01-12-2015 08:45 AM - edited 03-07-2019 10:11 PM
Dear all,
I'm currently in the process of configuring two Nexus 5672 Switches for our Network. I connected one of the switches to our catalyst 3750 Core using trunks on each side. Everything worked just fine - the link came up and I was able to manage the Nexus using the SVI I created in VLAN1.
However, after upgrading the Nexus 5672 from NX-OS 7.0(2)N1(1) to 7.1(0)N1(1), the connection between the Nexus and the Catalyst 3750 is broken - the corresponding port on the Nexus (eth 1/1) is blocked by STP due to a Port VLAN ID mismatch and it chooses itself to be the root bridge:
sw-5672-01# show spanning-tree
VLAN0001
Spanning tree enabled protocol rstp
Root ID Priority 32769
Address 8c60.4f1b.9181
This bridge is the root
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32769 (priority 32768 sys-id-ext 1)
Address 8c60.4f1b.9181
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Eth1/1 Desg BKN*4 128.129 P2p Peer(STP) *PVID_Inc
Eth2/1 Desg FWD 1 128.257 P2p
sw-5672-01# show spanning-tree detail
Port 129 (Ethernet1/1) of VLAN0001 is broken (Port VLAN ID Mismatch)
Port path cost 4, Port priority 128, Port Identifier 128.129
Designated root has priority 24577, address 000d.bce9.2b00
Designated bridge has priority 32769, address 8c60.4f1b.9181
Designated port id is 128.129, designated path cost 4
Timers: message age 0, forward delay 14, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default, Peer is STP
BPDU: sent 164, received 309
However, the trunks on both switches are configured with the same values and I don't see any problem here:
Trunk Port on the nexus switch:
sw-5672-01# show interface ethernet 1/1 switchport
Name: Ethernet1/1
Switchport: Enabled
Switchport Monitor: Not enabled
Operational Mode: trunk
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Trunking VLANs Allowed: 1-4094
Voice VLAN: none
Extended Trust State : not trusted [COS = 0]
Administrative private-vlan primary host-association: none
Administrative private-vlan secondary host-association: none
Administrative private-vlan primary mapping: none
Administrative private-vlan secondary mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk private VLANs: none
Operational private-vlan: none
Unknown unicast blocked: disabled
Unknown multicast blocked: disabled
Trunk port on the 3750 switch:
sw-3750-01# show interfaces gigabitEthernet 3/0/1 switchport
Name: Gi3/0/1
Switchport: Enabled
Administrative Mode: trunk
Operational Mode: trunk
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: dot1q
Negotiation of Trunking: On
Access Mode VLAN: 1 (default)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
Administrative private-vlan host-association: none
Administrative private-vlan mapping: none
Administrative private-vlan trunk native VLAN: none
Administrative private-vlan trunk Native VLAN tagging: enabled
Administrative private-vlan trunk encapsulation: dot1q
Administrative private-vlan trunk normal VLANs: none
Administrative private-vlan trunk associations: none
Administrative private-vlan trunk mappings: none
Operational private-vlan: none
Trunking VLANs Enabled: ALL
Pruning VLANs Enabled: 2-1001
Capture Mode Disabled
Capture VLANs Allowed: ALL
Protected: false
Unknown unicast blocked: disabled
Unknown multicast blocked: disabled
Appliance trust: none
When downgrading the Nexus 5672 back to NX-OS 7.0(2)N1(1) the connection is fine again, interface eth 1/1 on the Nexus switch is not blocked anymore and chooses the correct root bridge (which is the 3750):
sw-5672-01# show spanning-tree
VLAN0001
Spanning tree enabled protocol rstp
Root ID Priority 24577
Address 000d.bce9.2b00
Cost 4
Port 129 (Ethernet1/1)
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Bridge ID Priority 32769 (priority 32768 sys-id-ext 1)
Address 8c60.4f1b.9181
Hello Time 2 sec Max Age 20 sec Forward Delay 15 sec
Interface Role Sts Cost Prio.Nbr Type
---------------- ---- --- --------- -------- --------------------------------
Eth1/1 Root FWD 4 128.129 P2p Peer(STP)
Eth2/1 Desg FWD 1 128.257 P2p
I've also read through the Release Notes for NX-OS 7.1(0)N1(1) and haven't found anything that sounds suspicous. Do you think this might be a bug or could it also be another problem?
Thanks
Michael
01-12-2015 09:51 AM
Dont have the answer for ya but going to watch this as we had something similar over the weekend when we tried to upgrade a couple of 5596's from 5.x code to 7.x and while the first was loading we lost the abiltiy to get to the 2nd one . We go back to 5.x code and everything normalizes .
01-13-2015 12:28 AM
Thank you - an additional indication that this is a bug indeed. I'm trying 7.1(0)N1(1a) today, if it doesn't work either I'll downgrade to NX-OS Release 7.NX-OS Release 7.0(5)N1(1a) which is the recommend Version to use anyway. I'll post the results here.
I'll also check with our distributor how we can inform Cisco about a potential bug.
01-13-2015 04:52 AM
I just tested both 7.1(0)N1(1a) and can confirm that the problem is the same. 7.0(5)N1(1a) works fine! I'll get in touch with our distributer in order to have this checked - I currently cannot imagine anything else than a bug in NX OS 7.1. I will keep you posted.
03-22-2015 07:59 AM
I get the same results in 7.1(0)N1(1b) I will downgrade to 7.0(5)N1(1a)
03-23-2015 04:37 AM
Thanks for the update. I haven't received any and Information from our Distributor - since 7.0.5 is running fine I however haven't done anything further regarding the problem. It would be great of you could update the thread once you receive any Information on this.
07-14-2015 11:34 AM
bought a Nexus 56128 with 7.1(0)N1(a) installed from factory. had the same problem when connecting to 2960S via trunk. All other VLAN works, admin VLAN 1 does not. Also states VLAN ID mismatch and in BKN state.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide