Release Notes for Cisco Industrial Network Director, Release 1.6.x
Pre-Configuration Requirements for IE Switches
Requirements for ALL IE Switches Running Cisco IOS
Configuration Required for Discovery and Management of Cisco IOS
Device Manager Configuration Required for Discovery and Management of IE1000 Switches
Bootstrap Configuration for IE Switches
Bootstrap Configuration for IE 1000 Switches
These release notes contains the latest information about using Release 1.6.x of the Cisco Industrial Network Director (IND) application that supports configuration and management of Industrial Ethernet switches.
The IND application provides three types of Online Help (OLH): Context-Sensitive Help, Embedded Help such as the Guided Tours, and Tooltips.
This document uses the following conventions.
Note: Means reader take note. Notes contain helpful suggestions or references to material not covered in the manual.
Cisco Industrial Network Director provides operations teams in industrial networks an easily-integrated management system that delivers increased operator and technician productivity through streamlined network monitoring and rapid troubleshooting. IND is part of a comprehensive IoT solution from Cisco:
■Easy-to-adopt network management system purpose-built for industrial applications that leverages the full capabilities of the Cisco Industrial Ethernet product family to make the network accessible to non-IT operations personnel.
■Creates a dynamic integrated topology of automation and networking assets using industrial protocol (BACnet/IP, CIP, Modbus, PROFINET, OPC UA) discovery to provide a common framework for plant floor and plant IT personnel to monitor and troubleshoot the network and quickly recover from unplanned downtime.
■Rich APIs allow for easy integration of network information into existing industrial asset management systems and allow customers and system integrators to build dashboards customized to meet specific monitoring and accounting needs.
■Integration with existing systems and customization by system integrators.
■Role-based access control with customizable permission mapping – Restrict system access to authorized users on a per feature basis.
■Detailed Audit trails for operational visibility of network changes, additions, and modifications – Record user actions on network devices for change management.
■Search capability integrated with major functions - Easily locate functionality and mine for information.
■Cisco Active Advisor - Free cloud-based service that provides essential network life cycle information to make sure security and product updates are current.
■Guided tours - Step-by-step guidance to maximize productivity and ease adoption.
These Release Notes summarize the new features found within the four primary functions supported by IND:
Release 1.6.x supports the following new IND features and enhancements summarized in Features Supported in IND 1.6.0-438 and later.
The IND install process now allows you to select from two installation options based on the available storage available on your Microsoft Windows Operating System (OS): ■Regular Profile: Choose this option when your Windows OS system does meet the minimum system requirements specified in the Installation Guide for Cisco Industrial Network Director, Release 1.6.x ■Micro Profile: Choose this option when your Windows OS system does not meet system requirements noted in the Installation Guide for Cisco Industrial Network Director, Release 1.6.x |
Installation Guide for Cisco Industrial Network Director, Release 1.6.x |
|
New message for a CIP device such as a Discovered Bridge Device lets you know when to move the device to a licensed state: Move this device to licensed state to enable the following features: |
||
Upgrade or Downgrade a Cisco IOS software image on an |
After selecting the desired Cisco IOS software, you can initiate an upgrade or downgrade by selecting the Upgrade icon and confirming your software and IE switch (including IE 1000) selection in subsequent pages that display. Operate > Inventory > Device > Details Note: You can also perform this software image install on the Maintain > Software Images page. |
|
Allows you to monitor the DLR status of the Supervisor Module and Ring Nodes. To initiate this DLR monitoring capability, IND allows you to assign licenses to the Supervisor nodes (Stratix and non-Stratix nodes listed below). ■Rockwell Automation/Allen Bradley Stratix 5400 DLR Supported PIDs ■Rockwell Automation/Allen Bradley Stratix 5700 DLR Supported PIDs ■Rockwell Automation ControlLogix Chassis DLR Supported PIDs ■Rockwell Automation CompactLogix Chassis DLR Supported PIDs |
