Implementing Redundant Supervisor Engines in Catalyst Switches

Route processor redundancy enables a second Supervisor Engine to provide failover capabilities within a Catalyst switch. This topic explains how to implement redundant Supervisor Engines.

Cisco,co m

Cisco,co m

Single Supervisor Engine means single point of failure for the switch.

Redundant Supervisor Engine allows configuration for automatic failover.

f^c-V '■ ->r " y- - <1 i jffl^' ILOJtUF,T. yv-f+H, t feggggj sxm J J ■ jwsmä Jifmj/sjWiiSBsr/..«; >

jffl^' ILOJtUF,T. yv-f+H, t feggggj sxm J J ■ jwsmä Jifmj/sjWiiSBsr/..«; >

© 2004, Cisco Systems, Inc. All rights re

You can ensure availability by configuring dual Supervisor Engines within a Catalyst 6000 series switch. Dual Supervisor engines within a single device provide redundancy without having to add a separate switch. This solution can be a cost-effective alternative to deploying multiple devices. When multiple redundant switches are used, configuring redundant Supervisor Engines adds an extra level of availability assurance.

Cisco IOS Release 12.1(13)E and later support Supervisor Engine redundancy with Route Processor Redundancy (RPR) and Route Processor Redundancy Plus (RPR+).

Note The Cisco Catalyst switch features described in this topic apply to the Catalyst 6500 series.

For the Catalyst 4507R, for example, the RPR has a subminute failover time.

RPR and RPR+

mum cisco.com

• Route Processor Redundancy

- Switchover in 2 to 4 minutes

- Redundant Supervisor Engine booted but MSFC and PFC not operational

• Route Processor Redundancy Plus

- Switchover in 30 to 60 seconds

- Redundant Supervisor Engine booted with MSFC and PFC operational

© 2004, Cisco Systems, Inc. All rights reserved. BCMSN v2.1—6-10

Catalyst 6500 series switches support fault resistance by allowing a redundant Supervisor Engine to take over if the primary Supervisor Engine. RPR supports a switchover time of two to four minutes and RPR+ supports a switchover time of 30 to 60 seconds.

When RPR+ mode is used, the redundant Supervisor Engine is fully initialized and configured, which shortens the switchover time. The active Supervisor Engine checks the image version of the redundant Supervisor Engine when the redundant Supervisor Engine comes online. If the image on the redundant Supervisor Engine does not match the image on the active Supervisor Engine, RPR redundancy mode is used.

RPR supports these features:

■ Auto-startup and bootvar synchronization between active and redundant Supervisor Engines.

■ Hardware signals that detect and decide the active or redundant status of Supervisor Engines.

Clock synchronization every 60 seconds from the active to the redundant Supervisor Engine.

■ A redundant Supervisor Engine that is booted without all subsystems needing to be up: If the active Supervisor Engine fails, the redundant Supervisor Engine becomes fully operational.

■ An operational Supervisor Engine in place of the failed unit becomes the redundant Supervisor Engine.

Support for fast software upgrade. Note The two Gigabit Ethernet interfaces on the redundant Supervisor Engine are always active.

When the switch is powered on, RPR runs between the two Supervisor Engines. The Supervisor Engine that boots first, either in slot 1 or 2 becomes the RPR active Supervisor Engine. The Multilayer Switch Feature Card (MSFC) or Multilayer Switch Feature Card 2 (MSFC2) and the Policy Feature Card (PFC) or Policy Feature Card 2 (PFC2) become fully operational. The MSFC and PFC on the redundant Supervisor Engine come out of reset but are not operational.

These events cause an RPR switchover:

■ Clock synchronization failure between Supervisor Engines MSFC or PFC failure on the active Supervisor Engine

■ A manual switchover

In a switchover, the redundant Supervisor Engine becomes fully operational and these events occur:

All switching modules recycle power.

■ The remaining subsystems on the MSFC (including Layer 2 and Layer 3 protocols) are brought up.

■ Access control lists (ACLs) are reprogrammed into Supervisor Engine hardware.

Note In a switchover, there is a disruption of traffic. This is because some address states are lost and then restored after they are dynamically redetermined.

^^^^^^^^■rniiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiiii:: cisco.com

Capabilities:

• Standby Supervisor Engine fully booted

• Startup configuration synchronization between active and standby

• Running configuration synchronization between active and standby

• Card-state synchronization between active and standby Avoids service disruption in:

• Running configuration lost upon switchover

• Reset and redownload of modules upon switchover

© 2004, Cisco Systems, Inc. All rights re

With RPR+, the redundant Supervisor Engine is fully initialized and configured. This shortens the switchover time if the active Supervisor Engine fails or if a manual switchover is performed.

When the switch is powered on, RPR+ runs between the two Supervisor Engines. The Supervisor Engine that boots first, either in slot 1 or 2, becomes the active Supervisor Engine. The MSFC or MSFC2 and the PFC or PFC2 become fully operational. The MSFC and PFC on the redundant Supervisor Engine come out of reset but are not operational.

RPR+ enhances RPR by providing these additional benefits:

■ Reduced switchover time. Depending on the configuration, the switchover time is in the range of 30 to 60 seconds.

■ Installed modules are not reloaded. Because both the startup configuration and the running configuration are continually synchronized from the active to the redundant Supervisor Engine, installed modules are not reloaded during a switchover.

■ Online insertion and removal (OIR) of the redundant Supervisor Engine. RPR+ allows OIR of the redundant Supervisor Engine for maintenance. When the redundant Supervisor Engine is inserted, the active Supervisor Engine detects its presence and begins to transition the redundant Supervisor Engine to a fully initialized state.

■ Synchronization of OIR events.

■ Manual user-initiated switchover using the redundancy force-switchover command.

These events cause an RPR+ switchover:

Clock synchronization failure between Supervisor Engines MSFC or PFC failure on the active Supervisor Engine

During RPR mode operation, the startup configuration and register configuration are synchronized by default between the two Supervisor Engines. In a switchover, the new active Supervisor Engine uses the current configuration.

Note Unless autosynchronization has been disabled, the boot variables are synchronized by default.

When a redundant Supervisor Engine configuration is running in RPR+ mode, these operations trigger synchronization:

When a redundant Supervisor Engine first comes online, the configuration information is synchronized in bulk from the active Supervisor Engine to the redundant Supervisor Engine. This synchronization overwrites any existing startup configuration file on the redundant Supervisor Engine.

When configuration changes occur during normal operation, RPR+ performs an incremental synchronization from the active Supervisor Engine to the redundant Supervisor Engine. RPR+ synchronizes user-entered command-line interface (CLI) commands incrementally, line -by line, from the active Supervisor Engine to the redundant Supervisor Engine.

Note Even though the redundant Supervisor Engine is fully initialized, it interacts with the active

Supervisor Engine only to receive incremental changes to the configuration files as they occur. You cannot enter CLI commands on the redundant Supervisor Engine. Synchronization of the startup configuration file is enabled by default in RPR+ mode.

Continue reading here: Problem Using Proxy ARP

Was this article helpful?

0 0