0% found this document useful (0 votes)
17 views52 pages

COS Configuration

The COS Configuration Guide for version 4.0.x provides comprehensive instructions for installing and configuring COS software on C-Series systems, aimed at system integrators and qualified personnel. It covers system features, management options, user management, network configuration, and upgrade procedures, ensuring high performance and availability. The document also includes legal disclaimers and customer support information, emphasizing the importance of following the guidelines for optimal system operation.

Uploaded by

tommyp100
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
17 views52 pages

COS Configuration

The COS Configuration Guide for version 4.0.x provides comprehensive instructions for installing and configuring COS software on C-Series systems, aimed at system integrators and qualified personnel. It covers system features, management options, user management, network configuration, and upgrade procedures, ensuring high performance and availability. The document also includes legal disclaimers and customer support information, emphasizing the importance of following the guidelines for optimal system operation.

Uploaded by

tommyp100
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

COS Configuration Guide

COS Version 4.0.x

003423A
November 2005
© Copyright Crossbeam Systems, 2005, ALL RIGHTS RESERVED
The products, specifications, and other technical information regarding the products contained in this document are
subject to change without notice. All information in this document is believed to be accurate and reliable, but is
presented without warranty of any kind, expressed or implied, and users must take full responsibility for their
application of any products specified in this document. Crossbeam Systems disclaims responsibility for errors that
may appear in this document, and it reserves the right, in its sole discretion and without notice, to make substitutions
and modifications in the products and practices described in this document.
This material is protected by the copyright and trade secret laws of the United States and other countries. It may not
be reproduced, distributed, or altered in any fashion by any entity (either internal or external to Crossbeam Systems),
except in accordance with applicable agreements, contracts, or licensing, without the express written consent of
Crossbeam Systems.
For permission to reproduce or distribute please contact your Crossbeam Systems account executive.
This product includes software developed by the Apache Software Foundation
([Link]/).
CROSSBEAM, CROSSBEAM SYSTEMS, C10, C30, SecureShore and any logos associated therewith are
trademarks or registered trademarks of Crossbeam Systems, Inc. in the U.S. Patent and Trademark Office, and
several international jurisdictions.
All other product names mentioned in this manual may be trademarks or registered trademarks of their respective
companies.
Contents
About This Guide
Related Documentation .................................................................................................................................... vii
Conventions ...................................................................................................................................................... vii
Customer Support ........................................................................................................................................... viii
Customer Comments ....................................................................................................................................... viii

Chapter 1: Introduction
Features ............................................................................................................................................................ 7
Dual Kernels ...................................................................................................................................................... 8
Performance Options ......................................................................................................................................... 8
VPN and Firewall Acceleration .................................................................................................................... 8
StreamProtect Software .............................................................................................................................. 9
Dual Box High Availability Configuration ........................................................................................................... 9
Management Options ...................................................................................................................................... 10
Configuration Interface .............................................................................................................................. 10
Element Management System .................................................................................................................. 10
SecureShore Manager Network Management System ............................................................................. 11
RAID Controller ............................................................................................................................................... 11
System Passwords .......................................................................................................................................... 12

Chapter 2: Configuring System Parameters


Initial Configuration .......................................................................................................................................... 13
Changing the Root Password .......................................................................................................................... 14
Displaying System Configuration ..................................................................................................................... 14
Configuring Basic System Parameters ............................................................................................................ 14
Configuring Network Time Protocol (NTP) ...................................................................................................... 14
Configuring Domain Name Resolution ............................................................................................................ 15
Configuring Simple Network Management Protocol (SNMP) .......................................................................... 15
Configuring Alarm Monitors ............................................................................................................................. 16
Configuring Optional Features with License Manager ..................................................................................... 16
Activating a Feature .................................................................................................................................. 16
Inactivating a License ................................................................................................................................ 17
Backing Up and Restoring License Files .................................................................................................. 17
Displaying License Information ................................................................................................................. 18
Changing the Web Server SSL Certificate ...................................................................................................... 19
Changing Default SSH Keys ........................................................................................................................... 19
Enabling SecureShore Support ....................................................................................................................... 20
Saving Your System Configuration .................................................................................................................. 20
Restoring System to Factory Default Settings ................................................................................................. 20
Backing Up Your System ................................................................................................................................. 21

Chapter 3: Managing Users


Managing User Accounts ................................................................................................................................ 23
Managing Access Groups ............................................................................................................................... 23
Configuring Authentication .............................................................................................................................. 24
Configuring RADIUS and LDAP Servers ......................................................................................................... 25

iii
LDAP Server Configuration ....................................................................................................................... 25
RADIUS Server Configuration ................................................................................................................... 28

Chapter 4: Configuring Network Parameters


Displaying Network Configuration ................................................................................................................... 31
Configuring Physical Interfaces ....................................................................................................................... 31
Configuring Tap Interfaces .............................................................................................................................. 32
Tap Mode .................................................................................................................................................. 32
Tap Interface ............................................................................................................................................. 33
Configuring Network Interfaces ....................................................................................................................... 33
Configuring IP Aliases ..................................................................................................................................... 34
Configuring Static Routes ................................................................................................................................ 34
Configuring Static ARP Entries ........................................................................................................................ 34
Configuring High Availability with VRRP ......................................................................................................... 35
Configuring Network Interface Module (C30 Model Only) ............................................................................... 36
Configuring Layer 2 Switching (C30 Model Only) ............................................................................................ 36
Configuring Link Aggregation (C30 Model Only) ............................................................................................. 36
Configuring Rate Limiter (C30 Model Only) ..................................................................................................... 38
Installing Dynamic Routing Protocols .............................................................................................................. 39
Installing Applications ...................................................................................................................................... 40

Chapter 5: Upgrading COS


Upgrading the COS System Software ............................................................................................................. 41
Software Patch .......................................................................................................................................... 41
Safe Upgrade ............................................................................................................................................ 42
Upgrading C-Series Systems in a VRRP Configuration .................................................................................. 43
Using Multiple Versions of COS ...................................................................................................................... 43
Installing CS Linux v3 or v1 ............................................................................................................................. 44

Chapter 6: Useful Tools


Displaying Information for Technical Support .................................................................................................. 45
Toggling Boot Between Partitions ................................................................................................................... 45
Linux Tools ...................................................................................................................................................... 45
Swatch Dynamic Display Tool ......................................................................................................................... 45
Understanding the Swatch Tool ................................................................................................................ 46
Starting and Stopping the Swatch Tool ..................................................................................................... 46
Using Single Key Commands ................................................................................................................... 46
Creating Swatch Tool Configuration Files ................................................................................................. 47
Creating Useful Swatch Tool Configuration Files ...................................................................................... 47
Using the swacquire Command .......................................................................................................... 48
Using the swread Command .............................................................................................................. 48
Using the swcalc Command ............................................................................................................... 49
Using the swaggr Command .............................................................................................................. 49
Using the swscreen Command ........................................................................................................... 50
Using the swdisplay Command .......................................................................................................... 50
Using Swatch Tool Variables in All Commands ................................................................................. 51
Using Existing Swatch Tool Configuration Files ........................................................................................ 51
Swatch Performance Considerations ........................................................................................................ 51
Swatch Tool Child Processes ............................................................................................................. 51
Single Shared-Memory Region and Semaphore ................................................................................ 52
Troubleshooting the Swatch Tool .............................................................................................................. 52
Data Not Being Displayed or Updated ................................................................................................ 52
Data is Not Displayed in the Correct Location .................................................................................... 52
iv
About This Guide

This guide describes how to install and configure COS software on a C-Series system.
This guide is intended for system integrators and other qualified service personnel responsible for installing,
configuring, and managing the COS software on a C-Series system.

Related Documentation
The following documents provide an in depth description for installing and configuring the C-Series system
hardware and software.
• C2 Installation
• C6 Installation
• C10 Security Services Switch Hardware Installation Guide
• C30 Security Services Switch Hardware Installation Guide
• C30i Security Services Switch Hardware Installation Guide
• COS Applications Installation Guide
• Install Server Installation and Configuration Guide
• COS Release Notes

Conventions
The following conventions are used throughout this guide to emphasize certain information, such as, user input,
screen options and output, and menu selections.
italics − Indicates book and section titles.
Courier - Indicates user input and program output.
Courier italics - Indicates variables in commands.
Menu => − Indicates to select an Option from the menu pull-down.
Warnings, Cautions, and Notes indicate the following:

Warning: Warnings notify you to proceed carefully in order to avoid


personal harm.

Caution: Cautions notify you to proceed carefully in order to avoid


damaging equipment or losing data.

NOTE − Provides helpful suggestions or reference to materials not contained in this manual.

COS Configuration Guide v


Customer Support
When Technical Assistance is needed, Crossbeam Systems offers a variety of service plans to meet your specific
support requirements. For additional information, please contact your account representative or refer to
[Link].
Crossbeam Systems also offers customer training for our products. Refer to the web site for the course offering
and schedules.

Customer Comments
Customer comments are not only welcomed, they are encouraged. Please take a moment and let us know how we
are doing. To do this, respond in one of the following ways:
• E-mail your comments to documentation@[Link].
• FAX your comments to 978-287-4210, attention Technical Publications.

vi
1
Introduction

The C-Series system is a high performance system that integrates best-in-class firewall, virtual private networks,
intrusion detection, and content security engines. The system offers, high availability, and simplicity of
management in a compact, expandable form factor. The system’s unique flow management and acceleration
technology enables simultaneous processing of traffic by multiple services. The system is used by medium to
large enterprises to consolidate the functions of multiple appliances at a fraction of the cost.

Features
Standard network interfaces on the C-Series system include Gigabit Ethernet and 10/100 Ethernet ports.
Management and I/O interfaces include RS232 ports, 10/100/1000 Ethernet ports, and USB ports. Table 1 lists
the major system features. Not all features are supported by all hardware models.
Table 1 List of Features
Feature Description
Platform • Dual kernel support
• Various hardware models for different business needs
• EXT3 journaling file system
• RAID support for 2 disk drives (not user configurable)
Applications Security applications supported by COS are provided in an ADF kit. Refer to the ADF
Release Notes or the COS Applications Installation Guide for a complete list of
applications, and installation and configuration information.
Performance • Dual-Box High Availability (HA) using VRRP
• VPN and Firewall Acceleration
• QoS Rate-Limiter
• MD5 Checksum verification of packages
• StreamProtect software (optional)
Networking • OSPFv2 (optional)
• RIPv2 (optional)
• PIM-SM (optional)
• IGMP
• Layer 2 switching
• Link Aggregation Control Protocol (LACP) (IEEE 802.3ad)
• VLAN support
• IP static routes
Users • Authentication methods: RADIUS, SMB, LDAP
• Customizable user access groups
• Audit logs by username
Management • SNMP traps
• Various facility alarms
• Logging of all significant events that occur in the system

COS Configuration Guide 7


Dual Kernels
COS provides two different kernels, CS Linux v1 and CS Linux v3. You determine which kernel to install by
first deciding which applications you wish to install on the C-Series system. The ADF Release Notes provide a
matrix of which applications are supported with CS Linux v1 and v3.
A system cannot be upgraded from a CS Linux v1 to a CS Linux v3 operating system; instead, you must perform
an installation using the Install Server.

Performance Options
Performance can be enhanced by VPN and Firewall acceleration, with StreamProtect software, and by
configuring master and standby COS systems using the Virtual Router Redundancy Protocol (VRRP).

VPN and Firewall Acceleration


Virtual Private Network (VPN) traffic can be accelerated by off-loading the encryption process.
Firewall acceleration occurs when acceleration software accesses the Firewall application connections table and
helps to process traffic that the Firewall application has passed. It also provides information from the connections
table to other applications. Note that Firewall acceleration can be disabled from the Check Point configuration
program by disabling SecureXL.
If you intend to use a Check Point VPN-1/Firewall-1 application, you can select from the following acceleration
options. Except for the ACE module, these are software options.
• Check Point Performance Pack
This is an option provided with the Firewall-1 application, and requires a license from Check Point. It
performs both Firewall and VPN acceleration.
• Accelerated Cryptography Engine (ACE) module (hardware)
When installed in the chassis, it accelerates VPN traffic by performing encryption. It requires the VPN
Accelerator software option included with the FireWall-1 applications that support VPN acceleration. It is
not utilized when used with Check Point Performance Pack.
• Network Interface Module (NIM) Acceleration (C30 model only)
Performs Firewall acceleration. This is automatically installed and enabled.
• Firewall Acceleration Module (FAM) (not available with the C30 model)
Performs Firewall acceleration. On the C30i platform, it can be used with the optional StreamProtect
software.
Table 2 lists the performance options available on each model.

8 Introduction
Table 2 Performance Options Allowed Per Model

Model Firewall Acceleration VPN Acceleration Firewall and VPN Acceleration


C2 / C6 Choose ONE option: • Performance Pack • Performance Pack
• Performance Pack
• FAM
C10 Choose ONE option: Choose ONE option: Choose ONE option:
• Performance Pack • Performance Pack • Performance Pack
• FAM • ACE module • FAM and ACE module
C30 NIM Acceleration ACE module NIM Acceleration and ACE module
C30i Choose ONE option: Choose ONE option: Choose ONE option:
• Performance Pack • Performance Pack • Performance Pack
• FAM • ACE module • FAM and ACE module
• StreamProtect • FAM, ACE module, and
• FAM and StreamProtect StreamProtect

StreamProtect Software
The StreamProtect software resides below the general purpose operating system and interacts with the network
interface drivers and the security applications. It continually monitors the packet flow and the application packet
consumption and dynamically adjusts how many new packets are sent to the application at any given time,
essentially acting as a traffic cop between the network and the application. This mediation allows the application
to run at peak efficiency and prevents packets from being sent all the way up to the application layer only to be
dropped. This also prevents any one application from completely utilizing all of the CPU resources.
The StreamProtect software is not user configurable, other than enabling or disabling it. If using StreamProtect
software, you must first disable any Check Point Firewall-1 Performance Pack.
The StreamProtect software is an optional feature that requires a license. To obtain the license, you must contact
Customer Support or your sales representative. Refer to Configuring Optional Features with License Manager
on page 16 to install the StreamProtect software.
NOTE: To disable StreamProtect software, delete or unconfigure the license then reboot the system.
The StreamProtect software is only available for the C30i model.

Dual Box High Availability Configuration


Two C-Series systems can be configured for redundancy at the network interface level. Using a priority scheme,
one C-Series system is designated as the Master system, and the other is the Backup system. Traffic flows
through the interface on the Master system unless the interface fails or becomes unavailable, then the interface on
the Backup system acts as the Master. The Master system advertises the interface via ARP.
Virtual Router Redundancy Protocol (VRRP) manages the automatic switch-over of one C-Series system to the
other. Each network interface is assigned the same virtual IP address. Note that VRRP works only on LAN
(Ethernet) interfaces, not on WAN interfaces.
The network interface can be an interface for one physical port, or an aggregate of physical ports using Link
Aggregation Control Protocol (LACP) (IEEE 802.3ad), which is considered to be a virtual network interface. If
using a virtual network interface, all physical connections must fail or be unavailable for the virtual network to
be considered down and subsequently for the switch-over to occur.

COS Configuration Guide 9


Additionally, network interfaces can be grouped so that if any one of the network interfaces goes down, the
switch-over occurs. A similar group must be on both C-Series systems. An example of this configuration would
be to group incoming and outgoing traffic on different interfaces so that a failure of either interface would cause
a switch-over to the redundant system.
NOTE: The tap mode load balancing feature (C30 model only) can be used to augment the dual box
configuration, as described in Configuring Tap Interfaces on page 32.

Management Options
The C-Series system provides the following system management options:
• Menu-driven configuration interface
• Element Management System (EMS)
• SecureShore Network Management System (NMS)

Configuration Interface
COS uses a menu driven configuration interface to configure the C-Series system. The configuration interface is
launched from the UNIX admin prompt as follows:
1. Log into your system as an administrator. The default administrator username is admin, and the default
password is admin.
2. Execute the following command at the admin prompt to display the Main Menu.
[admin@xxxxx bin]# cos_config
The configuration interface is accessible from the serial port or the Ethernet management port using Telnet or
SSH. If configuring the C-Series system for the first time, use the Interview option from the Configuration Menu
to quickly configure the system for basic operations.
NOTE: You can type the initial letter of an option and press the Tab key to complete the entire string on
supported choices. Also, default values are provided when adding a component, and existing values are shown
when modifying a component.

Element Management System


The Element Management System (EMS) is a Java based application that offers a browser-based interface for
configuring and monitoring the C-Series system. All communications are XML-based, and secured through
Secure Socket Layer (SSL). SSL provides authentication, integrity and security between a browser and the COS
web server.
To log onto EMS, enter the C-Series system IP address into your browser's address field; for example,
[Link] The user ID and password are case sensitive. The default user ID and password are both
admin.
EMS requires a browser running the Java Runtime Environment (JRE) JAVA plug-in on the client system. It is
recommended that you have V1.4.2_x or higher. If using Internet Explorer as your browser and you have a JRE
version previous to V1.4, you will be automatically taken to Sun's web site to download JRE the first time you
start EMS. Otherwise, you can download it manually from [Link]

10 Introduction
If the browser is running JRE V1.4.1_x, you may encounter an access denied ([Link] ...) error. This problem is
corrected in JRE V1.4.2_x. To determine which version of the JAVA Plug-in you are using:
• Within EMS - With EMS running, open up your Java console window and look at the first two lines to
determine which version of the JAVA plug-in you are running.
• Within your Windows directory - Check the JAVA plug-in version number in one of these locations:
– C:\Windows\Downloaded Program Files\Java Runtime Environment
– C:\WINNT\Downloaded Program Files\
• Within Netscape Navigator - Go to Help =>About Plugins. Check the MIME types listed under Java Plug-
in. The version of JAVA plug-in is listed as at least one of the following:
application/x-java-applet;version=1.4
application/x-java-applet;version=1.3
application/x-java-applet;version=1.2
application/x-java-applet;version=1.1.2
application/x-java-applet;version=1.1.1
application/x-java-applet;version=1.1

NOTE: EMS cannot be used to install applications or optional components such as routing protocols or
StreamProtect software. This can only be done using the Configuration interface.

SecureShore Manager Network Management System


The SecureShore Manager Network Management System (NMS) is purchased separately and installed on a
separate system. It allows a user to manage multiple X-Series and C-Series systems. Should you have
SecureShore NMS, you need to enable support for NMS on the C-Series systemSecurity Switch and enable
HTTP external access ability, using the cos_config menu.

RAID Controller
The RAID (Redundant Array of Inexpensive Devices) Controller supports disk mirroring for the hardware
models that contain two disk drives. This feature is automatically configured for new systems and for systems
that are installing (not upgrading) COS Version 3.5 or later. Note that the RAID Controller is not available when
adding a second drive to a system after installing COS V3.5.
Should one disk drive fail, the system sends messages to the console port and to /var/log/messages.

COS Configuration Guide 11


System Passwords
To gain access to the COS configuration tools, use the following passwords:
• Configuration Interface - The default login name and password are admin and admin. To change the
password, select User Accounts from the User Authentication menu.
• EMS - To log in, use the following URL string: [Link] or ip_address/. The default login name and
password are admin and admin. To change the password, select User Admin from the EMS
Administration menu.
• Root user - By default, the root account does not have a password. During the initial boot process, there is a
15-second window where you are prompted to change the root password. If you miss this, refer to Changing
the Root Password on page 14.
• Optional routing software - Enter admin when prompted to log into the routing software command line
interface. This password can be changed in the routing software command line interface, as described in the
Routing Protocols Command Reference.
IMPORTANT: For security, you should change the default passwords.

12 Introduction
2
Configuring System Parameters

For the initial configuration of the C-Series system, use the Interview script as described in Initial Configuration.
Otherwise, use EMS or the Configuration Menu as described in the other sections in this chapter.
Before beginning, you must be connected to the management console of your system. Alternatively, you can
connect to the system through SSH if you have the DHCP service in your network. By default, DHCP and SSH
is enabled on your system. After your initial configuration, you can disable the DHCP service by assigning an IP
address to the management interface.
If you connect to the Management Console using a terminal or PC, configure the device’s serial port for 9600
baud, 8 data bits, 1 stop bit, no parity, and no flow control.
NOTE: During the initial boot process, there is a 15-second window where you are prompted to change the root
password. If you miss this, refer to Changing the Root Password on page 14.

Initial Configuration
The Interview script helps you to quickly configure your system for basic operations. Within this interview, you
can type the initial letter of an option and then press the Tab key to complete the entire string on supported
choices. To access the interview script, complete the following.
1. Log into your system as an administrator. The default administrator username is admin, and the default
password is admin.
2. Execute the following command at the admin prompt:
[admin@xxxxx bin]# cos_config

3. Select Interview from the Main Menu.

The interview script prompts you to configure the following:


• Host Name (name for the COS system)
• DNS Domain Name
• System Time and Time Zone
• Management Services (enable or disable Telnet, FTP, and Web management)
• IP address of any DNS Server
• SNMP parameters
• Administrator password, which is the password used to log into the system. For security, you should change
the password from its default setting.
• Individual user accounts
• Host interfaces (assigns IP addresses to physical ports)
• IP address of the default gateway
• IP address of any NTP server
Once you complete the interview script, the Configuration Menu displays. To continue configuring your system,
select Configuration from the Menu and refer to the other sections in this chapter.

COS Configuration Guide 13


Changing the Root Password
For security, you should change the default root password as follows:
1. If necessary, log into your system as an administrator. The default administrator username is admin, and the
default password is admin.
2. Execute the following command at the admin prompt:
[admin@xxxxx bin]# su - root

3. Change the root password, where password is the new password.


[root@xxxx admin]# passwd <password>

Displaying System Configuration


The Configuration Menu supports adding, modifying, deleting, and displaying any of the system configuration
parameters. To display system information from the Configuration interface, select System Information from
the Configuration Menu. You can then select various items to view from the System Information menu. To
display system information from EMS, open Configuration => System Information in the navigation bar.

Configuring Basic System Parameters


This basic system settings are:
• System host name.
• IP domain name used for IP routing applications.
• Default gateway IP address.
• Enable external access ability (Telnet, FTP, and HTTP). This includes the web session timeout interval, in
minutes, the COS system waits before automatically logging out.
• Firewall Accelerator Module (FAM) option, which is described in VPN and Firewall Acceleration on page
8. FAM can only be enabled or disabled.
• Time zone, date, and time information.
To configure system parameters from the Configuration interface, select Configuration from the Main Menu
then select System Parameters. The current system configuration displays.
From EMS, open Configuration => System from the Navigation Tree. Device Configuration and TimeZone
contains these parameters. However, date and time cannot be set using EMS.

Configuring Network Time Protocol (NTP)


The Network Time Protocol (NTP) is used to synchronize the time of a computer client or server to another
server or reference time source, such as a radio or satellite receiver or modem. It provides accuracies typically
within a millisecond on LANs and up to a few tens of milliseconds on WANs relative to Coordinated Universal
Time (UTC) through a Global Positioning Service (GPS) receiver, for example. Typical NTP configurations
utilize multiple redundant servers and diverse network paths in order to achieve high accuracy and reliability.
To configure NTP, select Network Time Protocol from the Configuration Menu. The current NTP server is
displayed. From EMS, open Configuration => System => NTP Server from the Navigation Tree.

14 Configuring System Parameters


Configuring Domain Name Resolution
Domain name resolution allows you translate and search domain names. The Domain Name System (DNS) is a
global network of servers that translate host names like [Link] into IP addresses.
The Domain Name Service (DNS) option from the Configuration Menu allows you to add or delete DNS servers
and DNS search domains. When you select one of these options from the DNS Menu, the system displays any
previously configured servers or search domains by IP address. From EMS, open Configuration => System =>
DNS Server from the Navigation Tree.

Configuring Simple Network Management Protocol (SNMP)


To access the SNMP settings, select SNMP from the Configuration Menu or open
Configuration => Protocols => SNMP in the EMS Navigation Tree. Configure the following:
• SNMP Server, which allows you to enable or disable SNMP, and configure the following:
– Contact information
– Location
– Engine ID, uniquely identifies an SNMP Agent. The agent needs is configured with an engine ID to
allow it to respond to SNMPv3 messages. The value of the engine ID for this agent must be configured
to the same value on any SNMP management station that communicates with the COS agent using the
SNMPv3 protocol.
• Communities, which allows you to add or remove communities, and configure the following:
– Name of the community
– Source IP address and mask
– Access Mode (read-only or read-write)
• SNMPv3 Users, which allows you to add or remove users, and configure the following:
– User name (must be unique)
– Authentication type, which specifies the authentication method for the user. Choices include: None (No
authentication), MD5 checksum, SHA authentication.
– Privacy Type - specifies whether authentication is used.
– Access Mode specifies the access privilege a user has. Valid values include: read-only - user has only
read access to the MIB; read-write - user has both read and write access to the MIB.
– OID specifies the MIB subtree that the user can access. For example: “iso” for the whole tree, or
“mib-2” to limit access to just the MIB objects that are part of the mib-2 tree. Smaller portions of the
MIB can be selected, such as entering “interfaces” to restrict access to just the interface table.
• Trap Destinations, which allows you to add, modify, or remove traps, and configure the following:
– Trap destination IP address
– Port number
– Trap type, which can be trap or inform.
– SNMP Version, which can be SNMP v1, SNMPv2c, or SNMPv3
– Community Name

NOTE: Any change to the SNMP configuration, such as community names, SNMP v3 users, and trap dests, will
cause the SNMP agent to restart and, subsequently, send a coldStart trap.

COS Configuration Guide 15


Configuring Alarm Monitors
Alarm Monitors can be created to send SNMP traps if the value of a MIB variable crosses a specified threshold.
When the alarm condition occurs, the value of the monitored MIB object along with any additional specified
objects are sent as a trap to all of the configured SNMP trap destinations.
To configure Alarm Monitors, select Alarm Monitors from the Configuration Menu or open Configuration =>
Protocols => SNMP => Alarm Monitors in the EMS Navigation Tree. The alarm monitor parameters are:
• Name - User specified name for the monitor.
• Frequency - Polling interval in seconds.
• OID - The MIB Object of integral type to monitor. The object should be specified using the last part of its
name less the instance ID, for example, ifInOctets.
• OP - Relation operator for comparison. Can be 'gt', 'ge', 'eq', 'ne', 'lt' or 'le'.
• Value - Specifies the threshold alarm value to be monitored.
• Additional OIDs - These are additional MIB Object values to be sent along with the trap. They can be any
MIB object that is either a member of the same conceptual table row as the monitored OID, or part of a table
that shares a common index scheme using the AUGMENTS clause.

Configuring Optional Features with License Manager


Only available with the C30i model, the License Manager is a program that allows you to enable, configure or
disable optional features available for the COS system. Each optional feature requires a license. To obtain the
license, you must contact Customer Support or your sales representative.
The License Manager only installs and configures licenses. It is up to the application being licensed when to
check for a valid license. For example, an application may check for a license periodically while running or only
at boot time.

Activating a Feature
Once you have a license, you can activate a feature using the License Manager as follows:
1. Make sure you log into the system as a root user. If not a root user, return to the Unix prompt and use the su
- root command.
2. Select the License Manager option from the Main Menu.
3. From the License Manager menu, select the option to install a license then enter the license string.
4. Back at the License Manager menu, select the option to configure the license. You are then prompted for
additional license information, such as the feature name and version.
Once completed, the license for the feature is activated.

16 Configuring System Parameters


Inactivating a License
There are two ways to inactivate a license: deleting or unconfiguring it. When you delete the license, the license
is removed from the system permanently. When you unconfigure a license, the license remains on the system and
can be reactivated later.
1. Select the License Manager option from the Main Menu.
2. From the License manager menu, select the option to unconfigure or delete a license.
3. When prompted, enter the feature name and version. The license is then removed from the license file.
4. To verify this, choose the option to display configured licenses from the License Manager menu. The license
feature name and version should not appear in the license list. If you deleted a license, display available
licenses and make sure that the license does not appear in that list.

Backing Up and Restoring License Files


The License Manager files should be backed up to a remote system whenever they are changed. Otherwise, a
disk crash could cause the license manager files to be lost. In this case, you must contact Customer Support to
obtain replacement licenses.
The License Manager stores three files in the archive: master license file, configured license file, and License
Manager configuration file. These files contain all the information License Manager needs to reconstitute its
state should a restore be needed.
To backup the License Manager files:
1. Select the License Manager option from the Main Menu.
2. From the License Manager menu, select the backup option.
3. When prompted, enter the directory location where the resulting archive file should be placed.
It is recommended that you transfer this file from the COS system to a backup system using FTP or similar
mechanism.
To restore License Manager files:
1. Transfer the archive file from its location to a known directory on the COS system.
2. From the License Manager menu, select the backup option.
3. When prompted, enter the directory location where the archive file is located.
The restore process performs automatically. There is no need to stop and restart the program after a restore.

COS Configuration Guide 17


Displaying License Information
The License Manager allows you to display information about the following:
• License Manager State, which displays program-specific information:
– Operating mode, which is always eModeNodeMaster when running on a COS system.
– Operating State, which should always be eStateActive.
– Locations of the Master License File, Configured License File, and Configuration File.
– Local Node identifier, which must match the node identifier on licenses installed on this system.
– Last error message from the last License Manager operation that failed.
• Master Licenses, which are product licenses obtained from Customer Support. This set consists of both
FEATURE and INCREMENT licenses. Each license in this set must have a unique product code.
• Available Licenses, which are derived from the master license set. FEATURE and INCREMENT licenses
for the same feature and version are combined to form a single active license. These licenses have been
installed but may not be activated.
• Configured Licenses, which are licenses that are activated.
The following table lists the parameters that may appear when you display master, available, or configured
licenses.

Parameter Definition
Type For a master license, this is eTypeFeature for a feature license, or eTypeIncrement
for an incremental license. For an active license, this is always eTypeFeature.
Feature Name Name of the feature being licensed.
Feature Version Version of the feature to which this license applies.
Product Code Generated product code for this license.
Expiration Date Date this license expires.
Number of Seats Always 1 for C-Series systems.
Node ID To configure a license, this ID must match the C-Series system local node ID as read
from the EEPROM.
Config State eConfigStateValid indicates that the license has the minimum set of configuration
parameters. eConfigStateInvalid indicates an invalid configuration.
Key State eKeyStateValid indicates that the calculated license key matches the key installed
with the license. eKeyStateInvalid indicates that the keys do not match.
Key License key string as typed in by the user.
Num Modules Always 1 for C-Series systems.
Configured
Configured Modules Always 1 for C-Series systems.
Module Name of the C-Series system.

18 Configuring System Parameters


Changing the Web Server SSL Certificate
The COS web server is based on the open-source apache web server. The web server provides a Secure Socket Layer (SSL)
certificate that users must accept to access the COS web server. This certificate can be replaced with your own certificate as
follows. Before starting you need a PC with OpenSSL installed.

1. On the PC, create the private key for the server which includes providing a pass-phrase. You will be
prompted for the pass-phrase later in the procedure.
% openssl genrsa -des3 -out [Link] 1024

2. Create a self-signed certificate. The following command creates a certificate valid for 730 days.
% openssl req -new -x509 -days 730 -key [Link] -out [Link]

3. Remove the pass_phrase from the server key. Otherwise, the httpd server, which is started from the /etc/
init.d scripts, will be unable to start since it will require a user to enter pass-phrase.
% cp [Link] [Link]
% openssl rsa -in [Link] -out [Link]

4. Copy the [Link] and [Link] files to a safe location on the C-series system. The recommended
directory is /usr/os/etc/ssl.
5. Configure this key and certificate in the Apache SSL config file, /etc/httpd/conf.d/[Link].
SSLCertificateFile /usr/os/etc/ssl/[Link]
SSLCertificateKeyFile /usr/os/etc/ssl/[Link]

Changing Default SSH Keys


The C-Series system provides default SSH keys. These should be changed as follows.
1. Log into the system as root.
su - root

2. Generate a new RSA1 key:


/usr/bin/ssh-keygen -q -t rsa1 -f /etc/ssh/ssh_host_key -C '' -N ''

The files /etc/ssh/ssh_host_key and /etc/ssh/ssh_host_key.pub are generated. These are the default filenames
and location for SSH. You may be prompted to overwrite the existing files.
3. Generate a new RSA key:
/usr/bin/ssh-keygen -q -t rsa -f /etc/ssh/ssh_host_rsa_key -C '' -N ''

The files /etc/ssh/ssh_host_rsa_key and /etc/ssh/ssh_host_rsa_key.pub are generated. These are the default
filenames and location for SSH. You may be prompted to overwrite the existing files.
4. Generate a new DSA key:
/usr/bin/ssh-keygen -q -t dsa -f /etc/ssh/ssh_host_dsa_key -C '' -N ''

The files /etc/ssh/ssh_host_dsa_key and /etc/ssh/ssh_host_dsa_key.pub are generated. These are the default
filenames and location for SSH. You may be prompted to overwrite the existing files.

COS Configuration Guide 19


Enabling SecureShore Support
The SecureShore Network Management System (NMS) application is a separately available product that
manages multiple C-series or X-series systems. You can allow or disallow the SecureShore NMS to access this
system by selecting Management Server from the Configuration Menu.

Saving Your System Configuration


The system configuration file contains a number of system parameters that is loaded when the system boots. You
can display the system configuration file from the EMS system by going to System Config in the menu bar. To
display the current system configuration at the admin prompt, use the following command:
[admin@xxxxx bin]# cos_show_system

To save your configuration at the admin prompt, use the following command:
[admin@xxxxx bin]# ./cos_show_system -f /directory/filename

Where the directory specifies the directory where the file is located, and filename is the configuration file.
You can also copy the configuration to a file using EMS, from the System Config item in the menu bar. The
copy is created in the admin directory of the COS system.
To restore a previous configuration, enter the following command at the admin prompt:
[admin@xxxxx bin]# ./cos_set_system -f /directory/filename

NOTE: You can use the backup tool to save additional information, as described in Backing Up Your System on
page 21.
This procedure only saves and restores the COS configuration file. It does not save or restore applications. Refer
to the COS Applications Installation Guide provided with the ADF software for application specific information.

Restoring System to Factory Default Settings


To delete the current configuration and return the system to its factory defaults, use the following command at
the admin prompt.
[admin@xxxxx bin]$ ./cos_reset_system

NOTE: The IP address of interface Management 1, Telnet, and the default gateway are left intact. This done in
the event you used Telnet to access the system.

20 Configuring System Parameters


Backing Up Your System
Use the Configuration Backup tool to backup everything under a specified directory tree. The tarred and zipped
output is then placed in /root. The tool prompts you for two inputs; the directory to back up and the archive name.
These options can be specified at the command line or interactively at run time.
To use the Backup Tool, complete the following:
1. Login as root.
su - root

2. Enter the following command at the root prompt.


/usr/os/bin/archive_dir [-dhV] [archive_name]

Command line options:


-d directory-name (Default = /usr/os)
-h Help
-V version
If you choose not to provide any options at the command line, the Backup Tool runs in interactive mode.
NOTE: This procedure only saves and restores the COS configuration file. It does not save or restore
applications. Refer to the COS Applications Installation guide provided with the ADF software for application
specific information.

COS Configuration Guide 21


22 Configuring System Parameters
3
Managing Users

Each system user is defined by a username, password, and access level. In addition, you can configure the
C-Series system to use RADIUS, SMB, or LDAP authentication. To configure individual user accounts, select
User Authentication and Access Control from the Configuration Menu.

Managing User Accounts


Each user account has a unique username and password, and belongs to one or more access groups that define the
complete set of privileges for the account. If assigned multiple access groups, the resulting set of privileges is
cumulative from all of the groups. The Linux user root is always treated as belonging to the Administrator group.
To manage user accounts, select User Accounts from the User Authentication menu or User Admin from the
EMS Administration menu. The existing user accounts display. Configure the following parameters:
• User Name
• Password
• Login Access, enabled allows the user to log into the Unix shell and disabled allows the user to only have
WEB access using EMS.
• Access Groups, which allows you to create groups with their own set of permissions.

Managing Access Groups


The system supports up to 16 access groups. Two of these groups, Guest and Administrator, are predefined and
cannot be deleted. The Administrator group has read and write access to all configuration and system
information. The Guest group has read-only access to all configuration and system information.
The other 14 groups can be created and assigned read-write or read-only privileges to specific configuration and
system information. After creating an access group, you must define the access permissions for the group,
including read-only.
To manage access groups, select Access Groups from the User Authentication menu or open
Configuration => Access Control => Access Groups in the EMS Navigation Tree. The system displays the
existing access groups.
To define access permissions for a group from the Configuration Interface, modify the permission list for each
object as follows:
1. Select Access Permissions from the User Authentication menu.
2. Choose Add to add an access group to the object’s permission list, or choose Modify to change the
permissions for an access group that is already in the object’s permissions list. When prompted for the
object’s name, you can press the Tab key to see a list of objects.
3. Enter the object name.
4. When prompted, enter the access group for read-only or read-write permissions. Afterwards, the system
displays the object’s updated permissions list.

COS Configuration Guide 23


Configuring Authentication
In addition to the local authentication of user accounts, you can verify user credentials with a RADIUS server,
Windows Active Directory server (SMB), Lightweight Directory Access Protocol (LDAP) server, or any
combination. The remote authentication methods defined are checked in the order listed followed by the local
password file. To enable remote authentication, both the protocol type and control must configured.
1. Select Authentication Methods from the User Authentication menu or open Configuration => Access
Control => Authentication Methods in the EMS Navigation Tree.
2. Select the authentication method: RADIUS, SMB, or LDAP.
3. Enter the desired level of authentication control.
The authentication control level determines how the remotely authenticated password it treated relative to
the locally administered password. Most configuration will use requisite if remote authentication is required
along with local authentication, or sufficient if remote authentication is all that is needed to access the
system. Valid values are:
– Requisite - The user's password is checked against the remote server and if the password is incorrect
the user is immediately denied access.
– Required - Checks the user's password using the remote server and if it is incorrect the user is denied
access, but only after all other authentication methods are checked.
– Sufficient - Checks the user's password using the remote service and if the password is correct the user
is allow access to the system with no further checks.
– Optional - The password is checked against the remote server but the result of this check is not used to
determine if the user can access the system unless no other authentication methods can make the
determination.
4. After selecting the authentication methods, you must provide information about the remote servers. For
RADIUS authentication, select RADIUS Servers and configure the following parameters:
– Server IP address
– Server port number
– Server Secret
– Timeout
5. For SMB authentication, select SMB Authentication and configure the following parameters:
– Workgroup - The workgroup system should use for authentication.
– Primary Server - The DNS name of the primary active directory server.
– Secondary Server - The DNS name of a backup active directory server.
6. For LDAP authentication, select LDAP Authentication. You can configure LDAP parameters or LDAP
servers.
a. Select LDAP Parameters and specify the following:
- LDAP version used
- LDAP Distinguished Name (DN) for the user accounts
b. Select LDAP Server and specify the following:
- Server IP address
- Server port number

24 Managing Users
Configuring RADIUS and LDAP Servers
The C-Series system can be configured as a RADIUS or LDAP server from the Linux prompt.

LDAP Server Configuration


To configure the system as an LDAP server, perform the following:
1. Log into COS as a root user.
# su - root

2. At the Linux prompt, setup an LDAP encrypted root password:


# slappasswd
New password:
Re-enter new password:

The encrypted password displays.


3. Edit the /etc/openldap/[Link] file. The lines that must be edited are suffix, rootdn, and one rootpw line.
Use the encrypted password in this file. The following is an example of changes to this file:
...
database ldbm
suffix "dc=mycompany,dc=com"
rootdn "cn=Manager,dc=mycompany,dc=com"
# Cleartext passwords, especially for the rootdn, should
# be avoided. See slappasswd(8) and [Link](5) for details.
# Use of strong authentication encouraged.
#rootpw secret
rootpw {SSHA}NAgK8hiFN8q8OAxtLyobYj1QF39rRyeX
...

4. Start the LDAP server:


# /etc/rc.d/init.d/ldap start
Starting slapd: [ OK ]

# /etc/rc.d/init.d/ldap status
slapd (pid 24768 24767 24766) is running...

5. Edit the migration file. This includes using provided tools to convert the configuration files to LDIF format.
The tools are located in the /usr/shar/openldap/migration dir. Edit the migration tool file and change the
following variables:
#vi /usr/share/openldap/migration/ migrate_common.ph
...
# Default DNS domain
$DEFAULT_MAIL_DOMAIN = "[Link]";

# Default base
$DEFAULT_BASE = "dc=mycompany,dc=com";
....

COS Configuration Guide 25


6. Create a base data file by adding the base entries into LDAP:
# /usr/share/openldap/migration/migrate_base.pl > [Link]
# ldapadd -a -W -x -D "cn=Manager,dc=mycompany,dc=com" -f [Link]
Enter LDAP Password:
adding new entry "dc=mycompany,dc=com"
adding new entry "ou=Hosts,dc=mycompany,dc=com"
adding new entry "ou=Rpc,dc=mycompany,dc=com"
adding new entry "ou=Services,dc=mycompany,dc=com"
adding new entry "nisMapName=[Link],dc=mycompany,dc=com"
adding new entry "ou=Mounts,dc=mycompany,dc=com"
adding new entry "ou=Networks,dc=mycompany,dc=com"
adding new entry "ou=People,dc=mycompany,dc=com"
adding new entry "ou=Group,dc=mycompany,dc=com"
adding new entry "ou=Netgroup,dc=mycompany,dc=com"
adding new entry "ou=Protocols,dc=mycompany,dc=com"
adding new entry "ou=Aliases,dc=mycompany,dc=com"
adding new entry "nisMapName=[Link],dc=mycompany,dc=com"

7. Add a new user in LDAP database:


# useradd -g users ldapuser
# passwd ldapuser
Changing the password for the user ldapuser
New UNIX password:
Retype new UNIX password:
passwd: all authentication tokens updated successfully.
# grep "ldapuser" /etc/passwd > /etc/openldap/[Link]
# cat /etc/openldap/[Link]
ldapuser:x:502:100::/home/ldapuser:/bin/bash

8. Use the conversion script to create a .ldif file:


# /usr/share/openldap/migration/migrate_passwd.pl /etc/openldap/[Link]
/etc/openldap/[Link]

9. Edit the .ldif file and change the password to cleartext. RADIUS requires passwords in cleartext.
# vi /etc/openldap/[Link]
dn: uid=ldapuser,ou=People,dc=mycompany,dc=com
uid: ldapuser
cn: ldapuser
objectClass: account
objectClass: posixAccount
objectClass: top
objectClass: shadowAccount
userPassword: {crypt}$1$uwbaUNv3$HxLEKJE2n3dTOltdu4e/y/

NOTE: Change the user password to ldapuser*passwd.


shadowLastChange: 12710
shadowMax: 30
shadowWarning: 7
loginShell: /bin/bash
uidNumber: 502
gidNumber: 100
homeDirectory: /home/ldapuser

26 Managing Users
10. Import the record to LDAP database, using rootpw:
# ldapadd -x -D "cn=Manager,dc=mycompany,dc=com" -W -f /etc/openldap/
[Link]
Enter the LDAP Password:
adding new entry "uid=ldapuser,ou=People,dc=mycompany,dc=com"

11. Search for the LDAP user entry:


# ldapsearch -x -b "dc=mycompany,dc=com" 'uid=ldapuser'
version: 2
#
# filter: uid=ldapuser
# requesting: ALL
#

# ldapuser, People, mycompany, com


dn: uid=ldapuser,ou=People,dc=mycompany,dc=com
uid: ldapuser
cn: ldapuser
objectClass: account
objectClass: posixAccount
objectClass: top
objectClass: shadowAccount
userPassword:: e2NyeXB0fSQxJHV3YmFVTnYzJEh4TEVLSkUybjNkVE9sdGR1NGUveS8=
shadowLastChange: 12710
shadowMax: 30
shadowWarning: 7
loginShell: /bin/bash
uidNumber: 502
gidNumber: 100
homeDirectory: /home/ldapuser
# search result
search: 2
result: 0 Success

# numResponses: 2
# numEntries: 1

12. Setup the LDAP client as follows:


a. Edit the /etc/openldap/[Link] file.
b. Add the IP address of your LDAP server and the BASE suffix at the end of file. For example:
HOST [Link]
BASE dc=mycompany,dc=com

The HOST entry specifies the LDAP server(s) to which the LDAP library connects to. A
space-separated list may be provided. For our purpose, we specify the IP address of local host.
If you need to delete an LDAP record, use the following command. This example deletes luser.
# ldapdelete -W -x -D "cn=Manager,dc=mycompany,dc=com" "uid=luser" ...

