background image

Chapter 6

6 - 6

 You have completed the switch startup configuration.
 The switch will now initialize the local database.
 When the login prompt appears, log into the switch using
 the crypto-officer's username and password.

Closing configuration file.
Processing configuration file. (boot-config)

...

The boot-up prompts continue until you reach the “Username” prompt. 
Confirm that an administrator can log in by using the Crypto-Officer 
username and password that you entered in the initial-boot script. For 
example:

...

User Access Authentication

Username: 

admin

Password: 

mypassword

SWITCH>

The switch is now ready for configuration through the CLI. See the 

ARX 

CLI Network-Management Guide

 (on the documentation CD provided with 

the switch) for configuration instructions.

Preparing for Switch Replacement

For switch replacement, the above process becomes more complicated. This 
section provides instructions for replacing a defunct switch.

Choosing Switch Replacement

The initial-boot script asks if this is a switch replacement. Answer 

yes

 to 

invoke the questions that are required to replace the failed switch. For 
example,

...
A switch replacement requires additional configuration questions.
6. Are you doing a switch replacement?
   in the format 'yes' or 'no'.(default=no) # 

yes

Matching the Private Subnet

The next set of questions ask for the switch’s 

private subnet

, the 

private 

VLAN

 for that subnet, and the VLAN for a private 

metalog subnet

. If the 

failed switch was in a redundant pair and/or Resilient-Overlay Network 
(RON), the private subnets of the replacement switch should match those of 
the switch that failed. Each ARX uses its private subnet for communication 
with other ARXes in the same RON and/or the switch’s redundant peer. All 
private subnets in the RON and/or pair are carried by the same VLAN. This 
private VLAN, and the separate metalog VLAN, must be reserved for ARX 
traffic only.

Summary of Contents for ARX 1000

Page 1: ...ARX 1000 Hardware Installation Guide version 4 01 001 810 0006 00 ...

Page 2: ......

Page 3: ...t WebAccelerator and ZoneRunner are trademarks or service marks of F5 Networks Inc in the U S and other countries and may not be used without F5 s express written consent Patents This product has several patents pending Export Regulation Notice This product may include cryptographic software Under the Export Administration Act the United States government may consider it a criminal offense to expo...

Page 4: ...exporting Copyright c 1995 2001 International Business Machines Corporation and others All rights reserved Copyright c 1990 2003 Sleepycat Software All rights reserved Copyright c 1995 1996 The President and Fellows of Harvard University All rights reserved Copyright c 1998 2004 The OpenSSL Project All rights reserved Revision History June 2004 Rev A July 2004 Rev B September 2004 Rev C October 20...

Page 5: ...Table of Contents ...

Page 6: ......

Page 7: ... 5 Supported Protocols 2 5 Network 2 5 File Services 2 6 Security and Authentication 2 6 Management 2 6 3 Switch Hardware Chassis Overview 3 3 Interfaces 3 4 Application Control Module ACM 3 4 Control and Management Functions 3 4 Adaptive Services 3 5 Network Services 3 5 Power Supply 3 6 Internal Disks 3 6 Fan Unit 3 6 4 System Specifications and Requirements Regulatory Compliance 4 3 FCC Complia...

Page 8: ...4 Sample Booting a Non Replacement Switch 6 4 Preparing for Switch Replacement 6 6 Preparing to Install a Redundant Peer 6 9 Sample Replacing a Redundant Peer 6 10 Connecting the Ethernet Management Port 6 13 7 Operational Status and Troubleshooting POST Diagnostics 7 3 LED Status Indicators 7 5 Status LEDs 7 5 Ethernet Port Link Status LEDs 7 6 Hard Drive HD LED 7 6 A Removing a Hard Disk Removin...

Page 9: ......

Page 10: ...Table of Contents x ...

Page 11: ...RX 1000 and its hardware components It also describes how to install the switch and connect it to the network This chapter contains the following sections Audience for this Manual Document Conventions Related Documents Safety and Regulatory Notices Contacting Customer Service ...

Page 12: ......

Page 13: ...entions This manual uses the following conventions when applicable courier text represents system output bold text represents user input italic text appears for emphasis new terms and book titles Note Notes provide additional or helpful information about the subject text Important Important notices show how to avoid possible service outage or data loss WARNING Warnings are instructions for avoidin...

Page 14: ...s Important The maximum ambient room temperature that the unit can operate in is 55 C Important Do not block power supply vents or otherwise restrict airflow when installing unit in rack WARNING Mechanical loading of rack should be considered so that the rack remains stable and unlikely to tip over Class A ITE Label This is a Class A product based on the standard of the Voluntary Control Council f...

Page 15: ...and French translations as follows This digital apparatus does not exceed the Class A or B limits for radio noise emissions from digital apparatus set out in the Radio Interference Regulations of the Canadian Department of Communications This Class A or B digital apparatus complies with ICES 003 Le present appareil numerique n emet pas de bruits radioelectriques depassant les limites applicables a...

Page 16: ...through the use of a special tool lock and key or other means of security and is controlled by the authority responsible for the location ATTENTION Cet appareil est à installer dans des zones d accès réservé Ces dernières sont des zones auxquelles seul le personnel de service peut accéder en utilisant un outil spécial un mécanisme de verrouillage et une clé ou tout autre moyen de sécurité L accès ...

Page 17: ...onstitue la seule unité montée en casier elle doit être placée dans le bas Si cette unité est montée dans un casier partiellement rempli charger le casier de bas en haut en plaçant l élément le plus lourd dans le bas Si le casier est équipé de dispositifs stabilisateurs installer les stabilisateurs avant de monter ou de réparer l unité en casier Power Power Cord Usage WARNING Do not use the attach...

Page 18: ...s ports étiquetés LINK 1 1 through 1 6 CONSOLE MGMT MIRROR et DEBUG sont des circuits de sécurité basse tension safety extra low voltage ou SELV Les circuits SELV ne doivent être interconnectés qu avec d autres circuits SELV Circuit Breaker 15A WARNING This product relies on the building s installation for short circuit overcurrent protection Ensure that a fuse or circuit breaker no larger than 12...

Page 19: ... Replace the battery only with the same or equivalent type recommended by the manufacturer Dispose of used batteries according to the manufacturer s instructions ATTENTION Danger d explosion si la pile n est pas remplacée correctement Ne la remplacer que par une pile de type semblable ou équivalent recommandée par le fabricant Jeter les piles usagées conformément aux instructions du fabricant Inte...

Page 20: ...uestions https support f5 com F5 Services Support Online F5 s online customer knowledge base and support request system https www f5 com training support custome r support F5 Online Request Form https login f5 com resource login jsp E Mail support f5 com Telephone Follow this link for a list of international Support numbers https www f5 com training support cu stomer support contact ...

Page 21: ...Overview This chapter provides a general overview of the F5 ARX 1000 Topics include the following The ARX 1000 Hardware Features Redundant Pairs Resilient Overlay Network RON Switch Management Supported Protocols ...

Page 22: ......

Page 23: ...ol Module ACM provides a subset of features and components from the ARX 6000 s Adaptive Services Module ASM and Network Services Module NSM storage aggregation of multiple back end shares into a single client volume inline management of storage capacity to adapt the back end storage to client demands ability to add or remove back end storage without any effect on clients and the ability to seamles...

Page 24: ... These are configured as a RAID1 a redundant mirrored array of disks Either disk is hot swappable Redundant Pairs You can purchase two ARX 1000 switches and configure them as a redundant pair If the primary switch fails all services fail over to the secondary switch This is a highly available configuration The redundant switches are interconnected through one or more of their Gigabit Ethernet port...

Page 25: ...rminal and command line interface CLI Out of band 10 100 Ethernet port labeled MGMT for accessing the CLI from your management network Inband Ethernet interfaces for accessing the CLI your client or server networks Chapter 6 Connecting the Switch to the Network explains how to configure the first two management interfaces See the ARX CLI Network Management Guide and ARX CLI Reference for general i...

Page 26: ...e Agent See the Secure Agent Installation Guide for information Kerberos authentication for Windows clients Network Information Service NIS also known as YP Remote Authentication Dial In User Service RADIUS for administrators Management Simple Network Management Protocol SNMP Telnet SSH Secure SHell Hypertext Transfer Protocol HTTP Hypertext Transfer Protocol over SSH HTTPS For transferring mainte...

Page 27: ...3 Switch Hardware Chassis Overview Interfaces Application Control Module ACM Power Supply Internal Disks Fan Unit ...

Page 28: ......

Page 29: ...ion Figure 3 1 ARX 1000 Front Panel View The switch contains the following components Interfaces for client server traffic and system management Application Control Module ACM which supports all system control adaptive services and network functions for the switch Power supply module Internal hard disks Fan Unit The following sections describe these components ...

Page 30: ... Services Module NSM Control and Management Functions The ACM supports the following switch fabric and control functions RS232 Console serial interface for local switch management Out of band 10 100 Ethernet interface for local remote switch management Service definition and policy enforcement Failover signaling and configuration information Port mirroring and debugging MAC address assignment for ...

Page 31: ...twork Services The ACM supports the following network services Two 1000BASE X Gigabit Ethernet ports small form factor pluggable SFP optical connectors Four 100 1000BASE T Ethernet ports RJ 45 connectors Auto negotiation for 100 1000 Ethernet transmission Standard Ethernet and jumbo frame 9K packet sizes Full duplex switching at line rates for Layer 2 processing Low latency store and forward switc...

Page 32: ...aintains full regulated load for a minimum of 20 milliseconds enabling the system to shut down power gracefully Internal Disks The switch uses internal disk drives to store its software image configuration files log files and other maintenance related data The ARX 1000 contains two redundant SATA drives configured RAID1 These drives are connected to the primary controller on the Application Contro...

Page 33: ...ements This chapter contains regulatory information and specifications for the ARX 1000 Regulatory Compliance FCC Compliance System Specifications System Power Requirements Power Cord and Cable Requirements Cable Connectors and Pinouts ...

Page 34: ......

Page 35: ...lass A digital device pursuant to part 15 of the FCC Rules These limits are designed to provide reasonable protection against interference when the equipment is operated in a commercial environment This equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the instruction manual may cause harmful interference to radio communications Operat...

Page 36: ... includes front bezel Height 3 375 in Width 19 00 in including the fixed mounting ears Depth 23 75 in Weight 35 lb 15 88 kg Power Load 5 7 amps 110Vac 3 1 amps 220Vac AC DC Power Supply 450 Watts 2 5 V 3 3 V and 12 0 V Note that the power supply draws a total of 608W from the AC power cord due to its operating efficiency Environmental Requirements Altitude 200 ft 60 m min to 8000 ft 2500 m max Hum...

Page 37: ...s 4 copper Gigabit Ethernet ports a100 1000BASE T Category 5 6 unshielded twisted pair UTP cable 24 AWG a Gigabit Ethernet ports support automatic MDI MDIX cross over This feature automatically corrects the polarity of the attached CAT5 cable regardless if it is a cross over or straight through type However for this feature to work the port speed must be set to auto auto negotiate through the CLI ...

Page 38: ...Gigabit Ethernet Optical ports small form factor pluggable SFP Two optical ports for 1 Gbps Ethernet connections over multi mode fiber Copper ports RJ 45 Four 100 1000BASE T Ethernet ports Important Fiber optic ports are shipped with cable connectors installed These ports must be protected by a rubber grommet filler or a cable connector at all times to prevent dust from collecting in the transceiv...

Page 39: ...5 Male Connector Figure 4 2 RJ 45 to Serial DB9 Adapter Table 4 4 lists the RJ 45 pinout assignments for the rollover cable and the adapter The left column shows the transmit TxD ground GND and receive RxD signals and the right column shows the signals reversed at the console device The intervening columns show the pins that carry each of those signals SCM ACM Console Port RJ 45 Rollover Cable RJ ...

Page 40: ...NING Fiber optic ports are shipped with SFP optics installed These ports must be protected by a rubber grommet filler or a cable connector at all times to prevent dust from collecting in the transceiver GND 4 green 5 5 green 5 Signal Ground GND 5 red 4 4 red RxD 6 black 3 3 black 3 TxD SCM ACM Console Port RJ 45 Rollover Cable RJ 45 to DB9 Adapter Console Device Table 4 4 ACM Console Port Signalin...

Page 41: ...s chapter describes the following topics and tasks Safety Instructions Tools and Equipment Verifying Shipment Unpacking the Switch Installing the Rack Mount Rails Rack Mounting the Switch Attaching the Power Cord Powering Up the Switch Cabling ...

Page 42: ......

Page 43: ...k of the switch and make sure it is set to OFF Disconnect any power or external cables before moving the switch Disconnect the power cord before servicing the unit to avoid electric shock Tools and Equipment You need the following equipment for unpacking rack mounting and installing the switch Utility knife optional for the packaging Phillips screwdriver for 10 screws A laptop or PC to use as a se...

Page 44: ... Tinnerman nut retainers 12 nuts per set each set fits a different type of rack rail ARX 1000 Quick Installation Card ARX 1000 Hardware Installation Guide this manual Unpacking the Switch The ARX 1000 switch is shipped in a single box with all components installed The switch weighs approximately 35 lb without packaging Unpack the switch as follows 1 First inspect the box for any shipping damage 2 ...

Page 45: ...e depth of the rails by loosening or tightening the locking screws with a Phillips head screwdriver 3 Secure the rails in place on both ends of the rack with the rack mount screws 4 per rail shipped in the accessory kit a Place the bottom screws loosely in the rack If there are no threads in the rack rails thread the screws through the Tinnerman nut retainers provided in the accessory kit b Set th...

Page 46: ...e the switch into place on the rails Figure 5 2 Aligning Switch with Rack Rails 3 Secure the switch to the rails by putting a screw through each ear on the front of the ARX This guards against the switch sliding out in the event of an extreme earthquake screw hole Firmly grip the switch edges and slide the switch into place on the rails ...

Page 47: ...rd and Cable Requirements on page 4 5 for power cord and cable specifications Powering Up the Switch WARNING Before applying power ensure that the AC outlet to the switch is properly grounded To power up the switch turn the ON OFF toggle switch es to the ON position Cabling You can cable the client server ports before or after the switch is connected to the network Ethernet cables are supplied by ...

Page 48: ...Chapter 5 5 8 ...

Page 49: ...chapter describes how to connect the ARX to a console terminal and boot the switch for the first time It contains the following sections Management Interfaces Connecting the Console Port Booting the Switch Connecting the Ethernet Management Port ...

Page 50: ......

Page 51: ...ibed in this chapter you can only access the serial Console port You configure the OOB management port MGMT as part of the procedures in this chapter Connecting the Console Port Set the following console terminal parameters to match those on the Console port 9600 baud rate default XON XOFF flow control 8 data bits 1 stop bit parity Connect the console terminal to the serial Console port RJ 45 on t...

Page 52: ... initial boot scenario for a new non replacement switch that is either standalone or the first member of a redundant pair The sample answers are not necessarily appropriate to the following scenarios this replaces a defunct switch this will join a running switch as its redundant peer or this switch is being re installed after F5 personnel performed a Manufacturing Installation on a previously runn...

Page 53: ...ult no no The crypto officer is the most privileged user in the system 7 Enter the crypto officer username in the format text 1 28 characters admin 8 Enter the crypto officer password in the format text 6 28 characters mypassword Confirm the crypto officer password mypassword A system password is required for access to the master key 9 Enter a system password in the format text 12 28 characters d0...

Page 54: ...es more complicated This section provides instructions for replacing a defunct switch Choosing Switch Replacement The initial boot script asks if this is a switch replacement Answer yes to invoke the questions that are required to replace the failed switch For example A switch replacement requires additional configuration questions 6 Are you doing a switch replacement in the format yes or no defau...

Page 55: ...et mask in the format nnn nnn nnn nnn default 255 255 255 0 Enter The private subnet VLAN is used externally for redundancy traffic Be sure this value does not conflict with existing VLAN IDs 9 Enter the chassis s private subnet VLAN in the format integer 1 4095 default 1002 Enter The private subnet metalog VLAN is used for storing file change logs on battery backed NVRAM possibly on a redundant p...

Page 56: ... 47 ONLINE d9bdece8 9866 11d8 91e3 f48e42637d58 10 1 1 7 provA5c None 0 days 02 01 04 ONLINE db922942 876f 11d8 9110 8dtu78fc8329 10 1 38 19 prtlndA1k prtlndA1kB 0 days 00 30 53 OFFLINE 876616f6 79ac 11d8 946f 958fcb4e6e35 10 1 23 11 bstnA6k Applying the UUID The initial boot script has a prompt for the UUID shown in the example above This is where you enter the UUID of the replaced switch For exa...

Page 57: ...characters At least one character in this password must be a number 0 9 or a symbol and so on Save this password you will need it to decrypt the master key later on the new switch This command outputs a base64 encoded string that is the encrypted master key Save this string and the wrapping password that you set in the command For example this shows the master key on a switch named prtlndA1kB prtl...

Page 58: ... in the format nnn nnn nnn nnn default 255 0 0 0 255 255 255 0 The switch s management port requires a gateway IP address 5 Enter the gateway IP address for the management interface in the format nnn nnn nnn nnn or none 10 1 23 1 This next question invokes the questions for switch replacement A switch replacement requires additional configuration questions 6 Are you doing a switch replacement in t...

Page 59: ...ndant peer The master key is used to encrypt critical security parameters 15 Enter the master key in the format base64 encoded key or keyword generate default generate 2oftVCwAAAAgAAAApwazSRFd2ww H1pi7R7JMDZ9SoIg4WGA XsZP HcXjsIAAAADDRbMCxE bc The wrapping password is used to encrypt and decrypt the master key 16 Enter the wrapping password in the format text 6 28 characters an0ther ecretpw Confir...

Page 60: ...ll local parameters such as the hostname and the network settings SWITCH ARX1000 SWITCH Version 1 01 000 05876 Aug 15 2004 19 18 40 nbuilds BETA SWITCH System UUID 876616f6 79ac 11d8 946f 958fcb4e6e35 SWITCH SWITCH config SWITCH cfg logging level all notice SWITCH cfg exit SWITCH system SWITCH config SWITCH cfg clock timezone 5 SWITCH cfg hostname prtlndA1k prtlndA1k cfg prtlndA1k cfg exit prtlndA...

Page 61: ... GUI or the Command Line Interface CLI To access the GUI direct a web browser to the interface over HTTPS for example https 10 1 23 11 Use the crypto officer username and password entered above to log in For the CLI use SSH with the interface and the crypto officer username for example ssh admin 10 1 23 11 The ARX GUI Quick Start Network Setup manual contains instructions for getting started with ...

Page 62: ...Chapter 6 6 14 ...

Page 63: ...tus and Troubleshooting This chapter describes the ARX 1000 hardware power on self test POST diagnostics and module and port status indicators LEDs and their associated conditions POST Diagnostics LED Status Indicators ...

Page 64: ......

Page 65: ...1 53 nbuilds Armed Release test3 rel Version 3 00 000 10557 Oct 10 2007 18 11 53 nbuilds Backup Release test1 rel Version 2 06 000 10247 Aug 31 2007 18 27 12 nbuilds System Configuration Version 300000 24 prtlndA1k uptime is 0 weeks 0 days 1 hours 42 minutes Slot Admin ModuleType ModuleState FW Upgrade 1 Enabled ACM Online Disabled Resource State Forwarding Switch Up Disabled Figure 7 2 Show Chass...

Page 66: ...0 10538 Slot FPGA Version NSM Boot Version NSM Diag Version NSM BootLdr Version 1 franklog 23 3 00 000 10538 3 00 000 10538 3 00 000 10538 Port Media Details Slot Port Type vendor Status 1 1 N A N A Not Present 1 2 N A N A Not Present Disk Usage Name Total MB Used MB Free MB Used System 1540 1021 440 70 Releases 3038 1972 911 69 Logs 2105 62 1935 4 Cores DiagInfo Lists 8582 202 7943 3 Reports Scri...

Page 67: ...4 on page 7 5 Figure 7 3 ARX 1000 System LEDs Figure 7 4 ARX 1000 Port LEDs Status LEDs The ARX 1000 front panel provides the following LED status indicators ALERT Illuminates Red to indicate an operational failure STATUS Illuminates Green or Yellow based on the system s current operational state system Alert red if hardware fails module Status green all OK yellow at least one failed Hard Disk act...

Page 68: ...pper left Activity LED blinking yellow indicates packet traffic Upper right Link status LED steady green indicates that the port is enabled and a link is established Hard Drive HD LED The hard drive HD LED is not supported ALERT STATUS State Off Green Online Red Green Blinking Failed or powering down Off Yellow Blinking Powering up and running all POST tests Off Yellow Online Partial at least one ...

Page 69: ...A Removing a Hard Disk This appendix describes how to remove and replace a disk drive in the ARX 1000 chassis Removing the Drive Silencing the RAID Alarm Replacing the Disk Drive ...

Page 70: ......

Page 71: ...ore handling disk drives Carefully remove the front bezel to expose the disk drives The two replaceable drives are on the right side of the front panel one over the other Each drive is held in place with two captive screws To remove a disk drive use a Phillips head screwdriver to loosen both captive screws Slide out the disk drive and sled from its slot in the chassis The chassis continues to run ...

Page 72: ...To replace the disk drive slide it into the empty slot and tighten its two captive screws The screws should be at least finger tight for the drive to properly engage Incorporating the Disk into the RAID To incorporate the disk into the RAID use the raid rebuild command from priv exec mode raid rebuild disk1 disk2 where disk1 disk2 specifies the disk to rebuild The top disk is disk1 For example the...

Page 73: ... Rate 1 Optimal Manual 10 Disk Details Disk Size State Transfer Rate Model Bay 1 68 50G Online 320MB sec ATLAS10K4_73SCA Bay 2 68 50G Rebuild 21 320MB sec ATLAS10K4_73SCA RAID Controller Details Rebuild Rate Max Transfer Rate Firmware RAID Alarm 90 320MB sec TL37 G117 Enabled Disk Usage Name Total MB Used MB Free MB Used System 2121 998 1014 50 Releases 4234 1701 2317 43 Logs 2121 99 1914 5 Cores ...

Page 74: ...Appendix A A 6 ...

Page 75: ...Index ...

Page 76: ......

Page 77: ...liance 4 3 File service protocols supported 2 6 Front bezel A 1 FRUs and static electricity A 3 disk drive A 1 H Hard disks in an ARX1000 3 6 Hardware 3 3 I IDE hard drive LEDs 7 6 L LEDs conditions and blinking patterns 7 5 front panel fig 7 5 port link LEDs 7 6 system status and alert 7 5 M Management port 6 3 connecting 6 13 Management ports 3 4 Management protocols supported 2 6 MGMT interface...

Page 78: ... 4 for a redundant switch 6 9 for a replacement switch 6 6 Switch cable connectors 4 6 Switch Installation unpacking and installing the chassis 5 1 Switch installation See Also Switch boot up safety instructions 5 3 tools required 5 3 Switch LEDs fig 7 5 Switch management ports 3 4 6 3 Switch replacement See Switch Installation and Switch boot up for a replacement switch Switch to switch failover ...

Reviews: