cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
558
Views
0
Helpful
6
Replies

ACL on Nexus 9000 - behavior difference

M.Fly
Level 1
Level 1

Good morning,

i have strange behavior on two Nexus 9000
same identical configuration also compared with diff
same identical ACLs
scanning with nmap on specific ports returns different results

For the first Nexus for example, the 161udp port result filtered, on the second Nexus with the same ACL and CoPP configuration result open.

No difference in CoPP config or ACL config, the ACL match in same way.

Any idea?

And also, same NXOS on Nexus.

Very curious, any idea on some show command to find the difference?

Many thanks to all.

 

6 Replies 6

Hello,

 

could just be an NMAP false positive. Which parameters are you using for the scan ?

For the scan i use the same parameter:

nmap -A -Pn -sU -sT -p 161 10.10.10.1

The same server used for scan, same network.

Hello,

 

are both Nexus using the same SNMP version ?

Same SNMP version, same configuration of SNMP, same NXOS and same hardware:

 

Software
BIOS: version 05.38
NXOS: version 7.0(3)I7(9)

 

Hardware
cisco Nexus9000 C93180YC-FX Chassis

Anyone have an idea???

Is possible that the CoPP is the issue?

The IP of SNMP polling is owned by the NX9K, the CoPP is operational only on IP on owned by the NX9K, right?

There is a possibility that the configuration of CoPP is different for different hardware revision?

The software is the same...