CRS IOS XR 4.2.3 ABF IP SLA

Dear all,
I got a problem when running Access-List Based Forwarding (ABF / PBR) with IP SLA.
The Cisco document its says Object Tracking IP SLA with ABF is supported on IOS XR 4.2.1, even with the sample.
http://www.cisco.com/en/US/docs/routers/asr9000/software/asr9k_r4.1/addr_serv/configuration/guide/ipaddr_cg41a9k_chapter1.html#concept_4CBDF391A97345A084853EE73C280FCE
If i looked at Feature Navigator, IP SLA is already supported on IOS XR 4.1.1, with MPLS package software.
But when i configured on CRS, IP SLA cannot be attached on ABF.
Log :
RP/0/RP0/CPU0:CG-P-03(admin)#show install activ sum
Mon Feb 18 17:28:28.023 WIB
Default Profile:
Admin Resources
SDRs:
   Owner
Active Packages:
   disk0:hfr-mini-px-4.2.3
   disk0:hfr-doc-px-4.2.3
   disk0:hfr-services-px-4.2.3
   disk0:hfr-mpls-px-4.2.3
   disk0:hfr-mgbl-px-4.2.3
   disk0:hfr-mcast-px-4.2.3
   disk0:hfr-px-4.2.3.CSCuc41902-1.0.0
   disk0:hfr-px-4.2.3.CSCuc11390-1.0.0
   disk0:hfr-fpd-px-4.2.3
   disk0:hfr-diags-px-4.2.3
RP/0/RP0/CPU0:CG-P-03(config)#track track?
WORD
RP/0/RP0/CPU0:CG-P-03(config)#track track1
RP/0/RP0/CPU0:CG-P-03(config-track)#type rtr 1 rea
RP/0/RP0/CPU0:CG-P-03(config-track)#delay up 5
RP/0/RP0/CPU0:CG-P-03(config-track)#delay down 10
RP/0/RP0/CPU0:CG-P-03(config-track)#comm
Mon Feb 18 17:29:21.213 WIB
RP/0/RP0/CPU0:CG-P-03(config-track)#ipv4 access-list testtrack
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit any nexthop1 ?
ipv4 Enter nexthop1 ipv4 address
vrf   Enter specific VRF Name for this nexthop
<cr>
RP/0/RP0/CPU0:CG-P-03(config)#ipsla
RP/0/RP0/CPU0:CG-P-03(config-ipsla)#operation 1
RP/0/RP0/CPU0:CG-P-03(config-ipsla-op)#type icmp echo
RP/0/RP0/CPU0:CG-P-03(config-ipsla-icmp-echo)#destination add 1.1.1.1
RP/0/RP0/CPU0:CG-P-03(config-ipsla-icmp-echo)#frequency 60
RP/0/RP0/CPU0:CG-P-03(config-ipsla-icmp-echo)#exi
RP/0/RP0/CPU0:CG-P-03(config-ipsla-op)#exi
RP/0/RP0/CPU0:CG-P-03(config-ipsla)#schedule operation 1
RP/0/RP0/CPU0:CG-P-03(config-ipsla-sched)#start-time now
RP/0/RP0/CPU0:CG-P-03(config-ipsla-sched)#life forever
RP/0/RP0/CPU0:CG-P-03(config-ipsla-sched)#commit
Mon Feb 18 17:31:42.496 WIB
RP/0/RP0/CPU0:CG-P-03(config)#ipv4 access-list testtrack
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ipv4 ?
A.B.C.D Enter nexthop1 IPv4 address
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ipv4 1.1.1.1 ?
nexthop2 Enter another nexthop
<cr>    
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ipv4 1.1.1.1 track track1
                                                                                   ^
Theres no option track on CLI, even if i specified track, CLI said error / invalid input.
Is there anything to make the ABF IP SLA run on CRS ?
Thanks,
Budi L

