Connectrix: "svc-nxcloud" User Visible When Intersight Feature is Disabled on Switch

Summary: This article explains the workaround when the "svc-nxcloud" user account is visible in the running-configuration.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Beginning with Cisco NX-OS MDS9000 Release 9.3(2), the Device Connector on NX-OS feature is supported which provides a secure way for the connected devices to send information and receive control instructions from the Cisco Intersight portal, using a secure Internet connection.

The Cisco MDS9000 switch must properly resolve svc.intersight.com and allow outbound initiated HTTPS connections on port 443. To resolve svc.intersight.com, you must configure DNS on the Cisco MDS9000 devices. If a proxy is required for an HTTPS connection to svc.intersight.com, the proxy can be configured in the NXDC user interface.

The "Intersight" (NXDC) feature gets enabled by default after NX-OS 9.3(2).

After upgrade to an Intersight capable release, "svc-nxcloud" and "svc-nxcloud-1" user accounts may be visible in the running configuration even if Intersight is disabled.

Excerpts from logs:

`show feature` 

Feature Name         Instance State 

-------------------- -------- -----

intersight           1        disabled

show running-config:

username svc-nxcloud password 5 <removed>  role network-admin

username svc-nxcloud passphrase  lifetime 99999 warntime 14 gracetime 3

Cause

Cisco issue CSCwh50405
The user account is related to Intersight functions and should be disabled if Intersight is disabled.

Resolution

Cisco switches were upgraded from NX-OS v9.2.1 to v9.3.2a code. After code upgrades, local users "svc-nxcloud-1" and "svc-nxcloud" with network-admin were created.

Workaround:
There is no workaround. This is cosmetic as account is not usable using real user processes that is CLI.

Disable the feature if it is not being used:
Example:

switch(config)# no feature intersight
NOTE:
  • The users get created for Intersight connectivity.
  • The purpose of this user is to allow Intersight to read or write data as needed if configured.
  • There are no default credentials for these users to log in to the switch.

Additional Information

More details about the feature are available from the Cisco guide, Cisco MDS9000 Series Fundamentals Configuration Guide, Release 9.xThis hyperlink is taking you to a website outside of Dell Technologies.

Products

Connectrix MDS-Series Firmware
Article Properties
Article Number: 000219684
Article Type: Solution
Last Modified: 15 Apr 2025
Version:  3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.