Cisco IOS Software Release 12.2(37)SG for Cisco Catalyst 4500 Series Engines PB403891 Overview This product bulletin describes the hardware and software features supported by Cisco IOS Software Release 12.2(37)SG for the Cisco Catalyst 4500 Series Engine II-Plus, II- Plus-TS, II-Plus-10GE, IV, V, and V-10GE. Key Release Message Cisco is pleased to announce the 12.2(37)SG IOS software release for all shipping Catalyst 4500 Series IOS engines. This new release further strengthens Cisco s leadership in edge security and integration with third party devices for data and voice communications. New Software Features Multi-Domain Authentication (MDA) Multi Domain Authentication (MDA) provides enhanced security for IP phone deployments. This feature allows any vendor s IP phone with an IEEE 802.1x supplicant and a single host behind the IP phone to independently authenticate into the network. The switch places the host in the data VLAN and the IP phone in the voice VLAN respectively. For any device without an 802.1x supplicant, MAC Authentication Bypass (which was introduced in a previous software release), continues to be the fallback mechanism for authentication. MAC Authentication Bypass for Voice VLAN MAC Authentication Bypass (MAB) for Voice VLAN allows any vendor s IP phone without an 802.1x supplicant to authenticate into the network. It builds on the existing MAC authentication bypass that allows data devices such as printers and fax machines to be authenticated. With the MAB for voice VLAN feature, the switch transparently initiates a conversation with the AAA server on behalf of the IP phone to authenticate it into the voice VLAN, based on the MAC address of the IP phone. This feature is typically deployed for one phone and one host behind the phone.. It is not applicable to other situations where multiple devices may appear on a port. IP Source Guard for Static Hosts IP Source Guard (IPSG) for static hosts extends the IPSG capability to non-dhcp and static environments. The existing IP Source Guard (IPSG) feature uses the entries created by the DHCP snooping feature to validate the hosts connected to a switch. Any traffic received from a host without a valid DHCP binding entry is dropped. In essence, a DHCP environment is a prerequisite for IPSG to work. The IPSG for static hosts feature removes IPSG s dependency on DHCP. The switch creates static entries based on ARP requests and uses them to maintain the list of valid hosts for a given port. In addition, the user can specify the number of hosts that would be allowed to send traffic to a given port. This is equivalent to port-security at Layer 3. All contents are Copyright 1992 2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 1 of 7
Selective DBL Selective DBL (Dynamic Buffer Limiting) is a Catalyst 4500 innovation that allows granular control over the traffic that can be dropped in a congested network. Traditional DBL (Dynamic buffer limiting) achieves AQM or active queue management by penalizing only those flows that the switch identifies as being rogue flows (instead of dropping random flows to avoid congestion). Selective DBL goes a step further and allows the user to choose the flows that would be subjected (or would not be subjected) to the DBL algorithm. For example, if the user decided to use DBL only for low priority data traffic and not for any voice traffic, he/she can achieve that by enabling DBL only for the traffic with a certain QoS(Cos or DSCP) value. In this example, even though there might be excessive voice flows, DBL would leave all the voice traffic untouched and apply DBL based dropping or marking only for the non-voice rogue flows. SVI Autostate Exclude SVI Autostate Exclude mode allows users to specify ports to be excluded from the following autostate calculation. The Layer 3 interface of a VLAN (the SVI) remains up and is advertised in the routing table if at least one port in the VLAN is active. When the last port on a VLAN goes down, the Layer 3 interface (SVI) for that VLAN is shut down However, if appliances such as load balancers or firewall servers are connected to a port in a certain VLAN, those ports can be configured to be excluded from the autostate feature. This helps ensure that if all other ports in a given VLAN, except the ones connected to a load -balancer or a sniffer, become inactive, the SVI for the VLAN goes down and its routing table entry is removed. To summarize, the excluded ports will not affect the state of the SVI for a given VLAN. BGP Route-Map Continue The BGP Route-Map Continue feature introduces the continue clause to Border Gateway Protocol (BGP) route-map configuration. The continue clause provides more programmable policy configuration and route filtering. It introduces the capability to execute additional entries in a route map after an entry is executed with successful match and set clauses. Continue clauses allow to configure and organize more modular policy definitions to reduce the number of policy configurations that are repeated within the same route map. This feature can be used for both inbound and outbound policies. Cisco IOS Software Packaging for the Cisco Catalyst 4500 Series A new Cisco IOS Software package for Cisco Catalyst 4500 Series switches was introduced in Cisco IOS Software Release 12.2(25)SG. It is a new foundation for features and functionality, and provides consistency across all Cisco Catalyst switches. The new Cisco IOS Software release train is designated as 12.2SG. Prior Cisco Catalyst 4500 Series IOS software images, formally known as Basic Layer 3 and Enhanced Layer 3, now map to IP and Enterprise Services respectively. BGP is now included in the Enterprise Services image All currently shipping Cisco Catalyst 4500 software features based on Cisco IOS Software are supported in the IP image of Release 12.2(37)SG with a few exceptions: The IP image does not support enhanced routing features such as NSF/SSO, BGP, EIGRP, OSPF, IS-IS, Internetwork Packet Exchange (IPX), Appletalk, VRF-lite, and Policy-base Routing (PBR). The IP image supports EIGRP-Stub for limited routing on Cisco Catalyst 4500 Series All contents are Copyright 1992 2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 2 of 7
Engines II-Plus, II-Plus-TS, II-Plus-10GE, IV, V, and V-10GE. For more information on EIGRP-Stub functionality, reference the following white paper: http://www.cisco.com/en/us/tech/tk365/technologies_white_paper0900aecd8023df6f.shtml. The Enterprise Services image supports all Cisco Catalyst 4500 Series software features based on Cisco IOS Software, including enhanced routing. Customers planning to enable BGP for Engine IV, V, or V-10GE will no longer need to purchase a separate BGP license (FR- IRC4) as BGP is included in the Enterprises Services package. Table 1 shows a more detailed description of the feature differences between the IP and Enterprise Services (ES) images as they relate to the Cisco Catalyst 4500 Series Engines. Table 1. Feature Comparison for Cisco IOS Software Release 12.2(37)SG IP and Enterprise Services Feature Engine II- Plus, II-Plus- TS, II-Plus- 10GE: IP Engine IV: IP Engine IV: ES Engine V: IP Engine V: ES Engine V- 10GE: IP Engine V- 10GE: ES ISSU Yes* Yes* Yes* Yes* Yes* Yes* Yes* Network Admission Control (NAC) v2.0 RIP and Static Route NetFlow v1, v5, or v8 No Yes Yes Yes Yes Yes Yes EIGRP No No Yes No Yes No Yes EIGRP-Stub OSPF/IS-IS No No Yes No Yes No Yes BGP No No Yes No Yes No Yes NSF-Aware No No Yes No Yes No Yes NSF-Aware EIGRP-Stub NSF/SSO No No Yes No Yes No Yes SSO Aware HSRP VRF-lite No No Yes No Yes No Yes AppleTalk No No Yes No Yes No Yes IPX No No Yes No Yes No Yes PBR No No Yes No Yes No Yes *ISSU is not supported on II-Plus-TS. ISSU requires a separate paper license. Refer to Table 3 for more details. Cisco Catalyst 4500 Cisco IOS Software Migration Guide Figure 1 displays the Cisco IOS Software Release 12.2(37)SG plan relative to the 12.2S release train and identifies the recommended migration path. Note that 12.2(37)SG will not be the base release for a new maintenance train. Currently, the Catalyst 4500 platform has two active maintenance trains: 12.2(25)EWA and 12.2(31)SGA. All contents are Copyright 1992 2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 3 of 7
Figure 1. Cisco IOS Software Release Plan for the Cisco Catalyst 4500 Series Summary of Migration Plan: Customers requiring the latest Cisco Catalyst 4500 Series hardware and software features should migrate to Cisco IOS Software Release 12.2(37)SG. Cisco IOS Software Release 12.2(31)SGA will continue offering maintenance releases. The latest release from the 12.2(31)SGA maintenance train is 12.2(31)SGA1. Cisco IOS Software Release 12.2(25)EWA will continue offering maintenance releases. The latest release from the 12.2(25)EWA maintenance train is 12.2(25)EWA9. Cisco IOS Software Release 12.2(18)EW is now EoS. Support Support for Cisco IOS Software Release 12.2(37)SG follows the standard Cisco support policy, available at http://www.cisco.com/en/us/products/products_end-of-life_policy.html. For more information about the Cisco Catalyst 4500 Series, visit http://www.cisco.com/univercd/cc/td/doc/product/lan/cat4000/index.htm. All contents are Copyright 1992 2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 4 of 7
Ordering Information Tables 2, 3, and 4 provide product numbers and ordering information for Cisco IOS Software Release 12.2(37)SG and supporting hardware. Table 2. Cisco IOS Software Release 12.2(37)SG Product Numbers and Images Product Number Description Image S45IPB-12237SG(=) S45IPBK9-12237SG(=) S45ES-12237SG(=) S45ESK9-12237SG(=) Cisco IOS Software for the Cisco Catalyst 4500 Series Engines II-Plus, II-Plus-TS, II-Plus-10GE, IV, V, and V-10GE (IP image) Cisco IOS Software for the Cisco Catalyst 4500 Series Engines II-Plus, II-Plus-TS, II-Plus-10GE, IV, V, and V-10GE (IP image with Triple Data Encryption Standard [3DES]) Cisco IOS Software for the Cisco Catalyst 4500 Series Engines IV, V, and V-10GE (Enterprise Services image with BGP support) Cisco IOS Software for the Cisco Catalyst 4500 Series Engines IV, V, and V-10GE (Enterprise Services image with 3DES and BGP support) Cat4500-ipbase-mz Cat4500-ipbasek9-mz Cat4500-entservices-mz Cat4500-entservicesk9-mz Table 3. Cisco Catalyst 4500 ISSU Paper Licenses (One per Chassis) Product Number FR45-ISSU-LIC(=) FR45-ISSU-POE-LIC Description Catalyst 45xxR Series ISSU paper license. Requires dual supervisors. Catalyst 45xxR Series ISSU promotional PoE paper license. Requires dual supervisors and at least 48-port PoE ports in a new factory configured system. Table 4. Cisco IOS Software Release 12.2(37)SG Hardware Support Product Number WS-X4013+ WS-X4013+/2 WS-X4013+TS WS-X4013+10GE WS-X4013+10GE/2 WS-X4515 WS-X4515/2 WS-X4516 WS-X4516/2 WS-X4516-10GE WS-X4516-10GE/2 WS-C4503 WS-C4506 WS-C4507R WS-C4510R WS-X4124-FX-MT(=) WS-X4124-RJ45(=) WS-X4148-FX-MT(=) WS-X4148-FE-LX-MT(=) WS-X4148-RJ(=) WS-X4148-RJ21(=) Description Cisco Catalyst 4500 Series Engine II-Plus Cisco Catalyst 4500 Series Redundant Engine II-Plus Cisco Catalyst 4503 Series Engine II-Plus-TS Cisco Catalyst 4500 Series Engine II-Plus-10GE Cisco Catalyst 4500 Series Redundant Engine II-Plus-10GE Cisco Catalyst 4500 Series Engine IV Cisco Catalyst 4500 Series Redundant Engine IV Cisco Catalyst 4500 Series Engine V Cisco Catalyst 4500 Series Redundant Engine V Cisco Catalyst 4500 Series Engine V-10GE Cisco Catalyst 4500 Series Redundant Engine V-10GE Cisco Catalyst 4503 Switch chassis Cisco Catalyst 4506 Switch chassis Cisco Catalyst 4507R Switch chassis Cisco Catalyst 4510R Switch chassis Cisco Catalyst 4500 Series 24-port Fast Ethernet switching module, 100BASE-FX multimode fiber (MMF), MTRJ Cisco Catalyst 4500 Series 24-port 10/100 module (RJ-45) Cisco Catalyst 4500 Series 48-port Fast Ethernet switching module, 100BASE-FX, MMF, MTRJ Cisco Catalyst 4500 Series 48-port Fast Ethernet switching module, 100BASE-LX10 singlemode fiber, MTRJ Cisco Catalyst 4500 Series 48-port 10/100 module (RJ-45) Cisco Catalyst 4500 Series 48-port 10/100 module, telco (4xRJ-21) All contents are Copyright 1992 2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 5 of 7
WS-X4148-RJ45V(=) WS-X4148-FE-BD-LC(=) WS-X4224-RJ45V(=) WS-X4232-GB-RJ(=) WS-X4232-RJ-XX(=) WS-X4248-FE-SFP(=) WS-X4248-RJ45V(=) WS-X4248-RJ21V(=) WS-X4424-GB-RJ45(=) WS-X4306-GB (=) WS-X4302-GB (=) WS-X4412-2GB-T (=) WS-X4418-GB (=) WS-X4448-GB-RJ45 (=) WS-X4448-GB-SFP (=) WS-X4506-GB-T (=) WS-X4524-GB-RJ45V (=) WS-X4548-GB-RJ45 (=) WS-X4548-GB-RJ45V (=) WS-U4504-FX-MT (=) WS-G5483= WS-G5484 (=) WS-G5486 (=) WS-G5487 (=) MEM-C4K-FLD64M (=) MEM-C4K-FLD128M (=) PWR-C45-4200ACV PWR-C45-2800ACV PWR-C45-1400DC PWR-C45-1400DC-P PWR-C45-1400AC PWR-C45-1300ACV PWR-C45-1000AC CWDM-GBIC-xxxx DWDM-GBIC-xx.yy DWDM-SFP-xx.yy WDM-GBIC-REC= WS-F4531(=) Cisco Catalyst 4500 Series 48-port inline power 10/100 module (RJ-45) Cisco Catalyst 4500 Series 48-port 100BASE-BX10-D line card Cisco Catalyst 4500 Series 24-port Power over Ethernet (PoE) 10/100 module (RJ-45) Cisco Catalyst 4500 Series 32-port 10/100 (RJ-45), 2-port Gigabit Ethernet module (GBIC) Cisco Catalyst 4500 Series 32-port 10/100 (RJ-45) with modular uplink slot Cisco Catalyst 4500 Series 48-port 100BASE-X (SFP optics optional) Cisco Catalyst 4500 Series 48-port PoE 10/100 (RJ-45) Cisco Catalyst 4500 Series 48-port PoE 10/100, telco (4xRJ-21) Cisco Catalyst 4500 Series 24-port 10/100/1000 module (RJ-45) Cisco Catalyst 4500 Series 6-port Gigabit Ethernet module (GBIC) Cisco Catalyst 4500 Series 2-port Gigabit Ethernet line card (GBIC) Cisco Catalyst 4500 Series 12-port Gigabit Ethernet module, 1000BASE-T (RJ-45) with two 1000BASE-X GBICs Cisco Catalyst 4500 Series 18-port Gigabit Ethernet module, server switching (GBIC) Cisco Catalyst 4500 Series 48-port 10/100/1000 module (RJ45) Cisco Catalyst 4500 Series 48-port 1000BASE-X (SFP optics optional) Cisco Catalyst 4500 Series 6-port alternatively wired 10/100/1000 PoE or 1000BASE-X, SFP optics Cisco Catalyst 4500 Series 24-port PoE 10/100/1000 line card (RJ-45) Cisco Catalyst 4500 Series 48-port 10/100/1000 line card (RJ45) Cisco Catalyst 4500 Series 48-port PoE 10/100/1000 line card (RJ45) Cisco Catalyst 4500 Series 4-port uplink daughter card 100BASE-FX (MTRJ) 1000BASE-T GBIC 1000BASE-SX short-wavelength GBIC (multimode only) 1000BASE-LX/LH long-haul GBIC (single-mode or multimode) 1000BASE-ZX extended-reach GBIC (single-mode) Cisco Catalyst 4500 Series Compact Flash, 64-MB option Cisco Catalyst 4500 Series Compact Flash, 128-MB option Cisco Catalyst 4500 4200W AC dual input power supply (data + PoE) 2800W AC power supply for Cisco Catalyst 4503, 4506, and 4507R chassis Cisco Catalyst 4500 Series 1400W DC power supply Cisco Catalyst 4500 Series 1400W DC power supply with integrated PEM Cisco Catalyst 4500 Series 1400W AC power supply (data only) 1300W AC power supply for Cisco Catalyst 4503, 4506, and 4507R chassis 1000W AC power supply for Cisco Catalyst 4503, 4506, and 4507R chassis (data only) Cisco 1000BASE coarse wavelength-division multiplexing (CWDM) xxxx nm GBIC, where xxxx is the number 1470, 1490, 1510, 1530, 1550, 1570, 1590, or 1610 Cisco 1000BASE dense wavelength-division multiplexing (DWDM) ITU 100-GHz grid 15xx.yy nm GBIC Cisco 1000BASE dense wavelength-division multiplexing (DWDM) ITU 100-GHz grid 15xx.yy nm SFP Cisco receive-only 1000BASE-WDM GBIC NetFlow Services Card for Cisco Catalyst 4500 Series Engines IV and V All contents are Copyright 1992 2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 6 of 7
Printed in USA C25-403891-00 04/07 All contents are Copyright 1992 2007 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 7 of 7