Nexus 5K and ERSPAN

So the documentation says that the 5k does not support RSPAN. So ERSPAN it is, but source only. So the question is, can you only use a device for the destination that supports ERSPAN? For instance I could not create a source session on my 5K's and shot that traffic to my destination host on 2960S.

Hi,
This is entirely possible provided the host has an IP address that can be used as the destination IP address in the ERSPAN configuration.
The following is the ERSPAN configuration on my Nexus 5548.
interface loopback0
  ip address 192.168.2.133/32
monitor session 1 type-erspan-source
  erspan-id 11
  vrf default
  destination ip 172.17.1.101
  source interface Ethernet1/31 both
  source interface Ethernet1/32 both
  no shut
monitor erspan origin ip-address 192.168.2.133 global
I have a Red Hat Linux server configured with an IP address 172.17.1.101 which is reachable from my Nexus switch:
ocs5548-1# ping 172.17.1.101
PING 172.17.1.101 (172.17.1.101): 56 data bytes
64 bytes from 172.17.1.101: icmp_seq=0 ttl=62 time=4.295 ms
64 bytes from 172.17.1.101: icmp_seq=1 ttl=62 time=0.868 ms
64 bytes from 172.17.1.101: icmp_seq=2 ttl=62 time=0.978 ms
64 bytes from 172.17.1.101: icmp_seq=3 ttl=62 time=7.211 ms
64 bytes from 172.17.1.101: icmp_seq=4 ttl=62 time=9.57 ms
--- 172.17.1.101 ping statistics ---
5 packets transmitted, 5 packets received, 0.00% packet loss
round-trip min/avg/max = 0.868/4.584/9.57 ms
And now when I run tcpdump on my Linux server I can see the GRE packets sourced from the ERSPAN session on the Nexus.
[sfuller@rhel5 ~]$ sudo tcpdump -i bond0 proto gre -c 10
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on bond0, link-type EN10MB (Ethernet), capture size 96 bytes
09:07:27.047805 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13102, length 50: gre-proto-0x88be
09:07:27.047891 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13103, length 50: gre-proto-0x88be
09:07:27.049757 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13104, length 122: gre-proto-0x88be
09:07:27.050813 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13105, length 127: gre-proto-0x88be
09:07:27.051899 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13106, length 50: gre-proto-0x88be
09:07:27.052054 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13107, length 50: gre-proto-0x88be
09:07:27.052211 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13108, length 50: gre-proto-0x88be
09:07:27.052645 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13109, length 50: gre-proto-0x88be
09:07:27.052852 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13110, length 50: gre-proto-0x88be
09:07:27.053009 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13111, length 50: gre-proto-0x88be
10 packets captured
10 packets received by filter
0 packets dropped by kernel
You'll obviously need a capture device that understand GRE, but that shouldn't be an issue.
The other thing to be mindful of with ERSPAN is the MTU size if you're trying to capture the entire packet. An ERSPAN packet comprises the encapsulated IPv4 header (20-bytes), GRE header (8-bytes), ERSPAN header (8-bytes) and the original packet and so a 1500-byte packet that is being captured would have to be truncated to make it through a network with a 1500-byte MTU. There's a section on Configuring Truncated ERSPAN in the Nexus System Management guide if you want to control the truncation.
Regards

Similar Messages

  • Diff b/w Nexus 5548P and 5548UP

    What is the
    Diff b/w Nexus 5548P and 5548UP
    regards.

    Hi,
    A UP or Unified ports allow you to configure ports as  Ethernet, native Fibre Channel or Fibre Channel over Ethernet (FCoE)  ports. By default, the ports are Ethernet ports but you can change the  port mode to Fibre Channel on the following unified ports:
    Any port on the Cisco Nexus 5548UP switch  or the Cisco Nexus 5596UP switch.
    The  ports on the Cisco N55-M16UP expansion module that is installed in a  Cisco Nexus 5548P switch.
    More details:
    http://www.cisco.com/web/techdoc/dc/reference/cli/nxos/commands/l2/port.html
    Comapre 5548 and 5548:
    http://www.cisco.com/en/US/products/ps9670/prod_models_comparison.html
    ./Abhinav

  • How to download MIB for NXOS or platform Nexus 7010 and Nexus 7004

    Hello,
    I need to monitor my Nexus 7004 and 7010 by my SNMP Agent, but I can't find the way to donload the required MIBs.
    For information I'm running the folling images:
    bootflash:///n7000-s2-dk9.6.2.6b.bin
    bootflash:///n7000-s1-dk9.6.1.5.bin
    By advance thanks for the support
    Gildas

    The module you are running requires a minimum software version of 5.1.
    You are currently running 5.0.3 which is why the module is not
    recognized.
    Below is a link that explains this:
    http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9402/data_s
    heet_c78-605482.html
    Product Specification
    Table 3 lists the specifications for the Cisco Nexus 7000 32-Port 10 Gigabit Ethernet
    Module with XL Option.
    Table 3. Product Specifications
    Item
    Specifications
    System
    Product compatibility
    Supported in all Cisco Nexus 7000 Series chassis
    Software compatibility
    Cisco NX-OS Software Release 5.1 or later (minimum requirement)
    You would need to upgrade you software.
    Hope this helps.
    Regards
    Muhammed M

  • ESXi 4.1 NIC Teaming's Load-Balancing Algorithm,Nexus 7000 and UCS

    Hi, Cisco Gurus:
    Please help me in answering the following questions (UCSM 1.4(xx), 2 UCS 6140XP, 2 Nexus 7000, M81KR in B200-M2, No Nexus 1000V, using VMware Distributed Switch:
    Q1. For me to configure vPC on a pair of Nexus 7000, do I have to connect Ethernet Uplink from each Cisco Fabric Interconnect to the 2 Nexus 7000 in a bow-tie fashion? If I connect, say 2 10G ports from Fabric Interconnect 1 to 1 Nexus 7000 and similar connection from FInterconnect 2 to the other Nexus 7000, in this case can I still configure vPC or is it a validated design? If it is, what is the pro and con versus having 2 connections from each FInterconnect to 2 separate Nexus 7000?
    Q2. If vPC is to be configured in Nexus 7000, is it COMPULSORY to configure Port Channel for the 2 Fabric Interconnects using UCSM? I believe it is not. But what is the pro and con of HAVING NO Port Channel within UCS versus HAVING Port Channel when vPC is concerned?
    Q3. if vPC is to be configured in Nexus 7000, I understand there is a limitation on confining to ONLY 1 vSphere NIC Teaming's Load-Balancing Algorithm i.e. Route Based on IP Hash. Is it correct?
    Again, what is the pro and con here with regard to application behaviours when Layer 2 or 3 is concerned? Or what is the BEST PRACTICES?
    I would really appreciate if someone can help me clear these lingering doubts of mine.
    God Bless.
    SiM

    Sim,
    Here are my thoughts without a 1000v in place,
    Q1. For me to configure vPC on a pair of Nexus 7000, do I have to connect Ethernet Uplink from each Cisco Fabric Interconnect to the 2 Nexus 7000 in a bow-tie fashion? If I connect, say 2 10G ports from Fabric Interconnect 1 to 1 Nexus 7000 and similar connection from FInterconnect 2 to the other Nexus 7000, in this case can I still configure vPC or is it a validated design? If it is, what is the pro and con versus having 2 connections from each FInterconnect to 2 separate Nexus 7000?   //Yes, for vPC to UCS the best practice is to bowtie uplink to (2) 7K or 5Ks.
    Q2. If vPC is to be configured in Nexus 7000, is it COMPULSORY to configure Port Channel for the 2 Fabric Interconnects using UCSM? I believe it is not. But what is the pro and con of HAVING NO Port Channel within UCS versus HAVING Port Channel when vPC is concerned? //The port channel will be configured on both the UCSM and the 7K. The pro of a port channel would be both bandwidth and redundancy. vPC would be prefered.
    Q3. if vPC is to be configured in Nexus 7000, I understand there is a limitation on confining to ONLY 1 vSphere NIC Teaming's Load-Balancing Algorithm i.e. Route Based on IP Hash. Is it correct? //Without the 1000v, I always tend to leave to dvSwitch load balence behavior at the default of "route by portID". 
    Again, what is the pro and con here with regard to application behaviours when Layer 2 or 3 is concerned? Or what is the BEST PRACTICES? UCS can perform L2 but Northbound should be performing L3.
    Cheers,
    David Jarzynka

  • VN-Tag with Nexus 1000v and Blades

    Hi folks,
    A while ago there was a discussion on this forum regarding the use of Catalyst 3020/3120 blades switches in conjunction with VN-tag.  Specifically, you can't do VN-Tag with that Catalyst blade switch sitting inbetween the Nexus 1000V and the Nexus 5000.  I know there's a Blade switch for the IBM blade servers, but will there be a similar version for the HP C-class blades?  My guess is NO, since Cisco just kicked HP to the curb.  But if that's the case, what are my options?  Pass-through switches?  (ugh!)
    Previous thread:
    https://supportforums.cisco.com/message/469303#469303

    wondering the same...

  • Interoperability issues between Nexus 5k and HP storageworks (8/20q)

    Hello community,
    I am trying to get a VM host and a windows server to connect to their storage across a nexus and HP (Qlogic) fabric switch. This is currently having issues with the VM host unable to see the datastores, possibly due to interoperability between Cisco and HP (Qlogic)
    I have configured and tested the connectivity using only the cisco nexus and this worked, I then tested it using only the HP fabric switch (HP 8/20q) and this also worked.
    However, when using the HP and Cisco Nexus as shown in the attached diagram, things stop working.
    The connection is using Native Fibre channel, On the Cisco side I performed the following steps
    Configured the Nexus with Domain ID 10 and the HP with Domain ID 20.
    Connected the 2 fabric switches on fc1/48 (Cisco) and port 0 (HP) and confirmed that the ISL came up (E_port 8G), I confirmed connectivity using fcping both ways.
    I connected the SAN to the Nexus and the servers to the HP
    Configured VSAN 10
    Added interfaces fc1/41 to 48 in VSAN 10
    Created 2 zones ( ESXI and Windows)
    Added the PWWN for the ESXI server and the MSA2040 to the ESXI zone
    Added the PWWN for the Windows 2k8 server and MS2040 to the Windows zones
    Created zoneset (Fabric-A) and added both the above zones in it
    Activated the FABRIC-A zoneset
    The result is that the zones and zoneset are synchronised to the HP switch .I confirmed that I was able to see the servers and SAN WWN in the correct zones on the HP.
    From the 8/20q switch I am able to fcping the SAN, Nexus and servers, however the Nexus is only able to fcping the SAN and the HP, it returns a “no response from destination”  when pinging the servers.
    I have added the FCID for all the units in the same zones to see if it makes any difference to no avail the result seem to be the same. I have gone through various Nexus/MDS/HP/Qlogic user guides and forums; unfortunately I have not come across any that shows this specific topology.
    source for HP user guide is here: http://h20565.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c02256394
    I’m attaching the nexus config and partial view of the “show interface brief” showing the fibre channel port status
    Interface  Vsan   Admin  Admin   Status          SFP    Oper  Oper   Port
                      Mode   Trunk                          Mode  Speed  Channel
                             Mode                                 (Gbps)
    fc1/47     10     auto   on      up               swl    F       8    --
    fc1/48     10     auto   on      up               swl    E       8    --
    Any help and advice would be greatly appreciated. thanks in advance

    Hi all, after much reading, Walter Dey provided the hint to put me on the right track. 
    By default the Nexus 5k is in interop mode 1. However, one of the requirement for this to be "interoperable" with other vendor the FCDomain ID in the entire fabric needs to be between 97 and 127 as stated in the Cisco website.
    http://www.cisco.com/en/US/docs/storage/san_switches/mds9000/interoperability/guide/ICG_test.html
    Another issue that had me and my colleague scratching our heads, was that we were seeing high level of CRC errors on the ISL interfaces. This was caused by ARBFF settings mismatch between the Nexus and the HP. This was resolved by ensuring that the ARBFF setting on the HP was set to false and the command "switchport fill-pattern ARBFF speed 8000" is configured on the ISL interface linking the 2 switches. (note that Cisco's default setting for the ports is IDLE, until this is changed the link will not stabilise)
    Thanks for all your help guys.

  • Fabric with two Nexus-5548 and a brocade switch does not get fabric updates

    We have a fabric containing two Nexus 5548 and a Brocade 5000 switch in interop mode 2. When i make changes to the zoning, the first nexus (the fabric principal) and the brocade switch see the zone changes. The second Nexus switch does not see it. There are no error messages but  the change just can't be seen.  What can i do to find out, what goes wrong ?

    Ouch, deprecated is not the word i wanted to read
    We are using 5.1(3)N1(1a) on nexus-rz1-a
    and 6.0(2)N1(2) on nexus-rz2-a.
    The fabric can be seen :
    nexus-rz2-a# show fcs ie vsan 10
    IE List for VSAN: 10
    IE-WWN                   IE     Mgmt-Id  Mgmt-Addr (Switch-name)
    10:00:00:05:1e:90:57:27  S(Rem) 0xfffc01 10.88.133.110 (bc-san1)
    20:0a:00:2a:6a:72:ba:01  S(Loc) 0xfffc1c 10.88.133.105 (nexus-rz2-a)
    20:0a:54:7f:ee:7f:dc:01  S(Adj) 0xfffc0b 10.88.133.100 (nexus-rz1-a)
    [Total 3 IEs in Fabric]
    nexus-rz1-a# show fcs ie vsan 10
    IE List for VSAN: 10
    IE-WWN                   IE     Mgmt-Id  Mgmt-Addr (Switch-name)
    10:00:00:05:1e:90:57:27  S(Adj) 0xfffc01 10.88.133.110 (bc-san1)
    20:0a:00:2a:6a:72:ba:01  S(Adj) 0xfffc1c 10.88.133.105 (nexus-rz2-a)
    20:0a:54:7f:ee:7f:dc:01  S(Loc) 0xfffc0b 10.88.133.100 (nexus-rz1-a)
    [Total 3 IEs in Fabric]
    I try to distribute the zoneset this way:
    zoneset distribute vsan 10
    Zoneset distribution initiated. check zone status
    nexus-rz1-a# show zone status
    VSAN: 10 default-zone: deny distribute: full Interop: 2
        mode: basic merge-control: allow
        session: none
        hard-zoning: enabled broadcast: disabled
    Default zone:
        qos: none broadcast: disabled ronly: unsupported
    Full Zoning Database :
        DB size: 6291 bytes
        Zonesets:1  Zones:62 Aliases: 44
    Active Zoning Database :
        DB size: 10243 bytes
        Name: FABRIC1  Zonesets:1  Zones:60
    Status: Zoneset distribution completed at 08:06:00 UTC Dec  3 2013
    nexus-rz2-a# show zone status
    VSAN: 1 default-zone: deny distribute: active only Interop: default
        mode: basic merge-control: allow
        session: none
        hard-zoning: enabled broadcast: disabled
    Default zone:
        qos: none broadcast: disabled ronly: unsupported
    Full Zoning Database :
        DB size: 4 bytes
        Zonesets:0  Zones:0 Aliases: 0
    Active Zoning Database :
        Database Not Available
    Status:
    VSAN: 10 default-zone: deny distribute: full Interop: 2
        mode: basic merge-control: allow
        session: none
        hard-zoning: enabled broadcast: disabled
    Default zone:
        qos: none broadcast: disabled ronly: unsupported
    Full Zoning Database :
        DB size: 6291 bytes
        Zonesets:1  Zones:62 Aliases: 44
    Active Zoning Database :
        DB size: 10243 bytes
        Name: FABRIC1  Zonesets:1  Zones:60
    Status: Activation completed at 13:03:42 UTC Dec  2 2013

  • SAN Port-Channel between Nexus 5000 and Brocade 5100

    I have a Nexus 5000 running in NPV mode connected to a Brocade 5100 FC switch using two FC ports on a native FC module in the Nexus 5000. I would like to configure these two physical links as one logical link using a SAN Port-Channel/ISL-Trunk. An ISL trunking license is already installed on the Brocade 5100. The Nexus 5000 is running NX-OS 4.2(1), the Brocade 5100 Fabric OS 6.20. Does anybody know if this is a supported configuration? If so, how can this be configured on the Nexus 5000 and the Brocade 5100? Thank you in advance for any comments.
    Best regards,
    Florian

    I tried that and I could see the status light on the ports come on but it still showed not connected.
    I configured another switch (a 3560) with the same config and the same layout with the fiber and I got the connection up on it. I just cant seem to get it on the 4506, would it be something with the supervisor? Could it be wanting to use the 10gb port instead of the 1gb ports?

  • Trunking nexus 5596 and netapp or exsi issue

    hi
    i have 2 issues with trunking between nexus 5596 and a esxi server .....can not get the servers to ping out
    and the netapp connected to the same 5596 cannot ping.
    if the server is a access port it works fine.
    is there any tricks that are required to be configured on the nexus to make this work.

    Make sure we are actually tagging for those vlans on the host (Netapp/ESXi). If we are not, then this would explain why it works in access mode on the switch.

  • Is there a twonky beam add on avaible for firefox beta running on a nexus 7 and where do i get it?

    I have looked through the add ons and their only download for windows, Mac or Linux none of which I can install on Firefox beta running on google nexus 7 and links to download and install the correct add on or one similar to twonky beam would be helpful thanks

    Twonky beam is not yet available for Mobile version.
    Note : Addons are not developed by Mozilla.

  • Nexus 5548P and GLC-T

    Hi,all.
    I have Nexus 5548P and 20 pc GLC-T  .  Temperature range in nexus about 60"C   ,  after reload nexus all or not all sfp in shut down  . I have to CLI no shut for to work sfp .  Does it from high temperature range ? I tried another party sfp , but result same.
    Best Regards/

    Hi Alexander
    What is the state of interfaces after reload (notconnected, sfp not inserted etc...)?
    Do you see any error/warning messages in the logs?
    What temerature do you have on the device in our lab?
    What SFP do you have - full PN
    -Alex

  • Cisco Nexus 5548UP and FI6248UP compatibility with FC SFP

    Cisco Nexus 5548UP and FI 6248UP comes with Unified Ports. What are the SFP types this port can take? 1Gig, 10Gig and 2/4/8FC. Could you please clarify?  
    Thanks,
    Cheriyan

    Hi Cheriyan,
    Here is te URL to the 6200 series FI data sheet:
    http://www.cisco.com/en/US/prod/collateral/ps10265/ps11544/data_sheet_c78-675245.pdf
    Check for the table to supported SFPs.
    Same for the 5500 switches
    http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9670/data_sheet_c78-618603.html.
    Hope this helps!
    ./Abhinav

  • Nexus 5548 and Define static route to forward traffic to Catalyst 4500

    Dear Experts,
    Need your technical assistance for the Static routing in between Nexus 5548 and Catalyst 4500.
    Further I connected both Nexus 5548 with Catalyst 4500 as individual trunk ports because there is HSRP on Catalyst 4500. So I just took 1 port from each nexus 5548, make it trunk with the Core Switch (Also make trunk from each Switch each port). Change the speed on Nexus to 1000 because other side on Catalyst 4500 line card is 1G RJ45.
    *Here is the Config on Nexus 5548 to make port a Trunk:*
    N5548-A/ N5548-B
    Interface Ethernet1/3
    Switchport mode trunk
    Speed 1000
    Added the static route on both nexus for Core HSRP IP: *ip route 0.0.0.0/0 10.10.150.39 (Virtual HSRP IP )*
    But I could not able to ping from N5548 Console to core Switch IP of HSRP? Is there any further configuration to enable routing or ping?
    Pleas suggest

    Hello,
    Please see attached config for both Nexus 5548. I dont have Catalyst 4500 but below is simple config what I applied:
    Both Catalyst 4500
    interface gig 3/48
    switchport mode trunk
    switchport trunk encap dot1q
    On Nexus 5548 Port 1/3 is trunk
    Thanks,
    Jehan

  • Nexus 5010 and 2248 compatible

    Hi
    We have installed nexus 5k - (N5K-C5010P-BF) with software - 4.2(1)N1(1)
    I need to buy a new Nexus 2k.
    Can you tell me if N2K-C2248TF are compatible with nexus (N5K-C5010P-BF) with software - 4.2(1)N1(1)
    Thanks

    HI leolaohoo,
    You are right, my N2 is N2K-C2248TP-1GE. I cannot change N5K-C5010P-BF software. I need to use 4.2(1)N1(1)
    I have found more information in datasheet in Table 3. Cisco Nexus 2000 Series Gigabit Ethernet Fabric Extenders Product Specifications - Minimum Software  - Cisco NX-OS Release 4.2 (Nexus 5000 Series)
    http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps10110/data_sheet_c78-507093.html
    And I found information in Release Notes for 4.2(1)N1(1)
    http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/release/notes/Rel_4_2_1_N1_1/Nexus5000_Release_Notes_4_2_1_N1_1.html#wp191436
    •Support for the Cisco Nexus 2232 and the Cisco Nexus 2248
    But i cannot find information about 4.2(1)N1(1) and N2K-C2248TP-1GE
    I just need to be 100% sure.
    Thanks

  • Verizon Galaxy Nexus LTE and the iPad

    I had Unlimited Data on my VZW account and I have a Verizon Galaxy Nexus (which uses a microSIM)
    Would I be able to pop my Nexus sim into the iPad and start using the data from my VZW account on my iPad?
    I've swapped SIM's with other 4G phones (Thunderbolt SIM with a MiFi). I get service disruption ocassionaly but a quick reboot fixes it.
    I assume that the disruption is caused by software issues on the MiFi or Verizon's LTE service.

    Certainly not going to renew with Verizon and I'm in the same boat about jumping ship early.  Depending on the prices, specs, and manufactures of the next crop of Nexus devices will determine if and when I jump ship early.  Never again will I be on a cellular contract or use a locked phone.  Verizon may claim to have the best network, but the other networks are not nearly as bad as Verizon's handling of the Nexus.  The ** about the delays be caused by "extensive" testing sure did a lot of good for the Nexus. Shortly after launch day OTA for bug fixes and then 4.0.4 delayed for 5 months just to get a somewhat more usable radio set.  At least if a straight from Google Nexus has an issue you can expect it to be fixed in days or weeks, not months.

Maybe you are looking for

  • How to use content code to redeem mountain lion

    when i had enter content code in redeem option its showing i have to make a payment method. tell me how to use content code to redeem mountain lion osx

  • CAVA integration with MS SCEP 2012 R2 ?

       EMC CAVA is a storage antivirus which connects to a single remote windows machine with compatible antivirus. (McAfee, Symantec....).   Can SCEP 2012 be used instead because we are replacing McAfee with System Center End Point Protection 2012. Shah

  • Matrix double-header

    Hi, I would like to create one matrix with 2 headers. Its similar to system forms for example store items where on pane Stock is in matrix disponibilty for each stores and bellow is sum for all stores. I read somewhere thats this are 2 matrixes - fir

  • Why some layers are in the middle of a frame on the timeline?

    Look: Blue Layers are in the middle of frame 01. And I can not put these blue layers in the beginning of a frame, like the Red layer, just in the middle. Because?

  • Can ASP with ODBC be used with Portal??

    I have seen many clients develop active server pages using Frontpage or Dreamweaver hitting Oracle through ODBC (also JDBC). I know you can apply FP and Dream Weaver extensions to Apache. Can this be used with Portal to prevent re-coding existing app