Cisco AAA/Identity/Nac :: Setup Tacacs Config Onto New NEXUS 5000

May 26, 2011

I m trying to setup a Tacacs config onto my new NEXUS 5000 series.Nevertheless the authentication doesn't work.Actually I followed the config guide but something is not working or missing.I have setup everything through VMWARE with ACS installed on a Windows server.

View 20 Replies


ADVERTISEMENT

Cisco Switching/Routing :: Nexus 5000 Tacacs

Oct 8, 2012

I have a little problem. My customer is using TACP-PLUS ALPHA (F4.0.3.alpha.v9). Well, the same user than have access to another Cisco equipment, with user test1 by sample, can configure anything in the equipment. But in the nexus 5000, el command "show user-account" indicate just the "network-operator" role. Well, I patch this situation with the next commands:

aaa authorization config-commands default group TACSERVER local
aaa authorization commands default group TACSERVER local
 
Well, when I do a telnet into the nexus, I can shut the interfaces, config and anything. But, when I ingress by console, I can not to configure the interfaces.I understand that the Nexus 5000 the Tacacs configuration is global for VTY and Console (different in the Cisco equipment Routers by sample).

View 1 Replies View Related

Cisco AAA/Identity/Nac :: TACACS Nexus 5548 Authorization?

Jan 3, 2012

I am having an issue with authorization on the Nexus 5548. Note: The tacacs configuration has and still works correctly with all non-Nexus gear.
 
Authentication succeeds, and initiatial authorization passes. However, all sh and config commands fail, though AAA Autho Config-Commands .... and Commands Default Group <Grp Name), are configured.
 
ACS generates the following error: 13025 Command failed to match a Permit rule. The Selected Command Set is DenyAllCommands. I created an AllowAll, but am unclear how to associate this with Access Policy.

View 1 Replies View Related

AAA/Identity/Nac :: Nexus 7000 Crashes Using Tacacs To ACS 4.1 Server

Apr 9, 2012

I see there is a similar post for Nexus 5000 to ACS 5.2.  Identical symptoms.  The supervisor crashed and switched to secondary.  Is there a comparable field for ACS 4.1 that needs to have something in it? 2012 Apr  9 11:07:55 va-core02 %$ VDC-1 %$ %SYSMGR-2-SERVICE_CRASHED: Service "Tacacs Daemon" (PID 9390) hasn't caught signal 11 (core will be saved). 2012 Apr  9 11:07:55 va-core02 %$ VDC-1 %$ %SYSMGR SYSMGR_AUTOCOLLECT_TECH_SUPPORT_LOG: This supervisor will temporarily remain online in order to collect show tech-support. This behavior is configurable via 'system [no] auto-collect tech-support'.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 Tacacs Custom Attribute For Nexus 1000V

Jul 18, 2011

how to add tacacs custom attribute to ACS 4.2 for Nexus 1000V:shell:roles="network-admin admin-vdc"In the interface configuration I've added new service, service - shell, protocol - tacacs+.In the group settings I've enabled this attribute configuration. And it is not works. Default privilege level is assigned to any user with access allowed.

View 8 Replies View Related

Cisco AAA/Identity/Nac :: Nexus 5010 Allows TACACS And Local Authentication Concurrently

Jun 6, 2011

I am experiencing an issue where NX-OS on our 5010s is allowing both Local AND TACACS authentication concurrently.  If I don't configure any aaa authorization commands, the locally logged in user has unmitigated access to the device.  Once I enable aaa authroization, all commands issued by the locally logged in user are denied by ACS, but they can still log in to the device.  When I comb through the logs on the ACS server, I see successful logins when TACACS credentials are used, and also the failed attempts when the locally configured credentials are used.  On the switch, however, I receive "%TACACS-3-TACACS_ERROR_MESSAGE:  All servers failed to respond" when using locally configured credentials on the switch itself.  We are running ACS v4.2.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: 7000 Setup Switch To Be Able To Authenticate Users With Tacacs+

May 2, 2012

I have a cisco nexus 7000 switch and a cisco ACS 5.2. I would like to setup the switch to be able to authenticate users with tacacs+ using RSA secureid tokens when they try to logon to the switch.

View 1 Replies View Related

Cisco Switching/Routing :: Nexus FEX Transceivers SNMP MIB Nexus 5000

Dec 22, 2011

Struggle to find the SNMP MIBS of the Nexus 5000 FEX tranceivers.

View 3 Replies View Related

Cisco :: Nexus 5000 As NTP Client?

Nov 26, 2010

We run 6509 core routers as NTP servers to other IOS routers/switches & servers of several OS flavours.All good.  Recently added some Nexus 5000s and cannot get them to lock.No firewalls or ACLs in the path
 
6509 (1 of 4) state:
LNPSQ01CORR01>sh ntp ***
      address         ref clock     st  when  poll reach  delay  offset    disp+ 10.0.1.2         131.188.3.220     2   223  1024  377     0.5   -6.23     0.7+~130.149.17.21    .PPS.             1   885  1024  377    33.7   -0.26     0.8*~138.96.64.10     .GPS.             1   680  1024  377    22.7   -2.15     1.0+~129.6.15.29      .ACTS.            1   720  1024  377    84.9   -3.37     0.6+~129.6.15.28      .ACTS.            1   855  1024  377    84.8   -3.30     2.3 * master (synced), # master (unsynced), + selected, - candidate, ~ configured

[code]....
 
Are we missing some NTP or managment vrf setup in the Nexus 5Ks?

View 5 Replies View Related

Cisco :: Port Diagnostic On Nexus (5000)?

Aug 15, 2012

I think I may have a bad port on a 5548, does the NX-OS has any sort of self-diagnostic test on its port?

View 6 Replies View Related

Cisco WAN :: Nexus 5000 - Viewing MAC Table In NX-os?

Feb 12, 2012

I am looking how to see the mac table on a Nexus 5000 switch running NX-OS and confirm the mac address on a certain port.  Similar to the Sh mac-address-table in IOS and sh cam in Cat-os.
 
I am sure this is simple I just cannot find the command.

View 2 Replies View Related

Cisco :: Disable Mac Learning In Nexus 5000?

Nov 22, 2011

Is it possible to disable mac learning on a specific vlan in the nexus 5000?

View 4 Replies View Related

Cisco Firewall :: NAT Configuration In 8.4 Nexus 5000

Mar 23, 2011

i have a use-case in which we need to firewall some of the security-sensitive-vlans to the ASA. In other words, there are few vlans that have their SVIs on the N5k (Layer-3 enabled) which talk to each other and there are some which have the layer-3 on the ASA. The ASA has sub-interfaces for those vlans. The N5k-sw and the ASA are interconnected on the same 1 physical link with a sub-interface on both ( /30) and the ASA is injecting default route to it in OSPF. They are advertising all of their networks in OSPF. I see all the routes in them. (Attached pic),My issue is: I am unable to ping the other sub-interface on the ASA from the N5k. (If you check the attached diagram, i cannot ping 20.1.1.1 from the N5k, although i can reach my next-hop 10.1.1.2) I have made the security-level to 100 for the subinterfaces and the physical interface on the ASA, also have allowed ip,icmps in the ACLs on the sub-interfaces of vlan 10 and 20 in both directions.

View 5 Replies View Related

Cisco :: NTP Error Logs On Nexus 5000

Oct 13, 2012

We are using almost 10 Nexus 5k in our DC currently we are getting same error logs in all Nexus 5k." ntpd[4746]: ntp:time reset +0.279670 s "  ,Is it major error or just for reset time?

View 1 Replies View Related

Cisco :: NEXUS 5000 / Read CPU Load With SNMP?

Sep 18, 2011

tried to read the NEXUS 5000 cpu load: cseSysCPUUtilization 1.3.6.1.4.1.9.9.305.1.1.1 but there is a  timeout: Timeout: No Response from 10.100.224.16 Other MIB values readout, like the system value, is ok.We use snmpv3.

View 4 Replies View Related

Cisco WAN :: Setting Up Nexus 5000 Series Switch?

Apr 23, 2013

Am new to Nexus switching, i have a  Nexus box that i need to link with IBM servers with 10GB Network Cards.
 
how to set up fiber channel on this machine

View 4 Replies View Related

Cisco Switching/Routing :: ACS Authorization On Nexus 5000

Jun 23, 2012

I have the following configured on my Nexus switches and works with success.
 
The problem I have is Once I switch of the ACS server I can log on to the Nexus as I have a admin user configured locally on the Nexus and the ACS server unfortunately can not run commands as it tries to point to the ACS server for auhtorization and the ACS server is turned off is it possible for the Nexus to ignore the authorization command if it can not see the ACS server ?
 
Feature tacacs+
ip tacacs source-interface vlan 705
tacacs-server host x.x.x.x key 7 "xxxxxx"
aaa group server tacacs+ Test-switch (Test-switch is a group configured on ACS 5.2)
[Code]...

View 1 Replies View Related

Cisco Switching/Routing :: Nexus 5000 - What Cause Loops On Ports

Dec 14, 2011

Any opinion on what could cause loops on nexus 5000 ports that are connected to esx hosts ?

View 3 Replies View Related

Cisco Switching/Routing :: Nexus 5000 Upgrade Really Non-disruptive?

May 15, 2013

I'm planning to upgrade N5K from 5.1(3)N2(1b) to 5.2(1)N1(4)."sh install all impact kickstart bootflash:n5000-uk9-kickstart.5.2.1.N1.4.bin system bootflash:n5000-uk9.5.2.1.N1.4.bin"reports:

...
Compatibility check is done:
Module bootable         Impact Install-type Reason
------ -------- -------------- ------------ ------
     1       yes non-disruptive         reset
...

Is the upgrade really non-disruptive?

View 1 Replies View Related

Cisco Infrastructure :: PortChannel Table In Nexus 7000 / 5000 Through MIB?

Apr 25, 2012

I  ma trying to query   "CISCO-PORT-CHANNEL"   mib on Nexus 7000 for portChannel table and I  am not getting any info.
 
Nexus OS versions : Nexus   7000  -  System version: 5.1(5)
Nuxus 5000 -    System version: 5.0(3)N1(1a)
  
Any pointers or other alternatives to query through MIB ?

View 1 Replies View Related

Cisco Switching/Routing :: VPC On Nexus 5000 With Catalyst 6500 (no VSS)?

Jan 23, 2011

The diagram below is the configuration we are looking to deploy, that way because we do not have VSS on the 6500 switches so we can not create only one  Etherchannel to the 6500s.Our blades inserted on the UCS chassis  have INTEL dual port cards, so they do not support full failover.
 
Questions I have are.

- Is this my best deployment choice?
- vPC highly depend on the management interface on the Nexus 5000 for the keep alive peer monitoring, so what is going to happen if the vPC brakes due to:
- one of the 6500 goes down
- STP?
- What is going to happend with the Etherchannels on the remaining  6500?
- the Management interface goes down for any other reason
- which one is going to be the primary NEXUS?
 
Below is the list of devices involved and the configuration for the Nexus 5000 and 65000. 
 
Devices

·         2  Cisco Catalyst with two WS-SUP720-3B each (no VSS)
·         2 Cisco Nexus 5010
·         2 Cisco UCS 6120xp
·         2 UCS Chassis
     -    4  Cisco  B200-M1 blades (2 each chassis)
          - Dual 10Gb Intel card (1 per blade)
 
vPC Configuration on Nexus 5000
 
TACSWN01
TACSWN02
feature vpc
vpc domain 5
reload restore
reload restore   delay 300

[code]...

View 22 Replies View Related

Cisco Switching/Routing :: SNMP / Does Nexus 5000 Support VRF

Jan 7, 2013

Iam having some issue trying to configure snmp-server context vrf XXX.From some reason even if i put my VRF name i cant see anything about this vrfthis is the command i add:
 
 snmp-server context def vrf datacenter

View 3 Replies View Related

Cisco Switching/Routing :: Nexus 5000 Jumbo Packets?

Oct 7, 2012

on some of our ports on Nexu 5000 and on the connected FEX we can see a lot of Jumbo Packets though there is not enableed any JumboFrame on the Switch, all Interface and system MTU is set to 1500.
 
DBE-LINZ-XX41# sh int Eth113/1/27
Ethernet113/1/27 is up
Hardware: 100/1000 Ethernet, address: d0d0.fd1b.b69c (bia d0d0.fd1b.b69c)

[Code]....

View 1 Replies View Related

Cisco WAN :: Routing / Ping Between Two Nexus 5000 - No Route To Destination

Jan 23, 2013

I have 2 nexus 5000 switches configured with a trunk linking the two how can i do the follwoing
 
BOX 2
 
vrf context management
  ip route 0.0.0.0/0 192.162.88.9
 
BOX 2
 
vrf context management
  ip route 0.0.0.0/0 192.168.88.10
 
1. ping between the two boxes, i set up static route's but when i ping i get the error "NO ROUTE TO DESTINATION"
 2. routing between the two

View 1 Replies View Related

Cisco Switching/Routing :: Nexus 5000 Jumbo Frames

Apr 16, 2013

We have a requirement to send span traffic to a destination port for monitoring purposes on two 5000s with some 2000 fex boxes attached.
Some of the servers are making use of frames larger than 1500. we have not changed any mtu configuration on the 5000 since installation, and I can see the policy maps is still on 1500.
 
My first assumption would be that frames larger than 1500 will not be dropped, but it seemingly not (see below). is there a reason why the switch would forward jumbo frames? Also, is there a limitation on MTU for span traffic? There is a MTU command under the span session, but the maximum is 1518. From what I can read the frame will be truncated if it exceeds this. Does that mean the fragments will be dropped?
 
RX
    7495685816 unicast packets  249 multicast packets  147899 broadcast packets
    7495833963 input packets  1426823388087 bytes
    1608134 jumbo packets  0 storm suppression bytes
[Code]....

View 1 Replies View Related

Cisco :: Nexus 5000 SNMP Monitor For Temperature Status

Aug 15, 2012

May I know how to monitor temperature status of below device by SNMP.How to find the exact oid of those devices? I can only find the mib file of Nexus 5000 at url...Cisco Nexus 5010PCisco UCS 6120XP Cisco ASR 1002F

View 1 Replies View Related

Cisco Switching/Routing :: Nexus 5000 Support Of Netflow

Jun 8, 2009

I can't seem to find any information on the Nexus 5000 support of netflow. I assume that means it doesn't do netflow.

View 5 Replies View Related

Cisco Switching/Routing :: Connect Nexus 2000 To Two 5000 With Different Links?

Feb 12, 2013

is it possible to connect one Cisco Nexus 2000 fabric extender to two Cisco Nexus 5000 and use one link on the first side and two links on the other side?

View 3 Replies View Related

Cisco Infrastructure :: Nexus 5000 SNMP - Limit Access To OIDs?

Dec 12, 2011

What is the correct way to create an SNMP user on a Nexus 5k Switches and limit the read/write access to some OIDs?I have been searching for hours for configuration examples or guides, but i had no luck.I guess a role has to be created, containing rules for some feature, but the list of features doesn't contain anything about snmp.This is my configuration on catalyst switches and i'd like to achieve the same result on the Nexus 5k:
 
conf term
access-list 10 permit host x.x.x.x
access-list 10 deny any
snmp-server view myview ccCopyTable included
snmp-server group mygroup v3 priv read myview write myview access 10
snmp-server user myuser mygroup v3 auth md5 xxxxxx priv aes 256 xxxxxx
end

View 1 Replies View Related

Cisco Switching/Routing :: Setting Up Nexus 5000(s) For Inband Management?

Feb 12, 2012

we do not have an out-of-band management network and setting one up at this point is not being planned.  We are mainly a swtiched environment and the only devices that are using L3 are the core switch for WAN purposes and the lab because it is mimicking the production environment.  I have two Nexus switches that are sitting on the other side of a 3750 switch which is currently acting as a L3 device because this is a pre-production environment for a new project.  We had an issue with management of the devices before but our workaround was to put them on the management vlan direcltly off of the core, allowing only management traffic to pass by means of mgmt0 on each device.  The problem I'm having now is that I've now setup the mgmt0 interfaces on both for the keepalive link for vpc only (vpc traffic is going accross 2x10gb connections and the link to the 3750 is 1gb each trunked) and have lost my ability to use the mgmt0 connections for management. How to connect my management connection through either the 3750 or directly off the core switch (as that's what will happen once it's put into production)

View 3 Replies View Related

Cisco Switching/Routing :: Getting Nexus 5000 Command (default Interface X / X)

Jun 26, 2012

when will be the command "default interface x/x" on the Nexus 5000 platform available? Even with latest software version (5.1.3.N2.1a) it is not possible. For Nexus7000 it's working fine with 5.2 train.Is there a feature request for it? If not here it is!!It's horrible to deconfigure many interfaces especially in N5k environments with many FEXes.

View 3 Replies View Related

Cisco Switching/Routing :: Nexus 5000 And 3750 Switch Redundancy

Oct 31, 2012

My network consist of that network device. cisco catalyst 3750 with stackwise, 2xnexsus 5000  series and servers.servers connected to nexsus switch. nexsus connect to 3750.

Each server have two link, one of them connect nexsus1 and other connect to nexsus2 switch.(same traffic) each nexsus have one link to 3750. At 3750 the nexsus link configurate etherchannel. but the flapping occur at 3750.

i understand that at 2 nexsus link have the same server source mac address so the flapping occur at 3750. how i solve this problem?

View 5 Replies View Related

Cisco Switching/Routing :: Default Configuration Lines On Nexus 5000

Feb 17, 2012

What is the purpose of these default configuration lines? What do they mean? I can't find an explanation of them anywhere. I believe some are written to the config when FCoE is enabled..
 
I would like to know exactly what they are doing.
 
class-map type qos class-fcoe
class-map type queuing class-fcoe
match qos-group 1

[Code].....

View 5 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved