Licensing for Cisco Catalyst 3850 Series Switches – Part 1

LAN Base: This provides Enterprise access layer 2 switching features

●   IP Base: This provides Enterprise access layer 3 switching features

●   IP Services: This provides Advanced enterprise layer 3 switching (IPv4 and IPv6) features

1. The LAN Base feature set provides improved intelligent services for example wide-ranging Layer 2 features, supporting up to 255 VLANs.

2. The IP Base feature set supplies entry-level basic enterprise services in addition to all the standard LAN Base features, supporting 1K VLANs. IP Base also provides with the support for wireless controller functionality (mobility agent and mobility controller roles; additional access point license is necessary for the mobility controller role), routed access, smart operations, FNF, etc.

3. The IP Services feature set supplies full enterprise services including advanced Layer 3 features like EIGRP, OSPF, BGP, PIM, and IPv6 routing including OSPFv3 and EIGRPv6. All the software feature sets have support for advanced security and MQC-based Quality of Service (QoS).

The Catalyst 3850 Series Switches having a LAN Base feature set can only be stacked with other Catalyst 3850 Series LAN Base networking switches. The same goes for IP Base and IP Services. A mixed stack of LAN Base switches with IP Base or IP Services feature set will not be supported.

The 12-port and 24-port SFP+- and SFP-based models along with the 48-port SFP+ model can only be ordered with IP Base or IP Services licenses. Consequently, to stack with the LAN Base models, they must be configured in LAN Base mode from the CLI.

Users can transparently upgrade the software feature sets in the Catalyst 3850 Series Switches via Cisco IOS Software CLI utilizing the right to use (RTU)-based software upgrade procedure. Software activation empowers the Cisco IOS Software feature sets. Based on the license type, Cisco IOS Software triggers the applicable feature set. License types can be modified, or upgraded, to trigger a different feature set.

Software Policy for Catalyst 3850 Series Switches

Users with Cisco Catalyst LAN Base and IP Base software feature sets will be supplied with maintenance updates and bug fixes developed to uphold the acquiescence of the software with available specifications, release notes, and industry standards compliance as long as the original end user continues ownership or use of the product, or up to one year from the end-of-sale (EOS) date for that product, whichever happens first. Users having licenses for Cisco IP Services software images need a service support contract like Cisco SMARTnet Service to be able to download updates. This policy takes the place of any preceding warranty or software statement and is subject to alteration without notice.

Need more guidance? Just contact us today. We are a 100% Cisco-Certified partner and can assist you with all of your Cisco support questions.

Licensing for Cisco Catalyst 3850 Series Switches – Part 2

Cisco ONE Software is an innovative method for users to buy and use Cisco’s infrastructure software. It provides an easy consumption model, focused on frequent user scenarios in the data center, WANs, and LANs.

Cisco ONE Software and services supply users with 4 key advantages:

  • Software suites which tackle typical user scenarios at an affordable cost
  • Investment defense of their software purchase via software services-empowered license transportability
  • Access to continuing modernization and new technology via Cisco Software Support Service (SWSS)
  • Flexible licensing models to effortlessly allocate the user’s software expense over time

For ordering information for Cisco ONE Software for the Cisco Catalyst 3850 Series Switches, go to http://www.cisco.com/c/en/us/products/software/one-access/switching-part-numbers.html.

