/images/logo.png
A Network Blog by a Network Engineer

Nexus 7000 and the Show Tech command (gzip too)

Recently I have experience some interesting first-level support from our Cisco VAR.  They are not too familiar with the Nexus 7000 and insisted on us sending them a SHOW TECH from the switch.  If you are not familiar with a Nexus 7000, let me tell you – the show tech from this box can be over 100 Megs!  So, when they asked for that I was like – are you sure?  really really sure? I just have to say – thank you DropBox and public folders!  I used DropBox place the file and then send the support the public link.  Not sure that most e-mail systems would appreciate that large of a file!
So, if the Show Tech Support is so big, how do you get the information that support needs?  Well, instead of running a complete show tech, you run it for the sections you need!
Here is a list of what you can append to a Show Tech-Support command: (show tech-support option)
N7K1-CoreSwitch1# sh tech-support ?

>               Redirect it to a file
»              Redirect it to a file in append mode
aaa             Display aaa information
aclmgr          ACL commands
adjmgr          Display Adjmgr information
arp             Display ARP information
ascii-cfg       Show ascii-cfg information for technical support personnel
assoc_mgr       Gather detailed information for assoc_mgr troubleshooting
bgp             Display BGP status and configuration
bootvar         Gather detailed information for bootvar troubleshooting
brief           Display the switch summary
callhome        Callhome troubleshooting information
cdp             Gather information for CDP trouble shooting
cert-enroll     Display certificates information
cfs             Gather detailed information for cfs troubleshooting
cli             Gather information for parser troubleshooting
clis            Gather information for CLI Server troubleshooting
commands        Show commands executed as part of show tech-support commands
details         Gather detailed information for troubleshooting
dhcp            Gather detailed information for dhcp troubleshooting
eem             Show EEM tech-support information
eigrp           Display EIGRP status and configuration
eltm            Eltm debug info
ethpm           Gather detailed information for ETHPM troubleshooting
forwarding      Forwarding debug information
ha              Gather detailed information for HA troubleshooting
hsrp            Show hsrp tech-support information
icmpv6          Display Icmpv6 information
im              Gather detailed information for IM troubleshooting
include-time    Gather tech-support and capture time taken to execute each
command
interface-vlan  Gather detailed information for interface-vlan
troubleshooting
internal        Gather internal info for troubleshooting
ip              Display IP information
ipqos           IP QoS Manager
ipv4            Display IP information
ipv6            Display IPV6 information
l2fm            L2fm debug info
l2pt            Gather information for l2pt troubleshooting
l3vm            Display VRF information
lacp            Gather detailed information for LACP component
license         Display licensing information
logging         Show information on logging for technical support staff
m2fib           Gather detailed information for M2FIB troubleshooting
m2rib           Gather detailed information for M2RIB troubleshooting
mfwd            Display MCASTFWD status and configuration
module          Gather info related to a module
monitor         Gather detailed information for monitor troubleshooting
multicast       Display V4 Multicast information
netflow         Show NetFlow tech-support information
netstack        Gather information for NETSTACK troubleshooting
npacl           Display npacl information
pixm            Gather detailed information for PIXM troubleshooting
pixmc           PIXMC Information
pktmgr          Display Packet Manager information
port-channel    Gather detailed information for port channel troubleshooting
port-profile    Gather information for troubleshooting port-profiles
port-security   Port security related command
Ok, color code again:
Red – Router Output
Blue – Commands
Green – Notes
Traditionally when we have done show tech-support, we have always done terminal length to 0, set the capture buffer on our terminal application, and then executed the command – like this:
First we set the length to 0
FryGuyR1#terminal length 0
Then we configure our terminal to capture the data

Integrated Switch Modules in Routers (SM-E3SG and NME-XD)

In the Small Branch office type of environment we are commonly limited to the budget of the design, the space for the hardware, as well as the remote supportability of the site.  By supportability I refer to being able to walk someone through what each device it, what it does, and how to check when (not if) there is a problem. Normally this design may look something a router connecting to WAN links (T1/DS3/etc), then that router connecting to some type of switch or switches, and finally the end stations being connected to the switch(es).  Perhaps in a simplistic fashion, the network looks like this:

1995 Mustang Cobra Hardtop Convertible

Well, if you have not figured it out from the title, this is not a technical blog posting.  I have had a few people ask me about my car and give me confused, bewildered, and otherwise mystified faces.  Why you wonder, well – most people do not know that Ford ever made this car.  Yes, it is a Mustang; Yes, it is a Cobra; Yes, it is a convertible; and Yes – it has a removable hard-top as well! This was a car that I have wanted since I first saw them in 1995 at a local dealership, but unfortunately at that time I was not able to afford one.  As they say, all good things come to those who wait.
The 1995 Cobra was powered by a 240-hp 5.0L V-8 and is the same engine used in the 1994 Mustang Cobra.  The cars do 0-60 in about 6.7 seconds (slow compared to most cars today but back then that was quick!) and has a top speed of 140 mph.  Color options for the standard Mustang Cobra were Black (1433), White (1125), and Red (1447), for a total of 4005 units, of those 1003 convertibles were produced.  The 1995 model year was the only year a convertible hardtop was produced and only 499 of these Hardtop Convertibles were produced – all in Black .  There was a hardtop/ragtop that was installed as a prototype on a V6 and some GT Mustangs but were never “officially” produced.  Another new feature for 1995 was the addition of SVT badging, the Cobra’s from the previous years did not designate themselves as Special Vehicle Team cars.
What is the purpose of the Hardtop Convertible one may ask?  Well, the whole reason behind it (from my understanding) is so you can have a convertible in the summer via the soft-top, and then when Winter comes, put the hardtop on and you are good to go.  It was designed to be an all year car, not like the regular convertibles of the day that were summer only.  The hardtop has glass in the rear with a defogger, so it is a fully functioning top. Interior light, headliner, etc!
You can see the V6 Hardtop Convertible as well as some of the other prototype cars in the VHS cassette that accompanied the purchase of the car.  This tape was the instructions for how to remove and install the hard-top.   When I purchased my car the VHS tape came with it – and it was in very good shape.  I have since paid for the VHS tape to be professionally transferred to DVD format so that I can review it any time I would like.  I have since taken the DVD video and converted it to WMV format. Below is the video:

Gestalt IT’s first datacenter-focused Field Day event

Well I got the official notice today that I will be attending a Gestalt IT Tech Field Day event on February 10th and 11th in 2011 in San Jose, CA.  I feel honored as well as humbled to be invited to this event.  It is a great chance to meet new people, learn from their experiences, listen to their war stories, as well as the chance to see what the vendors have to say.
What is Tech Field Day, you ask?  Well – to explain it best I am going to quote it from Gestalt’s website:

New Cisco Compact Switches!

Well, just the other day Cisco announced some new Compact switches that should replace the Cisco 2940(yeah, I know that they were EOL and replaced with 2960-8)  and 3560-8 series switches.  The product information can be found here – Link.  The new switches are the Cisco 3560-C and 2960-C series.
These really have my attention from an Enterprise perspective.  I cannot tell you how many conference rooms we have that have either the 2940 or the 3560-8 switches mounted under the table.  Those switches work great, except for the fact that we need to also run a power-cord to them.  I cannot tell you how many times our NOC has contacted us with regards to a switch being reset due to power-on and it turning out someone kicked the power cord.  We run the Cisco 3560-8 at places where we need PoE ports  for phones and such, and the 2940/2960 series are used where no PoE is required.
So what is so intriguing to me about the new 2960-C switches? Well, the biggest thing that I noticed is that you can now get switches that will be powered via PoE and  PoE+ ports instead of an external power cord. This is feature is called PD PSE -Powered Devices (PD) and Power Sourcing Equipment (PSE) and is in available it WS-C2960CPD series of switches.  The way that it works is that you connect the dedicated copper uplinks on the 2960CPD switch to a PoE or PoE+ capable switch, the switch then senses the device requesting the power and provides the power necessary to the device.  This is the 802.3af (PoE) and 802.3at (PoE+) standards and works just like an IP phone does connected to a switch. One thing to note on the PS/PSE 2960C is that you can also get an external power supply to power the device.  This is a nice feature if you do not have PoE capable devices today but plan to deploy them at a later date. Below is an image taken from Cisco’s website that shows the PD/PSE switches on the left and the non PD/PSE switches below

Sorry…

With the holidays and such, and now that I am sick – I have ignored this blog for a little bit. I promise I will get something good up soon. Need to focus on those VRF labs and get them published soon.
I promise…

Cisco ASR and LACP

I am currently working on a new site deployment utilizing some Cisco ASR1002 routers.  When we typically design a location we cross-connect the two WAN routers via a cross-over cable; this allows us to have the capability to continue to transit traffic over the connected WAN routers and WAN links if need to take down the Core at the site for maintenance.
If you look at the image below you will see three Sites – A – B – C.  Traffic that is destined to Site B from Site A will transit the connected WAN link.  So what happens if that WAN link goes down, it will transit through Site C instead.  By having the WAN routers connected via a cross-over cable, the traffic will stay at the end and not transverse the internal LAN of the site.

Ok, the background information is now out of the way. Lets continue.
Typically we use a single gigabit ethernet cross-over cable between the routers, due to hardware limitations. Well, with the ASR series we now have more interfaces that we can use for this connectivity.  What I have also found is that the ASR and IOS-XE support LACP and etherchannels.  This is a wonderful thing as it actually solves some of the problems of a single cross-over cable between routers.
So, how does one configure LACP on the ASR 1002?  It is done the same way as you would on the Nexus for L3 etherchannel. Below are the configuration commands as well as the ways to check.
For this example, we are going to create Port-Channel 12 on the router and assign interfaces G0/0/2 and G0/0/3 to the channel-group
Router#conf t
Router(config)#interface GigabitEthernet0/0/2
Router(config-if)# channel-group 12 mode active
Router(config-if)# no shut
Router(config-if)# exit
Router(config)#interface GigabitEthernet0/0/3
Router(config-if)# channel-group 12 mode active
Router(config-if)# no shut
Router(config-if)# exit
Now we can configure an IP address on the port-channel interface:
Router(config)#interface Port-channel12
Router(config-if)# ip address 10.1.1.1 255.255.255.252
T0 check the port-channel:
Router#sh int port-channel 12
Port-channel12 is up, line protocol is up
Hardware is GEChannel, address is c471.fe0c.55cb (bia c471.fe0c.55cb)
Internet address is 10.98.255.9/30
MTU 1500 bytes, BW 2000000 Kbit/sec, DLY 10 usec,
You can also look at the LACP information:
Router#sh lacp 12 neighbor
Flags:  S – Device is requesting Slow LACPDUs
F – Device is requesting Fast LACPDUs
A – Device is in Active mode       P – Device is in Passive mode
Channel group 12 neighbors
Partner’s information:
Partner Partner   LACP Partner  Partner   Partner  Partner     Partner
Port      Flags   State     Port Priority Admin Key Oper Key Port Number Port State
Gi0/0/2   SA      bndl      32768         0x0       0xC      0x3         0x3D
Gi0/0/3   SA      bndl      32768         0x0       0xC      0x4         0x3D
Router#
Now lets ping to test:
Router#p 10.1.1.2 t 1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.1.1.1, timeout is 1 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Router#
If you noticed I typed t 1 – that means use a 1 second timeout.  I did that in case, for some reason, it does not PING successfully I only have to wait half the normal time of 2 seconds per ping.  This might not seem like a big deal, but if you use this on some LAB test – you can save some time and frustration. 🙂

Clearing hung TCP session on a Cisco router

While going through some of my old notes I came across some notes from a few years ago on hung TCP sessions on some of our routers. These hung sessions where due to the latency differences on a Multi-link T1 connection that was in place.  Below are the notes (generalized IP and Names) on how to detect and reset these connections.It is my hope for you to never have to use these commands, but since there is little out there on them I figured I would share.

Type 7 password decryption via IOS router (? bonus)

I have seen a few posts out there about this as well as links to sites that will decrypt a Cisco type 7 password.  Since I am trying to share what I know I figured I might as well throw my hat into the ring and include this information here.
If you have a type 7 enable password such as : enable password 7 00331A0A087D071F012F7F5B1B0F0C011754 and want to decrpyt it, all you need is another router that you can get to enable (priv 15) access on and configuration mode.
Enter configuration mode and create a key-chain. For the key-string, tell it type 7 and cut-and-past the encrypted key
Rack1R6(config)#key chain DecrpytThis
Rack1R6(config-keychain)#key 1
Rack1R6(config-keychain-key)#key-string 7 00331A0A087D071F012F7F5B1B0F0C011754
Then all you have to do from a command prompt is issue show key chain
Rack1R6#sh key chain
Key-chain DecrpytThis:
key 1 — text “WillFlynnSurvive?
accept lifetime (always valid) – (always valid) [valid now]
send lifetime (always valid) – (always valid) [valid now]
Rack1R6#
As you can see here, the password is WillFlynnSurvive?
This works for any Type 7 password, including users.  Below I have done a show run | inc user and they added Key 2 with he user type 7 password.
Rack1R6#sh run | inc user
username Flynn privilege 15 password 7 0478071303245F5D
Rack1R6#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Rack1R6(config)#key chain DecryptThis
Rack1R6(config-keychain)#key 2
Rack1R6(config-keychain-key)#key-string 7 0478071303245F5D
Rack1R6(config-keychain-key)#^Z
Rack1R6#sh key chain
Key-chain DecrpytThis:
key 1 — text “WillFlynnSurvive?”
accept lifetime (always valid) – (always valid) [valid now]
send lifetime (always valid) – (always valid) [valid now]
Key-chain DecryptThis:
key 2 — text “Cluless
accept lifetime (always valid) – (always valid) [valid now]
send lifetime (always valid) – (always valid) [valid now]
Rack1R6#
As you can see, the password for Key 2 ( the user one we just added ) is Cluless
 
Now, I am not sure if you noticed but for the first example the password is WillFlynnSurvive? – yes, that is a question mark in the password.  If you want to use a question mark as part of your password, you need to enter ctrl-v prior to typing the question mark in the password or the IOS will think you are looking for help. Old dirty CCIE lab prep tricks there.