Adding Nexus 5596 to ACS v4.2
Hi. Does ACS v4.2 support the addition of the Nexus switches? We have a few new Nexus devices that have been added to ACS, but cannot be accessed successfully. A msg re: role based authentication is received. Do I have to do something special in ACS to support this?
Nexus 5596 v5.1(3)N2(1)
Thanks!
Hi Keely
Please check the following lins about nexus configuration:
http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/troubleshooting/guide/n5K_ts_sec.html
http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/sec_aaa.html
ACS should use cisco-av-pair attribute for nexus devices.
HTH,
Alex
Similar Messages
-
What is the best way to migrate zoning from an MDS9216i to a Nexus 5596?
I am migrating from a MDS9216i to a Nexus 5596. We have dual paths, so I can migrate one leg at a time and the full function for these switches is fiber channel attached storage.
What is the best way to migrate the zoning information? I have been told I can ISL the new and old switch together and then push the zoning to the new switch. Is that better than just cutting and pasting the zoning information to the new switch?
Also, I have to move four Brocade M4424 switches to the new switches - they are currently attached via interop mode 1, but will now be attached using NPIV. Has anyone done this before, and did you have any issues?
Any help or advice would be appreciated. Thanks!Use an ethernet cable to connect the two computers, and set up file sharing. After that copying files from one computer to the other is exactly like copying from one hard drive to another:
http://docs.info.apple.com/article.html?artnum=106658 -
Hello Friends,
Just want to save your precious time & effort, while doing Nexus 5596 upgrades so wanted to share some useful info which you can have a look prior to your upgrades of Cisco Nexus 5596 device.
I recently ran into trouble when upgarding one of datacenter switch Nexus 5596 does not boots up and after investigation from Cisco TAC it comes out to be Bug documented below.
https://tools.cisco.com/bugsearch/bug/CSCun66310/?reffering_site=dumpcr
My Upgrade path of device was : 5.1(3)N1(1) to 6.0(2)N2(5).
Since this upgarde involves upgrade of Bios and Power sequensor, I was having some doubts to get this succesfully upgraded, But there was more twist involved in this upgrade which I came to know after contacting Cisco TAC for my died Nexus 5596 device and got info that if you have below impacted version in your Nexus 5596 device and you are planning to do Upgrade, then you migh RUN into this serious BUG aftre which device won't come up at all and only Option left is to replace with RMA device.
PID Impacted Hardware versions Updated Versions
UCS-FI-6296UP 1.0 1.1
N5K-C5596UP 1.0 1.1
N5K-C5596T 1.1 1.2
You can check hardware version using below command from your device.
5596# show sprom sup | inc H/W
H/W Version : 1.1
So please be carefull when planning your Nexus 5596 upgrade and verify above things as this Bug is not present anywhere in Upgrade docuemntations unfortunately.
Hope this will help and save someone's precious Time.Today "upgraded" our switch (N5k-C5596UP) to from 5.1(2)N1 to 7.0(5) and after reboot no life from the switch either. Even no console response. show sprom sup | inc H/W shows 1:0.
Only thing we could do is RMA the switch. So what must I do with these switches? Have still to do 3 of them. -
Maximum number of interfaces in Port Channel on Nexus 5596
Let me preface this by saying I am not a network expert....
I noticed that our customer had configured a port channel on their Nexus 5596 comprised of 16 interfaces. I thought the maximum number of interfaces in a port channel was 8 interfaces? I see in the Nexus 7000 documentation that if you configure 16 interfaces, the remaining 8 will be in "hot standby." Is this the same behavior on the Nexus 5000 series?
Thank you.Same behavior on the 5500 series and other Cisco switches like 3750, 3850 , etc..
HTH -
Nexus 5596 Ethernet Port Configuration
I have a Cisco Nexus 5596 with 48 Ethernet Ports (two of which are now configured for Fibre Channel). It has a FEX attached to it as well.
I was able to configure ANY Ethernet port with the typical interface commands when in interface configuration mode. However, I can now only configure existing and new Port Channel interfaces, FEX ports and standard Ethernet ports that have never been configured before.
If I try to configure an Ethernet interface that was configured in the past, I only seem to have access to global interface commands when in interface configuration mode. I can set spanning-tree, duplex, speed or any other interface parameters. The CLI acts like I'm not in interface config mode, but the prompt shows that I am.
Anyone else seen such a thing? I am logged in as admin.Hi Mark
I suspect the interface in question is configured to be in a channel. Once an ethernet interface is configured to be in a port-channel. most interface commands need to be configured under the port-channel interface
Thanks
-Prashanth -
Question about Nexus 5596 log.
Dear Mister
When I connect toward Nexus 5596, using ipv4 telnet, send the next message:
NITE3# 2013 May 9 18:32:53 NITE3 %LOCAL7-4-SYSTEM_MSG: service telnet, IPV6_ADDRFORM - dcos-xinetd[3193]
What is the reason for this?
Could be a bug?
Best RegardsHi,
If you want to view the changes made to any an order than open that order and click on EXTRAS--> CHANGE DOCUMENTS in the main menu.
Also if u want to see the changes made it the status u can refer the table CRM_JCDS.
Regards,
PePe -
Nexus 5596 Licensing - filename exceeds 30 characters
Hi,
I'm trying to licensing two Nexus 5596 (Evaluated License), when i'm enter the "install license bootflash:LICENSE.lic" the Nexus reflect this error:
"Installing license failed: Invalid filename size, filename exceeds 30 characters".
After i changed the name the Nexus reflect this error:
"Installing license failed: Invalid/Corrupt license file"
I tried to clear the license from one switch and now i'm cannot reinstall the license.
In the mail that cisco sent to me with the license they wrote that do not change the filename.
Thanks in advance,
Nadav Katz.Hi Eric,
I received the Nexus switches with corrupted license.
The license team of cisco was generate a new license and send it to me.
Regareds,
Nadav. -
Nexus 5596 switch-profile synchronization problem
hi
I can't synchronize switch-profile
System version: 5.1(3)N1(1)
Sync-status: Not yet merged
Merge Flags: pending_merge:0 rcv_merge:1 pending_validate:1
Status: Verify Failure
Error(s):
Following commands failed parsing: If the error is 'Command Parsing Failed', please check if some conditional feature(s) needs to be enabled
switchport mode trunk (Command Parsing Failed)
how to find the source of the problem ?Hello Pawel
Can you attach following from both Nexus 5596 switches in question
term length 0
show version
show run
show tech-support port-profile -
Nexus 5596 FC-Port Link-Events
Hi all,
int the last 3 weeks,
almost every day , we have a series of events in the connection between one Nexus 5596 and one of our servers. The connection is in FC (4G).
I need help to understand the output of the following command to troubleshoot what could be happening.
Sw-cpd-mm-n5k-2# show hardware internal fc-mac 3 port 14 link-event
MMDDYY HHMMSS usecs Event Current State
- - LINK_ACTIVE
100113 020845 773895 (0001) E_LINK_IDLE LINK_LRR_RX
100113 020845 765016 (0000) E_LINK_LRR LINK_LR_TX
100113 020845 763545 (61CB28) E_LINK_LINK_RESET LINK_ACTIVE
Sw-cpd-mm-n5k-2# show hardware internal fc-mac 3 port 14 port-event
MMDDYY HHMMSS usecs Event Current State
- - IPS_LINK_UP
100113 020845 775908 (0000) E_IPS_LINK_INIT_SUC IPS_LINK_UP
100113 020845 775907 (0000) E_IPS_IDLE IPS_LINK_UP
100113 020845 770040 (0001) E_IPS_LRR IPS_LINK_UP
100113 020845 763562 (61CB28) E_IPS_CREDIT_LOSS IPS_LINK_UP
Looking at the output I don't know who generates "E_LINK_LINK_RESET" , Nexus switch or server?
Thanks in advance!Hi,
I know it is a little bit late, but hope it can still be of use...
According to the log output, The switch detects a Credit Loss condition
00113 020845 763562 (61CB28) E_IPS_CREDIT_LOSS IPS_LINK_UP
and to recover from it, the switch resets the link by sending a LR to the server
100113 020845 763545 (61CB28) E_LINK_LINK_RESET LINK_ACTIVE
the server replies with a LRR, IDLE, etc.
100113 020845 765016 (0000) E_LINK_LRR LINK_LR_TX
Kind rgds,
Felipon -
Nexus 5596 and QOS config guide
Hi,
I need to implement qos on a nexus device for a client
Basically what I am trying to implement is this but on the nexus
Policy Map Enhanced_QoS_Customer_Out
Description: Enhanced QoS customers outbound Percentages
Class Cust_VoIP_Out
priority 30 (%)
Class Cust_Gold_Out
bandwidth 30 (%)
Class Cust_Silver_Out
bandwidth 13 (%)
Class Cust_Bronze_Out
bandwidth 2 (%)
Policy Map Ethernet_QoS_Customer_Out_200Mb
Class class-default
Average Rate Traffic Shaping
cir 200000000 (bps)
service-policy Enhanced_QoS_Customer_Out
Is this possible on the nexus 5596?
