What's Popular

Meh, Whatever is Featured

Linking Active Directory to Palo Alto

 ###First you need to create a server profile under the LDAP section. DEVICE>Server Profiles>LDAP then click on the Add down at the bo...

Showing posts with label UCS. Show all posts
Showing posts with label UCS. Show all posts

Wednesday, September 25, 2024

Renew Default Security Keyring Cisco UCS

Step 1: UCS-A# scope security

Step 2: UCS-A /security # scope keyring default

Step 3: UCS-A /security/keyring # set regenerate yes

Step 4: UCS-A /security/keyring # commit-buffer

Factory Reset Cisco UCS 4.1 CLI

 ####You must use the local admin account in order for the option to be listed.

####Login through SSH to the FI VIP (or the current primary FI).

####Next connect to the local management CLI then execute the rease conifig command.


FI-A#local-mgmt

FI-A(local-mgmt)erase configuration

All UCS configurations will be erased and system will reboot. Are you sure? (yes/no):yes


####Make sure to do the same process on the other FI if you have a secondary.

####The configurations will be erased and the FIs will reboot.

Monday, April 1, 2019

Clearing UCSM error F0933 “named VLAN for vNIC cannot be resolved” errors

1.    First off upon logging onto your UCSM you find this lovely error:


2.    So what is happening here is you done messed up A A Ron! A VLAN was deleted from the global LAN Cloud area and more than likely is still attached to a vNIC template out there. There can be some other causes, but this has been the most common issue I have found with this error. Your UCS has a VLAN it does not know what to do with.
3.    So, from the error screen, go ahead and go to your LAN section in your UCS and go to your vNIC templates section:


4.    Now we can go ahead and select this VLAN we thought was gone, and click on the Delete at the bottom.


5.    Once you delete the VLAN, the errors should go down or start going away. You want to check all your vNIC templates to ensure it has been removed.

Friday, March 1, 2019

Upload Firmware into UCSM (GUI)

1.    First off, log into your UCSM system you wish to upload to.
2.    Next, click on the following tabs:
    a.    Equipment
    b.    Firmware Management
    c.    Installed Firmware
3.    Next, under the “Installed Firmware” section, click on “Download Firmware”. This option means the Fabric Interconnects (FIs) themselves will download the software into their flash. Not you downloading the software yourself. It is confusing at first, but remember this is you pushing the firmware to the FIs and they download it.
4.    After you click this, then you can select the file you wish to upload and then click “OK”.
5.    Your software will start uploading into the FI so it can download. If you need to check the progress of the download, click on the “Download Tasks” tab to the right of the “Installed Firmware” tab.
6.    Finally, you can verify your firmware was uploaded/downloaded by selecting the “Packages” tab and you should see your new firmware upload in here.

Reference:
https://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/ucs-manager/GUI-User-Guides/Firmware-Mgmt/4-0/b_UCSM_GUI_Firmware_Management_Guide_4-0/b_UCSM_GUI_Firmware_Management_Guide_4-0_chapter_0100.html#task_0EE4036D9F434685A3CD94EBC0501B66

Friday, February 22, 2019

Re-issue Certificate for UCSM

1.    You will sometimes have a certificate expire on your UCSM. This will show up as a “Major” error in your UCSM errors/logs. This can be cleared by re-issuing a new certificate within the fabric interconnects.
2.    First, log into the fabric interconnects through SSH.
3.    Once you have logged into the FI, use the following commands to re-issue new certificate:
    a.    #scope security
    b.    #scope keyring default
    c.    #set regenerate yes
    d.    #commit-buffer
        i.    WARNING!: This WILL disconnect your web sessions. Be wary if you have others currently working in the UCSM, for it will disconnect them all.
4.    It can take up to 3-5 minutes to re-generate a new certificate for the UCSM. Give it a few minutes then use the following commands to verify the new key has been created:
    a.    #scope security
    b.    #show keyring detail
    c.    The following should be showing:
        i.    RSA key modules: ModXXXX
        ii.    Trustpoint: XXX
        iii.    Cert Status: Valid (here it should show valid or self-signed, not expired)
5.    You should now be able to log back into your UCSM and see the error cleared.

Thursday, January 31, 2019

Adding VLANs to Cisco UCSM & HyperFlex

I know there are a few more ways to do these procedures, but this is just one example in this overall SOP.

1.    First, from the UCS manager, go to the LAN section on the left hand side, then expand LAN> Policies> root>Sub-Organizations>YourDataCenter>vNIC Templates>vNIC Template vm-network-a, and vNIC Template vm-network-b


2.    Once you navigate here, you can click on the “Modify VLANs” Action under the “General” tab.


3.    On the menu on the pop-up, click on “Create VLAN”


4.    On the Create VLANs screen, fill in your VLAN Name/Prefix with a name you wish to call this VLAN, example: MyTestVLAN-100. Then put in your VLAN number, example: 100


 5.    Now make sure to go to the second “vNIC Template vm-network-b” or whatever other vm-template policies you have to ensure it added there too (it should do this automatically with linked templates, but always good to check).



