Brkarc 2019
Brkarc 2019
Brkarc 2019
RP
RP
traffic flows through the active ESP,
standby is synchronized with all the states
ESP
ESP
ELC
SIP
MIP
AGG AGG AGG
IOCP IOCP IOCP
ASIC ASIC ASIC
RP
Maintains routing tables (RIB, FIB) (PAL)
Chassis Forwarding Provides abstraction layer between
Initialization of RP processes manager manager hardware & IOS
Initialization of installed cards Manages ESP redundancy
Detects and manages OIR of cards Linux Kernel Maintains copy of FIB and interface list
Manages system status, Communicates FIB status to active &
environments, power, EOBC standby ESP
Control
messaging
SIP
Chassis affect other SPAs in the chassis
Chassis Forwarding manager
Communicates with forwarding manager manager
manager on RP
Linux Kernel Linux Kernel
Maintains copy of FIBs
Provides interface to QFP client &
driver
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
ASR 1000 Series Chassis
ASR 1001-X ASR 1002-X ASR 1002-HX ASR 1004 ASR 1006-X ASR 1009-X ASR 1013
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Zero Touch Deployment ?
AutoInstall
Enables the initial configuration of a remote router tftp-server bootflash:ASR1000-bootstrap
automatically !
ip dhcp excluded-address 30.1.1.1
Combined with DHCP and TFTP Server. !
ip dhcp pool ZTP
network 30.1.1.0 255.255.255.0
Facilitate the centralized management of router bootfile ASR1000-bootstrap
installation default-router 30.1.1.1
option 150 ip 30.1.1.1
Supported on Mgmt interface.
DHCP + Option150
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
APIC-EM Network PnP
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
16.4
Secured PnP Deployment
ASR1k running DHCP Server
PnP Agent DMZ APIC PnP
Server DC
DHCP Request
PnP Server uses
1 DHCP response self-signed SSL
with options 43 certificate
for server ip
2
PnP Agent initiates HTTP communication with HTTP PnP work request with device serial number (UDI)
the server and sends the device UDI 3
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
What and How to Monitor
- Management Interface & Features
Mgmt Interface
ASR 1000 has out-of-band Mgmt GE interface attached to the RP
This interface on a default Mgmt-vrf, can not be removed/changed
Many mgmt features needs to be configured with vrf options or use Gig0 as
source interface: tftp, ntp, snmp, syslogging, tacacs/radius
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Mgmt Interface contd
There are few exceptions: Flexible Netflow Export & NAT/FW High Speed
Logging (HSL).
They are directly exported by QFP.
HSL - ASR 1000 export Netflowv9-like records to an external collector for
session creation/deletion events with 5-tuples.
HSL supported collector Lancope, Isarflow, ActionPacked, Plixer.
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
What and How to Monitor
- Facility & Environment
ASR 1000 PEM (Power Entry Module) = P/S + Integrated
FANs
P/S Failure:
The power supplies are redundant.
Failure of a P/S does not affect the FANs. PEM1
FAN Failure:
PEM2
A single fan failure has no impact on the other fans in
the PEM
On multi fan failure a critical alarm will be
generated. The system will continue to run and the
behavior would be based on where the fan failure
occurred.
Automatic Router Shutdown occurred when PEM1
PEM is removed for more than 5 minutes
Router Internal temperature or P/S is over 100C, If PEM2
facility-alarm critical exceed-action shutdown is
enabled
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
ASR1009-X / ASR1006-X Power Supply
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
Facility & Environment Monitoring
Facilities & Environment can be monitored via ASR1000# show facility-alarm status
System Totals Critical: 1 Major: 1 Minor: 0
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Facility & Environment Monitoring contd
Before using CISCO-ENTITY-SENSOR-MIB to Then search CISCO-ENTITY-SENSOR-MIB for
monitor env, 1st use ENTITY-MIB to find out required data, such as polling RP CPU
entPhysicalDescr ID temperature ENTITY-MIB::entPhysicalDescr.8022
= STRING: Temp: CPU AIR
[root@shmcp-lnx-1 ~]# snmpwalk -v 2c -c public 5.28.28.10
1.3.6.1.2.1.47.1.1.1.1.2 | more [root@shmcp-lnx-1 ~]# snmpwalk -v 2c -c public 5.28.28.10
ENTITY-MIB::entPhysicalDescr.1 = STRING: Cisco ASR1013 Chassis 1.3.6.1.4.1.9.9.91 | grep 8022
ENTITY-MIB::entPhysicalDescr.2 = STRING: CC Slot CISCO-ENTITY-SENSOR-MIB::entSensorValue.8022 = INTEGER: 30
ENTITY-MIB::entPhysicalDescr.3 = STRING: CC Slot
ENTITY-MIB::entPhysicalDescr.4 = STRING: CC Slot CISCO-ENTITY-SENSOR-MIB::entSensorStatus.8022 = INTEGER: ok(1)
ENTITY-MIB::entPhysicalDescr.5 = STRING: CC Slot
ENTITY-MIB::entPhysicalDescr.6 = STRING: CC Slot
ENTITY-MIB::entPhysicalDescr.7 = STRING: CC Slot
ENTITY-MIB::entPhysicalDescr.8 = STRING: RP Slot
ENTITY-MIB::entPhysicalDescr.9 = STRING: RP Slot
ENTITY-MIB::entPhysicalDescr.10 = STRING: FP Slot
ENTITY-MIB::entPhysicalDescr.11 = STRING: FP Slot
ENTITY-MIB::entPhysicalDescr.12 = STRING: Power Supply Bay
ENTITY-MIB::entPhysicalDescr.13 = STRING: Cisco ASR1013 AC Power Supply
ENTITY-MIB::entPhysicalDescr.14 = STRING: PEM Iout
ENTITY-MIB::entPhysicalDescr.15 = STRING: PEM Vout
ENTITY-MIB::entPhysicalDescr.16 = STRING: PEM Vin
ENTITY-MIB::entPhysicalDescr.17 = STRING: Temp: PEM
ENTITY-MIB::entPhysicalDescr.18 = STRING: Temp: FC
ENTITY-MIB::entPhysicalDescr.23 = STRING: Power Supply
ENTITY-MIB::entPhysicalDescr.24 = STRING: Fan
ENTITY-MIB::entPhysicalDescr.25 = STRING: Fan
ENTITY-MIB::entPhysicalDescr.26 = STRING: Fan
ENTITY-MIB::entPhysicalDescr.32 = STRING: Power Supply Bay
ENTITY-MIB::entPhysicalDescr.8022 = STRING: Temp: CPU AIR
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
What and How to Monitor
- System Resources used by Features
QoS Marking/Police
NAT Sessions
Memory
Crypto
Chassis Interconnect
Mgmt Bus
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
Key System Resources to Monitor - Summary
show mem stat 75%
show proc cpu sort
SIP
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
Key System Resources to Monitor
- IOSd CPU & Memory Utilization
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
Key System Resources to Monitor
- Control CPU & Memory Utilization (1)
For an overview of each Module CPU load on the ASR 1000, use the following
command:
Sample EEM script to
ASR1000# show platform software status control-processor brief
trigger the Load
monitoring at section Load Average
end reference slide Slot Status 1-Min 5-Min 15-Min
RP0 Healthy 0.06 0.06 0.01
RP1 Healthy 0.06 0.04 0.01
ESP0 Healthy 0.01 0.00 0.00
ESP1 Healthy 0.00 0.00 0.00
SIP1 Healthy 0.04 0.03 0.01
SIP2 Healthy 0.00 0.00 0.00
Load Average represents the process queue or process contention for CPU resources.
1. On a single core processor, an instantaneous load of 7 would mean that seven
processes were ready to run, one of which is currently running.
2. On a dual core processor, a load of 7 would represent seven processes were ready to
run, two of which are currently running.
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
Key System Resources to Monitor
- Control CPU & Memory Utilization (2)
Status: Critical,
Warning, Healthy.
