Cisco Catalyst 9200 System Management Guide
Cisco Catalyst 9200 System Management Guide
x (Catalyst
9200 Switches)
First Published: 2025-08-08
Americas Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
[Link]
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 527-0883
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS,
INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND,
EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH
THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY,
CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of
the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS" WITH ALL FAULTS.
CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT
LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS
HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network
topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional
and coincidental.
All printed copies and duplicate soft copies of this document are considered uncontrolled. See the current online version for the latest version.
Cisco has more than 200 offices worldwide. Addresses and phone numbers are listed on the Cisco website at [Link]/go/offices.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL:
[Link] Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a
partnership relationship between Cisco and any other company. (1721R)
© 2025 Cisco Systems, Inc. All rights reserved.
Preface
This preface describes the conventions of this document and information on how to obtain other documentation.
It also provides information on what's new in Cisco product documentation.
• Document Conventions , on page iii
• Related Documentation, on page v
• Obtaining Documentation and Submitting a Service Request, on page v
Document Conventions
This document uses the following conventions:
Convention Description
^ or Ctrl Both the ^ symbol and Ctrl represent the Control (Ctrl) key on a keyboard. For
example, the key combination ^D or Ctrl-D means that you hold down the Control
key while you press the D key. (Keys are indicated in capital letters but are not
case sensitive.)
bold font Commands and keywords and user-entered text appear in bold font.
Italic font Document titles, new or emphasized terms, and arguments for which you supply
values are in italic font.
Courier font Terminal sessions and information the system displays appear in courier font.
Bold Courier font Bold Courier font indicates text that the user must enter.
[x] Elements in square brackets are optional.
... An ellipsis (three consecutive nonbolded periods without spaces) after a syntax
element indicates that the element can be repeated.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
iii
Preface
Preface
Convention Description
{x | y} Required alternative keywords are grouped in braces and separated by vertical
bars.
[x {y | z}] Nested set of square brackets or braces indicate optional or required choices within
optional or required elements. Braces and a vertical bar within square brackets
indicate a required choice within an optional element.
string A nonquoted set of characters. Do not use quotation marks around the string or
the string will include the quotation marks.
!, # An exclamation point (!) or a pound sign (#) at the beginning of a line of code
indicates a comment line.
Note Means reader take note. Notes contain helpful suggestions or references to material not covered in the manual.
Tip Means the following information will help you solve a problem.
Caution Means reader be careful. In this situation, you might do something that could result in equipment damage or
loss of data.
Timesaver Means the described action saves time. You can save time by performing the action described in the paragraph.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
iv
Preface
Related Documentation
Related Documentation
Note Before installing or upgrading the device, refer to the device release notes.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
v
Preface
Obtaining Documentation and Submitting a Service Request
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
vi
CONTENTS
Related Documentation v
Obtaining Documentation and Submitting a Service Request v
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
vii
Contents
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
viii
Contents
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
ix
Contents
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
x
Contents
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
xi
Contents
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
xii
Contents
Examples 172
What to Do Next 173
Copying a Configuration File from the Device to the FTP Server 173
Examples 174
What to Do Next 175
Copying a Configuration File from a TFTP Server to the Device 175
Examples 177
What to Do Next 177
Copying a Configuration File from an FTP Server to the Device 177
Examples 178
What to Do Next 179
Maintaining Configuration Files Larger than NVRAM 179
Compressing the Configuration File 179
Storing the Configuration in Flash Memory on Class A Flash File Systems 181
Copying Configuration Files from Flash Memory to the Startup or Running Configuration 183
Copying a Configuration File from an FTP Server to Flash Memory Devices 185
Copying a Configuration File from a TFTP Server to Flash Memory Devices 187
Specifying the CONFIG_FILE Environment Variable on Class A Flash File Systems 190
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
xiii
Contents
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
xiv
Contents
Replacing the Current Running Configuration with a Saved Cisco IOS Configuration File 215
Reverting to the Startup Configuration File 216
Performing a Configuration Replace Operation with the configure confirm Command 216
Performing a Configuration Rollback Operation 216
Additional References for Configuration Replace and Configuration Rollback 218
Feature History for Configuration Replace and Configuration Rollback 218
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
xv
Contents
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
xvi
Contents
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
xvii
Contents
Overview 303
Support Articles 303
Feedback Request 304
Disclaimer and Caution 305
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
xviii
CHAPTER 1
Administering the Device
• Information About Administering the Device, on page 1
• How to Administer the Device, on page 9
• Configuration Examples for Device Administration, on page 36
• Additional References for Device Administration, on page 39
• Feature History for Device Administration, on page 39
Note For complete syntax and usage information for the commands used in this section, see the Cisco IOS
Configuration Fundamentals Command Reference on [Link].
System Clock
The basis of the time service is the system clock. This clock runs from the moment the system starts up and
keeps track of the date and time.
The system clock can then be set from these sources:
• RTC
• NTP
• Manual configuration
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
1
Administering the Device
Network Time Protocol
The system clock keeps track of time internally based on Coordinated Universal Time (UTC), also known as
Greenwich Mean Time (GMT). You can configure information about the local time zone and summer time
(daylight saving time) so that the time appears correctly for the local time zone.
The system clock keeps track of whether the time is authoritative or not (that is, whether it has been set by a
time source considered to be authoritative). If it is not authoritative, the time is available only for display
purposes and is not redistributed.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
2
Administering the Device
NTP Stratum
If the network is isolated from the Internet, Cisco’s implementation of NTP allows a device to act as if it is
synchronized through NTP, when in fact it has learned the time by using other means. Other devices then
synchronize to that device through NTP.
When multiple sources of time are available, NTP is always considered to be more authoritative. NTP time
overrides the time set by any other method.
Several manufacturers include NTP software for their host systems, and a publicly available version for
systems running UNIX and its various derivatives is also available. This software allows host systems to be
time-synchronized as well.
NTP Stratum
NTP uses the concept of a stratum to describe how many NTP hops away a device is from an authoritative
time source. A stratum 1 time server has a radio or atomic clock directly attached, a stratum 2 time server
receives its time through NTP from a stratum 1 time server, and so on. A device running NTP automatically
chooses as its time source the device with the lowest stratum number with which it communicates through
NTP. This strategy effectively builds a self-organizing tree of NTP speakers.
NTP avoids synchronizing to a device whose time might not be accurate by never synchronizing to a device
that is not synchronized. NTP also compares the time reported by several devices and does not synchronize
to a device whose time is significantly different than the others, even if its stratum is lower.
NTP Associations
The communications between devices running NTP (known as associations) are usually statically configured;
each device is given the IP address of all devices with which it should form associations. Accurate timekeeping
is possible by exchanging NTP messages between each pair of devices with an association. However, in a
LAN environment, NTP can be configured to use IP broadcast messages instead. This alternative reduces
configuration complexity because each device can simply be configured to send or receive broadcast messages.
However, in that case, information flow is one-way only.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
3
Administering the Device
Poll-Based NTP Associations
The client and the symmetric active modes should be used when NTP is required to provide a high level of
time accuracy and reliability.
When a networking device is operating in the client mode, it polls its assigned time-serving hosts for the
current time. The networking device will then pick a host from among all the polled time servers to synchronize
with. Because the relationship that is established in this case is a client-host relationship, the host will not
capture or use any time information sent by the local client device. This mode is most suited for file-server
and workstation clients that are not required to provide any form of time synchronization to other local clients.
Use the ntp server command to individually specify the time server that you want your networking device
to consider synchronizing with and to set your networking device to operate in the client mode.
When a networking device is operating in the symmetric active mode, it polls its assigned time-serving hosts
for the current time and it responds to polls by its hosts. Because this is a peer-to-peer relationship, the host
will also retain time-related information of the local networking device that it is communicating with. This
mode should be used when a number of mutually redundant servers are interconnected via diverse network
paths. Most stratum 1 and stratum 2 servers on the Internet adopt this form of network setup. Use the ntp
peer command to individually specify the time serving hosts that you want your networking device to consider
synchronizing with and to set your networking device to operate in the symmetric active mode.
The specific mode that you should set for each of your networking devices depends primarily on the role that
you want them to assume as a timekeeping device (server or client) and the device’s proximity to a stratum
1 timekeeping server.
A networking device engages in polling when it is operating as a client or a host in the client mode or when
it is acting as a peer in the symmetric active mode. Although polling does not usually place a burden on
memory and CPU resources such as bandwidth, an exceedingly large number of ongoing and simultaneous
polls on a system can seriously impact the performance of a system or slow the performance of a given network.
To avoid having an excessive number of ongoing polls on a network, you should limit the number of direct,
peer-to-peer or client-to-server associations. Instead, you should consider using NTP broadcasts to propagate
time information within a localized network.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
4
Administering the Device
NTP Security
be located on the same subnet. You must enable the time server that transmits NTP broadcast packets on the
interface of the given device by using the ntp broadcast command.
NTP Security
The time kept on a device is a critical resource; you should use the security features of NTP to avoid the
accidental or malicious setting of an incorrect time. Two mechanisms are available: an access list-based
restriction scheme and an encrypted authentication mechanism.
Note We do not recommend configuring Message Direct 5 (MD5) authentication. You can use other supported
authentication methods for stronger encryption.
If the source IP address matches the access lists for more than one access type, the first type is granted access.
If no access groups are specified, all access types are granted access to all systems. If any access groups are
specified, only the specified access types will be granted access.
For details on NTP control queries, see RFC 1305.
The encrypted NTP authentication scheme should be used when a reliable form of access control is required.
Unlike the access list-based restriction scheme that is based on IP addresses, the encrypted authentication
scheme uses authentication keys and an authentication process to determine if NTP synchronization packets
sent by designated peers or servers on a local network are deemed as trusted before the time information that
they carry along with them is accepted.
The authentication process begins from the moment an NTP packet is created. Cryptographic checksum keys
are generated using the message digest algorithm 5 (MD5) and are embedded into the NTP synchronization
packet that is sent to a receiving client. Once a packet is received by a client, its cryptographic checksum key
is decrypted and checked against a list of trusted keys. If the packet contains a matching authentication key,
the time-stamp information that is contained within the packet is accepted by the receiving client. NTP
synchronization packets that do not contain a matching authenticator key are ignored.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
5
Administering the Device
NTP Services on a Specific Interface
Note In large networks, where many trusted keys must be configured, the Range of Trusted Key Configuration
feature enables configuring multiple keys simultaneously.
It is important to note that the encryption and decryption processes used in NTP authentication can be very
CPU-intensive and can seriously degrade the accuracy of the time that is propagated within a network. If your
network setup permits a more comprehensive model of access control, you should consider the use of the
access list-based form of control.
After NTP authentication is properly configured, your networking device will synchronize with and provide
synchronization only to trusted time sources.
NTP Implementation
Implementation of NTP does not support stratum 1 service; it is not possible to connect to a radio or atomic
clock. We recommend that the time service for your network be derived from the public NTP servers available
on the IP Internet.
If the network is isolated from the Internet, NTP allows a device to act as if it is synchronized through NTP,
when in fact it has learned the time by using other means. Other devices then synchronize to that device
through NTP.
When multiple sources of time are available, NTP is always considered to be more authoritative. NTP time
overrides the time set by any other method.
Several manufacturers include NTP software for their host systems, and a publicly available version for
systems running UNIX and its various derivatives is also available. This software allows host systems to be
time-synchronized as well.
DNS
The DNS protocol controls the Domain Name System (DNS), a distributed database with which you can map
hostnames to IP addresses. When you configure DNS on your device, you can substitute the hostname for the
IP address with all IP commands, such as ping, telnet, connect, and related Telnet support operations.
IP defines a hierarchical naming scheme that allows a device to be identified by its location or domain. Domain
names are pieced together with periods (.) as the delimiting characters. For example, Cisco Systems is a
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
6
Administering the Device
Default DNS Settings
commercial organization that IP identifies by a com domain name, so its domain name is [Link]. A specific
device in this domain, for example, the File Transfer Protocol (FTP) system is identified as [Link].
To keep track of domain names, IP has defined the concept of a domain name server, which holds a cache
(or database) of names mapped to IP addresses. To map domain names to IP addresses, you must first identify
the hostnames, specify the name server that is present on your network, and enable the DNS.
Login Banners
You can configure a message-of-the-day (MOTD) and a login banner. The MOTD banner is displayed on all
connected terminals at login and is useful for sending messages that affect all network users (such as impending
system shutdowns).
The login banner is also displayed on all connected terminals. It appears after the MOTD banner and before
the login prompts.
In default banner configuration, the MOTD and login banners are not configured
Note For complete syntax and usage information for the commands used in this section, see the Cisco IOS
Configuration Fundamentals Command Reference, Release 12.4.
The address table lists the destination MAC address, the associated VLAN ID, and port number associated
with the address and the type (static or dynamic).
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
7
Administering the Device
MAC Address Table Creation
Note For complete syntax and usage information for the commands used in this section, see the command reference
for this release.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
8
Administering the Device
How to Administer the Device
address is found, the IP-MAC address association is stored in an ARP cache for rapid retrieval. Then the IP
datagram is encapsulated in a link-layer frame and sent over the network. Encapsulation of IP datagrams and
ARP requests and replies on IEEE 802 networks other than Ethernet is specified by the Subnetwork Access
Protocol (SNAP). By default, standard Ethernet-style ARP encapsulation (represented by the arpa keyword)
is enabled on the IP interface.
ARP entries added manually to the table do not age and must be manually removed.
For CLI procedures, see the Cisco IOS Release 12.4 documentation on [Link].
Procedure
Device> enable
Step 2 Use one of the following: Manually set the system clock using one of
these formats:
• clock set hh:mm:ss day month year
• clock set hh:mm:ss month day year • hh:mm:ss—Specifies the time in hours
(24-hour format), minutes, and seconds.
Example: The time specified is relative to the
configured time zone.
Device# clock set 13:32:00 23 March 2013
• day—Specifies the day by date in the
month.
• month—Specifies the month by name.
• year—Specifies the year (no abbreviation).
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
9
Administering the Device
Configuring the Time Zone
Procedure
Device> enable
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
10
Administering the Device
Configuring Summer Time (Daylight Saving Time)
Procedure
Device> enable
Step 3 clock summer-time zone date date month year Configures summer time to start and end on
hh:mm date month year hh:mm [offset]] specified days every year.
Example:
Step 4 clock summer-time zone recurring [week day Configures summer time to start and end on the
month hh:mm week day month hh:mm [offset]] specified days every year. All times are relative
to the local time zone. The start time is relative
Example:
to standard time.
Device(config)# clock summer-time The end time is relative to summer time.
PDT recurring 10 March 2013 2:00 3 Summer time is disabled by default. If you
November 2013 2:00
specify clock summer-time zone recurring
without parameters, the summer time rules
default to the United States rules.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
11
Administering the Device
Configuring NTP
Device(config)# end
Configuring NTP
These following sections provide configuration information on NTP:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
12
Administering the Device
Configuring NTP Authentication
NTP packet source IP address The source address is set by the outgoing interface.
NTP is enabled on all interfaces by default. All interfaces receive NTP packets.
Procedure
Device> enable
Step 4 [no] ntp authentication-key number {md5 | Defines the authentication keys.
cmac-aes-128 | hmac-sha1 | hmac-sha2-256}
• Each key has a key number, a type, and a
value
value.
Example:
• Keys can be one of the following types:
Device(config)# ntp authentication-key • md5: Authentication using the MD5
42 md5 aNiceKey algorithm.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
13
Administering the Device
Configuring NTP Authentication
Step 5 [no] ntp trusted-key key-number Defines trusted authentication keys that a peer
NTP device must provide in its NTP packets
Example:
for this device to synchronize to it.
Device(config)# ntp trusted-key 42 Use the no form of this command to disable
trusted authentication.
Step 6 [no] ntp server ip-address key key-id [prefer] Allows the software clock to be synchronized
by an NTP time server.
Example:
• ip-address: The IP address of the time
Device(config)# ntp server [Link] server providing the clock synchronization.
key 42
• key-id: Authentication key defined with
the ntp authentication-key command.
• prefer: Sets this peer as the preferred one
that provides synchronization. This
keyword reduces clock hop among peers.
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
14
Administering the Device
Configuring Poll-Based NTP Associations
Procedure
Device> enable
Step 3 [no] ntp peer ip-address [version number] [key Configures the device system clock to
key-id] [source interface] [prefer] synchronize a peer or to be synchronized by a
peer (peer association).
Example:
• ip-address: The IP address of the peer
Device(config)# ntp peer [Link] providing or being provided, the clock
version 2 synchronization.
• number: NTP version number. The range
is 1 to 3. By default, version 3 is selected.
• key-id: Authentication key defined with
the ntp authentication-key command.
• interface: The interface from which to pick
the IP source address. By default, the
source IP address is taken from the
outgoing interface.
• prefer: Sets this peer as the preferred one
that provides synchronization. This
keyword reduces switching back and forth
between peers.
Step 4 [no] ntp server [vrf vrf-name] ip-address Configures the device's system clock to be
[version number] [key key-id] [source synchronized by a time server (server
interface] [prefer] association).
Example: • vrf-name: The virtual routing and
forwarding (VRF) address of the server
Device(config)# ntp server [Link] providing the clock synchronization.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
15
Administering the Device
Configuring Broadcast-Based NTP Associations
Device(config)# end
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
16
Administering the Device
Configuring Broadcast-Based NTP Associations
Device(config)# interface
gigabitethernet1/0/1
Step 4 [no] ntp broadcast [version number] [key Enables the interface to send NTP broadcast
key-id] [destination-address] packets to a peer.
Example: • number: NTP version number. The range
is 1 to 4. By default, version 4 is used.
Device(config-if)# ntp broadcast version
2 • key-id: Authentication key.
• destination-address: IP address of the peer
that is synchronizing its clock to this
switch.
Step 5 [no] ntp broadcast client Enables the interface to receive NTP broadcast
packets.
Example:
Use the no form of this command to disable the
Device(config-if)# ntp broadcast client interface from receiving NTP broadcast packets.
Device(config-if)# exit
Step 7 [no] ntp broadcastdelay microseconds (Optional) Change the estimated round-trip
delay between the device and the NTP broadcast
Example:
server
Device(config)# ntp broadcastdelay 100 The default is 3000 microseconds. The range
is from 1 to 999999.
Use the no form of this command to disable the
interface from receiving NTP broadcast packets.
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
17
Administering the Device
Configuring NTP Access Restrictions
Procedure
Device> enable
Step 3 [no] ntp access-group {query-only | Create an access group, and apply a basic IP
serve-only | serve | peer} access-list-number access list..
Example: • query-only: NTP control queries.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
18
Administering the Device
Disabling NTP Services on a Specific Interface
Note
When creating an access list, remember that,
by default, the end of the access list contains
an implicit deny statement for everything if it
did not find a match before reaching the end.
Device(config)# end
Procedure
Device> enable
Device(config)# interface
gigabitethernet1/0/1
Step 4 [no] ntp disable Disables NTP packets from being received on
the interface.
Example:
Use the no form of this command to re-enable
receipt of NTP packets on an interface.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
19
Administering the Device
Configuring a System Name
Device(config-if)# end
Procedure
Device> enable
Step 3 hostname name Configures a system name. When you set the
system name, it is also used as the system
Example:
prompt.
Device(config)# hostname The default setting is Switch.
remote-users
The name must follow the rules for ARPANET
hostnames. They must start with a letter, end
with a letter or digit, and have as interior
characters only letters, digits, and hyphens.
Names can be up to 63 characters.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
20
Administering the Device
Setting Up DNS
Setting Up DNS
If you use the device IP address as its hostname, the IP address is used and no DNS query occurs. If you
configure a hostname that contains no periods (.), a period followed by the default domain name is appended
to the hostname before the DNS query is made to map the name to an IP address. The default domain name
is the value set by the ip domain name command in global configuration mode. If there is a period (.) in the
hostname, the Cisco IOS software looks up the IP address without appending any default domain name to the
hostname.
Follow these steps to set up your switch to use the DNS:
Procedure
Device> enable
Step 3 ip domain name name Defines a default domain name that the software
uses to complete unqualified hostnames (names
Example:
without a dotted-decimal domain name).
Device(config)# ip domain name [Link] Do not include the initial period that separates
an unqualified name from the domain name.
At boot time, no domain name is configured;
however, if the device configuration comes
from a BOOTP or Dynamic Host Configuration
Protocol (DHCP) server, then the default
domain name might be set by the BOOTP or
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
21
Administering the Device
Configuring a Message-of-the-Day Login Banner
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
22
Administering the Device
Configuring a Message-of-the-Day Login Banner
Procedure
Device> enable
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
23
Administering the Device
Configuring a Login Banner
Procedure
Device> enable
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
24
Administering the Device
Managing the MAC Address Table
Procedure
Device> enable
Step 3 mac address-table aging-time [0 | Sets the length of time that a dynamic entry
10-1000000] [routed-mac | vlan vlan-id] remains in the MAC address table after the entry
is used or updated.
Example:
The range is 10 to 1000000 seconds. The default
Device(config)# mac address-table is 300. You can also enter 0, which disables
aging-time 500 vlan 2 aging. Static address entries are never aged or
removed from the table.
vlan-id—Valid IDs are 1 to 4094.
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
25
Administering the Device
Configuring MAC Address Change Notification Traps
Procedure
Device> enable
Step 3 snmp-server host host-addr community-string Specifies the recipient of the trap message.
notification-type { informs | traps } {version
• host-addr—Specifies the name or address
{1 | 2c | 3}} {vrf vrf instance name}
of the NMS.
Example:
• traps (the default)—Sends SNMP traps
Device(config)# snmp-server host
to the host.
[Link] traps private
mac-notification
• informs—Sends SNMP informs to the
host.
• version—Specifies the SNMP version to
support. Version 1, the default, is not
available with informs.
• community-string—Specifies the string
to send with the notification operation.
Though you can set this string by using
the snmp-server host command, we
recommend that you define this string by
using the snmp-server community
command before using the snmp-server
host command.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
26
Administering the Device
Configuring MAC Address Change Notification Traps
Step 4 snmp-server enable traps mac-notification Enables the device to send MAC address
change change notification traps to the NMS.
Example:
mac-notification change
Step 5 mac address-table notification change Enables the MAC address change notification
feature.
Example:
Step 6 mac address-table notification change Enters the trap interval time and the history
[interval value] [history-size value] table size.
Example: • (Optional) interval value—Specifies the
notification trap interval in seconds
Device(config)# mac address-table between each set of traps that are
notification change interval 123 generated to the NMS. The range is 0 to
Device(config)#mac address-table
2147483647 seconds; the default is 1
notification change history-size 100
second.
• (Optional) history-size value—Specifies
the maximum number of entries in the
MAC notification history table. The range
is 0 to 500; the default is 1.
Step 8 snmp trap mac-notification change {added Enables the MAC address change notification
| removed} trap on the interface.
Example: • Enables the trap when a MAC address is
added on this interface.
Device(config-if)# snmp trap
mac-notification change added • Enables the trap when a MAC address is
removed from this interface.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
27
Administering the Device
Configuring MAC Address Move Notification Traps
Device(config)# end
Procedure
Device> enable
Step 3 snmp-server host host-addr {traps | informs} Specifies the recipient of the trap message.
{version {1 | 2c | 3}} community-string
• host-addr—Specifies the name or address
notification-type
of the NMS.
Example:
• traps (the default)—Sends SNMP traps to
Device(config)# snmp-server host
the host.
[Link] traps private
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
28
Administering the Device
Configuring MAC Address Move Notification Traps
Step 4 snmp-server enable traps mac-notification Enables the device to send MAC address move
move notification traps to the NMS.
Example:
mac-notification move
Step 5 mac address-table notification mac-move Enables the MAC address move notification
feature.
Example:
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
29
Administering the Device
Configuring MAC Threshold Notification Traps
What to do next
To disable MAC address-move notification traps, use the no snmp-server enable traps mac-notification
move global configuration command. To disable the MAC address-move notification feature, use the no mac
address-table notification mac-move global configuration command.
You can verify your settings by entering the show mac address-table notification mac-move privileged
EXEC commands.
Procedure
Device> enable
Step 3 snmp-server host host-addr {traps | informs} Specifies the recipient of the trap message.
{version {1 | 2c | 3}} community-string
• host-addr—Specifies the name or address
notification-type
of the NMS.
Example:
• traps (the default)—Sends SNMP traps to
Device(config)# snmp-server host
the host.
[Link] traps private
mac-notification
• informs—Sends SNMP informs to the
host.
• version—Specifies the SNMP version to
support. Version 1, the default, is not
available with informs.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
30
Administering the Device
Configuring MAC Threshold Notification Traps
Step 4 snmp-server enable traps mac-notification Enables MAC threshold notification traps to
threshold the NMS.
Example:
mac-notification threshold
Step 5 mac address-table notification threshold Enables the MAC address threshold notification
feature.
Example:
Step 6 mac address-table notification threshold Enters the threshold value for the MAC address
[limit percentage] | [interval time] threshold usage monitoring.
Example: • (Optional) limit percentage—Specifies the
percentage of the MAC address table use;
Device(config)# mac address-table valid values are from 1 to 100 percent. The
notification threshold interval 123 default is 50 percent.
Device(config)# mac address-table
notification threshold limit 78 • (Optional) interval time—Specifies the
time between notifications; valid values
are greater than or equal to 120 seconds.
The default is 120 seconds.
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
31
Administering the Device
Disabling MAC Address Learning on VLAN
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
32
Administering the Device
Adding and Removing Static Address Entries
Step 5 copy running-config startup-config (Optional) Save your entries in the configuration
file.
Example:
Device# copy running-config
startup-config
Step 6 default mac address-table learning (Optional) Reenable MAC address learning on
VLAN in a global configuration mode.
Example:
Device# default mac address-table
Procedure
Device> enable
Step 3 mac address-table static mac-addr vlan Adds a static address to the MAC address table.
vlan-id interface interface-id
• mac-addr—Specifies the destination MAC
Example: unicast address to add to the address table.
Packets with this destination address
Device(config)# mac address-table
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
33
Administering the Device
Configuring Unicast MAC Address Filtering
Procedure
Step 3 mac address-table static mac-addr vlan Enables unicast MAC address filtering and
vlan-id drop configure the device to drop a packet with the
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
34
Administering the Device
Monitoring and Maintaining Administration of the Device
clear mac address-table dynamic interface Removes all addresses on the specified physical port
interface-id or port channel.
clear mac address-table dynamic vlan vlan-id Removes all addresses on a specified VLAN.
show ip igmp snooping groups Displays the Layer 2 multicast entries for all VLANs
or the specified VLAN.
show mac address-table address mac-address Displays MAC address table information for the
specified MAC address.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
35
Administering the Device
Configuration Examples for Device Administration
Command Purpose
show mac address-table aging-time Displays the aging time in all VLANs or the specified
VLAN.
show mac address-table count Displays the number of addresses present in all
VLANs or the specified VLAN.
show mac address-table dynamic Displays only dynamic MAC address table entries.
show mac address-table interface interface-name Displays the MAC address table information for the
specified interface.
show mac address-table move update Displays the MAC address table move update
information.
show mac address-table notification {change | Displays the MAC notification parameters and history
mac-move | threshold} table.
show mac address-table static Displays only static MAC address table entries.
show mac address-table vlan vlan-id Displays the MAC address table information for the
specified VLAN.
This example shows how to set summer time start and end dates:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
36
Administering the Device
Example: Configuring a MOTD Banner
Device(config)#
This example shows the banner that appears from the previous configuration:
Trying [Link]...
Connected to [Link].
Password:
Access for authorized users only. Please enter your username and password.
Device(config)#
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
37
Administering the Device
Example: Configuring MAC Threshold Notification Traps
Note You cannot associate the same static MAC address to multiple interfaces. If the command is executed again
with a different interface, the static MAC address is overwritten on the new interface.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
38
Administering the Device
Additional References for Device Administration
Cisco IOS XE Fuji 16.9.2 Device Administration The device administration allows to configure the
system time and date, system name, a login banner,
and set up the DNS.
Cisco IOS XE Cupertino Active VLAN Support This feature was implemented on
17.9.1 C9200CX-12P-2X2G, C9200CX-8P-2X2G, and
C9200CX-12T-2X2G models of the Cisco Catalyst
9200CX Series Switches, which were introduced
in this release.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
39
Administering the Device
Feature History for Device Administration
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
40
CHAPTER 2
Boot Integrity Visibility
• Information About Boot Integrity Visibility, on page 41
• Verifying the Software Image and Hardware, on page 42
• Verifying Platform Identity and Software Integrity, on page 43
• Verifying Image Signing, on page 46
• Additional References for Boot Integrity Visibility, on page 47
• Feature History for Boot Integrity Visibility, on page 47
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
41
Boot Integrity Visibility
Verifying the Software Image and Hardware
The ROMMON follows these steps when it verifies a signed Cisco IOS XE image during the bootup:
1. Loads the Cisco IOS XE image into the CPU memory.
2. Examines the Cisco IOS XE package header.
3. Runs a non-secure integrity check on the image to ensure that there is no unintentional file corruption
from the disk or TFTP. This is performed using a non-secure SHA-1 hash.
4. Copies the Cisco's RSA 2048-bit public release key from the ROMMON storage and validates that the
Cisco's RSA 2048-bit public release key is not tampered.
5. Extracts the Code Signing signature (SHA-512 hash) from the package header and verifies it using Cisco's
RSA 2048-bit public release key.
6. Performs the Code Signing validation by calculating the SHA-512 hash of the Cisco IOS XE package
and compares it with the Code Signing signature. The Signed package is now validated.
7. Examines the Cisco IOS XE package header to validate the platform type and CPU architecture for
compatibility.
8. Extracts the Cisco IOS XE software from the Cisco IOS XE package and boots it.
Note In above process, step 3 is a non-secure check of the image which is intended to confirm the image against
inadvertent corruption due to disk errors, file transfer errors, or copying errors. This is not part of the image
code signing. This check is not intended to detect deliberate image tampering.
Image Code Signing validation occurs in step 4, 5, and 6. This is a secure code signing check of the image
using an SHA-512 hash that is encrypted with a 2048-bit RSA key. This check is intended to detect deliberate
image tampering.
Note On executing the following commands, you might see the message % Please Try After Few Seconds displayed
on the CLI. This does not indicate a CLI failure, but indicates setting up of underlying infrastructure required
to get the required output. We recommend waiting for a few minutes and then try the command again.
The messages % Error retrieving SUDI certificate and % Error retrieving integrity data signify a real
CLI failure.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
42
Boot Integrity Visibility
Verifying Platform Identity and Software Integrity
Procedure
Step 2 show platform integrity [sign [nonce Displays checksum record for boot stages.
nonce]]
• (Optional) sign - Show signature
Example:
• (Optional) nonce - Enter a nonce value
Device# show platform integrity sign
nonce 123
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
43
Boot Integrity Visibility
Verifying Platform Identity and Software Integrity
HhcNMTEwNjMwMTc1NjU3WhcNMjkwNTE0MjAyNTQyWjAnMQ4wDAYDVQQKEwVDaXNj
bzEVMBMGA1UEAxMMQUNUMiBTVURJIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA0m5l3THIxA9tN/hS5qR/6UZRpdd+9aE2JbFkNjht6gfHKd477AkS
5XAtUs5oxDYVt/zEbslZq3+LR6qrqKKQVu6JYvH05UYLBqCj38s76NLk53905Wzp
9pRcmRCPuX+a6tHF/qRuOiJ44mdeDYZo3qPCpxzprWJDPclM4iYKHumMQMqmgmg+
xghHIooWS80BOcdiynEbeP5rZ7qRuewKMpl1TiI3WdBNjZjnpfjg66F+P4SaDkGb
BXdGj13oVeF+EyFWLrFjj97fL2+8oauV43Qrvnf3d/GfqXj7ew+z/sXlXtEOjSXJ
URsyMEj53Rdd9tJwHky8neapszS+r+kdVQIDAQABo4IBWjCCAVYwCwYDVR0PBAQD
AgHGMB0GA1UdDgQWBBRI2PHxwnDVW7t8cwmTr7i4MAP4fzAfBgNVHSMEGDAWgBQn
88gVHm6aAgkWrSugiWBf2nsvqjBDBgNVHR8EPDA6MDigNqA0hjJodHRwOi8vd3d3
LmNpc2NvLmNvbS9zZWN1cml0eS9wa2kvY3JsL2NyY2EyMDQ4LmNybDBQBggrBgEF
BQcBAQREMEIwQAYIKwYBBQUHMAKGNGh0dHA6Ly93d3cuY2lzY28uY29tL3NlY3Vy
aXR5L3BraS9jZXJ0cy9jcmNhMjA0OC5jZXIwXAYDVR0gBFUwUzBRBgorBgEEAQkV
AQwAMEMwQQYIKwYBBQUHAgEWNWh0dHA6Ly93d3cuY2lzY28uY29tL3NlY3VyaXR5
L3BraS9wb2xpY2llcy9pbmRleC5odG1sMBIGA1UdEwEB/wQIMAYBAf8CAQAwDQYJ
KoZIhvcNAQEFBQADggEBAGh1qclr9tx4hzWgDERm371yeuEmqcIfi9b9+GbMSJbi
ZHc/CcCl0lJu0a9zTXA9w47H9/t6leduGxb4WeLxcwCiUgvFtCa51Iklt8nNbcKY
/4dw1ex+7amATUQO4QggIE67wVIPu6bgAE3Ja/nRS3xKYSnj8H5TehimBSv6TECi
i5jUhOWryAK4dVo8hCjkjEkzu3ufBTJapnv89g9OE+H3VKM4L+/KdkUO+52djFKn
hyl47d7cZR4DY4LIuFM2P1As8YyjzoNpK/urSRI14WdIlplR1nH7KNDl5618yfVP
0IFJZBGrooCRBjOSwFv8cpWCbmWdPaCQT2nwIjTfY8c=
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIDgTCCAmmgAwIBAgIEAp4UYzANBgkqhkiG9w0BAQsFADAnMQ4wDAYDVQQKEwVD
aXNjbzEVMBMGA1UEAxMMQUNUMiBTVURJIENBMB4XDTE4MDYwNTAzNDUwNVoXDTI5
MDUxNDIwMjU0MVowbTEpMCcGA1UEBRMgUElEOkM5MjAwTC0yNFQtNEcgU046SlBH
MjIwMjAwQTgxDjAMBgNVBAoTBUNpc2NvMRgwFgYDVQQLEw9BQ1QtMiBMaXRlIFNV
REkxFjAUBgNVBAMTDUM5MjAwTC0yNFQtNEcwggEiMA0GCSqGSIb3DQEBAQUAA4IB
DwAwggEKAoIBAQDBm2Dg0GWQ18wLTKxeCt87DL8KlRbx8Db1IigHjzebBXMpx7Ja
6Cp+kwRrIWGi5AmNmV7jZ2ZLj+vFVzBQ9eGM+6LdNg18c6nqmSmnuXMerD1UEMMK
bkFl4ydn1EIMoWpCArbgz+/zaLM2A5bpQXVndiKq1v0NA2Pgvqdxbm+8AELdDG/D
3SQ1anOja+yH5vu3NjyMJfqtjzk+n/ILp9iZMWzcA+O6E8KC5FclR2cfvWlQvoFM
ZEWmHdhHPtsnN+4hhmDeurgeM0S+xIvzZq0H7PxS0kT4vYQ9xWQEwavJAL44k0uY
JxKP6bDNssSLZ2s4/2OBsODjyBhb0GwrOAHdAgMBAAGjbzBtMA4GA1UdDwEB/wQE
AwIF4DAMBgNVHRMBAf8EAjAAME0GA1UdEQRGMESgQgYJKwYBBAEJFQIDoDUTM0No
aXBJRD1RRGx6T0FZUHQwRTJJRVFFQUFjQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB
PTANBgkqhkiG9w0BAQsFAAOCAQEAgLUxZfNmrXZ6ZMGX69dDPkmvp9cFqXR538LF
PdypCRuSk20GF8OeDUOsuIi4mbB87JSOWvLomdBtXdnxzRu4kPZNFz/7pjAVRT3R
gwMMyiEnDWQSvy7e4SZmyVgej55e3hTW/LTeU8lCE0KRoYGDce5Phv2zdHtIsXrV
XsY+Fropfntt1FV9qqDskDWcKf0bos6VsyWUpSCEGqF7LfNnBTKYvXUUmkXHKf/d
W5HgrYt6bQ/h/+0EP+MY2wpAiWMCfX6F+xW20vZfK8NzNesieB38IvuTkgefhz2s
yGCOavAxqGd0j7atcRpdrJt9+KM9Vwuy4VJZgK/t1fmTL4cawQ==
-----END CERTIFICATE-----
Signature version: 1
Signature:
2AF6EDA39A17403F621BB94E824C4FE00C19D31BF9DFAC00747C0187DF4040775056E0AE63520E763A5DF0FAEB4FA2B5BF2F9CCF3E8EDE25E7510573CF6669029FC4B22E4A15841EDA48075ADCBEED6E003C2B6637E0D4ADDBA3754AA1F2EE6AC36AE6FCE00DD075908148A25767C86F8121AF0DE95534046418A6771323C02801CEB6F412C131AA31EAB538B39B7143114AB033A3BAD1EA5F02D9A4AF89806BED6EDA0847B310FABD2247626A9FF150A8D3A82323E17C3DADECF3E2701B03336EA32C371CE88689892423F725D14919BF777DA60A823008E39A19FF65B8226D8CF4D415212C72A2814A7A7E50CCC759483B97C1704977B62191741EA5096BE9
The optional RSA 2048 signature is across the three certificates, the signature version and the
user-provided nonce.
RSA PKCS#1v1.5 Sign {<Nonce (UINT64)> || <Signature Version (UINT32)> || <Cisco Root CA
2048 cert (DER)> ||
<Cisco subordinate CA (DER)> || <SUDI certificate (DER)> }
Cisco management solutions are equipped with the ability to interpret the above output. However,
a simple script using OpenSSL commands can also be used to display the identity of the platform
and to verify the signature, thereby ensuring its Cisco unique device identity.
[linux-host:~]openssl x509 -in [Link] -subject -noout
subject= /serialNumber=PID:C9200L-24T-4G SN:FDO1946BG05/O=Cisco/OU=ACT-2 Lite
SUDI/CN=C9200L-24T-4G
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
44
Boot Integrity Visibility
Verifying Platform Identity and Software Integrity
Note Boot integrity hashes are not MD5 hashes. For example, if you run verify /md5 cat9k_iosxe.[Link]
command for the bundle file, the hash will not match.
The following is a sample output of the show platform integrity sign nonce 123 command in install mode.
This output includes measurements of each installed package file.
Device#show platform integrity sign nonce 123
Platform: C9200L-24T-4G
Boot 0 Version: SBOOT0.v27
Boot 0 Hash:
EE98DCD0D6AEA85C8891039F649664FCC3CF709CCFC7A6F248C9D5BA8463528F
Boot Loader Version: System Bootstrap, Version 10.2, DEVELOPMENT SOFTWARE
Boot Loader Hash:
9220B87E7A153A79EB9AE37311A1FDE2313C9996F21032F8A1E7EF4935D3E7427657E4CDEE537E7B3C50E84121C00BD2D556786A4EE155D3C0AFF67F63F1A69B
OS Version: 16.10.01
OS Hashes:
cat9k_lite-[Link] :
D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0
cat9k_lite-[Link] :
AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057
cat9k_lite-[Link] :
4FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057AD6A9673E211
cat9k_lite-[Link] :
CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057AD6A9673E2114FA7
[Link] :
AA7ED0AE935CB0BD84E0D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057AD6A9673E2114FA7CCCA
PCR0: 750E5D2EDAE6E3A68050638E0BFD8619BE4EA13066025D39DF79408719F5177E
PCR8: EB6E739A63F53E703B6CDAF3F6188833CEF6D32E2F726006B9AA34E1E73048C4
Signature version: 1
Signature:
5
A4
1
E6
C
7
2D
8
41
D
0
2F
5
A
7B
6
D
09
6
3
95
E
7
86
D
6
94
9
C
FC
9
E
C1
C
4
76
F
76
B
C
1C
5
9C
B
E
F3
E
6
9A
9
8
91
D
C
10E
A
2
56
C
E
19
B
7
CA
2
77
4
A7
8
9
4F
1
A
C1
4
D
17
F
6
71
7
6
02
9
0
29
22
8
2
58
6
1
B6
7
9
49
3
A
0B2
0
7
F6
7
4
63
1
7
2A
0
9
89
E
2
CB
3
A
3D
8
2
93
7
9B
2
A
6A
8
F
A4
7
5
7E
2
76
7
A
CB
F9
4
7
DB
8
2
6D
9
4
AB
4
7A
C
3
B6
E
B
E6
9
7
F7
9
A
56
B
2
D0
5
0
1B
F
2C
F
7
31
7
87
C
3
C4
2
F
4B
D
C
784
3
D
39
4
9
D1
0
E
78
BB
C
F
39
D8
B
4
2D
9
D
4B
0
BB
D
8
035F
6
8
63
1
5
98
9
2
65
8
37
96
8
5
10
B
0
F8
F
A
3E
B
F
6D
0
9
B3
F
C
46
D
0
9E
D
E
9C
0
B
D6
A
F
9E
2
4
65
8
3
9C
5
48
1
8
CE
6
1
C4
A
C
858
0
5
BD
C
E
FD
7
39
0
5
AB
8
17
4
5
B4
B
2
0F
9
B
C0
7
A8
D
6
B2
4
B
34
3
5
1F
D
F
75
1
5
1C
8
4
96
0
9
03
8
2
A9
3
6
C7B
2
3
DC
A
F
90
D
0
D5
96
F
0
AF
C
01
9
C
53
F
1
2F
4
E
40
2
8
5D
1
8
24
The following is a sample output of the show platform integrity sign nonce 123 command in bundle mode.
This output includes measurements of the bundle file and each installed package.
Device# show platform integrity sign nonce 123
Platform: C9200L-24T-4G
Boot 0 Version: SBOOT0.v27
Boot 0 Hash:
EE98DCD0D6AEA85C8891039F649664FCC3CF709CCFC7A6F248C9D5BA8463528F
Boot Loader Version: System Bootstrap, Version 10.2, DEVELOPMENT SOFTWARE
Boot Loader Hash:
9220B87E7A153A79EB9AE37311A1FDE2313C9996F21032F8A1E7EF4935D3E7427657E4CDEE537E7B3C50E84121C00BD2D556786A4EE155D3C0AFF67F63F1A69B
OS Version: 16.10.01
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
45
Boot Integrity Visibility
Verifying Image Signing
OS Hashes:
cat9k_lite_iosxe.[Link] :
F4CAD08BE1EF841C3A2E3ED8540829F08F3CBA9336F38E45669D4D8B15AD15E365B922AC8B4DC0D5B63E2806D6A1BDAB7839DD9DC8CD7E366A49ED648C113440
cat9k_lite-[Link] :
D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0
cat9k_lite-[Link] :
AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057
cat9k_lite-[Link] :
4FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057AD6A9673E211
cat9k_lite-[Link] :
CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057AD6A9673E2114FA7
[Link] :
AA7ED0AE935CB0BD84E0D0D155C1DEFDB03EB0C64057AD6A9673E2114FA7CCCAAA7ED0AE935CB0BD84E0D0D155C1DEFB03EB0C64057AD6A9673E2114FA7CCCA
PCR0: 750E5D2EDAE6E3A68050638E0BFD8619BE4EA13066025D39DF79408719F5177E
PCR8: EB6E739A63F53E703B6CDAF3F6188833CEF6D32E2F726006B9AA34E1E73048C4
Signature version: 1
Signature:
5
A4
1
E6
C
7
2D
8
41
D
0
2F
5
A
7B
6
D
09
6
3
95
E
7
86
D
6
94
9
C
FC
9
E
C1
C
4
76
F
76
B
C
1C
5
9C
B
E
F3
E
6
9A
9
8
91
D
C
10E
A
2
56
C
E
19
B
7
CA
2
77
4
A7
8
9
4F
1
A
C1
4
D
17
F
6
71
7
6
02
9
0
29
22
8
2
58
6
1
B6
7
9
49
3
A
0B2
0
7
F6
7
4
63
1
7
2A
0
9
89
E
2
CB
3
A
3D
8
2
93
7
9B
2
A
6A
8
F
A4
7
5
7E
2
76
7
A
CB
F9
4
7
DB
8
2
6D
9
4
AB
4
7A
C
3
B6
E
B
E6
9
7
F7
9
A
56
B
2
D0
5
0
1B
F
2C
F
7
31
7
87
C
3
C4
2
F
4B
D
C
784
3
D
39
4
9
D1
0
E
78
BB
C
F
39
D8
B
4
2D
9
D
4B
0
BB
D
8
035F
6
8
63
1
5
98
9
2
65
8
37
96
8
5
10
B
0
F8
F
A
3E
B
F
6D
0
9
B3
F
C
46
D
0
9E
D
E
9C
0
B
D6
A
F
9E
2
4
65
8
3
9C
5
48
1
8
CE
6
1
C4
A
C
858
0
5
BD
C
E
FD
7
39
0
5
AB
8
17
4
5
B4
B
2
0F
9
B
C0
7
A8
D
6
B2
4
B
34
3
5
1F
D
F
75
1
5
1C
8
4
96
0
9
03
8
2
A9
3
6
C7B
2
3
DC
A
F
90
D
0
D5
96
F
0
AF
C
01
9
C
53
F
1
2F
4
E
40
2
8
5D
1
8
24
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
46
Boot Integrity Visibility
Additional References for Boot Integrity Visibility
Expected hash:
DDAF35A193617ABACC417349AE204131
12E6FA4E89A97EA20A9EEEE64B55D39A
2192992A274FC1A836BA3C23A3FEEBBD
454D4423643CE80E2A9AC94FA54CA49F
Obtained hash:
DDAF35A193617ABACC417349AE204131
12E6FA4E89A97EA20A9EEEE64B55D39A
2192992A274FC1A836BA3C23A3FEEBBD
454D4423643CE80E2A9AC94FA54CA49F
Sha512 Self Test Passed
Found package arch type ARCH_i686_TYPE
Found package FRU type FRU_RP_TYPE
Performing Integrity Check ...
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
47
Boot Integrity Visibility
Feature History for Boot Integrity Visibility
Cisco IOS XE Fuji 16.9.2 Boot Integrity Visibility Boot Integrity Visibility allows Cisco's platform
identity and software integrity information to be
visible and actionable. Platform identity provides
the platform’s manufacturing installed identity.
Cisco IOS XE Cupertino Boot Integrity Visibility This feature was implemented on
17.9.1 C9200CX-12P-2X2G, C9200CX-8P-2X2G, and
C9200CX-12T-2X2G models of the Cisco Catalyst
9200CX Series Switches, which were introduced
in this release.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
48
CHAPTER 3
Performing Device Setup Configuration
• Restrictions for Performing Device Setup Configuration, on page 49
• Information About Performing Device Setup Configuration, on page 49
• How to Perform Device Setup Configuration, on page 59
• Configuration Examples for Device Setup Configuration, on page 67
• Additional References For Performing Device Setup, on page 75
• Feature History for Performing Device Setup Configuration, on page 75
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
49
Performing Device Setup Configuration
Software Install Overview
• Power over Ethernet (PoE) controller functionality test to check the chip accessibility, firmware
download, and health status of the power-sourcing equipment.
• Thermal test to verify the temperature reading from the device sensor.
• Stack interface loopback test to verify the stack-ring loopback functionality in the stacking
environment.
For information about the complete list of supported online diagnostics, see the Configuring Online
Diagnostics chapter.
The boot loader provides access to the file systems before the operating system is loaded. Normally, the boot
loader is used only to load, decompress, and start the operating system. After the boot loader gives the operating
system control of the CPU, the boot loader is not active until the next system reset or power-on.
If the switch experiences 5 consecutive unexpected reloads within 15 minutes of startup, autoboot will be
disabled, and the switch will enter ROMMON mode. To recover, issue the boot command manually. This
prevents continuous boot loops and ensures system stability.
Before you can assign device information, make sure you have connected a PC or terminal to the console port
or a PC to the Ethernet management port, and make sure you have configured the PC or terminal-emulation
software baud rate and character format to match these of the device console port:
• Baud rate default is 9600.
• Data bits default is 8.
Note If the data bits option is set to 8, set the parity option to none.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
50
Performing Device Setup Configuration
Software Boot Modes
Note We recommend that you use the install mode for Cisco Catalyst 9200 Series Switches.
Note The [Link] file for particular release is created on following the install workflow described in the
section, Installing a Software Package.
The provisioning file contains a list of software packages to boot, mount, and run. The ISO file system in
each installed package is mounted to the root file system directly from flash.
Note The packages and provisioning file used to boot in installed mode must reside in flash. Booting in installed
mode from usbflash0: or tftp: is not supported.
The provisioning file contained in a bundle is used to decide which packages to boot, mount, and run. Packages
are extracted from the bundle and copied to RAM. The ISO file system in each package is mounted to the
root file system.
Unlike install boot mode, additional memory that is equivalent to the size of the bundle is used when booting
in bundle mode.
Unlike install boot mode, bundle boot mode is available from several locations:
• flash:
• usbflash0:
• tftp:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
51
Performing Device Setup Configuration
Installing the Software Package
Note If you are using DHCP, do not respond to any of the questions in the setup program until the device receives
the dynamically assigned IP address and reads the configuration file.
If you are an experienced user familiar with the device configuration steps, manually configure the device.
Otherwise, use the setup program described in section Device Boot Process, on page 49.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
52
Performing Device Setup Configuration
Default Switch Information
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
53
Performing Device Setup Configuration
DHCP-Based Autoconfiguration and Image Update
The client, Device A, broadcasts a DHCPDISCOVER message to locate a DHCP server. The DHCP server
offers configuration parameters (such as an IP address, subnet mask, gateway IP address, DNS IP address, a
lease for the IP address, and so forth) to the client in a DHCPOFFER unicast message.
In a DHCPREQUEST broadcast message, the client returns a formal request for the offered configuration
information to the DHCP server. The formal request is broadcast so that all other DHCP servers that received
the DHCPDISCOVER broadcast message from the client can reclaim the IP addresses that they offered to
the client.
The DHCP server confirms that the IP address has been allocated to the client by returning a DHCPACK
unicast message to the client. With this message, the client and server are bound, and the client uses
configuration information received from the server. The amount of information the device receives depends
on how you configure the DHCP server.
If the configuration parameters sent to the client in the DHCPOFFER unicast message are invalid (a
configuration error exists), the client returns a DHCPDECLINE broadcast message to the DHCP server.
The DHCP server sends the client a DHCPNAK denial broadcast message, which means that the offered
configuration parameters have not been assigned, that an error has occurred during the negotiation of the
parameters, or that the client has been slow in responding to the DHCPOFFER message (the DHCP server
assigned the parameters to another client).
A DHCP client might receive offers from multiple DHCP or BOOTP servers and can accept any of the offers;
however, the client usually accepts the first offer it receives. The offer from the DHCP server is not a guarantee
that the IP address is allocated to the client; however, the server usually reserves the address until the client
has had a chance to formally request the address. If the device accepts replies from a BOOTP server and
configures itself, the device broadcasts, instead of unicasts, TFTP requests to obtain the device configuration
file.
The DHCP hostname option allows a group of devices to obtain hostnames and a standard configuration from
the central management DHCP server. A client (device) includes in its DCHPDISCOVER message an option
12 field used to request a hostname and other configuration parameters from the DHCP server. The configuration
files on all clients are identical except for their DHCP-obtained hostnames.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
54
Performing Device Setup Configuration
DHCP Autoconfiguration
• Unless you configure a timeout, the DHCP-based autoconfiguration with a saved configuration feature
tries indefinitely to download an IP address.
• The auto-install process stops if a configuration file cannot be downloaded or if the configuration file is
corrupted.
• The configuration file that is downloaded from TFTP is merged with the existing configuration in the
running configuration but is not saved in the NVRAM unless you enter the write memory or
copy running-configuration startup-configuration privileged EXEC command. If the downloaded
configuration is saved to the startup configuration, the feature is not triggered during subsequent system
restarts.
DHCP Autoconfiguration
DHCP autoconfiguration downloads a configuration file to one or more devices in your network from a DHCP
server. The downloaded configuration file becomes the running configuration of the device. It does not over
write the bootup configuration saved in the flash, until you reload the device.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
55
Performing Device Setup Configuration
Purpose of the TFTP Server
• If you want the device to receive the configuration file from a TFTP server, you must configure the
DHCP server with these lease options:
• TFTP server name (required)
• Boot filename (the name of the configuration file that the client needs) (recommended)
• Hostname (optional)
• Depending on the settings of the DHCP server, the device can receive IP address information, the
configuration file, or both.
• If you do not configure the DHCP server with the lease options described previously, it replies to client
requests with only those parameters that are configured. If the IP address and the subnet mask are not in
the reply, the device is not configured. If the router IP address or the TFTP server name are not found,
the device might send broadcast, instead of unicast, TFTP requests. Unavailability of other lease options
does not affect autoconfiguration.
• The device can act as a DHCP server. By default, the Cisco IOS DHCP server and relay agent features
are enabled on your device but are not configured. (These features are not operational.)
If you specify the TFTP server name in the DHCP server-lease database, you must also configure the TFTP
server name-to-IP-address mapping in the DNS-server database.
If the TFTP server to be used is on a different LAN from the device, or if it is to be accessed by the device
through the broadcast address (which occurs if the DHCP server response does not contain all the required
information described previously), a relay must be configured to forward the TFTP packets to the TFTP server.
The preferred solution is to configure the DHCP server with all the required information.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
56
Performing Device Setup Configuration
Purpose of the DNS Server
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
57
Performing Device Setup Configuration
How to Control Environment Variables
Note The device broadcasts TFTP server requests if the TFTP server is not obtained from the DHCP replies, if all
attempts to read the configuration file through unicast transmissions fail, or if the TFTP server name cannot
be resolved to an IP address.
The reload command halts the system. If the system is not set to manually boot up, it reboots itself.
If your device is configured for manual booting, do not reload it from a virtual terminal. This restriction
prevents the device from entering the boot loader mode and then taking it from the remote user’s control.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
58
Performing Device Setup Configuration
How to Perform Device Setup Configuration
If you modify your configuration file, the device prompts you to save the configuration before reloading.
During the save operation, the system requests whether you want to proceed with the save if the CONFIG_FILE
environment variable points to a startup configuration file that no longer exists. If you proceed in this situation,
the system enters setup mode upon reload.
To cancel a previously scheduled reload, use the reload cancel privileged EXEC command.
Procedure
Step 2 ip dhcp pool poolname Creates a name for the DHCP server address
pool, and enters DHCP pool configuration
Example:
mode.
Device(config)# ip dhcp pool pool
Device(dhcp-config)# boot
[Link]
Step 4 network network-number mask prefix-length Specifies the subnet network number and mask
of the DHCP address pool.
Example:
Note
Device(dhcp-config)# network [Link] The prefix length specifies the number of bits
[Link] that comprise the address prefix. The prefix
is an alternative way of specifying the network
mask of the client. The prefix length must be
preceded by a forward slash (/).
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
59
Performing Device Setup Configuration
Configuring DHCP Autoconfiguration (Only Configuration File)
Device(dhcp-config)# default-router
[Link]
Step 6 option 150 address Specifies the IP address of the TFTP server.
Example:
Device(dhcp-config)# exit
Device(config)# tftp-server
flash:[Link]
Step 9 interface interface-id Specifies the address of the client that will
receive the configuration file.
Example:
Step 10 no switchport Puts the interface into Layer 3 mode.
Example:
Device(config-if)# no switchport
Step 11 ip address address mask Specifies the IP address and mask for the
interface.
Example:
Device(config-if)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
60
Performing Device Setup Configuration
Manually Assigning IP Information to Multiple SVIs
Procedure
Device> enable
Step 3 interface vlan vlan-id Enters interface configuration mode, and enters
the VLAN to which the IP information is
Example:
assigned. The range is 1 to 4094.
Device(config)# interface vlan 99
Step 4 ip address ip-address subnet-mask Enters the IP address and subnet mask.
Example:
Device(config-vlan)# ip address
[Link] [Link]
Device(config-vlan)# exit
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
61
Performing Device Setup Configuration
Modifying Device Startup Configuration
Note
The device capwap relays on default-gateway
configuration to support routed access point
join the device.
Device(config)# end
Step 8 show interfaces vlan vlan-id Displays the interfaces status for the specified
VLAN.
Example:
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
62
Performing Device Setup Configuration
Booting the Device in Installed Mode
Device> enable
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
63
Performing Device Setup Configuration
Managing the Update Package
Procedure
Step 2 install add file tftp: filename [activate Copies the software install package from a
commit] remote location (via FTP, HTTP, HTTPs,
TFTP) to the device, performs a compatibility
Example:
check for the platform and image versions,
Device# install add file activates the software package, and makes the
flash:cat9k_lite_iosxe.[Link]
activate commit package persistent across reloads.
• This command extracts the individual
components of the .bin file into
sub-packages and [Link] file.
• The device reloads after executing this
command.
Procedure
Step 2 install add file tftp: filename Copies the software install package from a
remote location (via FTP, HTTP, HTTPs,
Example:
TFTP) to the device, and performs a
Device# install add file compatibility check for the platform and image
t[Link]
cat9k_iosxe.[Link] versions.
• This command extracts the individual
components of the .bin file into
sub-packages and [Link] file.
Step 3 install activate [auto-abort-timer] Activates the added software install package,
and reloads the device.
Example:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
64
Performing Device Setup Configuration
Managing the Update Package
Step 6 install rollback to committed (Optional) Rolls back the update to the last
committed version.
Example:
Device# install rollback to committed
Step 7 install remove {file filesystem: filename | (Optional) Deletes all unused and inactive
inactive} software installation files.
Example:
Device# install remove inactive
Step 8 show install summary Displays information about the active package.
Example: • The output of this command varies
Device# show install summary according to the install commands that are
configured.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
65
Performing Device Setup Configuration
Booting a Device in Bundle Mode
Procedure
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
66
Performing Device Setup Configuration
Configuration Examples for Device Setup Configuration
Step 5 reload at hh: mm [month day | day month] [text] Specifies the time in hours and minutes for the
reload to occur.
Example:
Note
Device(config)# reload at 14:00 Use the at keyword only if the device system
clock has been set (through Network Time
Protocol (NTP), the hardware calendar, or
manually). The time is relative to the
configured time zone on the device. To
schedule reloads across several devices to
occur simultaneously, the time on each device
must be synchronized with NTP.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
67
Performing Device Setup Configuration
Examples: Displaying Software Bootup in Install Mode
Cisco IOS Software [Fuji], Catalyst L3 Switch Software (CAT9K_IOSXE), Version 16.9.1, RELEASE
SOFTWARE (fc2)
Technical Support: [Link]
Copyright (c) 1986-2017 by Cisco Systems, Inc.
Compiled Tue 30-May-17 00:36 by mcpre
A summary of U.S. laws governing Cisco cryptographic products may be found at:
[Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
68
Performing Device Setup Configuration
Examples: Displaying Software Bootup in Install Mode
Defaulting CPP : Policer rate for all classes will be set to their defaults
Cisco IOS Software [Fuji], Catalyst L3 Switch Software (CAT9K_IOSXE), Version 16.9.1, RELEASE
SOFTWARE (fc2)
Technical Support: [Link]
Copyright (c) 1986-2017 by Cisco Systems, Inc.
Compiled Tue 30-May-17 00:36 by mcpre
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
69
Performing Device Setup Configuration
Example: Managing an Update Package
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY. You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0. For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.
A summary of U.S. laws governing Cisco cryptographic products may be found at:
[Link]
Defaulting CPP : Policer rate for all classes will be set to their defaults
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
70
Performing Device Setup Configuration
Example: Managing an Update Package
This operation requires a reload of the system. Do you want to proceed? [y/n]y
--- Starting Activate ---
Performing Activate on all members
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
71
Performing Device Setup Configuration
Verifying Software Install
Y2#
Chassis 7 reloading, reason - Reload command
The following is a sample output of the show install summary command after adding a software
package file to a device:
Device# show install summary
[ Switch 4 7 ] Installed Package(s) Information:
State (St): I - Inactive, U - Activated & Uncommitted,
C - Activated & Committed, D - Deactivated & Uncommitted
--------------------------------------------------------------------------------
Type St Filename/Version
--------------------------------------------------------------------------------
IMG C [Link].70
--------------------------------------------------------------------------------
Auto abort timer: inactive
--------------------------------------------------------------------------------
The following example shows how to activate an added software package file:
The following sample output from the show install summary command displays the status of the
software package as active and uncommitted:
The following example shows how to execute the install commit command:
The following example shows how to rollback an update package to the base package:
The following is a sample output from the install remove inactive command:
The following is sample output from the install abort command:
The following is a sample output from the install activate auto-abort-timer command:
Procedure
Step 1 enable
Example:
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
72
Performing Device Setup Configuration
Verifying Software Install
Displays information about all the software install operations that was performed since boot-up of the device.
Device# show install log
[0|install_op_boot]: START Tue Aug 30 06:39:48 Universal 2018
[0|install_op_boot]: END SUCCESS Tue Aug 30 06:39:50 Universal 2018
Displays information about the image versions and their corresponding install state for all
members/field-replaceable unit (FRU).
• The output of this command differs based on the install command that is executed.
--------------------------------------------------------------------------------
Auto abort timer: inactive
--------------------------------------------------------------------------------
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
73
Performing Device Setup Configuration
Example: Configuring a Device to Download Configurations from a DHCP Server
BOOT path-list:
Config file: flash:/[Link]
Private Config file: flash:/[Link]
Enable Break: no
Manual Boot: no
HELPER path-list:
NVRAM/Config file
buffer size: 32768
Timeout for Config
Download: 300 seconds
Config Download
via DHCP: enabled (next boot: enabled)
Device#
Reload scheduled for 19:30:00 UTC Wed Jun 5 2013 (in 2 hours and 25 minutes)
Proceed with reload? [confirm]
This example shows how to reload the software on a device at a future date and time:
Reload scheduled for 02:00:00 UTC Thu Jun 20 2013 (in 344 hours and 53 minutes)
Proceed with reload? [confirm]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
74
Performing Device Setup Configuration
Additional References For Performing Device Setup
Cisco IOS XE Fuji 16.9.2 Device Setup A device setup configuration can be performed,
Configuration including auto configuration of IP address
assignments and DHCP.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
75
Performing Device Setup Configuration
Feature History for Performing Device Setup Configuration
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
76
CHAPTER 4
Configuring Application Visibility and Control in
a Wired Network
• Information About Application Visibility and Control in a Wired Network, on page 77
• Supported AVC Class Map and Policy Map Formats, on page 77
• Restrictions for Wired Application Visibility and Control, on page 79
• How to Configure Application Visibility and Control, on page 81
• Monitoring Application Visibility and Control, on page 106
• Examples: Application Visibility and Control Configuration, on page 106
• Basic Troubleshooting - Questions and Answers, on page 118
• Additional References for Application Visibility and Control, on page 119
• Feature History for Application Visibility and Control in a Wired Network, on page 119
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
77
Configuring Application Visibility and Control in a Wired Network
Supported AVC Class Map and Policy Map Formats
The following table describes the detailed AVC policy format with an example:
Multiple set and police including policy-map webex-policy Ingress and egress
default class webex-class
set dscp af31
police 4000000
class class-webex-category
set dscp ef
police 6000000
class class-default
set dscp <>
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
78
Configuring Application Visibility and Control in a Wired Network
Restrictions for Wired Application Visibility and Control
policy-map client-in-police-only
class webex-class
police 100000
class class-webex-category
set dscp ef
police 200000
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
79
Configuring Application Visibility and Control in a Wired Network
Restrictions for Wired Application Visibility and Control
• NBAR2 based match criteria match protocol will be allowed only with marking or policing actions.
NBAR2 match criteria will not be allowed in a policy that has queuing features configured.
• ‘Match Protocol’: up to 255 concurrent different protocols in all policies (8 bits HW limitation).
• AVC is not supported on management port (Gig 0/0).
• IPv6 packet classification is not supported.
• Only IPv4 unicast(TCP/UDP) is supported.
• Only IPv4 unicast(TCP/UDP) is supported when 'match application name' is used in Netflow record.
• Web UI: You can configure application visibility and perform application monitoring from the Web UI.
Application Control can only be done using the CLI. It is not supported on the Web UI.
To manage and check wired AVC traffic on the Web UI, you must first configure ip http authentication
local and ip nbar http-service commands using the CLI.
• NBAR and ACL logging cannot be configured together on the same switch.
• Protocol-discovery, application-based QoS, and wired AVC FNF cannot be configured together at the
same time on the same interface with the non-application-based FNF. However, these wired AVC features
can be configured with each other. For example, protocol-discovery, application-based QoS and wired
AVC FNF can be configured together on the same interface at the same time.
• Only two wired AVC monitors each with a different predefined record can be attached to an interface
at the same time.
• Two directional flow records - ingress and egress - and two legacy flow records are supported.
• Attachment should be done only on physical Layer 2 and Layer 3 ports, and these ports cannot be part
of a port channel. Attachment to trunk ports are not supported.
• Performance: Each switch member is able to handle 500 connections per second (CPS) at less than 50%
CPU utilization.
• Scale: Able to handle up to 5000 bi-directional flows per 24 and 48 access ports.
• Wired AVC allows only the fixed set of fields listed in the procedures of this chapter. Other combinations
are not allowed. For a regular FNF flow monitor, other combinations are allowed (for the list of supported
FNF fields, refer the "Configuring Flexible NetFlow" chapter of the Network Management Configuration
Guide).
• Starting with Cisco IOS XE 16.12.1 release, a new flow record has been included - the DNS flow record.
The DNS flow record is similar to the 5-tuple record and includes the DNS domain name field. It accounts
only for DNS related fields. This record doesn't have the interface field as a match filed, so the information
from all interfaces is aggregated into the same record.
• For wired AVC traffic, four AVC flow monitors per direction, interface, and protocol (IPv4/6) are
supported on the system.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
80
Configuring Application Visibility and Control in a Wired Network
How to Configure Application Visibility and Control
Protocol-Discovery, application-based QoS and application-based FNF are all independent features. They
can be configured independently or together on the same interface at the same time.
Procedure
Step 2 interface interface-id Specifies the interface for which you are
enabling protocol-discovery and enters interface
Example:
configuration mode.
Device(config)# interface gigabitethernet
1/0/1
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
81
Configuring Application Visibility and Control in a Wired Network
Creating AVC QoS Policy
Device(config-if)# ip nbar
protocol-discovery
Device(config-if)# end
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
82
Configuring Application Visibility and Control in a Wired Network
Creating a Policy Map
Procedure
Step 2 policy-map policy-map-name Creates a policy map by entering the policy map
name, and enters policy-map configuration
Example:
mode.
Device(config)# policy-map webex-policy By default, no policy maps are defined.
The default behavior of a policy map is to set
the DSCP to 0 if the packet is an IP packet and
to set the CoS to 0 if the packet is tagged. No
policing is performed.
Note
To delete an existing policy map, use the no
policy-map policy-map-name global
configuration command.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
83
Configuring Application Visibility and Control in a Wired Network
Applying a QoS Policy to the switch port
Step 4 police rate-bps burst-byte Defines a policer for the classified traffic.
Example: By default, no policer is defined.
• For rate-bps, specify an average traffic
Device(config-pmap-c)# police 100000
80000 rate in bits per second (b/s). The range is
8000 to 10000000000.
• For burst-byte, specify the normal burst
size in bytes. The range is 1000 to
512000000.
Step 5 set {dscp new-dscp | cos cos-value} Classifies IP traffic by setting a new value in
the packet.
Example:
• For dscp new-dscp, enter a new DSCP
Device(config-pmap-c)# set dscp 45 value to be assigned to the classified
traffic. The range is 0 to 63.
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
84
Configuring Application Visibility and Control in a Wired Network
Configuring Wired AVC Flexible Netflow
Procedure
Step 4 match ipv4 version Specifies a match to the IP version from the
IPv4 header.
Example:
Device(config-flow-record)# match ipv4
version
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
85
Configuring Application Visibility and Control in a Wired Network
Flow Record 1 - Bidirectional Flow Record
Step 7 match connection client ipv4 address Specifies a match to the IPv4 address of the
client (flow initiator).
Example:
Device(config-flow-record)# match
connection client ipv4 address
Step 8 match connection server ipv4 address Specifies a match to the IPv4 address of the
server (flow responder).
Example:
Device(config-flow-record)# match
connection server ipv4 address
Step 9 match connection server transport port Specifies a match to the transport port of the
server.
Example:
Device(config-flow-record)# match
connection server transport port
Step 10 match flow observation point Specifies a match to the observation point ID
for flow observation metrics.
Example:
Device(config-flow-record)# match flow
observation point
Step 12 collect connection initiator Specifies to collect the side of the flow —
Initiator or Responder — relevant to the
Example:
direction of the flow specified by the collect
Device(config-flow-record)# collect flow direction command. The initiator
connection initiator
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
86
Configuring Application Visibility and Control in a Wired Network
Flow Record 1 - Bidirectional Flow Record
Step 14 collect connection client counter packets Specifies to collect the number of packets sent
long by the client.
Example:
Device(config-flow-record)# collect
connection client counter packets long
Step 15 collect connection client counter bytes Specifies to collect the total number of bytes
network long transmitted by the client.
Example:
Device(config-flow-record)# collect
connection client counter bytes network
long
Step 16 collect connection server counter packets Specifies to collect the number of packets sent
long by the server.
Example:
Device(config-flow-record)# collect
connection server counter packets long
Step 17 collect connection server counter bytes Specifies to collect the total number of bytes
network long transmitted by the server.
Example:
Device(config-flow-record)# collect
connection server counter bytes network
long
Step 18 collect timestamp absolute first Specifies to collect the time, in milliseconds,
when the first packet was seen in the flow.
Example:
Device(config-flow-record)# collect
timestamp absolute first
Step 19 collect timestamp absolute last Specifies to collect the time, in milliseconds,
when the most recent packet was seen in the
Example:
flow.
Device(config-flow-record)# collect
timestamp absolute last
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
87
Configuring Application Visibility and Control in a Wired Network
Flow Record 2 - Bidirectional Flow Record
Step 21 show flow record Displays information about all the flow
records.
Example:
Device# show flow record
Procedure
Step 4 match ipv4 version Specifies a match to the IP version from the
IPv4 header.
Example:
Device(config-flow-record)# match ipv4
version
Step 7 match connection client ipv4 address Specifies a match to the IPv4 address of the
client (flow initiator).
Example:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
88
Configuring Application Visibility and Control in a Wired Network
Flow Record 2 - Bidirectional Flow Record
Step 8 match connection client transport port (Optional) Specifies a match to the connection
port of the client as a key field for a flow
Example:
record.
Device(config-flow-record)# match
connection client transport port
Step 9 match connection server ipv4 address Specifies a match to the IPv4 address of the
server (flow responder).
Example:
Device(config-flow-record)# match
connection server ipv4 address
Step 10 match connection server transport port Specifies a match to the transport port of the
server.
Example:
Device(config-flow-record)# match
connection server transport port
Step 11 match flow observation point Specifies a match to the observation point ID
for flow observation metrics.
Example:
Device(config-flow-record)# match flow
observation point
Step 13 collect connection initiator Specifies to collect the side of the flow —
Initiator or Responder — relevant to the
Example:
direction of the flow specified by the collect
Device(config-flow-record)# collect flow direction command. The initiator
connection initiator
keyword provides the following information
about the direction of the flow :
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
89
Configuring Application Visibility and Control in a Wired Network
Flow Record 2 - Bidirectional Flow Record
Step 15 collect connection client counter packets Specifies to collect the number of packets sent
long by the client.
Example:
Device(config-flow-record)# collect
connection client counter packets long
Step 16 collect connection client counter bytes Specifies to collect the total number of bytes
network long transmitted by the client.
Example:
Device(config-flow-record)# collect
connection client counter bytes network
long
Step 17 collect connection server counter packets Specifies to collect the number of packets sent
long by the server.
Example:
Device(config-flow-record)# collect
connection server counter packets long
Step 18 collect connection server counter bytes Specifies to collect the total number of bytes
network long transmitted by the server.
Example:
Device(config-flow-record)# collect
connection server counter bytes network
long
Step 19 collect timestamp absolute first Specifies to collect the time, in milliseconds,
when the first packet was seen in the flow.
Example:
Device(config-flow-record)# collect
timestamp absolute first
Step 20 collect timestamp absolute last Specifies to collect the time, in milliseconds,
when the most recent packet was seen in the
Example:
flow.
Device(config-flow-record)# collect
timestamp absolute last
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
90
Configuring Application Visibility and Control in a Wired Network
Directional Flow Records
Step 22 show flow record Displays information about all the flow
records.
Example:
Device# show flow record
Procedure
Step 4 match ipv4 version Specifies a match to the IP version from the
IPv4 header.
Example:
Device(config-flow-record)# match ipv4
version
Step 6 match ipv4 source address Specifies a match to the IPv4 source address
as a key field.
Example:
Device(config-flow-record)# match ipv4
source address
Step 7 match ipv4 destination address Specifies a match to the IPv4 destination
address as a key field.
Example:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
91
Configuring Application Visibility and Control in a Wired Network
Flow Record 3 - Directional Flow Record - Ingress
Step 8 match transport source-port Specifies a match to the transport source port
as a key field.
Example:
Device(config-flow-record)# match
transport source-port
Step 12 collect interface output Specifies to collect the output interface from
the flows.
Example:
Device(config-flow-record)# collect
interface output
Step 13 collect counter bytes long Specifies to collect the number of bytes in a
flow.
Example:
Device(config-flow-record)# collect
counter bytes long
Step 14 collect counter packets long Specifies to collect the number of packets in
a flow.
Example:
Device(config-flow-record)# collect
counter packets long
Step 15 collect timestamp absolute first Specifies to collect the time, in milliseconds,
when the first packet was seen in the flow.
Example:
Device(config-flow-record)# collect
timestamp absolute first
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
92
Configuring Application Visibility and Control in a Wired Network
Flow Record 4 - Directional Flow Record - Egress
Step 18 show flow record Displays information about all the flow
records.
Example:
Device# show flow record
Procedure
Step 4 match ipv4 version Specifies a match to the IP version from the
IPv4 header.
Example:
Device(config-flow-record)# match ipv4
version
Step 6 match ipv4 source address Specifies a match to the IPv4 source address
as a key field.
Example:
Device(config-flow-record)# match ipv4
source address
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
93
Configuring Application Visibility and Control in a Wired Network
Flow Record 4 - Directional Flow Record - Egress
Step 8 match transport source-port Specifies a match to the transport source port
as a key field.
Example:
Device(config-flow-record)# match
transport source-port
Step 12 collect interface input Specifies to collect the input interface from the
flows.
Example:
Device(config-flow-record)# collect
interface input
Step 13 collect counter bytes long Specifies to collect the number of bytes in a
flow.
Example:
Device(config-flow-record)# collect
counter bytes long
Step 14 collect counter packets long Specifies to collect the number of packets in
a flow.
Example:
Device(config-flow-record)# collect
counter packets long
Step 15 collect timestamp absolute first Specifies to collect the time, in milliseconds,
when the first packet was seen in the flow.
Example:
Device(config-flow-record)# collect
timestamp absolute first
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
94
Configuring Application Visibility and Control in a Wired Network
DNS Flow Record
Step 18 show flow record Displays information about all the flow
records.
Example:
Device# show flow record
Procedure
Step 4 match ipv4 version Specifies a match to the IP version from the
IPv4 header.
Example:
Device(config-flow-record)# match ipv4
version
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
95
Configuring Application Visibility and Control in a Wired Network
Flow Record 5 - DNS Flow Record
Step 7 match connection client ipv4 address Specifies a match to the IPv4 address of the
client (flow initiator).
Example:
Device(config-flow-record)# match
connection client ipv4 address
Step 8 match connection client transport port Specifies a match to the connection port of the
client as a key field for a flow record.
Example:
Device(config-flow-record)# match
connection client transport port
Step 9 match connection server ipv4 address Specifies a match to the IPv4 address of the
server (flow responder).
Example:
Device(config-flow-record)# match
connection server ipv4 address
Step 10 match connection server transport port Specifies a match to the transport port of the
server.
Example:
Device(config-flow-record)# match
connection server transport port
Step 12 collect timestamp absolute first Specifies to collect the time, in milliseconds,
when the first packet was seen in the flow.
Example:
Device(config-flow-record)# collect
timestamp absolute first
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
96
Configuring Application Visibility and Control in a Wired Network
Flow Record 5 - DNS Flow Record
Step 14 collect connection initiator Specifies to collect the side of the flow —
Initiator or Responder — relevant to the
Example:
direction of the flow specified by the collect
Device(config-flow-record)# collect flow direction command. The initiator
connection initiator
keyword provides the following information
about the direction of the flow :
• 0x01 = Initiator - the flow source is the
initiator of the connection
Step 16 collect connection server counter packets Specifies to collect the number of packets sent
long by the server.
Example:
Device(config-flow-record)# collect
connection server counter packets long
Step 17 collect connection client counter packets Specifies to collect the number of packets sent
long by the client.
Example:
Device(config-flow-record)# collect
connection client counter packets long
Step 18 collect connection server counter bytes Specifies to collect the total number of bytes
network long transmitted by the server.
Example:
Device(config-flow-record)# collect
connection server counter bytes network
long
Step 19 collect connection client counter bytes Specifies to collect the total number of bytes
network long transmitted by the client.
Example:
Device(config-flow-record)# collect
connection client counter bytes network
long
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
97
Configuring Application Visibility and Control in a Wired Network
Creating a Flow Exporter
Procedure
Step 4 destination { hostname | ipv4-address | Specifies the hostname, IPv4 or IPv6 address
ipv6-address } of the system to which the exporter sends data.
Example:
Device(config-flow-exporter)# destination
[Link]
Step 5 option application-table [ timeout seconds (Optional) Configures the application table
] option for the flow exporter. The timeout option
configures the resend time in seconds for the
Example:
flow exporter. The valid range is from 1 to
Device(config-flow-exporter)# option 86400 seconds.
application-table timeout 500
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
98
Configuring Application Visibility and Control in a Wired Network
Creating a Flow Monitor
Procedure
Step 2 flow monitor monitor-name Creates a flow monitor and enters flow monitor
configuration mode.
Example:
Device(config)# flow monitor
flow-monitor-1
Step 4 record record-name Specifies the name of a record that was created
previously.
Example:
Device(config-flow-monitor)# record
flow-record-1
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
99
Configuring Application Visibility and Control in a Wired Network
Creating a Flow Monitor
Example:
Device(config-flow-monitor)# cache type
normal
Step 8 show flow monitor Displays information about all the flow
monitors.
Example:
Device# show flow monitor
Step 9 show flow monitor flow-monitor-name Displays information about the specified wired
AVC flow monitor.
Example:
Device# show flow monitor flow-monitor-1
Step 10 show flow monitor flow-monitor-name Displays statistics for wired AVC flow
statistics monitor.
Example:
Device# show flow monitor flow-monitor-1
statistics
Step 11 clear flow monitor flow-monitor-name Clears the statistics of the specified flow
statistics monitor. Use the show flow monitor
flow-monitor-1 statistics command after using
Example:
the clear flow monitor flow-monitor-1
Device# clear flow monitor statistics to verify that all the statistics have
flow-monitor-1 statistics
been reset.
Step 12 show flow monitor flow-monitor-name cache Displays flow cache contents in a tabular
format table format.
Example:
Device# show flow monitor flow-monitor-1
cache format table
Step 13 show flow monitor flow-monitor-name cache Displays flow cache contents in similar format
format record as the flow record.
Example:
Device# show flow monitor flow-monitor-1
cache format record
Step 14 show flow monitor flow-monitor-name cache Displays flow cache contents in CSV format.
format csv
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
100
Configuring Application Visibility and Control in a Wired Network
Associating Flow Monitor to an interface
Procedure
Step 3 ip flow monitor monitor-name { input | Associates a flow monitor to the interface for
output } input and/or output packets.
Example:
NBAR2 provides a way to manually customize such local applications. You can manually customize
applications using the command ip nbar custom myappname in global configuration mode. Custom
applications take precedence over built-in protocols. For each custom protocol, user can define a selector ID
that can be used for reporting purposes.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
101
Configuring Application Visibility and Control in a Wired Network
HTTP Customization
HTTP Customization
HTTP customization could be based on a combination of HTTP fields from:
• cookie - HTTP Cookie
• host - Host name of Origin Server containing resource
• method - HTTP method
• referrer - Address the resource request was obtained from
• url - Uniform Resource Locator path
• user-agent - Software used by agent sending the request
• version - HTTP version
• via - HTTP via field
HTTP Customization
Custom application called MYHTTP using the HTTP host “*[Link]” with Selector ID 10.
Device# configure terminal
Device(config)# ip nbar custom MYHTTP http host *[Link] id 10
SSL Customization
Customization can be done for SSL encrypted traffic using information extracted from the SSL Server Name
Indication (SNI) or Common Name (CN).
SSL Customization
Custom application called MYSSL using SSL unique-name “[Link]” with selector ID 11.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
102
Configuring Application Visibility and Control in a Wired Network
DNS Customization
DNS Customization
NBAR2 examines DNS request and response traffic, and can correlate the DNS response to an application.
The IP address returned from the DNS response is cached and used for later packet flows associated with that
specific application.
The command ip nbar custom application-name dns domain-name id application-id is used for DNS
customization. To extend an existing application, use the command ip nbar custom application-name dns
domain-name domain-name extends existing-application.
For more information on DNS based customization, see [Link]
qos_nbar/configuration/xe-3s/asr1000/qos-nbar-xe-3s-asr-1000-book/[Link].
DNS Customization
Custom application called MYDNS using the DNS domain name “[Link]” with selector
ID 12.
Device# configure terminal
Device(config)# ip nbar custom MYDNS dns domain-name *[Link] id 12
Composite Customization
NBAR2 provides a way to customize applications based on domain names appearing in HTTP, SSL or DNS.
Composite Customization
Custom application called MYDOMAIN using HTTP, SSL or DNS domain name “[Link]”
with selector ID 13.
Device# configure terminal
Device(config)# ip nbar custom MYDOMAIN composite server-name *[Link] id 13
L3/L4 Customization
Layer3/Layer4 customization is based on the packet tuple and is always matched on the first packet of a flow.
L3/L4 Customization
Custom application called LAYER4CUSTOM matching IP addresses [Link] and [Link],
TCP and DSCP ef with selector ID 14.
Device# configure terminal
Device(config)# ip nbar custom LAYER4CUSTOM transport tcp id 14
Device(config-custom)# ip address [Link] [Link]
Device(config-custom)# dscp ef
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
103
Configuring Application Visibility and Control in a Wired Network
Examples: Monitoring Custom Applications
Warning When using switch stacking, ensure that each switch has the same Protocol Pack file loaded. If you execute
the ip nbar protocol-pack flash protocol-pack-file command on the primary switch in the stack, any switch
in the stack that does not have the file loaded will be reloaded due to a configuration mismatch.
NBAR2 protocol packs are available for download on Cisco Software Center from this URL:
[Link] .
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
104
Configuring Application Visibility and Control in a Wired Network
Loading the NBAR2 Protocol Pack
Procedure
Device> enable
Device(config)# exit
Step 5 show ip nbar protocol-pack {protocol-pack | Displays the protocol pack information.
active} [detail]
• Verify the loaded protocol pack version,
Example: publisher, and other details using this
command.
Device# show ip nbar protocol-pack active
• Use the protocol-pack argument to display
information about the specified protocol
pack.
• Use the active keyword to display active
protocol pack information.
• Use the detail keyword to display detailed
protocol pack information.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
105
Configuring Application Visibility and Control in a Wired Network
Monitoring Application Visibility and Control
Device> enable
Device# configure terminal
Device(config)# ip nbar protocol-pack flash:newDefProtoPack
Device(config)# exit
The following example shows how to use the force keyword to load a protocol pack of a lower version:
Device> enable
Device# configure terminal
Device(config)# ip nbar protocol-pack flash:OldDefProtoPack force
Device(config)# exit
The following example shows how to revert to the built-in protocol pack:
Device> enable
Device# configure terminal
Device(config)# default ip nbar protocol-pack
Device(config)# exit
Command Purpose
show ip nbar protocol-discovery [interface Displays the statistics gathered by the NBAR Protocol
interface-type interface-number] Discovery feature.
[stats{byte-count | bit-rate |
• (Optional) Enter keywords and arguments to fine-tune
packet-count | max-bit-rate}] [protocol
the statistics displayed. For more information on each
protocol-name | top-n number] of the keywords, refer to the show ip nbar
protocol-discoverycommand in Cisco IOS Quality
of Service Solutions Command Reference.
show policy-map interface interface-type Displays information about policy map applied to the
interface-number interface.
This example shows how to create policy maps and define existing class maps for egress QoS:
Device # configure terminal
Device(config)# policy-map test-avc-up
Device(config-pmap)# class cat-browsing
Device(config-pmap-c)# police 150000
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
106
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
This example shows how to create policy maps and define existing class maps for ingress QoS:
Device# configure terminal
Device(config)# policy-map test-avc-down
Device(config-pmap)# class cat-browsing
Device(config-pmap-c)# police 200000
Device(config-pmap-c)# set dscp 10
Device(config-pmap-c)#end
This example shows how to create class maps based on NBAR attributes.
Device# configure terminal
Device(config)# class-map match-all rel-relevant
Device(config-cmap)# match protocol attribute business-relevance business-relevant
This example shows how to create policy maps based on class maps based on NBAR attributes.
Device# configure terminal
Device(config)# policy-map attrib--rel-types
Device(config-pmap)# class rel-relevant
Device(config-pmap-c)# set dscp ef
Device(config-pmap-c)# class rel-irrelevant
Device(config-pmap-c)# set dscp af11
Device(config-pmap-c)# class rel-default
Device(config-pmap-c)# set dscp default
This example shows how to attach a policy map based on NBAR attributes to a wired port:
Device# configure terminal
Device(config)# interface GigabitEthernet1/0/2
Device(config-if)# service-policy input attrib--rel-types
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
107
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
GigabitEthernet1/0/1
Last clearing of "show ip nbar protocol-discovery" counters 00:03:16
Input
Output
-----
------
Protocol Packet Count
Packet Count
Byte Count
Byte Count
30sec Bit Rate (bps)
30sec Bit Rate (bps)
30sec Max Bit Rate (bps)
30sec Max Bit Rate (bps)
------------------------ ------------------------
---------------------------------------------------
ms-lync 60580
55911
31174777
28774864
3613000
93000
3613000
3437000
Total 60580
55911
31174777
28774864
3613000
93000
3613000
3437000
show policy-map interface
Displays the QoS statistics and the configured policy maps on all interfaces.
The following is a sample output for the policy-maps configured on all the interfaces:
Device# show policy-map int
GigabitEthernet1/0/1
Service-policy input: MARKING-IN
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
108
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
109
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
110
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
Flows added: 26
Flows aged: 13
- Active timeout ( 1800 secs) 1
- Inactive timeout ( 15 secs) 12
clear flow monitor wdavc statistics
Clears the statistics of the specified flow monitor. Use the show flow monitor wdavc statistics command
after using the clear flow monitor wdavc statistics to verify that all the statistics have been reset. The
following is a sample output of the show flow monitor wdavc statistics command after clearing flow monitor
statistics.
Device# show flow monitor wdavc statistics
Cache type: Normal (Platform cache)
Cache size: 12000
Current entries: 0
Flows added: 0
Flows aged: 0
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
111
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
Flows added: 26
Flows aged: 13
- Active timeout ( 1800 secs) 1
- Inactive timeout ( 15 secs) 12
CONN IPV4 INITIATOR ADDR CONN IPV4 RESPONDER ADDR CONN RESPONDER PORT
FLOW OBSPOINT ID IP VERSION IP PROT APP NAME flow
dirn ...................
------------------------ ------------------------ -------------------
---------------- ---------- ------- ---------------------------
---------
[Link] [Link] 53
4294967305 4 17 port dns Input
....................
[Link] [Link] 67
4294967305 4 17 layer7 dhcp Input
....contd...........
[Link] [Link] 68
4294967305 4 17 layer7 dhcp Input
....................
[Link] [Link] 443
4294967305 4 6 layer7 ms-lync Input
....................
[Link] [Link] 443
4294967305 4 6 layer7 cisco-jabber-im Input
....contd...........
[Link] [Link] 68
4294967305 4 17 layer7 dhcp Input
....................
[Link] [Link] 67
4294967305 4 17 layer7 dhcp Input
....................
[Link] [Link] 5060
4294967305 4 17 layer7 cisco-jabber-control Input
....contd...........
[Link] [Link] 68
4294967305 4 17 layer7 dhcp Input
....................
[Link] [Link] 5060
4294967305 4 6 layer7 cisco-collab-control Input
....................
[Link] [Link] 80
4294967305 4 6 layer7 google-services Input
....contd...........
[Link] [Link] 68
4294967305 4 17 layer7 dhcp Input
....................
[Link] [Link] 67
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
112
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
Flows added: 26
Flows aged: 13
- Active timeout ( 1800 secs) 1
- Inactive timeout ( 15 secs) 12
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
113
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
114
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
115
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
116
Configuring Application Visibility and Control in a Wired Network
Examples: Application Visibility and Control Configuration
Flows added: 26
Flows aged: 13
- Active timeout ( 1800 secs) 1
- Inactive timeout ( 15 secs) 12
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
117
Configuring Application Visibility and Control in a Wired Network
Basic Troubleshooting - Questions and Answers
dns,Input,08:55:46.917,08:55:46.917,Initiator,2,1,1,190,106
[Link],[Link],67,4294967305,4,17,layer7
dhcp,Input,08:55:47.917,08:55:47.917,Initiator,1,0,1,0,350
[Link],[Link],68,4294967305,4,17,layer7
dhcp,Input,08:55:47.917,08:55:53.917,Initiator,1,0,4,0,1412
[Link],[Link],443,4294967305,4,6,layer7 ms-
lync,Input,08:55:46.917,08:55:46.917,Initiator,2,10,14,6490,1639
[Link],[Link],443,4294967305,4,6,layer7 cisco-jabber-
im,Input,08:55:46.917,08:55:46.917,Initiator,2,12,10,5871,2088
[Link],[Link],68,4294967305,4,17,layer7
dhcp,Input,08:55:47.917,08:55:47.917,Initiator,1,0,2,0,712
[Link],[Link],67,4294967305,4,17,layer7
dhcp,Input,08:55:47.917,08:55:47.917,Initiator,1,0,1,0,350
[Link],[Link],5060,4294967305,4,17,layer7 cisco-jabber-
control,Input,08:55:46.917,08:55:46.917,Initiator,1,0,2,0,2046
[Link],[Link],68,4294967305,4,17,layer7
dhcp,Input,08:55:47.917,08:55:47.917,Initiator,1,0,2,0,712
[Link],[Link],5060,4294967305,4,6,layer7 cisco-collab-
control,Input,08:55:46.917,08:55:47.917,Initiator,2,23,27,12752,8773
[Link],[Link],80,4294967305,4,6,layer7 google-
services,Input,08:55:46.917,08:55:46.917,Initiator,2,3,5,1733,663
[Link],[Link],68,4294967305,4,17,layer7
dhcp,Input,08:55:47.917,08:55:53.917,Initiator,1,0,4,0,1412
[Link],[Link],67,4294967305,4,17,layer7
dhcp,Input,08:55:47.917,08:55:47.917,Initiator,1,0,1,0,350
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
118
Configuring Application Visibility and Control in a Wired Network
Additional References for Application Visibility and Control
Answer: This usually indicates that NBAR sees asymmetric traffic: one side of the traffic is classified
in one switch member and the other on a different member. The recommendation is to attach NBAR
only on access ports where we see both sides of the traffic. If you have multiple uplinks, you can’t attach
NBAR on them due to this issue. Similar issue happens if you configure NBAR on an interface that is
part of a port channel.
7. Question: With protocol-discovery, I see an aggregate view of all application. How can I see traffic
distribution over time?
Answer: WebUI will give you view of traffic over time for the last 48 hours.
8. Question: I can't configure queue-based egress policy with match protocol protocol-name command.
Answer: Only shape and set DSCP are supported in a policy with NBAR2 based classifiers. Common
practice is to set DSCP on ingress and perform shaping on egress based on DSCP.
9. Question: I don’t have NBAR2 attached to any interface but I still see that NBAR2 is activated.
Answer: If you have any class-map with match protocol protocol-name, NBAR will be globally
activated on the stack but no traffic will be subjected to NBAR classification. This is an expected
behavior and it does not consume any resources.
10. Question: I see some traffic under the default QOS queue. Why?
Answer: For each new flow, it takes a few packets to classify it and install the result in the hardware.
During this time, the classification would be 'un-known' and traffic will fall under the default queue.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
119
Configuring Application Visibility and Control in a Wired Network
Feature History for Application Visibility and Control in a Wired Network
Cisco IOS XE Fuji 16.8.1a Wired Application Support for defining QoS classes and policies based
Visibility and Control on Network-Based Application Recognition
(Wired AVC) (NBAR) attributes instead of specific protocols,
Attribute-based QoS was made available, with a few limitations. Only
(EasyQoS) business-relevance and traffic-class are the
supported NBAR attributes.
Cisco IOS XE Gibraltar Application Visibility AVC is a critical part of Cisco’s efforts to evolve
16.11.1 and Control in a Wired its Branch and Campus solutions from being strictly
Network packet and connection based to being
application-aware and application-intelligent.
Cisco IOS XE Gibraltar DNS flow record Support for DNS flow record was introduced. DNS
16.12.1 flow record uses the DNS Domain-Name as the
collect field for defining the flow record.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
120
CHAPTER 5
Configuring SDM Templates
• Information About SDM Templates, on page 121
• How to Configure SDM Templates, on page 121
• Monitoring and Maintaining SDM Templates, on page 122
• Configuration Examples for SDM Templates, on page 123
• Additional References for SDM Templates, on page 124
• Feature History for SDM Templates, on page 124
It is recommended that you reload the system as soon as you make a change to the SDM template. After you
change the template and the system reboots, you can use the show sdm prefer privileged EXEC command
to verify the new template configuration. If you enter the show sdm prefer command before you enter the
reload privileged EXEC command, the show sdm prefer command shows the template currently in use
and the template that will become active after a reload.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
121
Configuring SDM Templates
Monitoring and Maintaining SDM Templates
Procedure
Device> enable
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
122
Configuring SDM Templates
Configuration Examples for SDM Templates
Command Purpose
show sdm prefer Displays the SDM template in use.
Note The SDM templates contain only those commands that are defined as part of the templates. If a template
enables another related command that is not defined in the template, then this other command will be visible
when the show running config command is entered. For example, if the SDM template enables the switchport
voice vlan command, then the spanning-tree portfast edge command may also be enabled (although it is
not defined on the SDM template).
If the SDM template is removed, then other such related commands are also removed and have to be
reconfigured explicitly.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
123
Configuring SDM Templates
Additional References for SDM Templates
Cisco IOS XE Fuji 16.9.2 SDM Template Standard SDM templates can be used to configure
system resources to optimize support for specific
features.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
124
Configuring SDM Templates
Feature History for SDM Templates
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to Cisco Feature Navigator.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
125
Configuring SDM Templates
Feature History for SDM Templates
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
126
CHAPTER 6
Configuring System Message Logs
• Information About Configuring System Message Logs, on page 127
• How to Configure System Message Logs, on page 129
• Monitoring and Maintaining System Message Logs, on page 137
• Configuration Examples for System Message Logs, on page 137
• Additional References for System Message Logs, on page 138
• Feature History for System Message Logs, on page 138
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
127
Configuring System Message Logs
System Log Message Format
The part of the message preceding the percent sign depends on the setting of these global configuration
commands:
• service sequence-numbers
• service timestamps log datetime
• service timestamps log datetime [localtime] [msec] [show-timezone]
• service timestamps log uptime
Element Description
seq no: Stamps log messages with a sequence number only if the service sequence-numbers
global configuration command is configured.
timestamp formats: Date and time of the message or event. This information appears only if the service
timestamps log [datetime | log] global configuration command is configured.
mm/dd h h:mm:ss
or
hh:mm:ss (short
uptime)
or
d h (long uptime)
facility The facility to which the message refers (for example, SNMP, SYS, and so forth).
description Text string containing detailed information about the event being reported.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
128
Configuring System Message Logs
Syslog Message Limits
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
129
Configuring System Message Logs
Setting the Message Display Destination Device
Procedure
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
130
Configuring System Message Logs
Synchronizing Log Messages
Procedure
Step 2 line [console | vty] line-number Specifies the line to be configured for
[ending-line-number] synchronous logging of messages.
Example: • console —Specifies configurations that
occur through the switch console port or
Device(config)# line console the Ethernet management port.
• line vty line-number—Specifies which vty
lines are to have synchronous logging
enabled. You use a vty connection for
configurations that occur through a Telnet
session. The range of line numbers is from
0 to 15.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
131
Configuring System Message Logs
Disabling Message Logging
Device(config)# end
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
132
Configuring System Message Logs
Enabling and Disabling Time Stamps on Log Messages
Device(config)# end
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
133
Configuring System Message Logs
Enabling and Disabling Sequence Numbers in Log Messages
Device(config)# end
Procedure
Device(config)# end
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
134
Configuring System Message Logs
Limiting Syslog Messages Sent to the History Table and to SNMP
Step 3 logging monitor level Limits messages logged to the terminal lines.
Example: By default, the terminal receives debugging
messages and numerically lower levels.
Device(config)# logging monitor 3
Step 4 logging trap level Limits messages logged to the syslog servers.
Example: By default, syslog servers receive informational
messages and numerically lower levels.
Device(config)# logging trap 3
Device(config)# end
Procedure
Step 2 logging history level Changes the default level of syslog messages
stored in the history file and sent to the SNMP
Example:
server.
Device(config)# logging history 3 By default, warnings, errors, critical, alerts,
and emergencies messages are sent.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
135
Configuring System Message Logs
Logging Messages to a UNIX Syslog Daemon
Device(config)# end
Note Some recent versions of UNIX syslog daemons no longer accept by default syslog packets from the network.
If this is the case with your system, use the UNIX man syslogd command to decide what options must be
added to or removed from the syslog command line to enable logging of remote syslog messages.
Procedure
Step 2 Enter these commands at the UNIX shell Creates the log file. The syslog daemon sends
prompt. messages at this level or at a more severe level
to this file.
Example:
$ touch /var/log/[Link]
$ chmod 666 /var/log/[Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
136
Configuring System Message Logs
Monitoring and Maintaining System Message Logs
show archive log config {all | number Displays the entire configuration log or the log for specified
[end-number] | user username [session parameters.
number] number [end-number] | statistics}
[provisioning]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
137
Configuring System Message Logs
Example: Switch System Message
Cisco IOS XE Fuji 16.9.2 System Message Logs A switch sends the output from system messages
to a logging process. The logging process controls
the distribution of logging messages to various
destinations, such as the logging buffer, terminal
lines, or a UNIX syslog server, depending on your
configuration
Cisco IOS XE Cupertino System Message Logs This feature was implemented on
17.9.1 C9200CX-12P-2X2G, C9200CX-8P-2X2G, and
C9200CX-12T-2X2G models of the Cisco Catalyst
9200CX Series Switches, which were introduced
in this release.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
138
CHAPTER 7
Configuring Online Diagnostics
• Restrictions for Online Diagnostics, on page 139
• Information About Configuring Online Diagnostics, on page 139
• How to Configure Online Diagnostics, on page 143
• Monitoring and Maintaining Online Diagnostics, on page 147
• Configuration Examples for Online Diagnostics, on page 148
• Additional References for Online Diagnostics, on page 150
• Feature History for Configuring Online Diagnostics, on page 150
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
139
Configuring Online Diagnostics
Generic Online Diagnostics (GOLD) Tests
Note • Before you enable online diagnostics tests, enable console logging to see all the warning messages.
• While tests are running, all the ports are shut down because a stress test is being performed with looping
ports internally, and external traffic might affect the test results. Reboot the switch to bring it to normal
operation. When you run the command to reload a switch, the system will ask you if the configuration
should be saved. Do not save the configuration.
• If you are running tests on other modules, after a test is initiated and complete, you must reset the module.
Attribute Description
Default Off.
Corrective action –
DiagThermalTest
This test verifies the temperature reading from a device sensor.
Attribute Description
Default On.
Corrective action –
DiagPhyLoopbackTest
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
140
Configuring Online Diagnostics
Generic Online Diagnostics (GOLD) Tests
This PHY loopback test verifies the PHY-level loopback functionality. In this test, a packet, which loops back
at the PHY level and is matched against the stored packet, is sent. It cannot be run as a health-monitoring test.
Note In certain cases when this test is run on-demand, ports are moved to the error-disabled state. In such cases,
use the shut and no shut command in interface configuration mode to reenable these ports.
Attribute Description
Default Off.
Corrective action –
DiagScratchRegisterTest
This Scratch Register test monitors the health of ASICs by writing values into registers, and reading back the
values from these registers.
Attribute Description
Default On.
Corrective action –
DiagPoETest
This test checks the Power over Ethernet (PoE) controller functionality. Do not perform this test during normal
switch operation.
Attribute Description
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
141
Configuring Online Diagnostics
Generic Online Diagnostics (GOLD) Tests
Attribute Description
Default Off.
Corrective action –
DiagStackCableTest
This test verifies the stack-ring loopback functionality in the stacking environment. It cannot be run as a
health-monitoring test.
Attribute Description
Default Off.
Corrective action If the test fails, check the stack cables and connectors.
TestUnusedPortLoopback
This test verifies the PHY-level loopback functionality for admin-down ports. In this test, a packet which
loops back at the PHY level and is matched against the stored packet, is sent.
Attribute Description
Default Off.
Corrective action Displays a syslog message if the test fails for a port.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
142
Configuring Online Diagnostics
How to Configure Online Diagnostics
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
143
Configuring Online Diagnostics
Scheduling Online Diagnostics
Procedure
Step 2 diagnostic schedule number test {name | Schedules on-demand diagnostic test for a
test-id | test-id-range | all | basic | complete | specific day and time.
minimal | non-disruptive | per-port} {daily |
When specifying the test to be scheduled, use
on mm dd yyyy hh:mm | port inter-port-number
these options:
port-number-list | weekly day-of-week hh:mm}
• name: Name of the test that appears in the
Example:
show diagnostic content command output.
Device(config)# diagnostic schedule 3 • test-id: ID number of the test that appears
test 1-5 on July 3 2013 23:10
in the show diagnostic content command
output.
• test-id-range: ID numbers of the tests that
appear in the show diagnostic content
command output.
• all: All test IDs.
• basic: Starts the basic on-demand
diagnostic tests.
• complete: Starts the complete test suite.
• minimal: Starts the minimal bootup test
suite.
• non-disruptive: Starts the nondisruptive
test suite.
• per-port: Starts the per-port test suite.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
144
Configuring Online Diagnostics
Configuring Health-Monitoring Diagnostics
Procedure
Device> enable
Step 3 diagnostic monitor interval switch number Configures the health-monitoring interval of
test {name | test-id | test-id-range | all} the specified test.
hh:mm:ss milliseconds day
When specifying a test, use one of these
Example: parameters:
• name: Name of the test that appears in
Device(config)# diagnostic monitor
interval switch 2 test 1 12:30:00 750 the show diagnostic content command
5 output.
• test-id: ID number of the test that appears
in the show diagnostic content command
output.
• test-id-range: ID numbers of the tests that
appear in the show diagnostic content
command output.
• all: All the diagnostic tests.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
145
Configuring Online Diagnostics
Configuring Health-Monitoring Diagnostics
Step 5 diagnostic monitor threshold switch number (Optional) Sets the failure threshold for the
number test {name | test-id | test-id-range | health-monitoring test.
all} failure count count
When specifying the tests, use one of these
Example: parameters:
• name: Name of the test that appears in
Device(config)# diagnostic monitor
threshold switch 2 test 1 failure count the show diagnostic content command
20 output.
• test-id: ID number of the test that appears
in the show diagnostic content command
output.
• test-id-range: ID numbers of the tests that
appear in the show diagnostic content
command output.
• all: All the diagnostic tests.
Step 6 diagnostic monitor switchnumber test {name Enables the specified health-monitoring tests.
| test-id | test-id-range | all}
The switch number keyword is supported only
Example: on stacking switches.
When specifying the tests, use one of these
Device(config)# diagnostic monitor
switch 2 test 1 parameters:
• name: Name of the test that appears in
the show diagnostic content command
output.
• test-id: ID number of the test that appears
in the show diagnostic content command
output.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
146
Configuring Online Diagnostics
Monitoring and Maintaining Online Diagnostics
Device(config)# end
Step 8 show diagnostic { content | post | result | (Optional) Display the online diagnostic test
schedule | status | switch } results and the supported test suites.
Command Purpose
show diagnostic content switch [number | all] Displays the online diagnostics configured for a switch.
show diagnostic status Displays the diagnostic tests that are running currently.
.
show diagnostic result switch [number | all] Displays the online diagnostics test results.
[detail | test {name | test-id | test-id-range | all}
[detail]]
show diagnostic switch [number | all] [detail] Displays the online diagnostics test results.
show diagnostic schedule [number | all] Displays the online diagnostics test schedule.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
147
Configuring Online Diagnostics
Configuration Examples for Online Diagnostics
Command Purpose
show diagnostic post Displays the POST results. (The output is the same as
the show post command output.)
show diagnostic events {event-type | module} Displays diagnostic events such as error, information,
or warning based on the test result.
show diagnostic description module [number] Displays the short description of the results from an
test { name | test-id | all } individual test or all the tests.
This example shows how to start all of the basic diagnostic tests:
This example shows how to schedule diagnostic testing to occur weekly at a certain time on a specific switch:
Device(config)# diagnostic schedule switch 1 test 1,2,4-6 weekly saturday 10:30
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
148
Configuring Online Diagnostics
Example: Displaying Online Diagnostics
Test iterations = 1
Action on test failure = continue
This example shows how to display the description for a diagnostic test:
DiagGoldPktTest :
The GOLD packet Loopback test verifies the MAC level loopback
functionality. In this test, a GOLD packet, for which doppler
provides the support in hardware, is sent. The packet loops back
at MAC level and is matched against the stored packet. It is a non
-disruptive test.
DiagThermalTest :
This test verifies the temperature reading from the sensor is below the yellow
temperature threshold. It is a non-disruptive test and can be run as a health
monitoring test.
DiagFanTest :
This test verifies all fan modules have been inserted and working properly on the
board
It is a non-disruptive test and can be run as a health monitoring test.
DiagPhyLoopbackTest :
The PHY Loopback test verifies the PHY level loopback
functionality. In this test, a packet is sent which loops back
at PHY level and is matched against the stored packet. It is a
disruptive test and cannot be run as a health monitoring test.
DiagScratchRegisterTest :
The Scratch Register test monitors the health of application-specific
integrated circuits (ASICs) by writing values into registers and reading
back the values from these registers. It is a non-disruptive test and can
be run as a health monitoring test.
DiagPoETest :
This test checks the PoE controller functionality. This is a disruptive test
and should not be performed during normal switch operation.
Device#
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
149
Configuring Online Diagnostics
Additional References for Online Diagnostics
Cisco IOS XE Fuji 16.9.2 Online Diagnostics With online diagnostics, you can test and verify the
hardware functionality of the device while the
device is connected to a live network.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
150
CHAPTER 8
Consistency Checker
• Limitations for Consistency Checker, on page 151
• Information about Consistency Checker, on page 152
• Running the Consistency Checker, on page 153
• Output Examples for Consistency Checker, on page 153
• Feature History for Consistency Checker, on page 159
• Forwarding engine hardware (FED) check is not entirely supported in Layer3 Multicast Consistency
Checker. You can only detect and report on programming failures.
• Forwarding Manager-RP software entry is not supported in Layer3 Multicast Consistency Checker.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
151
Consistency Checker
Information about Consistency Checker
Note The consistency checker is bound to CPU utilization and can not exceed the configured value while validating
the tables across processes.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
152
Consistency Checker
Running the Consistency Checker
Command Purpose
show consistency-checker mcast l2m Runs the consistency-checker on the Layer 2 multicast
forwarding tables.
show consistency-checker mcast l3m Runs the consistency-checker on the Layer 3 multicast
forwarding tables.
show consistency-checker run-id run-id Runs the End-to-End consistency-checker by run ID.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
153
Consistency Checker
Output Examples for Consistency Checker
Device#
*Feb 17 06:19:14.889: %FED_CCK_ERRMSG-4-INCONSISTENCY_FOUND: F0/0: fed: Consistency
Checker(CCK) detected inconsistency for l2m_vlan. Check 'show consistency run-id 2 detail'.
*Feb 17 06:19:14.890: %FED_CCK_ERRMSG-4-INCONSISTENCY_FOUND: F0/0: fed: Consistency
Checker(CCK) detected inconsistency for l2m_group. Check 'show consistency run-id 2 detail'.
Device#
*Feb 17 06:19:19.432: %IOSXE_FMANRP_CCK-6-FMANRP_COMPLETED: Consistency Check for Run-Id 2
is completed. Check 'show consistency-checker run-id 2'.
Device#
Device# show consistency-checker run-id 2 status
Process: IOSD
Object-Type Status Time(sec) Exceptions
l2m_vlan Completed 13 No
l2m_group Completed 13 No
Process: FMAN-FP
Object-Type Status Time(sec) State
l2m_vlan Completed 9 Consistent
l2m_group Completed 9 Consistent
Process: FED
Object-Type Status Time(sec) State
l2m_vlan Completed 9 Inconsistent
l2m_group Completed 9 Inconsistent
Device#
Device# show consistency-checker run-id 2
Process: IOSD
Object-Type Start-time Entries Exceptions
l2m_vlan 2021/02/17 06:19:05 22 0
l2m_group 2021/02/17 06:19:05 24 0
Process: FMAN-FP
*Statistics(A/I/M/S/Oth): Actual/Inherited/Missing/Stale/Others
Process: FED
*Statistics(A/I/M/S/HW/Oth): Actual/Inherited/Missing/Stale/Hardware/Others
Device#
Device# show consistency-checker run-id 2 detail
Process: IOSD
Process: FMAN-FP
Process: FED
Object-Type:l2m_vlan Start-time:2021/02/17 06:19:05
Status:Completed State:Inconsistent
Key/data Reason
(Ipv4, vlan: 768) Stale
snoop:off stp_tcn:off flood:off pimsn:off
(Ipv4, vlan: 769) Stale
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
154
Consistency Checker
Output Examples for Consistency Checker
Device#
The following is a sample output for the show consistency-checker mcast l2m command where the consistency
checker runs a recursive single-entry scan:
Device# show consistency-checker mcast l2m start vlan 900 [Link] recursive
Single entry scan started with Run_id: 2
Process: FMAN-FP
*Statistics(A/I/M/S/O): Actual/Inherited/Missing/Stale/Others
Process: FED
*Statistics(A/I/M/S/HW/O): Actual/Inherited/Missing/Stale/Hardware/Others
Device#
Device# show consistency-checker run-id 2 detail
Process: IOSD
Object-Type:l2m_vlan Start-time:2021/02/17 06:54:01
Key/data Reason
(Ipv4, vlan:900) Success
snoop:on stp_tcn:off flood:off pimsn:off
Process: FMAN-FP
Process: FED
Object-Type:l2m_group Start-time:2021/02/17 06:54:01
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
155
Consistency Checker
Output Examples for Consistency Checker
Status:Completed State:Inconsistent
Key/data Reason
(Ipv4, vlan:900 (*,[Link])) Inherited
Group ports: total entries: 1
TwentyFiveGigE1/0/5
---------------Recursion-level-1-----------------
Object-Type:l2m_vlan Start-time:2021/02/17 06:54:01
Status:Completed State:Inconsistent
Key/data Reason
(Ipv4, vlan: 900) Inconsistent
snoop:on stp_tcn:off flood:on pimsn:off
Device#
The following is a sample output for the show consistency-checker objects command where the consistency
checker runs a scan on objects:
Device# show consistency-checker objects l2m_group
Process: IOSD
Run-id Start-time Exception
1 2021/02/17 05:20:42 0
2 2021/02/17 06:19:05 0
Process: FMAN-FP
*Statistics(A/I/M/S/Oth): Actual/Inherited/Missing/Stale/Others
Process: FED
*Statistics(A/I/M/S/HW/Oth): Actual/Inherited/Missing/Stale/Hardware/Others
Device#
Stark#sh consistency-checker run 2 detail
Process: IOSD
Object-Type:l2m_vlan Start-time:2021/02/17 06:54:01
Key/data Reason
(Ipv4, vlan:900) Success
snoop:on stp_tcn:off flood:off pimsn:off
Process: FMAN-FP
Process: FED
Object-Type:l2m_group Start-time:2021/02/17 06:54:01
Status:Completed State:Inconsistent
Key/data Reason
(Ipv4, vlan:900 (*,[Link])) Inherited
Group ports: total entries: 1
TwentyFiveGigE1/0/5
---------------Recursion-level-1-----------------
Object-Type:l2m_vlan Start-time:2021/02/17 06:54:01
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
156
Consistency Checker
Output Examples for Consistency Checker
Status:Completed State:Inconsistent
Key/data Reason
(Ipv4, vlan: 900) Inconsistent
snoop:on stp_tcn:off flood:on pimsn:off
Process: FMAN-FP
Process: FED
Object-Type:l2m_group Start-time:2021/02/17 06:19:05
Status:Completed State:Inconsistent
Key/data Reason
(Ipv4, vlan:100 (*,[Link])) Inconsistent
Group ports: total entries: 0
(Ipv4, vlan:100 (*,[Link])) Missing
(Ipv4, vlan:100 (*,[Link])) Inconsistent
Group ports: total entries: 0
(Ipv4, vlan:100 (*,[Link])) Missing
(Ipv4, vlan:100 (*,[Link])) Inconsistent
Group ports: total entries: 0
(Ipv4, vlan:100 (*,[Link])) Inconsistent
Group ports: total entries: 0
Device#
The following is a sample output for the show consistency-checker mcast l3m command where the consistency
checker runs a full scan:
Device#sh consistency-checker mcast l3m start all
L3 multicast Full scan started. Run_id: 1
Use 'show consistency-checker run-id 1 status' for completion status.
Device#
*Apr 2 17:30:01.831: %IOSXE_FMANRP_CCK-6-FMANRP_COMPLETED: Consistency Check for Run-Id 1
is completed. Check 'show consistency-checker run-id 1'.
Device#sh consistency-checker run-id 1
Process: IOSD
Flags: F - Full Table Scan, S - Single Entry Run
RE - Recursive Check, GD - Garbage Detector
Hw - Hardware Check, HS - Hardware Shadow Copy
Object-Type Start-time Entries Exceptions Flags
l3m_entry 2021/04/02 17:29:35 8 0 F GD Hw HS
Process: FMAN-FP
*Statistics(A/I/M/S/Oth): Actual/Inherited/Missing/Stale/Others
Process: FED
*Statistics(A/I/M/S/HW/Oth): Actual/Inherited/Missing/Stale/Hardware/Others
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
157
Consistency Checker
Output Examples for Consistency Checker
Process: FMAN-FP
Object-Type Status Time(sec) State
l2m_vlan Completed 12 Consistent
l2m_group Completed 12 Consistent
l3m_entry Completed 12 Consistent
Process: FED
Object-Type Status Time(sec) State
l2m_vlan Completed 12 Consistent
l2m_group Completed 12 Consistent
l3m_entry Completed 12 Consistent
Process: FMAN-FP
Process: FED
The following is a sample output for the show consistency-checker mcast l3m command where the consistency
checker runs a recursive single-entry scan:
Device#sh consistency-checker mcast l3m start [Link] [Link] recursive
Single entry scan started with Run_id: 4
Use 'show consistency-checker run-id 4 status' for completion status.
Device#sh consistency-checker run-id 4 status
Process: IOSD
Object-Type Status Time(sec) Exceptions
l2m_vlan Completed 10 No
l2m_group Completed 10 No
l3m_entry Completed 10 No
Process: FMAN-FP
Object-Type Status Time(sec) State
l2m_vlan Completed 11 Consistent
l2m_group Completed 11 Consistent
l3m_entry Completed 11 Consistent
Process: FED
Object-Type Status Time(sec) State
l2m_vlan Completed 11 Consistent
l2m_group Completed 11 Consistent
l3m_entry Completed 11 Consistent
Device#sh consistency-checker run-id 4 detail
Process: IOSD
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
158
Consistency Checker
Feature History for Consistency Checker
Process: FMAN-FP
Process: FED
The following is a sample output for the show diagnostic content command where end to end consistency
is checked through gold diagnostics:
Device#show diagnostic content switch all
switch 2 module 1:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
159
Consistency Checker
Feature History for Consistency Checker
Cisco IOS XE Amsterdam Consistency Checker The Consistency Checker collects information on
17.3.1 various table states within the software and the
hardware and flags any inconsistency it finds
immediately. It supplements basic troubleshooting
and helps to identify scenarios where inconsistent
states between software and hardware tables are
causing issues in the network, thereby reducing the
mean time to resolve the issue.
Cisco IOS XE Bengaluru Consistency Checker This feature was enhanced and the multicast
17.6.1 consistency checkers were introduced. The
following keywords were added to the show
consistency-checker command: mcast, objects,
and run-id.
Use the Cisco Feature Navigator to find information about platform and software image support. To access
Cisco Feature Navigator, go to [Link]
[Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
160
CHAPTER 9
Managing Configuration Files
• Prerequisites for Managing Configuration Files, on page 161
• Restrictions for Managing Configuration Files, on page 161
• Information About Managing Configuration Files, on page 161
• How to Manage Configuration File Information, on page 168
• Feature History for Managing Configuration Files, on page 195
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
161
Managing Configuration Files
Configuration Mode and Selecting a Configuration Source
files can be different. For example, you may want to change the configuration for a short time period rather
than permanently. In this case, you would change the running configuration using the configure terminal
EXEC command but not save the configuration using the copy running-config startup-config EXEC
command.
To change the running configuration, use the configure terminal command, as described in the Modifying
the Configuration File, on page 169 section. As you use the Cisco IOS configuration modes, commands
generally are executed immediately and are saved to the running configuration file either immediately after
you enter them or when you exit a configuration mode.
To change the startup configuration file, you can either save the running configuration file to the startup
configuration using the copy running-config startup-config EXEC command or copy a configuration file
from a file server to the startup configuration (see the “Copying a Configuration File from a TFTP Server to
the Router” section for more information).
Configuring from the terminal allows you to enter configuration commands at the command line, as described
in the following section. See the “Re-executing the Configuration Commands in the Startup Configuration
File” section for more information.
Configuring from the network allows you to load and execute configuration commands over the network. See
the “Copying a Configuration File from a TFTP Server to the Switch” section for more information.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
162
Managing Configuration Files
Copy Configuration Files from a Network Server to the Device
• On Class A Flash file system platforms, the startup configuration is stored in the location specified by
the CONFIG_FILE environment variable (see the Specifying the CONFIG_FILE Environment Variable
on Class A Flash File Systems , on page 190 section). The CONFIG_FILE variable defaults to NVRAM
and can be a file in the following file systems:
• nvram: (NVRAM)
• flash: (internal flash memory)
• usbflash0: (external usbflash file system)
• usbflash1: (external usbflash file system)
The copy{ftp: | rcp: | tftp:system:running-config} EXEC command loads the configuration files into the
device as if you were typing the commands on the command line. The device does not erase the existing
running configuration before adding the commands. If a command in the copied configuration file replaces
a command in the existing configuration file, the existing command is erased. For example, if the copied
configuration file contains a different IP address in a particular command than the existing configuration, the
IP address in the copied configuration is used. However, some commands in the existing configuration may
not be replaced or negated. In this case, the resulting configuration file is a mixture of the existing configuration
file and the copied configuration file, with the copied configuration file having precedence.
To restore a configuration file to an exact copy of a file stored on a server, you need to copy the configuration
file directly to the startup configuration (using the copy ftp:| rcp:| tftp:} nvram:startup-config command)
and reload the device.
To copy configuration files from a server to a device, perform the tasks described in the following sections.
The protocol that you use depends on which type of server you are using. The FTP and rcp transport mechanisms
provide faster performance and more reliable delivery of data than TFTP. These improvements are possible
because the FTP and rcp transport mechanisms are built on and use the TCP/IP stack, which is
connection-oriented.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
163
Managing Configuration Files
Copying a Configuration File from the Device to an RCP Server
Restrictions
The RCP protocol requires a client to send a remote username on each RCP request to a server. When you
copy a configuration file from the device to a server using RCP, the Cisco IOS software sends the first valid
username it encounters in the following sequence:
1. The username specified in the copy EXEC command, if a username is specified.
2. The username set by the ip rcmd remote-username global configuration command, if the command
is configured.
3. The remote username associated with the current tty (terminal) process. For example, if the user is connected
to the device through Telnet and was authenticated through the username command, the device software
sends the Telnet username as the remote username.
4. The device host name.
For the RCP copy request to execute successfully, an account must be defined on the network server for the
remote username. If the server has a directory structure, the configuration file or image is written to or copied
from the directory associated with the remote username on the server. For example, if the system image resides
in the home directory of a user on the server, you can specify that user name as the remote username.
Use the ip rcmd remote-username command to specify a username for all copies. (Rcmd is a UNIX routine
used at the super-user level to execute commands on a remote machine using an authentication scheme based
on reserved port numbers. Rcmd stands for “remote command”). Include the username in the copy command
if you want to specify a username for that copy operation only.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
164
Managing Configuration Files
Requirements for the RCP Username
If you are writing to the server, the RCP server must be properly configured to accept the RCP write request
from the user on the device. For UNIX systems, you must add an entry to the .rhosts file for the remote user
on the RCP server. For example, suppose the device contains the following configuration lines:
hostname Device1
ip rcmd remote-username User0
If the device IP address translates to [Link], then the .rhosts file for User0 on the RCP server
should contain the following line:
[Link] Device1
For the RCP copy request to execute, an account must be defined on the network server for the remote
username. If the server has a directory structure, the configuration file or image is written to or copied from
the directory associated with the remote username on the server. For example, if the system image resides in
the home directory of a user on the server, specify that user name as the remote username.
Refer to the documentation for your RCP server for more information.
Note The password must not contain the special character '@'. If the character '@' is used, the copy fails to parse
the IP address of the server.
The FTP protocol requires a client to send a remote username and password on each FTP request to a server.
When you copy a configuration file from the device to a server using FTP, the Cisco IOS software sends the
first valid username it encounters in the following sequence:
1. The username specified in the copy EXEC command, if a username is specified.
2. The username set by the ip ftp username global configuration command, if the command is configured.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
165
Managing Configuration Files
Copying files through a VRF
3. Anonymous.
The device sends the first valid password it encounters in the following sequence:
1. The password specified in the copy command, if a password is specified.
2. The password set by the ip ftp password command, if the command is configured.
3. The device forms a password username @[Link] . The variable username is the username
associated with the current session, devicename is the configured host name, and domain is the domain
of the device.
The username and password must be associated with an account on the FTP server. If you are writing to the
server, the FTP server must be properly configured to accept the FTP write request from the user on the device.
If the server has a directory structure, the configuration file or image is written to or copied from the directory
associated with the username on the server. For example, if the system image resides in the home directory
of a user on the server, specify that user name as the remote username.
Refer to the documentation for your FTP server for more information.
Use the ip ftp username and ip ftp password global configuration commands to specify a username and
password for all copies. Include the username in the copy EXEC command if you want to specify a username
for that copy operation only.
Example
The following example shows how to copy files through a VRF, using the copy command:
Device#
Address or name of remote host [[Link]]?
Source username [ScpUser]?
Source filename [/auto/tftp-server/ScpUser/vrf_test.txt]?
Destination filename [vrf_test.txt]?
Getting the vrf name as test-vrf
Password:
Sending file modes: C0644 10 vrf_test.txt
!
223 bytes copied in 22.740 secs (10 bytes/sec)
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
166
Managing Configuration Files
Configuration Files Larger than NVRAM
After the configurations are copied, to save your configurations, use write memory command and then either
reload the switch or run the copy startup-config running-config command
Boot ROMs do not support NVRAM compression Config NOT written to NVRAM
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
167
Managing Configuration Files
Network Versus Host Configuration Files
configuration for the device is a mixture of the original startup configuration and the one or two downloaded
configuration files.
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
168
Managing Configuration Files
Modifying the Configuration File
Procedure
Device> enable
Step 4 Do one of the following: Ends the configuration session and exits to
EXEC mode.
• end
• ^Z Note
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
169
Managing Configuration Files
Copying a Configuration File from the Device to a TFTP Server
Examples
In the following example, the device prompt name of the device is configured. The comment line,
indicated by the exclamation mark (!), does not execute any command. The hostname command is
used to change the device name from device to new_name. By pressing Ctrl-Z (^Z) or entering the
end command, the user quits configuration mode. The copy system:running-config
nvram:startup-config command saves the current configuration to the startup configuration.
When the startup configuration is NVRAM, it stores the current configuration information in text
format as configuration commands, recording only non-default settings. The memory is checksummed
to guard against corrupted data.
Note Some specific commands might not get saved to NVRAM. You need to enter these commands again
if you reboot the machine. These commands are noted in the documentation. We recommend that
you keep a list of these settings so that you can quickly reconfigure your device after rebooting.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
170
Managing Configuration Files
What to Do Next
Procedure
Device> enable
Step 2 copy system:running-config tftp: [[[//location Copies the running configuration file to a TFTP
]/directory ]/filename ] server.
Example:
Step 3 copy nvram:startup-config tftp: [[[//location Copies the startup configuration file to a TFTP
]/directory ]/filename ] server.
Example:
Examples
The following example copies a configuration file from a device to a TFTP server:
What to Do Next
After you have issued the copy command, you may be prompted for additional information or for confirmation
of the action. The prompt displayed depends on how much information you provide in the copy command
and the current setting of the file prompt global configuration command.
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
171
Managing Configuration Files
Examples
Device> enable
Device(config)# end
Examples
Storing a Running Configuration File on an RCP Server
The following example copies the running configuration file named runfile2-confg to the netadmin1 directory
on the remote host with an IP address of [Link]:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
172
Managing Configuration Files
What to Do Next
Device(config)# end
What to Do Next
After you have issued the copy EXEC command, you may be prompted for additional information or for
confirmation of the action. The prompt displayed depends on how much information you provide in the copy
command and the current setting of the file prompt global configuration command.
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
173
Managing Configuration Files
Examples
Examples
Storing a Running Configuration File on an FTP Server
The following example copies the running configuration file named runfile-confg to the netadmin1 directory
on the remote host with an IP address of [Link]:
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
174
Managing Configuration Files
What to Do Next
What to Do Next
After you have issued the copy EXEC command, you may be prompted for additional information or for
confirmation of the action. The prompt displayed depends on how much information you provide in the copy
command and the current setting of the file prompt global configuration command.
Procedure
Device> enable
Step 2 copy tftp: [[[//location]/directory]/filename] Copies a configuration file from a TFTP server
system:running-config to the running configuration.
Example:
Device# copy
t[Link]
system:running-config
Step 3 copy tftp: [[[//location]/directory]/filename] Copies a configuration file from a TFTP server
nvram:startup-config to the startup configuration.
Example:
Device# copy
t[Link]
nvram:startup-config
Device# copy
t[Link]
flash:startup-config
Examples
In the following example, the software is configured from the file named tokyo-confg at IP
address [Link]:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
175
Managing Configuration Files
What to Do Next
What to Do Next
After you have issued the copy EXEC command, you may be prompted for additional information or for
confirmation of the action. The prompt displayed depends on how much information you provide in the copy
command and the current setting of the file prompt global configuration command.
Procedure
Device> enable
Step 5 Do one of the following: Copies the configuration file from an rcp server
to the running configuration or startup
• copy
configuration.
rcp:[[[//[username@]location]/directory]/filename]system:running-config
• copy
rcp:[[[//[username@]location]/directory]/filename]nvram:startup-config
Example:
Device# copy
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
176
Managing Configuration Files
Examples
Examples
Copy RCP Running-Config
The following example copies a configuration file named host1-confg from the netadmin1 directory on the
remote server with an IP address of [Link], and loads and runs the commands on the device:
What to Do Next
After you have issued the copy EXEC command, you may be prompted for additional information or for
confirmation of the action. The prompt displayed depends on how much information you provide in the copy
command and the current setting of the file prompt global configuration command.
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
177
Managing Configuration Files
Examples
Device> enable
Step 6 Do one of the following: Using FTP copies the configuration file from a
network server to running memory or the startup
• copy ftp:
configuration.
[[[//[username[:password]@]location]
/directory
]/filename]system:running-config
• copy ftp: [[[
/[username[:password]@]location]/directory]/filename]nvram:startup-config
Example:
Examples
Copy FTP Running-Config
The following example copies a host configuration file named host1-confg from the netadmin1 directory on
the remote server with an IP address of [Link], and loads and runs the commands on the device:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
178
Managing Configuration Files
Copy FTP Startup-Config
device#
%SYS-5-CONFIG: Configured from host1-config by ftp from [Link]
What to Do Next
After you have issued the copy EXEC command, you may be prompted for additional information or for
confirmation of the action. The prompt displayed depends on how much information you provide in the copy
command and the current setting of the file prompt global configuration command.
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
179
Managing Configuration Files
Compressing the Configuration File
Device(config)# end
Device(config)# copy
system:running-config
nvram:startup-config
Examples
The following example compresses a 129-KB configuration file to 11 KB:
Device(config)# end
Building configuration...
Compressing configuration from 129648 bytes to 11077 bytes
[OK]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
180
Managing Configuration Files
Storing the Configuration in Flash Memory on Class A Flash File Systems
Procedure
Device> enable
Step 4 boot config flash-filesystem: filename Specifies that the startup configuration file be
stored in flash memory by setting the
Example:
CONFIG_FILE variable.
Device(config)# boot config
usbflash0:switch-config
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
181
Managing Configuration Files
Loading the Configuration Commands from the Network
Device(config)# copy
system:running-config
nvram:startup-config
Examples
The following example stores the configuration file in usbflash0:
Device(config)# end
Procedure
Device> enable
Step 2 copy system:running-config {ftp: | rcp: | Saves the running configuration to an FTP,
tftp:} RCP, or TFTP server.
Example:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
182
Managing Configuration Files
Copying Configuration Files from Flash Memory to the Startup or Running Configuration
Device(config)# end
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
183
Managing Configuration Files
Copying Configuration Files Between Flash Memory File Systems
Examples
The following example copies the file named ios-upgrade-1 from partition 4 of the flash memory
PC Card in usbflash0 to the device startup configurations:
[OK]
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
184
Managing Configuration Files
Copying a Configuration File from an FTP Server to Flash Memory Devices
Example
The following example copies the file named running-config from partition 1 on internal flash memory
to partition 1 of usbflash0 on a device. In this example, the source partition is not specified, so the
device prompts for the partition number:
System flash
Partition Size Used Free Bank-Size State Copy Mode
1 4096K 3070K 1025K 4096K Read/Write Direct
2 16384K 1671K 14712K 8192K Read/Write Direct
[Type ?<no> for partition directory; ? for full directory; q to abort]
Which partition? [default = 1]
System flash directory, partition 1:
File Length Name/status
1 3142748 dirt/network/mars-test/[Link]
2 850 running-config
[3143728 bytes used, 1050576 available, 4194304 total]
usbflash0 flash directory:
File Length Name/status
1 1711088 dirt/gate/c3600-i-mz
2 850 running-config
[1712068 bytes used, 2482236 available, 4194304 total]
Source file name? running-config
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
185
Managing Configuration Files
What to Do Next
Device> enable
Step 6 copy ftp: [[//location]/directory ]/bundle_name Copies the configuration file from a network
flash: server to the flash memory device using FTP.
Example:
Device>copy
ftp:/cat9k_iosxe.[Link] flash:
What to Do Next
After you have issued the copy EXEC command, you may be prompted for additional information or for
confirmation of the action. The prompt displayed depends on how much information you provide in the copy
command and the current setting of the file prompt global configuration command.
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
186
Managing Configuration Files
Copying a Configuration File from a TFTP Server to Flash Memory Devices
Device> enable
Step 5 copy rcp: [[[//[username@]location ]/directory] Copies the configuration file from a network
/bundle_name] flash: server to the flash memory device using RCP.
Respond to any device prompts for additional
Example:
information or confirmation. Prompting depends
on how much information you provide in the
Device# copy
rcp://netadmin@[Link]/bundle1 copy command and the current setting of the
flash: file prompt command.
Procedure
Device> enable
Step 2 copy tftp: [[[//location ]/directory Copies the file from a TFTP server to the flash
]/bundle_name flash: memory device. Reply to any device prompts
for additional information or confirmation.
Example:
Prompting depends on how much information
you provide in the copy command and the
Device#
copy current setting of the file prompt command.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
187
Managing Configuration Files
Re-executing the Configuration Commands in the Startup Configuration File
Examples
The following example shows the copying of the configuration file named switch-config from a
TFTP server to the flash memory card inserted in usbflash0. The copied file is renamed new-config.
Device#
copy tftp:switch-config usbflash0:new-config
Procedure
Device> enable
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
188
Managing Configuration Files
Deleting a Specified Configuration File
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
189
Managing Configuration Files
Specifying the CONFIG_FILE Environment Variable on Class A Flash File Systems
Procedure
Device> enable
Step 2 copy [flash-url | ftp-url | rcp-url | tftp-url | Copies the configuration file to the flash file
system:running-config | system from which the device loads the file on
nvram:startup-config] dest-flash-url restart.
Example:
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
190
Managing Configuration Files
What to Do Next
Examples
The following example copies the running configuration file to the device. This configuration is then
used as the startup configuration when the system is restarted:
What to Do Next
After you specify a location for the startup configuration file, the nvram:startup-config command is aliased
to the new location of the startup configuration file. The more nvram:startup-config EXEC command
displays the startup configuration, regardless of its location. The erase nvram:startup-config EXEC command
erases the contents of NVRAM and deletes the file pointed to by the CONFIG_FILE environment variable.
When you save the configuration using the copy system:running-config nvram:startup-config command,
the device saves a complete version of the configuration file to the location specified by the CONFIG_FILE
environment variable and a distilled version to NVRAM. A distilled version is one that does not contain access
list information. If NVRAM contains a complete configuration file, the device prompts you to confirm your
overwrite of the complete version with the distilled version. If NVRAM contains a distilled configuration,
the device does not prompt you for confirmation and proceeds with overwriting the existing distilled
configuration file in NVRAM.
Note If you specify a file in a flash device as the CONFIG_FILE environment variable, every time you save your
configuration file with the copy system:running-config nvram:startup-config command, the old
configuration file is marked as “deleted,” and the new configuration file is saved to that device. Eventually,
Flash memory fills up as the old configuration files still take up memory. Use the squeeze EXEC command
to permanently delete the old configuration files and reclaim the space.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
191
Managing Configuration Files
Configuring the Device to Download Configuration Files
If the device fails to load a configuration file during startup, it tries again every 10 minutes (the default setting)
until a host provides the requested files. With each failed attempt, the device displays the following message
on the console terminal:
If there are any problems with the startup configuration file, or if the configuration register is set to ignore
NVRAM, the device enters the Setup command facility.
Procedure
Device> enable
Step 3 boot network {ftp:[[[//[username [:password Specifies the network configuration file to
]@]location ]/directory ]/filename ] | download at startup, and the protocol to be used
rcp:[[[//[username@]location ]/directory (TFTP, RCP, or FTP).
]/filename ] | tftp:[[[//location ]/directory
• If you do not specify a network
]/filename ]}
configuration filename, the Cisco IOS
Example: software uses the default filename
network-confg. If you omit the address,
Device(config)# boot network the device uses the broadcast address.
tftp:hostfile1
• You can specify more than one network
configuration file. The software tries them
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
192
Managing Configuration Files
Configuring the Device to Download the Host Configuration File
Device(config)# end
Procedure
Device> enable
Step 3 boot host {ftp:[[[//[username [:password Specifies the host configuration file to download
]@]location ]/directory ]/filename ] | at startup, and the protocol to be used (FTP,
rcp:[[[//[username@]location ]/directory RCP, or TFTP):
]/filename ] | tftp:[[[//location ]/directory
• If you do not specify a host configuration
]/filename ] }
filename, the device uses its own name to
Example: form a host configuration filename by
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
193
Managing Configuration Files
Configuring the Device to Download the Host Configuration File
Device(config)# end
Example
In the following example, a device is configured to download the host configuration file named
hostfile1 and the network configuration file named networkfile1. The device uses TFTP and the
broadcast address to obtain the file:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
194
Managing Configuration Files
Feature History for Managing Configuration Files
Cisco IOS XE Fuji 16.9.2 Managing Configuration Configuration files contain the Cisco IOS software
Files commands used to customize the functionality of
your Cisco device. Commands are parsed
(translated and executed) by the Cisco IOS software
when the system is booted (from the startup-config
file) or when you enter commands at the CLI in a
configuration mode.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
195
Managing Configuration Files
Feature History for Managing Configuration Files
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
196
CHAPTER 10
Secure Copy
This document provides the procedure to configure a Cisco device for Secure Copy (SCP) server-side
functionality.
• Prerequisites for Secure Copy, on page 197
• Information About Secure Copy, on page 197
• How to Configure Secure Copy, on page 198
• Configuration Examples for Secure Copy, on page 202
• Additional References for Secure Copy, on page 202
• Feature History for Secure Copy, on page 203
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
197
Secure Copy
Secure Copy Performance Improvements
Note • Enable the SCP option while using the [Link] file.
• An RSA public-private key pair must be configured on the device for SSH to work.
Similar to SCP, SSH File Transfer Protocol (SFTP) can be used to copy switch configuration or image files.
For more information, refer the Configuring SSH File Transfer Protocol chapter of the Security Configuration
Guide.
Procedure
Device> enable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
198
Secure Copy
Configuring SCP Username Password
Step 4 aaa authentication login {default | list-name} Enables the AAA access control system.
method1 [ method2... ]
Example:
Device(config)# exit
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
199
Secure Copy
Enabling Secure Copy on the SSH Server
Procedure
Step 4 aaa authentication login default local Sets AAA authentication to use the local
username database for authentication at login.
Example:
Device(config)# aaa authentication login
default local
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
200
Secure Copy
Enabling Secure Copy on the SSH Server
Step 7 ip ssh time-out seconds Sets the time interval (in seconds) that the
device waits for the SSH client to respond.
Example:
Device(config)# ip ssh time-out 120
Step 9 ip scp server enable Enables the device to securely copy files from
a remote workstation.
Example:
Device(config)# ip scp server enable
Step 10 ip ssh bulk-mode window-size (Optional) Sets the bulk mode window size to
enhance the throughput performance of SCP.
Example:
Device(config)# ip ssh bulk-mode Note
33107232 Beginning from Cisco IOS XE Dublin
17.10.1, SSH bulk data transfer mode is
enabled by default with default window size
of 128KB.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
201
Secure Copy
Configuration Examples for Secure Copy
! AAA authentication and authorization must be configured properly in order for SCP to work.
Device> enable
Device# configure terminal
Device(config)# aaa new-model
Device(config)# aaa authentication login default local
Device(config)# aaa authorization exec default local
Device(config)# username user1 privilege 15 password 0 lab
! SSH must be configured and functioning properly.
Device(config)# ip scp server enable
Device(config)# end
! AAA authentication and authorization must be configured properly for SCP to work.
Device> enable
Device# configure terminal
Device(config)# aaa new-model
Device(config)# aaa authentication login default group tacacs+
Device(config)# aaa authorization exec default group tacacs+
! SSH must be configured and functioning properly.
Device(config)# ip ssh time-out 120
Device(config)# ip ssh authentication-retries 3
Device(config)# ip scp server enable
Device(config)# end
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
202
Secure Copy
Feature History for Secure Copy
Technical Assistance
Description Link
Cisco IOS XE Fuji 16.9.2 Secure Copy The Secure Copy feature provides a secure and
authenticated method for copying device
configurations or device image files. SCP relies on
SSH, an application and protocol that provide a
secure replacement for the Berkeley r-tools suite.
The following commands were introduced or
modified: debug ip scp and ip scp server enable.
Cisco IOS XE Amsterdam Secure Copy SSH bulk mode enables certain optimizations to
17.2.1 Performance enhance the throughput performance of procedures
Improvements involving large amount of data transfer. This mode
can be enabled by using the ip ssh bulk-mode
global configuration command.
Cisco IOS XE Bengaluru Secure Copy Secure copy in large RTT settings can be
17.6.1 Improvement in Large configured by using the window-size variable option
RTT Scenario of the ip ssh bulk-mode command.
Cisco IOS XE Dublin 17.10.1 Secure Copy SSH bulk mode is enabled by default with the
Performance default window size of 128KB.
Improvements
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
203
Secure Copy
Feature History for Secure Copy
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
204
CHAPTER 11
Configuration Replace and Configuration
Rollback
• Prerequisites for Configuration Replace and Configuration Rollback, on page 205
• Restrictions for Configuration Replace and Configuration Rollback, on page 206
• Information About Configuration Replace and Configuration Rollback, on page 206
• How to Use Configuration Replace and Configuration Rollback, on page 209
• Configuration Examples for Configuration Replace and Configuration Rollback, on page 215
• Additional References for Configuration Replace and Configuration Rollback, on page 218
• Feature History for Configuration Replace and Configuration Rollback, on page 218
These indentation rules describe how the software creates configuration files for such commands as show
running-config or copy running-config destination-url. Any configuration file generated on a Cisco device
complies with these rules.
Free memory larger than the combined size of the two configuration files (the current running configuration
and the saved replacement configuration) is required.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
205
Configuration Replace and Configuration Rollback
Restrictions for Configuration Replace and Configuration Rollback
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
206
Configuration Replace and Configuration Rollback
Configuration Replace
Configuration Replace
The configure replace privileged EXEC command provides the capability to replace the current running
configuration with any saved Cisco IOS configuration file. This functionality can be used to revert to a previous
configuration state, effectively rolling back any configuration changes that were made since the previous
configuration state was saved.
When using the configure replace command, you must specify a saved Cisco IOS configuration as the
replacement configuration file for the current running configuration. The replacement file must be a complete
configuration generated by a Cisco IOS device (for example, a configuration generated by the copy
running-config destination-url command), or, if generated externally, the replacement file must comply with
the format of files generated by Cisco IOS devices. When the configure replace command is entered, the
current running configuration is compared with the specified replacement configuration and a set of diffs is
generated. The algorithm used to compare the two files is the same as that employed by the show archive
config differences command. The resulting diffs are then applied by the Cisco IOS parser to achieve the
replacement configuration state. Only the diffs are applied, avoiding potential service disruption from reapplying
configuration commands that already exist in the current running configuration. This algorithm effectively
handles configuration changes to order-dependent commands (such as access lists) through a multiple pass
process. Under normal circumstances, no more than three passes are needed to complete a configuration
replace operation, and a limit of five passes is performed to preclude any looping behavior.
The Cisco IOS copy source-url running-config privileged EXEC command is often used to copy a stored
Cisco IOS configuration file to the running configuration. When using the copy source-url running-config
command as an alternative to the configure replace target-url privileged EXEC command, the following
major differences should be noted:
• The copy source-url running-config command is a merge operation and preserves all of the commands
from both the source file and the current running configuration. This command does not remove commands
from the current running configuration that are not present in the source file. In contrast, the configure
replace target-url command removes commands from the current running configuration that are not
present in the replacement file and adds commands to the current running configuration that need to be
added.
• The copy source-url running-config command applies every command in the source file, whether or
not the command is already present in the current running configuration. This algorithm is inefficient
and, in some cases, can result in service outages. In contrast, the configure replace target-url command
only applies the commands that need to be applied—no existing commands in the current running
configuration are reapplied.
• A partial configuration file may be used as the source file for the copy source-url running-config
command, whereas a complete Cisco IOS configuration file must be used as the replacement file for the
configure replace target-url command.
A locking feature for the configuration replace operation was introduced. When the configure replace
command is used, the running configuration file is locked by default for the duration of the configuration
replace operation. This locking mechanism prevents other users from changing the running configuration
while the replacement operation is taking place, which might otherwise cause the replacement operation to
terminate unsuccessfully. You can disable the locking of the running configuration by using the no lock
keyword when issuing the configure replace command.
The running configuration lock is automatically cleared at the end of the configuration replace operation. You
can display any locks that may be currently applied to the running configuration using the show configuration
lock command.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
207
Configuration Replace and Configuration Rollback
Configuration Rollback
Configuration Rollback
The concept of rollback comes from the transactional processing model common to database operations. In
a database transaction, you might make a set of changes to a given database table. You then must choose
whether to commit the changes (apply the changes permanently) or to roll back the changes (discard the
changes and revert to the previous state of the table). In this context, rollback means that a journal file containing
a log of the changes is discarded, and no changes are applied. The result of the rollback operation is to revert
to the previous state, before any changes were applied.
The configure replace command allows you to revert to a previous configuration state, effectively rolling
back changes that were made since the previous configuration state was saved. Instead of basing the rollback
operation on a specific set of changes that were applied, the Cisco IOS configuration rollback capability uses
the concept of reverting to a specific configuration state based on a saved Cisco IOS configuration file. This
concept is similar to the database idea of saving a checkpoint (a saved version of the database) to preserve a
specific state.
If the configuration rollback capability is desired, you must save the Cisco IOS running configuration before
making any configuration changes. Then, after entering configuration changes, you can use that saved
configuration file to roll back the changes (using the configure replace target-url command). Furthermore,
because you can specify any saved Cisco IOS configuration file as the replacement configuration, you are not
limited to a fixed number of rollbacks, as is the case in some rollback models.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
208
Configuration Replace and Configuration Rollback
How to Use Configuration Replace and Configuration Rollback
Procedure
Device> enable
Device(config)# archive
Step 4 path url Specifies the location and filename prefix for
the files in the Cisco IOS configuration archive.
Example:
Note
Device(config-archive)# path If a directory is specified in the path instead of
flash:myconfiguration file, the directory name must be followed by a
forward slash as follows: path flash:/directory/.
The forward slash is not necessary after a
filename; it is only necessary when specifying
a directory.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
209
Configuration Replace and Configuration Rollback
Performing a Configuration Replace or Configuration Rollback Operation
Note
Before using this command, you must
configure the path command to specify the
location and filename prefix for the files in the
Cisco IOS configuration archive.
Note
Before using this command, you must
configure the path command to specify the
location and filename prefix for the files in the
Cisco IOS configuration archive.
Device(config-archive)# end
Note You must create a configuration archive before performing this procedure. See Creating a Configuration
Archive for detailed steps. The following procedure details how to return to that archived configuration in
the event of a problem with the current running configuration.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
210
Configuration Replace and Configuration Rollback
Performing a Configuration Replace or Configuration Rollback Operation
Procedure
Device> enable
Step 2 configure replace target-url [nolock] [list] Replaces the current running configuration file
[force] [ignore case] [revert trigger [error with a saved Cisco IOS configuration file.
][timer minutes] | time minutes] ]
• The target - url argument is a URL
Example: (accessible by the Cisco IOS file system)
of the saved Cisco IOS configuration file
Device# configure replace flash: that is to replace the current running
startup-config time 120 configuration, such as the configuration
file created using the archive config
command.
• The list keyword displays a list of the
command lines applied by the Cisco IOS
software parser during each pass of the
configuration replace operation. The total
number of passes performed is also
displayed.
• The force keyword replaces the current
running configuration file with the
specified saved Cisco IOS configuration
file without prompting you for
confirmation.
• The time minutes keyword and argument
specify the time (in minutes) within which
you must enter the configure confirm
command to confirm replacement of the
current running configuration file. If the
configure confirm command is not
entered within the specified time limit, the
configuration replace operation is
automatically reversed (in other words, the
current running configuration file is
restored to the configuration state that
existed prior to entering the configure
replace command).
• The nolock keyword disables the locking
of the running configuration file that
prevents other users from changing the
running configuration during a
configuration replace operation.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
211
Configuration Replace and Configuration Rollback
Performing a Configuration Replace or Configuration Rollback Operation
Note
In some cases, while performing the
revert trigger operation for multiple pass
operations, a partial configuration may be
missed out causing the revert operation
to the original configuration state to fail.
Step 3 configure revert { now | timer {minutes | idle (Optional) To cancel the timed rollback and
minutes} } trigger the rollback immediately, or to reset
parameters for the timed rollback, use the
Example:
configure revertcommand in privileged EXEC
mode.
Device# configure revert now
• now: Triggers the rollback immediately.
• timer: Resets the configuration revert
timer.
• Use the minutes argument with the
timer keyword to specify a new
revert time in minutes.
• Use the idle keyword along with a
time in minutes to set the maximum
allowable time period of no activity
before reverting to the saved
configuration.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
212
Configuration Replace and Configuration Rollback
Monitoring and Troubleshooting the Feature
Device# exit
Procedure
Step 1 enable
Use this command to enable privileged EXEC mode. Enter your password if prompted.
Example:
Device> enable
Device#
The following is sample output from the show archive command after several archive files of the running
configuration have been saved. In this example, the maximum number of archive files to be saved is set to
three.
Example:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
213
Configuration Replace and Configuration Rollback
Monitoring and Troubleshooting the Feature
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
214
Configuration Replace and Configuration Rollback
Configuration Examples for Configuration Replace and Configuration Rollback
Step 5 exit
Use this command to exit to user EXEC mode.
Example:
Device# exit
Device>
configure terminal
!
archive
path flash:myconfiguration
maximum 10
end
In the following example, the list keyword is specified in order to display the command lines that were applied
during the configuration replace operation:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
215
Configuration Replace and Configuration Rollback
Reverting to the Startup Configuration File
end
Total number of passes: 1
Rollback Done
The following example shows the use of the configure revert command with the timer keyword. You must
enter the configure revert command to cancel the timed rollback and trigger the rollback immediately, or to
reset parameters for the timed rollback.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
216
Configuration Replace and Configuration Rollback
Performing a Configuration Rollback Operation
running configuration. The generated output of the configure replace command indicates that only one pass
was performed to complete the rollback operation.
Note Before using the archive config command, you must configure the path command to specify the location
and filename prefix for the files in the Cisco IOS configuration archive.
You first save the current running configuration in the configuration archive as follows:
archive config
configure terminal
!
user netops2 password rain
user netops3 password snow
exit
After having made changes to the running configuration file, assume you now want to roll back these changes
and revert to the configuration that existed before the changes were made. The show archive command is
used to verify the version of the configuration to be used as a replacement file. The configure replace command
is then used to revert to the replacement configuration file as shown in the following example:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
217
Configuration Replace and Configuration Rollback
Additional References for Configuration Replace and Configuration Rollback
Cisco IOS XE Fuji 16.9.2 Configuration Replace The Cisco IOS configuration archive is intended
and Configuration to provide a mechanism to store, organize, and
Rollback manage an archive of Cisco IOS configuration files
to enhance the configuration rollback capability
provided by the configure replace command.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
218
CHAPTER 12
Software Maintenance Upgrade
Software Maintenance Upgrade (a SMU), is a package that can be installed on a system to provide a fix or a
security resolution to a released image.
• Restrictions for Software Maintenance Upgrade, on page 219
• Information About Software Maintenance Upgrade, on page 219
• How to Manage Software Maintenance Updates, on page 220
• Configuration Examples for Software Maintenance Upgrade, on page 223
• Additional References for Software Maintenance Upgrade, on page 236
• Feature History for Software Maintenance Upgrade, on page 236
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
219
Software Maintenance Upgrade
SMU Workflow
SMUs are supported only on Extended Maintenance releases and for the full lifecycle of the underlying
software release.
Perform these basic steps to install an SMU:
1. Add the SMU to the filesystem.
2. Activate the SMU on the system.
3. Commit the SMU changes so that it is persistent across reloads.
SMU Workflow
The SMU process is initiated with a request to the Cisco Customer Support. Contact your customer support
to raise an SMU request.
At release time, the SMU package is posted to the Cisco Software Download page and can be downloaded
and installed.
SMU Package
The SMU package contains a small set of files for patching the release along with metadata that describes the
contents of the package, and fix for the reported issue that the SMU is requested for. The SMU package also
supports patching of the public key infrastructure (PKI) component.
SMU Reload
All SMUs require a cold reload of the system during activation. A cold reload is the complete reload of the
operating system. This action affects the traffic flow for the duration of the reload. This reload ensures that
all processes are started with the correct libraries and files that are installed as part of the SMU.
Note If the user deletes the SMU file from the directory and performs a bootup, the device displays the error message
%BOOT-3-BOOTTIME_SMU_MISSING_DETECTED: R0/0: install_engine: SMU file
/bootflash/cat9k_iosxe-lni.BLD_POLARIS_DEV_LATEST_20210616_160027.[Link]
missing and system impact will be unknown. However, this will not lead to any functional
error.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
220
Software Maintenance Upgrade
Installing an SMU Package: 1-Step Process
Tip Use the 1-step process when you have to install just one SMU package file and use the 3-step process when
you have to install multiple SMUs. The 3-step process minimises the number of reloads required when you
have more than one SMU package file to install.
Procedure
Step 2 install add file flash: filename [activate Copies the maintenance update package from
commit] flash to the device, performs a compatibility
check for the platform and image versions,
Example:
activates the SMU package, and makes the
Device# install add file package persistent across reloads. This
flash:cat9k_lite_iosxe.[Link]
activate commit
command extracts the individual components
of the .bin file into the subpackages and
[Link] files.
You can also copy the SMU package from from
a remote location (through FTP, HTTP, HTTPS,
or TFTP).
Note
If the SMU file is copied using TFTP, use
bootflash to activate the SMU.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
221
Software Maintenance Upgrade
Installing an SMU Package: 3-Step Process
Procedure
Step 2 install add file location filename Copies the maintenance update package from
flash to the device, and then performs a
Example:
compatibility check for the platform and image
Device# install add file versions, and adds the SMU package on all
flash:cat9k_lite_iosxe.[Link]
Device# install add file
member nodes or FRUs, as applicable. This
flash:cat9k_lite_iosxe.[Link] command also runs base compatibility checks
on a file to ensure that the SMU package is
supported on the platform. It also adds an entry
in the package/[Link] file, so that its status
can be monitored and maintained.
You can also copy the SMU package from a
remote location (through FTP, HTTP, HTTPS,
or TFTP).
Step 3 install activate file location filename Activates the SMU package file that was added
and updates the package status details. You will
Example:
be promped to reload the system in order to
Device# install activate file complete the activation process.
flash:cat9k_lite_iosxe.[Link],
cat9k_lite_iosxe.[Link] When entering multiple SMUs, use a comma
(without a space before or after), to separate file
names. Also ensure that total number of
characters does not exceed 128. This step
involves a reload.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
222
Software Maintenance Upgrade
Managing an SMU
Managing an SMU
This task shows how to rollback the installation state, deactivate, and remove a previously installed SMU
package from the device. This can be used for a SMU that has been installed with the 1-step and 3-step process.
Procedure
Step 2 install rollback to {base | committed | id Returns the device to the previous installation
commit-ID} state. After the rollback, a reload is required.
Example:
Device# install rollback to committed
Step 3 install deactivate file location filename Deactivates an active package, updates the
package status, and triggers a process to restart
Example:
or reload.
Device# install deactivate file
flash:cat9k_lite_iosxe.[Link]
Step 4 install remove {file location filename | Checks if the specified SMU is inactive and if
inactive} it is, deletes it from the file system. The inactive
option deletes all the inactive packages from
Example:
the file system.
Device# install remove file
flash:cat9k_lite_iosxe.[Link]
Step 6 show install summary Displays information about the active package.
Example: The output of this command varies according
Device# show install summary to the install commands that are configured.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
223
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
Verifying the addition and installation of the SMU package file by using the show install
summary command. The status of the SMU package file is I, because it has not been activated
and committed yet.
Device# show install summary
--------------------------------------------------------------------------------
Auto abort timer: inactive
--------------------------------------------------------------------------------
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
224
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
This operation requires a reload of the system. Do you want to proceed? [y/n]y
Executing pre scripts....
Executing pre sripts done.
Initializing Hardware...
<output truncated>
###########
Jun 10 08:52:01.806: %BOOT-5-BOOTTIME_SMU_TEMP_ACTIVE_DETECTED: R0/0: install_engine:
SMU file /flash/cat9k_lite_iosxe.[Link] active temporary...
SMU commit is pending
Cisco IOS Software [Fuji], Catalyst L3 Switch Software (CAT9K_LITE_IOSXE), Version 16.9.4,
RELEASE SOFTWARE (fc2)
Technical Support: [Link]
Copyright (c) 1986-2019 by Cisco Systems, Inc.
Compiled Thu 22-Aug-19 17:30 by mcpre
<output truncated>
Verifying activation of the SMU package file by using the show install summary command.
The status of the SMU package file is U, because it has not been committed yet.
[ Switch 1 ] Installed Package(s) Information:
State (St): I - Inactive, U - Activated & Uncommitted,
C - Activated & Committed, D - Deactivated & Uncommitted
--------------------------------------------------------------------------------
Type St Filename/Version
--------------------------------------------------------------------------------
SMU U flash:cat9k_lite_iosxe.[Link]
IMG C [Link].3431
--------------------------------------------------------------------------------
Auto abort timer: active on install_activate, time before rollback - 01:41:52
--------------------------------------------------------------------------------
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
225
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
Verifying the commit by using the show install summary command. The SMU package file
has been installed, activated and committed and the status is C.
Device# show install summary
[ Switch 1 ] Installed Package(s) Information:
State (St): I - Inactive, U - Activated & Uncommitted,
C - Activated & Committed, D - Deactivated & Uncommitted
--------------------------------------------------------------------------------
Type St Filename/Version
--------------------------------------------------------------------------------
SMU C flash:cat9k_lite_iosxe.[Link]
IMG C [Link].3431
--------------------------------------------------------------------------------
Auto abort timer: inactive
--------------------------------------------------------------------------------
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
226
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
1. (Optional) Checking that the switch stack is ready and that the SMU package files are in the
device's flash.
Device# show switch
Switch/Stack Mac Address : 08ec.f586.aa80 - Local Mac Address
Mac persistency wait time: Indefinite
H/W Current
Switch# Role Mac Address Priority Version State
-------------------------------------------------------------------------------------
*1 Active 08ec.f586.aa80 1 V01 Ready
2 Member 7488.bb3c.f600 1 V01 Ready
3 Member 7488.bb3f.9c00 1 V01 Ready
4 Member 08ec.f5ee.1080 1 V01 Ready
5 Standby 08ec.f589.7c80 1 V01 Ready
Device# dir flash: | i smu
2. Copying the SMU package files from flash and adding them.
Only one SMU package file is added at a time; no reload is required between the addition of the
SMU package files.
Device# install add file flash:cat9k_lite_iosxe.[Link]
install_add: START Fri Oct 26 07:10:59 UTC 2035
Oct 26 07:11:01.695 %INSTALL-5-INSTALL_START_INFO: R0/0: install_engine: Started install
add flash:cat9k_lite_iosxe.[Link]
install_add: Adding SMU
install_add: Checking whether new add is allowed ....
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
227
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
Verifying the additiong of the first SMU package file by using the show install summary
command.
Device# show install summary
[ Switch 1 2 3 4 5 ] Installed Package(s) Information:
State (St): I - Inactive, U - Activated & Uncommitted,
C - Activated & Committed, D - Deactivated & Uncommitted
--------------------------------------------------------------------------------
Type St Filename/Version
--------------------------------------------------------------------------------
SMU I flash:cat9k_lite_iosxe.[Link]
IMG C [Link].3752
--------------------------------------------------------------------------------
Auto abort timer: inactive
--------------------------------------------------------------------------------
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
228
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
SMU_ADD: Passed on [1 2 3 4 5]
Finished SMU Add operation
Verifying the addition and installation of both the SMU package files by using the show install
summary command. The status of both package files is I, because they have not been activated
and committed yet.
Device# show install summary
--------------------------------------------------------------------------------
Auto abort timer: inactive
--------------------------------------------------------------------------------
This operation may require a reload of the system. Do you want to proceed? [y/n]y
Executing pre scripts....
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
229
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
Initializing Hardware...
#############
Oct 28 13:26:55.653: %BOOT-5-BOOTTIME_SMU_TEMP_ACTIVE_DETECTED: R0/0: install_engine:
SMU file /flash/cat9k_lite_iosxe.[Link] active temporary... SMU
commit is pending
Oct 28 13:26:55.912: %BOOT-5-BOOTTIME_SMU_TEMP_ACTIVE_DETECTED: R0/0: install_engine:
SMU file /flash/cat9k_lite_iosxe.[Link] active temporary... SMU
commit is pending
Verifying activation of the SMU package files by using the show install summary command.
The status of both files is U, because they have not been committed yet.
Device# show install summary
[ Switch 1 2 3 4 5 ] Installed Package(s) Information:
State (St): I - Inactive, U - Activated & Uncommitted,
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
230
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
--------------------------------------------------------------------------------
Auto abort timer: active on install_activate, time before rollback - 01:50:16
--------------------------------------------------------------------------------
JJ22-Vore_stack-24TE#
*Oct 28 13:35:53.749: %INSTALL-5-INSTALL_COMPLETED_INFO: Switch 1 R0/0: install_engine:
Completed install commit SMU
Verifying the commit by using the show install summary command. The SMU package files
have been installed, activated and committed, and the status is C.
Device# show install summary
[ Switch 1 2 3 4 5 ] Installed Package(s) Information:
State (St): I - Inactive, U - Activated & Uncommitted,
C - Activated & Committed, D - Deactivated & Uncommitted
--------------------------------------------------------------------------------
Type St Filename/Version
--------------------------------------------------------------------------------
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
231
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
SMU C flash:cat9k_lite_iosxe.[Link]
SMU C flash:cat9k_lite_iosxe.[Link]
IMG C [Link].3752
--------------------------------------------------------------------------------
Auto abort timer: inactive
--------------------------------------------------------------------------------
ECSG-SEC-C9200-24P#
025336: *Jun 22 2020 11:32:57 UTC: %INSTALL-5-INSTALL_COMPLETED_INFO: Switch 1 R0/0:
install_engine: Completed install add SMU
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
232
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
flash:cat9k_lite_iosxe.[Link]
--------------------------------------------------------------------------------
Auto abort timer: inactive
--------------------------------------------------------------------------------
Note You use TFTP to add the SMU package file (in the previous step) and flash, to activate - not TFTP.
Verifying that the update package is now committed, and that it will be persistent across reloads:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
233
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
Active Packages:
tftp:cat9k_lite_iosxe.[Link]
Inactive Packages:
No packages
Committed Packages:
tftp:cat9k_lite_iosxe.[Link]
Uncommitted Packages:
No packages
Device#
Active Packages:
tftp:cat9k_lite_iosxe.[Link]
Inactive Packages:
No packages
Committed Packages:
tftp:cat9k_lite_iosxe.[Link]
Uncommitted Packages:
No packages
Device#
The following is sample output from the show install active command:
Device# show install active
Active Packages:
tftp:cat3k-universalk9.2017-01-10_13.[Link]
The following example shows how to rollback an update package to the committed package:
Device# install rollback to base
The following is sample output from the show install summary command:
Device# show install summary
Active Packages:
tftp:cat9k_lite_iosxe.[Link]
Inactive Packages:
No packages
Committed Packages:
tftp:cat9k_lite_iosxe.[Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
234
Software Maintenance Upgrade
Configuration Examples for Software Maintenance Upgrade
Uncommitted Packages:
No packages
Device#
The following is sample output from the show install log command:
Initializing Hardware...
...
<after reload>
Device#
The following is sample output from the show install summary command:
Device# show install summary
Active Packages:
No packages
Inactive Packages:tftp:cat9k_lite_iosxe.[Link]
Committed Packages:
No packages
Uncommitted Packages:
No packages
Device#
The following example shows how to remove an SMU from the device:
Device# install remove file tftp:cat9k_lite_iosxe.[Link]
The following is sample output from the show install summary command:
Active Packages:
No packages
Inactive Packages:
No packages
Committed Packages:
No packages
Uncommitted Packages:
No packages
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
235
Software Maintenance Upgrade
Additional References for Software Maintenance Upgrade
Cisco IOS XE Fuji 16.9.4 Software Maintenance An SMU is a package that can be installed on a
Upgrade (SMU) system to provide a fix or a security resolution to
a released image.
On this platform, SMUs require a cold (complete)
reload of the operating system; hot patching is not
supported.
Cisco IOS XE Gibraltar Public Key The SMU package supports patching of the PKI
16.10.1 Infrastructure (PKI) component.
Patching
Cisco IOS XE Gibraltar Software Maintenance Support for this feature was introduced on the
16.12.1 Upgrade (SMU) C9200 SKUs. Hot patching is not supported.
Cisco IOS XE Cupertino Software Maintenance SMU installation is supported in install mode only.
17.9.1 Upgrade (SMU)
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
236
CHAPTER 13
Working with the Flash File System
• Information About the Flash File System, on page 237
• Displaying Available File Systems, on page 237
• Setting the Default File System, on page 240
• Displaying Information About Files on a File System, on page 240
• Changing Directories and Displaying the Working Directory , on page 241
• Creating Directories , on page 242
• Copying Files, on page 242
• Creating, Displaying and Extracting Files , on page 245
• Additional References for Flash File System, on page 247
• Feature History for Flash File System, on page 247
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
237
Working with the Flash File System
Displaying Available File Systems
- - opaque rw null:
- - opaque ro tar:
- - network rw tftp:
2097152 2089932 nvram rw nvram:
- - network rw rcp:
- - network rw http:
- - network rw ftp:
- - network rw scp:
- - network rw https:
- - opaque ro cns:
118014062592 111933124608 disk rw usbflash1:
This example displays the usbflash1 filesystem format.
Device#show usbflash1: filesys
Filesystem: usbflash1
Filesystem Path: /vol/usb1
Filesystem Type: ext4
Mounted: Read/Write
This example shows a device stack. In this example, the active device is stack member 2; the file system on
stack member 1 is displayed as flash-1:,the file system on stack member 2 is displayed as flash-2:, the file
system on stack member 3 is displayed as flash-3: and so on up to . The example also shows the crashinfo
directories and a USB flash drive plugged into the active device:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
238
Working with the Flash File System
Displaying Available File Systems
Field Value
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
239
Working with the Flash File System
Setting the Default File System
Command Description
show file systems Displays more information about each of the files on a file system.
show file descriptors Displays a list of open file descriptors. File descriptors are the internal
representations of open files. You can use this command to see if another user
has a file open.
For example, to display a list of all files in a file system, use the dir privileged EXEC command:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
240
Working with the Flash File System
Changing Directories and Displaying the Working Directory
Procedure
Device> enable
Device# pwd
Device# cd
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
241
Working with the Flash File System
Creating Directories
Creating Directories
Beginning in privileged EXEC mode, follow these steps to create a directory:
Procedure
Removing Directories
To remove a directory with all its files and subdirectories, use the delete /force /recursive filesystem:/file-url
privileged EXEC command.
Use the /recursive keyword to delete the named directory and all subdirectories and the files contained in it.
Use the /force keyword to suppress the prompting that confirms a deletion of each file in the directory. You
are prompted only once at the beginning of this deletion process.
For filesystem, use flash: for the system board flash device. For file-url, enter the name of the directory to be
deleted. All of the files in the directory and the directory are removed.
Copying Files
To copy a file from a source to a destination, use the copy source-url destination-url privileged EXEC
command. For the source and destination URLs, you can use running-config and startup-config keyword
shortcuts. For example, the copy running-config startup-config command saves the currently running
configuration file to the NVRAM section of flash memory to be used as the configuration during system
initialization.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
242
Working with the Flash File System
Copying Files from One Device in a Stack to Another Device in the Same Stack
You can also copy from special file systems (xmodem:, ymodem:) as the source for the file from a network
machine that uses the Xmodem or Ymodem protocol. SSH File Transfer Protocol (SFTP) is also another
option to copy switch configuration or image files. For more information, refer the Configuring SSH File
Transfer Protocol chapter of the Security Configuration Guide.
Network file system URLs include ftp:, rcp:, tftp:, scp:, http:, and https: and have these syntaxes:
• FTP—ftp:[[//username [:password]@location]/directory]/filename
• RCP—rcp:[[//username@location]/directory]/filename
• TFTP—tftp:[[//location]/directory]/filename
• SCP—scp:[[//username [:password]@location]/directory]/filename
• HTTP—http:[[//username [:password]@location]/directory]/filename
• HTTPS—https:[[//username [:password]@location]/directory]/filename
Note The password must not contain the special character '@'. If the character '@' is used, the copy fails to parse
the IP address of the server.
Copying Files from One Device in a Stack to Another Device in the Same Stack
To copy a file from one device in a stack to another device in the same stack, use the flash-X: notation, where
X is the device number.
To view all devices in a stack, use the show switch command in privileged EXEC mode, as in the following
example of a 9-member device stack:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
243
Working with the Flash File System
Deleting Files
To view all devices in a stack, use the show switch command in privileged EXEC mode, as in the following
example of a 8-member device stack:
Device# show switch
Switch/Stack Mac Address : 046c.9d01.3b80 - Local Mac Address
Mac persistency wait time: 4 mins
H/W Current
Switch# Role Mac Address Priority Version State
------------------------------------------------------------
*1 Active 046c.9d01.3b80 15 P4B Ready
2 Standby 046c.9d01.0f80 13 P3C Ready
3 Member 046c.9d01.1180 11 P4B Ready
4 Member 046c.9d01.0e80 9 P3C Ready
5 Member 046c.9d01.4d00 7 P3C Ready
6 Member 046c.9d01.2800 5 P3C Ready
7 Member 046c.9d01.6e80 3 P4B Ready
8 Member 046c.9d01.8180 1 P4B Ready
To view all file systems available to copy on a specific device, use the copy command as in the following
example of a 5-member stack:
Device# copy flash:?
flash:.installer
flash:.prst_sync
flash:.rollback_timer
flash:[Link]
flash:bootloader_evt_handle.log
flash:cat9k-cc_srdriver.[Link]
flash:[Link]
flash:[Link]
flash:[Link]
flash:[Link]
flash:[Link]
flash:[Link]
flash:[Link]
flash:[Link]
flash:[Link]
flash:core
flash:dc_profile_dir
flash:dc_stats.txt
flash:gs_script
flash:nvram_config
flash:[Link]
This example shows how to copy a config file stored in the flash partition of device 2 to the flash partition of
device 4. It assumes that device 2 and device 4 are in the same stack.
