Linux Storage - MDS base configuration commands
Linux Storage Solution · Config document · referenced from Cisco MDS base configuration
<ADMIN_PASSWORD> and <ADMIN_PASSWORD_HASH> are placeholders, not values to copy. The command set starts with write erase and reload, which wipe the switch. The notes hold this command set for FCSwitch1 only; the second blade switch of the enclosure was configured the same way by the schema, but nothing of it is in my notes.The command set that took the Cisco MDS 9124e blade switch FCSwitch1 from factory state to a switch with a management address, SSH, a name, two VSANs with their interfaces, and a local host entry. It is the first of the three switch command sets; the aliases and zoning follow in FC aliases and zoning and port security in Port security.
| Item | Value |
|---|---|
| Switch | FCSwitch1, Cisco MDS 9124e blade switch in the HP c7000 enclosure, SW1 of the cabling schema |
| Software | NX-OS 5.2(8), the version line of the running configuration taken later |
| Run as | user admin, role network-admin |
| Modes | write erase and reload at the exec prompt FCSwitch1#; the notes write everything after the setup dialogue at the same exec prompt, although username, interface, vsan database, feature, switchname and ip are configuration commands, which as I understand NX-OS means configure terminal was entered and not written down |
| Management | mgmt0 with 10.50.10.14 255.255.255.0, default gateway 10.50.10.254 |
| VSANs | 11 MGMT_DC with ext1, bay1, bay2, bay5; 12 DMZ with ext2, bay3, bay4 |
| Second switch | Not in the notes |
The commands
The switch was reset to defaults first. write erase ran at the exec prompt of FCSwitch1, as admin, and asked once; the y after [n] is the answer typed.
$ write eraseoutput 2 lines
Warning: This command will erase the startup-configuration. Do you wish to proceed anyway? (y/n) [n] y
Then reload, again at the exec prompt. After the reboot the switch ran its setup utility: it asked whether to enforce the secure password standard (the author's note above that question reads "password complexity"), asked for the admin password twice, and offered the basic configuration dialogue, which was declined with no. Everything else was then set by hand.
$ reloadoutput 25 lines
This command will reboot the system. (y/n)? [n] y Do you want to enforce secure password standard (yes/no) [y]: ---- System Admin Account Setup ---- Do you want to enforce secure password standard (yes/no) [y]: y Enter the password for "admin": <ADMIN_PASSWORD> Confirm the password for "admin": <ADMIN_PASSWORD> ---- Basic System Configuration Dialog ---- This setup utility will guide you through the basic configuration of the system. Setup configures only enough connectivity for management of the system. Please register Cisco MDS 9000 Family devices promptly with your supplier. Failure to register may affect response times for initial service calls. MDS devices must be registered to receive entitled support services. Press Enter at anytime to skip a dialog. Use ctrl-c at anytime to skip the remaining dialogs. Would you like to enter the basic configuration dialog (yes/no): no
Set the password for the user admin. The author's comment: not strictly needed, since the password was changed by the setup wizard. The line carries the hash form (password 5) with a placeholder where the hash was, and the role network-admin. Configuration mode on FCSwitch1.
$ username admin password 5 <ADMIN_PASSWORD_HASH> role network-admin
Set the management IP address of the FC switch and the default gateway. The address goes under interface mgmt0, the gateway is a global command; configuration mode on FCSwitch1.
$ interface mgmt0 $ ip address 10.50.10.14 255.255.255.0 $ ip default-gateway 10.50.10.254
Switch on the SSH server, configuration mode.
$ feature ssh
Set the name of the switch, configuration mode.
$ switchname FCSwitch1Create the VSANs: the vsan database sub-mode, configuration mode on FCSwitch1.
$ vsan database $ vsan 11 name MGMT_DC $ vsan 12 name DMZ
Assign the physical interfaces to the VSANs, again in the vsan database sub-mode. ext1 and ext2 are the external ports towards the 3PAR, bay1 to bay5 the internal ports to the blade slots.
$ vsan database $ vsan 11 interface ext1 $ vsan 12 interface ext2 $ vsan 11 interface bay1 $ vsan 11 interface bay2 $ vsan 12 interface bay3 $ vsan 12 interface bay4 $ vsan 11 interface bay5
Set the physical ports. The author's comment: not strictly needed, by default the ports are set to type F. Each interface line opens the interface sub-mode for the two lines after it; configuration mode on FCSwitch1.
$ interface ext1 $ switchport mode F $ no shutdown $ interface ext2 $ switchport mode F $ no shutdown $ interface bay1 $ switchport mode F $ no shutdown $ interface bay2 $ switchport mode F $ no shutdown $ interface bay3 $ switchport mode F $ no shutdown $ interface bay4 $ switchport mode F $ no shutdown $ interface bay5 $ switchport mode F $ no shutdown
An alternative to the file /etc/hosts: local resolution of domain names. Configuration mode on FCSwitch1.
$ ip domain-lookup $ ip host FCSwitch1 10.50.10.14
What the lines do
| Command | What it does |
|---|---|
write erase | deletes the startup configuration, so the next boot starts from factory defaults |
reload | reboots; the setup utility runs because there is no startup configuration |
username admin password 5 … role network-admin | sets the admin password from a hash (5 is the hash form) and gives the user the network-admin role |
interface mgmt0, ip address | the out-of-band Ethernet management port and its address and mask |
ip default-gateway | the gateway for the management network |
feature ssh | enables the SSH server |
switchname | the host name shown in the prompt |
vsan database, vsan N name | creates a VSAN with a number and a name |
vsan N interface | puts a physical port into that VSAN; a port belongs to exactly one VSAN |
switchport mode F | fixes the port as a fabric port for an end device, which the author notes is the default |
no shutdown | administratively enables the port |
ip domain-lookup, ip host | enables name resolution and adds one static name-to-address entry for the switch itself |
The explanations of what the commands do are my general understanding of NX-OS; the notes only give the step titles. What the notes do not hold: how the switch was reached for the reset (a reset removes the management address, so it was presumably the serial console or the enclosure's management path, but the notes do not say), the NX-OS version at the time of the reset, any SNMP, NTP, syslog or AAA configuration, and the whole of the second switch.
Checked against Cisco MDS NX-OS 9.4(5a)
| As built | Today |
|---|---|
Cisco MDS 9124e blade switch, NX-OS 5.2(8) | The parent MDS 9124 reached its last date of support on 31 January 2019; 5.2(8i) of late 2016 is the last release for it, and NX-OS 6.x and 7.x reached their last date of support on 30 April 2022. Current MDS NX-OS is 9.4(5a), on 32G and 64G switches such as the MDS 9124V and 9148V |
write erase, reload, setup utility with "Do you want to enforce secure password standard" | Unchanged; the setup utility also runs system default switchport mode F after a write erase or reload |
username admin password 5 … role network-admin | The command still knows the password types 0, 5 and 7. Since NX-OS 8.2(1) new accounts are hashed with SHA-2 by default on current hardware, existing MD5 accounts stay MD5 until the password is changed; password strength-check is on by default |
feature ssh | Still the command, but SSH is enabled by default with an RSA key and Telnet is disabled by default |
interface mgmt0, ip address, ip default-gateway, switchname | Unchanged |
vsan database, vsan N name, vsan N interface | Unchanged; current guides name interfaces fcX/Y, the bayN and extN names exist only on the blade variants |
switchport mode F, "the ports are set to type F by default" | The documented default port mode is auto; the F default on this switch most likely came from the setup utility's system default switchport mode F. A default specific to the blade switch's bay ports is not documented in any current guide |
ip domain-lookup | Unchanged, enabled by default |
ip host FCSwitch1 10.50.10.14 | Not in the 9.x Command Reference, the IP Services guide or the Fundamentals guide; what exists is ip domain-name, ip domain-list and ip name-server |
The hardware and the software of this document are out of support, and the one line that no longer exists is the ip host entry. Everything else in the command set would still be accepted by a current MDS.