Cisco Nexus 5000 Series NX-OS
Software Configuration Guide
Release 4.0(1a)N2(1)
June 2009
Americas Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 527-088
3
Text Part Number: OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL
STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT
WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT
SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE
OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH
ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT
LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF
DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING,
WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
CCDE, CCENT, Cisco Eos, Cisco HealthPresence, the Cisco logo, Cisco Lumin, Cisco Nexus, Cisco StadiumVision, Cisco TelePresence, Cisco WebEx, DCE, and Welcome
to the Human Network are trademarks; Changing the Way We Work, Live, Play, and Learn and Cisco Store are service marks; and Access Registrar, Aironet, AsyncOS,
Bringing the Meeting To You, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, CCSP, CCVP, Cisco, the Cisco Certified Internetwork Expert logo, Cisco IOS,
Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Collaboration Without Limitation, EtherFast, EtherSwitch, Event Center, Fast Step,
Follow Me Browsing, FormShare, GigaDrive, HomeLink, Internet Quotient, IOS, iPhone, iQuick Study, IronPort, the IronPort logo, LightStream, Linksys, MediaTone,
MeetingPlace, MeetingPlace Chime Sound, MGX, Networkers, Networking Academy, Network Registrar, PCNow, PIX, PowerPanels, ProConnect, ScriptShare, SenderBase,
SMARTnet, Spectrum Expert, StackWise, The Fastest Way to Increase Your Internet Quotient, TransPath, WebEx, and the WebEx logo are registered trademarks of
Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.
All other trademarks mentioned in this document or website are the property of their respective owners. The use of the word partner does not imply a partnership relationship
between Cisco and any other company. (0812R)
Any Internet Protocol (IP) addresses used in this document are not intended to be actual addresses. Any examples, command display output, and figures included in the
document are shown for illustrative purposes only. Any use of actual IP addresses in illustrative content is unintentional and coincidental.
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
Listing Commands and Syntax2-7
Entering Command Sequences2-7
Undoing or Reverting to Default Values or Conditions2-7
Using Keyboard Shortcuts2-8
Using CLI Variables2-9
User-Defined Persistent CLI Variables2-9
Using Command Aliases2-10
Defining Command Aliases2-11
Command Scripts2-11
Executing Commands Specified in a Script2-11
Using CLI Variables in Scripts2-12
Setting the Delay Time2-13
CHAPTER
ii
3Configuring the Switch3-1
Image Files on the Switch3-1
Starting the Switch3-2
Boot Sequence3-2
Console Settings3-3
Upgrading the Switch3-4
Downgrading from a Higher Release3-6
Initial Configuration3-7
Configuration Prerequisites3-7
Initial Setup3-8
Preparing to Configure the Switch3-8
Default Login3-9
Configuring the Switch3-9
Changing the Initial Configuration3-12
Accessing the Switch3-12
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Additional Switch Configuration3-12
Assigning a Switch Name3-13
Configuring Date, Time, and Time Zone3-13
Adjusting for Daylight Saving Time or Summer Time3-14
NTP Configuration3-15
About NTP3-15
NTP Configuration Guidelines3-16
Configuring NTP3-17
NTP CFS Distribution3-17
Management Interface Configuration3-19
About the mgmt0 Interface3-19
Configuring the Management Interface3-20
Displaying Management Interface Configuration3-20
Shutting Down the Management Interface3-21
Managing the Switch Configuration3-21
Displaying the Switch Configuration3-21
Saving a Configuration3-21
Clearing a Configuration3-22
Contents
CHAPTER
Using Switch File Systems3-22
Setting the Current Directory3-22
Displaying the Current Directory3-23
Listing the Files in a Directory3-23
Creating a Directory3-23
Deleting an Existing Directory3-23
Moving Files3-24
Copying Files3-24
Deleting Files3-24
Displaying File Contents3-25
Saving Command Output to a File3-25
Compressing and Uncompressing Files3-25
4Managing Licenses4-1
Licensing Terminology4-1
Licensing Model4-2
License Installation4-3
Obtaining a Factory-Installed License4-3
Performing a Manual Installation4-4
Obtaining the License Key File 4-4
Installing the License Key File4-4
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
iii
Contents
Send feedback to nx5000-docfeedback@cisco.com
Backing Up License Files4-6
Identifying License Features in Use4-6
Uninstalling Licenses4-6
Updating Licenses4-8
Grace Period Alerts4-8
License Transfers Between Switches4-9
Verifying the License Configuration4-10
LAN Switching
CHAPTER
5Configuring Ethernet Interfaces5-1
Information About Ethernet Interfaces5-1
About the Interface Command5-1
About the Unidirectional Link Detection Parameter5-2
About Interface Speed5-4
About the Cisco Discovery Protocol5-4
About the Debounce Timer Parameters5-4
About MTU Configuration5-5
Configuring Ethernet Interfaces5-5
Configuring the UDLD Mode5-5
Configuring Interface Speed5-6
Configuring the Cisco Discovery Protocol5-7
Configuring the Debounce Timer5-8
Configuring the Description Parameter5-9
Disabling and Restarting Ethernet Interfaces5-9
Displaying Interface Information5-10
Default Physical Ethernet Settings5-12
CHAPTER
6Configuring VLANs6-1
Information About VLANs6-1
Understanding VLANs6-1
Understanding VLAN Ranges6-2
Creating, Deleting, and Modifying VLANs6-3
Configuring a VLAN6-4
Creating and Deleting a VLAN6-4
Entering the VLAN Submode and Configuring the VLAN6-5
Adding Ports to a VLAN6-6
Verifying VLAN Configuration6-6
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
iv
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Contents
CHAPTER
CHAPTER
7Configuring Private VLANs7-1
About Private VLANs7-1
Primary and Secondary VLANs in Private VLANs7-2
Understanding Private VLAN Ports7-3
Understanding Broadcast Traffic in Private VLANs7-5
Understanding Private VLAN Port Isolation7-5
Configuring a Private VLAN7-5
Configuration Guidelines for Private VLANs7-6
Enabling Private VLANs7-6
Configuring a VLAN as a Private VLAN7-7
Associating Secondary VLANs with a Primary Private VLAN7-7
Configuring an Interface as a Private VLAN Host Port7-8
Configuring an Interface as a Private VLAN Promiscuous Port7-9
Verifying Private VLAN Configuration7-10
8Configuring Rapid PVST+8-1
Information About Rapid PVST+8-1
Understanding STP8-2
Understanding Rapid PVST+8-6
Rapid PVST+ and IEEE 802.1Q Trunks8-16
Rapid PVST+ Interoperation with Legacy 802.1D STP8-16
Rapid PVST+ Interoperation with 802.1s MST8-17
CHAPTER
OL-16597-01
Configuring Rapid PVST+8-17
Enabling Rapid PVST+8-17
Enabling Rapid PVST+ per VLAN8-18
Configuring the Root Bridge ID8-19
Configuring a Secondary Root Bridge8-20
Configuring the Rapid PVST+ Port Priority8-21
Configuring the Rapid PVST+ Pathcost Method and Port Cost8-21
Configuring the Rapid PVST+ Bridge Priority of a VLAN8-22
Configuring the Rapid PVST+ Hello Time for a VLAN8-23
Configuring the Rapid PVST+ Forward Delay Time for a VLAN8-23
Configuring the Rapid PVST+ Maximum Age Time for a VLAN8-23
Specifying the Link Type8-24
Restarting the Protocol8-25
Verifying Rapid PVST+ Configurations8-25
9Configuring MST9-1
Information About MST9-1
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
v
Contents
Send feedback to nx5000-docfeedback@cisco.com
MST Overview9-2
MST Regions9-2
MST BPDUs9-3
MST Configuration Information9-3
IST, CIST, and CST9-4
Hop Count9-7
Boundary Ports9-7
Detecting Unidirectional Link Failure9-8
Port Cost and Port Priority9-8
Interoperability with IEEE 802.1D9-9
Interoperability with Rapid PVST+: Understanding PVST Simulation9-9
Configuring MST9-9
MST Configuration Guidelines9-10
Enabling MST9-10
Entering MST Configuration Mode9-11
Specifying the MST Name9-12
Specifying the MST Configuration Revision Number9-13
Specifying the Configuration on an MST Region9-13
Mapping and Unmapping VLANs to MST Instances9-15
Mapping Secondary VLANs to Same MSTI as Primary VLANs for Private VLANs9-16
Configuring the Root Bridge9-16
Configuring a Secondary Root Bridge9-17
Configuring the Port Priority9-18
Configuring the Port Cost9-19
Configuring the Switch Priority9-20
Configuring the Hello Time9-21
Configuring the Forwarding-Delay Time9-22
Configuring the Maximum-Aging Time9-22
Configuring the Maximum-Hop Count9-22
Configuring PVST Simulation Globally9-23
Configuring PVST Simulation Per Port9-23
Specifying the Link Type9-24
Restarting the Protocol9-25
Verifying MST Configurations9-25