||
You can view the DLR ring path that connects all DLR member nodes by clicking on the badge that appears at the top of the Topology display. It does not show the link details. (Nodes and links shown in the topology represent information learned through either the CDP, LLDP or MAC address table.) The Ring number is obtained by the device. Click the Discover Topology button. Nodes and links shown in the topology represent information learned through either the CDP, LLDP or MAC address table. Note: To ensure an accurate Topology view, you must initiate a Topology Discovery when one of the two tasks noted below is performed. |
||
For Cisco IOS IE devices, feature allows you restore a backed up Startup Configuration of a switch to the Startup Configuration. Device reload occurs. For IE1000 devices, feature allows you restore a backed up Running Configuration of a switch. After a successful restore, the Running Configuration is saved to the Startup Configuration of a switch. |
||
Allows you to select the authentication mode for authenticating and authorizing IND users. A remote user is only granted access when both authentication and authorization are successful. |
||
A new page, Security Settings, allows.you to set the SSL Security Level (TLSv1.2, by default) for SSL communications such as Plug-n-Play (PnP) and Web UI services. Note: For non-SSL communications, the settings are: Strong (default setting) or Weak. Note: When PnP provisioning is running on IE switches running 15.2(4)EAx, the setting will remain set at “Certificate-Install_success state” since devices with this software version only use TLSv1.0 SSL. To proceed with PnP provisioning on an IE switch running 15.2(4)EAx software, you can change the Security Level in Security Settings page to ‘weak’ which will enable TLSv1.0, TLSv1.1 and TLSv1.2 SSL versions for SSL communications. |
||
Access to two Cisco Identity Services Engine (ISE) systems provides High Availability for Cisco Platform Exchange Grid (pxGrid) |
Cisco pxGrid (Platform Exchange Grid) allows multiple security products to share data and work together. This open, scalable, and IETF standards-driven platform helps you automate security to get answers and contain threats faster. IND can connect up to two Cisco ISE systems, each of which is selected from an available server pool, in a round robin fashion, to provide high-availability to pxGrid. Each of the ISE controllers has a different IP and hostname. Each of these IP and host names must be configured within IND pxGrid settings. Note: IND must be registered in Cisco Identity Services Engine (ISE) as a pxGrid node. Note: Endpoint information from IND is shared with Cisco Identity Services Engine (ISE) by integrating pxGrid in the IND application. |
Deploying Cisco Industrial Network Director with ISE using pxGrid |
IND allows you to select a single RADIUS server or multiple RADIUS servers. |
||
■Simple option allows you to define the following for servers: ■Advanced option includes all Simple options plus additional AAA settings (Retries, Timeout, Authentication Port). |
||
Cisco Releases 1.6 and 1.7 (Industrial Ethernet 1000 only) Cisco Universal IOS images supported: ■Cisco IOS Release 15.2(6)E2A, Cisco IOS Release 15.2(6)E2, Cisco IOS Release 15.2(6)E1, Cisco IOS Release 15.2(6)E0a ■Cisco IOS Release 15.2(5)E2,Cisco IOS Release 15.2(5)E1, Cisco IOS Release 15.2(5)E ■Cisco IOS Release 15.2(4)EC2(ED) ■Cisco IOS Release 15.2(4)EA5, Cisco IOS Release 15.2(4)EA2, Cisco IOS Release 15.2(4)EA1 ■Cisco IOS Release 15.2(3)E3, Cisco IOS Release 15.2(3)E2 Cisco Universal IOS XE images supported: Note: See Limitations and Restrictions for image limitations. The device pack supports the following Cisco and Rockwell Automation/Allen-Bradley platforms: ■Cisco IOS platforms supported: CGS 2520, IE 2000, IE 2000U, IE 3000, IE 3010, IE 4000, IE 4010 and IE 5000 ■Cisco IOS XE platforms supported: IE3200, IE 3300, Rockwell Automation/Allen-Bradley platforms: ■Stratix 8000/8300 Modular Managed Ethernet Switches ■Stratix 5800 Industrial Managed Ethernet Switches ■Stratix 5400 and 5700 Industrial Ethernet Switches |
The Cisco Industrial Network Director is licensed on a per-device, term subscription basis and supports two licensing models. For details on the supported lND licenses and PIDs for ordering purposes, refer to the: Cisco Industrial Network Director Data Sheet.
