background image

 

Corporate Headquarters:

Copyright © 2001–2002. Cisco Systems, Inc. All rights reserved.

Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA

Catalyst 6000 Family Network Analysis Module 
Installation and Configuration Note

WS-X6380-NAM

This publication describes how to install the Catalyst 6000 family Network Analysis Module (NAM) and 
how to configure the NAM using the Catalyst command-line interface (CLI), the NAM Traffic Analyzer 
application, or both. See the 

“Related Documentation” section on page 73

 for more information about 

software configuration for the switch. 

Note

For translations of the warnings in this publication, see the 

“Safety Overview” section on page 6

 and 

refer to the Regulatory Compliance and Safety Information for the Catalyst 6000 Family Switches.

Contents

This publication consists of these sections:

Overview, page 2

Safety Overview, page 6

Software Requirements, page 8

Hardware Requirements, page 9

Required Tools, page 9

Installing and Removing the NAM, page 9

Configuring the NAM, page 16

Administering the NAM, page 38

Troubleshooting the NAM, page 59

Supported RMON and RMON2 MIB Objects, page 64

GNU General Public License, page 68

FCC Class B Compliance, page 72

Summary of Contents for Network Analysis Module 6000

Page 1: ...tion on page 73 for more information about software configuration for the switch Note For translations of the warnings in this publication see the Safety Overview section on page 6 and refer to the Regulatory Compliance and Safety Information for the Catalyst 6000 Family Switches Contents This publication consists of these sections Overview page 2 Safety Overview page 6 Software Requirements page ...

Page 2: ...on to the basic RMON support provided by the Catalyst 6000 family supervisor engine You can use TrafficDirector or any other IETF compliant RMON application to access link host protocol and response time statistics for capacity planning departmental accounting and real time application protocol monitoring You also can use filters and capture buffers to troubleshoot the network The NAM can analyze ...

Page 3: ...using an SNMP management application such as the Cisco TrafficDirector real time network management application or NetScout nGenius Real Time Monitor RTM To use RMON and SNMP agent support you configure the NAM using the CLI Refer to the following URL for more information about using RTM http www cisco com univercd cc td doc product lan cat6000 fam_mod rel2_1_2 ol_2428 htm For more information abo...

Page 4: ...g Connection Control Part SCCP and H 323 voice protocols are now supported The trap destination table is available when you enter the show snmp CLI command Note Cisco IOS does not support the show snmp CLI command You can upgrade the maintenance image while the application is running Front Panel Description The NAM front panel see Figure 1 includes a STATUS LED hard drive LED SHUTDOWN button and P...

Page 5: ...t If the NAM fails to respond to these commands properly you must use the SHUTDOWN button on the front panel to initiate the shutdown procedure To push the button use a small pointed object such as a paper clip The shutdown procedure may require several minutes The STATUS LED turns off when the NAM shuts down Hard Drive Activity LED The hard drive HD activity LED is lit when the hard drive is in u...

Page 6: ...t werken dient u zich bewust te zijn van de bij elektrische schakelingen betrokken risico s en dient u op de hoogte te zijn van standaard maatregelen om ongelukken te voorkomen Voor vertalingen van de waarschuwingen die in deze publicatie verschijnen kunt u het document Regulatory Compliance and Safety Information Informatie over naleving van veiligheids en andere voorschriften raadplegen dat bij ...

Page 7: ... un pericolo La situazione potrebbe causare infortuni alle persone Prima di lavorare su qualsiasi apparecchiatura occorre conoscere i pericoli relativi ai circuiti elettrici ed essere al corrente delle pratiche standard per la prevenzione di incidenti La traduzione delle avvertenze riportate in questa pubblicazione si trova nel documento Regulatory Compliance and Safety Information Conformità alle...

Page 8: ...e för att förebygga skador Se förklaringar av de varningar som förkommer i denna publikation i dokumentet Regulatory Compliance and Safety Information Efterrättelse av föreskrifter och säkerhetsinformation vilket medföljer denna anordning Warning Only trained and qualified personnel should be allowed to install replace or service this equipment Software Requirements Table 3 lists the NAM software ...

Page 9: ...trostatic discharge ESD Installing and Removing the NAM Warning During this procedure wear grounding wrist straps to avoid ESD damage to the card Do not directly touch the backplane with your hand or any metal tool or you could shock yourself All Catalyst 6000 family switches support hot swapping which allows you to install remove replace and rearrange modules without turning off the system power ...

Page 10: ...ssis has thirteen slots See Figure 2 Note The Catalyst 6509 NEB switch has vertical slots numbered 1 to 9 from right to left Install the modules with the component side facing to the right Slot 1 is reserved for the supervisor engine Slot 2 can contain an additional redundant supervisor engine in case the supervisor engine in slot 1 fails If a redundant supervisor engine is not required slots 2 th...

Page 11: ...M AC TI VE PW R M G M T RES ET CONSOLE Switch Load 100 1 DTE DCE PCMCIA EJECT PORT 1 LI NK PORT 2 LI NK SUPERVISOR I WS X6K SUP1 ST AT US SY ST EM AC TI VE PW R M G M T RES ET CONSOLE Switch Load 100 1 DTE DCE PCMCIA EJECT PORT 1 LI NK PORT 2 LI NK 8 PORT GIGABIT ETHERNET WS X6408 1 LI N K ST AT U S 2 3 4 5 6 7 8 LI N K LI N K LI N K LI N K LI N K LI N K LI N K 8 PORT GIGABIT ETHERNET WS X6408 1 L...

Page 12: ...FAN OK OUTPUT FAIL o 1 2 3 4 5 6 7 8 9 SUPERVISOR I WS X6K SUP1 ST AT US SY ST EM AC TI VE PW R M G M T RES ET CONSOLE Switch Load 100 1 DTE DCE PCMCIA EJECT PORT 1 LI NK PORT 2 LI NK SUPERVISOR I WS X6K SUP1 ST AT US SY ST EM AC TI VE PW R M G M T RES ET CONSOLE Switch Load 100 1 DTE DCE PCMCIA EJECT PORT 1 LI NK PORT 2 LI NK 8 PORT GIGABIT ETHERNET WS X6408 1 LI N K ST AT U S 2 3 4 5 6 7 8 LI N ...

Page 13: ...ou perform a hot swap the console displays the message Module n has been inserted If you are running Cisco IOS the console displays the message Power to Module in slot n set on These messages do not appear when you are connected to the Catalyst 6000 family switch through a Telnet session Figure 4 Ejector Levers and Captive Installation Screws Step 10 Use a screwdriver to tighten the captive instal...

Page 14: ...Ok 3 00e0 b0ff 9050 to 00e0 b0ff 907f 0 702 4 2 0 24 7 1 0 9 Ok 5 0003 32bb dacb to 0003 32bb dacc 1 2 4B4LZ0XA 1 2 01 Ok 7 0003 3283 cae6 to 0003 3283 cae7 1 1 4B4LZ0XA 2 5 1 Ok Mod Sub Module Model Serial Hw Status 2 Policy Feature Card 2 WS F6K PFC2 SAD040801JA 0 305 Ok 2 Cat6k MSFC 2 daughterboard WS F6K MSFC2 SAD04450FSS 1 1 Ok When running Cisco IOS enter the show interface GigabitEthernet s...

Page 15: ...ebooted the NAM will reboot If the NAM does not respond to any commands from the NAM prompt or the supervisor engine use a small pointed object to access the SHUTDOWN button Catalyst OS software From the root account on the NAM enter the shutdown command In privileged mode from the CLI enter the set module disable mod command When this command is used you will have to enter the set module enable m...

Page 16: ...tain electromagnetic interference EMI that might disrupt other equipment and they direct the flow of cooling air through the chassis Do not operate the system unless all cards faceplates front covers and rear covers are in place Step 8 If the slot is to remain empty install a module filler plate to keep dust out of the chassis and to maintain proper airflow through the module compartment Configuri...

Page 17: ... on Router show module mod Step 2 Establish a console session with the NAM by entering Router session slot processor 1 Step 3 At the login prompt type root to log in to the root account Step 4 At the password prompt type root as the root password Note If you have not changed the password from the factory set default a warning message displays If you decide to change the password from the default s...

Page 18: ...ring the respective command without any parameters Step 15 Set the SNMP agent community string parameter password for read write access by entering root localhost snmp community community string rw Step 16 Set the SNMP agent community string parameter password for read only access by entering root localhost snmp community community string ro Note Clear the SNMP community string with the snmp delet...

Page 19: ...0 98 129 Nameserver s 171 69 2 133 HTTP server Enabled HTTP secure server Disabled HTTP port 80 HTTP secure port 443 TACACS configured Yes Exsession On root localhost root localhost snmp location Cisco Lab Building X Floor 1 root localhost snmp contact Jane Doe Cisco Systems 408 111 1111 root localhost snmp name 6k NAM Slot 2 root localhost snmp community public ro root localhost snmp community pr...

Page 20: ...urrent NDE configuration by entering Router show running config include mls mls rp nde address 172 20 27 229 mls rp ip route map mls rp ip no mls ip multicast aggregate no mls ip multicast non rpf cef mls aging fast mls flow ip full mls flow ipx destination source mls nde flow include protocol tcp mls nde sender mls qos statistics export interval 300 mls qos statistics export delimiter Router show...

Page 21: ...mls rp nde address 172 20 27 229 Router config mls flow ip full Router config mls nde flow include protocol tcp Router config ip flow export destination 172 20 27 229 3000 Note The UDP port number must be set at 3000 Router config ip flow export source vlan 2 Router config ip flow aggregation cache as Router config flow cache enable Router config interface GigabitEthernet8 6 Router config if ip ad...

Page 22: ...he NAM as a SPAN source port Refer to the Catalyst 6000 Family IOS Software Configuration Guide at the following website for more information on SPAN http www cisco com univercd cc td doc product lan cat6000 index htm For more information on configuring SPAN refer to the switch software configuration guide To enable SPAN on the NAM perform one of these tasks This example shows how to enable SPAN o...

Page 23: ...uter config monitor session 1 source vlan 1 both Note The SPAN destination for the NAM must always be port 1 Router 00 21 10 SYS 5 CONFIG_I Configured from console by console Router conf t Enter configuration commands one per line End with CNTL Z Router config monitor session 1 destination interface gi 8 1 Router show monitor Session 1 Source Ports RX Only None TX Only None Both None Source VLANs ...

Page 24: ...anager to communicate with the NAM you must configure the following SNMP MIB variables Access control for the SNMP agent System group settings on the NAM Start the web server using the ip http server enable command To configure these parameters for the NAM perform these steps in privileged mode Step 1 Verify that the NAM is installed and that the power is on by entering this command Console show m...

Page 25: ...NAM configuration by entering this command root localhost show ip Step 12 Configure the SNMP syslocation MIB variable by entering this command root localhost snmp location location string Note The MIB variables in Step 13 and Step 14 must be valid DisplayString texts each with a maximum length of 64 characters Step 13 Set the SNMP sysContact MIB variable by entering this command root localhost snm...

Page 26: ...ole 2 1 1a Copyright C 1999 2000 2001 Cisco Systems Inc WARNING Default password has not been changed root localhost ip address 172 20 52 29 255 255 255 224 root localhost ip broadcast 172 20 52 31 root localhost ip host nam1 root localhost ip gateway 172 69 2 132 root localhost ip domain cisco com root localhost ip nameserver 171 62 2 132 root localhost show ip IP address 172 20 52 29 Subnet mask...

Page 27: ...or the NAM you must enable the NetFlow Monitor option to allow the NAM to receive the NDE stream The statistics are presented on reserved ifIndex 3000 Note Configuration of the Multilayer Switch Function Card MSFC is necessary for using the NetFlow feature For information on configuring NDE refer to the Catalyst 6000 Family Software Configuration Guide To enable the NetFlow Monitor option perform ...

Page 28: ...e port 1 on the NAM module as the SPAN destination port Note You cannot use NAM ports as SPAN source ports The NAM can analyze Ethernet traffic from Ethernet Fast Ethernet Gigabit Ethernet trunk ports or Fast EtherChannel SPAN source ports You also can specify an Ethernet VLAN as the SPAN source You can use RSPAN traffic as a SPAN source for the NAM Verify that the SPAN source is set to the same V...

Page 29: ...tring Note The MIB variables you enter in Step 13 and Step 14 must be valid DisplayString texts each with a maximum length of 64 characters Step 2 Set the SNMP sysContact MIB variable by entering this command root localhost snmp contact contact string Step 3 Set the SNMP sysName MIB variable by entering this command root localhost snmp name name string Note You can delete the SNMP location SNMP co...

Page 30: ...001 Cisco Systems Inc WARNING Default password has not been changed root localhost ip address 172 20 52 29 255 255 255 224 root localhost ip broadcast 172 20 52 31 root localhost ip host nam1 root localhost ip gateway 172 69 2 132 root localhost ip domain cisco com root localhost ip nameserver 171 62 2 132 root localhost show ip IP address 172 20 52 29 Subnet mask 255 255 255 224 IP Broadcast 172 ...

Page 31: ...he NAM allows the following collection types to be started automatically addressMap addressMapTable from RMON2 MIB RFC 2021 If the NMS never sets the addressMapMaxDesiredEntries scalar then the NAM uses the value 1 for no limit art artControlTable from draft warth rmon2 artmib 01 txt etherStat etherStatsTable from RMON MIB RFC 1757 prioStats smonPrioStatsControlTable from SMON MIB RFC 2613 vlanSta...

Page 32: ...e from Cisco Systems before enabling it and using the ART MIB feature To enable the ART MIB perform this task in privileged mode To disable the ART MIB perform this task in privileged mode Configuring the HTTP or HTTP Secure Server Before you can access the NAM through a web browser HTTP or HTTPS you must enable the NAM Traffic Analyzer application from the NAM CLI For HTTP use the ip http server ...

Page 33: ...Note If you encounter the error alert httpd Could not determine the server s fully qualified domain name using 127 0 0 1 for ServerName reboot the NAM and the HTTP server will be enabled automatically Installing a Strong Crypto Patch The ip http secure commands are all disabled by default and you must enable the HTTP secure server by installing a strong crypto patch To install a strong crypto patc...

Page 34: ...CLI root and guest users Step 4 Enable the HTTP server by entering this command root localhost ip http server enable Enabling HTTP server No web users configured Please enter a web administrator username admin admin New password Confirm password User admin added Successfully enabled HTTP server Generating Certificates Certificates are used to validate the secure server connection You can generate ...

Page 35: ...manually to the certification authority After obtaining the certificate from the certification authority install the certificate Installing Certificates To install a certificate from a certification authority follow these steps Step 1 Generate a certificate signing request by entering this command root localhost ip http secure generate certificate request A certificate signing request already exis...

Page 36: ...y5jaXNjby5jb20wHhcNMDExMDMw MTAxMDI4WhcNMDIxMDMwMTAxMDI4WjBlMQswCQYDVQQGEwJBVTETMBEGA1UECBMK U29tZS1TdGF0ZTEhMB8GA1UEChMYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMR4w HAYDVQQDExVuYW1sYWItcGlrMy5jaXNjby5jb20wgZ8wDQYJKoZIhvcNAQEBBQAD gY0AMIGJAoGBANsO1T5ayA6pvkJad413V N ibvND0XRyXfFycTQRzeA8F4A etV s0Iq0muFfiL9mDr es9TkyfIM T2F6 NE13DxJ53ZBbh7ndb6WOnzeHLKh9EDfSI cy2s775lCPCjfLcMsWQLWSU7XUbi ExDpb9e2wQQgi6QBED...

Page 37: ...Monitor tab to configure and display voice monitoring Using a TACACS Server TACACS is a Cisco Systems authentication protocol that provides remote access authentication and related services With TACACS user passwords are administered in a central database instead of individual routers providing a scalable network security solution When a user logs into NAM Traffic Analyzer TACACS determines if the...

Page 38: ...ection contains the various administrative tasks you can perform on the NAM with Cisco IOS Logging in to the NAM page 38 Changing and Recovering the NAM CLI Passwords page 48 Resetting the NAM page 49 Upgrading the NAM Software page 49 Logging in to the NAM The NAM has two user levels with different access privileges guest Read only access The default password is guest root All read and write acce...

Page 39: ...cal database If the administrator is unknown you can use the CLI to remove the local web users from the web user database with the rmwebusers command Note New passwords must be at least six characters in length and may include uppercase and lowercase letters numbers and punctuation marks To change the password follow these steps while you are logged in to the root account on the NAM Step 1 Enter t...

Page 40: ..._number reset command to reset and reboot the NAM The reset process requires several minutes To reset the NAM from the CLI perform this task in privileged mode This example shows how to reset the NAM installed in slot 9 from the CLI Router hw mod mod 9 reset hdd 2 Proceed with reload of module confirm y reset issued for module 9 Note For the boot device you can specify hdd 1 for the application im...

Page 41: ...irm reset issued for module 9 Router 00 03 31 SNMP 5 MODULETRAP Module 9 Down Trap 00 03 31 SP The PC in slot 9 is shutting down Please wait 00 03 41 SNMP 5 COLDSTART SNMP agent on host R1 is undergoing a cold start 00 03 46 SP PC shutdown completed for module 9 00 03 46 C6KPWR SP 4 DISABLED power to module in slot 9 set off admin request 00 03 49 SP Resetting module 9 00 03 49 C6KPWR SP 4 ENABLED...

Page 42: ...t localhost show ip root localhost show snmp This example shows how to upgrade the NAM application software Router hw mod module 9 reset hdd 2 Device BOOT variable for reset hdd 2 Warning Device list is not verified Proceed with reload of module confirm reset issued for module 9 Router 00 16 06 SNMP 5 MODULETRAP Module 9 Down Trap 00 16 06 SP The PC in slot 9 is shutting down Please wait 00 16 21 ...

Page 43: ...exit Connection to 127 0 0 91 closed by foreign host Router Router hw mod module 9 reset Device BOOT variable for reset Warning Device list is not verified Proceed with reload of module confirm y reset issued for module 9 Router 00 24 04 SNMP 5 MODULETRAP Module 9 Down Trap 00 24 04 SP The PC in slot 9 is shutting down Please wait 00 24 18 SP PC shutdown completed for module 9 00 24 18 C6KPWR SP 4...

Page 44: ...e ftp url value ftp user host absolute path filename Enter your password when prompted Step 6 Follow the screen prompts during the upgrade Step 7 After completing the upgrade log out of the NAM Step 8 Boot into the maintenance image with this command to reset the NAM maintenance software Router hw mod module 9 reset hdd 2 Device BOOT variable for reset hdd 2 Warning Device list is not verified Pro...

Page 45: ...You can also type exit at the remote prompt to end the session Trying 127 0 0 91 Open Cisco Network Analysis Module WS X6380 NAM login root Password Network Analysis Module WS X6380 NAM Console 2 1 1 Copyright c 1999 2000 2001 by cisco Systems Inc root hostname cisco com upgrade ftp hostname pub rmon c6nam maint 1 2 1a m bin gz ftp hostname pub rmon c6nam maint 1 2 1a m bin gz 119506K 119506K 611 ...

Page 46: ...trative tasks you can perform on the NAM using the Catalyst OS software Logging into the NAM page 47 Changing and Recovering the NAM CLI Passwords page 48 Resetting the NAM page 49 Upgrading the NAM Software page 49 You can administer the NAM by using the NAM Traffic Analyzer application Refer to the User Guide for the Catalyst 6000 Network Analysis Module NAM Traffic Analyzer You can perform thes...

Page 47: ...th the NAM at the CLI prompt using the session mod command Console enable session 2 Trying NAM 2 Connected to NAM 2 Escape character is Network Analysis Module WS X6380 NAM Step 3 To log into the NAM type root to log in as the root user or guest to log in as a guest user at the login prompt login root Table 4 NAM User Administration User Interface Add Users Remove Users Set Password Recover Passwo...

Page 48: ...visor engine then use the clear module password module command Use NAM Traffic Analyzer n on the local database You create the initial NAM Traffic Analyzer application user with the CLI After starting NAM Traffic Analyzer you can establish and edit additional user passwords You use NAM Traffic Analyzer or the TACACS server to change passwords as follows As the NAM Traffic Analyzer application admi...

Page 49: ... an external Telnet session enter the reset command to reset and reboot the NAM The reset process requires several minutes To reset the NAM from the CLI perform this task in privileged mode This example shows how to reset the NAM installed in slot 2 from the CLI Console enable reset 2 Module 2 shut down in progress please don t remove module until shutdown completed Resetting module 2 2000 Feb 15 ...

Page 50: ...ver does not allow anonymous users use the following syntax for the ftp url value ftp user host absolute path filename Enter your password when prompted Step 6 Follow the screen prompts during the upgrade Step 7 After completing the upgrade log out of the NAM Step 8 Reset the NAM by entering this command Console enable reset mod Step 9 Optional Verify the initial configuration after the NAM comes ...

Page 51: ...odule 3 shut down in progress please don t remove module until shutdown completed 2000 May 25 09 30 59 SYS 5 MOD_RESET Module 3 reset from Software 2000 May 25 09 32 56 SYS 5 MOD_OK Module 3 is online Console enable Upgrading the NAM Maintenance Software To upgrade the NAM maintenance software follow these steps Step 1 Copy the NAM maintenance software image to a directory that is accessible to FT...

Page 52: ...ay 25 09 09 38 SYS 5 MOD_OK Module 3 is online Console enable session 3 Trying NAM 3 Connected to NAM 3 Escape character is Cisco Network Analysis Module WS X6380 NAM login root Password Network Analysis Module WS X6380 NAM Console 2 1 1a Copyright C 1999 2000 2001 Cisco Systems Inc WARNING Default password has not been changed root nam5 cisco com upgrade ftp hostname pub rmon c6nam maint 1 2 1a m...

Page 53: ...unt Step 4 Install the patch software to the NAM software by entering this command root localhost patch ftp url ftp url is the FTP location and the name of the NAM patch software image file Note If the FTP server does not allow anonymous users use the following syntax for the ftp url value ftp user host absolute path filename Enter your password when prompted Step 5 Follow the screen prompts durin...

Page 54: ...rpm Please wait Package cisco nam system patch 1 0 1 i386 rpm verified Applying cisco nam system patch 1 0 1 i386 rpm please wait 100 100 Downloading zsh 3 0 8 8 i386 rpm please wait ftp hostname pub patch_rpms zsh 3 0 8 8 i386 rpm 492K 492K 810 37K s 503944 bytes transferred in 0 61 sec 809 93k sec Verifying zsh 3 0 8 8 i386 rpm please wait Package usr local nam patch workdir zsh 3 0 8 8 i386 rpm...

Page 55: ...session on off Controls whether external Telnet sessions are accepted by the NAM from outside the switch The default is set to off If the exsession command is set to off you can only Telnet to the NAM from the supervisor engine on the switch If the exsession command is set to on new Telnet requests from any valid IP address are accepted This command will not drop any open sessions This command can...

Page 56: ...and can be used by both root and guest accounts show certificate Displays certificates you have installed for secure servers show certificate request Displays encrypted certificate request for secure servers show cpu Displays current processor load on the NAM CPU for all combined functions This command can be used by both root and guest accounts show date Displays current time of day information m...

Page 57: ...s the maximum time to live max number of hops used p port Sets the base UDP port number used in probes s src_addr Forces the source address to be something other than the IP address of the interface the packet is sent on t tos Sets the type of service in packets to the following value w waittim Sets the time in seconds to wait for a response to a probe upgrade ftp user passwd host full path filena...

Page 58: ...r enable module slot_number Shuts down the NAM and removes power clock timezone zone offset Sets the timezone for the switch or NAM clock summer time zone recurring Sets the switch to use summertime settings clock calendar valid Sets the current calendar time as the switch time on startup interface GigabitEthernet slot number port number Begins configuration for each NAM port monitor session sessi...

Page 59: ...ort gmrp set port gvrp set port host set port inlinepower set port jumbo set port membership set port negotiation set port protocol set port qos set port rsvp set port security set port speed set port trap set protocolfilter set rgmp set rspan set snmp set spantree set trunk set udld set vlan set vtp Troubleshooting the NAM This section provides troubleshooting information for the NAM Note Additio...

Page 60: ...he Admin Diagnostics Monitor and Capture Configuration screen Symptom The user receives a verification failed message when installing a patch on the NAM Possible Cause The time and date on the NAM are not correct or the patch is not the same as an official Cisco patch The FTP process may have failed or the FTP image being pointed to is not a patch It may be a full application image Recommended Act...

Page 61: ...ers as described in Configuring the HTTP or HTTP Secure Server section on page 32 Symptom After configuration the TACACS authentication and authorization fails Possible Cause There are three possible causes name and password do not match the login configuration in the TACACS server the TACACS secret key configured in the NAM does not match the secret key configured in the server and the wrong TACA...

Page 62: ...ed Action Log in to the TACACS server and grant access rights to the affected users See the TACACS documentation for information on login configuration Web Username and Password Issues The following web username and password issues apply You cannot use the CLI username root or guest and password to log into the NAM Traffic Analyzer application because they are administered separately You also cann...

Page 63: ...the NAM Traffic Analyzer application as a TACACS user You must be configured on the TACACS server with Account Management permission Step 2 Change the password of the local web admin user Note If a TACACS server has been configured and the local web user account is deleted you can still create the web admin user on the TACACS server In this case the admin user created on the TACACS server can log ...

Page 64: ...herStats for a specific VLAN configure the etherStatsTable on the NAM For the data source use the ifIndex corresponding to the VLAN of interest Any alarmVariable configured on the supervisor engine must reference a MIB object on the supervisor engine An alarmVariable configured on the NAM must reference a MIB object on the NAM Note You cannot configure an alarmVariable on the NAM that references a...

Page 65: ...et stream from frames that match a specified pattern Network Analysis mib 2 1 rmon 16 capture 8 RFC 1757 RMON MIB Manages buffers for packets captured by the Filter group for uploading to the management console Supervisor Engine mib 2 1 rmon 16 event 9 RFC 1757 RMON MIB Generates SNMP traps when an Alarms group threshold is exceeded and logs the events Network Analysis mib 2 1 rmon 16 event 9 RFC ...

Page 66: ...twork address Network Analysis mib 2 1 rmon 16 alMatrix 17 RFC 2021 RMON2 MIB Traffic statistics by application layer protocol for pairs of network layer addresses Network Analysis mib 2 1 rmon 16 usrHistory 18 RFC 2021 RMON2 MIB Extends history beyond RMON1 link layer statistics to include any RMON RMON2 MIB I or MIB II statistic Supervisor Engine mib 2 1 rmon 16 probeConfig 19 RFC 2021 RMON2 MIB...

Page 67: ...Objects 1 dsmonAggGroupTable 7 DSMON MIB Aggregation or profile control variables and tables rmon dsmonMib 26 dsmonObjects 1 dsmonStatsObjects 2 dsmonStatsControlTable 1 rmon dsmonMib 26 dsmonObjects 1 dsmonStatsObjects 2 dsmonStatsTable 2 DSMON MIB Per datasource statistics collection tables rmon dsmonMib 26 dsmonObjects 1 dsmonPdistObjects 3 dsmonPdistCtlTable 1 rmon dsmonMib 26 dsmonObjects 1 d...

Page 68: ...ead You can apply it to your programs too When we speak of free software we are referring to freedom not price Our General Public Licenses are designed to make sure that you have the freedom to distribute copies of free software and charge for this service if you wish that you receive source code or can get it if you want it that you can change the software or use pieces of it in new free programs...

Page 69: ...e is addressed as you Activities other than copying distribution and modification are not covered by this License they are outside its scope The act of running the Program is not restricted and the output from the Program is covered only if its contents constitute a work based on the Program independent of having been made by running the Program Whether that is true depends on what the Program doe...

Page 70: ...e or c Accompany it with the information you received as to the offer to distribute corresponding source code This alternative is allowed only for noncommercial distribution and only if you received the program in object code or executable form with such an offer in accord with Subsection b above The source code for a work means the preferred form of the work for making modifications to it For an ...

Page 71: ... willing to distribute software through any other system and a licensee cannot impose that choice This section is intended to make thoroughly clear what is believed to be a consequence of the rest of this License 8 If the distribution and or use of the Program is restricted in certain countries either by patents or by copyrighted interfaces the original copyright holder who places the Program unde...

Page 72: ...limits for a Class B digital device in accordance with the specifications in part 15 of the FCC rules The following information is for FCC compliance of Class B devices The equipment described in this manual generates and may radiate radio frequency energy If it is not installed in accordance with Cisco s installation instructions it may cause interference with radio and television reception This ...

Page 73: ...Network Analysis Module with nGenius Real Time Monitor For additional information about Catalyst 6000 family switches and command line interface CLI commands refer to the following Release Notes for Catalyst 6000 Family Software Release 6 x Catalyst 6000 Family Software Configuration Guide Catalyst 6000 Family Command Reference Site Preparation and Safety Guide For detailed hardware configuration ...

Page 74: ... at 408 527 0730 You can e mail your comments to bug doc cisco com To submit your comments by mail use the response card behind the front cover of your document or write to the following address Cisco Systems Attn Document Resource Connection 170 West Tasman Drive San Jose CA 95134 9883 We appreciate your comments Obtaining Technical Assistance Cisco provides Cisco com as a starting point for all ...

Page 75: ...pects of business operations No workaround is available Priority level 1 P1 Your production network is down and a critical impact to business operations will occur if service is not restored quickly No workaround is available Which Cisco TAC resource you choose is based on the priority of the problem and the conditions of service contracts when applicable Cisco TAC Web Site The Cisco TAC Web Site ...

Page 76: ...contact the TAC Escalation Center with a P1 or P2 problem a Cisco TAC engineer will automatically open a case To obtain a directory of toll free Cisco TAC telephone numbers for your country go to the following URL http www cisco com warp public 687 Directory DirTAC shtml Before calling please check with your network operations center to determine the level of Cisco support services to which your c...

Page 77: ...s Cisco Systems Cisco Systems Capital the Cisco Systems logo Cisco Unity Enterprise Solver EtherChannel EtherFast EtherSwitch Fast Step Follow Me Browsing FormShare GigaDrive HomeLink Internet Quotient IOS iPhone IP TV iQ Expertise the iQ logo iQ Net Readiness Scorecard iQuick Study LightStream Linksys MeetingPlace MGX Networking Academy Network Registrar Packet PIX ProConnect ScriptShare SMARTnet...

Page 78: ...78 Catalyst 6000 Family Network Analysis Module Installation and Configuration Note 78 10406 05 Obtaining Technical Assistance ...

Reviews: