Tuesday, April 3, 2018

Cisco Nexus 7000 and Nexus 7700 Supervisor Module

Cisco Nexus 7000 and Nexus 7700 Series switches have two slots that are available for supervisor modules.

Redundancy is achieved by having both supervisor slots populated.

Table 1-6 describes different options and specifications of the supervisor modules.

Key Topic

Table 1-6 Nexus 7000 and Nexus 7700 Supervisor Modules Comparison


Nexus 7700 Supervisor 2E
Nexus 7000 Supervisor 2E
Nexus 7000 Supervisor 2
Nexus 7000 Supervisor 1
CPU
Dual Quad-Core Xeon
Dual Quad-Core Xeon
Quad-Core Xeon
Dual-Core Xeon
Speed (GHz)
2.13
2.13
2.13
1.66
Memory (GB)
32
32
12
8
Flash memory
USB
USB
USB
Compact Flash
Fiber Channel over Ethernet (FCoE) on F2 module
Yes
Yes
Yes
No
CPU Share
Yes
Yes
Yes
No
Virtual Device Contexts (VDC)
8+1 admin VDC
8+1 admin VDC
4+1 admin VDC
4
Cisco Fabric Extender (FEX) Support
64 FEX/3072 ports
64 FEX/3072 ports
32 FEX/1536 ports
32 FEX/1536 ports
Connectivity Management Processor (CMP)
Not supported
Not supported
Not supported
Supported

Cisco Nexus 7000 Series Supervisor 1 Module

The Cisco Nexus 7000 supervisor 1 module shown in Figure 1-26 is the first-generation supervisor module for the Nexus 7000. As shown in Table 1-6, the operating system runs on a dedicated dual-core Xeon processor; dual supervisor engines run in active-standby mode with stateful switch over (SSO) and configuration synchronization between both supervisors. 

There are dual redundant Ethernet out-of-band channels (EOBC) to each I/O and fabric modules to provide resiliency for the communication between control and line card processors. An embedded packet analyzer reduces the need for a dedicated packet analyzer to provide faster resolution for control plane problems. The USB ports allow access to USB flash memory devices to software image loading and recovery.

Figure 1-26 Cisco Nexus 7000 Supervisor 1 Module


The Connectivity Management Processor (CMP) provides an independent remote system management and monitoring capability. It removes the need for separate terminal server devices for OOB management, and it offers complete visibility during the entire boot process. It has the capability to initiate a complete system restart and shutdown. Administrators must authenticate to get access to the system through CMP, and it also allows access to supervisor logs and full console control on the supervisor engine.

The Cisco Nexus 7000 supervisor 1 module incorporates highly advanced analysis and debugging capabilities. The Power-on Self Test (POST) and Cisco Generic Online Diagnostics (GOLD) provide proactive health monitoring both at startup and during system operation. This is useful in detecting hardware faults. If a fault is detected, corrective action can be taken to mitigate the fault and reduce the risk of a network outage.

Cisco Nexus 7000 Series Supervisor 2 Module

The Cisco Nexus 7000 supervisor 2 module shown in Figure 1-27 is the next-generation supervisor module. As shown in Table 1-6, it has a quad-core CPU and 12G of memory compared to the supervisor 1 module, which has single-core CPU and 8G of memory. The supervisor 2E module is the enhanced version of the supervisor 2 module with two quad-core CPUs and 32G of memory.

Figure 1-27 Cisco Nexus 7000 Supervisor 2 Module



The supervisor 2 module and supervisor 2E module have more powerful CPUs, larger memory, and next-generation ASICs that together will result in improved performance, such as enhanced user experience, faster boot and switchover times, and a higher control plane scale, such as higher VDC and FEX.

Both the supervisor 2 module and supervisor 2E module support FCoE; when you are choosing the proper line card, they support CPU shares, which will enable you to carve out CPU for higher priority VDCs. Sup2E supports 8+1 VDCs. Sup2 scale is the same as Sup1; it will support 4+1 VDCs.

NOTE: You cannot mix Sup1 and Sup2 in the same chassis. Note that this will be a disruptive migration requiring removal of supervisor 1. Sup2 and Sup2E can be mixed for migration only. This will be a nondisruptive migration.

Cisco Nexus 7000 and Nexus 7700 Fabric Modules

The Nexus 7000 and Nexus 7700 fabric modules provide interconnection between line cards and provide fabric channels to the supervisor modules. The Nexus 7000 has five fabric modules, and the Nexus 7700 has six; adding fabric modules increases the available bandwidth per I/O slot because all fabric modules are connected to all slots. Figure 1-28 shows the different fabric modules for the Nexus 7000 and Nexus 7700 products.

Figure 1-28 Cisco Nexus 7000 Fabric Module


In the case of Nexus 7000, when using Fabric Module 1, which is 46 Gbps, you can deliver a maximum of 230 Gbps per slot using five fabric modules. When using Fabric Module 2, which is 110 Gbps, you can deliver a maximum of 550 Gbps per slot. In Nexus 7700, by using Fabric Module 2, which is 220 Gbps per slot, you can deliver a maximum of 1.32 Tbps per slot.

All fabric modules support load sharing, and the architecture supports lossless fabric failover. In case of a failure or removal of one of the fabric modules, the remaining fabric modules will load balance the remaining bandwidth to all the remaining line cards.

Nexus 7000 supports virtual output queuing (VOQ) and credit-based arbitration to the crossbar to increase performance. VOQ and credit-based arbitration allow fair sharing of resources when a speed mismatch exists to avoid head-of-line (HOL) blocking.

The Nexus 7000 implements a three-stage crossbar switch. Fabric stage 1 and fabric stage 3 are implemented on the line card module, and stage 2 is implemented on the fabric module. Figure 1-29 shows how these stages are connected to each other. There are four connections from each fabric module to the line cards, and each one of these connections is 55 Gbps. When populating the chassis with six fabric modules, the total number of connections from the fabric cards to each line card is 24. It provides an aggregate bandwidth of 1.32 Tbps per slot.

Figure 1-29 Cisco Nexus 7700 Crossbar Fabric


There are two connections from each fabric module to the supervisor module. These connections are also 55 Gbps. When all the fabric modules are installed, there are 12 connections from the switch fabric to the supervisor module, providing an aggregate bandwidth of 275 Gbps.

NOTE: Cisco Nexus 7000 fabric 1 modules provide two 23Gbps traces to each fabric module, providing 230 Gbps of switching capacity per I/O slot for a fully loaded chassis. Each supervisor module has a single 23Gbps trace to each fabric module.


More Related

Friday, March 30, 2018

Cisco Nexus 7000 and Nexus 7700 Series Power Supply Options

The Nexus 7000 and Nexus 7700 use power supplies with +90% power supply efficiency, reducing power wasted as heat and reducing associated data center cooling requirements. The switches offer different types of redundancy modes. They offer visibility into the actual power consumption of the total system, as well as modules enabling accurate power consumption monitoring, for the right sizing of power supplies, UPSs, and environmental cooling. Variable-speed fans adjust dynamically to lower power consumption and optimize system cooling for true load.
  • Power redundancy: Multiple system-level options for maximum data center availability.
  • Fully hot-swappable: Continuous system operations; no downtime in replacing power supplies.
  • Internal fault monitoring: Detects component defect and shuts down unit.
  • Temperature measurement: Prevents damage due to overheating (every ASIC on the board has a temperature sensor).
  • Real-time power draw: Shows real-time power consumption.
  • Variable fan speed: Automatically adjusts to changing thermal characteristics; lower fan speeds use lower power.
Cisco Nexus 7000 and Nexus 7700 Series 3.0kW AC Power Supply Module
The 3.0kW AC power supply shown in Figure 1-30 is designed only for the Nexus 7004 chassis and is used across all the Nexus 7700 Series chassis. It is a single 20-ampere (A) AC input power supply. When connecting to high line nominal voltage (220 VAC) it will produce a power output of 3000W; connecting to low line nominal voltage (110 VAC) will produce a power output of 1400W.
Figure 1-30 Cisco Nexus 7000 3.0kW AC Power Supply

NOTE: Although the Nexus 7700 chassis and the Nexus 7004 use a common power supply architecture, different PIDs are used on each platform. Therefore, if you interchange the power supplies, the system will log an error complaining about the wrong power supply in the system; although technically this might work, it is not officially supported by Cisco.
Cisco Nexus 7000 and Nexus 7700 Series 3.0kW DC Power Supply Module
The 3.0kW DC power supply shown in Figure 1-31 is designed only for the Nexus 7004 chassis and is used across all the Nexus 7700 Series chassis. The Nexus 3.0kW DC power supply has two isolated input stages, each delivering up to 1500W of output power. Each stage uses a –48V DC connection. The unit will deliver 1551W when only one input is active and 3051W when two inputs are active.
Figure 1-31 Cisco Nexus 7000 3.0kW DC Power Supply

Cisco Nexus 7000 Series 6.0kW and 7.5kW AC Power Supply Modules
The 6.0kW and 7.5kW power supplies shown in Figure 1-32 are common across Nexus 7009, 7010, and 7018. They allow mixed-mode AC and DC operation, enabling migration without disruption and providing support for dual environments with unreliable AC power, with battery backup capability.
Figure 1-32 Cisco Nexus 7000 6.0kW and 7.5kW Power Supplies

Table 1-10 shows the specifications of both power supplies with different numbers of inputs and input types.
Table 1-10 Nexus 7000 and Nexus 7700 6.0kW and 7.5kW Power Supply Specifications
Power Supply Type
Number of Inputs
Input Power
Output
6.0kW
Single input
220V
3000W
110V
1200W
Dual input
220V
6000W
110V
2400W
Dual input
110 and 220V
4200W
7.5kW
Single input
220V
3750W
Dual input
220V
7500W
Cisco Nexus 7000 Series 6.0kW DC Power Supply Module
The 6kW DC power supply shown in Figure 1-33 is common to the 7009, 7010, and 7018 systems. The 6kW has four isolated input stages, each delivering up to 1500W of power (6000W total on full load) with peak efficiency of 91% (high for a DC power supply). The power supply can be used in combination with AC units or as an all DC setup. It supports the same operational characteristics as the AC units:
  • Redundancy modes (N+1 and N+N)
  • Real-time power—actual power levels
  • Single input mode (3000W)
  • Online insertion and removal
  • Integrated lock and On/Off switch (for easy removal)
Figure 1-33 Cisco Nexus 7000 6.0kW DC Power Supply

Multiple power redundancy modes can be configured by the user:
  • Combined mode, where the total power available is the sum of the outputs of all the power supplies installed. (This is not redundant.)
  • PSU redundancy, where the total power available is the sum of all power supplies minus one, otherwise commonly called N+1 redundancy.
  • Grid redundancy, where the total power available is the sum of the power from only one input on each PSU. Each PSU has two supply inputs, allowing them to be connected to separate isolated A/C supplies. In the event of an A/C supply failure, 50% of power is secure.
  • Full redundancy, which is the combination of PSU redundancy and grid redundancy. You can lose one power supply or one grid; in most cases this will be the same as grid redundancy.
Full redundancy provides the highest level of redundancy, so it is recommended. However, it is always better to choose the mode of power supply operation based on the requirements and needs.
An example of each mode is shown in Figure 1-34.
Figure 1-34 Nexus 6.0kW Power Redundancy Modes

To help with planning for the power requirements, Cisco has made a power calculator that can be used as a starting point. It is worth mentioning that the power calculator cannot be taken as a final power recommendation.
The power calculator can be found at http://www.cisco.com/go/powercalculator.


More Related

Tuesday, March 13, 2018

FEC/Forward Error Correction Enables 40km Reach QSFP28 100Gb Pluggable Optical Transceivers

FEC (Forward Error Correction) is used in many forms of data communication. You’ll find it in wireless networks, space communication, undersea fiber optic networks, bar code scanners, and your CD player (if you still have one).


In this article it shows that FEC enables longer reach in a new pluggable optical transceiver. (QSFP100 “ER4-Lite”, it is a new addition to the Cisco “QSFP100” product family, as it’s in a QSFP28 form factor, and is great for data center interconnects up to 40km reach without optical amplification.)

You might also be wondering why we need a “Lite” version, when we already have a 40km IEEE standardized “100GBASE-ER4” transceiver. It turns out the laser power and receiver sensitivity required by the IEEE standard make it more expensive and requires the larger CFP form factor. In contrast, QSFP100 ER4-Lite uses components with relaxed specifications and consumes less power, so it can fit in a QSFP28 form factor. This is a much better size for high density data center applications. And it can still support 40km reach as long as the host platforms at both ends encode and decode FEC.

FEC on host platforms is not that new. It’s actually required by IEEE 100GBASE-SR4 and other non-IEEE optical interface standards such as the CWDM4 MSA and the PSM4 MSA. So all Cisco switches and routers with QSFP28 ports have it.

For those who need to link to other systems already in place, the QSFP100 ER4-Lite interoperates with CPAK ER4-Lite, IEEE 100GBASE-ER4, and IEEE 100GBASE-LR4 at reaches identified in the figure below. 


These don’t use FEC, so make sure to have it turned off at both ends.
More information on Cisco’s QSFP100 ER4-Lite transceiver module is available on the QSFP100 product family data sheet.



More Related

Tuesday, January 30, 2018

SSD or HDD? Find it Out

SSD and HDD are the two storage components for the computers. When you're building or upgrading your PC, and you get to the business of storage, what should you go for? Building a PC can be hard enough before you get as far as thinking about what storage you're going to have inside it. But when you do get there, it's one of the most important parts of the build and a crucial thing to get right.
You can go for a Solid State Drive (SSD) or a more traditional Hard Disk Drive (HDD). There are merits to both, but what's going to be best for your build, and your budget?

What's the difference between the two?

In its simplest form, an SSD is flash storage and has no moving parts whatsoever. As a result, they're smaller and take up less space in a PC case, in some cases even mounting directly to the motherboard. SSD storage is much faster than its HDD equivalent.

HDD storage is made up of magnetic tape and has mechanical parts inside. They're larger than SSDs and much slower to read and write.

Why use an SSD?
If you're building a PC for any purpose, you're going to want speed. If you only have HDD storage in your machine, then speed isn't something coming your way. Windows will take longer to boot up, applications will take longer to load, files will take longer to open and save.

The beauty of an SSD is that this waiting time is dramatically reduced, even on cheaper drives, when compared to HDD. Anything you load on it will perform actions much quicker.

One of the best uses for an SSD in a PC is as a boot drive. This means installing a small-ish capacity drive on which your Windows 10 operating system will live and boot up from every day. By doing this, your PC will boot up and be ready to go in a flash. You can also put your most frequently used software on there for a similar effect.

The lifespan of an SSD isn't as lengthy as that of a HDD, but you can certainly use an SSD as your only drive in a PC. Many laptops only have SSD storage, for example. You're not looking at a short-term life, but compared to HDD storage it is reduced. SSDs don't handle being written to as well over time, but a boot drive wouldn't suffer this.

SSD prices have come down a lot in recent times, too, with the price per gigabyte much lower than it once was. Large capacity drives are still expensive, as are the highest performing ones, but generally speaking, they're more affordable than ever.

Why use a HDD?
The best case for HDD is mass storage. This type of drive is cheaper than SSD and available in some quite massive sizes. Have a lot of games or media to keep on your PC? No problem, you can get one or more drives over 1TB in size for a fraction of the cost of their SSD equivalents.

PC cases usually have space for more than one drive, meaning you can stack up as much mass storage as you can stash and your budget will allow.

Price per gigabyte is still much less than SSDs, and large capacity drives won't take all your money. 
An efficient system would have an SSD to boot Windows from and one or more HDDs for mass storage.

Our ultimate recommendation is to opt for a mixed system with HDD mass storage and an SSD boot drive for your Windows 10 install. This way you'll get a balance of price, performance, and space, and you'll have a well-rounded machine for all occasions.


More Related

More Info from

Friday, January 12, 2018

Top 10 features to Consider While Purchasing a Switch for Your Small Business

A reliable network is the foundation for any successful business. The network switch, a key cornerstone of any network, connects all the computers, printers, servers, and storage devices in your office, giving your employees access to shared resources.

A reliable network switch keeps data traffic moving efficiently, keeps unauthorized users from accessing sensitive data and allows you to add new users as your business grows.

Yes, the ideal switch will protect your small business network and give your company room to grow. 


Here’s a list of the Top 10 features to consider when purchasing a switch:
  1. Easy to configure: Look for a switch that provides common configurations for all the devices you might connect it to, including PCs, printers, and IP phones. For example, Cisco Smartports technology lets you click on a port and assign a configuration for a device, such as for an IP Phone. The switch then automatically configures that port to support the phone.
  2. Easy to manage: A managed switch gives you more control over the traffic traveling in and out of your network. Make sure it offers a Web-based user interface so you can easily handle setup, security, and traffic prioritization. The switch should also include an easy-to-use device discovery tool to help connect it to other devices on your network. Also look for advanced features such as remote management and online software upgrades.
  3. Energy efficiency: Switches consume a surprising amount of energy because they’re always on. Make sure you find one with features that optimize power use, such as a fanless chassis. A “green” switch can help you save money by cutting back on utility bills, so it’s good for your business as well as the environment.
  4. Power-over-Ethernet ports: A switch with power-over-Ethernet (PoE) ports instantly becomes another source of power in your office. PoE, also called “in-line power,” lets the switch provide electricity to networked-attached devices, such as video cameras, IP phones, wireless access points, point-of-sale devices, or security card readers. Using PoE switches gives you more placement options for devices and eliminates the need for separate power supplies, as well as the costs of running additional cable and circuits.
  5. Quality-of-Service (QoS) support: QoS gives priority to certain types of network traffic, such as real-time voice data. For example, QoS gives priority to telephone traffic over e-mail traffic, ensuring that the quality of a phone call isn’t degraded when someone downloads a large file.
  6. Security features: I can’t stress enough the importance of network security, and a switch with built-in security features is a must-have in order to protect a business’s vital data. A Look for a switch that includes the following:
    • embedded security for encrypting network communications
    • access control lists (ACLs) for restricting areas of the network from unauthorized users and guarding against network attacks
    • virtual LANS (VLANs) for segmenting the network to separte work groups or grant visitors access to the Internet without giving them access toall areas of your network.
  7. Support for IPv6: This is the newest version of the Internet Protocol (IP), which is the technology computers use to send data to each other over the Internet. Purchasing a switch that supports IPv6 now ensures that it will continue to work with next-generation networking applications, operating systems, and other devices as they become available.
  8. Expandability: Choose a switch that can grow with your business. As your business grows and you’ll need to support more users and devices, your network needs to be able to support that growth and maintain a high level of performance.  
  9. Interoperability: Getting locked into one vendor for all your technology needs is a concern for many small businesses. Choose switches that are built to work with other devices and are part of proven designs.  This will protect your investment long into the future.
  10. Support for multiple native languages: Your switch should be able to be used in any location by any employee, regardless of the local language. For a switch to offer true multiple language support, the user interfaces and documentation should be translated in several languages, including English, French, German, Italian, Spanish, Japanese, and simplified Chinese.
Of course, your criteria for purchasing a switch will vary, but these Top 10 features will serve as a solid baseline when researching your options.

Have you purchased or researched a switch lately? How do these features stack up against your criteria?

The info from

More Switch Topics you can read here: http://blog.router-switch.com/category/technology/switch/



Tuesday, December 19, 2017

How to Recover the Catalyst 9300 Password?

The common question: “How to recover the password on Cisco Catalyst switches, such as Catalyst 2960, 3750-X, 3650 switches, Catalyst 3850 series and the new Catalyst 9000 switches?”

Here we’d like to share an example of recovering the password on Catalyst 9300 switches. This example has been posted in Cisco’s communities

It is the same as Catalyst 3850.



Power cycle the switch. Immediately press and hold the Mode button. Hold the button till the Status LED will go amber. Then on the console you should be in Boot Loader.
Switch:

Add the following variables.
Switch: SWITCH_IGNORE_STARTUP_CFG=1

Then boot the switch.

Switch: boot

Once the switch has booted you can copy the saved config back into the running config.

Switch# copy start runn

Next set your password(s). Finally we want to remove the variables we set while in Boot Loader.

Switch# no system ignore startupconfig switch all

Save your new config.

Switch# copy runn start


Info from https://communities.cisco.com/thread/85760

Learn more:


Wednesday, November 29, 2017

UTM vs. NGFW in the Enterprise

UTM (unified threat management) products or a next-generation firewall (NGFW)? That’s a question. You may not distinguish between UTM and NGFW. Here we’d like to share the article “UTM vs. NGFW in the enterprise” written by Kevin Beaver from techtarget.com. What’s your opinion about this topic?

UTM vs. NGFW in the enterprise


When it comes to unified threat management systems, there are three main considerations I have seen during my work in the field. First, given the form factor, the feature list of a UTM system is impressive: firewalling, intrusion prevention, VPN, email content filtering, network activity monitoring, malware protection and even data loss prevention (DLP).

In many situations, getting these important security capabilities in one package is the only way to justify implementation; purchasing standalone products for each area is just too costly. That said, enterprises are probably not going to get the absolute best technology for each of the security areas. Many vendors like to the think they're the best at everything they offer, but experience has proven otherwise.

Second, each unique security system, application and console an organization has to monitor takes away from other work. Having to learn the interfaces, reporting, etc. for each of the vendor's products can be just as much of a distraction. A single interface can be one of the greatest selling points of unified threat management systems.

Lastly, enterprises must consider whether the specific configuration will be a single point of network (and security) failure or not. If so, how will this be addressed? Hardware and software are fairly resilient these days, but there's also the human component -- someone doing something incorrectly or at the wrong time may take the system down.

That said, there a few considerations around NGFWs I see regularly in my work. First, NGFW granular application layer features can help monitor and control the most complex of applications and malware.

Additionally, presumably more mature threat intelligence is available given the prevalence of NGFWs across large enterprises and large government agencies.

The potential expense of NGFWs--in both initial capital expenditures and ongoing operational costs--is a drawback of the technology. It has been my experience that the larger the vendor, the prouder it is of its products and service.

Lastly, if an organization has a person (or team) managing its NGFW(s), then who's managing the security controls for other security needs, such as DLP, VPN, email content filtering and the like? Enterprises will likely have dedicated resources for those, which is good, as they really need them to manage such diverse systems.

In UTM marketing circles, one of the common selling points is that UTM is good for SMBs. If a company is trying to figure out whether a UTM system can handle its network demands, don't assume that it is only for small mom and pop shops with a handful, or perhaps a couple dozen, of employees. I see plenty of businesses and government agencies that fall into the SMB category, yet have relatively large networks and overall information system complexity that rely on a UTM for much of their security controls.

Unified threat management systems are plenty scalable and feature-rich for sizeable organizations.

Making the decision: UTM vs. NGFW
In the end, the decision on purchasing a UTM or NGFW should be based on risk and what your business needs most. The following questions can help:
  • Which risks are you attempting to mitigate? If you cannot fully answer this, you're not ready to buy just yet. Perform your risk assessment (technical and operational) and determine what's at risk and what can be done about it.
  • What are your network throughput numbers, service-level agreement requirements and unique network visibility and control needs? Prospective vendors should be able to help you map your requirements to their offerings.
  • How much time do you have to dedicate to deploying, managing and troubleshooting these systems?
  • What are the independent test lab reports, product reviews and people using these systems saying? You'll learn more about what's best for your organization this way than through any other means.
The answers to these questions could very well be contrary to what a vendor's sales engineer or account manager thinks is best for you. Only your organization knows its network best; you know what's at risk and what you're capable of doing about it. Get as many people involved as you can and gather all the right information so you can decide on the solution that best helps you meet your goals.
The best choice--UTM or NGFW--will emerge and be quite obvious. Just don't get caught up in the semantics or vendor/analyst hype. Remember, it's not wrong to choose a different product (or products) altogether.



Learn more: UTM vs. NGFW