Hi Parthiv,
i have already test the configuration, but it cannot work:
RP/0/RP0/CPU0:CG-P-03#sh run | in track
Thu Feb 21 15:22:15.039 WIB
Building configuration...
track track1
RP/0/RP0/CPU0:CG-P-03#sh run track
Thu Feb 21 15:22:18.739 WIB
track track1
type rtr 1 reachability
delay up 5
delay down 10
RP/0/RP0/CPU0:CG-P-03#sh run ip sla
                              ^
% Invalid input detected at '^' marker.
RP/0/RP0/CPU0:CG-P-03#sh run sla
                              ^
% Invalid input detected at '^' marker.
RP/0/RP0/CPU0:CG-P-03#sh run ipsla
Thu Feb 21 15:22:32.501 WIB
ipsla
operation 1
  type icmp echo
   destination address 1.1.1.1
   frequency 60
schedule operation 1
  start-time now
  life forever
RP/0/RP0/CPU0:CG-P-03#sh run access-l
                              ^
% Invalid input detected at '^' marker.
RP/0/RP0/CPU0:CG-P-03#sh run ipv4 access-list
Thu Feb 21 15:22:54.753 WIB
ipv4 access-list ospf_traffic
10 permit ospf any any
RP/0/RP0/CPU0:CG-P-03#conf t
Thu Feb 21 15:22:59.523 WIB
RP/0/RP0/CPU0:CG-P-03(config)#ipv4 access-list testtrack
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any ?
  default        Use specified default nexthop on match against this entry
  dscp           Match packets with given DSCP value
  fragments      Check non-initial fragments
  log            Log matches against this entry
  log-input      Log matches against this entry, including input interface
  nexthop1       Forward to specified nexthop on match against this entry
  packet-length  Check packet length
  precedence     Match packets with given precedence
  ttl            match against ttl
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ?
  ipv4  Enter nexthop1 ipv4 address
  vrf   Enter specific VRF Name for this nexthop
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 track track1 ipv4 1.1.1.1
                                                                       ^
% Invalid input detected at '^' marker.
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ?
  ipv4  Enter nexthop1 ipv4 address
  vrf   Enter specific VRF Name for this nexthop
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ?   
  ipv4  Enter nexthop1 ipv4 address
  vrf   Enter specific VRF Name for this nexthop
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ipv4 ?
  A.B.C.D  Enter nexthop1 IPv4 address
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ipv4 track ?
                                                                            ^
% Invalid input detected at '^' marker.
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ipv4 1.1.1.1 ? 
  nexthop2  Enter another nexthop
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ipv4 1.1.1.1 track track1
                                                                                    ^
% Invalid input detected at '^' marker.
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ipv4 track1 1.1.1.1     
                                                                            ^
% Invalid input detected at '^' marker.
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#10 permit ipv4 any any nexthop1 ipv4 track track1 1.1.1.1
                                                                            ^
% Invalid input detected at '^' marker.
RP/0/RP0/CPU0:CG-P-03(config-ipv4-acl)#exit
RP/0/RP0/CPU0:CG-P-03(config)#exi
RP/0/RP0/CPU0:CG-P-03#

Similar Messages

  • Managing ACLs (7600, CRS IOS-XR, GSR) – advise on automation tools for SP

    /* Style Definitions */
    table.MsoNormalTable
    {mso-style-name:"Table Normal";
    mso-tstyle-rowband-size:0;
    mso-tstyle-colband-size:0;
    mso-style-noshow:yes;
    mso-style-priority:99;
    mso-style-qformat:yes;
    mso-style-parent:"";
    mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
    mso-para-margin:0cm;
    mso-para-margin-bottom:.0001pt;
    mso-pagination:widow-orphan;
    font-size:11.0pt;
    font-family:"Calibri","sans-serif";
    mso-ascii-font-family:Calibri;
    mso-ascii-theme-font:minor-latin;
    mso-hansi-font-family:Calibri;
    mso-hansi-theme-font:minor-latin;
    mso-fareast-language:EN-US;}
    Hello All,
    There are many wonderful Service Provider infrastructure hardening documents available from Cisco CCO and CiscoPress.
    I have seen many over my life. Sample documents are:
    Mannaging ACLs (7600, CRS IOS-XR, GSR) - automation tools, Document ID: 13608
    Network Core Infrastructure Best Practices, Yusuf Bhaiji
    Cisco Guide to Harden Cisco IOS XR Devices
    Each service provider is recommended to enable and configure rACLs, CoPP, block unnecessary control protocols over the edge, Protect BGP peering with interface ACLs and many many more. Unfortunately there is no tool available from Cisco to configure and maintain all those features.
    I would like to ask question to NetPro community. Have you seen any working products from Cisco or Cisco partners for ACL management. Lets keep Cisco Security Manager (CSM) aside. CSM is enterprise oriented tool and supporting routers up to 6500/7600.
    I’m looking for this tool for few years already. Looks like other Service Providers are using home made developments. Google recently partially published own tool capirca to a public domain (do search on “ACL Management @ Google” or capirca). This is good start but I is missing ACL deployment module (it is not released by google).
    Please share you experience!
    Cheers!

  • CRS, IOS-XR: local IGP route not installed in BGP table when learned from RR

    Hello,
    We use CRS routers in our IGP/BGP network core, some of which are acting as BGP originators and reflectors (RRs) for IPv4 unicast. We also use CRS routers as Internet PEs. The problem we have is between those PEs and the core routers.
    Premise: each Internet PE is terminating customer cisrcuits and injects those downstream routes in IGP (via redistributing static, or just learned via IGP from a downstream router). The core (P) routers then learn those routes from the PE via the IGP. Two of the P-routers act as BGP originators and install the necessary routes in BGP using the network statement. These routes are mostly supernets (i.e. summarized), but some coincide with IGP routes, as learned from the PEs. The P-routers acting as RRs then reflect all iBGP routes to all IPv4 unicast BGP speakers in the network, including the Internet PEs (we also have BGP peers on those PEs, which is why this is necessary).
    Problem: if a specific downstream route, learned on an Internet PE via IGP (i.e. from downstream), is then received by that PE from an RR via iBGP (i.e. from upstream), the route is not installed in the BGP table (the output of the show bgp x.x.x.x/xx command is: Network not in table)
    Question: does anyone know why this is happening? This is concictent on all of our CRS PEs. As far as I am aware there is no BGP rule that would explain this behavior. We don't expect the PE to prefer the iBGP route over the IGP route, but that should not prevent it from learning it and installing it in the BGP table... The only discrepancy I could think of is that the IGP route has a next-hop pointing downstream, whereas the the same route, learned over iBGP has a next-hop pointing upstream. Then again,this shouldn't prevent the route to appear in the BGP table....
    Your help would be appreciated!
    Thanks!

    Hi !
    If I am understandung you correctly then Split Horizon is the keyword
    Because if the route is learned from downstream BGP drops any same path information learned from upstream
    SPLIT-HORIZON only applies to distance-vector routing protocols.  In case of BGP,  it simply means that a prefix learned via a peer is not advertised back  to that peer.
    Split horizon will simply block out routes with the same neighbor as the next-hop for the router
    regards
    alexander

  • Route-map continue, in CRS RPL

    Dear all,
    what is the replacement for continue command in route-map for CRS IOS XR RPL ?
    is it ? pass command ??
    actually i had some issue matching almost 15 community attribute ingress from customer network...
    and i think, is it can be done with pass command ?
    like :
    if community (a:a) then
    action
    pass
    else if community (b:b) then
    action
    pass
    end if
    so, when the route contain community a:a, will get action assigned, and not yet to be forwarded, instead, will continue to run the next if, to check if the route also contain b:b community...
    so with this i dont have to create almost 2^15 combination if format on RPL.
    is it do able ? or is there any command that work simillar with "continue" command in route-map, if match, the route still get processed until the end of policy.
    Thanks a lot,
    Budi L

    Hello Budi
    Yes, the pass statement allows a policy to continue executing even though the route has not been modified. When a policy has finished executing, any route that has been modified in the policy or any route that has received a pass disposition in the policy, successfully passes the policy and completes the execution. Note, a policy does not modify route attribute values until all tests have been completed. In other words, comparison operators always run on the initial data in the route. Intermediate modifications of the route attributes do not have a cascading effect on the evaluation of the policy.
    Here is the PASS example:
    route-policy ak-community
    if community matches-any (11:11, 44:44) then
       set community (55:55) additive
       pass
    endif
    if community matches-any (22:22) then
       set community (77:77) additive
    endif
    end-policy
    If a route contains a community 11:11 then we add 55:55 and continue. So If the same route contain 22:22 as well, we’d add another community 77:77 to the same route. Note, if we have an action (like SET here), a PASS statement is not needed and we continue with the policy.
    Example 2. Here we can see nested IF. So if a route contains 11:11 then we add 55:55 and verify it further if the route has 22:22 and if so, add 77:77
    route-policy ak-community
    if community matches-any (11:11, 44:44) then
       set community (55:55) additive
       if community matches-any (22:22) then
         set community (77:77) additive
       endif
    endif
    end-policy
    Example 3.  In this example we add 55:55 to routes matching 11:11 or 44:44. Otherwise, if a route has 22:22, we add 77:77. Note, if a route has 11:11 AND 22:22 (or 44:44 AND 22:22) we’d add 55:55 only.
    route-policy ak-community
    if community matches-any (11:11, 44:44) then
       set community (55:55) additive
    elseif community matches-any (22:22) then
       set community (77:77) additive
    endif
    end-policy
    IF statement are flexible too. You noted we used MATCHES-ANY in the IF statement. We can use a list of different conations in one IF. For example:
    If community matches-every (11:11, 22:22) or destination in (11.1.3.0/24) then
       set local-preference 500
    Regards,
    /A

  • Cisco IOS IP SLAs Operations in IOS 15.2E

    Hi,
    does anybody know the required license for 3560-x in IOS 15.2E fo use of IP SLA.
    Cisco feature Navigator does not know yet, configuration guide says at least IP Services license needed, switch CLI permits configuration with LAN Base License.
    So what ?
    br Fritz

    Hey Stefan,
    I believe its a good candidate for a TAC case.
    HTH.
    Regards,
    RS.

  • IP SLA Monitor /Tracking 2921

    I am looking or IOS code for a Cisco 2921/K9 that will allow me to do IP SLA Tracking. The current code "c2900-universalk9-mz.SPA.151-4.M.bin" will only allow me to sset up IP SLA responder or IP SLA Server but  NOT IP SLA Monitor or IP SLA RTR.
    I have used the Cisco feature set research tool and chose what it recommended but to no avail.
    Am I missing something? Will the Server or Responder perform tracking?
    Thanks in advance to anyone who can  assist..
    ~g

    Dear All,
    I have the same problem with C2921. I want to config IP SLA for my C2921 but it seems do not support. The below for your reference.
    ####### Do not have option monitor
    ip sla ?
      key-chain  Use MD5 Authentication for IP SLAs Control Messages
      responder  Enable IP SLAs Responder
      server     IPPM server configuration
    Show version
    System image file is "flash0:c2900-universalk9-mz.SPA.151-4.M1.bin"
    License Info:
    License UDI:
    Device#   PID                   SN
    *0        CISCO2921/K9          FGL153913PM    
    Technology Package License Information for Module:'c2900'
    Technology    Technology-package           Technology-package
                  Current       Type           Next reboot 
    ipbase        ipbasek9      Permanent      ipbasek9
    security      None          None           None
    uc            None          None           None
    data          None          None           None
    Please kindly advise what ios I can use for configuring IP SLA. there're any problem with my licence for that
    Best Regards,
    Binh

  • CRS-8/S and SNMP - the correct release of IOS-XR

    Hello,
    What do you think if IOS-XR release 4.1.2 (CRS-8/S) is the good choice to use for management (SNMP)?  I heard that IOS-XR 4.1.2 has some problems with SNMP.
    I want to integrate Prime IP NGN NMS with CRS.
    Maybe ISO-XR 4.3.1 or 4.3.2 can be better solution? What do you think?
    Regards,
    Tomek

    Hi Tomek,
    Release 4.1.2 is almost EoM meaning no more SMUs will be created. As you alluded to there are some fixes for SNMP since 4.1.2, and I would recommend either 4.2.4 or 4.3.2 at this time.
    Thnaks,
    Sam

  • CRS-1 IOS XR Upgrade

    Hi,
    Anybody have alredy work with a CRS-1? I would like to understand the procedures to install and upgrade IOS XR. It's a new device to be installed in a service provider to replace a GSR Router. The documents I search, I noticed that there's a big difference compare to the normal IOS and more difficult to understand the concepts.
    Thanks.

    Hello Paulo,
    I agree that is quite different from classic IOS.
    In IOS XR you can have a full upgrade or the installation of patches called SMU.
    Similarly to unix or linux operating systems the process can be described as:
    copying to file system the installation files in appropriate path
    installation of packages
    activation of the packages
    there is no single image in IOS XR.
    a good starting point can be
    http://www.cisco.com/en/US/partner/docs/ios_xr_sw/iosxr_r3.7/getting_started/configuration/guide/gs37book.html
    or
    http://www.cisco.com/en/US/docs/ios_xr_sw/iosxr_r3.7/getting_started/configuration/guide/gs37book.html
    Be prepared for some issues when connecting to other IOS based devices there are some default settings that are different.
    You may be interested in the following white papers
    http://www.cisco.com/en/US/partner/products/ps5763/prod_white_papers_list.html
    http://www.cisco.com/en/US/products/ps5763/prod_white_papers_list.html
    Hope to help
    Giuseppe

  • Crs-1 ABF traceroute policy routing

    We config ABF on crs-1 interface to policy traffic to another next hop
    But when we use traceroute. Policy not work
    Cco said ABF not support ip option.  Traceroute is one of ip option
    How can I verify this policy
    Thanks

    Hello Fly,
    Normally default traceroute does not use ipv4 option and should work just fine.
    We can not test ABF with traffic originating from the router where the ABF is applied to. It has to be a transit traffic and ABF has to be applied to an ingress interface of the router with ABF.
    Here is the example:
    RP/0/RP1/CPU0:pixies#sh run ipv4 access-list abf33
    Tue May 22 09:53:52.884 CEST
    ipv4 access-list abf33
    10 permit ipv4 192.168.101.0 0.255.255.255 any nexthop 10.12.113.2
    20 permit ipv4 any any
    Traceroute from the adjacent router:
    before ABF configuration
    =================================
    RP/0/RP1/CPU0:placebo#traceroute 77.77.77.77
    Tue May 22 09:46:12.446 CEST
    Type escape sequence to abort.
    Tracing the route to 77.77.77.77
    1 192.168.101.2 9 msec 8 msec 7 msec
    2 12.1.1.1 14 msec * 11 msec
    After the ABF configuration on the ingress if of pixies
    =================================
    RP/0/RP1/CPU0:placebo#traceroute 77.77.77.77
    Tue May 22 09:49:12.049 CEST
    Type escape sequence to abort.
    Tracing the route to 77.77.77.77
    1 192.168.101.2 17 msec 9 msec 7 msec
    2 10.12.113.2 11 msec 11 msec 7 msec  <--------------------  NH from ABF
    3 13.1.1.1 7 msec * 9 msec
    RP/0/RP1/CPU0:pixies#show access-lists abf33 hardware ingress location 0/2/CPU0
    Tue May 22 09:50:55.047 CEST
    ipv4 access-list abf33
    10 permit ipv4 192.0.0.0 0.255.255.255 any (52 hw matches) (next-hop: 10.12.113.2) <------------------  matching entries in HW
    20 permit ipv4 any any (25 hw matches)
    Regards,
    /A

  • Improving install experience in IOS XR (ASR9K/CRS)

    This time its a question to our customers:
    If you insisted on keeping SMUs, SPs, Install rollback and the things you have gotten used to today, how would you change the install process to make it simpler, but still provide what we do now?
    Or asked differently what do struggle with today when it comes to Installing/Upgrading Software and what would you like to see improved.
    We want to hear your feedback. You can send a message too, please don't hold back..
    Eddie.

    Mathieu, inline:
    >For example we were running 4.3.4 on our ASR9K and faced few bugs. Most of them were fixed in >SP3. While upgrading a router from 4.3.4 to SP3, we ran into a bug that completely crashed our >router. We had to turboboot everything. We raised a ticket with TAC and they told us we had to install >asr9k-px-4.3.4.CSCul58246.tar before upgrading to SP3. Unfortunately, this fix needs >asr9k->px->4.3.4.CSCug75299.tar and asr9k-px-4.3.4.CSCui94441.tar. This means to upgrade a >router from 4.3.4 to SP3, you actually need to reboot it 3 times!!! By optimizing as much as we can >this process, this means a maintenance of ~50min which is a lot of downtime for our customers!
    Mathieu the SP Readme has been updated to include these per-requistes, so hopefully in the future it shouldn't be required. This process of pre-req smus for SP are not needed from 5.1.3 on.
    >Why not releasing a 4.3.4-SP image each time your release a SP? At least providers could turboboot >it already patched?
    Turboboot is the last thing we want you guys to do, its slow and painful, turboboot should rarely be used.
    >Concerning turboboot, the transfert speed thru an integrated management port is catastrophic. We >can't specify a large block size to speed up things so even if we have a TFTP directly connected to >the port, transfers are way too slow. A good way would be to be able to transfer files with HTTP / FTP >during a turboboot.
    We don't have a TCP stack in ROMMON and we don't plan to support it. We will support things like ONIE and IPXE in the future.
    >Then if transfers are done in a fast & efficient way, we could save time by directly sending an >uncompressed image over the network instead of waiting for the router to decompress the archive.
    I like the uncompressed image idea, we are exploring that.
    Thanks for the feedback and we'll keep you posted.
    Eddie.

  • How can you identify when a RP has a bootflash failure on CRS-1?

    Hi Everyone,
    I am hoping someone can assist me in identifying when a RP has a bootflash issue and requires RMA.  We have some CRS-1 running in our network with IOS XR 3.8.2 and some with 4.0.3.  All the commands that I am aware of do not identify when a RP has a problem in bootflash.  CCO recommends that if there is a problem with upgrade and you are moving to a code using filesystem fat 32 that you format the bootflash of the RP's.  It was at this point we started having issues.  We went into ROMMON and recieved the following error.
    rommon B1 > dir bootflash:disk0/hfr-os-mbi-4.0.3 Checksum failed on hfr-fslib-m
    Expected checksum: 6a53, calculated checksum: beba
    open: file "hfr-fslib-m" not found
    loadprog: error - on file open
    cannot load the monitor library "bootflash:%hfr-fslib-m" from device
    If someone has some insight on how we can validate the state of the RP outside of the typical command set:
    show redundancy summary
    show platform
    etc
    I'd appreciate it.
    Cheers,
    Rashmi

    Hi,
    Provide some more information on your problem.
    If you want to check the directory contect try
    dir bootflash:
    is it displaying any output?
    In general above error doesn't indicate that there is any problem but it is not able to find particular directory or file.
    Thanks
    Parthiv

  • Ask the Experts: IOS-XR Fundamentals and Architecture

    Welcome to the Cisco Support Community Ask the Expert conversation. 
    Learn and ask questions about IOS-XR Fundamentals and Architecture.
    November 18, 2014 through November 28, 2014.
    Cisco IOS XR Software is a modular and fully distributed network operating system for service provider networks. Cisco IOS XR creates a highly available, highly secure routing platform.
    It distributes processes across the control, data, and management planes with their own access controls and delivers routing-system scalability, service isolation, and manageability.
    This is a Q&A extension of the Live expert Webcast.
    Cisco subject matter experts Sudeep, Raj, and Sudhir, will focus on IOS-XR fundamentals.
    Including:-
    High-Level Overview of Cisco IOS XR
    Cisco IOS XR Infrastructure
    Configuration Management
    Cisco IOS XR Monitoring and Operations
    Cisco IOS XR Security
    Introduction to different IOS-XR platforms
    Sudeep Valengattil is a customer support engineer in High-Touch Technical Services at Cisco specializing in service provider technologies and platforms. Sudeep has got experience on XR platform like ASR9000, CRS, NCS and GSR. Sudeep has more than 9 years of experience in the IT industry and holds CCIE certification (36098) in Service provider.
    Sudhir Kumar is a customer support engineer in High-Touch Technical Services at Cisco specializing in service provider technologies and platforms. His areas of expertise include Cisco CRS, ASR 9K and Cisco XR 12000 Series Routers. Sudhir has more than 10 years of experience in the IT industry and holds CCIE certification (35219) in Service provider and Routing and switching.
    Raj Pathak is a customer support engineer in High-Touch Technical Services at Cisco specializing in service provider technologies and platforms. He serves as a support engineer for technical issues supporting Cisco IOS XR Software customers on Cisco CRS and Cisco XR 12000 Series Routers. Raj has more than 8 years of experience in the IT industry and holds CCIE certification (38760) in routing and switching.
    For more information about this topic, visit the Expert Corner > Knowledge Sharing
    Remember to use the rating system to let the experts know if you have received an adequate response.

