Beruflich Dokumente
Kultur Dokumente
Exam preparation
To prepare, my first source of information was the book from Cisco
Press: 640-916 Official Certification Guide from Cisco Press. The book
is very extensive in explaining details. Sometimes I found it even a little
overwhelming. For me personally, it would be better if they first explain
a technology in simple words and then focus more on the details.
Unlike with the 640-911 exam, I found that this exam cleanly covers the
exam objectives which are available from Cisco. The topics were
quite evenly distributed and they were clear. Sometimes a small detail
in the question really matters, so pay attention to that. Comparing with
640-911, I found the exam easier but the content was more difficult.
Maybe confusing but that’s my experience.
Network architecture
A classic datacenter network has a modular multi layer network design.
The most used model has three layers. Using a modular design is
scalable and each layer has it’s own specific task:
Core layer:
Distribution/aggregation layer:
Access layer:
Host connectivity
QoS marking
VLAN marking
More information:
http://www.w7cloud.com/cisco-3-layer-hierarchical-network-
model-core-distribution-access/
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 1/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
Collapsed core: Distribution and Core are one layer. Can be used
in smaller environments
Spine and leaf
Leaf = Access layer. More leaf-switches = more access
connectivity
Spine connects all leafs in a redundant way. More spine-
switches = more switching capacity
FabricPath
ACI (Application Centric Infrastructure)
Characteristics:
Terminology:
Configuration:
S1# con
Enter configuration commands, one per line. End with CNTL/Z.
S1(config)# int eth2/1
S1(config-if)# ip address 192.168.100.10 255.255.255.0
S1(config-if)# ip igmp version 3
S1(config-if)# no shut
Debug/check:
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 2/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
Site vlan : 10 (up)
AED-Capable : No (No extended vlan operationally up)
Capability : Multicast-Reachable
Overlay-Interface Overlay1 :
Hostname System-ID Dest Addr
S2 000c.29c6.b255 192.168.100.20
More
information: http://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/nx-
os/OTV/quick_start_guide/b-Cisco-Nexus-7000-Series-OTV-QSG.html
Characteristics:
Loop-free
Uses all bandwidth (without vPC, one of the links would be
blocked by STP)
Max. two switches per vPC domain
Max. one vPC domain per switch (or VDC)
Available of M or F line cards
best practice is to use dedicated rate mode
vPC keepalive is required to establish the vPC but can be lost
during usage
Traffic normally doesn’t pass the vPC peer link (but it can be)
There is no preemt after a failover
Terminology:
Configuration:
In the example, I’ll config vPC on one of both vPC peers. Ethernet 2/1
and 2/2 are used for the vPC peer link, mgmt0 is used for keepalive
and Ethernet 2/3 is used to connect a host (member port).
Debug/check:
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 3/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
vPC domain id : 1
Peer status : peer adjacency formed ok
vPC keep-alive status : peer is alive
Configuration consistency status : success
Configuration inconsistency reason: Consistency Check Not Perf
vPC role : secondary
Number of vPCs configured : 1
Peer Gateway : Disabled
Dual-active excluded VLANs : -
vPC Peer-link status
--------------------------------------------------------------
id Port Status Active vlans
-- ---- ------ -------------------------------------------
2 Po2 up 1,3001-3500
vPC status
--------------------------------------------------------------
id Port Status Consistency Reason
------ ----------- ------ ----------- ------------------------
1 Po1 up success success
More information:
http://www.cisco.com/c/en/us/products/collateral/switches/nexus-
5000-series-switches/configuration_guide_c07-543563.html
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/command/reference/vpc/n5k-
vpc-cr/n5k-vpc_cmds_show.html#wp1104923
FabricPath
FabricPath is used to get to a spine/leaf network design where a large
layer 2 environment is scalable and get’s the benefits of layer 3 routing
like multipathing, fast convergence and SPF without creating multiple
segments or STP disadvantages.
Characteristics:
Cisco proprietary
Does address lookup for incoming traffic to find outgoing
destination (SPF)
ECMP (Equal Cost Multipathing) is possible up to 16 links
Uses a tree topology to determine routes for ARP, broadcast or
multicast traffic. Trees are per VLAN
Uses IS-IS as routing protocol
Uses conversational MAC-learning: only learn relevant MAC’s on
a port
Not available for M1 interface, only on F1/2/3
Ehtertype: 0x8903
STP BPDUs do not pass core ports
For classic switches connected to the FabricPath network
appears as one STP bridge with a fixed BID: C84C.75FA.6000).
The edge port always needs to be the root for FabricPath VLANs
vPC+ enable FabricPath to work with a vPC domain (FabricPath
emulates a switch)
Terminology:
1. Edge port owning switch learns the source MAC for the host
connected
2. Perform a lookup to identify destination switch ID: fails
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 4/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
3. Encapsulate the original ethernet frame with a FabricPath header
4. Unicast root (elected earlier) will forward the request to all leafs
(they own the devices)
5. Leaf owning the device will answer via the root to the incoming
port
6. Learn the layer 2 route
7. Learn the destination MAC only on the switch owning the edge
port connected to the destination
Configuration:
S1# con
Enter configuration commands, one per line. End with CNTL/Z.
S1(config)# license grace-period
S1(config)# install feature-set fabricpath
S1(config)# feature-set fabricpath
S1(config)# show feature-set
Feature Set Name ID State
-------------------- -------- --------
fabricpath 2 enabled
fex 3 uninstalled
mpls 4 uninstalled
Configure interfaces that will be FabricPath core ports (will form IS-IS
adjecency):
Debug/check:
More information:
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/fabricpath/513_n1_1/N5K_FabricPath_Configuration_
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus7000/sw/fabricpath/command/reference/fp_cmd_book/fp__cmd
Characteristics:
FEX-types:
Terminology:
Configuration:
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 5/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
Configuration is only done on the parent switch, there is no console or
similar on the FEX-side.
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus2000/sw/configuration/guide/rel_4_0_1a/NX2000CLIConfig/FEX
Config.html
http://packetlife.net/blog/2012/mar/29/nexus-2200-fex-
configuration/
Model overview:
More information:
http://nexp.com.ua/technologies/dc/choosing-between-dynamic-
and-static-fex-interfaces-pinning/
https://www.packetmischief.ca/2012/08/28/what-the-fex-is-a-fex-
anyways/
http://vjswami.com/2011/11/10/wtf-what-the-fex-are-you-talking-
about/
Storage architecture
Traditional SAN infrastructure types:
For a switched fabric it’s a good practice to have at least two fabrics
(A/B) which are either separated by physical switches or VSAN
1. Port Initialization
2. Fabric login (FLOGI)
A. Switch assigns an FCID, based on the WWN
B. Switch reserves the necessary buffer2buffer credits (the
larger the distance, the more B2B credits are needed)
3. Port login (PLOGI)
A. Between nodes that want to communicate
Terminology:
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 6/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
Principal/secondary (per VSAN) based on priority
FCIP: FC frames in IP packets over normal L3 link (uses
acceleration and compression techniques)
VSAN: like VLAN for SAN: isolation between FC
max 4094 VSAN’s
FCID’s can be re-used in different VSANs
Port types:
Cisco MDS
Characteristics:
NPV
In NPV mode, the edge switch relays all traffic from server-side ports to
the core switch. The core switch provides F port functionality (such as
login and port security) and all the Fibre Channel switching capabilities.
This means that the edge looks like a host for the core and show flogi
database, … can’t be executed anymore on the edge
When enabling NPV mode (feature npv), the switch config is erased
and the switch reboots. Default switch mode is fabric mode.
When enable FCoE and NPV in one time, the switch doesn’t need to
change between Fabric mode and NPV so there no write-erase and a
reboot (feature fcoe-npv).
To avoid disruption of server traffic, enable this feature only after adding
a new NP uplink, and then disable it again after the server interfaces
have been redistributed.
More information:
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/CLIConfigurationGuide/npv.htm
http://blog.scottlowe.org/2009/11/27/understanding-npiv-and-npv/
Debug:
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 7/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
Fabric wide:
Unified ports
Configuration:
S1# con
Enter configuration commands, one per line. End with CNTL/Z.
S1(config)# slot 2
S1(config-slot)# port 1-8 type fc
S1(config-slot)# port 9-16 type ethernet
Create a VSAN:
Configure ports:
Zone configuration:
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 8/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
S1(config)# zoneset name testzs vsan 10
S1(config-zoneset)# member test
Activate a zoneset:
More information:
http://www.techworld.com/tutorial/storage/how-to-interpret-
worldwide-names-156
http://www.cisco.com/en/US/docs/storage/san_switches/mds9000/sw/san-
os/quick/guide/qcg_vin.html
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/troubleshooting/guide/N5K_Troubleshooting_Guide/n5
Characteristics
Terminology:
Configuration:
Enable FCoE:
Create a VLAN for Ethernet. It’s easy to keep the VLAN and VSAN
number equal:
Create VFC interface and map it to a physical port. It’s easy to keep the
same number for the VFC as the VSAN.
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 9/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
Bind the VFC to a VLAN and VSAN:
Configure the physical port. It must be a trunk and the allowed VLAN
must match:
Debug:
Nexus general
Planes:
Planes are isolated (one faulty plane does not influence the other)
Management plane: config/policy/CLI/GUI/SNMP/API/CoPP…
EEM: Embedded Event Manager: Can take action based on
an event (syslog/CLI/GOLD/environment/hardware)
Control plane:
OSPF/EIGRP/STP/CDP/BFD/UDLD/LACP/ARP/FabricPath/VRRP/
…
CoPP: Control Plane Policing: Protects the control plane
when problems occur in the data plane (for example:
broadcast storem/DoS)
Possible configuration for CoPP
CIR (Committed information rate)
PIR (Peak information rate)
EB (Extended burst)
Predefined CoPP policies:
Strict/Moderate/Lenient/Dense/Skip (default: skip)
Ethanalyzer: wireshark for the control plane
Data plane: packet forwarding
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 10/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
10G 1G Cut-trough
Characteristics:
VRF-aware commands:
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 11/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
A VDC allows one physical switch to be splitted up into multiple virtual
switches. Each VDC is running it’s own processes and configuration.
Characteristics:
VDC types:
Configuration:
Nexus 1000v
Characteristics:
Terminology:
Installation procedure:
1. Create VLAN’s on the vSwitch on every host that will run a VSM
for VSM control and management traffic
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 12/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
2. Deploy the OVA for the primary VSM (select manual or automatic
setup)
3. During deployment, map the control and management VLAN’s as
created in step 1
4. Connect to the VM’s console and do basic configuration
A. Admin password
B. Role: primary/secondary
C. Domain ID
D. Basic configuration dialog (as on a normal Nexus switch):
SNMP/switch name/IP/ssh/http-server/SVS control mode:
L2/L3)
5. Deploy the OVA for the secondary VSM (also see 3) (select VSM
secondary)
6. Enter the domain ID and admin password of the primary
7. The secondary automatically gets the configuration of the primary
8. Create a connection to vCenter (svs connection <name>,
protocol, remote ip,…)
A. Distributed virtual switch gets automatically created on the
vCenter
9. Configure the rest of the network (VLAN’s, port profiles,…)
10. Create a vmkernel interface for each host running a VSM for VEM
connectivity
n1000v# config t
n1000v(config)# port-profile vmware-dmz
n1000v(config-port-prof)# switchport mode access
n1000v(config-port-prof)# switchport access vlan 100
n1000v(config-port-prof)# no shut
n1000v(config-port-prof)# state enabled
Only after the last command, the port profile gets pushed to VMWare
Debug:
More information:
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus1000/sw/4_2_1_s_v_2_1_1/install_upgrade/vsm_vem/guide/b_
http://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus1000/sw/4_0/install/vem/guide/vem_install_n1000v.html
https://www.youtube.com/watch?v=gZJNcftZEcE
UCS are the x86-servers from Cisco. They come in two variations (B-
series: blade and C-series: rack). UCS-server are managed by UCSM
(UCS Manager), which is running on Fabric Interconnects.
Fabric Interconnect:
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 13/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
Unconfigured
Server: to a rack server or blade chassis
Ethernet uplink
Ethernet uplink (to upstream network)
FCoE uplink
Appliance: to NFS-storage
Fibre Channel uplink
Fibre Channel uplink port to upstream SAN-fabric
Fibre Channel storage port for Direct Attached FC Storage
Installation procedure:
1. Setup primary FI
2. Setup secondary FI (requires the cluster IP and admin password
chosen in step 1)
3. Login to the cluster IP
4. Configure connectivity
A. Create VLAN’s
B. Choose ports for LAN uplink
C. Create VSAN’s (min 1 fabric A, 1 fabric B)
D. Choose ports for SAN uplink
5. Configure port channels
6. Start discovery
Blade chassis:
B-series Blade:
C-series Rackserver:
UCS C240M3
Can also be managed by UCSM
also has CIMC
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 14/15
6/2/2018 How to prepare for Cisco CCNA Data Center 640-916 DCICT | Jensd's I/O buffer
Mezzanine adapter in server/blade
Can have up to 256 virtual network adapters presented to the OS
or hypervisor
Can be configured as IP, FCoE, Adapter FEX or VM FEX
Allows for fabric failover: in hardware failover without the OS
being aware of NIC teaming
More information:
http://www.cisco.com/c/en/us/support/docs/servers-unified-
computing/ucs-manager/116188-configure-fcoe-00.html
http://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/sw/gui/config/guide/2-
0/b_UCSM_GUI_Configuration_Guide_2_0/b_UCSM_GUI_Configuration_Guide_2_0_chapter_0101.html
Network services
Features:
Features:
http://jensd.be/698/network/how-to-prepare-for-cisco-ccna-data-center-640-916-dcict 15/15