Release Notes for Cisco Industrial Network Director, Release 1.3.x
Pre-Configuration Requirements for IE Switches
Requirements for ALL IE Switches Running Cisco IOS
Configuration Required for Discovery and Management of Cisco IOS
Device Manager Configuration Required for Discovery and Management of IE1000 Switches
Bootstrap Configuration for IE Switches
Bootstrap Configuration for IE 1000 Switches
Last Updated: February 12, 2017
First Published: December 1, 2017
This release note contains the latest information about using Release 1.3.x of the Cisco Industrial Network Director (IND) application that supports configuration and management of Industrial Ethernet switches.
The IND application provides three types of Online Help (OLH): Context-Sensitive Help, Embedded Help such as the Guided Tours, and Tooltips.
This document uses the following conventions.
Note: Means reader take note. Notes contain helpful suggestions or references to material not covered in the manual.
Cisco Industrial Network Director provides operations teams an easily-integrated system delivering increased operator and technician productivity through streamlined network monitoring and rapid troubleshooting. IND is part of a comprehensive IoT solution from Cisco:
■Easy-to-adopt network management system purpose-built for industrial applications that leverages the full capabilities of the Cisco Industrial Ethernet product family to make the network accessible to non-IT operations personnel.
■Creates a dynamic integrated topology of automation and networking assets using industrial protocol (BACnet/IP, CIP, Modbus, PROFINET) discovery to provide a common framework for plant floor and plant IT personnel to monitor and troubleshoot the network and quickly recover from unplanned downtime.
■Rich APIs allow for easy integration of network information into existing industrial asset management systems and allow customers and system integrators to build dashboards customized to meet specific monitoring and accounting needs.
Cisco IND Features and Benefits
■Purpose-built user experience for non-IT operations personnel - Rapid adoption by operations teams for improved productivity.
■Targeted discovery of plant floor network assets customized for industrial environments – Ensures that automation devices connected to the network are not affected by discovery process.
■Automation endpoint discovery using industrial protocols, including PROFINET, CIP, BACnet/IP, and Modbus Complete automation infrastructure inventory, not solely network inventory details.
■Optimized alarm management with real-time alerting of network events and reporting of effects to automation assets – Allows for operations and plant IT team to consume network events in context of the industrial process to simplify troubleshooting issues.
■Real-time monitoring of Supported device metrics, traffic statistics, and network infrastructure status – Increased visibility of network health for the operations team and reduced unplanned downtime.
■Comprehensive RESTful APIs for integration with automation applications and control systems – Rapid adoption and integration with existing systems and customization by system integrators.
■Role-based access control with customizable permission mapping – Restrict system access to authorized users on a per feature basis.
■Detailed audit trails for operational visibility of network changes, additions, and modifications – Record user actions on network devices for change management.
■Search capability integrated with major functions - Easily locate functionality and mine for information.
■Cisco Active Advisor - Free cloud-based service that provides essential network life cycle information to make sure security and product updates are current.
■Guided tours - Step-by-step guidance to maximize productivity and ease adoption.
In this release of the product, there are four primary functions supported:
Release 1.3.x supports the following new IND features and enhancements summarized in New Features in IND 1.3.x.
Each IND installation (including upgrades) generates a different self-signed certificate. |
|||
Cisco Platform Exchange Grid (pxGrid), allows multiple security products to share data and work together. This open, scalable, and IETF standards-driven platform helps you automate security to get answers and contain threats faster. Cisco Identity Services Engine (ISE) is a network administration product that enables the creation and enforcement of security and access policies for endpoint devices connected to the company's routers and switches. Integrating pxGrid with IND allows IND to share endpoint information available in the IND inventory with ISE. |
|||
You can upload Industrial Ethernet (IE) software images that you associate with a Plug and Play (PnP) profile. You can also delete images from this page. |
|||
The Unclaimed Devices page has a Locate button for a device in table or card view. Clicking Locate activates the Locate Switch feature to identify unclaimed devices. When Locate Switch is enabled, the switch LEDs blink alternately green and red (LEDs that are in one color blink) to provide a visual indication of the switch's location. |
|||
■Supported: Devices supported by Device Packs (Currently, Industrial Ethernet switches are the only Supported Device types) ■Other: Devices such as clients that are not supported by Device Packs and are identified by their protocol such as: BACnet, CIP (user-defined), Modbus, PROFINET, SNMP, or Unknown Note: The previously supported Device Category, Client, is now part of the Other category. Note: Unknown protocols display only common attributes such as ipAddress, macAddress (optional), or vendor (optional). |
|||
Support for three Device States: ■Licensed: Continued support for this state. No changes. –A supported device which has a valid license, is actively monitored (information polling, alarms, telemetry) and has its rich information collected. ■Unlicensed (includes former NEW and DECOMMISSIONED states) –No device monitoring is performed on devices in an UNLICENSED STATE. –A device in an UNLICENSED state also does not have a license associated with it. |
