background image

Page 40 

 

TLX640 Matrix Switch Product Manual          

thinklogical

 

Rev. H, February 2020 

At  system  power  up,  after  initial  boot-up,  the 

Primary  Controller  Card

  will  only  evaluate  its  Partition 

Table (upstream.csv file) once upon becoming active. The 

Back-Up Controller Card

 will NOT evaluate 

its Partition Table (upstream.csv file) at initial boot-up, but rather when a switchover occurs from Primary 
Active to Back-Up Active.  If  an 

upstream.csv

 file is found, a log entry to the 

deamon.log

 file is made 

indicating 

“Partition ENABLED.” If no file is found, then a log entry of “Partition DISABLED” is made. 

The  inactive  Back-Up  Controller  Card  will  not  verify  its  Partition  Table  (csv  file),  so  it  will  not  log  error 
messages with current time stamp entries until it becomes active. Also, any errors that occur during the 
Partition  Table  evaluation  process  will  be  logged  as 

“error”  with  a 

field  and  line  invalid

  identifier.  The 

daemon.log file

 will be at the following location on the controller card: 

/var/log/daemon.log

.

 

For  access  to  the 

daemon.log

  file  via  SSH,  refer  to  THE  NETWORK  INTERFACES  section  of  this 

manual  (pg.  5)  for  correct  IP  addresses  of  controller  cards  when  in  Primary  Active  or  Back-Up  Active 
mode. 

To verify the system

’s

 Partitioning policy

, Thinklogical recommends the following: 

1) Review  the 

daemon.log 

file  on  the  active  controller  card  and  correct  any  errors  in  the  Partition 

Table  before  implementing  multiple  levels  of  security  classification  domains  on  the  same  Matrix 
Switch. 

2) Fully  test  the 

Partitioning

  on  the  active  Primary  Controller  Card  before  implementing  multiple 

levels of security classification domains on the same Matrix Switch. 

3) In a redundant system, make the Back-Up Controller Card active by disconnecting the LAN cable 

from  the  Primary  Controller  Car

d’s  LAN  port.  Check  the 

daemon.log 

file  on  the  Back-Up 

Controller Card for any errors in the Partition Table and correct them before implementing multiple 
levels of security classification domains on the same Matrix Switch

 

using the Back-Up Controller 

Card. 

4) Fully  test  the  Back-Up  Controller 

Card’s 

Partitioning  Domains

  before  implementing  multiple 

levels of security classification domains on the same Matrix Switch. 

There are cases where updates to the Partition Table need to be made in an active system.

 When 

an  update  is  made  to  the  table,  the  Controller  will  not  evaluate  the  updated  table  until  the  procedures 
outlined below are followed. 

When updates are made to  the Partition Table in a 

non-redundant system

, Thinklogical recommends 

the following 

(This procedure will be disruptive to system connections)

1) Update the Partition Table of the Primary Controller Card. 

2) Take the Primary Controller Card out of service by following guidelines in th

e “Safely Remove an 

Active Controller Car

d” section of this document (pg. 22). 

When  updates  are  made  to  the  Partition  Table  in  a 

redundant  system

,  Thinklogical  recommends  the 

following 

(This procedure will NOT be disruptive to system connections)

1) Update the Partition Table of the inactive Back-Up Controller Card. 

2) Take the Primary Controller Card out of service by following guidelines in the 

“Safely Remove an 

Active Controller 

Card” section of this document (pg. 22). This will cause the Back-Up Controller 

Card to become active and evaluate its Partition Table. 

3) Update the Partition Table of the inactive Primary Controller Card with the same table used for the 

Back-Up Controller Card. 

4) Extract and re-inserted the Primary Controller Card back into the chassis to cause the system to 

make  the  Primary  Controller  Card  the  active  controller  and  begin  using  the  updated  Partition 
Table. Ensure that the LAN connection to the Primary Controller Card is restored promptly. 

Note:  When  using  a  Back-Up  Controller  configuration,  both  controllers  must  have  the 
same Partition Table file(s) to maintain the security of the system.

 

Содержание Thinklogical TLX640

Страница 1: ...Rev H February 2020...

Страница 2: ...U S A Telephone 1 203 647 8700 All trademarks and service marks are property of their respective owners Subject TLX640 10G Matrix Switch Product Manual Revision H February 2020 Website https www think...

Страница 3: ...ECTION 2 SET UP AND INSTALLATION 13 Contents 13 Unpacking the TLX640 13 Connecting to the TLX640 14 Ethernet Control 14 TLX640 DIP Switch Settings 14 Redundancy and Network Requirements 14 External Co...

Страница 4: ...Zealand 27 European Union 27 Declaration of Conformity 27 Standards with Which Our Products Comply 27 Supplementary Information 28 Product Serial Number 28 Connection to the Product 28 SECTION 4 THIN...

Страница 5: ...d NATO NIAPC Evaluation Scheme GREEN and the U S DoD DISA JITC UCR 2013 APL information assurance standards And Thinklogical Velocity products are the first system with both KVM and video matrix switc...

Страница 6: ...f the manual Note and Warning Symbols Throughout this manual you will notice certain symbols that bring your attention to important information These are Notes and Warnings Examples are shown below No...

Страница 7: ...paration between potential threats users and the target secure data is essential to a secure system design Thinklogical s system permits users to access sources up to 80 kilometers away with no perfor...

Страница 8: ...for replacement If you suspect a problem with the Interconnect Card call us at 203 647 8700 for assistance Thinklogical s TLX640 line replaceable modules include 2 Redundant Current Sharing Power Supp...

Страница 9: ...populated with modules THE CONTROLLER CARDS The hot swappable Controller Card connects the Matrix Switch to an External CPU The RS 232 serial port may be used for third party controller integration s...

Страница 10: ...can be set from 15 to 45 The default subnet used by the TLX640 is 192 168 13 xxx The user may use their own subnet by reconfiguring the switch s network startup This is detailed in the document Manua...

Страница 11: ...0 7 0x00 and 0xff are ignored SNMP SUPPORT The TLX640 can be monitored via SNMP Simple Network Management Protocol supports version V2c and V3 USM Please call our technical support staff at 1 203 647...

Страница 12: ...one DB9 DCE A straight cable is needed to connect to a PC not a null modem ASCII API RS232 Baud Rate 9600 Data Bits 8 Parity none Stop Bits 1 Flow Control XON XOFF Software DB9 DCE A straight cable is...

Страница 13: ...tics SFP Individual I O Cards list the ports as 1 through 20 on the TLX640 A blue LED located on each I O card indicates when power is ON to that card PORT NUMBERING The TLX640 can have a minimum of o...

Страница 14: ...12Gpbs asynchronous switch that can connect any input to any output of Thinklogical s TLX VX and MX Matrix Switches Video and Data signals are routed in both directions and the data stream is de multi...

Страница 15: ...Switch Card without shutting down the TLX640 The hot swappable feature allows easy replacement of a Switch Card without shutting down the TLX640 Card 8 Card 1 TLX640 Switch Cards TLX640 FEATURES Each...

Страница 16: ...nd the Controller Power 3 3V in both the Upper and Lower Card Cages is applied Warning KEEP THE DOOR CLOSED WHEN IN USE The TLX640 Front Door contains air flow baffles that are integral to the unit s...

Страница 17: ...00 1244 6 mm Depth 16 07 408 2 mm Width 17 16 435 9 mm Weight Fiber or CATx 132 0 lbs 59 9 kg Shipping Weight 160 0 lbs 72 6 kg Ports 20 x 20 min 640 x 640 max ENVIRONMENTAL Temperature Operating 0 to...

Страница 18: ...be mounted in a standard EIA 19 rack All physical connections to the product use industry standard connectors Non supplied cables that may be needed are commercially available All connections are fou...

Страница 19: ...ts are not possible then the control server will require two 2 network interfaces with one interface set to the static address 192 168 13 9 and dedicated to the TLX640 KVM Matrix Switch s while the ot...

Страница 20: ...n that allows it to communicate with both the Primary Controller and a server with the IP address 192 168 13 9 Without this interface the Back up Controller cannot take control of the switch Pluggable...

Страница 21: ...can extend up to a maximum of 400m and Single mode fiber can extend up to 80km T R T R LC LC Transmit Receive Handling Fiber optic Cable Unlike copper cabling fiber optic cable requires special handli...

Страница 22: ...trix Switch Product Manual thinklogical Rev H February 2020 TLX Extender Fiber Optic Cable Configurations SINGLE VIDEO MODULES DUAL VIDEO MODULES Note On Dual Video models SFPs 1 2 are Video 1 and SFP...

Страница 23: ...Cable Configurations There are currently several versions of CATx category 5 5a 6 6a etc cables on the market Thinklogical recommends using a minimum of CAT6 for your TLX KVM Matrix Switch and Extensi...

Страница 24: ...0 I O Card numbers the ports 1 through 20 An LED located on each card indi cates when power is applied to that card Input Output Port Numbering on the TLX640 At the bottom of the Lower Cage and at the...

Страница 25: ...S devices audio keyboard mouse etc are connected to the Receiver first using standard cables Power can then be applied to the unit The Receiver then connects to the TLX640 Receiver ports using fiber M...

Страница 26: ...and and must end with a carriage return CR and line feed LF or just a line feed LF The characters are not echoed The serial port is configured for 9600 baud 1 stop bit no parity and no flow control Th...

Страница 27: ...lt in timeout function therefore the PC should not be taken out of service for an extended period The timeouts can be set in increments of one second Typical timeouts are in the order of 10 seconds Or...

Страница 28: ...ned off on the TLX640 Remove the AC power cord s from the Matrix Switch or from the AC source for a complete system shut down Remove any cables LAN RS 232 Console etc from the Control Cards The Contro...

Страница 29: ...ed arrows right 5 Place the new module upright so that the four Status LEDs are at the bottom Grasp the module by the handles The card should slide in freely until it reaches the backplane connector A...

Страница 30: ...e card and start over 3 Once the module is completely seated hand tighten the thumbscrews Do not tighten the thumbscrews with a screwdriver How to Replace a Fan Tray The TLX640 uses three DC fans to m...

Страница 31: ...he backplane connector At this point use just enough force to firmly engage the card with the mating connector Ensure the locking mechanism snaps closed If the module does not slide easily into the co...

Страница 32: ...t Canadian Radiation Emitting Devices Act REDR C1370 IEC 60825 2001 Parts 1 and 2 Class 1 LASER Product Electromagnetic Interference FCC 47CFR Part 15 Subpart B 2013 Class A Industry Canada ICES 003 2...

Страница 33: ...in a commercial environment This equipment generates uses and can radiate radio frequency energy and if not installed and used in accordance with the instruction manual may cause harmful interference...

Страница 34: ...urchase on most products Thinklogical and its suppliers disclaim all other warranties Please refer to your product invoice for the Warranty Terms Conditions Defect remedy shall be the repair or replac...

Страница 35: ...Page 30 TLX1280 Matrix Switch Product Manual thinklogical Rev H February 2020 APPENDIX A TLX640 QUICK START GUIDE...

Страница 36: ...Page 31 TLX1280 Matrix Switch Product Manual thinklogical Rev H February 2020 Appendix B Setting the DIP Switch Instruction...

Страница 37: ...Page 32 TLX1280 Matrix Switch Product Manual thinklogical Rev H February 2020 Appendix C FPGA Program Code Update Procedure...

Страница 38: ...chassis backplane wait 5 seconds then reconnect it 10 Wait for the crng init done message then connect the network cable to the Back up Controller Card and wait 10 seconds 11 Unplug the network cable...

Страница 39: ...Page 34 TLX1280 Matrix Switch Product Manual thinklogical Rev H February 2020...

Страница 40: ...used to manage the Matrix Switch must be physically protected and have suitable identification authentication mechanisms to ensure that only trusted administrators have access Thinklogical s TLX VX a...

Страница 41: ...ech marks character code 34 Lower case i character code 105 i Lower case o character code 111 o Comma character code 44 Carriage Return character code 13 CR Line Feed character code 10 LF The Restrict...

Страница 42: ...s the following This procedure will be disruptive to system connections 1 Update the Restricted Switching Table of the Primary Controller Card 2 Take the Primary Controller Card out of service by foll...

Страница 43: ...Matrix Switches Restricted Switching Priority Scheme The following example shows a priority scheme for four levels of security managed by one TLX Matrix Switch Restricted switching is configured via...

Страница 44: ...he Switch This file contains the port number and the partitions to which it belongs Example VX80 Matrix Switch with four distinct partitions Four partitions set up for secure routing and extension app...

Страница 45: ...p Controller Card for any errors in the Partition Table and correct them before implementing multiple levels of security classification domains on the same Matrix Switch using the Back Up Controller C...

Страница 46: ...e Password Security For security purposes the Switch defaults to using the Message Digest Algorithm MD5 and shadow passwords It is highly recommended that you DO NOT alter these settings If you select...

Страница 47: ...from the Red Network to the Black Network using the Restricted Switching feature For example the TLX Matrix Switch Network Diagram should be configured with the following csv file Direction Number Pr...

Страница 48: ...Page 43 TLX640 Matrix Switch Product Manual thinklogical Rev H February 2020 TLX640 10G Matrix Switch Secure Application...

Отзывы: