LINUXOR.SK ... open source notes ...

Linux Storage - MDS base configuration commands

category: solutionz · date: 2013-12-31 · updated: 2026-10-03 · author: LALA

Linux Storage Solution · Config document · referenced from Cisco MDS base configuration

note<ADMIN_PASSWORD> and <ADMIN_PASSWORD_HASH> are placeholders, not values to copy. The command set starts with write erase and reload, which wipe the switch. The notes hold this command set for FCSwitch1 only; the second blade switch of the enclosure was configured the same way by the schema, but nothing of it is in my notes.

The command set that took the Cisco MDS 9124e blade switch FCSwitch1 from factory state to a switch with a management address, SSH, a name, two VSANs with their interfaces, and a local host entry. It is the first of the three switch command sets; the aliases and zoning follow in FC aliases and zoning and port security in Port security.

ItemValue
SwitchFCSwitch1, Cisco MDS 9124e blade switch in the HP c7000 enclosure, SW1 of the cabling schema
SoftwareNX-OS 5.2(8), the version line of the running configuration taken later
Run asuser admin, role network-admin
Modeswrite erase and reload at the exec prompt FCSwitch1#; the notes write everything after the setup dialogue at the same exec prompt, although username, interface, vsan database, feature, switchname and ip are configuration commands, which as I understand NX-OS means configure terminal was entered and not written down
Managementmgmt0 with 10.50.10.14 255.255.255.0, default gateway 10.50.10.254
VSANs11 MGMT_DC with ext1, bay1, bay2, bay5; 12 DMZ with ext2, bay3, bay4
Second switchNot in the notes

The commands

The switch was reset to defaults first. write erase ran at the exec prompt of FCSwitch1, as admin, and asked once; the y after [n] is the answer typed.

bash
$ write erase
output 2 lines
Warning: This command will erase the startup-configuration.
Do you wish to proceed anyway? (y/n)  [n] y

Then reload, again at the exec prompt. After the reboot the switch ran its setup utility: it asked whether to enforce the secure password standard (the author's note above that question reads "password complexity"), asked for the admin password twice, and offered the basic configuration dialogue, which was declined with no. Everything else was then set by hand.

bash
$ reload
output 25 lines
This command will reboot the system. (y/n)?  [n] y
Do you want to enforce secure password standard (yes/no) [y]:

 ---- System Admin Account Setup ----

Do you want to enforce secure password standard (yes/no) [y]: y

  Enter the password for "admin": <ADMIN_PASSWORD>
  Confirm the password for "admin": <ADMIN_PASSWORD>

---- Basic System Configuration Dialog ----

This setup utility will guide you through the basic configuration of
the system. Setup configures only enough connectivity for management
of the system.

Please register Cisco MDS 9000 Family devices promptly with your
supplier. Failure to register may affect response times for initial
service calls. MDS devices must be registered to receive entitled
support services.

Press Enter at anytime to skip a dialog. Use ctrl-c at anytime
to skip the remaining dialogs.

Would you like to enter the basic configuration dialog (yes/no): no

Set the password for the user admin. The author's comment: not strictly needed, since the password was changed by the setup wizard. The line carries the hash form (password 5) with a placeholder where the hash was, and the role network-admin. Configuration mode on FCSwitch1.

bash
$ username admin password 5 <ADMIN_PASSWORD_HASH>  role network-admin

Set the management IP address of the FC switch and the default gateway. The address goes under interface mgmt0, the gateway is a global command; configuration mode on FCSwitch1.

bash
$ interface mgmt0
$ ip address 10.50.10.14 255.255.255.0
$ ip default-gateway 10.50.10.254

Switch on the SSH server, configuration mode.

bash
$ feature ssh

Set the name of the switch, configuration mode.

bash
$ switchname FCSwitch1

Create the VSANs: the vsan database sub-mode, configuration mode on FCSwitch1.

bash
$ vsan database
$ vsan 11 name MGMT_DC
$ vsan 12 name DMZ

Assign the physical interfaces to the VSANs, again in the vsan database sub-mode. ext1 and ext2 are the external ports towards the 3PAR, bay1 to bay5 the internal ports to the blade slots.

bash
$ vsan database
$ vsan 11 interface ext1
$ vsan 12 interface ext2
$ vsan 11 interface bay1
$ vsan 11 interface bay2
$ vsan 12 interface bay3
$ vsan 12 interface bay4
$ vsan 11 interface bay5

Set the physical ports. The author's comment: not strictly needed, by default the ports are set to type F. Each interface line opens the interface sub-mode for the two lines after it; configuration mode on FCSwitch1.

bash
$ interface ext1
$ switchport mode F
$ no shutdown
$ interface ext2
$ switchport mode F
$ no shutdown
$ interface bay1
$ switchport mode F
$ no shutdown
$ interface bay2
$ switchport mode F
$ no shutdown
$ interface bay3
$ switchport mode F
$ no shutdown
$ interface bay4
$ switchport mode F
$ no shutdown
$ interface bay5
$ switchport mode F
$ no shutdown

An alternative to the file /etc/hosts: local resolution of domain names. Configuration mode on FCSwitch1.

bash
$ ip domain-lookup
$ ip host FCSwitch1 10.50.10.14

What the lines do

CommandWhat it does
write erasedeletes the startup configuration, so the next boot starts from factory defaults
reloadreboots; the setup utility runs because there is no startup configuration
username admin password 5 … role network-adminsets the admin password from a hash (5 is the hash form) and gives the user the network-admin role
interface mgmt0, ip addressthe out-of-band Ethernet management port and its address and mask
ip default-gatewaythe gateway for the management network
feature sshenables the SSH server
switchnamethe host name shown in the prompt
vsan database, vsan N namecreates a VSAN with a number and a name
vsan N interfaceputs a physical port into that VSAN; a port belongs to exactly one VSAN
switchport mode Ffixes the port as a fabric port for an end device, which the author notes is the default
no shutdownadministratively enables the port
ip domain-lookup, ip hostenables name resolution and adds one static name-to-address entry for the switch itself

The explanations of what the commands do are my general understanding of NX-OS; the notes only give the step titles. What the notes do not hold: how the switch was reached for the reset (a reset removes the management address, so it was presumably the serial console or the enclosure's management path, but the notes do not say), the NX-OS version at the time of the reset, any SNMP, NTP, syslog or AAA configuration, and the whole of the second switch.

Checked against Cisco MDS NX-OS 9.4(5a)

As builtToday
Cisco MDS 9124e blade switch, NX-OS 5.2(8)The parent MDS 9124 reached its last date of support on 31 January 2019; 5.2(8i) of late 2016 is the last release for it, and NX-OS 6.x and 7.x reached their last date of support on 30 April 2022. Current MDS NX-OS is 9.4(5a), on 32G and 64G switches such as the MDS 9124V and 9148V
write erase, reload, setup utility with "Do you want to enforce secure password standard"Unchanged; the setup utility also runs system default switchport mode F after a write erase or reload
username admin password 5 … role network-adminThe command still knows the password types 0, 5 and 7. Since NX-OS 8.2(1) new accounts are hashed with SHA-2 by default on current hardware, existing MD5 accounts stay MD5 until the password is changed; password strength-check is on by default
feature sshStill the command, but SSH is enabled by default with an RSA key and Telnet is disabled by default
interface mgmt0, ip address, ip default-gateway, switchnameUnchanged
vsan database, vsan N name, vsan N interfaceUnchanged; current guides name interfaces fcX/Y, the bayN and extN names exist only on the blade variants
switchport mode F, "the ports are set to type F by default"The documented default port mode is auto; the F default on this switch most likely came from the setup utility's system default switchport mode F. A default specific to the blade switch's bay ports is not documented in any current guide
ip domain-lookupUnchanged, enabled by default
ip host FCSwitch1 10.50.10.14Not in the 9.x Command Reference, the IP Services guide or the Fundamentals guide; what exists is ip domain-name, ip domain-list and ip name-server

The hardware and the software of this document are out of support, and the one line that no longer exists is the ip host entry. Everything else in the command set would still be accepted by a current MDS.

← solutionz