LMS User Tracking for NEXUS 5548UP
Dear,
A while ago I received a ticket from one of our customers because User Tracking was not working for NEXUS 5548UP on LMS 3.2. I opened a TAC case for this but this was normal since it is a Datacenter switch. Now the customer came back on this because they really want to see which server is connected to which switch port. I understood from the TAC engineer this is not on the roadmap to integrate in LMS 4.x. They want to know if there exists another product (they thought about DCNM) and wanted to know how this integrates or works together with LMS...
Kind regards,
Sven Laureyssens
My latest understanding of User Tracking and Nexus 5K series is that it is not supported due to a limitation of the MIB support in the NX-OS.
The current DCNM (release 5.2) is distinct from the LMS and Cisco Prime umbrella but that wil be changing a bit moving forwad as DCNM is enhanced and rolled into the Cisco Prime family. Last I heard there should be some information coming out of Cisco Live this week and a new release will have some additional functionality and better integration. Still, I doubt we'll see UT for the 5K due to the NX-OS limitation.
One way to do what you're asking apart from use of any of the Cisco products is to enable LLDP on your Nexus and servers. That will at least give you the ability to pull the information from the NX-OS command line ("show lldp neighbor")
Similar Messages
-
LMS 4.2 User Tracking for Avaya IP Handsets and Connected Devices
I manage an environment that makes extensive use of Avaya IP phones and it's frustrating that this seems to limit the usefulness of the User Tracking application within LMS.
We configure the switch (2960) ports connected to the handsets as dot1q trunks with the associated PC being connected to the switch built into the phone.
Having done some forum research it seems that UT only adds an entry for a device connected on a trunk port if it is a Cisco IP phone, not anything else. This is frustrating as it eliminates a large part of our network from being recorded in UT and is doubley frustrating since the PC connected to the switch on the phone also isn't recorded.
Is there any way to get around this problem that anybody is aware of? ThanksAs long as you have a supported Cisco Layer 3 device in your LMS-management domain, you should be able to correlate the IP-MAC addresses in User Tracking (UT).
UT support is not specifically listed for the ASA firewall - I'm not sure it will support that feature if it is the users' gateway.
Useful links:
UT explanation from the LMS Admin Guide
Supported devices listing
Hope this helps. -
Cisco Prime - User Tracking for N5K
Hi,
We are using Cisco Prime LMS 4.2.4. It isn't getting any user tracking information from our Nexus 5K's. Should it be able to?Indeed.
As I noted and Arfroz confirmed, the User Tracking functionality requires the target device supports the SNMP-BRIDGE-MIB. If that is important to you, then an upgrade is in order.
It's not a big deal to upgrade - just schedule some downtime and knock it out. The actual upgrade process only takes about 15 minutes per Nexus 5k. I usually schedule 1-2 hours for a pair of them just to allow myself time for some testing (and backout if necessary). I've done about dozen or two 5k upgrades and never had a problem yet - it's a very straightforward process. -
Partial collection Failure for nexus 5548UP in PI 2.1
Hi there,
I get "Partial Collection Failure" in the inventory collection status in Prime Infrastructure for all my Nexus 5548UP (8 devices).
i have seen in the PI 2.1 release notes that a bug CSCum16230 which look like my problem has been resolved in PI 2.1 but i continue getting the "partail collection failure"
Would like to know if the bug is still exist or get any other help to solve this problem.
Regards,
Alon.hello
I have this problem as well...
we've got four N5K-C5548UP. Two with a layer 3 daughter card and two without.
interestingly we see the issue just on those boxes with the l3 daughter cards N55-D160L3-V2 installed...
Any help or ideas are highly appreciated
regards
roman
Sh inventory:
OK:
device-a# sh module
Mod Ports Module-Type Model Status
1 32 O2 32X10GE/Modular Universal Pla N5K-C5548UP-SUP active *
3 0 O2 Non L3 Daughter Card N55-DL2 ok
Mod Sw Hw World-Wide-Name(s) (WWN)
1 5.1(3)N2(1c) 1.0 --
3 5.1(3)N2(1c) 1.0 --
NOT OK:
device-b# sh modu
Mod Ports Module-Type Model Status
1 32 O2 32X10GE/Modular Universal Pla N5K-C5548UP-SUP active *
3 0 O2 Daughter Card with L3 ASIC N55-D160L3-V2 ok
Mod Sw Hw World-Wide-Name(s) (WWN)
1 5.1(3)N2(1c) 1.0 --
3 5.1(3)N2(1c) 1.0 -- -
Problem with user tracking in cisco prime Lms
i attach my senario pic ,
i use snmp v3 for my switch ,,
discover -- ok
synchronization ---- ok
net config and config edit ----- ok
but my problem is
report / inventory / user tracking / quick report ---------------------------------------- i take this notification for all report : no end hosts found
i install UTU but this program can not found any record too .
please help meNMS servers access the Bridge-MIB data from devices, to get the MAC/CAM table. Because MAC-address or CAM table is maintained on device/VLAN basis, so query needs to be made per VLAN based.
In snmp v1/v2c SNMP Community String Indexing is used. Where vlan is polled by adding VLAN number after community string after @ sign. Example to see all the mac-address table from VLAN 1, if the community is test123, device would be polled like :
snmpwalk -v2c -c test123@1 10.10.10.1
The syntax is [community string]@[instance number].
For snmp v3 this is not an option, as it cant use SNMP community string indexing. So all the MAC/CAM table needs to made snmp v3 context aware, which exposes BRIDGE-MIB data to SNMP v3.
You must use contexts to get per-VLAN data from the BRIDGE-MIB with SNMPv3.Not all the IOS switches support this. In general, if the device supports the "show snmp context" command, contexts will work. If not, an upgrade is needed. However, some switches (e.g. 2950 series) will never support SNMPv3 contexts. You must use v1/v2c with these switches.
Very simply, you need to add the context to the SNMP group to allow your users to poll the given context. For example, to allow users to poll the BRIDGE-MIB for context vlan-6, you would add something like:
snmp-server group v3group v3 auth context vlan-6 read
You should add all those exact name after context which you see in output of show snmp context.
Also, about UTU, it is just a small utility tool to access the LMS User Tracking DB externally to show the UT data, so unless LMS has UT data in its DB, UTU won't a difference either.
-Thanks
Vinod
**Encourage Contributors. RATE Them.** -
LMS3.2 User Tracking IP Phones Discovery Doesn't Work
I am having difficulty getting the User tracking for IP Phones to work correctly in Ciscoworks LMS 3.2.
Callmanager is version 7.1.5.10000-12. Campus manager version is 5.2.1
The Callmanager publisher and two subscribers are all showing as application servers with green icons under the topology services view.
The callmanagers show as CDP neighbours on the switches to which they are connected.
I can do an SNMP walk of the ccmPhoneTable from the Ciscoworks devicecenter and get a ton of returned data.
The IP phones are discovered as end hosts and have mac address and IP address info when checked in the User Tracking utility.
Callmanager sysObjectID = OID: CISCO-PRODUCTS-MIB::ciscoMCS7835I
Any help you could give with troubleshooting would be greatly appreciated.
Regards
RobThanks Nick,
I had seen that document and been through the processes
The mac and IP addresses of the ip phone are discovered.
The callmanagers are discovered and have green application server icons in the topolgy view
I can do an snmpwalk of the ccmPhoneTable OID and get returned data (as per this post by JClarke https://supportforums.cisco.com/message/664859#664859)
I can't do an snmpwalk of the ccmPhoneExtension as described in that document but I assume that since it applies to campus manager 3.2 and 3.3 that it is a bit dated and not relevant to later versions of callmanager.
I think that I have covered all the basic cdp/snmp and discovery issues. Any suggestions on where to go from here would be appreciated.
Regards
Rob -
Prime Infrastructure 2.0 and User Tracking
Hello
I'm having a look at getting wired User Tracking working on Prime 2.0. I checked that it is supported in the following link:
http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps6504/ps6528/ps12239/guide_c07-729089.html
I'm having a problem getting dynamic user tracking working for wired non-802.1x clients. The switches are configured for mac-notification traps and the config works fine for LMS.
Another LMS User Tracking feature I'd link to get working in Prime 2.0 is CUCM intergartion where Prime would pull IP Phone extensions/names etc from CUCM.
Are either of these User Tracking features supported in Prime 2.0 (or at least roadmapped) or should I stick with LMS 4?
Thanks
AndyI am gettng good non-802.1x wired user tracking info. see the screenshot below (click to expand).
I don't have a CM so I can't comment on that bit.
Row 1 in the screenshot, for example, is confirmed with the following CLI output:
User_Access#sh run int fa1/0/41
Building configuration...
Current configuration : 177 bytes
interface FastEthernet1/0/41
description user access
switchport access vlan 10
switchport mode access
snmp trap mac-notification change added
spanning-tree portfast
end
User_Access#sh mac address-table | i 1/0/41
10 000f.b58e.3732 DYNAMIC Fa1/0/41
User_Access#sh inv
NAME: "1", DESCR: "WS-C3750-48P"
PID: WS-C3750-48PS-S , VID: V10 , SN: FDO1425X2M9
User_Access#sh ver | i bin
System image file is "flash:/c3750-ipservicesk9-mz.122-55.SE5.bin"
User_Access# -
Financial Reports User Tracking
Hi Guys
Can any one tell me how to track the user login, report modification, creation and deletion kind of activities in FR--System 9.X??
Appreciate your inputs..
Thanks
JaganThanks for your response.
Can you explain how can we set up this user tracking for FR and WA reports. I think this usage tracking is only for IR reports.
Really appreciate if you can share your experiance on this...
Thanks
Jagan -
Campus User Tracking Quick report of wan location
Hi All,
I have one WAN location for which I am not getting campus user tracking for the end host.
I added all the WAN location switches in cisco works and getting logging report. But when
I tried to pull up end host report via IP ADDRESS or hostname it says end host not found.
Any help would be appriciated.
Thanks in advance.
SamirDo the end hosts show up by MAC? Can you search for end hosts based on the remote switch name or IP? In order for UT to display IP information, the ARP cache of the remote router needs to be populated and pollable via SNMP. That means the remote router needs to be managed by Campus Manager.
-
is it possible to change the airflow of the Nexus 5548UP in the field by replacing fan and power supply or must the correct airflow been ordered.
I just completed the change of airflow direction for Nexus 5548UP while the switch is still online and running. It is possible to swap fan and power modules without shutting down the switch. There are few catches that you need to pay attentions when you want to change the airflow directions:
To swap two fans and two power modules on Nexus 5548UP while it's running:
1) make sure you have the latest IOS or at least 6.0+, I have system: version 6.0(2)N2(1). Also, please don't forget to save running config just in case if the switch will be shutdown.
2) make sure you have all your new fans and power modules unpacked and ready to be installed
3) connect to the switch console port to monitor the logs and status
4) Pay attention to the switch console, it will give out warnings about fan failure (but switch will continue to run).
5) Important: The first new fan that you just replaced (with opposite airflow direction), the switch will detect the the incorrect airflow, and begin to give out warnings with countdown timer. You have only less than 60 seconds to complete the rest of swapping before the switch will shutdown. Not only you need to swap out each module quickly, but need to pay attention to each new module wait for it online before replacing the next module.
6) To start the process, insert in the first new fan with opposite airflow direction, take about few seconds and wait for spinning up [green light]. The switch console will display: "incorrect airflow detected, the switch will shutdown in 60 seconds.....". Just move onto next step...
7) replace the second fan, wait few seconds for new fan to spin up [green light].
8) replace the first power module
9) Important: make sure the first new power module is online [green light], then you can proceed and replace the second power module.
10) Completed! you may check "show inventory" to see if all new fans and power modules are online and shown. The switch was up and running the whole time.
Please give rating if it helps you! Thanks! -
Cisco Prime Infrastructure 2.1 - User Tracking
Hello All,
I am facing some issues with user tracking for wired clients. I have configured PI to track one particular mac address, such that every time that mac is identified in the network an alarm should be generated. I have configured mac notification also in the switch ports. I observed that when the device is connected the switch is sending the mac change notification to prime but alarm is not generated until I go to " Administration>Back ground tasks>wired client status" and manually execute the task. Our requirement is that the client should send some trap to prime and prime should poll the client on receiving the trap and update the client database, subsequently generate the alarm.
Thanks
Shabeeb KunhipockerProgrammatic access to PI's data is via the REST API.
Check the help menu on your PI server to see documentation regarding the supported tables and fields that can be queried via that method. -
User Tracking supported for Nexus 5K in Prime Infrastructure 1.3
Hi,
Is User Tracking supported for Nexus 5K in Prime Infrastructure 1.3?
Regards
Francois BouchardHi Andy,
Check the below link , as per this Doc .. User tracking is supported in 2.0:
http://www.cisco.com/en/US/prod/collateral/netmgtsw/ps6504/ps6528/ps12239/guide_c07-729089.html
Thanks-
Afroz
[Do rate the usefu post] -
Hello,
I have a problem with LMS 4.2 user tracking.
When I generate a report on all my network all mac address are ok but there is no Hostname/Ip address in the result, except for 2 equipments.
the only difference between these 2 equipements and the rest of the network is that they are connected on a not routed vlan. All the other phones, computers are connected on a routed vlan.
I have a Nexus 5k as core and 2960 as access. Routing between vlans is done with the Nexus
My DNS server is ok and reachable
Here is a screenshot of the report attached.
Thanks for your helpYes, the Nexus 5000 series has a few issues with LMS (and other things). Among them is the non-support of User Tracking. I'm told it's a MIB variable issue but it's been the case for some time now and remains so with the current LMS release.
Here is the reference from the Supported Devices Table which states in part:
The following features are not supported:
User Tracking (Nexus 1K, 4K, 5K and 7K with FEX), VLAN Management, VRF Lite, LANE Management
Configuration Deploy Protocols: HTTPS, SCP, SSH, RCP
Configuration Fetch Protocols: HTTPS, SCP, SSH, RCP
Software Distribution by: Advanced flow, Image, Remote Staging
Software Repository Synchronization
CiscoView - [1.3.6.1.4.1.9.12.3.1.3.840, 1.3.6.1.4.1.9.12.3.1.3.903, 1.3.6.1.4.1.9.12.3.1.3.907, 1.3.6.1.4.1.9.12.3.1.3.930] -
LMS 4.2 User Tracking (Ani Server) issue
Running LMS 4.2.
I have an issue where Data Collection, UT Acquisition, and VRF Collection go from normal display (on Device Status Portal Page) to "loading". At this point user tracking stops functioning. Eventually a number of processes are reported as down. When trying to view items such as Discrepancies and Best Practice Deviations the message "ANIDbEngine process may be down"
If all daemons are stopped and restarted everything runs fine again for a few days then the same thing happens again.
I have attached some log files related to ani. These were collected while the problem is evident, prior to processes being restarted
Any feedback would be appreciatedYes, the Nexus 5000 series has a few issues with LMS (and other things). Among them is the non-support of User Tracking. I'm told it's a MIB variable issue but it's been the case for some time now and remains so with the current LMS release.
Here is the reference from the Supported Devices Table which states in part:
The following features are not supported:
User Tracking (Nexus 1K, 4K, 5K and 7K with FEX), VLAN Management, VRF Lite, LANE Management
Configuration Deploy Protocols: HTTPS, SCP, SSH, RCP
Configuration Fetch Protocols: HTTPS, SCP, SSH, RCP
Software Distribution by: Advanced flow, Image, Remote Staging
Software Repository Synchronization
CiscoView - [1.3.6.1.4.1.9.12.3.1.3.840, 1.3.6.1.4.1.9.12.3.1.3.903, 1.3.6.1.4.1.9.12.3.1.3.907, 1.3.6.1.4.1.9.12.3.1.3.930] -
User tracking not finding any hosts in Ciscoworks LMS 3.1
L.S.
Our test-configuration is as follows:
Application versions:
Ciscoworks LMS 3.1
Ciscoworks Common Services 3.2.0
Campus Manager 5.1.4
We have 31 managed devices in Campus Manager (data has been collected on all),
Edit: All of them show up green in the topology window.
The device are: 2 6509 cores (running IOS s72033_rp-IPSERVICESK9_WAN-M version 12.2(18)SXF8), 1 ASA firewall (running ASA-OS version 8.0.5) and 29 switches (2960 and 3560 models both running ios version 12.2(52)SE). The switches are connected as follows:
User tracking jobs are running normally, but aren't finding any end-hosts or IP phones at all (I suspect around 250-500 hosts+ on these switches)
We are running SNMP v3 on the switches and have added the following configuration items to all the switches:
snmp-server group readonly v3 auth context vlan-1
<repeat for all present snmp-contexts as shown in show snmp context output>
snmp-server group readonly v3 auth context vlan-83
Debugging is enabled in CM->Admin->Debugging Options->User Tracking Server
This is the UT.log file of the last major acquisition:
messages will remian logged to file: D:\PROGRA~1\CSCOpx\log\ut.log
2010/01/13 14:00:01 main MESSAGE ProcessInitializer: Properties will be read from D:\PROGRA~1\CSCOpx\campus\etc\cwsi\ut.properties
I= 0value *.*.*.*
I= 1value 6
I= 2value 1
2010/01/13 14:00:01 main MESSAGE DBConnection: Created new Database connection [hashCode = 10969598]
PartialOrderNode tree dump: time base = VMPSMajor
<root>
VMPSMajor: <root>
VMPSMajor: VMPSMajor.GetXMLData
VMPSMajor: VMPSMajor.PingSweep
VMPSMajor: VMPSMajor.PopulateFromDCR
VMPSMajor: VMPSMajor.GetPortStatus
VMPSMajor: VMPSMajor.GetBridgeTable
VMPSMajor: VMPSMajor.Sweep
VMPSMajor: VMPSMajor.GetIpXlateTable
VMPSMajor: VMPSMajor.GetIpv6XlateTable
VMPSMajor: VMPSMajor.GenerateTable6
VMPSMajor: VMPSMajor.GenerateTable
SMFunction evaluation order: time base = VMPSMajor
VMPSMajor.GetXMLData Major
VMPSMajor.PingSweep Minor
VMPSMajor.PopulateFromDCR Major
VMPSMajor.GetPortStatus Minor
VMPSMajor.Sweep Major
VMPSMajor.GetBridgeTable Minor
VMPSMajor.GetIpXlateTable Minor
VMPSMajor.GetIpv6XlateTable Minor
VMPSMajor.GenerateTable6 Major
VMPSMajor.GenerateTable Major
Time base VMPSMajor has 5 major nodes and 3 minor traversals.
log4j:ERROR No appenders could be found for category (CTM.common).
log4j:ERROR Please initialize the log4j system properly.
In classlist loader
In classlist loader processing sub classes
updation done
In classlist loader completed
2010/01/13 14:00:03 main MESSAGE DBConnection: Created new Database connection [hashCode = 12524859]
Calling default
Subnet to SubnetData Map Size :73
2010/01/13 14:01:31 DBConnecton-Reaper MESSAGE DBConnection: Closed Database connection [hashCode = 12524859]
2010/01/13 14:01:31 DBConnecton-Reaper MESSAGE DBConnection: Closed Database connection [hashCode = 10969598]
2010/01/13 14:04:50 main MESSAGE DCRDevWrapper: Closing DCRProxy
I'm slowly getting to a dead end here. What am I missing?Well, our problem was resolved finally through a weird coincendence after having a websession with a Cisco TAC engineer (TAC case SR 613376661)
We changed the
snmp-server group readonly v3 auth context vlan-xxxx
commands in the switches to:
snmp-server group writeonly v3 auth context vlan-xxxx
that is: use the writestring in the snmp-server groups instead of the read string.
After we changed that, all of the User Tracking mysteriously started working.
As far as I know, the writestring should not be needed, but apparently it is....
Is there any explanation for this?
Maybe you are looking for
-
Error while tansporting the Data Source & Transformation
Dear Experts, I stuck in one problem. I just tried to transport one data source & its transformation fron BWD to BWQ. After importing the request, it throws an error (mentioned below): Start of the after-import method RS_RSDS_AFTER_IMPORT for object
-
Windows 8.1 Pro Issues Downloading
Can anyone help? I have downloaded the 8.1 Pro onto my colleagues windows 8 system (took 5 hours from the VLSC web site) yet there is no where to upload the licence key? We have searched the computer for the file to access but nothing seems to be the
-
Hi Experts, I have problem with Rebate process. I have created new table with sales org and customer group as fields and assigned this table with access sq and condition type ZB01. Matained the rebate agreement and condition records also. Inserted th
-
How to remove gnome without dependency errors?
I'm a little frustrated with pacman right now. I downloaded gnome, thinking I wanted it. I don't. So I went to remove the two things I installed with pacman: gnome and gnome-extra. But I can't, because the other packages that came with them depend on
-
Why have I got "logitec device detection" in my fierfox add ons ?
recnnty got an update for logitec device detection which I have never heard of. Ifound it in my firefox add ons. Question is ,what is it and what is it doing there? I have not to my knowlage downloade it. should it be there? firefox was newly install