Got it

New DCN Features Cause Login Failures for New NEs Highlighted

Latest reply: Jan 10, 2022 19:06:02 390 6 10 0 3

Hello, everyone!

Today, I'd like to share a case with you.

Basic Information

Product NameVersion

OptiXtransE6608

OptiXtransE6608 R20C10

Problem Description

The OptiXtransE6608 of the R20C10 version is newly delivered at a site.NCE cannot be created on NCE through ECC communication. As a result, NEs cannot be logged in to and uploaded to NCE. The following error information is displayed.

err

Problem Analysis

1. Connectivity query

Check the ECC link management. A new device can be discovered, but the ping test fails.

ping test

2. Version Problem Analysis

To query the certificate validity time, run the following command:

        :pki-query-cert-detail-info:"PRESET_PKI_CA.CRT"

The preset KPI certificate time is 2021-06-16 08:33 to 2021-06-16 08:33.

conmand

The NE time is 2021-06-16 08:33.

NE time

The device time is not within the validity period of the PKI certificate. The certificate verification fails.

As a result, packets on the DCN channel from the gateway to the non-gateway are masked. Non-gateway NEs cannot be created and managed on NCE.

Root Cause

The DCN channel verification feature is added in V200R020C10. This feature uses the preconfigured PKI certificate for verification.

The device initialization script fixedly writes the NE time and factory time. The PKI certificate is preconfigured. The certificate takes effect at the application time. The device time is not within the valid range of the PKI certificate because the device initialization script is not the latest current time.

Solution

Using the command line to modify: Change the DTLS channel encryption mode of the gateway NE to normal. After the communication is normal, change the NE time to the latest time, and then restore the DTLS channel encryption mode.

    :cm-get-encrypt-mode;

    :cm-set-encrypt-mode:normal;

Using the NMS to Modify: On the NMS, choose Security > Communication Services > DTLS Channel Encryption Management. Select the GNE and change the mode to normal.

solution

Preventive Action   

1 Perform single-NE commissioning on the NE to synchronize the current NE time. After the NE accesses the network, synchronize the NE time with the NMS or NTP time.


2 After devices are delivered, use scripts to change the NE time to the latest time.


Welcome to leave a message below.

We study together.

Thank you!

Great share
View more
  • x
  • convention:

Good one
View more
  • x
  • convention:

This is a very valuable case, thank you for sharing!
View more
  • x
  • convention:

Great share
View more
  • x
  • convention:

Important
View more
  • x
  • convention:

Thank you for your sharing
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.