My quick comments on the Cisco Live! Session regarding Auto Config Deploument using Cisco Config Engine (CCE).
The first session I went to today was “Automatic Configuration Deployment Using Cisco Configuration Engine (CCE)”, session BRKNMS-2784. It was interesting to see, because I haven’t had hands on experience with CCE in the past. Based on what I saw, I won’t have hands on experience with it anytime in the future either.
This session was a very basic overview of what the engine offers, how it’s built out, some sample configs, and customer case studies. The basics for those who haven’t used it before, are that it’s an initial provisioning services and config template pusher. It does not perform configuration auditing or versioning. It seems strongly targeted at customers doing large deployments, carrier situations, etc.
The product is several years old, previously under the “CNS Intelligence Engine” product name. This is where I found it to be sort of strange. The product has been out for so long, but has poor support among Cisco’s product offering. It only “truly” supports IOS based devices. If you want to manage IOS XR or NX-OS, you will be out of luck with their main support method. If you’re using a product like Cisco wireless controllers, you can forget it. After so many years on the market, it seems like Cisco should have had a mandate across all business units to utilize a system like this. Instead, you end up with a wireless provisioning WCS, a switch/router provisioning CCE, a voice phone provisioning system, etc. Perhaps that’s the best model, but if you’re building this type of software in house to manage things, you’d likely focus on a very detailed template system that is flexible enough to handle any device you throw at it.
Cisco can handle systems that don’t have the CNS agent on them, but it’s using telnet/ssh scripts, which are less than optimal as you make subtle changes to syntax and provisioning code over time.
They also tout Zero-Touch Service Deployment, that only requires you to touch the backend server to assign templates to a device. (What?). The end device that is being provisioned then pulls its basic configuration from a TFTP server that was configured via DHCP. Their one-touch deployment requires just very basic configuration on the device to get CNS enabled and pointing to a server.
The backend server part can be made less painful I’m sure, by automating a process when you scan the serial number or MAC off of the box when its delivered, but even that is too much for me. It wouldn’t work in all situations, but it seems if they had the ability to make calls to your IPAM system and you could setup a few rules around it, it could auto determine 100% of the devices functionality and what IPs to assign to it and basic port/route configuration in some specific situations. It could do this based on looking at the devices CDP neighbors, perhaps you setup a rule that anytime a switches cdp neighbor is a 6408 on your 6509, and it sources from a remote office subnet, that it must be a new IDF switch, etc.
This also doesn’t work if the device you are provisioning can’t achieve IP service on its own. As someone in the audience pointed out, how exactly could CCE be used over the WAN to provision a new MPLS router? Sure, you could use a USB thumb drive with the config, if your router supports USB thumb drives. You could even take a Linksys WRT54G-L with OpenWRT on it and serve the initial configurations to the router from there, so the person racking the gear doesn’t really have to do anything directly on it. However, it’s still another process that isn’t quite automated. You can also use Cisco’s Configuration Express service, where Cisco pre-configures the device for you.. but, do you want a router pre-configured with your MPLS configuration in the hands of UPS and some stranger? I wouldn’t personally, but each persons network design and requirements are different.
All and all, this product may be perfect for some service providers, and probably fits quite well into the way some IT shops operate. However, at a holistic view of managing an enterprise with it, the idea of having a different configuration provisioning system for every different basic category of system on the network, with the soul purpose of pushing an initial config, pushing firmware, and pushing out config snippets, I’d rather see something that integrates into a much larger product line. I believe many companies with extra software people around could code most of this functionality themselves using Auto-Configure on the switches.
I expect more out of this software. I expect Cisco to require most of their internal business units to support CNS on their equipment, and not allow them to release initial versions without it. If it’s so open, and so “extensible”, why don’t they support it? How can this be focused on route/switch right now, and yet Cisco’s newest routers/switches aren’t supported by it depending on what code you load? I can see a case for something like voice to be broken off, but not different versions of switch or router software or wireless controllers, etc. Cisco could continue to offer those other softwares, but have dual support. Cisco did at least go with Velocity for a standard template mechanism, so hopefully we’ll see that support among other software products at Cisco.
One last important note, when you are trying to have a slice of delicious NY style Rocco’s pizza, skip the $120 round trip cab ride and use the free shuttle from the strip to the Red Rock Casino.. Too bad I figured that out after the fact.




