Search This Blog

Showing posts with label nexus. Show all posts
Showing posts with label nexus. Show all posts

Sunday, April 27, 2014

You can use bash shell instead of Cisco CLI on Nexus Switches

Every one who works on Linux and understand how to efficiently use Bash hates to work with the limited Cisco IOS CLI. The design objectives standing behind this CLI haven't changed for the last 20 years or so. It is obvious that this tools lacks plenty of features expected from a modern shell for many people.

But the evolution or even revolution that is happening in networking thanks to SDN is changing this terrible static network configuration landscape. The new generation of network devises like Cisco Nexus platform are going to support in the Cisco NX-OS :
  • Bash shell
  • Python shell 
  • API access
  • Linux containers for custom applications
For these who still don't believe you can read about this here:

References

http://www.cisco.com/c/en/us/products/switches/nexus-9000-series-switches/white-paper-listing.html
http://rtomaszewski.blogspot.co.uk/search/label/sdn
http://rtomaszewski.blogspot.co.uk/2013/09/cisco-cheat-sheet.html

Thursday, August 29, 2013

VMware NSX network virtualization platform

VMware announced its new product NSX. In comparison it should be the same for network virtualization what flagship iESX product was for host virtualization.

This 2 links give a glimpse into the architecture design:

http://blogs.vmware.com/networkvirtualization/2013/08/vmware-nsx-network-operations.html
http://blogs.vmware.com/networkvirtualization/2013/08/vmware-nsx.html

These 2 pictures from the links above give a high level overview what it does and how it should work:


On the VMware page we can find as well as these two videos below that present the virtual network challenge for cloud deployments and shows how to solve it with the help of VMware NSX platform. 

http://bcove.me/idrpiovw
http://bcove.me/qe36t4fc

Wednesday, May 29, 2013

How does Nexus 1000v support VXLAN protocol

In the previous post we we explained how VXLAN works. Below is a complementary video about VXLAN from a Cisco product manager Han Yang showing a live Cisco Nexus 1000V training session.


Interesting facts that are not directly mentioned in the previous post:
  • Only one Nexus 1000V (N1V) can be deployed on a single hypervisor (multiple hypervisors have its own 1000V virtual switch)
  • Nexus 1000V has built in mechanism for loop prevention (time ~21:00)
    • if it receives a packet on the outside interface with a src MAC address that belongs to one of its attached VMs it drops it
    • it drops STP BPDU; as hypervisors are considered 'leaves' in the network topology they don't have to participate in STP 
  • As VXLAN is an L3/L4 network overlay it handles the VM generated broadcast, multicast and unknowns unicast with a help of IP multicast (time ~27:00)
  • The point above says that for example VM ARP request will be distributed to all hypervisors using IP multicast (remember that each hypervisor has its own IP; when there is a communication between hypervisors they communicate using their own IPs. The real VMs communication is encapsulated using VXLAN and is carry over in UDP datagram)
  • You don't have to have a separate multicast domain per VXLAN domain (resulting in separate multicast trees and multicast groups that a router need to managed). A single multicast can be shared by many VXLAN (time ~36:00)
  • Not sure about this: I have couple of VMs in my VXLAN that want to communicate together using IP multicast. This multicast traffic is not the same like when an ARP need to be distributed among hypervisors. This is VMs internal traffic. Will this VM IP multicast traffic be distributed to all hypervisors or only to these who actually host a relevant VM(s) that joined the VM multicast group before (IGMP snooping) (time 30:00-30:35)
  • In a single VXLAN you can have multiple customer defined VLANs (this becomes obvious when you look at the VXLAN frame headers) (time ~30:00)
  • You can tunnel VXLAN using OTV (time 45:00)
  • You need an L3 gateway device to allow traffic between traditional VLAN and VXLAN domains
  • There is an option to integrate within VXLAN network a vASA (virtual ASA) firewall

Sunday, April 14, 2013

Cisco Nexus NX-OS operating systems has a build in Python shell

The world is changing and Cisco doesn't want to stay behind. In its new NX-OS os that is targeting data centre and service provider customer they build in a python shell: Python API

More info about the Cisco Nexus can be found here:
http://www.cisco.com/en/US/products/ps9494/Products_Sub_Category_Home.html

Example:
 
switch# show clock                                           
23:54:55.872 UTC Wed May 16 2012

switch# python                          !-- Enter Python interpreter
switch# >>> cli("conf term ; interface loopback 1")          
switch(config-if)# >>> cli("ip address 1.1.1.1/24")          
switch(config-if)# >>> cli("exit")      !-- Exit the CLI interface mode
switch(config)# >>> cli("exit")                              
switch# >>> i=0                                              
switch# >>> while i<8:                                       
switch# ...   i=i+1                     !-- Composite command; prompt indicates more input
switch# ...   cmd = "show module %i" % i                     
switch# ...   r=clid(cmd)                                    
switch# ...   if "TABLE_modinfo/model" in r.keys():          
switch# ...     if r["TABLE_modinfo/model"] == "Nurburgring":
switch# ...       print "got a racer in slot %d" % i         
switch# ...                             !-- Empty input indicates end of loop
got a racer in slot 3                                        
switch# >>> exit                        ! -- Exit Python interpreter          
switch#