Cat 6500 with DCNM 6.2(1)

Hi there,
for test purposes I installed Cisco Prime DCNM 6.2. It works great with out Nexus 5k and 7k, however I have trouble with our older Cat 6500 devices. While I know that support for these devices is limited I am surprised that the portchannels  could not be discovered performance wise and in regard to the topology map, even if they are connected to N7k's. Neither the normal portchannel ISLs between different 6500 nor the vPCs between 6500 and N7k appear in the topology, although the switches were successfully discovered and are considered "managable" via snmp and ssh.
Is there anything I need to do to make it work?
Best regards
Pille

Rafael,
I had the same issue.  You need to go into ACS and create a custom Shell Profile (Policy Elements > Authorization and Permissions > Device Administration > Shell Profiles), flip to the "Custom Attributes" tab, and add the following:
Attribute: cisco-av-pair
Requirement: Mandatory
Attribute Value: Static
Value: shell:roles="network-admin"
...although if you want a non-admin or DCNM "User" role, you would use the following instead:
Value: shell:roles="network-operator"
Save that.  Then make sure your Device Admin Authorization Policy (Access Policies > Access Services > Default Device Admin > Authorization) references that Shell Profile in the "Results" section.
I'm using DCNM version 6.2(5) and this works.
Here's a useful link for more info: http://www.cisco.com/en/US/products/ps9911/products_configuration_example09186a0080bf5512.shtml

Similar Messages

  • How to Configure Transparent caching on Cat 6500 with CSM in bridge mode?

    hi.
    I found How to Configure Transparent caching on Cat 6500 with CSM in routed mode.
    But,
    I need help How to Configure Transparent caching on Cat 6500 with CSM in bridge mode?
    Please let me know sample configuration.
    thanks.

    Hi,
    I wrote the document you mentioned and I also wrote the one below.
    http://www.cisco.com/en/US/partner/products/hw/modules/ps2706/products_configuration_example09186a00802c1201.shtml
    The one with the SSLM is a bridge mode config.
    If you replace the SSLM with a cache [or a farm of caches] it would be a similar config.
    Replace the SSL21 vserver with an HTTP vserver [most important is to keep the vlan configured on each vserver]
    Regards,
    Gilles.

  • How to Configure Transparent caching on Cat 6500 with CSM in routed mode

    I am trying to configure Transparent caching on Cat 6500 with CSM in routed mode, but facing some problems in it , also I have gone thru the example config on cisco site for transparent caching using CSM on Cat 6500 , but the above does not fit my clients requirement.
    The scenario is like
    Access Switches - Cat6500 with MSFC & CSM - Internet Router
    |
    Cache Engines and Real servers
    The clients as well as real servers are on seperate VLANs (L3) and the requirement is to load balance the internet traffic using cache engines.
    I'd really appreciate any helpful suggestions or any useful links/docs/info on this.
    Thanks
    kumar

    Hello Joerg,
    Thanks for the reply.
    I have already gone thru the sample config shown by this weblink, however this link refers to configuring transparent caching on the CSM in BRIDGED MODE ( i.e both the client and server vlans are having the same IP address ) but in our case , we have multiple L3 VLANS on the CAT6509 having IP addresses in different SUBNETS , and the Real servers to be used for caching also exist on one of these VLANS. Thus, the scenario described by the Weblink does not apply here. Also , in the configuration referred by the above weblink, the VLAN 100 is configured as client , however the endusers are shown to be on vlan200 which is configured as SERVER VLAN in the CSM.
    Dont you think there is something wrong here, I mean the endusers should be on VLAN 100 (Client) and real servers on VLAN 200 (SERVER).
    So, I have to configure CSM in routed mode ( i.e both the client and server vlans will have seperate IP addresses in different subnets ) and the endusers will be on all VLANS .
    Pls let me know , how I can implement this solution.
    Thanks again
    Sudhir

  • Who is anybody using a WISM with FWSM on a CAT 6500 Switch?

    Hi
    Who is anybody using a WISM with FWSM on CAT 6500 switch ?
    Are there any problem,if use?
    And How can I set them to connecting each other ?
    I have founded a document relate it on the cisco website that name is Integrating Cisco WiSM and Firewall Service Module.
    I have a question concern it.
    Why do I have make a VRF to communication each other ?
    Please let me know.

    As far as the FWSM is concerned you can have each of the wireless vlans come in to the same context of the FWSM and then just add those vlans to the FWSM as separate vlans.

  • Replacement for Cat 6500

    Hi all 
    Is there a replacement   for  Cat 6500
    Thanks 

    Hi ,
    You can use DFC4XL . XL means , it has more memory and store more TCAM table .
    What is the difference between DFC4 and DFC4XL?
    A. DFC4XL offers more scalability in terms of IPv4/IPv6 FIB entries, ACL entries, and NetFlow entries compared with DFC4 (see Table 3). Other than those hardware scalability differences, there are no feature differences between DFC4 and DFC4XL.
    Table 3. Feature Differences Between DFC4 and DFC4XL
    Feature
    DFC4
    DFC4XL
    IPv4 unicast/MPLS forwarding entries
    256K
    1024K
    IPv6 unicast/IPV4 multicast forwarding entries
    128K
    512K
    NetFlow entries
    512K
    1024K
    ACL and QoS TCAM size
    64K
    256K
    1K = 1024.
    http://www.cisco.com/c/en/us/products/collateral/switches/catalyst-6500-series-switches/qa_c67-362061.html
    HTH
    Regards,
    VS.Suresh.
    *Plz rate the usefull posts *

  • Migrate/Replace Cat 6500 Supervisor

    Any guides or tips on how to replace a Cat 6500 Sup 32 8G with Sup 720 10G? This is a single 6509 with 2 sup engines.
    thanks

    Because your supervisors are different you will need to remove both supervisors and replace them at the same time.  You won't be able to run a SUP32 and a SUP720 at the same time.

  • QoS Packets not matching on 6500 with SUP720-10GE and SU2T

    Hi,
    I do not see packets matching in policy. 
    output below:
    Switch#sh policy-map interface vlan 2232
     Vlan2232 
      Service-policy input: HARDPHONE-VVLAN
        Class-map: VOICETRAFFIC (match-all)
          0 packets, 0 bytes
          5 minute offered rate 0000 bps, drop rate 0000 bps
          Match: access-group name VOICETRAFFIC
        Class-map: VOICESIGNALING (match-all)
          0 packets, 0 bytes
          5 minute offered rate 0000 bps, drop rate 0000 bps
          Match: access-group name VOICESIGNALING
        Class-map: class-default (match-any)
          0 packets, 0 bytes
          5 minute offered rate 0000 bps, drop rate 0000 bps
          Match: any 
            0 packets, 0 bytes
            5 minute rate 0 bps
    I also not find packets matching ACL:
    switch#sh access-lists
    Extended IP access list VIDEOTRAFFIC
        10 permit udp any any range 16384 32767
    Extended IP access list VOICESIGNALING
        10 permit tcp any 10.128.0.0 0.3.255.255 range 2000 2002
        20 permit tcp any 10.128.0.0 0.3.255.255 eq 5060
        30 permit udp any 10.128.0.0 0.3.255.255 eq 5060
        40 permit tcp any 172.20.10.0 0.0.1.255 range 2000 2002
        50 permit tcp any 172.20.10.0 0.0.1.255 eq 5060
        60 permit udp any 172.20.10.0 0.0.1.255 eq 5060
    Extended IP access list VOICETRAFFIC
        10 permit udp 10.128.0.0 0.63.255.255 10.128.0.0 0.63.255.255 range 16384 32767
    I checked policies, they looks applied correctly.
    On SUP-720-10GE, I modified ACL to 'permit udp any any' but not found any matching packets. There are plenty of IP phones connected directly to this switch belongs to voice VLAN. I applied VLAN based QoS under voice VLAN and other VLANs too. 
    I observed different thing on SUP 2T. I saw packets matching ACL statement 'permit udp any any' but when I took off this line, ACL was not showing packets matching. 
    OUTPUT of IP phones connected to switch:
    switch#sh cdp neighbors | in SEP
    SEP0008308A5D7B  Gig 13/38         143             H P M  IP Phone  Port 1
    SEP0008308A5DE0  Gig 10/1          121             H P M  IP Phone  Port 1
    SEP0023049C6348  Gig 3/42          152             H P M  IP Phone  Port 1
    SEP0021A02D64D4  Gig 9/28          120             H P M  IP Phone  Port 1
    SEP1C6A7AE0588E  Gig 3/9           127             H P M  IP Phone  Port 1
    SEP00229059969E  Gig 12/48         166             H P M  IP Phone  Port 1
    SEP0008308AF26F  Gig 2/7           161             H P M  IP Phone  Port 1
    SEP00235EB7BE0E  Gig 4/2           154             H P M  IP Phone  Port 1
    SEP00229059BE5A  Gig 6/37          158             H P M  IP Phone  Port 1
    SEP1CAA07115CF3  Gig 12/29         148             H P M  IP Phone  Port 1
    SEP00235EB7884F  Gig 9/3           156             H P M  IP Phone  Port 1
    SEP0008308B03FB  Gig 2/30          178             H P M  IP Phone  Port 1
    SEP006440B42CD3  Gig 3/45          132             H P M  IP Phone  Port 1
    SEP0022905991C9  Gig 11/4          145             H P M  IP Phone  Port 1
    SEP0008308A5E6C  Gig 6/36          124             H P M  IP Phone  Port 1
    SEP006440B427CA  Gig 13/31         170             H P M  IP Phone  Port 1
    SEP006440B425FF  Gig 3/19          168             H P M  IP Phone  Port 1
    SEP0008308A7AD7  Gig 2/3           159             H P M  IP Phone  Port 1
    SEP0008308A3EB2  Gig 10/4          132             H P M  IP Phone  Port 1
    SEP002414B45A0E  Gig 10/28         170             H P M  IP Phone  Port 1
    SEP04C5A4B19C8B  Gig 2/15          162             H P M  IP Phone  Port 1
    SEP006440B43DE6  Gig 9/48          162             H P M  IP Phone  Port 1
    SEP006440B42B0D  Gig 9/23          179             H P M  IP Phone  Port 1
    Could anyone please help, how to make sure that packets are hitting correct ACL and policy on 6500 with SUP720-10GE and SUP2T.
    Thanks,
    Pruthvi

    Please note that 6500 is used as L2 switch only and SVI are used for applying policies only. 
    Configuration below:
    class-map match-all VOICESIGNALING
      match access-group name VOICESIGNALING
    class-map match-all VOICETRAFFIC
      match access-group name VOICETRAFFIC
    class-map match-all VIDEOTRAFFIC
      match access-group name VIDEOTRAFFIC
    policy-map HARDPHONE-VVLAN
      class VOICETRAFFIC
         police flow mask src-only 128000 8000 conform-action set-dscp-transmit ef exceed-action drop
      class VOICESIGNALING
         police flow mask src-only 32000 8000 conform-action set-dscp-transmit cs3 exceed-action policed-dscp-transmit
      class class-default
         police flow mask src-only 32000 8000 conform-action set-dscp-transmit default exceed-action policed-dscp-transmit
    policy-map STUDENT-DVLAN
      class class-default
         police flow mask src-only 25000000 1562500 conform-action set-dscp-transmit default exceed-action policed-dscp-transmit
    policy-map STAFF-DVLAN
      class VOICESIGNALING
         police flow mask src-only 32000 8000 conform-action set-dscp-transmit cs3 exceed-action policed-dscp-transmit
      class VOICETRAFFIC
         police flow mask src-only 128000 8000 conform-action set-dscp-transmit ef exceed-action drop
      class VIDEOTRAFFIC
         police flow mask src-only 2000000 150000 conform-action set-dscp-transmit ef exceed-action drop
      class class-default
         police flow mask src-only 50000000 1000000 conform-action set-dscp-transmit ef exceed-action drop
    ip access-list extended VOICESIGNALING
     remark Skinny and SIP protocols From Phones to Voice Core Infrastructure
     permit tcp any 10.128.0.0 0.3.255.255 range 2000 2002
     permit tcp any 10.128.0.0 0.3.255.255 eq 5060
     permit udp any 10.128.0.0 0.3.255.255 eq 5060
     permit tcp any 172.20.10.0 0.0.1.255 range 2000 2002
     permit tcp any 172.20.10.0 0.0.1.255 eq 5060
     permit udp any 172.20.10.0 0.0.1.255 eq 5060
    ip access-list extended VOICETRAFFIC
     permit udp any any dscp ef
     permit udp 10.128.0.0 0.63.255.255 10.128.0.0 0.63.255.255
     permit udp any any range 16384 32767 dscp ef
    ip access-list extended VOICESIGNALING
     remark Skinny and SIP protocols From Phones to Voice Core Infrastructure 
     permit tcp any 10.128.0.0 0.3.255.255 range 2000 2002
     permit tcp any 10.128.0.0 0.3.255.255 eq 5060
     permit udp any 10.128.0.0 0.3.255.255 eq 5060
     permit tcp any 172.20.10.0 0.0.1.255 range 2000 2002
     permit tcp any 172.20.10.0 0.0.1.255 eq 5060
     permit udp any 172.20.10.0 0.0.1.255 eq 5060
    ip access-list extended VIDEOTRAFFIC
     permit udp any any range 16384 32767 dscp ef
    interface Vlan104
     description PolicyOnlyInt
     no ip address
     service-policy input STAFF-DVLAN
    interface Vlan105
     description PolicyOnlyInt
     no ip address
     service-policy input STAFF-DVLAN
    interface Vlan573
     description PolicyOnlyInt
     no ip address
     service-policy input PUBLIC-DVLAN
    interface Vlan604
     description PolicyOnlyInt
     no ip address
     service-policy input PUBLIC-DVLAN
    interface Vlan654
     description PolicyOnlyInt
     no ip address
     service-policy input STUDENT-DVLAN
    interface Vlan674
     description PolicyOnlyInt
     no ip address
     service-policy input PUBLIC-DVLAN
    interface Vlan807
     ip address 172.18.128.5 255.255.255.0
    interface Vlan860
     description PolicyOnlyInt
     no ip address
     service-policy input PUBLIC-DVLAN
    interface Vlan2016
     description PolicyOnlyInt
     no ip address
     service-policy input HARDPHONE-VVLAN
    interface Vlan3124
     description PolicyOnlyInt
     no ip address
     shutdown
     service-policy input HARDPHONE-VVLAN
    switch#sh access-lists
    Extended IP access list VOICESIGNALING
        10 permit tcp any 10.128.0.0 0.3.255.255 range 2000 2002
        20 permit tcp any 10.128.0.0 0.3.255.255 eq 5060
        30 permit udp any 10.128.0.0 0.3.255.255 eq 5060
        40 permit tcp any 172.20.10.0 0.0.1.255 range 2000 2002
        50 permit tcp any 172.20.10.0 0.0.1.255 eq 5060
        60 permit udp any 172.20.10.0 0.0.1.255 eq 5060
    Extended IP access list VOICETRAFFIC
        10 permit udp any any dscp ef <----- not showing any match
        11 permit udp 10.128.0.0 0.63.255.255 10.128.0.0 0.63.255.255 <----not shwoing any match
        12 permit udp any any range 16384 32767 dscp ef<----not shwoing any match
    If I user "permit udp any any ", acl is showing match.
    switch#sh access-lists
    Extended IP access list VOICETRAFFIC
        10 permit udp any any dscp ef
        11 permit udp 10.128.0.0 0.63.255.255 10.128.0.0 0.63.255.255
        12 permit udp any any range 16384 32767 dscp ef
        13 permit udp any any (527055 matches)

  • Interfacing dolphin 6500 with Labview and windows 7

    Hi,
    someone has created and installed a application of labview in device dolphin 6500.
    I need to develop a aplication for capture data in honywell dolphin 6500  with labview but I have trouble to connect the device with my windows 7 for send the app.
    Any thoughts or assistance would be greatly appreciated.

