Showing posts with label Cat6K. Show all posts
Showing posts with label Cat6K. Show all posts

Sunday, April 6, 2008

Cat6K - Software Modularity System Tags

Similar to the idea of a database rollback, Cisco IOS Software Modularity can roll back to a set of installed files defined by a tag.

There are 3 Cisco-defined tags that are created by default:
- CISCO_BASE - This tag is defined as the base image with no patches or other tags. Using this tag with the install rollback command takes you back to the installed bsae image.
- CISCO_LATEST - This tag is defined as removing one level of install file. Using this tag with the install rollback command removes the set of files that were added with the last install file command entry. If the patch is in an active state, it will set the patch to a PendRoll state meaning that the changes will not take place until the install activate command is entered. If the patch as been installed but not activated, the install rollback command removes the installed patch.
- CISCO_LATEST_ACTIVATE - This tag is defined as removing one level of install activation. Using this tag with the install rollback command removes the set of files that were most recently activated by the install activate command. If multiple maintenance packs or patches werer installed with the install file command and then got activated simulatenously with a single install activate command, all files are marked to be rolled back.

Create Tag
1. To create a tag, execute the "install commit" command as seen below:
6500-x#install commit disk0:/sys ospf_fix

2. To verify what tags have been installed:
6500-x#show install tags running
Tags defined over software running on location s72033_rp - Slot 1 :
Tagname # of Files Date Committed
------------------------------- ---------- ------------------------
ospf_fix 2 19:31:48 UTC May 9 2006
Tags defined over software running on location s72033 - Slot 1 :
Tagname # of Files Date Committed
------------------------------- ---------- ------------------------
ospf_fix 1 19:31:48 UTC May 9 2006

Repackaging
The repackage feature will copy all necessary files to a single binary file which can be installed on another system. The "install repackage" command will be used.

6500-x#install repackage disk0:/sys disk0:/lab_repackage.bin

To verify, execute dir disk0:
6500-1#dir disk0:
Directory of disk0:/
1 -rwx 69213304 Apr 25 2006 20:08:28 +00:00 s72033-ipservicesk9-vz.sx4-demo
2 -rwx 636416 Apr 25 2006 20:10:44 +00:00 s72033-XMA0001.122-18.SXF4
3 -rwx 769024 Apr 25 2006 20:11:20 +00:00 s72033-XMA0002.122-18.SXF4
4 -rwx 1287168 Apr 25 2006 20:11:46 +00:00 s72033-XMA0003.122-18.SXF4
5 drwx 1 May 9 2006 18:08:48 +00:00 sys
81 -rwx 69963776 May 9 2006 19:44:08 +00:00 lab_repackage.bin
512065536 bytes total (278913024 bytes free)

Rollback
Execute "install rollback" to roll the system back:
6500-x#install rollback disk0:/sys ospf_fix

Verify the patch is in the "PendRoll" state:
6500-1#show install running
Software running on card installed at location s72033_rp - Slot 1 :
B/P C State Filename
--- - -------- --------
B * Active disk0:/sys/s72033_rp/base/DRACO2_MP
MP Maintenance Pack MA0001.122
P * Active disk0:/sys/s72033_rp/patch/patch-XAA2101-00-0-n.so
MP Maintenance Pack
P PendRoll disk0:/sys/s72033_rp/patch/patch-XAA2102-01-0-n.so
Software running on card installed at location s72033 - Slot 1 :
B/P C State Filename
--- - -------- --------
B * Active disk0:/sys/s72033/base/s72033-ipservicesk9-vm(12.2(20060403:18507))

Next step to activate the rollback by issuing the install activate command:
6500-x#install activate disk0:/sys

To remove the ospf_fix tag:
install prune disk0:/sys ospf_fix

Cat6K - Software Modularity

Software Modularity is an enhancement to the existing Cat6K IOS, which allows you apply patches to individual subsystem (Subsystem ISSU) and allows the change to be applied with no service disruption.

This example will show you how to enable the software modularity feature on IOS and apply maintenance packs.

You'll quickly identify the difference by doing a "show process cpu"

6500-1#show process cpu
CPU utilization for five seconds: 2%; one minute: 2%; five minutes: 2%
PID 5Sec 1Min 5Min Process
1 0.4% 0.5% 0.3% kernel
3 0.0% 0.0% 0.0% qdelogger
4 0.0% 0.0% 0.0% devc-pty
5 0.0% 0.0% 0.0% devc-mistral.proc
6 0.0% 0.0% 0.0% pipe
7 0.0% 0.0% 0.0% dumper.proc
4104 0.0% 0.0% 0.0% pcmcia_driver.proc
4105 0.0% 0.0% 0.0% bflash_driver.proc
12298 0.0% 0.0% 0.0% mqueue
12299 0.0% 0.0% 0.0% flashfs_hes.proc
12300 0.0% 0.0% 0.0% dfs_bootdisk.proc

You can also get more details on an individual process with "show process detailed iprouting.iosproc"

6500-x#show process detailed iprouting.iosproc
Job Id: 76
PID: 16427
Executable name: iprouting.iosproc
Executable Path: sbin/iprouting.iosproc
Instance ID: 1
Respawn: ON
Respawn count: 1
Respawn since last patch: 1
Max. spawns per minute: 30
Last started: Thu Apr 20 14:15:12 2006
Process state: Run
Feature name: iprouting
Core: SHAREDMEM MAINMEM
Max. core: 0
Level: 100
Mandatory: ON
Last restart userid:
Related Processes:
PID TID Stack pri state Blked HR:MM:SS:MSEC FLAGS NAME
16427 1 32K 10 Receive 1 0:00:00:0264 00000000 iprouting.iospro
16427 2 32K 10 Receive 1 0:00:00:0000 00000000 iprouting.iospro
16427 3 32K 10 Receive 1 0:00:00:0616 00000000 iprouting.iospro
16427 4 32K 11 Nanosleep 0:00:00:0000 00000000 iprouting.iospro
16427 5 32K 10 Receive 1 0:00:00:0068 00000000 iprouting.iospro
16427 6 32K 10 Receive 1 0:00:00:0000 00000000 iprouting.iospro

And "show process cpu detailed iprouting.iosproc"
6500-x#show proc cpu detailed iprouting.iosproc
CPU utilization for five seconds: 2%; one minute: 2%; five minutes: 2%
PID/TID 5Sec 1Min 5Min Process Prio STATE CPU
16427 0.0% 0.0% 0.0% iprouting.iosproc 1.236
1 0.0% 0.0% 0.0% 10 Receive 0.308
2 0.0% 0.0% 0.0% 10 Receive 0.000
3 0.0% 0.0% 0.0% 10 Receive 0.628
4 0.0% 0.0% 0.0% 11 Nanosleep 0.000
5 0.0% 0.0% 0.0% 10 Receive 0.068
6 0.0% 0.0% 0.0% 10 Receive 0.000
Process sbin/iprouting.iosproc, type IOS, PID = 16427
CPU utilization for five seconds: 0%/0%; one minute: 0%; five minutes: 0%
Task Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Task Name
1 60 498 120 0.00% 0.00% 0.00% 0 Hot Service Task
2 228 2764 82 0.00% 0.00% 0.00% 0 Service Task
3 0 9 0 0.00% 0.00% 0.00% 0 Service Task
4 0 4 0 0.00% 0.00% 0.00% 0 Service Task
5 3 5 600 0.00% 0.00% 0.00% 0 Chunk Manager
6 0 579 0 0.00% 0.00% 0.00% 0 Load Meter
7 0 1 0 0.00% 0.00% 0.00% 0 Connection Mgr
8 31 569 54 0.00% 0.00% 0.00% 0 OSPF Hello
9 0 291 0 0.00% 0.00% 0.00% 0 Check heaps
10 0 1 0 0.00% 0.00% 0.00% 0 Socket Timers
11 72 538 133 0.00% 0.00% 0.00% 0 IP Background
Task Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Task Name
12 0 111 0 0.00% 0.00% 0.00% 0 IP RIB Update
13 0 1 0 0.00% 0.00% 0.00% 0 Service Task
14 0 49 0 0.00% 0.00% 0.00% 0 Per-minute Jobs
15 76 496 153 0.00% 0.00% 0.00% 0 Hot Service Task
16 20 2928 6 0.00% 0.00% 0.00% 0 OSPF Router 1

1. In order to run the system in "installed" mode, the original binary file is expanded into a treed sub-dir file structure that allows for patching.

install file disk0:/s72033-ipservicesk9-vz.sxf4-demo disk0:/sys

2. Verfiy the creation of Directory Structure

dir disk0:/sys

3. Bind the system to the file system directory

install bind disk0:/sys

You'll see something like this after apply the "install bind" command:
6500-x#show running-config | include boot
boot system disk0:/sys/s72033/base/s72033-ipservicesk9-vm

To further verify, do a "show bootvar"
6500-x#show bootvar
BOOT variable = disk0:/sys/s72033/base/s72033-ipservicesk9-vm,12;
CONFIG_FILE variable does not exist
BOOTLDR variable =
Configuration register is 0x2102

4. Reload your system

Then verify your system after reload with the "show install running" command:
6500-1#show install running
Software running on card installed at location s72033_rp - Slot 1 :
B/P C State Filename
--- - -------- --------
B Active disk0:/sys/s72033_rp/base/DRACO2_MP
Software running on card installed at location s72033 - Slot 1 :
B/P C State Filename
--- - -------- --------
B Active disk0:/sys/s72033/base/s72033-ipservicesk9-vm(12.2(20060403:18507))
LEGEND:
-------:
B/P/MP - (B)ase image, (P)atch, or (M)aintenance (P)ack
'C' - (C)ommitted
Pruned - This file has been pruned from the system
Active - This file is active in the system
PendInst - This file is set to be made available to run on the
system after next activation.

5. Install maintenance pack
6500-x# install file disk0:/s72033-XMA0001.122-18.SXF4 disk0:/sys

6. Verify the maintenance pack installation
6500-x#show install running
Software running on card installed at location s72033 - Slot 1 :
B/P C State Filename
--- - -------- --------
B Active disk0:/sys/s72033/base/s72033-ipservicesk9-vm(12.2(20060403:185507))
Software running on card installed at location s72033_rp - Slot 1 :
B/P C State Filename
--- - -------- --------
B Active disk0:/sys/s72033_rp/base/DRACO2_MP
MP Maintenance Pack MA0001.122
P PendInst disk0:/sys/s72033_rp/patch/patch-XAA2101-00-0-n.so

7. Activate the maintenance pack
6500-x#install activate disk0:/sys

8. Verify activation of maintenance pack
6500-x#show install running
Software running on card installed at location s72033_rp - Slot 1 :
B/P C State Filename
--- - -------- --------
B Active disk0:/sys/s72033_rp/base/DRACO2_MP
MP Maintenance Pack MA0001.122
P Active disk0:/sys/s72033_rp/patch/patch-XAA2101-00-0-n.so
Software running on card installed at location s72033 - Slot 1 :
B/P C State Filename
--- - -------- --------
B Active disk0:/sys/s72033/base/s72033-ipservicesk9-vm(12.2(20060403:18507))


Monday, March 31, 2008

Virtual Switching System (VSS) Conversion

IOS: 12.2(33)SXH1

The conversion process involves 4 steps:

1. Configure Virtual Switch Domain and desingate each switch as either Switch 1 or Switch 2
2. Configure priority
3. Configure Virtual Switching Links (VSL)
4. Execute the Conversion command after which the switches will reload

Configure the Virtual Switch Domain
The virtual switch domain is a grouping of 2 members of VSS with an ID from 1-255, which both members must match this number in the virtual switch domain.

On switch 1:
sw1#conf t
Enter configuration commands, one per line. End with CNTL/Z.
sw1(config)#switch virtual domain 1
Domain ID 1 config will take effect only
after the exec command 'switch convert mode virtual' is issued
sw1(config-vs-domain)#switch 1
sw1(config-vs-domain)#

On switch 2:
sw2#conf t
Enter configuration commands, one per line. End with CNTL/Z.
sw2(config)#switch virtual domain 1
Domain ID 1 config will take effect only
after the exec command 'switch convert mode virtual' is issued
sw2(config-vs-domain)#switch 2
sw2(config-vs-domain)#


Configure Priority
Higher priority node will assume active virtual switch, similar to HSRP.

On Switch 1:
sw1(config-vs-domain)#switch 1 priority 110
sw1(config-vs-domain)#switch 2 priority 100

On Switch 2:
sw2(config-vs-domain)#switch 1 priority 110
sw2(config-vs-domain)#switch 2 priority 100


Configuring VSL

On Switch 1:
sw1(config)#interface port-channel 1
sw1(config)#no shut
sw1(config-if)#switch virtual link 1
sw1(config-if)#exit
sw1(config)#interface range tenGigabitEthernet 1/4 - 5
sw1(config-if-range)#no shut
sw1(config-if-range)#channel-group 1 mode on
sw1(config-if-range)#^Z

On Switch 2:
sw2(config)#int port-channel 2
sw2(config-if)#no shut
sw2(config-if)#switch virtual link 2
sw2(config-if)#exit
sw2(config)#interface range tenGigabitEthernet 1/4 – 5
sw2(config-if-range)#no shut
sw2(config-if-range)#channel-group 2 mode on
sw2(config-if-range)#^Z

Executing Conversion

On Switch 1:
sw1#switch convert mode virtual
This command will convert all interface names
to naming convention "interface-type switch-number/slot/port",
save the running config to startup-config and
reload the switch.
Do you want to proceed? [yes/no]: yes
Converting interface names
Building configuration...

On Switch 2:
sw2#switch convert mode virtual
This command will convert all interface names
to naming convention "interface-type switch-number/slot/port",
save the running config to startup-config and
reload the switch.
Do you want to proceed? [yes/no]: yes
Converting interface names
Building configuration...

You will see these output on the switch processor during reload:
Switch 1:
Initializing as Virtual Switch active

Switch 2:
Initializing as Virtual Switch standby

After reload, switch 2's console is no longer available:
sw1-sdby>
Standby console disabled
sw1-sdby>
Standby console disabled

One last step to complete the conversion:

sw1#switch accept mode virtual
This command will bring in all VSL configurations from the standby switch and populate
it into the running configuration. In addition the startup configurations will be updated with
the new merged configurations.
Do you want proceed? [yes/no]: yes
Merging the standby VSL configuration. . .
Building configuration...
[OK]