Sunday, March 5, 2017

Stacking a Cisco 3750 Switch

I've stacked Cisco 2960 and 3650 switches before but now I was asked to configure and stack a Cisco 3750 switch. The Cisco 3750 has built-in StackWise ports and use a StackWise cable. A Cisco 3750 switch can be stacked with other Cisco 3750 models. Here's a good link that shows the difference between a Cisco 3750-X, Cisco 3750 V2, Cisco 3750-G and Cisco 3750-E switches.

Below is a Cisco 3750 StackWise stacking cable.


There are two StackWise ports (STACK 1 and STACK 2) found at the back of a Cisco 3750 switch which is protected by a plastic cover.



Below is a Full Bandwidth connection setup.



Using driver version 1 for media type 1
Base ethernet MAC Address: f4:7f:35:22:e1:23
Xmodem file system is available.
The password-recovery mechanism is enabled.
Initializing Flash...
mifs[2]: 0 files, 1 directories
mifs[2]: Total bytes     :    3870720
mifs[2]: Bytes used      :       1024
mifs[2]: Bytes available :    3869696
mifs[2]: mifs fsck took 0 seconds.
mifs[3]: 416 files, 8 directories
mifs[3]: Total bytes     :   27998208
mifs[3]: Bytes used      :   13384704
mifs[3]: Bytes available :   14613504
mifs[3]: mifs fsck took 6 seconds.
...done Initializing Flash.
done.
Loading "flash:/c3750-ipbasek9-mz.122-50.SE5/c3750-ipbasek9-mz.122-50.SE5.bin"...@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

<OUTPUT TRUNCATED>

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
File "flash:/c3750-ipbasek9-mz.122-50.SE5/c3750-ipbasek9-mz.122-50.SE5.bin" uncompressed and

installed, entry point: 0x1000000
executing...

              Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

           cisco Systems, Inc.
           170 West Tasman Drive
           San Jose, California 95134-1706



Cisco IOS Software, C3750 Software (C3750-IPBASEK9-M), Version 12.2(50)SE5, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Tue 28-Sep-10 12:56 by prod_rel_team
Image text-base: 0x01000000, data-base: 0x02900000

Initializing flashfs...
Using driver version 1 for media type 1
mifs[3]: 0 files, 1 directories
mifs[3]: Total bytes     : 3870720
mifs[3]: Bytes used      : 1024
mifs[3]: Bytes available : 3869696
mifs[3]: mifs fsck took 1 seconds.
mifs[3]: Initialization complete.

mifs[4]: 416 files, 8 directories
mifs[4]: Total bytes     : 27998208
mifs[4]: Bytes used      : 13384704
mifs[4]: Bytes available : 14613504
mifs[4]: mifs fsck took 0 seconds.
mifs[4]: Initialization complete.

...done Initializing flashfs.
Checking for Bootloader upgrade.. not needed

POST: CPU MIC register Tests : Begin
POST: CPU MIC register Tests : End, Status Passed

POST: PortASIC Memory Tests : Begin
POST: PortASIC Memory Tests : End, Status Passed

POST: CPU MIC interface Loopback Tests : Begin
POST: CPU MIC interface Loopback Tests : End, Status Passed

POST: PortASIC RingLoopback Tests : Begin
POST: PortASIC RingLoopback Tests : End, Status Passed

SM: Detected stack cables at PORT1 PORT2

Waiting for Stack Master Election...
SM: Waiting for other switches in stack to boot...
##################################################################################################

#####################
SM: All possible switches in stack are booted up

front_end/ (directory)
extracting front_end/fe_type_1 (34760 bytes)
extracting front_end/fe_type_2 (78400 bytes)
extracting front_end/front_end_ucode_info (86 bytes)
extracting ucode_info (76 bytes)
POST: Inline Power Controller Tests : Begin
POST: Inline Power Controller Tests : End, Status Passed

POST: PortASIC CAM Subsystem Tests : Begin
POST: PortASIC CAM Subsystem Tests : End, Status Passed


POST: PortASIC Stack Port Loopback Tests : Begin
POST: Found Stack port 2 Down
POST: PortASIC Stack Port Loopback Tests : End, Status Passed

POST: PortASIC Port Loopback Tests : Begin
POST: PortASIC Port Loopback Tests : End, Status Passed

Election Complete
Switch 1 booting as Master
Waiting for Port download...Complete


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco WS-C3750V2-24PS (PowerPC405) processor (revision Q0) with 131072K bytes of memory.
Processor board ID FDO1619Y123
Last reset from power-on
1 Virtual Ethernet interface
48 FastEthernet interfaces
4 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.

512K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address       : F4:7F:35:22:E1:23
Motherboard assembly number     : 73-11704-13
Power supply part number        : 341-0266-03
Motherboard serial number       : FDO16190ABC
Power supply serial number      : DCA1610HXYZ
Model revision number           : Q0
Motherboard revision number     : A0
Model number                    : WS-C3750V2-24PS-S
System serial number            : FDO1619Y123
Top Assembly Part Number        : 800-31035-05
Top Assembly Revision Number    : B0
Version ID                      : V07
CLEI Code Number                : COMP400ARC
Hardware Board Revision Number  : 0x03


Switch Ports Model              SW Version            SW Image
------ ----- -----              ----------            ----------
*    1 26    WS-C3750V2-24PS    12.2(50)SE5           C3750-IPBASEK9-M
     2 26    WS-C3750V2-24PS    12.2(50)SE5           C3750-IPBASEK9-M


Switch 02
---------
Switch Uptime                   : Unknown
Base ethernet MAC Address       : F4:7F:35:23:33:45
Motherboard assembly number     : 73-11704-13
Power supply part number        : 341-0266-03
Motherboard serial number       : FDO16190JKL
Power supply serial number      : DCA1610HMNO
Model revision number           : Q0
Motherboard revision number     : A0
Model number                    : WS-C3750V2-24PS-S
System serial number            : FDO1619YGHI
Top assembly part number        : 800-31035-05
Top assembly revision number    : B0
Version ID                      : V07
CLEI Code Number                : COMP400ARC



Press RETURN to get started!


*Mar  1 00:02:58.870: %STACKMGR-4-SWITCH_ADDED: Switch 1 has been ADDED to the stack
*Mar  1 00:02:58.870: %STACKMGR-4-SWITCH_ADDED: Switch 2 has been ADDED to the stack
*Mar  1 00:03:08.877: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to down
*Mar  1 00:03:10.262: %SPANTREE-5-EXTENDED_SYSID: Extended SysId enabled for type vlan
*Mar  1 00:03:32.089: %STACKMGR-5-SWITCH_READY: Switch 1 is READY
*Mar  1 00:03:32.089: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 1 Switch 1 has changed to state UP
*Mar  1 00:03:32.089: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 2 Switch 1 has changed to state DOWN
*Mar  1 00:03:32.441: %STACKMGR-5-MASTER_READY: Master Switch 1 is READY
*Mar  1 00:03:32.777: %SYS-5-RESTART: System restarted --
Cisco IOS Software, C3750 Software (C3750-IPBASEK9-M), Version 12.2(50)SE5, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Tue 28-Sep-10 12:56 by prod_rel_team
*Mar  1 00:03:37.332: %STACKMGR-5-SWITCH_READY: Switch 2 is READY
*Mar  1 00:03:37.332: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 1 Switch 2 has changed to state UP
*Mar  1 00:03:37.332: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 2 Switch 2 has changed to state DOWN
*Mar  1 00:01:24.246: %STACKMGR-4-SWITCH_ADDED: Switch 1 has been ADDED to the stack (Switch-2)
*Mar  1 00:01:24.246: %STACKMGR-4-SWITCH_ADDED: Switch 2 has been ADDED to the stack (Switch-2)
*Mar  1 00:03:35.780: %SPANTREE-5-EXTENDED_SYSID: Extended SysId enabled for type vlan (Switch-2)
*Mar  1 00:03:37.290: %STACKMGR-5-SWITCH_READY: Switch 1 is READY (Switch-2)
*Mar  1 00:03:37.961: %STACKMGR-5-MASTER_READY: Master Switch 1 is READY (Switch-2)     // I BOOTED SWITCH 1 FIRST AND WAITED FOR 5 MINS BEFORE BOOTING SWITCH 2
*Mar  1 00:03:38.019: %STACKMGR-5-SWITCH_READY: Switch 2 is READY (Switch-2)
*Mar  1 00:03:38.179: %SYS-5-RESTART: System restarted -- (Switch-2)
Cisco IOS Software, C3750 Software (C3750-IPBASEK9-M), Version 12.2(50)SE5, RELEASE SOFTWARE (fc1)
(Switch-2)
Technical Support: http://www.cisco.com/techsupport (Switch-2)
Copyright (c) 1986-2010 by Cisco Systems, Inc. (Switch-2)
Compiled Tue 28-Sep-10 12:56 by prod_rel_team (Switch-2)


         --- System Configuration Dialog ---

Enable secret warning
----------------------------------
In order to access the device manager, an enable secret is required
If you enter the initial configuration dialog, you will be prompted for the enable secret
If you choose not to enter the intial configuration dialog, or if you exit setup without setting

the enable secret,
please set an enable secret using the following CLI in configuration mode-
enable secret 0 <cleartext password>
----------------------------------
Would you like to enter the initial configuration dialog? [yes/no]: no
Switch>enable
*Mar  1 00:04:32.688: %LINK-5-CHANGED: Interface Vlan1, changed state to administratively down
Switch#
Switch#show switch
Switch/Stack Mac Address : f47f.3522.e123
                                           H/W   Current
Switch#  Role   Mac Address     Priority Version  State
----------------------------------------------------------
*1       Master f47f.3522.e123     1      0       Ready
 2       Member f47f.3523.3345     1      0       Ready

Switch#show switch stack-ports
  Switch #    Port 1       Port 2
  --------    ------       ------
    1           Ok          Down
    2           Ok          Down

Switch#show switch neighbors
  Switch #    Port 1       Port 2
  --------    ------       ------
      1         2            None
      2         1            None

Switch#show platform stack manager all
Switch/Stack Mac Address : f47f.3522.e123
                                           H/W   Current
Switch#  Role   Mac Address     Priority Version  State
----------------------------------------------------------
*1       Master f47f.3522.e123     1      0       Ready
 2       Member f47f.3523.3345     1      0       Ready



         Stack Port Status             Neighbors
Switch#  Port 1     Port 2           Port 1   Port 2
--------------------------------------------------------
  1        Ok        Down               2      None
  2        Ok        Down               1      None


               Stack Discovery Protocol View
==============================================================


Switch   Active   Role    Current   Sequence   Dirty
Number                    State     Number     Bit
--------------------------------------------------------------------
1        TRUE    Master   Ready       052       FALSE
2        TRUE    Member   Ready       053       FALSE



                 Stack State Machine View
==============================================================

Switch   Master/   Mac Address          Version    Current
Number   Member                          (maj.min)  State
-----------------------------------------------------------
1        Master    f47f.3522.e123          1.41        Ready
2        Member    f47f.3523.3345          1.41        Ready

Last Conflict Parameters

Switch Master/ Cfgd Default Image H/W  # of    Mac Address
Number Member  Prio Config   Type Prio Members
-----------------------------------------------------------------------
 1     Member   1   Yes       4    2   0  f47f.3522.e123
 2     Member   1   Yes       4    2   0  f47f.3523.3345

            Stack Discovery Protocol Counters
        Messages Sent                  Messages Recvd
        UP       DOWN                  UP        DOWN
--------------------------------------------------------
*1: 0000004657 0000000000          0000000000 0000000000
 2: 0000000000 0000000000          0000002748 0000000000
 3: 0000000000 0000000000          0000000000 0000000000
 4: 0000000000 0000000000          0000000000 0000000000
 5: 0000000000 0000000000          0000000000 0000000000
 6: 0000000000 0000000000          0000000000 0000000000
 7: 0000000000 0000000000          0000000000 0000000000
 8: 0000000000 0000000000          0000000000 0000000000
 9: 0000000000 0000000000          0000000000 0000000000


             Misc  Counters
   Counter                      Up          Down
---------------------------------------------------

 Wrong Ver Number: Send:    0000000000    0000000000
 Wrong Ver Number: Recv:    0000000000    0000000000
 Missed Messages:           0000000000    0000000000
 Orphaned Messages          0000000000    0000000000
 Suppressed Messages        0000000000    0000000000
 No Available Messages      0000000006    0000000000
 Link Present               0000000003    0000000000
 Link Not Present           0000000003    0000000001
 Link RxReset               0000000013    0000000010
 Link Sync Stuck Resets     0000000000    0000000000
 Duplicates                 0000002130    0000000000
 RAC Not OK Resets          0000000000
 Switch# of last duplicate  0000000002
 Sequence Number Failures   0000000000
 RAC Not OK Resets          0000000000
 Sync Not OK Resets         0000000031    0000001041
 Switch# of last Failure:   256  Last Difference 0
 Switch Number Conflicts    0
 Stack Changes              6
 Int Stack Link changes     0
 Int Stack Link state       0x0
 Reciprocal Efficiency Changes: Upgrade 0, Downgrade 0
             Resource Counters
-------------------------------------------
 Chunk Alloc's        0000000008
 Chunk Free's         0000000007
 Enqueue Failures:    0000000000
 Null Queue Failures: 0000000000
 Chunk Alloc Errors:  0000000000


           Stack State Machine Counters
   Messages Sent              Messages Recvd
-------------------------------------------------
*1: 0000000000                 0000000000
 2: 0000000008                 0000000008
 3: 0000000000                 0000000000
 4: 0000000000                 0000000000
 5: 0000000000                 0000000000
 6: 0000000000                 0000000000
 7: 0000000000                 0000000000
 8: 0000000000                 0000000000
 9: 0000000000                 0000000000


I still didn't see Switch 3 joining the stack so I tightened its StackWise cable. I looked at the LED status lights and Switch 3 is still sees being the MASTER. I've observed the SYST light was blinking and it took Switch 3 a few of minutes to auto reboot and joined the stack.


Switch#
*Mar  1 00:11:20.123: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 2 Switch 2 has changed to state UP
*Mar  1 00:11:55.162: %STACKMGR-4-SWITCH_ADDED: Switch 3 has been ADDED to the stack
*Mar  1 00:11:55.128: %STACKMGR-4-SWITCH_ADDED: Switch 3 has been ADDED to the stack (Switch-2)
*Mar  1 00:12:01.546: %STACKMGR-5-SWITCH_READY: Switch 3 is READY
*Mar  1 00:12:01.546: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 1 Switch 3 has changed to state UP
*Mar  1 00:12:01.546: %STACKMGR-4-STACK_LINK_CHANGE: Stack Port 2 Switch 3 has changed to state DOWN
*Mar  1 00:12:01.512: %STACKMGR-5-SWITCH_READY: Switch 3 is READY (Switch-2)
*Mar  1 00:12:02.863: %STACKMGR-5-SWITCH_READY: Switch 1 is READY (Switch-3)
*Mar  1 00:12:02.980: %STACKMGR-5-MASTER_READY: Master Switch 1 is READY (Switch-3)
*Mar  1 00:12:02.980: %STACKMGR-5-SWITCH_READY: Switch 2 is READY (Switch-3)
*Mar  1 00:12:03.114: %STACKMGR-5-SWITCH_READY: Switch 3 is READY (Switch-3)

Switch#show switch
Switch/Stack Mac Address : f47f.3522.e123
                                           H/W   Current
Switch#  Role   Mac Address     Priority Version  State
----------------------------------------------------------
*1       Master f47f.3522.e123     1      0       Ready
 2       Member f47f.3523.3345    1      0       Ready
 3       Member a418.7554.1678     1      0       Ready

Switch#show switch stack-ports
  Switch #    Port 1       Port 2
  --------    ------       ------
    1           Ok          Down
    2           Ok           Ok
    3           Ok          Down

Switch#show switch neighbors
  Switch #    Port 1       Port 2
  --------    ------       ------
      1         2            None
      2         1             3
      3         2            None

Switch#show platform stack manager all
Switch/Stack Mac Address : f47f.3522.e123
                                           H/W   Current
Switch#  Role   Mac Address     Priority Version  State
----------------------------------------------------------
*1       Master f47f.3522.e123     1      0       Ready
 2       Member f47f.3523.3345     1      0       Ready
 3       Member a418.7554.1678     1      0       Ready


         Stack Port Status             Neighbors
Switch#  Port 1     Port 2           Port 1   Port 2
--------------------------------------------------------
  1        Ok        Down               2      None
  2        Ok         Ok                1        3
  3        Ok        Down               2      None


               Stack Discovery Protocol View
==============================================================


Switch   Active   Role    Current   Sequence   Dirty
Number                    State     Number     Bit
--------------------------------------------------------------------
1        TRUE    Master   Ready       122       FALSE
2        TRUE    Member   Ready       132       FALSE
3        TRUE    Member   Ready       123       FALSE


                 Stack State Machine View
==============================================================

Switch   Master/   Mac Address          Version    Current
Number   Member                          (maj.min)  State
-----------------------------------------------------------
1        Master    f47f.3522.e123         1.41        Ready
2        Member    f47f.3523.3345          1.41        Ready
3        Member    a418.7554.1678          1.41        Ready

Last Conflict Parameters

Switch Master/ Cfgd Default Image H/W  # of    Mac Address
Number Member  Prio Config   Type Prio Members
-----------------------------------------------------------------------
 1     Master   1   Yes       4    2   1  f47f.3522.e123
 2     Member   1   Yes       4    2   0  f47f.3523.3345

            Stack Discovery Protocol Counters
        Messages Sent                  Messages Recvd
        UP       DOWN                  UP        DOWN
--------------------------------------------------------
*1: 0000005883 0000000000          0000000000 0000000000
 2: 0000000000 0000000000          0000003830 0000000000
 3: 0000000000 0000000000          0000000123 0000000000
 4: 0000000000 0000000000          0000000000 0000000000
 5: 0000000000 0000000000          0000000000 0000000000
 6: 0000000000 0000000000          0000000000 0000000000
 7: 0000000000 0000000000          0000000000 0000000000
 8: 0000000000 0000000000          0000000000 0000000000
 9: 0000000000 0000000000          0000000000 0000000000


             Misc  Counters
   Counter                      Up          Down
---------------------------------------------------

 Wrong Ver Number: Send:    0000000000    0000000000
 Wrong Ver Number: Recv:    0000000000    0000000000
 Missed Messages:           0000000000    0000000000
 Orphaned Messages          0000000000    0000000000
 Suppressed Messages        0000000000    0000000000
 No Available Messages      0000000018    0000000000
 Link Present               0000000003    0000000000
 Link Not Present           0000000003    0000000001
 Link RxReset               0000000013    0000000010
 Link Sync Stuck Resets     0000000000    0000000000
 Duplicates                 0000002927    0000000000
 RAC Not OK Resets          0000000000
 Switch# of last duplicate  0000000002
 Sequence Number Failures   0000000000
 RAC Not OK Resets          0000000000
 Sync Not OK Resets         0000000031    0000002614
 Switch# of last Failure:   256  Last Difference 0
 Switch Number Conflicts    0
 Stack Changes              11
 Int Stack Link changes     0
 Int Stack Link state       0x0
 Reciprocal Efficiency Changes: Upgrade 0, Downgrade 0
             Resource Counters
-------------------------------------------
 Chunk Alloc's        0000000015
 Chunk Free's         0000000013
 Enqueue Failures:    0000000000
 Null Queue Failures: 0000000000
 Chunk Alloc Errors:  0000000000


           Stack State Machine Counters
   Messages Sent              Messages Recvd
-------------------------------------------------
*1: 0000000000                 0000000000
 2: 0000000010                 0000000010
 3: 0000000005                 0000000005
 4: 0000000000                 0000000000
 5: 0000000000                 0000000000
 6: 0000000000                 0000000000
 7: 0000000000                 0000000000
 8: 0000000000                 0000000000
 9: 0000000000                 0000000000

Switch#show version
Cisco IOS Software, C3750 Software (C3750-IPBASEK9-M), Version 12.2(50)SE5, RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2010 by Cisco Systems, Inc.
Compiled Tue 28-Sep-10 12:56 by prod_rel_team
Image text-base: 0x01000000, data-base: 0x02900000

ROM: Bootstrap program is C3750 boot loader
BOOTLDR: C3750 Boot Loader (C3750-HBOOT-M) Version 12.2(50r)SE, RELEASE SOFTWARE (fc1)

Switch uptime is 21 minutes
System returned to ROM by power-on
System image file is "flash:/c3750-ipbasek9-mz.122-50.SE5/c3750-ipbasek9-mz.122-50.SE5.bin"


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco WS-C3750V2-24PS (PowerPC405) processor (revision Q0) with 131072K bytes of memory.
Processor board ID FDO1619Y123
Last reset from power-on
1 Virtual Ethernet interface
72 FastEthernet interfaces
6 Gigabit Ethernet interfaces
The password-recovery mechanism is enabled.

512K bytes of flash-simulated non-volatile configuration memory.
Base ethernet MAC Address       : F4:7F:35:22:E1:23
Motherboard assembly number     : 73-11704-13
Power supply part number        : 341-0266-03
Motherboard serial number       : FDO16190ABC
Power supply serial number      : DCA1610HXYZ
Model revision number           : Q0
Motherboard revision number     : A0
Model number                    : WS-C3750V2-24PS-S
System serial number            : FDO1619Y123
Top Assembly Part Number        : 800-31035-05
Top Assembly Revision Number    : B0
Version ID                      : V07
CLEI Code Number                : COMP400ARC
Hardware Board Revision Number  : 0x03


Switch Ports Model              SW Version            SW Image
------ ----- -----              ----------            ----------
*    1 26    WS-C3750V2-24PS    12.2(50)SE5           C3750-IPBASEK9-M
     2 26    WS-C3750V2-24PS    12.2(50)SE5           C3750-IPBASEK9-M
     3 26    WS-C3750V2-24PS    12.2(50)SE5           C3750-IPBASEK9-M


Switch 02
---------
Switch Uptime                   : 20 minutes
Base ethernet MAC Address       : F4:7F:35:23:33:45
Motherboard assembly number     : 73-11704-13
Power supply part number        : 341-0266-03
Motherboard serial number       : FDO16190JKL
Power supply serial number      : DCA1610HMNO
Model revision number           : Q0
Motherboard revision number     : A0
Model number                    : WS-C3750V2-24PS-S
System serial number            : FDO1619YGHI
Top assembly part number        : 800-31035-05
Top assembly revision number    : B0
Version ID                      : V07
CLEI Code Number                : COMP400ARC

Switch 03
---------
Switch Uptime                   : 10 minutes
Base ethernet MAC Address       : A4:18:75:54:16:78
Motherboard assembly number     : 73-11704-13
Power supply part number        : 341-0266-03
Motherboard serial number       : FDO16150QRS
Power supply serial number      : DCA1606HTUV
Model revision number           : Q0
Motherboard revision number     : A0
Model number                    : WS-C3750V2-24PS-S
System serial number            : FDO1615X1J0
Top assembly part number        : 800-31035-05
Top assembly revision number    : B0
Version ID                      : V07
CLEI Code Number                : COMP400ARC

Configuration register is 0xF

Friday, February 3, 2017

Cisco 4331 Router IOS and License Upgrade

I've configured and installed Network Interface Module (NIM) and PVDM module on a Cisco 4331 ISR router on my previous post. Now I'll share the steps on how to perform an IOS upgrade and install a feature license on a Cisco 4000 series router. 


Router#dir ?
  /all             List all files
  /recursive       List files recursively
  all-filesystems  List files on all filesystems
  bootflash:       Directory or file name
  cns:             Directory or file name
  flash:           Directory or file name
  null:            Directory or file name
  nvram:           Directory or file name
  system:          Directory or file name
  tar:             Directory or file name
  tmpsys:          Directory or file name
  usb0:            Directory or file name      // usb0: WILL BE DISPLAYED IF ROUTER SUPPORTS IT
  |                Output modifiers
  <cr>

Router#dir usb0:
Directory of usb0:/

  112  -rwx                0  Aug 20 2013 07:39:20 +00:00  system
  113  -rwx         62682268  Mar 29 2012 12:04:58 +00:00  c2900-universalk9-mz.SPA.150-1.M4.bin
  114  -rwx          4968160   Dec 9 2014 11:44:34 +00:00  TeamViewerQS_en-idch93gk2g.exe
  115  -rwx        125231421  Feb 12 2015 17:00:24 +00:00  lms5.1.bin
  116  -rwx         95947928  Sep 26 2015 08:01:34 +00:00  c2900-universalk9-mz.SPA.153-3.M6.bin
  117  -rwx        302988468  Mar 29 2016 14:29:12 +00:00  cat3k_caa-universalk9.SPA.03.06.04.E.152-2.E4.bin
  118  -rwx         97911420  Mar 27 2015 18:25:44 +00:00  c3900-universalk9-mz.SPA.154-1.T1.bin
  119  -rwx         52420608   Apr 1 2016 13:13:32 +00:00  asa924-8-smp-k8.bin
  120  -rwx         69285888  Mar 24 2016 14:55:24 +00:00  asa942-11-smp-k8.bin
  121  -rwx             1402  Jun 30 2016 23:39:00 +00:00  BOOTEX.LOG
  122  drwx            32768   Jul 1 2016 00:02:18 +00:00  System Volume Information
  123  -rwx         45424992  Aug 12 2016 13:59:18 +00:00  c2800nm-advsecurityk9-mz.151-4.M10.bin
  124  -rwx         25819140  Nov 26 2016 21:45:52 +00:00  asdm-761.bin
  125  -rwx         86678080  Nov 26 2016 21:48:12 +00:00  asa961-10-lfbff-k8.SPA
  126  -rwx        174131122  Nov 25 2016 06:30:38 +00:00  AIR-CT2500-K9-8-0-140-0.aes
  127  -rwx        420461412  Nov 25 2016 05:54:08 +00:00  isr4300-universalk9.03.13.06a.S.154-3.S6a-ext.SPA.bin      // CISCO RECOMMENDED IOS VERSION AS OF THIS WRITING

2013200384 bytes total (448921600 bytes free)

Router#copy usb0:isr4300-universalk9.03.13.06a.S.154-3.S6a-ext.SPA.bin flash:
Destination filename [isr4300-universalk9.03.13.06a.S.154-3.S6a-ext.SPA.bin]?
Copy in progress...CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC

<OUTPUT TRUNCATED>

CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC

Router#dir
*Dec  3 07:10:11.475 UTC: %PARSER-5-CFGLOG_LOGGEDCMD: User:console  logged command:boot system bootflash:isr4300-universalk9.03.13.06a.S.154-3.S6a-ext.SPA.bin
*Dec  3 07:10:12.467 UTC: %SYS-5-CONFIG_I: Configured from console by console
Directory of bootflash:/

   11  drwx            16384  Mar 24 2016 03:53:01 +00:00  lost+found
193537  drwx             4096   Dec 3 2016 06:50:06 +00:00  .prst_sync
   12  -rw-        470602752  Mar 24 2016 04:12:15 +00:00  isr4300-universalk9.03.16.02.S.155-3.S2-ext.SPA.bin
80641  drwx             4096  Mar 24 2016 03:53:32 +00:00  .installer
177409  drwx             4096  Mar 24 2016 04:20:10 +00:00  core
64513  drwx             4096  Mar 24 2016 04:20:10 +00:00  .rollback_timer
   13  -rw-                0  Mar 24 2016 04:20:20 +00:00  tracelogs.219
209665  drwx             8192   Dec 3 2016 06:54:52 +00:00  tracelogs
   14  -rw-               30   Dec 3 2016 06:50:06 +00:00  throughput_monitor_params
   15  -rw-        420461412   Dec 3 2016 07:09:34 +00:00  isr4300-universalk9.03.13.06a.S.154-3.S6a-ext.SPA.bin

3249049600 bytes total (2191085568 bytes free)

Router#show run | include boot
boot-start-marker
boot-end-marker
license boot level appxk9

Router#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#boot system bootflash:isr4300-universalk9.03.13.06a.S.154-3.S6a-ext.SPA.bin
Router(config)#end
Router#sh run | i bootf
boot system bootflash:isr4300-universalk9.03.13.06a.S.154-3.S6a-ext.SPA.bin
Router#write memory
Building configuration...

[OK]
Router#reload
Proceed with reload? [confirm]

*Dec  3 07:10:45.779 UTC: %SYS-5-RELOAD: Reload requested by console. Reload Reason: Reload Command.Dec  3 07:11:00.990 R0/0: %PMAN-5-EXITACTION: Process manager is exiting: process exit with reload chassis code


<OUTPUT TRUNCATED>


I also needed to activate an evaluation (90-day) appxk9 license to support the MPLS commands on the Cisco 4331 router. The datak9 is the equivalent license in Cisco ISR G2 series routers (1900, 2900, 3900).

Router#show version
Cisco IOS XE Software, Version 03.13.06a.S - Extended Support Release
Cisco IOS Software, ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.4(3)S6a, RELEASE SOFTWARE (fc2)

Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2016 by Cisco Systems, Inc.
Compiled Tue 27-Sep-16 21:02 by mcpre


Cisco IOS-XE software, Copyright (c) 2005-2016 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.  For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


ROM: IOS-XE ROMMON

Router uptime is 1 minute
Uptime for this control processor is 2 minutes
System image file is "bootflash:isr4300-universalk9.03.13.06a.S.154-3.S6a-ext.SPA.bin"
Last reload reason: Reload Command


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

        
Suite License Information for Module:'esg'

--------------------------------------------------------------------------------
Suite                 Suite Current         Type           Suite Next reboot    
--------------------------------------------------------------------------------
FoundationSuiteK9     None                  None           None                 
securityk9
appxk9

AdvUCSuiteK9          None                  None           None                 
uck9
cme-srst
cube

Technology Package License Information:

-----------------------------------------------------------------
Technology    Technology-package           Technology-package
              Current       Type           Next reboot 
------------------------------------------------------------------
appxk9           None             None             None
uck9             None             None             None
securityk9       None             None             None
ipbase           ipbasek9         Permanent        ipbasek9

cisco ISR4331/K9 (1RU) processor with 1655569K/6147K bytes of memory.
Processor board ID FDO2012A123
3 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
3223551K bytes of flash memory at bootflash:.

Configuration register is 0x2102

Router#show license
Index 1 Feature: appxk9                        
        Period left: Not Activated
        Period Used: 0  minute  0  second 
        License Type: EvalRightToUse
        License State: Active, Not in Use, EULA not accepted
        License Count: Non-Counted
        License Priority: None
Index 2 Feature: uck9                          
        Period left: Not Activated
        Period Used: 0  minute  0  second 
        License Type: EvalRightToUse
        License State: Active, Not in Use, EULA not accepted
        License Count: Non-Counted
        License Priority: None
Index 3 Feature: securityk9                    
        Period left: Not Activated
        Period Used: 0  minute  0  second 
        License Type: EvalRightToUse
        License State: Active, Not in Use, EULA not accepted
        License Count: Non-Counted
        License Priority: None
Index 4 Feature: ipbasek9                      
        Period left: Life time
         
Router#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#license boot ?
  level  which level to boot
  suite  which suite to boot

Router(config)#license boot level ?
  appxk9      Appx License Level
  securityk9  Security License Level
  uck9        Unified Communication License Level

Router(config)#license boot level appxk9 ?
  disable  disable the group
  <cr>

Router(config)#license boot level appxk9
PLEASE  READ THE  FOLLOWING TERMS  CAREFULLY. INSTALLING THE LICENSE OR
LICENSE  KEY  PROVIDED FOR  ANY CISCO  PRODUCT  FEATURE  OR  USING SUCH
PRODUCT  FEATURE  CONSTITUTES  YOUR  FULL ACCEPTANCE  OF  THE FOLLOWING
TERMS. YOU MUST NOT PROCEED FURTHER IF YOU ARE NOT WILLING TO  BE BOUND
BY ALL THE TERMS SET FORTH HEREIN.

Use of this product feature requires  an additional license from Cisco,
together with an additional  payment.  You may use this product feature
on an evaluation basis, without payment to Cisco, for 60 days. Your use
of the  product,  including  during the 60 day  evaluation  period,  is
subject to the Cisco end user license agreement
http://www.cisco.com/en/US/docs/general/warranty/English/EU1KEN_.html
If you use the product feature beyond the 60 day evaluation period, you
must submit the appropriate payment to Cisco for the license. After the
60 day  evaluation  period,  your  use of the  product  feature will be
governed  solely by the Cisco  end user license agreement (link above),
together  with any supplements  relating to such product  feature.  The
above  applies  even if the evaluation  license  is  not  automatically
terminated  and you do  not receive any notice of the expiration of the
evaluation  period.  It is your  responsibility  to  determine when the
evaluation  period is complete and you are required to make  payment to
Cisco for your use of the product feature beyond the evaluation period.

Your  acceptance  of  this agreement  for the software  features on one
product  shall be deemed  your  acceptance  with  respect  to all  such
software  on all Cisco  products  you purchase  which includes the same
software.  (The foregoing  notwithstanding, you must purchase a license
for each software  feature you use past the 60 days evaluation  period,
so  that  if you enable a software  feature on  1000  devices, you must
purchase 1000 licenses for use past  the 60 day evaluation period.)   

Activation  of the  software command line interface will be evidence of
your acceptance of this agreement.


ACCEPT? (yes/[no]): yes

% use 'write' command to make license boot config take effect on next boot.

Router(config)#end
Router#write memory
Building configuration...

Router#show license
Index 1 Feature: appxk9                        
    Period left: 8  weeks 4  days
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse

    License State: Active, Not in Use, EULA accepted
    License Count: Non-Counted
    License Priority: Low
Index 2 Feature: uck9                          
    Period left: Not Activated
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 3 Feature: securityk9                    
    Period left: Not Activated
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 4 Feature: ipbasek9                      
    Period left: Life time
    License Type: Permanent
    License State: Active, In Use
    License Count: Non-Counted
    License Priority: Medium
Index 5 Feature: FoundationSuiteK9             
    Period left: Not Activated
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 6 Feature: AdvUCSuiteK9                  
    Period left: Not Activated
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 7 Feature: cme-srst                      
    Period left: Not Activated
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: 0/0  (In-use/Violation)
    License Priority: None
Index 8 Feature: hseck9                        
Index 9 Feature: throughput                    
    Period left: Not Activated
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 10 Feature: internal_service


Router#reload
Proceed with reload? [confirm]

*Dec  3 06:46:41.434 UTC: %SYS-5-RELOAD: Reload requested by console. Reload Reason: Reload Command.Dec  3 06:46:56.474 R0/0: %PMAN-5-EXITACTION: Process manager is exiting: process exit with reload chassis code

Initializing Hardware ..


<OUTPUT TRUNCATED>


Cisco IOS XE Software, Version 03.13.06a.S - Extended Support Release
Cisco IOS Software, ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.4(3)S6a, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2016 by Cisco Systems, Inc.
Compiled Tue 27-Sep-16 21:02 by mcpre


<OUTPUT TRUNCATED>


Technology Package License Information:

-----------------------------------------------------------------
Technology    Technology-package           Technology-package
              Current       Type           Next reboot 
------------------------------------------------------------------
appx             appxk9           EvalRightToUse   appxk9
uc               None             None             None
security         None             None             None
ipbase           ipbasek9         Permanent        ipbasek9

cisco ISR4331/K9 (1RU) processor with 1686708K/6147K bytes of memory.
Processor board ID FDO2012A123
3 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
3223551K bytes of flash memory at bootflash:.

Configuration register is 0x2102

Router#show license
Index 1 Feature: appxk9                        
    Period left: 8  weeks 4  days
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse
    License State: Active, In Use
    License Count: Non-Counted
    License Priority: Low

Index 2 Feature: uck9                          
    Period left: Not Activated
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 3 Feature: securityk9                    
    Period left: Not Activated
    Period Used: 0  minute  0  second 
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 4 Feature: ipbasek9                     
    Period left: Life time
    License Type: Permanent
    License State: Active, In Use
    License Count: Non-Counted
    License Priority: Medium
Index 5 Feature: FoundationSuiteK9            
    Period left: Not Activated
    Period Used: 0  minute  0  second
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 6 Feature: AdvUCSuiteK9                 
    Period left: Not Activated
    Period Used: 0  minute  0  second
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 7 Feature: cme-srst                     
    Period left: Not Activated
    Period Used: 0  minute  0  second
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: 0/0  (In-use/Violation)
    License Priority: None
Index 8 Feature: hseck9                       
Index 9 Feature: throughput                   
    Period left: Not Activated
    Period Used: 0  minute  0  second
    License Type: EvalRightToUse
    License State: Active, Not in Use, EULA not accepted
    License Count: Non-Counted
    License Priority: None
Index 10 Feature: internal_service

Monday, January 9, 2017

Password Recovery on a Cisco 3650 Catalyst Switch

I had to reconfigure some used Cisco 3650 switches from a previous deployment but wasn't able to login using known passwords so I had to perform a password recovery. I've been doing password recovery on Cisco 3560 switch which is identical on other switch platforms, but the password recovery for a Cisco 3650 is a bit different. The CONSOLE port is found at the back and it's the top most port (look at LED arrow pointing upward).


The MODE button is found in front and it's a small black button beside the Cisco logo.


Booting...Initializing RAM +++++++@@@@@@@@...++++++++++++++++++++++++++++++++@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@done.
Memory Test Pass!

Base ethernet MAC Address: f4:4e:05:57:f1:23

Interface GE 0 link down***ERROR: PHY link is down      // WAIT FOR SYST AND ACTV LED TO BECOME AMBER BEFORE RELEASING MODE BUTTON

The system has been interrupted prior to initializing some
filesystems and loading the operating system software.
Console will be reset to 9600 baud rate, need to change terminal setting first.
The following commands will initialize the remaining filesystems,
and finish loading the operating system software:

    flash_init
    boot

switch: flash_init
Initializing Flash...

flashfs[7]: 0 files, 1 directories
flashfs[7]: 0 orphaned files, 0 orphaned directories
flashfs[7]: Total bytes: 6784000
flashfs[7]: Bytes used: 1024
flashfs[7]: Bytes available: 6782976
flashfs[7]: flashfs fsck took 2 seconds....done Initializing Flash.

switch: SWITCH_IGNORE_STARTUP_CFG=1     // BYPASS STARTUP-CONFIG IN NVRAM

switch: boot flash:packages.conf
Getting rest of image
Reading full image into memory....done
Reading full base package into memory...: done = 79121160
Nova Bundle Image
--------------------------------------
Kernel Address    : 0x6042f350
Kernel Size       : 0x402ecf/4206287
Initramfs Address : 0x60832220
Initramfs Size    : 0xdb98e6/14391526
Compression Format: .mzip

Bootable image at @ ram:0x6042f350
Bootable image segment 0 address range [0x81100000, 0x82110000] is in range [0x80180000, 0x90000000].
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@boot_system: 377
Loading Linux kernel with entry point 0x81653a10 ...Bootloader: Done loading app on core_mask: 0xf

### Launching Linux Kernel (flags = 0x5)

All packages are Digitally Signed
Starting System Services

Dec 8 02:21:06 %PLATFORM_MGR-1-PLATMGR_INIT_FAIL: Platform Manager: Failed to set system LEDs after POST.

              Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

           cisco Systems, Inc.
           170 West Tasman Drive
           San Jose, California 95134-1706



Cisco IOS Software, IOS-XE Software, Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M), Version 03.03.03SE RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2014 by Cisco Systems, Inc.
Compiled Sun 27-Apr-14 18:33 by prod_rel_team

Cisco IOS-XE software, Copyright (c) 2005-2014 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.
(http://www.gnu.org/licenses/gpl-2.0.html) For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


FIPS: Flash Key Check : Begin
FIPS: Flash Key Check : End, Not Found,FIPS Mode Not Enabled

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco WS-C3650-24PS (MIPS) processor with 4194304K bytes of physical memory.
Processor board ID FDO1837EABC
2048K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
257008K bytes of Crash Files at crashinfo:.
1550272K bytes of Flash at flash:.
0K bytes of Dummy USB Flash at usbflash0:.
0K bytes of  at webui:.

Base Ethernet MAC Address          : f4:4e:05:57:f1:823
Motherboard Assembly Number        : 73-15128-05
Motherboard Serial Number          : FDO18370DEF
Model Revision Number              : D0
Motherboard Revision Number        : A0
Model Number                       : WS-C3650-24PS
System Serial Number               : FDO1837EABC


         --- System Configuration Dialog ---

Enable secret warning
----------------------------------
In order to access the device manager, an enable secret is required
If you enter the initial configuration dialog, you will be prompted for the enable secret
If you choose not to enter the intial configuration dialog, or if you exit setup without setting the enable secret,
please set an enable secret using the following CLI in configuration mode-
enable secret 0 <cleartext password>
----------------------------------
Would you like to enter the initial configuration dialog? [yes/no]: no


Press RETURN to get started!


*Dec  8 02:22:12.388: %SPANTREE-5-EXTENDED_SYSID: Extended SysId enabled for type vlan
*Dec  8 02:22:14.285: Registering wireless registries required for roaming

*Dec  8 02:22:14.617: %LINK-3-UPDOWN: Interface GigabitEthernet0/0, changed state to down
*Dec  8 02:22:14.617: %LINK-3-UPDOWN: Interface LIIN0, changed state to up
*Dec  8 02:22:14.619: %NGWC_PLATFORM_FEP-6-FRU_PS_OIR: Switch 1: FRU power supply A inserted
*Dec  8 02:21:32.078: *%INIT-7-SWITCH_BOOTING: 1 wcm:  Switch booting...
*Dec  8 02:22:15.618: %LINEPROT% Generating 1024 bit RSA keys, keys will be non-exportable...O-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to down
*Dec  8 02:22:15.618: %LINEPROTO-5-UPDOWN: Line protocol on Interface LIIN0, changed state to up
*Dec  8 02:22:16.507: %MGMTINFRA-3-CFG_PUSH: 1 eicored:  Config push failed.please check wcm provider.
*Dec  8 02:22:16.507: %MGMTINFRA-3-CFG_PUSH: 1 eicored:  Config push failed (rc=10000) for (wcm) on attributes [{ schedulerEnabled@1 : 10000, rtTimeout@1 : 10000, frameBurst@1 : 10000 }, { schedulerEnabled@1 : 10000, rtTimeout@
[OK] (elapsed time was 1 seconds)
1 : 10000, frameBurst@1 : 10000 }]
*Dec  8 02:22:16.893: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to down
*Dec  8 02:22:22.669: %SYS-6-STARTUP_CONFIG_IGNORED: System startup configuration is ignored based on the configuration register setting.
*Dec  8 02:22:26.454: %STACKMGR-6-ACTIVE_READY: 1 stack-mgr:  Active switch 1 is ready. System has been configured

*Dec  8 02:22:26.656: %SYS-5-RESTART: System restarted --
Cisco IOS Software, IOS-XE Software, Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M), Version 03.03.03SE RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2014 by Cisco Systems, Inc.
Compiled Sun 27-Apr-14 18:33 by prod_rel_team
*Dec  8 02:22:26.681: %AUTHMGR_SPI-6-START: Auth Manager SPI server started
*Dec  8 02:22:29.100: %LINK-5-CHANGED: Interface Vlan1, changed state to administratively down
*Dec  8 02:22:33.460: %SSH-5-ENABLED: SSH 1.99 has been enabled
*Dec  8 02:22:33.511: %PKI-6-AUTOSAVE: Running configuration saved to NVRAM
Switch>enable
Switch#copy startup-config running-config      // LOAD THE START-UP CONFIG FROM NVRAM
Destination filename [running-config]?
% Generating 1024 bit RSA keys, keys will be non-exportable...
[OK] (elapsed time was 1 seconds)
*Dec  8 04:12:14.228: %SSH-5-ENABLED: SSH 1.99 has been enabled
*Dec  8 04:12:14.271: %PKI-4-NOAUTOSAVE: Configuration was modified.  Issue "write memory" to save new certificate
*Dec  8 04:12:20.062: %AAAA-4-NOSERVER: Warning: Server 89.1.2.8 is not defined.
*Dec  8 04:12:20.063: %AAAA-4-NOSERVER: Warning: Server 66.5.3.8 is not defined.
*Dec  8 04:12:20.063: %AAAA-4-NOSERVER: Warning: Server 66.1.3.9 is not defined.
 Warning: The cli will be deprecated soon
 'tacacs-server host 89.1.2.8'       // STARTUP-CONFIG HAS TACACS CONFIGURED
 Please move to 'tacacs server <name>' CLI
 Warning: The cli will be deprecated soon
 'tacacs-server host 66.5.3.9'
 Please move to 'tacacs server <name>' CLI
 Warning: The cli will be deprecated soon
 'tacacs-server host 66.5.3.8'
 Please move to 'tacacs server <name>' CLI
9523 bytes copied in 10.430 secs (913 bytes/sec)
sw02#     // THE HOSTNAME WAS ALSO LOADED
*Dec  8 04:12:20.096: % Multiple self signed certificates in config
    certificate for trust point TP-self-signed-1212499775 ignored
*Dec  8 04:12:20.382: %PKI-4-NOAUTOSAVE: Configuration was modified.  Issue "write memory" to save new certificate        // SAVE AFTER YOU RE-CONFIGURE THE NEW PASSWORDS, ISSUE THE reload COMMAND AND HOLD THE MODE BUTTON AGAIN
sw02#
sw02#delete vlan.dat        // AT THIS POINT YOU CAN EITHER RE-CONFIGURE THE ENABLE, LOCAL USERNAME AND VTY PASSWORDS OR COMPLETELY WIPE OUT THE SWITCH USING THE delete vlan.dat AND write erase COMMANDS (then do a reload).
Delete filename [vlan.dat]?
Delete flash:/vlan.dat? [confirm]
sw02#write erase
Erasing the nvram filesystem will remove all configuration files! Continue? [confirm]
[OK]
Erase of nvram: complete
sw02#reload     // HOLD THE MODE BUTTON AGAIN
*Dec  8 04:17:00.314: %SYS-7-NV_BLOCK_INIT: Initialized the geometry of nvram

System configuration has been modified. Save? [yes/no]: no     // TYPE yes IF YOU RE-CONFIGURED PASSWORDS; TYPE no IF YOU WANT A CLEAN CONFIG
Reload command is being issued on Active unit, this will reload the whole stack
Proceed with reload? [confirm]
*Dec  8 04:18:11.797: %SYS-5-RELOAD: Reload requested by console. Reload Reason: Reload command.
*Dec  8 04:18:12.499: %STACKMGR-1-RELOAD_REQUEST: 1 stack-mgr:  Received reload request for all switches, reason Reload command
*Dec  8 04:18:12.500: %STACKMGR-1-RELOAD: 1 stack-mgr:  Reloading due to reason Reload command
*Dec  8 04:18:13.001: %IOSXE-3-PLATFORM: 1 process sysmgr: Reset/Reload requested by [stack-manager].
<Thu Dec  8 04:18:13 2016> Message from sysmgr: Reason Code:[3] Reset Reason:Reset/Reload requested by [stack-manager]. [Reload command]
umount: /proc/fs/nfsd: not mounted
Unmounting ng3k filesystems...
Unmounted /dev/sda3...
Warning! - some ng3k filesystems may not have unmounted cleanly...
Please stand by while rebooting the system...
Restarting system.


<OUTPUT TRUNCATED>


Booting...Initializing RAM +++++++@@@@@@@@...++++++++++++++++++++++++++++++++
Base ethernet MAC Address: f4:4e:05:51:a9:80

Interface GE 0 link down***ERROR: PHY link is down     // WAIT FOR SYST AND ACTV LED TO BECOME AMBER BEFORE RELEASING MODE BUTTON
The system has been interrupted prior to initializing some
filesystems and loading the operating system software.
Console will be reset to 9600 baud rate, need to change terminal setting first.
The following commands will initialize the remaining filesystems,
and finish loading the operating system software:

    flash_init      // SKIP THE flash_init and boot COMMANDS
    boot

switch: SWITCH_IGNORE_STARTUP_CFG=0      // INSTRUCTS THE SWITCH TO READ/LOAD THE STARTUP-CONFIG

switch: boot flash:packages.conf
Getting rest of image
Reading full image into memory....done
Reading full base package into memory...: done = 79121160
Nova Bundle Image
--------------------------------------
Kernel Address    : 0x6042d350
Kernel Size       : 0x402ecf/4206287
Initramfs Address : 0x60830220
Initramfs Size    : 0xdb98e6/14391526
Compression Format: .mzip

Bootable image at @ ram:0x6042d350
Bootable image segment 0 address range [0x81100000, 0x82110000] is in range [0x80180000, 0x90000000].
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@boot_system: 377
Loading Linux kernel with entry point 0x81653a10 ...
Bootloader: Done loading app on core_mask: 0xf

### Launching Linux Kernel (flags = 0x5)

All packages are Digitally Signed
Starting System Services

Dec 8 04:22:53 %PLATFORM_MGR-1-PLATMGR_INIT_FAIL: Platform Manager: Failed to set system LEDs after POST.

              Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

           cisco Systems, Inc.
           170 West Tasman Drive
           San Jose, California 95134-1706



Cisco IOS Software, IOS-XE Software, Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M), Version 03.03.03SE RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2014 by Cisco Systems, Inc.
Compiled Sun 27-Apr-14 18:33 by prod_rel_team

Cisco IOS-XE software, Copyright (c) 2005-2014 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.
(http://www.gnu.org/licenses/gpl-2.0.html) For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


FIPS: Flash Key Check : Begin
FIPS: Flash Key Check : End, Not Found,FIPS Mode Not Enabled

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco WS-C3650-24PS (MIPS) processor with 4194304K bytes of physical memory.
Processor board ID FDO1837EABC
2048K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
257008K bytes of Crash Files at crashinfo:.
1550272K bytes of Flash at flash:.
0K bytes of Dummy USB Flash at usbflash0:.
0K bytes of  at webui:.

