Cisco SCE 2000 and SCE 1000 Software
Configuration Guide
Release 3.5.5
June 15, 2009
Americas Headquarters
Cisco Systems, Inc.
170 West Tasman Drive
San Jose, CA 95134-1706
USA
http://www.cisco.com
Tel: 408 526-4000
800 553-NETS (6387)
Fax: 408 527-0883
Text Part Number: OL-7827-12
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL
STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT
WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT
SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE
OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH
ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT
LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF
DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING,
WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
CCDE, CCSI, CCENT, Cisco Eos, Cisco HealthPresence, the Cisco logo, Cisco Lumin, Cisco Nexus, Cisco Nurse Connect
Cisco TelePresence, Cisco WebEx, DCE, and Welcome to the Human Network are trademarks; Changing the Way We Work, Live, Play, and Learn and Cisco Store are
service marks; and Access Registrar, Aironet, AsyncOS, Bringing the Meeting To You, Catalyst, CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, CCSP, CCVP, Cisco, the
Cisco Certified Internetwork Expert logo, Cisco IOS, Cisco Press, Cisco Systems, Cisco Systems Capital, the Cisco Systems logo, Cisco Unity, Collaboration Without
Limitation, EtherFast, EtherSwitch, Event Center, Fast Step, Follow Me Browsing, FormShare, GigaDrive, HomeLink, Internet Quotient, IOS, iPhone, iQuick Study,
IronPort, the IronPort logo, LightStream, Linksys, MediaTone, MeetingPlace, MeetingPlace Chime Sound, MGX, Networkers, Networking Academy, Network Registrar,
PCNow, PIX, PowerPanels, ProConnect, ScriptShare, SenderBase, SMARTnet, Spectrum Expert, StackWise, The Fastest Way to Increase Your Internet Quotient, TransPath,
WebEx, and the WebEx logo are registered trademarks of Cisco Systems, Inc. and/or its affiliates in the United States and certain other countries.
All other trademarks mentioned in this document or website are the property of their respective owners. The use of the word partner does not imply a partnership relationship
between Cisco and any other company. (0903R)
Any Internet Protocol (IP) addresses used in this document are not intended to be actual addresses. Any examples, command display output, and figures included in the
document are shown for illustrative purposes only. Any use of actual IP addresses in illustrative content is unintentional and coincidental.
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
Obtaining Documentation and Submitting a Service Requestxxxviii
CHAPTER
CHAPTER
1Cisco Service Control Overview1-1
Introduction1-1
Cisco Service Control Solution1-1
Service Control for Broadband Service Providers1-2
Cisco Service Control Capabilities1-2
SCE Platform Description1-3
Management and Collection1-4
Network Management1-5
Subscriber Management1-5
Service Configuration Management1-6
Data Collection1-6
2Command Line Interface2-1
Introduction2-1
Authorization and Command Levels (Hierarchy)2-2
CLI Authorization Levels2-2
CLI Command Mode Hierarchy2-3
Prompt Indications2-6
Navigating Between Authorization Levels and Command Modes2-7
Configuring the Physical Ports2-9
CLI Help Features2-9
Partial Help2-9
Argument Help2-10
Navigational and Shortcut Features2-11
Command History2-11
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
i
Contents
Keyboard Shortcuts2-12
Auto-Completion2-13
FTP User Name and Password2-13
The "do" Command: Executing Commands Without Exiting2-14
Managing Command Output2-14
Scrolling the Screen Display2-15
Filtering Command Output2-15
Redirecting Command Output to a File2-15
Creating a CLI Script2-16
CHAPTER
3Operations3-1
Introduction3-1
Managing Configurations3-1
Viewing Configurations3-2
Viewing Configurations: Example3-3
Removing the Configuration3-3
Saving the Configuration Settings3-4
Saving the Configuration Settings: Example3-4
Restoring a Previous Configuration3-5
Restoring a Previous Configuration: Example3-6
Backing Up Configuration Files3-6
Options3-6
How to Create a Backup Configuration File3-7
How to Upload a Backup Configuration File3-7
Upgrading the SCE Platform Firmware3-7
Upgrading SCE Platform Firmware: Example3-8
Downgrading the SCE Platform to a Previous Version3-8
Managing Application Files3-9
Configuring Applications3-9
Managing Application Files3-9
How to Display Information about an Application File3-10
How to Install an Application3-10
How to Uninstall an Application3-10
How to Upgrade an Application3-11
How to Undo an Upgrade of an Application3-11
How to Display the Last pqi File that was Installed3-11
Monitoring the Operational Status of the SCE Platform3-12
How to Display the Current Operational Status of the SCE Platform3-13
Displaying the Current Operational Status of the SCE Platform: Example3-13
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
ii
OL-7827-12
Displaying the SCE Platform Version Information3-13
Displaying the SCE Platform Version Information: Example3-13
Displaying the SCE Platform Inventory3-14
Displaying the SCE Platform Inventory: Example3-14
Displaying the System Uptime3-15
Displaying the System Uptime: Example3-15
Rebooting and Shutting Down the SCE Platform3-15
Rebooting the SCE Platform3-15
Rebooting the SCE Platform: Example3-15
Shutting Down the SCE Platform3-16
Shutting Down the SCE Platform: Examples3-16
Contents
CHAPTER
4Utilities4-1
Introduction4-1
The Setup Command4-1
Setup Command Parameters4-1
Entering the Setup Command4-4
Defining Lists in the Setup Utility4-4
Working with SCE Platform Files4-5
Working with Directories4-5
Working with Files4-7
Multiple entry parameters (Lists)4-4
How to Create a Directory4-5
How to Delete a Directory4-6
How to Change Directories4-6
How to Display your Working Directory4-6
How to List the Files in a Directory4-6
How to Rename a File4-7
How to Delete a File4-7
Copying Files4-8
How to Display File Contents4-8
How to Unzip a File4-9
The User Log4-9
The Logging System4-9
Copying the User Log4-9
Enabling and Disabling the User Log4-10
Viewing the User Log Counters4-10
Viewing the User Log4-11
Clearing the User Log4-11
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
iii
Contents
Generating a File for Technical Support4-11
Generating a File for Technical Support: Example4-11
Flow Capture4-12
Limitations4-12
The Flow Capture Process4-12
Configuring a Flow Capture Traffic Rule4-13
Configuring the Flow Capture Settings4-13
Performing the Flow Capture4-14
Monitoring the Flow Capture4-15
CHAPTER
5Configuring the Management Interface and Security5-1
Configuring the Management Port Physical Parameters5-3
Setting the IP Address and Subnet Mask of the Management Interface5-4
Options5-4
Setting the IP Address and Subnet Mask of the Management Interface: Example5-4
Configuring the Management Interface Speed and Duplex Parameters5-5
Interface State Relationship to Speed and Duplex5-5
How to Configure the Speed of the Management Interface5-5
How to Configure the Duplex Operation of the Management Interface5-6
Specifying the Active Management Port5-6
Options5-7
Specifying the Active Management Port: Example5-7
Configuring Management Interface Redundancy5-7
About Management Port Redundancy5-7
How to Configure the Management Ports for Redundancy5-8
Configuring the Fail-Over Mode5-8
Options5-8
How to Enable Automatic Fail-Over Mode5-8
How to Disable Automatic Fail-Over Mode5-9
Configuring Management Interface Security5-9
Configuring the IP Fragment Filter5-9
Options5-9
How to Enable the IP Fragment Filter5-10
How to Disable the IP Fragment Filter5-10
Configuring the Permitted and Not-permitted IP Address Monitor5-10
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
iv
OL-7827-12
Options5-10
Monitoring Management Interface IP Filtering5-11
Configuring the Available Interfaces5-11
Configuring TACACS+ Authentication, Authorization, and Accounting5-11
Information About TACACS+ Authentication, Authorization, and Accounting5-12
Configuring the SCE Platform TACACS+ Client5-15
How to Manage the User Database5-19
Configuring AAA Login Authentication5-22
Configuring AAA Privilege Level Authorization Methods5-24
Configuring AAA Accounting5-25
Monitoring TACACS+ Servers5-25
Monitoring TACACS+ Users5-26
Configuring Access Control Lists (ACLs)5-26
Options5-27
How to Add Entries to an ACL5-28
How to Remove an ACL5-28
How to Define a Global ACL5-28
Configuring the Telnet Interface5-28
How to Prevent Telnet Access5-29
How to Assign an ACL to the Telnet Interface5-29
How to Configure the Telnet Timeout5-30
Configuring the SSH Server5-30
Information About the SSH Server5-30
Managing the SSH Server5-31
How to Monitor the Status of the SSH Server5-32
Enabling the SNMP Interface5-33
How to Enable the SNMP Interface5-33
How to Disable the SNMP Interface5-33
Contents
Configuring and Managing the SNMP Interface5-33
Information About the SNMP Interface5-33
The SNMP Interface5-34
SNMP Protocol5-34
Security Considerations5-35
CLI5-35
MIBs5-36
Configuration via SNMP5-41
Configuring SNMP Community Strings5-42
How to Define a Community String5-42
How to Remove a Community String5-43
How to Display the Configured Community Strings5-43
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
v
Contents
Configuring SNMP Notifications5-43
About SNMP Notifications5-43
How to Define SNMP Hosts5-44
Managing Passwords5-46
About Passwords5-47
Changing Your Password5-47
How to Change Your Password5-48
Verifying that the Password has been Successfully Changed5-48
Password Encryption5-49
How to Enable Password Encryption5-49
How to Disable Password Encryption5-49
Password Recovery5-49
How to Recover the Passwords: SCOS versions before 2.5.55-49
How to Recover the Passwords: SCOS versions 2.5.5 or later5-52
IP Configuration5-52
Configuring the IP Routing Table5-53
How to Configure the Default Gateway5-53
How to Add an Entry to the IP Routing Table5-54
Displaying the IP Routing Table5-54
IP Advertising5-55
Configuring IP Advertising5-55
How to Display the Current IP Advertising Configuration5-56
Configuring the IP Address of the Management Interface5-57
Options5-57
Configuring the IP Address of the Management Interface: Example5-57
Configuring Time Clocks and Time Zone5-58
How to Display the System Time5-58
Displaying the System Time: Example5-58
How to Display the Calendar Time5-59
Displaying the Calendar Time: Example5-59
How to Set the System Clock5-59
Options5-59
Setting the System Clock: Example5-59
How to Set the Calendar5-59
Options5-60
Setting the Calendar: Example5-60
How to Set the Time Zone5-60
Options5-60
Setting the Time Zone: Example5-61
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
vi
OL-7827-12
How to Remove the Current Time Zone Setting5-61
Configuring Daylight Saving Time5-61
Options5-61
Guidelines5-62
How to Define Recurring Daylight Saving Time Transitions5-63
How to Define Non-Recurring Daylight Saving Time Transitions5-63
How to Cancel the Daylight Saving Time Configuration5-63
How to Display the Current Daylight Saving Time Configuration5-64
Configure SNTP5-64
How to Enable the SNTP Multicast Client5-64
How to Disable the SNTP Multicast Client5-65
How to Enable the SNTP Unicast Client5-65
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
viii
OL-7827-12
How to Delete a Traffic Counter6-20
How to Delete all Existing Traffic Counters6-20
Configuring Traffic Rules6-20
How to Create a Traffic Rule6-20
How to Delete a Traffic Rule6-24
How to Delete all Traffic Rules6-24
How to Delete All Flow Control Traffic Rules6-24
Managing Traffic Rules and Counters6-25
How to View a Specified Traffic Rule6-25
How to View all Traffic Rules6-25
How to View a Specified Traffic Counter6-25
How to View all Traffic Counters6-26
How to Reset a Specified Traffic Counter6-26
How to Reset all Traffic Counters6-26
TOS Marking6-26
How to Display the TOS Marking Configuration6-27
Contents
CHAPTER
Counting Dropped Packets6-27
Configuring the Hardware Packet Drop6-27
How to Disable the Hardware Packet Drop6-27
How to Enable the Hardware Packet Drop6-28
7Configuring the Connection7-1
Introduction7-1
Configuring the Connection Mode7-1
Options7-2
Configuring the Connection Mode: Examples7-3
Monitoring the Connection Mode and Related Parameters7-3
How to View the Current Connection Mode7-3
How to View the SCE-ID7-4
How to View the Current Redundancy Status of the SCE Platform7-4
How to View Information about the Peer SCE Platform7-5
How to View the Current Connection Status of the SCE Platform7-5
How to Configure the Link Mode7-5
About the Link Mode7-6
Options7-6
Configuring Asymmetric Routing Topology7-7
Asymmetric Routing and Other Service Control Capabilities7-8
Enabling Asymmetric Routing7-8
How to Monitor Asymmetric Routing7-8
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
ix
Contents
Monitoring Asymmetric Routing: Example7-9
Configuring a Forced Failure7-9
How to Force a Virtual Failure7-9
How to Exit from a Virtual Failure7-9
Configuring the Failure Recovery Mode7-9
Options7-10
Configure the Failure Recovery Mode: Examples7-10
Example 17-10
Example 27-10
Configuring the SCE Platform/SM Connection7-10
Configuring the Behavior of the SCE Platform in Case of Failure of the SM7-11
Options7-11
Configuring the SM-SCE Platform Connection Timeout7-11
Options7-11
Enabling and Disabling Link Failure Reflection7-12
How to Enable Link Failure Reflection7-12
How to Disable Link Failure Reflection7-12
Enabling and Disabling Link Failure Reflection on All Ports7-12
Options7-13
How to Enable Link Failure Reflection on All Ports7-13
How to Disable Link Failure Reflection on All Ports7-13
Configuring Link Failure Reflection in Linecard-Aware Mode (SCE 2000 only)7-13
How to Enable Linecard-Aware Mode7-14
How to Disable Linecard-Aware Mode7-14
CHAPTER
8Raw Data Formatting: The RDR Formatter and NetFlow Exporting8-1
Introduction8-1
Information About the RDR Formatter and NetFlow Exporting Support8-1
The RDR Formatter8-2
NetFlow8-2
NetFlow Terminology8-2
NetFlow Exporting Support8-3
Data Destinations8-3
Categories8-4
Priority8-5
Setting DSCP for NetFlow8-5
Forwarding Modes8-5
Protocol8-6
Transport Type8-6
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
x
OL-7827-12
Configuring Data Destinations and Categories8-6
Configuring a Data Destination8-6
Options8-7
Configuring the Data Destinations: Examples8-7
Configuring the Data Categories8-8
How to Configure a Destination and Assign Categories8-8
Configuring the Forwarding Mode8-12
Options8-13
Configuring the Forwarding Mode: Example8-13
Configuring the RDR Formatter8-13
Options8-13
How to Enable the RDR Formatter8-13
How to Disable the RDR Formatter8-14
How to Configure the Size of the RDR Formatter History Buffer8-14
Options8-14
Contents
Configuring the NetFlow Exporting Support8-14
Options8-14
How to Configure a DSCP Value for NetFlow8-15
Options8-15
How to Configure the Template Refresh Interval8-15
Options8-15
Configuring Dynamic Mapping of RDRs to Categories8-15
How to Configuring Mappings8-16
Options8-16
How to Add a Mapping to a Category8-16
How to Remove a Mapping from a Category8-16
How to Restore the Default Mapping for a Specified RDR Tag8-16
Displaying Data Destination Configuration and Statistics8-17
How to the Display the Current RDR Formatter Configuration8-17
Displaying the RDR Formatter Configuration: Example8-17
How to the Display the Current RDR Formatter Statistics8-18
Displaying the Current RDR Formatter Statistics: Example8-18
Disabling the Linecard from Sending RDRs8-19
How to Disable the Linecard from Sending RDRs8-19
How to Enable the Linecard to Send RDRs8-19
CHAPTER
9Managing Subscribers9-1
Introduction9-1
Information About Subscribers9-1
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xi
Contents
What is a Subscriber?9-2
Subscriber Modes in Service Control Solutions9-3
Subscriber Database: Capacity and Limits9-4
Automatic VLAN VPNs9-5
Synchronizing Subscriber Information in a Cascade System9-6
Anonymous Groups and Subscriber Templates9-7
Information About Subscriber Files9-7
Subscriber Files9-7
Subscriber default csv file format9-8
Subscriber anonymous groups csv file format9-8
Importing and Exporting Subscriber Information9-9
Options9-9
How to Import Subscriber Information9-9
How to Export Subscriber Information9-10
How to Import a Subscriber Template9-10
How to Export a Subscriber Template9-10
Removing Subscribers and Templates9-10
How to Remove a Specific Subscriber9-11
Options9-11
How to Remove All Introduced Subscribers9-11
How to Remove a Specific Anonymous Subscriber Group9-12
Options9-12
