a way to change/configure this password within ANM apart from when the devices are initially imported?
    Any input would be greatly appreciated.
    Thanking you in advance.
    Paul
    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:"Table Normal";
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-priority:99;
    mso-style-qformat:yes;
    mso-style-parent:"";
    mso-padding-alt:0in 5.4pt 0in 5.4pt;
    mso-para-margin:0in;
    mso-para-margin-bottom:.0001pt;
    mso-pagination:widow-orphan;
    font-size:11.0pt;
    font-family:"Calibri","sans-serif";
    mso-ascii-font-family:Calibri;
    mso-ascii-theme-font:minor-latin;
    mso-fareast-font-family:"Times New Roman";
    mso-fareast-theme-font:minor-fareast;
    mso-hansi-font-family:Calibri;
    mso-hansi-theme-font:minor-latin;
    mso-bidi-font-family:"Times New Roman";
    mso-bidi-theme-font:minor-bidi;}

    Dears
    kindly your help  when i'm trying to import ACE Module i got the following massege .
    - Failed to import ACE configuration: Device discovery failed: cannot find the serial number.
    does any body have a resolutoin for this error ?.
    BR

  • Nexus 5595 7.0(5)N1(1) - Config Sync / CFS Issue

    Hello,
    Posting this fix as it may help anyone facing the same issue.
    We recently installed 2 x Nexus 5596 into our DC with the management connections running across 6500 VSS switches.  We have the same setup in another DC and all worked fine.  However, with the new installation we upgraded to 7.0(5)N1(1) and hit a problem with the config-sync not working across the mgmt0 interfaces.  However, the Peer was reachable over mgmt0 as VPc was up and we could ping / SSH no problem.
    We also have the necessary ‘cfs ipv4 distribute’ enabled.  Output of issue below:
    switch-profile  : Tcprofile
    Peer-IP-address            : 192.168.1.28
    Peer-sync-status           : Not yet merged
    Merge Flags: pending_merge:1 rcv_merge:0 pending_validate:0
    Peer-status                : Peer not reachable
    We tried various things such as removing the ‘cfs ipv4 distribute’ and re-enabling but this didn't fix the problem.  So spoke to a Cisco engineer who suggested the 6500 could be blocking multicast and therefore stoppping CFS traffic across our management Vlan.  Apparently there have been some changes to CFS in the latest NXOS.
    So the fix was simple in the end.  We just enabled PIM on our 6500 SVI and Config Sync sprang into life.  See below:
    interface vlan x
    description Management Vlan
    ip pim sparse-dense-mode
    Hope this helps

    Hi, I have upgraded from 5.2.1.N1.4 to 7.1.0.N1.1b.
    There were many bugs.
    I found we can't upgraded to 7.1.0 from NX-OS prior to 7.0 in Cisco official.
    So, I have upgraded to 7.0.5N1.1 then to 7.1.0N1.1b.
    In result, some part of startup-config such as logging server  is lost.
    I'm going to try to upgrade in same process a few times.
    Sincerery

  • ACE Ft config sync question during primary ACE blade replacement

    I am replacing my primary ACE blade and am wondering if when I reconfigure the admin context with the ft groups will I have any issues syncing the secondary back to the primary? I don't want to run the risk of a blank config from the new primary blade being pushed to secondary.
    Any help is appreciated.
    thanks

    Treat the current as primary and put the new module as a secondary (by applying low priority vlaues for ft vlans ) and disable premption.
    Complete steps will be...
    Before putting the new module in, configure the standby (which should be acting as master -- since primary is out) module with the "no-preempt" option on each FT vlan.
    Now with new module
    1. Bring the new ACE module online and upgrade it to the same software than is running on the temp master.
    2. Define all of your resource-maps, FT vlans
    3. Add "no preempt", set a lower "priority" than is defined on the peer (temp master)
    4. Install any SSL certificates
    5. Define your context (repeating the same for SSL certs if necessary).
    6. Add the command "ft auto-sync" to your Admin context.
    7. Once the configuration has synced, (by confirming the FT status is now
    "FSM_FT_STATE_STANDBY_HOT"), you're ready to perform the FT switch over.
    8.In your Admin context, change the peer priority to be lower than the new
    master for each FT group, then issue the command "ft switchover X",
    replacing X with each FT group beginning in the Admin context, then doing the same in your other context.
    Thanks
    Syed

  • How to transfert all my data and config from 4 to 4s

    Hello,
    Is there a "step by step" doc. On how to transfert all my data and config
    From one iphone 4 to a 4s without using outlook ( ex:for contacts ) etc...
    I don't get the ITunes method, sync direction etc...
    All my Iphone 4 Put into my knew Iphone 4 S within a click !
    Maybe there's an app for that :-).
    Thanks for the Help.

    iOS: Transferring information from your current iPhone, iPad, or iPod touch to a new device

  • Problem with config sync between two CSM-S modules

    Hi everybody,
    I have a problem with config sync between two CSM-S modules.
    I am using CSM-S software version 2.1(8).
    The acitve module is used in a 6509 with WS-SUP720-BASE supervisor running software version 12.2(18)SXF12a.
    The standby module is used in a 6509-V with VS-S720-10G supervisor (no VSS setup) running software version 12.2(33)SXI3.
    Failover seems to work fine:
    switch-active#sh modu csm 2 ft                                      
    FT group 1, vlan 398
    This box is active
    Configuration is out-of-sync
    priority 150, heartbeat 3, failover 40, preemption is on
    switch-standby# sh modu csm 2 ft
    FT group 1, vlan 398
    This box is in standby state
    Configuration is out-of-sync
    priority 80, heartbeat 3, failover 40, preemption is on
    The command (on active side) "hw-module contentSwitchingModule 2 standby config-sync" leads to following result:
    switch-active:
    2010-04-14T16:21:45+02:00 srz16-1b.net.dsh.at/srz16-1b.net.dsh.at 56042: Apr 14 16:21:44.223: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Active: Bulk sync started
    2010-04-14T16:21:45+02:00 srz16-1b.net.dsh.at/srz16-1b.net.dsh.at 56043: Apr 14 16:21:44.251: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Active: Sending configurations to Standby CSM, this may take several minutes!
    2010-04-14T16:21:46+02:00 srz16-1b.net.dsh.at/srz16-1b.net.dsh.at 56044: Apr 14 16:21:45.995: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Active: Sending configuration to Standby CSM
    2010-04-14T16:21:51+02:00 srz16-1b.net.dsh.at/srz16-1b.net.dsh.at 56045: Apr 14 16:21:50.831: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Active: Sending configuration to Standby CSM
    2010-04-14T16:21:57+02:00 srz16-1b.net.dsh.at/srz16-1b.net.dsh.at 56046: Apr 14 16:21:56.151: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Active: Sending configuration to Standby CSM
    2010-04-14T16:22:59+02:00 srz16-1b.net.dsh.at/srz16-1b.net.dsh.at 56047: Apr 14 16:22:58.791: %CSM_SLB-3-REDUNDANCY: Module 2 FT error: Active: Manual bulk sync timed out
    2010-04-14T16:22:59+02:00 srz16-1b.net.dsh.at/srz16-1b.net.dsh.at 56048: Apr 14 16:22:58.803: %CSM_SLB-3-REDUNDANCY: Module 2 FT error:
    2010-04-14T16:22:59+02:00 srz16-1b.net.dsh.at/srz16-1b.net.dsh.at 56049:  FT CONFIG SYNC: Failed config sync entity send
    switch-standby:
    2010-04-14T16:21:45+02:00 srz31-5a.net.dsh.at/srz31-5a.net.dsh.at 2475: Apr 14 16:21:44.232: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Standby: Bulk sync started
    2010-04-14T16:21:45+02:00 srz31-5a.net.dsh.at/srz31-5a.net.dsh.at 2476:
    2010-04-14T16:21:45+02:00 srz31-5a.net.dsh.at/srz31-5a.net.dsh.at 2477: Apr 14 16:21:44.240: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: STANDBY:Configuration is being received, This may take several minutes!
    2010-04-14T16:21:49+02:00 srz31-5a.net.dsh.at/srz31-5a.net.dsh.at 2478: Apr 14 16:21:48.824: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Standby: Receiving configuration from Active CSM
    2010-04-14T16:21:54+02:00 srz31-5a.net.dsh.at/srz31-5a.net.dsh.at 2479: Apr 14 16:21:53.964: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Standby: Receiving configuration from Active CSM
    2010-04-14T16:21:59+02:00 srz31-5a.net.dsh.at/srz31-5a.net.dsh.at 2480: Apr 14 16:21:58.852: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Standby: Started clearing configuration
    2010-04-14T16:21:59+02:00 srz31-5a.net.dsh.at/srz31-5a.net.dsh.at 2481: Apr 14 16:21:59.400: %CSM_SLB-4-REDUNDANCY_WARN: Module 2 FT warning: Standby: Config Sync does not save running-config to startup-config
    2010-04-14T16:22:00+02:00 srz31-5a.net.dsh.at/srz31-5a.net.dsh.at 2482: Apr 14 16:21:59.400: %CSM_SLB-6-REDUNDANCY_INFO: Module 2 FT info: Standby: Previous configuration are being deleted from supervisor
    The last log message on standby device seems to be correct - there is no CSM configuration after the attempted config sync.
    Our configuration includes about 3500 lines and it is really uncomfortable to keep in sync manually.
    Maybe someone has the same problem?
    kind regards,
    Christoph

    Hi Christoph,
    I am running into the exact same issue. Upon further investigation I've discovered that this is a known bug, CSCtd09117.  You can read more about it here: http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCtd09117 .   Apparently this is fixed in ver 12.2(32.8.11)SX323 .
    I haven't had a chance to upgrade yet, so I can't verify the fix, but if it works for you please let me know.
    Regards,
    Brandon

  • CSM config-sync in bridge mode?

    We are planning to upgrade our CSM from 4.1.6 to 4.2.6 and wanted to be able to utilize the config-sync capabilites in the new code. First, is config-sync supported in bridge mode and has anyone had much success or problems? We weren't able to find documentation on this? Please help!

    config-sync works with bridge mode and routing mode.
    You might want to go to 4.2.7 due to this ddts :
    CSCse65938: CSM config-sync causes standby csm to core dump
    Also, make sure your IOS version is at the right level due to this
    CSCej00341: CSM Configuartion Sync timing out for large configurations
    Gilles.

  • Getting "File copy Config Sync Failed. Commit unsuccessful! " on CSS-11155

    Getting a strange error "FILE copy Config Sync Failed. Commit unsuccessful!" from the following and I am not sure what it exactly means:
    cce01-c35-in# sh app
    APP CONFIGURATION:
    Enabled PortNumber: 5001 MaxFrameSize: 10240
    cce01-c35-in# sh app session
    App Session Information 'no hostname':
    Session ID: 839f0990 IP Address: 10.10.10.2 State: APP_SESSION_UP
    css-c09-nz# commit_redundConfig "10.10.10.2"
    Verifying app and redundancy configs ... -
    Checking local and remote switch versions ...|
    Checking Backup app session up.... \
    Checking redundancy state.... -
    Working /
    Waiting for completion signal from remote switch .../
    Verifying running-config copy success ...-
    File copy Config Sync Failed. Commit unsuccessful!
    localconfig: 6238 bytes
    remoteconfig : 6150 bytes
    css-c09-nz#

    there is at least one know bug :
    CSCdx89818 - config sync fails
    I could not check if this applies to you since you did not provide your version.
    This bug was fixed in the following release :
    006.010(000.004) 05.3(00.18)S 05.0(00.54)S 05.10(01.03)S
    Gilles.

  • ACE 4700 and Cisco ACS aaa authentication

    ACE version Software
    loader: Version 0.95
    system: Version A1(7b) [build 3.0(0)A1(7b)
    Cisco ACS version 4.0.1
    I am trying to authenticate admin users with AAA authentication for ACE management.
    This is what I've done:
    ACE-lab/Admin(config)# tacacs-server host 192.168.3.10 key 123456 port 49
    warning: numeric key will not be encrypted
    ACE-lab/Admin(config)# aaa group server tacacs+ cciesec
    ACE-lab/Admin(config-tacacs+)# server ?
    <A.B.C.D> TACACS+ server name
    ACE-lab/Admin(config-tacacs+)# server 192.168.3.10
    can not find the TACACS+ server
    specified TACACS+ server not found, please configure it using tacacs-server host ... and then retry
    ACE-lab/Admin(config-tacacs+)#
    Why am I getting this error? I have full
    connectivity between the ACE and the ACS
    server. Furthermore, the ACS server
    works fine with other Cisco IOS devices.
    Please help. Thanks.

    Thanks. Now I have another problem. I CAN
    log into the ACE via tacacs+ account(s).
    However, I get error when I try going into
    configuration mode:
    ACE-lab login: ngx1
    Password:
    Cisco Application Control Software (ACSW)
    TAC support: http://www.cisco.com/tac
    Copyright (c) 1985-2007 by Cisco Systems, Inc. All rights reserved.
    The copyrights to certain works contained herein are owned by
    other third parties and are used and distributed under license.
    Some parts of this software are covered under the GNU Public
    License. A copy of the license is available at
    http://www.gnu.org/licenses/gpl.html.
    ACE-lab/Admin# conf t
    ^
    % invalid command detected at '^' marker.
    ACE-lab/Admin#
    The ngx1 account can access other Cisco
    routers/switches just fine and can go into
    enable mode just fine. Only issue on the ACE.
    Any ideas? Thanks.

  • DHCP Failover Auto Config Sync

    Downloaded most current version of script and set it up in lab.  It works but the log file (.\dhcpautosynclogfile.txt) is growing at a fast rate.  Entries for sync complete and automatically sync again are being posted at rate of 3 or 4
    times per second.

    Script is the DHCP Failover Auto Config Sync script.  
    Questions is - why is log file filling at such an alarming rate ?
    And what script is that? Who wrote it? Have you contacted the author?
    Believe it or not, we haven't heard of every script ever written. =]
    EDIT: Is this what you're referring to?
    http://gallery.technet.microsoft.com/scriptcenter/Auto-syncing-of-configurati-6eb54fb0
    If so, post your question on the QandA tab so the author will see it.
    Don't retire TechNet! -
    (Don't give up yet - 12,830+ strong and growing)

  • Nexus 5K Config-Sync : Things to look out for

    I've looked through the Cisco config guides for setting up Config sync and have successfully used it to configure dual-homed FEX's ports.
    Is there anything I should be aware of that can cause issues?
    I enabled config sync on an existing pair of 5Ks.  In other words, the 5Ks already have existing configurations on them before I enabled config sync.

    Hi,
    According to the this link, you still have to configure the single port in switch profile. Config sync is used when your devices are connected to both 5ks, so you don't have configure the same thing twice.  If your device is going to be singly attached, there is no need for config sync.
    Guidelines and Limitations
    The guidelines for configuration synchronization are as follows:
    •You must configure the following interfaces in a switch profile:
    –Port-channel interfaces
    –Ports that are not channel-group members
    •You must configure all port-channel members outside the switch profile in configuration terminal mode.
    •You must follow configurations in a specified order.
    •Depending on the type of vPC topology (active/active or straight-through) and the type of configuration that is needed (port channel, nonport channel, FEX, QoS, and so on), you must use the switch profile mode or the configuration terminal mode. See the "At-A-Glance Configuration Modes" section to identify what mode is used for different types of configurations.
    Configuration synchronization has the following configuration limitations:
    •FCoE in vPC Topologies—FCoE configurations are not supported in switch profiles because configurations are typically different on peer switches. If you enable FCoE on a vPC peer switch, you must not configure the port channel in the switch profile.
    • Feature Commands—The feature feature name commands that enable a conditional feature are not supported in switch profiles. You should independently configure these commands on each peer switch in configuration terminal mode.
    •Configuration Rollback and Conditional Features—With configuration synchronization, when a conditional feature is present in a checkpoint and not in the running configuration, a configuration rollback to that checkpoint fails. The workaround is to reconfigure the conditional feature ("feature xyz") before the configuration rollback is executed. This workaround also applies to the vpc domain command and the peer-keepalive command in vpc-domain mode.
    link:
    http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/operations/n5k_config_sync_ops.html#wp1035414
    HTH

  • 5548 Config Sync issue - Suspended by vPC

    I have 2 UCS 6120 fabric interconnects which both have VPCs to 2 x 5548s.  First fabric interconnect uses Po260 & vPC 260 and second fabric interconnect uses Po261 & vPC 261.  I used config sync to add "spanning-tree port type edge trunk" to int po 260 & 261.  The commit worked properly, peers are in sync, etc.  The problem is when I committed the command, int po 260 & 261 on the secondary 5548 went into "suspended by vPC".  I can't figure out why they did this, the configurations are the same and all vPC consistency checks pass.  To fix the issue, all I had to do was bounce the port-channel on the secondary 5548 (shut/no shut) after which it came back online.  I only did this to Po260 so Po261 is still down so that I can troubleshoot further.  Please see below:
    vPC domain id                     : 70 
    Peer status                       : peer adjacency formed ok     
    vPC keep-alive status             : peer is alive                
    Configuration consistency status  : success
    Per-vlan consistency status       : success                      
    Type-2 consistency status         : success
    vPC role                          : secondary                    
    Number of vPCs configured         : 7  
    Peer Gateway                      : Disabled
    Dual-active excluded VLANs        : -
    Graceful Consistency Check        : Enabled
    Auto-recovery status              : Disabled
    vPC Peer-link status
    id   Port   Status Active vlans   
    1    Po255  up     1,10-13,26-29,151-156,180-181,200,318,331,399-417,       
                       419-422,424-431,433-436,438-443,446-448,450,452-45       
                       3,455-458,460-465,467-471,480-494,498-499,503,602-       
                       633,644-657,659,663-664,698-701,800,805,850-851,89       
                       0-891,899-904,906,908,912-950,952-958,975,987-988,    ....
    vPC status
    id     Port        Status Consistency Reason                     Active vlans
    171    Po171       up     success     success                    1,10-13,26-
                                                                     29,151-156,
                                                                     180-181,200
                                                                     ,318,331,39
                                                                     9-417,41....
    260    Po260       up     success     success                    10-13,26-29
                                                                     ,663-664,89
                                                                     0-891      
    261    Po261       down*  success     success                    -
    sh int po 261
    port-channel261 is down (suspended by vpc)
    Any help would be appreciated

