Campus Software Image Management Using Cisco DNA Center Deployment Guide
Campus Software Image Management Using Cisco DNA Center Deployment Guide
March, 2020
Reader tip
For more information on Cisco DNA Center supported devices please refer to the compatibility matrix information
https://www.cisco.com/c/en/us/support/cloud-systems-management/dna-center/products-device-support-tables-list.html
Use Cases
Standardize software images for your network devices with software image management (SWIM).
● The Define section presents a high-level overview of how software image management (SWIM) within Cisco DNA Center
can help reduce device installation and upgrade times from hours to minutes.
● The Design section discusses the pre-requisites for setting up software image management (SWIM) in a network with
Cisco DNA Center.
● The Deploy section of the guide shows how to standardize an image by marking as a golden image and go through the
update image workflow to distribute and activate the golden image on a network device.
● The Operate section briefly discusses the known caveats of software image management (SWIM) in Cisco DNA Center.
Reader tip
This guide only covers software image management (SWIM). For day-zero onboarding of a switch with Plug and Play (PnP) and return
merchandise authorization (RMA) refer to the following guide, Network Device Onboarding for Cisco DNA Center Deployment Guide.
Campus Topology highlighting Standardize software images for your network devices with SWIM.
Cisco DNA Center is designed for intent-based networking (IBN). The solution breaks the process in to Day 0 and Day N. The
solution provides a unified approach to provision enterprise networks comprised of Cisco routers, switches, and wireless devices
with a near zero touch deployment experience.
Reader tip
For more information on how to install Cisco DNA Center, refer to Cisco DNA Center Installation resources page.
3. CCO Credentials
Though this is not a mandatory requirement for SWIM but its strongly recommended to add CCO credentials. Otherwise,
certain features like ROMMON upgrade or suggested and latest image display list of images will not function. CCO
Credentials is also required to download the KGV file for Integrity Verification of Software Images.
Cisco DNA Center must be connected to Cisco (CCO) to display and allow you to select Cisco-recommended software images for
the devices that it manages.
Tech tip
As part of the Cisco DNA Center installation, you will be asked to complete a first-time setup wizard in which you will be required to
provide Cisco Credentials before the Terms and Conditions must be accepted. For any reason the Cisco Credentials need to be reentered
or changed please follow the instructions below.
Step 5. Enter the Cisco Connection Online (CCO) username and password.
The credentials (user and password) entered must have SUPER-ADMIN-ROLE OR NETWORK-ADMIN-ROLE privileges.
This process is used to import and upload the latest software images for a network device (example: Catalyst 9300 Series Switch)
to the Cisco DNA Center software image repository.
Tech tip
When doing a major code update (example: 16.9.1 to 16.11.1) there is additional delay due to ROMMON code upgrade
Cisco Catalyst 9300 Switch IOS XE Release 16.9.1 (Current) Install Mode (16.9.1)
Cisco Catalyst 9300 Switch IOS XE Release 16.9.3 (Upgrade image) Install Mode (16.9.3)
Images can be imported automatically through Cisco Connection Online (CCO) or manually uploaded. Cisco DNA Center perform
the following.
Cisco DNA Center displays the suggested and latest image list for each of the discovered device families.
Tech tip
CCO credentials are required for Cisco DNA Center to fetch and display the suggested list of images automatically. To learn how, refer
above to Process 1 (Option 1).
Use the following steps to apply software updates of images and software maintenance updates (SMUs) to the devices, by
importing the required images, marking images as golden, and applying images to devices.
Tech tip
For Cisco DNA Center to suggest Cisco recommended and latest images under image repository it requires CCO login as show above
in Process 1.
Tech tip
After you mark the Cisco-recommended image as golden, Cisco DNA Center automatically downloads the image from
cisco.com
Tech tip
Also select non-LDPE software image and avoid selecting the Licensed Data Payload Encryption (LDPE) software version as it
is a limited deployment export control version which limits IPSEC capabilities. An example of LDPE is
cat9k_iosxeldpe.X.X.X.SPA.bin, compared to non-LDPE cat9k_iosxe.X.X.X.SPA.bin
If the software image you would like to mark as golden is not available, you can upload the image manually.
Step 5. Under Image Repository, click Show Tasks to verify if the import was successful.
Step 6. Under Image Repository, click Imported Images to expand the list of all the imported images that are pending to be
assigned to a device family.
Step 8. The slide out panel will show the list of device series from CCO based on the selected image. Check the box next to
the Device Series and click Assign.
Step 11. (Optional) Click the pencil icon and select the appropriate role, to mark a Golden Image for specific device role.
Step 13. Verify image is marked as golden and ACCESS tag is selected.
Now that the image is in repository, it can be distributed and activated on the network devices. It’s recommended to run the
activation at a specified date and time to comply with existing network change windows.
Before pushing a software image to a device, Cisco DNA Center runs a compliance check of devices in inventory compared to the
images marked golden. Devices out of compliance with the golden image are marked as Need Update in inventory. If you have
not designated a golden image for the device type, then the device's image cannot be updated.
Cisco DNA Center also performs pre-checks on the device, such as checking the health of the CPU, disk space, and the route
summary etc. After it pushes a software image to a device, Cisco DNA Center repeats these checks to ensure that the state of
the network remains unchanged.
The following are the steps for distributing software images to the Catalyst 9300 switch or any network device in the inventory.
Step 1. From the main Cisco DNA Center dashboard navigate to Provision > Devices
Step 2. Click the devices focus which is set to Inventory by default and select Software Images.
Step 3. From the list of devices, locate the switch (example: AD1-9300.cisco.local)
If incorrect Golden Image is shown even after refreshing the page or running recheck the devices table, the image that is not set as Golden
Image anymore will need to be deleted from the image repository and then only the Need Update option will be available.
Step 5. Under Image Update Readiness Check, verify the correct Golden Image is shown.
Tech tip
Ensure that the Status column of all the checks shows either a green icon indicating success, or a yellow icon indicating a warning. If any
of the checks shows a red icon indicating failure, the image on the platform cannot be upgraded. If necessary, correct any issues on the
switch which resulted in a red icon indicating failure. Click the Recheck button in the upper right corner to re-run the readiness
assessment.
Step 6. Under the Actions drop-down menu, select Software Image > Update Image.
1. Distribute: Select Now or Later (recommended for production devices) and click Next.
2. Activate: Check Schedule Activation after Distribution is completed and click Next.
Tech tip
If you have scheduled the distribution and activation for a future date and/or time you can view the upcoming scheduled task.
Step 8. Verify the under the Software Image column, Need Update changed to In Progress.
Tech tip
During this process the device will reboot and become Unreachable for a while (15-30mins).
Verify the software image of the switch (example: AD1-9300.cisco.local) is now updated to the golden image (example: 16.9.3).