<continued from last show command output>
Definition in Memory (kB)
reference slide at Slot Status Total Used (Pct) Free (Pct) Committed (Pct)
section end RP0 Critical 3919788 3891940 (95%) 27848 (0%) 2005100 (98%)
RP1 Healthy 3919788 1164924 (28%) 2754864 (66%) 1994212 (48%)
ESP0 Healthy 2030288 520744 (24%) 1509544 (71%) 2816620 (84%)
ESP1 Healthy 2030288 514972 (24%) 1515316 (72%) 2816356 (84%)
SIP1 Healthy 484332 311868 (59%) 172464 (32%) 262472 (50%)
SIP2 Healthy 484332 332252 (63%) 152080 (29%) 317648 (60%)
CPU Utilization
Slot CPU User System Nice Idle IRQ SIRQ IOwait
RP0 0 1.28 1.15 0.00 97.25 0.01 0.10 0.20
RP1 0 0.94 1.23 0.00 97.48 0.00 0.02 0.30
ESP0 0 0.56 0.66 0.00 98.76 0.00 0.00 0.00
ESP1 0 0.52 0.64 0.00 98.82 0.00 0.00 0.00
SIP1 0 0.47 0.45 0.00 99.04 0.00 0.01 0.00
SIP2 0 0.58 0.53 0.00 98.85 0.00 0.01 0.00
*the first set of values is Invalid. Only the 2nd cycle or higher has valid CPU reported
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
Key System Resources to Monitor
- Control CPU & Memory Utilization (4)
To check process in each Module, use following command to check in VTY
*the "monitor" command does not work with console, vty works by default.
*Dont screen shot the 1st output, let the cycle go through few times.
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Key System Resources to Monitor
- Control CPU & Memory Utilization (5)
CISCO-PROCESS-MIB is able to monitor CPUs on RP, ESP and SIP. Only Active RP/ESP
can be monitored, not standby.
Here is an example:
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Key System Resources to Monitor
- QFP & Resource DRAM Utilization (1)
97%+
>=99% indicates
indicates QFP
crypto
chip chip is
is reaching
reaching
perf perf
limitlimit
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Key System Resources to Monitor
- QFP & Resource DRAM Utilization (2)
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Key System Resources to Monitor
- QFP & Resource DRAM Utilization (3)
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Key System Resources to Monitor
- QFP & Resource DRAM Utilization (4)
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
Key System Resources to Monitor
- QFP & Resource DRAM Utilization (5)
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
Key System Resources to Monitor
- TCAM
QFP TCAM usage can be found in following command:
ASR1000# show platform hardware qfp active tcam resource-manager usage
QFP TCAM Usage Information
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
Key System Resources to Monitor
- Crypto Chip Utilization (1)
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Key System Resources to Monitor
- Crypto Chip Utilization (2)
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Control-Process Health Definition (1)
Board FIELD WARNING CRITICAL FIELD WARNING CRITICAL FIELD WARNING CRITICAL
SIP10 1-MIN 5 8 5-MIN 5 8 15-MIN 5 8
show platform software status control-processor brief output in slide 25, the Load
Average Status can be Healthy, Warning and Critical, this table provides the Warning and
Critical status threshold for each field
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Control-Process Health Definition (2)
Board FIELD WARNING CRITICAL FIELD WARNING CRITICAL FIELD WARNING CRITICAL
SIP10 Committed 95% 100% MemFree 10% 5% MEMUSED 90% 95%
show platform software status control-processor brief output in slide 26, the Memory
Status can be Healthy, Warning and Critical, this table provides the Warning and Critical
status threshold for each field
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Triggered EEM Script to monitor system load
This is a sample EEM script that monitors RP0 one minute load.
A load of 5 triggers actions 1 through 5.
Action 1 generates a log message when the script triggers.
Actions 2 through 5 run CLI, outputs them to the bootflash, and appends the cpuinfo file
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
DoS Attack Detection and Mitigation
Best Practices
DoS Introduction
DoS attack is basically an attempt to make a resource unavailable to its intended
users.
1. Consumption of computational resources, such as bandwidth, or CPU cycles.
2. Disruption of configuration information, such as routing information.
3. Disruption of state information, such as unsolicited resetting of TCP sessions.
4. Obstructing the communication between the intended users and the router
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 42
DoS Introduction contd
Example Attack Type
1. ICMP
SMURF
PING Flood
2. SYN Flood
3. Teardrop
Mangling packets structure/content
4. Nuke
Rapid packet generation
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 43
DoS Detection (1)
Typical Router Symptoms:
1. CPUHOG Messages
Example:
ASR1000#show logging
Syslog logging: enabled (0 messages dropped, 18 messages rate-limited, 58 flushes, 0 overruns, xml disabled, filtering disabled)
Apr 9 22:12:21.399 JST: %IOSXE-2-PLATFORM: F1: cpp_cp: QFP:00 Thread:077
TS:00022029349683022400 %HAL_PKTMEM-2-OUT_OF_RESOURCES:
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 44
DoS Detection (2)
Check CPU Utilization Check Process Resources
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 45
DoS Detection (3)
Check FP punt activity Check FP punt policer
ASR1000# show platform software infrastructure packet ASR1000# show platform software punt-policer
Statistics for Punt Path activities: Per Punt-Cause Policer Configuration and Packet Counters
Punt Configured (pps) Conform Packets Dropped Packets
19858208 total packets processed Cause Description Normal High Normal High Normal High
0 minimum packet received, 2048 maximum packet received ---------------------------------------------------------------------------------------------
0 minimum packet process switched, 7 maximum packet process - 2 IPv4 Options 4000 3000 0 0 0 0
3 Layer2 control and legacy 40000 10000 1203060 2146805 0 0
switched 4 PPP Control 2000 1000 0 0 0 0
0 msec minimum clock runtime, 30 msec maximum clock runtime 5 CLNS IS-IS Control 2000 1000 0 0 0 0
0 msec minimum cpu runtime, 2 msec maximum cpu runtime 6 HDLC keepalives 2000 1000 0 0 0 0
7 ARP request or response 2000 1000 0 68540 0 0
6797817 puntpath invocation, 6797817 with message invocation 8 Reverse ARP request or re... 2000 1000 0 0 0 0
FP - Punt Policer: 9 Frame-relay LMI Control 2000 1000 0 0 0 0
10 Incomplete adjacency 2000 1000 0 5 0 0
11 For-us data 40000 5000 803926 0 0 0
ASR1000# show platform hardware qfp active infrastructure punt 12 Mcast Directly Connected ... 2000 1000 0 0 0 0
statistics type global-drop 13 Mcast IPv4 Options data p... 2000 1000 0 0 0 0
Global Drop Statistics 14 MPLS TTL expired 5120 2000 0 0 0 0
19 Mcast Internal Copy 2000 1000 0 0 0 0
Number of global drop counters = 21 20 Mcast IGMP Unroutable 2000 1000 0 0 0 0
Counter ID Drop Counter Name Packets 24 Glean adjacency 2000 5000 0 35052 0 0
------------------------------------------------------------- 25 Mcast PIM signaling 2000 1000 0 0 0 0
27 ESS session control 10000 40000 0 30507493 0 288003062
016 PUNT_CAUSE_GLOBAL_POLICER 27117
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 46
DoS Detection (4)
Check FP per-cause punt
ASR1000# show platform hardware qfp active infrastructure punt statistics type per-cause clear
Global Per Cause Statistics
Per Inject Cause Statistics
Packets Packets
Counter ID Inject Cause Name Received Transmitted
--------------------------------------------------------------------------------------
000 RESERVED 0 0
001 L2 control/legacy 0 0
002 QFP destination lookup 0 0
003 QFP IPv4/v6 nexthop lookup 0 0
004 QFP generated packet 0 0
005 QFP <->RP keepalive 2 0
006 QFP Fwall generated packet 0 0
007 QFP adjacency-id lookup 0 0
008 Mcast specific inject packet 0 0
009 QFP ICMP generated packet 0 0
010 QFP/RP->QFP ESS data packet 0 0
011 SBC DTMF 0 0
012 ARP request or response 0 0
013 Ethernet OAM loopback packet 0 0
014 Ingress redirect packet 0 0
015 PPPoE discovery packet 48764 48741
016 PPPoE session packet 0 0
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
DoS Mitigation (1)
ASR1000 implemented global policer to rate limit punt packets @ 146484 pps/2.5Gbps, in addition implemented per
cause punt policer based on common feature punt cause to classify punt packets into high & normal queues and set
policing threshold for each.
