Device Zeroization
Zeroization consists of erasing any and all potentially sensitive information in the switch securely and followed by sanitize operation. This includes erasure of Main memory, license, logs, cache memories, IOS-XE packages, system configs, and other memories containing packet data, NVRAM, and Flash memory.
The process of zeroization is launched upon the initiation of a user command and a subsequent trigger.
Note |
Ensure that you are familiar with the Emergency Recovery Installation procedure BEFORE attempting to test the Zeroize feature. |
On the ESS9300, the Push Button is used exclusively for triggering the Zeroization process. This process will zeroize and erase switch configuration files, or the entire flash file system, depending on the option provided under service declassify .
The Zeroization process starts as soon as the Push Button is pressed. The CLI command, service declassify , is used to set the desired action in response to the Push Button press. To prevent accidental erasure of the system configuration/image, the default setting is set to no service declassify .
Caution |
Zeroization does NOT erase removable media such as SD Card and USB Storage. This media must be removed from the system and erased or destroyed using procedures that are outside the scope of this document. |