How to Remove All Anonymous Subscriber Groups9-12
How to Remove All Anonymous Subscribers9-12
How to Remove All Subscriber Templates9-12
About VPN-based Subscribers9-13
How to Remove Subscribers by Device9-13
How to Remove Subscribers from the SM9-13
How to Remove Subscribers from a Specified SCMP Peer Device9-13
Creating Anonymous Groups9-14
Defining Anonymous Groups9-14
How to Define an Anonymous Group9-14
Importing and Exporting Anonymous Groups9-14
How to Import Anonymous Groups9-15
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xii
OL-7827-12
How to Export Anonymous Groups9-15
Monitoring Subscribers9-15
How to Monitor the Subscriber Database9-16
How to Display the Subscriber Database Counters9-17
Clearing the Subscriber Database Counters9-18
Displaying Subscribers9-18
Displaying Subscribers: All Current Subscriber Names9-19
Displaying Subscribers: By Subscriber Property or Prefix9-19
Displaying Subscribers: By Mapping (IP Address, VPN, VLAN ID, or MPLS/VPN)9-21
Displaying Subscriber Information9-23
How to display a listing of subscriber properties9-24
How to display complete information for a specified subscriber9-24
How to display values of subscriber properties for a specified subscriber9-24
How to display mappings for a specified subscriber9-25
How to display OS counters for a specified subscriber9-25
Displaying Anonymous Subscriber Information9-25
How to display currently configured anonymous groups9-26
How to display currently configured templates for anonymous groups9-26
How to display current configuration for a specified anonymous group9-26
How to display subscribers in a specified anonymous group9-26
How to display all subscribers currently in anonymous groups9-26
How to display the number of subscribers in a specified anonymous group9-27
How to display the total number of subscribers in all anonymous groups9-27
Managing VPNs and VPN Subscriber Mappings9-27
How to Display VPN-related Mappings9-27
How to Clear Upstream MPLS/VPN Mappings9-28
How to Clear Automatic VPNs9-29
Contents
Subscriber Traffic Processor IP Ranges9-29
Information About Traffic Processor IP Ranges9-29
Subscriber Mapping Modes9-30
Subscriber Mapping Conflicts9-30
Subscriber Rules for TIRs9-31
How to Reserve Rules for TIRs9-31
Options9-31
How to Configure TIRs9-31
Options9-32
How to Create or Update a TIR9-32
How to update a TIR even if subscriber mappings exist9-32
How to Remove TIRs and Subscriber Mappings9-32
How to Remove a Specified TIR9-33
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xiii
Contents
How to Remove All TIRs9-33
How to Remove Mappings from a Specified TIR9-33
How to Remove Mappings from a Specified IP Range9-34
How to Import and Export TIRs9-34
About TIR csv Files9-34
Options9-34
How to Import TIRs from a csv File9-35
How to Export TIRs to a csv File9-35
How to Monitor TIRs9-35
How to Display Traffic Processor Mappings State9-36
How to Display Configuration of a Specified TIR9-36
How to Display Configuration of All TIRs9-36
How to Display Mappings Related to a Specified TIR9-36
How to Display the Number of Subscribers with Mappings Related to a Specified TIR9-36
How to Display Complete Subscriber Information9-36
How to Display All Subscribers Mapped to a Specified IP Range9-37
How to Display the Number of Subscribers Mapped to a Specified IP Range9-37
Configuring the Actual Maximum Number of Subscribers9-37
How to Override the Configured Capacity Option9-37
How to Restore the Configured Capacity Option9-38
How to Monitor the Maximum Number of Subscribers9-38
Configuring Subscriber Aging9-38
How to Enable Aging for Anonymous Group Subscribers9-38
How to Enable Aging for Introduced Subscribers9-39
How to Disable Aging for Anonymous Group Subscribers9-39
How to Disable Aging for Introduced Subscribers9-39
How to Set the Aging Timeout Period for Anonymous Group Subscribers9-39
Options9-39
How to Set the Aging Timeout Period for Introduced Subscribers9-40
Options9-40
How to Display Aging for Anonymous Group Subscribers9-40
How to Display Aging for Introduced Subscribers9-40
Configuring the SCE Platform/SM Connection9-40
Options9-41
Configuring the Behavior of the SCE Platform in Case of Failure of the SM9-41
Options9-41
Configuring the SM-SCE Platform Connection Timeout9-42
Options9-42
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xiv
OL-7827-12
Contents
CHAPTER
10Redundancy and Fail-Over10-1
Introduction10-1
Information About Redundancy and Fail-Over10-1
Terminology and Definitions10-2
Redundant Topologies10-2
In-line Dual Link Redundant Topology10-3
Failure Detection10-4
Link Failure Reflection10-4
How to Configure Forced Failure10-5
How to Force a Virtual Failure Condition10-5
How to Exit a Virtual Failure Condition10-5
Hot Standby and Fail-over10-5
Hot Standby10-5
Fail-over10-6
Failure in the Cascade Connection10-7
Installing a Cascaded System10-7
Recovery10-8
Replacing the SCE platform (manual recovery)10-9
Manual steps:10-9
Automatic steps (in parallel with the manual steps, requires no user intervention):10-9
Reboot only (fully automatic recovery)10-9
CHAPTER
CLI Commands for Cascaded Systems10-10
Topology-Related Parameters for Redundant Topologies10-10
Configuring the Connection Mode10-10
Examples10-11
Monitoring a Cascaded System10-11
How to View the Current Connection Mode10-11
How to View the Current Link Mode10-11
How to View Current Link Mappings10-11
System Upgrades10-12
Firmware Upgrade (package installation)10-12
Application Upgrade10-13
Simultaneous Upgrade of Firmware and Application10-13
11Identifying and Preventing Distributed-Denial-Of-Service Attacks11-1
Introduction11-1
Attack Filtering and Attack Detection11-1
Attack Filtering11-2
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xv
Contents
Specific Attack Filtering11-2
Attack Detection11-3
Attack Detection Thresholds11-4
Attack Handling11-5
How to Enable Specific-IP Detection for the TCP Protocol Only for all Attack Directions11-9
How to Enable Specific-IP Detection for the TCP Protocol for Port-based Detections Only for
Dual-sided Attacks11-10
How to Disable Specific-IP Detection for Protocols Other than TCP, UDP, and ICMP for all Attack
Directions11-10
How to Disable Specific-IP Detection for ICMP for Single-sided Attacks Defined by the Source
IP11-10
How to Configure the Default Attack Detector11-10
Options11-11
How to Define the Default Action and Optionally the Default Thresholds11-11
How to Reinstate the System Defaults for a Selected Set of Attack Types11-12
How to Reinstate the System Defaults for All Attack Types11-12
Specific Attack Detectors11-13
Options11-13
How to Enable a Specific Attack Detector and Assign it an ACL11-14
How to Define the Action and Optionally the Thresholds for a Specific Attack Detector11-14
How to Define the Subscriber Notification Setting for a Specific Attack Detector11-15
How to Define the SNMP Trap Setting for a Specific Attack Detector11-15
How to Define the List of Destination Ports for TCP or UDP Protocols for a Specific Attack
Detector11-15
How to Delete User-Defined Values11-16
How to Disable a Specific Attack Detector11-16
How to Disable All Non-default Attack Detectors11-16
How to Disable All Attack Detectors11-16
Sample Attack Detector Configuration11-17
Configuring Subscriber Notifications11-18
How to Configure the Subscriber Notification Port11-18
Options11-18
How to Remove the Subscriber Notification Port11-18
Preventing and Forcing Attack Detection11-19
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xvi
OL-7827-12
Options11-19
Preventing Attack Filtering11-20
How to Configure a dont-filter Setting for a Specified Situation11-20
How to Remove a dont-filter Setting from a Specified Situation11-20
How to Remove All dont-filter Settings11-20
Forcing Attack Filtering11-20
How to Configure a force-filter Setting for a Specified Situation11-21
How to Remove a force-filter Setting from a Specified Situation11-21
How to Remove All force-filter Settings11-21
Monitoring Attack Filtering11-21
Monitoring Attack Filtering Using SNMP Traps11-21
Monitoring Attack Filtering Using CLI Commands11-23
How to display a specified attack detector configuration11-24
How to display the default attack detector configuration11-25
How to display all attack detector configurations11-26
How to display filter state (enabled or disabled)11-26
How to display configured threshold values and actions11-26
How to display the current counters11-28
How to display all currently handled attacks11-28
How to display all existing force-filter settings11-28
How to display all existing don't-filter settings11-28
How to display the list of ports selected for subscriber notification11-29
How to find out whether hardware attack filtering has been activated11-29
The Attack Log11-29
How to View the Attack Log11-30
How to Copy the Attack Log to a File11-30
Requirements for VAS Servers12-4
VAS Traffic Forwarding and SCA BB12-5
VLAN Tags for VAS Traffic Forwarding12-5
Service Flow12-6
Data Flow12-6
Non-VAS Data Flow12-7
VAS Data Flow12-8
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xvii
Contents
Load Balancing12-8
Load Balancing and Subscribers12-9
Load Balancing and Subscriber Mode12-9
VAS Redundancy12-9
VAS Server Failure12-10
VAS Server Group Failure12-10
Ethernet Switch Failure12-10
Disabling a VAS Server12-11
VAS Status and VAS Health Check12-11
VAS Server States12-12
VAS Traffic Forwarding Topologies12-12
Single SCE Platform, Multiple VAS Servers12-12
Data Flow12-13
Multiple SCE Platforms, Multiple VAS Servers12-14
SNMP Support for VAS12-15
Interactions Between VAS Traffic Forwarding and Other SCE Platform Features12-15
Incompatible SCE Platform Features12-15
VAS Traffic Forwarding and DDoS Processing12-15
Specific IP DDoS Attack Detection12-15
Specific IP Attack filter12-16
VAS Traffic Forwarding and Bandwidth Management12-16
Global Controllers and VAS flows12-16
Configuring VAS Traffic Forwarding12-16
Configuring VAS Traffic Forwarding from the SCA BB Console12-17
Global Options12-17
Enabling VAS Traffic Forwarding12-18
Options12-18
Disabling VAS Traffic Forwarding12-18
How to Configure the VAS Traffic Link12-19
Options12-19
How to Select the Link for VAS Traffic12-19
How to Revert to the Default Link for VAS Traffic12-19
How to Configure a VAS Server12-20
Options12-20
How to Enable a VAS Server12-20
How to Disable a VAS Server12-21
How to Restore all VAS Server Properties to Default12-21
How to Assign a VLAN ID to a VAS Server12-21
Options12-21
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xviii
OL-7827-12
How to Configure the VLAN Tag Number for a Specified VAS Server12-21
How to Remove the VLAN Tag Number from a Specified VAS Server12-22
How to Configure the Health Check12-22
How to Configure Pseudo IP Addresses for the Health Check Packets12-23
How to Configure a VAS Server Group12-25
About VAS Server Groups12-25
How to Add and Remove Servers12-25
How to Configure VAS Server Group Failure Parameters12-26
Monitoring VAS Traffic Forwarding12-28
How to Display Global VAS Status and Configuration12-28
Example12-28
How to Display Operational and Configuration Information for a Specific VAS Server Group12-29
Example12-29
How to Display Operational and Configuration Information for All VAS Server Groups12-29
How to Display Operational and Configuration Information for a Specific VAS Server12-29
Example12-29
How to Display Operational and Configuration Information for All VAS Servers12-30
How to Display the VAS Servers Used by a Specified Subscriber12-30
How to Display Health Check Counters for a Specified VAS Server12-30
Example12-30
How to Display Health Check Counters for All VAS Servers12-31
How to Clear the Health Check Counters for a Specified VAS Server12-31
How to Clear the Health Check Counters for All VAS Servers12-31
How to Display Bandwidth per VAS Server and VAS Direction12-31
Example12-31
Contents
VAS over 10G12-32
About VAS over 10G12-32
Data Flow in VAS over 10G Topology12-33
VAS Data Flow: To the VAS Server12-35
VAS Data Flow: From the VAS Server12-36
Failover Support12-37
Health Check in VAS over 10G Topology12-39
Configuring VAS over 10G: General Guidelines12-40
Configuring the 7600/6500 for VAS over 10G12-40
Configuring VAS over 10G12-41
How to Configure the VAS Traffic Link Auto-Select Parameters (VAS over 10G)12-41
How to Configure the Minimum Time between Link Switches12-42
How to Set the Active VAS Link12-43
How to Configure Health Check for VAS over 10G12-43
How to Configure the Health Check IP Address12-43
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xix
Contents
How to Remove the IP Address Configuration12-44
How to Enable the Health Check for VAS over 10G Topology12-45
Options12-45
How to Enable Health Check Compatibility for VAS over 10G (MGSCP)12-45
How to Remove the Health Check Compatibility Configuration12-45
What is an MPLS/VPN-based Subscriber?13-4
Private IP Subscriber Support13-5
How the Service Control MPLS/VPN Solution Works13-5
How the Service Control MPLS/VPN Solution Works: A Summary13-5
SCE Platform Tasks in the MPLS/VPN Solution13-5
BGP LEG Tasks in the MPLS/VPN Solution13-6
SM Tasks in the MPLS/VPN Solution13-6
How to Configure the MPLS Environment13-12
Configuring the SCE Platform for MPLS/VPN Support13-12
Defining the PE Routers13-12
Configuring the MAC Resolver13-14
Monitoring the MAC Resolver13-15
Configuring the SM for MPLS/VPN Support13-16
how to Configure the SM for MPLS/VPN Support13-16
How to Edit the SM Configuration File13-16
How to Configure the SM to Allow IP Ranges13-17
Contents
CHAPTER
Managing MPLS/VPN Support13-17
Managing MPLS/VPN Support via SNMP13-17
MPLS/VPN MIB Objects13-18
MPLS/VPN Traps13-18
Monitoring MPLS/VPN Support via SCE Platform CLI13-18
Displaying VPN-related Mappings13-18
Clearing Upstream VPN Mappings13-21
Monitoring Subscriber Counters13-22
Monitoring MPLS/VPN Counters13-23
Monitoring the PE Routers13-23
Monitoring Bypassed VPNs13-24
Monitoring Non-VPN Mappings13-24
Managing MPLS/VPN Support via SM CLU13-24
Managing VPNs13-25
How to Add Mappings to VPN-based Subscribers13-27
How to Remove VPN Mappings from Subscribers13-28
How to Monitor Subscriber MPLS/VPN Mappings13-29
14Managing the SCMP14-1
Introduction14-1
About SCMP14-1
SCMP Terminology14-2
Deployment Scenarios14-3
Single ISG Router with a Single SCE Platform (1xISG – 1xSCE)14-3
OL-7827-12
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xxi
Contents
Single ISG Router with Two Cascaded SCE Platforms (1xISG – 2xSCE)14-4
Multiple ISG Routers with Two Cascaded SCE Platforms (NxISG – 2xSCE)14-5
Multiple ISG Routers with Multiple SCE Platforms via Load Balancing (NxISG – MxSCE)14-6
SCMP Peer Devices14-7
Connection Management14-7
SCMP Subscriber Management14-8
GUID and Subscriber ID14-8
Configuring the SCMP14-8
Configuring SCMP Parameters14-9
How to Enable the SCMP14-9
How to Disable the SCMP14-9
Configuring the SCMP Peer Device to Push Sessions14-9
Configuring the SCMP Peer Device to Force Each Subscriber to Single SCE Platform14-10
How to Define the Keep-alive Interval Parameter14-11
How to Define the Reconnect Interval Parameter14-11
How to Define the Loss-of-Sync Timeout Parameter14-11
Adding an SCMP Peer Device14-12
How to Define an SCMP Peer Device14-12
Assigning the SCMP Peer Device to an Anonymous Group14-13
Deleting Subscribers Managed by an SCMP Peer Device14-13
Options14-13
Deleting an SCMP Peer Device14-14
Defining the Subscriber ID14-14
Options14-15
Configuring the RADIUS Client14-15
Options14-16
Monitoring the SCMP Environment14-16
Monitoring the SCMP14-16
Options14-16
How to display the general SCMP configuration14-17
How to display the configuration all currently defined SCMP peer devices14-17
How to display the configuration for a specified SCMP peer device14-17
How to display the statistics for all SCMP peer devices14-17
How to display the statistics for a specified SCMP peer device14-18
Monitoring the RADIUS Client14-18
APPENDIX
AMonitoring SCE Platform UtilizationA-1
IntroductionA-1
SCE Platform Utilization IndicatorsA-2
Cisco SCE 2000 and SCE 1000 Software Configuration Guide
xxii
OL-7827-12
CPU UtilizationA-2
Flows CapacityA-2
Subscribers CapacityA-2
Service LossA-3
Monitoring Service LossA-3
Contents
APPENDIX
BProprietary MIB ReferenceB-1
IntroductionB-1
pcube Enterprise MIBB-2
Application MIB IntegrationB-3
Application and Subscriber groupsB-4
The Engage MIB (pcubeEngageMIB)B-5
MIB UpdatesB-5
tpServiceLossB-6
Using this ReferenceB-6
pcubeModules (1.3.6.1.4.1.5655.2)B-6
pcubeSeMIB (1.3.6.1.4.1.5655.2.3)B-6
pcubeSeMIB Object Groups (1.3.6.1.4.1.5655.2.3.1.1)B-7
pcubeCompliances (1.3.6.1.4.1.5655.2.3.1.2)B-15