Nexus 5K and ERSPAN
So the documentation says that the 5k does not support RSPAN. So ERSPAN it is, but source only. So the question is, can you only use a device for the destination that supports ERSPAN? For instance I could not create a source session on my 5K's and shot that traffic to my destination host on 2960S.
Hi,
This is entirely possible provided the host has an IP address that can be used as the destination IP address in the ERSPAN configuration.
The following is the ERSPAN configuration on my Nexus 5548.
interface loopback0
ip address 192.168.2.133/32
monitor session 1 type-erspan-source
erspan-id 11
vrf default
destination ip 172.17.1.101
source interface Ethernet1/31 both
source interface Ethernet1/32 both
no shut
monitor erspan origin ip-address 192.168.2.133 global
I have a Red Hat Linux server configured with an IP address 172.17.1.101 which is reachable from my Nexus switch:
ocs5548-1# ping 172.17.1.101
PING 172.17.1.101 (172.17.1.101): 56 data bytes
64 bytes from 172.17.1.101: icmp_seq=0 ttl=62 time=4.295 ms
64 bytes from 172.17.1.101: icmp_seq=1 ttl=62 time=0.868 ms
64 bytes from 172.17.1.101: icmp_seq=2 ttl=62 time=0.978 ms
64 bytes from 172.17.1.101: icmp_seq=3 ttl=62 time=7.211 ms
64 bytes from 172.17.1.101: icmp_seq=4 ttl=62 time=9.57 ms
--- 172.17.1.101 ping statistics ---
5 packets transmitted, 5 packets received, 0.00% packet loss
round-trip min/avg/max = 0.868/4.584/9.57 ms
And now when I run tcpdump on my Linux server I can see the GRE packets sourced from the ERSPAN session on the Nexus.
[sfuller@rhel5 ~]$ sudo tcpdump -i bond0 proto gre -c 10
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on bond0, link-type EN10MB (Ethernet), capture size 96 bytes
09:07:27.047805 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13102, length 50: gre-proto-0x88be
09:07:27.047891 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13103, length 50: gre-proto-0x88be
09:07:27.049757 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13104, length 122: gre-proto-0x88be
09:07:27.050813 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13105, length 127: gre-proto-0x88be
09:07:27.051899 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13106, length 50: gre-proto-0x88be
09:07:27.052054 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13107, length 50: gre-proto-0x88be
09:07:27.052211 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13108, length 50: gre-proto-0x88be
09:07:27.052645 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13109, length 50: gre-proto-0x88be
09:07:27.052852 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13110, length 50: gre-proto-0x88be
09:07:27.053009 IP ocs5548-1-loop0.ntilab.net > rhel5-bond0.ntilab.net: GREv0, seq 13111, length 50: gre-proto-0x88be
10 packets captured
10 packets received by filter
0 packets dropped by kernel
You'll obviously need a capture device that understand GRE, but that shouldn't be an issue.
The other thing to be mindful of with ERSPAN is the MTU size if you're trying to capture the entire packet. An ERSPAN packet comprises the encapsulated IPv4 header (20-bytes), GRE header (8-bytes), ERSPAN header (8-bytes) and the original packet and so a 1500-byte packet that is being captured would have to be truncated to make it through a network with a 1500-byte MTU. There's a section on Configuring Truncated ERSPAN in the Nexus System Management guide if you want to control the truncation.
Regards
Similar Messages
-
Diff b/w Nexus 5548P and 5548UP
What is the
Diff b/w Nexus 5548P and 5548UP
regards.Hi,
A UP or Unified ports allow you to configure ports as Ethernet, native Fibre Channel or Fibre Channel over Ethernet (FCoE) ports. By default, the ports are Ethernet ports but you can change the port mode to Fibre Channel on the following unified ports:
Any port on the Cisco Nexus 5548UP switch or the Cisco Nexus 5596UP switch.
The ports on the Cisco N55-M16UP expansion module that is installed in a Cisco Nexus 5548P switch.
More details:
http://www.cisco.com/web/techdoc/dc/reference/cli/nxos/commands/l2/port.html
Comapre 5548 and 5548:
http://www.cisco.com/en/US/products/ps9670/prod_models_comparison.html
./Abhinav -
How to download MIB for NXOS or platform Nexus 7010 and Nexus 7004
Hello,
I need to monitor my Nexus 7004 and 7010 by my SNMP Agent, but I can't find the way to donload the required MIBs.
For information I'm running the folling images:
bootflash:///n7000-s2-dk9.6.2.6b.bin
bootflash:///n7000-s1-dk9.6.1.5.bin
By advance thanks for the support
GildasThe module you are running requires a minimum software version of 5.1.
You are currently running 5.0.3 which is why the module is not
recognized.
Below is a link that explains this:
http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9402/data_s
heet_c78-605482.html
Product Specification
Table 3 lists the specifications for the Cisco Nexus 7000 32-Port 10 Gigabit Ethernet
Module with XL Option.
Table 3. Product Specifications
Item
Specifications
System
Product compatibility
Supported in all Cisco Nexus 7000 Series chassis
Software compatibility
Cisco NX-OS Software Release 5.1 or later (minimum requirement)
You would need to upgrade you software.
Hope this helps.
Regards
Muhammed M -
ESXi 4.1 NIC Teaming's Load-Balancing Algorithm,Nexus 7000 and UCS
Hi, Cisco Gurus:
Please help me in answering the following questions (UCSM 1.4(xx), 2 UCS 6140XP, 2 Nexus 7000, M81KR in B200-M2, No Nexus 1000V, using VMware Distributed Switch:
Q1. For me to configure vPC on a pair of Nexus 7000, do I have to connect Ethernet Uplink from each Cisco Fabric Interconnect to the 2 Nexus 7000 in a bow-tie fashion? If I connect, say 2 10G ports from Fabric Interconnect 1 to 1 Nexus 7000 and similar connection from FInterconnect 2 to the other Nexus 7000, in this case can I still configure vPC or is it a validated design? If it is, what is the pro and con versus having 2 connections from each FInterconnect to 2 separate Nexus 7000?
Q2. If vPC is to be configured in Nexus 7000, is it COMPULSORY to configure Port Channel for the 2 Fabric Interconnects using UCSM? I believe it is not. But what is the pro and con of HAVING NO Port Channel within UCS versus HAVING Port Channel when vPC is concerned?
Q3. if vPC is to be configured in Nexus 7000, I understand there is a limitation on confining to ONLY 1 vSphere NIC Teaming's Load-Balancing Algorithm i.e. Route Based on IP Hash. Is it correct?
Again, what is the pro and con here with regard to application behaviours when Layer 2 or 3 is concerned? Or what is the BEST PRACTICES?
I would really appreciate if someone can help me clear these lingering doubts of mine.
God Bless.
SiMSim,
Here are my thoughts without a 1000v in place,
Q1. For me to configure vPC on a pair of Nexus 7000, do I have to connect Ethernet Uplink from each Cisco Fabric Interconnect to the 2 Nexus 7000 in a bow-tie fashion? If I connect, say 2 10G ports from Fabric Interconnect 1 to 1 Nexus 7000 and similar connection from FInterconnect 2 to the other Nexus 7000, in this case can I still configure vPC or is it a validated design? If it is, what is the pro and con versus having 2 connections from each FInterconnect to 2 separate Nexus 7000? //Yes, for vPC to UCS the best practice is to bowtie uplink to (2) 7K or 5Ks.
Q2. If vPC is to be configured in Nexus 7000, is it COMPULSORY to configure Port Channel for the 2 Fabric Interconnects using UCSM? I believe it is not. But what is the pro and con of HAVING NO Port Channel within UCS versus HAVING Port Channel when vPC is concerned? //The port channel will be configured on both the UCSM and the 7K. The pro of a port channel would be both bandwidth and redundancy. vPC would be prefered.
Q3. if vPC is to be configured in Nexus 7000, I understand there is a limitation on confining to ONLY 1 vSphere NIC Teaming's Load-Balancing Algorithm i.e. Route Based on IP Hash. Is it correct? //Without the 1000v, I always tend to leave to dvSwitch load balence behavior at the default of "route by portID".
Again, what is the pro and con here with regard to application behaviours when Layer 2 or 3 is concerned? Or what is the BEST PRACTICES? UCS can perform L2 but Northbound should be performing L3.
Cheers,
David Jarzynka -
VN-Tag with Nexus 1000v and Blades
Hi folks,
A while ago there was a discussion on this forum regarding the use of Catalyst 3020/3120 blades switches in conjunction with VN-tag. Specifically, you can't do VN-Tag with that Catalyst blade switch sitting inbetween the Nexus 1000V and the Nexus 5000. I know there's a Blade switch for the IBM blade servers, but will there be a similar version for the HP C-class blades? My guess is NO, since Cisco just kicked HP to the curb. But if that's the case, what are my options? Pass-through switches? (ugh!)
Previous thread:
https://supportforums.cisco.com/message/469303#469303wondering the same...
-
Interoperability issues between Nexus 5k and HP storageworks (8/20q)
Hello community,
I am trying to get a VM host and a windows server to connect to their storage across a nexus and HP (Qlogic) fabric switch. This is currently having issues with the VM host unable to see the datastores, possibly due to interoperability between Cisco and HP (Qlogic)
I have configured and tested the connectivity using only the cisco nexus and this worked, I then tested it using only the HP fabric switch (HP 8/20q) and this also worked.
However, when using the HP and Cisco Nexus as shown in the attached diagram, things stop working.
The connection is using Native Fibre channel, On the Cisco side I performed the following steps
Configured the Nexus with Domain ID 10 and the HP with Domain ID 20.
Connected the 2 fabric switches on fc1/48 (Cisco) and port 0 (HP) and confirmed that the ISL came up (E_port 8G), I confirmed connectivity using fcping both ways.
I connected the SAN to the Nexus and the servers to the HP
Configured VSAN 10
Added interfaces fc1/41 to 48 in VSAN 10
Created 2 zones ( ESXI and Windows)
Added the PWWN for the ESXI server and the MSA2040 to the ESXI zone
Added the PWWN for the Windows 2k8 server and MS2040 to the Windows zones
Created zoneset (Fabric-A) and added both the above zones in it
Activated the FABRIC-A zoneset
The result is that the zones and zoneset are synchronised to the HP switch .I confirmed that I was able to see the servers and SAN WWN in the correct zones on the HP.
From the 8/20q switch I am able to fcping the SAN, Nexus and servers, however the Nexus is only able to fcping the SAN and the HP, it returns a “no response from destination” when pinging the servers.
I have added the FCID for all the units in the same zones to see if it makes any difference to no avail the result seem to be the same. I have gone through various Nexus/MDS/HP/Qlogic user guides and forums; unfortunately I have not come across any that shows this specific topology.
source for HP user guide is here: http://h20565.www2.hp.com/hpsc/doc/public/display?docId=emr_na-c02256394
I’m attaching the nexus config and partial view of the “show interface brief” showing the fibre channel port status
Interface Vsan Admin Admin Status SFP Oper Oper Port
Mode Trunk Mode Speed Channel
Mode (Gbps)
fc1/47 10 auto on up swl F 8 --
fc1/48 10 auto on up swl E 8 --
Any help and advice would be greatly appreciated. thanks in advanceHi all, after much reading, Walter Dey provided the hint to put me on the right track.
By default the Nexus 5k is in interop mode 1. However, one of the requirement for this to be "interoperable" with other vendor the FCDomain ID in the entire fabric needs to be between 97 and 127 as stated in the Cisco website.
http://www.cisco.com/en/US/docs/storage/san_switches/mds9000/interoperability/guide/ICG_test.html
Another issue that had me and my colleague scratching our heads, was that we were seeing high level of CRC errors on the ISL interfaces. This was caused by ARBFF settings mismatch between the Nexus and the HP. This was resolved by ensuring that the ARBFF setting on the HP was set to false and the command "switchport fill-pattern ARBFF speed 8000" is configured on the ISL interface linking the 2 switches. (note that Cisco's default setting for the ports is IDLE, until this is changed the link will not stabilise)
Thanks for all your help guys. -
Fabric with two Nexus-5548 and a brocade switch does not get fabric updates
We have a fabric containing two Nexus 5548 and a Brocade 5000 switch in interop mode 2. When i make changes to the zoning, the first nexus (the fabric principal) and the brocade switch see the zone changes. The second Nexus switch does not see it. There are no error messages but the change just can't be seen. What can i do to find out, what goes wrong ?
Ouch, deprecated is not the word i wanted to read
We are using 5.1(3)N1(1a) on nexus-rz1-a
and 6.0(2)N1(2) on nexus-rz2-a.
The fabric can be seen :
nexus-rz2-a# show fcs ie vsan 10
IE List for VSAN: 10
IE-WWN IE Mgmt-Id Mgmt-Addr (Switch-name)
10:00:00:05:1e:90:57:27 S(Rem) 0xfffc01 10.88.133.110 (bc-san1)
20:0a:00:2a:6a:72:ba:01 S(Loc) 0xfffc1c 10.88.133.105 (nexus-rz2-a)
20:0a:54:7f:ee:7f:dc:01 S(Adj) 0xfffc0b 10.88.133.100 (nexus-rz1-a)
[Total 3 IEs in Fabric]
nexus-rz1-a# show fcs ie vsan 10
IE List for VSAN: 10
IE-WWN IE Mgmt-Id Mgmt-Addr (Switch-name)
10:00:00:05:1e:90:57:27 S(Adj) 0xfffc01 10.88.133.110 (bc-san1)
20:0a:00:2a:6a:72:ba:01 S(Adj) 0xfffc1c 10.88.133.105 (nexus-rz2-a)
20:0a:54:7f:ee:7f:dc:01 S(Loc) 0xfffc0b 10.88.133.100 (nexus-rz1-a)
[Total 3 IEs in Fabric]
I try to distribute the zoneset this way:
zoneset distribute vsan 10
Zoneset distribution initiated. check zone status
nexus-rz1-a# show zone status
VSAN: 10 default-zone: deny distribute: full Interop: 2
mode: basic merge-control: allow
session: none
hard-zoning: enabled broadcast: disabled
Default zone:
qos: none broadcast: disabled ronly: unsupported
Full Zoning Database :
DB size: 6291 bytes
Zonesets:1 Zones:62 Aliases: 44
Active Zoning Database :
DB size: 10243 bytes
Name: FABRIC1 Zonesets:1 Zones:60
Status: Zoneset distribution completed at 08:06:00 UTC Dec 3 2013
nexus-rz2-a# show zone status
VSAN: 1 default-zone: deny distribute: active only Interop: default
mode: basic merge-control: allow
session: none
hard-zoning: enabled broadcast: disabled
Default zone:
qos: none broadcast: disabled ronly: unsupported
Full Zoning Database :
DB size: 4 bytes
Zonesets:0 Zones:0 Aliases: 0
Active Zoning Database :
Database Not Available
Status:
VSAN: 10 default-zone: deny distribute: full Interop: 2
mode: basic merge-control: allow
session: none
hard-zoning: enabled broadcast: disabled
Default zone:
qos: none broadcast: disabled ronly: unsupported
Full Zoning Database :
DB size: 6291 bytes
Zonesets:1 Zones:62 Aliases: 44
Active Zoning Database :
DB size: 10243 bytes
Name: FABRIC1 Zonesets:1 Zones:60
Status: Activation completed at 13:03:42 UTC Dec 2 2013 -
SAN Port-Channel between Nexus 5000 and Brocade 5100
I have a Nexus 5000 running in NPV mode connected to a Brocade 5100 FC switch using two FC ports on a native FC module in the Nexus 5000. I would like to configure these two physical links as one logical link using a SAN Port-Channel/ISL-Trunk. An ISL trunking license is already installed on the Brocade 5100. The Nexus 5000 is running NX-OS 4.2(1), the Brocade 5100 Fabric OS 6.20. Does anybody know if this is a supported configuration? If so, how can this be configured on the Nexus 5000 and the Brocade 5100? Thank you in advance for any comments.
Best regards,
FlorianI tried that and I could see the status light on the ports come on but it still showed not connected.
I configured another switch (a 3560) with the same config and the same layout with the fiber and I got the connection up on it. I just cant seem to get it on the 4506, would it be something with the supervisor? Could it be wanting to use the 10gb port instead of the 1gb ports? -
Trunking nexus 5596 and netapp or exsi issue
hi
i have 2 issues with trunking between nexus 5596 and a esxi server .....can not get the servers to ping out
and the netapp connected to the same 5596 cannot ping.
if the server is a access port it works fine.
is there any tricks that are required to be configured on the nexus to make this work.Make sure we are actually tagging for those vlans on the host (Netapp/ESXi). If we are not, then this would explain why it works in access mode on the switch.
-
I have looked through the add ons and their only download for windows, Mac or Linux none of which I can install on Firefox beta running on google nexus 7 and links to download and install the correct add on or one similar to twonky beam would be helpful thanks
Twonky beam is not yet available for Mobile version.
Note : Addons are not developed by Mozilla. -
Hi,all.
I have Nexus 5548P and 20 pc GLC-T . Temperature range in nexus about 60"C , after reload nexus all or not all sfp in shut down . I have to CLI no shut for to work sfp . Does it from high temperature range ? I tried another party sfp , but result same.
Best Regards/Hi Alexander
What is the state of interfaces after reload (notconnected, sfp not inserted etc...)?
Do you see any error/warning messages in the logs?
What temerature do you have on the device in our lab?
What SFP do you have - full PN
-Alex -
Cisco Nexus 5548UP and FI6248UP compatibility with FC SFP
Cisco Nexus 5548UP and FI 6248UP comes with Unified Ports. What are the SFP types this port can take? 1Gig, 10Gig and 2/4/8FC. Could you please clarify?
Thanks,
CheriyanHi Cheriyan,
Here is te URL to the 6200 series FI data sheet:
http://www.cisco.com/en/US/prod/collateral/ps10265/ps11544/data_sheet_c78-675245.pdf
Check for the table to supported SFPs.
Same for the 5500 switches
http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9670/data_sheet_c78-618603.html.
Hope this helps!
./Abhinav -
Nexus 5548 and Define static route to forward traffic to Catalyst 4500
Dear Experts,
Need your technical assistance for the Static routing in between Nexus 5548 and Catalyst 4500.
Further I connected both Nexus 5548 with Catalyst 4500 as individual trunk ports because there is HSRP on Catalyst 4500. So I just took 1 port from each nexus 5548, make it trunk with the Core Switch (Also make trunk from each Switch each port). Change the speed on Nexus to 1000 because other side on Catalyst 4500 line card is 1G RJ45.
*Here is the Config on Nexus 5548 to make port a Trunk:*
N5548-A/ N5548-B
Interface Ethernet1/3
Switchport mode trunk
Speed 1000
Added the static route on both nexus for Core HSRP IP: *ip route 0.0.0.0/0 10.10.150.39 (Virtual HSRP IP )*
But I could not able to ping from N5548 Console to core Switch IP of HSRP? Is there any further configuration to enable routing or ping?
Pleas suggestHello,
Please see attached config for both Nexus 5548. I dont have Catalyst 4500 but below is simple config what I applied:
Both Catalyst 4500
interface gig 3/48
switchport mode trunk
switchport trunk encap dot1q
On Nexus 5548 Port 1/3 is trunk
Thanks,
Jehan -
Nexus 5010 and 2248 compatible
Hi
We have installed nexus 5k - (N5K-C5010P-BF) with software - 4.2(1)N1(1)
I need to buy a new Nexus 2k.
Can you tell me if N2K-C2248TF are compatible with nexus (N5K-C5010P-BF) with software - 4.2(1)N1(1)
ThanksHI leolaohoo,
You are right, my N2 is N2K-C2248TP-1GE. I cannot change N5K-C5010P-BF software. I need to use 4.2(1)N1(1)
I have found more information in datasheet in Table 3. Cisco Nexus 2000 Series Gigabit Ethernet Fabric Extenders Product Specifications - Minimum Software - Cisco NX-OS Release 4.2 (Nexus 5000 Series)
http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps10110/data_sheet_c78-507093.html
And I found information in Release Notes for 4.2(1)N1(1)
http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/release/notes/Rel_4_2_1_N1_1/Nexus5000_Release_Notes_4_2_1_N1_1.html#wp191436
•Support for the Cisco Nexus 2232 and the Cisco Nexus 2248
But i cannot find information about 4.2(1)N1(1) and N2K-C2248TP-1GE
I just need to be 100% sure.
Thanks -
Verizon Galaxy Nexus LTE and the iPad
I had Unlimited Data on my VZW account and I have a Verizon Galaxy Nexus (which uses a microSIM)
Would I be able to pop my Nexus sim into the iPad and start using the data from my VZW account on my iPad?
I've swapped SIM's with other 4G phones (Thunderbolt SIM with a MiFi). I get service disruption ocassionaly but a quick reboot fixes it.
I assume that the disruption is caused by software issues on the MiFi or Verizon's LTE service.Certainly not going to renew with Verizon and I'm in the same boat about jumping ship early. Depending on the prices, specs, and manufactures of the next crop of Nexus devices will determine if and when I jump ship early. Never again will I be on a cellular contract or use a locked phone. Verizon may claim to have the best network, but the other networks are not nearly as bad as Verizon's handling of the Nexus. The ** about the delays be caused by "extensive" testing sure did a lot of good for the Nexus. Shortly after launch day OTA for bug fixes and then 4.0.4 delayed for 5 months just to get a somewhat more usable radio set. At least if a straight from Google Nexus has an issue you can expect it to be fixed in days or weeks, not months.
Maybe you are looking for
-
How to use content code to redeem mountain lion
when i had enter content code in redeem option its showing i have to make a payment method. tell me how to use content code to redeem mountain lion osx
-
CAVA integration with MS SCEP 2012 R2 ?
EMC CAVA is a storage antivirus which connects to a single remote windows machine with compatible antivirus. (McAfee, Symantec....). Can SCEP 2012 be used instead because we are replacing McAfee with System Center End Point Protection 2012. Shah
-
Hi, I would like to create one matrix with 2 headers. Its similar to system forms for example store items where on pane Stock is in matrix disponibilty for each stores and bellow is sum for all stores. I read somewhere thats this are 2 matrixes - fir
-
Why some layers are in the middle of a frame on the timeline?
Look: Blue Layers are in the middle of frame 01. And I can not put these blue layers in the beginning of a frame, like the Red layer, just in the middle. Because?
-
Can ASP with ODBC be used with Portal??
I have seen many clients develop active server pages using Frontpage or Dreamweaver hitting Oracle through ODBC (also JDBC). I know you can apply FP and Dream Weaver extensions to Apache. Can this be used with Portal to prevent re-coding existing app