The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
This chapter contains the following sections:
Information About System-Level High Availability
The Cisco Nexus 1000V can be configured with a single Virtual Supervisor Module (VSM) or dual VSMs. The following table describes the HA supervisor roles for single and dual VSM operation.
The redundancy role indicates not only whether the VSM interacts with other VSMs, but also the module number it occupies. The following table shows the available HA roles for VSMs.
Independent of its role, the redundancy state of a VSM can be one of the following described in this table.
Redundancy State |
Description |
---|---|
Active |
Controls the system and is visible to the outside world. |
Standby |
Synchronizes its configuration with that of the active VSM so that it is continuously ready to take over in case of a failure or manual switchover. You cannot use Telnet or Secure Shell (SSH) protocols to communicate with the standby VSM. Instead, you can use the attach module command from the active VSM to access the standby VSM console. Only a subset of the CLI commands are available from the standby VSM console. |
The active and standby VSMs are in the operationally HA state and can automatically synchronize when the internal state of one supervisor module is Active with HA Standby and the internal state of the other supervisor module is HA Standby.
If the output of the show system redundancy command indicates that the operational redundancy mode of the active VSM is None, the active and standby VSMs are not yet synchronized. This example shows the VSM internal state of dual supervisors as observed in the output of the show system redundancy status command:
switch# show system redundancy status Redundancy role --------------- administrative: standalone operational: standalone Redundancy mode --------------- administrative: HA operational: None This supervisor (sup-1) ----------------------- Redundancy state: Active Supervisor state: Active Internal state: Active with no standby Other supervisor (sup-2) ------------------------ Redundancy state: Not present switch#
Information About VSM Restarts and Switchovers
In a system with only one supervisor, when all HA policies have been unsuccessful in restarting a service, the supervisor restarts. The supervisor and all services restart with no prior state information.
When a VSM fails in a system with dual supervisors, the system performs a switchover rather than a system restart in order to maintain a stateful operation. In some cases, a switchover might not be possible at the time of the failure. For example, if the standby VSM is not in a stable standby state, a restart rather than a switchover is performed.
A dual VSM configuration allows uninterrupted traffic forwarding with a stateful switchover (SSO) when a failure occurs in the VSM. The two VSMs operate in an active/standby capacity in which only one is active at any given time, while the other acts as a standby backup. The two VSMs constantly synchronize the state and configuration to provide a seamless and stateful switchover of most services if the active VSM fails.
A switchover occurs when the active supervisor fails (for example, if repeated failures occur in an essential service or if the system that is hosting the VSM fails).
A user-triggered switchover could occur (for example, if you need to perform maintenance tasks on the system hosting the active VSM).
An HA switchover has the following characteristics:
When a stable standby VSM detects that the active VSM has failed, it initiates a switchover and transitions to active. When a switchover begins, another switchover cannot be started until a stable standby VSM is available.
If a standby VSM that is not stable detects that the active VSM has failed, then, instead of initiating a switchover, it tries to restart the system.
Before you can initiate a manual switchover from the active to the standby VSM, the standby VSM must be stable.
Once you have verified that the standby VSM is stable, you can manually initiate a switchover.
Once a switchover process begins, another switchover process cannot be started until a stable standby VSM is available.
Although primary and secondary VSMs can reside in the same host, to improve redundancy, install them in separate hosts and, if possible, connect the VSMs to different upstream switches.
The console for the standby VSM is available by entering the module attach x command, but configuration is not allowed and many commands are restricted. Enter this command at the console of the active VSM.
You cannot use Telnet or Secure Shell (SSH) protocols to communicate with the standby VSM because the management interface IP is unconfigured until the VSM becomes active.
The active and standby VSMs must be on the same management subnet.
Configuring System-Level High Availability
The Cisco Nexus 1000V VSM software installation provides an opportunity for you to designate the role for each VSM. You can use this procedure to change that initial configuration.
Caution | Changing the role of a VSM can result in a conflict between the VSM pair. If a primary and secondary VSM see each other as active at the same time, the system resolves this problem by resetting the primary VSM. |
Use this procedure to change the role of a VSM to one of the following after it is already in service:
Before beginning this procedure, you must be logged in to the CLI in EXEC mode.
If you are changing a standalone VSM to a secondary VSM, be sure to first isolate it from the other VSM in the pair to prevent any interaction with the primary VSM during the change. Power the VM off from the SCVMM before reconnecting it as standby.
You must understand the following information:
switch# system redundancy role standalone switch# show system redundancy status Redundancy role --------------- administrative: standalone operational: standalone Redundancy mode --------------- administrative: HA operational: None This supervisor (sup-1) ----------------------- Redundancy state: Active Supervisor state: Active Internal state:Active with no standby Other supervisor (sup-2) ------------------------ Redundancy state: Not present switch#
Configuring a Switchover
Use one of the following commands to verify the configuration:
Command |
Purpose |
---|---|
show system redundancy status |
Displays the current redundancy status for the VSM(s). If the output indicates the following, then you can proceed with a system switchover, if needed: |
show module |
Displays information about all available VEMs and VSMs in the system. If the output indicates the following, then you can proceed with a system switchover, if needed: |
Be sure you know the following about manually switching the active VSM to a standby VSM:
A switchover can only be performed when two VSMs are functioning in the switch.
If the standby VSM is not in a stable state (ha-standby), then you cannot initiate a manual switchover. You will see the following error message:
Failed to switchover (standby not ready to takeover in vdc 1)
If a switchover does not complete successfully within 28 seconds, the supervisors will reset.
Logged in to the active VSM CLI in EXEC mode.
Completed the steps in the Verifying that a System is Ready for a Switchover section and have found the system to be ready for a switchover.
This example shows how to switch an active VSM to a standby VSM and displays the output that appears on the standby VSM as it becomes the active VSM.
switch# system switchover ---------------------------- (20 Feb 2013 9:39 PM) HOGWARTS# sh2013 Feb 21 02:23:56 HOGWARTS %PLATFORM-2-MOD_REMOVE: Module 1 removed (Serial number ) HOGWARTS# 2013 Feb 21 02:24:33 HOGWARTS %REDUN_MGR-4-CTRL_COMM_STATUS_CHANGE: Control Connectivity is UP with Primary VSM. 2013 Feb 21 02:24:43 HOGWARTS %BOOTVAR-5-NEIGHBOR_UPDATE_AUTOCOPY: auto-copy supported by neighbor supervisor, starting... 2013 Feb 21 02:22:20 HOGWARTS %SYSMGR-STANDBY-4-READCONF_STARTED: Configuration update started (PID 2971). 2013 Feb 21 02:25:19 HOGWARTS %SYSMGR-STANDBY-4-READCONF_STARTED: Configuration update started (PID 3129). 2013 Feb 21 02:25:22 HOGWARTS %MODULE-5-STANDBY_SUP_OK: Supervisor 1 is standby 2013 Feb 21 02:25:23 HOGWARTS %SYSMGR-STANDBY-5-MODULE_ONLINE: System Manager has received notification of local module becoming online.
This example shows how to display the difference between the running and startup configurations
switch# show running-config diff *** Startup-config --- Running-config *************** *** 1,13 **** ! !Command: show startup-config ! !Time: Thu Feb 21 02:26:23 2013 ! !Startup config saved at: Wed Feb 20 12:43:56 2013 version 5.2(1)SM1(5.1) svs switch edition advanced hostname HOGWARTS no feature telnet feature private-vlan feature netflow --- 1,13 ----
Adding a Second VSM to a Standalone System
Although primary and secondary VSMs can reside in the same host, to improve redundancy, install them in separate hosts and, if possible, connect them to different upstream switches.
When you install the second VSM, assign the secondary role to it.
The secondary VSM needs to have its control, management, and packet network interfaces in the same VLANs as the primary VSM.
To add a secondary VSM to the standalone VSM, convert the standalone VSM to a primary VSM.
After the secondary VSM is installed, the following occurs automatically:
Use this procedure to change the role of a VSM from standalone in a single VSM system to primary in a dual VSM system.
A change from a standalone to a primary VSM takes effect immediately.
Before beginning this procedure, you must be logged in to the CLI in EXEC mode.
This example shows how to display the current system redundancy status for the VSM.
switch# system redundancy role primary switch# show system redundancy status Redundancy role --------------- administrative: primary operational: primary Redundancy mode --------------- administrative: HA operational: None This supervisor (sup-1) ----------------------- Redundancy state: Active Supervisor state: Active Internal state: Active with no standby Other supervisor (sup-2) ------------------------ Redundancy state: Not present switch# copy running-config startup-config
Use one of the following commands to verify the configuration:
Command |
Purpose |
---|---|
show system redundancy status |
Displays the current redundancy status for VSMs in the system. |
show module |
Displays information about all available VSMs and VEMs in the system. |
Note | Equipment Outage—This procedures requires that you power down and reinstall a VSM. During this time, your system will be operating with a single VSM. |
Use this procedure to replace the primary VSM in a dual VSM system.
Note | Equipment Outage—This procedure requires powering down and reinstalling a VSM. During this time, your system will be operating with a single VSM. |
Log in to the CLI in EXEC mode.
Configure the port groups so that the new primary VSM cannot communicate with the secondary VSM or any of the VEMs during setup. VSMs with a primary or secondary redundancy role have built-in mechanisms for detecting and resolving the conflict between two VSMs in the active state. To avoid these mechanisms during the configuration of the new primary VSM, you must isolate the new primary VSM from the secondary VSM.
Have access to the console of both the primary VSM and thee secondary VSM.
Isolate the secondary VSM from the primary VSM to avoid the built-in mechanisms that detect and resolve conflict between two VSMs in a dual VSM system. This procedure includes the step for isolating the VSMs.
Note | Equipment Outage—This procedure requires powering down a VSM. During this time, your system will be operating with a single VSM. |
Use one of the following commands to verify the configuration:
Command |
Purpose |
---|---|
show system redundancy status |
Displays the HA status of the system. |
show module |
Displays information about all available VSMs and VEMs in the system. |
show processes |
Displays the state of all processes and the start count of the process. The states and types are described as follows: |
MIBs |
MIBs Link |
---|---|
CISCO-PROCESS-MIB |
To locate and download MIBs, go to the following URL: http://www.cisco.com/public/sw-center/netmgmt/cmtk/mibs.shtml |
Feature Name |
Releases |
Feature Information |
---|---|---|
System -Level High Availability |
5.2(1)SM1(5.1) |
This feature was introduced. |