First connection

On power-up the device boots automatically (Buildroot Embedded Linux). The built-in CLI is sysrepo-cli, a local sysrepo client with tab completion. The simplest way to watch startup and perform the first configuration is the console.

Local console (micro-USB)

  1. Connect a micro-USB cable to the front-panel PWR/console port.

  2. Open a serial terminal at 115200 baud, 8 data bits, no parity, 1 stop bit (115200 8N1). On Linux this is typically /dev/ttyUSB0; on Windows a COM port, for example with PuTTY.

  3. Log in as root. No password is required on the local console.

Security: local root access without a password is intended for first setup. Set a root password (First login and security) and restrict physical access.

Remote login (SSH)

Default remote access settings:

Item

Default

IP address

DHCP

User

dwdm

Password

dwdm

  1. Connect an Ethernet cable to eth0. The SFP port and eth1 also work, because all three ports share one bridge and one IP address (see Management ports and the SFP (OSC) port).

  2. Find the assigned address: on the console run ifconfig. The address is on the bridge interface br0, not on the physical ports. Alternatively, look it up in your DHCP server’s lease list.

  3. Check that the device is reachable: ping IP_ADDRESS.

  4. Log in:

$ ssh dwdm@IP_ADDRESS
(dwdm@IP_ADDRESS) Password:
Connected via NETCONF [datastore target: operational]
/>

The embedded CLI (sysrepo-cli) starts automatically.

First login and security

Change the default credentials immediately.

  • dwdm password: TODO: command

  • root password: log in on the console as root, start sysrepo-cli and run:

> prepare /czechlight-system:authentication/users[name='root']/change-password
(prepare: /czechlight-system:authentication/users[name='root']/change-password) > set password-cleartext "NEWPASSWORD"
(prepare: /czechlight-system:authentication/users[name='root']/change-password) > exec 
RPC/action output:
result = success
  • SSH public key (recommended): generate a key on your PC:

ssh-keygen -t ed25519

Then add it on the device (console, as root):

  1. Start sysrepo-cli.

  2. Enter: prepare czechlight-system:authentication/users[name='root']/add-authorized-key

  3. Enter: set key '...', replacing ... with the public key in ~/.ssh/authorized_keys format, for example ssh-ed25519 AAAA... login@hostname.example.org.

  4. Enter: exec

The key is active immediately; no reboot is needed.