    Yes, I did check that and all parameters match as follows:
    5548-2# sh vpc consistency-parameters int po 261
        Legend:
            Type 1 : vPC will be suspended in case of mismatch
    Name                        Type  Local Value            Peer Value            
    Shut Lan                    1     No                     No                   
    STP Port Type               1     Edge Trunk Port        Edge Trunk Port      
    STP Port Guard              1     None                   None                 
    STP MST Simulate PVST       1     Default                Default              
    lag-id                      1     [(7f9b,                [(7f9b,              
                                      0-23-4-ee-be-46, 8105, 0-23-4-ee-be-46, 8105,
                                       0, 0), (8000,          0, 0), (8000,       
                                      0-5-73-d4-d5-fc, 1, 0, 0-5-73-d4-d5-fc, 1, 0,
                                       0)]                    0)]                 
    mode                        1     active                 active               
    Speed                       1     10 Gb/s                10 Gb/s              
    Duplex                      1     full                   full                 
    Port Mode                   1     trunk                  trunk                
    Native Vlan                 1     10                     10                   
    MTU                         1     1500                   1500                 
    Admin port mode             1                                                 
    Allowed VLANs               -     10-13,26-29,663-664,89 10-13,26-29,663-664,89
                                      0-891                  0-891                
    Local suspended VLANs       -     -                      -      

  • Config-sync issue in Nexus5K

    Hello
    I am trying to add a vlan to my pair of Nexus 5K with the confi-sync, but I recieve a really strange error comming from the peer switch
    switch-profile  : S1-S2
    Peer-IP-address            : x.x.x.2
    Peer-sync-status           : In sync
    Peer-status                : Commit Failure
    Peer-error(s)              : Invalid username: user does not exist
    Does anybody know what does it mean ?
    Thank you in advance
    Regards
    Lucas

    My guess is that on the other Nexus switch the username/password/privilege information is different. Check out this document that has a lot of details on config-sync and the ways it can go wrong...
    http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/operations/n5k_config_sync_ops.html#wp1051910
    Hope it helps
    Peter

  • CSS11501 Hangs during Config Sync

    We have CSS11501 boxes in redundancy mode. Until now, the config sync process happened without any issues. For the last two occassions, the CSS hangs completely during manually initiated config sync thereby bringing down all active connections..After the sync is completed, the box returns back to normal.
    The only changes made in recent time is the Redundancy config (failover from master to backup forcefully)..
    Any know issues on the following bundle:-
    Version: sg0810002 (08.10.0.02)
    Flash (Locked): 07.40.0.04
    Flash (Operational): 08.10.0.02
    Type: PRIMARY
    Licensed Cmd Set(s): Standard Feature Set

    Hi, I will check to see if your are hitting any know issue but let me tell you that 8.10.002 is the first release of 8.10 code and we have 8.10.301 already which would be the best way to go at this point.
    I will update you with any know issue. It would be useful to see the showtechs when the issue is showing u.
    Also when you say that hangs completely:
    would no respond to ping to the VLAN IP?
    is it accesible via telnet or ssh?
    is it accesible via console?
    What kind of redundancy are you using? do you see any failover at the time of the problem?
    Can you show me the syntax you are using to sync the config?.

  • I upgraded from iPhone 3GS to iPhone 6.  Everything converted fine until I deleted an app in error.  When I downloaded it from iTunes, my account is no longer recognized by the app's host servers.  Can I go back and re-sync one app from my old phone?

    I upgraded from iPhone 3GS to iPhone 6.  Everything converted fine.  Yesterday I deleted an app in error.  When I downloaded the software it from iTunes ( did this many times on the old 3GS), my account is no longer recognized by the app's host servers (Playtika), even though it did after the initial conversion.  Can I go back and re-sync just one app from my old phone?  

    Try deleting what is called the iPod Photo Cache. 
    http://support.apple.com/kb/TS1314

Maybe you are looking for