Cisco Switching/Routing :: Limiting Outgoing Traffic On Single L2 Port On Nexus 7000 1GB

Aug 4, 2012

I am trying to limit the incoming and outgoing traffic on a l2 port to 8mbps for a ip subnet within the nexus 7000. The port is connected to my ISP router which has a bandwidth of 20mbps.Policing won't work on a l2 Port and shaping cannot be applied on a port level. url...I have been reading thru the qos guide for nexus release v6 and have problems understanding the different queues.

Cisco Switching/Routing :: Multiple VPC Domains On A Single Nexus 7000?

Nov 13, 2011

I have a customer with three rooms where teh access layer aggregation switches are run back to.
Access Switch Stack A -> room 1 + room 2
Access Switch Stack B -> room 2 + room 3
Is it possible to have three Nexus 7000s ie one in each room (1,2 and 3) and have them setup like this:
Nexus 7000#1     vPC domain 1
Nexus 7000#2     vPC domain 1 + vPC domain 2
Nexus 7000#3     vPC domain 2
Thus gving all access switch stacks redundant links to the core withouit spanning tree.
I know its not ideal but its a campus site and thats how the existing fibre runs go.

Cisco Switching/Routing :: QOS For VOIP Traffic On Nexus 7000

Mar 4, 2012

regarding QOS on Nexus 7000. Our Nexus 7000's form a collapsed distribution/core layer, our access layer switches are are a mixture of Cisco 3750 & Cisco 4507. 3750 switches will connect to Nexus switches via 1Gb uplink, 4507 switches will connect via 10Gb uplinks. Each Nexus will be connected via 20Gb port channel, all servers connect to the Nexus switches via 1Gb links. We're implementing a new telephone system soon which will be using VOIP so I need to configure the switches to perform QOS. The IP phones will mark the RTP traffic with DSCP value EF and call signaling traffic CS3. I'm fine configuring qos on the access layer switches, its just the Nexus switches which I'm not sure about.
Do I actually need to configure any QOS parameters on the Nexus switches so they will prioritise the VOIP traffic. If my understanding  the Nexus switches will trust the DSCP values and assign the traffic to the relevent queues?
Just for information VOIP is the only traffic I will be marking QOS values

Cisco Switching/Routing :: Nexus 7000 - Traffic Blackholing On Overlapping STP And VPC (CAM Table Related)

Aug 30, 2012

I have run into a very strange problem while doing pre-deployment vPC/STP testing in the lab with a pair of Nexus 7000s.
The basic configuration is as follows:
2x Nexus 7000 VDCs (ver 6.0(4)) are configured as vPC peers and connected with a vPC peer-link (redundant on different 10G blades) and a vPC peer-keepalive link. The switches also act as HSRP and EIGRP routers. The N7K-A switch is nominally configured as STP root and HSRP prime for all VLANs, N7K-B switch is STP backup root and HSRP secondary. STP version is PV-RSTP+. As it stands now STP root and vPC prime are on different switches, STP root is on N7K-A and vPC prime is on N7K-B.
3x Layer-2 access switches (3750-1, 3750-2, 3560-1) are configured as access switches and connected to the Nexus 7Ks with a 1G uplinks in V-pattern.
3750-1 and 3560-1 are configured for vPC as Port-Channel10 and Port-Channel12 respectively. 3750-2 is configured for STP. Vlan 35 is shared between all three switches and is enabled on the vPC peer-link (overlapping vPC and STP domains). The downlink port to the STP-only 3750-2 on N7Ks is configured as "vpc orphan suspend".
Everything seems to work fine and pings on VLAN 35  between access switches (that have mgmt interfaces in VLAN35) recover rapidly after failures. However, if I break the vpc peer-link the ping between the two vPC switches 3750-1 and 3560-1 stops. Moreover, this appears to be sporadic in nature with some vpc peer-link failure attempts recreating the problem and some not. Sometimes the problem manifests itself when the peer-link is brought back up rather than taken down.
After doing a bit of troubleshooting, I have isolated the problem to MAC address blackholing. Basically when the peer link is taken down, MAC Address table on the vPC primary switch, N7K-B, (I believe during vPC convergence) forces the traffic destined from 3750-1 to 3560-1 through the STP only switch 3750-2, which apparently goes through the RSTP convergence and enables its alternate link to N7K-B before vPC has finished its convergence. After vPC convergence is finished the path through the STP-only access layer switch 3750-2 no longer exists, as vPC will take down all vPC ports and suspend orphan ports on the vPC secondary switch (N7K-A). However the MAC Address table on N7K-B still points through the 3750-2 access layer switch instead of directly through Port-Channel 12 on N7K-B and thus creates a traffic blackhole. Issuing a ping or bouncing SVI interfaces on N7K-B fixes the problem.

Cisco Switching/Routing :: Nexus 7000 Voice Traffic Across Trunk Terminated On F1 Module

Oct 31, 2012

 I want to prioritize egress voice traffic across a trunk terminated on an F1 module,  N7K-F132XP-15. I am unsure about the setup; according to the "show interface capabilities" F1 interfaces support 8 egress queues, while the Nexus QoS documentation provides configuration referencing 4 queues. In addition, I am not clear about the relevance of network-qos on F1 queueing setup.

Cisco Switching/Routing :: Port Allocation In Nexus 7000

Mar 4, 2013

I have one cisco Nexus 7000 with version 6.1(2).I created 3 VDC
I have configured 1 - 45 ports for Core and 46 - 48 ports for Security.Now I am not using the VDC Security and I tried to move the assigned ports 46 - 48 from Security to ADMIN.Switch accepted the command .But the ports are not visible on ADMIN VDC.Now it is not showing on Security VDC also. I need this ports in ADMIN VDC

Cisco Switching/Routing :: Nexus 7000 Vlans Added To Port-profile Never Got Propagated

Dec 2, 2011

I'm running a couple of nexus 7000 to aggregate a building full of 3750Xs.In the past few weeks I have noticed that the vlans I added to the port-profile never got propagated.So I looked at port-profile sync information and here is what comes up: [code] Why the commands are getting cached?

Cisco Switching/Routing :: Nexus 7000 - (service Policy Type Queuing Output) On Port-channel?

Jan 24, 2013

We are planning to implement the following policy map for egress traffic on an Nexus 7000:
policy-map type queuing dd-1p3q1t-8e-out-10G    class type queuing 1p3q1t-8e-out-pq1      priority level 1      shape percent 10     class type queuing 1p3q1t-8e-out-q2        bandwidth remaining percent 5    class type queuing 1p3q1t-8e-out-q3        bandwidth remaining percent 5    class type queuing 1p3q1t-8e-out-q-default        bandwidth remaining percent 90
We are using two N7K's to which is one N5K connected through a vPC. From the N5k we use a port-channel with 4 * 10G. Two of this four ports are connected to on N7K and the other two are connected to the other N7K. On the n/K's we are using vPC.
My question now are:
1. Where i have to connect the policy map? To the port-channel or on each physical interface?

2. When i have to connect this policy to the port-channel, how does i have to set the shape percent, when i would like to reserve 10% from the 40G?    Does i have to set the shape value to 5% on each N7K because vPC?

Protocols / Routing :: Using Port 1 - 80 For All Outgoing Traffic Possible With Application?

Oct 9, 2012

I want to be able to use port 1-80 for all outgoing traffic. I have a VPS outside my home, which can redirect the packets to the prober ports.Is it possible with an application on the computer and VPS? Or is it impossible?

Cisco Switching/Routing :: Nexus 7000 With Fabric Extenders Nexus 2000?

Mar 15, 2013

I have been tasked to replace the existing Cat 6500 and 3750 switches by Nexus 7000 and Nexus 2000.I was told initially my boss plans to get 2 x Nexus 7000 and then eventually blow up to 4 x Nexus 7000s.For Nexus, is there a list of tasks / points that i need to consider for building the initial design?
Can i just link the Nexus 7000 like the following?
N7k-A    =========   N7k-B
|                                   |           
lots of N2ks               lots of N2ks

Cisco Switching/Routing :: Unexpected Traffic On Nexus 5000 Trunk Port?

Feb 6, 2013

So I took a laptop with wireshark and plugged it into a nexus 5000 port that is configured as a trunk with 3 vlans allowed on it. The laptop was seeing all kinds of traffic on the wire, most of it was not involving my laptop.
For example: Server A VLAN 10=  Server B VLAN 20= and wireshark laptop is plugged into a trunk port which is allowing those vlan's. The vlan's are routable. is seeing the entire conversation when backs up even though it has no reason to see it. It is as if the trunk is spanning traffic to the laptop port. No span is setup however. It's really weird. This is not just broadcast traffic, but actual tcp taffic between Server A and B. Why would a trunk port see traffic between 2 other servers talking to each other on the vlan.
Trunk port configuration below:
Interface Ethernet 141/1/3 
switchport mode trunk
switchport trunk allowed vlan 10, 20

Cisco Switching/Routing :: Nexus 7000 Vrf Not Enabled?

Dec 9, 2012

Should I install any special license to enable vrf within Nexus 7000 VDC? I observed that vrf routing instance is not enabled in the VDC.

Cisco Switching/Routing :: NTP Authentication On Nexus 7000?

Mar 3, 2013

I am configuring NTP on a new Cisco Nexus 7000 running version 6.1(2). NTP is working properly between the access switches and Nexus, however when configuring Authentication, NTP is not working anymore.
Nexus 7K server
ntp server x.x.x.x
ntp peer q.q.q.q
ntp server e.e.e.e
ntp server r.r.r.r
ntp source-interface  Vlanx

why NTP authentication is not working !!!!! on Nexus 7000

Cisco Switching/Routing :: FIB Inconsistency On Nexus 7000

Aug 3, 2011

On a 7K (5.0(2)), I have a situation where the FIB and RIB are out of sync.  I'm not sure it's causing a problem, but it's been implicated in some weird packet loss issues.  It seems like it could cause network issues if you had two routes in the RIB, only one in the FIB, and then you lost the single path in the FIB. How the RIB/FIB gets out of sequence, how to proactively know about it (nothing in the logs here), and whether or not this is a big deal or a red herring?
Here's sample output that illustrates the RIB and FIB being out of sequence.
ROUTER1# show ip route
IP Route Table for VRF "default"
'*' denotes best ucast next-hop


Cisco Switching/Routing :: Limiting Traffic Rates On 3560 Switchports

Jul 19, 2012

I have a 3560 switch where I have 4 ports connected, one is to our WAN provider - 10Mbps and the other three are connected to different customers who I want to get an equal share of the 10Mbps bandwidth.I'm fairly clued up about configuring modular QoS but I'm being thrown by the fact that you can't apply a service-policy outbound on the ethernet ports.

Cisco Switching/Routing :: Support For FeX 2232TM In Nexus 7000?

Feb 2, 2012

We recently purchased a pair of 2232TM Fabric eXtenders just to find out that our Nexus 7000 does not support it. Will there be support for the 2232TM FeX in Nexus 7000 any time soon?

Cisco Switching/Routing :: Nexus 7000 OTV With F1 Line Cards?

Jul 17, 2012

I have two data centres connected via a L2 DWDM, my manager wants to look into using OTV to get rid of the layer 2 broadcasting issues.
Problem is the DWDM is 1000BaseSX, which is only supported on the N7K-F132XP-15.   (and the N7K-M148GS-11 but that doesn't support FCOE, so many bloody caveats). From what I can gather OTV is not supported on the N7K-F132XP-15.
Is it possible to terminate the DWDM on the F1 card & loop another port from the F1 to a port on the N7K-M148GT-11 & run OTV on the M1????
Either using VDCs or just an isolated VLAN on the F1. Is there any better way to do this? Hardware has not yet been purchased.

Cisco Switching/Routing :: Nexus 7000 Vdc Vlan Configuration?

Dec 9, 2012

I am seeing an issue that after deleting/recreating one of the VDC in Nexus 7K, VLAN is not been able to be configured within the VDC although it is not actually a reserved VLAN. Could it be anything missing in the license installation? the version of the image is NX-OS 6.1.2
StorageVDC(config)# vlan 100
invalid vlans (reserved values) at '^' marker.

Cisco Switching/Routing :: Nexus 7000 Keep Alive Link For Vpc?

May 5, 2013

We setup two n7K as core switches in our network. We configure VPc peer link as well successfully. We are using mgmt interface of supervisors as a peer keep alive interface, so what happen when this keep alive gets down? Are we loss Vpc peer link between both nexus 7 K?

Cisco Switching/Routing :: Nexus 7000 QoS Marking For Both DSCP And COS

Jan 29, 2012

I have a pair of Nexus 7K's running 5.1(3). I have a handful of edge devices that I need to mark ingress traffic, and need to mark both DSCP and CoS. Right now, I have a working config that marks DSCP appropriately.While that works dor DSCP, the MQC will not allow me to mark both DSCP and COS in the same class, and unlike IOS, it appears that Nexus does not have a default DSCP-to-COS mapping. My understanding is this can be solved using table maps, but I don't see how that can solve my problem in this specific scenario (it appears I can do marking or table-map mutation, but not both?). How I can accomplish both?

Cisco Switching/Routing :: Nexus 7000 Cannot Get AAA Authentication To Work

Dec 5, 2011

I cannot get the AAA tacacs+ authentication to work on my Nexus 7000.

Cisco Switching/Routing :: Nexus 7000 To Know Ambient Temperature

Nov 2, 2012

I need to know how is the ambient temperature for the Nexus 7000 switches to plan a new datacenter. In the datasheet I found the following information regarding this topic:"GR-63-CORE Network Equipment Building Standards (NEBS) specification published by Telcordia Technologies in Section 4.1.2". How are the specification for temperature in this standard?

Cisco Switching/Routing :: Nexus 7000 Bandwidth Control

Oct 14, 2012

On Nexus 7000s I want to limit bandwidth of particular IP. I can do this using proper configuratio of IP ACL, policy map and class map. But what if I dont have information on interface?  Can I apply bandwidth control for particular IP without knowing the interface?

Cisco Switching/Routing :: Nexus 7000 And 2000 FEX Support With VPC

Apr 20, 2012

if vPC is supported between a single 2232PP FEX and two 7000 switches running 6.0(1)? I have been researching this for an implementation I am doing for a client and was able to determine it was not supported with earlier versions of 5.0 when the FEX is connected via vPC as I described above, but I can't find anything related to version 6.0(1). I have done this for other clients with 5000 and 2000 switches, but I don't have too much experience with 7000 switches.

Cisco Switching/Routing :: Nexus 7000 Log Entry Explanation?

Dec 4, 2011

I have some error messages in the Nexus 7000 log, after searching i cannot find an adequate explanation, pretty much the only thing i can find is below and i don’t think it is very relevant to my situation. The device is in production and so reloading and pulling card willy nilly is the last resort.

IOS version = 5.1(2)
Log messages=
2011 Dec  2 14:52:35 IAS01LVSWIPC01 %OC_USD-SLOT8-2-RF_CRC: OC2 received packets with CRC error from MOD 6 through XBAR slot 1/inst 1 and slot 2/inst 1 and slot 3/inst 1


Cisco Switching/Routing :: Nexus 7000 / Configuring Jumbo MTU?

Nov 17, 2011

I have a Nexus 7000 plus 6 boxes NX2000 on backbone.I have configured on 7000 :
conf t
system jumbomtu 9000
exitERROR: Ethernet111/1/1: requested config change not allowed
ERROR: Ethernet122/1/48: requested config change not allowed
1/111/14 is a NX2000 port conf tinterface ethernet 1/111/14 switchport mtu 9000 exit

I have gotten this message : Error: MTU cannot be configured on satellite port(s) - Eth122/1/11 ?I have tried on a NX7000 TP port:ERROR: Ethernet10/45: MTU on L2 interfaces can only be set to default or system-jumboMTU ?Does JUMBOMTU configuration can be done only when there are no NX2000 configured ?

Cisco Switching/Routing :: Nexus 7000 Span Limitation

Apr 18, 2012

I've learned recently that the Nexus 7000 only allows the configuration of a maximum of 2 Monitor sessions for spanning traffic. I only have one monitor session left and I need to do the following. 2 Core Nexus 7000 boxes with 2 different traffic probes/sniffers to each nexus( eg Sniffer 1 connects to Switch A on interface eth 1 and to Switch B on eth 1 ; Sniffer 2 connects to Switch A on eth 2 and to Switch B on eth 2.) My plan was to setup a standard session with multiple sources and destinations then on the interfaces connecting to the sniffers run a trunk and do 'sw trunk allowed xxxxx' and filter what I need to go to each sniffer box. However I've recently found out that some of my source traffic is coming from Port-Channel interfaces. Is there a way I can get around this and still do the filtering within only 1 monitor session ?

Cisco Switching/Routing :: How To Configure IP Helper In Nexus 7000

Jan 30, 2011

I'm interested to know whether we can configure ip helper in nexus 7000?

Cisco Switching/Routing :: Nexus 5500 / 7000 - Dependencies On VTP

Jun 26, 2012

Are there any dependencies on VTP on the Nexus platforms like the 5500 or 7000? In IOS P V LAN required VTP Transparent mode however I cannot find any reference to this for the Nexus platform. Are there any other features that would require the use of VTP? By default VTP is turned off on nexus and has to be enabled with the feature command so is there any benefit to running VTP in transparent mode vs off?

Cisco Switching/Routing :: Dedicated Mode On Nexus 7000?

Feb 22, 2012

i like to configure two ports in dedicated mode (eth4/1 + eth4/2).the ports are on a modultype "N7K-F132XP-15" (32x10GE)all ports are in one vdc membership (default configuration)
ive tried this for port eth 4/1:
bciscon7k01(config)# int eth 4/1,eth 4/3,eth 4/5,eth 4/7
bciscon7k01(config-if-range)# shut
bciscon7k01(config-if-range)# int eth 4/1
bciscon7k01(config-if)# rate-mode dedicated
after that i get the following message:"Ignoring command for interface Ethernet4/1 as rate-mode is fixed." i didn't find any documentation to this error message.whats wrong in my configuration?

Cisco Switching/Routing :: Nexus 7000 Errors Every 30 Seconds

Feb 3, 2013

I have a Nexus 7000 pair with Etherchannels connecting to various access switches. 2960's and 3750's.The access switches channel 2 ports together. LACP active mode. One link goes to one Nexus and one to the other. Those connections are a portchannel with vpc configured.Every 30 seconds on every interface connecting to one Nexus I see a FCS error. The errors increment at the same time every 30 seconds. Only on one port. If I shutdown that link and keep the channel up on the other link the errors move. No shut the interface and they move back.This must surely be some Nexus generated packet that the access switch does not recognize/ what is likely to be getting sent at 30 sec intervals to all Channel members on one link ?

Cisco Switching/Routing :: Nexus 2000 To 7000 Connection

Jan 13, 2013

If the latest release of NX-OS 6.1.2 supports dual homing a Nexus 2000 to a pair of Nexus 7000s (F2 Module)? The document does state something about support for vPC+ but is not really clear about it.

Cisco Switching/Routing :: SFP Showing Unknown On Nexus 7000

Mar 9, 2013

I have couple of SFP and most of them are working fine except this:-
Nexus7000# show interface ethernet 6/31 transceiver details

a) What is the reason this is not getting recognized?
b) Is theSFP SFBR-5766PZ-CS1 plug and play in the 7000 Nexus?