Deleting Files
When you no longer need a file on a flash memory device, you can permanently delete it. To delete a file or
directory from a specified flash device, use the delete [/force] [/recursive] [filesystem:]/file-url privileged
EXEC command.
Use the /recursive keyword for deleting a directory and all subdirectories and the files contained in it. Use
the /force keyword to suppress the prompting that confirms a deletion of each file in the directory. You are
prompted only once at the beginning of this deletion process. Use the /force and /recursive keywords for
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
244
Working with the Flash File System
Creating, Displaying and Extracting Files
deleting old software images that were installed by using the archive download-sw command but are no
longer needed.
If you omit the filesystem: option, the device uses the default device specified by the cd command. For file-url,
you specify the path (directory) and the name of the file to be deleted.
When you attempt to delete any files, the system prompts you to confirm the deletion.
This example shows how to delete the file myconfig from the default flash memory device:
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
245
Working with the Flash File System
Creating, Displaying and Extracting Files
Step 3 archive tar /xtract source-url flash:/file-url Extracts a file into a directory on the flash file
[dir/file...] system.
Example: For source-url, specify the source URL alias
for the local file system. The -filename. is the
Device# archive tar /xtract file from which to extract files. These options
tftp:/[Link]/saved. are supported:
flash:/new-configs
• Local flash file system syntax:
flash:
• FTP syntax:
ftp:[[//username[:password]@location]/directory]/-filename.
• RCP syntax:
rcp:[[//username@location]/directory]/-filename.
• TFTP syntax:
tftp:[[//location]/directory]/-filename.
For flash:/file-url [dir/file...], specify the
location on the local flash file system from
which the file is extracted. Use the dir/file...
option to specify a list of files or directories
within the file to be extracted. If none are
specified, all files and directories are extracted.
Step 4 more [ /ascii | /binary | /ebcdic] /file-url Displays the contents of any readable file,
including a file on a remote file system.
Example:
Device# more
flash:/new-configs
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
246
Working with the Flash File System
Additional References for Flash File System
Commands for managing flash: file systems Cisco IOS Configuration Fundamentals Command Reference
Cisco IOS XE Fuji 16.9.2 Flash File System The flash file system is a single flash device on
which you can store files. It also provides several
commands to help you manage software bundles
and configuration files.
Cisco IOS XE Cupertino Flash File System This feature was implemented on
17.9.1 C9200CX-12P-2X2G, C9200CX-8P-2X2G, and
C9200CX-12T-2X2G models of the Cisco Catalyst
9200CX Series Switches, which were introduced
in this release.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
247
Working with the Flash File System
Feature History for Flash File System
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
248
CHAPTER 14
Performing Factory Reset
• Prerequisites for Performing a Factory Reset, on page 249
• Restrictions for Performing a Factory Reset, on page 249
• Information About Performing a Factory Reset, on page 249
• How to Perform a Factory Reset, on page 251
• Configuration Examples for Performing a Factory Reset, on page 252
• Additional References for Performing a Factory Reset, on page 254
• Feature History for Performing a Factory Reset, on page 254
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
249
Performing Factory Reset
Secure Data Wipe
• Return Material Authorization (RMA) for a device: If you have to return a device to Cisco for RMA,
remove all the customer-specific data before obtaining an RMA certificate for the device.
• Recovering a compromised device: If the key material or credentials that are stored on a device are
compromised, reset the device to the factory configuration, and then reconfigure the device.
During a factory reset, the device reloads and enters ROMMON mode. After the factory reset, the device
removes all its environment variables, including the MAC_ADDRESS and the SERIAL_NUMBER variables,
which are required to locate and load the software. Perform a reset in ROMmon mode to automatically set
the environment variables. The BAUD rate environment variable returns to its default value after a factory
reset. Make sure that the BAUD rate and the console speed are the same at all times. Otherwise, the console
becomes unresponsive.
After the system reset in ROMmon mode is complete, add the Cisco IOS image either through an USB or
TFTP.
The following table provides details about the data that is erased and retained during the factory reset process:
All Cisco IOS images, including the current boot Data from remote field-replaceable units (FRUs)
image
Credentials such as FIPS-related keys Credentials such as Secure Unique Device Identifier
(SUDI) certificates, and public key infrastructure
(PKI) keys.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
250
Performing Factory Reset
How to Perform a Factory Reset
NIST 800-88 PURGE method, data cannot be recovered through simple non-invasive data recovery techniques
or advanced laboratory techniques.
Procedure
Step 2 • For a standalone device: Resets the device to its configuration at the time
of its shipping.
factory-reset {all[secure] [3-pass] |
config | boot-vars} No system configuration is required to use the
• For stacked devices: factory reset command.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
251
Performing Factory Reset
Configuration Examples for Performing a Factory Reset
Note
This option takes approximately thrice the
time taken to perform any other option.
The factory reset operation is irreversible for all operations. Are you sure? [confirm]
The following will be deleted as a part of factory reset:
1: Crash info and logs
2: User data, startup and running configuration
3: All IOS images, including the current boot image
4: OBFL logs
5: User added rommon variables
6: Data on Field Replaceable Units(USB/SSD/SATA)
The system will reload to perform factory reset.
It will take some time to complete and bring it to rommon.
You will need to load IOS image using USB/TFTP from rommon after
this operation is completed.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
252
Performing Factory Reset
Configuration Examples for Performing a Factory Reset
The following examples show how to perform a factory reset on stacked devices:
Device> enable
Device# factory-reset switch all all
The factory reset operation is irreversible for all operations. Are you sure? [confirm]
The following will be deleted as a part of factory reset:
1: Crash info and logs
2: User data, startup and running configuration
3: All IOS images, including the current boot image
4: OBFL logs
5: User added rommon variables
6: Data on Field Replaceable Units(USB/SSD/SATA)
The system will reload to perform factory reset.
It will take some time to complete and bring it to rommon.
You will need to load IOS image using USB/TFTP from rommon after
this operation is completed.
DO NOT UNPLUG THE POWER OR INTERRUPT THE OPERATION
Are you sure you want to continue? [confirm]
Chassis 1 reloading, reason - Factory Reset
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
253
Performing Factory Reset
Additional References for Performing a Factory Reset
After this the switch will come to boot prompt. Then the customer has to boot the device
from TFTP.
The following sample output from the show platform software factory-reset secure log command
displays the data sanitization report:
Device# show platform software factory-reset secure log
Factory reset log:
#CISCO C9200 DATA SANITIZATION REPORT#
START : 18-09-2022, 06:18:44
END : 18-09-2022, 06:23:36
-MTD-
PNM : nor
NIST : PURGE
-eMMC-
MID : 'Micron'
PNM : 'Q2J55L'
SN : 0x00000001
NIST : PURGE
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
254
Performing Factory Reset
Feature History for Performing a Factory Reset
Cisco IOS XE Fuji 16.9.2 Factory Reset Factory reset erases all the customer-specific data
stored in a device and restores the device to its
original configuration at the time of shipping
Cisco IOS XE Gibraltar Factory Reset for Performing a factory reset erases the contents of
16.12.1 Removable Storage removable storage devices, such as SATA, SSD,
Devices or USB.
Cisco IOS XE Amsterdam Factory Reset with A factory reset can be performed to erase all the
17.2.1 3-pass Overwrite content from the device securely with 3-pass
overwrite. The secure 3-pass keyword was
introduced.
Enhanced Factory Reset Support for factory reset on stacked devices and
Option for Stack and for Cisco StackWise Virtual enabled devices is
Cisco StackWise Virtual introduced.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
255
Performing Factory Reset
Feature History for Performing a Factory Reset
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
256
CHAPTER 15
Configuring Secure Storage
• Information About Secure Storage, on page 257
• Enabling Secure Storage , on page 257
• Disabling Secure Storage , on page 258
• Verifying the Status of Encryption, on page 258
• Feature History for Secure Storage, on page 259
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
257
Configuring Secure Storage
Disabling Secure Storage
Step 4 write memory Encrypts the private-config file and saves the
file in an encrypted format.
Example:
Device# write memory
Procedure
Step 4 write memory Decrypts the private-config file and saves the
file in plane format.
Example:
Device# write memory
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
258
Configuring Secure Storage
Feature History for Secure Storage
Cisco IOS XE Fuji 16.9.2 Secure Storage Secure Storage feature allows you to secure critical
configuration information by encrypting it. It
encrypts asymmetric key-pairs, pre-shared secrets,
the type 6 password encryption key and certain
credentials. An instance-unique encryption key is
stored in the hardware trust anchor to prevent it
from being compromised.
Use the Cisco Feature Navigator to find information about platform and software image support. To access
Cisco Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
259
Configuring Secure Storage
Feature History for Secure Storage
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
260
CHAPTER 16
Trace Management
• Information About Trace Management, on page 261
• How to Configure Conditional Debugging, on page 264
• Configuration Examples for Trace Management, on page 267
• Additional References for Trace Management, on page 270
• Feature History for Trace Management, on page 270
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
261
Trace Management
Tracing Levels
The Conditional debug allows granular debugging in a network that is operating at a large scale with a large
number of features. It allows you to observe detailed debugs for granular instances within the system. This
type of debugging is useful when we need to debug only a particular session among thousands of sessions.
It's also possible to specify multiple conditions.
A condition refers to a feature or identity, where an identity could be an interface, IP Address, or a MAC
address and so on.
Conditional debugging is in contrast to the general debug command, that produces its output without
discriminating on the feature objects that are being processed. General debug command consumes numerous
system resources and impacts the system performance.
Radioactive tracing provides the ability to form a chain of execution for operations of interest across the
system, at an increased verbosity level. This provides a way to print conditionally debug information (up to
DEBUG Level or a specified level) across threads, processes, and function calls.
Radioactive Tracing when coupled with Conditional Debugging, provides a single debug command to debug
all execution contexts related to the condition. You can execute this command without being aware of the
various control flow processes of the feature within the box and without having to issue debugs at these
processes individually.
Tracing Levels
Trace level determines the types of traces outputted. Each trace message is assigned a trace level. If the trace
level of a process or its module it set as greater than or equal to the level as the trace message, the trace message
is displayed otherwise, it's skipped. For example, the default trace level is Notice level, so all traces with the
Notice level and below the notice level are included while the traces above the Notice level are excluded.
The following table shows the available tracing levels, and provides descriptions of the message that are
displayed with each tracing level. The tracing levels listed in the table are from the lowest to the highest order.
The default trace level is Notice.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
262
Trace Management
Payload Filter
Noise All possible trace messages for the module are logged.
The noise level is always equal to the highest possible
tracing level. Even if a future enhancement to tracing
introduces a higher tracing level, the noise level will
become equal to the level of that new enhancement.
Payload Filter
This feature is used to filter trace messages. Trace messages contain actual debug information such as text
strings, special characters, and variable arguments (strings), integers, long, IPv4/IPv6/MAC addresses, and
so on. Using the payload feature, the trace messages can be filtered based on the selected criteria and without
string operations.
You can use the following set and show commands to configure a payload filter and to view the applied filters.
set platform software btrace-manager ... utm-pf Enables and disables the payload filtering feature.
enable
set platform software btrace-manager ... utm-pf
disable
set platform software btrace-manager ... Creates and deletes consumer/stream.
consumer-name <input> create
set platform software btrace-manager ...
consumer-name <input> delete
set platform software btrace-manager ... Applies and removes filter on stream/consumer
consumer-name <input> filter <input> add
set platform software btrace-manager ...
consumer-name <input> filter <input> remove
#show platform software btrace-manager ... utm-pf Shows the current status of the payload feature and
other additional details
show platform software btrace-manager ... utm-pf Shows all filters currently applied on
consumer-name <input> all-filters consumer/stream.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
263
Trace Management
How to Configure Conditional Debugging
show platform software btrace-manager ... utm-pf Shows all or selected LUID of consumer for the
consumer-name <input> all-luids applied filter.
show platform software btrace-manager ... utm-pf
consumer-name <input> filter <input>
show platform software btrace-manager ... utm-pf Shows consumer/stream messages.
message
Procedure
Device> enable
Step 2 debug platform condition mac {mac-address} Configures conditional debugging for the MAC
Address specified.
Example:
Device# debug platform condition mac
bc16.6509.3314
Step 3 debug platform condition start Starts conditional debugging (this step starts
radioactive tracing if there's a match on one of
Example:
the preceding conditions).
Device# debug platform condition start
Step 4 show platform condition OR show debug Displays the current conditions set.
Example:
Device# show platform condition
Device# show debug
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
264
Trace Management
Configuring Conditional Debugging
Step 6 request platform software trace archive [last (Optional) Displays historical logs of merged
{number} days] [target {crashinfo: | tracefiles on the system. Filter on any
flashinfo:}] combination of number of days or location.
Example:
# request platform software trace archive
last 2 days
Step 7 show platform software trace [filter-binary (Optional) Displays logs merged from the latest
| level | message] trace file. Filter on any combination of
application condition, trace module name, and
Example:
trace level.
Device# show platform software trace
message • filter-binary - Filter the modules to be
collated
• level - Show trace levels
• message - Show trace message ring
contents
Note
On the device:
• Available from IOS console in addition
to linux shell.
• Generates a file with merged logs
• Displays merged logs only from staging
area.
What to do next
Note The commands request platform software trace filter-binary and show platform software trace
filter-binary work in a similar way. The only difference is:
• request platform software trace filter-binary - Sources the data from historical logs.
• show platform software trace filter-binary – Sources the data from the flash Temp directory.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
265
Trace Management
Collecting Trace Files
The mac_log <..date..> is the important file, as it provides messages for the MAC that is being debugged.
The command show platform software trace filter-binary also generates the same flash files, and also prints
the mac_log on the screen.
You can copy the trace files using one of the following options:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
266
Trace Management
Configuring Payload Filter
Note It’s important to clear the generated report or archive files off the device so that there's flash space available
for tracelog and other purposes.
Procedure
Device> enable
Step 2 set platform software btrace-manager utm-pf Enables or disables the payload filter.
enable
Example:
Device# set platform software
btrace-manager chassis active r0 utm-pf
enable
Device# set platform software
btrace-manager chassis active r0 utm-pf
disable
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
267
Trace Management
Configuration Examples for Trace Management
The following is an example of the show logging command for the ios process.
Device# show logging process ios
Logging display requested on 2022/10/27 09:32:06 (PDT) for Hostname: [vwlc_1_9222], Model:
[C9800-CL-K9], Version: [17.11.01], SN: [9ZY0U03YBM0], MD_SN: [9ZY0U03YBM0]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
268
Trace Management
Configuration Examples for Trace Management
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
269
Trace Management
Additional References for Trace Management
Cisco IOS XE Fuji 16.9.2 Conditional Debugging The Conditional Debugging feature allows you to
and Radioactive Tracing selectively enable debugging and logging for
specific features based on the set of conditions you
define.
Cisco IOS XE Cupertino Binary Tracing Binary tracing helps in gathering of trace
17.7.x information with a minimal impact on performance.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
270
CHAPTER 17
Consent Token
• Restrictions for Consent Token, on page 271
• Information About Consent Token, on page 271
• Consent Token Authorization Process for System Shell Access, on page 272
• Feature History for Consent Token, on page 273
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
271
Consent Token
Consent Token Authorization Process for System Shell Access
administrator) to access system shell on your device. Consent Token is a lock, unlock and re-lock mechanism
that provides you with privileged, restricted, and secure access to the system shell.
When you request access to system shell, you need to be authorized. You must first run the command to
generate a challenge using the Consent Token feature on your device. The device generates a unique challenge
as output. You must then copy this challenge string and send it to a Cisco Authorized Personnel through e-mail
or Instant Message.
The Cisco Authorized Personnel processes the unique challenge string and generates a response that is unique.
The Cisco Authorized Personnel copies this response string and sends it to you through e-mail or Instant
Message.
You must then input this response string into your device. If the challenge-response pair match, you are
authorized to access system shell. If not, an error is displayed and you are required to repeat the authentication
process.
Once you gain access to system shell, collect the debug information required by the Cisco TAC engineer.
After you are done accessing system shell, terminate the session and continue the debugging process.
Figure 3: Consent Token
Procedure
Step 1 Generate a challenge requesting for access to system shell for the specified time period.
Example:
Device# request consent-token generate-challenge shell-access auth-timeout 900
zSSdrAAAAQEBAAQAAAABAgAEAAAAAAMACH86csUhmDl0BAAQ0Fvd7CxqRYUeoD7B4AwW7QUABAAAAG8GAAhDVEFfREVNTwcAGENUQV9ERU1PX0NUQV9TSUdOSU5HX0tFWQgAC0M5ODAwLUNMLUs5CQALOVpQUEVESE5KRkI=
Device#
*Jan 18 02:47:06.733: %CTOKEN-6-AUTH_UPDATE: Consent Token Update (challenge generation
attempt: Shell access 0).
Send a request for a challenge using the request consent-token generate-challenge shell-access
time-validity-slot command. The duration in minutes for which you are requesting access to system shell is
the time-slot-period.
In this example, the time period is 900 minutes after which the session expires.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
272
Consent Token
Feature History for Consent Token
The device generates a unique challenge as output. This challenge is a base-64 format string.
Input the response string sent to you by the Cisco Authorized Personnel using the request consent-token
accept-response shell-access response-string command.
If the challenge-response pair match, you are authorized to access system shell. If the challenge-response pair
do not match, an error is displayed and you are required to repeat steps 1 to 3.
After you are authorized, you can access system shell for the requested time-slot.
The device sends a message when there is ten minutes remaining of the authorization session.
Device#
*Jan 18 23:33:02.937: %CTOKEN-6-AUTH_UPDATE: Consent Token Update (terminate authentication:
Shell access 0).
Device#
When you finish accessing system shell, you can end the session using the request consent-token
terminate-auth command. You can also force terminate the session prior to the authorization timeout using
this command. The session also gets terminated automatically when the requested time slot expires.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
273
Consent Token
Feature History for Consent Token
These features are available on all releases subsequent to the one they were introduced in, unless noted
otherwise.
Cisco IOS XE Gibraltar Consent Token Consent Token is a security feature that is used to
16.11.1 authenticate the network administrator of an
organization to access system shell with mutual
consent from the network administrator and Cisco
Technical Assistance Centre (Cisco TAC).
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
274
CHAPTER 18
Troubleshooting the Software Configuration
This chapter describes how to identify and resolve software problems related to the Cisco IOS software on
the switch. Depending on the nature of the problem, you can use the command-line interface (CLI), Device
Manager, or Network Assistant to identify and solve problems.
Additional troubleshooting information, such as LED descriptions, is provided in the hardware installation
guide.
• Information About Troubleshooting the Software Configuration, on page 275
• How to Troubleshoot the Software Configuration, on page 281
• Verifying Troubleshooting of the Software Configuration, on page 289
• Scenarios for Troubleshooting the Software Configuration, on page 290
• Configuration Examples for Troubleshooting Software, on page 292
• Additional References for Troubleshooting Software Configuration, on page 294
• Feature History for Troubleshooting Software Configuration, on page 294
Note On these devices, a system administrator can disable some of the functionality of this feature by allowing an
end user to reset a password only by agreeing to return to the default configuration. If you are an end user
trying to reset a password when password recovery has been disabled, a status message reminds you to return
to the default configuration during the recovery process.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
275
Troubleshooting the Software Configuration
Ping
Note You cannot recover encryption password key, when Cisco WLC configuration is copied from one Cisco WLC
to another (in case of an RMA).
Follow the steps described in the section Recovering from a Lost or Forgotten Password, on page 281 to recover
from a lost or forgotten password.
Ping
The device supports IP ping, which you can use to test connectivity to remote hosts. Ping sends an echo request
packet to an address and waits for a reply. Ping returns one of these responses:
• Normal response—The normal response (hostname is alive) occurs in 1 to 10 seconds, depending on
network traffic.
• Destination does not respond—If the host does not respond, a no-answer message is returned.
• Unknown host—If the host does not exist, an unknown host message is returned.
• Destination unreachable—If the default gateway cannot reach the specified network, a
destination-unreachable message is returned.
• Network or host unreachable—If there is no entry in the route table for the host or network, a network
or host unreachable message is returned.
Refere the section Executing Ping, on page 287 to understand how ping works.
Layer 2 Traceroute
The Layer 2 traceroute feature allows the switch to identify the physical path that a packet takes from a source
device to a destination device. Layer 2 traceroute supports only unicast source and destination MAC addresses.
Traceroute finds the path by using the MAC address tables of the devices in the path. When the Device detects
a device in the path that does not support Layer 2 traceroute, the Device continues to send Layer 2 trace queries
and lets them time out.
The Device can only identify the path from the source device to the destination device. It cannot identify the
path that a packet takes from source host to the source device or from the destination device to the destination
host.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
276
Troubleshooting the Software Configuration
IP Traceroute
• You can enter the traceroute mac or the traceroute mac ip privileged EXEC command on a device
that is not in the physical path from the source device to the destination device. All devices in the path
must be reachable from this switch.
• The traceroute mac command output shows the Layer 2 path only when the specified source and
destination MAC addresses belong to the same VLAN. If you specify source and destination MAC
addresses that belong to different VLANs, the Layer 2 path is not identified, and an error message appears.
• If you specify a multicast source or destination MAC address, the path is not identified, and an error
message appears.
• If the source or destination MAC address belongs to multiple VLANs, you must specify the VLAN to
which both the source and destination MAC addresses belong. If the VLAN is not specified, the path is
not identified, and an error message appears.
• The traceroute mac ip command output shows the Layer 2 path when the specified source and destination
IP addresses belong to the same subnet. When you specify the IP addresses, the device uses the Address
Resolution Protocol (ARP) to associate the IP addresses with the corresponding MAC addresses and the
VLAN IDs.
• If an ARP entry exists for the specified IP address, the device uses the associated MAC address and
identifies the physical path.
• If an ARP entry does not exist, the device sends an ARP query and tries to resolve the IP address.
If the IP address is not resolved, the path is not identified, and an error message appears.
• When multiple devices are attached to one port through hubs (for example, multiple CDP neighbors are
detected on a port), the Layer 2 traceroute feature is not supported. When more than one CDP neighbor
is detected on a port, the Layer 2 path is not identified, and an error message appears.
• This feature is not supported in Token Ring VLANs.
• Layer 2 traceroute opens a listening socket on the User Datagram Protocol (UDP) port 2228 that can be
accessed remotely with any IPv4 address, and does not require any authentication. This UDP socket
allows to read VLAN information, links, presence of particular MAC addresses, and CDP neighbor
information, from the device. This information can be used to eventually build a complete picture of the
Layer 2 network topology.
• Layer 2 traceroute is disabled by default and can be enabled by running the l2 traceroute command in
global configuration mode. To disable Layer 2 traceroute, use the no l2 traceroute command in global
configuration mode
IP Traceroute
You can use IP traceroute to identify the path that packets take through the network on a hop-by-hop basis.
The command output displays all network layer (Layer 3) devices, such as routers, that the traffic passes
through on the way to the destination.
Your Device can participate as the source or destination of the traceroute privileged EXEC command and
might or might not appear as a hop in the traceroute command output. If the Device is the destination of the
traceroute, it is displayed as the final destination in the traceroute output. Intermediate devices do not show
up in the traceroute output if they are only bridging the packet from one port to another within the same VLAN.
However, if the intermediate Device is a multilayer Device that is routing a particular packet, this device
shows up as a hop in the traceroute output.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
277
Troubleshooting the Software Configuration
Debug Commands
The traceroute privileged EXEC command uses the Time To Live (TTL) field in the IP header to cause
routers and servers to generate specific return messages. Traceroute starts by sending a User Datagram Protocol
(UDP) datagram to the destination host with the TTL field set to 1. If a router finds a TTL value of 1 or 0, it
drops the datagram and sends an Internet Control Message Protocol (ICMP) time-to-live-exceeded message
to the sender. Traceroute finds the address of the first hop by examining the source address field of the ICMP
time-to-live-exceeded message.
To identify the next hop, traceroute sends a UDP packet with a TTL value of 2. The first router decrements
the TTL field by 1 and sends the datagram to the next router. The second router sees a TTL value of 1, discards
the datagram, and returns the time-to-live-exceeded message to the source. This process continues until the
TTL is incremented to a value large enough for the datagram to reach the destination host (or until the maximum
TTL is reached).
To learn when a datagram reaches its destination, traceroute sets the UDP destination port number in the
datagram to a very large value that the destination host is unlikely to be using. When a host receives a datagram
destined to itself containing a destination port number that is unused locally, it sends an ICMP port-unreachable
error to the source. Because all errors except port-unreachable errors come from intermediate hops, the receipt
of a port-unreachable error means that this message was sent by the destination port.
Go to Example: Performing a Traceroute to an IP Host, on page 293 to see an example of IP traceroute process.
Debug Commands
Caution Because debugging output is assigned high priority in the CPU process, it can render the system unusable.
For this reason, use debug commands only to troubleshoot specific problems or during troubleshooting sessions
with Cisco technical support staff. It is best to use debug commands during periods of lower network traffic
and fewer users. Debugging during these periods decreases the likelihood that increased debug command
processing overhead will affect system use.
All debug commands are entered in privileged EXEC mode, and most debug commands take no arguments.
System Report
System reports or crashinfo files save information that helps Cisco technical support representatives to debug
problems that caused the Cisco IOS image to fail (crash). It is necessary to quickly and reliably collect critical
crash information with high fidelity and integrity. Further, it is necessary to collect this information and bundle
it in a way that it can be associated or identified with a specific crash occurrence.
System reports are generated in case of a switchover: System reports are generated only on high availability
(HA) member switches. Reports are not generated for non-HA members.
The system does not generate reports in case of a reload.
During a process crash, the following is collected locally from the switch:
1. Full process core
2. Tracelogs
3. IOS syslogs (not guaranteed in case of non-active crashes)
4. System process information
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
278
Troubleshooting the Software Configuration
System Report
5. Bootup logs
6. Reload logs
7. Certain types of /proc information
This information is stored in separate files which are then archived and compressed into one bundle. This
makes it convenient to get a crash snapshot in one place, and can be then moved off the box for analysis. This
report is generated before the switch goes down to rommon/bootloader.
Except for the full core and tracelogs, everything else is a text file.
Use the request platform software process core fed switch active command to generate the core dump.
Device# request platform software process core fed switch active
SUCCESS: Core file generated.
Crashinfo Files
By default the system report file will be generated and saved into the /crashinfo directory. Ifit cannot be saved
to the crashinfo partition for lack of space, then it will be saved to the /flash directory.
To display the files, enter the dir crashinfo: command. The following is sample output of a crashinfo directory:
System reports are located in the crashinfo directory in the following format:
system-report_[switch number]_[date]-[timestamp]-[Link]
After a switch crashes, check for a system report file. The name of the most recently generated system report
file is stored in the last_systemreport file under the crashinfo directory. The system report and crashinfo files
assist TAC while troubleshooting the issue.
The system report generated can be further copied using TFTP, HTTP and few other options.
Device# copy crashinfo: ?
crashinfo: Copy to crashinfo: file system
flash: Copy to flash: file system
ftp: Copy to ftp: file system
http: Copy to http: file system
https: Copy to https: file system
null: Copy to null: file system
nvram: Copy to nvram: file system
rcp: Copy to rcp: file system
running-config Update (merge with) current system configuration
scp: Copy to scp: file system
startup-config Copy to startup configuration
syslog: Copy to syslog: file system
system: Copy to system: file system
tftp: Copy to tftp: file system
tmpsys: Copy to tmpsys: file system
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
279
Troubleshooting the Software Configuration
Onboard Failure Logging on the Switch
The tracelogs can be collected by issuing a trace archive command. This command provides time period
options. The command syntax is as follows:
Device# request platform software trace archive ?
last Archive trace files of last x days
target Location and name for the archive file
The tracelogs stored in crashinfo: or flash: directory from within the last 3650 days can be collected.
Device# request platform software trace archive last ?
<1-3650> Number of days (1-3650)
Switch#request platform software trace archive last 3650 days target ?
crashinfo: Archive file name and location
flash: Archive file name and location
Note It is important to clear the system reports or trace archives from flash or crashinfo directory once they are
copied out, in order to have space available for tracelogs and other purposes.
You should manually set the system clock or configure it by using Network Time Protocol (NTP).
When the device is running, you can retrieve the OBFL data by using the show logging onboard privileged
EXEC commands. If the device fails, contact your Cisco technical support representative to find out how to
retrieve the data.
When an OBFL-enabled device is restarted, there is a 10-minute delay before logging of new data begins.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
280
Troubleshooting the Software Configuration
How to Troubleshoot the Software Configuration
Note You can not access recovery partition when the switch is in Cisco IOS prompt. Note that the factory-reset
process does not erase this image.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
switch:
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
281
Troubleshooting the Software Configuration
Procedure with Password Recovery Enabled
Note On these switches, a system administrator can disable some of the functionality of this feature by allowing
an end user to reset a password only by agreeing to return to the default configuration. If you are an end user
trying to reset a password when password recovery has been disabled, a status message shows this during the
recovery process.
Procedure
Step 2 Set the line speed on the emulation software to 9600 baud.
Step 3 Power off the standalone switch or the entire switch stack.
Step 4 Reconnect the power cord to the switch or the active switch. As soon as the System LED blinks, press and
release the Mode button 2-3 times. The switch enters the ROMMON mode.
The following console messages are displayed during the reload:
Initializing Hardware...
Proceed to the Procedure with Password Recovery Enabled section, and follow the steps.
Step 5 After recovering the password, reload the switch or the active switch.
On a switch:
Switch> reload
Proceed with reload? [confirm] y
Procedure
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
282
Troubleshooting the Software Configuration
Procedure with Password Recovery Enabled
Device: MANUAL_BOOT=yes
Device: SWITCH_IGNORE_STARTUP_CFG=1
Note
If an error message is displayed, configure the ignore startup command as set
SWITCH_IGNORE_STARTUP_CFG=1 before entering the SWITCH_IGNORE_STARTUP_CFG=1 command.
Step 3 Boot the switch with the [Link] file from flash.
Device> enable
Device#
Press Return in response to the confirmation prompts. The configuration file is now reloaded, and you can
change the password.
Step 7 Enter global configuration mode and change the enable password.
Step 9 Write the running configuration to the startup configuration file and save the configuration.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
283
Troubleshooting the Software Configuration
Procedure with Password Recovery Disabled
Device# reload
Step 12 Boot the device with the [Link] file from flash.
Step 13 After the device boots up, disable manual boot on the device.
Would you like to reset the system back to the default configuration (y/n)?
Caution Returning the device to the default configuration results in the loss of all existing configurations. We recommend
that you contact your system administrator to verify if there are backup device and VLAN configuration files.
• If you enter n (no), the normal boot process continues as if the Mode button had not been pressed; you
cannot access the boot loader prompt, and you cannot enter a new password. You see the message:
• If you enter y (yes), the configuration file in flash memory and the VLAN database file are deleted. When
the default configuration loads, you can reset the password.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
284
Troubleshooting the Software Configuration
Procedure with Password Recovery Disabled
Procedure
Step 1 Choose to continue with password recovery and delete the existing configuration:
Would you like to reset the system back to the default configuration (y/n)? Y
You are prompted to start the setup program. To continue with password recovery, enter N at the prompt:
The secret password can be from 1 to 25 alphanumeric characters, can start with a number, is case sensitive,
and allows spaces but ignores leading spaces.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
285
Troubleshooting the Software Configuration
Preventing Autonegotiation Mismatches
Step 9 You must now reconfigure the device. If the system administrator has the backup device and VLAN
configuration files available, you should use those.
To maximize the device performance and ensure a link, follow one of these guidelines when changing the
settings for duplex and speed:
• Let both ports autonegotiate both speed and duplex.
• Manually set the speed and duplex parameters for the ports on both ends of the connection.
Note If a remote device does not autonegotiate, configure the duplex settings on the two ports to match. The speed
parameter can adjust itself even if the connected port does not autonegotiate.
Note The security error message references the GBIC_SECURITY facility. The device supports SFP modules and
does not support GBIC modules. Although the error message text refers to GBIC interfaces and modules, the
security messages actually refer to the SFP modules and module interfaces.
If you are using a non-Cisco SFP module, remove the SFP module from the device, and replace it with a Cisco
module. After inserting a Cisco SFP module, use the errdisable recovery cause gbic-invalid global
configuration command to verify the port status, and enter a time interval for recovering from the error-disabled
state. After the elapsed interval, the device brings the interface out of the error-disabled state and retries the
operation. For more information about the errdisable recovery command, see the command reference for
this release.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
286
Troubleshooting the Software Configuration
Executing Ping
If the module is identified as a Cisco SFP module, but the system is unable to read vendor-data information
to verify its accuracy, an SFP module error message is generated. In this case, you should remove and reinsert
the SFP module. If it continues to fail, the SFP module might be defective.
Executing Ping
If you attempt to ping a host in a different IP subnetwork, you must define a static route to the network or
have IP routing configured to route between those subnets.
IP routing is disabled by default on all devices.
Note Though other protocol keywords are available with the ping command, they are not supported in this release.
Use this command to ping another device on the network from the device:
Command Purpose
ping ip host | address Pings a remote host through IP or by supplying the hostname or network address.
Monitoring Temperature
The Device monitors the temperature conditions and uses the temperature information to control the fans.
Command Purpose
tracetroute mac [interface interface-id] Displays the Layer 2 path taken by the packets from
{source-mac-address} [interface interface-id] the specified source MAC address to the specified
{destination-mac-address} [vlan vlan-id] [detail] destination MAC address.
tracetroute mac ip {source-ip-address | Displays the Layer 2 path taken by the packets from
source-hostname}{destination-ip-address | the specified source IP address or hostname to the
destination-hostname} [detail] specified destination IP address or hostname.
Executing IP Traceroute
Note Though other protocol keywords are available with the traceroute privileged EXEC command, they are not
supported in this release.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
287
Troubleshooting the Software Configuration
Redirecting Debug and Error Message Output
Command Purpose
By default, the network server sends the output from debug commands and system error messages to the
console. If you use this default, you can use a virtual terminal connection to monitor debug output instead of
connecting to the console port .
Possible destinations include the console, virtual terminals, internal buffer, and UNIX hosts running a syslog
server. The syslog format is compatible with 4.3 Berkeley Standard Distribution (BSD) UNIX and its
derivatives.
Note Be aware that the debugging destination you use affects system overhead. When you log messages to the
console, very high overhead occurs. When you log messages to a virtual terminal, less overhead occurs.
Logging messages to a syslog server produces even less, and logging to an internal buffer produces the least
overhead of any method.
For more information about system message logging, see Configuring System Message Logging.
Caution Because debugging output is assigned high priority in the CPU process, it can render the system unusable.
For this reason, use debug commands only to troubleshoot specific problems or during troubleshooting sessions
with Cisco technical support staff. Moreover, it is best to use debug commands during periods of lower
network traffic and fewer users. Debugging during these periods decreases the likelihood that increased debug
command processing overhead will affect system use.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
288
Troubleshooting the Software Configuration
Verifying Troubleshooting of the Software Configuration
Example: Verifying the Problem and Cause for High CPU Utilization
To determine if high CPU utilization is a problem, enter the show processes cpu sorted privileged EXEC
command. Note the underlined information in the first line of the output example.
This example shows normal CPU utilization. The output shows that utilization for the last 5 seconds is 8%/0%,
which has this meaning:
• The total CPU utilization is 8 percent, including both time running Cisco IOS processes and time spent
handling interrupts.
• The time spent handling interrupts is zero percent.
Interrupt percentage value is The CPU is receiving too many Determine the source of the network
almost as high as total CPU packets from the network. packet. Stop the flow, or change the
utilization value. switch configuration. See the section on
“Analyzing Network Traffic.”
Total CPU utilization is greater One or more Cisco IOS process Identify the unusual event, and
than 50% with minimal time is consuming too much CPU time. troubleshoot the root cause. See the
spent on interrupts. This is usually triggered by an section on “Debugging Active
event that activated the process. Processes.”
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
289
Troubleshooting the Software Configuration
Scenarios for Troubleshooting the Software Configuration
Only one port does not have PoE. Verify that the powered device works on another PoE port.
Trouble is on only one switch port. Use the show run, or show interface status user EXEC commands
PoE and non-PoE devices do not work to verify that the port is not shut down or error-disabled.
on this port, but do on other ports.
Note
Most switches turn off port power when the port is shut down, even
though the IEEE specifications make this optional.
Verify that the total cable length from the switch front panel to the
powered device is not more than 100 meters.
Disconnect the Ethernet cable from the switch port. Use a short
Ethernet cable to connect a known good Ethernet device directly to
this port on the switch front panel (not on a patch panel). Verify that
it can establish an Ethernet link and exchange traffic with another
host, or ping the port VLAN SVI. Next, connect a powered device
to this port, and verify that it powers on.
If a powered device does not power on when connected with a patch
cord to the switch port, compare the total number of connected
powered devices to the switch power budget (available PoE). Use
the show power inline command to verify the amount of available
power.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
290
Troubleshooting the Software Configuration
Scenarios to Troubleshoot Power over Ethernet (PoE)
No PoE on all ports or a group of ports. If there is a continuous, intermittent, or reoccurring alarm related to
power, replace the power supply if possible it is a field-replaceable
Trouble is on all switch ports.
unit. Otherwise, replace the switch.
Nonpowered Ethernet devices cannot
establish an Ethernet link on any port, If the problem is on a consecutive group of ports but not all ports,
and PoE devices do not power on. the power supply is probably not defective, and the problem could
be related to PoE regulators in the switch.
Use the show log privileged EXEC command to review alarms or
system messages that previously reported PoE conditions or status
changes.
If there are no alarms, use the show interface status command to
verify that the ports are not shut down or error-disabled. If ports are
error-disabled, use the shut and no shut interface configuration
commands to reenable the ports.
Use the show env power and show power inline privileged EXEC
commands to review the PoE status and power budget (available
PoE).
Review the running configuration to verify that power inline never
is not configured on the ports.
Connect a nonpowered Ethernet device directly to a switch port. Use
only a short patch cord. Do not use the existing distribution cables.
Enter the shut and no shut interface configuration commands, and
verify that an Ethernet link is established. If this connection is good,
use a short patch cord to connect a powered device to this port and
verify that it powers on. If the device powers on, verify that all
intermediate patch panels are correctly connected.
Disconnect all but one of the Ethernet cables from switch ports.
Using a short patch cord, connect a powered device to only one PoE
port. Verify the powered device does not require more power than
can be delivered by the switch port.
Use the show power inline privileged EXEC command to verify
that the powered device can receive power when the port is not shut
down. Alternatively, watch the powered device to verify that it
powers on.
If a powered device can power on when only one powered device is
connected to the switch, enter the shut and no shut interface
configuration commands on the remaining ports, and then reconnect
the Ethernet cables one at a time to the switch PoE ports. Use the
show interface status and show power inline privileged EXEC
commands to monitor inline power statistics and port status.
If there is still no PoE at any port, a fuse might be open in the PoE
section of the power supply. This normally produces an alarm. Check
the log again for alarms reported earlier by system messages.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
291
Troubleshooting the Software Configuration
Configuration Examples for Troubleshooting Software
Cisco pre-standard powered device Verify all electrical connections from the switch to the powered
disconnects or resets. device. Any unreliable connection results in power interruptions and
irregular powered device functioning such as erratic powered device
After working normally, a Cisco phone
disconnects and reloads.
intermittently reloads or disconnects
from PoE. Verify that the cable length is not more than 100 meters from the
switch port to the powered device.
Notice what changes in the electrical environment at the switch
location or what happens at the powered device when the disconnect
occurs.
Notice whether any error messages appear at the same time a
disconnect occurs. Use the show log privileged EXEC command to
review error messages.
Verify that an IP phone is not losing access to the Call Manager
immediately before the reload occurs. (It might be a network problem
and not a PoE problem.)
Replace the powered device with a non-PoE device, and verify that
the device works correctly. If a non-PoE device has link problems
or a high error rate, the problem might be an unreliable cable
connection between the switch port and the powered device.
IEEE 802.3af-compliant or IEEE Use the show power inline command to verify that the switch power
802.3at-compliant powered devices do budget (available PoE) is not depleted before or after the powered
not work on Cisco PoE switch. device is connected. Verify that sufficient power is available for the
powered device type before you connect it.
A non-Cisco powered device is
connected to a Cisco PoE switch, but Use the show interface status command to verify that the switch
never powers on or powers on and then detects the connected powered device.
quickly powers off. Non-PoE devices
Use the show log command to review system messages that reported
work normally.
an overcurrent condition on the port. Identify the symptom precisely:
Does the powered device initially power on, but then disconnect? If
so, the problem might be an initial surge-in (or inrush) current that
exceeds a current-limit threshold for the port.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
292
Troubleshooting the Software Configuration
Example: Performing a Traceroute to an IP Host
Character Description
. Each period means the network server timed out while waiting for a reply.
To end a ping session, enter the escape sequence (Ctrl-^ X by default). Simultaneously press and release the
Ctrl, Shift, and 6 keys and then press the X key.
The display shows the hop count, the IP address of the router, and the round-trip time in milliseconds for each
of the three probes that are sent.
Character Description
A Administratively unreachable. Usually, this output means that an access list is blocking traffic.
H Host unreachable.
N Network unreachable.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
293
Troubleshooting the Software Configuration
Additional References for Troubleshooting Software Configuration
Character Description
P Protocol unreachable.
Q Source quench.
U Port unreachable.
To end a trace in progress, enter the escape sequence (Ctrl-^ X by default). Simultaneously press and release
the Ctrl, Shift, and 6 keys and then press the X key.
Cisco IOS XE Amsterdam System-Report Files The hostname is prepended to the system-report
17.3.1 files. This makes the system-report files uniquely
identifiable.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
294
CHAPTER 19
Line Auto Consolidation
• Line Auto Consolidation, on page 295
• Feature History for Line Auto Consolidation, on page 301
After auto consolidation is disabled the show run command output will be lengthy. This will impact the sizes
of the running configuration and start-up configuration files. If you disable auto consolidation you will observe
the following behaviors:
• Contiguous groups of lines that belong to the same configuration in a sub-mode will not be combined
into a single range.
Device#show run | sec line
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 9
transport input all
Device#configure terminal
Device(config)#no line auto-consolidation
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
295
Line Auto Consolidation
Line Auto Consolidation
Device(config)#line vty 10 15
Device(config-line)#transport input all
Device(config-line)#end
Device#show run | sec line
no line auto-consolidation
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 9
transport input all
line vty 10 15
transport input all
• If you disable auto consolidation after configuring some lines with auto consolidation enabled, only the
lines which were configured after auto consolidation was disabled will not be consolidated.
Device#show run | sec line
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 9
transport input all
Device#configure terminal
Device(config)#line vty 10 15
Device(config-line)#transport input all
Device(config-line)#end
Device#show run | sec line
line con 0
stopbits 1
consolidated line vty 0 4
transport input ssh
line vty 5 15
transport input all
Device#configure terminal
Device(config)#no line auto-consolidation
Device(config)#line vty 16 20
Device(config-line)#transport input all
Device(config-line)#end
Device#show run | sec line
no line auto-consolidation
line con 0
stopbits 1
consolidated line vty 0 4
transport input ssh
line vty 5 15
transport input all
line vty 16 20
transport input all
• If you enable auto consolidation after it has been disabled, lines that were not consolidated will be auto
consolidated.
Device#sh running-config | sec line
no line auto-consolidation
line con 0
exec-timeout 0 0
logging synchronous
stopbits 1
line vty 0 4
transport input ssh
line vty 5 15
transport input ssh
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
296
Line Auto Consolidation
Line Auto Consolidation
line vty 16 19
transport input ssh
Device#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Device(config)#line vty 20 25
Device(config-line)#transport input ssh
Device(config-line)#end
Device#sh running-config | sec line
no line auto-consolidation
line con 0
exec-timeout 0 0
logging synchronous
stopbits 1
line vty 0 4
transport input ssh
line vty 5 15
transport input ssh
line vty 16 19
transport input ssh
line vty 20 25
transport input ssh
Device#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Device(config)#line auto-consolidation
Device(config)#end
Device#show running-config | sec line
line con 0
exec-timeout 0 0
logging synchronous
stopbits 1
line vty 0 4
transport input ssh
line vty 5 25
transport input ssh
• You can configure lines with contiguous ranges. The configuration will be permitted.
Device#show run | sec line
no line auto-consolidation
line con 0
stopbits 1
line vty 0 4
transport input ssh
Device#configure terminal
Device(config)#line vty 5 20
Device(config)#transport input all
Device(config-line)#end
Device#show run | sec line
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 20
transport input all
• You can't configure lines with non-contiguous ranges. The configuration is rejected.
Device#show run | sec line
no line auto-consolidation
line con 0
logging synchronous
line aux 0
line vty 0 4
transport input none
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
297
Line Auto Consolidation
Line Auto Consolidation
• You can delete lines which are contiguous and at the end of the list. In the controller mode, you can
delete one line at a time. You cannot delete lines in bulk. In autonomous mode, you can delete lines in
bulk.
Device# show run | sec line
no line auto-consolidation
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 20
transport input all
Device# configure terminal
Device(config)# no line vty 5 20
Device(config)# end
Device#show run | sec line
line con 0
stopbits 1
line vty 0 4
transport input ssh
• You can't delete lines which are not contiguous and at the end of the list. You can't delete a line that will
result in a non-contiguous range when it is deleted. This will generate an error stating the line cannot be
deleted.
Device# show run | sec line
no line auto-consolidation
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 9
transport input none
line vty 10 20
transport input all
Device# configure terminal
Device(config)# no line vty 5 9
% Cannot delete the 9 line number as it is not the last VTY line number
• You can't delete lines that are in use or are default lines.
Device#show run | sec line
no line auto-consolidation
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 20
transport input ssh
Device#configure terminal
Router(config)#no line vty 15
% Can't delete last 16 VTY lines, lines in use, statbit: 0x10C40, tiptop: 590
% process name: SSH Process
• You can modify subranges in autonomous mode. This will cause the lines to split which will cause a
reverse sync of the configuration. You can’t modify subranges in the controller mode. This is a behavioural
change between the controller and autonomous modes. In the controller mode, any modification of
subranges is rejected to avoid discrepancy with the configuration pushed from a controller.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
298
Line Auto Consolidation
Line Auto Consolidation
The following examples shows how you can modify subranges in autonomous mode.
Device#show run | sec line
no line auto-consolidation
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 9
transport input none
Device#configure terminal
Device(config)#line vty 7 8
Device(config-line)#transport input telnet
Device(config-line)#end
Device#show run | sec line
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 6
transport input none
line vty 7 8
transport input telnet
line vty 9
transport input none
• The following example shows that modification of subranges is not supported in controller mode
Device#show run | sec line
no line auto-consolidation
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 9
transport input none
Device#configure terminal
Device(config)# line vty 5 8
Device(config-line)# end
Uncommitted changes found, commit them? [yes/no/CANCEL] yes
Aborted: inconsistent value: Device refused one or more commands:
line vty 5 8
^
% Invalid input detected at '^' marker.
Component Response: "
% Modifications of overlapping/sub range is not allowed in controller mode"
Error executing command: CLI command error -
Device(config)# end
• You can modify overlapping ranges in autonomous mode. This will cause the lines to split which will
cause a reverse sync of the configuration. You cannot modify overlapping ranges in the controller mode.
In the controller mode, any modification of overlapping ranges is rejected to avoid discrepancy with the
configuration pushed from a controller.
The following example shows how you can modify overlapping ranges in autonomous mode.
Device#show run | sec line
no line auto-consolidation
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 10
transport input none
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
299
Line Auto Consolidation
Line Auto Consolidation
line vty 11 20
transport input all
Device#configure terminal
Device(config)#line vty 8 12
Device(config-line)#transport input ssh
Device(config-line)#end
Device#show run | sec line
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 7
transport input none
line vty 8 10
transport input ssh
line vty 11 12
transport input ssh
line vty 13 20
transport input all
• The following example shows that modification of overlapping ranges is not supported in controller
mode.
Device#show run | sec line
no line auto-consolidation
line con 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 10
transport input none
line vty 11 20
transport input all
Device(config)# line vty 5 11
Device(config-line)# end
Uncommitted changes found, commit them? [yes/no/CANCEL] yes
Aborted: inconsistent value: Device refused one or more commands:
line vty 5 11
^
% Invalid input detected at '^' marker.
Component Response: "
% Modifications of overlapping/sub range is not allowed in controller mode"
Error executing command: CLI command error -
Device(config)# end
• You can replace a configuration from an auto consolidation enabled state to an auto consolidation disabled
state.
Device#show run | sec line
line con 0
stopbits 1
line vty 0 4
transport input all
line vty 5 9
transport input ssh
line vty 10 15
transport input telnet
line vty 16 20
transport input ssh
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
300
Line Auto Consolidation
Feature History for Line Auto Consolidation
• You can replace a configuration from an auto consolidation disabled state to an auto consolidation enabled
state
Device#show run | sec line
no line auto-consolidation
line vty 0 4
transport input all
line vty 5 20
transport input ssh
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
301
Line Auto Consolidation
Feature History for Line Auto Consolidation
Cisco IOS XE Bengaluru 17.4.1 Line Auto Consolidation Auto Consolidation of Line
commands is enabled by default.
The no line auto-consolidation
command can be used to disable
the auto consolidation of Line
commands.
The line auto-consolidation
command was introduced.
Use Cisco Feature Navigator to find information about platform and software image support. To access Cisco
Feature Navigator, go to [Link]
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
302
CHAPTER 20
Troubleshooting System Management
• Overview, on page 303
• Support Articles, on page 303
• Feedback Request, on page 304
• Disclaimer and Caution, on page 305
Overview
This chapter provides links to documents authored by Cisco subject matter experts (SMEs). They aim to help
you resolve technical issues without requiring a support ticket. If these documents are unable to resolve your
issue, we recommend visiting the applicable Cisco Community. There is a wealth of information and advice
available from fellow Cisco customers who may have experienced this issue already and provided a solution.
If you are not able to find a resolution on the Community, it may be best that you raise a support ticket at
Cisco Support. In cases where a support ticket has to be raised, these documents provide guidance about the
data that should be collected and added to the support ticket. Specify the support document you referred, and
TAC can create an improvement request with the document owner.
Support Articles
The documents in this section were created using specific software and hardware listed in the Components
Used section of each article. However, this does not mean that they are limited to what is listed in Components
Used, and generally remain relevant for later versions of software and hardware. Note that there could be
some changes in the software or hardware that can cause commands to stop working, the syntax to change,
or GUIs and CLIs to look different from one release to another.
The following are the support articles associated with this technology:
Document Description
Cisco Smart Licensing - Troubleshooting Steps and This document describes how to work with Cisco
Considerations on Catalyst platforms Smart Licensing (cloud-based system) to manage
software licenses on Catalyst switches.
Recommended Releases for Catalyst This document is to help customers find a stable
9200/9300/9400/9500/9600 and Catalyst 3650/3850 software release for the enterprise switching platforms
Platforms running Catalyst 9000 series switches.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
303
Troubleshooting System Management
Feedback Request
Document Description
Migrate Catalyst License to Smart Licensing Using This document describes what to expect after
Policy migration from an older license mechanism to the new
"Smart Licensing Using Policy" mechanism in Cisco
IOS XE 17.3.2 release and future releases.
Smart Licensing using Policy on Catalyst Switching This document describes the Smart Licensing feature
Platforms using Policy on Catalyst Switching Platforms and its
various supported deployment mechanisms, from
Cisco IOS XE 17.3.2 release and future releases.
Troubleshoot and Recover Catalyst 9000 Switches This document describes the common failure scenarios
from Upgrade Failure Scenarios that occur when Catalyst 9000 series devices are
upgraded along with the procedure to recover them.
Configuration Register equivalent CLIs in IOS-XE This document describes how to modify certain
system parameters using CLI commands on Catalyst
9000 switches running Cisco IOS XE. These
commands are an alternative to changing the
configuration-register value on Cisco IOS.
Understand Hardware Resources on Catalyst 9000 This document describes how to understand and
Switches troubleshoot hardware resources on Catalyst 9000
series switches.
Understand IPv4 Hardware Resources on Catalyst This document describes how to understand and verify
9000 Switches IPv4 Forwarding Information Base (FIB) hardware
usage on Catalyst 9000 series switches.
Use the -O Option to Ensure Successful SCP from This document describes how to use the -O option to
Clients on OpenSSH9.0 to IOS XE Devices ensure successful SCP from clients on OpenSSH9.0
to Cisco IOS XE devices.
Feedback Request
Your input helps. A key aspect to improving these support documents is customer feedback. Note that these
documents are owned and maintained by multiple teams within Cisco. If you find an issue specific to the
document (unclear, confusing, information missing, etc):
• Provide feedback using the Feedback button located at the right panel of the corresponding article. The
document owner will be notified, and will either update the article, or flag it for removal.
• Include information regarding the section, area, or issue you had with the document and what could be
improved. Provide as much detail as possible.
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
304
Troubleshooting System Management
Disclaimer and Caution
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
305
Troubleshooting System Management
Disclaimer and Caution
System Management Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9200 Switches)
306
Cisco Catalyst 9200 Series Switches facilitate MAC address management by allowing users to configure the MAC address table, set address aging times, and enable notification traps for MAC address changes, MAC moves, and MAC threshold breaches. Users can also disable MAC address learning on VLANs and add/remove static address entries, enabling precise control over network operations .
Both RCP and TFTP can be used to manage Cisco Catalyst 9200 configuration files, with RCP offering more robust security features through user authentication and TFTP presenting a simpler, less secure method primarily suitable for local network transfers. RCP's authentication capabilities make it preferable for environments requiring heightened security, whereas TFTP's simplicity supports rapid, basic configuration file management without authentication overhead .
The SMU process on Cisco Catalyst 9200 Switches involves three stages: adding, activating, and committing. The SMU package is first copied and added using 'install add file', followed by activation through 'install activate file', which may require a system reload. The final stage is committing with 'install commit', ensuring the SMU is saved and permanently implemented across reboots. This procedure allows for systematic software updates while maintaining network stability .
Configuration files on Cisco Catalyst 9200 Switches can be managed using commands like 'show running-config' and 'show startup-config' to display current settings. To recover from system reboots, configurations are saved using 'copy running-config startup-config', ensuring that any changes persist through a reboot by storing them in NVRAM. Comments can enhance configuration files but are not saved to NVRAM, prompting users to maintain additional documentation for any non-persistent settings .
Boot integrity visibility in Cisco Catalyst 9200 switches ensures that the platform's manufacturing identity and software integrity are verified and transparent, enhancing security by allowing for the detection of any unauthorized changes to the system. This capability employs boot integrity measurements, which provide administrators with critical insights into the authenticity and reliability of the software running on their devices, thus preventing potential security breaches .
To enhance monitoring effectiveness through flow records, Cisco Catalyst 9200 Switches can leverage detailed flow matching capabilities, specifying matches to IP versions, protocols, application names, and connection attributes such as client/server IP and transport ports. Collecting comprehensive statistics on byte and packet counts, as well as time stamps, provides a granular view of network flows, allowing administrators to identify and respond more swiftly to anomalies and performance issues .
To add a static MAC address on Cisco Catalyst 9200 Switches, use the command 'mac address-table static <MAC address> vlan <VLAN ID> interface <interface>' to specify the MAC, VLAN, and port. A key restriction is that the same static MAC address cannot be associated with multiple interfaces. If reconfigured for a different interface, the address is overwritten, indicating a one-to-one association .
MOTD and login banners on Cisco devices are significant as they help communicate critical information and security notices to all users who access the device. A MOTD banner is displayed on all user interfaces upon connection and can be used for general information, whereas a login banner displays during the login process and emphasizes the security aspect, reminding users of restricted access and encouraging adherence to policies .
To configure NTP on Cisco Catalyst 9200 Switches, users must setup NTP authentication, configure poll-based or broadcast-based NTP associations if necessary, and apply NTP access restrictions to limit which devices can affect the switch's time. Additionally, setting the NTP server using 'ntp server' command ensures time synchronization across devices .
Before working on Cisco Catalyst 9200 Series Switches, it is crucial to be aware of hazards involved with electrical circuitry and to be familiar with standard safety practices to prevent accidents. Users should read the installation instructions before using, installing, or connecting the system to a power source. It is recommended to refer to the device release notes before installing or upgrading the device .