Base Ethernet MAC Address          : f4:4e:05:51:a1:23
Motherboard Assembly Number        : 73-15128-05
Motherboard Serial Number          : FDO18370DEF
Model Revision Number              : D0
Motherboard Revision Number        : A0
Model Number                       : WS-C3650-24PS
System Serial Number               : FDO1837EABC



         --- System Configuration Dialog ---

Enable secret warning
----------------------------------
In order to access the device manager, an enable secret is required
If you enter the initial configuration dialog, you will be prompted for the enable secret
If you choose not to enter the intial configuration dialog, or if you exit setup without setting the enable secret,
please set an enable secret using the following CLI in configuration mode-
enable secret 0 <cleartext password>
----------------------------------
Would you like to enter the initial configuration dialog? [yes/no]: no

Would you like to terminate autoinstall? [yes]:


Press RETURN to get started!


Switch>enable
Switch#configure terminal
Switch(config)#no manual ?     // no manual boot COMMAND IS UNAVAILABLE
% Unrecognized command
Switch(config)#no m?    
mab       mac     macro    map-class
map-list  memory  monitor 

Switch(config)#end
Switch#no m?


I chose to completely wipe out the switch, re-configure it and tested again by rebooting and the startup-config stored in NVRAM remained intact.

Sunday, January 1, 2017

Installing PVDM4-64 and NIM-2FXS on a Cisco 4331 Router

I went to the Land of Smiles, Bangkok Thailand, the second time around and was hired to setup an office IT network that uses a Cisco 4331 router. I took a side trip after it was done and visited Wat Pho, which is one of the many Buddhist temples in Bangkok. This temple is known as the birthplace of the traditional Thai massage and it houses a huge reclining Buddha. Thai cuisine is amazingly good! I had Phat Thai (or Pad Thai), which is their famous stir-fried rice noodles, and Green Chicken Curry.





The Cisco 4331 is Cisco's latest ISR router in the 4000 series. The 4000 series routers are said to be 4-10 times faster (and cheaper) compared to the ISR G2 series routers. Here's the initial bootup process and startup-config. It now uses the IOS-XE which is Cisco classic IOS that runs on a Linux platform. There's also no need to issue a write erase and reload commands just to remove the default configurations such as the one-time username "cisco", ip http access-class 23 (used for HTTP/CCP) and transport input none (used on VTY lines), which locked me out of a router a few times.


Initializing Hardware ...

System integrity status: 00000610

Rom image verified correctly


System Bootstrap, Version 15.4(3r)S5, RELEASE SOFTWARE
Copyright (c) 1994-2015  by cisco Systems, Inc.

Current image running: Boot ROM0

Last reset cause: PowerOn

Cisco ISR4331/K9 platform with 4194304 Kbytes of main memory


no valid BOOT image found

Final autoboot attempt from default boot device...

Warning: filesystem is not clean

Warning: filesystem is not clean

File size is 0x1c0cd400

Located isr4300-universalk9.03.16.02.S.155-3.S2-ext.SPA.bin

Image size 470602752 inode num 12, bks cnt 114894 blk size 8*512

###############################################################################

Boot image size = 470602752 (0x1c0cd400) bytes

Package header rev 1 structure detected

Calculating SHA-1 hash...done

validate_package: SHA-1 hash:

    calculated 964c232a:7ae904ce:2722d662:5a878b27:c84ad6da

    expected   964c232a:7ae904ce:2722d662:5a878b27:c84ad6da

RSA Signed RELEASE Image Signature Verification Successful.
Package Load Test Latency : 8547 msec
Image validated
%IOSXEBOOT-4-FILESYS_ERRORS_CORRECTED: (rp/0): bootflash 1 contained errors which were auto-corrected.
%IOSXEBOOT-4-FILESYS_ERRORS_CORRECTED: (rp/0): bootflash 5 contained errors which were auto-corrected.
%IOSXEBOOT-4-FILESYS_ERRORS_CORRECTED: (rp/0): bootflash 6 contained errors which were auto-corrected.
%IOSXEBOOT-4-FILESYS_ERRORS_CORRECTED: (rp/0): bootflash 7 contained errors which were auto-corrected.
%IOSXEBOOT-4-FILESYS_ERRORS_CORRECTED: (rp/0): bootflash 8 contained errors which were auto-corrected.
%IOSXEBOOT-4-FILESYS_ERRORS_CORRECTED: (rp/0): bootflash 9 contained errors which were auto-corrected.
%IOSXEBOOT-4-FILESYS_ERRORS_CORRECTED: (rp/0): bootflash 10 contained errors which were auto-corrected.
%IOSXEBOOT-4-BOOT_SRC: (rp/0): mounting /boot/super.iso to /tmp/sw/isos

              Restricted Rights Legend

Use, duplication, or disclosure by the Government is
subject to restrictions as set forth in subparagraph
(c) of the Commercial Computer Software - Restricted
Rights clause at FAR sec. 52.227-19 and subparagraph
(c) (1) (ii) of the Rights in Technical Data and Computer
Software clause at DFARS sec. 252.227-7013.

           cisco Systems, Inc.
           170 West Tasman Drive
           San Jose, California 95134-1706


Cisco IOS Software, ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.5(3)S2, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2016 by Cisco Systems, Inc.
Compiled Thu 11-Feb-16 08:58 by mcpre


Cisco IOS-XE software, Copyright (c) 2005-2016 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.  For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.

% failed to initialize nvram

This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

cisco ISR4331/K9 (1RU) processor with 1655569K/6147K bytes of memory.
Processor board ID FDO2012A123
3 Gigabit Ethernet interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
3223551K bytes of flash memory at bootflash:.

         --- System Configuration Dialog ---

Would you like to enter the initial configuration dialog? [yes/no]: no


Press RETURN to get started!


*Nov 29 05:16:16.090: %SMART_LIC-6-AGENT_READY: Smart Agent for Licensing is initialized
*Nov 29 05:16:17.867: %IOS_LICENSE_IMAGE_APPLICATION-6-LICENSE_LEVEL: Module name = esg Next reboot level = ipbasek9 and License = ipbasek9
*Nov 29 05:16:19.041: %ISR_THROUGHPUT-6-LEVEL: Throughput level has been set to 100000 kbps
*Nov 29 05:16:20.019: %IOSXE_RP_NV-3-NV_ACCESS_FAIL: Initial read of NVRAM contents failed
*Nov 29 05:16:23.500: dev_pluggable_optics_selftest attribute table internally inconsistent @ 0x125
*Nov 29 05:16:27.288: %SPANTREE-5-EXTENDED_SYSID:
Router>Extended SysId enabled for type vlan
*Nov 29 05:16:28.261: %LINK-3-UPDOWN: Interface Lsmpi0, changed state to up
*Nov 29 05:16:28.262: %LINK-3-UPDOWN: Interface EOBC0, changed state to up
*Nov 29 05:16:28.262: %LINK-3-UPDOWN: Interface GigabitEthernet0, changed state to down
*Nov 29 05:16:28.270: %LINK-3-UPDOWN: Interface LIIN0, changed state to up
*Nov 29 05:16:29.596: %IOSXE_MGMTVRF-6-CREATE_SUCCESS_INFO: Management vrf Mgmt-intf created with ID 1, ipv4 table-id 0x1, ipv6 table-id 0x1E000001
*Nov 29 05:16:29.647: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, changed state to down
*Nov 29 05:16:29.648: %LINEPROTO-5-UPDOWN: Line protocol on Interface Lsmpi0, changed state to up
*Nov 29 05:16:29.648: %LINEPROTO-5-UPDOWN: Line protocol on Interface EOBC0, changed state to up
*Nov 29 05:16:29.648: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0, changed state to down
*Nov 29 05:16:29.648: %LINEPROTO-5-UPDOWN: Line protocol on Interface LIIN0, changed state to up
*Nov 29 05:16:21.218: %CMLIB-6-THROUGHPUT_VALUE: SIP1: cmand:  Throughput license found, throughput set to 100000 kbps
*Nov 29 05:16:30.959: %IOSXE_OIR-6-REMSPA: SPA removed from subslot 0/0, interfaces disabled
*Nov 29 05:16:30.959: %IOSXE_OIR-6-REMSPA: SPA removed from subslot 0/1, interfaces disabled
*Nov 29 05:16:30.963: %SPA_OIR-6-OFFLINECARD: SPA (ISR4331-3x1GE) offline in subslot 0/0
*Nov 29 05:16:30.964: %SPA_OIR-6-OFFLINECARD: SPA (NIM-2FXS) offline in subslot 0/1
*Nov 29 05:16:30.968: %IOSXE_OIR-6-INSCARD: Card (fp) inserted in slot F0
*Nov 29 05:16:30.968: %IOSXE_OIR-6-ONLINECARD: Card (fp) online in slot F0
*Nov 29 05:16:30.969: %IOSXE_OIR-6-INSCARD: Card (cc) inserted in slot 0
*Nov 29 05:16:30.969: %IOSXE_OIR-6-ONLINECARD: Card (cc) online in slot 0
*Nov 29 05:16:30.973: %IOSXE_OIR-6-INSCARD: Card (cc) inserted in slot 1
*Nov 29 05:16:31.003: %IOSXE_OIR-6-INSSPA: SPA inserted in subslot 0/0
*Nov 29 05:16:31.007: %IOSXE_OIR-6-INSSPA: SPA inserted in subslot 0/1
*Nov 29 05:16:31.043: %SPA-3-ENVMON_NOT_MONITORED: SIP1: iomd:  Environmental monitoring is not enabled for ISR4331-3x1GE[0/0]
*Nov 29 05:16:36.423: %SPA_OIR-6-ONLINECARD: SPA (ISR4331-3x1GE) online in subslot 0/0
*Nov 29 05:16:38.370: %LINK-3-UPDOWN: Interface GigabitEthernet0/0/0, changed state to down
*Nov 29 05:16:38.415: %LINK-3-UPDOWN: Interface GigabitEthernet0/0/1, changed state to down
*Nov 29 05:16:38.419: %LINK-3-UPDOWN: Interface GigabitEthernet0/0/2, changed state to down
*Nov 29 05:17:00.882: new extended attributes received from iomd(slot 0 bay 1 board 0)
*Nov 29 05:17:01.371: %SPA_OIR-6-ONLINECARD: SPA (NIM-2FXS) online in subslot 0/1
*Nov 29 05:17:01.372: %IOSXE_OIR-6-SOFT_RELOADSPA: SPA(NIM-2FXS) reloaded on subslot 0/1
*Nov 29 05:17:01.373: %SPA_OIR-6-OFFLINECARD: SPA (NIM-2FXS) offline in subslot 0/1
*Nov 29 05:17:35.853: %SPA_OIR-6-ONLINECARD: SPA (NIM-2FXS) online in subslot 0/1
*Nov 29 05:17:39.700: %LINK-3-UPDOWN: Interface Service-Engine0/1/0, changed state to up
*Nov 29 05:17:40.700: %LINEPROTO-5-UPDOWN: Line protocol on Interface Service-Engine0/1/0, changed state to up
*Nov 29 05:23:13.895: %LINK-5-CHANGED: Interface GigabitEthernet0/0/0, changed state to administratively down
*Nov 29 05:23:13.896: %LINK-5-CHANGED: Interface GigabitEthernet0/0/1, changed state to administratively down
*Nov 29 05:23:13.896: %LINK-5-CHANGED: Interface GigabitEthernet0/0/2, changed state to administratively down
*Nov 29 05:23:13.897: %LINK-5-CHANGED: Interface GigabitEthernet0, changed state to administratively down
*Nov 29 05:23:13.933: %LINK-5-CHANGED: Interface Vlan1, changed state to administratively down
*Nov 29 05:23:20.117: %SYS-5-RESTART: System restarted --
Cisco IOS Software, ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.5(3)S2, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2016 by Cisco Systems, Inc.
Compiled Thu 11-Feb-16 08:58 by mcpre
Router>enable
Router#
Router#show version
Cisco IOS XE Software, Version 03.16.02.S - Extended Support Release
Cisco IOS Software, ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 15.5(3)S2, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2016 by Cisco Systems, Inc.
Compiled Thu 11-Feb-16 08:58 by mcpre


Cisco IOS-XE software, Copyright (c) 2005-2016 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.  For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


ROM: IOS-XE ROMMON

Router uptime is 7 minutes
Uptime for this control processor is 8 minutes
System returned to ROM by reload at 03:53:06 UTC Thu Mar 24 2016
System image file is "bootflash:/isr4300-universalk9.03.16.02.S.155-3.S2-ext.SPA.bin"
Last reload reason: PowerOn


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.

     
Suite License Information for Module:'esg'

--------------------------------------------------------------------------------
Suite                 Suite Current         Type           Suite Next reboot   
--------------------------------------------------------------------------------
FoundationSuiteK9     None                  None           None                
securityk9
appxk9
AdvUCSuiteK9          None                  None           None                
uck9
cme-srst
cube


Technology Package License Information:

-----------------------------------------------------------------
Technology    Technology-package           Technology-package
 Current         Type           Next reboot
------------------------------------------------------------------
appxk9           None             None             None
uck9             None             None             None
securityk9       None             None             None
ipbase           ipbasek9         Permanent        ipbasek9

cisco ISR4331/K9 (1RU) processor with 1655569K/6147K bytes of memory.
Processor board ID FDO2012A123
3 Gigabit Ethernet interfaces
2 Voice FXS interfaces
32768K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
3223551K bytes of flash memory at bootflash:.

Configuration register is 0x2102


Router#show run
Building configuration...


Current configuration : 1293 bytes
!
! Last configuration change at 05:23:22 UTC Tue Nov 29 2016
!
version 15.5
service timestamps debug datetime msec
service timestamps log datetime msec
no platform punt-keepalive disable-kernel-core
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
vrf definition Mgmt-intf
 !
 address-family ipv4
 exit-address-family
 !
 address-family ipv6
 exit-address-family
!
!
no aaa new-model
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
!
subscriber templating
multilink bundle-name authenticated
!
!
!
!
license udi pid ISR4331/K9 sn FDO20090ABC
!
spanning-tree extend system-id
!
!
redundancy
 mode none
!
!
vlan internal allocation policy ascending
!
!
!
!
!
!
interface GigabitEthernet0/0/0
 no ip address
 shutdown
 negotiation auto
!
interface GigabitEthernet0/0/1
 no ip address
 shutdown
 negotiation auto
!
interface GigabitEthernet0/0/2
 no ip address
 shutdown
 negotiation auto
!
interface Service-Engine0/1/0
 no ip address
!
interface GigabitEthernet0
 vrf forwarding Mgmt-intf
 no ip address
 shutdown
 negotiation auto
!
interface Vlan1
 no ip address
 shutdown
!
ip forward-protocol nd
no ip http server
no ip http secure-server
ip tftp source-interface GigabitEthernet0
!
!
!
!
!
!
control-plane
!
!
line con 0
 stopbits 1
 line aux 0
 stopbits 1
line vty 0 4
 login
!
!
end


These are the pictures of the front and back panels.



There's a dedicated out-of-band management port GE0 in front. It uses the default forwarding VRF Mgmt-intf, that can't be changed.


The serial number pull-out label is found at the back which is a bit long and foldable.


The Cisco 4000 uses a fourth generation Network Interface Module (NIM) cards, which is long and NOT supported on ISR G2 routers (such as 2900 and 3900). Below is a NIM-2FXS card that I've installed.


To install a PVDM4-64 module, you'll need to remove 6 small screws: 4 on top and 2 on the sides.



The Cisco 4331 router has only 1 PVDM slot which is found between the 3 heat sinks on the left of the picture.



Router#show inventory
NAME: "Chassis", DESCR: "Cisco ISR4331 Chassis"
PID: ISR4331/K9        , VID: V02, SN: FDO2012AABC

NAME: "Power Supply Module 0", DESCR: "250W AC Power Supply for Cisco ISR 4330"
PID: PWR-4330-AC       , VID: V01, SN: DCA19501DEF

NAME: "Fan Tray", DESCR: "Cisco ISR4330 Fan Assembly"
PID: ACS-4330-FANASSY  , VID:    , SN:           

NAME: "module 0", DESCR: "Cisco ISR4331 Built-In NIM controller"
PID: ISR4331/K9        , VID:    , SN:           

NAME: "NIM subslot 0/1", DESCR: "NIM-2FXS Voice Analog Module"
PID: NIM-2FXS          , VID: V01, SN: FOC19494GHI
  

NAME: "PVDM subslot 0/4", DESCR: "PVDM4-64 Voice DSP Module"
PID: PVDM4-64          , VID: V02, SN: FOC20028JKL
 

NAME: "NIM subslot 0/0", DESCR: "Front Panel 3 ports Gigabitethernet Module"
PID: ISR4331-3x1GE     , VID: V01, SN: JAB09270MNO

NAME: "module 1", DESCR: "Cisco ISR4331 Built-In SM controller"
PID: ISR4331/K9        , VID:    , SN:           
         
NAME: "module R0", DESCR: "Cisco ISR4331 Route Processor"
PID: ISR4331/K9        , VID: V02, SN: FDO20090PQR

NAME: "module F0", DESCR: "Cisco ISR4331 Forwarding Processor"
PID: ISR4331/K9        , VID:    , SN: