Tamper detection

Tamper detection scenarios

Cisco Catalyst IR8140H routers use IR sensors and switches to detect tampering events such as module or cover removal in Unified Inventory Management (UIM) slots and the BBU unit.

  • IR sensors in UIM slots detect the presence or absence of slot covers or modules.

  • A switch on the BBU board monitors BBU removal in progress.

  • Alarms and events are generated when tampering is detected and sent to Cisco IOT-FND.

Tamper detection mechanisms and scenarios

Cisco Catalyst IR8140H routers provide IR sensors for cover detection in the UIM slots, and a switch on the BBU board for the BBU unit. For each UIM slot, IR8140H routers have an IR Time of Flight sensor to detect the distance to the slot cover when there is no UIM installed in the slot. If no cover is detected, an alarm syslog message is generated. If the router is registered to Cisco IOT-FND, a corresponding event is also sent to Cisco IOT-FND.

The cover detection applies for these scenarios:

  • Any UIM module is removed during operation.

  • The cover for an unused UIM slot is removed.

  • BBU removal detected in progress (through a switch on the BBU board).

In cases where the Supervisor (CPU) module is removed or the BBU is removed (if its alarm could not be sent when the BBU removal in progress was detected), a tamper indication is stored in the flash of the secondary MCU, which allows IR8140H routers to send an alarm to Cisco IOT-FND at a later time.


Note


The ability to send the alarm to Cisco IOT-FND depends on the WAN interface (Ethernet or LTE connectivity) being available at the time of the occurrence of the tamper detection.



Note


It is recommended to power down the module prior to physically removing it, using these CLI commands:


                        IR8140H(config)#
                        hw-module subslot 0/3 shutdown unpowered
                    

After inserting the replacement module, power it up using this command:


                        IR8140H(config)#
                        no hw-module subslot 0/3 shutdown unpowered