CiscoView Device Manager Version 1.1 for the Cisco® Catalyst® 6500 Series Switch is a device-management software application that resides on the switch and manages several Layer 2 and Layer 3 features for a single chassis. A task-based tool, CiscoView Device Manager eases the initial setup and deployment of end-to-end services across modules by offering configuration templates based on recommended best practices. It further enhances the user-friendliness of the Cisco Catalyst 6500 Series through graphical representation of VLANs, and by providing a single launch point for multiple module managers. CiscoView Device Manager is a free application with a small footprint that can easily be downloaded and installed on the supervisor-engine flash memory.
CiscoView Device Manager 1.1 for the Cisco Catalyst 6500 Series Switch includes the following new features:
• Support for the Cisco Content Switching Module (CSM) with SSL and the Cisco Catalyst 6500 Series Wireless LAN Services Module (WLSM)
• Support for the transparent firewall feature in Cisco Catalyst 6500 Series Firewall Services Module (FWSM)
• Setup of Virtual Routing and Forwarding (VRF) instances
KEY FEATURES AND BENEFITS
The Next Generation of Device-Embedded Solutions
Managing the Cisco Catalyst 6500 Series Switch requires a high level of command-line interface (CLI) awareness for users to completely control the versatility of all the features and services available. Some typical challenges faced by users include:
• Support of initial deployment of several services, such as wireless services, firewalls, content load balancing, and intrusion detection
• Complete "service deployment" instead of only "module configuration"
• Visualization of VLAN interconnectivity between services
CiscoView Device Manager for the Cisco Catalyst 6500 Series manages several Layer 2 and Layer 3 features on the Catalyst 6500 Series and helps users accomplish these tasks with ease. CiscoView Device Manager offers the following features:
• Easy-to-use graphical interface for VLAN visualization, monitoring, and port setup (Figure 1)
• Configuration based on templates and recommended best practices to simplify the initial setup of services
• Comprehensive end-to-end services setup using a single tool
• Setup of VRF instances
Graphical VLAN Visualization
CiscoView Device Manager makes it easier than was previously possible through the CLI to visualize the Cisco Catalyst 6500 "network-in-a-box."
Figure 1. The Home Page Gives Users a Graphical Snapshot of the Chassis Status
CiscoView Device Manager provides network and security operations personnel with a clear picture of the VLAN connectivity in a chassis. Representing individual modules within a chassis as nodes on a network topology map is useful to highlight security loopholes, such as VLANs being inadvertently configured to bypass firewalls. This view allows users a quick and easy way to troubleshoot such potential security issues with a more appropriate configuration. Port configuration, setup, and VLAN assignments are easy using this graphical interface. Configuration can be accomplished through a series of mouse clicks, significantly reducing the time required to complete the initial setup on the switch. CiscoView Device Manager will also help users add a separate VRF instance on the service topology map and connect this VRF instance to other services modules.
Initial Setup
CiscoView Device Manager facilitates initial configuration using wizards and dialog boxes (Figure 2).
Figure 2. Configuration Based on Templates and Recommended Practices
Users create configurations by responding to a series of questions in user-friendly wizards and dialog boxes, and CiscoView Device Manager designs the best-practice CLI configuration based on those responses. At the end of the process, users view the CLI command syntax created and decide whether to deploy the configurations to the chassis immediately or to save them for future editing.
CiscoView Device Manager includes the following templates for initial configuration:
• Wireless firewall---This scenario is used to secure wireless access to the inside network. Placing wireless-mobility groups inside their own dedicated VRF provides an effective way to segment wireless traffic. Each group's wireless traffic can then be forwarded to the firewall, which determines if it can be forwarded to the inside network (Figure 3).
Figure 3. Wireless-Firewall Template
• Firewall inside---This scenario typically is used in the Internet data center. Placing the Cisco Catalyst 6500 Series Multilayer Switch Feature Card (MSFC) outside the Cisco Catalyst 6500 Series Firewall Services Module (FWSM) makes it possible for the MSFC to perform routing toward the core network. The FWSM provides routing to the border routers and the demilitarized zone (DMZ).
• Firewall inside with Cisco Content Switching Module (CSM)---This scenario typically is used in intranet data centers. Placing the MSFC outside the Cisco Catalyst 6500 Series FWSM in the intranet data center means that the MSFC faces the core network. In this design, the default gateway for the servers is either the FWSM or the Cisco CSM.
• Firewall outside---This scenario typically is used in Internet data centers. Placing the Cisco Catalyst 6500 Series FWSM outside the MSFC in the Internet data center allows the MSFC to face the core network (Figure 4). In this design, the default gateway for the servers is the FWSM.
Figure 4. Firewall Outside with Cisco CSM Template
• Firewall outside with Cisco CSM---This scenario is usually used in Internet data centers. Placing the Cisco Catalyst 6500 Series FWSM outside the MSFC means that the MSFC performs routing toward the core network. The FWSM performs routing toward the border routers and the DMZ.
• VPN and firewall---This scenario usually is used to terminate secure connections to remote offices and telecommuters while providing the firewall function to the general public accessing an Internet server farm. The Cisco Catalyst 6500 Series FWSM is used to apply firewall policies to untrusted clients while the Cisco 7600/Catalyst 6500 IPSec VPN Services Module (VPNSM) provides secure access to the internal network (Figure 5).
Figure 5. VPN and Firewall Template
• VPN outside---This scenario is used when the Cisco 7600/Catalyst 6500 IPSec VPNSM serves as the head-end VPN termination platform for either remote access or enterprise customers. The VPNSM and Cisco Catalyst 6500 Series FWSM protect the internal and DMZ networks.
• MSFC and Cisco CSM---This scenario configures connectivity between the MSFC and Cisco CSM modules. The Cisco CSM provides load-balancing services for the server farm.
A custom setup mode is available that allows additional services to be specified, where VLANs can be created by drag-and-drop of lines between any modules on the topology map (Figure 6). CiscoView Device Manager intelligently detects VLANs being created between modules that should not be directly connected and cautions users against connecting them.
Figure 6. Custom VLAN Creation
End-to-End Setup Using a Single Tool
Users not familiar with the CLI can create complex end-to-end service configurations using the GUI tools in CiscoView Device Manager (Figure 7).
Figure 7. End-to-End Configuration Using GUI Tools
CiscoView Device Manager configures global parameters, such as spanning tree, banners, setting up connectivity to individual modules, and other chassis-level features. After the configurations are complete, users can launch the embedded managers for each of the modules (such as CiscoView Device Manager for the Secure Sockets Layer (SSL) module, Firewall Device Manager on the firewall module, etc.) for deeper module-specific configuration.
Providing a single launch point for the device managers for each module in a Cisco Catalyst 6500 Series chassis, CiscoView Device Manager makes configuring end-to-end services smooth, reducing error-prone tasks associated with using a CLI.
SYSTEM REQUIREMENTS
Table 1 lists the specifications for using CiscoView Device Manager for the Cisco Catalyst 6500 Series. Table 2 lists the Cisco IOS® Software releases supported by the CiscoView Device Manager.
Note: CiscoView Device Manager 1.1 for the Cisco Catalyst 6500 Series supports native-mode deployments only.
Table 3 and 4 list the Layer 2 features and the services modules supported by CiscoView Device Manager for the Cisco Catalyst 6500 Series.
Table 3. Layer 2 Features Supported
Feature
Functions
System
Hostname, IP address, domain name, default gateway, contact, uptime
Cisco Discovery Protocol
Enable and disable Cisco Discovery Protocol, Cisco Discovery Protocol timers such as hold time, Cisco Discovery Protocol packet rate, show Cisco Discovery Protocol neighbor information
Ports
Port types: Supports configuration of Ethernet, Fast Ethernet, Gigabit Ethernet (GE), 10 GE ports only; other port types are supported only in read-only mode
Basic port configuration: Speed, duplex mode, link negotiation, flow control, Unidirectional Link Detection Protocol
Supports bulk port configuration
VLAN
Supports configuration of Ethernet VLANs; supports bulk VLAN configuration; add, edit, and delete VLANs; and switch virtual interfaces
Spanning tree
Supports only Per-VLAN Spanning Tree Plus, global spanning tree parameters, per-VLAN and per-port spanning tree parameters; only global Spanning Tree Protocol parameters are supported for other Spanning Tree Protocol modes.
CiscoView Device Manager for the Cisco Catalyst 6500 Series Switch is part of the CiscoView Device Manager suite of device-embedded management applications. These management solutions are available as downloadable files from Cisco.com or as part of the purchase of a Cisco Catalyst 6500 Series Switch through regular Cisco sales and distribution channels worldwide.
Cisco Systems® offers a wide range of services programs to accelerate customer success. These innovative services programs are delivered through a unique combination of people, processes, tools, and partners, resulting in high levels of customer satisfaction. Cisco services help you to protect your network investment, optimize network operations, and prepare the network for new applications to extend network intelligence and the power of your business. For more information about Cisco services, see Cisco Technical Support Services or Cisco Advanced Services.
FOR MORE INFORMATION
For more information about the CiscoView Device Manager applications, visit http://www.cisco.com/go/cvdm or contact your local Cisco account representative or send an e-mail to the Product Marketing group at ciscoworks@cisco.com.