New Features in Cisco IOS 12.4



Similar documents
Advanced ColdFusion 4.0 Application Development Server Clustering Using Bright Tiger

Setting Up Your Internet Connection

Avaya Remote Feature Activation (RFA) User Guide

TCP/IP Gateways and Firewalls

SNMP Reference Guide for Avaya Communication Manager

Chapter 3: JavaScript in Action Page 1 of 10. How to practice reading and writing JavaScript on a Web page

NCH Software BroadCam Video Streaming Server

Early access to FAS payments for members in poor health

NCH Software FlexiServer

NCH Software MoneyLine

Teach yourself Android application development - Part I: Creating Android products

Cisco Certified Network Associate Exam. Operation of IP Data Networks. LAN Switching Technologies. IP addressing (IPv4 / IPv6)

A Description of the California Partnership for Long-Term Care Prepared by the California Department of Health Care Services

NCH Software Express Accounts Accounting Software

IP SLAs Overview. Finding Feature Information. Information About IP SLAs. IP SLAs Technology Overview

NCH Software Warp Speed PC Tune-up Software

Sage Accounts Production Range

AA Fixed Rate ISA Savings


3.3 SOFTWARE RISK MANAGEMENT (SRM)

Lecture 7 Datalink Ethernet, Home. Datalink Layer Architectures

Key Features of Life Insurance

Fast Robust Hashing. ) [7] will be re-mapped (and therefore discarded), due to the load-balancing property of hashing.

Lexmark ESF Applications Guide

Transport and Network Layer

Vision Helpdesk Client Portal User Guide

COURSE AGENDA. Lessons - CCNA. CCNA & CCNP - Online Course Agenda. Lesson 1: Internetworking. Lesson 2: Fundamentals of Networking

IMPLEMENTING THE RATE STRUCTURE: TIERING IN THE FEE-FOR-SERVICE SYSTEM

DOING BUSINESS WITH THE REGION OF PEEL A GUIDE FOR NEW AND CURRENT VENDORS

How To Learn Cisco Cisco Ios And Cisco Vlan

Smart Tips. Enabling WAN Load Balancing. Key Features. Network Diagram. Overview. Featured Products. WAN Failover. Enabling WAN Load Balancing Page 1

Business Banking. A guide for franchises

Driving Accountability Through Disciplined Planning with Hyperion Planning and Essbase

"Charting the Course...

Cisco Networking Professional-6Months Project Based Training

Data Networking and Architecture. Delegates should have some basic knowledge of Internet Protocol and Data Networking principles.

MICROSOFT DYNAMICS CRM

CUSTOM. Putting Your Benefits to Work. COMMUNICATIONS. Employee Communications Benefits Administration Benefits Outsourcing

Beginning BGP. Peter J. Welcher. Introduction. When Do We Need BGP?

Let s get usable! Usability studies for indexes. Susan C. Olason. Study plan

DigitalKitbag. marketing

Income Protection Solutions. Policy Wording

NCH Software Copper Point of Sale Software

IOS NAT Load Balancing with Optimized Edge Routing for Two Internet Connections

gdoc Core Cross-platform document conversion, optimization and manipulation technology

Cisco ASA, PIX, and FWSM Firewall Handbook

Teamwork. Abstract. 2.1 Overview

Design Considerations

Health Savings Account reference guide

Lucent Technologies Bell Labs Innovations. PARTNER II Communications System PARTNER Plus Communications System Release 4.1.

ELECTRONIC FUND TRANSFERS YOUR RIGHTS AND RESPONSIBILITIES

Cisco Configuring Basic MPLS Using OSPF

CERTIFICATE COURSE ON CLIMATE CHANGE AND SUSTAINABILITY. Course Offered By: Indian Environmental Society

We are XMA and Viglen.

Income Protection Options

Cisco Which VPN Solution is Right for You?

Cisco - Catalyst 2950 Series Switches Quality of Service (QoS) FAQ

SPOTLIGHT. A year of transformation

Eaton Power Xpert Gateway PXGX UPS Card. User's Guide

TERM INSURANCE CALCULATION ILLUSTRATED. This is the U.S. Social Security Life Table, based on year 2007.

Cisco Discovery 3: Introducing Routing and Switching in the Enterprise hours teaching time

Remote Feature Activation Getting Started with Remote Feature Activation (RFA)

Introduction about cisco company and its products (network devices) Tell about cisco offered courses and its salary benefits (ccna ccnp ccie )

Interconnecting Cisco Networking Devices Part 2

WHITE PAPER BEsT PRAcTIcEs: PusHIng ExcEl BEyond ITs limits WITH InfoRmATIon optimization

Human Capital & Human Resources Certificate Programs

Course Contents CCNP (CISco certified network professional)

ICAP CREDIT RISK SERVICES. Your Business Partner

Troubleshooting and Maintaining Cisco IP Networks Volume 1

A Conversation with

Cisco Certified Network Associate (CCNA) 120 Hours / 12 Months / Self-Paced WIA Fee: $

Oracle Project Financial Planning. User's Guide Release

DISPLAYING NASDAQ LEVEL II DATA

Health Savings Account reference guide

Example of Credit Card Agreement for Bank of America Visa Signature and World MasterCard accounts

CCT vs. CCENT Skill Set Comparison

Introduction: 8x8 Referral Rewards Program

IOS NAT Load Balancing for Two ISP Connections

How To Get Acedo With Microsoft.Com

Cisco Catalyst 3750 Metro Series Switches

Oracle. L. Ladoga Rybinsk Res. Volga. Finland. Volga. Dnieper. Dnestr. Danube. Lesbos. Auditing Oracle Applications Peloponnesus

NatWest Global Employee Banking Eastwood House Glebe Road Chelmsford Essex England CM1 1RS Depot Code 028

Best Practices for Push & Pull Using Oracle Inventory Stock Locators. Introduction to Master Data and Master Data Management (MDM): Part 1

Table of Contents. Cisco Configuring a Basic MPLS VPN

Secure Network Coding with a Cost Criterion

Pay-on-delivery investing

Introduction to Routing and Packet Forwarding. Routing Protocols and Concepts Chapter 1

NCH Software PlayPad Media Player

Integrating Risk into your Plant Lifecycle A next generation software architecture for risk based

Network Simulator Lab Study Plan

NCH Software WavePad Sound Editor

Transcription:

Page 1 of 5 New Features in Cisco IOS 12.4 Peter J. Wecher Introduction I'm writing this in mid-august. Things have been hot (business, weather). That means its time for my more-or-ess annua artice about new features in Cisco IOS. I'm going to mainy cover Cisco IOS 12.4. The features in PIX 7.0 are aso very interesting, but wi have to be another whoe artice. My intent here is to ca attention to features I think are interesting, amazing, neat, or just pain usefu. There is no way this artice can be compete (hey, I do have a fu-time job, despite what some of you think about consutants, that stuff about iving a ife of uxury?). So I' refer the curious to the Cisco onine documents for the entire set of new features. About Reease 12.4 The mainine or non-t reease accumuates features in the 12.3 T and "etter" reeases. New features wi be added to the 12.4 T train of reeases, whereas 12.4 mainine is for bug fixes. Thus new features for the 12.4 mainine code is reay describing features added at some point in 12.3, ones that may be approaching the maturity required for production use. Note that I am not impying you shoud be running 12.4 code in production yet, just anticipating that you wi probaby be doing so at some point, after more of the bugs are fixed. I do have a customer aready running 12.4 code in production -- due to a need for hardware support. Most sites wi probaby wait a whie. The cumuative new features ist can be found at http://www.cisco.com/en/us/products/ps6350/prod_reease_notes_ist.htm as a Reease Note. Or off the http://www.cisco.com/go/ios page, aka http://www.cisco.com/warp/pubic/732/. If you cick on "Cisco IOS Software Major Reease 12.4" you' see inks to the new features Buetin. New Features Roed into 12.4 Mainine The Buetin at http://www.cisco.com/en/us/products/ps6350/prod_buetin09186a0080457b39.htm provides the info about new features roed up into 12.4. The foowing attempts to summarize and ca attention to items that have caught my eye. To find the detais that were necessariy omitted beow, consut this document! The 12.4 new features document ists the foowing broad areas of new features: Hardware support Broadband High avaiabiity Infrastructure IP Mobiity IP Muticast IP Routing IP Services IPv6 Management Instrumentation MPLS QoS http://www.netcraftsmen.net/wecher/papers/newios124.htm

Page 2 of 5 Security and VPN Voice Let's take a ook at some of the new features in these categories. The ist of new hardware support accumuated into 12.4 is impressive. It incudes NAM for moduar routers, the new ISR routers, Cisco Unity Express, IDS Network Modue. The engineers have stayed busy! Broadband encompasses DSL aggregation features, ties to MPLS, enhanced dia-ike features, that sort of thing. Interesting but a bit speciaized? High avaiabiity is two features: Cisco IOS Warm Upgrade, Cisco IOS IPsec statefu Faiover. In Warm Upgrade, you decompress and oad IOS to memory, greaty speeding the boot process in switching over. The new image need not be burned to fash to do this. You do need sufficient RAM to decompress the new image. Infrastructure is two items: Cisco IOS Embedded Event Manager 2.1, and Embedded Resource Manager (ERM). The former is the surrounding framework for TCL in IOS. See aso my previous artice http://www.netcraftsmen.net/wecher/papers/iostc01.htm. The idea is to detect events and then trigger oca actions within the router, namey any CLI command(s). ERM aows monitoring of interna resources, pus the "abiity to perform actions to improve performance and avaiabiity of the device", and "yieds information to aow better understanding of scaabiity requirements" (resource consumption). They even say those IBM words, "autonomic computing". IP Mobiity: support for Mobie IP through NAT (RFC 3519), some other Mobie IP enhancements, and Dynamic Security Associations and Key Distribution (i.e. Mobie IP SA's no onger have to be staticay configured in advance). IP Muticast incudes some IPv6 muticast features, MSDP enhancements per IETF MSDP Draft 20, and PIM Dense Mode Faback Prevention after RP Loss. I' skip over IPv6 as not being of genera interest (with apoogies to those in DoD or government agencies). The PIM-DM Faback Prevention feature I ike, since my feeing for quite a whie has been that one shoud engineer muticast to avoid PIM-DM even with RP oss. RP-of-ast-resort and other techniques have aowed this for a whie, but it wi be nice as a safety measure to be abe to te the router to never revert to Dense Mode. One woud expect IP Routing to be an area with many new features. One minor goodie is that routemap dispay via show commands now incudes more ACL detais. Optimized Edge Routing (OER) is an interesting new feature that may be the subject of a future whoe artice in itsef. OER is technoogy for determining best outbound route, usuay when one has two or more ISP's. It is based on NetFow and SAA. OER can dynamicay detect path faiures at the WAN edge. "... Cisco OER is unique in that it can make instant routing adjustments based on criteria other than static routing metrics: response time, packet oss, path avaiabiity, traffic oad distribution, and financia cost minimization poicies." The newest features added to OER are (monetary) cost optimization and traceroute reporting. Another new OER feature is support for poicy-rues configuration, whereby you can configure poicies and then switch between them. Yet another: support for prefix earning based on protoco ports of interest. For the detais of OER (at east unti I write that future artice), see: http://www.cisco.com/en/us/products/ps6350/products_configuration_guide_chapter09186a008046460e.htm Poicy Based Routing now supports a recursive next hop, i.e. one that is not directy connected. That makes it much easier to depoy consistent PBR across mutipe routers, without creating a routing oop. IGMPv3 Host Stack means the router can now act ike a host, aso do Source Specific Muticast. This heps with Music on Hod, aso muticast troubeshooting. There are routing protoco protections, to prevent Denia of Service via routing protoco (accidenta or deiberate). EIGRP has configurabe prefix imits and OSPF has database overoad protection, to protect against exhausting CPU or memory. You can simiary imit mroute state per-interface. This prevents for exampe home users from creating a muticast-based Denia of Service situation, for exampe. Historicay, OSPF was enabed on interfaces using the network command in router mode. OSPF can now be enabed on interfaces in interface mode, for consistency with OSPFv3. http://www.netcraftsmen.net/wecher/papers/newios124.htm

Page 3 of 5 There are a number of other routing enhancements I won't ist here (minor or more speciaized). The category IP Services encompasses a variety of items. Among these: DHCP and NAT features, many for VRF and MPLS VPN support. The feature tited "First Hop Routing Protocos Object Tracking List Support" aows you to use object tracking to trigger HSRP, VRRP, or GLBP faiover. But not just for singe objects, but tracking a ist of things. Booean operations, threshods, and weighting can aso be appied for compex faiover ogic. See my "The Missing Link" artice for an expanation of singe object tracking. It is at http://www.netcraftsmen.net/wecher/papers/missingink.htm. "Rate Based Sateite Contro Protoco (RBSCP)" provides optimizations for sateite inks, intended to repace Performance Enhancing Proxies (PEPs) and some reated probems. IP Access Lists now support fitering on IP Options if you wish. You can choose to drop seected packets, or any packets that use IP Options. You can now aso fiter on TCP fags. There are a arge number of new features reating to IPv6 and MPLS, not necessariy grouped into those sections. As I consider these somewhat speciaized, I'm not going to ist them here. I wi note that SNMP with IPv6 transport is among the new features. Under Management Instrumentation are a number of new SNMP MIBs, as one might expect. One new feature is ocking of configuration sessions, preventing others from changes during the ock. Another is fine-grained contro over which subsystems can be configured via HTTP. The feature "Bandwidth Estimation via Corvi Technoogy" is rather intriguing to me, as a practitioner of QoS. This is patented technoogy you icense for seected routers. You then configure SLAs for desired packet oss and deay bounds or characteristics, on a per-cass basis. The QoS command "show poicy interface" then dispays recommended bandwidth eves. The Corvi management software (or other appications) can pu in this info via the updated CBQoS MIB, to recommend QoS cass bandwidth eves and ink bandwidth. The caim is this takes into account the bursty nature of appications. For the data sheet, see http://www.cisco.com/en/us/tech/tk543/tk759/tech_brief0900aecd8024d5ff.htm. The new name for SAA is "IP Service Leve Agreements" or "IP SLA". The bottom ine is, this whoe area seems to be getting a ot of emphasis atey. The IP SLA capabiities now support measuring VoIP Ca Setup and VoIP Gateway deay. One way synthetic voice measurements are now avaiabe, as we MOS cacuation. The CLI is being migrated to a new simper set of commands, whie retaining support for the oder rtr commands. The accuracy has been improved from one miisecond to one-tenth of a miisecond. More efficient time stamping adds to greater accuracy of measurements. A feature caed "SAA Mutipe Operation Scheduing" aows you to easiy set up and schedue performance measurements to a group of destinations from a source router, one SNMP set or CLI command. Egress NetFow provides tracking of packets as they eave (e.g. after QoS or NAT changes). It can be used with IP and MPLS. NetFow information (and configuration) is now accessibe via an SNMP MIB. This incudes a Top N Takers and Conversations faciity, aso supported with a show command. Configuration Roback/Repace is a big dea! It aows you to send out a fu configuration. The router then generates differences, which can be viewed, and appies them to its running state. This aows you to revert to a "ast known good" configuration. The "Contextua Configuration Diff Utiity" aows you to do diff comparisons of any two config fies, e.g. in fash or any Cisco fie system. These features are aware of order-sensitive commands as we! Embedded Sysog Manager (ESM) aows correation, augmentation, fitering, and routing of sysog messages. You can customize messages, send certain messages to a specific sysog receiver, correate events within one device to imit event storms, and send SMTP notifications from the Cisco IOS device. Severa interesting new features are isted under the heading QoS. As noted above, the Corvi feature is instrumentation usefu for QoS. Severa of the QoS features refine AutoQoS. The "show auto discovery qos" dispays the recommended autoqos configuration that "auto qos" woud appy. "AutoQoS for the Enterprise" records statistics for observed traffic using NBAR, then generates a recommended QoS configuration from that. This feature ony works on PPP, Frame Reay, and ATM WAN interfaces. For more info, see the foowing URL: http://www.cisco.com/en/us/partner/products/sw/iosswre/ps5207/products_feature_guide09186a00802000a7.htm http://www.netcraftsmen.net/wecher/papers/newios124.htm

Page 4 of 5 NBAR is now enhanced to detect HTTP on ports other than 80 ("NBAR Extended Inspection for HTTP Traffic"). The feature "NBAR User-Defined Custom Appication Cassification" now aows you to define your own match criteria, based on string or byte at specific offset within the packet payoad. Source and destination ports or ranges of ports can aso be used. You can define more than 30 custom appication cassifications this way. Finay, turbo ACL's can be used on the 7200 to enhance performance where turbo ACL's and QoS are both in use. The Security and VPN category of new IOS features is arge enough I' have to eave it for another artice. It contains 62 new features! The Voice category of new features incudes ony Ca Manager Express (a big incusion). Consider however that a arge number of the other features discussed above or bypassed aso reate to voice. Switches: L2 Traceroute I hadn't noticed this switch feature unti somebody mentioned it in passing. I mention it here since you may not have noticed it either. Layer 2 traceroute works within a VLAN to show the switches and ports used to reach the destination device (MAC address). The command is "traceroute mac" or "traceroute mac ip". Layer 2 traceroute has been around for a whie! Layer 2 traceroute is in reease 12.2(18) SXE for the 6500, CatOS 6.2.1 for the 4000, 12.1(13) EW for Cat4500 SupIII/IV, and 12.1(14)EA1 for Catayst 3750, 3550, 2970, 2955, 2950, and 2950- LRE. For detais, see one of the foowing. http://www.cisco.com/en/us/products/hw/switches/ps708/products_configuration_guide _chapter09186a00804357b3.htm http://www.cisco.com/en/us/products/hw/switches/ps663/prod_buetin09186a008008886f.htm http://www.cisco.com/en/us/products/hw/switches/ps4916/prod_buetin09186a00801a759a.htm Even Newer New Features Going to the "od" documentation, I found the New Features page where it traditionay has been. See http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124newft/124_x/index.htm. Listed there: Support for two hardware modues L2TP IPsec Support for NAT/PAT Windows Cients MPLS LDP (defaut is now LDP not TDP) NBAR (a patforms) Scaabiity for Statefu NAT (hods HSRP changeover unti state information is fuy exchanged) These are aso the "Feature Guides" on the TAC documentation pages at http://www.cisco.com/en/us/products/ps6350/products_feature_guides_ist.htm. They represent features added in 12.4(1) and (3). For the adventurous, new features in the 12.4 T trains can be found at http://www.cisco.com/univercd/cc/td/doc/product/software/ios124/124newft/124t/124t2/index.htm. Or as "Feature Guides" in the new documentation pages for 12.4 T. Summary I hope this artice has been usefu, if for no other reason than to remind you that it's time once again to ook at a the features the Cisco engineers have put into the Cisco IOS. We did skip some of the "gap-fiing" features that were necessary but not so exciting, at east not unti the day you need them. I pan to write an artice about QoS in the 7600, since I've recenty spent some time carifying bits and pieces of the documentation, with some hep from various foks. Your comments, questions, and suggestions for future artices are of course wecome! See beow to decipher my emai http://www.netcraftsmen.net/wecher/papers/newios124.htm

Page 5 of 5 address. Dr. Peter J. Wecher (CCIE #1773, CCSI #94014, CCIP) is a Senior Consutant with Chesapeake NetCraftsmen. NetCraftsmen is a high-end consuting firm and Cisco Premier Partner dedicated to quaity consuting and knowedge transfer. NetCraftsmen has ten CCIE's, with expertise incuding arge network high-avaiabiity routing/switching and design, VoIP, QoS, MPLS, IPSec VPN, wireess LAN and bridging, network management, security, IP muticast, and other areas. See http://www.netcraftsmen.net for more information about NetCraftsmen. Pete's inks start at http://www.netcraftsmen.net/wecher. New artices wi be posted under the Artices ink. Questions, suggestions for artices, etc. can be sent to pjw <at> netcraftsmen <dot> net (formatted this way to foo emai harvesting software). 8/15/2005 Copyright (C) 2005 Peter J. Wecher http://www.netcraftsmen.net/wecher/papers/newios124.htm