
C H A P T E R
8-1
Cisco Nexus 1000V Troubleshooting Guide, Release 5.2(1)SV3(1.1)
OL-31593-01
8
L3Sec
This chapter describes how to secure the internal control plane communications (Control and Packet
traffic) of Nexus 1000V in a more robust way than in previous releases. It operates only in Layer 3
Control mode.
•
Troubleshooting L3Sec, page 8-1
Troubleshooting L3Sec
The following are symptoms, possible causes and solutions identified while troubleshooting L3Sec.
Symptom
Table 8-1
Troubleshooting L3Sec
Possible Causes
Solution
SVS connection is not up.
1.
Verify SVS connection.
Show svs connection
2.
If the connection is “not connected”, do connect
Key mismatch between VSM /
VEM.
1.
Verify key fields mismatch between switch opaque data and vem.
2.
Do, show vms internal info dvs and check the keys present.
3.
On vem, perform “vemcmd show sod” and check if the fields chunk1, chunk2 and
chunk3 are matching.
4.
If mismatches, disable and enable l3sec again using “[no] enable l3sec” under
svs-domain.
Boot variables are not set.
1.
Verify running config.
Show running config
2.
If “enable l3sec” is present under svs-domain.
3.
If not present, do “enable l3sec” and check for any error messages and perform action
accordingly.