레이블이 네트워크인 게시물을 표시합니다. 모든 게시물 표시
레이블이 네트워크인 게시물을 표시합니다. 모든 게시물 표시

2020년 5월 27일 수요일

Nexus 7000 Initial Startup System Verification

http://kim10322.blog.me/150156885676



Initial Startup System Verification 

 

이번 장에서는 Nexus 7010 스위치 기본 정보 확인에 대해서 알아보도록 하겠습니다.

 

 

1. 'show version' 명령어를 이용한 Software Version 정보 확인

 

N7K-2-VDC-1# show version
Cisco Nexus Operating System (NX-OS) Software <- NX-OS 소프트웨어 정보 확인
TAC support: http://www.cisco.com/tac
Documents: http://www.cisco.com/en/US/products/ps9372/tsd_products_support_serie
s_home.html
Copyright (c) 2002-2011, Cisco Systems, Inc. All rights reserved.
The copyrights to certain works contained in this software are
owned by other third parties and used and distributed under
license. Certain components of this software are licensed under
the GNU General Public License (GPL) version 2.0 or the GNU
Lesser General Public License (LGPL) Version 2.1. A copy of each
such license is available at
http://www.opensource.org/licenses/gpl-2.0.php and
http://www.opensource.org/licenses/lgpl-2.1.php

Software
  BIOS:      version 3.22.0
  kickstart: version 6.0(1) <- NX-OS 버전 확인
  system:    version 6.0(1) <- NX-OS 버전 확인
  BIOS compile time:       02/20/10
  kickstart image file is: bootflash:///n7000-s1-kickstart.6.0.1.bin <- NX-OS 파일 저장 위치 확인
  kickstart compile time:  12/25/2020 12:00:00 [10/19/2011 12:00:34]
  system image file is:    bootflash:///n7000-s1-dk9.6.0.1.bin <- NX-OS 파일 저장 위치 확인
  system compile time:     9/25/2011 2:00:00 [10/19/2011 13:42:59]


Hardware
  cisco Nexus7000 C7010 (10 Slot) Chassis ("Supervisor module-1X")
  Intel(R) Xeon(R) CPU         with 4104304 kB of memory. <- 시스템 CPU 및 DRAM 용량 확인
  Processor Board ID JAF1606APAE

  Device name: N7K-2-VDC-1
  bootflash:    2048256 kB <- Bootflash 용량 확인
  slot0:              0 kB (expansion flash) <- Expansion Flash 용량 확인

Kernel uptime is 0 day(s), 1 hour(s), 16 minute(s), 27 second(s) <- 시스템 구동 시간 확인

Last reset at 148581 usecs after  Mon Dec 17 04:59:22 2012

  Reason: Reset Requested by CLI command reload
  System version: 6.0(1)
  Service:

plugin
  Core Plugin, Ethernet Plugin


CMP (Module 5) ok
 CMP Software
  CMP BIOS version:        02.01.05
  CMP Image version:       6.0(1) [build 6.0(0.66)]
  CMP BIOS compile time:   8/ 4/2008 19:39:40
  CMP Image compile time:  9/25/2011 2:00:00

 

 



2. 'show hardware fabric-utilization' 명령어를 이용한 패브릭 대역폭 정보 확인 

 

N7K-2-VDC-1# show hardware fabric-utilization
------------------------------------------------
Slot        Total Fabric        Utilization
              Bandwidth         Ingress % Egress %
------------------------------------------------
1             138 Gbps           0.00          0.00  <- 46G x 패프릭 3개
5              69 Gbps           0.00          0.00  <- SE - 23G x 패프릭 3개 

 

 





3. 'show boot' 명령어를 이용한 Boot 내용 정보 확인

 

N7K-2-VDC-1# show boot
Current Boot Variables:

sup-1
kickstart variable = bootflash:/n7000-s1-kickstart.6.0.1.bin
system variable = bootflash:/n7000-s1-dk9.6.0.1.bin

Boot Variables on next reload:

sup-1
kickstart variable = bootflash:/n7000-s1-kickstart.6.0.1.bin
system variable = bootflash:/n7000-s1-dk9.6.0.1.bin 

 

 

4. 'show bootflash:' 명령어를 이용한 Bootflash에 저장된 파일 정보 확인

 

N7K-2-VDC-1# dir bootflash:
        328      May 03 00:59:41 2012  MDS20120501190914247.lic <- 라이센스
        330      May 03 01:00:01 2012  MDS20120501191529773.lic <- 라이센스
       4310      Jul 04 17:28:52 2012  VDC_1_CONFIG0704
       4096      Dec 17 23:35:53 2012  lost+found/
  201314850    Feb 22 20:36:38 2012  n7000-s1-dk9.6.0.1.bin <- NX-OS
   29588480    Feb 22 20:35:11 2012  n7000-s1-kickstart.6.0.1.bin <- NX-OS
      12180     Nov 28 15:45:33 2011  setup
       4096     Aug 10 15:17:35 2011  sup-local/
       9250     Aug 10 15:22:25 2011  test
       2607     May 11 09:09:32 2012  test_config
       4377     May 11 09:41:26 2012  vdc1-config
       4096     Dec 06 07:26:09 2012  vdc_2/
       4096     Dec 17 05:30:14 2012  vdc_3/
       4096     Dec 17 06:07:42 2012  vdc_4/

Usage for bootflash://sup-local
  359104512 bytes used
 1494011904 bytes free
 1853116416 bytes total 

 

 

5. 'show license usage' 명령어를 이용한 라이센서 사용 유무 정보 확인

 

N7K-2-VDC-1# show license usage
Feature                                          Ins  Lic   Status Expiry Date Comments
                                                         Count
--------------------------------------------------------------------------------
MPLS_PKG                                     No    -   Unused               -
STORAGE-ENT                               No    -    Unused               -
ENTERPRISE_PKG                          No    -    Unused               -
FCOE-N7K-F132XP                          No    0   Unused               -
ENHANCED_LAYER2_PKG                No    -   Unused                -
SCALABLE_SERVICES_PKG             No    -   Unused                -
TRANSPORT_SERVICES_PKG           No    -   Unused                -
LAN_ADVANCED_SERVICES_PKG     Yes   -   In use Never         -   <- 현재 활성화된 라이센스
LAN_ENTERPRISE_SERVICES_PKG   Yes   -   Unused Never       -
-------------------------------------------------------------------------------- 

 

 

6. 'show license' 명령어를 이용한 라이센서 파일 정보 확인 

 

N7K-2-VDC-1# show license
MDS20120501190914247.lic: <- 라이센스
SERVER this_host ANY
VENDOR cisco
INCREMENT LAN_ADVANCED_SERVICES_PKG cisco 1.0 permanent uncounted \
        VENDOR_STRING=<LIC_SOURCE>MDS_SWIFT</LIC_SOURCE><SKU>L-N7K-ADV1K9=</SKU> \
        HOSTID=VDH=JAF1547ATMB \ <- 호스트 ID
        NOTICE="<LicFileID>20120501190914247</LicFileID><LicLineID>1</LicLineID> \
        <PAK>3111J75B9B4</PAK>" SIGN=043E0E5E79CA

MDS20120501191529773.lic: <- 라이센스
SERVER this_host ANY
VENDOR cisco
INCREMENT LAN_ENTERPRISE_SERVICES_PKG cisco 1.0 permanent uncounted \
        VENDOR_STRING=<LIC_SOURCE>MDS_SWIFT</LIC_SOURCE><SKU>L-N7K-LAN1K9=</SKU> \
        HOSTID=VDH=JAF1547ATMB \ <- 호스트 ID
        NOTICE="<LicFileID>20120501191529773</LicFileID><LicLineID>1</LicLineID> \
        <PAK>3111J6C0ACD</PAK>" SIGN=DEFE450889CC 

 

 

7. 'show inventory:' 명령어를 이용한 Nexus 7010 스위치 모듈 및 Power Supply 정보 확인  

 

N7K-2-VDC-1# show inventory
NAME: "Chassis",  DESCR: "Nexus7000 C7010 (10 Slot) Chassis "   
PID: N7K-C7010           ,  VID: V02 ,  SN: JAF1547ATMB         

NAME: "Slot 1",  DESCR: "10/100/1000 Mbps Ethernet XL Module"  
PID: N7K-M148GT-11L      ,  VID: V02 ,  SN: JAF1601ABCF         

NAME: "Slot 5",  DESCR: "Supervisor module-1X"                 
PID: N7K-SUP1            ,  VID: V14 ,  SN: JAF1606APAE         

NAME: "Slot 11",  DESCR: "Fabric card module"                   
PID: N7K-C7010-FAB-1     ,  VID: V04 ,  SN: JAF1601AKND         

NAME: "Slot 12",  DESCR: "Fabric card module"                   
PID: N7K-C7010-FAB-1     ,  VID: V04 ,  SN: JAF1601AKNQ         

NAME: "Slot 13",  DESCR: "Fabric card module"                   
PID: N7K-C7010-FAB-1     ,  VID: V04 ,  SN: JAF1601AKSF         

NAME: "Slot 33",  DESCR: "Nexus7000 C7010 (10 Slot) Chassis Power Supply"
PID: N7K-AC-6.0KW        ,  VID: V02 ,  SN: AZS155100B0         

NAME: "Slot 34",  DESCR: "Nexus7000 C7010 (10 Slot) Chassis Power Supply"
PID: N7K-AC-6.0KW        ,  VID: V02 ,  SN: AZS155100AE         

NAME: "Slot 36",  DESCR: "Nexus7000 C7010 (10 Slot) Chassis Fan Module"
PID: N7K-C7010-FAN-S     ,  VID: V01 ,  SN: FLN160102QD         

NAME: "Slot 37",  DESCR: "Nexus7000 C7010 (10 Slot) Chassis Fan Module"
PID: N7K-C7010-FAN-S     ,  VID: V01 ,  SN: FLN160102K2         

NAME: "Slot 38",  DESCR: "Nexus7000 C7010 (10 Slot) Chassis Fan Module"
PID: N7K-C7010-FAN-F     ,  VID: V02 ,  SN: FOX1543XAE4         

NAME: "Slot 39",  DESCR: "Nexus7000 C7010 (10 Slot) Chassis Fan Module"
PID: N7K-C7010-FAN-F     ,  VID: V02 ,  SN: FOX1543XAE0         

 

 

8. 'show redundancy status' 명령어를 이용한 Supervisor Redundancy 정보 확인

 

N7K-2-VDC-1# show redundancy status
Redundancy mode
---------------
      administrative:   HA
         operational:   None

This supervisor (sup-5)   <- Supervisor Engine 정보 확인
-----------------------
    Redundancy state:   Active
    Supervisor state:   Active
      Internal state:   Active with no standby

Other supervisor (sup-6) <- Supervisor Engine 정보 확인(현재 없음)
------------------------
    Redundancy state:   N/A

    Supervisor state:   N/A
      Internal state:   N/A

System start time:          Mon Dec 17 23:39:26 2012

System uptime:              0 days, 0 hours, 26 minutes, 37 seconds
Kernel uptime:              0 days, 0 hours, 30 minutes, 58 seconds
Active supervisor uptime:   0 days, 0 hours, 26 minutes, 37 seconds 

 

 

9. 'show module' 명령어를 이용한 Module Status 정보 확인

 


N7K-2-VDC-1# show module




모듈 번호  포트 개수    모듈타입                                                      모델명                                 모듈상태
Mod          Ports        Module-Type                                                Model                                 Status
------     --------    --------------------------------------- ----- --------------------------- ------------
1            48              10/100/1000 Mbps Ethernet XL Module               N7K-M148GT-11L                 ok
5             0               Supervisor module-1X                                      N7K-SUP1                           active *
6             0               Supervisor module-1X                                      N7K-SUP1                           ha-standby
7             48             1000 Mbps Optical Ethernet XL Module               N7K-M148GS-11L                 ok

Mod  Sw                  Hw
---  --------------  ------
1      6.0(1)               1.2    
5      6.0(1)               2.1    


Mod  MAC-Address(es)                               Serial-Num
---  --------------------------------------  ----------
1    f0-f7-55-0c-fc-08 to f0-f7-55-0c-fc-3c        JAF1601ABCF
5    6c-9c-ed-46-89-08 to 6c-9c-ed-46-89-10   JAF1606APAE 

 

Mod  Online Diag Status
---  ------------------
1     Pass
5     Pass 

 

Xbar Ports  Module-Type                                  Model                   Status
---  -----  ----------------------------------- ------------------ ----------
1      0       Fabric Module 1                               N7K-C7010-FAB-1    ok
2      0       Fabric Module 1                               N7K-C7010-FAB-1    ok
3      0       Fabric Module 1                               N7K-C7010-FAB-1    ok 

 

Xbar Sw                  Hw
---  --------------  ------
1     NA                   1.1    
2     NA                   1.1    
3     NA                   1.1    


Xbar MAC-Address(es)                                Serial-Num
---  --------------------------------------  ----------
1     NA                                                       JAF1601AKND
2     NA                                                       JAF1601AKNQ
3     NA                                                       JAF1601AKSF

 

* this terminal session

 

 

만약, 특정 모듈을 재부팅하려면 다음과 같은 명령어를 사용합니다.

 

N7K-2-VDC-1#reload module 1

 

또는

 

N7K-2-VDC-1(config)#poweroff module 1 

 

 

10. 'show environment' 명령어를 이용한 Power Status 정보 확인

 

N7K-2-VDC-1# show environment
Power Supply:
Voltage: 50 Volts
Power                                    Actual        Total
Supply    Model                       Output       Capacity       Status
                                             (Watts )     (Watts )
-------  -------------------  -----------  -----------  --------------
1           N7K-AC-6.0KW             314 W        3000 W        Ok       
2           N7K-AC-6.0KW             244 W        3000 W        Ok       
3           ------------                0 W           0 W            Absent   


                                             Actual       Power     
Module    Model                      Draw        Allocated       Status
                                            (Watts )     (Watts )    
-------  -------------------  -----------  -----------  --------------
1          N7K-M148GT-11L         292 W         400 W          Powered-Up
5          N7K-SUP1                   N/A           210 W           Powered-Up
6          supervisor                   N/A           210 W          Absent
Xb1      N7K-C7010-FAB-1         N/A           80 W           Powered-Up
Xb2      N7K-C7010-FAB-1         N/A           80 W           Powered-Up
Xb3      N7K-C7010-FAB-1         N/A           80 W           Powered-Up
Xb4      xbar                            N/A           80 W           Absent
Xb5      xbar                            N/A           80 W           Absent
fan1     N7K-C7010-FAN-S         67 W         720 W           Powered-Up
fan2     N7K-C7010-FAN-S         67 W         720 W           Powered-Up
fan3     N7K-C7010-FAN-F          7 W         120 W           Powered-Up
fan4     N7K-C7010-FAN-F          7 W         120 W           Powered-Up

N/A - Per module power not available


Power Usage Summary:
--------------------
Power Supply redundancy mode (configured)                  PS-Redundant
Power Supply redundancy mode (operational)                 Non-Redundant

Total Power Capacity (based on configured mode)           6000 W
Total Power of all Inputs (cumulative)                              6000 W
Total Power Output (actual draw)                                   558 W
Total Power Allocated (budget)                                      2900 W
Total Power Available for additional modules                   3100 W

Clock:
----------------------------------------------------------
Clock           Model                 Hw         Status
----------------------------------------------------------
A               Clock Module         --         NotSupported/None
B               Clock Module         --         NotSupported/None


Fan:
------------------------------------------------------
Fan                  Model                       Hw         Status
------------------------------------------------------
Fan1(sys_fan1)  N7K-C7010-FAN-S      1.1          Ok 
Fan2(sys_fan2)  N7K-C7010-FAN-S      1.1          Ok 
Fan3(fab_fan1)  N7K-C7010-FAN-F       1.1          Ok 
Fan4(fab_fan2)  N7K-C7010-FAN-F       1.1          Ok 
Fan_in_PS1       --                             --           Ok            
Fan_in_PS2       --                             --           Ok            
Fan_in_PS3       --                             --           Absent        
Fan Air Filter :  Absent


Temperature:
--------------------------------------------------------------------
Module   Sensor        MajorThresh   MinorThres   CurTemp     Status
                                   (Celsius)     (Celsius)    (Celsius)        
--------------------------------------------------------------------
1        CPU     (s4)         115             95                38         Ok            
1        Crossbar(s5)       105             95                33         Ok            
1        CTSdev4 (s9)      115             105                52         Ok            
1        CTSdev5 (s10)     115             105               48         Ok            
1        CTSdev7 (s12)     115             105               47         Ok            
1        CTSdev9 (s14)     115             105               44         Ok            
1        CTSdev10(s15)     115             105              45         Ok            
1        CTSdev11(s16)     115             105              42         Ok            
1        CTSdev12(s17)     115             105              40         Ok            
1        QEng1Sn1(s18)     115             105              44         Ok            
1        QEng1Sn2(s19)     115             105              42         Ok            
1        QEng1Sn3(s20)     115             105              41         Ok            
1        QEng1Sn4(s21)     115             105              41         Ok            
1        L2Lookup(s22)      120             110              38         Ok            
1        L3Lookup(s23)      120             110              48         Ok            
5        Intake  (s3)           60              42               16         Ok            
5        EOBC_MAC(s4)    105             95               35         Ok            
5        CPU     (s5)          105             95               28         Ok            
5        Crossbar(s6)        105             95               41         Ok            
5        Arbiter (s7)           110             100             42         Ok            
5        CTSdev1 (s8)        115             105             31         Ok            
5        InbFPGA (s9)        105             95              32         Ok            
5        QEng1Sn1(s10)     115             105             38         Ok            
5        QEng1Sn2(s11)     115             105             37         Ok            
5        QEng1Sn3(s12)     115             105             34         Ok            
5        QEng1Sn4(s13)     115             105             35         Ok            
xbar-1   Intake  (s2)         60              42              17         Ok            
xbar-1   Crossbar(s3)      105             95              38         Ok            
xbar-2   Intake  (s2)         60              42              17         Ok            
xbar-2   Crossbar(s3)      105             95              36         Ok            
xbar-3   Intake  (s2)         60              42              16         Ok            
xbar-3   Crossbar(s3)      105             95              38         Ok      

 

 

11. 'show run' 명령어를 이용한 'Running-Config' 설정 내용 확인

 

N7K-2-VDC-1# sh run

!Command: show running-config
!Time: Tue Dec 18 00:08:57 2012

version 6.0(1)
hostname N7K-2-VDC-1 <- 호스트 네임
vdc N7K-2-VDC-1 id 1 <- VDC-1
  limit-resource module-type m1 f1 m1xl
  allocate interface Ethernet1/7-31,Ethernet1/35-41,Ethernet1/45-48
  limit-resource vlan minimum 16 maximum 4094
  limit-resource monitor-session minimum 0 maximum 2
  limit-resource monitor-session-erspan-dst minimum 0 maximum 23
  limit-resource vrf minimum 2 maximum 4096
  limit-resource port-channel minimum 0 maximum 768
  limit-resource u4route-mem minimum 96 maximum 96
  limit-resource u6route-mem minimum 24 maximum 24
  limit-resource m4route-mem minimum 58 maximum 58
  limit-resource m6route-mem minimum 8 maximum 8
vdc VDC-2 id 2 <- VDC-2 
  limit-resource module-type m1 f1 m1xl
  allocate interface Ethernet1/1,Ethernet1/3,Ethernet1/32,Ethernet1/42
  boot-order 1
  limit-resource vlan minimum 16 maximum 4094
  limit-resource monitor-session minimum 0 maximum 2
  limit-resource monitor-session-erspan-dst minimum 0 maximum 23
  limit-resource vrf minimum 2 maximum 4096
  limit-resource port-channel minimum 0 maximum 768
  limit-resource u4route-mem minimum 8 maximum 8
  limit-resource u6route-mem minimum 4 maximum 4
  limit-resource m4route-mem minimum 8 maximum 8
  limit-resource m6route-mem minimum 5 maximum 5
vdc VDC-3 id 3 <- VDC-3
  limit-resource module-type m1 f1 m1xl
  allocate interface Ethernet1/2,Ethernet1/5,Ethernet1/33,Ethernet1/43
  boot-order 1
  limit-resource vlan minimum 16 maximum 2048
  limit-resource monitor-session minimum 0 maximum 2
  limit-resource monitor-session-erspan-dst minimum 0 maximum 23
  limit-resource vrf minimum 2 maximum 2048
  limit-resource port-channel minimum 0 maximum 512
  limit-resource u4route-mem minimum 8 maximum 8
  limit-resource u6route-mem minimum 4 maximum 4
  limit-resource m4route-mem minimum 3 maximum 3
  limit-resource m6route-mem minimum 5 maximum 5
vdc VDC-4 id 4 <- VDC-4 
  limit-resource module-type m1 f1 m1xl
  allocate interface Ethernet1/4,Ethernet1/6,Ethernet1/34,Ethernet1/44
  boot-order 1
  limit-resource vlan minimum 16 maximum 4094
  limit-resource monitor-session minimum 0 maximum 2
  limit-resource monitor-session-erspan-dst minimum 0 maximum 23
  limit-resource vrf minimum 2 maximum 4096
  limit-resource port-channel minimum 0 maximum 768
  limit-resource u4route-mem minimum 8 maximum 8
  limit-resource u6route-mem minimum 4 maximum 4
  limit-resource m4route-mem minimum 8 maximum 8
  limit-resource m6route-mem minimum 5 maximum 5

feature telnet
feature interface-vlan

username admin password 5 $1$sLAt/RhC$l6n7DSlWC57tnKYk/ObBd/  role network-admin <-  Username/Password
ip domain-lookup
copp profile strict
snmp-server user admin network-admin auth md5 0xbb3d7f080dc57a471ea9b0c04c1bc4fe priv 0xbb3d7f080dc57
a471ea9b0c04c1bc4fe localizedkey
rmon event 1 log trap public description FATAL(1) owner PMON@FATAL
rmon event 2 log trap public description CRITICAL(2) owner PMON@CRITICAL
rmon event 3 log trap public description ERROR(3) owner PMON@ERROR
rmon event 4 log trap public description WARNING(4) owner PMON@WARNING
rmon event 5 log trap public description INFORMATION(5) owner PMON@INFO

vrf context management
vlan 1

interface Vlan1

interface cmp-mgmt module 5 <-  Supervisor Engine I CMP 관리 포트
      ip address 10.2.1.5 255.255.255.0
      ip default-gateway 10.2.1.1
interface cmp-mgmt module 6 <- Supervisor Engine I CMP 관리 포트 
      ip address 10.2.1.6 255.255.255.0
      ip default-gateway 10.2.1.1


interface Ethernet1/7

interface Ethernet1/8

interface Ethernet1/9

interface Ethernet1/10

interface Ethernet1/11

interface Ethernet1/12

interface Ethernet1/13

interface Ethernet1/14

interface Ethernet1/15

interface Ethernet1/16

interface Ethernet1/17

interface Ethernet1/18

interface Ethernet1/19

interface Ethernet1/20

interface Ethernet1/21

interface Ethernet1/22

interface Ethernet1/23

interface Ethernet1/24

interface Ethernet1/25

interface Ethernet1/26

interface Ethernet1/27

interface Ethernet1/28

interface Ethernet1/29

interface Ethernet1/30

interface Ethernet1/31

interface Ethernet1/35

interface Ethernet1/36

interface Ethernet1/37

interface Ethernet1/38

interface Ethernet1/39

interface Ethernet1/40

interface Ethernet1/41

interface Ethernet1/45

interface Ethernet1/46

interface Ethernet1/47

interface Ethernet1/48

interface mgmt0 <- 관리용 인터페이스
  ip address 10.2.1.14/24
line console
line vty
boot kickstart bootflash:/n7000-s1-kickstart.6.0.1.bin sup-1
boot system bootflash:/n7000-s1-dk9.6.0.1.bin sup-1
boot kickstart bootflash:/n7000-s1-kickstart.6.0.1.bin sup-2
no system default switchport shutdown
 



 

기본적인 시스템 정보 확인은 Cisco IOS 장비와 다른점은 없는거 같습니다. 단, 대형 장비이기때문에 Cisco Catalyst 6500 스위치처럼 슈퍼바이저 엔진 모듈, 패브릭 모듈, 이더넷 모듈, 파워 서플라이에 대한 정보 확인만 잘하시면 될듯합니다.
 

Cisco IOS/Nexus 7000 NX-OS 비교 ( AAA 관련 명령어 )

Cisco IOS/Nexus 7000 NX-OS 비교 - AAA 관련 명령어 -

 

 

Cisco IOS CLI Cisco NX-OS CLI
Enabling LDAP
Cisco IOS Software does not support LDAP for authentication and authorization services. feature ldap
Configuring an LDAP Search Map
N/A ldap search-map ldap-map

userprofile attribute-name description search-filter "sAMAccountNAme=$userid" base-DN dc=cisco,dc=com

Configuring an LDAP Server
N/A ldap-server host 192.168.1.1 rootDN cn=N7K-device,cn=Users,dc=cisco,dc=com password 7 Qxz12345
Configuring a RADIUS Server with a Key
radius-server host 192.168.1.1 key cisco123 radius-server host 192.168.1.1 key 7 "fewhg123"
Specifying Non defualt RADIUS UDP Ports
radius-server host 192.16.1.1 auth-port 1645 acct-port 1646 radius-server 192.168.1.1 auth-port 1645 acct-port 1646
Specifying the RADIUS Timeout Value (Global)
radius-server host 192.168.1.1 timeout 10 radius-server timeout 10
Specifying the RADIUS Source Interface (Global)
ip radius source-interface loopback0 ip radius source-interface loopback0
Enabling TACACS+
Cisco IOS Software does not have the ability to enable or disable TACACS+. feature tacacs+
Configuring a TACACS+ Server with a Key
tacacs-server host 192.168.1.1 key cisco123 tacacs-server host 192.168.1.1 key 7 "fewhg123"
Specifying a Nondefualt TACACS+ TCP Port
tacacs-server host 192.168.1.1 port 85 tacacs-server host 192.168.1.1 port 85
Specifying the TACACS+ Timeout Value (Global)
tacacs-server timeout 10 tacacs-server timeout 10
Specifying the TACACS+ Source Interface (Global)
ip tacacs source-interface loopback0 ip tacacs source-interface loopback0
Configuring an AAA Server Group (LDAP)
N/A aaa group server ldap AAA-Servers

server 192.168.1.1

ldap-search-map ldap-map

Configuring an AAA Server Group (RADIUS)
aaa group server radius AAA-Servers

server 192.168.1.1

aaa group server radius AAA-Servers

server 192.168.1.1

Configuring an AAA Server Group for a VRF Instance (RADIUS)
aaa group server radius AAA-Servers

server 192.168.1.1

ip vrf forwarding management

aaa group server radius AAA-Servers

server 192.168.1.1

use-vrf management

Configuring the AAA Server Group Dead Time (RADIUS)
aaa group server radius AAA-Servers

deadtime 5

aaa group server radius AAA-Servers

deadtime 5

Configuring an AAA Server Group (TACACS+)
aaa group server tacacs+ AAA-Servers

server 192.168.1.1

aaa group server tacacs+ AAA-Servers

server 192.168.1.1

Enabling AAA Authentication with an AAA Server Group
aaa new-model

aaa authentication login default group AAA-Servers

aaa authentication login default group AAA-Servers
Enabling AAA Authorization with an AAA Server Group
aaa new-model

aaa authorization config-commands

aaa authorization commands 1 default group AAA-Servers

aaa authorization config-commands default group AAA-Servers

aaa authorization commands default group AAA-Servers

Enabling AAA Accounting with an AAA Server Group
aaa new-model

aaa accounting exec default start-stop group AAA-Servers

aaa accounting default group AAA-Servers

 

