21-11
Cisco ONS 15454 Procedure Guide, R5.0
March 2005
Chapter 21 DLPs A400 to A499
DLP-A433 Enable Node Security Mode
DLP-A433 Enable Node Security Mode
Caution
The IP address assigned to the TCC2P LAN port must reside on a different subnet from the backplane
LAN port and the ONS 15454 default router. Verify that the new TCC2P IP address meets this
requirement and is compatible with ONE 15454 network IP addresses.
Note
The node will reboot after you complete this task, causing a temporary disconnection between the CTC
computer and the node.
Step 1
Click the
Provisioning > Security > Data Comm
tabs.
Step 2
Click
Change Mode
.
Step 3
Review the information on the Change Secure Mode wizard page, then click
Next
.
Step 4
On the TCC Ethernet Port page, enter the IP address and subnet mask for the TCC2P LAN (TCP/IP) port.
The IP address cannot reside on the same subnet as the backplane LAN port, nor the ONS 15454 default
router.
Step 5
Click
Next
.
Step 6
On the Backplane Ethernet Port page, modify the backplane IP address, subnet mask, and default router,
if needed. (You normally do not modify these fields if no ONS 15454 network changes have occurred.)
Step 7
Click
Next
.
Step 8
On the SOCKS Proxy Server Settings page, choose one of the following options:
•
External Network Element (ENE)
—If selected, the CTC computer is only visible to the ONS
15454 to which the CTC computer is connected. The computer is not visible to the DCC-connected
nodes. In addition, firewall is enabled, which means that the node prevents IP traffic from being
routed between the DCC and the LAN port.
•
Gateway Network Element (GNE)
—If selected, the CTC computer is visible to other
DCC-connected nodes. The node prevents IP traffic from being routed between the DCC and the
LAN port.
Note
The SOCKS proxy server is automatically enabled when you enable secure mode.
Purpose
This task enables the ONS 15454 security mode. When security mode is
enabled, two IP addresses are assigned to the node. One address is assigned
to the backplane LAN port and the other to the TCC2P RJ-45 TCP/IP
(LAN) port.
Tools/Equipment
TCC2P cards must be installed.
Prerequisite Procedures
NTP-A108 Back Up the Database, page 15-4
DLP-A60 Log into CTC, page 17-66
Required/As Needed
As needed
Onsite/Remote
Onsite or remote
Security Level
Superuser
Summary of Contents for ONS 15454 Series
Page 28: ...Tables xxviii Cisco ONS 15454 Procedure Guide R5 0 December 2004 ...
Page 44: ...Tasks xliv Cisco ONS 15454 Procedure Guide R5 0 December 2004 ...
Page 53: ...liii Cisco ONS 15454 Procedure Guide R5 0 December 2004 About this Guide Document Conventions ...
Page 55: ...lv Cisco ONS 15454 Procedure Guide R5 0 December 2004 About this Guide Document Conventions ...
Page 850: ...Index IN 22 Cisco ONS 15454 Procedure Guide R5 0 December 2004 description 4 11 remove 18 23 ...