此产品的文档集力求使用非歧视性语言。在本文档集中,非歧视性语言是指不隐含针对年龄、残障、性别、种族身份、族群身份、性取向、社会经济地位和交叉性的歧视的语言。由于产品软件的用户界面中使用的硬编码语言、基于 RFP 文档使用的语言或引用的第三方产品使用的语言,文档中可能无法确保完全使用非歧视性语言。 深入了解思科如何使用包容性语言。
思科采用人工翻译与机器翻译相结合的方式将此文档翻译成不同语言,希望全球的用户都能通过各自的语言得到支持性的内容。 请注意:即使是最好的机器翻译,其准确度也不及专业翻译人员的水平。 Cisco Systems, Inc. 对于翻译的准确性不承担任何责任,并建议您总是参考英文原始文档(已提供链接)。
本文档介绍在使用Cisco NX-OS的vPC中Cisco Nexus 9000交换机的升级过程。
建议掌握下列主题的相关知识:
本文档中的信息基于以下软件和硬件版本:
本文档中的信息都是基于特定实验室环境中的设备编写的。本文档中使用的所有设备最初均采用原始(默认)配置。如果您的网络处于活动状态,请确保您了解所有命令的潜在影响。
注意:Cisco Nexus 7000交换机的升级过程可基于本文档,但命令和输出可能有所不同。有关详情,请参阅特定于Cisco Nexus交换机的官方Cisco指南。
注意:从主交换机开始升级,或者从交换机不会产生任何功能差异。尽管如此,启动主交换机可确保两个设备都恢复其初始配置的主角色和辅助角色。尽管了解Nexus的一些功能在vPC中作为操作主角色非常重要。
步骤1.打开Cisco Nexus 9000和3000 ISSU支持表
注意:Cisco TAC建议您始终使用具有建议路径的中断(重新加载)升级选项。
注意:建议的路径可以显示多个跳跃。对于每一跳,必须重复步骤2至11,直到两台Cisco Nexus交换机都拥有目标NX-OS版本。
步骤2.根据您的Cisco Nexus交换机线路卡,下载推荐路径中所述的所有Cisco NX-OS文件。
N9K-1(config)# ping 192.168.9.9 vrf management
N9K-1(config)# copy sftp: bootflash:
Enter source filename: nxos64-cs.10.2.5.M.bin
Enter vrf (If no input, current vrf 'default' is considered): management
Enter hostname for the sftp server: 192.168.9.9
Enter username: admin
The authenticity of host ‘192.168.9.9 (192.168.9.9)' can't be established.
RSA key fingerprint is SHA256:ABCDEFGHIJK.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added ‘192.168.9.9' (RSA) to the list of known hosts.
Inbound-ReKey for 192.168.9.9
User Access Verification
Password: cisco
N9K-1(config)# dir | include nxos
1978203648 Mar 31 01:36:06 2023 nxos.9.3.11.bin
1943380992 Mar 17 09:54:16 2023 nxos64-cs.10.2.5.M.bin
Usage for bootflash://
20548902912 bytes used
96040308736 bytes free
116589211648 bytes total
N9K-1(config)# show file bootflash:nxos64-cs.10.2.5.M.bin md5sum
2f60a186cb9c2d55c90086302e51f655
步骤3.确定每个Cisco Nexus交换机在vPC中的操作角色。
N9K-1(config)# show vpc role
vPC Role status
-----------------------------------------
vPC role : primary
Dual Active Detection Status : 0
vPC system-mac : 00:23:04:ee:be:01
vPC system-priority : 32667
vPC local system-mac : 44:b6:be:11:17:67
vPC local role-priority : 32667
vPC local config role-priority : 32667
vPC peer system-mac : f8:a7:3a:4e:40:07
vPC peer role-priority : 32667
vPC peer config role-priority : 32667
N9K-2(config)# show vpc role
vPC Role status
-----------------------------------------
vPC role : secondary
Dual Active Detection Status : 0
vPC system-mac : 00:23:04:ee:be:01
vPC system-priority : 32667
vPC local system-mac : f8:a7:3a:4e:40:07
vPC local role-priority : 32667
vPC local config role-priority : 32667
vPC peer system-mac : 44:b6:be:11:17:67
vPC peer role-priority : 32667
vPC peer config role-priority : 32667
步骤4.在vPC中验证两个Cisco Nexus交换机上的Cisco NX-OS不兼容。
N9K-1(config)# show incompatibility-all nxos bootflash:nxos64-cs.10.2.5.M.bin
Checking incompatible configuration(s) for vdc 'N9K-1':
-------------------------------------------------------
No incompatible configurations
Checking dynamic incompatibilities:
-----------------------------------
No incompatible configurations
步骤5.检验vPC中两台Cisco Nexus交换机对Cisco NX-OS的影响。
N9K-1(config)# show install all impact nxos bootflash:nxos64-cs.10.2.5.M.bin
Installer will perform impact only check. Please wait.
Verifying image bootflash:/nxos64-cs.10.2.5.M.bin for boot variable "nxos".
[####################] 100% -- SUCCESS
Verifying image type.
[####################] 100% -- SUCCESS
Preparing "nxos" version info using image bootflash:/nxos64-cs.10.2.5.M.bin.
[####################] 100% -- SUCCESS
Preparing "bios" version info using image bootflash:/nxos64-cs.10.2.5.M.bin.
[####################] 100% -- SUCCESS
Performing module support checks.
[####################] 100% -- SUCCESS
Notifying services about system upgrade.
[####################] 100% -- SUCCESS
Compatibility check is done:
Module bootable Impact Install-type Reason
------ -------- -------------- ------------ ------
1 yes disruptive reset default upgrade is not hitless
Images will be upgraded according to following table:
Module Image Running-Version(pri:alt) New-Version Upg-Required
------ ---------- ---------------------------------------- --------------------
1 nxos 9.3(11) 10.2(5) yes
1 bios v05.47(04/28/2022):v05.43(11/22/2020) v05.47(04/28/2022) no
Additional info for this installation:
--------------------------------------
Service "vpc" in vdc 1: Vpc is enabled, Please make sure both Vpc peer switches have same boot mode using 'show boot mode' and proceed
第 6 步(可选): 从vPC中的两台Cisco Nexus交换机导出运行配置的备份。
N9K-1(config)# copy running-config sftp:running-config-backup
Enter vrf (If no input, current vrf 'default' is considered): default
Enter hostname for the sftp server: 192.168.9.9
Enter username: admin
The authenticity of host '192.168.9.9 (192.168.9.9)' can't be established.
RSA key fingerprint is SHA256:ABDCEFGHI.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '192.168.9.9' (RSA) to the list of known hosts.
Inbound-ReKey for 192.168.9.9:22
User Access Verification
Password:
Connected to 192.168.9.9.
步骤7.在具有vPC主要角色的Nexus交换机上安装NX-OS。
N9K-1(config)# install all nxos bootflash:nxos64-cs.10.2.5.M.bin
Installer will perform compatibility check first. Please wait.
Installer is forced disruptive
Verifying image bootflash:/nxos64-cs.10.2.5.M.bin for boot variable "nxos".
[####################] 100% -- SUCCESS
Verifying image type.
[####################] 100% -- SUCCESS
Preparing "nxos" version info using image bootflash:/nxos64-cs.10.2.5.M.bin.
[####################] 100% -- SUCCESS
Preparing "bios" version info using image bootflash:/nxos64-cs.10.2.5.M.bin.
[####################] 100% -- SUCCESS
Performing module support checks.
[####################] 100% -- SUCCESS
Notifying services about system upgrade.
[####################] 100% -- SUCCESS
Compatibility check is done:
Module bootable Impact Install-type Reason
------ -------- -------------- ------------ ------
1 yes disruptive reset default upgrade is not hitless
Images will be upgraded according to following table:
Module Image Running-Version(pri:alt) New-Version Upg-Required
------ ---------- -------------------------------------------------------------
1 nxos 9.3(11) 10.2(5) yes
1 bios v05.47(04/28/2022):v05.43(11/22/2020) v05.47(04/28/2022) no
Additional info for this installation:
--------------------------------------
Service "vpc" in vdc 1: Vpc is enabled, Please make sure both Vpc peer switches have same boot mode using 'show boot mode' and proceed
Switch will be reloaded for disruptive upgrade.
Do you want to continue with the installation (y/n)? [n] y
注意:您必须正确读取成功。之后,Cisco Nexus交换机将重新启动,安装过程可能需要几分钟。每个Cisco Nexus交换机上的情况可能有所不同。
步骤8.等待Cisco Nexus交换机上的状态变为活动状态。
N9K-1(config)# show module
Mod Ports Module-Type Model Status
--- ----- ------------------------------------- ------------------------------
1 54 24x10/25G/32G + 6x40/100G Ethernet/FC N9K-C93180YC-FX-24 active *
Mod Sw Hw Slot
--- ----------------------- ------ ----
1 9.3(11) 1.0 NA
Mod MAC-Address(es) Serial-Num
--- -------------------------------------- ----------
1 44-b6-aa-aa-aa-aa to 44-b6-be-bb-bb-bb ABCDEFGHIJK
Mod Online Diag Status
--- ------------------
1 Pass
* this terminal session
注意:请注意,vPC保活和/或对等链路可能不能处于UP状态。这是预期结果,因为vPC中的Cisco Nexus交换机具有不受支持的不同版本Cisco NX-OS。
步骤9.在vPC对等Cisco Nexus交换机上安装Cisco NX-OS。
N9K-2(config)# install all nxos bootflash:nxos64-cs.10.2.5.M.bin
Installer will perform compatibility check first. Please wait.
Installer is forced disruptive
Verifying image bootflash:/nxos64-cs.10.2.5.M.bin for boot variable "nxos".
[####################] 100% -- SUCCESS
Verifying image type.
[####################] 100% -- SUCCESS
Preparing "nxos" version info using image bootflash:/nxos64-cs.10.2.5.M.bin.
[####################] 100% -- SUCCESS
Preparing "bios" version info using image bootflash:/nxos64-cs.10.2.5.M.bin.
[####################] 100% -- SUCCESS
Performing module support checks.
[####################] 100% -- SUCCESS
Notifying services about system upgrade.
[####################] 100% -- SUCCESS
Compatibility check is done:
Module bootable Impact Install-type Reason
------ -------- -------------- ------------ ------
1 yes disruptive reset default upgrade is not hitless
Images will be upgraded according to following table:
Module Image Running-Version(pri:alt) New-Version Upg-Required
------ ---------- -------------------------------------------------------------
1 nxos 9.3(11) 10.2(5) yes
1 bios v05.47(04/28/2022):v05.42(06/14/2020) v05.47(04/28/2022) no
Additional info for this installation:
--------------------------------------
Service "vpc" in vdc 1: Vpc is enabled, Please make sure both Vpc peer switches have same boot mode using 'show boot mode' and proceed
Switch will be reloaded for disruptive upgrade.
Do you want to continue with the installation (y/n)? [n] y
步骤10.等待Cisco Nexus交换机上的状态变为活动状态。
N9K-2(config)# show module
Mod Ports Module-Type Model Status
--- ----- ------------------------------------- --------------------- ---------
1 54 24x10/25G/32G + 6x40/100G Ethernet/FC N9K-C93180YC-FX-24 active *
Mod Sw Hw Slot
--- ----------------------- ------ ----
1 9.3(11) 1.0 NA
Mod MAC-Address(es) Serial-Num
--- -------------------------------------- ----------
1 f8-a7-3a-nn-nn-nn to f8-a7-3a-n1-n1-n1 98765432109
Mod Online Diag Status
--- ------------------
1 Pass
* this terminal session
步骤11.检验keep-alive、peer-link和vPC端口通道是否处于UP状态。
N9K-1(config)# show vpc
Legend:
(*) - local vPC is down, forwarding via vPC peer-link
vPC domain id : 1
Peer status : peer adjacency formed ok
vPC keep-alive status : peer is alive
Configuration consistency status : success
Per-vlan consistency status : success
Type-2 consistency status : success
vPC role : primary
Number of vPCs configured : 2
Peer Gateway : Enabled
Dual-active excluded VLANs : -
Graceful Consistency Check : Enabled
Auto-recovery status : Disabled
Delay-restore status : Timer is off.(timeout = 30s)
Delay-restore SVI status : Timer is off.(timeout = 10s)
Operational Layer3 Peer-router : Enabled
Virtual-peerlink mode : Disabled
vPC Peer-link status
-----------------------------------------------------------------
id Port Status Active vlans
-- ---- ------ -------------------------------------------------
1 Po1 up 1
vPC status
-----------------------------------------------------------------
Id Port Status Consistency Reason Active vlans
-- ------------ ------ ----------- ------ ---------------
50 Po50 up success success 1
60 Po60 up success success 1
N9K-2(config)# show vpc
Legend:
(*) - local vPC is down, forwarding via vPC peer-link
vPC domain id : 1
Peer status : peer adjacency formed ok
vPC keep-alive status : peer is alive
Configuration consistency status : success
Per-vlan consistency status : success
Type-2 consistency status : success
vPC role : secondary
Number of vPCs configured : 2
Peer Gateway : Enabled
Dual-active excluded VLANs : -
Graceful Consistency Check : Enabled
Auto-recovery status : Disabled
Delay-restore status : Timer is off.(timeout = 30s)
Delay-restore SVI status : Timer is off.(timeout = 10s)
Operational Layer3 Peer-router : Enabled
Virtual-peerlink mode : Disabled
vPC Peer-link status
---------------------------------------------------------------------
id Port Status Active vlans
-- ---- ------ -------------------------------------------------
1 Po1 up 1
vPC status
----------------------------------------------------------------------------
Id Port Status Consistency Reason Active vlans
-- ------------ ------ ----------- ------ ---------------
50 Po50 up success success 1
60 Po60 up success success 1
版本 | 发布日期 | 备注 |
---|---|---|
1.0 |
05-Oct-2023 |
初始版本 |