Professional Documents
Culture Documents
Cisco Catalyst 9000 Series Technical Overview: Product Marketing March 2020
Cisco Catalyst 9000 Series Technical Overview: Product Marketing March 2020
Technical Overview
Product Marketing
March 2020
• Catalyst 9000 Family
• Catalyst 9600 Series
• Catalyst 9500 Series
• Catalyst 9400 Series
• Catalyst 9300 Series
Catalyst
9600 Series
Catalyst
Catalyst 9500 Series
9400 Series Catalyst
Catalyst 9000
9300 Series
Catalyst
9200 Series
Switching
Platform
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 Series – Common Building Blocks
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Multi-Core CPU (x86) – Built for App Hosting
IOT & Enterprise
IOS
Control
Plane
Custom
App
x86
IOS XE
IOS XE Kernel
Kernel
CPU
x86 CPU enables hosting NFV devices, Containers and 3rd-party Apps
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational * Cisco Catalyst 9200 Series uses an embedded ARMv8 CPU
** Catalyst 9200 has an Embedded CPU (not x86 based)
Cisco IOS XE – A Modern Operating System
Cisco IOS
Cisco XEXE
IOS 16 &17.x
Management Interfaces
Cisco
Module Drivers
IOS XE
DB
IOX / Docker containers
Kernel Cisco and 3rd-party App hosting
Protected Memory
Adaptable Tables
Universal Deployment
Multi-Core Resources
Enhanced Scale and Buffering
Up to 20B Transistors
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
UADP 2.0 – Next Gen ASIC for Access Switching
Used in Catalyst 9300, 9400 and 9500 Series
Investment protection
Flexible pipeline
UADP 2.0 & 2.0 XL
Universal deployments
Adaptable tables
1 2 3
7.46
billion transistors
CPU
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
UADP 2.0+ Architecture
ASIC Block Diagram
Stack or ASIC Interface
SQS AQM
PBC – Packet Buffers Complex
Q
Q Q
IQS EQS
Rewrite engine
Double-Width 3X FIB
memory tables table scale
16nm technology
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
UADP 3.0 - Architecture
ASIC Block Diagram
BACKPLANE 800 Gbps
SQS AQM
Unified PBC (shared buffer)
Q Q Q
IQS EQS
Flexible
Ingress Forwarding lookup Egress Forwarding
Controller tables Controller
(IFC) (EFC)
(shared
across
Core 1 cores*) Core 1
Rewrite engine
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
UADP 2.0 Mini
Architectural simplicity with powerful innovations
Investment protection
Flexible pipeline
6-MB
100G 1G, 2.5G, 5G, 10G, 40G
packet buffer
bandwidth Supports different speeds
160G, 80G Up to 2x to 4x
stacking capacity forwarding + TCAM
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000
Quick Comparison
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 – Quick Comparison
Flexible Netflow * 16K per ASIC 16K per ASIC 64K per ASIC 64K per ASIC 128K per ASIC 128K per ASIC
Perpetual & Fast POE Yes Yes Yes Yes Yes Yes
MACsec Encryption 128-bit AES 128-bit AES 256-bit AES 256-bit AES 256-bit AES 256-bit AES
Software Defined Access Edge Edge Edge, Border, CP Edge, Border, CP Edge, Border, CP Edge, Border, CP
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 – Core Comparison
Flexible Netflow * 128K per ASIC 98K per ASIC 64K per ASIC
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
Foundation of the Cloud-Scale Campus
Industry-leading Purpose-built
High L2 scale (ACLs)
programmable ASIC
Powered by
UADP 3.0
for Resiliency with
and Open
IOS-XE Scalability
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
Quick Overview
2 Supervisor slots
Built-in RFID (dedicated)
Dimensions
4 Modular N+1 Power 8RU
Supplies 13.95 x 17.4 x 16.1
(H x W x D in inches)
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
Supervisor 1
CPU
Mgmt ports:
16G DDR4 memory
copper and fiber
2x USB3
Blue Beacon
1x mini-B USB console
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
Line cards
C9600-LC-48S- 1G (fiber)
• 48 ports
• SFP
• Supports 1G IOS-XE 17.2.1
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
C9600-LC-24C - 100G/40G Line-Card
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
C9600-LC-48YL - 25G/10G/1G Line-Card
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series IOS-XE 17.1.1
C9600-LC-48TX - mGig Line Card
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series IOS-XE 17.2.1
1G Line card - C9600-LC-48S
*Roadmap
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
Centralized Modular Architecture
• Centralized Architecture
Supervisor
UADP X86 CPU • Hitless Switchover & Upgrades
Data Plane Open Control Plane • Lower Latency (fewer ASIC)
Features Cisco Containers
Micro Engines IOS-XE SSO/NSF/ISSU • Forwarding, Queuing & Security
on the Supervisor (UADP)
• Unlock new performance &
features with new Supervisor
Passive Backplane (Up to 6.4T BW per slot) • X86 CPU + Storage
• Native Docker App Hosting
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
Supervisor 1 – Block Diagram
Switch backplane
1.6 Tbps
USB console/
2x USB3 Console/Mgmt SFP+
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
C9600-LC-24C – Block Diagram
Switch backplane
OBFL
(1 Gb)
2x QSFP28 2x QSFP28 2x QSFP28
1-2 3-4 23-24
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
C9600-LC-48YL – Block Diagram
Switch backplane
OBFL
(1 Gb)
4x SFP28 4x SFP28 4x SFP28
1-4 5-8 45-48
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series IOS-XE 17.1.1
C9600-LC-48TX – Block Diagram
Switch backplane
OBFL
(1 Gb)
4x Copper 4x Copper 4x Copper
1-4 5-8 45-48
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
1G line card block diagram IOS-XE 17.2.1
Switch backplane
OBFL
(1 Gb)
4x SFP 4x SFP 4x SFP
1-4 5-8 45-48
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 & 9500H Series
Switch Database Management (SDM) Templates
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 & 9500H Series
SDM Templates, Scale & Customization
IOSXE 17.1.1
Feature Distribution Core (default) SDA NAT
Routes (IPv4/IPv6) 114K/114K 212K/212K 212K/212K 212K/212K
Multicast routes (IPv4/IPv6) 16K/16K 32K/32K 32K/32K 32K/32K
MAC address table 82K 32K 32K 32K
IGMP/MLD snooping 2K 2K 2K 2K
Flexible NetFlow (Ingress) 49K/ASIC 32K/ASIC 32K/ASIC 32K/ASIC
Flexible NetFlow (Egress) 49K/ASIC 32K/ASIC 32K/ASIC 32K/ASIC
SGT label 32K 32K 32K 32K
Ingress 12K 8K 12K
Security ACL
Egress 15K 19K 8K
Ingress 8K 8K 4K
QOS ACL
Egress 8K 8K 4K
Ingress 1K 1K 1K
NetFlow ACL
Egress 1K 1K 1K
Ingress 0.5K 0.5K 0.5K
SPAN
Egress 0.5K 0.5K 0.5K
PBR/NAT 3K 2K 15.5K
CPP 1K 1K 1K
Tunnel termination and MACsec 3K 3K 2K
LISP 1K 2K 1K
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
Power supplies
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9600 Series
Power Supply redundancy
• Equal load sharing • Equal load sharing among remaining • Equal load sharing
Operation
and all active power supplies
• Combined mode: Use all available • Combined mode: Line card can shut • Combined mode: Line card can shut
power supplies for system budgeting down if there isn’t down if there isn’t
Power enough power enough power
• N+1 mode: Use N power supplies
budgeting for system budgeting • N+1 mode: Always enough power • N+1 mode: Always enough power
with single power supply outage with single power supply outage
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst
9500 Series
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 Series
Purpose-Built Medium & High-End Fixed Core
Catalyst 9500
UADP 2.0 UADP 3.0 Premium Fixed Core
SD-Access
C9500-24Y4C
C9500-16X MACsec-256 on all ports
C9500-40X C9500-48Y4C
Customizable Templates
C9500-24Q C9500-32QC
Extending Fixed Core beyond
C9500-12Q C9500-32C Catalyst 6800-X and 4500-X
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 Series
New generation of purpose-built fixed midrange core/aggregation switches
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 Series
High-level overview
2.4-GHz quad-core x86 CPU
Built-in RFID UADP 2.0 XL ASIC Every port 40G,10G,* Cisco StackWise
USB 2.0 flash drive 16 GB of DDR4 DRAM
(passive) 240G bandwidth and 1G* capable Virtual
32 MB per ASIC packet buffer
C9500-24Q
24x 40G
C9500-12Q
12x 40G
C9500-40X
40x 1/10G
C9500-16X
16x 1/10G
C9500-NM-2Q C9500-NM-8X
Cisco Catalyst 9500 Series Cisco Catalyst 9500 Series
network module 2-port 40G network module 8-port
with QSFP+ 1G/10G with
SFP and SFP+
Support for Online Insertion and Removal (OIR)
Uplink modules supported on C9500-40X and C9500-16X
Uplink modules supported on C9500-40X and C9500-16X
Support for Online Insertion and Removal (OIR)
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 Series
Redundant power supplies and fans
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 Series
New generation of purpose-built fixed high-end core/aggregation switches
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 25G/100G
High-level overview
2.4-GHz quad-core x86 CPU Next-generation
Built-in RFID 16 GB of DDR4 DRAM Every port 100G, 40G, 10G,* Cisco StackWise
USB 3.0 flash drive UADP 3.0 ASIC
(passive) 16 GB flash and 1G* capable Virtual
1.6-Tb bandwidth
36 MB per ASIC unified packet buffer
C9500 – 32C
32x 40G/100G
C9500-32QC
16x 100G or
32x 40G
C9500-24Y4C
24x 1G/10G/25G +
4x 40G/100G
C9500-48Y4C
48x 1G/10G/25G +
4x 40G/100G
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 - C9500-32QC,24Y4C,48Y4C
Redundant power supplies and fans
Redundant 1+1
Redundant 1+1 240-, 480-, or 960-GB
650W AC and 930W DC
fan tray SATA SSD storage
power supplies
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 Series
Power supply redundancy
Redundant mode (default) Redundant mode (failure) AC – DC power supplies
• Load sharing and redundancy are • In case of power supply or power feed failure, • Mix of AC and DC power
enabled automatically active power supply operates at 100% capacity supplies supported
• Each power supply provides ~50%
of capacity
• This is the recommended and only mode
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9500 Series
9500-32C Block diagram
X86 2.4-GHz
400 Gbps 400 Gbps 400 Gbps 400 Gbps quad-core CPU
FPGA
ASIC 0 Packet buffer (36 MB) ASIC 1 Packet buffer (36 MB)
DRAM – 16 GB
Flash
Forwarding controller Forwarding controller Forwarding controller Forwarding controller 16 GB
Reassembly Rewrite Reassembly Rewrite Reassembly Rewrite Reassembly Rewrite USB 2.0
crypto crypto crypto crypto
Ingress Egress Ingress Egress Ingress Egress Ingress Egress USB 3.0
FIFO FIFO FIFO FIFO FIFO FIFO FIFO FIFO
Core 1 Core 0 Core 1 Core 0 Mgmt Console
PHY PHY PHY PHY PHY PHY PHY PHY PHY PHY PHY PHY PHY PHY PHY PHY
0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15
SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI SFI
0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7 0-3 4-7
QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28 QSFP28
Cage 1 Cage 2 Cage 3 Cage 4 Cage 5 Cage 6 Cage 7 Cage 8 Cage 9 Cage 10 Cage 11 Cage 12 Cage 13 Cage 14 Cage 15 Cage 16
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9500 Series
9500-48Y4C Block diagram
X86 2.4-GHz
Packet buffer (36 MB)
quad-core CPU
SFI 0-7 SFI 0-3 SFI 4-7 SFI 0-7 SFI 0-7 SFI 0-3 SFI 4-7 SFI 0-7 SFI 0-7 SFI 0-7
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 Series
Switch Database Management (SDM) template
Cisco Catalyst
9500 Series
* Cisco Catalyst 9500 High Performance switch security ACL TCAM only
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9500 Series Comparison
Catalyst 9500 Catalyst 9500
Capabilities (per ASIC)
Series (UADP 2.0) 100G/25G (UADP 3.0)
Switching and forwarding capacity 240 Gbps (360 Mpps) 1.6 Tbps (1 Bpps)
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst
9400 Series
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series
480G BW
Redundancy per slot
is now
table stakes
IEEE 802.3BT
90W PoE
compliant
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series
Chassis Options
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series – Sup-1
Overview
USB 2.0/3.0
Uplinks:
MACsec-256 8x 10G, 2x 40G
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series – Sup-1XL
Overview
USB 2.0/3.0
2.4-GHz quad-core x86 CPU
MACsec-256 Uplinks:
8x 10G, 2x 40G
Optimized for core deployment
MACsec is not supported on 1G speed on uplinks
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series – Sup-1XL-Y
Overview
USB 2.0/3.0
2.4-GHz quad-core x86 CPU
MACsec-256 Uplinks:
2x 25G, 8x 10G, 2x 40G
Optimized for core deployment
*MACsec is not supported on 25G ports of Sup-1XL-Y
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series
Copper Line Cards
RJ-45 (data)
48x 10/100/1000
Cisco TrustSec® and MACsec (256)
48x 10/100/1000 data
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series
Copper Multi-Gigabit Line-Cards
RJ-45 (Multi-Gigabit)
24x 10/100/1000 + 24x 100, 1G, 2.5G, 5G, 10G
PoE, PoE+, and Cisco UPOE
Cisco TrustSec and MACsec (256)
24x 1G + 24x Multi-Gigabit UPOE
RJ-45 (Multi-Gigabit)
48x 100, 1G, 2.5G, 5G
PoE, PoE+, UPOE and UPOE+
Cisco TrustSec and MACsec (256)
48x Multi-Gigabit UPOE+
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series
Fiber Line-Cards
SFP (1G)
48x 100/1000
TrustSec and MACsec (256)
24x SFP 48x SFP
Fiber (1G/10G)
24x 1G, 10G
TrustSec and MACsec (256)
24x SFP, SFP+
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series
Centralized Modular Architecture
Centralized architecture
Supervisor
Passive backplane
Up to 480G bandwidth per slot
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series
Sup-1, Sup-1XL and Sup-1XL-Y block diagram
Switch backplane
24x 24x 16x
240G 40G
SLI SLI SLI
8x
SupIO
SLI PCIe Ethernet
UADP 2.0 XL UADP 2.0 XL UADP 2.0 XL (I2C)
#1 #2 #3
720 Gbps
Quad-core CPU
(control traffic, containers
for apps)
ASIC # 4-slot 7-slot 10-slot
UADP #1 Slot 1 Slots 2 and 7 Slots 1, 9,
and 10
M.2 SATA
UADP #2 Slot 4 Slots 1 and 5 Slots 2, 3 SDRAM
(optional)
and 4
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9300 Flexible Tables - UADP 2.0 XL
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series - Power supplies
• Modular design: 4 PS for 4-slot chassis; 8 PS for 7- and 10-slot chassis
• Shared: Power for both data and inline power
• Slot priority: Lower-number slot with higher power priority (configurable in future software)
• Platinum-rated PS: 90%+ efficiency
• Output:
• 3200W AC PS with 240V input (1570W with 120V input. 16A input)
• 2100W AC PS with 240V input (940W with 120V input. 10.4A input)
• 3200W DC PS input voltage (-40 to -72 VDC)
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9400 Series - Fan tray
• Flexible service:
Fan tray can be replaced from the
front or the back
• Efficient:
Variable speed per fan depends on
the load, temperature, and altitudes
(=> lower noise)
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst
9300 Series
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9300 Series
Flexible High-End Fixed Access
Catalyst 9300
Modular Uplinks Fixed Uplinks Premium Fixed Access
(C9300 SKUs) (C9300L SKUs) UADP 2.0
x86 CPU
Copper Ports MGig + Fixed Uplinks
Cisco IOS XE
StackWise 480/320
StackPower*
48 ports 48 ports UPOE 24 ports 48/24 ports 48/24 ports SD-Access
UPOE 5G 12 MultiGigabit + 36 2.5G UPOE MultiGigabit UPOE Data
Application Hosting
1/10G + Fixed Uplinks Encrypted Traffic Analytics
MACsec-256 encryption
Trustworthy Solutions
48/24 ports 48/24 ports 48/24 ports 48/24 ports 48/24 ports IEEE1588 and AVB
UPOE/UPOE+ 1G PoE+ 1G Data 1G PoE+ Data NBAR2 App Visibility
Full Flexible NetFlow
Fiber Ports Stackwise-320 Kit
Perpetual and Fast PoE
IEEE 802.3bt Type 3
48/24 ports SFP 1G Model-Driven
Programmability & Telemetry
Hot Patching and GIR
* Modular SKUs Only
Uplink Modules Modular Fans AC & DC Power Supplies
Platinum
rated
8x 10G 2x 40G 4x Multigigabit 4x 1G 2x 25G 315W AC 715W AC/DC 1100W AC 1900W AC
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9300 Series
Front view
Unmatched PoE/
USB console Flexible fixed
Multigigabit capable Cisco UPOE®
Mini-USB Type B or modular uplinks
resiliency – Perpetual/Fast
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9300 Series
Back view
External storage
USB 3.0 removable storage Stack cables Redundant fans Redundant power
(120-GB SSD)
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational * Supported only on Cisco Catalyst 9300 Series modular uplink models (C9300 SKUs).
Catalyst 9300 Increased Scale Platform
Fixed Access optimized for Media Distribution and IP Storage
UADP 2.0 XL
2x Cisco IOS® XE Software
Buffers C9300-48UB: 48 Port 1G switch with UPOE
x86 CPU and containers
More Cisco SD-Access
Packet Buffers Encrypted Traffic Analytics (ETA)
AES-256/MACsec-256
2-4x C9300-24UXB: 24 Port Multigigabit switch with UPOE Trustworthy systems
Scale
Cisco StackWise-480
IEEE1588 and AVB*
Increased NBAR2
Network Scale
C9300-24UB: 24 Port 1G switch with UPOE Perpetual/Fast PoE
Model-driven programmability
New Patching/GIR
Modular Higher-efficiency AC
Modular uplinks Platinum Streaming telemetry
fans and DC power supplies rated
StackWise-480
8x 10G 2x 40G 4x Multigigabit 4x 1G 2x 25G 315W AC 715W AC/DC 1100W AC 1900W AC Stackpower
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
111
Catalyst 9300 Series 1G SFP Fiber
Expanding FTTD and 1G Fiber aggregation designs
1G fiber aggregation
StackWise-480
4x 1G/2.5G/5G/10G
copper uplink module
48x 5G ports
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9300 Series
Uplink options
4x 1G Fixed uplinks
C9300L-24/48P-4G, C9300L-24/48T-4G
Modular uplink options on all C9300 SKUs Fixed uplink options on C9300L SKUs
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9300 Series
C9300-48T/P/U SKUs - Block diagram
StackWise-480
X86 1.8-GHz
Packet buffer (8 MB) Packet buffer (8 MB)
quad-core CPU
40G 40G
PHY PHY PHY PHY PHY PHY
PHY PHY
0 1 2 3 4 5
0 1
TX 0-7 TX 0-7
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9300 Flexible Tables - UADP 2.0
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9300 Series Switches
Platinum-rated power supply options
New
350W AC-P 715W AC-P 1100W AC-P 1900W AC-P 715W WDC
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
StackPower
“Zero-footprint” Redundant Power System (RPS) deployment
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst
9200 Series
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9200 Series Switches
Flexible fast and light ASIC Densest downlink offering Modular and
UADP 2.0 mini 24x 1G, 48x 1G fixed uplink offering
* Hardware capable
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9200 Series
Data & PoE SKUs
Data/PoE+ (modular uplinks and fans) Data/PoE+ (fixed uplinks and fans)
24 ports 24 ports
Data Data
48 ports 48 ports
24 ports 24 ports
PoE+ PoE+
48 ports 48 ports
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9200 Series
Multigigabit models
Cisco Catalyst 9200 with Modular Uplinks Cisco Catalyst 9200L with fixed uplinks
2x 25G Uplinks
16x 1G and 8x Multigigabit Ports
PoE+ 2x 25G Uplinks PoE+
4x 10G Uplinks
16x 1G and 8x Multigigabit Ports 16x 1G and 8x Multigigabit Ports
2x 25G Uplinks
40x 1G and 8x Multigigabit Ports
PoE+ 2x 40G Uplinks PoE+
4x 10G Uplinks
40x 1G and 8x Multigigabit Ports 36x 1G and 12x Multigigabit Ports
Cisco Catalyst 9200 Series switching SKUs for SD-Access Fabric Edge
• 4x 1G • 4x 10G
• SFP transceivers • SFP and SFP+ transceivers
• Supported on all • Supported on all modular
modular SKUs SKUs
C9200-NM-4G C9200-NM-4X
• 2x 25G • 2x 40G
• SFP and SFP+ transceivers • QSFP transceivers
• 1/10/25G Speed support • Supported on all 9200 mGig
• SKUs only
Supported on all 9200 mGig
SKUs only
C9200-NM-2Y C9200-NM-2Q
Up to 8-
member stack
switching models
• StackWise-80 supported on all fixed Cisco Catalyst 9200 Series switching
models Stack adapters Stacking cable
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational *Mixed stacking not supported between StackWise-160 and StackWise-80
Cisco Catalyst 9200 Series
48-port SKUs - Block diagram
USB 2.0
Octal PHY Octal PHY Octal PHY Octal PHY Octal PHY Octal PHY
Mini USB console
12 ports PoE+ 12 ports PoE+ 12 ports PoE+ 12 ports PoE+
RJ-45 console
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9200 Series – UADP 2.0 Mini
Lookup tables
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Resilient power supplies
600W AC 1000W AC
Supported only on 24- Supported only on 48-
125W AC port PoE+ SKUs port PoE+ SKUs
Supported only on 1G data SKUs
Load sharing (1+1) mode supported for PoE+ SKUs
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Resilient fan modules
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000
High Availability
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Today our networks are most resilient
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Mission-Critical Resiliency
Your business stops if the network is down
StackWise® Virtual • No downtime when device in maintenance Redundant Fan & Power Supplies
New
• Virtualized redundant system for xFSU on C9300/L Standalone • In case of any hardware failure
simplified configuration & protocols
• < 30 sec traffic downtime - Standalone upgrade
Active
Active
SSO SSO NSF
SSO
Standby aware/capable
Standby
Stateful switchover (SSO)
SSO-aware applications
FIB, ACLs, 802.1X Cisco Catalyst StackWise Virtual Cisco Catalyst
Non-Stop Forwarding
PAgP / LACP 9500 Series 9500 Series (NSF) or Graceful Restart
…and more SSO
Active Standby OSPF, BGP, LDP, etc.
SSO-compliant applications
Routing protocols,
NetFlow, etc.
NSF
aware/capable
Active Active
Active Sup StackWise-480/320/160/80
SSO SSO
Standby Sup Standby Standby
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9600 StackWise Virtual
Quad SUP RPR
IOSXE 17.2.1
SSO
• Active supervisor in chassis-2 become StackWise Active RPR: Route Processor Redundancy
SSO: Stateful Switchover
• Warm standby supervisor in chassis-1 continue the boot process StackWise-A: StackWise Virtual Active
StackWise-S: StackWise Virtual Standby
• Become StackWise standby while the line cards in chassis-1 reset ICS: In-chassis Warm Standby
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
139
Cisco Catalyst 9300 Series
StackWise-480/320 and high availability
A
Centralized control plane
S
SSO/NSF
StackWise-480
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9200 Series
StackWise-160/80 with Stateful Switchover (SSO)
Up to 8-
member stack
• StackWise-160 supported on all modular Cisco Catalyst 9200 Series switching models
• StackWise-80 supported on all fixed Cisco Catalyst 9200 Series switching models
• Same Cisco IOS XE and license required on all members
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 - In-Service Software Upgrade
Dual supervisor ISSU
3-step process
• Install add file <tftp/ftp/flash/disk:*.bin>
• Install activate issu
• Install commit
Granular control on the upgrade
with ability to roll back
1-step process
• Install add file <tftp/ftp/flash/disk:*.bin> activate issu commit
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 - Extended Fast Software Upgrade
Regular upgrade vs. Extended Fast Software Upgrade (xFSU)
#Install add file image activate commit #Install add file image activate reloadfast commit
< 30 seconds of
Control Contrtraffic
ol pimpact
p
Data plalane Data plalane
ne ne
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Layer 2 and 3 Topology with GIR Maintenance
9300#start maintenance
Template default will be applied.
Do you want to continue?[confirm]
*Mar 25 17:43:20.162: %MMODE-6-
MMODE_CLIENT_TRANSITION_START: Maintenance Isolate
start for router isis 1
*Mar 25 17:43:50.213: %MMODE-6-
MMODE_CLIENT_TRANSITION_COMPLETE: Maintenance Isolate
complete for router isis 1
*Mar 25 17:43:50.213: MMODE-6-MMODE_CLIENT_TRANSITION
%_START: Maintenance Isolate start for shutdown l2
*Mar 25 17:44:20.214: %MMODE-6-
MMODE_CLIENT_TRANSITION_COMPLETE: Maintenance Isolate Set-overload-bit IS-IS
complete for shutdown l2 Set-overload-bit
*Mar 25 17:44:20.214: %MMODE-6-MMODE_ISOLATED: System Set-overload-bit
is in Maintenance
• Quick (able to deliver point fixes much faster than possible in Cisco IOS)
• Effective (does not require a monolithic code upgrade)
• Focused (targets the specific area of code that has the issue)
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000
Quality of Service
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
QoS Features in Catalyst 9000
QoS Features
• Trust/Conditional Trust
• Classify Traffic
• Police Traffic
• Remark/Conditional Remark
Queuing Features
• Prioritize strict traffic (PQ)
• Schedule traffic based on weight (WRR)
• Shape the traffic rate (SRR)
• Manage Congestion (WRED/WTD)
• Dynamic buffers for traffic bursts (DTS)
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 QoS
QoS Highlights
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 QoS
Buffer Size Comparison
UADP2.0 UADP2.0XL UADP3.0
5 MB Egress
10 MB Egress 27 MB Egress
0.75 MB
FIFO
0.5 MB 1 MB – 1.75 MB
– 1 MB Stack
Ingress 1.5 MB 5 MB
per Core 8 MB
per ASIC 8+8 MB FIFO FIFO
1.5MB – 3.5 2.6 MB
0.4MB- MB Stack 1.4
1.5 MB Stack
UADP2.0 Mini
Ingress
Ingress
3.4 MB Egress
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 QoS
Conditional
Conditional
Policing Marking
Marking
Trust Classification
Unconditional
Unconditional
Marking
Marking
Conditional
Marking Policing
Scheduler
8q3t PQ1
Classification PQ or Q
1p7q3t
PQ2
2p6q3t
Unconditional
Unconditional Q3
Marking
Marking WTD
Q4 or
WTD WRED
Q5 or
WRED
Q6
Q7
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Q7
Catalyst 9000 QoS
Dynamic Threshold Scalability (DTS)
• Shared buffer is best for
Switch
burst absorption
Unused
Unused
Dynamic Shared Pool (DTS)
• Dedicated buffer is best for
Unused
predictable performance
Unused
Unused
Unused
(for each port)
Unused
Unused
• Configurable dedicated threshold
Unused
Unused
per-port/queue
Unused
Unused
Unused
Unused
• Configurable global maximum
shared threshold
• Automatic adjusts depends
Port 1 Port 2 Port N on the available shared pool
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 QoS
DTS – Dynamic Fair Buffer Sharing
Maximum buffer per
queue (Configurable) • SoftMin – Minimum shared buffer given to a port
SoftMin
Dedicated for fairness
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Ingress Forwarding & QoS
UADP 2.0 / 2.0 XL / Mini
Stack Interface
5 4 SQS AQM
Q PBC – Packet Buffers Complex
IQS Ingress Pipeline Egress Pipeline Q Q
1. Received, processed by MACSec and 3 IGR Flex Parser EQS
into FIFO
Lookup Lookup Lookup Lookup
Table Table Table Table
Lookup Lookup Lookup Lookup
Table Table Table Table
Stage
Stage #15
#15 Stage
Stage #1
#1
2. A copy to buffer and a copy to IFC
Flexible
Ingress Forwarding Egress Forwarding
Lookup Lookup Lookup Lookup
Table Table Table Table
Lookup Lookup Lookup Lookup
Stage
Stage #2
Table Table Table Table
Stage
Stage #..
#.. Look up #2
Controller XF XF ControllerStage #..
3. Goes through IFC, result descriptor Stage
Stage #..
#.. XF Lookup
Table
Lookup
Table
Tables
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table XF Stage #..
send to PBC (IFC) C
C C
C (EFC) Stage #..
Stage #2
Stage #2 Stage #..
* Classify based on Original Packet Lookup
Table
Lookup
Table
Lookup
Table
(shared
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
(shared Stage
* Ingress Policer Stage Stage #8
#8
Stage #1
#1 across
across cores)
cores)
* Conditional mark Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
1
MACSEC
MACSEC MACSEC
MACSEC
Network Interfaces
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Egress Forwarding & QoS
UADP 2.0 / 2.0 XL / Mini
6
Stack Interface
SQS AQM
Q PBC – Packet Buffers Complex
IQS Ingress Pipeline Egress Pipeline Q Q
IGR Flex Parser EQS 7
Lookup Lookup Lookup Lookup
Table Table Table Table
Lookup Lookup Lookup Lookup
Table Table Table Table
Stage
Stage #15
#15 Stage
Stage #1
#1
Flexible 6. PBC received the frame and sends
Ingress Forwarding Egress Forwarding
Lookup Lookup Lookup Lookup
Stage
Stage #2
Table Table Table Table
Stage
Stage #..
#.. Look up #2
Controller XF XF ControllerStage #..
Stage
Stage #..
#.. XF Lookup
Table
Lookup
Table
Tables
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table XF Stage #.. 7. SQS provided Scheduling from the
(IFC) C
C C
C (EFC) Stage #.. Stack. AQM applies Egress
Stage #2
Stage #2 Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Stage #.. Scheduling.
(shared
Lookup Lookup Lookup Lookup
Table Table Table Table
(shared Stage
Stage Stage #8
#8
Stage #1
#1 across cores)
across cores)
ReWrite
EGR8
8. EFC sends results to ReWrite
Lookup Lookup Lookup Lookup
Table Table Table Table
Lookup Lookup Lookup Lookup
Table Table Table Table
MACSEC
MACSEC MACSEC
MACSEC
Network Interfaces
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Ingress & Egress Forwarding & QoS
UADP 3.0 – In same ASIC
Backplane 800 Gbps
SQS AQM
Unified Packet Buffer Complex(PBC)
Q Q EQS Q
IQS EQC ESM
Flexible
Ingress Forwarding lookup Egress Forwarding Step 10. EFC performs
Step 1: Packet arrives Step 8:
10.PBCEFCrewrites
performs
at
Step
Step
Step
at
Step
6:
ingress
3:
ingress
3:
PBC
6: MACsec
PBC
port,
MACsec
port,
uses
uses
PHY
the
the
engine
PHY
engine
Controller tables Controller Step
Step
egress
Step
Step
Step9.
Step
egress
Step
packet
11.
7.
12.
9.
11.
7. lookup
12.EFC
EQS
Rewrite
MACsec
lookup
EFC
EQS snoops
Rewrite
with
–– functions
MACsec replication,
snoops
new
engine
engine
packet
functions to
replication,
engine
engine
packet
frame to
Step
frame
Step 5:
2:descriptor
IFC
Network
returns
to
interface
lookup between
rewrites
learn
scheduling,
encrypts
SRC packets
PBC
packet
MAC,
and andqueue
queue
and
prior
egress
rewrite
sends
to
converts
decrypts
Step
converts
decrypts
Step
result
result
4: IFC
the
CTS
4:(frame
determine
passes
determine
passes
IFC
the
CTS
packet
(frame
packet
snoops
signal
packet
snoops
signal
the
the
and
packetpacket
andand
packet
and
descriptor)
to
egress
ingress
port.
descriptor)
to
egress
ingress to
port.
to
(IFC) (EFC) between
rewrites
learn
scheduling,
encrypts
SRC packets
PBC
packet
MAC,
and and and
prior
egress
rewrite
descriptor, reassembles and sends
to
serializes
passes
between unencrypted
FIFO
the bits,
andand
PBC.
packet
then (shared
(shared engine.
through
SPAN,
management.
placingetc.
enqueues the
itthe
on
and
egress
NIF.
sends
frame. FIFO.
PBC.
Egress
MACsec
PBC.
Egress
MACsec onengine.
on engine.
same ASIC,
same ASIC, soso enqueues
results to the frame.
rewrite engine.
ittosends
ingress to FIFO.
network
result to moved to EQS. Core 1 across
across Core 1
interface ports. cores*)
cores*)
Rewrite engine
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000
Multicast
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 Multicast
Multicast Highlights
Performance Internet
Data
Branch
Center
• High L2 and L3 multicast throughput
• Low latency (average ~5us for IMIX)
Flexible Scalability
• Different SDM templates allow reallocating
Multicast routes & IGMP snooping groups
Optimized Replication L3 L3
L2 L2
• Replications are done at the egress stage
• Single copy in buffer memory, during replication
Enhanced Features
• IP-Based forwarding for IGMP snooping
• IGMPv3 snooping explicit host tracking
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 Series
Multicast Highlights
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 - Multicast Scale
Feature/Product Catalyst 9200 Catalyst 9300 Catalyst 9400 Catalyst 9500 Catalyst 9500 Catalyst 9600
High-Performance
*The numbers are with the default template when multiple templates are supported.
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Multicast – Egress Remote on Input
UADP 2.0 / 2.0 XL / Mini
5 Stack Interface
4
SQS AQM
Q PBC – Packet Buffers Complex
IQS Ingress Pipeline Egress Pipeline Q Q
1. Received, processed by 3 IGR Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Flex Parser EQS
MACSec and into FIFO
Lookup Lookup Lookup Lookup
Table Table Table Table
Stage
Stage #15
#15 Stage
Stage #1
#1
Flexible
Ingress Forwarding Egress Forwarding
Lookup Lookup Lookup Lookup
Stage
Stage #2
Table Table Table Table
Stage
Stage #..
#.. Look up #2
IFC Controller XF XF ControllerStage
Stage XF Tables XF #..
Stage #..
Stage #..
Lookup Lookup Lookup Lookup
#..
Table Table Table Table
Lookup Lookup Lookup Lookup
Table Table Table Table
(shared
Lookup Lookup Lookup Lookup
Table Table Table Table
(shared Stage
Stage Stage #8
#8
Stage #1
#1 across
across cores)
cores)
4. Descriptor has remote Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
1
MACSEC
MACSEC MACSEC
MACSEC
Network Interfaces
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational Descriptor can contain both local and remote destinations
Multicast – Egress Remote Output Replication done on egress =>
UADP 2.0 / 2.0 XL / Mini Efficient use of BW
Stack Interface
6
SQS AQM
Q PBC – Packet Buffers Complex
IQS Ingress Pipeline Egress Pipeline Q Q
IGR Flex Parser EQS 7
Lookup Lookup Lookup Lookup
Table Table Table Table
Lookup Lookup Lookup Lookup
Table Table Table Table
Stage
Stage #15
#15 Stage
Stage #1
#1 6. PBC received the frame and
Flexible
Ingress Forwarding Egress Forwarding
Lookup Lookup Lookup Lookup
Stage
Stage #2
Table Table Table Table
Stage
Stage #..
#.. Look up #2
Controller XF XF ControllerStage #..
Stage
Stage #..
#.. XF Lookup
Table
Lookup
Table
Tables
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table
Lookup
Table XF Stage #.. 7. AQM within EQS generate the
(IFC) C
C C
C (EFC) Stage #.. list of egress ports based on
Stage #2
Stage #2 Stage #..
descriptor, schedule for each
Lookup Lookup Lookup Lookup
Table Table Table Table
(shared
Lookup Lookup Lookup Lookup
Table Table Table Table
(shared Stage
Stage Stage #8
#8 egress port
Stage #1
#1 across cores)
across cores)
EGR8
Lookup Lookup Lookup Lookup
Table Table Table Table
Lookup Lookup Lookup Lookup
Table Table Table Table
Flex Parser
8. For each egress port, frame
ReWrite
goes though the EFC, Rewrite and
Engine
Encryption Recirculation Egress FIFO
Engine Engine
Ingress
Egress
FIFO
FIFO
MACSEC
MACSEC MACSEC
MACSEC
Network Interfaces
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Multicast - Ingress & Egress Single copy of packet in
UADP 3.0 – In same ASIC buffer memory during
replication
SQS AQM
Unified PBC (shared buffer)
Q Q EQS Q
IQS EQC ESM
Step
Step 1:
1:3:Packet
Packet arrives
arrives at
at Ingress Forwarding Flexible Egress Forwarding
Step
Step MACsec
3:port,
MACsec engine
engine Step
Step 6:
6: AQM
AQM within
within EQS
EQS generates
generates
ingress
Step
ingress
Step 2: Network
port,
2: PHY
Network
PHY converts
interface
converts
interfacethe
and the lookup
decrypts
Step 4:
decrypts
Step
signal
passes
signal
4: CTS
and
passes
and
CTS
IFC snoops
IFC
packet
packet
snoops
packetpacket
packet
serializes
serializes
FIFO to
packet
and
to ingress
the bits,
bits, and
andingress
the and Controller Controller the
the list
list of
of egress
egress ports
ports based
based on
on
passes
between
passes
between
then
MACsec
it
unencrypted
unencrypted
it sends
FIFO
engine
to and
to network
packet
PBC
packet
PBC
network interface
to
to tables descriptor,
descriptor, schedule
schedule for
for each
each egress
egress
then
MACsec
ingress
ingress
ports
ports
sends
FIFO
FIFO
engine interface
(IFC) (EFC) port.
port.
(shared
(shared
Core 1 across
across cores)
cores)
Core 1
Step
Step 5:
5: IFC
IFC returns
returns lookup
lookup result
result
(frame
(frame descriptor)
descriptor)
to
to PBC
PBC Rewrite engine
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000
Security
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 Security
Feature Highlights
• SPAN/ERSPAN
Visibility • Security NetFlow &
Encrypted Traffic Analytics (ETA)
Consistently delivered
throughout the
Cisco® Catalyst® 9000 family
• Highest level of Macro
and Micro-Segmentation
Segmentation with Cisco SD-Access
• Multi-domain policy integration
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
177
Cisco Catalyst 9000 Security
Four types of Security ACLs
Router ACL (RACL) VLAN ACL (VACL) Port ACL (PACL) Security group ACL (SG ACL)
Standard/extended/ Standard/extended/
Standard/extended ACLs Standard/extended ACLs
MAC ACLs MAC ACLs
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 Security
Platform Trustworthy Solutions
PnP SUDI Physical security practices + security technology innovations + logical security processes
Secure boot
support Boot sequence check
Two-way trust
Integrity
Image signing
Authentic OS
verification
Malware protection
Hardware
Runtime defenses
authenticity 64-bit ASLR
Genuine hardware
Cisco® trustworthy systems use industry best practices to help ensure full development lifecycle integrity and end-to-end security
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
180
Catalyst 9000 Security
Cisco DNA & SD-Access
DNA Center
Automated
Network Fabric
Policy Automation Analytics
Single Fabric for Wired & Wireless
with simple Automation
B B
C
Outside
Identity-Based
Policy & Segmentation
Decouples Security & QoS
from VLAN and IP Address
Insights &
SDA Telemetry
Extension User Mobility
Analytics and Insights into
Policy stays with User
User and Application behavior
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
IoT Network Employee Network
Cisco Umbrella Native Connector
Available on Catalyst 9000 Series Switches
C9200: IOS-XE 16.12
C9300: IOS-XE 17.1
Branch Office
INTERNET
Catalyst 9000 a
Guest Native connector on
Catalyst 9000 forwards
DNS
DNS queries to OpenDNS
cloud
IOS-XE
16.12
IOS-XE
Employees 17.1
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000 Security
Encrypted Traffic Analytics (ETA)
Cisco StealthWatch® Cognitive learning
Encrypted
Traffic Analytics
Cisco Catalyst 9000 Series 99%+ accuracy
* Cisco Catalyst 9200 Series does not support ETA
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Media Access Control Security (MACsec 256)
Available on Cisco Catalyst 9000 Series Switches
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
187
Catalyst 9000 Security - MACsec in Hardware
UADP 2.0/3.0/Mini ASIC
Stack Interface
PBC – Buffers Complex (Core 0)
PBC – Buffers Complex (Core 1)
IGR Flex Parser
Core 1 Core 1
Stage Stage
Flexible
Stage Stage
#15 #1
#15 Looku Looku Looku Looku
#1
Ingress
Ingress Forwarding
Looku Looku Looku Looku
Ingress Forwarding
p p p p
(IFC)
(IFC)
Stage
Stage
#.. (IFC)
(IFC) XF Looku
p
p
Table
Looku
p
p
Table
Looku
p
p
Table
Looku
p
p
Table XF (EFC)
(EFC)
Stage
Stage
#.. (EFC)
(EFC)
#..
C
C
Table Table Table Table
C
C
#..
Stage Stage
Stage Stage
Core
Core 0
0
#2
#2 Core
Core 1
1
Looku
Looku
p
p
Looku
Looku
p
p
Looku
Looku
p
p
Looku
Looku
p
p Core
Core 11
#..
#.. Core
Core 00
(Shared
Table Table
(Shared
Table Table
Table
Table
Table
Table
Stage Stage
Stage
#1
#1 Across
Across Cores)
Cores)
Stage
#8
#8
Looku Looku Looku Looku
Looku
p Looku
p Looku
p Looku
p
p
Table p
Table p
Table p
Table
Table Table Table Table
Rewrite
Rewrite Block Rewrite
Block Rewrite Block
Block
FIFO
FIFO
FIFO
FIFO FIFO
FIFO FIFO
FIFO Hardware
Encrypt & Decrypt
MACsec
MACsec MACsec
MACsec
Modules
MACsec
MACsec Network Interfaces (Core 1) MACsec
MACsec
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
188
Catalyst 9000
Unique Innovations
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Evolution of PoE
2003
IT OT
• IEEE 802.3bt complements Cisco UPOE+ by adding four new classes of devices
• Safety measures help ensure that up to 90W of power is safely delivered
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco innovations in PoE
Deliver a robust low-voltage infrastructure
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9000 augments Cisco’s leadership in IoT
IBN expands IoT endpoints with security, visibility, scale, and cloud tethering
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Audio Video Bridging (IEEE 802.1BA)
Fewer cables and a transparent collaboration experience
AVB not supported on Cisco Catalyst 9400 and 9300 Series in StackWise-480
*Source: Axon and Axis report.
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9000 family
Programmability and automation
B
Open Open
ZTP
bootloader config
PnP
YANG
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Model-Driven Telemetry
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Continue your IBN journey
Application Hosting
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
25GE - A Better Alternative
Provides seamless migration path from 10GE
C9500-48Y4C
* - Roadmap
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9000 Series
Seamless backbone speed migration enabling any speed, any distance
Flexible
deployment
Fiber infrastructure Diverse deployment
1G to 100G
investment protection options
* Roadmap
www.cisco.com/c/en/us/products/interfaces-modules/transceiver-modules/
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Multimode fiber, parallel
100G-CR4
IEEE compliant
<5 m copper
4x SFP28 breakout
IEEE compliant (25G)
<5 m copper
100G AOC
IEEE compatible(100G)
<30 m active optical
5m 30 m 100 m 500 m 2 km 10 km 25 km 40 km 80 km
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco 100G optics
Support for 100G optics (QSFP28)
500 m to
100 m, MMF 10 km, SMF 2 km, SMF
SR4 QSFP28 LR4 QSFP28 SM-SR QSFP28
CWDM QSFP28
1, 2, 3, 5, 7, 10, 15
1, 2, 3, 5 m, copper
20, 25, 30 m, optical
CU QSFP28 AOC QSFP28
Built-in cable/optics
Built-in cable/optics
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Multimode fiber, parallel
IEEE compliant
40G CSR4 (1.5W) 12 fiber MPO (parallel fiber), MMF
400 m on MMF (OM4)
IEEE compliant
40G SR Bidir (3.5W) Duplex fiber LC, MMF
150 m on MMF (OM4)
IEEE compliant 40G LR4 (3.5W) Duplex fiber LC, SMF
10 km on SMF
IEEE compatible
40G LR4 Lite (3.5W) Duplex fiber LC, SMF
2 km on SMF
IEEE compatible
40G ER4 (3.5W) Duplex fiber LC, SMF
40 km on SMF
5m 30 m 100 m 300 m 2 km 10 km 40 km
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco 40G optics
Support for 40G optics
150 m,
100 m, MMF 10 km, SMF 40 km, SMF MMF
SR4 QSFP+ LR4 QSFP+ ER4 QSFP+ BD
QSFP+
2 km, SMF 10 m,
10 m, copper
WSP- AOC optical QSA
CU/AC/AOC 4X10G
Q40GLR4L ADAPTER
QSF+S CU/AC
QSFP+
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
20
Multimode fiber, parallel
IEEE compliant
25G AOC (1W)
1 to <10 m active optical
25G SR (1.5W)
IEEE compliant 70 m on MMF (OM3) Duplex fiber, MMF
100 m on MMF (OM4)
10/25G CSR (1.5W)
Cisco® proprietary 300 m* on MMF (OM3) Duplex fiber, MMF
400 m* on MMF (OM4)
MSA compliant
10/25G LR (1.5W) Duplex fiber LC, SMF
10 km on SMF
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco 25G optics
Support for 25G optics
10 m fiber 10 m, copper
AOC cables CU cables
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Catalyst 9000
Summary
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9000 Family
Scalability, Reliability, Security across the network
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Cisco Catalyst 9000 Catalyst 9K continues to be the fastest
ramping product in the company's history”
The Fastest Ramping Product!
- Chuck Robbins, CEO Cisco Systems
Security
CRN ®
CRN® Design Licensing
Products of Products of
the Year the Year
2017 2018
Cisco UADP Open IOS XE
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational
Would you like to know more?
FREE
• cisco.com/go/cat9K
• Cisco Catalyst 9000 At-a-Glance
cs.co/cat9kbook
© 2019-2020 Cisco and/or its affiliates. All rights reserved. Cisco Informational