General Considerations for Upgrade to FastIron
Release 10.0.00 or Later
Note: Before you begin an upgrade, read
the release notes for the target release carefully to familiarize yourself with any
behavior and CLI changes. Refer to the latest version of the RUCKUS FastIron
Release Notes.
Beginning with FastIron release 10.0.00, a
switch ("Layer 2") image will no longer be provided for ICX devices. Only the router
("Layer 3") image will be available. On upgrade to FastIron 10.0.00, the configuration
of any ICX devices operating with the switch image will automatically be translated
to
the equivalent router image configuration.
The switch image for the ICX 71501, ICX 7550 and ICX 7650 is discontinued in FastIron release 10.0.00.
When upgrading these devices there is an automated migration which will change the
configuration after the upgrade.
Note: ICX 7150 stacks with more than eight switches cannot be upgraded to FastIron release
10.0.10f.
Configuration related to the following
features will be modified:
Management VLAN and Management
Port
Spanning Tree Protocol (STP)
Multicast
Forwarding Profile for the ICX
7550
IP address is configured at the
interface level
Support for management VLAN and
the default gateway is discontinued
Configuration related to certain
features is modified during migration to the FastIron 10.0.0 or later router image.
The following table provides details.
Command to enable dhcp client – Ip dhcp-client
enable
Command to disable dhcp client – no ip dhcp-client
enable
Router Image:
DHCP
client enabled at global level on a VE
Enabled
at interface level including the lease setting
Command to enable dhcp client – no ip dhcp-client
disable
Command to disable dhcp client – ip dhcp-client
disable
Router Image:
DHCP client enabled at global level on a VE
Enabled at interface level including the lease
setting
Command to enable dhcp client – no ip dhcp-client
disable
Command to disable dhcp client – ip dhcp-client
disable
DHCP-client is
enabled by default at global level, but DHCP-client can be
enabled at interface level in router image as well.
The no ip
dhcp-client enable command will be migrated to
ip
dhcp-client disable command during the
upgrade.
FDP
Switch Image:
FDP is
enabled at the global level
Example:
9000Switch(config) #fdp
advertise Control advertising of address type
holdtime Specify the holdtime (in sec) to be sent in packets
run Enable FDP globally
timer Specify the rate at which FDP packets are sent (in sec)
Router Image:
FDP is
enabled at the interface level
Example:
9000Router(config)# fdp
holdtime Specify the holdtime (in sec) to be sent in packets
run Enable FDP globally
timer Specify the rate at which FDP packets are sent (in sec)
Router Image:
FDP is
enabled at the interface level
Example:
holdtime Specify the holdtime (in sec) to be sent in packets
run Enable FDP globally
timer Specify the rate at which FDP packets are sent (in sec
In the switch
image, FDP advertise (both IPv4 and IPv6) is configured at
global level, but in the router image, it is configured at
interface level.
After the upgrade
from a switch image to FastIron 10.0.0, you must manually
configure the fdp advertise command on
individual interfaces.
Management VLAN and Management
Port Considerations
For releases prior to FastIron
10.0.00, the IP address can be configured at the global level with the switch image.
With the router image, the IP address must be configured at the interface level.
FastIron software will determine
whether the management port is being used for accessing the device. Based on the
detection, IP address configuration will be translated to equivalent router image
commands according to the table below:
Management Configuration
Scenarios for DHCP (IPv4)
Default
gateway configuration will be converted to a static route
!
int ve 9
ip address 9.1.1.1 255.255.255.0
!
ip route 0.0.0.0/0 9.1.1.2
Both the data port and management port is used to access the
device
Example:
!
ip address 10.177.133.138 255.255.255.128
ip default-gateway 10.177.133.129
!
FastIron selects the port through which the default gateway is
reachable
Example:
!!
int management 1
ip address 10.177.133.138
255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.129
(or)
!
int ve 1
ip address 10.177.133.138
255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.129
No gateway
configured
!
ip address 9.1.1.1 255.255.255.0
!
IP address is assigned to the management
port
!
int management 1
ip address 9.1.1.1 255.255.255.0
!
Not Configured
Default gateway is reachable via management
port
Example:
ip address 10.177.133.138 255.255.255.128
ip default-gateway 10.177.133.129
IP address is
assigned to the management port
Gateway will
be converted to default route
Example:
!
int management 1
ip address 10.177.133.138 255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.12
Default
gateway is reachable via a data port
Port is not
part of VLAN
Example:
!
interface ethernet 1/1/9
!
ip address 9.1.1.1 255.255.255.0
ip default-gateway 9.1.1.2
VE interface
is created on the default VLAN
IP address is
assigned to this VE interface
Gateway will
be converted to default route
Example:
!
int ve 1
ip address 9.1.1.1 255.255.255.0
!
ip route 0.0.0.0/0 9.1.1.2
Default
gateway reachable via a data port
Port is part
of VLAN
Example:
!
vlan 100
untagged ethernet 1/1/9
!
ip address 10.1.1.1 255.255.255.0
ip default-gateway 10.1.1.2
VE interface
is created on the corresponding VLAN
IP address is
assigned to the VE interface
Example:
!
vlan 100
untagged ethernet 1/1/9
!
int ve 100
ip address 10.1.1.1 255.255.255.0
!
ip route 0.0.0.0/0 10.1.1.2
Both the data port and management port is used to access the
device
Example:
!
ip address 10.177.133.138 255.255.255.128
ip default-gateway 10.177.133.129
!
FastIron selects the port through which the default gateway is
reachable.
Example:
!
int management 1
ip address 10.177.133.138
255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.129
(or)
!
int ve 1
ip address 10.177.133.138
255.255.255.128
!
ip route 0.0.0.0/0 10.177.133.129
Not Configured Continued
No Gateway
configured
Device is
getting accessed through any port (same subnet as Switch
IP
Example:
!
ip address 9.1.1.1 255.255.255.0
!
Management IP address is assigned to the management
port
Example:
!
int management 1
ip address 9.1.1.1 255.255.255.0
!
Default VLAN
is configured
Gateway is
reachable through a data port
Example:
!
default-vlan-id 100
!
ip address 9.1.1.2 255.255.255.0
ip default-gateway 9.1.1.1
IP address is assigned to the VE of the default
VLAN
Example:
!
int ve 100
ip address 9.1.1.2 255.255.255.0
!
ip route 0.0.0.0/0 9.1.1.1
Spanning Tree Protocol
Configuration
The switch image by default runs
spanning-tree and attaches a new spanning instance as and when a new VLAN is
created. Since this is a system default behavior, spanning-tree is not generated
under a VLAN in the running configuration file.
However for the router image, VLAN
does not run spanning-tree by default. Unless spanning-tree string is explicitly
present under the VLAN configuration, the router image will not run spanning-tree
under that VLAN. During upgrade, the running configuration shall be modified to
generate the spanning-tree under the VLAN configuration (once the system detects
that the original running-config was from a switch image) as shown below:
Spanning Tree Protocol
Configuration
Switch Image Sample Configuration
Configuration After Migration to FastIron 10.0.00 or
Later
Running config has single spanning-tree configured
No change in the running configuration
Considerations for
Multicast
For MLD snooping no changes or
additional rules are needed. Rules for selecting the IP address to send MLD query
packets in order of decreasing priority include:
Snooping VLAN querier
address
Switch IPv6 Link Local
Address+
For IGMP snooping, if querier-address
is not configured specifically then IGMP snooping uses the IP address configured on
these interfaces as source address in the query packets (querier address) as per the
rules in below table.
Rules for Selecting the IP
Address to Send IGMP Query Packets
Switch Image (Before FastIron 10.0.00)
Router Image (Before FastIron 10.0.00)
10.0.00 Single Router Image
Snooping VLAN
querier address
Device IP
address
Snooping VLAN
Querier address
Snooping VLAN
VE IP address
First
loopback interface IP address
Snooping VLAN
querier address
Snooping VLAN
VE IP address
First
loopback interface IP address
First VE IP
address
Added to support upgrade from switch image to the
single router image.
OB management
port IP address
Added to
support upgrade from switch image to the single router
image.
Example: IP Address Configured on
VE Interface After Upgrade
Before Upgrade on Switch Image
vlan 9
untagged ethernet 1/1/9
management-vlan
default-gateway 9.1.1.1 1
default-gateway 20.1.1.2 2
!
ip address 9.1.1.2 255.255.255.0
!
vlan 1000 by port
tagged ethe 3/1/11 lag 102
multicast active
multicast6 active
!
!
device# show ip multicast vlan 1000
Version=2, Intervals: Query=125, Group Age=260, Max Resp=10, Other Qr=255,
Leave Wait=2, Robustness=2
VL1000: dft V2, vlan cfg active, 0 grp, 0 (*G) cache, no rtr port,
My Query address: 9.1.1.2 (management)
e3/1/11 has 0 grp, QR, default V2
lg102 has 0 grp, QR, default V2 trunk
device#
After Upgrade to 10.0.00 Router Image
vlan 9 by port
untagged ethernet 1/1/9
spanning-tree
!
int ve 9
ip address 9.1.1.2 255.255.255.0
!
ip route 0.0.0.0/0 9.1.1.1
!
vlan 1000 by port
tagged ethe 3/1/11 lag 102
multicast active
multicast6 active
!
device# show ip multicast vlan 1000
Version=2, Intervals: Query=125, Group Age=260, Max Resp=10, Other Qr=255,
Leave Wait=2, Robustness=2
VL1000: dft V2, vlan cfg active, 0 grp, 0 (*G) cache, no rtr port
My Query address: 9.1.1.2 (ve/loopback/management)
Edge ports: ALL
Non-Edge ports: NONE
e3/1/11 has 0 grp, QR, default V2
lg102 has 0 grp, QR, default V2 trunk
device#
Example: IP Address Configured on
Out of Band Management Interface After Upgrade
Before Upgrade on Switch Image
ip address 9.1.1.2 255.255.255.0
ip default-gateway 9.1.1.1
!
vlan 1000 by port
tagged ethe 3/1/11 lag 102
multicast active
multicast6 active
!
device# show ip multicast vlan 1000
Version=2, Intervals: Query=125, Group Age=260, Max Resp=10, Other Qr=255,
Leave Wait=2, Robustness=2
VL1000: dft V2, vlan cfg active, 0 grp, 0 (*G) cache, no rtr port,
My Query address: 9.1.1.2 (management)
e3/1/11 has 0 grp, QR, default V2
lg102 has 0 grp, QR, default V2 trunk
device#
After Upgrade to 10.0.00 Router
Image
int management 1
ip address 9.1.1.2 255.255.255.0
!
ip route 0.0.0.0/0 9.1.1.1
!
vlan 1000 by port
tagged ethe 3/1/11 lag 102
multicast active
multicast6 active
!
ICX# show ip multicast vlan 1000
Version=2, Intervals: Query=125, Group Age=260, Max Resp=10, Other Qr=255,
Leave Wait=2, Robustness=2
VL1000: dft V2, vlan cfg active, 0 grp, 0 (*G) cache, no rtr port
My Query address: 9.1.1.2 (ve/loopback/management)
Edge ports: ALL
Non-Edge ports: NONE
e3/1/11 has 0 grp, QR, default V2
lg102 has 0 grp, QR, default V2 trunk
device#
Default Forwarding Profile
Migration for ICX 7550
The forward table scale numbers
(system max) are different between the default router forwarding profile and the
switch default profile. During upgrade from switch image to the router image,
profile2 will be chosen this migrates to the router image forwarding profile that
is
closest to the switch image default forwarding table numbers.
Forwarding Profile
Migration
Prior to FastIron 10.0.00 Switch Image Forwarding Profile
FastIron 10.0.00 Route Image Migrated to Forwarding Profile:
Profile2
The ICX 7150 devices are not
supported on 10.0.x releases prior to the FastIron 10.0.10f release. These include
FastIron 10.0.00 and FastIron 10.0.10 (from 10.0.10a to 10.0.10e). ↩