I havent found much information around shaping.. Please advise if the above policy is achelievable on the nexus and if not what does the nexus support?
regards,Hi,
I don't think the 5500 support shaping since it is mostly a layer-2 device. Here is the config guide for QOS.
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/CLIConfigurationGuide/QoS.html
HTH -
Trunking nexus 5596 and netapp or exsi issue
hi
i have 2 issues with trunking between nexus 5596 and a esxi server .....can not get the servers to ping out
and the netapp connected to the same 5596 cannot ping.
if the server is a access port it works fine.
is there any tricks that are required to be configured on the nexus to make this work.Make sure we are actually tagging for those vlans on the host (Netapp/ESXi). If we are not, then this would explain why it works in access mode on the switch.
-
We have a pair of Nexus 5596 switches, that each have a 1 gigabit conection to ISP CE switches (ME3400).
Switch 1 has a fibre connection using GLC-SX-MM with the following information...
sh int e1/48 trans
Ethernet1/48
transceiver is present
type is SFP-1000BASE-SX
name is CISCO-AVAGO
part number is SFBR-5766PZ-CS2
revision is
serial number is AGA1549L2BE
nominal bitrate is 1300 MBit/sec
cisco id is --
cisco extended id number is 4
I cannot get the port to come up on switch 2, transceiver info...
sh int e1/48 trans
Ethernet1/48
transceiver is present
type is SFP-1000BASE-SX
name is CISCO-AVAGO
part number is SFBR-5766PZ-CS2
revision is
serial number is AGA1549L2BE
nominal bitrate is 1300 MBit/sec
cisco id is --
cisco extended id number is 4
The port is up on the ISP switch, but down on the N5K...
Ethernet1/48 is down (Link not connected)
Hardware: 1000/10000 Ethernet, address: 547f.ee41.e337 (bia 547f.ee41.e337)
Description: Intech WAN ME3400-1 (BT)
MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec
reliability 255/255, txload 255/255, rxload 255/255
Encapsulation ARPA
Port mode is trunk
full-duplex, 1000 Mb/s, media type is 10G
Beacon is turned off
Input flow-control is off, output flow-control is off
Rate mode is dedicated
Switchport monitor is off
EtherType is 0x8100
Last link flapped 00:31:00
Last clearing of "show interface" counters 00:00:47
30 seconds input rate 0 bits/sec, 0 packets/sec
30 seconds output rate 0 bits/sec, 0 packets/sec
Load-Interval #2: 5 minute (300 seconds)
input rate 242.30 Gbps, 163.37 Mpps; output rate 63.30 Gbps, 231.54 Mpps
RX
17828772964 unicast packets 2506759 multicast packets 991 broadcast packets
17831280714 input packets 3305852407174 bytes
897530002 jumbo packets 0 storm suppression bytes
20 runts 0 giants 0 CRC 0 no buffer
20 input error 0 short frame 0 overrun 0 underrun 0 ignored
0 watchdog 0 bad etype drop 0 bad proto drop 0 if down drop
0 input with dribble 0 input discard Ethernet1/48 is down (Link not connected)
Hardware: 1000/10000 Ethernet, address: 547f.ee41.e337 (bia 547f.ee41.e337)
Description: Intech WAN ME3400-1 (BT)
MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec
reliability 255/255, txload 255/255, rxload 255/255
Encapsulation ARPA
Port mode is trunk
full-duplex, 1000 Mb/s, media type is 10G
Beacon is turned off
Input flow-control is off, output flow-control is off
Rate mode is dedicated
Switchport monitor is off
EtherType is 0x8100
Last link flapped 00:31:00
Last clearing of "show interface" counters 00:00:47
30 seconds input rate 0 bits/sec, 0 packets/sec
30 seconds output rate 0 bits/sec, 0 packets/sec
Load-Interval #2: 5 minute (300 seconds)
input rate 242.30 Gbps, 163.37 Mpps; output rate 63.30 Gbps, 231.54 Mpps
RX
17828772964 unicast packets 2506759 multicast packets 991 broadcast packets
17831280714 input packets 3305852407174 bytes
897530002 jumbo packets 0 storm suppression bytes
20 runts 0 giants 0 CRC 0 no buffer
20 input error 0 short frame 0 overrun 0 underrun 0 ignored
0 watchdog 0 bad etype drop 0 bad proto drop 0 if down drop
0 input with dribble 0 input discard
I have tested the SFP's in use on a pair of 2960's & they work fine!
If i replace the SFP's for copper, then they work fine also.
Does anyone know of any incompatibility issue with this SFP?
Thanks
ColinDid you try a different port such as e1/1? Sounds like a bug to me
http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9670/data_sheet_c78-618603.html
Table 2.
Cisco Nexus 5500 Platform Transceiver Support Matrix -
MAC flapping reported between 2 port channels on Nexus 5596
Hi all, I'm seeing messages like the following reported on a Nexus 5596:
2015 Jan 7 12:40:48.954 Switch-5596A %FWM-6-MAC_MOVE_NOTIFICATION: Host 00ab.cdef.0123 in vlan 104 is flapping between port Po5 and port Po10
Po5 is connected to a storage cluster and is configured as an access port. It is connected to 2 Nexus 5596 switches using vpc.
interface port-channel5
description Storage Shelf 1
priority-flow-control mode off
switchport access vlan 104
spanning-tree port type edge
spanning-tree bpduguard enable
speed 10000
flowcontrol receive on
vpc 5
Po10 is the uplink to the core switch:
interface port-channel10
description uplink
switchport mode trunk
switchport trunk native vlan 2702
switchport trunk allowed vlan 64,94,104,124
spanning-tree port type network
speed 10000
vpc 10
Any ideas on why we would be seeing these log messages?
Thank you.You need to trace this mac address: - 00ab.cdef.0123 and check if this has dual nic card if yes then check if nic teaming is configured correctly ...then shut down one of the link and see if you are learning the same mac address on two different ports?
HTH -
VPC trouble - link flapping between C3750 stack and Nexus 5596
Hi All,
I have configured 1 vPC's between 2 Nexus 5596 and 1 stack C3750 switch. The links in the stack are distributed over both members.
Gi1/1/1 -> Eth 1/44 NX 5596-02
Gi 2/1/1 -> Eth 1/45 NX 5596-02
Gi 1/1/2 -> Eth 1/46 NX 5596-01
Gi 2/1/2 -> Eth 1/47 NX 5596-01
The same logic is for another stack C3750 to the same pair of Nexus 5596 switches.
The problem is that the links from the vPCs keep flapping at random moments - 1-2 times per hour.
The network is not loaded at this time and the same issue is on both vPC's.
the flaps in the nexus 5596 looks like this
%ETH_PORT_CHANNEL-5-PORT_DOWN: port-channel108: Ethernet1/44 is down
%ETH_PORT_CHANNEL-5-FOP_CHANGED: port-channel108: first operational port changed from Ethernet1/44 to Ethernet1/45
%ETHPORT-5-IF_DOWN_INITIALIZING: Interface Ethernet1/44 is down (Initializing)
%ETH_PORT_CHANNEL-5-PORT_UP: port-channel108: Ethernet1/44 is up
%ETHPORT-5-IF_UP: Interface Ethernet1/44 is up in mode trunk
On the stack is just up/down the pair interface.
I started few debugs on the stack and captured the folowing output:
C3750X-02#im_if_stack_relationship_add: Posting the ACP job for stack add for 5018.10902
im_if_stack_relationship_add: Posted the ACP job for stack add successfully
im_add_ifstackentry: higher_if_index = 5018 lower_if_index = 10902
im_add_ifstackentry: Failed to delete nolayerelem from NoLowerLayerTree for higher_ifIndex = 5018
im_add_ifstackentry: Failed to delete nolayerelem from NoHigherLayerTree for lower_ifIndex = 10902
im_add_ifstackentry: Deleted nolayerelems from NoHigherLayerTree and NoLowerLayerTree
im_add_ifstackentry: Failed to insert stackelem into StackTree
Jul 12 03:35:26.122: %LINEPROTO-5-UPDOWN: Line protocol on Interface TenGigabitEthernet2/1/2, changed state to downim_if_stack_relationship_add: Posting the ACP job for stack add for 5018.10902
im_if_stack_relationship_add: Posted the ACP job for stack add successfully
im_add_ifstackentry: higher_if_index = 5018 lower_if_index = 10902
im_add_ifstackentry: Failed to delete nolayerelem from NoLowerLayerTree for higher_ifIndex = 5018
im_add_ifstackentry: Failed to delete nolayerelem from NoHigherLayerTree for lower_ifIndex = 10902
im_add_ifstackentry: Deleted nolayerelems from NoHigherLayerTree and NoLowerLayerTree
im_add_ifstackentry: Failed to insert stackelem into StackTree
Jul 12 03:35:29.058: %LINEPROTO-5-UPDOWN: Line protocol on Interface TenGigabitEthernet2/1/2, changed state to up
Do someone have any idea what happens here ?
The configuration is ok because i have another vPC connected to FEX's and is working fine.