Per cause policer can be seen via show platform software punt-policer
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
DoS Mitigation (2)
Global Config Interface Config
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
DoS Mitigation (3)
Control Plane Policing - Routing Control-Plane Policing - Management
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 50
DoS Mitigation (4)
Control Plane Policing - Normal Control-Plane Policing - Undesirable
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
DoS Mitigation (5)
Control Plane Policing - ARP Control-Plane Policing Catch-All-IP Control-Plane Policing Class-
default
class-map match-all ARP class-map match-all Catch-All-IP ! L2 keepalives, CDP, CLNS, and other non-
match protocol arp match access-group name Catch-All-IP IP packets
! ! !
policy-map CONTROL-PLANE-POLICY ip access-list extended Catch-All-IP policy-map CONTROL-PLANE-POLICY
class ARP permit tcp any any class class-default
police rate 1 pps burst 50 packets permit udp any any police rate 100 pps burst 100 packets
conform-action transmit permit icmp any any conform-action transmit
exceed-action drop permit ip any any exceed-action transmit
! !
policy-map CONTROL-PLANE-POLICY control-plane
class Catch-All-IP service-policy input CONTROL-PLANE-POLICY
police rate 1 pps burst 100 packets
conform-action transmit
exceed-action drop
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
DoS Mitigation (6)
Control-Plane Policing IPv6 Control
!
policy-map CONTROL-PLANE-POLICY
class IPv6-CONTROL
police rate 200 pps burst 1000 packets
conform-action transmit
exceed-action drop
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
Device Programmability (Demo)
Device Programmability
gRPC
RESTconf NETCONF
(IOS-XR only)
Data Model
Configuration Operational
Device Device
Standard Standard
Specific Specific
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 55
XE16.3 Supported Models
IETF-Interfaces IETF-OSPF v2/v3 IETF-QoS (shape, Cisco-MPLS static
COMMON
MODELS
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
Demo
1. Provision DMVPN Tunnels LB: 2.2.2.2
HUB
2. Unprovision DMVPN Tunnels Tunnel200: 192.99.99.1
Spoke1 Spoke2
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
CLI Config converted to Yang Data Model
IOS XE Config Yang data model
Build Number
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 60
What to expect HW (1)
Supported Unsupported
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
What to expect HW (2)
Supported Unsupported
Ethernet Port EPA-1X100GE N/A
Adapters (EPA) EPA-10X10GE
EPA-18X1GE
Shared Port SPA-8XCHT1/E1-V2, SPA-4XCT3/DS0-V2, SPA-2XCT3/DS0-V2, SPA-2XT3/E3-V2, SPA-8XCHT1/E1,
Adapters (SPA) SPA-4XT3/E3-V2, SPA-8XT3/E3, SPA-1CHSTM1/OC3V2, SPA-1XCHOC12/DS0, SPA- SPA-4XCT3/DS0,
4XT-SERIAL SPA-2XCT3/DS0,
SPA-4X1FE-TX-V2, SPA-8X1FE-TX-V2, SPA-2X1GE-V2, SPA-5X1GE-V2, SPA-8X1GE- SPA-2XT3/E3, SPA-
V2, SPA-10X1GE-V2, SPA-1X10GE-L-V2, SPA-1X10GE-WL-V2 4XT3/E3, SPA-
SPA-2XOC3-POS-V2, SPA-4XOC3-POS-V2, SPA-8XOC3-POS, SPA-1XOC12-POS-V2, 1XCHSTM1/OC3
SPA-2XOC12-POS, SPA-4XOC12-POS, SPA-8XOC12-POS, SPA-1XOC48POS/RPR, SPA-2XOC3-POS,
SPA-2XOC48POS/RPR, SPA-4XOC48POS/RPR, SPA-OC192POS-XFP SPA-4XOC3-POS,
SPA-1XOC3-ATM-V2, SPA-3XOC3-ATM-V2, SPA-1XOC12-ATM-V2 SPA-1XOC12-POS
SPA-DSP SPA-2X1GE-SYNCE
SPA-1CHOC3-CE-ATM, SPA-2CHT3-CE-ATM, SPA-24CHT1-CE-ATM SPA-WMA-K9
Network NIM-1MFT-T1/E1, NIM-2MFT-T1/E1, NIM-4MFT-T1/E1, NIM-8MFT-T1/E1, NIM- N/A
Interface Module 1CE1T1-PRI, NIM-2CE1T1-PRI, NIM-8CE1T1-PRI, NIM-SSD, SSD-SATA-200G, SSD-
(NIM) SATA-400G
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
What to expect - Features
1. Nearly all features in XE3.17 are supported in 16.2, except MACSec and Storm
Control which will be supported in 16.3
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
What to expect image type
XE 3.x XE 16.x
ASR1001-X Universal Image Universal Image
No
ASR1002-X - All the licenses will continue to work as is Change
- No config changes are needed besides the boot image
RP2 based platforms Reformation Image Universal Image + License boot level
IP BASE W/O CRYPTO asr1000rp2-ipbase.* asr1000rpx86-universalk9.* ipbase
IP Base asr1000rp2-ipbasek9.* asr1000rpx86-universalk9_npe.* ipbase
ADVANCED ENTERPRISE asr1000rp2-adventerprisek9_noli.* asr1000rpx86-universalk9_noli.* adventerprise
SERVICES W/O LI
ADVANCED ENTERPRISE W/O asr1000rp2-adventerprise.* asr1000rpx86-universalk9_npe.* adventerprise
CRYPTO
ADVANCED ENTERPRISE asr1000rp2-adventerprisek9.* asr1000rpx86-universalk9.* adventerprise
SERVICES
ADVANCED IP SERVICES W/O LI asr1000rp2-advipservicesk9_noli.* asr1000rpx86-universalk9_noli.* advipservices
ADVANCED IP SERVICES W/O asr1000rp2-advipservices.* asr1000rpx86-universalk9_npe.* advipservices
CRYPTO
ADVANCED IP SERVICES asr1000rp2-advipservicesk9.* asr1000rpx86-universalk9.* advipservices
2. RP2
Install the 16.3.1 universal image / reload
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Get yourself ready for a maintenance window
1. Read the IOS XE 16.3.1 Migration Guide
2. Download latest ROMmon image to the router
3. Download IOS XE 16.3.1 universal image to the router
4. Backup your router configuration
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Summary and Take away
Operating an ASR 1000
Summary and Take Away
Proactive Monitoring
FECP Mem Crypto QFP IOS CPU IOS Mem RP Mem RP CPU TCAM DRAM
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Relevant Sessions at Cisco Live 2016
Breakout Sessions
BRKARC-2001 Cisco ASR1000 Series Routers: System & Solution
Architectures
BRKARC-2031 QoS Config Migrations From Classic IOS to IOS XE
BRKCRS-3147 Advanced troubleshooting of the ASR1K and ISR 4451-X made
easy
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Complete Your Online Session Evaluation
Give us your feedback to be
entered into a Daily Survey
Drawing. A daily winner will
receive a $750 Amazon gift card.
Complete your session surveys
through the Cisco Live mobile
app or from the Session Catalog
on CiscoLive.com/us.
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Continue Your Education
Demos in the Cisco campus
Walk-in Self-Paced Labs
Lunch & Learn
Meet the Engineer 1:1 meetings
Related sessions
BRKARC-2019 2016 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Thank you