    Hi Charles,
    To answer your question,
    LPTS would be acting only on packet/traffic which is ingressing the router and destined for the router itself (for-us packets).  It provides an internal forwarding table to route control/management protocol packets destined to local router to the right application for further processing.  Once we have a packet entering the interface, the network processor would be performing a lookup to determine, if this packet is destined for us.  Based on which, it will forward to LPTS.  For eg, the ICMP packets coming in on an interface with destination IP of router itself, would be processed by LPTS.  It also provides policing function for this traffic transparently.
    Key facts about LPTS
    1. LPTS is an always on feature.  No user configuration needed to enable it.
    2. LPTS is only applicable for traffic entring to the router and destined to the local router. Applies for control-plane and management plane traffic.
    3. Packets originated by router and transit traffic is not processed by LPTS
    4. LPTS polices the incoming traffic based on the pre-defined policer rates.
    Here is an o/p snip to view the LPTS entries.
    RP/0/RP0/CPU0:CRS-C#sh lpts pifib hard police loc 0/0/cpu0
    Tue Nov 25 23:32:10.666 EDT
    Node 0/0/CPU0:
    Burst = 100ms for all flow types
    FlowType Policer Type Cur. Rate Def. Rate Accepted Dropped
    unconfigured-default 100 Static 500 500 0 0
    L2TPv2-fragment 185 Static 700 700 0 0
    Fragment 106 Static 1000 1000 0 0
    OSPF-mc-known 107 Static 20000 20000 44818 0
    OSPF-mc-default 111 Static 5000 5000 11366 0
    Do let us know if you have any further queries.
    Regards,
    Sudeep Valengattil

  • Cisco CRS-1/8 to CRS-3/8 upgrade

    Hi Folks,
    has any body done CRS-1/8 to CRS-3/8 upgrade smoothly ? from the CCO I could find only that it needs IOS-XR 4.0 and Fabric Upgrade.
    just want to make  sure these are the only two actions to perform to make CRS-1 to CRS-3,
    my upgrading procedure will be as follows
    1. Upgrade the code to IOS-XR 4.0 with CRS-1 fabric.
    2. once the router is loaded with 4.0, replace Fabric cards one by one.
    Need your comments.
    Rgds
    Harin

    Hello Harin,
    your procedure looks like reasonable, various rommon firmware upgrades should be part of first step as necessary.
    Hope to help
    Giuseppe

  • CRS-1 boot failed problem ( REDFS-5-INIT_FAILED)

    Hi expert ,
    today I face new problem with one RP , :
    Initializing DDR SDRAM...found 4096 MB
    Initializing ECC on bank 0
    Initializing ECC on bank 1
    Initializing ECC on bank 2
    Initializing ECC on bank 3
    Turning off data cache, using DDR for first time
    Initializing NVRAM...
    Testing a portion of DDR SDRAM ...done
    Reading ID EEPROMs ...
    Initializing SQUID ...
    Initializing PCI ...
    PCI0 device[1]: Vendor ID 0x10ee
    PCI0 device[1]: Device ID 0x300e
    PCI1 device[1]: Device ID 0x1100
    PCI1 device[1]: Vendor ID 0x1013
    PCI1 device[2]: Device ID 0x680
    PCI1 device[2]: Vendor ID 0x1095
    PCI1 device[3]: Device ID 0x5618
    PCI1 device[3]: Vendor ID 0x14e4
    Configuring MPPs ...
    Configuring PCMCIA slots ...
    System Bootstrap, Version 1.53(20090311:225342) [CRS-1 ROMMON],
    Copyright (c) 1994-2009 by Cisco Systems, Inc.
    Acquiring backplane mastership ........failed
    Board type is 0x100002 (1048578)
    Switch 0 initialized
    Backplane FE port Up... Enabling
    Enabling watchdog
    G4(7457-NonSMP-MV64360 Rev 4) platform with 4096 MB of main memory
    Acquiring backplane mastership....failed.
    Unable to access backplane ... invoking READ EEPROM protocol
    Enabling only inter-RP port... successful
    Sending backplane ID EEPROM read request
    Our MAC address is 0249.4450.0008
    Interface link changed state to UP.
    Sending ID EEPROM read request.
    HIT CTRL-C to abort
    ID EEPROM read request successful.
    Reconfiguring switches with default config ...
    Chassis type: 484
        CARD_RACK_NUMBER: 0
        CARD_SLOT_NUMBER: 0
            CPU_INSTANCE: 1
      RACK_SERIAL_NUMBER: TBM13332678    
    MBI Validation starts ...Our MAC address is 001e.1392.84ee
    Interface link changed state to UP.
    Interface link state up.
    MBI validation sending request.
    HIT CTRL-C to abort
    MBI validation sending request.
    HIT CTRL-C to abort
    mbi_val_process_packet: received response.
    RACK_NUM = 0, RACK_TYPE=0
    Local image to boot : bootflash:disk0/hfr-os-mbi-3.8.2/mbihfr-rp.vm
    boot: booting from bootflash:disk0/hfr-os-mbi-3.8.2/mbihfr-rp.vm
    tracelogger: starting tracing in background ring mode
    tracelogger running with args: -startring -F 1 -F 2
                   Restricted Rights Legend
    Use, duplication, or disclosure by the Government is
    subject to restrictions as set forth in subparagraph
    (c) of the Commercial Computer Software - Restricted
    Rights clause at FAR sec. 52.227-19 and subparagraph
    (c) (1) (ii) of the Rights in Technical Data and Computer
    Software clause at DFARS sec. 252.227-7013.
               cisco Systems, Inc.
               170 West Tasman Drive
               San Jose, California 95134-1706
    Cisco IOS XR Software for the Cisco XR HFR, Version 3.8.2
    Copyright (c) 2009 by Cisco Systems, Inc.
    This (D)RP Node is not ready or active for login /configuration
    This (D)RP Node is not ready or active for login /configuration
    RP/0/RP0/CPU0:Jan 15 09:28:36 : redfs_svr[83]: %OS-REDFS-5-INIT_FAILED : Failed to initialize no devices available: 0x13:No such device
    and reboot again , I disabled WATCHDOG but nothing happen,?
    this is the show platform from RP0
    RP/0/RP1/CPU0:BGD-JAD-PGW1#sh plat
    Wed Jan 15 12:08:50.549 Iraq
    [KNode            Type            PLIM            State           Config State
    0/0/CPU0        MSC             Jacket Card     IOS XR RUN      PWR,NSHUT,MON
    0/0/0           MSC(SPA)        10X1GE          OK              PWR,NSHUT,MON
    0/0/1           MSC(SPA)        1x10GE          OK              PWR,NSHUT,MON
    0/0/2           MSC(SPA)        10X1GE          OK              PWR,NSHUT,MON
    0/0/4           MSC(SPA)        1x10GE          OK              PWR,NSHUT,MON
    0/RP0/CPU0      RP(Standby)     N/A             MBI-BOOTING     PWR,NSHUT,MON
    0/RP1/CPU0      RP(Active)      N/A             IOS XR RUN      PWR,NSHUT,MON
    thanks alot

    Duplicate posts. 
    Go here:  https://supportforums.cisco.com/thread/2260981

  • CRS with 10GE port

    Hi ,
    As of now we use 1 port 10GE card only (Cisco 1-Port 10-Gigabit Ethernet LAN/WAN-PHY SPA) in our CRS connects to Core backbone.
    We might need 10GE for access now to provide 10GE to PE ( pure ethernet not any optical technology).
    I was trying to find out the line card support more 10GE port density for this purpose. Cisco support 8 port 10GE module but that is not SPA rather normal Ethernet card (Cisco CRS-1 8-Port 10 Gigabit Ethernet Interface Module). How is it diff than SPA to use for PE-P - MPLS link includes LSP, Qos etc feature....
    Can I use this 8 port 10GE card for the above puropse ? Important thing there should not be any major limitation
    Regards,
    Chintan

    Hello Chintan,
    in other platforms we are used to see more features or different features supported on SPA modules.
    the datasheet of the 8 TenGiga
    http://www.cisco.com/en/US/prod/collateral/routers/ps5763/ps5862/product_data_sheet09186a008022d5e9.html
    About SW it just says:
    Software Compatibility
    Cisco IOS XR Software Release 3.0 or later
    the list of features for SPA GE and 10GE
    http://www.cisco.com/en/US/prod/collateral/modules/ps6267/product_data_sheet0900aecd804d884d_ps5763_Products_Data_Sheet.html
    There is some more detail.
    then I've gone to
    www.cisco.com/go/crs
    but I've found no useful info
    Looking at the configuration guides, the QoS for example I didn't find any distinction about the linecards
    http://www.cisco.com/en/US/docs/ios_xr_sw/iosxr_r3.7/qos/configuration/guide/qc37fab.html#wp998930
    Ask to your cisco account manager or even open a TAC service request to request info to be sure.
    Hope to help
    Giuseppe

Maybe you are looking for