6.    Oh we are not done yet folks! Now, we have the VLAN added to the vm-network templates, now we can add the VLANs to the actual servers so they can start processing the VLAN tagging. This part is easy, just check the box on the new VLAN/VLANs you wish to add to the vm-network templates.




7.    Now, in the top tabs, next to the “General” tab, you can click on VLANs and verify your VLAN has appeared and is now showing in the VLANs for the UCS vNIC Template. You can now add your Port-Group/VLAN information into the VMware vSphere and your Cisco equipment. Ensure the VLAN tag is connected all the way through the Layer 2 systems for it to fully pass through.


Reference:
https://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/ucs-manager/GUI-User-Guides/Network-Mgmt/4-0/b_UCSM_Network_Mgmt_Guide_4_0/b_UCSM_Network_Mgmt_Guide_4_0_chapter_0110.html

Tuesday, January 29, 2019

Re-acknowledging a Blade Server in UCSM

1.    Sometimes you will need to re-acknowledge a server in order to clear alarms in the UCS/HyperFlex system. Start off by ensuring the server is in maintenance mode if it is linked in vCenter (this will help offload important VMs if in vMotion, and prevent issues in vCenter).
2.    Next, log into your UCS manager.
3.    Once you are logged into the UCS manager, navigate to the Equipment tab in the top left of the screen.
4.    From the Equipment tab, expand the following:
    a.    Equipment>Servers>Server you wish to work on.
5.    From here, click on the “Server Maintenance” in the “Actions” section. Also, I found out if you use the "reset" option it is displayed here too, a few ways you can get to it.
6.    Select “Re-Acknowledge” from the selection and then click “OK”.
7.    The process can take anywhere from 10-40 minutes depending on the system you are utilizing.
8.    Verify errors have cleared.

Reference:

https://www.cisco.com/c/en/us/td/docs/unified_computing/ucs/ucs-manager/GUI-User-Guides/Server-Mgmt/3-1/b_Cisco_UCS_Manager_Server_Mgmt_Guide_3_1/b_Cisco_UCS_Manager_Server_Mgmt_Guide_3_1_chapter_01001.html#task_DAD508E1ACC2406B81D00C1099E442EF

Friday, September 21, 2018

UCSM Server Clear Logs When Full

1.    UCS Manager Screen click on Equipment tab
2.    Click on Chassis under the equipment tab on the left
3.    Then select Service Profiles in the middle screen
4.    Once you are in the service profiles section, click on the server you wish to view by clicking
5.    On the blue hyperlink on the right of the server you wish to view.
6.    From here, select SEL Logs tab.
7.    Click on backup to backup
8.    Then click clear to clear the logs.

Reference: https://www.cisco.com/en/US/docs/unified_computing/ucs/sw/gui/config/guide/141/UCSM_GUI_Configuration_Guide_141_chapter49.html#d20716e687_navtitle

Friday, September 14, 2018

Shut Down and Power Off HyperFlex Storage Cluster

1. First, backup the HX/UCS configuration through the UCS Manager (Click on Creating a Backup Operation).
a. https://www.cisco.com/c/en/us/td/docs/hyperconverged_systems/HyperFlex_HX_DataPlatformSoftware/AdminGuide/3_0/b_HyperFlexSystems_AdministrationGuide_3_0/b_HyperFlexSystems_AdministrationGuide_3_0_chapter_0100.pdf
2. Next, shut down all the VMs in the cluster or migrate the VMs to a new cluster.
3. Log into one of the storage cluster VMs (you can click on one of the storage cluster VMs to get an IP to SSH into).
4. Perform the following command to shut down the cluster:
a. # stcli cluster shutdown
5. Next, run the following command to confirm cluster is offline:
a. # stcli cluster info
b. Confirm the “healthstate” is “unknown” to verify it is offline.
6. Next, power off the storage controller VMs in vCenter by doing the following:
a. Find the storage VMs and right click
b. Select Power>Shutdown Guest OS (Cisco shows Power Off also shuts down gracefully, although I have not called Cisco to confirm this. As all VMs, I use “Shutdown Guest OS” instead for now.
7. Finally, you can now shutdown the ESXi hosts in the cluster in vCenter by doing the following:
a. Locate the ESXi host and right click.
b. Select Power>Shutdown and put in the reason why you are shutting the system down.
8. The cluster is now shut down. If you need to shut down the UCS FIs, then Cisco recommends you can just pull the plug on them since there is no other tasks to shut these down.

Reference for Shutdown Procedures: https://www.cisco.com/c/en/us/td/docs/hyperconverged_systems/HyperFlex_HX_DataPlatformSoftware/AdminGuide/3_0/b_HyperFlexSystems_AdministrationGuide_3_0/b_HyperFlexSystems_AdministrationGuide_3_0_chapter_0100.pdf