Adding Nexus 5596 to ACS v4.2

Hi.  Does ACS v4.2 support the addition of the Nexus switches?  We have a few new Nexus devices that have been added to ACS, but cannot be accessed successfully.  A msg re: role based authentication is received.  Do I have to do something special in ACS to support this?
Nexus 5596 v5.1(3)N2(1)
Thanks!

Hi Keely
Please check the following lins about nexus configuration:
http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/troubleshooting/guide/n5K_ts_sec.html
http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/sec_aaa.html
ACS should use cisco-av-pair attribute for nexus devices.
HTH,
Alex

Similar Messages

  • What is the best way to migrate zoning from an MDS9216i to a Nexus 5596?

    I am migrating from a MDS9216i to a Nexus 5596.  We have dual paths, so I can migrate one leg at a time and the full function for these switches is fiber channel attached storage.
    What is the best way to migrate the zoning information? I have been told I can ISL the new and old switch together and then push the zoning to the new switch.  Is that better than just cutting and pasting the zoning information to the new switch?
    Also, I have to move four Brocade M4424 switches to the new switches - they are currently attached via interop mode 1, but will now be attached using NPIV.  Has anyone done this before, and did you have any issues?
    Any help or advice would be appreciated. Thanks!

    Use an ethernet cable to connect the two computers, and set up file sharing. After that copying files from one computer to the other is exactly like copying from one hard drive to another:
    http://docs.info.apple.com/article.html?artnum=106658

  • Cisco Nexus 5596 does not boots up after NX-OS upgrade 5.1.3.N1.1 to 6.0.2.N2.5 [CSCun66310]

    Hello Friends,
    Just want to save your precious time & effort, while doing Nexus 5596 upgrades so wanted to share some useful info which you can have a look prior to your upgrades of Cisco Nexus 5596 device.
    I recently ran into trouble when upgarding one of datacenter switch Nexus 5596 does not boots up and after investigation from Cisco TAC it comes out to be Bug documented below.
    https://tools.cisco.com/bugsearch/bug/CSCun66310/?reffering_site=dumpcr
    My Upgrade path of device was : 5.1(3)N1(1)  to  6.0(2)N2(5).
    Since this upgarde involves upgrade of Bios and Power sequensor, I was having some doubts to get this succesfully upgraded,  But there was more twist involved in this upgrade which I came to know after contacting Cisco TAC for my died Nexus 5596 device and got info that if you have below impacted version in your Nexus 5596 device and you are planning to do Upgrade, then you migh RUN into this serious BUG aftre which device won't come up at all and only Option left is to replace with RMA device.
    PID                            Impacted                   Hardware versions      Updated Versions
    UCS-FI-6296UP                                            1.0                                       1.1
    N5K-C5596UP                                              1.0                                        1.1
    N5K-C5596T                                                 1.1                                         1.2
    You can check hardware version using below command from your device.
    5596# show sprom sup | inc H/W
    H/W Version     : 1.1
    So please be carefull when planning your Nexus 5596 upgrade and verify above things as this Bug is not present anywhere in Upgrade docuemntations unfortunately.
    Hope this will help and save someone's precious Time.

    Today "upgraded" our switch (N5k-C5596UP) to from 5.1(2)N1 to 7.0(5) and after reboot no life from the switch either. Even no console response. show sprom sup | inc H/W shows 1:0.
    Only thing we could do is RMA the switch. So what must I do with these switches? Have still to do 3 of them.

  • Maximum number of interfaces in Port Channel on Nexus 5596

    Let me preface this by saying I am not a network expert....
    I noticed that our customer had configured a port channel on their Nexus 5596 comprised of 16 interfaces. I thought the maximum number of interfaces in a port channel was 8 interfaces? I see in the Nexus 7000 documentation that if you configure 16 interfaces, the remaining 8 will be in "hot standby." Is this the same behavior on the Nexus 5000 series?
    Thank you.

    Same behavior on the 5500 series and other Cisco switches like 3750, 3850 , etc..
    HTH

  • Nexus 5596 Ethernet Port Configuration

    I have a Cisco Nexus 5596 with 48 Ethernet Ports (two of which are now configured for Fibre Channel). It has a FEX attached to it as well.
    I was able to configure ANY Ethernet port with the typical interface commands when in interface configuration mode. However, I can now only configure existing and new Port Channel interfaces, FEX ports and standard Ethernet ports that have never been configured before.
    If I try to configure an Ethernet interface that was configured in the past, I only seem to have access to global interface commands when in interface configuration mode. I can set spanning-tree, duplex, speed or any other interface parameters. The CLI acts like I'm not in interface config mode, but the prompt shows that I am.
    Anyone else seen such a thing? I am logged in as admin.                 

    Hi Mark
    I suspect the interface in question is configured to be in a channel. Once an ethernet interface is configured to be in a port-channel. most interface commands need to be configured under the port-channel interface
    Thanks
    -Prashanth

  • Question about Nexus 5596 log.

    Dear Mister
    When I connect toward Nexus 5596, using ipv4 telnet, send the next message:
    NITE3# 2013 May  9 18:32:53 NITE3 %LOCAL7-4-SYSTEM_MSG: service telnet, IPV6_ADDRFORM - dcos-xinetd[3193]
    What is the reason for this?
    Could be a bug?
    Best Regards

    Hi,
    If you want to view the changes made to any an order than open that order and click on EXTRAS--> CHANGE DOCUMENTS in the main menu.
    Also if u want to see the changes made it the status u can refer the table CRM_JCDS.
    Regards,
    PePe

  • Nexus 5596 Licensing - filename exceeds 30 characters

    Hi,
    I'm trying to licensing two Nexus 5596 (Evaluated License), when i'm enter the "install license bootflash:LICENSE.lic" the Nexus reflect this error:
    "Installing license failed: Invalid filename size, filename exceeds 30 characters".
    After i changed the name the Nexus reflect this error:
    "Installing license failed: Invalid/Corrupt license file"
    I tried to clear the license from one switch and now i'm cannot reinstall the license.
    In the mail that cisco sent to me with the license they wrote that do not change the filename.
    Thanks in advance,
    Nadav Katz.

    Hi Eric,
    I received the Nexus switches with corrupted license.
    The license team of cisco was generate a new license and send it to me.
    Regareds,
    Nadav.

  • Nexus 5596 switch-profile synchronization problem

    hi
    I can't synchronize switch-profile
    System version: 5.1(3)N1(1)
    Sync-status: Not yet merged
    Merge Flags: pending_merge:0 rcv_merge:1 pending_validate:1
    Status: Verify Failure
    Error(s):
    Following commands failed parsing: If the error is 'Command Parsing Failed', please check if some conditional feature(s) needs to be enabled
    switchport mode trunk (Command Parsing Failed)
    how to find the source of the problem ?

    Hello Pawel
    Can you attach following from both Nexus 5596 switches in question
    term length 0
    show version
    show run
    show tech-support port-profile

  • Nexus 5596 FC-Port Link-Events

    Hi all,
    int the last 3 weeks,
    almost every day , we have a series of events in the connection between one Nexus 5596 and one of our servers. The connection is in FC (4G).
    I need help to understand the output of the following command to troubleshoot what could be happening.
    Sw-cpd-mm-n5k-2# show hardware internal fc-mac 3 port 14 link-event
    MMDDYY           HHMMSS usecs                                 Event                                      Current State
    -                          -                                                                                                      LINK_ACTIVE      
    100113              020845 773895 (0001)                              E_LINK_IDLE                               LINK_LRR_RX
    100113              020845 765016 (0000)                           E_LINK_LRR                           LINK_LR_TX
    100113              020845 763545 (61CB28)                       E_LINK_LINK_RESET             LINK_ACTIVE 
    Sw-cpd-mm-n5k-2# show hardware internal fc-mac 3 port 14 port-event
    MMDDYY               HHMMSS usecs                              Event                                                     Current State
    -                              -                                                                                                        IPS_LINK_UP     
    100113                 020845 775908 (0000)                        E_IPS_LINK_INIT_SUC                   IPS_LINK_UP     
    100113                 020845 775907 (0000)                        E_IPS_IDLE                                   IPS_LINK_UP     
    100113                 020845 770040 (0001)                        E_IPS_LRR                                    IPS_LINK_UP     
    100113                 020845 763562 (61CB28)                    E_IPS_CREDIT_LOSS                    IPS_LINK_UP  
    Looking at the output I don't know who generates "E_LINK_LINK_RESET" , Nexus switch or server?
    Thanks in advance!

    Hi,
    I know it is a little bit late, but hope it can still be of use...
    According to the log output, The switch detects a Credit Loss condition
    00113                 020845 763562 (61CB28)                    E_IPS_CREDIT_LOSS                    IPS_LINK_UP
    and to recover from it, the switch resets the link by sending a LR to the server
    100113              020845 763545 (61CB28)                       E_LINK_LINK_RESET             LINK_ACTIVE
    the server replies with a LRR, IDLE, etc.
    100113              020845 765016 (0000)                           E_LINK_LRR                           LINK_LR_TX
    Kind rgds,
    Felipon

  • Nexus 5596 and QOS config guide

    Hi,
    I need to implement qos on a nexus device for a client
    Basically what I am trying to implement is this but on the nexus
    Policy Map Enhanced_QoS_Customer_Out
          Description: Enhanced QoS customers outbound Percentages
        Class Cust_VoIP_Out
          priority 30 (%)
        Class Cust_Gold_Out
          bandwidth 30 (%)
        Class Cust_Silver_Out
          bandwidth 13 (%)
        Class Cust_Bronze_Out
          bandwidth 2 (%)
    Policy Map Ethernet_QoS_Customer_Out_200Mb
        Class class-default
          Average Rate Traffic Shaping
          cir 200000000 (bps)
          service-policy Enhanced_QoS_Customer_Out
    Is this possible on the nexus 5596?
    I havent found much information around shaping.. Please advise if the above policy is achelievable on the nexus and if not what does the nexus support?
    regards,

    Hi,
    I don't think the 5500 support shaping since it is mostly a layer-2 device.  Here is the config guide for QOS.
    http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/CLIConfigurationGuide/QoS.html
    HTH

  • Trunking nexus 5596 and netapp or exsi issue

    hi
    i have 2 issues with trunking between nexus 5596 and a esxi server .....can not get the servers to ping out
    and the netapp connected to the same 5596 cannot ping.
    if the server is a access port it works fine.
    is there any tricks that are required to be configured on the nexus to make this work.

    Make sure we are actually tagging for those vlans on the host (Netapp/ESXi). If we are not, then this would explain why it works in access mode on the switch.

  • Nexus 5596 SFP Issue

    We have a pair of Nexus 5596 switches, that each have a 1 gigabit conection to ISP CE switches (ME3400).
    Switch 1 has a fibre connection using GLC-SX-MM with the following information...
    sh int e1/48 trans
    Ethernet1/48
        transceiver is present
        type is SFP-1000BASE-SX
        name is CISCO-AVAGO
        part number is SFBR-5766PZ-CS2
        revision is
        serial number is AGA1549L2BE
        nominal bitrate is 1300 MBit/sec
        cisco id is --
        cisco extended id number is 4
    I cannot get the port to come up on switch 2, transceiver info...
    sh int e1/48 trans
    Ethernet1/48
        transceiver is present
        type is SFP-1000BASE-SX
        name is CISCO-AVAGO
        part number is SFBR-5766PZ-CS2
        revision is
        serial number is AGA1549L2BE
        nominal bitrate is 1300 MBit/sec
        cisco id is --
        cisco extended id number is 4
    The port is up on the ISP switch, but down on the N5K...
    Ethernet1/48 is down (Link not connected)
      Hardware: 1000/10000 Ethernet, address: 547f.ee41.e337 (bia 547f.ee41.e337)
      Description: Intech WAN ME3400-1 (BT)
      MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec
      reliability 255/255, txload 255/255, rxload 255/255
      Encapsulation ARPA
      Port mode is trunk
      full-duplex, 1000 Mb/s, media type is 10G
      Beacon is turned off
      Input flow-control is off, output flow-control is off
      Rate mode is dedicated
      Switchport monitor is off
      EtherType is 0x8100
      Last link flapped 00:31:00
      Last clearing of "show interface" counters 00:00:47
      30 seconds input rate 0 bits/sec, 0 packets/sec
      30 seconds output rate 0 bits/sec, 0 packets/sec
      Load-Interval #2: 5 minute (300 seconds)
        input rate 242.30 Gbps, 163.37 Mpps; output rate 63.30 Gbps, 231.54 Mpps
      RX
        17828772964 unicast packets  2506759 multicast packets  991 broadcast packets
        17831280714 input packets  3305852407174 bytes
        897530002 jumbo packets  0 storm suppression bytes
        20 runts  0 giants  0 CRC  0 no buffer
        20 input error  0 short frame  0 overrun   0 underrun  0 ignored
        0 watchdog  0 bad etype drop  0 bad proto drop  0 if down drop
        0 input with dribble  0 input discard Ethernet1/48 is down (Link not connected)
      Hardware: 1000/10000 Ethernet, address: 547f.ee41.e337 (bia 547f.ee41.e337)
      Description: Intech WAN ME3400-1 (BT)
      MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec
      reliability 255/255, txload 255/255, rxload 255/255
      Encapsulation ARPA
      Port mode is trunk
      full-duplex, 1000 Mb/s, media type is 10G
      Beacon is turned off
      Input flow-control is off, output flow-control is off
      Rate mode is dedicated
      Switchport monitor is off
      EtherType is 0x8100
      Last link flapped 00:31:00
      Last clearing of "show interface" counters 00:00:47
      30 seconds input rate 0 bits/sec, 0 packets/sec
      30 seconds output rate 0 bits/sec, 0 packets/sec
      Load-Interval #2: 5 minute (300 seconds)
        input rate 242.30 Gbps, 163.37 Mpps; output rate 63.30 Gbps, 231.54 Mpps
      RX
        17828772964 unicast packets  2506759 multicast packets  991 broadcast packets
        17831280714 input packets  3305852407174 bytes
        897530002 jumbo packets  0 storm suppression bytes
        20 runts  0 giants  0 CRC  0 no buffer
        20 input error  0 short frame  0 overrun   0 underrun  0 ignored
        0 watchdog  0 bad etype drop  0 bad proto drop  0 if down drop
        0 input with dribble  0 input discard
    I have tested the SFP's in use on a pair of 2960's & they work fine!
    If i replace the SFP's for copper, then they work fine also.
    Does anyone know of any incompatibility issue with this SFP?
    Thanks
    Colin

    Did you try a different port such as e1/1?  Sounds like a bug to me
    http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9670/data_sheet_c78-618603.html
    Table 2.
    Cisco Nexus 5500 Platform Transceiver Support Matrix

  • MAC flapping reported between 2 port channels on Nexus 5596

    Hi all, I'm seeing messages like the following reported on a Nexus 5596:
    2015 Jan  7 12:40:48.954 Switch-5596A %FWM-6-MAC_MOVE_NOTIFICATION: Host 00ab.cdef.0123 in vlan 104 is flapping between port Po5 and port Po10
    Po5 is connected to a storage cluster and is configured as an access port. It is connected to 2 Nexus 5596 switches using vpc.
    interface port-channel5
      description Storage Shelf 1
      priority-flow-control mode off
      switchport access vlan 104
      spanning-tree port type edge
      spanning-tree bpduguard enable
      speed 10000
      flowcontrol receive on
      vpc 5
    Po10 is the uplink to the core switch:
    interface port-channel10
      description uplink
      switchport mode trunk
      switchport trunk native vlan 2702
      switchport trunk allowed vlan 64,94,104,124
      spanning-tree port type network
      speed 10000
      vpc 10
    Any ideas on why we would be seeing these log messages?
    Thank you.

    You need to trace this mac address: - 00ab.cdef.0123 and check if this has dual nic card if yes then check if nic teaming is configured correctly ...then shut down one of the link and see if you are learning the same mac address on two different ports?
    HTH

  • VPC trouble - link flapping between C3750 stack and Nexus 5596

    Hi All,
    I have configured 1 vPC's between 2 Nexus 5596 and 1 stack C3750 switch. The links in the stack are distributed over both members.
    Gi1/1/1  -> Eth 1/44  NX 5596-02
    Gi 2/1/1 -> Eth 1/45  NX 5596-02
    Gi 1/1/2 -> Eth 1/46  NX 5596-01
    Gi 2/1/2 -> Eth 1/47  NX 5596-01
    The same logic is for another stack C3750 to the same pair of Nexus 5596 switches.
    The problem is that the links from the vPCs keep flapping at random moments - 1-2 times per hour.
    The network is not loaded at this time and the same issue is on both vPC's.
    the flaps in the nexus 5596 looks like this
    %ETH_PORT_CHANNEL-5-PORT_DOWN: port-channel108: Ethernet1/44 is down
    %ETH_PORT_CHANNEL-5-FOP_CHANGED: port-channel108: first operational port changed from Ethernet1/44 to Ethernet1/45
    %ETHPORT-5-IF_DOWN_INITIALIZING: Interface Ethernet1/44 is down (Initializing)
    %ETH_PORT_CHANNEL-5-PORT_UP: port-channel108: Ethernet1/44 is up
    %ETHPORT-5-IF_UP: Interface Ethernet1/44 is up in mode trunk
    On the stack is just up/down the pair interface.
    I started few debugs on the stack and captured the folowing output:
    C3750X-02#im_if_stack_relationship_add: Posting the ACP job for stack add for 5018.10902
    im_if_stack_relationship_add: Posted the ACP job for stack add successfully
    im_add_ifstackentry: higher_if_index = 5018 lower_if_index = 10902
    im_add_ifstackentry: Failed to delete nolayerelem from NoLowerLayerTree for higher_ifIndex = 5018
    im_add_ifstackentry: Failed to delete nolayerelem from NoHigherLayerTree for lower_ifIndex = 10902
    im_add_ifstackentry: Deleted nolayerelems from NoHigherLayerTree and NoLowerLayerTree
    im_add_ifstackentry: Failed to insert stackelem into StackTree
    Jul 12 03:35:26.122: %LINEPROTO-5-UPDOWN: Line protocol on Interface TenGigabitEthernet2/1/2, changed state to downim_if_stack_relationship_add: Posting the ACP job for stack add for 5018.10902
    im_if_stack_relationship_add: Posted the ACP job for stack add successfully
    im_add_ifstackentry: higher_if_index = 5018 lower_if_index = 10902
    im_add_ifstackentry: Failed to delete nolayerelem from NoLowerLayerTree for higher_ifIndex = 5018
    im_add_ifstackentry: Failed to delete nolayerelem from NoHigherLayerTree for lower_ifIndex = 10902
    im_add_ifstackentry: Deleted nolayerelems from NoHigherLayerTree and NoLowerLayerTree
    im_add_ifstackentry: Failed to insert stackelem into StackTree
    Jul 12 03:35:29.058: %LINEPROTO-5-UPDOWN: Line protocol on Interface TenGigabitEthernet2/1/2, changed state to up
    Do someone have any idea what happens here ?
    The configuration is ok because i have another vPC connected to FEX's and is working fine.
    Kind regards,

    Hello,
    Problem solved after  upgrade to the last version of NX OS  6.0.2.N2.3
    BR,

  • Problem reset Nexus 5596

    Hello,
    Some equipments Nexus 5596 from a customer have reinitiated and it seems to have been provoked by an OSPF problem although I am not sure.
    The logs from the equipment show:
    2013 Jan  9 07:29:42 ROISBPRE2CN %BTCM-5-BTCM_LOG_L3_READY: system becomes L3 Ready
    2013 Jan  9 07:29:44 ROISBPRE2CN %VSHD-5-VSHD_SYSLOG_CONFIG_I: Configured from vty by  on ppm.3726
    2013 Jan  9 07:29:45 ROISBPRE2CN %OSPF-5-ADJCHANGE:  ospf-1 [3236]  Nbr 180.101.250.26 on Vlan902 went TWOWAY
    2013 Jan  9 07:29:48 ROISBPRE2CN %OSPF-5-ADJCHANGE:  ospf-1 [3236]  Nbr 180.101.250.29 on Vlan902 went TWOWAY
    2013 Jan  9 07:29:49 ROISBPRE2CN %OSPF-5-ADJCHANGE:  ospf-1 [3236]  Nbr 180.101.250.28 on Vlan902 went TWOWAY
    2013 Jan  9 07:29:52 ROISBPRE2CN %OSPF-5-ADJCHANGE:  ospf-1 [3236]  Nbr 180.101.250.17 on Vlan902 went TWOWAY
    2013 Jan  9 07:29:52 ROISBPRE2CN %OSPF-5-ADJCHANGE:  ospf-1 [3236]  Nbr 180.101.250.29 on Vlan902 went FULL
    2013 Jan  9 07:29:52 ROISBPRE2CN %OSPF-5-ADJCHANGE:  ospf-1 [3236]  Nbr 180.101.250.26 on Vlan902 went FULL
    2013 Jan  9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_INITIALIZING: Interface port-channel902 is down (Initializing)
    2013 Jan  9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_INITIALIZING: Interface port-channel100 is down (Initializing)
    2013 Jan  9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_INITIALIZING: Interface Ethernet1/31 is down (Initializing)
    2013 Jan  9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_INITIALIZING: Interface Ethernet1/32 is down (Initializing)
    2013 Jan  9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_PORT_CHANNEL_MEMBERS_DOWN: Interface port-channel112 is down (No operational mem
    bers)
    2013 Jan  9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_PORT_CHANNEL_MEMBERS_DOWN: Interface port-channel111 is down (No operational mem
    bers)
    I wanted to know if you know something about a problem with OSPF in next version:
      cisco Nexus5596 Chassis ("O2 48X10GE/Modular Supervisor")
      Intel(R) Xeon(R) CPU         with 8263880 kB of memory.
       bootflash:    2007040 kB
    Kernel uptime is 0 day(s), 2 hour(s), 25 minute(s), 35 second(s)
    System version: 5.1(3)N1(1a)
    Thank you very much.

    OSPF logs say that your switch is fully adjacent with 180.101.250.26 and .29, this means normal operation.
    Bi-directional communication has been established between the Nexus and 180.101.250.17 and .28. They are in the middle of the OSPF neighboring process.
    Some interfaces are initializing, and Po111 and 112 have no member ports (the channel-group <111|112> command hasn't been issued on any physical interfaces).
    More information about OSPF neighbor states can be found here.

Maybe you are looking for

  • How do I transfer iTunes Library from external hard drive to another drive?

    I have filled by 160GB drive with my iTunes music library so I am purchasing a 400GB external drive. I want to transfer the entire library to the bigger drive. Can I simply drag via fire wire then entire libarary to the new drive and then "tell" by i

  • Error of method not found in C# class in VS 2013 on win7

    I am changing a C# code in a solution (it has many files and projets) from VS 2013 on win 7. I added some properties in class1. It was built well. But, it has run-time error: Method not found : class1.set_p1(system.string) The code logic is as follow

  • Access of the KM documents.

    Hello, Does anybody know, if there are any report available, with which you can analyse the access of the KM documents. They should answer questions like 1)   when was the last access to a documents? 2)   The name of the  document 3)   how often has

  • Oracle Real Application Testing

    I'm capturing a 10.2.0.5 RAC workload and attempting to replay it on a 11.2.0.3 RAC. All the Docs describe going from a standalone node to RAC and all the steps for doing so. However, I can't find anything outlining the process from RAC to RAC. Any h

  • Support for JDk1.3+ in J2ME

    Hi, Can somebody tell me if j2ME supports all classes written using JDk1.3 and JDK1.4? I mean if we write some java classes using Jdk1.3 will they run seamlessly on a PDA or mobile device that supports the latest version of J2ME? (By seamlessly i mea