|||
Integrated DHCP server allows for easier deployment of Industrial Switches within networks. |
|||
Allows discovery of BACnet/IP clients. BACnet devices are displayed under Other Devices. |
|||
Allows discovery of Modbus TCP clients. Modbus devices are displayed under Other Devices. |
|||
■Upload and upgrade of.tar or.bin images—Allows you to associate multiple.tar images with a single Profile and deploy that image to a device by defining the device type. Design > Plug and Play > Profiles ■Locate Switch for Unclaimed Devices—Clicking the Locate button for a device in table or card view activates the Locate Switch feature to identify unclaimed devices. When Locate Switch is enabled, the switch LEDs blink alternately green and red (LEDs that are in one color blink) to provide a visual indication of the switch's location. Design > Plug and Play > Unclaimed Devices ■DHCP Helper—Assigns a temporary DHCP IP address to a device so it can contact the Plug-and-Play server. |
|||
Cisco Universal IOS images supported: ■Cisco IOS Release 15.2(4)EC2(ED) Note: See Limitations and Restrictions for image limitations. The device pack supports the following Cisco and Rockwell Automation/Allen-Bradley platforms: Note: IND only supports PROFINET clients on IE 1000. Rockwell Automation/Allen-Bradley platforms: ■Stratix 8000/8300 Modular Managed Ethernet Switches ■Stratix 5700 Industrial Managed Ethernet Switches ■Stratix 5700 Industrial Ethernet Switches ■Stratix 5410 Industrial Distribution Switches |
The Cisco Industrial Network Director is licensed on a per-device, term subscription basis and supports two licensing models. For details on the supported lND licenses, refer to the:
The following information describes the CLI configuration required for IND to discover a Supported Device and transition the device from UNLICENSED to LICENSED state in secure mode.
■For IE switches running Cisco IOS, refer to Requirements for ALL IE Switches Running Cisco IOS
■For IE1000 switches, refer to Device Manager Configuration Required for Discovery and Management of IE 1000 Switches
■Configuration Required for Discovery and Management of Cisco IOS
1. Login to the IE 1000 Device Manager.
2. Leave the username field blank and enter cisco as password.
4. Create Device Access User and use the same in Access Profile on IND.
5. Configure SNMP community string for Read Only (ro):
a. Choose Configure > SNMP. Click OK in the pop-up windows to confirm enabling SNMP.
b. Check the check box to enable SNMP Mode globally. Click Submit
6. Select Community Strings tab. Add a public Community String read only access. (By default, this is a Read Only (ro) string)
a. Select the Users tab and add an snmpv3 user with name, security level, authentication protocol, authentication password, privacy protocol, and privacy password. Click OK.
b Select the Group tab, select the created user, and specify the group name. Click OK.
7. Choose Admin > Access Management.
a. Check the check box to enable either SSH or Telnet. (This option determines how the IE1000 communicates with IND)
The system pushes the following configuration when you move the device to the Licensed state in the system:
The installation procedure for IND is described in the Installation Guide for Industrial Network Director for Release 1.3.x.
IND Device Packs can only be installed with an IND application that has a matching version number, and the release number must be the same or greater than the IND release number.
For example, in release 1.3.0-365, 1.3.0 is the version number and 365 is the release number.
A new Device Pack must be version 1.3.0 and the release must be 365 or higher.
For Device Pack installation steps, refer to the Installation Guide for Cisco Industrial Network Director, Release 1.3.x.
Please note the following information about Cisco IOS software and PID support on IND.
The following IE 2000 PIDs are not supported by IND 1.1.x and are not supported by IND 1.1.0-x Device Packs:
Cisco recommends that you review this section before you begin working with IoT IND. These are known limitations that will not be fixed, and there is not always a workaround for these issues. Some features might not work as documented, and some features might be affected by recent changes to the software.
■PnP process fails intermittently in Cisco IOS Release 15.2(6)E0a.
■A PnP Service Error 1410 occurs in Cisco IOS Release 15.2(6)E0a due to AAA command not working (CSCvg64039).
■A crash occurs on IE 2000 and Stratix 5700 devices with IOS 15.2(6)E0a if the PnP process is enabled using DHCP option 43 (CSCvg72151).
This section presents open caveats in this release and information on using the Bug Search Tool to view details on those caveats.
■Accessing the Bug Search Tool
The following caveats are resolved in IND release version 1.3.1-5 (bug fix only release).
PnP profile: Template variables having space are not displayed correctly during Edit & Claim |
|
PnP Profile form - example for device list is in the form of IP Address |
|
You can use the Bug Search Tool to find information about caveats for this release, including a description of the problems and available workarounds. The Bug Search Tool lists both open and resolved caveats.
To access the Bug Search Tool, you need the following items:
■Cisco.com user ID and password
To access the Bug Search Tool, use the following URL: https://tools.cisco.com/bugsearch/search
To search using a specific bug ID, use the following URL: https://tools.cisco.com/bugsearch/bug/ <BUGID>
Installation Guide for Industrial Network Director Application for Release 1.3.x at:
http://www.cisco.com/c/en/us/support/cloud-systems-management/industrial-network-director/tsd-products-support-series-home.html
Find documentation for the Cisco Industrial Ethernet Switches at: (select the link for the relevant switch to access user guide)
http://www.cisco.com/c/en/us/products/switches/industrial-ethernet-switches/index.html
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)