
27-5
Cisco Nexus 1000V Troubleshooting Guide, Release 5.2(1)SV3(1.1)
OL-31593-01
Chapter 27 Cisco TrustSec
Problems with Cisco TrustSec
Problems with Cisco TrustSec
This section includes symptoms, possible causes and solutions for the following problems with Cisco
TrustSec.
Symptom
Possible Causes
Verification and Solution
The Cisco Nexus 1000V is
unable to form an SXP session
with Cisco TrustSec.
There is no connection between the
Cisco Nexus 1000V and its peer.
Verify if the Cisco Nexus 1000V is connected to
its peer.
ping
The Cisco TrustSec SXP is not enabled
on the Cisco Nexus 1000V.
Verify if the Cisco TrustSec SXP is enabled on the
Cisco Nexus 1000V.
show cts sxp
If not, enable the Cisco TrustSec SXP.
cts sxp enable
The password configured on the Cisco
Nexus 1000V does not match the
password configured on its peer.
Verify if the passwords configured on the Cisco
Nexus 1000V matches its peer.
show cts sxp
The default source IPv4 address is not
configured on the Cisco Nexus 1000V.
Verify if the default source IPv4 address is not
configured on the Cisco Nexus 1000V.
show cts sxp
The SXP peer is not configured as the
listener.
Verify that the SXP peer is configured as the
listener.
show cts sxp connection
Cisco TrustSec SXP is unable to
learn any IP-SGT mappings on
the Cisco Nexus 1000V.
The Cisco TrustSec device tracking is
not enabled on the Cisco Nexus 1000V.
Verify if the Cisco TrustSec device tracking is
enabled on the Cisco Nexus 1000V.
show cts device tracking
If not, enable the Cisco TrustSec device tracking.
cts sxp device tracking
DHCP snooping is not enabled globally
on the Cisco Nexus 1000V.
Verify if DHCP snooping feature is enabled
globally on the Cisco Nexus 1000V.
show feature
If not, enable DHCP snooping globally.
feature dhcp
Verify if DHCP snooping is enabled on a VLAN
on the Cisco Nexus 1000V.
show ip dhcp snooping
If not, enable DHCP snooping on a VLAN.
ip dhcp snooping vlan
vlan-list