Page 2 - Prerequisites for Configuring Secure Domain Routers
Configuring Secure Domain Routers on Cisco IOS XR Software Prerequisites for Configuring Secure Domain Routers SMC-128 Cisco IOS XR System Management Configuration Guide Prerequisites for Configuring Secure Domain Routers Before configuring SDRs, the following conditions must be met: Initial configu...
Page 3 - Information About Configuring Secure Domain Routers; What Is a Secure Domain Router?; Owner SDR and Administration Configuration Mode
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-129 Cisco IOS XR System Management Configuration Guide Information About Configuring Secure Domain Routers Review the following topics before configuring secure domain routers: • What I...
Page 4 - SDR Access Privileges
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-130 Cisco IOS XR System Management Configuration Guide See the “SDR Access Privileges” section on page SMC-130 for more information. Note The Administration modes cannot be used to conf...
Page 5 - Other SDR Users
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-131 Cisco IOS XR System Management Configuration Guide • Ability to assign nodes (RPs, DRPs, and LCs) to SDRs. • Ability to create other users with similar or lower privileges. • Comple...
Page 6 - Designated Secure Domain Router System Controller (DSDRSC); DSCs and DSDRSCs in a Cisco CRS-1 Router; Using a DRP or DRP Pair as the DSDRSC in a Cisco CRS-1 Router; primary
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-132 Cisco IOS XR System Management Configuration Guide Designated Secure Domain Router System Controller (DSDRSC) In a router running the Cisco IOS XR software, one Route Processor is a...
Page 7 - Using a RP Pair as the DSDRSC in a Cisco CRS-1 Router; DSC and DSDRSCs in a Cisco XR 12000 Series Router
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-133 Cisco IOS XR System Management Configuration Guide • DRPs are supported in the Cisco CRS-1 only. DRPs are not supported in the Cisco XR 12000 Series Routers. Note DRPs can also be u...
Page 9 - Removing a DSDRSC Configuration; Default Configuration for New Non-Owner SDRs
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-135 Cisco IOS XR System Management Configuration Guide Removing a DSDRSC Configuration There are two ways to remove a DSDRSC from an SDR: • First remove all other nodes from the SDR con...
Page 10 - High Availability Implications; Fault Isolation; DSDRSC Redundancy; DSC Migration on Cisco CRS-1 Multishelf Systems
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-136 Cisco IOS XR System Management Configuration Guide High Availability Implications Fault Isolation Because the CPU and memory of an SDR are not shared with other SDRs, configuration ...
Page 11 - Cisco IOS XR Software Package Management
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-137 Cisco IOS XR System Management Configuration Guide another 30 seconds. This causes an inconsistent system view in the named SDR using DRP paired across the rack in which the DRP los...
Page 12 - install
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-138 Cisco IOS XR System Management Configuration Guide • To access install commands, you must be a member of the root-system user group with access to the Administration EXEC mode. • Mo...
Page 13 - Caveats
Configuring Secure Domain Routers on Cisco IOS XR Software Information About Configuring Secure Domain Routers SMC-139 Cisco IOS XR System Management Configuration Guide which is also the new DSDRSC. This operation takes some time, during which routing protocols such as BGP that use loopback or null...
Page 14 - How to Configure Secure Domain Routers; Contents; Creating SDRs; Creating SDRs in a Cisco CRS-1 Router
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-140 Cisco IOS XR System Management Configuration Guide How to Configure Secure Domain Routers To create an SDR, configure an SDR name and then add nodes to the configuration. In Cisco CRS-1 routers,...
Page 15 - SUMMARY STEPS
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-141 Cisco IOS XR System Management Configuration Guide Complete the following steps to create a non-owner SDR. Note The procedures in this section can be performed only on a router that is already r...
Page 16 - DETAILED STEPS; Command or Action
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-142 Cisco IOS XR System Management Configuration Guide DETAILED STEPS Command or Action Purpose Step 1 admin Example: RP/0/RP0/CPU0:router# admin Enters Administration EXEC mode. Step 2 configure Ex...
Page 17 - pair
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-143 Cisco IOS XR System Management Configuration Guide Step 7 pair pair-name primary or location partially-qualified-nodeid primary Example: RP/0/RP0/CPU0:router(admin-config-sdr:rname 2)# pair drp1...
Page 19 - Creating SDRs in a 12000 Series Router
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-145 Cisco IOS XR System Management Configuration Guide Creating SDRs in a 12000 Series Router To create a non-owner SDR in a Cisco XR 12000 Series Router, create an SDR name, add an RP (that can act...
Page 22 - Adding Nodes to a Non-Owner SDR; Adding Nodes to an SDR in a Cisco CRS-1 Router
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-148 Cisco IOS XR System Management Configuration Guide Adding Nodes to a Non-Owner SDR When adding nodes to an existing non-owner SDR, the following rules apply: • By default, all nodes in a new sys...
Page 24 - Adding Nodes to an SDR in a Cisco XR 12000 Series Router
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-150 Cisco IOS XR System Management Configuration Guide Adding Nodes to an SDR in a Cisco XR 12000 Series Router SUMMARY STEPS 1. admin 2. configure 3. sdr sdr-name 4. location partially-qualified-no...
Page 25 - Removing Nodes and SDRs
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-151 Cisco IOS XR System Management Configuration Guide Removing Nodes and SDRs This section contains the following instructions: • Removing Nodes from a Secure Domain Router in a Cisco CRS-1 Router,...
Page 26 - Removing Nodes from a Secure Domain Router in a Cisco CRS-1 Router
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-152 Cisco IOS XR System Management Configuration Guide • You must first remove a node from a non-owner SDR before it can be reassigned to another non-owner SDR. • To remove a node from the owner SDR...
Page 30 - Removing a Secure Domain Router
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-156 Cisco IOS XR System Management Configuration Guide Removing a Secure Domain Router This section provides instructions to remove a secure domain router from either a Cisco CRS-1 or a Cisco XR 120...
Page 31 - Configuring a Username and Password for a Non-Owner SDR
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-157 Cisco IOS XR System Management Configuration Guide Configuring a Username and Password for a Non-Owner SDR After you create an SDR, you can create a username and password on that SDR. When you a...
Page 35 - Disabling Remote Login for SDRs
Configuring Secure Domain Routers on Cisco IOS XR Software How to Configure Secure Domain Routers SMC-161 Cisco IOS XR System Management Configuration Guide Disabling Remote Login for SDRs When you disable admin plane authentication, the admin username cannot be used to log in to non-owner SDRs. Onl...
Page 36 - Configuration Examples for; Secure Domain Routers
Configuring Secure Domain Routers on Cisco IOS XR Software Configuration Examples for Secure Domain Routers SMC-162 Cisco IOS XR System Management Configuration Guide Configuration Examples for Secure Domain Routers Creating a New SDR on a Cisco CRS-1 Router RP/0/RP0/CPU0:router# admin RP/0/RP0/CPU0...
Page 38 - Additional References; Related Documents
Configuring Secure Domain Routers on Cisco IOS XR Software Additional References SMC-164 Cisco IOS XR System Management Configuration Guide Additional References The following sections provide references related to SDR configuration. Related Documents Standards MIBs Related Topic Document Title SDR ...
Page 39 - RFCs
Configuring Secure Domain Routers on Cisco IOS XR Software Additional References SMC-165 Cisco IOS XR System Management Configuration Guide RFCs Technical Assistance RFCs Title No new or modified RFCs are supported by this feature, and support for existing RFCs has not been modified by this feature....