Cisco has more than 200 offices worldwide.
Addresses, phone numbers, and fax numbers
are listed on the Cisco website at
www.cisco.com/go/offices.
Text Part Number: OL-30621-02
THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL
STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT
WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.
THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT
SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE
OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.
NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS” WITH
ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT
LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF
DEALING, USAGE, OR TRADE PRACTICE.
IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING,
WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this
URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership
relationship between Cisco and any other company. (1110R)
Any Internet Protocol (IP) addresses used in this document are not intended to be actual addresses. Any examples, command display output, and figures included in the
document are shown for illustrative purposes only. Any use of actual IP addresses in illustrative content is unintentional and coincidental.
Obtaining Documentation and Submitting a Service Request7
CHAPTER
CHAPTER
1Cisco Service Control Overview1-1
Introduction1-1
Cisco Service Control Solution1-2
Service Control for Broadband Service Providers1-2
Cisco Service Control Capabilities1-3
Cisco SCE Platform Description1-4
Bandwidth Management of P2P Traffic1-5
Management and Collection1-6
Network Management1-6
Subscriber Management1-7
Service Configuration Management1-7
Data Collection1-7
IPv6 Support1-8
2Command-Line Interface2-1
Introduction2-1
Authorization and Command Mode Levels (Hierarchy)2-2
CLI Authorization Levels2-2
CLI Command Mode Hierarchy2-3
Prompt Indications2-6
Navigating Between Authorization Levels and Command Modes2-6
The do Command: Executing Commands Without Exiting2-7
OL-30621-02
CLI Help Features2-9
Partial Help2-9
Argument Help2-9
Cisco SCE 8000 10GBE Software Configuration Guide
iii
Contents
Navigational and Shortcut Features2-11
Command History2-11
Keyboard Shortcuts2-11
Auto-Completion2-12
FTP User Name and Password2-13
Managing Command Output2-14
Scrolling the Screen Display2-14
Filtering Command Output2-14
Redirecting Command Output to a File2-15
Creating a CLI Script2-16
CHAPTER
3Basic Cisco SCE 8000 Platform Operations3-1
Introduction3-1
Starting the Cisco SCE 8000 Platform3-2
Checking Conditions Prior to System Startup3-2
Starting the System and Observing Initial Conditions3-2
Final Tests3-3
How to Verify Operational Status3-3
How to View the User Log Counters3-3
Managing Configurations3-5
Viewing Configurations3-5
How to Save or Change the Configuration Settings3-6
Example for Saving or Changing the Configuration Settings3-7
Restoring a Previous Configuration3-8
Example for Restoring a Previous Configuration3-8
How to Display the Cisco SCE Platform Version Information3-10
Example for Displaying the Cisco SCE Platform Version Information3-10
How to Display the Cisco SCE Platform Inventory3-13
Examples for Displaying the Cisco SCE Platform Inventory3-13
Displaying the Cisco SCE Platform Inventory: FRUs Only3-13
Displaying the Complete Cisco SCE Platform Inventory3-14
iv
How to Display the System Uptime3-17
Example for Displaying the System Uptime3-17
Configuring the System Mode3-17
Configuring the IPv6 Prefix Length3-18
Monitoring Control Processor CPU Utilization3-20
CLI Commands for Monitoring Control Processor CPU Utilization3-20
Example for Monitoring Control Processor CPU Utilization3-21
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Rebooting and Shutting Down the Cisco SCE Platform3-23
Rebooting the Cisco SCE Platform3-23
Examples for Rebooting the Cisco SCE Platform3-23
How to Shut Down the Cisco SCE Platform3-23
Example for Shutting Down the Cisco SCE Platform3-24
Contents
CHAPTER
4Utilities4-1
Introduction4-1
Working with Cisco SCE Platform Files4-2
Working with Directories4-2
Working with Files4-4
The User Log4-7
The Logging System4-7
Generating a File for Technical Support4-9
How to Create a Directory4-2
How to Delete a Directory4-2
How to Change Directories4-3
How to Display your Working Directory4-3
How to List the Files in a Directory4-3
How to Rename a File4-4
How to Delete a File4-4
Copying Files4-5
How to Display File Contents4-6
How to Unzip a File4-6
Copying the User Log4-7
Enabling and Disabling the User Log4-8
Viewing the User Log Counters4-8
Viewing the User Log4-9
Clearing the User Log4-9
Generating a File for Technical Support: Example4-9
OL-30621-02
Managing Syslog4-10
Enabling and Disabling Syslog4-10
Configuring Remote Syslog Hosts4-10
How to Add a Remote Syslog Host4-11
How to Remove a Remote Syslog Host4-11
Configuring the Minimum Severity Level to be Logged to Syslog4-11
How to Configure the Minimum Severity Level for Syslog Messages4-12
How to Restore the Default Minimum Severity Level for Syslog Messages4-12
Configuring the Syslog Facility4-12
Cisco SCE 8000 10GBE Software Configuration Guide
v
Contents
How to Configure the Syslog Facility4-13
How to Restore the Default Syslog Facility4-13
Configuring the Syslog Logging Rate Limit4-13
How to Configure the Syslog Rate Limit4-14
How to Restore the Default Syslog Rate Limit4-14
Configuring the Syslog Time Stamp Format4-14
How to Configure the Syslog Time Stamp Format4-15
How to Restore the Default Syslog Time Stamp Format4-15
Enabling and Disabling the Syslog Message Counter4-15
Monitoring Syslog4-15
How to Display the Syslog Configuration4-16
How to Display the Syslog Counters4-16
Flow Capture4-17
Limitations4-17
The Flow Capture Process4-18
Configuring a Flow Capture Traffic Rule4-18
Configuring the Flow Capture Settings4-18
Performing the Flow Capture4-20
Monitoring the Flow Capture4-20
CHAPTER
5Configuring the Management Interface and Security5-1
Introduction5-1
Management Interface and Security5-2
Configuring the Management Ports5-3
Entering the Management Interface Configuration Mode5-3
Configuring the Management Port Physical Parameters5-4
Setting the IP Address and Subnet Mask of the Management Interface5-4
Configuring the Management Interface Speed and Duplex Parameters5-5
Specifying the Active Management Port5-7
Management Interface Redundancy5-8
Configuring the Management Ports for Redundancy5-8
Configuring the Fail-Over Mode5-9
Monitoring the Management Interface5-10
Configuring Management Interface VLANs5-11
Monitoring Management VLANs5-14
TACACS+ Authentication, Authorization, and Accounting5-15
Information About TACACS+ Authentication, Authorization, and Accounting5-15
Login Authentication5-15
Accounting5-16
vi
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Privilege-Level Authorization5-16
Command-Level Authorization5-17
General AAA Fallback and Recovery Mechanism5-17
About Configuring TACACS+5-18
Configuring the Cisco SCE Platform TACACS+ Client5-19
Adding a New TACACS+ Server Host5-19
Removing a TACACS+ Server Host5-20
Configuring the Global Default Key5-20
Configuring the Global Default Timeout5-21
Managing the User Database5-22
Adding a New User to the Local Database5-22
Defining the User Privilege Level5-24
Adding a New User with Privilege Level and Password5-24
Deleting a User5-26
Displaying Statistics, Keys, and Timeouts for TACACS+ Servers5-30
Monitoring TACACS+ Users5-31
Contents
OL-30621-02
Configuring Access Control Lists (ACLs)5-32
Adding Entries to an ACL5-33
Removing an ACL5-33
Defining a Global ACL5-34
Managing the Telnet Interface5-35
Preventing Telnet Access5-35
Assigning an ACL to the Telnet Interface5-35
Removing ACL Assignment from the Telnet Interface5-36
Configuring Telnet Timeout5-36
Configuring the SSH Server5-37
The SSH Server5-37
Key Management5-37
Managing the SSH Server5-38
Generating a Set of SSH Keys5-38
Enabling the SSH Server5-38
Cisco SCE 8000 10GBE Software Configuration Guide
vii
Contents
Disabling the SSH Server5-38
Running Only SSHv25-39
Assigning an ACL to the SSH Server5-39
Removing the ACL Assignment from the SSH Server5-39
Deleting the Existing SSH Keys5-39
Monitoring the Status of the SSH Server5-40
Configuring and Managing the SNMP Interface5-41
About the SNMP Interface5-41
SNMP Protocol5-41
Security Considerations5-42
About CLI5-43
About MIBs5-44
Configuration via SNMP5-44
Enabling the SNMP Interface5-45
How to Enable the SNMP Interface5-45
How to Disable the SNMP Interface5-45
Configuring SNMP Community Strings5-45
Defining a Community String5-46
Removing a Community String5-46
Displaying the Configured Community Strings5-47
Configuring SNMP Notifications5-47
Configuring SNMP Server Group5-48
Configuring SNMP Server View5-48
Configuring SNMP Server User5-49
Defining SNMP Hosts5-50
Configuring SNMP Traps5-51
SNMP Walk Acceleration for linkServiceUsage Queries5-53
How to Enable SNMP Query Acceleration5-53
SNMPv3 Configuration Example5-53
CHAPTER
viii
6Global Configuration6-1
Introduction6-1
IP Routing Configuration6-2
Configuring the IP Routing Table6-2
How to Configure the Default Gateway6-2
How to Add an Entry to the IP Routing Table6-3
How to Display the IP Routing Table6-3
IP Advertising6-4
Configuring IP Advertising6-4
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
How to Display the Current IP Advertising Configuration6-5
Configuring Time Clocks and Time Zone6-6
Displaying the System Time6-6
Displaying the System Time: Example6-6
Displaying the Calendar Time6-7
Displaying the Calendar Time: Example6-7
Setting the System Clock6-7
Options6-7
Setting the System Clock: Example6-7
Setting the Calendar6-7
Options6-8
Setting the Calendar: Example6-8
Setting the Time Zone6-8
Options6-8
Setting the Time Zone: Example6-9
Removing the Current Time Zone Setting6-9
Configuring Daylight Saving Time6-9
Options6-9
Guidelines6-10
How to Define Recurring Daylight Saving Time Transitions6-11
How to Define Non-Recurring Daylight Saving Time Transitions6-11
How to Cancel the Daylight Saving Time Configuration6-11
How to Display the Current Daylight Saving Time Configuration6-12
Contents
OL-30621-02
Configuring SNTP6-13
How to Enable the SNTP Multicast Client6-13
How to Disable the SNTP Multicast Client6-14
How to Enable the SNTP Unicast Client6-14
Options6-14
Enabling SNTP Unicast Client: Example6-14
Disabling the SNTP Unicast Client6-14
How to Disable the SNTP Unicast Client and Remove All Servers6-14
How to Remove One SNTP Server6-15
How to Define the SNTP Unicast Update Interval6-15
Options6-15
How to Display SNTP Information6-15
Domain Name Server (DNS) Settings6-17
Configuring DNS Lookup6-17
How to Enable DNS Lookup6-17
How to Disable DNS Lookup6-17
Cisco SCE 8000 10GBE Software Configuration Guide
ix
Contents
Configuring Name Servers6-18
Options6-18
How to Define Domain Name Servers6-18
How to Remove a Domain Name Server6-18
How to Remove All Domain Name Servers6-19
How to Add a Host to the Host Table6-19
Options6-19
Adding Hosts to Removing them from the Host Table: Example6-19
How to Display Current DNS Settings6-19
Displaying Current DNS Settings: Example6-19
Configuring Cisco Discovery Protocol6-20
Cisco Discovery Protocol6-20
Cisco Discovery Protocol on the Cisco SCE 8000 Platform6-21
CDP Operational Modes on the Cisco SCE 80006-21
CDP Limitations on the Cisco SCE 80006-22
Configuring CDP on the Cisco SCE 8000 Platform6-22
Enabling CDP Globally6-22
Setting CDP Mode6-23
Enabling CDP on a Specific Traffic Interface6-23
Setting the Hold Time6-24
Setting the Timer6-24
Monitoring and Maintaining CDP6-25
CDP Configuration Examples6-27
Example: Setting the CDP Mode6-27
Example: Monitoring and Maintaining CDP6-27
CHAPTER
x
Enabling the CLI Interface Warning Banner6-29
OS Fingerprinting and NAT Detection6-30
Restrictions and Limitations6-30
Configuring OS Fingerprinting6-31
Monitoring OS Fingerprinting6-33
7Configuring Line Interfaces7-1
Introduction7-1
Line Interfaces7-2
Information About Line Interfaces7-2
Flow Control and Bandwidth Considerations7-2
Maximum Packet Size7-2
How to Configure the Ten Gigabit Ethernet Line Interfaces7-2
Changing the Traffic Direction on the Ten Gigabit Ethernet Line Interfaces7-3
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
How to Specify the Traffic Direction on Link 17-3
Tunneling Protocols7-4
Tunneling IPv6 Traffic7-6
Selecting the Tunneling Mode7-7
Configuring the 6to4 Tunnels7-8
Configuring DS-Lite Tunnels7-9
Configuring L2TP Tunnels7-10
Configuring GRE Tunneling7-11
Configuring IPinIP Tunneling7-13
Configuring DSCP Marking7-14
Configuring the 6to4 Environment7-15
Configuring the VLAN Environment7-16
Configuring the MPLS Environment7-17
Configuring the L2TP Environment7-18
Asymmetric L2 Support7-18
Displaying the Tunneling Configuration7-19
How to Delete all Existing Traffic Counters7-28
Configuring Traffic Rules7-29
How to Create a Traffic Rule for IPv4 Addresses7-29
How to Create a Traffic Rule for IPv6 Addresses7-32
How to Delete a Traffic Rule7-33
How to Delete All Traffic Rules7-33
OL-30621-02
Cisco SCE 8000 10GBE Software Configuration Guide
xi
Contents
How to Delete All Flow Control Traffic Rules7-34
Managing Traffic Rules and Counters7-34
How to View a Specified Traffic Rule7-34
How to View All Traffic Rules7-34
How to View a Specified Traffic Counter7-34
How to View All Traffic Counters7-35
How to Reset a Specified Traffic Counter7-35
How to Reset All Traffic Counters7-35
DSCP Marking7-36
How to Display the DSCP Marking Configuration7-36
Counting Dropped Packets7-37
About Counting Dropped Packets7-37
Disabling the Hardware Packet Drop7-37
CHAPTER
8Configuring the Connection8-1
Introduction8-1
Configuring the Connection Mode8-2
Options8-2
Configuring the Connection Mode Examples8-3
Monitoring the Connection Mode and Related Parameters8-4
Connection Mode Examples8-4
Configuring the Link Mode8-6
About the Link Mode8-6
Options8-6
External Optical Bypass8-7
How to Activate the External Bypass8-7
How to Deactivate the External Bypass8-8
How to Set the External Bypass to the Default State8-8
How to Display the State of the External Bypass8-8
Hardware Bypass8-9
How to Enable the Hardware Bypass Mode8-9
How to Disable the Hardware Bypass Mode8-10
How to Display the Status of the Hardware Bypass Mode8-10
How to Set the Hardware Bypass Status for a Static Party8-10
How to Reset the Hardware Bypass Staus of a static party8-10
How to Display the Hardware Bypass Status of a Static Party8-11
How to Display the Startup Configuration Party Database8-11
How to Display the Currently Running Party Database Configuration8-12
xii
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
How to Copy the Running Configuration Party Database to the Startup Configuration Party
Database
How to Copy the Startup Configuration Party Database and Create a Backup File8-12
Configuring the Static Subscribers8-13
How to the Set the IP Address for a Static Subscriber8-13
How to Set the IP Range for a Static Subscriber8-13
How to Display All Mappings to Dual Stack Static Subscriber8-13
How to Display IPv6 Mappings to Dual Stack Static Subscriber8-14
How to Display Dual Stack Static Subscriber8-14
Link Failure Reflection8-15
How to Enable Link Failure Reflection8-15
How to Disable Link Failure Reflection8-15
Enabling and Disabling Link Failure Reflection on All Ports8-15
Options8-16
How to Enable Link Failure Reflection on All Ports8-16
How to Disable Link Failure Reflection on All Ports8-16
Configuring Link Failure Reflection in Linecard-Aware Mode8-16
How to Enable Linecard-Aware Mode8-17
How to Disable Linecard-Aware Mode8-17
8-12
Contents
CHAPTER
Asymmetric Routing Topology8-18
Asymmetric Routing and Other Service Control Capabilities8-18
Enabling Asymmetric Routing8-18
Monitoring Asymmetric Routing8-19
Monitoring Asymmetric Routing: Example8-19
Configuring a Forced Failure8-20
Configuring the Failure Recovery Mode8-21
Options8-21
Configure the Failure Recovery Mode: Examples8-21
Configuring the Cisco SCE Platform/SM Connection8-22
Configuring the Behavior of the Cisco SCE Platform in Case of Failure of the SM8-22
Options8-22
Configuring the SM-SCE Platform Connection Timeout8-22
Options8-23
9Raw Data Formatting: The RDR Formatter and NetFlow Exporting9-1
Categories9-5
Priority9-5
Setting DSCP for NetFlow9-6
Forwarding Modes9-6
Protocol9-6
Transport Type9-6
Configuring Data Destinations and Categories9-7
Configuring a Data Destination9-7
Options9-7
Configuring the Data Destinations: Examples9-7
Configuring the Data Categories9-8
Configuring the Buffer Size9-9
Configuring a Destination and Assigning Categories9-9
Configuring the Forwarding Mode9-13
Options9-13
Configuring the Forwarding Mode: Example9-13
Configuring the RDR Formatter9-14
Options9-14
How to Configure the Size of the RDR Formatter History Buffer9-14
Configuring NetFlow Exporting Support9-15
Options9-15
How to Configure a DSCP Value for NetFlow9-15
Options9-15
How to Configure the Template Refresh Interval9-15
Options9-15
Configuring Dynamic Mapping of RDRs to Categories9-17
Configuring Mappings9-17
Options9-17
How to Restore the Default Mapping for a Specified RDR Tag9-17
Displaying Data Destination Configuration and Statistics9-18
How to the Display the Current RDR Formatter Configuration9-18
Displaying the RDR Formatter Configuration: Example9-19
How to the Display the Current RDR Formatter Statistics9-19
Displaying the Current RDR Formatter Statistics: Example9-19
xiv
Disabling the Linecard from Sending RDRs9-21
Disabling RDR Aggregation9-22
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Contents
CHAPTER
10Managing Subscribers10-1
Introduction10-1
Information About Subscribers10-2
What is a Subscriber?10-2
Subscriber Modes in Service Control Solutions10-3
Subscriber Database: Capacity and Limits10-4
Working with Large Numbers of Subscribers10-5
Actual Maximum Number of Subscribers10-5
Subscriber Mapping Limits10-5
Rate of Creating Anonymous Subscribers10-5
Aging Subscribers10-5
VPN-Based Subscribers10-6
Automatic VLAN VPNs10-6
Synchronizing Subscriber Information in a Cascade System10-6
Anonymous Groups and Subscriber Templates10-7
Subscriber Files10-8
Subscriber Default csv File Format10-8
IPv6 Subscriber csv File Format10-9
Here is an example of a subscriber csv file in the default format:10-9
Subscriber Anonymous Groups csv File Format10-9
Importing and Exporting Subscriber Information10-10
Editing the subaware.pro File10-10
Options10-11
How to Import Subscriber Information10-11
How to Export Subscriber Information10-11
How to Import a Subscriber Template10-12
How to Export a Subscriber Template10-12
Removing Subscribers and Templates10-13
How to Remove a Specific Subscriber10-13
Options10-13
How to Remove All Introduced Subscribers10-14
How to Remove a Specific Anonymous Subscriber Group10-14
Options10-14
How to Remove All Anonymous Subscriber Groups10-14
How to Remove All the Anonymous Subscribers10-14
How to Remove All Subscriber Templates10-15
Removing VPN-based Subscribers10-15
How to Remove Subscribers by Device10-15
How to Remove Subscribers from the SM10-15
OL-30621-02
Cisco SCE 8000 10GBE Software Configuration Guide
xv
Contents
How to Remove Subscribers from a Specified SCMP Peer Device10-17
Creating Anonymous Groups10-18
Defining Anonymous Groups10-18
How to Define an Anonymous Group10-18
Importing and Exporting Anonymous Groups10-19
How to Import Anonymous Groups10-19
How to Export Anonymous Groups10-19
Monitoring Subscribers10-20
How to Monitor the Subscriber Database10-20
How to Display the Subscriber Database Counters10-21
Clearing the Subscriber Database Counters10-22
Displaying Subscribers10-22
Displaying Subscribers: All Current Subscriber Names10-22
Displaying Subscribers: By Subscriber Property or Prefix10-23
How to Display Subscribers: By Mapping (IP Address, VPN, or VLAN ID)10-25
How to Display Subscriber Information10-27
How to Display a Listing of Subscriber Properties10-28
How to Display Complete Information for a Specified Subscriber10-28
How to Display Values of Subscriber Properties for a Specified Subscriber10-28
How to Display Mappings for a Specified Subscriber10-28
How to Display OS Counters for a Specified Subscriber10-29
Displaying Anonymous Subscriber Information10-29
How to Display Currently Configured Anonymous Groups10-29
How to Display Currently Configured Templates for Anonymous Groups10-30
How to Display Current Configuration for a Specified Anonymous Group10-30
How to Display Subscribers in a Specified Anonymous Group10-30
How to Display All Subscribers Currently in Anonymous Groups10-30
How to Display the Number of Subscribers in a Specified Anonymous Group10-31
How to Display the Total Number of Subscribers in All Anonymous Groups10-31
xvi
Configuring the Actual Maximum Number of Subscribers10-32
How to Override the Configured Capacity Option10-32
How to Override the Configured Capacity Option in a Cascade Setup10-32
How to Restore the Configured Capacity Option10-33
How to Monitor the Maximum Number of Subscribers10-33
Configuring Subscriber Aging10-34
How to Enable Aging for Anonymous Group Subscribers10-34
How to Enable Aging for Introduced Subscribers10-34
How to Disable Aging for Anonymous Group Subscribers10-34
How to Disable Aging for Introduced Subscribers10-35
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
How to Set the Aging Timeout Period for Anonymous Group Subscribers10-35
Options10-35
How to Set the Aging Timeout Period for Introduced Subscribers10-35
Options10-35
How to Display Aging for Anonymous Group Subscribers10-35
How to Display Aging for Introduced Subscribers10-36
Managing VPNs and VPN Subscriber Mappings10-37
How to Display VPN-Related Mappings10-37
How to Clear Automatic VPNs10-37
Configuring the Cisco SCE Platform/SM Connection10-39
Configuring the Behavior of the Cisco SCE Platform in Case of Failure of the SM10-39
Options10-39
Configuring the SM-SCE Platform Connection Timeout10-40
Options10-40
Contents
CHAPTER
11Redundancy and Failover11-1
Introduction11-1
Redundancy and Failover11-2
Terminology and Definitions11-2
Redundant Topologies11-2
External Bypass11-3
Hardware Bypass11-3
In-line Dual Link Redundant Topology11-3
Failure Detection11-3
Link Failure Reflection11-5
Hot Standby and Failover11-6
Hot Standby11-6
Failover11-6
Hardware Crash Mode11-8
Failure in the Cascade Connection11-9
Installing a Cascaded System11-9
Recovery11-11
Replacing the Cisco SCE Platform (Manual Recovery)11-11
Manual Steps11-11
Automatic Steps (in parallel with the manual steps, requires no user intervention):11-12
Reboot Only (Fully Automatic Recovery)11-12
OL-30621-02
CLI Commands for Cascaded Systems11-13
Topology-Related Parameters for Redundant Topologies11-13
Configuring the Connection Mode11-13
Cisco SCE 8000 10GBE Software Configuration Guide
xvii
Contents
Examples11-14
Monitoring the System11-14
How to View the Current Connection Mode11-14
How to View the Cisco SCE-ID11-15
How to View the Current Redundancy Status of the Cisco SCE Platform11-15
How to View Information about the Peer Cisco SCE Platform11-15
How to View Information about the Cascade Connections11-16
How to View the Current Link to Port Mappings11-16
How to View the Current Link Mode11-17
Configuring Forced Failure11-18
System Upgrades11-19
Firmware Upgrade (package installation)11-19
Application Upgrade11-19
Simultaneous Upgrade of Firmware and Application11-20
CHAPTER
12Identifying and Preventing Distributed Denial-of-Service Attacks12-1
Options12-10
How to Enable Specific-IP Detection12-10
How to Enable Specific-IP Detection for the TCP Protocol Only for all Attack Directions12-11
How to Enable Specific-IP Detection for the TCP Protocol for Port-Based Detections Only for
Dual-Sided Attacks
12-11
How to Disable Specific-IP Detection for Protocols Other than TCP, UDP, and ICMP for all Attack
Directions
12-11
How to Disable Specific-IP Detection for ICMP for Single-Sided Attacks Defined by the Source
12-11
IP
Configuring the Default Attack Detector12-11
Options12-12
How to Define the Default Action and Optionally, the Default Thresholds12-13
How to Reinstate the System Defaults for a Selected Set of Attack Types12-13
xviii
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
How to Reinstate the System Defaults for All Attack Types12-14
Specific Attack Detectors12-14
Options12-14
How to Enable a Specific Attack Detector and Assign it an ACL12-15
How to Define the Action and Optionally the Thresholds for a Specific Attack Detector12-16
How to Define the Subscriber Notification Setting for a Specific Attack Detector12-16
How to Define the SNMP Trap Setting for a Specific Attack Detector12-16
How to Define the List of Destination Ports for TCP or UDP Protocols for a Specific Attack
Detector
How to Delete User-Defined Values12-17
How to Disable a Specific Attack Detector12-17
How to Disable All Non-default Attack Detectors12-18
How to Disable All Attack Detectors12-18
Sample Attack Detector Configuration12-18
Subscriber Notifications12-20
Configuring the Subscriber Notification Port12-20
Options12-20
How to Remove the Subscriber Notification Port12-20
12-17
Contents
Preventing and Forcing Attack Detection12-21
Options12-21
Preventing Attack Filtering12-21
How to Remove All dont-filter Settings12-22
Forcing Attack Filtering12-22
How to Remove All force-filter Settings12-23
Monitoring Attack Filtering12-24
Monitoring Attack Filtering Using SNMP Traps12-24
Monitoring Attack Filtering Using CLI Commands12-26
How to Display a Specified Attack Detector Configuration12-26
How to Display the Default Attack Detector Configuration12-28
How to Display All Attack Detector Configurations12-28
How to Display Filter State (Enabled or Disabled)12-29
How to Display Configured Threshold Values and Actions12-29
How to Display the Current Counters12-30
How to Display all Currently Handled Attacks12-31
How to Display all Existing Force-Filter Settings12-31
How to Display all Existing Don't-Filter Settings12-31
How to Display the List of Ports Selected for Subscriber Notification12-31
How to Find out Whether Hardware Attack Filtering has been Activated12-32
Viewing the Attack Log12-32
The Attack Log12-32
OL-30621-02
Cisco SCE 8000 10GBE Software Configuration Guide
xix
Contents
How to View the Attack Log12-33
How to Copy the Attack Log to a File12-33
CHAPTER
13Managing the SCMP13-1
Introduction13-1
About SCMP13-2
SCMP Terminology13-3
Deployment Scenarios13-3
Single ISG Router with a Single Cisco SCE Platform (1xISG – 1xCisco SCE)13-4
Single ISG Router with Two Cascaded Cisco SCE Platforms (1xISG – 2xCisco SCE)13-4
Multiple ISG Routers with Two Cascaded Cisco SCE Platforms (NxISG – 2xCisco SCE)13-5
Multiple ISG Routers with Multiple Cisco SCE Platforms via Load Balancing (NxISG – MxCisco
SCE)
13-6
SCMP Peer Devices13-7
Connection Management13-7
SCMP Subscriber Management13-8
GUID and Subscriber ID13-8
Configuring the SCMP13-9
Configuring SCMP Parameters13-9
How to Enable the SCMP13-9
How to Disable the SCMP13-10
How to Configure the SCMP Peer Device to Push Sessions13-10
Configuring the SCMP Peer Device to Force Each Subscriber to Single Cisco SCE Platform13-10
Defining the Keep-alive Interval Parameter13-11
Defining the Reconnect Interval Parameter13-11
Defining the Loss-of-Sync Timeout Parameter13-12
Adding an SCMP Peer Device13-12
How to Define an SCMP Peer Device13-12
How to Assign the SCMP Peer Device to an Anonymous Group13-13
Deleting Subscribers Managed by an SCMP Peer Device13-14
Options13-14
Deleting an SCMP Peer Device13-14
Defining the Subscriber ID13-14
Options13-15
Configuring the RADIUS Client13-15
Options13-16
xx
Monitoring the SCMP Environment13-17
How to Monitor the SCMP13-17
Options13-17
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
How to display the general SCMP configuration13-17
How to display the configuration all currently defined SCMP peer devices13-18
How to display the configuration for a specified SCMP peer device13-18
How to display the statistics for all SCMP peer devices13-18
How to display the statistics for a specified SCMP peer device13-19
Requirements for VAS Servers14-4
VAS Traffic Forwarding and SCA BB14-5
VLAN Tags for VAS Traffic Forwarding14-5
Service Flow14-5
Data Flow14-6
Non-VAS Data Flow14-7
VAS Data Flow14-7
Load Balancing14-8
Load Balancing and Subscribers14-8
Load Balancing and Subscriber Mode14-9
VAS Redundancy14-10
VAS Server Failure14-10
VAS Server Group Failure14-10
Ethernet Switch Failure14-11
Disabling a VAS Server14-11
OL-30621-02
VAS Status and VAS Health Check14-12
VAS Server States14-13
VAS Traffic Forwarding Topologies14-14
Single Cisco SCE Platform, Multiple VAS Servers14-14
Data Flow14-15
Multiple Cisco SCE Platforms, Multiple VAS Servers14-15
SNMP Support for VAS14-17
Interactions Between VAS Traffic Forwarding and Other Cisco SCE Platform Features14-18
Incompatible Cisco SCE Platform Features14-18
VAS Traffic Forwarding and DDoS Processing14-18
Specific IP DDoS Attack Detection14-18
Specific IP Attack Filter14-18
Cisco SCE 8000 10GBE Software Configuration Guide
xxi
Contents
VAS Traffic Forwarding and Bandwidth Management14-19
Global Controllers and VAS Flows14-19
Configuring VAS Traffic Forwarding14-20
Configuring VAS Traffic Forwarding from the SCA BB Console14-21
Global Options14-21
Enabling VAS Traffic Forwarding14-21
Options14-21
Disabling VAS Traffic Forwarding14-22
Configuring the VAS Traffic Link14-22
Options14-23
How to Select the Link for VAS Traffic14-23
How to Revert to the Default Link for VAS Traffic14-23
Configuring a VAS Server14-23
Options14-24
How to Enable a VAS Server14-24
How to Disable a VAS Server14-24
How to Restore all VAS Server Properties to Default14-24
Assigning a VLAN ID to a VAS Server14-24
Options14-25
How to Configure the VLAN Tag Number for a Specified VAS Server14-25
How to Remove the VLAN Tag Number from a Specified VAS Server14-25
Configuring the Health Check14-25
How to Enable VAS Server Health Check14-26
How to Disable VAS Server Health Check14-27
How to Define the UDP Ports to be Used for Health Check14-27
How to Remove the UDP Ports Configuration14-27
Configuring Pseudo IP Addresses for the Health Check Packets14-27
Configuring a VAS Server Group14-28
Adding and Removing Servers14-29
Configuring VAS Server Group Failure Parameters14-29
VAS Configuration Example14-31
xxii
Monitoring VAS Traffic Forwarding14-32
How to Display Global VAS Status and Configuration14-32
Example14-32
How to Display Operational and Configuration Information for a Specific VAS Server Group14-33
Example14-33
How to Display Operational and Configuration Information for All VAS Server Groups14-33
How to Display Operational and Configuration Information for a Specific VAS Server14-33
Example14-33
How to Display Operational and Configuration Information for All VAS Servers14-34
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
How to Display the VAS Servers Used by a Specified Subscriber14-34
How to Display Health Check Counters for a Specified VAS Server14-34
Example14-34
How to Display Health Check Counters for All VAS Servers14-35
How to Clear the Health Check Counters for a Specified VAS Server14-35
How to Clear the Health Check Counters for All VAS Servers14-35
Intelligent Traffic Mirroring14-36
Using Traffic Mirroring for Behavioral Targeting14-36
How Traffic Mirroring Works14-37
Temperature Sensor Traps UpdatedA-29
Release 3.7.0 MIB UpdatesA-29
SNMP Support for Aggregative Global ControllersA-29
OL-30621-02
Cisco SCE 8000 10GBE Software Configuration Guide
xxiii
Contents
linkUp and linkDown Notification TrapsA-29
Release 4.1.0 MIB UpdatesA-30
SNMP TRAP for Global AttacksA-30
SNMP Walk Functionality for Temperature MIBsA-30
APPENDIX
APPENDIX
BMonitoring Cisco SCE Platform UtilizationB-1
IntroductionB-1
Cisco SCE Platform Utilization IndicatorsB-2
CPU UtilizationB-2
Flows CapacityB-2
Subscribers CapacityB-2
Service LossB-3
Monitoring Service LossB-3
CCisco SCE 8000 Licensing InformationC-1
OpenSSH LicenseC-1
NetSNMP LicenseC-9
xxiv
Cisco SCE 8000 10GBE Software Configuration Guide
OL-30621-02
Introduction
About this Guide
Revised: February 07, 2014, OL-30621-02
This preface describes who should read Cisco SCE 8000 10GBE Software Configuration Guide, how it
is organized, and its document conventions.
This guide is for experienced network administrators who are responsible for configuring and
maintaining the Cisco SCE platform.
OL-30621-02
Cisco SCE 8000 10GBE Software Configuration Guide
1
Document Revision History
The following Document Revision History records the changes made to this document.
Table 1Document Revision History
Cisco Service Control
Revision
OL-30621-02Release 4.1.x
OL-30621-01Release 4.1.x
Release and DateChange Summary
February 07, 2014
December 23, 2013
Updated “MIB Updates” section on page A-27 with
limitations on linkUp/linkDown trap.
First version of this document (new for the Release
4.1.x train).
The following changes were made from the last release
of the 4.0.x train:
• Updated “Configuring and Managing the SNMP
Interface” section on page 5-41 with SNMPv3
details.
• Updated the “Tunneling Protocols” section on
page 7-4.
• Added “Release 4.1.0 MIB Updates” section on
page A-30.
Cisco SCE 8000 10GBE Software Configuration Guide
2
OL-30621-02
Organization
This guide contains the following sections.
Table 2Document Organization
SectionTitleDescription
Chapter 1Cisco Service Control OverviewOverview of Cisco SCE platform management.
Chapter 2Command-Line InterfaceDetailed explanation of how to use the Cisco SCE
Chapter 3Basic Cisco SCE 8000 Platform
Chapter 4UtilitiesExplanation of the setup wizard and the user log,
Chapter 5Configuring the Management
Chapter 6Global ConfigurationExplanation of how to configure various global
Chapter 7Configuring Line InterfacesExplanation of how to configure tunneling, TOS
Chapter 8Configuring the ConnectionExplanation of how to configure the connection
Chapter 9Raw Data Formatting: The RDR
Chapter 10Managing SubscribersExplanation of how to import and export
Chapter 11Redundancy and FailoverExplanation of how to configure and manage a
Chapter 12Identifying and Preventing
Chapter 13Managing the SCMPExplanation of Service Control Management
Operations
Interface and Security
Formatter and NetFlow Exporting
Distributed Denial-of-Service
Attacks
Command-line Interface.
Explanation of how to manage configurations,
install applications and upgrade the system
software.
as well as of file operations.
Explanation of how to configure the various
management options: Telnet, SSH, and SNMP.
Also how to configure the system time, Domain
Name Settings, management IP address, and
passwords.
settings, such as system time, Domain Name
Settings, and IP routing.
marking, and traffic rules.
mode, link mode, and failure behaviors
Explanation of how to configure the connection
mode, link mode, and failure behaviors.
subscriber information and how to monitor
subscribers.
redundant system.
Explanation of how to configure attack filtering.
Protocol (SCMP), which is a protocol that
integrates the Cisco SCE platform and the ISG
(Intelligent Service Gateway) functionality of the
Cisco routers. It also explains how to configure
and manage SCMP, SCMP peer devices and the
RADIUS client.
OL-30621-02
Cisco SCE 8000 10GBE Software Configuration Guide
3
Table 2Document Organization (continued)
SectionTitleDescription
Chapter 14Value-Added Services (VAS) Traffic
Forwarding
Appendix A Cisco Service Control MIBsExplanation of how to map the proprietary pcube
Appendix B Monitoring Cisco SCE Platform
Utilization
Appendix C Cisco SCE 8000 Licensing
Information
Explanation of Value Added Services (VAS)
traffic forwarding and how to configure it. Also
explains how the same capabilities are used for
traffic mirroring.
MIB supported in previous releases to the new
MIB structure.
Explanation of how to monitor Cisco SCE
platforms that are installed in real traffic.
Copy of Open SSH and NetSNMP license
information.
Cisco SCE 8000 10GBE Software Configuration Guide
4
OL-30621-02
Related Publications
Your Cisco SCE platform and the software running on it contain extensive features and functionality,
which are documented in the following resources:
• For further information regarding the Service Control CLI and a complete listing of all CLI
commands, refer to the Cisco SCE8000 CLI Command Reference
• For initial installation and startup information, refer to the relevant installation guide:
–
Cisco SCE8000 10GBE Installation and Configuration Guide
• For international agency compliance, safety, and statutory information for wide-area network
(WAN) interfaces for the Cisco SCE 2000 platform, refer to the regulatory and safety information
document:
–
Regulatory Compliance and Safety Information for Cisco SCE8000
• For installation and configuration of the other components of the Service Control Management Suite
refer to:
–
Cisco SCMS Subscriber Management User Guide
–
Cisco SCMS Collection Manager User Guide
–
Cisco Service Control Application for Broadband User Guide
–
Cisco Insight User Guide
• To view Cisco documentation or obtain general information about the documentation, refer to the
following sources:
–
Obtaining Documentation and Submitting a Service Request, page 7
–
The Cisco Information Packet that shipped with your Cisco SCE 8000 platform.
OL-30621-02
Cisco SCE 8000 10GBE Software Configuration Guide
5
Conventions
This document uses the following conventions.
Table 3Conventions
ConventionIndication
bold fontCommands and keywords and user-entered text appear in bold font.
italic fontDocument titles, new or emphasized terms, and arguments for which you supply
values are in italic font.
[ ]Elements in square brackets are optional.
{x | y | z}Required alternative keywords are grouped in braces and separated by
vertical bars.
[x | y | z]Optional alternative keywords are grouped in brackets and separated by
vertical bars.
stringA nonquoted set of characters. Do not use quotation marks around the string or
the string will include the quotation marks.
courier fontTerminal sessions and information the system displays appear in courier font.
< >Nonprinting characters such as passwords are in angle brackets.
[ ]Default responses to system prompts are in square brackets.
!, #An exclamation point (!) or a pound sign (#) at the beginning of a line of code
indicates a comment line.
NoteMeans reader take note.
TipMeans the following information will help you solve a problem.
CautionMeans reader be careful. In this situation, you might perform an action that could result in equipment
damage or loss of data.
TimesaverMeans the described action saves time. You can save time by performing the action described in
the paragraph.
Warning
Means reader be warned. In this situation, you might perform an action that could result in
bodily injury.
Cisco SCE 8000 10GBE Software Configuration Guide
6
OL-30621-02
Loading...
+ 448 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.