![Belden ThinkLogical TLX320 Product Manual Download Page 38](http://html1.mh-extra.com/html/belden/thinklogical-tlx320/thinklogical-tlx320_product-manual_2725552038.webp)
Page 32
TLX320 Matrix Switch Product Manual
thinklogical
Rev. I, May 2021
To verify the system
’s
Restricted Switching policy
, Thinklogical recommends the following:
1) Review the
daemon.log
file on the active Controller Card and correct any errors in the Restricted
Switching Table before implementing multiple levels of security classification domains on the
same Matrix Switch.
2) Fully test the
Restricted Switching
on the active Primary Controller Card before implementing
multiple levels of security classification domains on the same Matrix Switch.
3) In a redundant system, make the Back-Up Controller Card active by disconnecting the LAN cable
from the Primary Controller Card
’s LAN port. The Back-Up Controller Card, upon becoming active,
will evaluate its Restricted Switching Table. Check the
daemon.log
file on the Back-Up Controller
Card for any errors in the Restricted Switching Table and correct them before implementing
multiple levels of security classification domains on the same Matrix Switch
using the Back-Up
Controller Card.
4) Fully test the Back-Up Controller
Card’s
Restricted Switching
before implementing multiple
levels of security classification domains on the same Matrix Switch.
There are cases where updates to the Restricted Switching Table must be made in an active
system.
When an update is made to the table, the Controller will not evaluate the updated table until the
following procedures are followed:
When updates are made to the Restricted Switching Table in a
non-redundant system
, Thinklogical
recommends the following
(This procedure will be disruptive to system connections)
:
1) Update the Restricted Switching Table of the Primary Controller Card.
2) Take the Primary Controller Card out of service by following guidelines in the
“Safely Remove an
Active Controller Car
d” section of this document (pg. 20).
When updates are made to the Restricted Switching Table in a
redundant system
, Thinklogical
recommends the following
(This procedure will NOT be disruptive to system connections)
:
1) Update the Restricted Switching Table of the active Primary Controller Card. The table will not
take affect at this time.
2) Update the Restricted Switching Table of the inactive Back-Up Controller Card with the same
table used for the Primary Controller Card.
3) Take the Primary Controller Card out of service by typing
‘halt’ at the command line. This will
make the Back-Up Controller Card active and evaluate its Restricted Switching Table.
Thinklogical recommends verifying the changes to the Back-Up Controller Card.
4) Ensure that the LAN connection to the Primary Controller Card is connected. Extract the Primary
Controller Card, wait 10 seconds, then re-insert the Primary Controller Card back into the
chassis, allowing the system to make the Primary Controller Card the active controller and begin
using the updated Restricted Switching Table.
Note: When using a Back-Up Controller configuration, both controllers must have the same
Restricted Switching Table file(s) to maintain the security of the system.
Restricted Switching is disabled when Restricted Switching Table files are removed.
By default,
when there are no Restricted Switching Table files, all input and output ports will have a priority of 1. All
Switches are shipped without Restricted Switching Table files stored on the Controller Card and
therefore do not restrict any connection.