วันพุธที่ 1 กันยายน พ.ศ. 2564

ปัญหา "No space left on device" บน Cisco AP1800/2800/3800 เมื่อ Upgrade Version

ปัญหา "No space left on device" บน Cisco AP1800/2800/3800

พอดีจะทำการ upgrade Cisco AP จาก lightweight ไปเป็น Mobility Express (ME) version 8.10.151.0 แต่ดันเจอปัญหา ดังนี้

#ap-type mobility-express tftp://X.X.X.X/AIR-AP2800-K9-ME-8-10-151-0.tar
Starting the ME image download...
It may take a few minutes to finish download.
If it is longer, please abort command, check network connection and try again
#######################################################################   99.4%
Image downloaded, writing to flash...
do CHECK_ME, part1 is active part
tar: write error: No space left on device
sh: write error: No space left on device
 
Error, image file size is smaller than image+key+signature 0x02339000 : 0x02ae45a1
Segmentation fault (core dumped)
part.bin signature verification failure, exit the script
Error: Image update failed.


ก็เลยลองตรวจสอบ storage ดู ด้วยคำสั่ง #show file system ปรากฎว่า มี Size แค่ 57.5 MB

Filesystem                Size      Used Available Use% Mounted on
flash                    57.5M    164.0K     54.3M  0% /storage


ซึ่ง Software ของ ME version 8.10.151.0 มีขนาด 65.56 MB



อ้าว เฮ้ย !! ทำไมอัพเกรดไม่ได้ทั้งๆที่ software ยังรองรับ แล้วทำไม size มันไม่พอได้อย่างไร เลยไปลองเปิด datasheet ดู ปรากฎว่า flash มีขนาด 256 MB !!! อ้าว ยังไงวะเนี่ยยย



สุดท้ายก็ไม่ได้คำตอบแต่สังเกตุว่า AP ที่ผลิต lot ประมาณปี 2016 ลงไป จะเป็นแบบนี้ (จากการสันนิษฐานเพราะไม่แน่ใจเหมือนกัน)

ก็เลยลองไป download software ของ Lightweight AP ของ version 8.5 เพื่อหวังว่ามันจะสามารถ convert ได้ เพราะ size มันน้อยกว่า 39.59 MB ก็น่าจะพอได้



#archive download-sw /reload tftp://X.X.X.X/ap3g3-k9w8-tar.153-3.JJ1.tar


สรุปว่าผ่านนนน จากนั้น ก็ทำการ upgrade ME 8.10.151.0 เข้าไปโดยใช้ไฟล์ image bundle


จากนั้นแตกไฟล์ออกมาจะได้แบบนี้ ซึ่งผมจะใช้ไฟล์ ap3g3 สำหรับ AP2802 (สังเกตุ size ว่ามัน 68.7MB ซึ่งมันเกิน size บน AP ที่มีแค่ 57.5 MB แต่ผมก็งงว่าทำไมมันได้ เดี๋ยวลองทำตามไปเรื่อยๆ)



ส่วนรุ่นอื่นสามารถใช้ตามนี้ได้เลย


จากนั้นก็ upgrade image เข้าไปโดยเลือกเฉพาะ ap3g3 ที่เป็นของรุ่น AP 2802

#archive download-sw /reload tftp://X.X.X.X/AIR-AP3800-K9-ME-8-10-121-0/ap3g3



สรุปว่า ได้เฉยเลย

(Cisco Controller) >show sysinfo 

Manufacturer's Name.............................. Cisco Systems Inc.
Product Name..................................... Cisco Controller
Product Version.................................. 8.10.151.0
OUI File Last Update Time........................ N/A

System Name...................................... ME
System Location.................................. 


