General Considerations for Upgrade to FastIron Release 10.0.00 or Later

Note: Before you begin an upgrade, read the release notes for the target release carefully to familiarize yourself with any behavior and CLI changes. Refer to the latest version of the RUCKUS FastIron Release Notes.

Beginning with FastIron release 10.0.00, a switch ("Layer 2") image will no longer be provided for ICX devices. Only the router ("Layer 3") image will be available. On upgrade to FastIron 10.0.00, the configuration of any ICX devices operating with the switch image will automatically be translated to the equivalent router image configuration.

The switch image for the ICX 7550 and ICX 7650 is discontinued in FastIron release 10.0.00. When upgrading these devices there is an automated migration which will change the configuration after the upgrade.

Configuration related to the following features will be modified:

  • Management VLAN and Management Port
  • Spanning Tree Protocol (STP)
  • Multicast
  • Forwarding Profile for the ICX 7550
  • IP address is configured at the interface level
  • Support for management VLAN and the default gateway is discontinued

Before upgrade, also review the information in General Considerations for Upgrade to FastIron Release 09.0.10a or Later.

Configuration Migration Considerations

Configuration related to certain features is modified during migration to the FastIron 10.0.00 or later router image. The following table provides details.

FastIron Release 10.0.00 Configuration Migration Considerations

Feature FastIron 9.0.10x and Before Behavior FastIron 10.0.00 and Later Behavior Notes
DHCP-client (v4)

Switch Image:

  • DHCP client enabled at global level
  • No interface level configuration

Command to enable dhcp client – Ip dhcp-client enable

Command to disable dhcp client – no ip dhcp-client enable

Router Image:

  • DHCP client enabled at global level on a VE
  • Enabled at interface level including the lease setting

Command to enable dhcp client – no ip dhcp-client disable

Command to disable dhcp client – ip dhcp-client disable

Router Image:

  • DHCP client enabled at global level on a VE
  • Enabled at interface level including the lease setting

Command to enable dhcp client – no ip dhcp-client disable

Command to disable dhcp client – ip dhcp-client disable

DHCP-client is enabled by default at global level, but DHCP-client can be enabled at interface level in router image as well.

The no ip dhcp-client enable command will be migrated to ip dhcp-client disable command during the upgrade.

FDP

Switch Image:

  • FDP is enabled at the global level

Example:

9000Switch(config) #fdp

  advertise   Control advertising of address type

  holdtime    Specify the holdtime (in sec) to be sent in packets

  run         Enable FDP globally

  timer      Specify the rate at which FDP packets are sent (in sec)

Router Image:

  • FDP is enabled at the interface level

Example:

9000Router(config)# fdp

  holdtime   Specify the holdtime (in sec) to be sent in packets

  run        Enable FDP globally

  timer      Specify the rate at which FDP packets are sent (in sec)

Router Image:

  • FDP is enabled at the interface level

Example:

  holdtime        Specify the holdtime (in sec) to be sent in packets

  run                  Enable FDP globally

  timer              Specify the rate at which FDP packets are sent (in sec

In the switch image, FDP advertise (both IPv4 and IPv6) is configured at global level, but in the router image, it is configured at interface level.

After the upgrade from a switch image to FastIron 10.0.0, you must manually configure the fdp advertise command on individual interfaces.

Management VLAN and Management Port Considerations

For releases prior to FastIron 10.0.00, the IP address can be configured at the global level with the switch image. With the router image, the IP address must be configured at the interface level.

FastIron software will determine whether the management port is being used for accessing the device. Based on the detection, IP address configuration will be translated to equivalent router image commands according to the table below:

Management Configuration Scenarios for DHCP (IPv4)

Management VLAN Status Prior to FastIron 10.0.00 Upgrade to FastIron 10.0.00 or Later
Configured
  • Management-VLAN configured
  • DHCP Client configured

Example:

vlan 45 
 untagged ethernet 1/1/4 
 management-vlan 
 default-gateway 45.1.1.1 1 dynamic
!
ip address 45.1.1.2 255.255.255.0 dynamic
!

Configuration added:

  • VE is created on the VLAN
  • VE is configured as a DCHP client
    • ip dhcp client ve

Example:

ip dhcp-client ve 45
!
int ve 45
 ip address 45.1.1.2 255.255.255.0 dynamic
!
ip route 0.0.0.0/0 45.1.1.1 distance 254 dynamic
Not Configured
  • DHCP Client configured
  • No management-vlan configured
  • DHCP Server reachable on data port in any VLAN

Example:

vlan 45 
 untagged ethernet 1/1/4 
 default-gateway 45.1.1.1 1 dynamic 
!
ip address 45.1.1.2 255.255.255.0 dynamic
!
VE is created on the default VLAN and will be configured as DHCP client

Example:

!
interface ve 1
 ip address 45.1.1.2 255.255.255.0 dynamic
!
ip route 0.0.0.0/0 45.1.1.1 distance 254 dynamic
  • DHCP Client configured
  • No management-vlan configured
  • DHCP Server reachable on management port
  • Basically no configuration for management access.

Example:

ip default-gateway 45.1.1.1 1 dynamic 
!
ip address 45.1.1.2 255.255.255.0 dynamic
!
DHCP server reachable over management port

Example:

int management 1
 ip address 45.1.1.2 255.255.255.0 dynamic
!
ip route 0.0.0.0/0 45.1.1.1 distance 254 dynamic

Management Configuration Scenarios for Static IP Address

Management VLAN Status Prior to FastIron 10.0.00 Router Image for FastIron 10.0.00 or Later
Configured
  • Switch has static IP address configured along with management VLAN
  • Default gateway is reachable via management port

Example:

!
vlan 9
 untagged ethernet 1/1/9
 management-vlan
 default-gateway 10.177.133.129 1
 default-gateway 9.1.1.2 1
 default-gateway 19.1.1.2 2
!
ip address 10.177.133.138 255.255.255.128
!
  • IP address will be configured on the management port
  • Default gateway will be converted to a static route

Example:

!
int management 1
 ip address 10.177.133.138 255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.129
Default gateway reachable via data port

Example:

!
vlan 9
 untagged ethernet 1/1/9
 management-vlan
 default-gateway 9.1.1.2 1
 default-gateway 20.1.1.2 2
!
ip address 9.1.1.1 255.255.255.0
!

Example:

  • VE is created on the VLAN
  • IP address will be configured on the VE
  • Default gateway configuration will be converted to a static route
!
int ve 9
 ip address 9.1.1.1 255.255.255.0
!
ip route 0.0.0.0/0 9.1.1.2
Both the data port and management port is used to access the device

Example:

!
ip address 10.177.133.138 255.255.255.128 
ip default-gateway 10.177.133.129
!
FastIron selects the port through which the default gateway is reachable

Example:

!!
int management 1
ip address 10.177.133.138
255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.129

(or)
!
int ve 1
ip address 10.177.133.138
255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.129
No gateway configured
!
ip address 9.1.1.1 255.255.255.0
!
IP address is assigned to the management port
!
int management 1
 ip address 9.1.1.1 255.255.255.0
!
Not Configured Default gateway is reachable via management port

Example:

ip address 10.177.133.138 255.255.255.128
    ip default-gateway 10.177.133.129
  • IP address is assigned to the management port
  • Gateway will be converted to default route

Example:

!
int management 1
 ip address 10.177.133.138 255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.12
  • Default gateway is reachable via a data port
  • Port is not part of VLAN

Example:

 !
    interface ethernet 1/1/9
    !
    ip address 9.1.1.1 255.255.255.0
    ip default-gateway 9.1.1.2
  • VE interface is created on the default VLAN
  • IP address is assigned to this VE interface
  • Gateway will be converted to default route

Example:

!
int ve 1
 ip address 9.1.1.1 255.255.255.0
!

ip route 0.0.0.0/0 9.1.1.2
  • Default gateway reachable via a data port
  • Port is part of VLAN

Example:

!
    vlan 100
     untagged ethernet 1/1/9
    !
    ip address 10.1.1.1 255.255.255.0
    ip default-gateway 10.1.1.2
  • VE interface is created on the corresponding VLAN
  • IP address is assigned to the VE interface

Example:

!
vlan 100 
 untagged ethernet 1/1/9 
!
int ve 100
 ip address 10.1.1.1 255.255.255.0
!
ip route 0.0.0.0/0 10.1.1.2
Both the data port and management port is used to access the device

Example:

!
ip address 10.177.133.138 255.255.255.128 
ip default-gateway 10.177.133.129
!
FastIron selects the port through which the default gateway is reachable.

Example:

!
int management 1
ip address 10.177.133.138
255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.129

(or) 

!
int ve 1
ip address 10.177.133.138
255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.129
Not Configured Continued
  • No Gateway configured
  • Device is getting accessed through any port (same subnet as Switch IP

Example:

!
ip address 9.1.1.1 255.255.255.0
!
Management IP address is assigned to the management port

Example:

!
int management 1
 ip address 9.1.1.1 255.255.255.0
!
  • Default VLAN is configured
  • Gateway is reachable through a data port

Example:

!
default-vlan-id 100
!
ip address 9.1.1.2 255.255.255.0
ip default-gateway 9.1.1.1
IP address is assigned to the VE of the default VLAN

Example:

!
int ve 100
 ip address 9.1.1.2 255.255.255.0
!
ip route 0.0.0.0/0 9.1.1.1

Spanning Tree Protocol Configuration

The switch image by default runs spanning-tree and attaches a new spanning instance as and when a new VLAN is created. Since this is a system default behavior, spanning-tree is not generated under a VLAN in the running configuration file.

However for the router image, VLAN does not run spanning-tree by default. Unless spanning-tree string is explicitly present under the VLAN configuration, the router image will not run spanning-tree under that VLAN. During upgrade, the running configuration shall be modified to generate the spanning-tree under the VLAN configuration (once the system detects that the original running-config was from a switch image) as shown below:

With the move to RSTP instead of STP in 10.0.20a, are there changes to this table?

Spanning Tree Protocol Configuration

Switch Image Sample Configuration Configuration After Migration to FastIron 10.0.00 or Later
vlan 10
    tagged ethernet 1/1/1
vlan 20
    tagged ethernet 1/1/1
vlan 30
  no spanning-tree
  tagged ethernet 1/1/1
vlan 40
spanning-tree 802.1w
tagged ethernet 1/1/1
vlan 10
  spanning-tree
  tagged ethernet 1/1/1
vlan 20
  spanning-tree
  tagged ethernet 1/1/1
vlan 30
  no spanning-tree
  tagged ethernet 1/1/1
vlan 40
spanning-tree 802.1w
tagged ethernet 1/1/1
Running config has MSTP configuration No change in the running configuration
Running config has single spanning-tree configured No change in the running configuration

Considerations for Multicast

For MLD snooping no changes or additional rules are needed. Rules for selecting the IP address to send MLD query packets in order of decreasing priority include:

  1. Snooping VLAN querier address
  2. Switch IPv6 Link Local Address+

For IGMP snooping, if querier-address is not configured specifically then IGMP snooping uses the IP address configured on these interfaces as source address in the query packets (querier address) as per the rules in below table.

Rules for Selecting the IP Address to Send IGMP Query Packets

Switch Image (Before FastIron 10.0.00) Router Image (Before FastIron 10.0.00) 10.0.00 Single Router Image
  1. Snooping VLAN querier address
  2. Device IP address
  1. Snooping VLAN Querier address
  2. Snooping VLAN VE IP address
  3. First loopback interface IP address
  1. Snooping VLAN querier address
  2. Snooping VLAN VE IP address
  3. First loopback interface IP address
  4. First VE IP address

    Added to support upgrade from switch image to the single router image.

  5. OB management port IP address

    Added to support upgrade from switch image to the single router image.

Example: IP Address Configured on VE Interface After Upgrade

Before Upgrade on Switch Image

vlan 9
 untagged ethernet 1/1/9
 management-vlan
 default-gateway 9.1.1.1 1
 default-gateway 20.1.1.2 2
!
ip address 9.1.1.2 255.255.255.0
!
vlan 1000 by port
 tagged ethe 3/1/11 lag 102 
 multicast active
 multicast6 active
!
!
device# show ip multicast vlan 1000
Version=2, Intervals: Query=125, Group Age=260, Max Resp=10, Other Qr=255,
                      Leave Wait=2, Robustness=2

VL1000: dft V2, vlan cfg active, 0 grp, 0 (*G) cache, no rtr port, 
  My Query address: 9.1.1.2 (management)
  e3/1/11   has    0 grp, QR, default V2
  lg102     has    0 grp, QR, default V2 trunk
device#

After Upgrade to 10.0.00 Router Image

vlan 9 by port
 untagged ethernet 1/1/9 
 spanning-tree
!
int ve 9
 ip address 9.1.1.2 255.255.255.0
!
ip route 0.0.0.0/0 9.1.1.1
!
vlan 1000 by port
 tagged ethe 3/1/11 lag 102 
 multicast active
 multicast6 active
!
device# show ip multicast vlan 1000
Version=2, Intervals: Query=125, Group Age=260, Max Resp=10, Other Qr=255,
                      Leave Wait=2, Robustness=2

VL1000: dft V2, vlan cfg active, 0 grp, 0 (*G) cache, no rtr port
  My Query address: 9.1.1.2 (ve/loopback/management)
  Edge ports: ALL
  Non-Edge ports: NONE
  e3/1/11   has    0 grp, QR, default V2
  lg102     has    0 grp, QR, default V2 trunk
device#

Example: IP Address Configured on Out of Band Management Interface After Upgrade

Before Upgrade on Switch Image

ip address 9.1.1.2 255.255.255.0 
ip default-gateway 9.1.1.1
!
vlan 1000 by port
 tagged ethe 3/1/11 lag 102 
 multicast active
 multicast6 active
!
device# show ip multicast vlan 1000
Version=2, Intervals: Query=125, Group Age=260, Max Resp=10, Other Qr=255,
                      Leave Wait=2, Robustness=2

VL1000: dft V2, vlan cfg active, 0 grp, 0 (*G) cache, no rtr port, 
  My Query address: 9.1.1.2 (management)
  e3/1/11   has    0 grp, QR, default V2
  lg102     has    0 grp, QR, default V2 trunk
device#

After Upgrade to 10.0.00 Router Image

int management 1
 ip address 9.1.1.2 255.255.255.0
!
ip route 0.0.0.0/0 9.1.1.1
!
vlan 1000 by port
 tagged ethe 3/1/11 lag 102 
 multicast active
 multicast6 active
!
ICX# show ip multicast vlan 1000
Version=2, Intervals: Query=125, Group Age=260, Max Resp=10, Other Qr=255,
                      Leave Wait=2, Robustness=2

VL1000: dft V2, vlan cfg active, 0 grp, 0 (*G) cache, no rtr port
  My Query address: 9.1.1.2 (ve/loopback/management)
  Edge ports: ALL
  Non-Edge ports: NONE
  e3/1/11   has    0 grp, QR, default V2
  lg102     has    0 grp, QR, default V2 trunk
device#

Default Forwarding Profile Migration for ICX 7550

The forward table scale numbers (system max) are different between the default router forwarding profile and the switch default profile. During upgrade from switch image to the router image, profile2 will be chosen this migrates to the router image forwarding profile that is closest to the switch image default forwarding table numbers.

Forwarding Profile Migration

Prior to FastIron 10.0.00 Switch Image Forwarding Profile FastIron 10.0.00 Route Image Migrated to Forwarding Profile: Profile2
ICX7550-48 Switch# show default values    

forwarding profile: profile2

mac                      :98304    
ip-route                 :0          ip6-route                :0        
igmp-snoop-mcache        :8192       igmp-snoop-group-addr    :8192     
mld-snoop-mcache         :2048       mld-snoop-group-addr     :8192     
pim-hw-mcache            :0          pim6-hw-mcache           :0        
hw-ip-next-hop           :21504
ICX7550-48 Router# show forwarding-profile details
Parameter-name                       profile1       profile2       profile3
mac                                   16384          114688         32768
ip-route                              97280          8192           21504
ip6-route                             8192           2048           17408
igmp-snoop-mcache                     6144           6144           6144
igmp-snoop-group-addr                 6144           6144           6144
mld-snoop-mcache                      2048           2048           2048
mld-snoop-group-addr                  8192           8192           8192
pim-hw-mcache                         6144           6144           6144
pim6-hw-mcache                        2048           2048           2048
hw-ip-next-hop                        21504          21504          21504
Default                               YES            NO             NO