Nexus 4000i in blade center H to 5548UP - no Flogi login
I have a fully integrated network in 2 separate data centers built solely on Nexus 5500UP switches that I just got finished designing and implementing. It connects FCoE to all hosts, FCoE from server access 5596UP to a pair of 5596 that act as "SAN" swtiches where I have native FC SFP that connect to XIV storage. In that environement all works great, multi-hop FCoE, NPIV, etc. All zoning and SAN administration is done fully on the N5K 5500 platform. (I even have MDS 9222i sole used for FCIP tunneling on the A and B fabric and that works like a champ too, DCNM sees both data centers as one large A and B fabric with the FCIP tunnels linking them)
The issue is when I introduced a pair of blade centers with N4K switches and a pair of 5548UP switches as their upstream FCF. The documentation isn't rocket science and yet I can't get a FLOGI login. The N7K sees the server MAC in the FIP snooping, it also sees the 5548 as it's FCF. But the 5548 vfc is stuck in "initializing". QoS is there, NXOS is upgraded, etc...I'm stumped and annoyed at this point. DCNM sees the 5548 as part of the fabric and it is a subordinated switch in the fcdomain and once I brought the switch up, all zoning, aliasing, etc was received on the switch...so I know the 5548 can see the fabric. Below are some configs (I cut out what isn't relevant)
5548UP:
Software
BIOS: version 3.5.0
loader: version N/A
kickstart: version 5.1(3)N1(1)
system: version 5.1(3)N1(1)
feature npiv
feature telnet
no feature http-server
feature tacacs+
cfs eth distribute
feature interface-vlan
feature lacp
feature vpc
feature lldp
class-map type qos class-fcoe
class-map type queuing class-fcoe
match qos-group 1
class-map type queuing class-all-flood
match qos-group 2
class-map type queuing class-ip-multicast
match qos-group 2
class-map type network-qos class-fcoe
match qos-group 1
class-map type network-qos class-all-flood
match qos-group 2
class-map type network-qos class-ip-multicast
match qos-group 2
system qos
service-policy type qos input fcoe-default-in-policy
service-policy type queuing input fcoe-default-in-policy
service-policy type queuing output fcoe-default-out-policy
service-policy type network-qos fcoe-default-nq-policy
interface port-channel10
description 20Gbps Trunk to CLT-BC1-4001-PD-01 port e1/15 and 16
switchport mode trunk
switchport trunk allowed vlan 310
spanning-tree port type network
interface vfc141
bind mac-address 00:c0:dd:20:50:41
switchport description CLT-BC1 Blade #1
no shutdown
vsan database
vsan 310 interface vfc55
vsan 310 interface vfc141
interface Ethernet1/7
description Trunk to CLT-BC1-4001-PD-01 port e1/15
switchport mode trunk
switchport trunk allowed vlan 310
channel-group 10 mode active
interface Ethernet1/8
description Trunk to CLT-BC1-4001-PD-01 port e1/16
switchport mode trunk
switchport trunk allowed vlan 310
channel-group 10 mode active
CLT-SAC-5548-PD-05# show int vfc 141
vfc141 is trunking
Bound MAC is 00:c0:dd:20:50:41
Port description is CLT-BC1 Blade #1
Hardware is Ethernet
Port WWN is 20:8c:54:7f:ee:5a:d2:bf
Admin port mode is F, trunk mode is on
snmp link state traps are enabled
Port mode is TF
Port vsan is 310
Trunk vsans (admin allowed and active) (310)
Trunk vsans (up) ()
Trunk vsans (isolated) ()
Trunk vsans (initializing) (310)
1 minute input rate 0 bits/sec, 0 bytes/sec, 0 frames/sec
1 minute output rate 0 bits/sec, 0 bytes/sec, 0 frames/sec
0 frames input, 0 bytes
0 discards, 0 errors
0 frames output, 0 bytes
0 discards, 0 errors
last clearing of "show interface" counters never
Interface last changed at Mon Mar 12 21:26:47 2012
CLT-SAC-5548-PD-05# show flogi database
No flogi sessions found.
CLT-SAC-5548-PD-05#show fcdomain
VSAN 310
The local switch is a Subordinated Switch.
Local switch run time information:
State: Stable
Local switch WWN: 21:36:54:7f:ee:5a:d2:81
Running fabric name: 21:36:54:7f:ee:1c:d0:81
Running priority: 128
Current domain ID: 0xec(236)
Local switch configuration information:
State: Enabled
FCID persistence: Enabled
Auto-reconfiguration: Disabled
Contiguous-allocation: Disabled
Configured fabric name: 20:01:00:05:30:00:28:df
Optimize Mode: Disabled
Configured priority: 128
Configured domain ID: 0x00(0) (preferred)
Principal switch run time information:
Running priority: 2
Interface Role RCF-reject
vfc55 Upstream Disabled
Nexus 4000i switch
Software
BIOS: version 1.0.37
loader: version N/A
kickstart: version 4.1(2)E1(1h)
system: version 4.1(2)E1(1h)
feature telnet
feature tacacs+
feature interface-vlan
feature lacp
feature fip-snooping
policy-map type queuing policy-fcoe-bandwidth
class type queuing 1p7q4t-out-q-default
bandwidth percent 50
class type queuing 1p7q4t-out-pq1
bandwidth percent 7
class type queuing 1p7q4t-out-q2
bandwidth percent 7
class type queuing 1p7q4t-out-q3
bandwidth percent 7
class type queuing 1p7q4t-out-q4
bandwidth percent 7
class type queuing 1p7q4t-out-q5
bandwidth percent 7
class type queuing 1p7q4t-out-q6
bandwidth percent 7
class type queuing 1p7q4t-out-q7
bandwidth percent 7
class-map type network-qos class-fcoe
match cos 3
class-map type network-qos class-non-fcoe
match cos 0-2,4-7
policy-map type network-qos policy-fcoe
class type network-qos class-fcoe
pause no-drop
mtu 2500
class type network-qos class-non-fcoe
system qos
service-policy type network-qos policy-fcoe
service-policy type queuing output policy-fcoe-bandwidth
vlan 310
fip-snooping enable
interface port-channel10
description 20Gbps Trunk to CLT-SAC-5548-PD-05 port e1/7 and 8
switchport mode trunk
switchport trunk allowed vlan 310
fip-snooping port-mode fcf
spanning-tree port type network
speed 10000
interface Ethernet1/1 <----the server is in slot 1
switchport mode trunk
spanning-tree port type edge trunk
speed auto
interface Ethernet1/15
description Trunk to CLT-SAC-5548-PD-05 port e1/7
switchport mode trunk
switchport trunk allowed vlan 310
speed 10000
channel-group 10 mode active
interface Ethernet1/16
description Trunk to CLT-SAC-5548-PD-05 port e1/8
switchport mode trunk
switchport trunk allowed vlan 310
speed 10000
channel-group 10 mode active
CLT-BC1-4001-PD-01# show fip-snooping fcf
Legend:
Interface VLAN Active FPMA/ FCMAP FCF-MAC Pri Switch WWN Fabric Name
Enodes SPMA
por10 310 0 FPMA 0x0efc00 54:7f:ee:5a 128 21:36:54:7f: 21:36:54:7f:
:d2:8a ee:5a:d2:81 ee:1c:d0:81
CLT-BC1-4001-PD-01# show fip-snooping vlan-discovery
Legend:
Interface VLAN FIP MAC
Eth1/1 1 00:c0:dd:20:50:41
Any suggestions because I'm stumped!! I'm also attaching a PDF copy of my Visio that shows port by port mapping and configuration for this blade chassis and port-channel 10.
Thanks for the help.
Chris
In the inital post where I put "
The N7K sees the server MAC in the FIP snooping, it also sees the 5548 as it's FCF. But the 5548 vfc is stuck in "initializing".
I meant to put N4K...not N7K...sorry about that.
Similar Messages
-
Connect 5548UP to Blade Center with Fabric Extenders
I had a quick question about connecting a 5548 to a blade chasis. Right now we have the Nexus connected and are presenting storage to the servers over the 10GB links using NFS and we're not seeing any issues. We're considering adding some FC storage to the Nexus and presenting it to the blade center. I have the fcoe feature enabled on the Nexus and believe it is ready for implementation. Most of the guides I see speak about using a MDS or refer to a pair of Nexus switches. Will what we have setup be fine (I can zone directly from the Nexus and present that storage to the blades)? I know ideally there would be a 2nd Nexus, but for now I'd like to make sure it can be done properly before looking into getting the storage. I can post the current config of the Nexus if it helps
Hi David,
Yes, you can do all in the Nexus 5548UP (Ethernet/NFS and FC zoning).
This document is for flexpod implementation but can help in the Nexus 5548UP configuration.
http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/Virtualization/flexpod_deploy.html -
Hyper-V fails to start, though NX bit is in proper state. IBM Blade Center.
Hi!
Please help, I'm in dead end.
I'm trying to start hyper-v in Blade. But launch fails. Here is an event log error:
System
Microsoft-Windows-Hyper-V-Hypervisor
2/6/2009 11:59:36 AM
Error code: 52
Error
User: SYSTEM
Computer: WIN-4DG9NOAK4J9
Description:
Hyper-V launch failed; No-execute (NX) or DEP not enabled on processor 0x0 (check BIOS settings).
Xml events:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-Hyper-V-Hypervisor" Guid="{52fc89f8-995e-434c-a91e-199986449890}" />
<EventID>52</EventID>
<Version>0</Version>
<Level>2</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2009-02-06T08:59:36.921Z" />
<EventRecordID>6140</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="8" />
<Channel>System</Channel>
<Computer>WIN-4DG9NOAK4J9</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData>
<Data Name="CPU">0x0</Data>
</EventData>
</Event>
I checked bios settings for blade, Dep is enabled. But hyper-v still fails.
Blade configuration (bought a month ago):
IBM Blade Center
Blade HS21:
2x Intel Xeon 5405.
6GB RAM
2x SAS 76GB.
I looked through other disscussions on the subject but nothing helped. Trick with changing Regional setting doesn't help either.
W2k8 std I bought in august 2008.
uchJust to clarify:
You have enabled virtualization on the chipset.
You have enabled DEP
You then powered off the server.
Then you added the Hyper-V role.
I mention the first steps, becuase the machine must be fully shut down (cold boot) after DEP is enabled for it to properly report. Just rebooting or exiting the BIOS and booting (warm boot) won't take the setting properly.
I have done this a couple times myself with new hardware.. Just getting in a rush.Brian Ehlert
(hopefully you have found this useful) -
Dataguard - does it make sense in a Blade center?
Hello,
I have a simple question:
Our deciders have chosen a dataguard installation on two virtual database servers in the same Blade Center. In my opinion, that doesn't make sense, but my opinion might be false. Both databases, the primary and the standby are be fully backed up every week and incremental every day.
Are there any reasons, which I currently might not see, that the dataguard installation is necessary?
Thank you for your help.
Rgds
Michael
Edited by: user451255 on 28.10.2010 03:49Hi,
First I see no reasin to backup the primary AND the standby as they share the same catalog and same backup it's totally not usefull.
In the same blade center looks like you can do it of course if it's for using the stnadby as read only for exemple.
For as kind of security data guard then I see not i big value to use this like that !
Greetings,
Loïc -
VN-Tag with Nexus 1000v and Blades
Hi folks,
A while ago there was a discussion on this forum regarding the use of Catalyst 3020/3120 blades switches in conjunction with VN-tag. Specifically, you can't do VN-Tag with that Catalyst blade switch sitting inbetween the Nexus 1000V and the Nexus 5000. I know there's a Blade switch for the IBM blade servers, but will there be a similar version for the HP C-class blades? My guess is NO, since Cisco just kicked HP to the curb. But if that's the case, what are my options? Pass-through switches? (ugh!)
Previous thread:
https://supportforums.cisco.com/message/469303#469303wondering the same...
-
We are working with a Nexus 5548UP connected to a EMC VNX5500 and four Dell R610 servers
We created VSAN 332 and VLAN 330
Here is the config.
class-map type qos class-fcoe
class-map type queuing class-fcoe
match qos-group 1
class-map type queuing class-all-flood
match qos-group 2
class-map type queuing class-ip-multicast
match qos-group 2
class-map type network-qos class-fcoe
match qos-group 1
class-map type network-qos class-all-flood
match qos-group 2
class-map type network-qos class-ip-multicast
match qos-group 2
system qos
service-policy type qos input fcoe-default-in-policy
service-policy type queuing input fcoe-default-in-policy
service-policy type queuing output fcoe-default-out-policy
service-policy type network-qos fcoe-default-nq-policy
slot 1
port 1-32 type ethernet
vlan 330
fcoe vsan 332
vsan database
vsan 332
fcdomain fcid database
vsan 332 wwn 50:06:01:69:3e:e4:00:d6 fcid 0x320000 dynamic
vsan 332 wwn 50:06:01:61:3e:e4:00:d6 fcid 0x320001 dynamic
vsan 332 wwn 21:00:00:c0:dd:1a:69:c7 fcid 0x320002 dynamic
vsan 332 wwn 21:00:00:c0:dd:1a:6a:4f fcid 0x320003 dynamic
vsan 332 wwn 21:00:00:c0:dd:1a:68:07 fcid 0x320004 dynamic
vsan 332 wwn 21:00:00:c0:dd:1a:67:db fcid 0x320005 dynamic
interface vfc17
bind interface Ethernet1/17
switchport trunk allowed vsan 332
switchport description HS-XEN-1
no shutdown
interface vfc18
bind interface Ethernet1/18
switchport trunk allowed vsan 332
switchport description HS-XEN-2
no shutdown
interface vfc19
bind interface Ethernet1/19
switchport trunk allowed vsan 332
switchport description HS-XEN-3
no shutdown
interface vfc20
bind interface Ethernet1/20
switchport trunk allowed vsan 332
switchport description HS-XEN-4
no shutdown
interface vfc31
bind interface Ethernet1/31
switchport trunk allowed vsan 332
no shutdown
interface vfc32
bind interface Ethernet1/32
switchport trunk allowed vsan 332
no shutdown
vsan database
vsan 332 interface vfc17
vsan 332 interface vfc18
vsan 332 interface vfc19
vsan 332 interface vfc20
vsan 332 interface vfc31
vsan 332 interface vfc32
interface Ethernet1/17
description HS-XEN-1
switchport mode trunk
switchport access vlan 330
switchport trunk allowed vlan 34,300,310,320,330
spanning-tree port type edge trunk
interface Ethernet1/18
description HS-XEN-2
switchport mode trunk
switchport access vlan 330
switchport trunk allowed vlan 34,300,310,320,330
spanning-tree port type edge trunk
interface Ethernet1/19
description HS-XEN-3
switchport mode trunk
switchport access vlan 330
switchport trunk allowed vlan 34,300,310,320,330
spanning-tree port type edge trunk
interface Ethernet1/20
description HS-XEN-4
switchport mode trunk
switchport access vlan 330
switchport trunk allowed vlan 34,300,310,320,330
spanning-tree port type edge trunk
interface Ethernet1/31
description VNX (B8) B1-P0
switchport mode trunk
switchport access vlan 330
switchport trunk allowed vlan 330
spanning-tree port type edge trunk
interface Ethernet1/32
description VNX (A8) A1-P0
switchport mode trunk
switchport access vlan 330
switchport trunk allowed vlan 330
spanning-tree port type edge trunk
When we change the VSAN and VLAN, the flogi information dissapears for the EMC VNX5500. The Flogi information is still present for the four Dell servers
changed VSAN and VLAN
vlan 102
fcoe vsan 1002
vlan 300,310,320,330
vpc domain 100
vsan database
vsan 1002
fcdomain fcid database
vsan 1002 wwn 21:00:00:c0:dd:1a:69:c7 fcid 0xae0000 dynamic
vsan 1002 wwn 21:00:00:c0:dd:1a:67:db fcid 0xae0001 dynamic
vsan 1002 wwn 21:00:00:c0:dd:1a:6a:4f fcid 0xae0002 dynamic
vsan 1002 wwn 21:00:00:c0:dd:1a:68:07 fcid 0xae0003 dynamic
interface vfc17
bind interface Ethernet1/17
switchport trunk allowed vsan 1002
switchport description HS-XEN-1
no shutdown
interface vfc18
bind interface Ethernet1/18
switchport trunk allowed vsan 1002
switchport description HS-XEN-2
no shutdown
interface vfc19
bind interface Ethernet1/19
switchport trunk allowed vsan 1002
switchport description HS-XEN-3
no shutdown
interface vfc20
bind interface Ethernet1/20
switchport trunk allowed vsan 1002
switchport description HS-XEN-4
no shutdown
interface vfc31
bind interface Ethernet1/31
switchport trunk allowed vsan 1002
no shutdown
interface vfc32
bind interface Ethernet1/32
switchport trunk allowed vsan 1002
no shutdown
vsan database
vsan 1002 interface vfc17
vsan 1002 interface vfc18
vsan 1002 interface vfc19
vsan 1002 interface vfc20
vsan 1002 interface vfc31
vsan 1002 interface vfc32
interface Ethernet1/17
description HS-XEN-1
switchport mode trunk
switchport access vlan 102
switchport trunk allowed vlan 34,300,310,320,330
spanning-tree port type edge trunk
interface Ethernet1/18
description HS-XEN-2
switchport mode trunk
switchport access vlan 102
switchport trunk allowed vlan 34,300,310,320,330
spanning-tree port type edge trunk
interface Ethernet1/19
description HS-XEN-3
switchport mode trunk
switchport access vlan 102
switchport trunk allowed vlan 34,300,310,320,330
spanning-tree port type edge trunk
interface Ethernet1/20
description HS-XEN-4
switchport mode trunk
switchport access vlan 102
switchport trunk allowed vlan 34,300,310,320,330
spanning-tree port type edge trunk
interface Ethernet1/31
description VNX (B8) B1-P0
switchport mode trunk
switchport access vlan 102
switchport trunk allowed vlan 102
spanning-tree port type edge trunk
interface Ethernet1/32
description VNX (A8) A1-P0
switchport mode trunk
switchport access vlan 102
switchport trunk allowed vlan 102
spanning-tree port type edge trunk
Is there a set procedure for changing VLAN and VSAN's ?
Thanks!We found the problem. The VNX uses VLAN tagging. The original install team set the wrong vlan. We changed the VNX vlan and the FLOGI's are now visible.
Regards
JG -
Screen off-center after waking. Happens to login and fullscreen apps.
When I wake my MBP up the screen is offcenter by a few inches resulting in this happenening. http://imgur.com/OGwWs
This happens to my fullscreen apps and my login screen but that is it. When I un-fullscreen and fullscreen again it goes back to normal.Hi,
Regarding current information, please check if the video card drivers are up to date. Install the latest video card drivers for Windows 7.
Tips for fixing common driver problems:
http://windows.microsoft.com/en-US/windows7/Tips-for-fixing-common-driver-problems
I would suggest you to run the Power troubleshooter to adjust your computer's power settings, and check if it works properly.
Here are the steps:
1. Open the Power troubleshooter by clicking the Start button , and then clicking Control Panel.
2. In the search box, type troubleshooter, and then click Troubleshooting.
3. Under System and Security, click Improve power usage.
If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
For more information, logon to:
http://windows.microsoft.com/en-US/windows7/Open-the-Power-troubleshooter
http://windows.microsoft.com/en-us/windows7/Sleep-and-hibernation-frequently-asked-questions
How to troubleshoot performance issues with standby, hibernate, and resume:
http://support.microsoft.com/kb/950686
Note: The article holds good for Windows 7 as well though it is for Vista.
Kate Li
TechNet Community Support -
Nexus 5548UP / FEX Connectivity doubt
Hello Everybody,
Some weeks ago, we decided to do a connectivity test with our nexus equipment. The topology was fairly simple, only one Nexus 5548UP, no vPC domain configured. 2 Nexus 2248TP Fabric Extenders connected to the 5548UP. Finally, a server, doing NIC teaming, ACTIVE-ACTIVE in a PortChannel config, one link to each Nexus 2248TP Fabric Extender. Topology attached below.
My understanding was that the FEXs were remote line cards, so what we are doing here is like adding 2 linecards to a moludar switch like a 6500 and creating a PortChannel using 1 link to 1 linecard, and 1 link to another linecard.
To my surprise, this was not allowed.
I tried to find and explanation why this could not be configured, but nothing found.
Anyone has an idea why this could be happening?
thanks in advance,
FernandoHello Everybody,
Some weeks ago, we decided to do a connectivity test with our nexus equipment. The topology was fairly simple, only one Nexus 5548UP, no vPC domain configured. 2 Nexus 2248TP Fabric Extenders connected to the 5548UP. Finally, a server, doing NIC teaming, ACTIVE-ACTIVE in a PortChannel config, one link to each Nexus 2248TP Fabric Extender. Topology attached below.
My understanding was that the FEXs were remote line cards, so what we are doing here is like adding 2 linecards to a moludar switch like a 6500 and creating a PortChannel using 1 link to 1 linecard, and 1 link to another linecard.
To my surprise, this was not allowed.
I tried to find and explanation why this could not be configured, but nothing found.
Anyone has an idea why this could be happening?
thanks in advance,
Fernando -
I have a question in regards to multicast support for the NEXUS 1000V/4001i/5548 w/L3 Daughter card. Before the questions a quick background: We are in the process of buying a IBM blade center with the aforementioned network pieces. We are a modeling and simulations site and the servers we use primarily communicate via multicast. Typically 6 class C’s worth of multicast addresses are reserved for this per event. I was looking at doing layer 3 on the 5548’s but it has a limitation of 2000 multicast entries and I’m not even sure what that means i.e per VLAN/VRF or just total. We have 4 suites - so if we run two events at the same time we will bust that number quick. So we will continue to do layer 3 at the 6509’s for mcast and the nexus family will handle it at layer 2.
My real questions and concerns are these:
The 4001i states it will hold 1000 IGMP (Snooping) entries. What happens when it exceeds this number? Should we just turn IGMP snooping off and let it flood everything in that VLAN (I have my concerns with that).
I cannot find any multicast limitations on the 1000v – are there any?
Any advice/help will be greatly appreciated.
Thanks
BradEx,
Yes, all three Nexus products are available for order as of today.
As for Fabric Path, it's currently only supported on the Nexus 7K, with the F1 Line cards running NXOS 5.1 or later. Fabric Path will be available on the 5548/5596 running 5.1(3)N1(1) codename "Fairhaven" release of NXOS. Currenlty targeting mid-late 2011.
FYI - Fabric Path will require a separate license.
Regards,
Robert -
Connecting dell vrtx switch module to nexus 7k
I have a dell vrtx chassis with built in switch. How do I configure the nexus 7k port to connect the switch module to it?
We can have a Nexus 7k VPC pair with CB3020 HP Blade Center switches attached through a VPC group.
Regards,
Naveen -
I'm looking at a couple options for a small network in a data center. I seem to be getting hung up on all the different options. One of the options I'm looking at is end or row using both 2960Ss and Blade Center chassis switches with each physical server dual homed into a 2960, each ESX server dual homed into a blade switch and each of the switches with a Layer 2 10Gb uplink (20 total with etherchannel) to one of two 4900Ms. The 4900Ms would then have a layer 2 uplink between them to accomodate VLANs that span the access layer switches. This would be an inverted U topology. That's simple enough, and maybe that is where I should leave it, but there is the now available stacking feature of 2960s that has me wondering if there is another option available with dual homing a stack. Is there such a beast? Would it be better to stack 2960s, or even 3750s, so as to make each end of row with 2 redundant switches appear as one logical stack, and then uplink that stack to an aggregate multilayer switch such as a pair of 4900Ms? Or might that limit me to keeping VLANs within a stack and end or row?
thank you,
BillHi Bill-
First, I personally would not use the 2960S for the data center, no matter the size. That switch was purposely built for user access and has some limitations. Also, depending on what you need to accomplish will determine your design. I recently did a design similar to what you are describing. We ended up putting 3750X's at the top of rack as a stack. This allows for etherchannel to your servers with both server NICs being active. From there we uplinked to a pair of 6509's in VSS. From a layer 2 point of view this was about as simple as it gets; 1 switch connected to another switch connected to a server. No spanning tree! If you can't afford stackable switches, you may want to look at routing at the top of rack. However you will lose functionality like moving VLAN's between racks, relying on server NIC software for active/passive links and the moving of VM's could be limited. -
Multicast mac-address Nexus 7k
Hi,
i'm going to use Nexus 7000 in Data Center.
During analysis configuration, I need define mac-address-static configuration for multicast mac address for Firewall Checkpoint cluster.
In "Layer 2 Switching Configuration Guide, Release 4.1.pdf" documentation speak about
"Configuring a Static MAC Address
[..]You cannot configure broadcast or multicast addresses as static MAC addresses[..]"
Have you a suggestion to manage this problem and why is it not possible configure mac address static multicast?
Regards
DinoJoseph - The ClusterXL A/A configuration is a variation of the StoneSoft or Rainfinity clustering technologies that have been used to cluster Solaris and other *NIX flavored servers and firewalls for years. (In fact, StoneSoft filed suit against Check Point in Europe 8 or 9 years ago for patent violations, and lost.) These configurations were very common on Check Point clusters running on Solaris from the late 90's forward - and, as you describe, have unicast IP's with a multicast MAC for the VIP. Even from the days of installing these on the brand new (at the time) 2900 series switches you had to do exactly as you state above - static MAC entries (or in some cases port mirrors) so traffic was directed to both active switch ports. In Active/Passive mode Check Point ClusterXL clusters are almost always "plug and play" today - rarely do the switches need anything beyond speed/duplex settings. The VIP assumes the MAC of the physical NIC it is currently bound to, and therefore there are no issues as far as switch config or proxy ARP entries on the gateways. All of these issues have to do with traffic flowing to the VIP and through the firewall, and the ability of the switch to correctly identify which physical switch port(s) the VIP is currently patched in to. This is one of three types of traffic associated with ClusterXL itself. The second is state synchronization, which is accomplished through a crossover cable and therefore not relevant. Even when using a switch state sync is a typical TCP 18181 connection from a unicast IP/unicast MAC on one gateway to the other through a dedicated interface pair.
The challenge described by CJ is not with the traffic flowing to the VIP, however. It is an entirely separate process - Check Point Clustering Protocol (aka CPHA if filtering in WireShark) is essentially the heart beat traffic. Every interface pair within a Check Point cluster continually communicates with its "partner" interface on the other cluster members. If any packet takes over 100ms or shows more than a 5% loss the gateway is forced in to "probing" mode where it falls back to ICMP to determine the state of the other cluster member. Depending on the CPHA timing settings an active gateway will failover to the passive in as quickly as 500ms or so. ClusterXL will fail over the entire gateway to the standby to avoid complications with asynchronous routing.
Out of the box, CCP is configured to use multicast, but it supports broadcast as well. To change this in real time (no restart required) simply issue the command:
cphaconf set_ccp {broadcast/multicast}
At the Ethernet level, CCP traffic will always have a source MAC of the Magic MAC of 00:00:00:00:xx:yy where XX is the “Cluster ID” – something identical on each cluster member but unique from one cluster to another, and YY is the cluster priority (00, 01, etc.) based on the priority levels set on cluster members within Dashboard on the cluster object. The destination MAC will always be the Ethernet broadcast of ff:ff:ff:ff:ff:ff.
At the IP level the source of CCP will always appear as 0.0.0.0. The destination will always be the network address (ie, x.x.x.0).
Similarly in multicast mode you will see the same traffic at the IP level but at the Ethernet level the destination will now be a IPv4 multicast MAC (ie, 01:00:5e:4e:c2:1e).
In a tcpdump with the –w flag opened in WireShark and a filter applied of just “cpha” (without the quotes) you should see a continual stream of traffic with the same source and destination IPs on all packets (0.0.0.0 and network IP), the destination of either a bcast or mcast MAC and the source MAC alternating between 00:00:00:00:xx:00 and 00:00:00:00:xx:01.
Long story short, the problem CJ is describing is a behavior on the 7K where a packet capture taken on the Check Point interface itself (ie, tcpdump –i eth0 –w capture.cap) ONLY shows CPHA traffic from it’s own source MAC and no packets from it’s partner. A tcpdump on the 7K itself will show traffic from both.
As CJ mentioned, a simple NxOS upgrade will fix the issue per:
This one:CSCtl67036 basically pryer to NX-OS 5.1(3) the nexus will discard packets that have a source of 0.0.0.0. Which in broadcast mode is exactly what the CCP heartbeat is. We bypassed this one.CSCsx47620 is the bug for the for static multicast MAC address feature but it requires 5.2 code on the 7k
(NOTE:Additional RAM may be required for the 5.2 update)
Also note that Check Point gateways do support IGMP multicast groups, given that you have the correct license. It is a feature of SecurePlatform Professional on the higher end gateways or as a relatively inexpensive upgrade on the lower end boxes or open platforms. For lab purposes you can simply type “pro enable” at the CLI (without the quotes). As of the latest build there is no technical limitation (no license check) so you can enable advanced routing features as needed for testing in a lab. For step by step details on configuring IGMP on SPLAT Pro go to the Check Point support site and search for sk32702.
This can be a frustrating issue to troubleshoot, so hopefully this helps someone avoid the headaches I ran in to. -
Span blade server on Cisco 3020?
I have an HP blade center with a Cisco 3020. From what I know, the baldes use a connection on the backplane for network connectivity. So my question is, can you setup a monitoring session to capture traffic from one individual blade server? I would normally span source interface destination interface. But how do I specify the blade server's interface when it's not on the switch itself? Thanks.
Hi Josh,
I'm not sure I really follow you here. The backplane of the blade server chassis is simply used as a communications channel between the blade server NICs and the server facing interfaces of the switch i.e., Gi0/1-16 and has no real bearing on how SPAN would work.
SPAN in the Catalyst 3020 switch works in exactly the same way as other Catalyst switches, with you specifying the source and destination interfaces etc., as you normally would. So assuming you have a server connected to Gi0/1 that you wanted to capture traffic to/from then you would configure something along the lines of monitor session 1 source interface gi0/1.
The tricky part can be the SPAN session destination and you have a number of options.
Use a server within the same chassis as the capture device.
If you have a server in the same chassis that has packet capture capability then you simply specify its NIC interface as the SPAN destination e.g., monitor session 1 destination interface gi0/2. The problem here is that when the destination interface goes into the monitoring state you'll lose in-band connectivity to the server so you would need to use the console to access the server.
Attach an external capture device to one of the switches external interfaces
The Catalyst 3020 has eight external facing interfaces i.e., Gi0/17-24 which are typically used for upstream network connectivity. If not all of these are in use then attach your capture device to one of those interfaces and configure the SPAN destination appropriately e.g., monitor session 1 destination interface Gi0/24.
Attach your capture device to an upstream switch and, on the Catalyst 3020, use an RSPAN VLAN as the destination to carry the traffic
This requires you define an RSPAN VLAN on the Catalyst 3020 and configure this as the SPAN destination. This VLAN is then configured on the external interfaces between your Catalyst 3020 and the upstream switch, where you would connect your capture device. In this case the upstream switch obviously requires a SPAN session to be configured as well.
There's discussion on the use of SPAN and RSPAN in the Integrating the Cisco Catalyst Blade Switch 3020 for the HP c-Class BladeSystem into the Cisco Data Center Network Architecture design guide that would go into more detail and has examples configurations.
Regards -
Dear Experts:
my sap system occured a lot of error and all user operation failed, so i have to restart it urgently, following are some messages in trace log file, please kindly help to investigate it, thanks!
OS: Windows Server 2003 SP1
DB: MSS 2005(9.0.3042)
SAP: ECC 5.0
Kernel: 6.40 unicode 221
in the dev_disp:
Wed Jan 14 09:07:28 2009
NiPWrite: ENOBUFS: buffers reduced to 4/4096 (errNo=10055; cnt=1; len=7208; hdl 28 / socket 824)
NiPWrite: ENOBUFS: buffers reduced to 4/1024 (errNo=10055; cnt=2; len=7208; hdl 28 / socket 824)
NiPWrite: ENOBUFS: buffers reduced to 0/4096 (errNo=10055; cnt=1; len=6184; hdl 28 / socket 824)
in the syslog:
09:11:51 DIA 003 300 GO01 ZFIR BY4 Database error 0 at FET access to table DDFTX
09:11:51 DIA 003 300 GO01 ZFIR BY0 > [10054] TCP Provider: An existing connection was f
09:11:51 DIA 003 300 GO01 ZFIR BY0 > closed by the remote host.#[10054] Communication l
09:11:51 DIA 003 300 GO01 ZFIR BY0 > failure#[-1] Session Provider: Physical connection
09:11:51 DIA 003 300 GO01 ZFIR BY0 > usable [xFFFFFFFF].#[-1] Communication link failur
09:11:51 DIA 003 300 GO01 ZFIR BY0 > Session Provider: Physical connection is not usabl
09:11:51 DIA 003 300 GO01 ZFIR BY0 > [xFFFFFFFF].#[-1] Communication link failure#[0] P
09:11:51 DIA 003 300 GO01 ZFIR BY0 > error in TDS stream
09:11:51 DIA 003 300 GO01 ZFIR D01 Transaction Canceled 00 951 ( 0 )
09:11:51 DIA 003 300 GO01 ZFIR BZY Unexpected return value 8 when calling up DbSlR
09:11:51 DIA 003 300 GO01 ZFIR BYJ Function ROLLBACK on connection R/3 failed
09:11:51 DIA 003 300 GO01 ZFIR R39 Error in DB rollback/SyFlush, return code 016384
09:11:51 DIA 003 300 GO01 ZFIR Q02 Stop Workproc 3, PID 23580
09:11:51 RD Q0I Operating system call recv failed (error no. 10054)
09:12:02 WRK 000 Q0Q Start Workproc 3, Pid 25920
In the dev_w3 dialog work process:
C Wed Jan 14 09:11:51 2009
C GetNextRows: line 20630. hr: 0x80004005 Protocol error in TDS stream
C sloledb.cpp [GetNextRows,line 20630]: Error/Message: (err 0, sev 0), Protocol error in TDS stream
C Procname: [##Y3LAX05SESr3p00000059800000000020094911]
C sloledb.cpp [GetNextRows,line 20630]: Error/Message: (err -1, sev 0), Communication link failure
C Procname: [##Y3LAX05SESr3p00000059800000000020094911]
C sloledb.cpp [GetNextRows,line 20630]: Error/Message: (err -1, sev 0), Session Provider: Physical connection is not usable [xFFFFFFFF].
C Procname: [##Y3LAX05SESr3p00000059800000000020094911]
C sloledb.cpp [GetNextRows,line 20630]: Error/Message: (err -1, sev 0), Communication link failure
C Procname: [##Y3LAX05SESr3p00000059800000000020094911]
C sloledb.cpp [GetNextRows,line 20630]: Error/Message: (err -1, sev 0), Session Provider: Physical connection is not usable [xFFFFFFFF].
C Procname: [##Y3LAX05SESr3p00000059800000000020094911]
C sloledb.cpp [GetNextRows,line 20630]: Error/Message: (err 10054, sev 0), Communication link failure
C Procname: [##Y3LAX05SESr3p00000059800000000020094911]
C sloledb.cpp [GetNextRows,line 20630]: Error/Message: (err 10054, sev 0), TCP Provider: An existing connection was forcibly closed by the remote host.
C Procname: [##Y3LAX05SESr3p00000059800000000020094911]
C DbSlExeRead - Error 99 (dbcode 10054) on get_next_row
C 1 times error (0,0) in sequence
B ***LOG BY4=> sql error 0 performing FET on table DDFTX [dbtran#10 @ 7292] [dbtran 7292 ]
B ***LOG BY0=> [10054] TCP Provider: An existing connection was forcibly closed by the remote host.
Kind Regards
Alex ChengLooking in SM21, I see the following:
A database operation returned a return code that indicates
that the work process is no longer connected to the database, or that
this connection was broken for a while.
This error can occur, for example, if the database was shut
down, but not the SAP System. Network problems can also cause the
connection between the application server and the database server to be
broken.
For initial information on the cause of the error, see the
database error text.
The work process with the return code has the status
Reconnect. It attempts to reconnect itself to the database status. If it
reconnects successfully, it can start sending database requests to the
database instance again. An appropriate message is written in the
syslog.
If the work process cannot reconnect itself, it remains in
Reconnect status and attempts to reconnect itself to the database instance until
it is successful.
After talking to my network guys, I get the following answer: problems reported this morning appear to be connected to an issue with one of the IBM Blade Center chassis. They have
found that resets have occurred on one of the I/O modules.
Good luck! -
I just created a new Apple ID for my son (under 13 so could not have an account until new), as part of the new family sharing option in iOS 8.0.2, and I want to transfer the Game Center account he was using to the new Apple ID. I see in Settings > Game Center it has the option to login into an Apple ID but not Game Center separately. How do I get the new Apple ID to use the old Game Center account he was using?
There is no way to merge or transfer anything to another AppleID. The App Store license also specifies that purchases cannot be transferred.
Maybe you are looking for
-
How to create a default value of timestamp column?
I am trying to create a table with a default value on a timestamp column, can it be done? CREATE TABLE myTbl FutureDateTime date default TIMESTAMP WITH TIME ZONE '2999-12-31 23:23:59.000' )
-
My camera Canon G3 (i know it's old) no longer connects to iPhoto (8.1.2) on my iMac, I have checked with my friends iMac same model iPhoto version and it works fine using my cable, I would appreciate any help getting this sorted
-
I recently had to buy a new computer and want to transfer my playlists to my new computer
I recently had to buy a new computer and want to move my playlists from my old one. The playlists include both purchased tracks and tracks uploaded from my cd collection. My old os is Windows XP and my new os is Windows 8 if that is of any relevanc
-
File Upload: no error but don't work. Why?
Hi all, i'm an application with a jsp for upload a file. I have the following code in my Action (extention of the DataForwardAction): // UploadForm extends org.apache.struts.action.ActionForm UploadForm uf = (UploadForm) ctx.getActionForm(); // ctx i
-
IPhoto not exporting photos properly
iPhoto 9.4.2. When I try to export photos with the 'export' feature, some come out wrong. Sometimes the photo is almost cut in half, with one half filtered and skewed. Other times the photo is cut with a grey background across it. Tried exporting to