cc/td/doc/product/rtrmgmt/baccable/cable27
hometocprevnextglossaryfeedbacksearchhelp
PDF

Table Of Contents

Configuration Workflows and Checklists

Component Workflows

RDU Checklist

Hardware DPE Checklist

Solaris DPE Checklist

Network Registrar Checklist

Technology Workflows

DOCSIS Checklist

PacketCable Checklists

Non-Secure CableHome Provisioning Checklist


Configuration Workflows and Checklists


This chapter is divided into two major sections that define the processes to follow when configuring BACC components to support various technologies. These sections are:

Component Workflows

Technology Workflows

Component Workflows

This section describes the workflows you must follow to configure each BACC component for the technologies supported by BACC. These configuration activities are performed before configuring BACC to support specific technologies. In some instances certain procedures may only be applicable to a lab or component installation. In these cases that appropriate indication is made.

The component workflows described in this section are arranged in a checklist format and include:

RDU Checklist

DPE Checklists including:

Hardware DPE Checklist

Solaris DPE Checklist

Network Registrar Checklist


Note Items marked with an asterisk (*) are mandatory tasks or procedures.


RDU Checklist

Table 3-1 identifies the workflow to follow when configuring the RDU.

Table 3-1 RDU Workflow Checklist

No.
Procedure
Refer to...
Installation Type

1.

Configure the system syslog service for use with BACC.

Cisco Broadband Access Center for Cable Installation Guide.

Both

2.

Access the BACC administrative user interface.

"Accessing the BACC Administrators Graphical User Interface" section on page 8-1.

Both

3.

Change the admin password.

"Accessing the BACC Administrators Graphical User Interface" section on page 8-1.

Both

4.

Add the appropriate license keys.

"Managing License Keys" section on page 10-29.

Both

5.

Configure the RDU database backup procedure.

"Backup and Recovery" section.

Component Only

6.

Configure the RDU SNMP agent.

"Using the snmpAgentCfgUtil.sh Command" section on page 12-46.

Component Only


Hardware DPE Checklist

You must perform the activities described in Table 3-2 after those described in Table 3-1, RDU Workflow Checklist.


Note Items marked with an asterisk (*) are mandatory tasks or procedures.


Table 3-2 Hardware DPE Configuration Checklist  

No.
Procedure
Refer to ...
Installation Type

1.

Change the passwords.

"password" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

2.

Configure the system syslog service for use with BACC.

Cisco Broadband Access Center for Cable Installation Guide.

Both

3.

Configure your IP address.*

"interface ethernet 0..1 ip address" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

4.

Configure the provisioning interface.*

"interface <0..1> provisioning enabled" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

5.

Configure the default hardware gateway.*

"ip default-gateway" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

6.

Configure the provisioning FQDN.

"Automatic FQDN Generation" section on page 10-35 for more information on enabling and configuring the auto generation of FQDNs.

Component Only

7.

Configure the BACC shared secret.*

"dpe shared-secret" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

8.

Configure the DPE to connect to the desired RDU.*

"dpe rdu-server (IP)" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

9.

Configure the network time protocol (NTP).

"ntp server (IP)" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

10.

Configure the primary provisioning group.*

"dpe provisioning-group primary" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

11.

Configure a hostname.*

"hostname" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

12.

Configure a domain name.*

"ip domain-name" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

13.

Configure a minimum of one name server.*

"ip name-server" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

14.

Configure the required routes to the other BACC components as well as to the devices in the network.

"ip route" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

15.

Configure the DPE SNMP agent.

SNMP Agent Commands section in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

16.

Verify that you are connected to RDU.

"Viewing Servers" section on page 9-18.

Component Only


Solaris DPE Checklist

You must perform the activities described in Table 3-3 after those described in Table 3-1, RDU Workflow Checklist.


Note This checklist applies to component installation of the Solaris DPE. A lab installation prompts for the required parameters, and automatically configures the selected technologies. Lab installations also use a single SNMP agent to monitor both the DPE and the RDU. You can configure this using either the DPE CLI or the snmpAgentCfgUtil.sh tool. See the "Using the snmpAgentCfgUtil.sh Command" section on page 12-46 for additional information.



Note Items marked with an asterisk (*) are mandatory tasks or procedures.


Table 3-3 Solaris DPE Configuration Checklist  

No.
Procedure
Refer to ...
Installation Type

1.

Configure the system syslog service for use with BACC.

Cisco Broadband Access Center for Cable Installation Guide.

Both

2.

Change the passwords.

"password" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Both

3.

Configure the provisioning interface.*

"interface ethernet [intf0|intf1]" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

4.

Configure the provisioning FQDN.

"Automatic FQDN Generation" section on page 10-35 for more information on enabling and configuring the auto generation of FQDNs.

Component Only

5.

Configure the BACC shared secret.*

"dpe shared-secret" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

6.

Configure the DPE to connect to the desired RDU.*

"dpe rdu-server (IP)" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

7.

Configure the network time protocol (NTP).

See the Solaris documentation for configuration information.

Component Only

8.

Configure the primary provisioning group.*

"dpe provisioning-group primary" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

9.

Configure the required routes to the other BACC components as well as to the devices in the network.

"ip route" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

10.

Configure the DPE SNMP agent.

SNMP Agent Commands section in the Cisco Broadband Access Center for Cable Command Line Interface Reference.

Component Only

11.

Verify that you are connected to RDU.

"Viewing Servers" section on page 9-18.

Both


Network Registrar Checklist

You must perform the activities described in Table 3-4 after those described in either Table 3-2, Hardware DPE Configuration Checklist or Table 3-3, Solaris DPE Configuration Checklist.


Caution The BACC DHCP option settings always replace any DHCP option values set within Network Registrar.


Note Items marked with an asterisk (*) are mandatory tasks or procedures.


Table 3-4 Network Registrar Workflow Checklist 

No.
Procedure
Refer to ...
Installation Type

1.

Validate the Network Registrar extensions.

Broadband Access Center for Cable Installation Guide for information on configuring valid extensions.

Both

2.

Configure the system syslog service for use with BACC.

Broadband Access Center for Cable Installation Guide for more information on configuring the system syslog service for BACC.

Both

3.

Configure client-classes/scope selection- tags that match those defined in the RDU.*

Network Registrar User's Guide for more information about configuring client-classes and scope-selection-tags.

Both

4.

Configure scopes.*

Network Registrar User's Guide for more information about configuring scopes.

Both

5.

Configure policies.*

Network Registrar User's Guide for more information about configuring policies.

Both

6.

Configure the backup procedure for the Network Registrar database.

Network Registrar User's Guide for more information about backing up the Network Registrar database.

Component Only

7.

Verify that you are connected to the correct RDU.

"Viewing Servers" section on page 9-18.

Both


Technology Workflows

This section describes the activities that you must perform when configuring BACC to support specific technologies. These configuration activities are performed subsequent to configuring BACC components and may, in limited circumstances, apply only to a lab or component installation. In these cases that appropriate indication is made.

The technology workflows described in this section are arranged in a checklist format and include:

DOCSIS Checklist

PacketCable Checklists including:

PacketCable

Non-Secure PacketCable

Euro-PacketCable

Non-Secure CableHome Provisioning Checklist


Note Items marked with an asterisk (*) are mandatory tasks or procedures.


DOCSIS Checklist

You must perform the activities described in the "Component Workflows" section, in addition to those described in Table 3-5 in order to successfully configure BACC for DOCSIS operation.

Perform the activities in this checklist in the order specified.

Table 3-5 DOCSIS Checklist  

Step
Action
Refer to ...
Configure the RDU

1.

Configure all provisioned DHCP criteria.

"Configuring DHCP Criteria" section on page 10-23 for more information.

2.

Configure provisioned classes of service.

Add all classes of service that may be used by any provisioned DOCSIS modem.

"Configuring the Class of Service" section on page 10-1.

3.

Configure the promiscuous mode of operation.

"System Defaults" section on page 10-21.

Configure Network Registrar

1.

Configure client-classes/scope-selection- tags to match those added for the provisioned DOCSIS modem DHCP criteria.

Network Registrar User's Guide for more information about configuring client-classes and scope-selection-tags.


PacketCable Checklists

BACC supports three different variations of PacketCable. This section identifies the activities that must be performed for each, including:

PacketCable

Non-Secure PacketCable

Euro-PacketCable


Note The checklists in this section assume that an appropriate PacketCable configuration file and the correct MIBs have been loaded.


PacketCable

You must perform the PacketCable related activities described in Table 3-6 after those described in the "Component Workflows" section. The PacketCable checklist involves working with almost every BACC component.

Perform the activities in this checklist in the order specified.


Note The default maximum clock skew between the KDC and the DPEs is 5 minutes.



Note Items marked with an asterisk (*) are mandatory tasks or procedures.


Table 3-6 PacketCable Checklist  

Step
Action
Refer to...
Configure the RDU

1.

Enable the autogeneration of MTA FQDNs.

"Automatic FQDN Generation" section on page 10-35 for more information on enabling and configuring the auto generation of FQDNs.

2.

Configure all provisioned DHCP criteria.

"Configuring DHCP Criteria" section on page 10-23 for more information.

3.

Configure all provisioned classes of service.

"Configuring the Class of Service" section on page 10-1 for more information.

4.

Configure an SNMPv3 cloning key.*

the "packetcable snmp key-material" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

Note This command must be run from the console mode.

Configure the DPE

1.

Configure a KDC service key.*

the "packetcable registration kdc-service-key" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

2.

Configure a privacy policy.*

the "packetcable registration policy-privacy" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

3.

Configure an SNMPv3 cloning key.*

the "packetcable snmp key-material" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

Note This command must be run from the console mode.

4.

Enable PacketCable.*

the "packetcable enable" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

5.

Configure the optional MTA file encryption.

the "packetcable registration encryption" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

Configure the KDC

1.

Obtain a KDC license from your Cisco representative and copy that file to the <BACC_HOME>/kdc directory.

"KDC Licenses" section on page 2-12.

2.

Configure a certificate chain.

"Using the PKCert.sh Tool to Manage KDC Certificates" section on page 12-41.

3.

Configure a service key pair for each DPE's provisioning FQDN.

"Using the Keygen Tool" section on page 12-45.

4.

Configure service keys for the ticket-granting-ticket (TGT).

"Using the Keygen Tool" section on page 12-45.

5.

Configure service keys for the Call Management Server.

"Using the Keygen Tool" section on page 12-45.

6.

Configure network time protocol (NTP).

Solaris documentation for more information on configuring NTP for Solaris.

Configure DHCP

1.

Configure all necessary PacketCable voice technology properties.

"Using the changeNRProperties.sh Tool" section on page 12-43.

2.

Configure dynamic DNS for the MTA scopes.

Network Registrar User's Guide for more information on configuring dynamic DNS.

3.

Configure client-classes/scope-selection- tags that match those defined in the RDU.*

Network Registrar User's Guide for more information about configuring client-classes and scope-selection-tags.

Configure DNS

1.

Configure dynamic DNS for each DHCP server.

Network Registrar User's Guide for more information on configuring dynamic DNS.

2.

Configure a zone for the KDC realm.

Network Registrar User's Guide for more information on configuring zones.

3.

Configure an SRV record for the KDC.

"Configuring the SRV Record in the Network Registrar DNS Server" section on page 10-34 and the Network Registrar User's Guide for more information on configuring SRV records.

4.

Configure records for the KDC and DPE provisioning interface names.

Network Registrar User's Guide for more information on configuring records.

Note Cisco recommends that the DNS procedure be used to configure a reverse zone for the DNS server's IP address. Some DNS clients, including nslookup, attempt to resolve the DNS server IP address to an FQDN. This may fail to retrieve any records from the DNS unless the reverse zone is present and properly configured.


Non-Secure PacketCable

You must perform the PacketCable related activities described in Table 3-7 after those described in the "Component Workflows" section. The non-secure PacketCable checklist involves working with almost every BACC component.

Perform the activities in this checklist in the order specified.


Note The default maximum clock skew between the KDC and the DPEs is 5 minutes.



Note Items marked with an asterisk (*) are mandatory tasks or procedures.


Table 3-7 Non-Secure PacketCable Checklist  

Step
Action
Refer to...
Configure the DPE

1.

Configure a KDC service key.*

the "packetcable registration kdc-service-key" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

2.

Configure a privacy policy.*

the "ipacketcable registration policy-privacy" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

3.

Configure an SNMPv3 cloning key.*

the "packetcable snmp key-material" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

Note This command must be run from the console mode.

4.

Enable PacketCable.*

the "packetcable enable" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

Configure DHCP

1.

Configure all necessary non-secure PacketCable voice technology properties.

Using the changeNRProperties.sh Tool, page 12-43.

2.

Configure dynamic DNS for the MTA scopes.

Network Registrar User's Guide for more information on configuring dynamic DNS.

3.

Configure client-classes/scope-selection- tags that match those defined in the RDU.*

Network Registrar User's Guide for more information about configuring client-classes and scope-selection-tags.

Configure DNS

1.

Configure dynamic DNS for each DHCP server.

Network Registrar User's Guide for more information on configuring dynamic DNS.

Note Cisco recommends that the DNS procedure be used to configure a reverse zone for the DNS server's IP address. Some DNS clients, including nslookup, attempt to resolve the DNS server IP address to an FQDN. This may fail to retrieve any records from the DNS unless the reverse zone is present and properly configured.


Euro-PacketCable

You must perform the Euro-PacketCable related activities described in Table 3-8 after those described in the "Component Workflows" section. The Euro- PacketCable checklist involves working with almost every BACC component.

Perform the activities in this checklist in the order specified.


Note Items marked with an asterisk (*) are mandatory tasks or procedures.


Table 3-8 Euro-PacketCable Checklist  

Step
Action
Refer to...
Configure the RDU

1.

Enable the autogeneration of MTA FQDNs.

"Automatic FQDN Generation" section on page 10-35 for more information on enabling and configuring the auto generation of FQDNs.

2.

Configure all provisioned DHCP criteria.

"Configuring DHCP Criteria" section on page 10-23 for more information.

3.

Configure all provisioned classes of service.

"Configuring the Class of Service" section on page 10-1 for more information.

4.

Configure an SNMPv3 cloning key.*

the "packetcable snmp key-material" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

Note This command must be run from the console mode.

Configure the DPE

1.

Configure a KDC service key.*

the "packetcable registration kdc-service-key" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

2.

Configure a privacy policy.*

the "ipacketcable registration policy-privacy" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

3.

Configure an SNMPv3 cloning key.*

the "packetcable snmp key-material" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

Note This command must be run from the console mode.

4.

Enable PacketCable.*

the "packetcable enable" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

5.

Configure the optional MTA file encryption.

the "packetcable registration encryption" command described in the Cisco Broadband Access Center for Cable Command Line Interface Reference and the Cisco Broadband Access Center for Cable Installation Guide.

Configure the KDC

1.

Obtain a KDC license from your Cisco representative and copy that file to the <BACC_HOME>/kdc directory.

"KDC Licenses" section on page 2-12.

2.

Configure a certificate chain using the -e switch in the PKCert.sh tool.

"Using the PKCert.sh Tool to Manage KDC Certificates" section on page 12-41.

3.

Configure a service key pair for each DPE's provisioning FQDN.

"Using the Keygen Tool" section on page 12-45.

4.

Configure service keys for the ticket-granting-ticket (TGT).

"Using the Keygen Tool" section on page 12-45.

5.

Configure service keys for the Call Management Server.

"Using the Keygen Tool" section on page 12-45.

6.

Configure network time protocol (NTP).

Solaris documentation for more information on configuring NTP for Solaris.

Configure DHCP

1.

Configure all necessary PacketCable voice technology properties.

"Using the changeNRProperties.sh Tool" section on page 12-43.

2.

Configure dynamic DNS for the MTA scopes.

Network Registrar User's Guide for more information on configuring dynamic DNS.

3.

Configure client-classes/scope-selection- tags that match those defined in the RDU.*

Network Registrar User's Guide for more information about configuring client-classes and scope-selection-tags.

Configure DNS

1.

Configure dynamic DNS for each DHCP server.

Network Registrar User's Guide for more information on configuring dynamic DNS.

2.

Configure a zone for the KDC realm.

Network Registrar User's Guide for more information on configuring zones.

3.

Configure an SRV record for the KDC.

"Configuring the SRV Record in the Network Registrar DNS Server" section on page 10-34 and the Network Registrar User's Guide for more information on configuring SRV records.

4.

Configure records for the KDC and DPE provisioning interface names.

Network Registrar User's Guide for more information on configuring records.

Note Cisco recommends that the DNS procedure be used to configure a reverse zone for the DNS server's IP address. Some DNS clients, including nslookup, attempt to resolve the DNS server IP address to an FQDN. This may fail to retrieve any records from the DNS unless the reverse zone is present and properly configured.


Non-Secure CableHome Provisioning Checklist

You must perform the activities described in the "Component Workflows" section, in addition to those described in Table 3-9 to successfully configure BACC for non-secure CableHome provisioning operation.

Perform the activities in this checklist in the order specified.

Table 3-9 Non-secure CableHome Provisioning Checklist  

Step
Action
Refer to ...
Configure the RDU

1.

Configure provisioned DHCP criteria.

Add all the DHCP criteria that will be used by the non-secure CableHome devices you will provision.

"Configuring DHCP Criteria" section on page 10-23.

2.

Configure provisioned classes of service.

Add all classes of service that may be used by any provisioned non-secure CableHome device.

"Configuring the Class of Service" section on page 10-1.

3.

Configure the promiscuous mode of operation.

"System Defaults" section on page 10-21.

Configure Network Registrar

1.

Configure the client-classes/scope- selection-tags to match those added for the provisioned non-secure CableHome DHCP criteria.

Network Registrar User's Guide for more information about configuring client-classes and scope-selection tags.



hometocprevnextglossaryfeedbacksearchhelp

Posted: Thu Feb 2 13:14:16 PST 2006
All contents are Copyright © 1992--2006 Cisco Systems, Inc. All rights reserved.
Important Notices and Privacy Statement.