Available Licenses for the Cisco Catalyst 3850 Series Switches

Software Licenses

C3850-12-S-E

Cisco Catalyst 3850 12-port IP Base to IP Services RTU paper license

C3850-24-L-S

Cisco Catalyst 3850 24-port Switch LAN Base to IP Base RTU paper license

C3850-48-L-S

Cisco Catalyst 3850 48-port Switch LAN Base to IP Base RTU paper license

C3850-24-L-E

Cisco Catalyst 3850 24-port LAN Base to IP Services RTU paper license

C3850-48-L-E

Cisco Catalyst 3850 48-port LAN Base to IP Services RTU paper license

C3850-24-S-E

Cisco Catalyst 3850 24-port IP Base to IP Services RTU paper license

C3850-48-S-E

Cisco Catalyst 3850 48-port IP Base to IP Services RTU paper license

L-C3850-24-L-S

Cisco Catalyst 3850 24-port LAN Base to IP Base RTU electronic license

L-C3850-48-L-S

Cisco Catalyst 3850 48-port LAN Base to IP Base RTU electronic license

L-C3850-24-L-E

Cisco Catalyst 3850 24-port LAN Base to IP Services RTU electronic license

L-C3850-48-L-E

Cisco Catalyst 3850 48-port LAN Base to IP Services RTU electronic license

L-C3850-24-S-E

Cisco Catalyst 3850 24-port IP Base to IP Services RTU electronic license

L-C3850-48-S-E

Cisco Catalyst 3850 48-port IP Base to IP Services RTU electronic license

L-C3850-12-S-E

Cisco Catalyst 3850 12-port IP Base to IP Services RTU electronic license

Access Point Licenses

L-LIC-CT3850-UPG

Primary upgrade license SKU for Cisco 3850 wireless controller (e-delivery)

L-LIC-CTIOS-1A

1 access point adder license for Cisco IOS Software based wireless controller (e-delivery)

LIC-CT3850-UPG

Primary upgrade license SKU for Cisco 3850 wireless controller (paper license)

LIC-CTIOS-1A

1 access point adder license for the Cisco IOS Software based wireless controller (paper license)

 

Access Point Licensing for Cisco Catalyst 3850: An access point license is necessary for Cisco Catalyst 3850 switches functioning in mobility controller mode. No access point license is necessary for a Catalyst 3850 switch functioning in mobility agent mode. This feature is included in the IP Base feature set. Other equipment which can function as a mobility controller include the WLC 5760, WLC 5508, and WiSM2 wireless controllers. Access point licenses can be relocated only amongst two Catalyst 3850 switches or amongst 3850 and 5760 controllers and vice versa.

Need more guidance? Just contact us today. We are a 100% Cisco-Certified partner and can assist you with all of your Cisco support questions.

Cisco IOS Packaging FAQs – Part 3

A. For assistance with IOS package selection, please have a look at the Cisco IOS Packaging Product Bulletin available on Cisco’s website: http://www.cisco.com/en/US/products/sw/iosswrel/ps5460/index.html

Q. Which Cisco tools can identify the memory impact of the new packages?

A.

• Cisco Software Advisor: http://www.cisco.com/pcgi-bin/Support/CompNav/Index.pl

• Cisco IOS Upgrade Planner: http://www.cisco.com/pcgi-bin/Software/Iosplanner/Planner-tool/iosplanner.cgi

• Cisco Feature Navigator: http://tools.cisco.com/ITDIT/CFN/jsp/index.jsp

By utilization of these tools together, registered clients and partners can search by feature or release, and can compare differentiated releases and feature sets.

IOS Packaging at Cisco

Q. Can clients transfer licenses for older packages?

A. Yes, clients will be allowed a one-time only opportunity to transfer licenses from the old packages that they are using today to a new package. No client action is necessary for updating the old licensing to the new ones.

Q. How can Cisco IOS Packaging be related to other differentiated Cisco packaging efforts?

A. Cisco IOS Packaging is just one part of a complete repackaging initiative at Cisco. The other pieces are Cisco IOS Streamlining, Cisco IOS Image Reduction, and Cisco IOS Extended Support.

For further information about these programs, please visit the below Cisco resource page: http://www.cisco.com/en/US/products/sw/iosswrel/ps5460/index.html

Cisco IOS Future Roadmap

Q. What future Packaging changes are currently planned and in the pipeline for the future IOS upgrades?

A.

• Cisco IOS Packaging 12.2S for Cisco 6500 Series LAN Switches and Cisco 7600
Series Routers.

– This has happened. For further information about these programs, please see: http://www.cisco.com/en/US/products/sw/iosswrel/ps5460/prod_bulletin0900aecd80281b17.html

• Cisco IOS Packaging 12.2S for Edge/Core Routers for the Cisco 7200 Series Routers, Cisco 10000 Series Internet Routers, and more

 – This has happened. For further information about these programs, please see: http://www.cisco.com/en/US/products/sw/iosswrel/ps5460/prod_bulletin0900aecd80281b17.html

Q. Will Cisco be addressing the platforms which are not supported by these new packaging initiatives?

A. Cisco will continue to provide the older packages for such older platforms.

Cisco IOS Resources

Q. Where can we see a full mapping of older packages to the new IOS Packaging?

A. For migration information, please have a look at the Cisco IOS Packaging Product Bulletin: http://www.cisco.com/en/US/products/sw/iosswrel/ps5460/index.html

Need more guidance? Just contact us today. We are a 100% Cisco-Certified partner and can assist you with all of your Cisco support questions.

Cisco IOS Software Licensing – Part 3

In addition, the BGP routing protocol is now supported which was not a component of IP Base. Another vital area is IPv6 support. IP Services supplies OSPFv3 and EIGRP for IPv6 which are not accessible in IP Base. As a lot of clients are running out of IPv4 addresses, IPv6 support is quickly becoming a high priority necessity for the networks. Yet another significant area is full scale support for PIM for IP multicast routing, comprising PIM sparse mode (PIM-SM), PIM dense mode (PIM-DM), PIM sparse-dense mode and Source Specific Multicast (SSM). The full PIM routing support vastly enhances network efficacy as multimedia, interactive video and business collaborations produce huge traffic growth. Here is another vital improvement which IP Services allows: VRF-lite support is not included with IP Base but it is a part of IP Services. As you may remember, VRF-lite is a good method of segmenting a physical network into numerous logical networks for the purpose of network virtualization. Further included IP Services abilities comprise Web Cache Coordination Protocol (WCCP) and policy-based routing (PRB) support.

Please see below some information on numerous license SKUs, so that you can identify them with ease.

For the Cisco Catalyst 2960 and 2960S switches, the SKU group ending with
-S represents LAN Lite
-L represents LAN Base

For the Cisco Catalyst 3560-X and 3750-X switches, the SKU group ending with
-L represents LAN base
-S represents IP Base
-E represents IP Services

Given below are some sample SKUs.

Switches

LAN Lite

LAN Base

IP Base

IP Services

Catalyst
2960,
2960-S
switches

WS-C2960-24-S
(24 Ethernet ports, LAN Lite image)

WS-C2960S-24TD-L
(24 Ethernet ports, LAN Base image)

N/A

N/A

Catalyst
3560-X,
3750-X
switches

N/A

WS-C3750X-24T-L
(Stackable 24  Ethernet ports, LAN Base feature set)

WS-C3750X-24T-S
(Stackable 24  Ethernet ports,
IP Base feature set)

WS-C3750X-24T-E
(Stackable 24  Ethernet ports,
IP Services feature set)


Conclusion

In case you need dynamic routing for your enterprise access corporate networks, you will have to begin with IP Base. It provides you complete layer 2 proficiencies, plus vigorous Layer 3 features to support your access network with greater scale, performance and network services like protection and application enhancement. IP Services takes you one step ahead with complete scale support of unicast and multicast routing protocols, along with crucial services like network segmentation and IPv6 support for OSPF/EIGRP to allow the complete experience for the next generation modern workplace.

Final Comment

In the old days, your early software options were either the LAN Base or an IP Base license for your Cisco Catalyst 3560-X and 3750-X series switches. You would require an upgrade license to install IP Services. Moving forward, a family of new IP Services SKUs is now offered (SKUs ending with –E).  These new SKUs make it simple for you to install IP Services directly.

Need more guidance? Just contact us today. We are a 100% Cisco-Certified partner and can assist you with all of your Cisco support questions.

Cisco IOS Explained – Part 1

Even though the Cisco IOS code base comprises of a cooperative multitasking kernel, nearly all of the Cisco IOS features have been moved to different kernels including QNX and Linux for utilization in Cisco products or simulators like Cisco VIRL.

Not all of Cisco’s products run IOS. Prominent exemptions comprise of ASA security products, which run a Linux-derived operating system (OS), and carrier routers which run the IOS-XR.

Cisco IOS User Interface

The Cisco IOS command line interface supplies a permanent set of multiple-worded user commands. The set which is available is identified by the “mode” and the privileged access level of the current user. “Global configuration mode” supplies commands to modify the system’s configuration, and “interface configuration mode” supplies commands to modify the configuration of a particular interface. All commands are allocated a user privilege level, from 0 to 15, and can only be retrieved by users who have the requisite privilege level. Via the CLI, the commands accessible for each privilege level can be demarcated.

Nearly all of the builds of Cisco IOS come with a Tcl interpreter. By utilizing the Embedded Event Manager feature, the interpreter can be scripted to respond to happenings inside the network environment, like interface failure or periodic timers.

The available command modes comprise some of the below:

  • User EXEC Mode
  • Privileged EXEC Mode
  • Global Configuration Mode
  • ROM Monitor Mode
  • Setup Mode

Please note that in excess of one hundred configuration modes and sub modes are available.

Cisco IOS Versioning

Cisco IOS is versioned by utilizing three numbers and a few letters, the general form a.b(c.d)e, where:

  • a indicates the major version number
  • b indicates the minor version number
  • c indicates the release number, which commences at one and increases as the new releases in a same method a.b train are released. Just so you know, “Train” is Cisco-verbiage meaning, “a vehicle for providing Cisco software to a particular set of platforms and features.”
  • d (excluded from general releases) indicates the interim build number
  • e (0, 1 or two letters) indicates the software release train identifier, for example 0 (which identifies the mainline), T (indicating Technology), E (indicating Enterprise), S (indicating Service provider), XA indicating a special functionality train, XB indicating a differentiated special functionality train, and so on.

Need more guidance? Just contact us today. We are a 100% Cisco-Certified partner and can assist you with all of your Cisco support questions.

Cisco IOS Explained – Part 2

For example, 12.1(8)E14 is a Rebuild, the 14 indicating the 14th rebuild of 12.1(8)E. Rebuilds are developed to either rapidly remediate a fault, or to mollify Cisco’s customers who do not wish to upgrade to a later major revision as they could already be running crucial infrastructure on their hardware devices, and therefore choose to reduce modifications and the associated risks involved.

Cisco IOS Interim Releases – Interim Releases for Cisco IOS are normally developed on a weekly basis, and form a roll-up of the present developmental efforts. The Cisco advisory web site might have more than one possible interim to remediate a related problem (the purpose for this is not known yet to the general public).

Cisco IOS Maintenance Releases – IOS Maintenance Releases are basically meticulously tested releases which are made available and have improvements and bug fixes. Cisco recommends that it’s customers upgrade to Maintenance releases whereever possible, over Interim and Rebuild releases.

Trains

Cisco defines Trains as, “A train is a vehicle for providing Cisco software to a particular set of platforms and features.”

Cisco IOS Until Version 12.4

Prior to the release of Cisco IOS release 15, releases were divided into numerous trains, each comprising a dissimilar set of features. Trains more or less map onto distinctive markets or customer groups which Cisco is targeting.

  • The mainline train is meant to be the most stable release which Cisco can offer, and therefore it’s feature set is never expanded during its lifetime. Updates are released only to remediate bugs present in the product. The preceding technology train becomes the source for the present mainline train — as an example, the 12.1T train becomes the foundation for the 12.2 mainline. Consequently, to identify the features accessible with a specific mainline release, one can simply look at the previous T train release.
  • The T – Technology train, has access to the newest features and bug fixes during the course of its life, and is hence theoretically less stable as compared to the mainline. (In releases before the Cisco IOS Release 12.0, the P train functioned as the Technology train.) Cisco doesn’t advise usage of T train in any production locations except where there is urgency to execute a specific T train’s new IOS features.
  • The S – Service Provider train, runs only on Cisco’s core routing equipment and is comprehensively tailored for Service Provider clients.
  • The E – Enterprise train, is tailored for deployment in enterprise settings.
  • The B – broadband train, provides support for internet based broadband features.
  • The X* (XA, XB, etc.) – Special Release train, comprises of one-off releases developed to remediate a specific bug or supply a new feature. These are ultimately merged with one of the above trains.

There have been other trains from time to time, developed for particular requirements — for example, the 12.0AA train had new code which was a necessary requirement of Cisco’s AS5800.

Need more guidance? Just contact us today. We are a 100% Cisco-Certified partner and can assist you with all of your Cisco support questions.

Cisco IOS Explained – Part 3

The M releases are extended maintenance releases, for which Cisco will supply bug fixes for a period of 44 months. The T releases are standard maintenance releases, for which Cisco will only supply bug fixes for a period of 18 months.

Cisco IOS Packaging and Feature Sets

Nearly all of the Cisco equipment which is running IOS also has one or more “feature sets” or “packages”, normally eight packages for Cisco routers and five packages for Cisco network switches. As an example, Cisco IOS releases intended for deployment on Catalyst switches are obtainable as “standard” versions (supplying just basic IP routing), “enhanced” versions, which supply you with complete IPv4 routing support, and “advanced IP services” versions, which supply the improved features along with IPv6 support.

Each distinct package relates to one service category, including:

  • IP Data
  • Converged Voice & Data
  • Security & VPN

The precise feature set needed for a certain function can be found using the Cisco Feature Set Browser.

Starting with the 1900, 2900 and 3900 series of Cisco ISR Routers, Cisco revised the licensing model of IOS. Routers come out of the box with IP Base preinstalled, and supplementary feature pack licenses can be deployed as bolt-on additions to enlarge the feature set of the routing device. The obtainable feature packs are:

  • Data adds features including BFD, IP SLAs, IPX, L2TPv3, Mobile IP, MPLS, SCTP.
  • Security adds features including VPN, Firewall, IP SLAs, NAC.
  • Unified Communications (UC) adds features including CallManager Express, Gatekeeper, H.323, IP SLAs, MGCP, SIP, VoIP, CUBE(SBC).

An Interface Descriptor Block, long for IDB, is a part of memory or Cisco IOS internal data structure which comprises of information like the IP address, interface state, and packet statistics for networking data. Cisco’s IOS software keeps one IDB for each hardware interface in a specific Cisco switch or router and one IDB for each subinterface. The number of IDBs existing in a system differs with the Cisco hardware platform types.

Need more guidance? Just contact us today. We are a 100% Cisco-Certified partner and can assist you with all of your Cisco support questions.

Cisco IOS Explained – Part 4

On router platforms having software-only forwarding (e.g., Cisco 7200) most traffic handling, including access control list filtering and forwarding, is performed at interrupt level utilizing Cisco Express Forwarding (CEF) or dCEF (Distributed CEF). This implies that IOS does not need to perform a process context switch to forward a packet. Routing functions like OSPF or BGP run at the process level. In routers having hardware-based forwarding, like the Cisco 12000 series, IOS calculates the FIB in software and loads it into the forwarding hardware (like an ASIC or network processor), which completes the actual packet forwarding function.

Cisco IOS possesses a “monolithic” architecture, which implies that it runs as a single image and all processes will be sharing the same memory space. There is no memory protection amongst the processes, which implies that any bugs in IOS code can possibly corrupt data being utilized by other processes. It also comes with a run to completion scheduler, which implies that the kernel does not preventively stop a running process — the process must perform a kernel call before other processes get an opportunity to run. For Cisco equipment which needed very high availability, like the Cisco CRS-1, these restrictions were not satisfactory. In addition, competitive router operating systems which appeared 10 to 20 years after IOS, like Juniper’s JUNOS, were developed not to have these restrictions.

Cisco’s reply was to design a new version of Cisco IOS named IOS XR which provided modularity and memory protection amongst processes, lightweight threads, preventive scheduling and the capability to autonomously restart failed processes. IOS XR employs a third party real-time operating system microkernel (QNX), and a huge part of the current Cisco IOS code was re-written to benefit from the features provided by the new kernel. But the microkernel architecture eliminates from the kernel all processes which are not completely needed to run in the kernel, and implements them as processes comparable to the application processes. Via this method, IOS XR is able to attain the high availability necessary for the new router platform. Therefore, Cisco IOS and IOS XR are very dissimilar codebases, although they are actually interrelated in their functionality and design. In 2005, Cisco launched IOS XR for the Cisco 12000 series platform, extending the microkernel architecture from the CRS-1 to Cisco’s extensively installed core router.

In 2006, Cisco has presented IOS Software Modularity which extends the QNX microkernel into a more old-style IOS environment, but still supplying the software upgrade abilities which clients are demanding. It is presently obtainable on the Cisco Catalyst 6500 enterprise switch.

Cisco IOS – Security and Vulnerabilities

Due to the fact that Cisco IOS has to know the cleartext password for specific uses, (e.g., CHAP authentication) passwords entered into the CLI by default are feebly encrypted as ‘Type 7’ ciphertext, like “Router(config)#username jdoe password 7 0832585B1910010713181F”. This is developed to pre-empt “shoulder-surfing” attacks when studying router configurations and is not a safe method – they can be easily decrypted utilizing software known as “getpass” obtainable as of 1995, or “ios7crypt”, a current variant, even though the passwords can be decoded by the router by utilizing the “key chain” command and entering the type 7 password as the key, and then delivering a “show key” command; the above example decrypts to “stupidpass”. However, the program will not be able to decrypt ‘Type 5’ passwords or passwords set with the enable secret command, which utilizes salted MD5 hashes.

Cisco strongly recommends that all Cisco IOS equipment implement the authentication, authorization, and accounting (AAA) security model. AAA can use local, RADIUS, and TACACS+ databases. Nevertheless, a local account is normally still needed for emergency circumstances.

At the Black Hat Briefings conference held back in July 2005, Michael Lynn, while employed by Internet Security Systems at the time, presented proof of a possible vulnerability in Cisco IOS. Cisco had previously released a patch, but requested that this flaw not be made public. Cisco henceforth filed a lawsuit, but later settled this after an injunction was issued to pre-empt future disclosures.

Need more guidance? Just contact us today. We are a 100% Cisco-Certified partner and can assist you with all of your Cisco support questions.

Cisco IOS Software Licensing – Part 1

Here we will have a look at four common Cisco IOS Software feature licenses for Cisco Catalyst 2K and 3K switches. A quick proviso before we advance any further: This post is for information-sharing purposes only. It does not embody or substitute any official Cisco product documentation. Product specifications can be modified very hastily and usage of this post is only at the readers’ own risk.

The four common Cisco IOS Software feature licenses for switching are specified below:

LAN Lite:             Enterprise Entry Level Layer 2 Switching

LAN Base:           Enterprise Access Layer 2 Switching

IP Base:               Enterprise Access Layer 3 Switching

IP Services:        Advanced Layer 3 Switching

To be exact, we will focus on the Cisco Catalyst 2960, Catalyst 2960-S, Catalyst 3560-X and Catalyst 3750-X series switches.

LAN Lite License: Catalyst 2960 and 2960-S Series Switches

LAN Lite and LAN Base are the two common licenses for the Cisco 2960 and 2960-S series switches. As the name implies, LAN Lite is an entry level license for Enterprise Layer 2 access switches with a lot of convenient features like 802.1Q trunking, (M)STP, STP extensions, CDP, DTP, UDLD, VTPv2, PAGP/LACP, and LLDP. It also provides support for vital protection features including TACACS+, RADIUS, port protection, 802.1X and DHCP snooping. At this layer, this license does not supply layer 3 routing abilities. Nor does it have advanced protection and management abilities like Dynamic ARP Inspection and advanced Quality of Service (QoS) beyond some basic functionality, like priority queuing.