COS Configuration Guide 27


RADIUS Server Configuration
To configure the system as a RADIUS server, perform the following:
1. Log into COS as a root user.
# su - root

2. At the Linux prompt, start the RADIUS server:


# /etc/rc.d/init.d/radiusd start
Starting RADIUS server: [ OK ]

3. Configure the /etc/raddb/[Link] file. This file stores the main RADIUS parameters. Allow LDAP
queries from RADIUS as follows:
a. In the "authorization" section, activate the use of LDAP module by uncommenting the word ldap. For
example:
authorize {
...
ldap
...
}

b. In the module{} section, define the LDAP domain. LDAP server and password methodologies to be
used in the LDAP block are as follows:
ldap {
server = "localhost"
# identity = "cn=admin,o=My Org,c=UA"
# password = mypass
basedn = "dc=mycompany,dc=com"
filter = "(uid=%{Stripped-User-Name:-%{User-Name}})"
# base_filter = "(objectclass=radiusprofile)"

# set this to 'yes' to use TLS encrypted connections


# to the LDAP database by using the StartTLS extended operation.
# The StartTLS operation is supposed to be used with normal
# ldap connections instead of using ldaps (port 689) connections
start_tls = no

# access_attr = "dialupAccess"

# Mapping of RADIUS dictionary attributes to LDAP


# directory attributes.
dictionary_mapping = ${raddbdir}/[Link]

ldap_connections_number = 5

#
# NOTICE: The password_header directive is NOT case insensitive
#
# password_header = "{clear}"
#
password_attribute = userPassword

28 Managing Users
timeout = 4
timelimit = 3
net_timeout = 1

4. Configure the /etc/raddb/[Link] file. This file is used to define a shared password or secret to be used
by the RADIUS server and its clients. Passwords can be allocated for ranges of IP addresses in each network
block using the secret keyword. For example, testing123 is the password for all queries from localhost, and
s3star is the password for the [Link]/24 network. All RADIUS clients have to peer with the RADIUS
server using the correct password before logins are correctly accepted. The following is an example of
adding a client to this RADIUS server:
client [Link] {
secret = testing123
#
# The short name is used as an alias for the fully qualified
# domain name, or the IP address.
#
shortname = localhost
}

client [Link]/24 {
secret = s3star
shortname = home-network
}

#Added for the client switch


client [Link] {
secret = my*radius*key
shortname = Cisco1
nastype = cisco
}

5. Restart the RADIUS server:


# /etc/rc.d/init.d/radiusd restart
Stopping RADIUS server: [ OK ]
Starting RADIUS server: [ OK ]

You can test RADIUS server by running it in the debug mode as follows:
# /usr/sbin/radiusd -X -A

The radtest command can be used to perform RADIUS queries. The arguments are the LDAP username, LDAP
password, LDAP server IP address, a NAS port value (any value between 1-100), and the RADIUS client shared
secret password key. Successful queries will show an "Access-Accept" message as follows:
# radtest ldapuser "ldapuser*passwd" localhost 2 testing123
Sending Access-Request of id 11 to [Link]:1812
User-Name = "ldapuser"
User-Password = "ldapuser*passwd"
NAS-IP-Address = anila
NAS-Port = 2
rad_recv: Access-Accept packet from host [Link]:1812, id=11, length=20

COS Configuration Guide 29


30 Managing Users
4
Configuring Network Parameters

This chapter describes the procedure for configuring the network parameters of the C-Series system. The
network parameters include:
• Physical Interfaces
• Tap Interfaces
• Network Interfaces
• IP Aliases
• Static Routes
• Static ARP Entries
• Virtual Router Redundancy Protocol (VRRP)
• Network Interface Module (C30 model only)
• Layer 2 Switching
• Link Aggregation
• Rate Limiter Configuration
• Routing protocols RIP, OSPFv2, and PIM-SM (optional)

Displaying Network Configuration


To display network information from the Configuration interface, select Network Information from the
Configuration Menu. You can then select various items to view from the Network Information menu.
To display network information from EMS, open Configuration => Performance and Stats in the navigation
bar. In each window, you can use the Help button to obtain a definition of the various parameters.

Configuring Physical Interfaces


There are three types of physical interfaces on the system: management, gigabitethernet, and fastethernet. The
management interfaces allow you to manage the configured interfaces.
To configure the physical interfaces, select Physical Interfaces from the Configuration Menu or open
Configuration => Interfaces => Physical Interfaces in the EMS Navigation Tree. A list of all the system’s
physical interfaces display. You can modify the following parameters for any interface:
• MAC Address
• Auto Negotiate (off or on)
NOTE: Autonegotiation must be ON for the copper Gigabit Ethernet ports on the C30 model.
• Duplex (half or full)
• Speed

COS Configuration Guide 31


Configuring Tap Interfaces
Network tap interfaces are used to copy the input and output packets from a physical interface prior to processing
by the Network Interface Module Acceleration. These taps can be used by Intrusion Detection System (IDS)
software, such as Dragon, to sniff the interface. Tap interfaces can be given a device name of up to 15 characters,
and a single tap can capture the traffic for multiple physical interfaces.
To configure the tap interfaces, select Tap Interfaces from the Configuration Menu or open Configuration =>
Interfaces => Tap Interfaces in the EMS Navigation Tree. When configuring a network tap interface, you
configure the Tap Mode (C30 model only) and various Tap Interface parameters.
NOTE: The C2 and C6 models do not support the network tap interface.

Tap Mode
Tap Mode controls how traffic is encapsulated when sent to an application and can be configured to one of the
following modes:
• normal - Used when the loop cable is installed and the traffic is sent to an application on the device.
• raw - Traffic is sent out the Ethernet port exactly as it is received on the front panel ports. Note that the
interface only operates at 1GB and is not configurable.
• VLAN - Traffic is tagged using the incoming and outgoing VLAN IDs, which are tap interface parameters.
• Port-VLAN - Traffic is tagged using the incoming and outgoing VLAN tags as above, but the VLAN tag in
the tap interface configuration is treated as a "base" tag and port number of the NIM interface that the traffic
transmitted or received on is added to it to create the VLAN tag value.
• Load-Balance-Primary and Load-Balance-Secondary - Used with two systems with the rear ports
connected with a cable. These parameters determine traffic flow by designating which system is Primary
and which is Secondary. Use Load Balancing mode (tap interface parameter) to configure the load-balance
behavior of the Primary system. Typically, the Load Balancing mode is local for the Secondary system.
Example: You can configure load balancing so that two systems are both configured with a Firewall
application and an IDS application. The Primary system handles Firewall traffic, then taps the output traffic
and shares it with the Secondary system. Furthering this example, you would configure the Primary system
as a Master in a VRRP dual-box configuration. The Secondary system is the Backup. When operating
normally, the Firewall application is not used on the Secondary system. Should the Master fail, the Backup
processes traffic with the Firewall application in addition to IDS traffic. The tap configuration would be as
follows:

Primary System Secondary System

Tap Mode = Load-Balance-Primary Tap Mode = Load-Balance-Secondary

Tap Interface Name = Firewall Tap Interface Name = Firewall

Tap State = enabled Tap State = enabled

Load Balancing Mode = ip_hash Load Balancing Mode = local

32 Configuring Network Parameters


Tap Interface
The Tap Interface parameters are as follows:
• Tap Name
• Tap State (enabled or disabled)
• Promiscuous Mode, allows this device to receive copies of all the data packets on this physical interface. If
disabled, the destination MAC-address is local or broadcast for this interface. In most cases, the default
setting is the appropriate setting.
• Input VLAN Tag (C30 model only), tags incoming traffic with this VLAN ID.
• Output VLAN Tag (C30 model only), tags outgoing traffic with this VLAN ID.
• Load Balancing Mode (C30 model only), which has the following options:
– local - All packets from this tap are sent to the local host. This is the default if no value is specified.
– remote - All packets from this tap are sent to the remote host.
– ip_hash - All packets are load balanced between the local and remote system based on the hash of the
source IP address and the destination IP address.
• Physical Interfaces, which adds or removes physical interfaces from the tap interface. A tap can have
multiple physical interfaces; however, a physical interface can only be assigned to one tap.

Configuring Network Interfaces


A network interface associates an IP address with a physical connection and optionally a VLAN ID. You can
add, remove or modify network interfaces by selecting Network Interfaces from the Configuration Menu or
opening Configuration => Protocols => IP => IP Interfaces in the EMS Navigation Tree. A list of all the
network interfaces displays.
There are four types of network interfaces: management, gigabitethernet, fastethernet, and virtual. The first three
types indicate the type of physical interface. The virtual interface is used with LACP to aggregate multiple
physical interfaces. The C-Series system supports up to 8 virtual interfaces, virtual 0 through 7.
By default, DHCP is enabled on the C-Series system. Therefore, if there is a DHCP server on the network, the
Management 1 port is automatically assigned an IP address. (No other ports are assigned IP addresses by
DHCP.) If using a Check Point VPN-1/FireWall-1 application, you must disable the DHCP IP address by
manually assigning an IP address to the management port.
If adding or modifying a network interface, you must enter the Physical Interface name. Then configure the
following parameters:
• VLAN interface, which allows you to associate the interface with a VLAN ID.
• Interface state (enable or disable)
• IP address with netmask
• Broadcast address
• MTU
• Proxy ARP (enable or disable)
NOTE: When deleting a network interface associated with a VLAN ID using the Configuration Interface, you
must enter the VLAN ID when prompted to delete the interface.
NOTE: The management interface is designed for management traffic. Do not forward Firewall traffic over this
interface.

COS Configuration Guide 33


Configuring IP Aliases
IP aliases are additional network addresses that are assigned to a network interface. You can add, remove or
modify IP aliases by selecting IP Aliases from the Configuration Menu or opening Configuration => Protocols
=> IP => IP Alias in the EMS Navigation Tree. A list of all the IP Aliases displays.
If adding or modifying an IP alias, you must enter the Physical Interface name. Then configure the following
parameters:
• VLAN interface, which allows you to associate the IP alias with a VLAN ID. However, you must create the
VLAN on the physical interface before adding it to an IP alias, as described in Configuring Network
Interfaces on page 33.
• Alias IP Address
• Alias Network Mask
• Broadcast Address

Configuring Static Routes


Static IP routes are user-defined routes that cause packets moving between a source and a destination to take a
specific path. To add, remove, or modify static routes, select Static Routes from the Configuration Menu. From
EMS, open Configuration => Protocols =>IP => Static IP Routes in the Navigation Tree. Configure the
following parameters:
• Destination IP address
• Destination Network Mask
• Next Hop Gateway IP address
• Metric, which is the cost associated with the next hop route
If your system is not configured with a Check Point Firewall-1 application or the Firewall-1 application was
stopped, you need to perform the following from the unix prompt if you wish to forward IP traffic:
echo "1" > proc/sys/net/ipv4/ip_forward

Use the following command to check the status of IP forwarding. If a 0 is returned, forwarding is disabled. A 1
indicates that forwarding is enabled.
cat /proc/sys/net/ipv4/ip_forward

Configuring Static ARP Entries


You define static Address Resolution Protocol (ARP) entries by relating an IP address to a MAC address. To
add, remove, or modify static ARP entries, select Static ARP Entries from the Configuration Menu. From EMS,
open Configuration => Protocols => ARP => Static ARP in the Navigation Tree. Configure the following
parameters:
• Static Host IP address
• Static Host MAC address

34 Configuring Network Parameters


Configuring High Availability with VRRP
As described in Dual Box High Availability Configuration on page 9, VRRP manages automatic switch-over of
an interface from one C-Series system to another.
To configure C-Series systems for High Availability (HA), select Virtual Router Redundancy Protocol (VRRP)
from the Configuration Menu or open Configuration => Protocols => VRRP => VRRP in the EMS Navigation
Tree.
In the Configuration Menu, select VRRP Parameters to configure the VRRP Hold Down Time (seconds). This
is the time that VRRP waits prior to transitioning to the master state following a system reboot or VRRP daemon
restart. This setting applies to all VRRP instances on the system. The setting can be between 0 - 65535 seconds.
The default is 0 seconds.
In the Configuration Menu, select VRRP List to add, modify or delete a VRRP instance. Configure the
following parameters:
• VRRP ID, specifies the Virtual Router group ID for the set of redundant routers. Enter a number that
uniquely identifies this group of redundant COS systems. This number must be the same on both systems in
this group. Use a number from 1 (default) to 255. A COS system can support up to 255 VRRPs.
• Interface Name, indicates the port name/type; fastethernet or gigabitethernet, and indicates the port number
assigned to the physical interface.
• VLAN ID, creates the VLAN interface and assigns an IP address to a VLAN.
• VRRP MAC, enables or disables the use of the VRRP MAC address.
• Preemption, allows or disallows the original Master to resume being Master after failing and becoming
available again. In either case, the Backup services traffic when the Master fails. If Preemption is enabled,
the Master resumes servicing traffic when it becomes available. If Preemption is disabled, the original
Master does not resume servicing traffic unless or until the Backup fails. The Preemption setting must be the
same on both systems.
• Priority, specifies the priority level for this VRRP entry.
• Advertisement Interval, specifies the interval (seconds) between VRRP advertisements to other systems in
this group. Only the Master system sends advertisements; this field is ignored on Backup systems while they
remain Backup. The minimum interval is 1 second. The default interval is 1 second. The maximum is 255
seconds. Since a Backup system can become a Master system, you should use the default value for all
systems.
• Group ID, allows you to group interfaces into a Failover group by assigning the same Group number to each
interface. A similar group needs to be defined on both systems. If any one of the network interfaces in a
Failover group goes down, a switch-over occurs. For simplicity, the group on both systems should have the
same number. Valid values are 1 to 600, with 1 being the default.
• IP Address, the virtual IP address assigned to both the Master and Backup interfaces.

COS Configuration Guide 35


Configuring Network Interface Module (C30 Model Only)
Use the Network Interface Module (NIM) Configuration to enable or disable cold, warm and error boot
diagnostics and to set the ICMP rate limiting time to control the amount of ICMP traffic that goes through your
system.
ICMP rate limiting is configured in Kbytes per second and the system drops any ICMP packets that exceed the
specified rate. To disable ICMP rate limiting, set the rate to zero. Be aware that for rate limiting purposes, ICMP
packets forwarded by your system are counted twice (while receiving and transmitting). For example, if your
system forwards a 64 byte ICMP packet, the system consumes 128 bytes of bandwidth. Therefore, setting ICMP
rate limiting to 2000 Kbytes/second allows traffic to pass at 1000 Kbytes/second in both directions.
ICMP rate limiting only limits ICMP Echo Request packets. It has no effect on other ICMP packets, such as echo
reply and network unreachable. Also, ICMP rate limiting requires a Check Point VPN-1/Firewall-1 application
with SecureXL enabled (which is the Check Point default setting).
To configure the NIM parameters, select Network Interface Module Configuration from the Configuration Menu
or open Configuration => System => NIM Configuration in the EMS Navigation Tree.

Configuring Layer 2 Switching (C30 Model Only)


Layer 2 switching allows the COS system to provide Layer 2 network functions for applications. Typically,
Layer 2 switching is needed for an Intrusion Detection System (IDS) application, such as Dragon. To configure
Layer 2 Switching Parameters and Groups, select Layer 2 Switching from the Configuration Menu or open
Configuration => Interfaces in the EMS Navigation Tree.
Layer 2 functions are divided into Parameters and Groups. Parameters enable or disable Layer 2 switching and
set the Switching Age time in seconds. The value for the timer is 10 to 1000000 seconds.
The Layer 2 Groups select and group Fast Ethernet ports that support Layer 2 switching. When adding or
modifying a group, you are prompted for these parameters:
• Group Name
• Layer 2 Switch State (disabled or enabled)
• Associated physical interfaces
Layer 2 groups do not have an IP address. Therefore, if the application requires an IP route between Layer 2
groups, you need to physically connect an external port with a network interface and IP address to a port in the
Layer 2 group.

Configuring Link Aggregation (C30 Model Only)


Link Aggregation allows you to bundle several physical ports together to form a single virtual interface. Link
Aggregation Control Protocol (LACP) (802.3ad) is a control protocol that automatically detects multiple links
between two LACP enabled devices and configures them to use their maximum possible bandwidth by
automatically trunking the links together.
LACP controlled ports can be in Active or Passive mode. A port in Active mode sends LACP Data Units
(LACPDUs) at regular intervals to seek out partners. A Passive mode port only sends LACPDUs in response to a
received LACPDU. Ports are in Active mode by default.
When enabled, LACP sends LACPDUs to each Active mode connected link to find partners that also have LACP
enabled. If a reply is received, the device builds a database of which link goes to which partner device. When
LACP detects that two or more links are connected to the same partner device, have the same key, and two or
more of this group are not specified to be individual, it aggregates them into one logical link.

36 Configuring Network Parameters


Additional physical links added to the same partner system will be added to the now existing trunk group (within
physical bounds). The same actions takes place if a port is in passive mode and it receives a LACP control
packet; it builds a database of connected partners and sends control packets out that interface.
Before aggregating links, you must first create a “virtual” network interface. The following describes how to
aggregate physical links from the Configuration interface. Note that the physical links must be configured for
full-duplex.
1. Select Network Interfaces from the Configuration Menu.
2. Choose to add a network interface.
3. When prompted for the Physical Interface name, enter virtual x, where x is a number from 0 to 7.
4. Configure the following parameters:
– VLAN interface, which allows you to associate the interface with a VLAN ID.
– Interface state (enable or disable)
– IP address with netmask
– Broadcast address
– MTU
– Proxy ARP (enable or disable)
5. Create as many virtual interfaces as needed then exit Network Interfaces.
6. Select Link Aggregation from the Configuration Menu. A list of virtual network interfaces displays.
7. Select a virtual interface by its ID and configure the following parameters:
– Distribution Algorithm, specifies the distribution algorithm to use, for example dasa or tcpudp.
– Physical Interfaces, specifies the list of physical interfaces to aggregate.
NOTE: The gigabitethernet and fastethernet physical interfaces cannot be combined in one virtual
interface.
To configure Link Aggregation from EMS, open Configuration => Interfaces => Link Aggregation in the
Navigation Tree.

COS Configuration Guide 37


Configuring Rate Limiter (C30 Model Only)
The COS QoS software supports per-port traffic conditioning at the interface level. The per-port traffic
conditioning are applicable to both Gigabit Ethernet and Fast Ethernet interfaces. The Rate-Limiter rate
parameter supports a guaranteed input and output bandwidth, while the excess-burst parameter supports an
excessive burst size that the COS system can handle before traffic exceeds this rate and is dropped.
Traffic arriving within the rate parameter is considered to conform and traffic flows as normal. However, if the
traffic arrives at a rate higher than the rate parameter, and if the excess-burst parameter is not specified, the
traffic rate-limiter drops the traffic. When the excess-burst parameter is configured, the rate-limiter delays excess
traffic using a buffer and drops traffic only when the buffer overflows.
Classifiers are used to classify IP packets arriving on an interface so that different actions can be applied, based
on which classifier control the packet matches.
The following describes how to configure rate limiting:
1. Select Rate Limiter Configuration from the Configuration Menu.
2. Choose Rate Limiter Parameters to configure the following:
– Name of the rate limiter
– Rate (KB/sec)
– Burst (KB/sec)
3. From the menu, choose Classifier to configure the following:
– Classifier, indicates the user defined name assigned to the classifier (up to 32 characters).
– Physical Interface, indicates the name of the physical interface that is being classified. For example,
gigabitethernet 17. Or indicates all interfaces.
– VLAN, indicates the default outbound VLAN tag, which is a value ranging from 0 - 4094.
– IP Protocol, indicates the protocol attributes, such as source and destination IP address and mask
– IP Port, indicates the IP port number assigned to the physical interface.
– Rate Limiters, indicates the Rate Limiters applied to the classifier.
To configure Rate Limiters using EMS, open Configuration => Interfaces => Rate Limiter in the Navigation
Tree. To configure classifiers, open Configuration => Interfaces => Classifier.

38 Configuring Network Parameters


Installing Dynamic Routing Protocols
The C-Series system supports the following routing protocols:
• Routing Information Protocol (RIP)
• Open Shortest Path First (OSPF)
• Protocol Independent Multicast-Sparse Mode (PIM-SM)
The routing protocols are optional and purchased separately.
The routing protocol RPMs are on the Routing Software CD in directory: /RSW/RSW-RPMS/. If using RSW
V7.0 or later, there are two sets of routing protocols; one for CS Linux v1 and one for CS Linux v3. The set for
CS Linux v3 has an “EL” in the RPM name. In each set, there is a Common RPM and one RPM for each
protocol. Only install the protocol RPMs you wish to use; the Common RPM is automatically installed when
installing the first protocol.
Perform the following to install each RPM:
1. Log into your system as an administrator. The default administrator username is admin, and the default
password is admin.
2. Log into your system as root.
[admin@cos_system admin]$ su root
[root@xxxxx admin]#

3. If your C-Series system has CS Linux v3 installed, copy the “EL” RSW RPMs to the /usr/os/rsw/rpm
directory. Otherwise, copy the non-EL RSW RPMs. Create the directory structure if necessary.
zebos-common-xxxxxxxxxx
zebos-rip-xxxxxxxxxx
zebos-ospf-xxxxxxxxxx
zebos-pim-xxxxxxxxxx

NOTE: Refer to the COS Release Notes for the correct RPM names for your version of COS.
You configure the routing protocols from the Configuration Menu, which launches the ZebOS CLI. To install the
protocols:
1. Execute the following command at the admin prompt to display the Main Menu.
[root@hostname admin]# cos_config

2. Select the Routing Protocols menu item.


3. Select the Install menu item.
4. Select the Routing Protocol to install.
NOTE: The Network Service Module (NSM) option enables access to the routing protocol NSM daemon;
however, you actually access the NSM daemon from the ZebOS command prompt. Enabling access to the
NSM daemon allows the RSW user to configure basic routing services for all protocols, which includes
configuring a loopback adapter or virtual links.
5. Confirm the version, type Y and press Enter. A “Finished installing” message displays.
Before launching the ZebOS CLI, you are prompted for a password. Refer to the Routing Protocols Command
Reference guide for the default password, how to configure the routing protocols, and how to change the default
password. When finished using the ZebOS CLI, type exit to return to the Configuration menu.
The routing configuration files are stored by default in /usr/os/etc/zebos/.

COS Configuration Guide 39


NOTE: Device naming conventions differ between this document (mapped devices such as gigabitethernet 1)
and the Routing Software documentation (raw devices such as ethX).
NOTE: If your system is not configured with a Check Point Firewall-1 application or the Firewall-1 application
was stopped, perform the following from the unix prompt if you wish to forward IP traffic:
echo "1" > proc/sys/net/ipv4/ip_forward

The routing protocol menu options include:

Install Installs a protocol. If there is more than one RPM in the /usr/os/rpm/rsw directory, you
are prompted for the version.
Uninstall Removes the protocol.
Configure Launches the routing protocol prompt. Refer to the routing documentation to configure the
protocol.
Status Displays the status of a routing protocol.
Start Starts the protocol.
Stop Stops the protocol.
Restart Restarts the protocol. This is useful should you wish to force a running protocol, such as
OSPF, to rebuild its routing table.
Upgrade Upgrades an installed protocol to another version; however, you may need to upgrade the
Common RPM first.

Installing Applications
You access the applications installation menu by selecting Applications Install from the Main Menu. Refer to the
COS Applications Installation Guide provided with the ADF software to install and configure the applications.
The guide also provides a list of requirements for each application.

