15-20
Cisco ONS 15454 DWDM Reference Manual, R8.5
78-18343-02
Chapter 15      Management Network Connectivity
15.2.9    Scenario 9: IP Addressing with Secure Mode Enabled
provisioned for the TCC2P Ethernet port. Both addresses reside on different subnets, providing an 
additional layer of separation between the craft access port and the ONS 15454 LAN. If secure mode is 
enabled, the IP addresses provisioned for the backplane LAN port and TCC2P Ethernet port must follow 
general IP addressing guidelines and must reside on different subnets from each other. 
In secure mode, the IP address assigned to the backplane LAN port becomes a private address, which 
connects the node to an operations support system (OSS) through a central office LAN or private 
enterprise network. A Superuser can configure the node to hide or reveal the backplane's LAN IP address 
in CTC, the routing table, or TL1 autonomous message reports.
In repeater mode, a node can be a GNE or ENE. Placing the node into secure mode automatically turns 
on SOCKS proxy and defaults the node to GNE status. However, the node can be changed back to an 
ENE. In repeater mode, an ENE’s SOCKS proxy can be disabled—effectively isolating the node beyond 
the LAN firewall—but it cannot be disabled in secure mode. To change a node’s GNE or ENE status and 
disable the SOCKS proxy, refer to the “Turn Up a Node” chapter in the Cisco ONS 15454 DWDM 
Procedure Guide.
Caution Enabling secure mode causes the TCC2P card to reboot; a TCC2P card reboot affects traffic.
Note The secure mode option does not appear in CTC if TCC2 cards are installed. If one TCC2 and one 
TCC2P card are installed in a node, secure mode will appear in CTC but it cannot be modified.
Note If both front and backplane access ports are disabled in an ENE and the node is isolated from DCC 
communication (due to user provisioning or network faults), the front and backplane ports are 
automatically reenabled. 
Figure 15-15 shows an example of secure mode ONS 15454 nodes with front-access Ethernet port 
addresses that reside on the same subnet.