MLNX-OS First-Time Setup: Console Wizard Walkthrough - 夜莺博客

MLNX-OS First-Time Setup: Console Wizard Walkthrough

Getting a NVIDIA (formerly Mellanox) MLNX-OS switch out of the box and into production is a one-time process that trips up many engineers because the details matter: the console baud rate, the boot menu partition choice, mandatory password entry since software 3.8.2000, and DHCP behavior on the mgmt0 port. This article walks through the official MLNX-OS Getting Started procedure step by step, from physical console connection through the configuration wizard and license installation, so your first switch comes up cleanly.

Physical Connection and Console Settings

Connect a PC to the console (RJ-45) port — not the MGT port. If you have a DHCP server, you can skip the console entirely: DHCP is enabled by default on mgmt0, and the switch simply obtains an IP. For console access, configure the terminal as:

Baud rate: 115200
Data bits: 8, Stop bits: 1
Parity: None, Flow control: None

Note: California Senate Bill No. 327 means that from software version 3.8.2000, Admin and Monitor passwords must be typed manually — no automatic passwords are created. If you hold the reset button for 15 seconds, the management module resets and the password is deleted, allowing recovery.

Boot Menu and Login

At the boot menu, select image 0 or image 1 to boot the desired software partition; it is fine to let the countdown timer run out. Log in as admin with password admin on first boot. While the system initializes, the CLI may be unavailable until all modules are configured.

The Setup Wizard Step by Step

The wizard asks (with defaults in brackets):

  • Hostname [switch-1]
  • DHCP on mgmt0 [yes] — choose "no" to enter a static IP or zeroconf
  • Enable IPv6 [yes], SLAAC [no], DHCPv6 on mgmt0 [yes]
  • Update time
  • Enable password hardening [yes]
  • Admin password (must be typed) — required since 3.8.2000
  • Monitor password (must be typed)

The wizard then prints a summary of your choices; press Enter to save, or enter a step number to go back and change an answer. You can rerun the wizard from config mode with configuration jump-start.

Licenses and Verification

switch (config) # show inventory
-----------------------------------------------------------------------------
Module           Part Number        Serial Number        Asic Rev.    HW Rev.
-----------------------------------------------------------------------------
CHASSIS          MSB7800-ES2F       MT1602X17464         N/A          A1
...
switch (config) # show licenses
switch (config) # license install <license-key>

Install licenses with license install, view them with show licenses, and always save the configuration after installing — otherwise licenses are lost at the next boot. If you lose a license key, contact your authorized NVIDIA reseller with the chassis serial number from show inventory.

Understanding the MLNX-OS Boot and Image Model

MLNX-OS keeps two software images side by side, referred to simply as image 0 and image 1 on the boot menu. This is not decoration: it is the mechanism that makes in-service upgrades and rollbacks safe. When you upgrade, the new release is written to the inactive partition, the switch reboots into it, and if the new image fails to boot or behaves badly you can select the other image at the next boot menu. Before any upgrade, note which partition you are running, and remember that the running configuration, licenses and user accounts are shared across both images rather than duplicated per partition.

The boot menu is reached over the console only. After the firmware banner, you are offered the two images and a countdown; letting the timer expire simply boots the default. Because the menu is console-only, always have console access available before you start a risky upgrade — a remote SSH session will disappear the moment the switch reboots, and if the new image does not come up cleanly you will have no way back in.

What the Monitor Account Is For

The wizard asks for two passwords, not one, and engineers often set the monitor account to something throwaway. That is a mistake. The monitor account is a read-only role intended for monitoring platforms, syslog collectors and NOC staff who need visibility without the ability to change configuration. Give it a real, strong password, and hand it to tooling instead of spreading the admin credential. When someone needs to troubleshoot without the risk of an accidental change, the monitor role is the correct answer.

Rerunning the Wizard and Backing Up the Configuration

The setup wizard is not a one-shot. You can call it again at any time from configuration mode with configuration jump-start, which is useful when a switch was staged with placeholder values or inherited someone else's hostname. Once the configuration is correct, back it up off the switch so a replacement unit can be staged quickly:

switch # configuration write to /admin/switch-1.cfg
switch # show configuration files
switch # copy /admin/switch-1.cfg scp: / configs

Version-control the exported configuration text in the same place you keep your device templates. A switch that is lost to hardware failure is replaced in minutes when its configuration is a file on a jump host rather than a memory of what someone typed during the original install.

Before You Start: The Pre-Deployment Checklist

Most first-boot frustration comes from missing one of five small prerequisites. Gather these before you rack the switch so the wizard takes ten minutes instead of an afternoon:

  • Power and airflow: confirm the correct PSU type for your AC or DC plant, and keep the front-to-back or back-to-front airflow direction consistent across every switch in the rack. A single reversed fan unit in a shared plenum can overheat its neighbours.
  • Console cable: an RJ-45-to-DB9 or RJ-45-to-USB rollover cable. A straight-through patch lead will not work.
  • Out-of-band plan: decide the management subnet, gateway and DNS server ahead of time. If you will bootstrap over DHCP, reserve the MAC of the mgmt0 interface in your DHCP server so the address is predictable.
  • License keys: the switch boots with a base feature set. Ethernet L3 routing, advanced features and certain port speeds need a license key file or activation string.
  • Software image: note which partition (image 0 or image 1) holds the target release so you boot the intended version the first time.

Static Management IP vs DHCP on mgmt0

DHCP is enabled by default on mgmt0 because it lets a freshly racked switch appear on the network with zero console time. In a production fabric, however, a static out-of-band address is usually the right answer: you know the address before the switch is even installed, and you never depend on a DHCP scope staying correct. If you answer "no" to DHCP in the wizard, MLNX-OS lets you type the address directly. You can also change it later from config mode:

switch (config) # interface mgmt0 ip address 10.10.20.5 /24
switch (config) # ip route default via 10.10.20.1
switch (config) # ip name-server 10.10.20.10
switch (config) # exit
switch # write memory

Keep the management interface on a dedicated OOB VLAN that is reachable only from your jump hosts. The same mgmt0 port serves the web UI, SNMP, gNMI streaming telemetry and software uploads, so treat it as a control plane, not a data path. If the management network is the only way in, an outage there is an outage everywhere.

Setting Clock, Timezone and NTP

The system clock matters more than it looks: syslog timestamps, license validation and certificate checks all rely on it. Set the timezone and an NTP source as part of bring-up rather than "later":

switch (config) # ntp enable
switch (config) # ntp server 10.10.20.30
switch (config) # ntp server 10.10.20.31
switch (config) # clock timezone CST 8
switch (config) # exit
switch # show ntp

show ntp should report the servers as reachable and the sync state as synchronized. If the switch has no route to your NTP servers, the clock drifts and every log you read afterwards becomes suspect — correlating events across devices gets much harder than it needs to be.

Password Hardening and Local Users

From software 3.8.2000 the wizard insists that you type the admin and monitor passwords by hand — automatic default passwords are gone. That is a security improvement, but it also means a lost password is a console-recovery exercise, not a support call. Best practice is to enable password hardening (already the default recommendation), set a minimum length of twelve characters, and add named accounts with least privilege instead of sharing admin:

switch (config) # username netops password
switch (config) # username netops privilege admin
switch (config) # no username admin default-password
switch (config) # exit

Record the recovery procedure — the 15-second reset button that clears the management password — in your runbook, so a future on-call engineer does not lock themselves out of a switch at 3 a.m.

Verifying a Clean First Bring-Up

Before you hand the switch to the network team, run a short verification pass. Every command below should return the value you expect, with no amber alerts left unexplained:

switch # show version
switch # show inventory
switch # show licenses
switch # show interface status
switch # show system health
switch # show logging

show version confirms the image and uptime, show inventory confirms every module and PSU is recognised, show licenses confirms the feature set, and show logging should be free of CRC or fan alerts. Do not skip the log check — a flapping fan or a marginal optic is far cheaper to fix now than after the switch is carrying production traffic.

Troubleshooting First-Boot Problems

  • No console output: nine times out of ten the baud rate is wrong. MLNX-OS uses 115200, not the 9600 you may remember from older gear, and flow control must be off.
  • mgmt0 never gets an address: check the link LED and that you are in the MGT port, not a data port. If DHCP fails, the wizard falls back and lets you type a static address.
  • "CLI unavailable" during boot: the switch is still initialising its modules; wait for every module to report ready before typing.
  • Licenses vanish after reboot: you forgot write memory. Licensing state lives in the saved configuration.
  • Cannot log in at all: hold the reset button for fifteen seconds to clear the management-module password, then log in and immediately set a strong one.

Once the switch is up, the natural next steps are to define ports and VLANs and then to build link aggregates. See our MLNX-OS switch port types article, the SONiC ONIE installation quick start, automating NVIDIA Air networks with Ansible, and the follow-up guide to MLNX-OS LAG and LACP configuration.

原文链接:https://networking-docs.nvidia.com/mlnxosum/3121002/getting-started