ซึ่งตอนนี้ก็ยัง งง อยู่เหมือนกัน ว่าทำไม

สรุปครับ ถ้าเกิดปัญหาไม่สามารถ upgrade/convert Cisco AP 1800/2800/3800 ไปเป็น version ตั้งแต่ 8.8++ ได้ เพราะ flash sizing ไม่พอ มีแค่ 57.5 MB ให้ทำการ upgrade เป็น lightweight version 8.5 ก่อน แล้วค่อย upgrade ไปเป็น ME โดยเลือกไฟล์ ap3g3 (หรือตามรุ่นของ AP) ต่อไป


จบบริบูรณ์ครับ ปล้ำมาหลายวัน :(

ref:
https://community.cisco.com/t5/wireless/ap3802-8-5-135-gt-8-10-121-quot-no-space-left-quot/m-p/4419609

วันพฤหัสบดีที่ 20 พฤษภาคม พ.ศ. 2564

การ Convert Install Mode กับ Bundle Mode บน Cisco Switch 3850/9000 IOS-XE


ใน Cisco Switch รุ่น Catalyst 3850 หรือ 9000 Series จะใช้งาน IOS-XE ซึ่งประกอบไปด้วย 2 modes ในการ boot image คือ Install mode และ Bundle mode


Install Mode

ใช้ package-provisioning file ชื่อว่า package.conf เพื่อทำการ boot switch ไม่รองรับการ boot จาก USB หรือ TFTP


Bundle Mode

ใช้ Cisco IOS image ที่เป็น .bin เพื่อทำการ boot switch ก็คือแบบดั้งเดิมที่เราคุ้นเคยนั่นเอง แบบนี้จะใช้ RAM มากกว่าแบบ Install mode เพราะ package จะถูกกระจายไปยัง RAM และจะไม่รองรับการทำงานบางอย่าง เช่น Auto-upgrade หรือ การใช้งานกับ feature บน SD-Access


Converting from Install Mode to Bundle Mode


1. ตรวจสอบ mode โดยใช้คำสั่ง show version ว่าปัจจุบันเป็น Install mode อยู่
Device# show version Cisco IOS Software, Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M), Experimental Version Denali 16.1.20151117:003253 [v161_0_throttle-BLD-BLD_V161_0_THROTTLE_LATEST_20151116_230450 104] Copyright (c) 1986-2015 by Cisco Systems, Inc. Compiled Mon 16-Nov-15 16:34 by mcpre Cisco IOS-XE software, Copyright (c) 2005-2015 by cisco Systems, Inc. All rights reserved. Certain components of Cisco IOS-XE software are licensed under the GNU General Public License ("GPL") Version 2.0. The software code licensed under GPL Version 2.0 is free software that comes with ABSOLUTELY NO WARRANTY. You can redistribute and/or modify such GPL code under the terms of GPL Version 2.0. For more details, see the documentation or "License Notice" file accompanying the IOS-XE software, or the applicable URL provided on the flyer accompanying the IOS-XE software. ROM: IOS-XE ROMMON BOOTLDR: CAT3K_CAA Boot Loader (CAT3K_CAA-HBOOT-M) Version 3.1, engineering software (D) Device uptime is 8 minutes Uptime for this control processor is 15 minutes System returned to ROM by Power Failure System image file is "flash:packages.conf" Last reload reason: Reload Command This product contains cryptographic features and is subject to United States and local country laws governing import, export, transfer and use. Delivery of Cisco cryptographic products does not imply third-party authority to import, export, distribute or use encryption. Importers, exporters, distributors and users are responsible for compliance with U.S. and local country laws. By using this product you agree to comply with applicable laws and regulations. If you are unable to comply with U.S. and local laws, return this product immediately. A summary of U.S. laws governing Cisco cryptographic products may be found at: http ://www.cisco.com /wwl /export /crypto/tool/stqrg. html If you require further assistance please contact us by sending email to export@cisco.com. Technology Package License Information: ----------------------------------------------------------------- Technology-package Technology-package Current Type Next reboot ------------------------------------------------------------------ lanbasek9 Permanent lanbasek9 cisco WS-C3850-24P (MIPS) processor with 894696K/6147K bytes of memory. Processor board ID FOC1602V2GZ 2 Virtual Ethernet interfaces 56 Gigabit Ethernet interfaces 8 Ten Gigabit Ethernet interfaces 2048K bytes of non-volatile configuration memory. 4194304K bytes of physical memory. 147136K bytes of Crash Files at crashinfo:. 1735776K bytes of Flash at flash:. 891K bytes of TCL Script Files at script:. 3830880K bytes of USB Flash at usbflash0:. 0K bytes of at webui:. Base Ethernet MAC Address : 20:37:06:53:0c:80 Motherboard Assembly Number : 73-12238-03 Motherboard Serial Number : FOC160159MG Model Revision Number : P2 Motherboard Revision Number : 03 Model Number : WS-C3850-24P System Serial Number : FOC1602V2GZ Switch Ports Model SW Version SW Image Mode ------ ----- ----- ---------- ---------- ---- * 1 32 WS-C3850-24T Denali 16.1.1 CAT3K_CAA-UNIVERSALK9 INSTALL Configuration register is 0x102


2. ทำการตั้งค่า Boot file โดยชี้ไปที่ .bin (ถ้าไม่มีไฟล์ให้ทำการ download และ copy เข้าไปใน flash ก่อน) จากนั้นทำการ save และสั่ง reload

Device# configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.

Device(config)# no boot system
Device(config)# boot system switch all flash:cat3k_caa-universalk9.xx.SSA.bin
Device(config)# do write memory 

Building configuration...
Compressed configuration from 9209 bytes to 4151 bytes[OK]

Device(config)# exit
Device# reload

Reload command is being issued on Active unit, this will reload the whole stack
Proceed with reload? [confirm]

Chassis 1 reloading, reason - Reload command 

 

3. หลังจาก boot ขึ้นมาใหม่แล้ว ให้ตรวจสอบ mode อีกครั้ง จะเห็นว่าเป็น Bundle mode แล้ว

Press RETURN to get started!

Device> enable
Device# show version
Cisco IOS Software, Catalyst L3 Switch Software (CAT3K_CAA-UNIVERSALK9-M), Experimental Version Denali 16.1.20151117:003253 [v161_0_throttle-BLD-BLD_V161_0_THROTTLE_LATEST_20151116_230450 104]
Copyright (c) 1986-2015 by Cisco Systems, Inc.
Compiled Mon 16-Nov-15 16:34 by mcpre


Cisco IOS-XE software, Copyright (c) 2005-2015 by cisco Systems, Inc.
All rights reserved.  Certain components of Cisco IOS-XE software are
licensed under the GNU General Public License ("GPL") Version 2.0.  The
software code licensed under GPL Version 2.0 is free software that comes
with ABSOLUTELY NO WARRANTY.  You can redistribute and/or modify such
GPL code under the terms of GPL Version 2.0.  For more details, see the
documentation or "License Notice" file accompanying the IOS-XE software,
or the applicable URL provided on the flyer accompanying the IOS-XE
software.


ROM: IOS-XE ROMMON
BOOTLDR: CAT3K_CAA Boot Loader (CAT3K_CAA-HBOOT-M) Version 3.1, engineering software (D)

NSWA uptime is 1 minute
Uptime for this control processor is 8 minutes
System returned to ROM by Power Failure
System image file is "flash:cat3k_caa-universalk9.BLD_V161_0_THROTTLE_LATEST_20151116_230450.SSA.bin"
Last reload reason: Reload Command



This product contains cryptographic features and is subject to United
States and local country laws governing import, export, transfer and
use. Delivery of Cisco cryptographic products does not imply
third-party authority to import, export, distribute or use encryption.
Importers, exporters, distributors and users are responsible for
compliance with U.S. and local country laws. By using this product you
agree to comply with applicable laws and regulations. If you are unable
to comply with U.S. and local laws, return this product immediately.

A summary of U.S. laws governing Cisco cryptographic products may be found at:
http :// www.cisco.com /wwl /export/crypto/tool/stqrg. html

If you require further assistance please contact us by sending email to
export@cisco.com.


Technology Package License Information:

-----------------------------------------------------------------
Technology-package                   Technology-package
Current             Type             Next reboot
------------------------------------------------------------------
lanbasek9           Permanent        lanbasek9

cisco WS-C3850-24P (MIPS) processor with 894696K/6147K bytes of memory.
Processor board ID FOC1602V2GZ
2 Virtual Ethernet interfaces
56 Gigabit Ethernet interfaces
8 Ten Gigabit Ethernet interfaces
2048K bytes of non-volatile configuration memory.
4194304K bytes of physical memory.
147136K bytes of Crash Files at crashinfo:.
1735776K bytes of Flash at flash:.
891K bytes of TCL Script Files at script:.
3830880K bytes of USB Flash at usbflash0:.
0K bytes of  at webui:.

Base Ethernet MAC Address          : 20:37:06:53:0c:80
Motherboard Assembly Number        : 73-12238-03
Motherboard Serial Number          : FOC160159MG
Model Revision Number              : P2
Motherboard Revision Number        : 03
Model Number                       : WS-C3850-24P
System Serial Number               : FOC1602V2GZ


Switch Ports Model              SW Version        SW Image              Mode
------ ----- -----              ----------        ----------            ----
*    1 32    WS-C3850-24T       Denali 16.1.1     CAT3K_CAA-UNIVERSALK9 BUNDLE

Configuration register is 0x102 


วันศุกร์ที่ 12 กุมภาพันธ์ พ.ศ. 2564

Dynamic Routing over Virtual Port Channel (vPC) บน Cisco Nexus

การทำ Dynamic Routing ผ่าน Virtual Port Channel (vPC) บน Cisco Nexus Platform นั้น จะมีประเด็นอะไรให้สนใจบ้างในบทความนี้ มาดูกันดีกว่าครับ

ปกติแล้วการส่งข้อมูลผ่าน vPC บน Cisco Nexus นั้นมันจะมีกฎของมันอยู่ ถ้ามีการ forward  data ผ่าน Peer-Link แล้ว Nexus ตัวที่ได้รับ data เข้ามาจาก Peer-Link จะไม่ถูก forward ไปยัง vPC member เพื่อป้องกัน Loop


จากรูปจะเห็นว่า NXOS1 กับ NXOS2 มีการทำ vPC เชื่อมต่อลงมาหา Switch ด้านล่าง และ เชื่อมต่อไปหา Router ด้านบน ในกรณีนี้ ถ้า NXOS2 คือ Active สำหรับ  HSRP vPC แต่ data traffic นั้น forward ไปฝั่ง NXOS1 ทำให้ NXOS1 ทำการ forward data traffic ไปหา NXOS2 ที่เป็น Active (Gateway)

เมื่อ NXOS2 ได้รับ data traffic เข้ามาทาง Peer-Link ตามกฎ มันจะไม่ forward traffic ไปยัง vPC member เพื่อป้องกัน Loop ทำให้ traffic ที่ forward ผ่าน Peer-Link มาหา NXOS2 ถูก drop และใช้งานไม่ได้ จึงมี feature ที่เข้ามาช่วยแก้ไขปัญหานี้ นั่นคือ Peer-Gateway

ปกติแล้ว Peer-Gateway จะแนะนำให้ใช้งานกับพวก NAS และ Load Balance ที่มีพฤติกรรมในการตอบกลับการรับส่งข้อมูลโดยใช้ที่อยู่ MAC ของอุปกรณ์ที่ส่งแทนที่จะเป็น HSRP MAC (ซึ่งผมอาจจะไม่ได้ลงรายละเอียดในภาพของ Peer-Gateway มากในบทความนี้นะครับ แต่พอดีมันเกี่ยวข้องด้วยนิดๆหน่อยๆ ก็เลยพูดถึงให้พอเข้าใจกันเล็กน้อย)

ซึ่งที่กล่าวมานั้นในการใช้งานที่เป็นแบบ Non-vPC มันไม่เคยทำให้เกิดปัญหา (อันที่จริงคนส่วนใหญ่อาจไม่เคยสังเกตเห็นเลยด้วยซ้ำ) แต่เมื่อใช้บน vPC ก็จะทำให้เกิดปัญหาดังกล่าวได้ Peer-Gateway เข้ามาช่วยแก้ไขปัญหานี้


และเมื่อเราใช้งาน Dynamic Routing ผ่าน vPC ล่ะ มันสามารถทำงานได้เหมือนกับ Data traffic โดยใช้ Peer-Gateway หรือไม่ ??


จากรูปด้านบน จะเห็นว่ามีการใช้งาน Dynamic Routing เป็น OSPF ระหว่าง NXOS1 , NXOS2 และ Router ซึ่งระหว่าง NXOS2 และ Router ก็สามารถ peer OSPF neighbor ได้ปกติดี แล้วลองมาดูรูปด้านล่าง


จากรูปด้านล่างจะเห็นว่า รูปซ้าย ถ้า Router ทำการ peer OSPF กับ NXOS2 แล้ว OSPF packet ส่งมาทาง direct connect เลยก็จะไม่เป็นปัญหาอะไร แต่ถ้าเกิด OSPF packet ถูกส่งไปหา NXOS1 แล้ว มันต้องสามารถส่งผ่าน Peer-Link ไปหา NXOS2 ได้ถูกไหมครับ แต่กรณีมันจะไม่ได้ !! สาเหตุเพราะ OSPF จะถูก set TTL = 1 เมื่อมาถึง NXOS1 แล้ว จะเหลือ TTL = 0 ทำให้ OSPF packet ถูก drop

เช่นเดียวกันกับ รูปขวา ถ้า Router ทำการ peer OSPF กับ NXOS1 แล้วส่ง OSPF packet ไปหา NXOS2 ก็จะเกิดปัญหาเช่นเดียวกัน


มาลองดูผลการทดสอบจากรูปดีกว่าครับ

ผลที่เห็นบน NXOS1

N9K1# show ip ospf nei
 OSPF Process ID 1 VRF default
 Total number of neighbors: 2
 Neighbor ID     Pri State            Up Time  Address         Interface
 N9K2            1 FULL/DR            00:02:30 10.0.0.3        Vlan100 
 Router          1 EXSTART/BDR        00:00:02 10.0.0.254      Vlan100 

ผลที่เห็นบน Router

Router# show ip ospf nei

Neighbor ID     Pri   State           Dead Time   Address         Interface
N9K1           1   EXSTART/DROTHER    00:00:39    10.0.0.2        Port-channel1
N9K2           1   FULL/DR            00:00:34    10.0.0.3        Port-channel1


วิธีแก้ไข

ในกรณีเราจะใช้คำสั่ง "layer3 peer-router" ภายใต้ vpc domain คำสั่งนี้จะทำให้ Nexus ไม่ลดค่า TTL ลงนั่นเอง

บน NXOS1 และ NXOS2

vpc domain 1
  peer-keepalive destination 169.254.0.2 source 169.254.0.1
  peer-gateway
  layer3 peer-router

ผลที่เห็นบน NXOS1

N9K1# show ip ospf nei
 OSPF Process ID 1 VRF default
 Total number of neighbors: 2
 Neighbor ID     Pri State            Up Time  Address         Interface
 N9K2            1 FULL/DR            00:02:30 10.0.0.3          Vlan100 
 Router          1 FULL/BDR           00:00:02 10.0.0.254        Vlan100 

ผลที่เห็นบน Router

Router# show ip ospf nei

Neighbor ID     Pri   State           Dead Time   Address         Interface
N9K1           1   FULL/DROTHER       00:00:39    10.0.0.2        Port-channel1
N9K2           1   FULL/DR            00:00:34    10.0.0.3        Port-channel1


จริงๆแล้วยังมีรายละเอียดอีกมากสำหรับการใช้งาน Dynamic Routing over vPC ทั้งการต่อแบบ Orphan อีก สามารถลองติดตามอ่านข้อมูลเพิ่มเติมได้ตาม Reference ด้านล่างเลยครับ

https://networkdirection.net/articles/virtual-port-channels-vpc/vpcandroutingprotocols/

https://www.cisco.com/c/en/us/support/docs/ip/ip-routing/118997-technote-nexus-00.html

https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2017/pdf/BRKDCN-2378.pdf

https://adamraffe.com/nexus%207000/virtual%20port%20channel/2013/03/25/peer-gateway-doesnt-solve-l3-over-vpc/

https://www.youtube.com/watch?v=KPsnI6h1RIs&t=127s

วันอาทิตย์ที่ 4 ตุลาคม พ.ศ. 2563

เมื่อ Console เข้า Cisco AP ที่ Join C9800 แล้วขึ้นข้อความ "No valid user found, please configure a valid user from Controller"


ถ้าเราใช้งาน C9800 WLC แล้วจะ Console เข้าไปที่ AP ในขณะที่ AP นั้น Join WLC ไปแล้ว เราจะเห็นข้อความนี้ขึ้นมา
No valid user found, please configure a valid user from Controller
% Authentication failed

ซึ่งโดยปกติแล้วบน Cisco WLC แบบเก่าที่เป็น AireOS นั้น เวลาที่ AP join กับ AireOS WLC แล้ว เราสามารถใช้ default username/password เป็น Cisco/Cisco ได้เลย หรือจะตั้งค่าเปลี่ยน username/password ให้สำหรับ AP ก็ได้ 

แต่สำหรับ AP ที่ join กับ C9800 WLC นั้น จะไม่เป็นแบบนั้น ด้วยเหตุผลเรื่อง Security ซึ่ง เราก็สามารถตั้งค่า username/password สำหรับ AP ที่ join กับ C9800 WLC ได้ ดังนี้



สามารถตั้งค่าโดยใช้ CLI ได้

ap profile NP-HQ

 description "NP-HQ"
 mgmtuser username admin password 0 cisco secret 0 cisco


ลองทดสอบ Console เข้า AP เพื่อ Logon อีกครั้ง

No valid user found, please configure a valid user from Controller

% Authentication failed

 

No valid user found, please configure a valid user from Controller[*10/04/2020 05:09:44.5537] chpasswd: password for user changed

 

User Access Verification

Username: admin

Password: 

AP0C75.BDB2.0634>enable 

Password: 

AP0C75.BDB2.0634#

AP0C75.BDB2.0634#

ap profile default-ap-profile
 description "default ap profile"
 mgmtuser username admin password 0 Cisco1112 secret 0 Cisco1112
ap profile default-ap-profile
 description "default ap profile"
 mgmtuser username admin password 0 Cisco1112 secret 0 Cisco1112

วันเสาร์ที่ 11 กรกฎาคม พ.ศ. 2563

Cisco SD-WAN Tips and Notes




Cisco SDWAN Quiz of the day:
  •     What is the function of "Validate the uploaded vEdge list and send to controllers" highlighted in the screenshot below?
  •     What is the result of not selecting that option?


The answer is:

  • The function of "Validate the uploaded vEdge list and send to controllers" is to make sure that all the controllers (especially vBond) add the Edge devices to their whitelisted devices that can talk and authenticate to join the Cisco SDWAN overlay.
  • If you don't select that option, it will add the devices but it won't put them in staging mode (they will be in invalid mode). staging mode still allows cEdges/vEdges to join the overlay but no build BFD tunnels, so technically the Edge device is joining and talking to the controllers. in staging mode the Edge device is allowed to setup a netconf session as well with vManage to receive configuration. in a valid state, the Edge device will build both control connections and BFD tunnels.
  • If you forget to tick that option, you can go to the configuration tab, then to certificates, make sure that the edge device in question is changed to "staging" or "valid". then at the top, click "Send to controllers" so they can receive the updated list.