Pages

Friday, March 28, 2014

Cisco Integrated Services Routers Licensing - 3945E as example

1. Situation

My work environment has a Cisco Route 3945E which is running following IOS:

Cisco IOS Software, C3900e Software (C3900e-UNIVERSALK9-M), Version 15.1(4)M4, RELEASE SOFTWARE (fc1)
ROM: System Bootstrap, Version 15.1(1r)T5, RELEASE SOFTWARE (fc1)

Technology Package License Information for Module:'c3900e' 

-----------------------------------------------------------------
Technology    Technology-package           Technology-package
              Current       Type           Next reboot  
------------------------------------------------------------------
ipbase        ipbasek9      Permanent      ipbasek9
security      None          None           None
uc            None          None           None
data          None          None           None

I will need to figure out how to enable IP SLA feature. 

2. Research

Based Cisco IOS Packaging Model, Data IOS will be the rightt package if IP SLA feature will need for our environment.
 IOS Packaging Model for 1900, 2900 and 3900 ISRs


Technology Package

Details

Software Activation Feature Licenses

Right to Use Feature Licenses

IPBaseK9

Offers features found in IPBase IOS image on ISR 1800,2800 and 3800 + Flexible Netflow + IPV6 parity for IPV4 features present in IPBase. Some of the key feature are AAA BGP, OSPF, EIGRP, ISIS, RIP PBR IGMP, Multicast DHCP HSRP, GLBP NHRP HTTP HQF QoS ACL, NBAR GRE CDP, ARP NTP PPP PPPoA PPPoE RADIUS TACACS SCTP SMDS SNMP STP VLAN DTP IGMP Snooping SPAN WCCP ISDN ADSL over ISDN NAT-Basic X.25, RSVP, NTP, Flexible Netflow etc.

None

None

SECK9

Offers the security features found in Advanced Security IOS image on ISR 1800,2800 and 3800 e.g. IKE v1 / IPsec / PKI, IPsec/GRE, Easy VPN w/ DVTI, DMVPN, Static VTI, Firewall, Network Foundation Protection,GETVPN etc.

SSLVPN 

Intrusion Prevention 

Content Filtering 

None

UC

Offers the UC Features found in IPVoice IOS image on ISR 1800,2800 and 3800 e.g. TDM/PSTN Gateway, Video Gateway[H320/324],Voice Conferencing, Codec Transcoding, RSVP Agent (voice), FAX T.37/38, CAC/QOS, Hoot-n-Holler etc.

Gatekeeper

Land Mobile Radio

CME: Voice & Video 

SRST: Voice & Video 

VXML/IVR Gateway 

CUBE [IPIP Gateway] 

DATA

Data features found in SP Services and Enterprise Services IOS image on ISR 1800,2800 and 3800 e.g. MPLS, BFD, RSVP ,L2VPN, L2TPv3 ,Layer 2 Local Switching , Mobile IP, Multicast Authentication,FHRP-GLBP ,IP SLAs, PfR ,DECnet, RSRB, BIP, DLSw+, FRAS, Token Ring ,ISL, IPX ,STUN, SNTP, SDLC, QLLC etc.

SNA Switching

None

3. Solution

PO has been created with our network device vendor. After a couple of days, received Cisco email forwarded from our supplier.

 go to http://www.cisco.com/go/license

Log in with your CCO account

Product License Registration page will be shown up:

Enter your PAK (Product Authorization Key) got from Cisco's email:

Choose Quantity and also Router 3945E's info from show version command:

Last step is to download the license. At the same time you will get the email with license in it.

4. Useful Commands

copy ftp://test:test@10.10.10.10 flash:

license install flash:license.lic

more flash:license.lic

reload

5. Verify

show license
Index 1 Feature: ipbasek9                       
        Period left: Life time
        License Type: Permanent
        License State: Active, In Use
        License Count: Non-Counted
        License Priority: Medium
Index 2 Feature: securityk9                     
        Period left: Not Activated
        Period Used: 0  minute  0  second  
        License Type: EvalRightToUse
        License State: Not in Use, EULA not accepted
        License Count: Non-Counted
        License Priority: None
Index 3 Feature: uck9                           
        Period left: Not Activated
        Period Used: 0  minute  0  second  
        License Type: EvalRightToUse
        License State: Not in Use, EULA not accepted
        License Count: Non-Counted
        License Priority: None
Index 4 Feature: datak9                         
        Period left: Life time
        License Type: Permanent
        License State: Active, Not in Use
        License Count: Non-Counted
        License Priority: Medium
Index 5 Feature: gatekeeper                     
        Period left: Not Activated
        Period Used: 0  minute  0  second  
        License Type: EvalRightToUse
        License State: Not in Use, EULA not accepted
        License Count: Non-Counted
        License Priority: None
Index 6 Feature: LI                             
Index 7 Feature: SSL_VPN                        
        Period left: Not Activated
        Period Used: 0  minute  0  second  
        License Type: EvalRightToUse
        License State: Not in Use, EULA not accepted
        License Count: 0/0  (In-use/Violation)
        License Priority: None
Index 8 Feature: ios-ips-update                 
        Period left: Not Activated
        Period Used: 0  minute  0  second  
        License Type: EvalRightToUse
        License State: Not in Use, EULA not accepted
        License Count: Non-Counted
        License Priority: None
Index 9 Feature: SNASw                          
        Period left: Not Activated
        Period Used: 0  minute  0  second  
        License Type: EvalRightToUse
        License State: Not in Use, EULA not accepted
        License Count: Non-Counted
        License Priority: None
Index 10 Feature: hseck9                         
Index 11 Feature: cme-srst                       
        Period left: Not Activated
        Period Used: 0  minute  0  second  
        License Type: EvalRightToUse
        License State: Not in Use, EULA not accepted
        License Count: 0/0  (In-use/Violation)
        License Priority: None
Index 12 Feature: UCVideo                        
        Period left: Not Activated
        Period Used: 0  minute  0  second  
        License Type: EvalRightToUse
        License State: Not in Use, EULA not accepted
        License Count: Non-Counted
        License Priority: None

After system reloaded, license will be used in IOS. You will see it is in use from Show license command:
Index 4 Feature: datak9                         
        Period left: Life time
        License Type: Permanent
        License State: Active, In Use
        License Count: Non-Counted
        License Priority: Medium

Show version:
-----------------------------------------------------------------
Technology    Technology-package           Technology-package
              Current       Type           Next reboot  
------------------------------------------------------------------
ipbase        ipbasek9      Permanent      ipbasek9
security      None          None           None
uc            None          None           None
data          datak9        Permanent      datak9

Monday, March 24, 2014

%PLATFORM_PBR-4-SDM_MISMATCH: PBR requires sdm template routing - Enable PBR on Cisco 3560E

Symptons

Working on Cisco 3560E with IOS C3560-IPSERVICESK9-M and trying to enable Policy Based Routing on vlan interface with command :

ip access-list extended Re_Route_10.99.13.66

 permit ip host 10.99.13.66 any

route-map Map_Re_Route_10.99.13.66 permit 10
 match ip address Re_Route_10.99.13.66
 set ip next-hop 10.99.2.30
!
interface Vlan13
ip policy route-map Map_Re_Route_10.99.13.66 

but got following errors in the log:
017242: .Mar 24 14:59:46.961 EDT: %PLATFORM_PBR-4-SDM_MISMATCH: PBR requires sdm template routing




Switch information is list below:
SW-3560E#sh ver
Cisco IOS Software, C3560 Software (C3560-IPSERVICESK9-M), Version 12.2(53)SE1, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Fri 12-Mar-10 16:54 by prod_rel_team
Image text-base: 0x01000000, data-base: 0x02E00000

ROM: Bootstrap program is C3560 boot loader
BOOTLDR: C3560 Boot Loader (C3560-HBOOT-M) Version 12.2(44)SE5, RELEASE SOFTWARE (fc1)

M-CSWO2001 uptime is 42 weeks, 3 days, 23 hours, 47 minutes
System returned to ROM by power-on
System restarted at 15:01:02 EDT Thu May 30 2013
System image file is "flash:c3560-ipservicesk9-mz.122-53.SE1.bin"
....

cisco WS-C3560G-24TS (PowerPC405) processor (revision C0) with 131072K bytes of memory.
Processor board ID FOC10030125
Last reset from power-on
4 Virtual Ethernet interfaces
28 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.

512K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address       : 00:17:94:30:40:80
Motherboard assembly number     : 73-9718-04
Power supply part number        : 341-0090-01
Motherboard serial number       : FOC10030125
Power supply serial number      : AZS100006CN
Model revision number           : C0
Motherboard revision number     : A0
Model number                    : WS-C3560G-24TS-S
System serial number            : FOC10030125
SFP Module assembly part number : 73-7757-03
SFP Module revision Number      : A0
SFP Module serial number        : CAT1007110
Top Assembly Part Number        : 800-2584-02
Top Assembly Revision Number    : B0
Version ID                      : V02
CLEI Code Number                : CNMW2001RB
Hardware Board Revision Number  : 0x05


Switch Ports Model              SW Version            SW Image                 
------ ----- -----              ----------            ----------               
*    1 28    WS-C3560G-24TS     12.2(53)SE1           C3560-IPSERVICESK9-M     


Research
Googled Internet, and found SDM template has to change to meet this requirement. Here are some documentation explains this:
Understanding Policy Routing
Configuring SDM Templates

SDM templates is used to configure system resources in the switch to optimize support for specific features, depending on how the switch is used in the network. You can select a template to provide maximum system usage for some functions or use the default template to balance resources.

To allocate ternary content addressable memory (TCAM) resources for different usages, the switch SDM templates prioritize system resources to optimize support for certain features. You can select SDM templates to optimize these features:

•Access—The access template maximizes system resources for access control lists (ACLs) to accommodate a large number of ACLs.

•Default—The default template gives balance to all functions.

•Routing—The routing template maximizes system resources for IPv4 unicast routing, typically required for a router or aggregator in the center of a network.

•VLANs—The VLAN template disables routing and supports the maximum number of unicast MAC addresses. It would typically be selected for a Layer 2 switch.

Solution

SW-3560E#show sdm prefer default 
 "desktop default" template:
 The selected template optimizes the resources in
 the switch to support this level of features for
 8 routed interfaces and 1024 VLANs. 

  number of unicast mac addresses:                  6K
  number of IPv4 IGMP groups + multicast routes:    1K
  number of IPv4 unicast routes:                    8K
    number of directly-connected IPv4 hosts:        6K
    number of indirect IPv4 routes:                 2K
  number of IPv4 policy based routing aces:         0
  number of IPv4/MAC qos aces:                      0.5K
  number of IPv4/MAC security aces:                 1K

SW-3560E(config)#sdm prefer ?
  access              Access bias
  default             Default bias
  dual-ipv4-and-ipv6  Support both IPv4 and IPv6
  ipe                 IPe bias
  routing             Unicast bias
  vlan                VLAN bias


SW-3560E(config)#sdm prefer routing 
Changes to the running SDM preferences have been stored, but cannot take effect 
until the next reload.
Use 'show sdm prefer' to see what SDM preference is currently active.

SW-3560E(config)#sdm prefer default 

Performance Impact 

For the negative impact on CPU after implemented PBR, please refer to doc:

Troubleshooting Reference

Some troubleshooting commands:

SW-3560E#show processes cpu history 
SW-3560E#show platform tcam utilization

CAM Utilization for ASIC# 0                      Max            Used
                                             Masks/Values    Masks/values

 Unicast mac addresses:                        784/6272         37/209   
 IPv4 IGMP groups + multicast routes:          152/1216          6/26    
 IPv4 unicast directly-connected routes:       784/6272         37/209   
 IPv4 unicast indirectly-connected routes:     272/2176         13/69    
 IPv4 policy based routing aces:                 0/0             0/0     
 IPv4 qos aces:                                768/768         260/260   
 IPv4 security aces:                          1024/1024         33/33    

Note: Allocation of TCAM entries per feature uses
a complex algorithm. The above information is meant
to provide an abstract view of the current TCAM utilization

SW-3560E#sh controller cpu-interface | i icmp 
icmp              436790153  0          0          24         0         
icmp              0            24   


SW-3560E#show ip cef 10.99.2.64 detail 
10.99.2.64/32, epoch 2, flags attached
  Adj source: IP adj out of Vlan2, addr 10.99.2.64 052DCC00
   Dependent covered prefix type adjfib cover 10.99.2.0/24
  attached to Vlan2



SW-3560E#show platform ip unicast adjacency 10.99.2.64 0
10.99.2.64 Vlan:2 Mac:3cb1.5b51.629b OI:33 PDFlags:0x108 MAD:0x3F19384(RWI-IP:33 RWI-HMSM:33) Ref:1
        COMPLETE  MAD OK Stn OK Mvid OK MvidLock VlLock:2
        HMSM_hdl: 0x3F19384, Stn:0x138


SW-3560E#sh controllers cpu-interface
ASIC    Rxbiterr   Rxunder    Fwdctfix   Txbuflos   Rxbufloc   Rxbufdrain
-------------------------------------------------------------------------
ASIC0     0          0          0          0          0          0         
ASIC1     0          0          0          0          0          0         
ASIC2     0          0          0          0          0          0         
ASIC3     0          0          0          0          0          0         
ASIC4     0          0          0          0          0          0         
ASIC5     0          0          0          0          0          0         
ASIC6     0          0          0          0          0          0         

HOL Fix Counts
--------------
No Fixes:          0 Added:          1 In Use:          0 Both:         23

CPU Heartbeat Statistics

Tx Success Tx Fail    1st Thr    2nd Thr    Unthr      RetryCtMax
---------- ---------- ---------- ---------- ---------- ----------
 511575214          0          0          0          0          1

Rx Delay
         0          1          2          3          4 
---------- ---------- ---------- ---------- ---------- 
 511575214          0          0          0       


SW-3560E#debug platform cpu-queues software-fwd-q





Monday, March 10, 2014

My Cisco IOU Racks - from flyxj IOUv3

My Cisco IOU Racks:
- from flyxj

Vmware configuration:



I have modified Interface IP to match my local configuration:
Root password is flyxj.cn
Change IOUv3 interface ip command:
root@flyxj:~/LAB# ifconfig eth0 192.168.80.160




This is topology looks like. Totally there are six routers and four switches. Good enough to finish most routing / switching lab.

Enabled R1 and R2. Now it shows green in the topology.

root@flyxj:~/LAB# ifconfig
eth0      Link encap:Ethernet  HWaddr 00:0c:29:df:93:07
          inet addr:192.168.80.159  Bcast:192.168.80.255  Mask:255.255.255.0
          inet6 addr: fe80::20c:29ff:fedf:9307/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:52 errors:0 dropped:0 overruns:0 frame:0
          TX packets:13 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:5397 (5.2 KiB)  TX bytes:908 (908.0 B)
          Interrupt:19 Base address:0x2000

eth1      Link encap:Ethernet  HWaddr 00:0c:29:df:93:11
          inet addr:10.10.10.160  Bcast:10.10.10.255  Mask:255.255.255.0
          inet6 addr: fe80::20c:29ff:fedf:9311/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:141 errors:0 dropped:0 overruns:0 frame:0
          TX packets:95 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:13924 (13.5 KiB)  TX bytes:12882 (12.5 KiB)
          Interrupt:16 Base address:0x2080

eth2      Link encap:Ethernet  HWaddr 00:0c:29:df:93:1b
          inet addr:192.168.20.160  Bcast:192.168.20.255  Mask:255.255.255.0
          inet6 addr: fe80::20c:29ff:fedf:931b/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:44 errors:0 dropped:0 overruns:0 frame:0
          TX packets:6 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:4843 (4.7 KiB)  TX bytes:468 (468.0 B)
          Interrupt:17 Base address:0x2400

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Mask:255.0.0.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:16436  Metric:1
          RX packets:16 errors:0 dropped:0 overruns:0 frame:0
          TX packets:16 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:2014 (1.9 KiB)  TX bytes:2014 (1.9 KiB)


Using Telnet access 10 devices with port from 2001 to 2010. Also IOU3 itself support ssh access.

Enjoying.....

File Copy Between Two Juniper SRX Cluster Members

I have two SRX Cluster Members and managed from remotely. Each time when transferring package file remotely it will take several hours for 140M new junos file.

File copy command can copy file between routing engines but looks does not work well on SRX Cluster.

I tried to login into routing engine re0 or re1 on SRX. It is always in same routing engine. But with node 0 and node 1, it works well.


root@fw-1% cli
{primary:node0}
root@fw-1> 



root@fw-1% request routing-engine login re0  
root@fw-1%

root@fw-1% request routing-engine login re1
root@fw-1%


root@fw-1> request routing-engine login node 1 

--- JUNOS 11.4R7.5 built 2013-03-01 11:40:03 UTC



root@fw-2> file copy /var/tmp/junos10.3.tgz re1:/var/tmp/junos10.3.tgz
re1: No route to host
re1: No route to host
error: put-file failed
error: could not send local copy of file

root@fw-2> file copy /var/tmp/junos10.3.tgz node0:/var/tmp/junos10.3.tgz
ssh: Could not resolve hostname node0: hostname nor servname provided, or not known
lost connection
error: put-file failed
error: could not send local copy of file

After a couple of times try, I found a way to use fxp0.0 interface ip to do file transferring:
  file copy /var/tmp/junos10.3.tgz 10.2.8.4:/var/tmp/junos10.3.tgz


and the speed is 2.2MB/s. pretty nice. And file transferring can be done in 1 minutes.

Thursday, March 6, 2014

Juniper NSM Schema Upgrade Failed


My Juniper NSM version is 2012.1R6.
Tried to upgrade Juniper NSM Schema online from current 280 to latest 293, but got following failed message:
Error Code: 

Error Text:
   Schema Download Failed.

Error Details:
   No such file or directory
svn: Can't open file '/usr/netscreen/GuiSvr/var/dmi-schema-stage/nsm/dmi/junos-es/releases/12.1R5.5/.svn/text-base/config.xsd.svn-base': No such file or directory

Basically this NSM will have to manually upgrade schema, online is not working. Here are steps for how to do it:


Note: Technote ID:TN86 -NSM & Junos Compatibility Matrix, will be needed to download latest Schema from Schema Offline Download Links.