Ansible连接Nexus 5600超时及重定向问题求助
Hey there, let's break down how to fix those connection issues you're hitting with your Nexus 5600 and Ansible's cisco-programmable-fabric playbook. Since you can ping the switch and access the NXAPI sandbox, basic network connectivity is good—so we'll focus on configuration mismatches and Ansible-specific settings.
1. 先确认NXAPI的完整配置
Even if you can access the sandbox, double-check that NXAPI is set up correctly for Ansible. Log into your Nexus switch and run this command to verify:
show nxapi
Make sure these critical settings are in place:
nxapi enabledis present (obviously, but worth confirming)- Either
http portorhttps portis configured (Ansible defaults to HTTPS) - If you see
redirect http-to-httpsenabled, that's likely the cause of the redirect error onmt-l1—either disable the redirect temporarily, or update your playbook to use HTTPS instead of HTTP.
2. 检查Ansible Inventory(hosts文件)配置
Your hosts file needs the right variables to talk to Nexus via NXAPI. For each Nexus host, add these variables to your inventory:
[nexus_switches] mt-l1 ansible_host=X.X.X.X ansible_network_os=nxos ansible_connection=httpapi ansible_httpapi_port=443 ansible_httpapi_use_ssl=yes ansible_httpapi_validate_certs=no
Let's break down the key ones:
ansible_network_os=nxos: Critical for Ansible to load the correct Nexus modulesansible_connection=httpapi: The standard connection method for NXAPI in Ansible 2.5+ (older setups might usenxapi, buthttpapiis preferred)ansible_httpapi_use_ssl=yes: Matches most Nexus HTTPS configurationsansible_httpapi_validate_certs=no: Skips cert validation for self-signed switch certs (remove this if you use valid, trusted certs)
The timeout error could be a port mismatch—make sure ansible_httpapi_port matches the port you configured on the switch (443 for HTTPS, 80 for HTTP).
3. 验证Playbook中的连接参数
Check your playbook's vars or connection settings to ensure they align with your inventory. For example, if your playbook uses:
vars: ansible_connection: nxapi
Consider switching to httpapi since it's the recommended method for your Ansible version. Also, confirm that any nxapi_port variables in the playbook match the switch's configured port.
4. 用简化Playbook测试连接
Before running the full cisco-programmable-fabric playbook, test connectivity with a minimal playbook to isolate the issue:
- name: Test Nexus basic connectivity hosts: nexus_switches gather_facts: no tasks: - name: Fetch switch version nxos_command: commands: show version
Run it with verbosity to get detailed error logs:
ansible-playbook test_nexus.yml -v
This will show you exactly where the connection fails—whether it's a cert issue, port mismatch, or authentication problem.
5. 检查认证设置
Make sure you're passing the correct credentials. You can add them directly to your inventory (for testing):
ansible_user=admin ansible_password=your_nexus_password
Or use Ansible Vault for secure storage later. Note that NXAPI uses HTTP/HTTPS auth, not SSH keys—so password-based auth is required here.
6. 版本兼容性提示
You're on Ansible 2.5.1 and Python 2.7.5—while this should work, newer Ansible versions (like 2.9+) have better Nexus 5600 support. If possible, upgrading Ansible might resolve hidden compatibility bugs. If you can't upgrade, ensure the cisco-programmable-fabric playbook is explicitly compatible with Ansible 2.5.
Finally, double-check if your switch has ACLs or firewall rules that might block HTTP/HTTPS traffic from your CentOS VM. Even though you can access the sandbox, playbook traffic might be filtered if rules target API-specific endpoints.
内容的提问来源于stack exchange,提问作者P Lew

