04-22-2013 04:24 AM - edited 03-07-2019 12:57 PM
Guys,
How separate is the management interface on a Nexus 5548?
In context - what's the risk of having a layer 2 only Nx5K in a DMZ and running the managment ports down into an internal managment VLAN, to form peer-keepalive links and software upgrades.
Thanks
Nik
Solved! Go to Solution.
04-22-2013 12:49 PM
No, you can't create loop with monument interface. It is in a separate vrf, out of band and also a host port. As you said, it is just a NIC.
HTH
04-22-2013 05:21 AM
What you describe is a supported Nexus deployment.
I'm not sure what you mean by separate, however the Management interface is assigned to its own Management VRF. This separates the management traffic from other VRFs and the global routing table. This in turn helps to improve security.
See below:
Don't forget to rate all helpful posts.
04-22-2013 07:41 AM
Good to hear may thanks
I guess - is the mgmt0 interface participate in bridging traffic? As such could the mgmt 0 interface create a layer 2 loop? Or it is just a NIC (i.e. a non-switchport)?
04-22-2013 12:49 PM
No, you can't create loop with monument interface. It is in a separate vrf, out of band and also a host port. As you said, it is just a NIC.
HTH
04-22-2013 11:43 PM
Reza,
Nice one cheers, spot on.
Many thanks nik
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide