Phase 1-Cisco HCS Data Center Infrastructure Upgrades

Data Center Upgrade Strategy

Infrastructure Upgrade Strategy

The architecture of the Cisco HCS VMDC and PoD infrastructure enables service providers to onboard multiple enterprises from the cloud. Your strategy for upgrading the data center is key to maintaining service uptime. Upgrading can affect services for multiple enterprises simultaneously.


Note

Maintain the infrastructure versioning to the current supported version within the data center. Minimum Version and the Recommended Version within a solution system release is subject to change based upon feature enhancement, critical fixes, and security updates. If the system release is running a component version earlier than the latest recommended release, upgrade the image to the recommended release as soon as possible. Ensure to perform continual data center upgrades, regardless of management and application upgrades, to maintain the application compatibility.


Discontinuation of third party vSwitch

VMware announced the discontinuation of its third party virtual switch (vSwitch) and deprecated the VMware vSphere APIs used by third party switches in the releases following vSphere 6.5 Update 1. Subsequent vSphere versions have the third party vSwitch APIs removed and third party vSwitches like the Cisco Nexus 1000v no longer function. For Cisco HCS this requires the complete removal of the Nexus 1000v including the Virtual Ethernet Module (VEM) from the environment. It is therefore recommended to transition to the VMware vSphere Distributed Switch (VDS) as soon as possible and required before attempting to upgrade to vSphere 6.5 Update 2 and later. VMware has provided a migration tool for use by Network Administrators and System Administrators who are migrating their hosts from Cisco Nexus 1000v (N1KV) distributed switch to VMware’s VDS and is available for download from vmware.com.


Caution

Failure to completely remove the Nexus 1000v and VEM from vCenter and all ESXi hosts can lead to network connectivity issues and complete outages.


Upgrade Sequence and Time Requirements

The sequence in which you perform upgrade procedures depends on your deployment, and on how you want to balance the level of user impact with the amount of time required to complete the upgrade. You must identify the sequence that you will follow before you are ready to perform the upgrade process.

Recommended Sequence for the Least Time

Performing upgrades that takes the least amount of time will have the greatest service impact on your network. To perform an upgrade in the least amount of time, you can upgrade all components in parallel; with this option, some devices will be out of service for the duration of the upgrade. You can reduce the impact on services by organizing the component upgrades into subgroups.

Recommended Sequence for the Least Impact

Performing upgrades that takes the least impact on your network assuming you can accept the completion of the upgrade over a longer period.

Sequence Rules

When you are planning to perform an upgrade of Cisco UC applications using either the Unified CM OS Admin interface or the PCD upgrade task, you must ensure that your plan takes sequencing rules into account.

Upgrade time requirements

The time required to upgrade the software is variable and depends on several factors. Use the information in the Factors that Affect Upgrade Time Requirements section to understand the steps you can take to optimize the upgrade process. This section provides information and examples to estimate the time requirements for an upgrade.

Factors that Affect Upgrade Time Requirements

The factors that impact the amount of time that an upgrade requires is listed in the table. You can reduce the amount of time required for an upgrade by ensuring that your system meets these conditions.

Parameter

Description

External Services and Tools

Time requirements are reduced when external services and tools, such as NTP servers, DNS servers, LDAP directories, and other network services are reachable with response times as short as possible with no dropped packets.

Accessibility of upgrade images

Save time by ensuring that software, firmware and ISO images are on DVD or are already downloaded and staged within the same LAN of the device being upgraded.

System Health

  • Review logs, syslog and configurations.

  • Commit un-committed run-time changes.

  • Low memory or memory leaks will impact the upgrade.

  • Round Trip Times (RTT) between nodes will extend the time required for things like UC apps.

  • Verify High Availability for the device type is functioning properly.

  • Remove old, used software or firmware.

  • Execute Runtime or Health Monitoring Diagnostics.

  • System errors can impact upgrade time. Ensure that there are no errors for the device being upgraded.

Physical and virtual hardware infrastructure

Upgrade time is reduced when your infrastructure is configured for high-capacity and low-latency, and when there is low contention from other traffic. For example, you can optimize the upgrade process by ensuring that:

  • There are no infrastructure bottlenecks from VMs sharing same ESXi host, the same Direct Attached Storage (DAS) volume, the same Logical Unit Number (LUN), or the same congested network link.

  • Storage latencies meet the requirements specified at https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/uc_system/virtualization/cisco-collaboration-virtualization.html.

  • The physical CPU cores and the virtualization design comply with virtualization requirements of Unified Communications Manager and IM and Presence Service. Do not oversubscribe CPUs by having VMs share the host resources; use logical cores or resource reservations

  • Unified Communications Manager and IM and Presence Service virtual machines are on same hosts, or on hosts with 1GbE LAN between them with low contention from other traffic.

  • If the cluster is over a WAN, ensure that you follow all bandwidth and latency rules listed in the Solution Reference Network Designs (SRND)guide.

Estimating the Minimum Time Requirements

The table lists the minimum amount of elapsed time to expect for each major data center component in the upgrade process under ideal conditions. Your upgrade may take longer than the times listed in this table, depending on your network conditions and on the upgrade sequence that you follow.

Task

Minimum Time

Service Impact

Nexus 7K, 9K Aggregation or Access Layer Switches

30 to 50 minutes depending on the chassis type and how many modules are installed.

Add 1 hour if it is a traditional upgrade

Reference the Cisco Nexus Series NX-OS Software Upgrade and Downgrade Guide for the specific device. See the Release Notes for the target upgrade release before starting the upgrade.

Note 

The Cisco NX-OS software supports in-service software upgrades (ISSUs) on devices with dual supervisor modules. An ISSU can update the software images on your device without disrupting data traffic. Only control traffic is disrupted. If an ISSU causes a disruption of data traffic, the Cisco NX-OS software warns you before proceeding so that you can stop the upgrade and reschedule it to a time that minimizes the impact on your network. See the Cisco NX-OS ISSU Support application.

ASR IP/Sec Site-to-Site VPN (ASR 1K)

30 minutes

Use Cisco Feature Navigator to find information about platform support and Cisco software image support. To access Cisco Feature Navigator, see www.cisco.com/go/cfn

Cisco ASR 1000 Series Aggregation Services Routers supports In-Service Software Upgrades (ISSU) procedure to upgrade software. The ISSU-using-install-cmds-for-ASR1k feature introduces a new method of software upgrade process by using the install command for Dual RP and Dual IOS routers on Cisco ASR 1000 Series Aggregation Services Routers.

ASA 5500-X Series Next-Generation Firewalls

30 minutes for deployments with small clusters

2 hours for larger clusters

See the Cisco ASA Upgrade Guide

Cisco Firepower Series Next-Generation Firewalls

30 minutes for deployments with small clusters

2 hours for larger clusters

See the Cisco ASA Upgrade Guide

MDS 9000 Series Switches

30 to 50 minutes depending on the chassis type and how many modules are installed.

  • Information is available on non-disruptive upgrade paths that are supported for Cisco MDS NX-OS software Release 8.x within the Release Notes.

  • If you have the SAN analytics feature enabled, you may need to disable the SAN analytics feature using the no feature analytics command before upgrading.

UCS Manager (Fabric Interconnects, IOM, B-series Blades, C-series Rack Mount)

2 to 4 hours depending on the chassis type and the number of modules that are installed.

Add 1 hour for each blade

UCS-M 3.2 and later contains the ability to stage firmware through Prepare for Update while the systems are online, and without a maintenance window. Activating the firmware, may require a reboot, is done much more quickly reducing the downtime during the maintenance window.

UCS C-series Standalone Rack Mount Servers

1 to 2 hours

VMware vCenter/vCSA

1 to 8 hours depending on if a major or minor release, Virtual Distributed Switch in use (N1K vs VDS), or if migrating from Windows to vCSA appliance

Update sequence for vSphere 6.7 and its compatible VMware products (53710)

https://kb.vmware.com/kb/53710

VMware vCenter Server 6.5 Update 3 Release Notes and the VMware ESXi 6.7 Update 2 Release Notes

VMware ESXi Hosts

2 to 4 hours each depending on Virtual Distributed Switch in use (N1K vs VDS)

ESXi 6.7.x Quick Boot is a vSphere feature that speeds up the upgrade process of an ESXi server. A regular reboot involves a full power cycle that requires firmware and device initialization. Quick Boot optimizes the reboot path to avoid this, saving considerable time from the upgrade process.

Component Migration for Capacity Increase

The Cisco HCS VMDC PoD design data center consists of the following network components:

  • Cisco ASA 5500-X Series Firewalls

  • Cisco ASR 1000 Series Aggregation Services Routers

  • Cisco Firepower 2100 Series

  • Cisco Firepower 4100 Series

  • Cisco HyperFlex HX Data Platform

  • Cisco MDS 9100 Series Multilayer Fabric Switches

  • Cisco Nexus 7000 Series Switches

  • Cisco Nexus 9000 Series Switches

  • Cisco Unified Computing System

  • VMware vSphere Distributed Switch (VDS)

With proper design and upgrade planning, you can increase capacity by adding or upgrading these components with minimal user impact depending upon Service Level Agreements. The Cisco HCS PoD design provides a flexible yet granular resource container definition that allows for adding services and capacity on-demand.

Use Cisco Data Center Optimization Services to improve business agility, end-user experience, and total cost of ownership with minimal risk, complexity, and resource usage. For more information see Cisco Data Center Optimization Services. For more information about the Cisco Data Center Migration Service and other Cisco Services for the data center, contact your Cisco support representative.

For example, it is possible to migrate from a Cisco HCS Small Pod to a Large Pod simply by adding Cisco Nexus 9500 Series Switches or Cisco Nexus 7000 Series Switches and reconfiguring the Aggregation functionality from the Cisco Nexus 9300 Series Switches.

Maintenance Window Considerations

Upgrades can take a long time, depending on the number of customers to be migrated, or the size of individual customers.

Upgrading an entire customer (such as Cisco Unified Communications Manager, Cisco Unity Connection, or Cisco Emergency Responder) may require more than one maintenance window for larger customers. Therefore, you can break the upgrade into phases or maintenance windows, providing you follow the overall upgrade order.

For more information on the sequence of upgrade activities during the maintenance windows, see the following topics:

It is important to determine whether to complete Management Upgrades during one maintenance window or multiple maintenance windows. We recommend that you complete all activities mentioned in Management Upgrades in one maintenance window. However, you can perform customer upgrades in a maintenance window that is separate from upgrade stages involving Cisco HCS Management Applications and Telephony Aggregation components.

For virtual machine upgrades to support newer VMware hardware and tools for UC applications, the following link describes the supported upgrade processes: Unified Communications VMware Requirements. Each VM must be running on a blade that has been upgraded to the latest version before the VM may be upgraded. For more information, see VMware Knowledge Base article 1010675, Upgrading a virtual machine to the latest hardware version: http://kb.vmware.com/selfservice/microsites/microsite.do.