cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3328
Views
20
Helpful
10
Replies

CSACS-3415 ACS 5.4 NIC Bonding / Teaming possible ?

ffischer
Level 1
Level 1

Hi Team,

I know, this topic has been answered for the "old" 11x Appliances: not possible.

Does the new UCS hardware change anything ?

Can we bundle 2 NICs somehow to get interface redundancy ?

If still not possible to configure that in ACS 5 itself:

Can it enentually be done on the "hardware" level

within the appliance firmware (UCS BIOS)  ?

Frank

(RHEL would provide NIC bonding,,, unfortunately its not accessable from ACS5 CLI)

10 Replies 10

Jatin Katyal
Cisco Employee
Cisco Employee

The server is shipped with a default NIC mode called Shared LOM, default NIC redundancy is active-active, and DHCP is enabled. Shared LOM mode enables the two 1-Gb Ethernet ports to access the Cisco Integrated Management Interface (CIMC). If you want to use the 1-Gb Ethernet dedicated management port, or a port on a Cisco UCS P81E Virtual Interface Card (VIC) to access the CIMC, you must first connect to the server and change the NIC mode as described in Step 3 of the following procedure. In that step, you can also change the NIC redundancy and set static IP settings.

NIC Modes and NIC Redundancy Settings

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/installation/guide/csacs_hw_ins_ucs.html#wp1185589

Jatin Katyal


- Do rate helpful posts -

~Jatin

Thanks, I read that already.

But I think this only applies to CIMC Service on the UCS Server

but not how the interfaces show up an can be used in ACS5 (ADE-OS)

The new applance is delivered with a additional PCI NIC, totally 5 Eth Ports.

We have 3 "On Board"  NICs (1x "GbE dedicated management”, 2x GbE named LAN1 and LAN2)

and  2 other Ports on the SNS-N2XX-ABPCI01 Broadcom 5709 Dual Port 10/100/1Gb PCI card

Our client requests having non redundandent CIMC access over the dedicated management port

and use 2 other NICs teamed together for ACS 5.4. to get interface redundancy...

Frank

Yep! As per below listed doc. it seems it only applies for Cisco Integrated Management Interface (CIMC)

step 4. Set the NIC mode to your choice for which ports to use to access the CIMC for server management

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/installation/guide/csacs_hw_ins_ucs.html#wp1188250

You might have read that doc. too but just wanted to share what I find.

Jatin Katyal


- Do rate helpful posts -

~Jatin

While helping someone, I found this defect with using gig0(mgmt) and gig1(service) on primary ACS

CSCuf44685    5.4: Incorrect host entry added on adding a new interface.

If we have ACS 5.4 in deployment.

- Secondary ACS will unable to join primary.

- Login to secondary ACS will be slow after configuring eth1 or eth2 on primary.

Jatin Katyal


- Do rate helpful posts -

~Jatin

ffischer
Level 1
Level 1

According to feedback from Cisco,

NIC teaming is not possible with ACS 5.4.

But we heard, apparently we are not the only one requesting it.

So I would guess there could be some chance

to get it with one of the upcoming ACS releases.

btw:

We used the dedicated Management Port for CIMC Access.

Then we had to connect on-board physical ethernet port labled "LAN1" to the LAN on a 3415.

This will be interface GigabitEthernet 0 in ADE-OS.

It seems obvious, but I did not found that mapping described anywhere in the manuals...

Regards, Frank

NIC bonding is a commited feature for ACS 5.5.

ACS 5.5 will be posted towards the end of this year

y.lo
Level 1
Level 1

May I know if ACS 5.5 on 3415 appliance support NIC bonding? In installation and upgrade guide of ACS 5.5, I can only find NIC bonding on 1121 appliance.

If it is supported on 3415 appliance, how to configure it?

Thanks a lot.

Yes it does. ACS 5.5 with the Cisco SNS-3415, Cisco SNS-3495, virtual machine, or CSACS-1121 platform allows you to use up to four network interfaces: Ethernet 0, Ethernet 1, Ethernet 2, and Ethernet 3.

NIC Bonding

http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/installation/guide/csacs_book/csacs_hw_ins.html#pgfId-1191791

Creating interface bonding

http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-5/installation/guide/csacs_book/csacs_hw_ins.html#pgfId-1197533

 

Regards,

Jatin Katyal

*Do rate helpful posts*

~Jatin

Anoop Saxena
Level 1
Level 1

Hi Jatin,

 

Will this require LAG configuration on Switch end for this work?

-Anoop

Switch doesn't require any port-channel configuration. Both ports connected to ACS should be simply access ports.

 

ACS uses only one of them simultaneously, so if active link goes down, appliance copies IP to redundant interface and continue working as previous. Switch even doesn't know about bonding.