This document provides information about Crosswork Data Gateway 5.0.x for on-premise deployments, including features, compatibility information and updates.

Product Overview

Cisco Crosswork Data Gateway is a model-driven scalable data collection platform that enables real-time data collection from multiprotocol capable devices, thereby reducing the need for multiple collection points for multiple applications requiring data from the network.

Cisco Crosswork Data Gateway is not a standalone product and is expected to be used with Crosswork deployments. There is no separate software license required for Cisco Crosswork Data Gateway. Use of Cisco Crosswork Data Gateway to forward data to third-party destinations is only supported when using the Crosswork Data Gateway with Crosswork on-premise deployments.

What's New

This section lists the features delivered in Cisco Crosswork Data Gateway 5.0.

Table 1. New Features in Crosswork Data Gateway 5.0
Feature Description

Enhancement to stagger the SNMP and CLI collection jobs

For each collection task, the collectors add an initial skew based on a random 'seed'. This assists the collectors in spacing out the load by distributing poll requests rather than grouping them all on a single clock tick.

Additional language support

Crosswork now lets you change the language of the Crosswork UI to Japanese. The user-specific values such as device names and server names continue to be in English. To change the language, from the Log in screen, select your preferred language.

Enhancement to support the GNMI bundling feature by IOS XR release 7.8.1 and later 1

In IOS XR, gNMI bundling is implemented to stitch together several Update messages that are included in the Notification message of a SubscribeResponse. These messages are sent to the IOS XR device. To bundle the Update messages, you must enable bundling and specify the size of the message in the IOS XR device.

Ability to dynamically enable and disable the collectors1

Crosswork Data Gateway allows the administrator to enable and disable the data collection job on certain containers in the network. With this flexibility, you can regulate the load on the collection to monitor only the needed resources optimally and reduce the resource footprint.

Improvement to the security framework1

When adding a data destination, an additional security authentication layer is added to increase the security. In the Administration > Data Gateway Global Settings > Data Destinations window, you can choose the authentication process type as:

  • Mutual-Auth: Authenticates external server and the CDG collector after the CA certificate, and Intermediate certificate or Key is uploaded to the Crosswork UI.

  • Server-Auth: Authenticates external server and the CDG collector after the CA certificate is uploaded to the Crosswork UI.

Ability to configure multiple Syslog servers1

In the Day 0 configuration, you can configure many remote servers to use the same port and protocol. After the Day 1 configuration, you can modify the remote server settings using the interactive menu in the 5.0 release. You can customize the server IP, port, protocol, TLS peer name, and Syslog root certificate with this option.

When one of the servers becomes inaccessible, a standby server takes its place to ensure continuity. The objective of having numerous servers is to achieve high availability.

Support for predefined HA pool types 1

During the Crosswork Data Gateway pool creation, predefined pool types are introduced. The pool types are:

  • L2 Stretch: The pool in which the network devices connect to Crosswork Data Gateway instances that are part of a HA pool residing on a single IP subnet. The subnet can be intra-DC (Domain Controller) or extended inter-DC.

  • L3 with Load Balancer: The pool in which the network devices connect to Crosswork Data Gateway instances that reside across multiple different subnets which are part of the same HA pool. This configuration requires an external Network Load Balancer (NLB) to host a VIP towards the network devices while shielding the internal subnet addresses of the Crosswork Data Gateway HA pool.

    Note

     
    The L3 with Load Balancer pool type is supported only when you are creating a pool in the Amazon EC2 environment.

Additional operational alarms1

Additional alarms are introduced to send a notification when an exception occurs during the deployment stage.

Option to modify the interface address1

Crosswork Data Gateway allows you to modify the interfaces that are already associated with a data gateway instance after it has been installed. When Crosswork Data Gateway indicates IP address difficulties such as address conflicts or erroneous addresses, this may be required.

Reconfiguring an interface involves modifying the interface name, assigning it an IP address, and obtaining access to the security group that is linked to it.

Included the auto-configuration functionality to deploy Crosswork Data Gateway2

Auto-configuration feature discovers the missing configuration parameters and automatically introduces the required parameters to install Base VM. The auto-configuration approach defines only the essential parameters with default values in the Day 0 configuration.

The Dynamic Host Configuration Protocol (DHCP) framework used to communicate the configuration settings.

gNMI Collector Enhancements

Optimized the gNMI collector performance for increased scale.

Improvement to the way data is sent to gRPC-based destination1

Crosswork Data Gateway send the collected data to gRPC destinations following a data stream.

