Showing posts with label ios. Show all posts
Showing posts with label ios. Show all posts

Monday, January 16, 2012

COMMANDS: A Primer on Some of the Differences Between IOS and NX-OS

NX-OS is starting to be my favorite OS from Cisco.  However, dealing with IOS for so long I find myself typing the wrong commands in NX-OS and IOS.  So I thought of posting up the NX-OS v4.x commands with the IOS counterpart commands for all to see.



NX-OS Smart Call-Home IOS Smart Call-Home Command Description
show callhome show call-home Displays global Call-Home configuration
show callhome destination-profile show call-home profile Displays Call-Home profiles
show callhome transport-email show call-home mail-server Displays destination Call-Home mail server
show callhome user-def-cmds N/A Displays user defined "show" commands for output



NX-OS Cisco Discovery Protocol (CDP) IOS Cisco Discovery Protocol (CDP) Command Description
show cdp all N/A Displays all interfaces with CDP enabled
show cdp entry all show cdp entry * Displays the CDP database entries
show cdp global show cdp Displays Global Parameters (Enabled, Timers, etc…)
show cdp interface show cdp interface Displays interface specific information
show cdp neighbors show cdp neighbors Displays a summer list of neighbors
show cdp neighbors detail show cdp neighbors detail Displays detailed information per neighbor
show cdp neighbors interface show cdp neighbors interface-type Displays CDP neighbor for a specified interface
show cdp traffic interface  N/A - "show cdp traffic" is only global Provides statistics on a per interface basis



NX-OS Command Scheduler IOS Command Scheduler Command Description
show scheduler config N/A Displays the scheduler configuration
show scheduler job N/A Displays the Jobs configured in the scheduler
show scheduler logfile N/A Displays the contents of the execution log file
show scheduler name N/A Displays the schedules configured



NX-OS Embedded Event Manager (EEM) IOS Embedded Event Manager (EEM) Command Description
show event manager environment show event manager environment Displays EEM environment variables
show event manager event-type N/A Displays registered event types
show event manager history show event manager history Displays information on history and past events
show event manager policy N/A Displays applets or script policies
show event manager policy-state N/A Displays the state of a policy
show event manager script N/A Displays information about a script
show event manager system-policy show event manager policy Displays information on system default entries



NX-OS Generic Online Diagnostics (GOLD) IOS Generic Online Diagnostics (GOLD) Command Description
show diagnostics bootup level show diagnostics bootup level Displays current bootup level
show diagnostics content module  show diagnostics content module  Displays test contents for a specified module
show diagnostics description module  show diagnostics description module  Displays description for a specified diagnostic test
show diagnostic results module show diagnostic results module Displays information and result of a diagnostic
show diagnostic status module  show diagnostic status Displays test status for all tests on a module



NX-OS Netflow IOS Netflow Command Description
show flow exporter show mls nde Displays information about configured exporter maps
show flow interface N/A Displays interfaces configured for Netflow
show flow monitor N/A Displays information about monitor maps
show flow record N/A Displays information about record maps
show flow timeout N/A Displays the Netflow timeout value
show hardware flow aging show mls netflow aging Displays the Netflow table aging timeout value
show hardware flow entry show mls netflow ip flow Displays flow specific information
show hardware flow ip show mls netflow ip  Displays the IP Netflow Table
show hardware flow sampler show mls sampling Displays the Netflow Sampling Configuration
show hardware flow utilization module show mls netflow table summary Displays Netflow table utilization per module
show sampler show flow-sampler Displays information about sampler maps



NX-OS Onboard Fault Logging (OBFL) IOS Onboard Fault Logging (OBFL) Command Description
show logging onboard module # boot-uptime    show logging onboard module # uptime Displays OBFL boot and uptime information per module
show logging onboard module # counter-stats        N/A Displays OBFL counter statistics per module
show logging onboard module # device-version          N/A Displays OBFL device version information per module
show logging onboard module # endtime                 show logging onboard module # end Displays OBFL logs till end time mm/dd/yy-HH:MM:SS per module
show logging onboard module # environmental-history   show logging onboard module # temperature Displays OBFL environmental history per module
show logging onboard module # error-stats            N/A Displays OBFL error statistics per module
show logging onboard module # exception-log          N/A Displays OBFL exception log per module
show logging onboard module # interrupt-stats         show logging onboard module # interrupt Displays OBFL interrupt statistics per module
show logging onboard module # kernel-trace           N/A Displays OBFL Kernel Trace per module
show logging onboard module # module                N/A Displays OBFL information for Module per module
show logging onboard module # obfl-history          N/A Displays OBFL history information per module
show logging onboard module # stack-trace          N/A Displays OBFL kernel stack trace per module
show logging onboard module # starttime        show logging onboard module # start Displays OBFL logs from start time mm/dd/yy-HH:MM:SS per module
show logging onboard module # status              show logging onboard module # status Displays OBFL status enable/disable per module



NX-OS RMON IOS RMON Command Description
show rmon alarms show rmon alarms Displays configured RMON alarms
show rmon events show rmon events Displays configured RMON Events
show rmon hcalarms N/A Displays information for 64 bit alarms
show rmon logs show rmon history Displays RMON log messages



NX-OS SNMP IOS SNMP Command Description
show snmp show snmp Displays SNMP Counters, Users, Community Strings, etc...
show snmp community show snmp community Displays the SNMP community strings
show snmp context show snmp context Displays the SNMP Context mapping
show snmp engineID show snmp engineID Displays Hex and Decimal SNMP Engine ID
show snmp group show snmp group Displays configured SNMP groups/roles
show snmp host show snmp host Displays Host specific information
show snmp sessions show snmp sessions Displays active SNMP sessions
show snmp trap N/A Displays what traps are enabled
show snmp user show snmp user Displays SNMP users and notification targets (v3)



NX-OS Switch Port Analyzer (SPAN) IOS Switch Port Analyzer (SPAN) Command Description
show monitor session # show monitor session # Displays a specific sSPAN session
show monitor session all show monitor session all Displays all SPAN sessions
show monitor range #-# show monitor range #-# Displays a range of specified SPAN sessions



NX-OS Logging (Syslog) IOS Logging (Syslog) Command Description
show logging show logging Displays how logging is configured with log
show logging info N/A Displays how logging is configured without log
show logging last # N/A Displays the last "#" of log messages
show logging level N/A Displays the Facility, Default Severity, and Configured Severity
show logging logfile N/A Displays all of the Syslog information
show logging module N/A Displays the module logging configuration
show logging monitor N/A Displays the monitor logging configuration
show logging nvram N/A Displays the Severity 0, 1, and 2 message stored in NVRAM
show logging server N/A Displays information for each configured syslog server
show logging timestamp N/A Displays the configured timestamp for log messages



NX-OS NTP IOS NTP Command Description
show ntp peers show ntp associations Displays what NTP peers are configured
show ntp peer-status show ntp status (not on a peer basis) Shows the status of each NTP peer
show ntp source N/A Displays the source IP address for the NTP service
show ntp statistics peer ipaddr x.x.x.x N/A Show statistics for each NTP peer
show ntp timestamp-status N/A Displays if the timestamp check is enabled



NX-OS XML IOS XML Command Description
show xml server logging N/A Displays XML Logging
show xml server status N/A Displays XML Server Status



You can also find the same kind of material on the following link
http://docwiki.cisco.com/wiki/Cisco_Nexus_7000_NX-OS/IOS_Comparison_Tech_Notes

COMMANDS: CISCO IOS Enabling Top N Utility Report Creation


One of the hardest things to remember is using the TOP N uility on some IOS based devices.  The following are some commands that help me.


Enabling Top N Utility Report Creation

This examples shows how to enable Top N Utility report creation for an interval of 76 seconds for the four ports with the highest utilization:

collect top 4 counters interface all sort-by utilization interval 76


collect top counters interface all sort-by utilization interval 76 


collect top counters interface all interface 76

Displaying all the Top N Utility Reports
show top counters interface report

This example shows how to display a specific Top N Utility report
show top counters interface report 1

Clearing Top N Utility Reports (All)
clear top counters interface report

Clearing Top N Utility Report 4
clear top counters interface report 4

CONFIGURATION: CISCO NETFLOW

After going through a sea of documentation regarding Netflow, I wanted to come up with the basic guide of how to turn it on and apply it.

The first rule of netflow is that you can ONLY collect information on a routed interface

! Lock the SNMP ifIndex - prevents ifIndex drift after router reboot
snmp-server ifindex persist

! Make sure you have the correct community string
! This is mostly a NetQoS requirement; but it's usually required
! by any NetFlow collecting device that needs to verify the device
! it's collecting from.
snmp-server community community_name RO


! Enable NetFlow export globally
! Using loopback
ip flow-export version 5
ip flow-export source lo0
ip flow-cache timeout active 1

! Set export destination  and port to closest Netflow Collector. The port
! listed below is based on NetQOS product
! other Netflow collectors might use a different port
ip flow-export destination IP_ADDRESS 9995


! MLS commands are required for Sup720 running Native IOS ONLY
mls nde sender version 5
mls flow ip interface-full
mls nde interface
mls aging long 64
mls aging fast threshold 1 time 64


Now that Netflow is turned on we need to apply the commands to a routed interface.  The following are examples of interfaces where netflow is applied on:

int fa3/1
ip route-cache flow
int s2/0/0
ip route-cache flow
int gig4/0
ip route-cache flow
int vlan123
ip route-cache flow

Sunday, January 15, 2012

COMMAND REFERENCE: CISCO IOS FTP and TFTP

I don't know how many times someone has forgotten the following set of commands.


------------------------------
FTP

config t
ip ftp username
ip ftp password
ip ftp source-interface loopback0


# You need to run this the first time if the command has never been used.  Performing the statements below insures that passive is turned off.

ip ftp passive
no ip ftp passive  



Examples of commands:
copy ftp://ip_address_of_ftp_server/filename.bin bootflash:filename.bin

copy ftp://ip_address_of_ftp_server/filename.bin sup-bootflash:filename.bin



----------------
TFTP

config t
ip ftp source-interface loopback0


Examples of commands:
copy tftp://ip_address_of_tftp_server/filename.bin bootflash:filename.bin

copy tftp://ip_address_of_tftp_server/filename.bin sup-bootflash:filename.bin

COMMAND REFERENCE: CISCO PIX

From time to time I kick myself for not knowing certain commands that I take for granted.  Here they are

Description: Sometimes PIX PDM is inaccessible because the SSL key is corrupted or you setting up the PDF for the first time.  I found these sequence of commands useful

ca zero rsa
Hostname devicename
domain-name dot.com
ca gen rsa key 2048
ca save all
show ca mypubkey rsa



Various other useful commands

show object-group service - Lists the servicesshow object-group - Lists all groups including services
show failover - shows the failover information
show version - shows the version including serial number of the PIX
show access-list – shows all access list even shows details within a groups
show access-list | inc TEXT – shows specific filtered results 
show access-list | beg TEXT - Shows the start of content beginning with what is contain in TEXT
sho config – shows the entire config
show config | inc TEXT – shows a filtered config
show config | beg TEXT - Shows the start of content beginning with what is contain in TEXT
show nat – lists NAT access-list


Troubleshooting commands

show arp
– shows the arp table (Layer 4)
ping IP_ADDRESS
– pings the ip addresses
show cpu usage
– show cpu utilization for 5 seconds, 1 minute and 5 minutes
show conn
– shows the connections table at the given time
show memory
– shows memory block
show xlate
– shows translation address (NAT) in memory
show processes
– shows different firewall processes
show static
– Shows static address
show route
– shows routing information
show logging
Shows all the alerts stored on the PIX (disappears when rebooted)
 

Saturday, January 14, 2012

Cisco IOS VLAN to VLAN F5 Bypass

From time to time, I usually receive a request that goes something like this.

“I have a pair of F5 ADC in an Internet DMZ, where the servers behind the load balancer need to access NAS system(s) on a VLAN located in the same network on another VLAN that is not behind the load balancer.
The problem is that in my current design I have to route through the F5 Load balancer to access the NAS system(s).  Unfortunately the amount of bandwidth it takes supersedes the F5 ADC’s total throughput.  I would like to by pass this without adding extra network cards or recreating a new VLAN and would like preserve the IP addresses as much as possible.”




For the purposes of the blog we will call the person requesting this Keyser Söze.   Yes I have to call him Keyser.




Based on this description above you can extrapolate a high-level logical network design as shown in Figure 1.


Figure 1


In the figure 1, we have the following VLANS
  • VLAN 10 - Which is for VIPs (Virtual IP addresses).  The VLAN is routable via Cisco HSRP.   Gateway is .1.  The F5's floating address will be .11.  The floating address is used as the NEXT HOP to get to VLAN 11.
  • VLAN 11 - Where the Servers that will be load balanced -  is a non Cisco routable VLAN.  From Cisco's perspective it's simply a VLAN without HSRP.   The gateway for this segment is on the F5 which is .1
  • VLAN 12 - This is a routable VLAN similar to VLAN 10, except there are physical servers on this segment.  In our case this is where the NAS will sit.  The gateway is .1 for the NAS.
Here are some facts we know about this design
  • VLAN 12 is accessible by any part of this network
  • VLAN 10 has a floating IP address which is the shared address between F5.  It is used in scenario to be the gateway to the segment in VLAN 11
  • In order for a Web server in VLAN 11 to access the NAS server in VLAN12 and vice versa, the F5 is the router.


There is nothing entirely wrong with this done and it most cases this works.  However, Keyser is worried that multiple web servers in VLAN 11 will request so much content from the NAS server in VLAN 12 that there is a throughput concern.


So how do we change the network to accommodate the result that Kyser is looking for?


It is actually much easier then you might think.


For the purposes of this explanation, let us assume the switches are connected on Cisco Switch routers


The first item you want to remove is the the static route on the switch pointing to point to .11 on VLAN10 to access VLAN12. You will not need this since the end result is to allow VLAN 12 and VLAN 11 to communicate directly via the Cisco Switch router.
Next you will need to change VLAN11 from a non-routable network to a routable network. Thus, VLAN 11 will have a gateway of .1 on the switch router. The F5 will then change its own floating address to say .11 and subsequently change the self-addresses. All the servers will continue to use .1 on VLAN11 as their default gateway.


Thus the network will now look more like Figure 2
Figure 2




At this point, you are thinking well if that is the case then how do we get traffic back to the F5 for Load balancing traffic. Well the easy way is to apply SNAT Automap across all the Virtual addresses. Which works, but then you run into another problem where you lose the client IP address. Normally this might be work, BUT if you are tracking clients for statistical purposes, this is not going to work.
The short answer to this is utilizing a Cisco’s Policy Based Route. How does that work?
On a Cisco switch you can do the following configuration (IOS Syntax):


ip access-list extended from_vlan11
Deny y.y.y.0 0.0.0.255 z.z.z.0 0.0.0.255
Permit y.y.y.0 0.0.0.255 any
route map to_lb_vlan11
Match ip address from_vlan11
ip default next-hop y.y.y.11
interface Vlan11
ip policy route-map to_lb_vlan11




What these statements mean is that any traffic from VLAN11 is destined to addresses on VLAN12, skip the route-map statement and use the internal routing table of the switch. Thus allowing VLAN11 to communicate directly to VLAN12 and vice-versa.


Subsequently, if traffic from VLAN11 is attempting to talk to the internet then it will match the permit statement in the IP access list “from_vlan11” then apply the route map statement and thus your next hope is .11, which is hosted on VLAN11.
That pretty much sums up how to use the switches throughput for VLAN-to-VLAN traffic and the F5 ADC continues to do what it does best while Kyser can go home happy.