Beruflich Dokumente
Kultur Dokumente
BRKDCT-2309
Identifying Migration use cases of Supervisor 2T and step by step migration walkthrough (what is happening during each step)
Provide best practices, configuration and reference material for Migration process and VSS technology
Cisco Catalyst 6500 Switch Architecture Cisco Catalyst 6500 Technical Deep Dive Troubleshooting Cisco Catalyst 6500 Series Switches Cisco Catalyst Virtual Switching System (VSS)
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Verify
Plan
Execute
Presentation Legend
Acronyms Used
VSS Virtual Switching System
Sup Supervisor 2T 2 Terabit Switching HSRP Hot Standby Redundancy Protocol STP Spanning Tree Protocol VSL Virtual Switch Link MEC Multi Chassis Etherchannel
VSS Sup720
Dual Supervisor 2T
Access Switch
CFC Centralized Forwarding Card DFC Distributed Forwarding Card PFC Policy Feature Card MSFC Multi-layer Switch Feature Card X-Bar Cross Bar Switch Fabric
BRKDCT-2309
Cisco Public
Agenda
Current Network Challenges
network design with spanning Tree, User downtime, VSS Solution
BRKDCT-2309
Cisco Public
Business Continuity
Challenges: STP Loops and Slow Routing Convergence Traditional | With Spanning Tree
Productivity Loss
User Downtime (seconds) Switch 1 10GE Switch 2
X
Si
X
VLAN 15
VLAN 10 Access Switch or ToR or Blades Access Switch or ToR or Blades VLAN 10 VLAN 15
The Challenge
Complex network design
BRKDCT-2309
Routing Reconvergence
Business Continuity
Enhanced Availability and Simplified Network Design with VSS
Logical View VSS | Physical View
10GE
Si Si
LACP or PagP
LACP or PagP
LACP LACP
Server Server
The Solution
4 Tbps Virtual Switching System
BRKDCT-2309
With Active-Active MultiSpanning Tree and First Chasis Etherchannel (LACP Hop Redundancy Cisco Public / PagP) 2013 Cisco and/or its affiliates. All rights reserved. Protocols Eliminated
Agenda
Current Network Challenges
network design with spanning Tree, User downtime, VSS Solution
BRKDCT-2309
Cisco Public
10
Supervisor 2T Architecture
Overview
Deployment at Core & Distribution layers 2Tbps switching capacity (4Tbps with VSS) Line-rate encryption (MACSec) New hardware and software features
BRKDCT-2309
Cisco Public
12
Supervisor 2T
At @ Glance
New MSFC5 with single Dual-Core CPU & single IOS image
Supervisor 2T
Block Diagram
Fabric Connector
Local-Bus Fabric Intf 1
PFC4
Bus Replication ASIC
Layer 3/4 forwarding Engine Layer 2 forwarding Engine
Fabric Intf 0
MSFC5
DRAM
Bootdisk
Compact Flash Serial Port
Front Panel
SFP-1
SFP-2
X2-1
SFP-3
X2-2
BRKDCT-2309
Cisco Public
14
PFC4
Virtualization Native (H)VPLS MPLS Aggregate Labels (16K) Multi-point EoMPLS L2oGRE VRF-based NAT & FnF
Monitoring Flexible Netflow (FnF) Egress Netflow L2 (per VLAN) Netflow TCP Flags Per-Protocol Counters
QoS & Security Cisco TrustSec & SGACLs Increased ACL TCAM (256K) Increased ACL Labels (16K) Per-Port / Per-VLAN QoS Distributed Policers (512)
2013 Cisco and/or its affiliates. All rights reserved. Cisco Public
15
FIB TCAM
Contains Layer 2 rewrite information & pointers
Adjacency Table
Adjacency Statistics
Exception Table
LIF Table
LIF Statistics
Contains the actual LIF Database entries
Bus Backplane
Cisco Public
BRKDCT-2309
As each packet header enters the L3 Forwarding ASIC, the IFE pipeline will perform L3 Lookup and Ingress Security, QoS & Netflow processing The header is merged with IFE results and then passed to the OFE pipeline, which will perform Egress Security, QoS & Netflow processing, to generate final result. Headers From L2 Engine
Ingress ACL
L3 Lookup
Ingress QoS
Headers To L2 Engine
BRKDCT-2309
Egress QoS
*also applies to each DFC4
Egress NetFlow
Cisco Public
Egress ACL
17
BRKDCT-2309
Cisco Public
18
2 x 2 GB DDR2 Memory
I/O ASIC
Rommon 32 MB
CMP
CPU 266 MHz
256 MB Memory
Bootdisk
MUX
Front Panel
Compact Flash
Serial Port
10/100/100 Auto-MDI
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public
2T Switch Fabric
Introduction
Integrated 2Tbps Switch Fabric
26 Channels to support the 6513-E Dual Queues (Hi/Lo) per fabric channel Redundant channel to Standby for faster traffic convergence, during SSO switchover... Provides backplane interconnects
BRKDCT-2309
Cisco Public
22
2T Switch Fabric
High Availability
If using VS-S720-10G or VS-SUP2T-10G with a redundant Standby Supervisor, then two (2) fabric channels are connected "back to back": Standby Supervisor uplink connection to Active Supervisor Active Supervisor bus connection to Standby Supervisor
The Standby Supervisor is in DFC Mode, with its Bus connection disabled With Sup2T the redundant Standby Supervisor enables its redundant channels for WS-6908-10GE and WS-6904-40GE modules, for "hitless" failover... Line Card Slot 1
Active Supervisor
Standby Supervisor
Cisco Public 23
720 vs 2T Fabric
Hardware Data-Plane
Feature
Number of Channels Aggregate Bandwidth Channel Speeds (bps) Fabric Redundancy SSO Fabric Hot Synch Redundant Channels Fabric Priority (QoS) Clear Block Support Switching Modes
Header Size) (DBUS
Sup720
18 720 Gbps 8G / 20G Yes No No
Sup720-10G
20* 720 Gbps 8G / 20G Yes Yes* No
Sup2T
26 2 Tbps 20G / 40G Yes Yes Yes
Requires E-Series
Sup2T
Supported WS-F6K-DFC4-A WS-F6K-DFC4-A WS-F6K-DFC4-E WS-F6K-DFC4-E 6908-10G Supported Supported
BRKDCT-2309
Cisco Public
25
Distributed Forwarding
DFC Interoperability with PFC
PFC3A DFC3A DFC3B
Compatible
PFC4 X X
PFC4XL X X
Operate as DFC3A
Operate as DFC3A Operate as DFC3A Operate as DFC3A X X
Operate as PFC3B
Compatible
Operate as PFC3B
Operate as PFC3B & DFC3B
Compatible
Operate as PFC3B
Operate as PFC3BXL Operate as PFC3C
Compatible
DFC3BXL
DFC3C
Operate as DFC3C X X
X X
Operates as PFC4
Compatible
BRKDCT-2309
Cisco Public
26
Catalyst 6500
E Series Chassis
Enhanced (E) Series chassis offer: higher bandwidth higher power capacity, better signal integrity to support Supervisor 2T
3, 4, 6, 9 & 13-slot versions Classic Data Bus traces/connectors Crossbar Fabric traces/connectors Redundant Power supplies
BRKDCT-2309
Cisco Public
27
Slots 1 - 8 each get a single fabric channel Slots 9 - 13 each get dual fabric channels
8x1=8
SWITCH FABRIC
5 x 2 = 10
8 + 10 = 18
Cisco Public 28
BRKDCT-2309
SWITCH FABRIC
13 x 2 = 26
NOTE: This is now possible due to the additional fabric channel traces (physical connectors & wires) on both the Supervisor2T -AND- 6513-E Hence, Supervisor 2T + 6513 (non-E) chassis combination will NOT be supported...
Cisco Public 29
BRKDCT-2309
Sup720
3A/B: 64K 3C: 96K
Sup2T
128K Dual Bank
16K (BD) 1M 120K 16K 12K 64K 32K 4K 1K
Single Bank
4K (VLAN) 1M 100K 12K 8K 32K N/A N/A N/A
BRKDCT-2309
* Available inAll future IOS software 2013 Cisco and/or its affiliates. rights reserved.
releases
Cisco Public
30
Sup720
256K Entries 1M Entries 144 bits 750K / 1K 20K / 50 20K / 50 10K / 10 30K 500 256K (Ingress Only) 2K 1K 16 paths
Sup2T
256K Entries 1M Entries 288 bits 1M / 2K 30K / 75 30K / 75 50K / 50 100K 1K 512K Ingress / 512K Egress 4K 5K 16 paths
BRKDCT-2309
Cisco Public
31
Agenda
Current Network Challenges
network design with spanning Tree, User downtime, VSS Solution
BRKDCT-2309
Cisco Public
32
Standalone to VSS
VSS to VSS
BRKDCT-2309
Cisco Public
34
Single Supervisor
Topology and traffic details
Single Sup720 deployed in pair of Non-E chassis at distribution layer Vlans are divided in group of Red and Green Dist-1 is configured as HSRP Primary/STP root for Red vlans
Dist-1
Dist-2
Dual Supervisors
Topology and traffic details
Dual Sup720s deployed in pair of Non-E chassis at distribution layer (HA or SSO mode) Vlans are divided in group of Red and Green Dist-1 is configured as HSRP Primary/STP root for Red vlans
Dist-1
Dist-2
Dist-1
Dist-2
Spirent traffic generator is used to inject 5000 mac addresses, 100 VLANs, 5000 simulated transmit nodes (Layer 2), 50 SVIs at each core, 50 HSRP groups, 5000 ARP entries (Layer 3)
Layer 3 termination at distribution layer End-hosts are connected to access switch
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
VSS Introduction
L3 Core
L2/L3 Distribution
Access
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved.
L2/L3 Core
L2/L3 Distribution
L2 Access
Cisco Public
40
Traditional
10GE
Si Si
802.3ad or PagP
802.3ad
802.3ad or PagP
802.3ad
Server
Server
Server
Minimizes traffic disruption from switch or uplink failure with Deterministic subsecond
BRKDCT-2309
Stateful and Graceful Recovery (SSO/NSF) 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public
41
L3 Core
L2/L3 Distribution
Access
BRKDCT-2309
Cisco Public
42
L2/L3 Core
L2 Distribution
L2 Access
BRKDCT-2309
Cisco Public
43
Active
Control Plane
Standby Hot
Switch 1
Data Plane
Switch 2
BRKDCT-2309
Cisco Public
44
VS Header
L2 Hdr
L3 Hdr
Data
CRC
Link Management Protocol (LMP) used to track and reject Unidirectional Links, Exchange Chassis ID and other information between the 2 switches
LMP RRP
LMP RRP
Role Resolution Protocol (RRP) used to determine compatible Hardware and Software versions to form the VSL as well as determine which switch becomes Active and Hot Standby from a control plane perspective
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
VSL
VSLP Ping
VSLP Ping
Switch1
Switch2
The VSLP Ping operates on a per-physical interface basis and parameters such as COUNT, DESTINATION, SIZE, TIMEOUT may also be specified
vss#ping vslp output interface tenGigabitEthernet 1/5/4 Type escape sequence to abort. Sending 5, 100-byte VSLP ping to peer-sup via output port 1/5/4, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 12/12/16 ms
BRKDCT-2309
Cisco Public
47
Virtual Switch
Switch Virtual Domain ID Switch Virtual Switch ID Switch Priority Switch Preempt VSL Port Channel Link ID VSL Port state, interfaces Power Redundancy mode Power Enable on VSL cards
Note that if configurations do not match, the Hot-Standby Supervisor will revert to RPR mode, disabling all non-VSL interfaces
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
CFC or DFC Line Cards CFC or DFC Line Cards CFC or DFC Line Cards
VSL
CFC or DFC Line Cards CFC or DFC Line Cards CFC or DFC Line Cards
SF
RP
PFC
SF
RP
PFC
Active Supervisor
CFC or DFC Line Cards CFC or DFC Line Cards CFC or DFC Line Cards
SSO Synchronization
CFC or DFC Line Cards CFC or DFC Line Cards CFC or DFC Line Cards
BRKDCT-2309
Cisco Public
49
Manage traffic forwarded over VSL link by avoiding single homed devices
In case of loss of all members of the VSL bundle, the standby supervisor will go active, creating dual active condition Dual active leads to
Two independent routers with same control plane information e.g. IP address, router ID etc. Error disabling of access-layer due to two STP BPDU sent with different source MAC
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
Switch 2 Slot 5 Processor Information : ---------------------------------------------Current Software state = STANDBY HOT (switchover target) <snip>
Cisco Public
51
Both LACP and PAGP Etherchannel protocols and Manual ON modes are supported
Blue Traffic destined for the Server will result in Link 1 in the MEC link bundle being chosen as the destination path
Link 1
Link 2
Orange Traffic destined for the Server will result in Link 2 in the MEC link bundle being chosen as the destination path
BRKDCT-2309
Cisco Public
53
Etherchannel Concepts
Etherchannel Hash Distribution The default hashing algorithm will redistribute all the Result Bit Hash values across the available ports when there is a change. This affects all traffic traversing the Etherchannel
RBH (for MEC) 2 Link Bundle Example Link 1 Link 2 Flow 1 Flow 2 Flow 3 Flow 4 Flow 5 Flow 6 Flow 7 Flow 8 RBH (for MEC) 3 Link Bundle Example Link 1 Link 2 Link 3 Flow 1 Flow 2 Flow 3 Flow 4 Flow 5 Flow 6 Flow 7 Flow 8
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Etherchannel Concepts
Etherchannel Hash Distribution Adaptive
Adaptive Hash Distribution Enhancement allows for the addition or removal of links in a bundle without affecting all of the traffic in an Etherchannel. Note in the below example, only Flow 7 and 8 are affected by the addition of an extra link to the Channel
RBH (for MEC) 2 Link Bundle Example Link 1 Link 2 Flow 1 Flow 2 Flow 3 Flow 4 Flow 5 Flow 6 Flow 7 Flow 8 Link 1 Flow 1 Flow 3 Flow 5 RBH (for MEC) 3 Link Bundle Example Link 2 Link 3 Flow 2 Flow 7 Flow 4 Flow 8 Flow 6
vss#conf t Enter configuration commands, one per line. End with CNTL/Z. vss(config)#port-channel hash-distribution adaptive vss(config)# ^Z vss#
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
4 5 6 7
BRKDCT-2309
Cisco Public
56
VSL bundle is a special purpose EtherChannel however all the best practices of designing and configuring of any general EtherChannel applies to VSL bundle
Redundancy of VSL is important to avoid dual ACTIVE condition and instability of VSS Diversify VSL bundle on two separate hardware just like any resilient EtherChannel design VSL link hardware selection also affect the QOS configuration on the rest of the ports on supervisors.
BRKDCT-2309
Cisco Public
57
VSL Design
Link Diversification (Dual-Sup Design Option #1)
Ten 1/1/1
Ten 2/1/1
CFC or DFC Linecard CFC or DFC Linecard CFC or DFC Linecard CFC or DFC Linecard
Ten 1/5/4
Ten 2/5/4
VSS Standby CFC or DFC Linecard CFC or DFC Linecard CFC or DFC Linecard
Minimum of two links provides protection from port and SFP failures Separate linecard provides protection from certain interface failures on a single Supervisor Diverse physical paths protect from physical layer outages
VSL Design
Link Diversification (Dual-Sup Design Option #2)
CFC or DFC Linecard VSS Standby CFC or DFC Linecard CFC or DFC Linecard CFC or DFC Linecard CFC or DFC Linecard
Minimum of two links provides protection from port and SFP failures Diverse physical paths protect from physical layer outages No additional VSL-capable linecards are required (Minimal Cost)
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Agenda
Current Network Challenges
network design with spanning Tree, User downtime, VSS Solution
BRKDCT-2309
Cisco Public
60
Verify
Plan
Execute
61
Migration Tips
Distribution switches MUST BE Spanning-tree ROOT
10GE
Si Si
It is a best practice to move the HSRP(Layer 3) first to redundant switch followed by spanning tree root for optimal results and convergence
Download the Sup2T supported image in advance to external compact flash before migration
Use root guard at the edge ports to protect external switch introducing superior BPDUs, e.g. temporary connectivity
Use Spanning tree portfast on all the access ports connected to servers and hosts
BRKDCT-2309
Cisco Public
63
Software Recommendation
Platform
Supervisor 720 Supervisor 2T Minimum 12.2 (SXI3) 12.2 (SY)
IOS version
Recommended 12.2(SXJ) 15.1(SY1)
VSS cannot be formed between Sup 720 running 12.2 SX and Sup 2T running 12.2(SY) or 15.0 (SY)
BRKDCT-2309
Cisco Public
65
Traditionally, traffic is load-balanced among distribution switches using vlan loadsharing and HSRP configuration
L3 Core
Red Vlan
Green Vlan
Distribution
Access
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Forward Delay
Forward Delay
Dist-1#sh standby brief P indicates configured to preempt. | Interface Grp Pri P State Active Vl10 10 120 P Active local Vl20 20 110 P Standby 20.100.100.2
How to read
Dist-1 is root bridge for vlan 10 and secondary root for vlan 20 Dist-1 is HSRP active for group 10
BRKDCT-2309
Cisco Public
67
Dist-2
Dist-1# *Apr 20 02:01:19.559: %HSRP-5-STATECHANGE:Vlan20 Grp 20 state Standby -> Active Dist-1#sh standby brief P indicates configured to preempt. Interface Grp Pri P State Active Vl10 10 120 P Active local Vl20 20 110 P Active local
Green vlans traversing through the Dist-2 will be affected due to HSRP change for 4 secs, largely depends on the HSRP timers
BRKDCT-2309
Cisco Public
68
Make Dist-1 switch STP root for Green vlans Neighboring devices will detect this change and switch all traffic to Dist-1 switch Shutdown Dist-2 physical interfaces to completely remove Dist-2 switch from the network
Dist-1(config)#spanning-tree vlan 20 root primary Dist-1(config)#end Dist-1#sh spanning-tree vlan 20 VLAN0020 Spanning tree enabled protocol rstp Root ID Priority 8192 Address 0017.df3f.e814 This bridge is the root Hello Time 2 sec Max Age 20 sec Bridge ID Priority 8192 Address 0017.df3f.e814 Hello Time 2 sec Max Age 20 sec Aging Time 480
Dist-2
Red vlans traversing through the Dist-2 will be affected, due to STP root change, for 30 secs, largely depends on the STP mode
Cost --------4 1
L3 Core
STP & HSRP Active Dist-1 STP & HSRP Secondary Dist-2
Distribution
Access
The traffic will still be flowing through the Dist-1 BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved.
Distribution
Access
Dist-2#show interfaces gi2/48 To Access Switch GigabitEthernet2/48 is up, line protocol is up (connected) Hardware is C6k 1000Mb 802.3, address is 001f.6cf6.528f (bia 001f.6cf6.528f) - Omit Output Dist-2#show interfaces Po 1 To Primary HSRP Switch Port-channel1 is up, line protocol is up (connected) Hardware is EtherChannel, address is 588d.09e6.81ab (bia 588d.09e6.81ab) - Omit Output -
Dist-2#show interfaces gi2/4 To Core Block GigabitEthernet2/4 is up, line protocol is up (connected) Hardware is C6k 1000Mb 802.3, address is 001f.6cf6.527c (bia 001f.6cf6.527c) - Omit Output BRKDCT-2309
Cisco Public
71
Dist-2#sh standby brief P indicates configured to preempt. | Interface Grp Pri P State Active Standby Vl10 10 100 P Standby 10.100.100.1 local Vl20 20 100 P Standby 20.100.100.1 local
How to read
Dist-2 is now secondary root bridge for vlan 10 and vlan 20 Dist-2 is HSRP standby for group 10 and 20 after migration
BRKDCT-2309
Cisco Public
72
Case 1 : Verification
Supervisor 2T Verification
Dist-2#show version Cisco IOS Software, s2t54 Software (s2t54IPBASEK9-M), Version 15.1(1)SY, RELEASE SOFTWARE (fc5) Technical Support: http://www.cisco.com/techsupport Copyright I 1986-2011 by Cisco Systems, Inc. Compiled Tue 27-Sep-11 02:02 by prod_rel_team ROM: System Bootstrap, Version 12.2(50r)SYS2, RELEASE SOFTWARE (fc1) Dist-2uptime is 51 minutes Uptime for this control processor is 51 minutes System returned to ROM by power on System image file is "bootdisk:s2t54-ipbasek9mz.SPA.151-1.SY.bin" Last reload reason: power-on - Omit Output Cisco WS-C6509-E (M8572) processor (revision) with 1769472K/262144K bytes of memory. Processor board ID SMG0929N81U CPU: MPC8572_E, Version: 2.1, (0x80E80021) CORE: E500, Version: 3.0, (0x80210030) CPU:1500MHz, CCB:600MHz, DDR:600MHz L1: D-cache 32 kB enabled I-cache 32 kB enabled Last reset from power-on
BRKDCT-2309
Dist-2# show module Mod Ports Card Type Model Serial No. --- ----- -------------------------------------1 8 DCEF2T 8 port 10GE WS-X6908-10G SAL16095SXR 2 48 CEF720 48 port 10/100/1000mb Ethe WS-X6748-GE-TX SAL1208GW5C 5 5 Supervisor Engine 2T 10GE w/CTS (Acti VS-SUP2T-10G SAL16020SSN Mod MAC addresses Hw Fw Sw Status --- ---------------------------------1 442b.0311.5588 to 442b.0311.56cf 1.1 2 001f.6cf6.5260 to 001f.6cf6.52f2 2.7 5 588d.098a.b517 to 588d.098a.b654 1.2
Mod Sub-Module Model Serial Hw Status ---- --------------------------- ------------------ ----------1 Distributed Forwarding Card WS-F6K-DFC4-E SAL16095R3F 1.2 Ok 2 Centralized Forwarding Card WS-F6700-CFC SAL1207GEH3 4.0 Ok 5 Policy Feature Card 4 VS-F6K-PFC4 SAL16010C7B 1.1 Ok 5 CPU Daughterboard VS-F6K-MSFC5 SAL16020TKS 1.3 Ok Mod Online Diag Status ---- ------------------1 Pass 2 Pass 5 Pass
Verify the Sup2T insertion and software version using show module and show version
Cisco Public 73
- a brief 4 sec traffic drop was seen for Green vlans during HSRP convergence - during Spanning tree root primary change, 30 sec traffic disruption was seen for Green vlans due to STP re-calculations
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
L3 Core
STP & HSRP Active Dist1 Dist-2 Red Vlan Green Vlan Distribution
Access
Red and Green vlans traversing through the Dist-1 will experience a brief outage due to HSRP change for 4 secs, largely depends on the HSRP timers
Adjust the priorities to make Dist-2 STP root primary and Dist-1 STP root secondary for all vlans Neighboring devices will detect and switch traffic to Dist-2 switch Shutdown Dist-1 physical interfaces to completely remove Dist-1 switch from the network
Dist-2(config)#spanning-tree vlan 10,20 priority 4096 Dist-2(config)#end Dist-2#sh spanning-tree vlan 20 VLAN0020 Spanning tree enabled protocol rstp Root ID Priority 4096 Address 0017.df3f.e814 This bridge is the root Hello Time 2 sec Max Age 20 sec Bridge ID Priority 4095 Address 0017.df3f.e814 Hello Time 2 sec Max Age 20 sec Aging Time 480
STP & HSRP Active Dist-2 Red Vlan Green Vlan Distribution
Access
Vlans traversing through the Dist-1 will be affected, due to STP root change, for 30 secs, largely depends on the STP mode
Cost --------4 1
Both the chassis in distribution pair have now been migrated to new generation Supervisor 2T
Same steps has to be followed for Dual Supervisors 720 in HA mode
Red vlans traversing through the Dist-2 will be affected, due to STP root change and HSRP convergence, for 34 secs
BRKDCT-2309
Cisco Public
- a brief 4 sec traffic drop was seen for all vlans during HSRP convergence - during Spanning tree root primary change, 30 sec traffic disruption was seen for all vlans due to STP re-calculations
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Red Vlan
Green Vlan
Distribution
Access
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
80
802.3ad or PagP
802.3ad
Server
Use root guard at the edge ports to protect external switch introducing superior BPDUs, e.g. temporary connectivity
Use Spanning tree portfast on all the access ports connected to servers and hosts
Do not use loop guard as it will disable the entire MEC channel on fault detection
Cisco Public 81
BRKDCT-2309
L3 Core
Red Vlan
Green Vlan
Distribution
Access
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
L3 Core
1. 2.
L2/L3 Distribution
Migration Steps between Distribution and Access-layer 1. 2. Modify FHRP Configuration Configure Multichassis Ethrechannel Move L2 Trunk configuration to MEC interfaces Move Policies to MEC if needed Keep Spanning-Tree Enabled
Cisco Public 83
Access
3. 4. 5.
BRKDCT-2309
Forward Delay
Forward Delay
Dist-1#sh standby brief P indicates configured to preempt. | Interface Grp Pri P State Active Vl10 10 120 P Active local Vl20 20 110 P Standby 20.100.100.2
How to read
Dist-1 is root bridge for vlan 10 and secondary root for vlan 20 Dist-1 is HSRP active for group 10
BRKDCT-2309
Cisco Public
84
Dist-2
Dist-1# *Apr 20 02:01:19.559: %HSRP-5-STATECHANGE:Vlan20 Grp 20 state Standby -> Active Dist-1#sh standby brief P indicates configured to preempt. Interface Grp Pri P State Active Vl10 10 120 P Active local Vl20 20 110 P Active local
Green vlans traversing through the Dist-2 will be affected due to HSRP change for 4 secs, largely depends on the HSRP timers
BRKDCT-2309
Cisco Public
85
Make Dist-1 switch STP root for Green vlans Neighboring devices will detect this change and switch all traffic to Dist-1 switch Shutdown Dist-2 physical interfaces to completely remove Dist-2 switch from the network
Dist-1(config)#spanning-tree vlan 20 root primary Dist-1(config)#end Dist-1#sh spanning-tree vlan 20 VLAN0020 Spanning tree enabled protocol rstp Root ID Priority 8192 Address 0017.df3f.e814 This bridge is the root Hello Time 2 sec Max Age 20 sec Bridge ID Priority 8192 Address 0017.df3f.e814 Hello Time 2 sec Max Age 20 sec Aging Time 480
Dist-2
Red vlans traversing through the Dist-2 will be affected, due to STP root change, for 30 secs, largely depends on the STP mode
Cost --------4 1
L3 Core
STP & HSRP Active Dist-1 STP & HSRP Secondary Dist-2
Distribution
Access
rommon>boot disk0:s2txx_new_sup2t_image Boot the new Supervisor 2T image from compact disk in rommon prompt,copied from cisco.com -------- <omit output> ------Dist-2#copy disk0:saved_config system:running_config
Cisco Public
Case 2 : Verification
Supervisor 2T Verification
Dist-2#show version Cisco IOS Software, s2t54 Software (s2t54IPBASEK9-M), Version 15.1(1)SY, RELEASE SOFTWARE (fc5) Technical Support: http://www.cisco.com/techsupport Copyright I 1986-2011 by Cisco Systems, Inc. Compiled Tue 27-Sep-11 02:02 by prod_rel_team ROM: System Bootstrap, Version 12.2(50r)SYS2, RELEASE SOFTWARE (fc1) Dist-2uptime is 51 minutes Uptime for this control processor is 51 minutes System returned to ROM by power on System image file is "bootdisk:s2t54-ipbasek9mz.SPA.151-1.SY.bin" Last reload reason: power-on - Omit Output Cisco WS-C6509-E (M8572) processor (revision) with 1769472K/262144K bytes of memory. Processor board ID SMG0929N81U CPU: MPC8572_E, Version: 2.1, (0x80E80021) CORE: E500, Version: 3.0, (0x80210030) CPU:1500MHz, CCB:600MHz, DDR:600MHz L1: D-cache 32 kB enabled I-cache 32 kB enabled Last reset from power-on
BRKDCT-2309
Dist-2# show module Mod Ports Card Type Model Serial No. --- ----- -------------------------------------1 8 DCEF2T 8 port 10GE WS-X6908-10G SAL16095SXR 2 48 CEF720 48 port 10/100/1000mb Ethe WS-X6748-GE-TX SAL1208GW5C 5 5 Supervisor Engine 2T 10GE w/CTS (Acti VS-SUP2T-10G SAL16020SSN Mod MAC addresses Hw Fw Sw Status --- ---------------------------------1 442b.0311.5588 to 442b.0311.56cf 1.1 2 001f.6cf6.5260 to 001f.6cf6.52f2 2.7 5 588d.098a.b517 to 588d.098a.b654 1.2
Mod Sub-Module Model Serial Hw Status ---- --------------------------- ------------------ ----------1 Distributed Forwarding Card WS-F6K-DFC4-E SAL16095R3F 1.2 Ok 2 Centralized Forwarding Card WS-F6700-CFC SAL1207GEH3 4.0 Ok 5 Policy Feature Card 4 VS-F6K-PFC4 SAL16010C7B 1.1 Ok 5 CPU Daughterboard VS-F6K-MSFC5 SAL16020TKS 1.3 Ok Mod Online Diag Status ---- ------------------1 Pass 2 Pass 5 Pass
Verify the Sup2T insertion and software version using show module and show version
Cisco Public 88
- a brief 4 sec traffic drop was seen for Green vlans during HSRP convergence - during Spanning tree root primary change, 30 sec traffic disruption was seen for Green vlans due to STP re-calculations
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 89
Dist - 1
T5/4 T5/4
Dist - 2
Port-Channel 2
Dist- 2
Dist - 2
SWITCH CONSOLE OUTPUT After reload <snip> *Apr 20 04:59:53.999: %PFREDUN-6-ACTIVE: Initializing as ACTIVE processor for this switch *Apr 20 05:00:04.843: %VSL_BRINGUP-6-MODULE_UP: VSL module in slot 5 switch 2 brought up *Apr 20 05:02:06.363: %VSLP-5-RRP_PEER_TIMEOUT: VSLP peer timer expired without detecting peer. Resolving role as Active *Apr 20 05:02:06.415: %VSLP-2-VSL_DOWN: VSL links down and not ready for any traffic <snip.> *Apr 20 05:03:59.795: %DIAG-SW2-6-DIAG_OK: Switch 2 Module 1: Passed Online Diagnostics *Apr 20 05:03:59.987: %SATVS_IBC-SW2-5-VSL_DOWN_SCP_DROP: VSL inactive - dropping cached SCP packet: (SA/DA:0x0/0x4, SSAP/DSAP:0x0/0x1, OP/SEQ:0x1030/0x8, SIG/INFO:0x1/0x21, eSA:0000.0100.0000)
BRKDCT-2309
Cisco Public
92
VSS Switch - 1
BRKDCT-2309
Cisco Public
93
2. 3.
4.
5. 6.
L3 Core
TGig2/2
TGig2/1
TGig1/2/2
TGig1/1/21
Dist-1
Gig1/1 Gig1/2 Gig1/3 Gig1/1/3
Dist-2
Gig1/1/2
VSS
Gig1/1/1
Distribution
Access
BRKDCT-2309
Cisco Public
95
VSS Active
Traditional config
interface TenGigabitEthernet1/2/1 ip address 192.168.4.2 255.255.255.0 interface GigabitEthernet1/1/2 switchport switchport trunk encapsulation dot1q switchport trunk allowed vlan 10,20
MEC to Access
VSS(config-if)#switchport VSS(config-if)#switchport trunk encap dot1q VSS(config-if)#switchport trunk allowed vlan 10,20 VSS(config-if)no shut VSS(config-if)#int gig 1/1/2 VSS(config-if)#switchport VSS(config-if)# channel-group 10 mode desirable
Cisco Public 96
BRKDCT-2309
Core(config-if)#int gig 1/1 Core(config-if)#no ip address Core(config-if)#int po20 Core(config-if)# ip address 192.168.4.2 255.255.255.0 Core(config-if)#no shut Core(config-if)#int gig 1/1 Core(config-if)#channel-group 20 mode desirable
Access(config)#int po10 Access(config)#switchport Access(config)# switchport trunk encapsulation dot1q Access(config)#switchport mode trunk Access(config)#no shut Access(config)#int range gig 1/1 Access(config-if#channel-group 10 mode desirable
BRKDCT-2309
Cisco Public
97
Traditional config
interface Vlan10 ip address 10.1.1.2 255.255.255.0 standby 10 ip 10.1.1.1 standby 10 priority 110 ! interface Vlan20 ip address 20.1.1.2 255.255.255.0 standby 20 ip 20.1.1.1 standby 20 priority 110
BRKDCT-2309
VSS(config)#interface Vlan10 VSS(config-if)# no standby 10 ip 10.1.1.1 VSS(config-if)# no standby 10 pri 110 VSS(config-if)#ip address 10.1.1.1 255.255.255.0 VSS(config)#interface Vlan20 VSS(config-if)# no standby 20 ip 20.1.1.1 VSS(config-if)# no standby 20 pri 110 VSS(config-if)# ip address 20.1.1.1 255.255.255.0
Cisco Public
98
Core Previous L3 interfaces are merged as MEC, hence some routing statement are not needed..
Core#sh run | beg ospf router ospf 1 log-adjacency-changes network 192.168.4.0 0.0.0.255 area 0 network 192.168.5.0 0.0.0.255 area 0 Demo-Core(config)#router ospf 1 Demo-Core(config-router)# nsf Demo-Core(config-router)#no network 192.168.5.0 0.0.0.255 area 0
Cisco Public
99
L3 Core
TGig1/2/2 TGig1/1/21
1.
2. 3. 4.
Dist-1
Gig1/1 Gig1/2 Gig1/3 Gig1/1/2 VSS
Dist-2
Gig1/1/1 Gig1/1/3
Distribution
5.
Access
Cisco Public
100
Dist - 1
T5/4 T5/4
Dist - 2
Port-Channel 2
Dist- 1
102
no shut on VSL port channel 1 and port channel 2 on both VSS switches Both VSS switches will detect this change using VSL control messages Switch-1 is already working in VSS as ACTIVE switch, use redundancy reload shelf command to bring the Dist-1 in preferred STANDBY state after the Dist-1 comes back up, do a no shut on MEC port channels to load balance the traffic over to remaining channel members
Cisco Public
103
L3 Core
VSS
Distribution
Access
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 104
No Pre-empt configuration
Configured and Operational priorities are 100, decided during bootup Local switch is working as STANDBY and remote switch is working as ACTIVE Hostname is automatically adjusted as Dist-2 because Dist-2 migrated first and boots up as ACTIVE VSS switch Dist-1 boots up as STANDBY VSS switch
BRKDCT-2309
Cisco Public
105
Cisco Public
106
During Traffic switchover to VSS-Switch-1 with Sup2T, 50secs disruption for all the vlans were observed due to re-arping for SVI mac addresses and STP convergence
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 107
108
Dist-1 and Dist-2 switches are configured as VSS ACTIVE and STANDBY pair respectively
Traffic is hashed on both the switches from access block and core block using MEC port channels Shutdown the MEC members connected to Dist-2, the core and access block will rehash the traffic flow to the remaining active link in MEC port channel towards Dist1 After traffic redirection shutdown the VSL Port channel on both active and standby pair Hot-standby failover does not introduce control plane convergence because it is not actively responsible for managing various protocols and their updates a brief packet loss (4 secs) is expected when traffic is being rehashed to the remaining MEC members
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public
Dist-1
VSS
Dist-2
Distribution
Access
109
Shutdown all the MEC members on Dist-2 (VSS STANDBY switch) Shutdown the VSL port channel between VSS pair This step will leave the Dist-1 (ACTIVE VSS switch) in simplex mode forwarding all the traffic from remaining MEC members
110
Dist-2
Distribution
Access
111
L3 Core
Dist-1
VSS
Dist-2 Distribution
Access
no shut on VSL port channel 1 and port channel 2 on both VSS switches Both VSS switches will detect this change using VSL control messages Switch-1 is already working in VSS as ACTIVE switch, use redundancy reload shelf command to bring the Dist-1 in preferred STANDBY state after the Dist-1 comes back up, it will sync up the configs from active VSS switch (Dist-2) do a no shut on MEC port channels to load balance the traffic over to remaining channel members
113
Cisco Public
L3 Core
VSL
Distribution
Access
BRKDCT-2309 2013 Cisco and/or its affiliates. All rights reserved. Cisco Public 114
Cisco Public
115
Agenda
Current Network Challenges
network design with spanning Tree, User downtime, VSS Solution
BRKDCT-2309
Cisco Public
116
Migration Results and Summary Traffic impact on Green Vlans moved from Dist-2 switch to Dist-1 switch, 34
Single/Dual Supervisor Migration
seconds Traffic impact on all the vlans moved from Dist-1 switch to Dist-2 switch, 34 seconds Traffic impact on Red Vlans moved from Dist-2 switch to Dist-1 switch, 34 seconds
Traffic impact on Green Vlans moved from Dist-2 switch to Dist-1 switch, 34 seconds Traffic impact on all the vlans moved from Dist-1 switch to Active VSS switch, 50 seconds Traffic hashed to remaining Dist-1 MEC members, 4 seconds
Traffic impact of shutting down MEC members on Standby VSS switch, to re-hash the traffic on Active VSS switch, 4 seconds Traffic impact of all the vlans re-directed from Dist-1 switch to Dist-2 VSS switch, 30 seconds
118
Q&A
References
Supervisor 2T Migration White Paper http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/guide_c07-717261.html
Supervisor 2T Architecture http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/white_paper_c11-676346.html#wp9001122 Cisco Virtual Switching System Design Guide https://www.cisco.com/en/US/docs/solutions/Enterprise/Campus/VSS30dg/campusVSS_DG.html Migrate Standalone Cisco Catalyst 6500 Switch to Cisco Catalyst 6500 Virtual Switching System http://www.cisco.com/en/US/products/ps9336/products_tech_note09186a0080a7c74c.shtml
High Availability Campus Network Design: Routed Access Layer using EIGRP or OSPF http://www.cisco.com/en/US/docs/nsite/campus/ha_campus_routed_access_cvd_ag.pdf
Enterprise Campus 3.0 Architecture: Overview and Framework http://www.cisco.com/en/US/docs/solutions/Enterprise/Campus/campover.html
BRKDCT-2309
Cisco Public
120
Please visit the Cisco Book Store in the World of Solutions and browse through the extensive range of Cisco Press titles.
BRKDCT-2309
Cisco Public
121 121
Call to Action
Visit the Cisco Campus at the World of Solutions
to experience Cisco innovations in action
Schedule face to face meeting with one of Ciscos engineers at the Meet the Engineer center
Discuss your projects challenges at the Technical Solutions Clinics
BRKDCT-2309
Cisco Public
122
Thank you
125
switch virtual domain 10 ! Must configure unique domain ID VSS Global Configuration switch mode virtual switch 1 priority 110 ! Not needed, helps in operational mgmt switch 2 priority 100 ! Not needed, helps in operational mgmt dual-active exclude interface GigabitEthernet1/5/3 ! Connectivity to VSS during dual active mac-address use-virtual ! Required for consistent MAC address dual-active detection pagp trust channel-group 202!Enhanced PAgP based dual-active detection redundancy ! Default SSO Enabled main-cpu auto-sync running-config mode sso interface Port-channel1!Unique portchannel number for SW 1 description VSL Link from Switch 1 no switchport no ip address switch virtual link 1!Defines switch ID for SW 1 mls qos trust cos no mls qos channel-consistency interface ten 1/5/4 channel-group 1 mode on ! EC mode is ON EtherChannel Managemeent Protocol off interface ten 1/1/1 channel-group 1 mode on
spanning-tree mode rapid-pvst no spanning-tree optimize bpdu transmission spanning-tree extend system-id spanning-tree vlan 2-999 priority 24576 ! STP Root port-channel load-balance src-dst-mixed-ip-port ! Enhanced hash algorithem
interface Port-channel2 ! Unique port-channel number for SW 1 description VSL Link from Switch 2 no switchport no ip address switch virtual link 2!Defines switch ID for SW 2 mls qos trust cos no mls qos channel-consistency interface ten 2/5/4 channel-group 2 mode on ! EC mode is ON EtherChannel Managemeent Protocol off interface ten 2/1/1 channel-group 2 mode on Interface Gigabitethernet2/8/23 description Access Switch switchport switchport trunk encapsulation dot1q swtichport trunk native vlan 202 switchport trunk allowed vlan 2,102 <snip> channel-protocol pagp (lacp is an option) channel-group 202 mode desirable
126
Interface Gigabitethernet1/8/23 description Access Switch switchport switchport trunk encapsulation dot1q swtichport trunk native vlan 202 switchport trunk allowed vlan 2,102 <snip> channel-protocol pagp (lacp is an option) channel-group 202 mode desirable
MEC
Interface Port-channel202 description Access Switch switchport switchport trunk encapsulation dot1q swtichport trunk native vlan 202 switchport trunk allowed vlan 2,102
BRKDCT-2309
Cisco Public
127