Catalyst 6500 Update
Total Page:16
File Type:pdf, Size:1020Kb
Catalyst 6500 update Per Jensen [email protected] DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential 1 Agenda • SUP2T + software update • 12.2(33)SXI4 update • 12.2(33)SXJ update DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential The New 2 Terabit Catalyst 6500-E Sup2T and 6513-E 69xx Series 80Gbps 68xx/67xx Service Modules 8p 10G Series 40Gbps WiSM-2 4p 40G/16p 10G 1GbE Fiber: 24p/48p ASM-SM Built-in DFC4 10/100/1000: 48p NAM-3 10GBASE-T: 16p ACE-30 Early Adopter Release: 10G Fiber: 16p Feature Parity with 12.2(33)SXI3 Built-in DFC4 Innovation Cat6500-E Investment Protection ALL E-Series Upgrade Option All 61XX Legacy Service Chassis for 67xx Line Cards POE/ POE+ Modules © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3 Performance with Network Services 4T VSS (with Quad-Sup VSS*) VSS 4T 40G Ready Next Gen Cat6k/ Tunnels, L3VPNomGRE CORE Sup2T L3SGT For TrustSec Interoperability OTV, Trill Ready Sampled Netflow 4T VSS VSS 4T Integrated NG Svcs (WisM2, ASA, NAM, Next Gen Cat6k/ ACE-30), Multicast HA Sup2T Smart Install Director* OTV, Trill Ready Flexible Netflow, Egress Netflow DISTRIBUTION DISTRIBUTION TrustSec Next Gen EnergyWise Cat4k/ Sup7-E NGPoE (60W) Ready Cat3k/ 3750X Flexible Netflow ACCESS Cat2K/2960S IPv6 First Hop Sec. Secure Robust Simple VDI Ready Resilient Virtualized Video Optimized Turn Key IPv6 © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4 Wireless Service Adaptive Security M Service Module (ASA- O Module 2 (WiSM 2) B SM) I L • 500 access points, I 1.7x better • 16 Gbps per blade, 3x S T E Y better C • 10 Gbps throughput U • Industry-leading price/ R • Control and data I T plane encryption performance Y • Consistency with entire ASA product family Network Analysis Module 3 (NAM-3) Application Control M A Engine 30 (ACE 30) N N • 10+ Gbps throughput, E A A P T G 10x better • 30,000 SSL transactions P E W E P R O M per second, 2x better L F R E • Advanced hardware I O K C R N filters • Lower TCO - industry’s A M T T A only virtualized application I N • High performance O C packet captures delivery controller N E Designed to Deliver Borderless Services for Next 10 Years DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential © 2011 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6 Borderless Networks CatalystNew Innovations6500 Family Architecture Delivers the Borderless Experience Borderless End-Point/User Services Mobility Workplace Video Experience AnyConnect Borderless Network Services Borderless Management Infrastructure and Policy Video: Green: Security: Performance Mobility Medianet EnergyWise TrustSec Energywise VSS Quad Multicast IPv6 security Service Phase 1 Sup Uplink Service Architecture Phase 2 TrustSec IPv6 Forwarding Reflection Framework (SAF) DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential 7 Catalyst 6500 12.2(33)SXI4 New Borderless Features Video Green Security Performance Mobility Medianet Policy . Service . EnergyWise . IPv6 HSRP Global . VSS Quad Sup . Industrial Architecture Phase 1 & 2 Address Uplink Forwarding Ethernet DHCP Framework . VSS support for Server Port . Cisco . IPv6 Port Access (SAF) SIP-400 Based Address Orchestrator Control List . Service Allocation . Multicast software (PACL) support Advertisement Service support . Advanced VPLS . IPv6 Policy-Based Framework (SAF) Reflection support for Routing . Fast UDLD SIP-400 . Performance . IPv6 RA-Guard . VPLS MAC Monitoring MIBS Host Mode Address . 