The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
This chapter describes the command-line interface (CLI) commands that you can use to manage and monitor the PacketCable voice technology on the Cisco Broadband Access Center (BAC) Device Provisioning Engine (DPE).
The commands described in this chapter are:
Use the debug service packetcable command to debug the PacketCable technology service on the DPE. Table 4-1 lists the keywords that you can use with this command. The PacketCable service on the DPE features one instance of the service, which you can configure to suit your requirements.
Before using any debug command, you must enable debugging by running the debug on command. If you run the following commands on an unlicensed DPE, a message similar to this one appears:
This DPE is not licensed. Your request cannot be serviced. Please check with your
system administrator for DPE licenses.
Use the service packetcable enable command to enable the PacketCable service on the DPE.
To enable PacketCable, you must:
•Configure at least one interface with a fully qualified domain name (FQDN) and enable provisioning. See interface ip provisioning fqdn, page 3-15, and interface ip provisioning, page 3-13.
If you do not configure an interface with an FQDN and enable provisioning on that interface, the following error appears:
Enabling packetcable requires at least one interface must have an FQDN configured and provisioning enabled
Error processing command
•Set the service key for the Key Distribution Center (KDC). See service packetcable registration kdc-service-key.
If you do not set a service key for the KDC, the following error appears:
A KDC service key must be present in order to enable PacketCable
Error processing command
After you use this command, run the dpe reload command so that the changes take effect. See dpe reload, page 3-10.
service packetcable 1..1 enable
1..1—Identifies the instance of the PacketCable service.
The PacketCable service on the DPE is by default enabled.
bac_dpe# service packetcable 1 enable
% OK (Requires DPE restart "> dpe reload")
Use the no service packetcable enable command to disable the PacketCable service on the DPE.
no service packetcable 1..1 enable
1..1—Identifies the instance of the PacketCable service.
The PacketCable service on the DPE is by default enabled.
bac_dpe# no service packetcable 1 enable
% OK (Requires DPE restart "> dpe reload")
Use the service packetcable registration encryption enable command to enable encryption of MTA configuration files.
To disable encryption of MTA configuration files, use the no form of this command. See no service packetcable registration encryption.
service packetcable 1..1 registration encryption enable
1..1—Identifies the instance of the PacketCable service.
Encryption of MTA configuration files is by default disabled.
bac_dpe# service packetcable 1 registration encryption enable
% OK
Use the no service packetcable registration encryption command to disable encryption of MTA configuration files.
To enable encryption of MTA configuration files, see service packetcable registration encryption enable.
no service packetcable 1..1 registration encryption
1..1—Identifies the instance of the PacketCable service.
Encryption of MTA configuration files is by default disabled.
bac_dpe# no service packetcable 1 registration encryption
% OK
Use the service packetcable registration kdc-service-key command to generate and set a security key for communication between the KDC and a DPE.
After you use this command, run the dpe reload command so that the changes take effect. See dpe reload, page 3-10.
service packetcable 1..1 registration kdc-service-key password
•1..1—Identifies the instance of the PacketCable service.
•password—Identifies the password, which must be from 6 to 20 characters.
Note The password that you enter must match the password that you enter while configuring the KDC using the KeyGen tool. Refer to the Cisco Broadband Access Center Administrator Guide 4.0 for information on how to use the KeyGen tool.
You can verify the service key that this command creates by viewing the dpe.properties file, which resides in the BPR_HOME/dpe/conf directory. Look for the value of the following parameter: /pktcbl/regsvr/KDCServiceKey
.
For example:
# more dpe.properties
...
/pktcbl/regsvr/KDCServiceKey=2e:d5:ef:e9:5a:4e:d7:06:67:dc:65:ac:bb:89:e3:2c:bb:
71:5f:22:bf:94:cf:2c
...
The output of this example is trimmed.
No default behavior or values.
bac_dpe# service packetcable 1 registration kdc-service-key password3
% OK (Requires DPE restart "> dpe reload")
Use the service packetcable registration policy-privacy command to set the customer policy on enforcing SNMP privacy in MTA communications.
Entering a value of zero lets the MTA choose the SNMPv3 privacy option. Entering a nonzero value means that the provisioning server sets the privacy option in SNMPv3 to a specific protocol, which is currently limited to DES.
After you use this command, run the dpe reload command so that the changes take effect. See dpe reload, page 3-10.
service packetcable 1..1 registration policy-privacy value
•1..1—Identifies the instance of the PacketCable service.
•value—Enter any zero or nonzero value to identify the customer policy. Values include:
–0—Indicates that the MTA selects the privacy option with Privacy being optional.
–1—Indicates that the policy is enforced, causing all MTAs to use Privacy. If Privacy is not used, the MTA does not start.
–32—Indicates that there is no Privacy.
–33—Indicates that Privacy is enabled for all devices.
The default value for enforcing SNMP privacy is 1.
This result occurs when you enforce SNMP privacy, using the default value of 1, causing all MTAs to use Privacy.
bac_dpe# service packetcable 1 registration policy-privacy 1
% OK (Requires DPE restart "> dpe reload">
Use the service packetcable snmp key-material command to generate and set a security key on the DPE to permit secure communication with the RDU. The secure communication channel with the RDU is used for PacketCable SNMPv3 cloning support only.
Note You must set the same security key on both the DPE and the RDU. Use the generateSharedSecret.sh command-line tool, located in the BPR_HOME/rdu/bin directory.
After you use this command, run the dpe reload command so that the changes take effect. See dpe reload, page 3-10.
To clear the SNMPv3 service key and turn off the SNMPv3 cloning support, use the no form of this command. See no service packetcable snmp key-material.
service packetcable 1..1 snmp key-material password
•1..1—Identifies the instance of the PacketCable service.
•password—Identifies the password that you create, which must be from 6 to 20 characters.
Generating a security key for secure communication with the RDU is by default disabled.
bac_dpe# service packetcable 1 snmp key-material password4
% OK (Requires DPE restart "> dpe reload")
Use the no service packetcable snmp key-material command to clear the SNMPv3 service key and turn off SNMPv3 cloning support.
After you use this command, run the dpe reload command so that the changes take effect. See dpe reload, page 3-10.
To generate and set a security key on the DPE for secure communication with the RDU, see service packetcable snmp key-material.
no service packetcable 1..1 snmp key-material
1..1—Identifies the instance of the PacketCable servicee.
Generating a security key for secure communication with the RDU is by default disabled.
bac_dpe# no service packetcable 1 snmp key-material
% OK (Requires DPE restart "> dpe reload")
Use the service packetcable snmp timeout command to dynamically set the length of time that the PacketCable SNMP service waits for a response to any SNMP `Set' operation.
service packetcable 1..1 snmp timeout time
•1..1—Identifies the instance of the PacketCable service.
•time—Indicates the length of time that the PacketCable SNMP service waits, in seconds.
The default maximum length of time that the PacketCable SNMP service waits for a response to an SNMP `Set' operation is 10 seconds.
bac_dpe# service packetcable 1 snmp timeout 15
% OK
Use the service packetcable show snmp log command to show recent log entries for the PacketCable SNMP provisioning service, which includes information about the general PacketCable SNMP provisioning service and the logging of any MTA provisioning errors or severe problems.
service packetcable 1..1 show snmp log [last 1..9999 | run]
•1..1—Identifies the instance of the PacketCable service.
•last 1..9999—Identifies the specified number of recent log entries from the PacketCable SNMP log file that you want to display. This keyword is optional.
•run—Displays all log messages from the PacketCable SNMP log file. This keyword is optional.
No default behavior or values.
This result occurs when you use the service packetcable show snmp log command to display all log entries for the PacketCable SNMP service.
bac_dpe# service packetcable 1 show snmp log
Error [SS_MSG] 2007-12-18 14:30:44,000 - SNMP Service Tracing Set To 400
...
Note The output presented in this example is trimmed.
This result occurs when you use the service packetcable show snmp log last command to display a specific number of recent log entries; in this example, the last 5 entries.
bac_dpe# service packetcable 1 show snmp log last 5
Error [SS_MSG] 2007-12-18 14:35:44,000 - SNMP Service Tracing Set To 800
This result occurs when you use the service packetcable show snmp log run command to display a running PacketCable SNMP log. The command continues to run until you press Enter.
bac_dpe # service packetcable 1 show snmp log run
Press <enter> to stop.
2007 12 17 11:43:43 CDT: %CSRC-5: Notification DPE: Device Provisioning Engine starting up
2007 12 17 11:43:44 CDT: %CSRC-6: Info DPE: Attempt to connect to RDU dpe failed;
2007 12 17 11:43:44 CDT: %CSRC-6: Info TFTP: Ready to service requests
Stopped.