40 Configuring Network Parameters


5
Upgrading COS

This chapter describes how to update your system software, and how to configure your system to use multiple
versions of COS or multiple system configurations. It also describes how to install COS from the Install Server.

Upgrading the COS System Software


You can upgrade your system using a software patch, as described in Software Patch on page 41, or upgrade
while maintaining the current configuration, as described in Safe Upgrade on page 42. Note that a system cannot
be upgraded from CS Linux v1 to CS Linux v3.
IMPORTANT: Make sure that the Management 1 port is assigned a permanent IP address (not from DHCP)
before upgrading. Refer to Configuring Network Interfaces on page 33 for the procedure to assign an IP address.

Software Patch
If upgrading your system software from a previously configured release, you do not need to use the full system
software. Instead, you can use the upgrade patch, which is a .[Link] file. Refer to the COS Release Notes for the
correct file name for your COS version.
You can upgrade COS on a stand-alone system or a system in a VRRP configuration. If your system is in a
VRRP configuration, refer to Upgrading C-Series Systems in a VRRP Configuration on page 43.
To upgrade COS, perform the following:
1. Login to your system as root.
su - root

2. Change to the root directory:


cd /root

3. Create a directory as follows, where X.X.X-X, is the current software version.


mkdir cos-upgradepack-X.X.X-X

4. Use FTP or copy the file, [Link], from your System Software
CDROM or software package to /root/cos-upgradepack-X.X.X-X.
5. Change the directory to cos-upgradepack-X.X.X-X:
cd cos-upgradepack-X.X.X-X

6. Enter the following command at the root prompt:


gzip –d [Link]

7. Once the command completes, enter the following command at the root prompt:
chmod 700 [Link]

8. Once the command completes, enter the following command at the root prompt:
./[Link]

COS Configuration Guide 41


9. Answer "Y" when prompted.
The system software is upgraded when this action completes. You may ignore any "Exec'ed Program Error"
messages displayed during the upgrade process if upgrading from a release prior to V2.1.3. Your system will
still be upgraded properly.
10. Reboot your system.

Safe Upgrade
The C-Series system ships with two disk partitions, one partition is used for the current runtime version of
software and the other partition is for the upgraded version of software. Each partition provides 20 Gigabytes of
disk space. The two partitions, Running Partition (RP) and Upgrade Partition (UP), allow you to upgrade your
system software while maintaining a previous version of your configuration. COS V2.1 and greater allows you to
do a full copy of the RP to the UP before actually upgrading your COS software. To do this:
1. Make sure you are connected to the console.
2. Reboot your system into single user mode. To do this, at the root prompt, enter:
init 1

3. Once the system boots into single user prompt, enter the following:
/usr/os/sbin/cos-copy-dist -p 2

This copies the entire RP disk contents into the UP, including the application configurations.
4. Once the copy is complete, enter the following:
/usr/os/bin/cos_toggle_boot other

5. Reboot your system. Your system is booted into the UP.


6. Upgrade your system software or applications, as needed.
7. Reboot if necessary.

If all upgrades are working normally, you are now on the UP (partition set 2). If the upgrades fail or the system
fails to boot, you must reboot. When you see the bootup choices for the kernel under Grub, select the Chains
option. Alternatively, if you can get to the root prompt and do not want to upgrade, enter the following:
/usr/os/bin/cos_toggle_boot other

NOTE: To view the current partition, enter the following:


/usr/os/bin/cos_toggle_boot

The default value is “/[Link]-x” and indicates your original RP. To list possible selections, enter the
following:
/usr/os/bin/cos_toggle_boot -l

The “other” value indicates the second part of the disk, which is your UP.
When done, reboot the system. To go back to the original partition (RP) that was working properly, reboot the
system.

42 Upgrading COS
Upgrading C-Series Systems in a VRRP Configuration
To upgrade COS on a system in a VRRP configuration, upgrade the backup system first as follows:
1. Make sure the systems in VRRP group are in sync.
2. Disable one of the interfaces in the VRRP group on the backup system so that it stays backup after being
upgraded.
3. Perform the upgrade procedure as described in Upgrading the COS System Software on page 41.
4. After upgrading the backup system, verify that the system is in sync with the master system.
5. Bring up the disabled interface on the back-up system.
6. Make sure that the systems in the cluster are in sync with each other.
7. Fail over the traffic to the back-up system and repeat the process on the master system.

Using Multiple Versions of COS


The two partitions, Running Partition (RP) and Upgrade Partition (UP), allows you to maintain two separate
versions of COS on your system, or two different system configurations using the same COS version. This is
done using /usr/os/install-cos, which can install to either partition 1 or 2 of the disk. You can run install-cos
while the system is booted from the Install Server or the system is running off the disk.

Caution: When installing COS to the Upgrade Partition, make sure you
specify “2” in the install command (in step 1); otherwise, you will
overwrite your configuration in the Running Partition.

To install a later version of COS to the Upgrade Partition:


1. Enter the following command:
/usr/os/sbin/install-cos -p 2 <release directory>

2. Manually configure the UP identically to the RP (System configuration and applications).

Later, you can switch to the RP and upgrade the RP. Should the upgrade fail, reboot the system. By default the
system boots with the functional UP.
NOTE: If using Install Server, the Install Server must be configured on the same subnet as the COS
management 1 interface.

COS Configuration Guide 43


Installing CS Linux v3 or v1
A system cannot be upgraded from CS Linux v1 to CS Linux v3. If you wish to install CS Linux v3, you will
need the Install Server to perform the following:
On the Install Server:
1. Start the IS menu with /usr/os/bin/is-config.
2. Press 1 to Manage the diskless partition.
3. Press 2 to Upgrade the COS diskless partition.
4. Enter the name of the COS partition. The default is COS.
5. Type in the path and source file of the COS 3.6 system software file.
6. After the upgrade is complete, verify the Diskless partition status with option 4.

On the C-Series system:


1. Reboot the system and force a network boot.
– On the C2, C6 or C10 model, press "L" if the Network boot message appears on the screen.
– On the C30 model, press F12 if the Network boot message appears on the screen. You need a Terminal
Emulation, such as Linux, that supports the F12 key.
– On the C30 or C30i model, press the "ESC" button if the Network boot <F12> text appears.
The following message appears on the screen:
Entering boot selection menu...
Choose a boot option via the cursor keys and confirm with <ENTER>
GE Slot 0339 = Network boot via Port Mgmt2
GE Slot 0338 = Network boot via Port Mgmt1

2. After the boot is completed, log in as a root user without any password.
# su - root

3. Execute the following installation command:


[root@COS root]# /usr/os/bin/install-cos -v cslinux_v3 <install_directory>

If installing CS Linux V1, use this command:


[root@COS root]# /usr/os/bin/install-cos -v cslinux_v1 <install_directory>

4. After the installation is complete, reboot the system. You should see a Grub menu similar to the following:
GRUB version 0.91 (639K lower / 523200K upper memory)
Distribution 1
+-------------------------------------------------------------------------+
| Linux ([Link]) |
| Linux ([Link]) |
| Linux (ChainII) |

44 Upgrading COS
6
Useful Tools

This chapter describes the tools provided with the C-Series system. The tools are located in /usr/os/bin. To
receive help on any of these commands, use -h.

Displaying Information for Technical Support


The cos_tech_support command displays verbose system information. Typically, you only use this command
when troubleshooting a problem with Technical Support. The command is available at the admin prompt.

Toggling Boot Between Partitions


The cos_toggle_boot command is used to determine which partition is used to boot the COS system. This is
useful if you have different versions of COS on the partitions, or are using different configurations with the same
version of COS.

Linux Tools
You can use various Linux tools such as netstat and ifconfig, which are stored in the /sbin/ directory.
You can use ifconfig to display the status of the currently active interfaces. However, ifconfig does not always
report the promiscuity of a device correctly, depending on how the device was placed into promiscuous mode.
Instead, use the ip link show <devname> command.
Also, ifconfig and netstat only display the first 9 characters. Instead, you should use cos_config and /proc/net/
dev for correct displays.

Swatch Dynamic Display Tool


The COS Open Security Appliance Swatch Dynamic Display Tool (Swatch) is a Linux tool designed to display
dynamically-changing data on a terminal screen in a customized display format. Unlike X-windows, which
forces the use of a Graphic User Interface (GUI), the Swatch tool operates directly from the Command Line
Interface (CLI).
Originally designed to format and display device packet statistics from Linux/proc files, the Swatch tool now
allows you to easily spot changes in your system status and can display any type of data that can be obtained
from an ASCII file or by executing any Linux command that writes to a standard output.
The Swatch tool supports the following data types:
• String
• 32-bit integer
• 64-bit integer
• 64-bit floating point
The Swatch tool can also perform simple arithmetic operations on data, such as rate, min, max, sum, and diff. All
data items can be reset (resets min, max, rate) and counter data items can be zeroed out.

COS Configuration Guide 45


Understanding the Swatch Tool
The Swatch tool is designed to read a configuration files, determine the data items (known as swatch variables)
to acquire, and then determine where to display them on your screen. Configuration files are simple text files that
can be created and edited using any text editor. Refer to the TCL documentation for the appropriate TCL
commands and Creating Swatch Tool Configuration Files on page 47 for Swatch-specific commands.
When reading the configuration file, the Swatch tool:
• Parses the file using a TCL interpreter, allowing you to use any TCL commands. After parsing the
configuration files, the Swatch tool displays all items on the first screen.
• Defines one or more acquisition files to obtain data from. The Swatch tool periodically reads all fields from
acquisition files into swatch variables in memory.
• Defines one or more virtual screens that can be displayed. The Swatch tool periodically displays values of
swatch variables on a virtual screen.

Starting and Stopping the Swatch Tool


To start the Swatch Tool from the Linux shell prompt, go to root and enter the following command:
swatch [<options>] <cfgfile> [<cfgfile> ...]

Where the valid options are:


-D<TCLvar>=[<value>,...], defines the TCL variables and assign values.
-i, show information about the script.
-g<n>, sets the debugging level to <n>. Where the value zero means display no debug information and a
higher value means display more information.
-x<n>, causes the Swatch tool to dump internal program objects up to level <n>, with a higher level value
meaning to display more information.
-h | - help, displays help for command usage and exits.
-v | -version, displays the Swatch tool program version and exits.
To stop the Swatch tool, press the q or Q key anytime while the Swatch tool is running.

Using Single Key Commands


The following single-key commands can be used anytime while the Swatch tool is running:
<space-bar>, pauses/resumes screen updates.
s, causes a single screen update.
c (lowercase), clears all counters on the current screen.
C (uppercase), clears all counters on all screens.
u (lowercase), restores the original values of the counters on the current screen.
U (uppercase), restores the original values of the counters on all screens.
r (lowercase), resets the data items on the current screen.
R (uppercase), resets the data items on all screens.
d, downloads the current screen to a file, where the filename is <screenname>.scr.

46 Useful Tools
+/-, moves to the next or previous screen respectively.
0-9, moves to the designated screen number from 0 to 9.
h, displays a help page.
l, displays a screen list page.
q or Q, quits the Swatch tool program.

Creating Swatch Tool Configuration Files


This sections describes the following:
• How to create useful Swatch tool configuration files.
• How to use Swatch tool commands.
• How to use predefined TCL variables in a Swatch tool configuration file
• How to use Swatch tool variables in all commands

Creating Useful Swatch Tool Configuration Files


The following are guidelines to use when creating a Swatch tool configuration file.
• Use the first few lines of the file to set default values for TCL variables, which can be overridden by using a
-D option on the swatch command line. You can use -Dline=x to limit the output display. For example, ./
swatch -Dline=10 interrupts will display the interrupt stats from line 10 onwards.
• Minimize the number of swacquire commands within a given configuration file.
• Minimize the number of lines and columns displayed on a virtual screen.
• Place a Title line at the top of each virtual screen.
• Use unique virtual screen names to allow users to easily identify the screen.
• Use the counter option on all swread commands to indicate if an item is a counter.
• Use the once option on swread commands if the item value does not change.
• Define only one or two different screen types per configuration file.
To create a Swatch tool configuration file, use the following commands:
• swacquire
• swread
• swcalc
• swaggr
• swscreen
• swdisplay

COS Configuration Guide 47


Using the swacquire Command
The swacquire command specifies the file read periodically or the shell run to retrieve the command output.

Syntax
swacquire [file <filename>] [shell <shell>] [shellinit <prompt> <resp>]
[shellcmd <prompt> <resp>] [period <poll-period>] [delim <delim-chars>]

Where:
file is the existing files (including /proc files) or you can specify a file that saves the shell command output.
shell designates the running commands that generate output.
shellinit defines a one-time dialog. For example, use this parameter to specify a login-prompt/username or
password-prompt/password.
shellcmd defines a dialog at each poll period. For example, use this parameter to specify a shell prompt/
command executed in a telnet session.
delim specifies a set of characters used as a delimiter between fields.

Example
swacquire file /proc/net/dev period 2

This example specifies that the file /proc/net/dev is read every 2 seconds.
The following information defines the position of a display or data item when using this command.

Syntax
line/field/column-spec [+|-]x[@y]

Where:
+|- specifies the new position is relative to last position.
@y specifies the new position is incremented by y for each variable instance.

Example
line-spec is +4@2

In this example, the starting line number is +4 from the current line number, and the line number is incremented
by 2 for each variable instance referenced in the command.

Using the swread Command


The swread command defines a data item at fixed positions within the swacquire file (or shell output).

Syntax
swread <varname> <line-spec> <field-spec> <fmt> [counter] [once]

Where:
<varname> is a Swatch tool variable name that holds values read from a file.
<line-spec> and <field-spec> define the line# and field# position within a file.
<fmt> defines how a data value is read. This is the same value as the scanf() function.
counter parameter indicates that the data item is a counter. This value can be zeroed out.
once indicates that a data item is read one-time only.
NOTE: All swread commands are relative to the last swacquire command

48 Useful Tools
Example
swread pktdrops 2 1 %u counter

This example defines an integer variable pktdrops at line 2; field 1 is read from the previous acquisition file with
a format of %u. This variable is a counter.

Using the swcalc Command


The swcalc command defines the data item calculated from other data items.

Syntax
swcalc <varname> <operation> <operand> [<operand> ...]

Where:
<varname> is the result variable name. Note, this can be an array. If this is an array, the number of array
indices in the operands must match the number of array indices in the result.
<operation> is the rate, min, max, add, or sub.
<operand> is the name of Swatch tool variable used as a source for the operation. If this is an array, the
number of array indices in the operands must match the number of array indices in the result.

Example
swcalc droprate(1:10) rate pktdrops(1:10)

This example defines an array droprate that is calculated by computing the rate of the values in the pktdrops
array.

Using the swaggr Command


The swaggr command defines a data item aggregated from other data items.

Syntax
swaggr <varname> <operation> <operand> [<operand> ...]

Where:
<varname> is the result variable name. This must be a scalar value.
<operation> is the sum or diff operation.
<operand> is the name of the Swatch tool variable used as the source for operation. This can also be an
array.

Example
swaggr totdrops sum pktdrops(1:10)

This example defines a scalar variable totdrops that is calculated by computing the sum of all values in the
pktdrops array.

COS Configuration Guide 49


Using the swscreen Command
The swscreen command defines the virtual screen displayed.

Syntax
swscreen <screenname> [period <n>]

Where period defines the screen refresh rate in seconds. Default is 1 second.

Example
swscreen devpktcnt 2

This example defines a virtual screen named devpktcnt that when displayed, refreshes every 2 seconds.

Using the swdisplay Command


The swsdisplay command defines the display item created at a fixed position on a virtual screen.

Syntax
swdisplay <line-spec> <col-spec> <size> <fmt> [<varname>]
[scale <scale-factor>]

Where:
<line-spec>, <col-spec> define the position of the display item on the virtual screen.
<size> is the total width of the display item.
<fmt> is the format used for writing a display item. This value is the same as the printf function.
<varname> is the name of the previously defined Swatch tool data variable.
scale defines the scale factor applied to the data variable prior to output.
All swdisplay commands are relative to the last swscreen command.

Example
swdisplay 4@1 15 10 %u pktdrops(1:10)

This example displays the values of the array pktdrops at column 15 on lines 4-13, with a width of 10 characters.
The following information defines the position of a display or data item, when using this command.

Syntax
line/field/column-spec [+|-]x[@y]

Where:
+|- specifies the new position is relative to last position.
@y specifies the new position is incremented by y for each variable instance.

Example
line-spec is +4@2

In this example, the starting line number is +4 from the current line number, and the line number is incremented
by 2 for each variable instance referenced in the command.

50 Useful Tools
Using Swatch Tool Variables in All Commands
The following are Swatch tool variable guidelines and restrictions:
• Variable names can be any alphanumeric string. For example, pktdrops.
• Variables can be either scalar or arrays.
• Variables are only visible in current configuration file, unless they are prefixed with global tag.
• Array elements are specified as <varname>(<index>) where the index is a non-negative integer. The
notation varname(<index1>:<index2>) is shorthand, which expands the command for each variable instance
between varname(index1) and varname(index2) inclusive.

Using Existing Swatch Tool Configuration Files


This section describes the existing Swatch tool configuration files that you can use:
• [Link], displays Firewall stats if Firewall is installed. Stats include in and out traffic counters (per
packets) and rates per interface. Counters are total ingress/egress (in/out) traffic, accepted in/out traffic, deny
in/out traffic, and log in/out traffic. Rates are in/out total traffic, in/out deny traffic, and in/out log traffic.
Counters are on screen 1 and rates are on screen 2.
• [Link], displays interrupts stats counts and rate. Stats include the interrupts count and rate per
interruptable devices (timer, keyboard, etc.)
• [Link], displays packet statistics for all Linux devices.
• [Link], displays NIM link status, speed, duplex mode, and auto-negotiation (C30 model only).
• [Link], displays packet statistics for all Linux devices with the exception of management interfaces
(C30 model only).
• [Link], displays the 'uptime' which has current time, duration since last boot, number of current users
logged in, and CPU load average.
• [Link], displays the SNMP stats per IP, ICMP, TCP, and UDP, per screen.

Swatch Performance Considerations


The following are performance considerations to heed when using the Swatch tool.

Swatch Tool Child Processes


The Swatch tool creates many child processes on a local host. This can slow system performance. The following
are examples of this:
• There is one child process for computing all derived or calculated data items. For example, data items
defined in swcalc or swaggr commands.
• There is one child process for each swacquire command in the configuration files listed on startup. Note, if
a swacquire command has a shell option, an additional child process is created to execute the shell
command in.
NOTE: Some shell commands may cause TCP/UDP connections to remote hosts or cause new processes to be
created on a remote host.

COS Configuration Guide 51


Single Shared-Memory Region and Semaphore
The Swatch tool uses a single shared-memory region to communicate data between processes. Currently, the
region is set to 400,000 bytes.
The Swatch tool also uses a single semaphore to provide atomic access to the shared memory region.

Troubleshooting the Swatch Tool


The following are some known problems that may result when using the Swatch Tool.

Data Not Being Displayed or Updated


Problem
Some data is not being displayed or updated.

Possible Solutions
• For swacquire file commands, make sure the file exists.
• For swacquire shell commands, make sure that the shell command can be invoked manually.
• Run the Swatch tool with a -g<n> option to create debug files. Higher debug levels give more debug
information. Debug files are located in the [Link], where the xxxxx is the child process ID.

Data is Not Displayed in the Correct Location


Problem
Data is not displayed in correct screen location.

Possible Solutions
• Check the swdisplay line, column, and format options for the data item.
• Run the Swatch tool with the -x<n> option to download program objects. Higher dump levels give more
dump information.

52 Useful Tools

Common questions

Powered by AI

The Swatch tool uses configuration files to manage data display by reading these files through a TCL interpreter, allowing TCL commands to define display settings and data acquisition. TCL variables set within these files dictate the definition, acquisition, and presentation of data on virtual screens. This structure allows for customized and flexible monitoring setups .

Autonegotiation is crucial for ensuring that both ends of a network link can agree on the optimal settings for speed and duplex mode, improving compatibility and performance. It should be enabled, especially on the copper Gigabit Ethernet ports, such as those on the C30 model, to ensure seamless communication and optimal data transfer rates .

After booting the system for the first time, it is recommended to connect via SSH if a DHCP service is available in the network. Then, disable the DHCP service by assigning a static IP to the management interface. During the initial boot process, change the default root password within the 15-second window provided. Use the Interview script from the Main Menu to configure aspects like Host Name, DNS Domain Name, System Time and Time Zone, Management Services, IP addresses, SNMP parameters, and the Administrator password .

VLAN interfaces enable traffic segmentation by associating a network interface with a specific VLAN ID, allowing distinct network policies or routing domains. This is crucial when configuring network interfaces to ensure traffic isolation and security. When dealing with IP aliases, VLANs allow for additional network addresses to be associated, meaning that each alias can be linked to a VLAN, ensuring traffic is managed according to specific network policies .

To configure a new physical interface on the C-Series system, access the Configuration Menu and select Physical Interfaces, or navigate to Configuration => Interfaces => Physical Interfaces in the EMS Navigation. You can then modify parameters such as MAC Address, Auto Negotiate setting, Duplex, and Speed. For copper Gigabit Ethernet ports, ensure Autonegotiation is enabled .

Enabling Proxy ARP allows a device to respond to ARP requests on behalf of another device, effectively making it appear that both devices share the same network segment even if they do not. This can simplify network management by reducing the need for more complex routing tables or VPN configurations. However, it should be used judiciously as it can introduce potential security vulnerabilities and network loops if misconfigured .

Unlike GUI-based monitoring tools, the Swatch tool operates directly from the Command Line Interface, enabling it to run on systems without graphical environments. It offers functionalities like dynamic display updates, variable tracking, arithmetic operations on data, and custom screen layouts. This allows for real-time monitoring of system changes by reading configuration files and displaying variable values in user-defined formats on terminal screens .

Both tap and physical interface configurations involve similar processes of using the Configuration Menu or EMS Navigation Tree. Physical interfaces deal with core LAN connectivity settings like MAC Address and Duplex settings, while tap interfaces focus on capturing traffic for monitoring or intrusion detection, using IDS software. Unlike physical interfaces, tap interfaces can have multiple assigned physical interfaces but are specific to applications needing data packets for analysis .

To create a Swatch tool configuration file for monitoring packet drops, use text editors to write lines beginning with swacquire commands to specify the source file or shell command for packet data. Utilize swaggr to define derived variables, such as total packet drops by summing array values. Define screens with swscreen and position the display with swdisplay commands. Ensure the configuration is precise, with commands reflecting data sources and display logic correctly established .

The Swatch tool can be utilized to monitor system performance by dynamically displaying data from ASCII files or outputs of Linux commands on a terminal screen. It supports data types including strings, 32-bit and 64-bit integers, and 64-bit floating point numbers. The tool allows operations such as rate computation, min, max, sum, and differences, thereby assisting in detecting changes in system status .

You might also like