CHAPTER
10Configuring STP Extensions10-1
Information About STP Extensions10-1
Understanding STP Port Types10-2
Understanding Bridge Assurance10-2
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
STP Extensions Configuration Guidelines10-5
Configuring Spanning Tree Port Types Globally10-6
Configuring Spanning Tree Edge Ports on Specified Interfaces10-7
Configuring Spanning Tree Network Ports on Specified Interfaces10-7
Enabling BPDU Guard Globally10-8
Enabling BPDU Guard on Specified Interfaces10-9
Enabling BPDU Filtering Globally10-10
Enabling BPDU Filtering on Specified Interfaces10-10
Enabling Loop Guard Globally10-12
Enabling Loop Guard or Root Guard on Specified Interfaces10-12
Contents
CHAPTER
Verifying STP Extension Configuration10-13
11Configuring EtherChannels11-1
Information About EtherChannels11-1
Understanding EtherChannels11-2
Compatibility Requirements11-2
Load Balancing Using EtherChannels11-3
Understanding LACP11-4
Configuring EtherChannels11-7
Creating an EtherChannel11-7
Adding a Port to an EtherChannel11-8
Configuring Load Balancing Using EtherChannels11-9
Enabling LACP11-10
Configuring Port-Channel Port Modes11-10
Configuring the LACP System Priority and System ID11-11
Configuring the LACP Port Priority11-11
Verifying Port-Channel Configuration11-12
CHAPTER
12Configuring Access and Trunk Interfaces12-1
Information About Access and Trunk Interfaces12-1
Understanding Access and Trunk Interfaces12-1
Understanding IEEE 802.1Q Encapsulation12-2
Understanding Access VLANs12-3
Understanding the Native VLAN ID for Trunk Ports12-3
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
vii
Contents
Send feedback to nx5000-docfeedback@cisco.com
Understanding Allowed VLANs12-4
Configuring Access and Trunk Interfaces12-4
Configuring a LAN Interface as an Ethernet Access Port12-4
Configuring Access Host Ports12-5
Configuring Trunk Ports12-6
Configuring the Native VLAN for 802.1Q Trunking Ports12-6
Configuring the Allowed VLANs for Trunking Ports12-7
Verifying Interface Configuration12-8
CHAPTER
CHAPTER
CHAPTER
13Configuring the MAC Address Table13-1
Information About MAC Addresses13-1
Configuring MAC Addresses13-1
Configuring a Static MAC Address13-2
Configuring the Aging Time for the MAC Table13-2
Clearing Dynamic Addresses from the MAC Table13-3
Verifying the MAC Address Configuration13-3
14Configuring IGMP Snooping14-1
Information About IGMP Snooping14-1
IGMPv1 and IGMPv214-2
IGMPv314-3
IGMP Snooping Querier14-3
IGMP Forwarding14-3
Configuring IGMP Snooping Parameters14-4
Verifying IGMP Snooping Configuration14-6
15Configuring Traffic Storm Control15-1
Information About Traffic Storm Control15-1
Guidelines and Limitations15-2
Configuring Traffic Storm Control15-3
Verifying Traffic Storm Control Configuration15-3
Displaying Traffic Storm Control Counters15-3
Traffic Storm Control Example Configuration15-4
Default Settings15-4
Switch Security Features
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
viii
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Contents
CHAPTER
16Configuring AAA16-1
Information About AAA16-1
AAA Security Services16-1
Benefits of Using AAA16-2
Remote AAA Services16-2
AAA Server Groups16-3
AAA Service Configuration Options16-3
Authentication and Authorization Process for User Login16-4
Prerequisites for Remote AAA16-5
AAA Guidelines and Limitations16-6
Configuring AAA16-6
Configuring Console Login Authentication Methods16-6
Configuring Default Login Authentication Methods16-8
Enabling Login Authentication Failure Messages16-8
Enabling MSCHAP Authentication16-9
Configuring AAA Accounting Default Methods16-10
Using AAA Server VSAs with Nexus 5000 Series Switches16-11
Displaying and Clearing the Local AAA Accounting Log16-12
CHAPTER
Verifying AAA Configuration16-12
Example AAA Configuration16-12
Default Settings16-13
17Configuring RADIUS17-1
Information About RADIUS17-1
RADIUS Network Environments17-1
RADIUS Operation17-2
RADIUS Server Monitoring17-3
Vendor-Specific Attributes17-3
Prerequisites for RADIUS17-4
Guidelines and Limitations17-4
Configuring RADIUS Servers17-4
Configuring RADIUS Server Hosts17-5
Configuring Global Preshared Keys17-6
Configuring RADIUS Server Preshared Keys17-6
Configuring RADIUS Server Groups17-7
Allowing Users to Specify a RADIUS Server at Login17-8
Configuring the Global RADIUS Transmission Retry Count and Timeout Interval17-9