LAN Base License: Catalyst 2960, 2960-S, 3560-X, and 3750-X Switches

LAN Base is a potent license for Cisco’s Layer 2 access switches. Its wide array of access features encompasses all the LAN Lite features and adds more forceful features such as VTPv3 and FlexLinks. VTP version 3 provides improved managerial control of VLAN topology data and information sharing to minimize unintentional or disrupting changes. It also provides increased VLAN environment support comprising more ISL VLAN support range. FlexLinks increases Layer 2 resilience by the addition of a pair of quickly converging active and backup links amongst the access and distribution switches. LAN Base permits layer 3 routing by the addition of static routing support. A lot of robust protection features are included in LAN Base, as well. Some examples are Flexible Authentication, Radius Change of Authorization and advanced 802.1X functionality. On the management side, a lengthy list of functionalities is available with LAN Base like a broader range of MIBs, Ingress policing, Trust Boundary, AutoQoS, and DSCP mapping.

Conclusion

We are aware that there are a lot of technical particulars here. The bottom line is that in case you possess a basic layer 2 access corporate network with fundamentally no routing requirements and no advanced protection or administration needs, you may want to think about getting LAN Lite. For a majority of enterprise layer 2 networks, LAN Base is the minimum necessity. It allows you a strong layer 2 access network with outstanding network administration, protection and user experience.

Cisco IOS Software Licensing – Part 2

Now we will have a quick look at Layer 3, IP Base and IP Services licensing. We reiterate again that this post is not supposed to epitomize or substitute any official Cisco product documentation. Product specifications are subject to change very quickly and therefore using this post for reference is solely at our readers’ own risk.

For many of us who have deployed Cisco switches for a long time period, we may recall the Cisco Catalyst 5500 switches having a Route Switch Module (RSM). This used to be how Layer 2 and Layer 3 were combined inside a singular chassis – in a kludgy manner. Those days of yore are now long gone. The Cisco Catalyst switches these days possess powerful incorporated Layer 3 functionalities. Layer 3 switching and routing are so closely intertwined that they trigger a plethora of interesting conversations. Here, we will focus on the Layer 3 switching abilities of the Cisco Catalyst 3560-X and Catalyst 3750-X series switches.

IP Base License: Catalyst 3560-X and 3750-X Series Switches

Dynamic routing supplies you with corporate network scalability, flexibility and resilience. IP Base is a standard enterprise services license for the Cisco 3560-X and 3750-X series switches having dynamic routing support. It possesses all the Layer 2 features included in the LAN Base licensing, plus a remarkable collection of Layer 3 functionalities like static routing, RIP, EIGRP stub, Protocol Independent Multicast (PIM) stub and OSPF for Routed Access. Here EIGRP stub implies that the switch partakes in EIGRP routing as a stub and the EIGRP routes will not be extended to any downstream hardware devices connected to the switch. Also, please take note that OSPF for Routed Access is developed specially to extend Layer 3 routing functionalities to wiring closets. It provides support for only one OSPFv2 and one OSPFv3 occurrence, with a maximum allowed quantity of 200 dynamically learned paths. On the protection front, a large amount of network protection functionalities are provided by IP Base. Some examples are ACLs, Private VLANs, TrustSec SXP, and IEEE 802.1AE (also known as MACsec). A novel and stimulating protection feature is the device sensor.  It is a component of the Cisco IOS software installed on a switch which gathers specific endpoint device attributes and forwards such data to the Cisco Identify Services Engine (ISE) via RADIUS accounting packets. Cisco ISE then implements the suitable policies as a component of the Bring Your Own Device (BYOD) solution. In addition, some more new administration aptitudes have been supplemented to the IP Base image. A great example is Embedded Event Manager (EEM). This is a policy-based framework which permits you to tailor a script for real-time network event discovery and onboard automation. Also, Medianet support provides you the capability to troubleshoot and tailor business applications like video-based collaborations.

Need more guidance? Just contact us today. We are a 100% Cisco-Certified partner and can assist you with all of your Cisco support questions.