Showing posts with label VIRL. Show all posts
Showing posts with label VIRL. Show all posts

Cisco VIRL is out! It's not free!

Cisco VIRL

Cisco VIRL has been released today.

After waiting for what seems like ages, since it was first mentioned, it is finally here.

You can get it from http://virl.cisco.com.

The rumours were that is would be free, and would run up to fifteen (15) nodes, that could be either IOSV, IOS XRv, NX-OSv, or the CSR1000v.

While the capabilities remain the same, it is not free. It costs $199.99 PER YEAR.

This does seem to be a bit of a kick to the groin, really. Whilst this is the true, Cisco virtual environment, with all the support and abilities needed (obviously barring a few layer 2 technologies), $200 a year is a little costly.

For a limited time you can get $50 off using the code "VIRL50" at checkout. Which still makes it $150. It's not a bad price I suppose, but many people did expect this to be released without an associated cost.

I think I will stick with IOU and GNS3 for the moment!

New toys for budding CCIEs

I know I have been a bit slack on the blogging side of things for the last couple of weeks, but things have been really busy at work, and I am trying to finish off "MPLS for Cisco Networks", so I hope you'll understand.

Anyway there are a couple of new tools on the horizon for CCIE candidates, and for general Cisco networking fun.


Firstly there is VIRL, which looks like it should be with us by the end of the month (July 30th), possibly subject to change and delay but it should drop soon!
Secondly is the CCIE Lab Builder. No dates as yet, but it does look a lot like the old v4 interface made public. It will be cloud hosted and will run topologies on IOL (IOS on Linux), so in many ways it's the same as IOU, so layer 2 support will probably be limited (as it is in IOU). The downside is that it looks like it will be a paid offering, again no details as yet. I think it will be useful, but eclipsed by VIRL, which will be free (you just need to register on the Cisco Developer site.

It looks like there will be a plethora of tools for the CCIE candidate to build and play with networks, it's just a shame that the official guide hasn't been released yet!

The scoop on CML and VIRL!

It's always nice on a wet British morning when the sky looks grey and drab and you don't want to get out of bed to have something to counterbalance the crap UK weather.

Firstly one of my sons woke up at 5:40am, usually this would mean the start to my day, but one quick nappy change later and he was back in his bed fast asleep, they then woke up at a very respectable 7:30 allowing the wife and I to get a rare lie-in together.

The second was getting a message from Craig at Cisco. He picked up on a post that I made on some information on CML (Cisco Modeling Lab) and offered "to clear up people's questions and misinformation". Clearly there are a lot of people wanting to hear more about CML, and more importantly, to start having some real hands on experience of it, so I wasn't going to pass up the chance to quiz him, and having him clarify what we know (or what we think we know) would certainly be a good idea.

Over the last few months we have heard a lot of supposed "fact" about CML, how it is what used to be code named VIRL, and quite frankly, there is probably more wrong information out there than truth.

So with coffee in hand I sent him a few questions through Google+, and he got back to me on email.

I am pasting things in context of my questions to him. My questions are in bold, Craig's replies are in blue. We'll start with Craig's introduction so you can get an understanding of who he is in relation to CML.

Hi Craig, thanks for getting in touch. I have a few questons about CML, and then would love to hear anything else you'd like to add.

In terms of introductions, I am the Cisco Technical Marketing Engineer for Cisco Modeling Labs, and you can reference these answers. I represent CML within the organization called Learning@Cisco (L@C) who will be launching CML which is based on VIRL. There are other organizations such as the Innovate team and the OnePk team who also use VIRL

CML is built for the Corporate users that are looking to validate
VIRL will be available via Devnet and will be free for any registered user to download. This will be a community-supported platform. For more information on 'Devnet', please take a look at https://developer.cisco.com/site/devnet/home/index.gsp. More information on VIRL will be posted there soon. Target FCS is 7/30

People ask what’s the difference between VIRL and CML? L@C collaborated with the Innovation team (the developers of VIRL) to productize it, run the full test regime so that it’s stable, document, and provide TAC support.
VIRL will be available in other formats, available to customers, but not with the testing regime, TAC supported version, docs, and so on.

I started my studies (as most do) with my head deep into Packet Tracer, will CML replace Packet Tracer?

I haven’t had a conversation about what the story and to be honest, I haven’t compared to two products yet – but will put that on my to-do list

Cisco are very evidently embracing the open networking technologies that are emerging, so will CML link into the ONE (onePK) suite?

For onePk, you can install the OnePk All-in-one OVA today and the CML OVA and they will communicate. Also, I installed the OnePK API directly in the CML server and that works too

What is the estimated release date for the "consumer" version? I have heard from different sources that it will be available through DevNet for free, or that it will be sub $100, is this the case?

Answered above in Craig's introduction.

Will CML have a new logo?

This is the CML logo



Does CML support DMVPN?

Not at this time.

Will CML (at some stage) have more support for layer 2? Clearly these functions are more ASIC driven, but as the CCIE requires the ability to do spanning-tree this is something that people will be looking for

Yes, we are building a Layer 2 image now and working around some of the ASIC issues.

Speaking of the CCIE, Cisco have said that the lab will be 100% virtualized, is CML going to be the back-end for the new exam?

Yes, CML will be the backend for L@C CCIE labs, in the future. (L@C runs the CCIE labs so that’s the correlation)

CML supports connections to real equipment, which will probably overcome the layer 2 issue, does this mean that (in time) we would be able to join CML and GNS3 networks?

CML does have external connections for both L2 and L3 so you can connect to external devices or other virtual images

Will CML allow us (again in time) to run other vendors equipment within it?

 In the first release you can run any image that runs within OpenStack, Cisco image or other.
So there you go, some concrete information from Cisco!

sh brief

In short:
  • CML and VIRL are actually separate
  • VIRL will be free, and out soon (end of July by the looks of it)
  • VIRL will be community supported, CML will  have full Cisco support (TAC, documentation etc)
  • Integration with ONE (onePK) will be possible (how cool is that?!)
  • There will be ASIC support! (in time)
  • It will connect to GNS3!
  • It will run OpenStack images (Ubuntu, RedHat variants, SuSe)
Keep watch on the DevNet site and keep your eyes open around the end of July for VIRL.

I would like to express my thanks to Craig for taking the time out to answer the questions, and to clear up the confusion surrounding CML and VIRL.

Cisco ViRL - a first taste!

I was playing around with the onePK VM yesterday when I noticed something a little interesting, well, OK, it was all interesting, but something really stood out:

Cisco VIRL network topology

When you launch the nodes it looks like it uses a file with a .virl extension!

So it looks like onePk shares some of it's code with ViRL (or to call it by its official name, CML). We can dig a little deeper into the virl file and have a little poke about, I havn't seen much about it I last wrote about it, so it'll be nice to get a little taster if what is to come.

From an ssh connection (if you have given the onePK vm an IP on your network you can do "sudo apt-get install openssh-server") and then simply cd through to /usr/share/vmcloud/data/examples/3node/ and do "vi 3node.virl".

.virl files

What we are presented with is a bunch of XML, and if you have read anything about ViRL/CML then you'll know that it uses XML to share configuration data.

The first line gives us a little insight that there is a schema for CML, and specifically for the vmmaestro GUI interface (the last line):

<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <topology xmlns="http://www.cisco.com/VIRL" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" schemaVersion="0.3" xsi:schemaLocation="http://www.cisco.com/VIRL http://cide.cisco.com/vmmaestro/schema/virl.xsd">

Next we have the node information, one for each of our routers, but I am only showing one example here:

<node name="router1" type="SIMPLE" subtype="vios" location="188,263" vmImage="/usr/share/vmcloud/data/images/vios.ova">
<extensions>
<entry key="bootstrap configuration" type="String">/usr/share/vmcloud/data/examples/3node/router1.con</entry>
<entry key="import files" type="String">/home/cisco/vmcloud-example-networks/3node/router1.p12</entry>
</extensions>
<interface name="GigabitEthernet0/0"/>
<interface name="GigabitEthernet0/1"/>
<interface name="GigabitEthernet0/2"/>
<interface name="GigabitEthernet0/3"/>
</node>

Interestingly because the IOSv routers used in onePK come in an ova format if might be possible to run these as standalone VirtualBox routers, or even bring them into GNS3. I might have a play with that later on!. Don't try and cat the .p12 file, it's not humanly readable.

Each router has a bootstrap configuration, in the form of a .con file, so we'll look at those in a moment.

We then have another node, which looks to be our management communication - to allow is access to the routers:

<node name="vmc_lan_1" type="SEGMENT" location="374,520"/>
<node name="eth1" type="ASSET" location="671,235">
<interface name="none0"/>
<interface name="none1"/>
</node>

Lastly we have our physical connection information, followed by the closing topology brackets:

<node name="lan_ex" type="SEGMENT" location="722,161"/>
<connection src="/topology/node[1]/interface[1]" dst="/topology/node[2]/interface[1]"/>
<connection src="/topology/node[1]/interface[2]" dst="/topology/node[3]/interface[1]"/>
<connection src="/topology/node[1]/interface[3]" dst="/topology/node[4]"/>
<connection src="/topology/node[2]/interface[2]" dst="/topology/node[4]"/>
<connection src="/topology/node[3]/interface[2]" dst="/topology/node[4]"/>
<connection src="/topology/node[3]/interface[3]" dst="/topology/node[6]"/>
<connection src="/topology/node[5]/interface[1]" dst="/topology/node[6]"/>
<connection src="/topology/node[1]/interface[4]" dst="/topology/node[6]"/>
<connection src="/topology/node[2]/interface[3]" dst="/topology/node[5]/interface[2]"/>
</topology>

So we should be able to see that node 1 connects to nodes 2 and 3 through its first and second interfaces - GigabitEthernet0/0 and GigabitEthernet0/1 respectively, and from the router, that certainly seems to be the case:

Connectivity through virl configuration

Reachability is also good:

Pinging routers in onePK

.con files

Looking at the router1.con file it is pretty standard Cisco configuration, I have removed extra exclamation marks though to make it a bit shorter:
cisco@onepk:/usr/share/vmcloud/data/examples/3node$ cat router1.con
version 15.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router1
!
boot-start-marker
boot-end-marker
!
no aaa new-model
mmi polling-interval 60
no mmi auto-configure
no mmi pvc
mmi snmp-timeout 180
!
ip cef
no ipv6 cef
ipv6 multicast rpf use-bgp
!
multilink bundle-name authenticated
!
username CISCOUSERNAME privilege 15 password 0 CISCOPASSWORD
!
redundancy
!
interface GigabitEthernet0/0
 ip address 10.10.20.110 255.255.255.0
 duplex auto
 speed auto
 no shutdown
!
interface GigabitEthernet0/1
 ip address 10.10.30.110 255.255.255.0
 no shutdown
 duplex auto
 speed auto
!
interface GigabitEthernet0/2
 ip address 10.10.10.110 255.255.255.0
 no shutdown
 duplex auto
 speed auto
!
interface GigabitEthernet0/3
 ip address dhcp
 no shutdown
 duplex auto
 speed auto
!
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
control-plane
!
banner exec ^C
************************************************************************
*vIOS - Cisco Systems Confidential                                     *
*                                                                      *
*This software is provided as is without warranty for internal         *
*development and testing purposes only under the terms of the Cisco    *
*onePK Software Development Kit License Agreement. Under no            *
*circumstances may this software be used for production purposes or    *
*deployed in a production environment.                                 *
*                                                                      *
*By using the software, you agree to abide by the terms and conditions *
*of the Cisco onePK Software Development Kit License Agreement as well *
*as the terms and conditions of the Cisco End User License Agreement at*
*http://www.cisco.com/go/eula                                          *
*                                                                      *
*Unauthorized use or distribution of this software is expressly        *
*Prohibited.                                                           *
************************************************************************
^C
banner incoming ^C
************************************************************************
*vIOS - Cisco Systems Confidential                                     *
*                                                                      *
*This software is provided as is without warranty for internal         *
*development and testing purposes only under the terms of the Cisco    *
*onePK Software Development Kit License Agreement. Under no            *
*circumstances may this software be used for production purposes or    *
*deployed in a production environment.                                 *
*                                                                      *
*By using the software, you agree to abide by the terms and conditions *
*of the Cisco onePK Software Development Kit License Agreement as well *
*as the terms and conditions of the Cisco End User License Agreement at*
*http://www.cisco.com/go/eula                                          *
*                                                                      *
*Unauthorized use or distribution of this software is expressly        *
*Prohibited.                                                           *
************************************************************************
^C
banner login ^C
************************************************************************
*vIOS - Cisco Systems Confidential                                     *
*                                                                      *
*This software is provided as is without warranty for internal         *
*development and testing purposes only under the terms of the Cisco    *
*onePK Software Development Kit License Agreement. Under no            *
*circumstances may this software be used for production purposes or    *
*deployed in a production environment.                                 *
*                                                                      *
*By using the software, you agree to abide by the terms and conditions *
*of the Cisco onePK Software Development Kit License Agreement as well *
*as the terms and conditions of the Cisco End User License Agreement at*
*http://www.cisco.com/go/eula                                          *
*                                                                      *
*Unauthorized use or distribution of this software is expressly        *
*Prohibited.                                                           *
************************************************************************
^C
!
line con 0
line aux 0
line vty 0 4
 transport input all
!
onep
 transport type tls localcert demoTP disable-remotecert-validation
 start
!
! IOS PKI will fail to import the tftp file if we attempt this before
! the config has been fully applied. So if we just do:
!   crypto pki import demoTP pkcs12 [location] [etc...]
! We would see something similar to this in the boot log:
!   *Nov 29 19:27:32.415: CRYPTO_PKI: Copying pkcs12 from flash1://bootstrap_admin.con
!   *Nov 29 19:27:32.492: %PKI-6-PKCS12IMPORT_FAIL: PKCS #12 Import Failed.
! Therefore we use a short delay before loading the pkcs12 file:
!
event manager applet load_identity
 event timer countdown name Delay time 20
 action 0.0 cli command "enable"
 action 1.0 cli command "config terminal"
 action 2.0 cli command "file prompt quiet"
 action 3.0 cli command "crypto pki import demoTP pkcs12 flash2://router1.p12 password NOTsecure"
 action 4.0 syslog msg "Loaded bootstrap identity certificate"
!
end
Pretty cool stuff really, and it looks like when CML is finally released configuration will not be too hard, even without the fancy GUI! I am rather liking this onePK!

GNS3 1.0 Vs Cisco CML


Last week I started backing the crowd funded GNS3 1.0 project by making a small(ish) donation, I watched the preview video and I was very impressed. Some of the exciting new features of GNS3 are:

Grouping of devices for easier management
IOS on UNIX Support
IOU Switching Support
Ability to plug in network cables to running routers and switches (instead of having to turn them off)
Rapid Spanning Tree support
Enhanced Idle-PC calculations

Many of you have probably used GNS3 for some time now. some of you may even have weighed up the pros and cons of using IOU, so its great that GNS3 now offers the ability to leverage the best of both worlds in one interface, but how does it shape up to CML, which is clearly going to be it's main (if not only rival)?

Costs and Limits

CML is going to be with us pretty soon (although Cisco are still keeping pretty quiet about it). The word on the street is that for the likes of you and I it will cost $100 and support a maximum of 15 devices.

GNS3 does not have such a cost or device limit (although it does require memory from the host machine), and the CCIE exam itself has far more that 15 devices (30 from what I have seen of the v4.0, and would guess its roughly the same for the v5.0).  

Switching

With CML IOS switching won't be released until later in the year, possibly as an upgrade, maybe as an add-on, unknown if there is a price association.

GNS3 Switching will be handled through connectivity to an IOU VM.

Resources

There are expected to be other issues with CML, in that as each device runs as a separate VM it is a "huge resource hog" - and this is coming from someone who worked on the beta from a thread over at the Cisco learning network here.

Both CML and GNS3 1.0 will hook into VMs for different requirements, out of the box GNS3 works exceedingly well, granted switching has been a bug-bear for most. GNS3 can already hook into VirtualBox for VMs and can run IOS XR vms, and any manner of VirtualBox guest. CMLs VM connectivity will be decided by Cisco.

Other features

CML offers a great way of overlaying data - from my earlier post on VIRL (as it was known then) you can overlay information such as BGP connections, which will be great for presentations, especially as the engine can be separated from the GUI (called VM Maestro), the GUI can run on a laptop and the engine could for instance run on a server back in the office. Both can however live happily on the one laptop though (if suitably specced). This separation of roles is very good, especially if this is in a corporate environment.

GNS3 can connect to read equipment whereas CML seems to be more self contained, which also keeps it within the node limit imposed by your license, but also means that one of the great features of GNS3, that overcame the switching issue, will go back to relying on emulation of ASICs to provide switching.

Who will win?

It's really early days yet, but for the one-off consumer looking to study for an exam I think it will be GNS3 that has the greater install base. CML will get a lot of attention, thats pretty obvious, but its device number limitation for the like of you and I that will be a real bug bear. GNS3 is free and will remain free, it has a great following and is only limited by the imagination. Yes I will will buy CML, just like I bought about $2000 worth of routers and switches before finding out that they are going to be no good for the CCIE v5, but I think I will probably use GNS3 more.
VIRL/CML landing soon

VIRL/CML landing soon

It seems like forever since VIRL (now called CML) was announced. But finally the release is nearly upon us!

Cisco CML (Content Modelling Lab) will be released in April, so not long to wait now.

The personal edition which will support 15 nodes will cost $99 per year, and will run on Macs and PCs.

Looking forward to this!

Cisco goes VIRL


Cisco VIRL


There is much chatter about Cisco's new VIRL, so here is what I have collated.

The Virtual Internet Routing Lab. It is a network virtualization platform that can run IOS-XE, IOS-XR, IOS and NXOS (as well as 3rd party appliances).

So you can run all your exisiting IOS based images along with Nexus switches, and high-end carrier-grade equipment.

Rumours are that this will completely replace the physical hardware used in the R+S exam when V5 comes out next year.

Platform

It looks like VIRL will be supplied as an OVA format within an Ubuntu OS, therefore will be usable on any desktop virtualization product. A bare-metal version will also be available to allow for larger topologies.

A game of two halves

VIRL will allow for for the topology to be designed on a laptop and executed on a separate server (or all on the same machine if you wish) as the UI designer (called Maestro) and engine (Auto net-kit) will be separate components. Once the you are happy with the design and layout you can then deploy the topology as a bunch of virtual machines that you can log into. XML will be used as the common back-end format.

Usability

VIRL will be less CPU intensive than GNS3/Dynamips, more like IOU/IOL in that respect - which makes sense from a evolutionary standpoint.

Connecting to actual hardware will be easy through the "Actual Hardware Asset" toolbox, because VIRL will lack the ASICs used by real switches this will be very useful.

Easy configuration for routing and IP addressing will borrow from PacketTracer, allowing for configuration through a GUI, making it easier for those less knowledgeable about Cisco configurations to set up training labs.

These screen shots are taken from the video presentation from Cisco - the link is at then end of this post.

The main screen allows us to formulate our network (similar to GNS3, PacketTracer, or IOU).

Cisco VIRL topology

More complex environments can be set up, such as MPLS networks (as shown below) where we just need to enter our MPLS VPN tags, and the configuration engine will create the IOS configs for us.

Cisco VIRL MPLS

The next screen shows us the map view

Cisco VIRL map

And from here we can select component layers from the drop down menu on the left hand side:

Cisco VIRL protocol drilldown

This allows is to see all the connections (say for a BGP network)

Cisco VIRL BGP connections

The topology can be over-layed on top of a map

Cisco VIRL map overlay

Release date

Expected early 2014

Price

Free for virtual appliance!

Video

Here is a video taster to whet your appetite!

Hands-on experience / Further reading

http://herdingpackets.net/2013/07/18/going-virl/
http://kemot-net.com/blog/virl-why-you-need-to-know-about-it