Chapter 3
Connecting the Switch to the Network
3 - 10
Installing a Redundant Peer or Cluster Peer
If you are installing the second switch in a redundant pair (also called an
ARX cluster) or if you are configuring a second ARX cluster in a Disaster
Recovery (DR) configuration, you need to provide additional information to
the initial-boot script because all members of the cluster share a common
master key.
Note
A master key is an encryption key for all critical-security parameters
(CSPs), such as administrative passwords.
Redundant switches must use the same master key because they share the
same users, groups, and passwords. In the case of of a DR configuration, all
four ARX devices must be configured with a common master key.
At the peer that is currently installed, enter the
show master-key
command
to create an encrypted copy of the master key.
The CLI prompts you for the following passwords:
• System password. The system password is entered at initial-boot time
and validates that you have permission to access the master key. See
step 9 in the example shown in section
Booting a Non-Replacement
Switch, on page 3-4.
The system password is 12-32 characters long.
• Wrapping password. The wrapping password is set with the
show master-key
command. The security software uses the wrapping
password to encrypt (and later decrypt) the master key string.
Enter 12-32 characters. At least one character in this password must be a
number (0-9) or a symbol (!, @, #, $, and so on).
Important
Save this password because you will need it later to decrypt the master key
on the replacement switch.
The
show master-key
command outputs a base64-encoded string that is the
encrypted master key. Save this string and the wrapping password that you
set in the command.
The following example shows the master key on a switch named
stoweB
.
stoweB#
show
master
‐
key
Master
Key
System
Password:
%uper$ecretpw
Wrapping
Password:
an0ther$ecretpw
Validate
Wrapping
Password:
an0ther$ecretpw
Encrypted
master
key:
2oftVCwAAAAgAAAApwazSRFd2ww/H1pi7R7JMDZ9SoIg4WGA/XsZP+HcXjsIAAAADDRbM
CxE/bc=
stoweB#
...
Summary of Contents for ARX-2500
Page 1: ...ARX 2500 Hardware Installation Guide MAN 0417 00 ...
Page 2: ......
Page 6: ...vi ...
Page 7: ...Table of Contents ...
Page 8: ......
Page 10: ...Table of Contents x ...
Page 11: ......
Page 12: ...Table of Contents xii ...
Page 14: ......
Page 22: ...Chapter 1 Introduction 1 10 ...
Page 24: ......
Page 36: ...Chapter 2 Unpacking and Installing the Switch 2 14 ...
Page 38: ......
Page 55: ...4 Maintenance POST Diagnostics ...
Page 56: ......
Page 60: ......
Page 64: ...Appendix A Replacing Optical Transceivers or Chassis A 6 ...
Page 65: ...Index ...
Page 66: ......
Page 68: ...Index Index 4 ...