Management and Configuration Guide K/KA/KB.15.15

In terms of physical security, access to the switch's console port and USB port are equivalent.
Keeping the switch in a locked wiring closet or other secure space helps to prevent unauthorized
physical access. As additional precautions, you have the following configuration options via the
CLI.
Disable autorun by setting an operator or manager password.
Disable or re-enable the USB autorun function via the CLI.
Enable autorun in secure mode to verify signatures in autorun command files and to decrypt
encrypted command files.
Troubleshooting autorun operations
You can verify autorun operations by checking the following items:
USB auxiliary port LEDs
The following table shows LED indications on the Auxiliary Port that allow you to identify the different
USB operation states.
MeaningStateColor
Switch is processing USB AutoRun file.Slow blinkingGreen
Switch has finished processing USB AutoRun file. This LED state indicates the AutoRun file
was successfully executed and the report files were generated. You can review the report
SolidGreen
files on a USB-enabled computer for more details. Upon removal of the USB device, the LED
turns OFF.
Indicates one or more of the following:OffN/A
No USB device has been inserted.
A USB device that cannot be recognized as a USB storage device has been inserted.
No AutoRun file can be found on the inserted USB device..
If the USB device has just been removed from the port, the switch executes any post
commands.
Processing Error. The AutoRun file stops processing when an error is encountered (for example,
no more disk space is available on the USB device to write the result and report files.) For
Fast blinkingAmber
more information on the error, remove the USB device and inspect its contents on a
USB-enabled computer.
AutoRun status files.
The following files are generated during autorun operations and written to the USB flash drive:
Report files (.xml file)—show which CLI commands have been run. The file name includes a
serial number and datetime stamp to indicate when and on which device the AutoRun file was
executed.
Result files (.txt file)—contain the CLI output for each command that was run on the switch,
allowing you to verify whether a command was executed successfully or not.
NOTE: PCM+ provides a mechanism to read these status files and capture the results of the
commands executed. It also allows you to verify the report files for their authenticity and reject files
that have not been signed.
The status files do not include any records of post commands that may have been executed after
the USB flash drive was removed from the switch.
300 File transfers