Brkarc 2885
Brkarc 2885
Brkarc 2885
BRKARC-2885
“Want to be
‘the Catalyst 8500 Expert’?”
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 2
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
Cisco Webex App
Questions?
Use Cisco Webex App to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install the Webex App or go directly to the Webex space Enter your personal notes here
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Expert
Solutions
Agenda
Troubleshooting
Platform Architecture
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 5
Catalyst 8500 Series
Edge Platforms
Cisco Catalyst 8000 Series Portfolio
Ready to refresh the Enterprise Networks for Branch, Aggregation and Cloud
Catalyst
8500 Series
ENCS 5100 Series ISR4321, ISR4300 ISR4400 ASR1000 Fixed ASR1000 Fixed
CSR1000v ISR4221 Series Series X-Series HX-Series
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
Catalyst 8500, 8500L Series Edge Platforms
10G, 1G 12 SFP+
‘X’
C8500-12X
10G, 1G 8 SFP,
‘X’ ‘S’ 4 SFP+
C8500L-8S4X
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 8
Catalyst 8500-20X6C Series Edge Platform
High Performance driven by 4x Packet Processing Engines
C8500-20X6C
100/40G 6 QSFP28
‘C’
10/1G 20 SFP+
‘X’
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 9
Cisco Catalyst 8500 Series Edge Platforms
Highly Capable SD-WAN Headend
C8500-20X6C
C8500-12X4QC
CEF: up to 500 Gbps
IPsec: up to 150 Gbps
Performance
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 10
Catalyst 8500
Platform Architecture
Cisco Third Generation QFP
Exceptional Data Path ASIC
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 13
Third Generation QFP Architecture QFP
PKT / xBAF
• Flow queues for complex stateful features
Ingress Classification, Egress Buffering, Scheduling
Accounting, Policing and and Flow Control, Time Stamp
Oversubscription Buffer and 1588*
Layer-2 Aggregation
L2 MACs w/MACsec / Interlaken & Mesh
• 240Gbps of aggregation
• Per Port Classification and Accounting
QFP 3.0
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 14
QFP 3.0 Traffic Manager QFP
PKT / xBAF
Flow Control, GEC
Ingress Classification, Egress Buffering, Scheduling
• Event Driven (Xon/Xoff) flow control Accounting, Policing and
Oversubscription Buffer
and Flow Control, Time Stamp
and 1588*
support on all egress queues
L2 MACs w/MACsec / Interlaken & Mesh
• Ether-channel support for bundled ports
supported for single and multi-QFP
complexes
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 15
QFP 3.0 In-line Crypto QFP
PKT / xBAF
Ingress Classification, Egress Buffering, Scheduling
Digest SHA1 SHA2- MD5 GCM Accounting, Policing and and Flow Control, Time Stamp
Oversubscription Buffer and 1588*
Cipher 256/384/512
AES L2 MACs w/MACsec / Interlaken & Mesh
DES/ N/A
3DES
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
QFP 3.0 Layer 2 Sub-system QFP
Layer 2 Aggregation
DDR4 Memory Controller
• 240Gpbs ethernet port aggregation
• Per port 12.5ms Ingress Oversubscription HW Assist:
DST
Buffers FLB
Traffic Manager Crypto PLU
Packet Processor RLB
Engines (PPEs) ARL
Classification, Accounting TCM
Pkt Buffer
• Supports per port, L2/L3, TCAM based Manager
GPM
PKT / xBAF
classification
Ingress Classification, Egress Buffering, Scheduling
• Supports Ingress sub-intf classification Accounting, Policing and and Flow Control, Time Stamp
Oversubscription Buffer and 1588*
• Supports Ingress and Egress per Port
High, Low priority accounting L2 MACs w/MACsec / Interlaken & Mesh
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
C8500-20X6C Block Diagram
sTCAM
SDRAM 80Mb x2 SDRAM SDRAM SDRAM
DDR4 sTCAM
80Mb x2
QFP ASIC 0
Crypto
QFP ASIC 1
Control Plane
Processor Crypto
QFP ASIC 2
8 Core
Crypto
QFP ASIC 3
Crypto
Interconnect
Chassis L2 complexes
Mgmt.
CPLD/FPGA
Reset Ctrl Bay 0 Bay 1
TE TE TE TE Hu Hu Hu
.. ..
0/0/0 0/0/2 0/0/16 0/0/18 0/1/0 0/1/2 0/1/4
TE TE TE TE Hu Hu Hu
SFP+ Ports .. .. QSFP28 Ports
C8500-20X6C 10/1G
0/0/1 0/0/3 0/0/17 0/0/19 0/1/1 0/1/3 0/1/5
100/40G
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
C8500-12X4QC Block Diagram
sTCAM
SDRAM SDRAM SDRAM 80Mb
DDR4
Control Plane
Packet Buffer Resource Memory sTCAM I/F
Processor
4 Core 3rd Generation QFP
Crypto
EP0 EP1
120Gbps 120Gbps
Chassis
Bay 2 Bay 1 Bay 0
Mgmt.
CPLD/FPGA
Reset Ctrl
Fo/Hu Fo Fo Fo/Hu Ten Ten Ten Ten Ten Ten
0/2/0 0/2/4 0/2/8 0/1/0 0/1/0 0/1/2 0/0/0 0/0/2 0/0/4 0/0/6
QSFP28 QSFP Port QSFP28 Ten Ten Ten Ten Ten Ten
Port 40G Port 0/1/1 0/1/3 0/0/1 0/0/3 0/0/5 0/0/7
100/40G 100/40G
SFP+ Ports SFP+ Ports
10/1 G 10/1G
C8500-12X4QC
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 19
C8500-12X Block Diagram
sTCAM
sTCAM
5Mbx2
SDRAM SDRAM SDRAM 5Mbx2
DDR4
Control Plane
Packet Buffer Resource Memory sTCAM I/F
Processor
4 Core 3rd Generation QFP
Crypto
EP0 EP1
120Gbps
Chassis
Bay 0
Mgmt.
CPLD/FPGA
Reset Ctrl
TE TE TE TE TE TE
0/0/0 0/0/2 0/0/4 0/0/6 0/0/8 0/0/10
TE TE TE TE TE TE
0/0/1 0/0/3 0/0/5 0/0/7 0/0/9 0/0/11
C8500-12X
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 20
Life of a Packet
sTCAM
SDRAM SDRAM SDRAM 80Mb
DDR4
Control Plane
Packet Buffer Resource Memory sTCAM I/F
Processor
4 Core 3rd Generation QFP
Crypto
EP0 EP1
120Gbps 120Gbps
IP CEF Traffic
Chassis
Crypto Traffic Bay 2 Bay 1 Bay 0
Mgmt.
CPLD/FPGA
Reset Ctrl
RP Control Traffic
QE/HE QE QE QE/HE TE TE TE TE TE TE
0/2/0 0/2/4 0/2/8 0/1/0 0/1/0 0/1/2 0/0/0 0/0/2 0/0/4 0/0/6
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
C8500-12X4QC Port Connectivity
Purpose-built 100GE, 40GE Port SD-WAN 1RU Platform
Max 120G of Max 120G of ports across
ports from Bay 2 Bay 0 + Bay 1
Note: 1/10GE port’s speed is detected based on SFP/SFP+ used in the port, *breakout cable support in autonomous mode only
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
100GE, 40GE Connectivity Options (i)
C8500-12X4QC
Port Enabled
Port Disabled
Option 1 2 x 100GE
100G 100G
Note: For port speed change on any bay; there is an expected 1 sec traffic disruption due to backplane reset
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
100GE, 40GE Connectivity Options (ii)
C8500-12x4QC
Port Enabled
Port Disabled
Option 3 1 x 100GE + 12 x 10GE
Note: For port speed change on any bay; there is an expected 1 sec traffic disruption due to backplane reset
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 24
100GE, 40GE Connectivity Options (iii)
C8500-12x4QC
Port Enabled
Port Disabled
Option 5 3 x 40GE + 12 x 10GE
Note: For port speed change on any bay; there is an expected 1 sec traffic disruption due to backplane reset
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 25
C8500-12X4QC, Bay Speed Configuration
Autonomous Mode
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
C8500-12X4QC, Bay Speed Configuration
Controller Mode
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
High Density 10GE, 1GE Connectivity Options
C8500-12X and C8500-12x4QC
Port Enabled
Port Disabled
Option 7, 8 C8500-12X: 12 x 1/10GE
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Support
C8500-12X4QC Breakout Cable from 17.4.1
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
C8500L - Performance enhancements using
advanced flow-based forwarding
Advanced flow-based
forwarding algorithm
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Advanced Flow-based Forwarding x86
Ingress
Flow
Quick Assist Technology
Match Yes Forward to
found in
‘DP core’
flowDB?
Protocol Tuple hashing elements
No
Calculate TCP/UDP srcIP, dstIP, protocol, srcPort, dstPort, vrfID
hash
ESP srcIP, dstIP, protocol, vrfID
Add entry in
flowDB All other
srcIP, dstIP, protocol, vrfID
Protocols
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 32
Data Plane vs Service Plane Heavy x86
i e
Data
Plane o d
Heavy
Control I/O & Data Crypto
Plane queuing Plane
i e
o d
Service
Plane
Heavy
Control Service I/O & Data Crypto
Plane Plane queuing Plane
CLI configuration and reboot required to change modes. Roadmap for future software to not require reboot.
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 33
C8500L Data Plane Heavy x86
Configure, Verify
C8500L(config)#platform resource data-plane-heavy
C8500L(config)# do show platform software cpu allocation
CPU alloc information:
C8500L(config)#
DP heavy is the default mode for IOS XE Routing ‘autonomous’ mode operation
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 34
C8500L Service Plane Heavy x86
Configure, Verify
C8500L(config)#platform resource service-plane-heavy
C8500L(config)# do show platform software cpu allocation
CPU alloc information:
C8500L(config)#
SP heavy is the default mode for Cisco SD-WAN ‘controller’ mode operation
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 35
C8500L-8S4X Block Diagram
Chassis
Bay 1 Bay 0
Mgmt.
CPLD/FPGA
Reset Ctrl
TE TE GE GE GE GE
0/1/0 0/1/2 0/0/0 0/0/2 0/0/4 0/0/6
TE TE GE GE GE GE
0/1/1 0/1/3 0/0/1 0/0/3 0/0/5 0/0/7
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
Secure Platform with Trustworthy Technologies TAm
TAm
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Catalyst 8500
Software Architecture
Open IOS XE — A Modern Operating System
Confd Telemetry
Native Container
I/O Forwarding Control and Management Apps Apps
VM
DPDK
IOS XE Database
Kernel
Kernel
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 47
Easy Operations with Single Image
IOS-XE
IOS-XE Single
SD-WAN
IMAGE Image IMAGE
universalk9 universalk9 ucmk9
IOS XE
IOS XE
SD-WAN
‘Autonomous’
‘Controller’
mode
mode
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 48
Catalyst 8500 Programmability
Intent Context
Cisco
Day n Day 1
IOS XE
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 49
Catalyst 8500 Product
Comparison
ASR1002-HX vs C8500-12X4QC
Product Comparison
Up to 18Gbps SD-WAN, 6000 tunnels Up to 29Gbps SD-WAN, 8000 tunnels
Ports: 8x 1G, 8x 10G, One EPA Slot Ports: 12x 1/10G, 2x 40/100G, 2x 40G
QFP 2.0, 124 Cores, extra Crypto HW QFP 3.0, 224 Cores, Inbuilt Crypto, L2
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 51
ASR1001-HX vs C8500-12X
Product Comparison
Up to 11Gbps SD-WAN, 6000 tunnels Up to 24Gbps SD-WAN, 8000 tunnels
QFP 2.0, 124 Cores, extra. Crypto HW QFP 3.0, 224 Cores, Inbuilt Crypto, L2
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 52
Catalyst 8500 TCAM Capacity
47,000 200,000
25,000
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 53
ASR1001-X vs C8500L-8S4X
Product Comparison
Up to 4.5 Gbps SD-WAN, 6000 tunnels Up to 10Gbps SD-WAN, 6000 tunnels
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 54
Solutions,
Use-Cases
C8500 for Cloud-scale SD-WAN
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 56
C8500 for Enterprise Networks
DCI
Remote
Users
WAN Aggregation
Internet
Gateway
Campus
WAN Internet
Cloud
IaaS
Edge
High End SaaS
Branch
DC/Private Cloud
IPsec Gateway
High Speed Customer Edge IPsec VPN, GETVPN Data Center Interconnect
High Scale NAT, Firewall DMVPN, FlexVPN High Speed Cloud Access
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 57
C8500 for Service Provider Networks
Remote Workforce Access and Aggregation MSP Edge
Cloud Convergence
MPLS Traffic Engineering IPsec Cloud SP Cloud
Wireless
Peering
Segment Routing NAT
IPsec, NAT, Firewall Firewall
Services VxLAN
AVC, NBAR2
ETTx
VPN RR
IP/MPLS RR
CPE xDSL
Core
P
xPON
DSLAM
Micro-Branch
PE
Content Farm
L2VPN
OLT L3VPN
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 58
Catalyst 8500: One Platform, Many Solutions
SD-WAN Internet Gateway Cloud GW, CoLo Secure WAN
High Speed DIA, DCA High Throughput Performance Multi-Tenant, VRF Aware Site-to-site, Remote
Access VPN
Multi-Region Fabric BR NAT44/NAT64/NAT66 High Scale NAT, AVC, Firewall
GETVPN, DMVPN, FlexVPN,
Multi-Tenant Edge/Gateway AVC, Firewall Inter VRF Services- VASI
IPsec over GRE, sVTI
SD-WAN Remote Access High Speed DIA, DCA Stateful B2B High Availability
High Scale NAT, AVC, Firewall
Multicast Replication Dynamic Application Policy MACsec, IPsec
WAN MACsec
Routing (DAPR)
Catalyst 8500 Inherits Cisco ASR 1000 features for IOS XE and IOS XE SD-WAN use-cases
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 59
Best Practices,
Troubleshooting
Platform Resource Summary
Reference
slide
C8500#
A system wide platform resource summary command- show
platform resources. It covers most of the critical resources.
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 61
Software Status- Control Processor
Reference
slide
Memory (kB)
Slot Status Total Used (Pct) Free (Pct) Committed (Pct)
RP0 Healthy 15939320 3081200 (19%) 12858120 (81%) 9046624 (57%)
CPU Utilization
Slot CPU User System Nice Idle IRQ SIRQ IOwait
RP0 0 0.60 0.40 0.00 99.00 0.00 0.00 0.00
Alerts
1 0.09 0.19 0.00 99.60 0.00 0.09 0.00 %PLATFORM-4-ELEMENT_WARNING
2 0.49 0.39 0.00 99.00 0.00 0.09 0.00 → Look out for committed memory
3 0.20 0.20 0.00 99.59 0.00 0.00 0.00
4 0.50 0.40 0.00 99.10 0.00 0.00 0.00 %OOM-0-NO_MEMORY_RESET:
5 0.10 0.20 0.00 99.69 0.00 0.00 0.00
6 0.20 0.20 0.00 99.59 0.00 0.00 0.00
→ System is completely out of memory
7 2.40 0.70 0.00 96.80 0.00 0.10 0.00
%OOM-3-NO_MEMORY_AVAIL:
→ System is low on available memory
C8500#
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 62
IOSd CPU Consumption
Reference
slide
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 63
IOSd Memory Consumption
Reference
slide
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 64
Linux level (top) CPU, Memory Usage
Reference
slide
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 65
Data Plane: TCAM Consumption
Reference
slide
TCAM is very important resource for classification configuration, should always be below critical limit.
