This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| network_stuff:cisco:ios [2021/07/26 16:42] – jotasandoku | network_stuff:cisco:ios [2024/10/02 11:48] (current) – jotasandoku | ||
|---|---|---|---|
| Line 31: | Line 31: | ||
| ---- | ---- | ||
| - | **COPY FILES FROM AND TO NIX BOX** | + | __**IOS NEW HARDWARE SETUP INITIAL CONFIGURATION**__\\ |
| + | - If this is a used device, remove the configuration and the vlan database | ||
| + | - write erase ; reload **without saving the configuration** | ||
| + | - delete flash: | ||
| + | - reload again | ||
| + | - Add IP in the mgmt interface. Normally g0/0 | ||
| + | - Add a static route in mgmt interface. It needs to be in the mgmt vrf | ||
| + | - enable ssh: | ||
| + | - crypto key generate rsa modulus 1024 | ||
| + | - ip ssh version 2 ; time-out 60 ; authentication-retries 2 | ||
| + | - do not add any aaa configuration as yet | ||
| + | - Add the device to TACACS server (eg: to cisco ISE via the GUI) | ||
| + | |||
| + | ---- | ||
| + | |||
| + | __**COPY FILES FROM AND TO LINUX BOX**__\\ | ||
| + | ** scp needs to be enabled in the switch. Also in some cases this aaa needs to be in for authentication ** | ||
| + | \\ | ||
| + | Regarding TFTP, remember that it uses udp-69 just for the initial message but then it uses 64001 through 65000 as ports are specific per each session (both in src and dst). | ||
| + | |||
| + | aaa new-model | ||
| + | aaa authentication login default local | ||
| + | aaa authorization exec default local if-authenticated | ||
| + | \\ | ||
| (IOS)#copy scp:// | (IOS)#copy scp:// | ||
| (IOS)#cd ? ! To show available file systems | (IOS)#cd ? ! To show available file systems | ||
| (IOS)# | (IOS)# | ||
| - | | + | |
| + | |||
| \\ | \\ | ||
| (linux)# scp test1 netrobot@10.8.90.21: | (linux)# scp test1 netrobot@10.8.90.21: | ||
| Line 57: | Line 82: | ||
| show line | show line | ||
| clear line <n> | clear line <n> | ||
| + | control-shift-6 then x ! disconnects session | ||
| Line 63: | Line 89: | ||
| **SOFTWARE UPGRADES:** | **SOFTWARE UPGRADES:** | ||
| \\ | \\ | ||
| - | ASA: [[http:// | + | __ASA UPGRADES__: [[http:// |
| \\ | \\ | ||
| ASA: Apply lincense: | ASA: Apply lincense: | ||
| Line 76: | Line 102: | ||
| show run brief | s crypto|isakmp|access-list | show run brief | s crypto|isakmp|access-list | ||
| \\ | \\ | ||
| - | \\ | + | __IOS (ios-xe) UPGRADE__: [[https:// |
| + | |||
| + | Old way: upload the image and change the boot command | ||
| + | boot system switch all flash: | ||
| + | |||
| + | New way: | ||
| + | software install file flash: | ||
| + | |||
| + | ---- | ||
| + | |||
| AAA RADIUS TACACS+ \\ | AAA RADIUS TACACS+ \\ | ||
| To verify AAA authentication: | To verify AAA authentication: | ||
| Line 278: | Line 314: | ||
| A useful analogy is: Catalyst VSS is like juniper VC. VSS operates on a unified control plane with a distributed forwarding architecture in which the active supervisor (or switch) is responsible for actively participating with the rest of the network and for managing and maintaining control plane information. | A useful analogy is: Catalyst VSS is like juniper VC. VSS operates on a unified control plane with a distributed forwarding architecture in which the active supervisor (or switch) is responsible for actively participating with the rest of the network and for managing and maintaining control plane information. | ||
| \\ | \\ | ||
| - | [[http:// | + | * [[http:// |
| - | [[http:// | + | |
| \\ | \\ | ||
| Line 346: | Line 382: | ||
| Netflow status: | Netflow status: | ||
| show platform hardware capacity netflow | show platform hardware capacity netflow | ||
| + | show mls sampling | ||
| + | show ip flow export # To see see Netflow packets being exported from router | ||
| + | show mls nde # Netflow Data Export | ||
| + | show mls netflow table-contention summary # To see if there is excessive Netflow CAM Utilization (and potential buffer overflows) | ||
| + | |||
| | | ||
| \\ | \\ | ||
| Line 355: | Line 396: | ||
| show ip cef < | show ip cef < | ||
| show ip cef exact-route <src> <dst> | show ip cef exact-route <src> <dst> | ||
| + | show ip cef 10.1.93.0/ | ||
| [[http:// | [[http:// | ||
| * receive: for connected IP subnets for the base address of the IP subnet and for the local IP address in the IP subnet. | * receive: for connected IP subnets for the base address of the IP subnet and for the local IP address in the IP subnet. | ||
| Line 383: | Line 425: | ||
| \\ | \\ | ||
| - | **TERMINAL SERVER**\\# | ||
| - | Disconnect session: | ||
| - | control-shift-6 then x | ||
| - | |||
| ---- | ---- | ||
| Line 438: | Line 476: | ||
| for host in $(seq --format=' | for host in $(seq --format=' | ||
| **__TEMPLATE__** | **__TEMPLATE__** | ||
| - | for host in $(seq --format=' | + | for host in $(seq --format=' |
| To send a bunch of commands (e.g.: edit, configuration and commit, contained in a file called ' | To send a bunch of commands (e.g.: edit, configuration and commit, contained in a file called ' | ||
| - | for host in $(seq --format=' | + | for host in $(seq --format=' |
| \\ | \\ | ||
| PIPE NOT AVAILABLE \\ | PIPE NOT AVAILABLE \\ | ||
| Line 447: | Line 485: | ||
| \\ | \\ | ||
| Extract current IPs in dns server | Extract current IPs in dns server | ||
| - | ssh root@marrow "egrep " | + | ssh root@marrow "egrep " |
| - | ssh root@marrow "egrep " | + | ssh root@marrow "egrep " |
| \\ | \\ | ||
| Line 508: | Line 546: | ||
| + | ---- | ||
| + | **CABLE TESTING**: | ||
| + | test cable-diagnostics tdr interface | ||
| + | show cable-diagnostics | ||
| + | |||
| + | |||
| + | ---- | ||
| + | ==== CISCO DNAC AND NDO ==== | ||
| + | ( CATALYST CENTER AND NEXUS DASHBOARD ORCHESTRATOR ) | ||
| + | |||
| + | * You cannot run Catalyst Centre (DNAC) and NDO on the same VM/ Appliance. | ||
| + | * Cisco have DNAC/ NDO appliances which are built on UCS platforms but sold as appliances (bundled h/w s/w). | ||
| + | === DNAC platform support=== | ||
| + | * DNAC offers flexible deployment options. It can be deployed on a hardware appliance or as a virtual appliance, on either VMware ESXi or AWS. | ||
| + | * DNAC can be run as 1 node 3 or 5 node clusters – base level is 1 node for **lifecycle and assurance** (recommend 3+nodes for fabric deployments) [[https:// | ||
| + | === NDO platform support === | ||
| + | * NDO Cisco Nexus Dashboard portfolio comprises physical, virtual, and cloud form factors also – base level is 1 to 3 nodes (up to 9 in a cluster) | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | * NOTE: Onboarding standalone switches is supported only on 3-node physical clusters. | ||