10G BASE-T Withdrawal . TrustSec IPv6 16-Port 10 Gigabit SGT Learning Ethernet Copper . New support for from Data-Path Module MPLS Egress . SFP+ LRM optics netflow. LACP Auto . Netflow Data Interleaved Port Export to a Priority collector in a . NAM Visibility into VRF Virtual Machine DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential Networks 8 Catalyst 6500 12.2(33)SXI4 New Borderless Features Video Green Security Performance Mobility Medianet . Service . EnergyWise . IPv6 HSRP Global . VSS Quad Sup . Industrial Architecture Phase 1 & 2 Address Uplink Forwarding Ethernet DHCP Server Port Framework . VSS support for . Cisco . IPv6 Port Access Based Address (SAF) SIP-400 Orchestrator Control List Allocation . Multicast software (PACL) support . Fast UDLD Service support . Advanced VPLS . IPv6 Policy-Based . Performance support for Reflection Routing Monitoring MIBS SIP-400 . IPv6 RA-Guard . 10G BASE-T . VPLS MAC Host Mode 16-Port 10 Gigabit Address . TrustSec IPv6 Ethernet Copper Withdrawal Module SGT Learning . New support for from Data-Path . SFP+ LRM optics MPLS Egress netflow. LACP Auto Interleaved Port . Netflow Data Priority Export to a collector in a VRF DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential 9 Multicast Service Reflection Translate external multicast feeds Conform to internal addressing policy Receive redundant feeds. Financial News Subscriber to Broadcaster Financial News Service MSR translation occurs at the edge of your company DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential 10 Multicast Service Reflection Translates multicast source and destination address in the IPv4 header. 239.1.1.1 239.2.1.1 Multicast Src Solves multicast address overlap Multicast Src Receive multicast streams from External different companies Manage internal multicast groups Hardware support Multicast Src Internal 239.2.1.1 Multicast Receiver Multicast Receiver Supported in 12.2(33)SXI4 DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential 11 Multicast Service Reflection ip multicast-routing ! Src: Dst: Payload interface Loopback0 72.163.225.70 239.2.1.1 description Rendezvous Point for Public Net ip address 2.2.2.2 255.255.255.255 interface Gig2/1 ip pim sparse-mode ! interface gig2/1 description “ip nat inside” not required ip address 10.0.0.1 255.255.255.0 ip pim sparse-mode interface … ! interface gig2/48 description “ip nat outside” not required ip address 20.20.20.1 255.255.255.0 ip pim sparse-mode interface Gig2/48 ! Src: Dst: Payload interface Vif1 72.163.225.70 239.2.1.1 ip address 1.1.1.1 255.255.255.0 ip pim sparse-mode ip service reflect Ethernet0 destination 239.2.1.1 to 230.2.1.1 mask-len 32 source 1.1.1.2 Src: Dst: Payload ip igmp static-group 239.1.1.239 1.1.1.2 230.2.1.1 ! ip pim rp-address 2.2.2.2 DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential 12 Catalyst 6500 12.2(33)SXI4 New Borderless Features Video Green Security Performance Mobility Medianet . Service . EnergyWise . IPv6 HSRP Global . VSS Quad Sup . Industrial Architecture Phase 1 & 2 Address Uplink Forwarding Ethernet DHCP Server Port Framework . VSS support for . Cisco . IPv6 Port Access Based Address (SAF) SIP-400 Orchestrator Control List Allocation . Multicast software (PACL) support . Fast UDLD Service support . Advanced VPLS . IPv6 Policy-Based . Performance support for Reflection Routing Monitoring MIBS SIP-400 . IPv6 RA-Guard . 10G BASE-T . VPLS MAC Host Mode 16-Port 10 Gigabit Address . TrustSec IPv6 Ethernet Copper Withdrawal Module SGT Learning . New support for from Data-Path . SFP+ LRM optics MPLS Egress netflow. LACP Auto Interleaved Port . Netflow Data Priority Export to a collector in a VRF DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential 13 IPv6 Market Drivers Address space depletion National IT Strategy . Slow down of Internet Technologies U.S. Federal Mandate . Limiting expansion of enterprise into IPv6 Task Force and promotion councils: emerging markets Africa, India, Japan, Korea,… China Next Generation Internet (CNGI) project European Commission sponsored projects IP NGN Architecture Requires IPv6 IPv6 “on” & “preferred” by default DOCSIS 3.0, FTTH, HDTV, Quad Applications only running Play over IPv6 (P2P framework) Mobile SP – 3G, WiMax, PWLAN Networks in Motion Networked Sensors, ie: AIRS NAT Overlap – M&A MSFT Vista & Server 2008 Infrastructure Evolution DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential 14 Catalyst 6500 IPv6 Software Leadership Comprehensive IPv6 Feature Set IPv6 HA • IPv6 with VSS • ACL, DHCPv6 Snooping* • HSRPv6 , GLBPv6 • IPv6 First Hop Security* • BFD for OSPFv3* • TrustSec with IPv6* • NSF/SSO IPv6 forwarding* IPv6 Tunneling Multicast • MLDv1, access group, PIM SSM, • Configured, Automatic & ISATAP BSR, PIM embedded RP tunnels (RFC 2893) • Multicast over 6VPE with Inter-AS • 6to4 (RFC 3056) and Extranet Support* • IPv6 over GRE/IPv4/MPLS (6PE) • Multicast over GRE • Native IPv6 VPNs (6VPE) IPv6 Routing IPv6 QoS • Support for following protocols: • Full support for classification Static routes, RIPng IS-IS , MP- policing, queuing of IPv6 packets BGP4, OSPFv3, Neighbor • IPv6 CoPP* discovery (RFC 2461) Applications & Mgmt • OSPFv3 Authentication* • IPv6 PBR, PBR Set VRF* • Telnet, TFTP, DNS resolver, HTTP, ping, traceroute, SSH, SNMP*, Forwarding Syslog*, TACACS+*, NTPv4*, Radius*, AAA*, NAM Support* • Unicast and Multicast IPv6 in • FlexNetFlowfor IPv6 in hardware Hardware (RFC 2460), CEFv6/ • ICMPv6 (RFC 2463) dCEFv6 • DHCPv6 and DHCP Relay • VRF Aware Svcs* , ECMP • IPv6 Stats and Counters* • 200Mpps+ HW forwarding • IPv6 DHCP Helper Address MIB* • WCCP v3 with IPv6 support* DRAFT Version © 2010 Cisco Systems, Inc. All rights reserved. Cisco Confidential Note: items marked with (*) indicate features under development Security - IPv6 PACL support (IPv4 Parity) IPv4 IPv6 RACL VACL PACL RACL VACL PACL PFC/DFC 3A ✔ ✔ ✔ ✔ ✔ 12.2(33)SXI4 PFC/DFC 3B ✔ ✔ ✔ ✔ ✔ 12.2(33)SXI4 PFC/DFC 3BXL ✔ ✔ ✔ ✔ ✔ 12.2(33)SXI4 PFC/DFC 3C ✔ ✔ ✔ ✔ ✔ 12.2(33)SXI4 PFC/DFC 3CXL ✔ ✔ ✔ ✔ ✔ 12.2(33)SXI4 VSS ✔ ✔ ✔ ✔ ✔ 12.2(33)SXI4 . Catalyst 6500 supports IPv6 PACL by programming IPv6 ACEs into layer 3 forwarding engine security TCAM, same capabilities as IPv6 RACL. IPv6 PACL is an ingress security feature. IPv6 PACL requires advance ip service IOS feature set or above. Port based ACL (PACL) provides a mechanism to filer the incoming packets based on layer 2-4 parameters at layer 2 port level.