Configuring the RADIUS Transmission Retry Count and Timeout Interval for a Server17-9
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
ix
Contents
Send feedback to nx5000-docfeedback@cisco.com
Configuring Accounting and Authentication Attributes for RADIUS Servers17-10
Configuring Periodic RADIUS Server Monitoring17-11
Configuring the Dead-Time Interval17-12
Manually Monitoring RADIUS Servers or Groups17-13
Verifying RADIUS Configuration17-13
Displaying RADIUS Server Statistics17-13
Example RADIUS Configuration17-14
Default Settings17-14
CHAPTER
18Configuring TACACS+18-1
Information About TACACS+18-1
TACACS+ Advantages18-2
User Login with TACACS+18-2
Default TACACS+ Server Encryption Type and Preshared Key18-3
TACACS+ Server Monitoring18-3
Prerequisites for TACACS+18-4
Guidelines and Limitations18-4
Configuring TACACS+18-4
TACACS+ Server Configuration Process18-4
Enabling TACACS+18-5
Configuring TACACS+ Server Hosts18-5
Configuring Global Preshared Keys18-6
Configuring TACACS+ Server Preshared Keys18-7
Configuring TACACS+ Server Groups18-7
Specifying a TACACS+ Server at Login18-8
Configuring the Global TACACS+ Timeout Interval18-9
Configuring the Timeout Interval for a Server18-9
Configuring TCP Ports18-10
Configuring Periodic TACACS+ Server Monitoring18-11
Configuring the Dead-Time Interval18-12
Manually Monitoring TACACS+ Servers or Groups18-12
Disabling TACACS+18-12
Displaying TACACS+ Statistics18-13
Verifying TACACS+ Configuration18-13
Example TACACS+ Configuration18-13
Default Settings18-14
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
x
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Contents
CHAPTER
19Configuring SSH and Telnet19-1
Information About SSH and Telnet19-1
SSH Server19-1
SSH Client19-2
SSH Server Keys19-2
Telnet Server19-2
Prerequisites for SSH19-2
Guidelines and Limitations19-3
Configuring SSH19-3
Generating SSH Server Keys19-3
Specifying the SSH Public Keys for User Accounts19-4
Starting SSH Sessions to Remote Devices19-6
Clearing SSH Hosts19-6
Disabling the SSH Server19-6
Deleting SSH Server Keys19-6
Clearing SSH Sessions19-7
Configuring Telnet19-7
Enabling the Telnet Server19-7
Starting Telnet Sessions to Remote Devices19-8
Clearing Telnet Sessions19-8
CHAPTER
Verifying the SSH and Telnet Configuration19-9
SSH Example Configuration19-9
Default Settings19-10
20Configuring ACLs20-1
Information About ACLs20-1
IP ACL Types and Applications20-1
Rules20-2
Configuring IP ACLs20-4
Creating an IP ACL20-5
Changing an IP ACL20-5
Removing an IP ACL20-6
Changing Sequence Numbers in an IP ACL20-7
Applying an IP ACL as a Port ACL20-7
Applying an IP ACL as a VACL20-8
Verifying IP ACL Configurations20-8
Displaying and Clearing IP ACL Statistics20-9
Configuring MAC ACLs20-9
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xi
Contents
Send feedback to nx5000-docfeedback@cisco.com
Creating a MAC ACL20-10
Changing a MAC ACL20-10
Removing a MAC ACL20-11
Changing Sequence Numbers in a MAC ACL20-12
Applying a MAC ACL as a Port ACL20-12
Applying a MAC ACL as a VACL20-13
Verifying MAC ACL Configurations20-13
Displaying and Clearing MAC ACL Statistics20-13
Information About VLAN ACLs20-14
VACLs and Access Maps20-14
VACLs and Actions20-14
Statistics20-15
Configuring VACLs20-15
Creating or Changing a VACL20-15
Removing a VACL20-16
Applying a VACL to a VLAN20-16
Verifying VACL Configuration20-17
Displaying and Clearing VACL Statistics20-17
CHAPTER
Default Settings20-18
System Management
21Using Cisco Fabric Services21-1
Information About CFS21-1
CFS Distribution21-2
CFS Distribution Modes21-2
Enabling/Disabling CFS Distribution on a Switch21-3
Verifying CFS Distribution Status21-4
CFS Distribution over IP21-4
CFS Distribution over Fibre Channel21-5
CFS Distribution Scopes21-5
CFS Merge Support21-6
CFS Support for Applications21-6
CFS Application Requirements21-6
Enabling CFS for an Application21-7
Locking the Network21-8
Committing Changes21-8
Discarding Changes21-9
Saving the Configuration21-9
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xii
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Clearing a Locked Session21-9
CFS Regions21-9
About CFS Regions21-10
Example Scenario21-10
Managing CFS Regions21-10
Configuring CFS over IP21-12
Enabling CFS over IP21-12
Verifying the CFS Over IP Configuration21-13
Configuring IP Multicast Address for CFS over IP21-13
Verifying IP Multicast Address Configuration for CFS over IP21-14
Displaying CFS Distribution Information21-14
Default Settings21-16
Contents
CHAPTER
22Configuring User Accounts and RBAC22-1
Information About User Accounts and RBAC22-1
About User Accounts22-1
Characteristics of Strong Passwords22-2
About User Roles22-2
About Rules22-3
About User Role Policies22-3
Guidelines and Limitations22-4
Configuring User Accounts22-4
Configuring RBAC22-5
Creating User Roles and Rules22-5
Creating Feature Groups22-7
Changing User Role Interface Policies22-7
Changing User Role VLAN Policies22-8
Changing User Role VSAN Policies22-8
Verifying User Accounts and RBAC Configuration22-9
Example User Accounts and RBAC Configuration22-9
Default Settings22-10
CHAPTER
23Configuring Session Manager23-1
Information About Session Manager23-1
Configuration Guidelines and Limitations23-1
Configuring Session Manager23-2
Creating a Session23-2
Configuring ACLs in a Session23-2
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xiii
Contents
Send feedback to nx5000-docfeedback@cisco.com
Verifying a Session23-3
Committing a Session23-3
Saving a Session23-3
Discarding a Session23-3
Session Manager Example Configuration 23-3
Configuring System Message Logging to Terminal Sessions25-2
Configuring System Message Logging to a File25-3
Configuring Module and Facility Messages Logged25-4
Configuring syslog Servers25-5
Configuring syslog Server Configuration Distribution25-7
Displaying and Clearing Log Files25-8
Verifying System Message Logging Configuration25-9
System Message Logging Example Configuration25-9
Default Settings25-10
CHAPTER
26Configuring Smart Call Home26-1
Information About Call Home26-1
Call Home Overview26-1
Destination Profiles26-2
Call Home Alert Groups26-2
Call Home Message Levels 26-4
Obtaining Smart Call Home26-5
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xiv
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Prerequisites for Call Home26-5
Configuration Guidelines and Limitations26-5
Configuring Call Home26-6
Guidelines for Configuring Call Home26-6
Configuring Contact Information26-6
Creating a Destination Profile26-8
Modifying a Destination Profile26-8
Associating an Alert Group with a Destination Profile26-9
Adding show Commands to an Alert Group26-10
Configuring E-Mail26-10
Configuring Periodic Inventory Notification26-11
Disabling Duplicate Message Throttle26-12
Enabling or Disabling Call Home26-12
Testing Call Home Communications26-13
Verifying Call Home Configuration26-13
Contents
CHAPTER
Call Home Example Configuration26-14
Default Settings26-14
Additional References26-15
Message Formats26-15
Sample syslog Alert Notification in Full-Text Format26-18
Sample syslog Alert Notification in XML Format26-19
Configuring Global LLDP Commands29-7
Configuring Interface LLDP Commands29-8
Verifying FCoE Configuration29-8
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xvi
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Contents
CHAPTER
CHAPTER
30Configuring Virtual Interfaces30-1
Information About Virtual Interfaces30-1
Guidelines and Limitations30-1
Configuring Virtual Interfaces30-2
Creating a Virtual Fibre Channel Interface30-2
Mapping VSANs to VLANs30-2
Deleting a Virtual Fibre Channel Interface30-3
Verifying Virtual Interface Information30-4
Quality of Service
31Configuring QoS31-1
Information About QoS31-1
MQC31-2
System Classes31-2
Default System Classes31-3
Link-Level Flow Control31-3
Priority Flow Control31-3
MTU31-4
Trust Boundaries31-4
Ingress Policies31-5
Egress Policies31-5
QoS for Multicast Traffic31-5
Policy for Fibre Channel Interfaces31-6
QoS for Traffic Directed to the CPU31-6
Configuring Class Maps31-9
Configuring Policy Maps31-9
Creating the System Service Policy31-11
System Class Example31-11
Enabling Jumbo MTU31-11
Verifying Jumbo MTU31-12
Configuring QoS on Interfaces31-13
Configuring Untagged CoS31-13
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
Configuring a Fibre Channel Interface32-8
Setting the Interface Administrative State32-9
Configuring Interface Modes32-9
Configuring the Interface Description32-10
Configuring Port Speeds32-10
Configuring SD Port Frame Encapsulation32-11
Configuring Receive Data Field Size32-11
Understanding Bit Error Thresholds32-11
Configuring Buffer-to-Buffer Credits32-12
CHAPTER
xviii
Configuring Global Attributes for Fibre Channel Interfaces32-13
Configuring Switch Port Attribute Default Values32-13
About N Port Identifier Virtualization32-14
Enabling N Port Identifier Virtualization32-14
About Domain Restart33-3
Restarting a Domain33-3
About Domain Manager Fast Restart33-3
Enabling Domain Manager Fast Restart33-4
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
About Switch Priority33-4
Configuring Switch Priority33-4
About fcdomain Initiation33-5
Disabling or Reenabling fcdomains33-5
Configuring Fabric Names33-5
About Incoming RCFs33-5
Rejecting Incoming RCFs33-6
About Autoreconfiguring Merged Fabrics33-6
Enabling Autoreconfiguration33-6
Domain IDs33-6
About Domain IDs33-7
Specifying Static or Preferred Domain IDs33-9
About Allowed Domain ID Lists33-9
Configuring Allowed Domain ID Lists33-10
About CFS Distribution of Allowed Domain ID Lists33-10
Enabling Distribution33-10
Locking the Fabric33-11
Committing Changes33-11
Discarding Changes33-11
Clearing a Fabric Lock33-12
Displaying CFS Distribution Status33-12
Displaying Pending Changes33-12
Displaying Session Status33-13
About Contiguous Domain ID Assignments33-13
Enabling Contiguous Domain ID Assignments33-13
Contents
FC IDs33-13
About Persistent FC IDs33-14
Enabling the Persistent FC ID Feature33-14
Persistent FC ID Configuration Guidelines33-15
Configuring Persistent FC IDs33-15
About Unique Area FC IDs for HBAs33-16
Configuring Unique Area FC IDs for an HBA33-16
About Persistent FC ID Selective Purging33-17
Purging Persistent FC IDs33-18
Verifying fcdomain Information33-18
Default Settings33-19
CHAPTER
34Configuring N Port Virtualization34-1
Information About NPV34-1
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
Guidelines and Restrictions35-3
Enabling or Disabling the VSAN Trunking Protocol35-3
About Trunk Mode35-3
Configuring Trunk Mode35-4
About Trunk-Allowed VSAN Lists35-4
Configuring an Allowed-Active List of VSANs35-6
Displaying VSAN Trunking Information35-6
Default Settings35-7
36Configuring SAN Port Channels36-1
Information About SAN Port Channels36-1
Understanding Port Channels and VSAN Trunking36-2
Understanding Load Balancing36-2
Configuring SAN Port Channels36-4
SAN Port Channel Configuration Guidelines36-5
Creating a SAN Port Channel36-6
About SAN Port Channel Modes36-6
About SAN Port Channel Deletion36-7
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xx
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Deleting SAN Port Channels36-8
Interfaces in a SAN Port Channel36-8
About Interface Addition to a SAN Port Channel36-9
Adding an Interface to a SAN Port Channel36-9
Forcing an Interface Addition36-10
About Interface Deletion from a SAN Port Channel36-10
Deleting an Interface from a SAN Port Channel36-11
Port Channel Protocol36-11
About Channel Group Creation36-12
Autocreation Guidelines36-13
Enabling and Configuring Autocreation36-14
About Manually Configured Channel Groups36-14
Converting to Manually Configured Channel Groups36-14
Verifying SAN Port Channel Configuration36-15
Default Settings36-16
Contents
CHAPTER
37Configuring and Managing VSANs37-1
Information About VSANs37-1
VSAN Topologies37-1
VSAN Advantages37-3
VSANs Versus Zones37-4
Configuring VSANs37-5
About VSAN Creation37-6
Creating VSANs Statically37-6
About Port VSAN Membership37-7
Assigning Static Port VSAN Membership37-7
Displaying VSAN Static Membership37-7
About the Default VSAN37-8
About the Isolated VSAN37-8
Displaying Isolated VSAN Membership37-8
Operational State of a VSAN37-9
About Static VSAN Deletion37-9
Deleting Static VSANs37-10
About Load Balancing37-10
Configuring Load Balancing37-10
About Interop Mode37-11
Displaying Static VSAN Configuration37-11
Default Settings37-11
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xxi
Contents
Send feedback to nx5000-docfeedback@cisco.com
CHAPTER
38Configuring and Managing Zones38-1
Information About Zoning38-1
Zoning Features38-2
Zoning Example38-3
Zone Implementation38-4
Active and Full Zone Set Configuration Guidelines38-4
Configuring Zones38-7
Zone Sets38-8
Activating a Zone Set38-9
About the Default Zone38-10
Configuring the Default Zone Access Permission38-10
About FC Alias Creation38-10
Creating FC Aliases38-11
Creating Zone Sets and Adding Member Zones38-12
Zone Enforcement38-13
Zone Set Distribution38-13
Enabling Full Zone Set Distribution38-14
Enabling a One-Time Distribution38-14
About Recovering from Link Isolation 38-14
Importing and Exporting Zone Sets38-15
Zone Set Duplication38-16
Copying Zone Sets38-16
Renaming Zones, Zone Sets, and Aliases38-16
Cloning Zones, Zone Sets, FC Aliases, and Zone Attribute Groups38-17
Clearing the Zone Server Database38-17
Verifying Zone Information38-18
Enhanced Zoning38-18
About Enhanced Zoning38-19
Changing from Basic Zoning to Enhanced Zoning38-20
Changing from Enhanced Zoning to Basic Zoning38-20
Enabling Enhanced Zoning38-20
Modifying the Zone Database38-21
Releasing Zone Database Locks38-21
Merging the Database38-22
Configuring Zone Merge Control Policies38-23
Default Zone Policies38-23
Configuring System Default Zoning Settings38-23
Verifying Enhanced Zone Information38-24
Compacting the Zone Database38-24
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xxii
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Zone and Zone Set Analysis38-24
Default Settings38-25
Contents
CHAPTER
39Distributing Device Alias Services39-1
Information About Device Aliases39-1
Device Alias Features39-1
Device Alias Requirements39-2
Zone Aliases Versus Device Aliases39-2
Device Alias Databases39-2
Creating Device Aliases39-3
Device Alias Modes39-4
Changing Device Alias Mode Guidelines39-4
Configuring Device Alias Modes39-5
About Device Alias Distribution39-5
Locking the Fabric39-5
Committing Changes39-6
Discarding Changes39-6
Fabric Lock Override39-7
Disabling and Enabling Device Alias Distribution39-7
About Legacy Zone Alias Configuration39-8
Importing a Zone Alias39-8
CHAPTER
Database Merge Guidelines39-8
Verifying Device Alias Configuration39-9
Default Settings 39-10
40Configuring Fibre Channel Routing Services and Protocols40-1
Information About FSPF40-1
FSPF Examples40-2
FSPF Global Configuration40-3
About SPF Computational Hold Times40-3
About Link State Records40-4
Configuring FSPF on a VSAN40-4
Resetting FSPF to the Default Configuration40-5
Enabling or Disabling FSPF40-5
Clearing FSPF Counters for the VSAN40-5
FSPF Interface Configuration40-5
About FSPF Link Cost40-6
Configuring FSPF Link Cost40-6
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xxiii
Contents
Send feedback to nx5000-docfeedback@cisco.com
About Hello Time Intervals40-6
Configuring Hello Time Intervals40-6
About Dead Time Intervals40-7
Configuring Dead Time Intervals40-7
About Retransmitting Intervals40-7
Configuring Retransmitting Intervals40-8
About Disabling FSPF for Specific Interfaces40-8
Disabling FSPF for Specific Interfaces40-8
Clearing FSPF Counters for an Interface40-9
FSPF Routes40-9
About Fibre Channel Routes40-9
Configuring Fibre Channel Routes40-10
In-Order Delivery40-10
About Reordering Network Frames40-11
About Reordering SAN Port Channel Frames40-11
About Enabling In-Order Delivery40-12
Enabling In-Order Delivery Globally40-12
Enabling In-Order Delivery for a VSAN40-13
Displaying the In-Order Delivery Status40-13
Configuring the Drop Latency Time40-13
Displaying Latency Information40-14
41Managing FLOGI, Name Server, FDMI, and RSCN Databases41-1
Information About Fabric Login41-1
Name Server Proxy41-2
About Registering Name Server Proxies41-2
Registering Name Server Proxies41-2
About Rejecting Duplicate pWWNs41-2
Rejecting Duplicate pWWNs41-3
About Name Server Database Entries41-3
Displaying Name Server Database Entries41-3
FDMI41-4
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xxiv
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Displaying FDMI41-4
RSCN41-4
About RSCN Information41-5
Displaying RSCN Information41-5
About the multi-pid Option41-5
Configuring the multi-pid Option41-6
Suppressing Domain Format SW-RSCNs41-6
Clearing RSCN Statistics41-6
Configuring the RSCN Timer41-7
Verifying the RSCN Timer Configuration41-7
RSCN Timer Configuration Distribution41-8
Default Settings41-10
Contents
CHAPTER
CHAPTER
42Discovering SCSI Targets42-1
Information About SCSI LUN Discovery42-1
About Starting SCSI LUN Discovery42-1
Starting SCSI LUN Discovery42-2
About Initiating Customized Discovery42-2
Initiating Customized Discovery42-2
Displaying SCSI LUN Information42-3
43Advanced Fibre Channel Features and Concepts43-1
Fibre Channel Timeout Values43-1
Timer Configuration Across All VSANs43-2
Timer Configuration Per-VSAN43-2
About fctimer Distribution43-3
Enabling or Disabling fctimer Distribution43-3
Committing fctimer Changes43-3
Discarding fctimer Changes43-4
Fabric Lock Override43-4
Database Merge Guidelines43-4
Verifying Configured fctimer Values43-5
World Wide Names43-5
Verifying WWN Information43-6
Link Initialization WWN Usage43-6
Configuring a Secondary MAC Address43-6
FC ID Allocation for HBAs43-7
Default Company ID List43-7
Verifying the Company ID Configuration43-8
OL-16597-01
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xxv
Contents
Send feedback to nx5000-docfeedback@cisco.com
Switch Interoperability43-9
About Interop Mode43-9
Configuring Interop Mode 143-11
Verifying Interoperating Status43-12
Default Settings43-15
CHAPTER
44Configuring FC-SP and DHCHAP44-1
Information About Fabric Authentication44-1
DHCHAP44-2
DHCHAP Compatibility with Fibre Channel Features44-3
About Enabling DHCHAP44-4
Enabling DHCHAP44-4
About DHCHAP Authentication Modes44-4
Configuring the DHCHAP Mode44-5
About the DHCHAP Hash Algorithm44-5
Configuring the DHCHAP Hash Algorithm44-6
About the DHCHAP Group Settings44-6
Configuring the DHCHAP Group Settings44-6
About the DHCHAP Password44-6
Configuring DHCHAP Passwords for the Local Switch44-7
About Password Configuration for Remote Devices44-7
Configuring DHCHAP Passwords for Remote Devices44-8
About the DHCHAP Timeout Value44-8
Configuring the DHCHAP Timeout Value44-8
Configuring DHCHAP AAA Authentication44-9
Displaying Protocol Security Information44-9
Sample Configuration44-9
Default Settings44-11
CHAPTER
45Configuring Port Security45-1
Information About Port Security45-1
Port Security Enforcement45-2
About Auto-Learning45-2
Port Security Activation45-3
Configuring Port Security45-3
Configuring Port Security with Auto-Learning and CFS Distribution45-3
Configuring Port Security with Auto-Learning without CFS45-4
Configuring Port Security with Manual Database Configuration45-5
Enabling Port Security45-5
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xxvi
OL-16597-01
Send feedback to nx5000-docfeedback@cisco.com
Port Security Activation45-5
Activating Port Security45-6
Database Activation Rejection45-6
Forcing Port Security Activation45-6
Database Reactivation45-7
WWN Identification Guidelines45-10
Adding Authorized Port Pairs45-11
Port Security Configuration Distribution45-12
Enabling Distribution45-12
Locking the Fabric45-13
Committing the Changes45-13
Discarding the Changes45-13
Activation and Auto-Learning Configuration Distribution45-13
Contents
CHAPTER
Database Merge Guidelines45-14
Database Interaction45-15
Database Scenarios45-15
Copying the Port Security Database45-17
Deleting the Port Security Database45-18
Clearing the Port Security Database45-18
Displaying Port Security Configuration45-19
Default Settings45-19
46Configuring Fabric Binding46-1
Information About Fabric Binding46-1
Licensing Requirements46-1
Port Security Versus Fabric Binding46-2
Fabric Binding Enforcement46-2
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xxvii
Contents
Send feedback to nx5000-docfeedback@cisco.com
About Fabric Binding Activation and Deactivation46-4
Activating Fabric Binding46-5
Forcing Fabric Binding Activation46-5
Copying Fabric Binding Configurations46-5
Clearing the Fabric Binding Statistics46-6
Deleting the Fabric Binding Database46-6
Verifying Fabric Binding Information46-6
Default Settings46-7
CHAPTER
CHAPTER
47Configuring Fabric Configuration Servers47-1
Information About FCS47-1
FCS Characteristics47-2
FCS Name Specification47-2
Displaying FCS Information47-3
Default Settings47-4
48Configuring Port Tracking48-1
Information About Port Tracking48-1
Configuring Port Tracking48-2
Enabling Port Tracking48-3
About Configuring Linked Ports48-3
Operationally Binding a Tracked Port48-3
About Tracking Multiple Ports48-4
Tracking Multiple Ports48-5
About Monitoring Ports in a VSAN48-5
Monitoring Ports in a VSAN48-5
About Forceful Shutdown48-6
Forcefully Shutting Down a Tracked Port48-6
Displaying Port Tracking Information48-6
Default Port Tracking Settings48-7
Troubleshooting
CHAPTER
49Configuring SPAN49-1
SPAN Sources49-1
Characteristics of Source Ports49-1
SPAN Destinations49-2
Characteristics of Destination Ports49-2
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
xxviii
OL-16597-01
Loading...
+ 674 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.