Cisco Systems SMC-127 To assign a DRP pair as the Dsdrsc, To assign an RP pair as the Dsdrsc

Page 17

Configuring Secure Domain Routers on Cisco IOS XR Software

How to Configure Secure Domain Routers

 

Command or Action

Purpose

 

 

 

Step 7 pair pair-nameprimary

Specifies a DSDRSC for the non-owner SDR. You can assign a

 

or

redundant DRP pair, an RP pair, or a single DRP as the

 

location partially-qualified-nodeid primary

DSDRSC. You cannot assign a single RP as the DSDRSC.

 

 

 

 

Every SDR must contain a DSDRSC.

 

Example:

We recommend the use of DRP pairs as the DSDRSC for

 

RP/0/RP0/CPU0:router(admin-config-sdr:rname

 

all non-owner SDRs to ensure DSC migration in a

 

2)# pair drp1 primary

 

Cisco CRS-1 system. See the “DSC Migration on Cisco

 

 

 

or

CRS-1 Multishelf Systems” section on page SMC-136for

 

 

more information.

 

RP/0/RP0/CPU0:router(admin-config-sdr:rname

The primary keyword configures the RPs, DRP pair, or

 

2)# location 0/0/* primary

 

 

DRP as the DSDRSC. If the primary keyword is not used,

 

or

the node is assigned to the SDR, but it is not be the

 

RP/0/RP0/CPU0:router(admin-config-sdr:rname

DSDRSC.

 

 

 

2)# location 0/RP*/* primary

If an RP is already assigned to the SDR, it must be removed

 

 

before a DRP or DRP pair can be assigned as the DSDRSC.

 

 

See the “Removing Nodes from a Secure Domain Router in

 

 

a Cisco CRS-1 Router” section on page SMC-152.

 

 

To assign a DRP pair as the DSDRSC

 

 

To assign a DRP pair as the DSDRSC, you must first create a

 

 

DRP pair, as described in step 3 and step 4. After the DRP pair

 

 

is created, you can add the pair to the configuration with the

 

 

command pair pair-name.To assign the pair as the DSDRSC,

 

 

use the primary keyword.

 

 

To assign a single DRP node as the DSDRSC

 

 

The value of the partially-qualified-nodeidargument is entered

 

 

in the rack/slot/* notation. The node ID is specified at the slot

 

 

level, so the wildcard (*) is used to specify the CPU.

 

 

To assign an RP pair as the DSDRSC

 

 

The value of the partially-qualified-nodeidargument for RPs is

 

 

entered in the rack/RP*/* notation. This command assigns the

 

 

redundant RP pair as the DSDRSC. One RP is automatically

 

 

elected as the DSDRSC, and the second RP acts as the standby

 

 

DSDRSC.

 

 

 

Cisco IOS XR System Management Configuration Guide

SMC-143

Image 17
Contents Contents Configuring Secure Domain Routers on Cisco IOS XR SoftwareSMC-128 Prerequisites for Configuring Secure Domain RoutersWhat Is a Secure Domain Router? Information About Configuring Secure Domain RoutersOwner SDR and Administration Configuration Mode SMC-129Non-Owner SDRs SDR Access PrivilegesRoot-System Users SMC-130SMC-131 Root-lr UsersOther SDR Users SMC-132 Designated Secure Domain Router System Controller DsdrscDSCs and DSDRSCs in a Cisco CRS-1 Router SMC-133 DSC and DSDRSCs in a Cisco XR 12000 Series RouterSMC-134 Removing a Dsdrsc Configuration Default Configuration for New Non-Owner SDRsDefault Software Profile for SDRs SMC-135Rebooting an SDR Fault IsolationHigh Availability Implications Dsdrsc RedundancySMC-137 Cisco IOS XR Software Package ManagementSMC-138 DSC Migration on Cisco CRS-1 Multishelf SystemsSMC-139 CaveatsCreating SDRs How to Configure Secure Domain RoutersContents SMC-141 Summary StepsSMC-142 Command or Action PurposeExample To assign a single DRP node as the Dsdrsc To assign a DRP pair as the DsdrscTo assign an RP pair as the Dsdrsc SMC-143To add a DRP pair To add a single nodeTo add an RP pair SMC-144SMC-145 Creating SDRs in a 12000 Series RouterSee the DSC and DSDRSCs in a DSDRSCs in a Cisco XR 12000 Series Router section onCisco XR 12000 Series Router section on page SMC-133 SMC-146SMC-147 Refer to the Adding Nodes to a Non-Owner SDR sectionSMC-148 Adding Nodes to a Non-Owner SDRAdding Nodes to an SDR in a Cisco CRS-1 Router SMC-149 Creating SDRs in a Cisco CRS-1 RouterSMC-150 Adding Nodes to an SDR in a Cisco XR 12000 Series RouterSMC-151 Removing Nodes and SDRsA Cisco XR 12000 Series Router section on SMC-152 To remove a single node To remove a DsdrscTo remove a DRP pair To remove an RP pairSMC-154 SMC-155 Nodes to an SDR in a Cisco XR 12000 Series RouterSection on page SMC-150 SMC-156 Removing a Secure Domain RouterSMC-157 Configuring a Username and Password for a Non-Owner SDRSMC-158 Group root-lr End or commit ExitSMC-159 System Security Configuration Guide for moreSMC-160 SMC-161 Disabling Remote Login for SDRsSee Disabling Remote Login for SDRs, page SMC-161for Creating a New SDR on a Cisco CRS-1 Router Configuration Examples for Secure Domain RoutersCreating an SDR on a Cisco XR 12000 Series Router SMC-162SMC-163 Related Documents Additional ReferencesStandards MIBsTechnical Assistance RFCsRFCs Title Description LinkSMC-166