Improvements in the Data Gateway Management Page in the Cisco Crosswork UI1

Numerous improvements in the Data Gateway Management pages in the Cisco Crosswork UI (Administration > Data Gateway Management) to improve usability.

Ability to deploy multiple system devices packages1

A system device package is supplied through the application-specific manifest file as a simple JSON file whenever an application is installed or updated.

Cisco Element Management Functions (EMF), Crosswork Applications, and other applications can deploy multiple system device packages for each collector.

Protocol data collection1

Added customization options enable the user to choose either gNMI or SNMP protocols to be used for collecting interface state and statistics data.

Crosswork Data Gateway works with devices that support the OpenConfig data models.

Introduced the maintenance mode feature1

The maintenance mode feature allows a Crosswork Data Gateway VM to be taken offline without disrupting the data collection ability. The maintenance mode allows you to force a failover from a VM to a standby VM that resides within the same pool. To optimally use this feature, enter the maintenance mode before you perform maintenance or tuning procedures.

Provision to disable the SNMP trap check1

The Device Management > Network Devices window has a new check box. If you select it, Crosswork disables the SNMPv2 community string validation between the network device and Crosswork Data Gateway.

Deprecation of data collection using the NETCONF collector

Crosswork Data Gateway is announcing the deprecation of the Network Configuration Protocol (NETCONF)-based data collection from network devices from the Cisco Crosswork Network Controller 5.0 release.

Documentation

  • An Information Portal is now available for Crosswork Network Controller 5.0. Information is categorized per functional area, making it easy to find and easy to access.

  • The Cisco Crosswork Network Controller 5.0 Installation Guide covers installation of the cluster and installation of Crosswork applications on top of the infrastructure. This guide includes Cisco Crosswork Data Gateway installation.

  • The Cisco Crosswork Network Controller 5.0 Administration Guide covers setup and maintenance of the Crosswork system. There is no longer a Getting Started Guide for Cisco Crosswork Network Controller. This guide includes Cisco Crosswork Data Gateway and ZTP information.

  • The Cisco Crosswork Network Controller 5.0.x Solution Workflow Guide provides an overview of the solution and its supported use cases. It walks users step-by-step through various common usage scenarios to illustrate how users can work with the solution components to achieve the desired benefits.

1 For more information about these features, see the Cisco Crosswork Data Gateway section in Cisco Crosswork Network Controller 5.0 Administration Guide.

2 For more information about the auto-configuration features, see the Auto-configuration for Deploying Crosswork Data Gateway section in Cisco Crosswork Network Controller 5.0 Installation Guide.

Compatibility Information

Crosswork Data Gateway 5.0 supports deployment with Crosswork on-premise only.

The following table shows software requirements for the supported virtualization platforms along with the physical and network resource requirements needed to support the Crosswork Data Gateway.


Note


The values shown in the Table 1 are the defaults which we recommended using. Deviations from these values should not be made unless you are working with Cisco to determine the unique requirements of your deployment.


Crosswork Data Gateway 5.0 VM Requirements for Crosswork On-premise

Crosswork Data Gateway supports the following profiles for deployment with Crosswork on-premise:

  • On-Premise Standard (default): To deploy Crosswork Data Gateway with all Crosswork on-premise deployments except Crosswork Health Insights and Crosswork Service Health.

  • On-Premise Extended: To deploy Crosswork Data Gateway when Crosswork Health Insights and Crosswork Service Health are installed.


Attention


The On-Premise Standard with Extra Resources profile is available as a limited-availability feature and must not be used while deploying Crosswork Data Gateway in your data center.


Table 2. Crosswork Data Gateway 5.0 VM Requirements for Crosswork on-premise deployments

Requirement

Description

Data Center

Hypervisor and vCenter supported

  • VMware vCenter Server 6.7 (Update 3g or later) and ESXi 6.7 (Update 1).

  • VMware vCenter Server 7.0 and ESXi 7.0.

Amazon EC2

  • Crosswork Data Gateway deployment and operations have been validated on the current publicly available Amazon platform.

For memory, vCPUs, and storage requirements for the data center, see Installation Requirements in Cisco Crosswork Network Controller 5.0 Installation Guide.

Interfaces

Minimum: 1

Maximum: 3

Crosswork Data Gateway can be deployed with either 1, 2, or 3 interfaces as per the combinations below:

Note

 

If you use one interface on your Crosswork cluster, you must use only one interface on the Crosswork Data Gateway. If you use two interfaces on your Crosswork Cluster, then you can use two or three interfaces on the Crosswork Data Gateway as per your network requirements.

No. of NICs

vNIC0

vNIC1

vNIC2

1
  • Management Traffic

  • Control/Data Traffic

  • Device Access Traffic

2
  • Management Traffic

  • Control/Data Traffic

  • Device Access Traffic

3
  • Management Traffic

  • Control/Data Traffic

  • Device Access Traffic

  • Management traffic: for accessing the Interactive Console and passing the Control/Data information between servers (for example, a Crosswork application to Crosswork Data Gateway).

  • Control/Data traffic: for data and configuration transfer between Crosswork Data Gateway and Crosswork deployments and other external data destinations.

  • Device access traffic: for device access and data collection.

Note

 

Due to security policies, traffic from subnets of a vNIC received on other vNICs is dropped. For example, in a 3 vNIC model setup, all device traffic (incoming and outgoing) must be routed through vNIC2. Crosswork Data Gateway drops device traffic received over vNIC0 and vNIC1.

IP Addresses

1 or 2 IPv4 or IPv6 addresses based on the number of interfaces you choose to use. Including one additional IP address to be used as the Virtual IP (VIP) address.

Note

 

Crosswork does not support dual stack configurations. Therefore, ALL addresses for the environment must be either IPv4 or IPv6.

In a 3-NIC deployment, you will need to provide an IP address for Management interface (vNIC0) and Control/Data interface (vNIC1) only during installation. A virtual IP address for Device Access Traffic (vNIC2) is assigned when you create a Crosswork Data Gateway pool as explained in the Create a Crosswork Data Gateway Pool section in Cisco Crosswork Network Controller 5.0 Administration Guide.

NTP Servers

The IPv4 or IPv6 addresses or host names of the NTP servers you plan to use. If you want to enter multiple NTP servers, separate them with spaces. These should be the same NTP servers you use to synchronize devices, clients, and servers across your network. Verify that the NTP IP address or host name is reachable on the network or installation will fail.

Also, the ESXi hosts that will run the Crosswork application and Crosswork Data Gateway VM must have NTP configured, or the initial handshake may fail with "certificate not valid" errors.

DNS Servers

The IPv4 or IPv6 addresses of the DNS servers you plan to use. These should be the same DNS servers you use to resolve host names across your network. Confirm that the DNS servers are reachable on the network before attempting installation. The installation will fail if the servers cannot be reached.

DNS Search Domain

The search domain you want to use with the DNS servers, for example, cisco.com. You can have only one search domain.

(optional) Proxy Server

URL of an optional management network proxy server if your environment.

If your environment requires an HTTP or HTTPS proxy in order to access URLs on the public Internet, you must configure a proxy server in order for the Cisco Crosswork Data Gateway to successfully connect to Cisco Crosswork

(optional) Syslog Sever

The hostname or IPv4 or IPv6 address of an external syslog server.

(optional) Auditd Server

The hostname or IPv4 or IPv6 address of an external auditd server.

Tested Cisco OS

The following table lists the software versions with which Cisco Crosswork Data Gateway was tested.


Note


Cisco Crosswork Data Gateway allows you to expand device coverage by means of custom packages (see the Manage Custom Device Packages section in Cisco Crosswork Network Controller 5.0 Administration Guide.


Cisco Crosswork Data Gateway 5.0 for on-premise applications is compatible with all of the IOS and NX-OS versions listed in the table below.

Table 3. Cisco Crosswork Data Gateway 5.0 Support for IOS/NX-OS and Device Data Collection Protocols
OS Version CLI gNMI1 MDT2 SNMP1 Syslog

IOS-XR

7.1.2
7.2.1
7.3.1
7.3.2
7.4.1
7.5.2
7.7.1

IOS-XE

16.12.3
17.3.1
17.4.1
17.5.1
17.6.1
17.7.1
17.8.1

NX-OS

9.2.1
9.3.1
10.1
10.2

1 Third Party Devices: Crosswork Data Gateway can collect data from compatible third-party devices using SNMP or gNMI collectors. For information about deploying and validating non-Cisco collections, see Cisco Devnet or contact Cisco Professional Services.

2 Model-Driven Telemetry: For MDT configuration via Cisco NSO on IOS-XR, use NSO NED 7.40.1.

Product Documentation

An Information Portal is now available for Crosswork Network Controller 5.0. Information is categorized per functional area, making it easy to find and easy to access.

The following table lists the documentation available for Cisco Crosswork Data Gateway.

Document Title

What is included

Cisco Crosswork Data Gateway 5.0 Release Notes

This document.

Provides an overview of the product, compatibility information, and important information that should be considered before using the product.

Cisco Crosswork Network Controller 5.0 Installation Guide

Shared installation guide for all the Cisco Crosswork on-premise applications and their common infrastructure. Covers:

  • System requirements

  • Installation prerequisites

  • Installation instructions

  • Upgrade instructions

  • Uninstallation procedure

Cisco Crosswork Network Controller 5.0 Administration Guide

Shared administration guide for all the Cisco Crosswork on-premise applications and their common infrastructure. Covers:

  • Overview of Cisco Crosswork Data Gateway

  • Managing Cisco Crosswork Data Gateway VMs

  • Managing Cisco Crosswork Data Gateway Pools

  • Managing External Data Destinations

  • Managing Custom Packages

  • Collection jobs

  • Configuring Cisco Crosswork Data Gateway Base VM.

  • Monitoring Cisco Crosswork Data Gateway health

  • Troubleshooting

Open Source used in Cisco Crosswork Data Gateway 5.0

Lists of licenses and notices for open source software used.

API Documentation Advanced users can extend the Cisco Crosswork functionality using the APIs. API documentation is available on Cisco Devnet.

Related Product Documentation

You can access documentation for all Cisco Crosswork products at the Cisco Crosswork Network Automation home page on cisco.com.

Demos

If you are interested in seeing a demo of the Crosswork features and functions, please contact your Cisco account team, and they can arrange demos by leveraging our demo cloud resources.

Bugs

If you encounter problems while working with Cisco Crosswork, please check this list of open bugs. You can use the Cisco Bug Search Tool to search for a specific bug.

  1. Go to the Cisco Bug Search Tool.

  2. Enter your registered Cisco.com username and password, and click Log In.

    The Bug Search page opens.


    Note


    If you do not have a Cisco.com username and password, you can register here.


  3. To search for all Cisco Crosswork bugs, from the Product list select Cloud and Systems Management > Routing and Switching Management > Cisco Crosswork Network Automation and enter additional criteria (such as bug ID, problem description, a feature, or a product name) in the Search For field. Examples: "Data Gateway" or "CSCwc34821".

  4. When the search results are displayed, use the filter tools to narrow the results. You can filter the bugs by status, severity, and so on.


    Tip


    To export the results to a spreadsheet, click Export Results to Excel.

Security

Cisco takes great strides to ensure that all our products conform to the latest industry recommendations. We firmly believe that security is an end-to-end commitment and are here to help secure your entire environment. Please work with your Cisco account team to review the security profile of your network.

For details on how we validate our products, see Cisco Secure Products and Solutions and Cisco Security Advisories.

If you have questions or concerns regarding the security of any Cisco products, please open a case with the Cisco Customer Experience team and include details about the tool being used and any vulnerabilities it reports.

Accessibility Features

All product documents are accessible except for images, graphics and some charts. If you would like to receive the product documentation in audio format, braille, or large print, contact accessibility@cisco.com.

If any product document could not be converted to the accessible formats, please contact the Cisco Customer Experience team.

Scale Support

Crosswork Data Gateway (Standard deployment profile) is tested with up to 2000 devices integrated with Crosswork Network Controller running Crosswork Optimization Engine and Crosswork Active Topology. The number of Crosswork Data Gateway VMs required varies based on a combination of factors such as the number and type of collection jobs, the number of destinations data is forwarded to, and other variables. To determine if your configuration requires additional Crosswork Data Gateway VMs, see Monitor Crosswork Data Gateway Health and for information on how to add a Crosswork Data Gateway VM to the pool, see Attach Devices to a Crosswork Data Gateway.

Support and Downloads

The Cisco Support and Downloads website provides online resources to download documentation, software, and tools. Use these resources to install and configure the software and to troubleshoot and resolve technical issues with Cisco products and technologies.

Access to most tools on the Cisco Support and Downloads website requires a Cisco.com user ID and password.

For more information, see https://www.cisco.com/c/en/us/support/index.html.

Obtain Documentation and Submit a Service Request

For information on obtaining documentation, using the Cisco Bug Search Tool (BST), submitting a service request, and gathering additional information, see What’s New in Cisco Product Documentation.

To receive new and revised Cisco technical content directly to your desktop, you can subscribe to the Cisco Notification Tool.