Chapter 3
Connecting the Switch to the Network
3 - 10
Installing a Redundant Peer or Cluster
If you are installing the second switch in a redundant pair (called an ARX
cluster) or if you are configuring a second ARX cluster in a Disaster
Recovery (DR) configuration, you need to provide additional information to
the initial-boot script because all members of the cluster share a common
master key.
Note
A master key is an encryption key for all critical-security parameters
(CSPs), such as administrative passwords.
Redundant switches must use the same master key because they share the
same users, groups, and passwords. In the case of of a DR configuration, all
four ARX devices must be configured with a common master key.
At the peer that is currently installed, enter the
show master-key
command
to create an encrypted copy of the master key.
The CLI prompts you for the following passwords:
• System password. The system password is entered at initial-boot time
and validates that you have permission to access the master key. See
Booting a Non-Replacement Switch, on page 3-4
.
The system password is 12 – 32 characters long.
• Wrapping password. The wrapping password is set with the
show master-key
command. The security software uses the wrapping
password to encrypt (and later decrypt) the master key string.
Enter 12 – 32 characters. At least one character in this password must be
a number (0-9) or a symbol (!, @, #, $, and so on).
Important
Save this password as you will need it to decrypt the master key on the new
switch.
The
show master-key
command outputs a base64-encoded string that is the
encrypted master key. Save this string and the wrapping password that you
set in the command.
The following example shows the master key on a switch named
provB
:
provB#
show
master
‐
key
System
Password:
%uper$ecretpw
Wrapping
Password:
an0ther$ecretpw
Validate
Wrapping
Password:
an0ther$ecretpw
Encrypted
master
key:
2oftVCwAAAAgAAAApwazSRFd2ww/H1pi7R7JMDZ9SoIg4WGA/XsZP+HcXjsIAAAADDR
bMCxE/bc=
provB#
...
Содержание ARX-500
Страница 1: ...ARX 500 Hardware Installation Guide 810 0039 00 ...
Страница 2: ......
Страница 7: ...Table of Contents ...
Страница 8: ......
Страница 10: ...Table of Contents x ...
Страница 11: ......
Страница 12: ...Table of Contents xii ...
Страница 14: ......
Страница 22: ......
Страница 32: ......
Страница 50: ...Chapter 3 Connecting the Switch to the Network 3 20 ...
Страница 51: ...4 Maintenance Powering Down the ARX 500 POST Diagnostics Front Panel LEDs Rear Panel LEDs ...
Страница 52: ......
Страница 59: ...Index ...
Страница 60: ......
Страница 62: ...Index Index 4 ...