PB503086
Last Updated: November, 2008
1. Cisco IOS Software Release 12.2(33)SXI Introduction
2. Release 12.2(33)SXI Packaging, Migration, Service Module Support, and Software Modularity Considerations
3. Release 12.2(33)SXI Highlights
4. Release 12.2SX Additional Information
1. Cisco IOS Software Release 12.2(33)SXI Introduction
2. Release 12.2(33)SXI IP Version 6 (IPV6) Repackaging
• IPbase image-IPv6 Host features like:
– IPv6 addressing
– ICMPv6 and redirect
– IPv6 Maximum Transmission Unit (MTU) path discovery
– IPv6 Neighbor discovery
– Syslog over IPv6
– Simple Network Management Protocol (SNMP) over IPv6
– Telnet over IPv6
– SSH over IPv6
• IPservices image-Same IPv6 features as supported in advipservicesk9 images in prior releases, including EIGRPv6, IPv6 multicast, IPv6 tunneling, DHCPv6 and 6VPE
Benefits
Product Management Contact
• Niraj Gopal (niraj@cisco.com)
• Amit Datar (datar@cisco.com)
2.1. Release 12.2(33)SXI Migration
• Supervisor-720 IOS Software images:
– Cisco Catalyst 6500 Supervisor 720 IOS IP Services
– Cisco Catalyst 6500 Supervisor 720 IOS IP Services (MODULAR)
– Cisco Catalyst 6500 Supervisor 720 IOS IP Services (SSH) LAN ONLY
– Cisco Catalyst 6500 Supervisor 720 IOS IP Services (SSH) LAN ONLY (MODULAR)
– Cisco Catalyst 6500 Supervisor 720 IOS IP Services (SSH)
– Cisco Catalyst 6500 Supervisor 720 IOS IP Services (SSH) (MODULAR)
– Cisco Catalyst 6500 Supervisor 720 IOS Advanced IP Services (SSH)
– Cisco Catalyst 6500 Supervisor 720 IOS Advanced IP Services (SSH) (MODULAR)
– Cisco Catalyst 6500 Supervisor 720 IOS Advanced Enterprise services (SSH)
– Cisco Catalyst 6500 Supervisor 720 IOS Advanced Enterprise services (SSH) (MODULAR)
Figure 1. Supervisor-720 Software Image Upgrade to 12.2(33)SXI

• Supervisor-32 IOS Software images:
– Cisco Catalyst 6500 Supervisor 32 IOS IP Base LAN ONLY
– Cisco Catalyst 6500 Supervisor 32 IOS IP Base LAN ONLY (MODULAR)
– Cisco Catalyst 6500 Supervisor 32 IOS IP Base (SSH) LAN ONLY
– Cisco Catalyst 6500 Supervisor 32 IOS IP Base (SSH) LAN ONLY (MODULAR)
– Cisco Catalyst 6500 Supervisor 32 IOS IP Services SSH
– Cisco Catalyst 6500 Supervisor 32 IOS IP Services SSH (MODULAR)
– Cisco Catalyst 6500 Supervisor 32 IOS Advanced IP Services (SSH)
– Cisco Catalyst 6500 Supervisor 32 IOS Advanced IP Services (SSH) (MODULAR)
– Cisco Catalyst 6500 Supervisor 32 IOS Advanced Enterprise Services (SSH)
– Cisco Catalyst 6500 Supervisor 32 IOS Advanced Enterprise Services (SSH) (MODULAR)
Figure 2. Supervisor-32 Software Image Upgrade to 12.2(33)SXI

• ME6524 Software Feature sets:
– Cisco ME 6524 IOS IP Base (SSH) LAN ONLY
– Cisco ME 6524 IOS IP Base (SSH) LAN ONLY (MODULAR)
– Cisco ME 6524 IOS IP Base LAN ONLY
– Cisco ME 6524 IOS IP Base LAN ONLY (MODULAR)
– Cisco ME 6524 IOS Advanced IP Services (SSH) LAN ONLY
– Cisco ME 6524 IOS Advanced IP Services (SSH) LAN ONLY (MODULAR)
Figure 3. Catalyst 6500 ME-6524 Software Image Upgrade to 12.2(33)SXI

2.2. Catalyst 6500 Series Switch Service Module Support in Release 12.2(33)SXH and Release 12.2(33)SXI
Table 1.
Table 2.
|
Service Module |
Description |
Migration Path |
Description |
|
WS-SVC-AGM-1-K9 |
Catalyst 6500 Cisco Anomaly Guard Module |
AGXT-5650-MMF-B-K9 For more information, please visit http://www.cisco.com/en/US/netsol/ns615/networking_solutions_sub_solution.html |
Cisco Guard XT 5650, 1000Base-SX MMF, Dual AC, RAID |
|
WS-SVC-ADM-1- K9 |
Catalyst 6500 Cisco Anomaly Detector Module |
ADXT-5600-MMF-B-K9 For more information, please visit http://www.cisco.com/en/US/netsol/ns615/networking_solutions_sub_solution.html |
Cisco Traffic Anomaly Detector XT 5600,1000Base MMF |
|
WS-SVC-CSG-1 |
Content Services Gateway |
||
|
WS-SVC-IPSEC-1 |
IPSec VPN Services Module for Cisco Catalyst 6500 and Cisco 7600 Series Routers |
SPA-IPSEC-2G and 7600-SSC-400 For more information, please visit: http://www.cisco.com/en/US/prod/collateral/modules/ps8768/ps4221/prod_end-of-life_notice0900aecd80349e2c_ps8768_Products_End-of-Life_Notice.html |
Cisco 7600/Catalyst 6500 IPSec VPN SPA with DES/3DES/AES; Cisco 7600/Catalyst 6500 Services SPA Carrier Card |
|
WS-SVC-WLAN-1-K9 |
Wireless LAN Services Module, CEF256 |
WS-SVC-WISM-1-K9 For more information, please visit http://cisco.com/en/US/products/hw/modules/ps2706/prod_eol_notice0900aecd80550b4c.html |
Cisco Wireless Services Module (WiSM) |
2.3. Release 12.2(33)SXH (and Later 12.2SX Releases) Software Modularity Deployment Considerations
• Complete hardware and software feature parity between Cisco IOS Software Modular and Cisco IOS Native images
• Cisco IOS Software Modularity as a feature set of Cisco IOS Native images
Table 3.
3. Release 12.2(33)SXI Feature Highlights
Table 4. Release 12.2(33)SXI Highlights
Hardware
Cisco® Dense Wavelength-Division Multiplexing (DWDM) X2 Pluggable Module
• The Cisco DWDM X2 supports 10GBASE Ethernet
• The hot-swappable input/output device plugs into an Ethernet X2 port of a Cisco switch or router to link the port with the network
• The Cisco DWDM X2 supports the Cisco Quality Identification (ID) feature, which enables a Cisco switch or router to identify whether or not the module is an X2 module certified and tested by Cisco
• The module supports 32 non-tunable ITU 100-GHz wavelengths compatible with the Cisco ONS DWDM channel plan
• The Cisco DWDM X2 supports digital optical monitoring capability
For Additional Information
• http://www.cisco.com/en/US/prod/collateral/modules/ps5455/ps6576/data_sheet_c78_489725.html
Cisco X2-10GB-ZR Module
For Additional Information
Catalyst 6500 Series Shared Port Adapter (SPA) and SPA Interface Processor (SIP) Support Enhancements
• Previously supported on SIP-200, new support on SIP-400:
– SPA-8XCHT1/E1
– SPA-2XT3/E3
– SPA-4XT3/E3
– SPA-2XCT3/DS0
– SPA-4XCT3/DS0
• The ATM SPAs were previously supported in Release 12.2(33)SXH, and is also available in Release 12.2(33)SXI:
– SPA-2XOC3-ATM
– SPA-4XOC3-ATM
– SPA-1XOC12-ATM
– SPA-1XOC48-ATM
• SIP-600 support is now available with support for the following SPAs:
– SPA-2XOC48POS/RPR
– SPX-4XOC48POS/RPR
– SPA-OC192POS-VSR
– SPA-OC192POS-LR
– SPA-OC192POS-XFP
– SPA-5X1GE
– SPA-10X1GE
– SPA-1XTENGE-XFP
– SPA-10X1GE-V2
– SPA-1X10GE-L-V2
Cisco Catalyst® 6500 Series VPN Services Port Adapter (VSPA)
Figure 4. Cisco VSPA

Benefits
• High performance: The Cisco VSPA can deliver up to 8 Gbps of Advanced Encryption Standard (AES) traffic at large packet sizes and 7 Gbps Internet mix (IMIX) traffic
• Modular design and scalability: Terminate up to 16,000 site-to-site or remote-access IPSec tunnels on each VSPA; Up to 10 VSPAs can be combined in a single chassis
• Enhanced Quality of Service (QoS): The VSPA is designed to handle pre-encryption QoS configured on IPsec tunnel interfaces and provides priority, bandwidth, and traffic shaping services
• Scalable IPv6 encryption: Support for multi-gigabit IPv6 networks based on Static Virtual Tunnel Interfaces (sVTIs)
• Support for industry-leading encryption technology: In addition to Data Encryption Standard (DES) and Triple Data Encryption Standard (3DES), the Cisco VSPA also supports AES 192 and 256, the latest standard in encryption technology demanded by most government agencies and the leading financial institutions in the most secure network environments
For Additional Information
• http://www.cisco.com/en/US/products/ps9893/index.html
Product Management Contact
Cisco Catalyst 6500 Series Services SPA Carrier-600 (WS-SSC-600)
Figure 5. Cisco Services SPA Carrier-600 with Two Cisco VPN Services Port Adapters

Benefits
• Modularity-Creates investment protection and offers flexibility for the Cisco Catalyst 6500 Series Switches
• Scalability-Up to 10 Cisco Services SPA Carrier-600 modules and 10 Cisco VSPAs in a Cisco Catalyst 6500 chassis
For Additional Information
• http://www.cisco.com/en/US/products/ps9893/index.html
Product Management Contact
MPLS
Layer 3 MPLS VPN Feature Enhancements
• MPLS VPN-VPN Routing/Forwarding Instance (VRF) Command-Line Interface (CLI) for IPv4 and IPv6 VPNs
• MPLS VPN-IPv6 VPN over MPLS (6VPE) Support over IP tunnels
Benefits
• MPLS VPN-VRF CLI for IPv4 and IPv6 VPNs: Provides a CLI improvement and integration for VRF IPv4 and IPv6 commands
• MPLS VPN 6VPE support over IP tunnels: This new option of the L3VPN solutions suite enables network providers to run IPv6 VPNs over classical IPv4 transport networks without the requirement to run MPLS and LDP/MPLS-TE within the core network
For Additional Information
• http://www.cisco.com/en/US/products/ps6604/products_ios_protocol_group_home.html
• http://www.cisco.com/en/US/products/ps6017/products_feature_guides_list.html
Product Management Contact
• Bertrand Duvivier (bduvivie@cisco.com)
Ethernet OAM Enhancements
IEEE 802.1ag Ethernet Connectivity Fault Management (CFM)
1. Continuity check messages-these are "heartbeat" messages issued periodically by maintenance endpoints. They allow maintenance endpoints to detect loss of service connectivity among themselves. They also allow maintenance endpoints to discover other maintenance endpoints within a domain, and allow maintenance intermediate points to discover maintenance endpoints.
2. Link trace messages-these are transmitted by a maintenance endpoint on the request of the administrator to track the path (hop-by-hop) to a destination maintenance endpoint. They allow the transmitting node to discover vital connectivity data about the path. Link trace is similar in concept to UDP Traceroute.
3. Loopback messages-these are transmitted by a maintenance endpoint on the request of the administrator to verify connectivity to a particular maintenance point. Loopback indicates whether the destination is reachable or not; it does not allow hop-by-hop discovery of the path. It is similar in concept to ICMP Echo (Ping).
Maintenance End Points (MEPs) on Switchports (Inward)
Maintenance Intermediate Points (MIPs)
CFM MIP/MEP over EtherChannel
CFM-Outward Facing MEPs on Routed Ports
• Continuity Check (CC) 3
• Traceroute
• Loopback
• Crosscheck
• SNMP Traps
Product Management Contact
• Eric Matkovich (ematkovi@cisco.com)
Link Layer OAM-IEEE 802.3ah Ethernet Operations, Administration, and Maintenance (OAM)
Figure 6. OAM Protocol Data Units

• OAM Discovery
Discovery is the first phase of Link Layer OAM. It identifies the devices at each end of the link along with their OAM capabilities.
• Link Monitoring
Link monitoring OAM serves for detecting and indicating link faults under a variety of conditions. Faults in link connectivity that are caused by slowly deteriorating quality are difficult to detect. Link OAM provides a mechanism for an OAM entity to convey these types of failure conditions to its peer via specific flags in the OAMPDUs. It provides statistics on the number of frame errors (or percent of frames that have errors) as well as the number of coding symbol errors.
• Remote Loopback
An OAM entity can put its remote peer into loopback mode using the loopback control OAMPDU. In loopback mode, every frame received is transmitted back on the same port (except for OAMPDUs needed to maintain the OAM session). This helps the administrator ensure the quality of links during installation or when troubleshooting, and can also be used to test SLA requirements such as delay, jitter, and throughput. This feature is asymmetric, the provider device can put the customer device into loopback mode, but not conversely.
• Remote Fault Indication (RFI)-Dying Gasp
The failure conditions that can be communicated are a loss of signal in one direction on the link, an unrecoverable error (such as a power failure), or some critical event. Currently, Cisco supports the Dying Gasp generation and can receive the Critical Event and Link Fault.
– Administratively Down
– Error Disabled
– Reload
Product Management Contact
• Eric Matkovich (ematkovi@cisco.com)
Ethernet Local Management Interface (E-LMI)
Figure 7. Ethernet Local Management Interface

• Notification to the Customer Edge (CE) device of the addition of an EVC
An example use case of this is if a new branch office is connected to headquarters. The CE device at headquarters will be notified via the U-PE of the EVC and the associated VLAN to be configured. Future releases of E-LMI will also support auto-configuration, which provides notable benefits in that the branch office CE device can be deployed at the convenience of the customer and it will begin operation as soon as the Service Provider turns up the service.
• Notification to the CE device of the deletion of an EVC
This is very similar to the previous examples, except the EVC is being removed.
• CE EVC State notification (active) or (inactive)
The primary benefit is that the CE device can take some corrective action, such as re-routing traffic to a different EVC or other WAN service, when informed that an EVC has become inactive.
• EVC and Remote User Network Interface (UNI) Status
Remote UNI status is a Cisco proprietary extension which is supported by the OAM Interworking component.
• Traffic Shutdown on CE based on EVC Status
Product Management Contact
• Eric Matkovich (ematkovi@cisco.com)
Cisco Performance Management and Monitoring Through IP SLAs for Ethernet
• A reduction in OPEX by employing:
– Point-to-Point and Multipoint support
– Auto-discovery of endpoints (Moves/Adds/Changes)
– No IP overlay required to manage native Ethernet service
• Hierarchical Performance Management
– Monitor Customer, Operator and Service Provider networks
– Monitoring is transparent to lower layers
• In-Band Performance Management using Ethernet Frames
• Policy threshold alerts via SNMP Traps
