Cisco Catalyst IE9300 Rugged Series Switches and Cisco Catalyst ESS9300 Embedded Series Switch

This document provides release information for the following Catalyst IE switches:

  • Cisco Catalyst IE9310 GE Fiber switch

  • Cisco Catalyst IE9320 GE Fiber switch

  • Cisco Catalyst IE9320 Fiber switch with 10 Gigabit uplinks

  • Cisco Catalyst ESS9300 Embedded Series Switch

Cisco Catalyst IE9300 Rugged Series Switches provide rugged and secure switching infrastructure for harsh environments. It is suitable for industrial Ethernet applications, including manufacturing, utility substations, intelligent transportation systems (ITSs), rail transportation, and other similar deployments.

The switch fulfills the need for a high-density SFP, rack-, or wall-mount switch that can function as a software-defined (SD)-Access fabric edge. It provides end-to-end architectural uniformity in the Cisco Digital Network Architecture (DNA) for Internet of Things (IoT) connected communities and extended enterprises.

In industrial environments, the switch can be connected to any Ethernet-enabled industrial communication devices. These devices include programmable logic controllers (PLCs), human-machine interfaces (HMIs), drives, sensors, and input and output (I/O) devices.

The Cisco Catalyst ESS9300 Embedded Series Switch is a Small Form Factor (SFF) Ruggedized 10 GigE Embedded platform for tactical, outdoor, and mobile environments. The compact design simplifies integration and offers the system integrator the ability to use the ESS9300 in a wide variety of applications. The Cisco ESS 9300 consists of one switch card. There are no cooling plates sold with it. It is up to the system integrator to design a thermal solution. The ESS-9300-10X-E board supports up to 10 ports of 10 GE fiber. Thermal power is 35 Watts.

New Features for Cisco Catalyst IE9300 Rugged Series Switches and Cisco Catalyst ESS9300 Embedded Series Switch

The following features apply to all versions of the IE9310 GE Fiber, IE9320 GE Fiber switches and the Cisco Catalyst ESS9300 Embedded Series Switch unless otherwise noted. The features are new in this release for the switches.

Table 1. Cisco Catalyst IE9300 Rugged Series Switches

Feature Name

License Level

Description

Supported Switches

Precision Time Protocol alarms

Network Essentials

PTP alarms can help you manage and monitor PTP on the switch. You can configure the PTP alarms to trigger the external alarm relay output and send system messages to a syslog server.

  • IE-9310-26S2C-A

  • IE-9310-26S2C-E

  • IE-9320-26S2C-A

  • IE-9320-26S2C-E

Layer 2 Network Address Translation

Network Essentials

One-to-one Layer 2 NAT (Network Address Translation) is a service that allows the assignment of a unique public IP address to an existing private IP address (end device). Layer 2 NAT enables the end device to communicate on both the private and public subnets.

  • IE-9310-26S2C-A

  • IE-9310-26S2C-E

  • IE-9320-26S2C-A

  • IE-9320-26S2C-E

Table 2. Cisco Catalyst ESS9300 Embedded Series Switch

Feature Name

License Level

Description

Supported Switches

Network Advantage License

Network Advantage

Release 17.10.1 offers the Network Advantage License level for the Cisco Catalyst ESS9300 Embedded Series Switch.

Note

 
Only MACsec 256 bit feature is supported.
Cisco Catalyst ESS9300 Embedded Series Switch

The following table describes the features available in Network Essentials for the Cisco Catalyst IE 9300 and ESS9300 Embedded Series Switch:

Table 3. Network Essentials

Layer 2 Switching

IEEE 802.1Q VLAN Trunking, 802.1W Spanning Tree Rapid Reconfiguration, 802.1ab LLDP (Link Layer Discovery Protocol), 802.1s - Multiple Spanning Tree Protocol (MSTP) Standard Compliance, 802.1s VLAN Multiple Spanning Trees , 802.1Q Tunneling, 802.3 standard, Unidirectional Link Detection (UDLD), Cisco Discovery Protocol, unicast MAC filter, VLAN Trunk Protocol (VTP) v2 and v3, EtherChannel, voice VLAN, Per-VLAN Spanning Tree Plus (PVST+), and Rapid STP (RSTP)

Multicast

IGMPv1, v2, v3 snooping, IGMP filtering, IGMP querier

Management

Web UI, MIB, SmartPort, Simple Network Management Protocol (SNMP), syslog, Dynamic Host Configuration Protocol (DHCP) server, Switched Port Analyzer (SPAN) session (1), Full Flexible NetFlow (FnF), Network Time Protocol (NTP)

Security

Zeroization, secure boot, port security, IEEE 802.1X, DHCP snooping, dynamic Address Resolution Protocol (ARP) inspection, IP Source Guard, private VLAN. MAC authentication bypass, 802.1X multidomain authentication, storm control - unicast, multicast, broadcast, Secure Copy (SCP), Secure Shell (SSH), SNMPv3, TACACS+, RADIUS server/client, MAC address notification, Bridge Protocol Data Unit (BPDU) guard, hardware physical alarm inputs (2), and relay output (1)

Quality of service (QoS)

Ingress policing, rate limit, egress queuing/shaping, autoQoS

Layer 2 IPv6

IPv6 host support, HTTP over IPv6, SNMP over IPv6

Precision Time Protocol alarms

PTP alarms can help you manage and monitor PTP on the switch. You can configure the PTP alarms to trigger the external alarm relay output and send system messages to a syslog server.

Layer 2 Network Address Translation

One-to-one Layer 2 NAT (Network Address Translation) is a service that allows the assignment of a unique public IP address to an existing private IP address (end device). Layer 2 NAT enables the end device to communicate on both the private and public subnets.

The following table describes the features available in Network Advantage for the Cisco Catalyst IE 9300 Switch:

Table 4. Network Advantage License

IP Routing

OSPF (V2 and V3), RIP (V1 and V2), ISIS (for IPv4 and IPv6), EIGRP (for IPv4 and IPv6), PBR (Policy Based Routing)

Virtualization

VRF-lite

Security

MACsec-256

IP Multicast

PIM sparse mode (PIM-SM), PIM dense mode (PIM-DM) and PIM Sparse dense mode

High Availability

Bidirectional Forwarding Detection (BFD) echo mode, HSRP (IPv4 and IPv6), VRRP (IPv4 and IPv6)


Important


Only MACsec 256 is supported on ESS9300 as part of Network Advantage License. All other Network Advantage features do not apply to the ESS9300 at this time.

Important Notes

Switch Model Numbers

Cisco Catalyst IE9300 Rugged Series Switches

The following table lists the supported IE9300 series hardware models and the default license levels that they are delivered with.

Model Number

Default License Level

Stacking Support

Description

IE-9310-26S2C-A

Network Advantage

No

  • Total ports: 28

  • SFP uplinks: 4x 1-Gb SFP

    SFP downlinks: 22x 1-Gb SFP, 2x 1-Gb dual-media ports

  • Power supplies: Support for field-replaceable, redundant AC or DC power supplies.

IE-9310-26S2C-E

Network Essentials

IE-9320-26S2C-A

Network Advantage

Yes

IE-9320-26S2C-E

Network Essentials

All Cisco Catalyst IE9300 Rugged Series Switches have 4 GB of DRAM, four alarm inputs, and one alarm output. Other I/O include the following:

  • SD-cards socket

  • Power input

  • RJ-45 (RS-232) console

  • Micro-USB console

  • USB-A host port


Note


This document uses the term IE9310 GE Fiber when referring to both IE-9310-26S2C-A and IE-9310-26S2C-E switches. This document uses the term IE9320 GE Fiber when referring to both IE-9320-26S2C-A and IE-9320-26S2C-E switches.


Cisco Catalyst ESS9300 Embedded Series Switch

The ESS9300 is a ruggedized 10G embedded platform that is designed for embedded applications for tactical, outdoor, and mobile installations requiring low power, small size, and ruggedization. Its features include:

  • Single board

  • Small form-factor board size (110 x 85 mm; 4.3 x 3.3 in.)

  • 10 ports of 10G: Enhanced Small Form-Factor Pluggable (SFP+)

  • Ethernet management port (optional)

  • RS-232 and USB console

  • Common +3.3VDC and +5VDC power inputs

  • Low power—35W (typical)

  • 4 GB DDR4 DRAM

  • 8 GB onboard eMMC flash storage (2.5 GB usable space)

Starting with release 17.10.1, both the Network Essentials license and the Network Advantage license are available. The features available in the two licenses follow the IE9300 series, with the exception of MACsec-256.

Table 5. Ordering Information

Product ID

Product Description

ESS-9300-10X-E

ESS9300 board, no cooling plate, Network Essentials software.

ESS9300-NW-A=

Cisco Network Advantage license for ESS9300 Series Spare.

Network Advantage License

Description

Security

MACsec-256

Upgrading the Switch Software

This section covers the various aspects of upgrading or downgrading the device software.


Note


See the Cisco IOS XE Migration Guide for IIoT Switches for the latest information about upgrading and downgrading switch software.


SSH Algorithms for Common Criteria Certification Limitation

Starting from Cisco IOS XE Release 17.10, the following Key Exchange and MAC algorithms are removed from the default list:

  • Key Exchange algorithm:

    • diffie-hellman-group14-sha1

  • MAC algorithms:

    • hmac-sha1

    • hmac-sha2-256

    • hmac-sha2-512


Note


You can use the ip ssh server algorithm kex command to configure the Key Exchange algorithm and the ip ssh server algorithm mac command to configure the MAC algorithms.


Finding the Software Version

The package files for Cisco IOS XE software can be found on the system board's internal flash memory device (flash:) or an external USB, depending on the device configuration.

You can use the show version privileged EXEC command to see the software version that is running on your switch.


Note


Although the show version output always shows the software image running on the switch, the model name shown at the end of this display is the factory configuration and does not change if you upgrade the software license.

You can also use the dir filesystem: privileged EXEC command to see the names and versions of other software images that you might have stored in flash memory.

Software Images for Cisco IOS XE Dublin 17.10.x

The following table provides the filenames for the IOS XE 17.10.x software image for Cisco Catalyst IE9300 Rugged Series Switches and the Cisco Catalyst ESS9300 Embedded Series Switch.

Release

Image Type

Filename

Switch Model

Cisco IOS XE.17.10.1

Universal

ie9k_iosxe.17.10.01.SPA.bin

IE9300

NPE

ie9k_iosxe_npe.17.10.01.SPA.bin

IE9300

ESS9300

Software Installation Options

The following table lists the options for the install command for Cisco Catalyst IE9300 Rugged Series Switches.

To install and activate the specified file, and to commit changes to be persistent across reloads, enter the following command: install add file filename [ activate commit]

Option

Description

abort

Abort the current install operation.

activate

Activate an installed package.

add

Install a package file to the system.

auto-abort-timer

Install auto-abort-timer.

autoupgrade

Initiate software auto-upgrade on all incompatible switches.

commit

Commit the changes to the load path.

deactivate

Deactivate an install package.

label

Add a label name to any installation point.

remove

Remove installed packages.

rollback

Rollback to a previous installation point.

Licensing

This section provides information about the licensing packages for features available on Cisco Catalyst IE9300 Rugged Series Switches.

License Levels

The software features available on Cisco Catalyst IE9300 Rugged Series Switches fall under these base or add-on license levels.

Base Licenses

  • Network Essentials

  • Network Advantage: Includes features available with the Network Essentials license and more.

Add-on Licenses

Add-on licenses require a Network Essentials or Network Advantage as a prerequisite. The features available with add-on license levels provide Cisco innovations on the switch, and on the Cisco Catalyst Center.

  • Catalyst Center DNA Essentials

  • Catalyst Center DNA Advantage: Includes features available with the Catalyst Center DNA Essentials license and more.

To find information about platform support and to know which license levels a feature is available with, use Cisco Feature Navigator. To access Cisco Feature Navigator, go to https://cfnng.cisco.com. An account on Cisco.com is not required.

Smart Licensing Using Policy

Smart Licensing Using Policy, which is an enhanced version of Smart Licensing, is the default and the only supported method to manage licenses.

Smart Licensing using Policy provides a licensing solution that does not interrupt the operations of your network. Instead, it enables a compliance relationship to account for the hardware and software licenses you purchase and use.

With this licensing model, you do not have to complete any licensing-specific operations, such as registering or generating keys before you start using the software and the licenses that are tied to it. Only export-controlled and enforced licenses require Cisco authorization before use. License usage is recorded on your device with timestamps, and the required workflows can be completed later.

Multiple options are available for license usage reporting – this depends on the topology you implement. You can use the Cisco Smart Licensing Utility (CSLU) Windows application, or report usage information directly to Cisco Smart Software Manager (CSSM). A provision for offline reporting for air-gapped networks, where you download usage information and upload to CSSM, is also available.

Starting with this release, Smart Licensing Using Policy is automatically enabled on the device. This is also the case when you upgrade to this release.

By default, your Smart Account and Virtual Account in CSSM is enabled for Smart Licensing Using Policy.

Caveats

Caveats describe unexpected behavior in Cisco IOS XE releases. Caveats listed as open in a prior release are carried forward to the next release as either open or resolved.

Open Caveats

There are no open caveats for this release.

Resolved Caveats

Identifier

Description

CSCwc33322

IOX: Observing Disk space issue for Cisco Cyber Vision app installation through sensor extension.

CSCwc04550

Unable to Change PTP Profile via Web UI.

CSCwc06817

Incremental Memory leaks seen with traffic (link trigger scenarios) over rep ring.

CSCwd09742

Boot failed, due to mounting issues of perma locked device.

Troubleshooting

For the most up-to-date, detailed troubleshooting information, see the Cisco TAC website at this URL:

https://www.cisco.com/en/US/support/index.html

Go to Product Support and select your product from the list or enter the name of your product. Look under Troubleshoot and Alerts, to find information for the problem that you are experiencing.

Related Documentation

Information about Cisco IOS XE at this URL: https://www.cisco.com/c/en/us/products/ios-nx-os-software/ios-xe/index.html.

Information about Cisco Catalyst IE9300 Rugged Series Switches is at this URL: https://www.cisco.com/c/en/us/products/ios-nx-os-software/ios-xe/index.html

Cisco Validated Designs documents at this URL: https://www.cisco.com/go/designzone

To locate and download MIBs for selected platforms, Cisco IOS releases, and feature sets, use Cisco MIB Locator found at the following URL: http://www.cisco.com/go/mibs

Communications, services, and additional information

  • To receive timely, relevant information from Cisco, sign up at Cisco Profile Manager.

  • To get the business impact you’re looking for with the technologies that matter, visit Cisco Services.

  • To submit a service request, visit Cisco Support.

  • To discover and browse secure, validated enterprise-class apps, products, solutions, and services, visit Cisco DevNet.

  • To obtain general networking, training, and certification titles, visit Cisco Press.

  • To find warranty information for a specific product or product family, access Cisco Warranty Finder.

Cisco Bug Search Tool

Cisco Bug Search Tool (BST) is a gateway to the Cisco bug-tracking system, which maintains a comprehensive list of defects and vulnerabilities in Cisco products and software. The BST provides you with detailed defect information about your products and software.

Documentation feedback

To provide feedback about Cisco technical documentation, use the feedback form available in the right pane of every online document.