The following information describes the CLI configuration required for IND to discover a Supported Device and transition the device from UNLICENSED to LICENSED state in secure mode.
Note: In all configuration examples below, a Hashtag (#) precedes all comment text.
■For IE switches running Cisco IOS, refer to Requirements for ALL IE Switches Running Cisco IOS
■For IE1000 switches, refer to Device Manager Configuration Required for Discovery and Management of IE 1000 Switches
■Configuration Required for Discovery and Management of Cisco IOS
1. Login to the IE 1000 Device Manager.
2. Leave the username field blank and enter cisco as password.
4. Create Device Access User and use the same in Access Profile on IND.
5. Configure SNMP community string for Read Only (ro):
a. Choose Configure > SNMP. Click OK in the pop-up windows to confirm enabling SNMP.
b. Check the check box to enable SNMP Mode globally. Click Submit
6. Select Community Strings tab. Add a public Community String read only access. (By default, this is a Read Only (ro) string)
a. Select the Users tab and add an snmpv3 user with name, security level, authentication protocol, authentication password, privacy protocol, and privacy password. Click OK.
b Select the Group tab, select the created user, and specify the group name. Click OK.
7. Choose Admin > Access Management.
a. Check the check box to enable either SSH or Telnet. (This option determines how the IE1000 communicates with IND)
The system pushes the following configuration when you move the device to the Licensed state in the system:
Note: In the configuration script below, the {certificate key length} is obtained from the device access profile.
The installation procedure for IND is described in the Installation Guide for Industrial Network Director for Release 1.6.x.
IND Device Packs can only be installed with an IND application that has a matching version number, and the release number must be the same or greater than the IND release number.
For example, in release 1.6.x, 1.6 is the version number and x is the release number.
A new Device Pack must be version 1.6.x and the release must x value or higher.
Please note the following information about Windows OS, Cisco IOS software and PID support on IND.
Cisco recommends that you review this section before you begin working with IoT IND. These are known limitations that will not be fixed, and there is not always a workaround for these issues. Some features might not work as documented, and some features might be affected by recent changes to the software.
■pxGrid service needs to be registered again after the upgrade from 1.5 to 1.6 if Cisco ISE servers are in HA mode.
■PnP process is supported only on single-homed (Single IP) IND servers for Cisco IOS Release 15.2(6)E1.
■A PnP Service Error 1410 occurs in Cisco IOS Release 15.2(6)E0a due to AAA command not working (CSCvg64039)
■IE 5000: Horizontal Stacking is not supported. Stacked devices can be discovered on IND but cannot be licensed.
■IE2000/IE3000: Image upgrade is not supported without a SD Card through IND. For a successful image upgrade from IND, currently running images of Cisco IOS should be set to SD Flash on these product families. Device manager can be used to upgrade software images for devices with no SD Card.
This section presents open caveats in this release and information on using the Bug Search Tool to view details on those caveats.
■Accessing the Bug Search Tool
IND 1.6 Open Caveats displays open caveats for IND 1.6
Platform-related Open Caveats displays open caveats for Industrial Ethernet switches that may affect the functionality of IND 1.6.
You can use the Bug Search Tool to find information about caveats for this release, including a description of the problems and available workarounds. The Bug Search Tool lists both open and resolved caveats.
To access the Bug Search Tool, you need the following items:
■Cisco.com user ID and password
To access the Bug Search Tool, use the following URL: https://tools.cisco.com/bugsearch/search
To search using a specific bug ID, use the following URL: https://tools.cisco.com/bugsearch/bug/ <BUGID>
Installation Guide for Industrial Network Director Application for Release 1.6.x at:
http://www.cisco.com/c/en/us/support/cloud-systems-management/industrial-network-director/tsd-products-support-series-home.html
Find documentation for the Cisco Industrial Ethernet Switches at: (select the link for the relevant switch to access user guide)
http://www.cisco.com/c/en/us/products/switches/industrial-ethernet-switches/index.html