    Hi,
    http://www.ni.com/white-paper/4577/en/
    Please refer this link. Also please send screenshots of any error messages if you get.

  • Hi, I have a Catalyst 6500 with X6K-SUP2-2ge, the IOS and bootlader image been wiped out, it starts in ROMmon SP mod end can't switch to RP to start download the IOS using Xmodem, though it shouldn't work in ROMmon SP omde but the xmodem is not gving the

    Hi, I have a Catalyst 6500 with X6K-SUP2-2ge, the IOS and bootlader image been wiped out, it starts in ROMmon SP modw and I can't switch to RP to start download the IOS using Xmodem, though Xmodem shouldn't work in ROMmon SP mode but the it's not gving the
    not executable message, the slot0: and disk0: are not accessable can't see the files inside, when I try the dir slot0: or dir disk0: it says it can't be opened and when I try to boot from them there's noting as well, what can I do to load an IOS image to the booflash: or slot0: ,each time I load the image using Xmodem at the end it gives me *** System received a Software forced crash ***
    signal=0x17, code=0x5, context=0x0
    When I run the command:
    rommom1> boot bootflash:
    boot: cannot determine first file name on deice "bootflash:"
    rommon2> boot slot0:
    boot: cannot open "slot0:"
    boot: cannot dtermine first file name on device "slot0:"
    BTW  System Bootstrap, version 7.1
    I''m looking to format the PCMCIA using a PC and format it to FAT16 and copy the boot image into it and then try to load from the PCMCIA afterward if it works I'll format it using the Supervisor engine 2.
    Any one have another new idea I can use, thanks in advance

    This is a potentially complex issue.
    Is this SUP configured to run as IOS native or CatOS Hybrid?
    While in ROMMON can you do the 'dev' command and see whad drives are recognized. Then 'dir' the drives that the SUP recognizes.
    Can you provide the screen captures as it boots?
    You would be bette served by hacing a TAC case.

  • 802.1q between CAT 6500 and Passport 8600

    Hi,
    I`m configuring 802.1q trunking between CAT 6500 and passport 8600, in CAT 6500 I configure the port as trunk dot1q mode ON. In Passport 8600 I configure the port as TAG port.
    I cretate the same vlans in both switch, but the interface vlans are create in CAT Switch. all hosts in Passport Switch that belongs to vlan 1 can ping his default gateaway (Interface Vlan) but hosts that belong to other vlan no.

    Please somebody helpme

  • 6500 with SLB blade dropped the packets from HA device.

    A weird behavior observed in 6500 with SLB blade. the topology is as below:
    client--HA---6500 with SLB----server farm
    The first Syn packet reached the 6500 with client MAC address as source MAC and can be forwarded to the server correctly. But due to HA vendor special behavior, the second Syn packet's source MAC is rewritten to HA device MAC address and this Syn is dropped by the 6500.
    Is this a special feature for 6500? And is it possible to change this behavior?
    Thanks in advance.

    Thanks for your reply.
    1, HA device is from other vendor. It works as transparent mode and the session will be processed by 2 blades in the round-robin schedule.
    The first SYN is processed by the master and reach the 6500 with client MAC as the source MAC. the second SYN is processed by the slave and the source MAC is rewritten to the slave's interface mac. This SYN packet is dropped by either 6500 or CSM, not quite sure.
    2, The image on the 6500 is as below:
    Cisco Internetwork Operating System Software
    IOS (tm) s72033_rp Software (s72033_rp-PK9SV-M), Version 12.2(17d)SXB10, RELEASE SOFTWARE (fc1)
    Technical Support: http://www.cisco.com/techsupport
    Copyright (c) 1986-2005 by cisco Systems, Inc.
    Compiled Thu 11-Aug-05 14:15 by kellythw
    Image text-base: 0x40020FBC, data-base: 0x41F20000
    cisco WS-C6503-E (R7000) processor (revision 1.1) with 458752K/65536K bytes of memory.
    Processor board ID FOX0930005J
    SR71000 CPU at 600Mhz, Implementation 0x504, Rev 1.2, 512KB L2 Cache
    3, which command should be used to "Capture a trace of the csm etherchannel"?
    It seems that only the SYN with rewritten source MAC is dropped. The SYN with client MAC works fine.
    Should you need any other information, pls let me know.
    Thanks & Regards

  • Jumbo Frame - Enabling on a VLAN of CAT 6500 running IOS

    Jumbo frames needs to be enabled on one of the vlan interface on Cisco 6500 IOS Switch.
    =================================================================
    •1) Once enabled the mtu 9216 on the required vlan interface do we need to reload the switch to take effect (I believe that in some low end swicthes it needs a reload)
    •2) If we enable only one Vlan interface, how about the other vlan interfaces(about 200 are on this switch)? Do we need to specify mtu1500 on other vlan interfaces?
    I have read information at the following two links, but I still wish to reconfirm by asking the questions in this forum. Someone who has already implemented this may have gained more experience while implementing it on CAT 6500 IOS Switch.
    https://supportforums.cisco.com/message/963341#963341
    http://www.cisco.com/en/US/products/hw/switches/ps700/products_configuration_example09186a008010edab.shtml
    http://www.cisco.com/en/US/products/hw/switches/ps700/products_configuration_example09186a008010edab.shtml#backinfo1
    Thanks.
    Alphonse

    You do not need to reboot your 6500 after you enable jumbo frames, but it is good idea to do it during an outage window. You only need to reboot smaller switches i.e. 3560, 3750, etc...after enabling jumbo frames. On these switches you can only enable it globally.  Only enable jumbo frames for the vlans you need.  You usually need jumbo frames for vlans connecting to the storage systems.
    Good Luck

  • Catalyst 6500 with CatOS ISCSI

    Hi, I'm configuring a Catalyst 6500 with for ISCSI.
    Following the recommendations I have to configure: portfast, jumbo frames, flow control and disable unicast storm control
    - Portfast: on the server and ISCSI SAN ports
        >
    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:"Tabla normal";
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-priority:99;
    mso-style-qformat:yes;
    mso-style-parent:"";
    mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
    mso-para-margin-top:0cm;
    mso-para-margin-right:0cm;
    mso-para-margin-bottom:10.0pt;
    mso-para-margin-left:0cm;
    line-height:115%;
    mso-pagination:widow-orphan;
    font-size:11.0pt;
    font-family:"Calibri","sans-serif";
    mso-ascii-font-family:Calibri;
    mso-ascii-theme-font:minor-latin;
    mso-fareast-font-family:"Times New Roman";
    mso-fareast-theme-font:minor-fareast;
    mso-hansi-font-family:Calibri;
    mso-hansi-theme-font:minor-latin;}
    set spantree portfast
    - Jumbo frames: Set port jumbo
    - Flow Control:
         > set port flow control receive desired
    Questions:
    1. Where I have to configure flow control? only on the SAN ports and NIC servers? or server ports too?
    2. Unicast Storm control: how can i configure this option?
    Thanks

    We are having the same exact problem. We've done what you've tried with no luck also. Strange thing is that in another building we have the same setup but only with a 6148V blade and that Tandberg has no issues. We're using a 6148AF with the one we're having problems with. We've tried with a 6348 blade and it works fine. I'm thinking it's something with the 6148AF firmware (ver. 8.2(2)).
    Were you able to solve your problem?

  • Multiple RSPAN Vlan on cat 6500

    Hi,
    Can we create multiple RSPAN Vlans on one switch and span across the same VTP domain ?
    I am using Cat 6500 switch.
    Is it possible to have multiple RSPAN sessions Simultaneously
    require valuable inputs for the same.

    Hi
    24 max RSPAN sessions

  • Cat 6500 SupEng MSFC II IOS SLB performance

    Hello,
    anyone know which are the current cat 6500 Supervisor Engine II MSFC II IOS SLB performance ? I need to know the max tcp/udp cuncurrent active session and the max tcp/udp setup rate.
    Thanks a lot.
    Best regards
    Fabio Bellini

    check out the following link for the performance details :
    http://www.cisco.com/en/US/products/hw/modules/ps2706/products_data_sheet09186a00800887f3.html

Maybe you are looking for