38
TLX48 Matrix Switch Product Manual
thinklogical
Rev. B, April, 2016
At system power up, upon becoming active after the initial boot-up, the
Primary Control Card
will only evaluate
its Partition Table (upstream.csv file) once. The
Secondary Control Card
will NOT evaluate its Partition Table
(upstream.csv file) at initial boot-up, but rather when a switchover occurs from Primary to Secondary Active. If
an
upstream.csv
file is found, a log entry to the
deamon.log
file is made indicating “Partition ENABLED”. If
no file is found, then a lo
g entry of “Partition DISABLED” is made,
Note: The inactive Secondary Control Card will not verify its Partition Table (csv file), and as a
result, not log error messages with current time-stamp entries until it becomes active.
Also, any
errors that occur during the Partition Table evaluation process will be logged as “error” with a
field
and line invalid
identifier. The
daemon.log file
will be at the following location on the control card:
/var/log/daemon.log
Note:
For access to the
daemon.log
file via SSH, refer to “THE NETWORK INTERFACES”
section of this manual (page 10) for correct IP addresses of control cards when in Primary
Active or Secondary Active mode.
To verify the
system partition policy
, Thinklogical recommends the following:
1) Review the
daemon.log
file on the active control card and correct any errors in the Partition Table before
implementing multiple levels of security classification domains on the same Matrix Switch
.
2) Fully test the
Partitioning
on the active Primary Control Card before implementing multiple levels of
security classification domains on the same Matrix Switch.
3) In a redundant system, make the Secondary Control Card active by disconnecting the LAN cable from
the Primary Control Card
’s LAN port. Check the
daemon.log
file on the Secondary Control Card for any
errors in the Partition Table and correct them before implementing multiple levels of security classification
domains on the same Matrix Switch
using the Secondary Control Card.
4) F
ully test the Secondary Control Card’s
Partitioning Domains
before implementing multiple levels of
security classification domains on the same Matrix Switch.
There are cases where updates to the Partition Table need to be made in an active system.
When an
update is made to the table, the Controller will not evaluate the updated table until the procedures outlined
below are followed.
When updates are made to the Partition Table in a
non-redundant system
, Thinklogical recommends the
following
(This procedure will be disruptive to system connections)
:
1) Update the Partition Table of the Primary Control Card
.
2) Take the Primary Control C
ard out of service by following guidelines in the “Safely Remove an Active
Control
Card” section of this document (page 23).
When updates are made to the Partition Table in a
redundant system
, Thinklogical recommends the following
(This procedure will NOT be disruptive to system connections)
:
1) Update the Partition Table of the inactive Secondary Control Card
.
2) Take the Primary Control C
ard out of service by following guidelines in the “Safely Remove an Active
Control Card” section of this document (page 23). This will cause the Secondary Control Card to become
active and evaluate its Partition Table.
3) Update the Partition Table of the inactive Primary Control Card with the same table used for the
Secondary Control Card.
4) Extract and re-inserted the Primary Control Card back into the chassis to cause the system to make the
Primary Control Card the active controller and begin using the updated Partition Table. Insure that the
LAN connection to the Primary Control Card is restored promptly.
Note: When using a Back-up Controller configuration, both controllers must have the same
Restricted Switching Table file(s) to maintain the security of the system.