Friday, September 8, 2023

Cisco Export Compliance Tool

The Cisco products, software, and technology (Cisco products) are subject to export controls under the laws and regulations of the United States (U.S.), European Union (EU) and other applicable countries’ export laws and regulations. Export, re-export, transfer, and use of Cisco products may require obtaining U.S. and local authorizations, permits, or licenses.

There's a free Cisco Export Compliance online tool to check the Export Control Classification Number (ECCN), Harmonized System (HS) and other info on various Cisco products. This is useful when dealing with a courrier or customs in other countries.

In the example, I tried to search for the Export Compliance codes for a Cisco 4331 ISR router.

Type Product ID: ISR4331/K9 > click Search (bottom page).


You can also download the result into an excel file (XLSX).




Thursday, August 3, 2023

Change Cisco Switch Stack Member Number

Here's a link in changing the interface name or renumber a Cisco stack member switch. There's a logical correlation between the switch number and the interface name, i.e. GigabitEthernet1/0/x belongs to Switch 1 and GigabitEthernet2/0/x belongs to Switch 2 and so on.

Issue a show switch command to verify the role and number of member switches in the stack. I used a Cisco 3650 switch but the command is similar in other Cisco Catalyst switch that supports stacking.

3650#show switch
Switch/Stack Mac Address : 188b.9db0.8888 - Local Mac Address
Mac persistency wait time: Indefinite
                                             H/W   Current
Switch#   Role    Mac Address     Priority Version  State
-------------------------------------------------------------------------------------
 1       Member   188b.9d0f.6666     13     V02     Ready                
 2       Standby  7c31.0ee7.7777     14     V05     Ready                
*3       Active   188b.9db0.8888     15     V02     Ready                


In this case, I wanted Switch 3 interfaces to be renumbered from Gi3/0/x to Gi1/0/x. Use the switch <CURRENT STACK NUMBER> renumber <NEW STACK NUMBER> privileged EXEC command.

3650#show interface status

Port         Name               Status       Vlan       Duplex  Speed Type
Gi1/0/1                         connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/2                         connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/3                         connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/4                         connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/5                         connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/6                         connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/7                         connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/8                         connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/9                         connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/10                        connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/11                        connected    1          a-full a-1000 10/100/1000BaseTX
Gi1/0/12                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/13                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/14                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/15                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/16                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/17                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/18                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/19                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/20                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/21                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/22                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/23                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/24                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/25                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/26                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/27                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/28                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/29                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/30                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/31                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/32                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/33                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/34                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/35                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/36                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/37                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/38                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/39                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/40                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/41                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/42                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/43                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/44                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/45                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/46                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/47                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/0/48                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi1/1/1                         notconnect   1            auto   auto unknown
Gi1/1/2                         notconnect   1            auto   auto unknown
Gi1/1/3                         notconnect   1            auto   auto unknown
Gi1/1/4                         notconnect   1            auto   auto unknown
Gi2/0/1                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/2                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/3                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/4                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/5                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/6                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/7                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/8                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/9                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/10                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/11                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/12                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/13                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/14                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/15                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/16                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/17                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/18                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/19                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/20                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/21                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/22                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/23                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/0/24                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi2/1/1                         notconnect   1            auto   auto unknown
Gi2/1/2                         notconnect   1            auto   auto unknown
Gi2/1/3                         notconnect   1            auto   auto unknown
Gi2/1/4                         notconnect   1            auto   auto unknown
Gi3/0/1                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/2                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/3                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/4                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/5                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/6                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/7                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/8                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/9                         notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/10                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/11                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/12                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/13                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/14                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/15                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/16                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/17                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/18                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/19                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/20                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/21                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/22                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/23                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/24                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/25                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/26                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/27                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/28                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/29                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/30                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/31                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/32                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/33                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/34                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/35                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/36                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/37                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/38                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/39                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/40                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/41                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/42                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/43                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/44                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/45                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/46                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/47                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/0/48                        notconnect   1            auto   auto 10/100/1000BaseTX
Gi3/1/1                         connected    trunk        full   1000 1000BaseSX SFP
Gi3/1/2                         connected    trunk        full   1000 1000BaseSX SFP
Gi3/1/3                         notconnect   1            auto   auto unknown
Gi3/1/4                         notconnect   1            auto   auto unknown


3650#switch ?           
  <1-9>  Switch Number
  clear  Reset the switch mode to N+1

3650#switch 1 ?
  priority  Set the priority of the specified switch
  renumber  Renumber the specified switch number
  role      Set the new switch mode of the Switch
  stack     Stack port enable or disable

3650#switch 1 renumber ?
  <1-9>  New number of the Switch

3650#switch 1 renumber 2
WARNING: Changing the switch number may result in a configuration change for that switch.  The interface configuration associated with the old switch number will remain as a provisioned configuration. New Switch Number will be effective after next reboot.. Do you want to continue?[y/n]? [yes]: yes

 

You need to reload the switch slot in order for the change to take effect.


3650#reload slot ?
  <1-9>  Slot number of RP or line card

3650#reload slot 1
Proceed with reload?[confirm]    // HIT ENTER
 

3650#terminal monitor
Sep  2 07:45:58.336:  Successfully sent switch reload message for switch num: 1 and reason Reload Slot Command
Sep  2 07:45:58.333: %STACKMGR-6-STACK_LINK_CHANGE: Switch 2 R0/0: stack_mgr: Stack port 2 on Switch 2 is down
Sep  2 07:45:58.336: %STACKMGR-4-SWITCH_REMOVED: Switch 2 R0/0: stack_mgr: Switch 1 has been removed from the stack.
Sep  2 07:45:58.338: %STACKMGR-6-STACK_LINK_CHANGE: Switch 3 R0/0: stack_mgr: Stack port 1 on Switch 3 is down
Sep  2 07:45:58.340: %STACKMGR-4-SWITCH_REMOVED: Switch 3 R0/0: stack_mgr: Switch 1 has been removed from the stack.
Sep  2 07:45:58.956: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/1: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.958: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/2: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.960: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/3: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.962: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/4: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.963: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/5: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.965: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/6: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.967: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/7: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.969: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/8: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.971: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/9: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.974: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/10: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:58.979: %ILPOWER-5-PD_ENTRY_REMOVAL: Interface GigabitEthernet1/0/11: power device entry removed. admin_state: 2, oper_state: 3
Sep  2 07:45:59.164: %HMANRP-5-CHASSIS_DOWN_EVENT: Chassis 1 gone DOWN!
Sep  2 07:46:00.353: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/1, changed state to down
Sep  2 07:46:00.394: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/2, changed state to down
Sep  2 07:46:00.418: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/3, changed state to down
Sep  2 07:46:00.420: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/4, changed state to down
Sep  2 07:46:00.435: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/5, changed state to down
Sep  2 07:46:00.503: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/6, changed state to down
Sep  2 07:46:00.516: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/7, changed state to down
Sep  2 07:46:00.529: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/8, changed state to down
Sep  2 07:46:00.543: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/9, changed state to down
Sep  2 07:46:00.555: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/10, changed state to down
Sep  2 07:46:00.646: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/11, changed state to down
Sep  2 07:46:00.660: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/12, changed state to down
Sep  2 07:46:00.665: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/13, changed state to down
Sep  2 07:46:00.670: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/14, changed state to down
Sep  2 07:46:00.674: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/15, changed state to down
Sep  2 07:46:00.679: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/16, changed state to down
Sep  2 07:46:00.683: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/17, changed state to down
Sep  2 07:46:00.688: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/18, changed state to down
Sep  2 07:46:00.693: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/19, changed state to down
Sep  2 07:46:00.696: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/20, changed state to down
Sep  2 07:46:00.724: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/21, changed state to down
Sep  2 07:46:00.725: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/22, changed state to down
Sep  2 07:46:00.726: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/23, changed state to down
Sep  2 07:46:00.734: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/24, changed state to down
Sep  2 07:46:00.749: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/25, changed state to down
Sep  2 07:46:00.749: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/26, changed state to down
Sep  2 07:46:00.750: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/27, changed state to down
Sep  2 07:46:00.762: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/28, changed state to down
Sep  2 07:46:00.763: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/29, changed state to down
Sep  2 07:46:00.763: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/30, changed state to down
Sep  2 07:46:00.769: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/31, changed state to down
Sep  2 07:46:00.772: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/32, changed state to down
Sep  2 07:46:00.778: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/33, changed state to down
Sep  2 07:46:00.811: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/34, changed state to down
Sep  2 07:46:00.819: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/35, changed state to down
Sep  2 07:46:00.826: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/36, changed state to down
Sep  2 07:46:00.830: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/37, changed state to down
Sep  2 07:46:00.835: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/38, changed state to down
Sep  2 07:46:00.841: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/39, changed state to down
Sep  2 07:46:00.847: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/40, changed state to down
Sep  2 07:46:00.852: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/41, changed state to down
Sep  2 07:46:00.858: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/42, changed state to down
Sep  2 07:46:00.864: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/43, changed state to down
Sep  2 07:46:00.869: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/44, changed state to down
Sep  2 07:46:00.894: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/45, changed state to down
Sep  2 07:46:00.905: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/46, changed state to down
Sep  2 07:46:00.909: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/47, changed state to down
Sep  2 07:46:00.913: %LINK-3-UPDOWN: Interface GigabitEthernet1/0/48, changed state to down
Sep  2 07:46:00.917: %LINK-3-UPDOWN: Interface GigabitEthernet1/1/1, changed state to down
Sep  2 07:46:00.921: %LINK-3-UPDOWN: Interface GigabitEthernet1/1/2, changed state to down
Sep  2 07:46:00.926: %LINK-3-UPDOWN: Interface GigabitEthernet1/1/3, changed state to down
Sep  2 07:46:00.930: %LINK-3-UPDOWN: Interface GigabitEthernet1/1/4, changed state to down
Sep  2 07:46:01.353: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/1, changed state to down
Sep  2 07:46:01.394: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/2, changed state to down
Sep  2 07:46:01.418: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/3, changed state to down
Sep  2 07:46:01.437: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/4, changed state to down
Sep  2 07:46:01.437: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/5, changed state to down
Sep  2 07:46:01.502: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/6, changed state to down
Sep  2 07:46:01.515: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/7, changed state to down
Sep  2 07:46:01.530: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/8, changed state to down
Sep  2 07:46:01.543: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/9, changed state to down
Sep  2 07:46:01.555: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/10, changed state to down
Sep  2 07:46:01.647: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/11, changed state to down
Sep  2 07:47:37.292: %HMANRP-6-HMAN_IOS_CHANNEL_INFO: HMAN-IOS channel event for switch 1: EMP_RELAY: Channel DOWN!


I had to temporarily create Switch 4 for flexibility in renumbering the rest of the switch stack numbers:

Original Switch 1 > renumber as Switch 2

Original Switch 2 > renumber as Switch 3

Original Switch 3 > renumber as Switch 1


3650##show switch
Switch/Stack Mac Address : 188b.9db0.8888 - Local Mac Address
Mac persistency wait time: Indefinite
                                             H/W   Current
Switch#   Role    Mac Address     Priority Version  State
-------------------------------------------------------------------------------------
*1       Active   188b.9db0.8888     15     V02     Ready               
 2       Member   188b.9d0f.6666     13     V02     Ready                
 3       Standby  7c31.0ee7.7777     12     V05     Ready                
 4       Member   0000.0000.0000     0      V02     Removed   


Saturday, July 1, 2023

Packet Capture in a Cisco 4000 ISR

I needed to perform a packet capture in our Cisco 4K Integrated Services Router (ISR) to troubleshoot a Session Initiation Protocol (SIP) problem. Here's a Cisco link for the monitor capture commands.

Below is a summary of the CLI commands applied. Majority of these commands are applied in the privileged EXEC mode (Router#).

ip access-list extended CAP-ACL
 permit ip 172.27.17.0 0.0.0.31 10.12.16.0 0.0.0.255
 permit ip 10.12.16.0 0.0.0.255 172.27.17.0 0.0.0.31

#monitor capture CAP access-list CAP-ACL
 

#monitor capture CAP interface GigabitEthernet0/0/0.41 both

#monitor capture CAP start

show monitor capture CAP buffer brief

show monitor capture CAP buffer detailed

#monitor capture CAP export tftp://<TFTP IP ADDRESS>/CAP.pcap

#monitor capture CAP stop

#monitor capture CAP clear

 

Configure an ACL to narrow down specific TCP/UDP port (or IP) and IP address.

4K#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
4K(config)#ip access-list extended CAP-ACL
4K(config-ext-nacl)#permit ip 172.27.17.0 0.0.0.31 10.12.16.0 0.0.0.255
4K(config-ext-nacl)#permit ip 10.12.16.0 0.0.0.255 172.27.17.0 0.0.0.31

Configure the packet capture arbitrary name, interface, ingress/egress direction and apply the ACL previously configured.

4K#monitor capture CAP access-list CAP-ACL
 

4K#monitor capture CAP interface GigabitEthernet0/0/0.41 both 

 

Start the packet capture. Issue the show monitor capture <NAME> command to view the summary of the configuration.

4K#monitor capture CAP start

4K#show monitor capture CAP

Status Information for Capture CAP
  Target Type:
   Interface: GigabitEthernet0/0/0.41, Direction: both
   Status : Active
  Filter Details:
   Access-list: CAP-ACL
  Buffer Details:
   Buffer Type: LINEAR (default)
   Buffer Size (in MB): 10
  Limit Details:
   Number of Packets to capture: 0 (no limit)
   Packet Capture duration: 0 (no limit)
   Packet Size to capture: 0 (no limit)
   Maximum number of packets to capture per second: 1000
   Packet sampling rate: 0 (no sampling)

 

Use the show monitor capture <NAME> buffer brief command to view traffic.

4K#show monitor capture CAP buffer brief
 -------------------------------------------------------------
 #   size   timestamp     source             destination   protocol
 -------------------------------------------------------------
   0 1046    0.000000   172.27.17.8     ->  10.12.16.5     TCP
   1   70    0.569022   172.27.17.8     ->  10.12.16.5     TCP
   2   70    0.577018   172.27.17.8     ->  10.12.16.5     TCP
   3 1050    4.057996   172.27.17.12    ->  10.12.16.5     TCP
   4   70    4.617024   172.27.17.12    ->  10.12.16.5     TCP
   5   70    4.623020   172.27.17.12    ->  10.12.16.5     TCP

<OUTPUT TRUNCATED>


You'll need Wireshark in order to view the detailed packet capture from the show monitor capture <NAME> buffer detailed command. You can export the .pcap file to an external TFTP/FTP server using the monitor capture CAP export command.

Make sure the TFTP server IP address is reachable. You can use the ip tftp source-interface <INTERFACE> command if you have multiple sub-interfaces using VRF.

4K(config)#ip tftp source-interface GigabitEthernet0/0/0.41

4K#show monitor capture CAP buffer detailed
 -------------------------------------------------------------
 #   size   timestamp     source             destination   protocol
 -------------------------------------------------------------
   0 1046    0.000000   172.27.17.8     ->  10.12.16.5     TCP
  0000:  682C7BD2 9A205061 BF3D7715 81006191   h,{.. Pa.=w...a.
  0010:  08004560 0404529F 00004006 AD48AC1B   ..E`..R...@..H..
  0020:  B0080A70 1019C71D 13C4EC3E 0B5E5DFB   ...p.......>.^].
  0030:  939C8018 0A510F25 00000101 080A0037   .....Q.%.......7

   1   70    0.569022   172.27.17.8     ->  10.12.16.5     TCP
  0000:  682C7BD2 9A205061 BF3D7715 81006191   h,{.. Pa.=w...a.
  0010:  08004560 003452AF 00004006 B108AC1B   ..E`.4R...@.....
  0020:  B0080A70 1019C71D 13C4EC3E 0F2E5DFB   ...p.......>..].
  0030:  94E58010 0A5185F9 00000101 080A0037   .....Q.........7

   2   70    0.577018   172.27.17.8     ->  10.12.16.5     TCP
  0000:  682C7BD2 9A205061 BF3D7715 81006191   h,{.. Pa.=w...a.
  0010:  08004560 003452B0 00004006 B107AC1B   ..E`.4R...@.....
  0020:  B0080A70 1019C71D 13C4EC3E 0F2E5DFB   ...p.......>..].
  0030:  977C8010 0A518360 00000101 080A0037   .|...Q.`.......7

4K#monitor capture CAP export tftp://172.27.5.3/CAP.pcap
!
Exported Successfully


Remove the packet capture and ACL once you're finished.

4K#monitor capture CAP clear

4K#monitor capture CAP stop
 

4K#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
4K(config)#no ip access-list extended CAP-ACL

 

Thursday, June 1, 2023

Cisco Network Convergence System (NCS) 540 Router

Here's a link regarding the Cisco NCS 540 series routers and a link for the hardware installation guide. 

The NCS 540 1RU router have the interfaces and power supply in the front chassis.

It has dual power supply, out-out-band (OOB) MGMT port and console (CON) port.

The power uses an IEC C15 U-notch/kettle plug.


The NCS 540 interfaces are color coded: pink ports are 10G SFP+ (it can also support 1G), yellow ports are 25G SFP+ and green ports are 100G QSFP28.


There are 4 fans in the rear chassis.

It uses N540-RCKMT-19= mount kit/ear.


The NCS 540 uses the IOS-XR software and the bootup only took 2 minutes. The IOS-XR has a similar feel with Junos OS.

 

Booting CISCO Route Processor Module

ME Firmware Status #1: 0x000F0345
ME Firmware Status #2: 0x38002000
ME Current State: Operational
ME Error Code: No Error
ME Operational Firmware Version: 06:3.0.3.27

Baseboard IOFPGA Information:
    Revision = 0x17
    ID = 0x74971FD3
    Creation Date = 0x20201222
CPU Board IOFPGA Information:
    Revision = 0x7
    ID = 0x70971FD3
    Creation Date = 0x20191205
    Fab Revision = P0

Baseboard Present!
Booting from Upgrade Bios
Code Signing Results:(0xC0)                                    0x0
Using Upgrade FPGA

Product: XR OS PRODUCT
Base Board IOFPGA found at PCI Bus: 0x05
Base Board MIFPGA found at PCI Bus: 0x06
CPU Board IOFPGA found at PCI Bus: 0x07
All FPGA devices are up and running.

SATA Port 0: SAMST128G3FEIT - 128.0 GB
DISK Boot Partition = UEFI: SAMST128G3FEITL261, Partition 4

XR OS Boot Mode = 0x0

Selected Boot Option:
        XROS: Harddisk Boot
Version 2.18.1260. Copyright (C) 2021 American Megatrends, Inc.                 
Winterfell BIOS: v1.14.0 Date: 07/08/2021 14:38:25                              
Press <ESC> to enter setup.                                                     
Image Name = \EFI\BOOT\BOOTX64.EFI                                              
                                                                                
Image Size = 926750 Bytes                                                       
                                                                                
 ------------Cisco Secure Boot: Begin ------------                              
                                                                                
 -----------Cisco Secure Boot: Verifying-----------                             
                                                                                
Image verified successfully. Booting..                                          
                                                                                
 ------------Cisco Secure Boot: End ------------                                
                                                                                
                                                                                
GNU GRUB version 2.00                                                           
Press F2 to goto grub Menu..                                                    
Booting from Disk..                                                             
Loading Kernel..                                                                
Kernel Secure Boot Validation Result: PASSED                                    
Loading initrd..                                                                
Initrd Secure Boot Validation Result: PASSED                                    
[    0.191412] Allocating netns hash table                                      
Enable selinux to relabel filesystem from initramfs                            
Load IMA appraise policy: OK
Switching to new root and running init.
Sourcing /etc/sysconfig/udev
Starting udev: udevd[486]: unknown key 'RUN{builtin}' in /lib/udev/rules.d/64-btrfs-dm.rules:8

udevd[486]: invalid rule '/lib/udev/rules.d/64-btrfs-dm.rules:8'

[  OK  ]
Configuring network interfaces... done.
Starting system message bus: dbus.
Tue Jan 31 07:25:21 UTC 2023: in hostos !!!!!!!!!
/etc/rc3.d/S08check-flash: line 487: pd_is_hdd_partition_needed: command not found
UBI device number 3, total 144 LEBs (18855936 bytes, 18.0 MiB), available 0 LEBs (0 bytes), LEB size 130944 bytes (127.9 KiB)
Punching IOFPGA watchdog
UBI device number 5, total 32 LEBs (4190208 bytes, 4.0 MiB), available 0 LEBs (0 bytes), LEB size 130944 bytes (127.9 KiB)
Punching IOFPGA watchdog
Starting OpenBSD Secure Shell server: sshd
sshd start/running, process 3540
Starting rpcbind daemon...done.
Starting kdump:[  OK  ]
Starting random number generator daemon.
Starting system log daemon...0
Starting kernel log daemon...0
tftpd-hpa disabled in /etc/default/tftpd-hpa
Starting internet superserver: xinetd.
Starting S.M.A.R.T. daemon: smartd.
Starting Lighttpd Web Server: lighttpd.
Starting libvirtd daemon: [  OK  ]
Starting crond: OK
Starting cgroup-init
Network ieobc_br defined from /etc/init/ieobc_br_network.xml

Network local_br defined from /etc/init/local_br_network.xml

Network ieobc_br started

Network local_br started

Network xr_local_br started

mcelog start/running, process 5514
diskmon start/running, process 5520
initctl: Unknown instance: /dev/ttyS0

/etc/rc.d/init.d/pd-functions: line 142: /bin: Is a directory

Connecting to 'default-sdr--1' console
ootlogd: ioctl(/dev/pts/2, TIOCCONS): Device or resource busy
Configuring network interfaces... done.
Starting system message bus: dbus.
Starting OpenBSD Secure Shell server: sshd
sshd start/running, process 1800
Starting rpcbind daemon...done.
Starting random number generator daemon.
Starting system log daemon...0
Starting kernel log daemon...0
tftpd-hpa disabled in /etc/default/tftpd-hpa
Starting internet superserver: xinetd.
Libvirt not initialized for container instance
Starting crond: OK
SIOCADDRT: File exists
osSignalTask: started


ios con0/RP0/CPU0 is now available


Press RETURN to get started.

0/RP0/ADMIN0:Jan 31 07:27:44.345 UTC: vm_manager[2666]: %INFRA-VM_MANAGER-4-INFO : Info: vm_manager started VM default-sdr--2  


This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply third-party
authority to import, export, distribute or use encryption. Importers,
exporters, distributors and users are responsible for compliance with
U.S. and local country laws. By using this product you agree to comply
with applicable laws and regulations. If you are unable to comply with
U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be
found at:
http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

If you require further assistance please contact us by sending email to
export@cisco.com.



!!!!!!!!!!!!!!!!!!!! NO root-system username is configured. Need to configure root-system username. !!!!!!!!!!!!!!!!!!!!

         --- Administrative User Dialog ---


  Enter root-system username: admin
  Enter secret:
  Enter secret again:

Use the 'configure' command to modify this configuration.
User Access Verification

Username: admin
Password:

The same Cisco basic IOS commands are still used. You use the "Rack 0" serial number in the show inventory command output when raising a Cisco TAC case.


RP/0/RP0/CPU0:ios#show inventory
Tue Jan 31 07:32:37.831 UTC
NAME: "0/RP0", DESCR: "Cisco NCS 540 16G Series Fixed Router 24x10G,8x25G,2x100G"
PID: N540-ACC-SYS      , VID: V02, SN: FOC26431234

NAME: "Rack 0", DESCR: "NCS 540 Series 16G 24x1/10GE, 8x10/25GE, 2x100GE Fixed Chassis"
PID: N540-ACC-SYS      , VID: V02, SN: FOC2644567

NAME: "0/FT0", DESCR: "NCS 540 Fan"
PID: N540-FAN          , VID: V01, SN: N/A

NAME: "0/FT1", DESCR: "NCS 540 Fan"
PID: N540-FAN          , VID: V01, SN: N/A

NAME: "0/FT2", DESCR: "NCS 540 Fan"
PID: N540-FAN          , VID: V01, SN: N/A

NAME: "0/FT3", DESCR: "NCS 540 Fan"
PID: N540-FAN          , VID: V01, SN: N/A

NAME: "0/PM0", DESCR: "NCS 540 400W AC power supply"
PID: N540-PWR400-A     , VID: V02, SN: LIT26431234

NAME: "0/PM1", DESCR: "NCS 540 400W AC power supply"
PID: N540-PWR400-A     , VID: V02, SN: LIT2643567
          

RP/0/RP0/CPU0:ios#show version
Tue Jan 31 07:32:43.379 UTC
Cisco IOS XR Software, Version 7.4.2
Copyright (c) 2013-2022 by Cisco Systems, Inc.

Build Information:
 Built By     : ingunawa
 Built On     : Wed Feb 16 05:24:50 PST 2022
 Built Host   : iox-lnx-025
 Workspace    : /auto/srcarchive15/prod/7.4.2/ncs540/ws
 Version      : 7.4.2
 Location     : /opt/cisco/XR/packages/
 Label        : 7.4.2

cisco NCS-540 () processor
System uptime is 5 minutes

When I checked, it already has the OSPF and MPLS RPM package by default.


RP/0/RP0/CPU0:ios#show install active
Tue Jan 31 07:32:48.121 UTC
Label : 7.4.2

Node 0/RP0/CPU0 [RP]
  Boot Partition: xr_lv0
  Active Packages: 10
        ncs540-xr-7.4.2 version=7.4.2 [Boot image]
        ncs540-eigrp-1.0.0.0-r742
        ncs540-isis-1.0.0.0-r742
        ncs540-li-1.0.0.0-r742
        ncs540-mgbl-1.0.0.0-r742
        ncs540-mpls-1.0.0.0-r742
        ncs540-mpls-te-rsvp-1.0.0.0-r742
        ncs540-ospf-2.0.0.0-r742
        ncs540-mcast-1.0.0.0-r742
        ncs540-k9sec-1.0.0.0-r742

Node 0/0/CPU0 [LC]
  Boot Partition: xr_lcp_lv0
  Active Packages: 10
        ncs540-xr-7.4.2 version=7.4.2 [Boot image]
        ncs540-eigrp-1.0.0.0-r742
        ncs540-isis-1.0.0.0-r742
        ncs540-li-1.0.0.0-r742
        ncs540-mgbl-1.0.0.0-r742
        ncs540-mpls-1.0.0.0-r742
        ncs540-mpls-te-rsvp-1.0.0.0-r742
        ncs540-ospf-2.0.0.0-r742
        ncs540-mcast-1.0.0.0-r742
        ncs540-k9sec-1.0.0.0-r742


RP/0/RP0/CPU0:ios#show ip ospf ?
  WORD                 OSPF process name
  bad-checksum         Bad ospf checksum packets queue(cisco-support)
  border-routers       Border and Boundary Router Information
  cmd                  Generic command support(cisco-support)
  database             Database summary
  fast-reroute         IP Fast-reroute
  flood-list           Link state flood list
  interface            Interface information
  maxage-list          Maxage List(cisco-support)
  message-queue        Hello, TE and router message queue data(cisco-support)
  mpls                 MPLS related information
  neighbor             Neighbor list
  our-address          our address Database(cisco-support)
  private              Lightweight version of show ospf (skip LSA db walks).(cis
co-support)
  request-list         Link state request list
  retransmission-list  Link state retransmission list
  routes               OSPF routes table
  segment-routing      OSPF Segment-routing(cisco-support)
  sid-database         SID Database(cisco-support)
  srlg                 SRLG related info
  standby              Retrieve operational information from standby process(cis
co-support)
  statistics           OSPF statistics information(cisco-support)
  summary              OSPF summary information
  summary-prefix       Summary-prefix redistribution Information
  timers               OSPF timers information(cisco-support)
  topology             OSPF Topo Library Information(cisco-support)
  trace                OSPF trace information(cisco-support)
  virtual-links        Virtual link information
  vrf                  Show one or more non-default OSPF VRFs in process
  |                    Output Modifiers
  <cr>                         
RP/0/RP0/CPU0:ios#show mpls ?
  ea           MPLS EA
  forwarding   Forwarding information
  interfaces   MPLS enabled interfaces information
  io           Show mpls io data
  label        Label information
  lctrl        Line Protocol Control information(cisco-support)
  ldp          Label Distribution Protocol
  lib          Library information
  lsd          Label Switching Database
  ma           MPLS MA
  mldp         mLDP information
  oam          OAM info
  static       Static label bindings
  tp-oam       MPLS Transport Profile OAM(cisco-support)
  traffic-eng  Traffic Engineering information
  vpn          MPLS VPN MIB 


Sunday, May 21, 2023

Cisco ASR1K IOS-XE 17.6.3 Software Upgrade

My family and I recently visited the Omniverse Museum and it houses a large collection of toys and memorabilia from DC, Marvel, Star Wars, Harry Potter, etc. It's located in Level 4 (Japan Town area) Glorietta 2 Makati City, Philippines.

This is the Iron Man hall which displays the complete 14 Iron Man suit/armor.

This is Superman's Fortress of Solitude.

This is my favorite part of the museum, Hogwarts castle's The Great Hall.

This is Star Wars' Jabba the Hutt.

Below is the upgrade process for a Cisco ASR1K from IOS-XE 16.x to 17.x. You'll need to check first the ROMMON and IOS-XE compatibility matrix. The initial ROMMON upgrade took around 8 minutes to complete.

Per the Cisco doc, in a Cisco ASR 1001 and Cisco ASR 1002-X after all the RTU licenses, there is NO expiration of license and are valid for a lifetime. Permanent licenses are NOT affected by Cisco IOS-XE release upgrades.

Per the Cisco doc, the 17.x IOS-XE upgrade performs a PAK licenses "snapshot": To continue supporting and honouring any existing PAK licenses you may have, the system automatically takes a snapshot of the PAK license and triggers a Device-led Conversion process, to convert PAK license to a Smart license.

 

 

ASR1K#upgrade rom-monitor filename bootflash:asr1000-rommon.173-1r.SPA.pkg all

Verifying the code signature of the ROMMON package...

Chassis model ASR1002-X has a single rom-monitor.

 

Upgrade rom-monitor

 

Target copying rom-monitor image file

File size : //tmp/rommon_upgrade/latest.bin

File size is : 2097152

FIPS File size is : 2097152

ROMMON Image Type : X86

File /tmp/rommon_upgrade/latest.bin is a FIPS ROMMON image

FIPS-140-3 Load Test on /tmp/rommon_upgrade/latest.bin has PASSED.

Authenticity of the image has been verified.

Checking upgrade image...

2097152+0 records in

4096+0 records out

2097152 bytes (2.1 MB, 2.0 MiB) copied, 2.04224 s, 1.0 MB/s

Upgrade image MD5 signature is 917ad3396182f922eea0cadaf1221513

Burning upgrade partition...

2097152+0 records in

2097152+0 records out

2097152 bytes (2.1 MB, 2.0 MiB) copied, 47.7425 s, 43.9 kB/s

Checking upgrade partition...

2097152+0 records in

2097152+0 records out

2097152 bytes (2.1 MB, 2.0 MiB) copied, 7.20536 s, 291 kB/s

Upgrade flash partition MD5 signature is 917ad3396182f922eea0cadaf1221513

2097152+0 records in

2097152+0 records out

2097152 bytes (2.1 MB, 2.0 MiB) copied, 5.05746 s, 415 kB/s

65536+0 records in

65536+0 records out

65536 bytes (66 kB, 64 KiB) copied, 0.29747 s, 220 kB/s

Copying ROMMON environment

2097152+0 records in

2097152+0 records out

2097152 bytes (2.1 MB, 2.0 MiB) copied, 46.2797 s, 45.3 kB/s

65536+0 records in

65536+0 records out

65536 bytes (66 kB, 64 KiB) copied, 1.44509 s, 45.4 kB/s

65536+0 records in

65536+0 records out

65536 bytes (66 kB, 64 KiB) copied, 1.45039 s, 45.2 kB/s

ROMMON upgrade complete.

To make the new ROMMON permanent, you must restart the RP.

 

ASR1K#reload

Proceed with reload? [confirm]

Mar 16 06:20:11.088: %PMAN-5-EXX

 

 

Initializing Hardware ...

 

System integrity status: 00000610

 

 

System Bootstrap, Version 16.7(1r), RELEASE SOFTWARE

Copyright (c) 1994-2017 by cisco Systems, Inc.

 

Current image running: Boot ROM1

Last reset cause: LocalSoft

 

 

SPI Flash 4KB Descriptor Area Checksum = 0x6f5a0db2

ASR1002-X platform with 8388608 Kbytes of main memory

 

Rommon upgrade requested

Flash upgrade reset 1 in progress

..

 

 

Initializing Hardware ...

 

System integrity status: 00000610

 

 

System Bootstrap, Version 16.7(1r), RELEASE SOFTWARE

Copyright (c) 1994-2017 by cisco Systems, Inc.

 

Current image running: Boot ROM1

Last reset cause: LocalSoft

 

 

SPI Flash 4KB Descriptor Area Checksum = 0x6f5a0db2

ASR1002-X platform with 8388608 Kbytes of main memory

 

Rommon upgrade requested

Flash upgrade reset 1 in progress

.......

 

Initializing Hardware ...

 

System integrity status: 00000610

 

 

Initializing Hardware ...

 

System integrity status: 00000610

 

 

System Bootstrap, Version 17.3(1r), RELEASE SOFTWARE

Copyright (c) 1994-2020 by cisco Systems, Inc.

 

Current image running: Boot ROM0

Last reset cause: Watchdog/ICH

 

Saving cur/min version to nvram 2

 

 ***          Incorrect BIOS parameters           ***

 *** Correcting the BIOS parameters and rebooting ***

ÿ

 

Initializing Hardware ...

 

System integrity status: 00000610

 

 

System Bootstrap, Version 16.7(1r), RELEASE SOFTWARE

Copyright (c) 1994-2017 by cisco Systems, Inc.

 

Current image running: Boot ROM1

Last reset cause: LocalSoft

 

 

SPI Flash 4KB Descriptor Area Checksum = 0x6f5a0db2

ASR1002-X platform with 8388608 Kbytes of main memory

 

Rommon upgrade requested

Flash upgrade reset 2 in progress

.......

 

Initializing Hardware ...

 

System integrity status: 00000610

 

 

System Bootstrap, Version 17.3(1r), RELEASE SOFTWARE

Copyright (c) 1994-2020 by cisco Systems, Inc.

 

Current image running: *Upgrade in progress* Boot ROM0

Last reset cause: BootRomUpgrade

 

 

SPI Flash 4KB Descriptor Area Checksum = 0x6f5a0db2

ASR1002-X platform with 8388608 Kbytes of main memory

 

File size is 0x2b0414ba

Located asr1002x-universalk9.16.09.08.SPA.bin

Image size 721687738 inode num 17, bks cnt 176194 blk size 8*512

################################################################

 

 

Issue the show platform command to verify new ROMMON code.

 

ASR1K#show platform

Chassis type: ASR1002-X          

 

Slot      Type                State                 Insert time (ago)

--------- ------------------- --------------------- -----------------

0         ASR1002-X           ok                    00:03:05     

 0/0      6XGE-BUILT-IN       ok                    00:01:45     

R0        ASR1002-X           ok, active            00:03:05     

F0        ASR1002-X           ok, active            00:03:05     

P0        ASR1002-PWR-AC      ps, fail              00:02:39     

P1        ASR1002-PWR-AC      ok                    00:02:39     

 

Slot      CPLD Version        Firmware Version                       

--------- ------------------- ---------------------------------------

0         14012203            17.3(1r)                           

R0        14012203            17.3(1r)                           

F0        14012203            17.3(1r) 

 

 

ASR1K#show version

Cisco IOS XE Software, Version 16.09.08

Cisco IOS Software [Fuji], ASR1000 Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 16.9.8, RELEASE SOFTWARE (fc4)

Technical Support: http://www.cisco.com/techsupport

Copyright (c) 1986-2021 by Cisco Systems, Inc.

Compiled Wed 01-Sep-21 01:43 by mcpre

 

 

Cisco IOS-XE software, Copyright (c) 2005-2021 by cisco Systems, Inc.

All rights reserved.  Certain components of Cisco IOS-XE software are

licensed under the GNU General Public License ("GPL") Version 2.0.  The

software code licensed under GPL Version 2.0 is free software that comes

with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such

GPL code under the terms of GPL Version 2.0.  For more details, see the

documentation or "License Notice" file accompanying the IOS-XE software,

or the applicable URL provided on the flyer accompanying the IOS-XE

software.

 

 

ROM: IOS-XE ROMMON

 

ASR1K uptime is 2 minutes

Uptime for this control processor is 5 minutes

System returned to ROM by BootRomUpgrade at 10:04:16 UTC Fri Jul 29 2022

System restarted at 06:25:34 UTC Thu Mar 16 2023

System image file is "bootflash:asr1002x-universalk9.16.09.08.SPA.bin"

Last reload reason: BootRomUpgrade

 

 

This product contains cryptographic features and is subject to United

States and local country laws governing import, export, transfer and

use. Delivery of Cisco cryptographic products does not imply

third-party authority to import, export, distribute or use encryption.

Importers, exporters, distributors and users are responsible for

compliance with U.S. and local country laws. By using this product you

agree to comply with applicable laws and regulations. If you are unable

to comply with U.S. and local laws, return this product immediately.

 

A summary of U.S. laws governing Cisco cryptographic products may be found at:

http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

 

If you require further assistance please contact us by sending email to

export@cisco.com.

 

License Type: Permanent

License Level: adventerprise

Next reload license Level: adventerprise

The current throughput level is 10000000 kbps

 

 

Smart Licensing Status: Smart Licensing is DISABLED

 

cisco ASR1002-X (2RU-X) processor (revision 2KP) with 3852984K/6147K bytes of memory.

Processor board ID FOX17511234

6 Gigabit Ethernet interfaces

32768K bytes of non-volatile configuration memory.

8388608K bytes of physical memory.

6684671K bytes of eUSB flash at bootflash:.

0K bytes of WebUI ODM Files at webui:.

 

Configuration register is 0x2102

 

 

Change to the bootflash variable to point to the new IOS-XE code. Then issue a reload command to take effect.

 

ASR1K#show run | inc boot

boot-start-marker

boot system flash bootflash:asr1002x-universalk9.16.09.08.SPA.bin

boot system flash bootflash:asr1002x-universalk9.03.10.05.S.153-3.S5-ext.SPA.bin

boot-end-marker

no ip bootp server

diagnostic bootup level minimal



ASR1K#configure terminal

Enter configuration commands, one per line.  End with CNTL/Z.

ASR1K(config)#no boot system

ASR1K(config)#boot system flash bootflash:asr1002x-universalk9.17.06.03a.SPA.bin    

ASR1K(config)#boot system flash bootflash:asr1002x-universalk9.16.09.08.SPA.bin

ASR1K(config)#end

ASR1K#write memory

Building configuration...

[OK]

 

 

ASR1K#show run | inc boot

boot-start-marker

boot system flash bootflash:asr1002x-universalk9.17.06.03a.SPA.bin

boot system flash bootflash:asr1002x-universalk9.16.09.08.SPA.bin

boot-end-marker

no ip bootp server

diagnostic bootup level minimal


ASR1K#show bootvar

BOOT variable = bootflash:asr1002x-universalk9.17.06.03a.SPA.bin,1;bootflash:asr1002x-universalk9.16.09.08.SPA.bin,1;

CONFIG_FILE variable does not exist

BOOTLDR variable does not exist

Configuration register is 0x2102

 

Standby not ready to show bootvar

 

ASR1K#reload

Proceed with reload? [confirm]

Mar 16 06:32:55.978: %PMAN-5-EX

 

 

Initializing Hardware ...

 

System integrity status: 00000610

 

 

System Bootstrap, Version 17.3(1r), RELEASE SOFTWARE

Copyright (c) 1994-2020 by cisco Systems, Inc.

 

Current image running: Boot ROM0

Last reset cause: LocalSoft

 

 

SPI Flash 4KB Descriptor Area Checksum = 0x6f5a0db2

ASR1002-X platform with 8388608 Kbytes of main memory

 

File size is 0x2a235209

Located asr1002x-universalk9.17.06.03a.SPA.bin

Image size 706957833 inode num 15, bks cnt 172598 blk size 8*512

####################################################################

 

 

The main IOS-XE 17.x upgrade took around 6 minutes to complete.

 

ASR1K#show version

Cisco IOS XE Software, Version 17.06.03a

Cisco IOS Software [Bengaluru], ASR1000 Software (X86_64_LINUX_IOSD-UNIVERSALK9-M), Version 17.6.3a, RELEASE SOFTWARE (fc1)

Technical Support: http://www.cisco.com/techsupport

Copyright (c) 1986-2022 by Cisco Systems, Inc.

Compiled Fri 08-Apr-22 04:50 by mcpre

 

 

Cisco IOS-XE software, Copyright (c) 2005-2022 by cisco Systems, Inc.

All rights reserved.  Certain components of Cisco IOS-XE software are

licensed under the GNU General Public License ("GPL") Version 2.0.  The

software code licensed under GPL Version 2.0 is free software that comes

with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such

GPL code under the terms of GPL Version 2.0.  For more details, see the

documentation or "License Notice" file accompanying the IOS-XE software,

or the applicable URL provided on the flyer accompanying the IOS-XE

software.

 

 

ROM: IOS-XE ROMMON

 

ASR1K uptime is 2 minutes

Uptime for this control processor is 4 minutes

System returned to ROM by Reload Command at 06:32:35 UTC Thu Mar 16 2023

System restarted at 06:36:56 UTC Thu Mar 16 2023

System image file is "bootflash:asr1002x-universalk9.17.06.03a.SPA.bin"

Last reload reason: Reload Command

 

 

This product contains cryptographic features and is subject to United

States and local country laws governing import, export, transfer and

use. Delivery of Cisco cryptographic products does not imply

third-party authority to import, export, distribute or use encryption.

Importers, exporters, distributors and users are responsible for

compliance with U.S. and local country laws. By using this product you

agree to comply with applicable laws and regulations. If you are unable

to comply with U.S. and local laws, return this product immediately.

 

A summary of U.S. laws governing Cisco cryptographic products may be found at:

http://www.cisco.com/wwl/export/crypto/tool/stqrg.html

 

If you require further assistance please contact us by sending email to

export@cisco.com.

 

License Type: Smart License is permanent

License Level: adventerprise

Next reload license Level: adventerprise

The current throughput level is 10000000 kbps

 

 

Smart Licensing Status: Registration Not Applicable/Not Applicable

 

cisco ASR1002-X (2RU-X) processor (revision 2KP) with 3742322K/6147K bytes of memory.

Processor board ID FOX17511234

Router operating mode: Autonomous

6 Gigabit Ethernet interfaces

32768K bytes of non-volatile configuration memory.

8388608K bytes of physical memory.

6684671K bytes of eUSB flash at bootflash:.

 

Configuration register is 0x2102

 

 

ASR1K#show platform

Chassis type: ASR1002-X          

 

Slot      Type                State                 Insert time (ago)

--------- ------------------- --------------------- -----------------

0         ASR1002-X           ok                    00:03:17     

 0/0      6XGE-BUILT-IN       ok                    00:02:06     

R0        ASR1002-X           ok, active            00:03:17     

F0        ASR1002-X           ok, active            00:03:17     

P0        ASR1002-PWR-AC      ps, fail              00:02:46     

P1        ASR1002-PWR-AC      ok                    00:02:46     

 

Slot      CPLD Version        Firmware Version                       

--------- ------------------- ---------------------------------------

0         14012203            17.3(1r)                           

R0        14012203            17.3(1r)                           

F0        14012203            17.3(1r)              

 

 

The previous PAK/traditional license remained permanent. Issue a show platform software sl-infra pak-info to verify licenses.

 

ASR1K#show platform software sl-infra pak-info
Pak License Snapshot Information
=================================
Platform Supports PAK License snapshot
PAK License Snapshot integrity check pass
PAK License Snapshot available

 

<OUTPUT TRUNCATED>

 

License Name                : adventerprise

  Index                     : 0

  In Use Count              : 0

  In Use Count Valid        : 0

  License Precedence        : 0

  License Type              : 0 - Permanent

  License Get Type          : 0 - Permanent

  Number of License         : 65535 - Non-Counted

  Current State             : 2 - Active, Not in Use

  License State             : 1 - Active, In Use

  Timestamp lower 32bits    : 1678948640 - Thu Mar 16 06:37:20 2023

  Timestamp upper 32bits    : 0

  Trial Elapsed Period Left : 0

Total Number of Feature Info in Snapshot: 21

 

 

ASR1K#show license all

Smart Licensing Status

======================

 

Smart Licensing is ENABLED

 

License Conversion:

  Automatic Conversion Enabled: True

  Status: Not started

 

Export Authorization Key:

  Features Authorized:

    <none>

 

Utility:

  Status: DISABLED

 

Smart Licensing Using Policy:

  Status: ENABLED

 

Data Privacy:

  Sending Hostname: yes

    Callhome hostname privacy: DISABLED

    Smart Licensing hostname privacy: DISABLED

  Version privacy: DISABLED

 

Transport:

  Type: cslu

  Cslu address: <empty>

  Proxy:

    Not Configured

 

Miscellaneous:

  Custom Id: <empty>

 

Policy:

  Policy in use: Merged from multiple sources.

  Reporting ACK required: yes (CISCO default)

  Unenforced/Non-Export Perpetual Attributes:

    First report requirement (days): 365 (CISCO default)

    Reporting frequency (days): 0 (CISCO default)

    Report on change (days): 90 (CISCO default)

  Unenforced/Non-Export Subscription Attributes:

    First report requirement (days): 90 (CISCO default)

    Reporting frequency (days): 90 (CISCO default)

    Report on change (days): 90 (CISCO default)

  Enforced (Perpetual/Subscription) License Attributes:

    First report requirement (days): 0 (CISCO default)

    Reporting frequency (days): 0 (CISCO default)

    Report on change (days): 0 (CISCO default)

  Export (Perpetual/Subscription) License Attributes:

    First report requirement (days): 0 (CISCO default)

    Reporting frequency (days): 0 (CISCO default)

    Report on change (days): 0 (CISCO default)

 

Usage Reporting:

  Last ACK received: <none>

  Next ACK deadline: Mar 15 06:37:56 2024 UTC

  Reporting push interval: 30  days

  Next ACK push check: <none>

  Next report push: Mar 16 06:39:56 2023 UTC

  Last report push: <none>

  Last report file write: <none>

 

Trust Code Installed: <none>

 

License Usage

=============

 

throughput_10g (ASR_1002X_Throughput_5G-10G):

  Description: throughput_10g

  Count: 1

  Version: 1.0

  Status: IN USE

  Export status: NOT RESTRICTED

  Feature Name: throughput_10g

  Feature Description: throughput_10g

  Enforcement type: NOT ENFORCED

  License type: Perpetual

 

adventerprise (ASR_1000_AdvEnterprise):

  Description: adventerprise

  Count: 1

  Version: 1.0

  Status: IN USE

  Export status: NOT RESTRICTED

  Feature Name: adventerprise

  Feature Description: adventerprise

  Enforcement type: NOT ENFORCED

  License type: Perpetual

 

Product Information

===================

UDI: PID:ASR1002-X,SN:JAE181701KH

 

Agent Version

=============

Smart Agent for Licensing: 5.1.26_rel/120

 

License Authorizations

======================

Overall status:

  Active: PID:ASR1002-X,SN:JAE18175678

      Status: NOT INSTALLED

      Status:PAK

 

Legacy License Info:

  regid.2015-06.com.cisco.ASR_1000_AdvEnterprise,1.0_855386bf-6b9a-4aae-bc41-6d398da6abcd:

    DisplayName: adventerprise

    Description: adventerprise

    Total available count: 1

    Term information:

      Active: PID:ASR1002-X,SN:JAE18175678

        License type: PERPETUAL

          Term Count: 1

         

Purchased Licenses:

  No Purchase Information Available

 

 

Derived Licenses:

  Entitlement Tag: regid.2015-08.com.cisco.ASR_1002X_Throughput_5G-10G,1.0_ed4193e9-8505-40b2-8f51-d12ed5e830af

  Entitlement Tag: regid.2015-06.com.cisco.ASR_1000_AdvEnterprise,1.0_855386bf-6b9a-4aae-bc41-6d398da6b2be