Cisco NX-OS AAA Cisco IOS Software AAA Command Description
show aaa accounting - Displays the status of AAA accounting
show aaa authentication - Displays the default and console login methods
show aaa authentication login ascii-authentication - Displays the status of ascii authentication; enabled or disabled
show aaa authentication login chap - Displays the status of the Challenge Handshake authentication protocol (CHAP); enabled or disabled
show aaa authentication login error-enable - Displays the login error message status; enabled or disabled.
show aaa authentication login mschap - Displays the status of Microsoft CHAP (MS-CHAP); enabled or disabled.
show aaa authentication login mschapv2 - Displays the status of MS-CHAPv2; enabled or disabled)
show aaa authorization - Displays the AAA authorization configuration
show aaa groups - Displays the AAA groups that are configured
show aaa users show aaa user Displays the AAA users that authenticated remotely
- - -
show accounting log - Displays the local AAA configuration accounting log
- - -
show ldap-search-map - Displays the global LDAP search map configuration
show ldap-server - Displays the LDAP server configuration for all servers
show ldap-server groups - Displays LDAP server groups
show ldap-server statistics <x.x.x.x> - Displays LDAP statistics for a specific server
- - -
show radius-server - Displays the RADIUS server configuration for all servers
show radius-server <x.x.x.x> - Displays a specific RADIUS server configuration
show radius-server directed-request - Displays the status of the directed-request feature (enabled or disabled)
show radius-server groups show radius server-group Displays RADIUS server groups
show radius-server sorted - Displays RADIUS servers sorted by name
show radius-server statistics <x.x.x.x> show radius statistics Displays RADIUS statistics for a specific server
- - -
show tacacs-server show tacacs Displays the TACACS+ server configuration for all servers
show tacacs-server <x.x.x.x> - Displays a specific TACACS+ server configuration
show tacacs-server directed-request - Displays the status of the directed-request feature (enabled or disabled)
show tacacs-server groups - Displays TACACS+ server groups
show tacacs-server sorted - Displays TACACS+ servers sorted by name
show tacacs-server statistics <x.x.x.x> - Displays TACACS+ statistics for a specific server
- - -
show user-account - Displays a list of locally configured users
show users show users Displays the users who are logged in

 

 

Cisco IOS/Nexus 7000 NX-OS 비교 (SPAN 관련 명령어)

Cisco IOS/Nexus 7000 NX-OS 비교 - SPAN 관련 명령어 -

 

 

Cisco IOS CLI Cisco NX-OS CLI
Configuring the Destination Switchport Mode
Cisco IOS Software does not require any destination port configuration. interface ethernet 2/2

switchport

switchport monitor

Configuring Destination Port Ingress Forwarding and Learning
monitor session 1 type local

destination interface gigabitethernet2/2 ingress learning

interface ethernet 2/2

switchport

switchport monitor ingress learning

Configuring a SPAN Monitor (Ethernet Source and Destination)
monitor session 1 type local

source interface gigabitethernet 2/1

destination interface gigabitethernet 2/2

no shutdown

monitor session 1

source interface ethernet 2/1 both

destination interface ethernet 2/2

no shut

Configuring a SPAN Monitor (VLAN Source)
monitor session 1 type local

source vlan 10 , 20 both

destination interface gigabitethernet 2/2

no shutdown

monitor session 1

source vlan 10,20 both

destination interface ethernet 2/2

no shut

Filtering VLANs for IEEE 802.1q Trunk Sources
interface gigabitethernet 2/1

switchport

switchport trunk encapsulation dot1q

switchport trunk allowed vlan 10-20

switchport mode trunk


monitor session 1 type local

filter vlan 15 - 20

source interface gigabitethernet 2/1

destination interface gigabitethernet 2/1

no shutdown

interface ethernet 2/1

switchport

switchport mode trunk

switchport trunk allowed vlan 10-20


monitor session 1

source interface ethernet 2/1 both

destination interface ethernet 2/2

filter vlan 15-20

no shut

Configuring a SPAN Monitor (CPU Source)
monitor session 1 type local

source cpu rp rx

destination interface gigabitethernet 2/2

no shutdown

monitor session 1

source interface sup-eth0 rx

destination interface ethernet 2/2

no shut

Configuring an ERSPAN Monitor (Source)
monitor session 1 type erspan-source

source interface gigabitethernet 2/2

destination

ip address 192.168.2.1

origin ip address 192.168.1.1

erspan-id 1

no shutdown

monitor erspan origin ip-address 192.168.1.1 global


monitor session 1 type erspan-source

destination ip 192.168.2.1

erspan-id 1

vrf default

source interface ethernet 1/26 both

no shut

Configuring an ERSPAN Monitor (Destination)
monitor session 1 type erspan-destination

destination interface gigabitethernet 1/26

source

ip address 192.168.2.1

erspan-d 1

no shutdown

interface ethernet 1/26

switchport

switchport monitor

 

monitor session 1 type erspan-destination

source ip 192.168.2.1

destination interface ethernet 1/26

erspan-id 1

vrf default

no shut

 

Cisco NX-OS SPAN Cisco IOS Software SPAN Command Description
show interface show interface Displays interface status and characteristics
- - -
show monitor session <#> show monitor session <#> Displays a specific monitor session
show monitor session <#> brief - Displays brief information for a specific monitor session
show monitor session all show monitor session all Displays all SPAN and monitor sessions
show monitor session all brief - Displays brief information for all monitor sessions
show monitor range <#-#> show monitor range <#-#> Displays a range of specific monitor sessions
show monitor range <#-#> brief - Displays brief information for a range of specific monitor sessions

 

 

Cisco IOS/Nexus 7000 NX-OS 비교 ( Netflow 관련 명령어 )

Cisco IOS/Nexus 7000 NX-OS 비교 - Netflow 관련 명령어 -

 

 

Cisco IOS CLI Cisco NX-OS CLI
Enabling the NetFlow Feature
Cisco IOS Software does not have the ability to enable or disable NetFlow. feature netflow
Configuring a Layer-3 NetFlow Flow Record (Custom)
Cisco IOS Software does not have the ability to create custom layer-3 NetFlow records. A system wide flow mask is defined. The following example uses interface-full.


mls netflow interface

mls flow ip interface-full

mls nde sender version 5

flow record Netflow-Record-1

description Custom-Flow-Record

match ipv4 source address

match ipv4 destination address

match transport destination-port

collect counter bytes

collect counter packets

Configuring a Layer-2 NetFlow Flow Record (Custom)
Cisco IOS Software does not have the ability to create custom layer-2 NetFlow records to capture MAC address information or reference it as a key field. flow record Netflow-Record-1

description Layer-2-Flow-Record

match datalink mac source-address

match datalink mac destination-address

collect counter bytes

collect counter packets

Configuring a NetFlow Flow Export
ip flow-export source GigabitEthernet2/2

ip flow-export version 9

ip flow-export destination 192.168.11.2 2000

flow exporter Netflow-Exporter-1

description Production-Netflow-Exporter

destination 192.168.11.2

source Ethernet2/2

version 9

Configuring a NetFlow Monitor with a Custom Record
Cisco IOS Software does not have the ability to create flow monitors that associate NetFlow records to NetFlow exporters. flow monitor Netflow-Monitor-1

description Applied Inbound-Eth-1/1

record Netflow-Record-1

exporter Netflow-Exporter-1

Configuring a NetFlow Monitor with an Original Record
Cisco IOS Software does not have the ability to create flow monitors that associate NetFlow records to NetFlow exporters. flow monitor Netflow-Monitor-2

description Use Predefined “Original-Netflow-Record”

record netflow-original

exporter Netflow-Exporter-1

Adjusting NetFlow Timers
mls aging fast

mls aging long 120

mls aging normal 32

flow timeout active 120

flow timeout inactive 32

flow timeout fast 32 threshold 100

flow timeout session

flow timeout aggressive threshold 75

Configuring a NetFlow Sampler
mls sampling packet-based 64 8000

mls flow int-full

mls nde sender version 5

sampler NF-Sampler-1

description Sampler-for-high-traffic-environment

mode 1 out-of 1000

Applying a NetFlow Monitor to an Interface
interface gigabitethernet 1/1

ip flow ingress

interface ethernet 1/1

ip flow monitor Netflow-Monitor-1 input

Applying a NetFlow Monitor to a VLAN
ip flow ingress layer2-switched vlan 10 vlan configuration 10

ip flow monitor Netflow-Monitor input

Applying a Layer-2 NetFlow Monitor an Interface
Cisco IOS Software does not have the ability to apply a layer-2 flow monitor to an interface and specify the input or output direction. Cisco IOS software uses a global command to specify the VLAN for which only ingress bridged-traffic is captured. See the previous example. interface etherent 1/1

switchport

switchport access vlan 100

mac packet-classify

layer2-switched flow monitor Netflow-Monitor-L2 input

Applying a NetFlow Sampler to an Interface
interface gigabitethernet1/1

mls netflow sampling

interface ethernet 1/1

ip flow monitor Netflow-Monitor-1 input sampler NF-Sampler-1

Applying a NetFlow Sampler to a VLAN
Cisco IOS Software does not have the ability to apply a sampler to a VLAN. vlan configuration 10

ip flow monitor Netflow-Monitor-1 input sampler NF-Sampler-1

Applying a Layer-2 NetFlow Sampler an Interface
Cisco IOS Software does not have the ability to apply a layer-2 sampler to an interface. interface etherent 1/1

switchport

switchport access vlan 100

mac packet-classify

layer2-switched flow monitor Netflow-Monitor-L2 input sampler NF-Sampler-1

 

Cisco NX-OS NetFlow Cisco IOS Software NetFlow Command Description
show flow exporter show mls nde Displays the configured exporter maps
show flow interface - Displays interfaces configured for NetFlow
show flow monitor - Displays information about monitor maps
show flow record - Displays information about record maps
show flow timeout - Displays the NetFlow timeout value
show hardware flow aging show mls netflow aging Displays the NetFlow table aging timeout value
show hardware flow entry show mls netflow ip flow Displays flow-specific information
show hardware flow ip show mls netflow ip Displays the IP NetFlow table
show hardware flow l2 - Displays the Layer-2 NetFlow table
show hardware flow sampler show mls sampling Displays the NetFlow sampling configuration
show hardware flow utilization module show mls netflow table summary Displays NetFlow table utilization per module
show sampler show flow-sampler Displays information about sampler maps