%CPP_FM-3-CPP_FM_TCAM_WARNING → TCAM exhaustion warning syslog
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 66
Data Plane: QFP Memory Statistics
Reference
slide
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 67
Data Plane: BQS DRAM Utilization
Reference
slide
Utilization: 0 % Alerts
: 1 % cblk
%CPPBQS-4-QLIMITEXCEEDED
Threshold Values: → Max number of queues exceeded
Vital : 160.94 MB, Status: False
: 962.91 MB cblk %CPPBQS-6-QLIMITOK
Packet Priority : 159.44 MB, Status: False → Queues usage is withing platform limit
: 953.39 MB cblk
Priority : 152.94 MB, Status: False
: 914.81 MB cblk %CPP_BQS-3-CARVE
Non-Priority : 136.81 MB, Status: False → BQS proxy failed to initialize software
: 818.44 MB cblk memory region
C8500#
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 68
Data Plane: BQS Queue and Schedules
Reference
slide
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 69
Data Plane: QFP Utilization
Reference
slide
C8500#
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 70
Data Plane: Crypto Utilization
Reference
slide
C8500#
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 71
Data Plane: x86 Per Core Utilization
Reference
slide
ID Port Wght Global WRKR0 WRKR1 WRKR2 WRKR3 WRKR4 WRKR5 WRKR6 WRKR7 WRKR8
WRKR9 Total
1 rcl0 1: 6048 0 0 0 0 0 0 96 0 0 0 6144 10 fpe6 2: 1952 0 0 0 0 0 0 0 96 0 0 2048
11 fpe7 1: 1952 0 0 0 0 0 0 96 0 0 0 2048
1 rcl0 128: 6048 0 0 0 0 0 0 96 0 0 0 6144
2 ipc 1: 0 0 0 0 0 0 0 0 0 0 0 0 11 fpe7 2: 1952 0 0 0 0 0 0 96 0 0 0 2048
12 fpe8 1: 2012 0 0 0 0 0 0 0 36 0 0 2048
3 vxe_punti 1: 476 0 0 0 0 0 0 36 0 0 0 512
4 fpe0 1: 1952 0 0 0 0 0 0 96 0 0 0 2048 12 fpe8 2: 1952 0 0 0 0 0 0 0 96 0 0 2048
4 fpe0 2: 1952 0 0 0 0 0 0 96 0 0 0 2048 13 fpe9 1: 1952 0 0 0 0 0 0 96 0 0 0 2048
5 fpe1 1: 1952 0 0 0 0 0 0 96 0 0 0 2048 13 fpe9 2: 1952 0 0 0 0 0 0 96 0 0 0 2048 PP: Packet Processing
5 fpe1 2: 1952 0 0 0 0 0 0 96 0 0 0 2048 14 fpe10 1: 1952 0 0 0 0 0 0 0 96 0 0 2048 RX: Receive core
6 fpe2 1: 1952 0 0 0 0 0 0 0 96 0 0 2048 14 fpe10 2: 1952 0 0 0 0 0 0 0 96 0 0 2048 TM: Traffic Manager core
6 fpe2 2: 1952 0 0 0 0 0 0 0 96 0 0 2048 15 fpe11 1: 1979 0 0 0 0 0 0 69 0 0 0 2048 COFF: Crypto core
7 fpe3 1: 1953 0 0 0 0 0 0 95 0 0 0 2048 15 fpe11 2: 1952 0 0 0 0 0 0 96 0 0 0 2048
7 fpe3 2: 1952 0 0 0 0 0 0 96 0 0 0 2048
8 fpe4 1: 1952 0 0 0 0 0 0 0 96 0 0 2048 Core Utilization over preceding 604610.7457 seconds
8 fpe4 2: 1952 0 0 0 0 0 0 0 96 0 0 2048 ---------------------------------------------------
9 fpe5 1: 1952 0 0 0 0 0 0 96 0 0 0 2048 ID: 0 1 2 3 4 5 6 7 8 9
9 fpe5 2: 1952 0 0 0 0 0 0 96 0 0 0 2048 % PP: 36.58 69.20 74.43 39.66 72.78 76.07 0.00 0.00 0.00 0.00
10 fpe6 1: 1952 0 0 0 0 0 0 0 96 0 0 2048% RX: 0.00 0.00 0.00 0.00 0.00 0.00 28.43 4.86 0.00 0.00
% TM: 0.00 0.00 0.00 0.00 0.00 0.00 70.81 17.48 0.00 0.00
% COFF: 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.27 0.27
% IDLE: 63.42 30.80 25.57 60.34 27.22 23.93 0.76 77.65 99.73 99.73
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 72
Data Plane: QFP drops Reference
slide
C8500#
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 73
Data Plane: Software Object-Manager
Reference
slide
C8500#
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 74
Control Plane Policing- CoPP
Reference
slide
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 75
Control-Plane CoPP Policer (rate based)
Reference
slide
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 76
Per-interface, per-cause drops
Reference
slide
C8500#
The statistic above is the total of per-interface and per-cause
per-interface drops on the system.
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 77
Global per-cause Punt Policer
Reference
slide
Punt Config Rate(pps) Conform Packets Dropped Packets Config Burst(pkts) Config Alert
Cause Description Normal High Normal High Normal High Normal High Normal High
----------------------------------------------------------------------------------------------------------------------------- --------------------------------
2 IPv4 Options 4000 3000 0 0 0 0 4000 3000 Off Off
3 Layer2 control and legacy 40000 10000 0 0 0 0 40000 10000 Off Off
4 PPP Control 2000 1000 0 0 0 0 2000 1000 Off Off
5 CLNS IS-IS Control 40000 10000 0 0 0 0 40000 10000 Off Off
6 HDLC keepalives 2000 1000 0 0 0 0 2000 1000 Off Off
7 ARP request or response 2000 1000 0 0 0 0 2000 1000 Off Off
8 Reverse ARP request or repso 2000 1000 0 0 0 0 2000 1000 Off Off
9 Frame-relay LMI Control 2000 1000 0 0 0 0 2000 1000 Off Off
10 Incomplete adjacency 2000 1000 0 0 0 0 2000 1000 Off Off
11 For-us data 40000 5000 0 0 0 0 40000 5000 Off Off
12 Mcast Directly Connected Sou 2000 1000 0 0 0 0 2000 1000 Off Off
13 Mcast IPv4 Options data pack 2000 1000 0 0 0 0 2000 1000 Off Off
15 MPLS TTL expired 5120 2000 0 0 0 0 5120 2000 Off Off
16 MPLS Reserved label (ie: 0-1 5120 2000 0 0 0 0 5120 2000 Off Off
18 IPV6 Hop-by-hop Options 2000 1000 0 0 0 0 2000 1000 Off Off
19 Mcast Internal Copy 2000 1000 0 0 0 0 2000 1000 Off Off
23 Mcast IGMP Unroutable 2000 1000 0 0 0 0 2000 1000 Off Off
24 Glean adjacency 2000 5000 0 0 0 0 2000 5000 Off Off
<snip>
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 78
Global Punt Policer
Reference
slide
C8500# show platform hardware qfp active infrastructure punt statistics type global-drop
Global Drop Statistics
5
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 79
Sample CoPP Configuration
Reference
slide
policy-map CONTROL-PLANE-POLICY
ip access-list extended Catch-All-IP class Management
10 permit tcp any any police rate 100 pps burst 100 packets
20 permit udp any any conform-action transmit
30 permit icmp any any exceed-action drop
40 permit ip any any class Undesirable
ip access-list extended Management police rate 1 pps burst 1 packets
remark NOC traffic for trusted management conform-action drop
ip access-list extended Undesirable exceed-action drop
10 remark deny Undesirable traffic class ARP
10 permit icmp any any fragments police rate 1 pps burst 50 packets
conform-action transmit
class-map match-all Catch-All-IP exceed-action drop
match access-group name Catch-All-IP class Catch-All-IP
class-map match-all Management police rate 1 pps burst 100 packets
match access-group name Management conform-action transmit
class-map match-all ARP exceed-action drop
match protocol arp class class-default
class-map match-all Undesirable police rate 100 pps burst 100 packets
match access-group name Undesirable conform-action transmit
exceed-action transmit
control-plane
service-policy input CONTROL-PLANE-POLICY
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 80
Punt Path drops, statistics
Reference
slide
C8500# show platform hardware qfp active infrastructure punt statistics type queue-stats
Queue Statistics
C8500#show platform hardware qfp active infrastructure punt statistics type global-drop
C8500# Global Drop Statistics
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 81
Embedded Packet Capture
Reference
slide
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 82
IOS XE Data Path Reference
slide
IPv4 validation
show platform hardware qfp active interface if-name <name>
IPv4
Classify
MLP
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 83
Per Interface FIA
Reference
slide
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 84
Conditional FIA Tracing Steps
Reference
slide
C8500#
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 85
Conditional FIA Tracing
Reference
slide
C8500#
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 86
Key Takeaways
Cisco Catalyst 8500 Series Edge Platforms
Best Platforms for Cloud-scale Enterprise Networks
Accelerated
04 SD-WAN Services
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 90
Complete your Session Survey
• Please complete your session survey
after each session. Your feedback
is important.
• Complete a minimum of 4 session
surveys and the Overall Conference
survey (open from Thursday) to
receive your Cisco Live t-shirt.
• All surveys can be taken in the Cisco Events Mobile App or
by logging in to the Session Catalog and clicking the
"Attendee Dashboard” at
https://www.ciscolive.com/emea/learn/sessions/session-catalog.html
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 91
Continue
Agenda Your Education
BRKARC-2885 © 2023 Cisco and/or its affiliates. All rights reserved. Cisco Public 92
Thank you