background image

 

11

Release Notes for the Cisco IE 2000 Switches, Cisco IOS Release 15.2(1)EY

NEW DOC # PENDING

Limitations and Restrictions

Security Group Tag Exchange Protocol for Cisco TrustSec 

Cisco Industrial Ethernet switches now can participate in the Cisco TrustSec security architecture by 
using the SGT Exchange Protocol (SXP). Cisco TrustSec establishes domains of trusted network 
devices. After a device is authenticated, communication is secured by using encryption and other 
mechanisms. As packets enter the network, they are classified by security group tags (SGTs) for the 
purpose of applying security policies. SXP is used to propagate the SGTs across network devices, such 
as the IE switches, that do not have hardware support for Cisco TrustSec. 

To use this feature, enable SXP and configure the connections on each device that needs to participate 
in SXP exchanges.

Enable SXP by entering the 

cts sxp enable

 command in global configuration mode. 

Configure each SXP connection by specifying the peer’s IP address, the password, and the role. For 
role, you can specify which device is the “speaker” and the “listener” in the exchange. 

For detailed information about the configuration commands and show commands, see “SGT Exchange 
Protocol over TCP (SXP)” at 

http://www.cisco.com/en/US/partner/docs/switches/lan/trustsec/

configuration/guide/sxp_config.html#wp1056896

Limitations and Restrictions

You should review this section before you begin working with the switch. These are known limitations 
that will not be fixed, and there is not always a workaround. Some features might not work as 
documented, and some features could be affected by recent changes to the switch hardware or software.

Cisco IOS Limitations

Ethernet

IP

QoS

RADIUS

SPAN and RSPAN

Spanning Tree Protocol

Trunking

VLAN

Ethernet

Traffic on EtherChannel ports is not perfectly load-balanced. Egress traffic on EtherChannel ports 
are distributed to member ports on load balance configuration and traffic characteristics like MAC 
or IP address. More than one traffic stream may map to same member ports based on hashing results 
calculated by the ASIC.

If this happens, uneven traffic distribution will happen on EtherChannel ports. 

Changing the load balance distribution method or changing the number of ports in the EtherChannel 
can resolve this problem. Use any of these workarounds to improve EtherChannel load balancing:

Summary of Contents for IE 2000

Page 1: ...include important information about Cisco IOS Release15 2 1 EY and any limitations restrictions and caveats that apply to it Verify that these release notes are correct for your switch If you are installing a new switch see the Cisco IOS release label on your switch rear panel If your switch is on use the show version privileged EXEC command See the Finding the Software Version and Feature Set sec...

Page 2: ...d in This Release page 16 Documentation Updates page 17 Related Documentation page 17 Obtaining Documentation Obtaining Support and Security Guidelines page 18 Cisco IOS Release Strategy The release strategy for Cisco IE 2000 series switches is represented in Figure 1 Figure 1 Software Release Strategy for Cisco IE 2000 Series Switches ...

Page 3: ...Cisco IOS Release 15 0 2 EA1 Cisco IE 2000 4TS B 4 10 100BASE T Ethernet ports 2 100 Mb s SFP module uplink slots Cisco IOS Release 15 0 2 EA1 Cisco IE 2000 4TS G L 4 10 100BASE T downlink ports 2 100 1000 Mb s SFP module uplink slots Cisco IOS Release 15 0 2 EA1 Cisco IE 2000 4TS G B 4 10 100BASE T downlink ports 2 100 1000 Mb s SFP module uplink slots Cisco IOS Release 15 0 2 EA1 Cisco IE 2000 8...

Page 4: ...dule uplink slots Cisco IOS Release 15 0 2 EA1 Cisco IE 2000 16TC G N 16 10 100BASE T downlink ports 2 Gigabit Ethernet dual purpose uplink ports and 2 100Mb s SFP module downlink slots Supports IEEE 1588 standard for synchronizing clocks and Network Address Translation NAT Cisco IOS Release 15 0 2 EA1 Cisco IE 2000 16TC G X1 16 10 100BASE T downlink ports 2 Gigabit Ethernet uplink ports 2 100 Mb ...

Page 5: ...2 1 EY Cisco IE 2000 16T67 B 16 port 10 100BASE T M12 connectors Layer 2 switch all FE ports Cisco IOS Release 15 2 1 EY Cisco IE 2000 24T67 B 16 port 10 100BASE T M12 connectors Layer 2 switch all FE ports Cisco IOS Release 15 2 1 EY Cisco IE 2000 8T67P G E 8 port 10 100BASE T 8 port POE 4 port POE 2 port 10 100 1000 uplink Precision Time Protocol PTP support Cisco IOS Release 15 2 1 EY Cisco IE ...

Page 6: ...Modules Switch Model Description Rugged and industrial SFP modules1 GLC FE 100LX RGD GLC FE 100FX RGD GLC SX MM RGD2 GLC LX SM RGD2 GLC ZX SM RGD2 Commercial SFP modules GLC SX MM GLC LH SM GLC BX U2 GLC BX D2 CWDM SFP2 DWDM SFP2 GLC T Extended temperature SFP modules SFP GE S2 SFP GE L2 SFP GE Z2 GLC EX SMD GLC LX SMD GLC FE 100FX GLC FE 100LX GLC FE 100EX GLC FE 100ZX GLC FE 100BX U GLC FE 100BX...

Page 7: ...e new software releases However to upgrade from LAN Base to Enhanced LAN Base for NAT you require both software and license upgrades See Software Activation Licensing Upgrade for detailed steps http www cisco com en US docs switches lan cisco_ie2000 software release 15_0_2_eb upgrade guide ie2000_ug html Upgrading the Switch Software Finding the Software Version and Feature Set page 7 Deciding Whi...

Page 8: ...n software image file on the flash memory to the appropriate TFTP directory on a host by using the copy flash tftp privileged EXEC command Note Although you can copy any file on the flash memory to the TFTP server it is time consuming to copy all of the HTML files in the tar file We recommend that you download the tar file from Cisco com and archive it on an internal host in your network You can a...

Page 9: ...server to the switch If you are installing the same version of software that is currently on the switch overwrite the current image by entering this privileged EXEC command Switch archive download sw overwrite reload tftp location directory image name tar The overwrite option overwrites the software image in flash memory with the downloaded one The reload option reloads the system after downloadin...

Page 10: ...le only with DOM capable transceiver modules When using an SFP module in a dual purpose port DOM is supported if the interface media type is configured to SFP or if global transceiver monitoring is enabled Transceiver monitoring is enabled by default Precision Time Protocol PTP Several enhancements were made to improve the implementation of Precision time Protocol PTP End to End Transparent Clock ...

Page 11: ...ker and the listener in the exchange For detailed information about the configuration commands and show commands see SGT Exchange Protocol over TCP SXP at http www cisco com en US partner docs switches lan trustsec configuration guide sxp_config html wp1056896 Limitations and Restrictions You should review this section before you begin working with the switch These are known limitations that will ...

Page 12: ...to choose compatible buffer sizes and threshold levels CSCea76893 When auto QoS is enabled on the switch priority queuing is not enabled Instead the switch uses shaped round robin SRR as the queuing mechanism The auto QoS feature is designed on each platform based on the feature set and hardware limitations and the queuing mechanism supported on each platform might be different There is no workaro...

Page 13: ... the trunk port is forwarding in VLAN Y even though the port has no group membership in VLAN Y There is no workaround CSCdz42909 For trunk ports or access ports configured with IEEE 802 1Q tagging inconsistent statistics might appear in the show interfaces counters privileged EXEC command output Valid IEEE 802 1Q frames of 64 to 66 bytes are correctly forwarded even though the port LED blinks ambe...

Page 14: ... Table 1 of the guide Note To meet 10V m or 20V m Radiated Immunity levels shielded cables must be used on the uplink ports G1 1 and G1 2 This note applies to these SKUs IE 2000 4T G L IE 2000 4T G B IE 2000 8TC G L IE 2000 8TC G B Express Setup Notes This browser setting is recommended for speeding up the time required to display Express Setup from Microsoft Internet Explorer 1 Choose Tools Inter...

Page 15: ... do not have copper ports for PC a GLC T copper SFP is required to perform express setup Command Purpose Step 1 configure terminal Enters global configuration mode Step 2 ip http authentication aaa enable local Configures the HTTP server interface for the type of authentication that you want to use aaa Enables the authentication authorization and accounting feature You must enter the aaa new model...

Page 16: ...tts Work Around There is no operational impact and there is no workaround CSCtx35101 The password must be entered twice before it is accepted in Express Setup Work Around There is no workaround CSCum76147 No warning for Port Security Settings changes displayed via Device Mgr Work Around There is no workaround CSCum67722 Maximum mac address range should vary according to the SDM template settings o...

Page 17: ...h Express Setup online help Device Manager online help SFP Information Compatibility Information www cisco com en US products hw modules ps5455 products_device_support_tables_list html Installation Notes www cisco com en US products hw modules ps5455 prod_installation_guides_list html MIBs MIBs for this product are listed in the datasheet www cisco com en US prod collateral switches ps9876 ps12451...

Page 18: ...w html Subscribe to the What s New in Cisco Product Documentation as a Really Simple Syndication RSS feed and set content to be delivered directly to your desktop using a reader application The RSS feeds are a free service and Cisco currently supports RSS version 2 0 This document is to be used in conjunction with the documents listed in the Related Documentation section Cisco and the Cisco logo a...

Reviews: