Cisco APIC Installation and ACI Upgrade and Downgrade Guide

PDF

Cisco APIC Installation and ACI Upgrade and Downgrade Guide

Install the Cisco APIC software using virtual media

Want to summarize with AI?

Log in

This topic explains how to install or upgrade the Cisco APIC software using virtual media (vMedia), outlining the required steps and important considerations for a successful installation process.


  • Installation or upgrade of Cisco APIC software can be performed using virtual media (vMedia).

  • The process involves preparing the CIMC, obtaining the correct ISO image, and following a sequence of steps to ensure a reliable installation.

  • Special attention is required for mounting the ISO and responding to installer prompts for optimal speed and compatibility.

High-level installation steps and key considerations

The following steps outline the process for installing or upgrading Cisco APIC software using virtual media:

  • Upgrade the Cisco Integrated Management Controller (CIMC) software, if necessary.

  • Obtain the relevant Cisco APIC .iso image from Cisco.com .

  • Access the CIMC web interface for the controller.

    Note

    For detailed instructions on accessing the CIMC and managing virtual media, see the CIMC Configuration Guide for your controller's version of CIMC software (1.5 or 2.0).

  • Mount the .iso image using the CIMC-mapped vDVD functionality. Do not use the vKVM-mapped vDVD feature, which is not reliable for large images and is not supported on Cisco APIC.

  • Boot or power cycle the controller.

  • During the boot process, press F6 to select Cisco CIMC-Mapped vDVD as the one-time boot device. You may be required to enter the BIOS password. The default password is password .

  • Follow the onscreen instructions to install the Cisco APIC software.

    Note

    To enable a significant speedup in install time, provide the URL to the ISO image a second time after the installer starts. This speedup supports both HTTP and HTTPS, but does not support user/password authentication.

    To skip the speedup process and enable user/password authentication, use the following process:

    • For pre-Cisco APIC 6.0(2) releases:

      The console prints the prompt: "To speed up the install, enter the ISO URL:". If no input is provided after 10 minutes, the installer will continue with the slower path of reading the ISO contents through the CIMC vMedia mapping. Pressing Enter during the 10 minute wait period will immediately continue with the slower path installation process. Pressing Enter after the 10 minute wait period has no effect.

    • For Cisco APIC 6.0.(2):

      The console prints the prompt: "To speed up the install, enter iso url. Type 'skip' to use local media:". This prompt requires an input. You must provide either the URL or the word 'skip', otherwise it will wait indefinitely.

    • For all Cisco APIC versions:

      If you have skipped the speedup, no further input is required. If you have provided an ISO URL, you will also need to provide the host networking configuration to bring up an interface with connectivity to the host serving the ISO. Answer the prompts by choosing either DHCP , if available, or Static , then select the appropriate interface, and answer further prompts as necessary. At this point the installer will download the ISO completely and install with no further input required.


Upgrade the CIMC software

Before you begin

  • Review the information provided in the Cisco APIC Release Notes and confirm which CIMC software image to use for the upgrade. The Cisco APIC Release Notes are available on the APIC documentation page .

  • Obtain the software image from the Software Download site .

  • Confirm that the MD5 checksum of the image matches the one published on Cisco.com.

  • Allow for the appropriate amount of time for the upgrade. The time needed for the process of upgrading a CIMC version varies, based on the speed of the link between the local machine and the UCS-C chassis, and the source/target software image, as well as other internal component versions.

  • Changing the CIMC version might also require changes to the Internet browser and Java software version to run the vKVM.

Note

Upgrading the CIMC version does not affect the production network as the Cisco APIC s are not in the data path of the traffic. Also, you do not have to decommission the Cisco APIC s when upgrading the CIMC software.

Note

Starting with Cisco APIC release 6.2(1), you can upgrade Cisco APIC CIMC through APIC instead of separately logging into CIMC. See Upgrade or downgrade the Cisco APIC CIMC from releases 6.2 or later for details.

If you upgrade the Cisco APIC software in the Cisco ACI fabric, you might also have to upgrade the version of CIMC that is running on your fabric. Therefore, we recommend that you check the appropriate Cisco APIC Release Notes for the list of the supported CIMC software versions for each Cisco APIC release.

In order to upgrade the CIMC software, you must first determine the type of UCS C Series server that you have for the Cisco APIC s in your fabric.

APIC Platform Corresponding UCS Platform Description
APIC-SERVER-M1 UCS-C220-M3 Cluster of three Cisco APIC first-generation controllers, with a medium-sized CPU, hard drive, and memory configurations for up to 1000 edge ports.
APIC-SERVER-M2 UCS-C220-M4 Cluster of three Cisco APIC second-generation controllers, with a medium-sized CPU, hard drive, and memory configurations for up to 1000 edge ports.
APIC-SERVER-M3 UCS-C220-M5 Cluster of three Cisco APIC second-generation controllers, with a medium-sized CPU, hard drive, and memory configurations for up to 1000 edge ports.
APIC-SERVER-M4 UCS-C225-M6 Cluster of three Cisco APIC second-generation controllers, with a medium-sized CPU, SSD, and memory configurations for up to 1000 edge ports.
APIC-SERVER-L1 UCS-C220-M3 Cluster of three Cisco APIC first-generation controllers, with a large-sized CPU, hard drive, and memory configurations for more than 1000 edge ports.
APIC-SERVER-L2 UCS-C220-M4 Cluster of three Cisco APIC second-generation controllers, with a large-sized CPU, hard drive, and memory configurations for more than 1000 edge ports.
APIC-SERVER-L3 UCS-C220-M5 Cluster of three Cisco APIC second-generation controllers, with a large-sized CPU, hard drive, and memory configurations for more than 1000 edge ports.
APIC-SERVER-L4 UCS-C225-M6 Cluster of three Cisco APIC second-generation controllers, with a large-sized CPU, SSD/NVME, and memory configurations for more than 1000 edge ports.
APIC-SERVER-G5 UCS-C225-M8 Cluster of three Cisco APIC second-generation controllers, with a large-sized CPU, NVME, and memory configurations for any size.

These procedures describe how to upgrade the Cisco APIC CIMC using the Cisco Host Upgrade Utility (HUU). Full instructions for upgrading software using the HUU are provided in Upgrading the Firmware on a Cisco UCS C-Series Server Using the HUU .

Procedure

  Command or Action Purpose
1.

Log in to the CIMC using the CIMC credentials.

Note that the CIMC credentials may be different from the Cisco APIC credentials.

2.

Determine the model of UCS platform for your Cisco APIC through the CIMC GUI.

3.

Locate the appropriate HUU .iso image at https://software.cisco.com/download .

4.

Go to the Recommended Cisco APIC and Cisco Nexus 9000 Series ACI-Mode Switches Releases document and locate the row that contains the appropriate entry for your UCS platform and APIC software release.

Keep in mind that the UCS version shown in the table might not be the latest version of CIMC software, based on corresponding APIC release.

5.

Compare the information from the two sources to verify that you are downloading the correct version of the HUU .iso image.

If you find conflicting information between the two sources, use the information provided in the Recommended Cisco APIC and Cisco Nexus 9000 Series ACI-Mode Switches Releases document as the final word on the correct version of the HUU .iso image for your UCS platform and APIC software release.
6.

Download the appropriate HUU .iso image from the https://software.cisco.com/download site.

7.

Launch the KVM console from CIMC GUI.

Note

If you are having problems opening the KVM console, this is generally an issue with your Java version. Review the information in the Cisco APIC Release Notes for your CIMC version to learn the different workarounds available.

8.

In the KVM console, click Virtual Media > Activate Virtual Devices and accept the session.

9.

Click Virtual Media > Map CD/DVD and navigate to the downloaded HUU .iso image on your PC.

10.

Select the downloaded HUU .iso image, then click Map Device to map the downloaded ISO on your PC.

11.

Click Macros > Static Macros > Ctrl-Alt-Del to reboot the server.

If you are not able to reboot the server using this option, click Power > Power cycle System to perform a cold reboot instead.

12.

Press F6 to enter the boot menu so that you can select the mapped DVD that you want to boot from.

You can also create a user-defined macro to perform this action, if you are using a Remote Desktop application, by selecting Macros > User Defined Macros > F6 .

13.

When prompted, enter the password.

The default password is password .

14.

When prompted to select the boot device, select the Cisco vKVM-Mapped vDVD option.

15.

Wait for the process to complete, then accept the terms and conditions when prompted.

It will take around 10-15 minutes for the ISO to be extracted by the HUU, then another 15-20 minutes to copy the firmware and other tools.

16.

Make the appropriate selection in the HUU screen, when it appears.

We recommend that you select the Update All option to update all the firmware for all components.

17.

If you see a pop-up asking if you want to enable Cisco IMC Secure Boot, select No for that option.

Refer to the "Introduction to Cisco IMC Secure Boot" section in the Cisco UCS C-Series Servers Integrated Management Controller CLI Configuration Guide, Release 4.0 document for more information.

18.

Monitor the progress of the updates using the information provided in the Update Status column in the HUU.

19.

Once you see a status of PASS for each component, click Exit to reboot the server.

When the server reboots, you will be pushed out of the CIMC GUI. You will need to log back into the CIMC and verify the upgrade has completed successfully.

You can verify the upgrade was completed successfully through the GUI or by booting up the CIMC HUU and selecting Last Update Verify to ensure that all of the components passed the upgrade successfully.


Install the Cisco APIC software using the CIMC virtual media

Use this procedure to install the Cisco APIC software using Cisco Integrated Management Controller (CIMC) Virtual Media.

Note

You will open two console windows in these procedures:

  • vKVM console

  • Serial over LAN (SOL) console

You will be flipping back and forth between the two console windows, entering certain commands in one or the other console window for most of the steps in this procedure.

Before you begin

Review the information in Upgrade the CIMC software to determine if you should upgrade your Cisco Integrated Management Controller (CIMC) software before you begin the procedures in this section.

  • APIC -M4/L4 servers must be configured with a CIMC connection.

  • The Cisco APIC ISO must be available on an HTTP server reachable from the APIC -M4/L4 Server CIMC management interface and the OOB management interface.

  • Obtain the relevant Cisco APIC .iso image from Cisco.com and copy the .iso image to the HTTP server.

Procedure

1.

Access the vKVM console:

  1. Open the Cisco Integrated Management Controller (CIMC) GUI for the controller.

  2. For an APIC -M1, M2, M3, L1, L2, or L3 server, from the CIMC GUI, choose Server > Summary > Launch KVM , then select either Java based KVM or HTML based KVM to access the KVM console.

    We recommend using the Java based KVM option whenever possible, because it is a more reliable option for larger-sized files.

  3. For an APIC -M4/L4 server, from the CIMC GUI, choose Server > Summary > Launch vKVM to access the HTTP-based vKVM console.

2.

Access the Serial over LAN (SOL) console :

  1. From a terminal window, log in to the CIMC console:

    
                                    # 
                                    
                                        ssh admin@
                                        cimc_ip
                                    
                                

    Where cimc_ip is the CIMC IP address. For example:

    
                                    # 
                                    ssh admin@192.0.2.1
    admin@192.0.2.1's password: 
    system#
                                
  2. Change the scope to virtual media:

    
                                    system# 
                                    scope vmedia
    system /vmedia #
                                
  3. Map the .iso image to the HTTP server:

    
                                    system /vmedia # 
                                    
                                        map-www 
                                        volume_name
                                         http://
                                        http_server_ip_and_path
                                        iso_file_name
                                    
                                

    Where:

    • volume_name is the name of the volume.

    • http_server_ip_and_path is the IP address of the HTTP server and the path to the .iso file location.

    • iso_filename is the name of the .iso file.

    Note that there is a space between the http_server_ip_and_path and the iso_filename .

    For example:

    
                                    system /vmedia # 
                                    map-www apic http://198.51.100.1/home/images/ aci-apic-dk9.4.0.3d.iso
    Server username:
                                
  4. Check the mapping status:

    
                                    system /vmedia # 
                                    show mappings detail
                                

    The Map-Status should be shown as OK .

  5. Connect to SOL to monitor the installation process:

    
                                    system /vmedia # 
                                    connect host
                                
3.

From the KVM console : Choose Power > Power Cycle System (cold boot) to power cycle the controller.

4.

From the SOL console : Watch the screen during the boot process and prepare to press F6 at the appropriate moment to enter the boot selection menu.

You should first see the following messages as the boot process begins:


Cisco Systems, Inc.
Configuring and testing memory..
Configuring platform hardware...
...

System bootup messages continue to appear, until the point where you should see the following screen:


...
Press <F2> Setup, <F6> Boot Menu, <F7> Diagnostics, <F8> Cisco IMC COnfiguration, <F12> Network Boot
5.

From the SOL console : When you see the message above, press F6 to enter the boot selection menu.

You should see Entering boot selection menu... if you were able to press F6 at the appropriate moment. If you miss your opportunity and were not able to press F6 at the appropriate moment, go back to Step 3 to power cycle the controller and repeat the process until you are able to press F6 to enter the boot selection menu.

6.

From the SOL console : At the boot selection menu, select the Cisco CIMC-Mapped vDVD1.22 option as the one-time boot device.


/------------------------------------\
| Please select boot device:         |
|------------------------------------|
| (Bus 05 Dev 00)PCI RAID Adapter    |
| UNIGEN PHF16H0CM1-DTE PMAP         |
| Cisco vKVM-Mapped vHDD1.22         |
| Cisco CIMC-Mapped vHDD1.22         |
| Cisco vKVM-Mapped vDVD1.22         |
| 
                        Cisco CIMC-Mapped vDVD1.22
                                 |
| Cisco vKVM-Mapped vFDD1.22         |
| UEFI: Built-in EFI Shell           |
| IBA GE Slot 0100 v1585             |
| IBA GE Slot 0101 v1585             |
| Enter Setup                        |
|------------------------------------|
|    ^ and v to move selection       |
|    ENTER to select boot device     |
|     ESC to boot using defaults     |
\------------------------------------/
                    

You might also have to enter the BIOS password. The default password is password .

7.

From the SOL console : Enter the following:

  1. Determine if you want to enter the ISO URL to speed up the installation process.

    During the boot-up process, you might see the following message:

    To speed up the install, enter iso url in next ten minutes:

    You have two options at this stage:

    • Enter the ISO URL: This option will make the installation process go faster. Following is an example HTTP URL that you might enter here:

      http://10.75.61.1/aci-apic-dk9.4.2.1j.iso

      If you choose this option, you will be asked to provide the protocol type, as shown in the following example:

      
      ? 
                                              http://10.75.61.1/aci-apic-dk9.4.2.1j.iso
      ++ awk -F '/|:' '{print $4}'
      + urlip=10.75.61.1
      + '[' -z http://10.75.61.1/aci-apic-dk9.4.2.1j.iso ']'
      + '[' -z 10.75.61.1 ']'
      + break
      + '[' -n http://10.75.61.1/aci-apic-dk9.4.2.1j.iso ']'
      + set +e
      + configured=0
      + '[' 0 -eq 0 ']'
      + echo 'Configuring network interface'
      Configuring network interface
      + echo 'type static, dhcp, bash for a shell to configure networking, or url to re-enter the url: '
                                          

      Choose the appropriate protocol type:

      • static: If you choose this option, you will be asked to enter the interface name, management IP address and gateway. Following is an example of how to find the correct management interface:

        
        ? 
                                                        static
        + case $ntype in
        + configure_static
        + echo 'Available interfaces'
        Available interfaces
        + ls -l /sys/class/net
        total 0
        lrwxrwxrwx. 1 root root 0 Sep 26 16:04 enp11s0 -> ../../devices/pci0000:00/0000:00:03.0/0000:06:00.0/0000:07:01.0/0000:09:00.0/0000:0a:00.0/0000:0b:00.0/net/enp11s0
        lrwxrwxrwx. 1 root root 0 Sep 26 16:04 enp12s0 -> ../../devices/pci0000:00/0000:00:03.0/0000:06:00.0/0000:07:01.0/0000:09:00.0/0000:0a:01.0/0000:0c:00.0/net/enp12s0
        lrwxrwxrwx. 1 root root 0 Sep 26 16:04 enp1s0f0 -> ../../devices/pci0000:00/0000:00:01.0/0000:01:00.0/net/enp1s0f0
        lrwxrwxrwx. 1 root root 0 Sep 26 16:04 enp1s0f1 -> ../../devices/pci0000:00/0000:00:01.0/0000:01:00.1/net/enp1s0f1
        lrwxrwxrwx. 1 root root 0 Sep 26 16:04 lo -> ../../devices/virtual/net/lo
        + read -p 'Interface to configure: ' interface
        Interface to configure:
        [anaconda] 1:main* 2:shell  3:log  4:storage-lo> Switch tab: Alt+Tab | Help: F1
                                                    

        In the output above, the network interface with the shorter pci numbering corresponds to the two Out-Of-Band management interfaces: enp1s0f0 (eth1-1) and enp1s0f1 (eth1-2). If both interfaces are cabled as they should be, you can select either of them. However, if only one interface has a cable connected to it, you must choose the interface that corresponds to the cabled port.

      • dhcp

      Also note that you do not have a space between the http_server_ip_and_path and the iso_filename for this ISO URL (for example, http://198.51.100.1/home/images/aci-apic-dk9.4.0.3d.iso ).

    • Do not enter the ISO URL: If you do not want to enter the ISO URL, the installation process starts after ten minutes. This option is not supported on Cisco APIC versions 5.3(x) , 6.0(2), and above.

    The system starts fetching the ISO at this point.

    
    + read -p 'Interface to configure: ' interface
    Interface to configure: enp1s0f0
    + read -p 'address: ' addr
    address: 10.75.39.72/24
    + read -p 'gateway: ' gw
    gateway: 10.75.39.254
    + ip addr add 10.75.39.72/24 dev enp1s0f0
    + ip link set enp1s0f0 up
    + ip route add default via 10.75.39.254
    ++ seq 1 2
    + for count in '$(seq 1 2)'
    + ping -c 1 10.75.61.1
    PING 10.75.61.1 (10.75.61.1) 56(84) bytes of data.
    64 bytes from 10.75.61.1: icmp_seq=1 ttl=125 time=0.875 ms
    --- 10.75.61.1 ping statistics ---
    1 packets transmitted, 1 received, 0% packet loss, time 0ms
    rtt min/avg/max/mdev = 0.875/0.875/0.875/0.000 ms
    + configured=1
    + break
    + '[' 1 -eq 0 ']'
    + echo 'Fetching http://10.75.61.1/aci-apic-dk9.4.2.1j.iso'
    Fetching http://10.75.61.1/aci-apic-dk9.4.2.1j.iso
    + wget -o /dev/null -O /tmp/cdrom.iso http://10.75.61.1/aci-apic-dk9.4.2.1j.iso
    

    You can track the status of the process by going to Tools > Stats in the KVM console .

  2. Wait until you see the message poweroff in the SOL console, then exit from SOL by pressing Ctrl and x ( Ctrl+x ).

  3. Change the scope to virtual media again:

    
                                    system# 
                                    scope vmedia
    system /vmedia #
                                
  4. Unmap the .iso image that you mapped in 2.c :

    
                                    system /vmedia # 
                                    
                                        unmap 
                                        volume_name
                                    
                                

    At the Save mapping prompt, enter yes if you want to save the mapping or no if you do not want to save the mapping. For example:

    
                                    system /vmedia # 
                                    unmap apic
    Save mapping? Enther 'yes' or 'no' to confirm (CTRL-C to cancel) → 
                                    yes
    system /vmedia # 
                                
  5. Connect back to SOL again:

    
                                    system /vmedia # 
                                    connect host
                                
8.

From the KVM console : Choose Power > Power on System to power on the controller.

9.

From the SOL console : Enter the following:

  1. Enter the options for the initial setup, such as fabric name, number of controllers, tunnel endpoint address pool, and infra VLAN ID to complete the installation process.