Kind regards,Hello,
Problem solved after upgrade to the last version of NX OS 6.0.2.N2.3
BR, -
Hello,
Some equipments Nexus 5596 from a customer have reinitiated and it seems to have been provoked by an OSPF problem although I am not sure.
The logs from the equipment show:
2013 Jan 9 07:29:42 ROISBPRE2CN %BTCM-5-BTCM_LOG_L3_READY: system becomes L3 Ready
2013 Jan 9 07:29:44 ROISBPRE2CN %VSHD-5-VSHD_SYSLOG_CONFIG_I: Configured from vty by on ppm.3726
2013 Jan 9 07:29:45 ROISBPRE2CN %OSPF-5-ADJCHANGE: ospf-1 [3236] Nbr 180.101.250.26 on Vlan902 went TWOWAY
2013 Jan 9 07:29:48 ROISBPRE2CN %OSPF-5-ADJCHANGE: ospf-1 [3236] Nbr 180.101.250.29 on Vlan902 went TWOWAY
2013 Jan 9 07:29:49 ROISBPRE2CN %OSPF-5-ADJCHANGE: ospf-1 [3236] Nbr 180.101.250.28 on Vlan902 went TWOWAY
2013 Jan 9 07:29:52 ROISBPRE2CN %OSPF-5-ADJCHANGE: ospf-1 [3236] Nbr 180.101.250.17 on Vlan902 went TWOWAY
2013 Jan 9 07:29:52 ROISBPRE2CN %OSPF-5-ADJCHANGE: ospf-1 [3236] Nbr 180.101.250.29 on Vlan902 went FULL
2013 Jan 9 07:29:52 ROISBPRE2CN %OSPF-5-ADJCHANGE: ospf-1 [3236] Nbr 180.101.250.26 on Vlan902 went FULL
2013 Jan 9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_INITIALIZING: Interface port-channel902 is down (Initializing)
2013 Jan 9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_INITIALIZING: Interface port-channel100 is down (Initializing)
2013 Jan 9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_INITIALIZING: Interface Ethernet1/31 is down (Initializing)
2013 Jan 9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_INITIALIZING: Interface Ethernet1/32 is down (Initializing)
2013 Jan 9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_PORT_CHANNEL_MEMBERS_DOWN: Interface port-channel112 is down (No operational mem
bers)
2013 Jan 9 07:30:41 ROISBPRE2CN %ETHPORT-5-IF_DOWN_PORT_CHANNEL_MEMBERS_DOWN: Interface port-channel111 is down (No operational mem
bers)
I wanted to know if you know something about a problem with OSPF in next version:
cisco Nexus5596 Chassis ("O2 48X10GE/Modular Supervisor")
Intel(R) Xeon(R) CPU with 8263880 kB of memory.
bootflash: 2007040 kB
Kernel uptime is 0 day(s), 2 hour(s), 25 minute(s), 35 second(s)
System version: 5.1(3)N1(1a)
Thank you very much.OSPF logs say that your switch is fully adjacent with 180.101.250.26 and .29, this means normal operation.
Bi-directional communication has been established between the Nexus and 180.101.250.17 and .28. They are in the middle of the OSPF neighboring process.
Some interfaces are initializing, and Po111 and 112 have no member ports (the channel-group <111|112> command hasn't been issued on any physical interfaces).
More information about OSPF neighbor states can be found here.
Maybe you are looking for
-
How do I transfer iTunes Library from external hard drive to another drive?
I have filled by 160GB drive with my iTunes music library so I am purchasing a 400GB external drive. I want to transfer the entire library to the bigger drive. Can I simply drag via fire wire then entire libarary to the new drive and then "tell" by i
-
Error of method not found in C# class in VS 2013 on win7
I am changing a C# code in a solution (it has many files and projets) from VS 2013 on win 7. I added some properties in class1. It was built well. But, it has run-time error: Method not found : class1.set_p1(system.string) The code logic is as follow
-
Access of the KM documents.
Hello, Does anybody know, if there are any report available, with which you can analyse the access of the KM documents. They should answer questions like 1) when was the last access to a documents? 2) The name of the document 3) how often has
-
Oracle Real Application Testing
I'm capturing a 10.2.0.5 RAC workload and attempting to replay it on a 11.2.0.3 RAC. All the Docs describe going from a standalone node to RAC and all the steps for doing so. However, I can't find anything outlining the process from RAC to RAC. Any h
-
Support for JDk1.3+ in J2ME
Hi, Can somebody tell me if j2ME supports all classes written using JDk1.3 and JDK1.4? I mean if we write some java classes using Jdk1.3 will they run seamlessly on a PDA or mobile device that supports the latest version of J2ME? (By seamlessly i mea