You are on page 1of 75

victory belongs to those that believe in it the most and believe in it the

longest

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
ONE
QQ: 119960991

50722586 ,
4565,85,76,12410,12416,CRS-1
:.---
,

2010 100
2010 100
2011 ccie
2011 ccie
2011 100
2009 100
2010
2010 CCIE
2009 100
2009 mpls vpn
2009 ISIS
2009 3560
2008 vpn
2008 ospf
2008 bgp
2008
RHCE5.0
3600
BGP
JUNIPER NETSCREEN

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

..................................................................................................................................... 5
............................................................................................................................. 6
....................................................................................................................................... 6
......................................................................................................................... 6
CCNP -.................................... 6
............................................................................................................................. 7
----------------------.......................................................................................................... 7
........................................................................................................................... 16
............................................................................................................... 16
N7000............................................................................................................. 17
N5000............................................................................................................................... 18
N2000............................................................................................................................... 20
N1000............................................................................................................................... 21
N1000---VN-link.............................................................................................................. 22
N1000---VM ESX Server................................................................................................ 25
............................................................................................................................... 29
........................................................................................................................... 31
M F .......................................................................................................... 31
............................................................................................................................... 32
VDC.............................................................................................................................. 33
VRF................................................................................................................................34
....................................................................................................................... 34
............................................................................................................................... 37
VLAN............................................................................................................................ 37
....................................................................................................................... 38
MSTP............................................................................................................................. 39
UDLD.............................................................................................................................39
VPC...........................................................................................................................39
Peer keepalive link............................................................................................... 41
peer-link...................................................................................................................42
peer-gateway and switch.............................................................................. 43
VPC..................................................................................................43
FEXes---FEXes NX ......................................................................45
static pinning......................................................................................................... 46
dynamic pinning...................................................................................................47
FEXes NX .................................................................................... 48
active-active FEX......................................................................................................50
N7K FEX........................................................................................................... 52
FEX ....................................................................................52
........................................................................................................................... 55
OSPF......................................................................................................................... 56

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
EIGRP........................................................................................................................56
ISIS............................................................................................................................. 57
BGP...........................................................................................................................57
IPV6 ..........................................................................................................58
........................................................................................................................... 58
--PIM............................................................................................................................. 59
IGMP.........................................................................................................................59
MSDP........................................................................................................................ 59
........................................................................................................................... 60
fabric path..............................................................................................................60
DCNM...................................................................................................................... 62
L2L3 .......................................................................................................... 63
Port-Profile...............................................................................................................63
ACS...........................................................................................................................64
CFS ........................................................................................... 65
ISSU............................................................................................................................... 66
ACL........................................................................................................................... 66
QOS.......................................................................................................................... 66
CMP..........................................................................................................................67
BFD............................................................................................................................67
................................................................................................................... 67
FCOE........................................................................................................................ 68
SCSIFCFCOE .......................................................................................... 68
SCSI\FC .................................................................................................. 69
FCOE ........................................................................................... 70
FCOE ....................................................................................................... 73
FCOE TOP...........................................................................................74

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest


2007
100

NX-OS 5.0 OS

FCOE

VDC
N7K 4
5 clear
TOP

SUP1

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

Love means never having to say youre sorry.----(

one

nexus
one 100 30
TAC

TAC50722586

300

taobao <http://ccie19.taobao.com/ >>

Stay hungry,stay foolish.--


.


CCNP -
http://bbs.56cto.com/thread-81313-1-1.html
700 800

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

1,5

56cto
Security IPS 642-627 Official Cert Guide 700
Security VPN 642-647 Official Cert Guide 800
Security Firewall 642-617 Official Cert Guide 700
Security Secure 642-637 Official Cert Guide
800


----------------------
victory belongs to those that believe in it the most and believe in it
the longest

Cisco ( 2 )
, 80

56cto bgp

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

EIGRP

ASA
ASA ASA
8.2 8.42
8.42

08 100
ccie

XXXX juniper

65 vss 65 sup 2T

100 5 mpls

56cto 56cto ,
56cto
56cto

2011 8 2

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

7010

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
Quan
Product

Description

tity

Price
63,000.

N7K-C7018

18 Slot Chassis, No Power Supplies, Fans Included

00

N7KS1K9-51

Cisco NX-OS Release 5.1

N7K-LAN1K9

Nexus 7000 LAN Enterprise License (L3 protocols)

31,500.
Nexus 7000 - 48 Port 10/100/1000, RJ-45, 40G

00

N7K-M148GT-11

Fabric

31,500.
1

00
56,700.

N7K-M148GS-11

Nexus 7000 - 48 Port 1G,

SFP, 40G Fabric

00
1,493.0

GLC-LH-SM

GE SFP, LC connector LX/LH transceiver

GLC-SX-MM

GE SFP, LC connector SX transceiver

750

GLC-T

1000BASE-T SFP

830

GLC-ZX-SM

1000BASE-ZX SFP

8,390.0
0
2,310.0
SFP-GE-L

1000BASE-LX/LH SFP (DOM)

0
1,155.0

SFP-GE-S

1000BASE-SX SFP (DOM)

SFP-GE-T

1000BASE-T SFP (NEBS 3 ESD)

924
8,390.0

SFP-GE-Z

1000BASE-ZX Gigabit Ethernet SFP (DOM)


Nexus 7000 - 32 Port 10GbE,

N7K-M132XP-12

80G Fabric (req.

SFP+)

147,000
1

.00
21,000.

SFP-10G-ER

10GBASE-ER SFP Module

00
8,390.0

SFP-10G-LR

10GBASE-LR SFP Module

0
3,140.0

SFP-10G-SR

10GBASE-SR SFP Module

N7K-M148GS-11

Nexus 7000 - 48 Port GE Module with XL Option

(req. SFP)

0
56,700.

00
1,493.0

GLC-LH-SM

GE SFP, LC connector LX/LH transceiver

GLC-SX-MM

GE SFP, LC connector SX transceiver

750

GLC-T

1000BASE-T SFP

830
8,390.0

GLC-ZX-SM

1000BASE-ZX SFP

0
2,310.0

SFP-GE-L

1000BASE-LX/LH SFP (DOM)

SFP-GE-S

1000BASE-SX SFP (DOM)

1,155.0

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
0
SFP-GE-T

1000BASE-T SFP (NEBS 3 ESD)

924
8,390.0

SFP-GE-Z

1000BASE-ZX Gigabit Ethernet SFP (DOM)

N7K-M108X2-12

92,400.
Nexus 7000 - 8 Port 10GbE with XL option (req. X2)

00
1,260.0

X2-10GB-CX4

10GBASE-CX4 X2 Module

0
21,000.

X2-10GB-ER

10GBASE-ER X2 Module

00
8,400.0

X2-10GB-LR

10GBASE-LR X2 Module

0
3,140.0

X2-10GB-LRM

10GBASE-LRM X2 Module

0
6,290.0

X2-10GB-LX4

10GBASE-LX4 X2 Module

0
4,190.0

X2-10GB-SR

10GBASE-SR X2 Module

0
33,600.

X2-10GB-ZR

10GBASE-ZR X2 Module

Nexus 7000 - 32 Port 1G/10G Ethernet Module,

00

N7K-F132XP-15

SFP/SFP+

105,000
1

.00
1,493.0

GLC-LH-SM

GE SFP, LC connector LX/LH transceiver

GLC-SX-MM

GE SFP, LC connector SX transceiver

750

GLC-T

1000BASE-T SFP

830
8,390.0

GLC-ZX-SM

1000BASE-ZX SFP

0
8,390.0

SFP-10G-LR

10GBASE-LR SFP Module

0
2,720.0

SFP-10G-LRM

10GBASE-LRM SFP Module

0
3,140.0

SFP-10G-SR

10GBASE-SR SFP Module

0
2,310.0

SFP-GE-L

1000BASE-LX/LH SFP (DOM)

0
1,155.0

SFP-GE-S

1000BASE-SX SFP (DOM)

SFP-GE-T

1000BASE-T SFP (NEBS 3 ESD)

924
8,390.0

SFP-GE-Z

1000BASE-ZX Gigabit Ethernet SFP (DOM)

Active Twinax cable assembly, 10m

861

SFP-H10GB-ACU
10M

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
SFP-H10GB-ACU
7M

Active Twinax cable assembly, 7m

756

10GBASE-CU SFP+ Cable 1 Meter

315

10GBASE-CU SFP+ Cable 3 Meter

441

10GBASE-CU SFP+ Cable 5 Meter

546

N7K-M148GT-11

Nexus 7000 - 48 Port 10/100/1000 Module with XL

option

N7K-M132XP-12

Nexus 7000 - 32 Port 10GbE with XL Option,

Fabric (req.

SFP-H10GB-CU1
M
SFP-H10GB-CU3
M
SFP-H10GB-CU5
31,500.
1
80G

00
147,000

.00
21,000.

SFP-10G-ER

10GBASE-ER SFP Module

00
8,390.0

SFP-10G-LR

10GBASE-LR SFP Module

0
2,720.0

SFP-10G-LRM

10GBASE-LRM SFP Module

0
3,140.0

SFP-10G-SR

10GBASE-SR SFP Module

Active Twinax cable assembly, 10m

861

Active Twinax cable assembly, 7m

756

10GBASE-CU SFP+ Cable 1 Meter

315

10GBASE-CU SFP+ Cable 3 Meter

441

10GBASE-CU SFP+ Cable 5 Meter

546

SFP-H10GB-ACU
10M
SFP-H10GB-ACU
7M
SFP-H10GB-CU1
M
SFP-H10GB-CU3
M
SFP-H10GB-CU5
M

Nexus 7000 - Supervisor, Includes External 8GB Log


N7K-SUP1

Flash

52,500.
1

Nexus Compact Flash Memory 2GB (Expansion

00

N7K-CPF-2GB

Flash - Slot 0)

2,520.0
1

Nexus 7000 - Supervisor, Includes External 8GB Log

N7K-SUP1

Flash

52,500.
1

00

Nexus Compact Flash Memory 2GB (Expansion

2,520.0

N7K-CPF-2GB

Flash - Slot 0)

N7K-C7018-FAB-

Nexus 7000 - 18 Slot Chassis - 46Gbps/Slot Fabric

Module

N7K-AC-7.5KW-I

Nexus 7000 - 7.5KW AC Power Supply Module

NT

International (cab

00

N7K-C7018-FD-

Nexus 7018 Front Door Kit

3,150.0

63,000.
5

00
63,000.

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
MB

N7K-SUP1-8GBU
PG

Nexus 7000 Supervisor 1 8GB Memory Upgrade Kit

PG

Nexus 7000 Supervisor 1 8GB Memory Upgrade Kit

N7K-C7018-FAN

Nexus 7000 - 18 Slot Fan

CON-OSP-N7KC

ONSITE 24X7X4 18 Slot Chassis, No Power Supplies,

7018

Fans

CON-OSP-C701

ONSITE 24X7X4 Nexus 7000 - 18 Slot Slot

8FB1

Chassis-46Gpbs

CON-OSP-7F32

ONSITE 24X7X4 Nexus 7000 - 32 Port 1G/10G

XP

Ethernet Fab

ONSITE 24X7X4 Nexus 7000 LAN Enterprise Lic

900

N7K-SUP1-8GBU

3,600.0
1

0
3,600.0

0
2,625.0

CON-OSP-N7LA
N
CON-OSP-N708

3,300.0

X2L

ONSITE 24X7X4 Nexus 7000 - 8 Port 10GbE

CON-OSP-N732

ONSITE 24X7X4 Nexus 7000 - 32 Port 10GbE, 80G

XP

Fabric

CON-OSP-7M32

ONSITE 24X7X4 Nexus 7000 - 32 Port 10GbE with XL

XPL

Opt

CON-OSP-M148

ONSITE 24X7X4 Nexus 7000 - 48 Port 1G, SFP, 40G

GS11

Fabric

0
5,252.0

0
5,252.0

0
2,025.0

CON-OSP-N748

0
2,025.0

GSL

ONSITE 24X7X4 Nexus 7000 - 48 Port GE Module

CON-OSP-N748

ONSITE 24X7X4 Nexus 7000 - 48 Port 10/100/1000,

RJ-45

CON-OSP-N748

ONSITE 24X7X4 Nexus 7000 - 48 Port 10/100/1000

GL

Module

CON-OSP-N7SU

ONSITE 24X7X4 Nexus 7000 - Supervisor, Includes

P1

Ext

CON-OSP-N7SU

ONSITE 24X7X4 Nexus 7000 - Supervisor, Includes

P1

Ext

0
1,125.0

0
1,125.0

0
3,000.0

0
3,000.0

127679
3

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

Quant
Product

Description

ity

Price

N5K-C5020P-B

N5000 2RU Chassis no PS 5 Fan Modules 40 ports (req

SFP+)

00

1.1

Nexus 5000 Base OS Software Rel 4.2(1)N1(1)

N5000FMS1K9

Nexus 5000 Fabric Manager Server License

14,700.

72,450.

N5KUK9-421N

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
00
50,400.
N5020-SSK9

Nexus 5020 Storage Protocols Services License

N5000 1000 Series Mod 4x10GE 4xFC 4/2/1G(req

00
10,920.

N5K-M1404

SFP+/SFP)

N5K-M1060

N5000 1000 Series Module 6port 8/4/2/1G FC

00
6,720.0

N5K-PAC-1200
W

0
6,300.0

Nexus 5020 PSU module, 100-240VAC 1200W

SFS Power Cord - 250V, 10A - PRC

Nexus 5020 Accessory Kit, Option

CON-OSP-N5S

ONSITE 24X7X4 Nexus 5020 Storage Protocols Svc

SK

License

ONSITE 24X7X4 N5000 2RU Chassis no PS 5

60

ONSITE 24X7X4 N5000 1000 Series Module

768

CON-OSP-N54

ONSITE 24X7X4 N5000 1000 Series Mod 4x10GE 4xFC

04

4/2/1G

SFS-250V-10ACN
N5020-ACC-KI
5,400.0

CON-OSP-N50
20

0
8,280.0

CON-OSP-N50
1,248.0
1

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest


PPT10G
1Tier: N7K2KN7K10G1GL2N7K
2Tier: N7K-N5K-N2K N7K-N7K-MDS,port-channel
MFNexus10GE
GE ethernet X/X,
N7KN5KLICN5KLIC
LICLIC
VDCSUP1
VDC
R S -2 3 2
T e r m in a l S e r v e r

IP N e t w o r k

? ? ?

IP A d d re s s C

Sup 1
IP A d d re s s A

(S h a r e d

IP )

IP A d d re s s B

Sup 2

gm t 0
V R F ( )

A c t iv e ? ? ? ? ?
IP N e t w o r k


interface eth 2/1-3 inter eth 2/1,eth 2/4-6 inter range
N7K-1-pod3(config)# int e1/18, e1/20,e1/22,e1/24
config config tdo show show
config-if
trunkswitch mode trunk ISL
NX-OS
UDLDN7Kfeatrue udld)10GUDLD1G

NX-OS profile,pro
profileprofile
NX-OSDTPtrunkTRUNKVLAN
VLAN
NX-OSVDC VLAN1600044000
NX-OSLACPPAGP
NX-OS STPSTP

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
RSTPPVST
span port type edge span portfast
NNX-OSIOSACL /24

N7000
N7KC6500
FWSMACE6509N7KFWSM
6509N7K

N7010

N7018

N7KVDC VLAN1600044000
N7KN2KN5K
N7Khardware
N7K
N7K DCCISCO

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

N5000
N5500N5000
501020 10E/FC0E/DCB 1 502040 2

8FCOEFC

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

N2000N5KFEX FEX FEXN2K


N2KFEX

5548:

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

N2000
N2000N2K
N5KN5KN2000K
N5KFEX FEX FEXN2KN2K
FEX
N5KN2KN2K
N7KN2KN5K

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

Descriptio
n

Specification

Cisco
Nexus
2148T

48 1000BASE-T host interfaces and 4 10 Gigabit


Ethernet fabric interfaces (Small Form-Factor
Pluggable Plus [SFP+])

Cisco
Nexus
2224TP

24 100/1000BASE-T host interfaces and 2 10 Gigabit


Ethernet fabric interfaces (SFP+)

Cisco
Nexus
2248TP

48 100/1000BASE-T host interfaces and 4 10 Gigabit


Ethernet fabric interfaces (SFP+)

Cisco
Nexus
2232PP

32 1/10 Gigabit Ethernet and Fibre Channel over


Ethernet (FCoE) host interfaces (SFP+) and 8 10
Gigabit Ethernet and FCoE fabric interfaces (SFP+)

Cisco
Nexus
2232TM

32 1/10GBASE-T host interfaces and modular


uplinks (8 10 Gigabit Ethernet fabric interfaces
(SFP+))

N1000

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N1000 N1000N1010ACS1U
ACS

VEM

VSM VMVSMVEM

N1000
N1000VSWN1000VCISCOVM
SW1000SWN1000V

CISCO VEMN1010VEMN1010
VEMV1010
N1010VSMVEM
N1000VN1010WLCAP
N1000VN1010NEXUS
NK-OSN5KN2KVPC

N1000NX
N5KN1000V VSMVN-link,
VN-LINK
N1KVVLANVM
VLANVMVLAN
NIV
VN-LINK
N1000VVMVLAN
accessVLANtrunk

N1000---VN-link
vn-link:N5KN1KVM
N5000N5K
Vn-linkVnicCISCOVN-LINK
()
VN-link nexus 1000v
NIV(network interface virtualization)VN-LINK
interface virtualizerpolo
nexus 1000V

VN-LINK

nexus
1000V
VN-LINK
VMwareAPINexus 1000v
ACCESSNIVvEthuplink
uplink trunk

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
ACCESSvlan
1.
Nexus1000V
1Virtual Ethernet module (VEM)-data plane
------Each hypervisor is embedded
with one VEM
2Virtual supervisor module (VSM)-control plane----
vCenterNexus 1000V system(VSM
)VSM64VEMVSMActive/StandbyHAVSM
VEM
VEM()

2.
NEXUS1000V
1 EthNIC(config) #int eth2/1ESXVEM
nexus 1000
2 vEthN1KACCESS
vMotion(ESX)

vEth pool

1.
NEXUS 1000V VN-LINK
1) profile
(config)# port-profile webservers
(config-port-prof)# switchport access vlan 10
(config-port-prof)# ip access-group 500 in
(config-port-prof)# inherit port-profile server
The port profile can then be assigned to a given vEth interface as follows:
(config)# interface veth1
(config-if)# inherit port-profile webservers
profileprofilevEther interfaceprofile
profilevEther
N1KVSMport-profileport-profileN1KvEthport-profile
up-link up-linkup-linkprofile
UPLINK profileuplinktrunkup-link profilesystem port-profile(
VSMVEM)uplink port-profile()
port-profilevCentervCenterN1Kport-profile
port groupport
groupVnicvNICport group

2)
VEM

vMotion
3NEXUS 1000VvMotion
Nexus 1000VVMwarevCenter
VMware VMotion

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
vCenter kick off vMotion()
NEXUS 1000VvCenterVMN1KVM(
port policy)VMup,VMvNICN1K port group
ConnectVMARPMAC

vMotionvEth
vCenterVMUUIDprofilevMotionUUID
profilevEth
NIV

VN-LINK

NIV
NIV
VN-LINK
NIVVN-LINKinterface virtualizer
poloVN-LINKinterface virtualizer
VN-TagVN-TagVN-LINK
2. NIV
NIV(network interface virtualization) CISCO
CISCOVMwareCisco VN-link
hypervisor
NIVVIS(virtual interface switch)802.1D802.1D
VIS

VNTagVISTag
IEEE802.3
NIVinterface virtualizerhypervisor
interface virtualizer
vEthVMvNICvNICvEthvEth
VN-TagVN-TagVN-linkNIV
interface virtualizer+VNTag+VN-linkVN-link
3.
1)VN-LINK
IVvEth
IVVISCIVVirtual Interface Control ProtocolIVvNIC
IVVISVIFVIFVISIV
IV(IVVISVIF)
VIFIVVIS vNIC enableVIFVIS enable
VIF IDIVIVVIF ID vNICvNICVIF
VN-LINKLinkVIF
vNICMACVIF VIS
MACVIF(VN-TAG)
IVMACtag
2)

interface virtualizervNICvNIC
tag(VN-tag)(VN-TagMACTag
VISTagVIF
)VISVN-TagVIF

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
VN-TagTaginterface virtualizervEth
vNIC interface virtualizer interface
virtualizerVN-TagVNtag Vnic
interface virtualizer
hypervisorinterface virtualizer
virtual interface switch (VIS)
virtual interfaces (VIFs)VIFvNIC(vEth)
VIFVIS
hypervisorVISNIV(network interface virtualization)

4.
NIV VMotion
1)
vMotion
2)
vCentervMontion
3)
copy
4)
(vEth)copy
5)
RARPMAC

N1000---VM ESX Server


VMware ESX

VMware ESX Server

VMotion
IT
( )
VMware ESX

VMware ESX
VMware ESX

1.ESX Server 2.5.x


ESX Server 2.5.x
ESX server
ESX Server16CPU
ESX Server80CPU
ESX Server64GB
8swapswap64GB
64

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
816
32
ESX Server16
128LUN
ESX Server128LUN
ESX Server 2.5.x
vSMP2CPU
3.6GB
4scsi15scsi
9GB
4

http://www.vmware.com/vmtn/resources/esx_resources.html
2.ESX Server 2.5.x
ESX Server 2.5.x
ESX Server 2.5.x
VirtualCenter 1.3
vSMP
Vmotion
ESXServerVirtualCenter
VirtualCenter
ESXServerVirtualCenterESXServer
vSMPVMotion
license
VMwareVINVirtual Infrastructure Nodelicense
ESX Server license
Virtual SMP license
VirtualCenter Agent license
vMotion license
VIN licenselicense
3.

ESX
4-5CPUCPU
41620CPU83240
CPUCPU
1GB

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
8232GBx395032
16464GBx395064
CPUCPU100%
cpu1.5CPU1CPUCPU
67
CPUMHz
500MHzCPUCPU
50%,CPU500MHz
CPUCPU

IBM TivoliHP OpenViewNetIQ

ESX Server3GHzCPU
28x395024000MHz10
OS21600MHz
20%
17280MHz500MHz
34(17,280/500=34.5)

54MB512MB
32MB Service Console
8ESX Server512MBVMkernel24MB

10512MB5120MB
54MB5120+540=5660 MB
Service Console (5660+512= 6172 MB) VMkernel 24MB
(6172+24=6196)106GB
8x3950

ESX Server

VMware

CPUI/O

4.VMotion
VMotionVMotion
VMotion
CPU
VMotionCPU
CPU(Intel or AMD)
CPU(Pentium III, Pentium 4, Opteron, etc)
CPU64SSE3

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
VMotionCPUCPU
VMotion
x366x260x3950CPUx3950VMotion
CPUxSeries
VMotionVMwareVMotion
VMwareVMotion
VMotion
5.Server farm
VirtualCenter 1.xfarmESX Server
farmVMotionVMotion
farmfarmVMware
farm
VMwareVMFSESX Server16
VMwareLUN32I/O100I/O

VMFS255
2TB
VMotionfarm16ESX Server
farmVMotionESX Server
farm
6

VMFSI/O32
SCSI
VMFS
28x395032CPU
32LUNLUN
20GB
LUN640GB10%
720GBredo

7
farm
ESX Server
ESX Server 2.5.x
Service console
VMwareService console
service console
service console
service console

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
service console
32

10208x395032
212

VLANVLAN

VLANESX Server
10ESX Server
2.5.x8
ESX ServerVLAN802.1qVLAN

ESX Server 2.5.x

VMotion
VMwareVMotion
VMotion
ESX Server
VMotion
8.
ESX Server 2.5.x
MACESX Server

ip
802.3adCisco
EtherChannel
ESX Server 2.5.xDMZ
VMware

http://www.vmware.com/support/pubs/esx_pubs.html
http://www.vmware.com/vmtn/resources/esx_resources.html

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

Cisco NX-OS
1
VDCCisco TrustSec
2
Cisco NX-OS 4.0
IP
OSPF v2v3 (IPv4v6)
IS-IS
BGP
EIGRP
IP
PIM: (IPv4IPv6)SSM
MSDP
PBR
GRE
3
Cisco NX-OS 4.0
VDC (OTVVDC
Cisco TrustSec


Cisco NX-OS N7K-LAN1K9
Cisco NX-OS N7K-ADV1K9
Cisco NX-OS 4.0Cisco Nexus 7000 Supervisor 1

N7KS1K9-401A1.1

MFnon-XLXL XLMAC
non-XL128KXL
VDC

DCNMVDC FP
N5K
N5010-SSK9(=)
Nexus 5010 Storage Protocol Services License
N5020-SSK9(=)
Nexus 5020 Storage Protocol Services License

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

N5000FMS1K9(=)
Nexus 5000 Fabric Manager Server License

22II / O
O
46

46 Gbps

46

Fabric 1

Requires
43Gbps

46

92 Gbps

46

Fabric 2

230
48 Port 1GE SFP

46

138 Gbps

46

Fabric 3
46

Requires
80Gbps

46

184 Gbps

230

Fabric 4

46

32 Port 10GE SFP+

230 Gbps

46

Fabric 5

CISCO
N+1
550Gb/s

M F
M-moduleL3(
MFCOE,F

F-moduleL2SUP

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

N7K-F132XP-15 SOCL2
FL3MMSUP1
MSUP1L3FL3M
Minter vlanPSVLANF
N7KMFN5000
L3L3M
non-XLXL XL128KXL
XL3VDC128K
VDC,2VDC128K

fu red 18KW6KW23KW
12KW N+1,16+6=12 6
grid redundancy 9KW 13+3+3=9KW

fu red 9KW 1
N exus 7010 6K w
w

(6x 220v = 18K w )

C an Lose 1 P S
or 1 G R ID

= ~9K w
= ~9K w

G R ID

( 6x 220v = 18K w )

= ~9K w
= ~9Kw

C an Lose 1 G R ID

X
N+1

( 6x 220v = 18K w )

= ~12K w

C an Lose 1 P S

= ~6K w

(6x 220v = 18K w )

= ~18Kw
= 0Kw

? ? ? !

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

::
7010 2400w
7018 2193w

10
18
10
18

32
4810/100/1000M
48SFP

1680w
1273w
60w
100w
210w
750w
400w
400w

300w
569w
55w
90w
190w
611w
358w
358w

VDC
(N7K 4VDC
VD1 VD1
VDC1VDC13VDC
N7KVDC1VDC1VDC
VDC VLANN7K-OS

VDC1reloadVDC.VDC reloadVDC
VDCboot image\SW\NTP\COPP\IN-BAN
SPAN SESSIONS
VDCIMAGE

OOB
VDCVDC

VDC1 switch VDC VDCVDC


VDC1VDC
VDCVDC 1
restartVDCVDCreload, 2
switchover switchover.restart VDC
restart,switchoverVDCVDC1
VDC1VDC
VDC120VDC
VDC1VDCVDCVDC1

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
VDC1VDC2VDC2VDC1
VDC1

VRF
NX-OSVRFMPLS VPNVRF
NX-OSVDC2VRFVRF
VRF
VRFVRFVRFVRF
VDCVRF
mgmt0VRFVDC
VDCVRFVRFVDC
VRF vrf context XX
vrf member (VRFL3L2VRF

N7K-1(config)#vrf context TEST


N7K-1(config)#interface vlan 10
N7K-1(config-if)#vrf member TEST
N7K-1(config-if)#ip add 10.10.10.1/24

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
Step 1. VDC03
VDC03 VDC03 VDC03
DCcisco123 VLAN 101-104LACP
DC-A-N7010 VDC03
vdc VDC03
allocate interface Ethernet1/9-16
allocate interface Ethernet3/13-24
VDC03 VRF
vrf context management
ip route 0.0.0.0/0 10.75.58.1
interface mgmt0
ip address 10.75.58.172/24
VLAN 101-104
vlan 101-104
OTV LACP
feature otv
feature lacp
Step 2. VDC03 VDC02/01
E1/15-16 Port-channel 20 VDC01 VDC02
interface port-channel20
switchport
switchport mode trunk
interface Ethernet1/15-16
switchport
switchport mode trunk
channel-group 20 mode active
no shutdown

VDC01 E1/5 VDC02 E1/21 Port-channel 301 VPC301


VPD01
interface port-channel301
switchport
switchport mode trunk
vpc 301
interface Ethernet1/5

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
switchport
switchport mode trunk
channel-group 301 mode active
no shutdown
VPD02
interface port-channel301
switchport
switchport mode trunk
vpc 301
interface Ethernet1/21
switchport
switchport mode trunk
channel-group 301 mode active
no shutdown

Step 3. OTV
VDC03 E1/9 IP
A VDC03 E1/910.1.1.1/24.
B VDC03 E1/910.1.1.2/24.
A VDC03
interface Ethernet1/9
ip address 10.1.1.1/24
ip igmp version 3
no shutdown
interface Overlay1
description site A
otv join-interface Ethernet1/9
otv control-group 239.1.1.1
otv data-group 232.1.1.0/28
otv extend-vlan 101-104
no shutdown

B VDC03
interface Ethernet1/9
ip address 10.1.1.2/24
ip igmp version 3
no shutdown

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

interface Overlay1
description site B
otv join-interface Ethernet1/9
otv control-group 239.1.1.1
otv data-group 232.1.1.0/28
otv extend-vlan 101-104
no shutdown


NX-OSDTPtrunkTRUNKVLAN
VLAN
N7KVDC VLAN1600044000
NX-OS STPSTP
RSTPPVST
MSTPPVST
MSTPVLAN
span port type edge span portfast
bridge assurance loop guardBPDU
hello bridge
assurance
spanning-tree port type network

VLAN
vlan1:VLAN
VLAN2-1005VLAN
VLAN 1006-4094 VLANVLAN
VLAN
VLAN 3948-40474094
VDCVLAN VDCVDC VLAN
16000
N7K-1(config)#vlan 20
N7K-1(config-vlan)#exit
N7K-1(config)#switchto vdc RED
N7K-1-RED#config
N7K-1-RED(config)#vlan 20

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N7K-1(config-vlan)#

VDC256
NX-OS
1()
2(LaCP) 802.3ad
NX-OSLACPPAGP
LACPACTIVEpassiveON
LACP
NX-OSP-C
n7000(config)# port-channel load-balance ethernet ?
dest-ip-port
Destination IP address and L4 port
dest-ip-port-vlan
Destination IP address, L4 port and VLAN
destination-ip-vlan
Destination IP address and VLAN
destination-mac
Destination MAC address
destination-port
Destination L4 port
source-dest-ip-port
Source & Destination IP address and L4 port
source-dest-ip-port-vlan Source & Destination IP address, L4 port and VLAN
source-dest-ip-vlan
Source & Destination IP address and VLAN
(Default for IP)
source-dest-mac
Source & Destination MAC address (Default for
Non-IP)
source-dest-port
Source & Destination L4 port
source-ip-port
Source IP address and L4 port
source-ip-port-vlan
Source IP address, L4 port and VLAN
source-ip-vlan
Source IP address and VLAN
source-mac
Source MAC address
source-port
Source L4 port
L2P-C
n7000(config)#feature lacp
n7000(config)# interface ethernet 1/25,ethernet 1/27
n7000(config-if-range)#switchport
n7000(config-if-range)#channel-group 1 mode active
n7000(config)#interface port-channel 1
n7000(config-if)#switchport mode trunk
n7000(config-if)#L2

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
L3P-C
interface port-channel1
ip address 192.168.10.1/24
interface Ethernet1/13
channel-group 1 mode active
interface Ethernet1/14
channel-group 1 mode active
P-C
show port-channel summary

MSTP
NX-OSCISCO
STP\RSTP\PVST
CISCONX-OSSTP6509PVST
CISCOMSTP
N7K-1config)#spanning-tree mod mst
N7K-1config)#spanning-tree mst configuration
N7K-1config-mst)#name MST
N7K-1config-mst)#revision 10
N7K-1config-mst)#instance 1 vlan 1,100
N7K-1config-mst)#instance 1 vlan 101,200
N7K-1config)#spanning-tree mst 1 root primary
N7K-1config)#spanning-tree mst 2 root secondary
N7K-2config)#spanning-tree mst 2 root primary
N7K-2config)#spanning-tree mst 1 root secondary

UDLD
UDLD10GUDLD1G
N7K-1(config)#feature udld
N7K-1(config)#udld aggressive
\\

VPC
STPVPC2
VPCN7KC65PC server

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
VPCL2port-channel,L3
N7K16N7K8N7K
IPTCP
1688
162216N52
N782N52N7162N5816

VPCPEERorphan port

VPCBPDU
VPCSWN7K2VDC
VPCsw port,L2L3inter vlan
VPCIPIPN5KN7K
L3
VPC
peer-link
Peer keepalive link
VPC
peer-gateway
peer-switch
VPC

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

Peer keepalive link


Peer keepalive link: L3OOBL3
peer-link
2CFS
L3L3

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

peer-link
peer-link:VPCN7K cfspeer-link

PEER-LINK10G
PEER-LINK Peer keepalive link
Peer keepalive linkL3PEER-LINK

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

peer-gateway and

switch

peer-gateway: 2
2
peer-gatewaySW
HSRP
peer-g
peer-switch L2BPDUBPDUBPDU
bridgeIDL2

VPC
TOP

N5K-1C6509
(
1N7K2
2N7KN5K
3N7Kvpc domain ID (VPC
4Peer keepalive link,

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
5peer-link,
6Peer-gateway Peer-switch VPC
7 VPCN7KN7K-N5K
VPCN7K VPC
N7KN5KVPC
12
N7K-1(config)#feature lacp
N7K-1(config)# interface ethernet 1/25,ethernet 1/27
N7K-1(config-if-range)#switchport
N7K-1(config-if-range)#channel-group 1 mode active
N7K-1(config)#interface port-channel 1
N7K-1(config-if)#switchport mode trunk
N7K-1(config-if)#switchport trunk allowed vlan 1-200
N7K-1(config-if)#spanning-tree port type network
N7K-2N7K-1
2N7KN5K
N7K
N7K-1(config)# interface ethernet 1/23
N7K-1(config-if-range)#switchport
N7K-1(config-if-range)#channel-group 2 mode active
N7K-1(config)#interface port-channel 2
N7K-1(config-if)#switchport mode trunk
N7K-1(config-if)#switchport trunk allowed vlan 1-200
N7K-1(config-if)#spanning-tree port type network
N5K
N5K(config)# interface ethernet 1/19,ethernet 1/20
N5K(config-if-range)#switchport
N5K(config-if-range)#channel-group 2 mode active
N5K(config)#interface port-channel 2
N5K(config-if)#switchport mode trunk
N5K(config-if)#switchport trunk allowed vlan 1-200
N5K(config-if)#spanning-tree port type network
3vpc domain ID
N7K-1config)#feature vpc
N7K-1config)#vpc domain 10
4Peer keepalive link,
N7K-1 config-vpc-domain)#peer-keepalive destination 192.168.1.2 source
192.1.68.1.1 vrf management
VRF VPC-KEEPALIVE
5peer-link,

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N7K-1(config)#interface port-channel 1
N7K-1(config-if)#peer-link
6Peer-gateway Peer-switch VPC
N7K-1config)#vpc domain 10
N7K-1config-vpc-domain)#Peer-gateway
N7K-1config-vpc-domain)#Peer-switch
7VPC
N7K-1(config)#interface port-channel 1
N7K-1(config-if)#vpc 1
N7K-1(config)#interface port-channel 2
N7K-1(config-if)#vpc 2

FEXes---FEXes NX
N5000+N2000
N5000N2000N5000802.1Qbh
N5000CBN2000PEN5000
N2000Cisco4500
PFC6500N5000

N5000+N2000CiscoFEXFabric ExtendPort Extend


N5000N2000FEXN2000
N2000FEX HIFHost
InterfaceN5000N2000NIFNetwork Interface
2248TNIFHIF

FEXes
1:straight-through using static pinning
2:straight-through using dynamic pinning
3:Active-active FEX using vpc
N7Kstraight-through using static pinning
N5K

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

static pinning
straight-through using static pinning:N2000

48N2000410GEN5K10GE12
1GE12
N2K410GEN5K

N5K-1(config)#feature fex
N5K-1(config)# fex 111
N5K-1(config-fex)#description "FEX 111, rack 1,top"
N5K-1(config-fex)#pinning max-links 4 (4422

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N5K-1(config)#interface ethernet 1/1-4
N5K-1(config-if-range)#switchport mode fex-fabric
N5K-1(config-if-range)#fex associate 111
show fex
show fex detail

dynamic pinning
straight-through using dynamic pinning
port-channelN2KN5K
N2K

N5K-1(config)#feature fex
N5K-1(config)# fex 121
N5K-1(config-fex)#description "FEX 121, rack 2,top"
N5K-1(config-fex)#pinning max-links 1 1
N5K-1(config)#interface ethernet 1/9-12
N5K-1(config-if-range)#switchport mode fex-fabric
N5K-1(config-if-range)#channel-group 21
N5K-1(config)#interface port-channel 21
N5K-1(config-if-range)#fex associate 121

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

FEXes NX

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

active-active FEX
Active-active FEX using vpc
N2KN5KN5K
VPCFEXportchannel.
N2KN5KVPCportchanneldynamic
pinning)

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

N5K-1N5K-2FEX
N5K-1(config)#feature fex
N5K-1(config)# fex 131
N5K-1(config-fex)#description "FEX 131, rack 3,top"
N5K-1(config-fex)#pinning max-links 1 1
N5KN2K4FEX31
N5K-1(config)#interface ethernet 1/17-20
N5K-1(config-if-range)#switchport mode fex-fabric
N5K-1(config-if-range)#channel-group 31
VPCVPCpeer-keepalive link
N5K-1config)#feature vpc
N5K-1config)#vpc domain 37
N5K-1config-vpc-domain)#peer-keepalive destination 192.168.1.2
N5K-1N5K-221
N5K-1(config)#interface ethernet 1/39-40
N5K-1(config-if-range)#channel-group 1
1trunkpeer-linkN5K
N5K-1(config)#interface port-channel 1
N5K-1(config-if)#switchport mode trunk
N5K-1(config-if)#vpc peer-link
N5K-1N5K-231VPCFEX

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N5K-1(config)#interface port-channel 31
N5K-1(config-if)#vpc 31
N5K-1(config-if)#fex associate 131
FEXN5KN5K
N5K-1(config)#interface ethernet 131/1/1
N5K-1(config-if)#switchport access vlan 10
N5K-2(config)#interface ethernet 131/1/1
N5K-2(config-if)#switchport access vlan 10
show vpc consistancy-parameters interface ethernet 131/1/2

N7K FEX
N7KFEXN5KN7KVDCFEX
VDCFEXN7Kport-channelN2K
N7K-1config)#install feature-set fex
N7K-1config-vdc)#no allow feature-set fex

N7K-1config)#install feature-set fex


N7K-1(config)#feature-set fex
N7K-1(config)# fex 141
N7K-1(config-fex)#description "FEX 141, rack 4,top"
N7K-1(config-fex)#pinning max-links 4 (N7K
N7K-1(config)#interface ethernet 1/1-2ethernet 1/9-10
N7K-1(config-if-range)#switchport
N7K-1(config-if-range)#switchport mode fex-fabric
N7K-1(config-if-range)#channel-group 41
N7K-1(config-if-range)#no shutdown
N7K-1(config)#interface port-channel 41
N7K-1(config-if-range)#fex associate 141

FEX

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

N2KN5Kfull mesh
full mesh
N2K4
N5KN2Kdynamic pinning VPCN2K
VPCport-channel,
port-channel
Step 1. Configure the management interface IP address and default route.
N5k-1(config)# int mgmt 0
N5k-1(config-if)# ip address 172.25.182.51/24
N5k-1(config-if)# vrf context management
N5k-1(config-vrf)# ip route 0.0.0.0/0 172.25.182.1
Step 2. Enable vPC and LACP.
N5k-1(config)# feature vpc
N5k-1(config)# feature lacp
Step 3. Create a VLAN.
N5k-1(config)#vlan 101
Step 4. Create the vPC domain.
N5k-1(config)# vpc domain 1
Step 5. Configure the vPC role priority (optional).

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N5k-1(config-vpc-domain)# role priority 1000
Step 6. Configure the peer keepalive link. The management interface IP address
for Cisco Nexus 5000 Series Switch 2 is 172.25.182.52.
N5k-1(config-vpc-domain)# peer-keepalive destination 172.25.182.52
Note:
--------:: Management VRF will be used as the default VRF ::-------Step 7. Configure the vPC peer link. Note that, as for a regular interswitch trunk,
trunking must be turned on for the VLANs to which the vPC member port belongs.
N5k-1(config-vpc-domain)# int ethernet 1/17-18
N5k-1(config-if-range)# channel-group 1 mode active
N5k-1(config-if-range)# int po1
N5k-1(config-if)# vpc peer-link
N5k-1(config-if)# switchport mode trunk
N5k-1(config-if)# switchport trunk allowed vlan 1,101
Step 8. Configure the Cisco Nexus 2000 Series Fabric Extenders and the fabric
interface.
N5k-1(config)# fex 100
N5k-1(config-fex)# pinning max-links 1
Change in Max-links will cause traffic disruption.
N5k-1(config-fex)# int e1/7-8
N5k-1(config-if-range)# channel-group 100
N5k-1(config-if-range)# int po100
N5k-1(config-if)# switchport mode fex-fabric
N5k-1(config-if)# fex associate 100
Step 9. Move the fabric extender interface to vPC. After fabric extender 100 (fex
100) comes online, create the PortChannel for interface eth100/1/1 and move the
PortChannel to the vPC. Note that the PortChannel number and vPC number can
be different, but the vPC number must be the same on both Cisco Nexus 5000
Series Switches.
N5k-1(config-if)# int ethernet 100/1/1
N5k-1(config-if)# channel-group 10
N5k-1(config-if)# int port-channel 10
N5k-1(config-if)# vpc 10
N5k-1(config-if)# switchport access vlan 101
The configuration steps for the second switch, Cisco Nexus 5000 Series Switch 2,
are:
N5k-2(config)# int mgmt 0
N5k-2(config-if)# ip address 172.25.182.52/24
N5k-2(config-if)# vrf context management

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N5k-2(config-vrf)# ip route 0.0.0.0/0 172.25.182.1
N5k-2(config)# feature vpc
N5k-2(config)# feature lacp
N5k-2(config)#vlan 101
N5k-2(config)# vpc domain 1
N5k-2(config-vpc-domain)# peer-keepalive destination 172.25.182.51
Note:
--------:: Management VRF will be used as the default VRF ::-------N5k-2(config-vpc-domain)# int ethernet 1/17-18
N5k-2(config-if-range)# channel-group 1 mode active
N5k-2(config-if-range)# int po1
N5k-2(config-if)# vpc peer-link
N5k-2(config-if)# switchport mode trunk
N5k-2(config-if)# switchport trunk allowed vlan 1,101
N5k-2(config)# fex 100
N5k-2(config-fex)# pinning max-links 1
Change in Max-links will cause traffic disruption.
N5k-2(config-fex)# int e1/9-10
N5k-2(config-if-range)# channel-group 100
N5k-2(config-if-range)# int po100
N5k-2(config-if)# switchport mode fex-fabric
N5k-2(config-if)# fex associate 100
N5k-2(config-if)# int ethernet 100/1/1
N5k-2(config-if)# channel-group 10
N5k-2(config-if)# int port-channel 10
N5k-2(config-if)# vpc 10
N5k-2(config-if)# switchport access vlan 101
For the deployment scenario in Figure 5, the fabric extender is dual-connected to
a pair of Cisco Nexus 5000 Series Switches. Most vPC-related configuration steps
are the same as in the previous example, except that the fabric interfaces on the
Cisco Nexus 5000 Series Switches will be moved to the vPC rather than to the
fabric extender host interface.


N7KL3RIP V2HSRPOSPF
256LIC
OSPF 108/BW 4 X 1010/BWISIS
OSPFnetwork
eigrp: N7Krouter eigrp 90 90AS

autonomous-system 20090AS

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
IOSVRF90
MPLS VRFIOS
N7KPBR
IPV6
OSPF V3IPV6
V2 IP V4
ISISN7K
-

OSPF
OSPF IPV4:
N7K-1(config)#feature ospf(LIC
N7K-1(config)#router ospf 1
N7K-1(config-router)#router-id 10.10.10.10
N7K-1(config-router)#log-adjacency-changes
N7K-1(config-router)#auto-cost reference-bandwidth 100 Gbps
NX-OS40G
N7K-1(config)#interface vlan 10,vlan 20-25
N7K-1(config-if-range)#ip router ospf 1 area 11
N7K-1(config-if-range)#ip ospf passive-interface
N7K-1(config)#interface ethernet 1/12-15
N7K-1(config-if-range)#ip router ospf 1 area 0
N7K-1(config-if-range)#ip ospf authentication message-digest
N7K-1(config-if-range)#ip ospf message-digest-key 1 md5 S3cr3t
OSPF IPV6:
N7K-1(config)#feature ospfv3(LIC
N7K-1(config)#router ospfv3 100
N7K-1(config-router)#router-id 10.10.10.10
N7K-1(config)#interface vlan 10,vlan 20-25
N7K-1(config-if-range)#ipv6 router ospfv3 100 area 11

EIGRP
EIGRP IPV4:
N7K-1(config)#feature eigrp(LIC
N7K-1(config)#router eigrp 1
N7K-1(config-router)#router-id 10.10.10.10
N7K-1(config-router)#log-adjacency-changes
N7K-1(config-router)#auto-cost reference-bandwidth 100 Gbps
NX-OS40G

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N7K-1(config)#interface vlan 10,vlan 20-25
N7K-1(config-if-range)#ip router eigrp 1
N7K-1(config-if-range)#ip passive-interface eigrp
N7K-1(config)#interface ethernet 1/12-15
N7K-1(config-if-range)#ip router eigrp 1
N7K-1(config-if-range)#ip authentication mode eigrp 1 md5
N7K-1(config-if-range)#ip authentication key-chain eigrp 1 EIGRP-CHAIN
N7K-1(config)#key chain EIGRP-CHAIN
N7K-1(config-keychain)#key 1
N7K-1(config-keychain)#key-string S3cr3t
EIGRP IPV6:
N7K-1(config)#feature eigrp(LIC
N7K-1(config)#router eigrp 200
N7K-1(config-router)#router-id 10.10.10.10
N7K-1(config-router)#address-family ipv6 unicast
N7K-1(config)#interface vlan 10,vlan 20-25
N7K-1(config-if-range)#ipv6 router eigrp 200

ISIS
N7K-1(config)#feature isis(LIC
N7K-1(config)#router isis DC
N7K-1(config-router)#net 49.0001.1921.6801.1011.00
N7K-1(config-router)#is-type level-1 (level-1-2)
N7K-1(config-router)#log-adjacency-changes
N7K-1(config-router)#reference-bandwidth 100 Gbps NX-OS
40G
N7K-1(config)#interface vlan 10,vlan 20-25
N7K-1(config-if-range)#ip router isis DC
N7K-1(config-if-range)#isis passive level-1
N7K-1(config)#interface ethernet 1/12-15
N7K-1(config-if-range)#ip router isis DC
N7K-1(config-if-range)#isis authentication-type md5 level-1
N7K-1(config-if-range)#ip authentication key-chain ISIS-CHAIN level-1
N7K-1(config)#key chain ISIS-CHAIN
N7K-1(config-keychain)#key 1
N7K-1(config-keychain)#key-string S3cr3t

BGP
BGP IPV4:
N7K-1(config)#feature bgp(LIC

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N7K-1(config)#router bgp 65000
N7K-1(config-router)#router-id 10.10.10.10
N7K-1(config-router)#address-family ipv4 unicast
N7K-1(config-router-af)#network 192.168.16.0/20
N7K-1(config-router)#neighbor 10.1.1.2 remote as 65001
N7K-1(config-router-neighbor)#description ISP peer router
N7K-1(config-router-neighbor)#address-family ipv4 unicast
N7K-1(config-router-neighbor-af)#next-hop-self
N7K-1(config-router)#neighbor 192.168.16.2 remote as 65000
N7K-1(config-router-neighbor)#description Internal peer N7K-2
N7K-1(config-router-neighbor)#update-source loopback 0
N7K-1(config-router)#address-family ipv4 unicast
BGP IPV6:
N7K-1(config)#feature bgp(LIC
N7K-1(config)#router bgp 65000
N7K-1(config-router)#router-id 10.10.10.10
N7K-1(config-router)#address-family ipv6 unicast
N7K-1(config-router-af)#network 2001:db8::/32
N7K-1(config-router)#neighbor 2001:db8:1::1/32 remote as 65001
N7K-1(config-router-neighbor)#address-family ipv6 unicast

IPV6
N7K-1(config)#interface vlan 10
N7K-1(config-if)#ipv6 address 2001:db8:1:10::/64 eui64(64
N7K-1(config)#interface ethernet 1/1
N7K-1(config-if)#ipv6 address 2001:db8:ffff:ffff::5/126
N7K-1(config)#interface ethernet 1/2
N7K-1(config-if)#ipv6 address use-link-local-only
N7K-1(config)#interface mgmt0
N7K-1(config-if)#ipv6 address 2001:db8:100:100::100/64
N7K-1(config)#ipv6 route ::/0 2001:db8:ffff:ffff::6
eui6464
use-link-local-onlyIPV6IPV6


NX-OSDM
NX-OS IGMP V2 V3

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

NX-OS
1PIM sparse mode: ASMRP
RPRP

2PIM Bidir: PIM PIM Bidir


RPRPRP

3PIM SSMPIM SSMSSMPIM Bidir


PIM SSM
IGMP V3
PIM SSMRP
CISCONX-OSIGMP V3 PIM SSM
MSDPNX-OSMBGP

--PIM
N7K-1(config)#feature pim
N7K-1(config)#ip pim log-neighbor-changes
N7K-1(config)#ip pim rp-address 192.168.1.1
N7K-1(config)#interface vlan 10
N7K-1(config-if)#ip pim sparse-mode
VRFRP
N7K-1(config)#vrf context VIDEO
N7K-1(config-vrf)#ip pim rp-address 10.1.1.1

IGMP
IGMPPIMIGMP
NX-OSIGMPV2
N7K-1(config)#interface vlan 10
N7K-1(config-if)#ip igmp version 3
IGMPNX-OSVLAN
vlan config 10(vlan 10)
no ip igmp snooping
IPNXL2IGMP

N7K-1(config)#interface vlan 10
N7K-1(config-if)#ip igmp snooping querier 192.168.37.1

MSDP

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N7K-1(config)#feature msdp
N7K-1(config)#interface loopback 1
N7K-1(config-if)#ip address 192.168.1.1/32
N7K-1(config)#ip msdp peer 192.168.1.2 connect-source

loopback1


N7K4
VDC
IP
VDCVDC

1 op
N7K-1(config)#role name op
N7K-1(config-role)#

2:
2:
N7K-1(config-role)#rule 1 permit read
N7K-1(config-role)#rule 2 permit read-writ feature diagnostics
N7K-1(config-role)#rule 3 permit read-writ feature ping
N7K-1(config-role)#rule 4 permit read-writ feature vlan
3
username op password cisco
show role name op
sho role pending-diff
NX-OS password check(
NX-OSCFS

CFSpeerlink
SSH V2
RSADSA
N7KDCNMN7KCLI
DCNMLIC,DCNMN7K
smart call home email
FTP
N7KXMLXMLAPI

fabric path
fabric path L2 over L3 LIC120fabric path
L2()

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

D M A C

S M A C

8 0 2 .1 Q
H e a d e r

E th e r
T y p e

P a y lo a d

C R C

FP16
O u te r
D A
(4 8 )*

O u te r
S A
(4 8 )*

F P
T A G
(3 2 *)

D M A C

S M A C

8 0 2 .1 Q
H e a d e r

E th e r
T y p e

P a y lo a d

STPISIS16256
L2L3COST
N7Kfabric pathMACN7KARP
MACMAC MAC
fabric pathISIS
fabric pathfabric pathFM
fabric path
MVLANFP
MVLANFPF
F VLANFPFP FP VLANFP CE
VLAN

N7K(config)# feature-set fabricpath


N7K(config)# vlan 10-19
N7K(config-vlan)# mode fabricpath
N7K(config)# interface port-channel 1
N7K(config-if)# switchport mode fabricpath
fabric pathN7000N5500N7KN5000

VPCfabric pathVPC+

http://ccie.taobao.com/

C R
(N e

victory belongs to those that believe in it the most and believe in it the
longest

N7K

DCNM
Cisco DCNM1
DCNM
1IP
2FCAPS

3 API

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

DCNMCISCO WORKS

1L1L2TOP
2
3CPU
4
5AAARBAC
DC
1VDC
2N
3VPC
4fabric path
5NX-OS

L2L3
L2BPDU UDLD
L3 NSFOSPFgraceful-restart HSRP VRRP
VRRPHSRPVRRP
HSRPHSRP VRRP

GLBPMAC

Port-Profile
,Port-Profile
n7000(config)# port-profile type ?
ethernet
Ethernet type
interface-vlan Interface-vlan type
port-channel
Port-channel type
n7000(config)# port-profile type ethernet Email-Template

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
n7000(config-ppm)# switchport
n7000(config-ppm)# switchport access vlan 10
n7000(config-ppm)# spanning-tree port type edge
n7000(config-ppm)# no shutdown
n7000(config-ppm)# description Email Server Port
n7000(config-ppm)# state enabled
n7000(config)# interface ethernet 2/1-2
n7000(config-if-range)# inherit port-profile Email-Template

ACS
ACSNX-OS
VDCACS
CISCOraduisLDAP
NX-OSAAAACS serverN7K

ACS

ACS
ACS
radius
100
N7K-1(config)#aaa group server radius RADSERVER
N7K-1(config-radius)#server 10.1.1.1
//ACS
N7K-1(config-radius)#server 10.1.1.2
N7K-1(config-radius)#deadtime 30
//
ACST
N7K-1(config-radius)#use-vrf management
ACS

ACS
ACS
ACS(
N7K-1(config)#aaa authentication login default group radius
// radius
radius\tacacs+\LDAPNX-OS

N7K-1(config)#aaa authentication logins console group RADSERVER


//CON
ACS

ACS
ACS

N7K-1(config)#redius-server host 10.1.1.1 test idle-time 20


//

N7K-1(config)#radius-server host 10.1.1.1 test username testuser //

N7K-1(config)#radius-server deadtime 30
//

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

N7K-1#test aaa server radius 10.1.1.1 test test

CFS
CFS NX-OS
radius\tacacs+\callhome\ntp\user&administrator roles
distribute
CFSCFSIPV4IPV6,
N7K
N7KPIM
N5K
cfs region x N7K
CFSCFScommit

CFS
CFS

1
CFS
CFS
N7K-1(config)#cfs ipv4 mcast-address 239.255.XX.XX(XX
are you sure?(y/n) [n] y
CFS

2
CFS
CFS
N7K-1(config)#cfs ipv4 distribute
3CFSCFS
N7K-1(config)#cfs region XX
N7K-1(config-cfs-region)#role
//roleCFS
y
are you sure?(y/n) [n]
N7K-1(config-cfs-region)#radius
//radiusCFS
are you sure?(y/n) [n] y

role
radius

4CFS
CFS
role
role
radius
N7K-1(config)#role distribute
N7K-1(config)#radius distribute

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

ISSU
ISSU:IOS2

:
install
all
kickstart
bootflash:n7000-s1-kickstart.4.0.1a.bin
system
bootflash:n7000-s1-dk9.4.0.1a.bin
FLASH
sys switchover
NX-OSEPLD
install module 5 epld bootflash:n7000-s1-epld.5.1.2.img

ACL
NX-OSIOSACL /24
ATOMIC ACLACLACL

NX-OS ACL config session

NX-OS PACLport ACLL2


ACLACL
ACL
N7KSGTSGACLACL
SGACLACS
ACS4.2
VMMACVN-LINK

QOS
N7Kinb QOS
N7KQOSIOSQOSpolicymap
N7Kpolicy map
N7Kqueuing policy map QOS policy map
inboundqueuing policy mapQOS policy map
outbound
queuing class map
1G 2 10G8
N55484WHY
service-policy
FCOE 4G
N5KN7K

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

CMP
SUP1CMP2511
CMPIOSN7KCMPN7K
CMP
attach cmp CATALISTsession
sup5,6 CMPSUPCMP
N7Kssh server enable
telnet server enable
CMP2SUPCMPIOS

moniter CP (N7K console CMP


attach CP CMPN7K console)

BFD
BFDBFDno hardware ip verify add ress identical
BFDno ip redirects
BFDIPN7K(N7KIDSIP
IP

N7K-1(config)#feature bfd
N7K-1(config)#router ospf 1
N7K-1(config-router)#bfd
N7K-1(config)#router eigrp 1
N7K-1(config-router)#bfd
N7K-1(config)#int vlan 10
N7K-1(config-if)#no ip redirects
N7K-1(config-if)#hsrp bfd
BFDno ip redirects
OSPFBFDOSPFno ip redirects


=auto-
VDC10
n7000# checkpoint
Processing the Request... Please Wait
................................. Done

n7000# show checkpoint summary


-------------------------------------------------------------------------------

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
Name
UserName
------------------------------------------------------------------------------auto-2
admin
2005

Created at
Tue May 24 22:24:01

VLAN 2030
n7000# config t
n7000(config)# no vlan 20, 30
auto-2
n7000# rollback running-configuration checkpoint auto-2
Processing the Request... Please Wait
Generating the Rollbackpatch... Please Wait
Executing the patch... Please Wait
`conf t`
\\ VLAN 20 & 30
running configuration
`vlan 20, 30`
!
n7000# clear checkpoint database
Processing the Request... Please Wait
.................................. Done

FCOE
IP

SCSIFCFCOE

SCSI
SCSI:Small Computer System Interface; :SCSI

SCSI

Fibre Channel
ChannelFCT11SAN

FC
FC
SCSIIPSCSI3
FCPFC Protocol

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
FC1Gb/s2Gb/s4Gb/s8Gb/sNMb

FCOE
FCOEFibre Channel over Ethernet
FCoE4ITANSIT11

FCoESAN
FC-SANFC-SANFC-SAN
FCI/O
FCoE802.3x PAUSE

SCSI\FC
Fibre channel\SCSI busFCOESCSI
TCP/IPfibre channel

FCloginLOGINIPTCP

FCTCP/IPwindowwindow
buffer-to-buffer flow
control.
FCTCP
end-to-end control

FC
1point to point oriented
LOGINTCP
2N_port to N_port connection
3Flow controlled : hop-by-hop and end-to-end basis

4acknowledged TCPACK
5 Multiple connections allowed per device
TCP/UPD

FC E port,FCF port,FC
HUBFL Port.
FCID/WWN TCP/IP IP/MAC

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
FCFCID
FCWWNMAC

FCOE
FCOE

CISCOFCOEN5KFCOE
FCOE (
N5KFCOEFCOE
FCOESAN

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

N5Ktrunk 2
VLANVLANVLAN
N5KLOGINN5K
FIP

VLANVLAN
VSANNXSAN
N5KVLANVSAN
VSAN14094VSAN
FCOESANSANV
SAN VS VSAN , FC port VS VFC ,E port VS VE port

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

SANNX
SANVSANSANSAN
VSAN
VSAN

DCVSANVSAN1
VSANVLANNXSANSWaccess
VSAN trunkTE port
MDS

FCOE
FCOE
N5K

FCOE

trunk
1
N5K
N5K
FCOE
FCOE
trunk
N5K-1(config)# interface ethernet 131/1/1
//131N2KFEXFCOE
N2232
N5K-1(config-if)#switch mode trunk
N5K-1(config-if)#span port type dege trunk

VLAN

2:
2:
VLAN
VLAN
N5K-1(config-if)#switch trunk native vlan 2(VLAN2
vlan1 VLAN10
VLANVLAN,
VLANVLAN

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
N5K-1(config-if)#switch trunk allowed vlan 2,20

VFC

VFC

3:
3:
VFC
VFC
VFC
VFC
N5K-1(config)#inter vfc 30
N5K-1(config-if)#bind inter ethernet 131/1/1
N5K-1(config-if)#no shut
VLAN 20
VSAN VLAN 200

VLAN20
VSAN VLAN 200

4
VLAN
20
200
VLAN20
VLAN20
200

N5K-1(config)#vlan 20
N5K-1(config-vlan)#fcoe vsan 200
N5K-1(config-vlan)#exit
N5K-1(config)#vsan database
N5K-1(config-vsan)#vsan 200
N5K-1(config-vsan)#vsan 200 inter vfc 30VFCVSAN)
N5K-1(config-vsan)#exit
show vsan membership
show vlan fcoe
VSAN
VSANVLAN
N5K-1(config)#vsan databaes
N5K-1(config-vsan)#vsan 2
N5K-1(config-vsan)#vsan 2 name AB
N5K-1(config-vsan)#vsan 3
N5K-1(config-vsan)#vsan 3 name CD
N5K-1(config-vsan)#no vsan 2

FCOE
FCOE
F PORTFCIDVMFCIV
FCID
FIPFCOEFIP

FCOEtrunk
FCOESANSWFCOE
MAC
FCOEN5KFCOEV Eport
FCOEQOS

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest
FCLLDPCDP
FCOEDCBDCBXDCB
.
FCOETRUNKVSANVLAN
VSANVLANVFCVSANVSAN VLANFCOE

VLAN
VFCVLANFCVSAM(VSAN
VSAN VLAN VFC VLAN VSAN VFC
VLAN
VLANVLAN
VFC VLANnative vlan
VSAN14094VSAN
SWIDSWFCIDVSAN
domain ID
domainIDVSAN ID

FCOE TOP

http://ccie.taobao.com/

victory belongs to those that believe in it the most and believe in it the
longest

http://ccie.taobao.com/

You might also like