I was involved with a network migration that made me look at using the power of EEM, below is a solution for anyone who may find themselves in a similar situation.
I was tasked to upgrade a legacy access layer of a network which was still consisting of unmanaged switches (flat network) to a Cisco solution which consisted of 3850's (Core/Distribution Layer) and 2960X for the access layer with dedicated subnets for each specific service operating on the network.
The challenge was the access layer as there were multiple devices such as printers, access control and other devices on the network with static IP's. Therefore we would need to determine on which ports they are connected to so we can migrate them over to the new structured VLAN's that was designed for each service. Since the device are connected to unmanaged switches, there was no way to verify this on the switch port level and it was also not practical to physically trace the cable from the end device to the switch port. There was also a very large amount of end device so to try and track them once they were on the Cisco access layer would result in a large amount of effort and time.
The other problem was that we did not have Cisco ISE to utilise the MAB functionality so ports can be dynamically assigned VLAN's based on the end device MAC address.
Using EEM we would create a script to create a description on the switch ports so we can identify the type of devices. In order to get the correct MAC addresses, we requested the system admins who support the end device to provide a list of the device with their static IP's.
Since the Cisco core was already active and we had an SVI that was in the same subnet as the legacy network, we could pull the IP's and associated MAC addresses from the ARP table.
This gave us clarity on what the OUI addresses were for the end devices. In this solution we had to break the devices up in the following classes:
In our situation, we would do the port configuration in a two-step approach, first replace unmanaged switches with Cisco 2960X's and identify the ports by applying a description. The second step would be to change the switch port VLAN configuration once system admin confirmed they changed the end device's IP address.
Once all the ports were identified we knew which ports still need to stay on the legacy VLAN, while the remainder can be configured as per the new design, it was easy to coordinate with the support teams onsite when they were migrating the end devices to the new IP subnets. We could also modify the scripts to automatically apply the VLAN configuration should a new device connect to the switch or if someone moves the cable to a different port.
There are of course other solutions out there such as SmartPort and ISE, however, if you don't have these options to your disposal, EEM is an extremely powerful tool that can give you the same results.
Hello! I need to connect remote network 10.180.100.0/24 to our corporate network. I'm going to use SVI Vlan 500 as point-to-point link on L3 swtich on both switches, network 10.255.1.10/30. The question is can I use SVI Vlan 500 with network 10.255.1.10/3...
Hello, There is a Cisco router configured by another IT guy with specified addresses from ISP, now the problem is that the ISP give us new net mask and default gateway addresses, so what i did was changing the following addressesold ISP address -ip addres...
Regarding the cisco nexus 93180YC-Fx switch the data sheet or user manual claims that it supports 1g/10g/25g. But it is not supporting 1g. The ethernet port by default shows that the media type is 10g. I use an intel sfp. Is that the problem or the switch...
Hi Anyone can you please explain me how the stacking capacity is 80 Gbps for 2960x switch. On what basis it was considered. Is there any port for stacking. If yes what kind of port it is and what is its speed.
Hi All, I have configured the netflow v5 collection on one of my ASR1002 , but it never collect the flow . Could you guys give some suggestion ? Version : ASR1000 Software (PPC_LINUX_IOSD-ADVENTERP...